A new bill would require ransomware victims to report payments within 48 hours
Full article594 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
It's one of numerous pieces of legislation under consideration in Congress.
Democrats introduced legislation in the House and Senate Tuesday requiring ransomware victims who pay hackers to notify the Department of Homeland Security within 48 hours of payment.
The bill would also require DHS to release a report publicly disclosing information about payments from the prior year. The report would not include identifying information about victims. The legislation, which was introduced in the Senate by Elizabeth Warren, D-Mass, also directs DHS to study the role cryptocurrency plays in ransomware attacks and produce recommendations for improving cybersecurity.
“The U.S. cannot continue to fight ransomware attacks with one hand tied behind our back,” said Rep. Deborah Ross, D-N.C., who introduced the legislation in the House. “The data that this legislation provides will ensure both the federal government and private sector are equipped to combat the threats that cybercriminals pose to our nation.”
The bill is the most recent in a collection of cybersecurity incident notification bills under consideration in Congress. The House Homeland Security Committee is considering legislation that would give DHS’s Cybersecurity and Infrastructure Security Agency the authority to create incident reporting rules that require critical infrastructure victims to report no sooner than 72 hours from a breach.
The Senate Committee on Homeland Security & Governmental Affairs, meanwhile, marks up its incident notification bill on Wednesday. The bill would require critical infrastructure owners and operators to report cyber incidents within 72 hours, and a wider range of organizations to report a ransomware payment.
Sen. Mark Warner, D-Va., has introduced a competing bill that would require critical infrastructure owners, cybersecurity incident response firms, and federal contractors to report cyber incidents to DHS within 24 hours.
Department of Homeland Security Secretary Alejandro Mayorkas, CISA director Jen Easterly and U.S. Cyber Command director Paul Nakasone have all come out in favor of incident reporting requirements.
In September, the Treasury Department issued an update on its 2020 ransomware guidance strongly discouraging the payment of ransom attacks or extortion. The advisory encourages victims to report incidents to law enforcement and said cooperation would be considered in weighing whether to bring sanctions against victims who decide to pay.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/warren-ross-ransomware-notification-bill/