TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Firms must report hacks to DHS in 72 hours under law

124 pointsby marc__1about 3 years ago

7 comments

ericbarrettabout 3 years ago
Here&#x27;s the text of the newly signed bill: <a href="https:&#x2F;&#x2F;www.congress.gov&#x2F;bill&#x2F;117th-congress&#x2F;house-bill&#x2F;2471&#x2F;text" rel="nofollow">https:&#x2F;&#x2F;www.congress.gov&#x2F;bill&#x2F;117th-congress&#x2F;house-bill&#x2F;2471...</a><p>The ransomware reporting stuff is at the bottom; search for &quot;ransom&quot; and you&#x27;ll find the section easily.<p>Note this is amending existing law, so think of it as a legal diff. There may be important context not presented in this text.
评论 #30700256 未加载
rectangabout 3 years ago
It&#x27;s apparently &quot;critical infrastructure operators&quot;, not all &quot;firms&quot;.<p>&gt; <i>sweeping cybersecurity legislation that will require critical infrastructure operators to quickly report data breaches and ransomware payments.</i><p>Pretty expansive though:<p>&gt; <i>The agency lists 16 broad sectors spanning health, energy, food and transportation as critical to the U.S., although the new legislation is yet to spell out precisely which companies would be required to report cyber incidents.</i><p>This data will eventually become public. So long as the DHS database exists it will be hacked eventually.
评论 #30701670 未加载
boomboomsubbanabout 3 years ago
I may be missing something, law is a pain to read, but I&#x27;m not seeing any penalty for failure to report being mentioned. So you must report or we&#x27;ll be cross with you?
评论 #30700725 未加载
评论 #30701693 未加载
评论 #30700407 未加载
bokohutabout 3 years ago
Enforcement will be what exactly?<p>How is an impacting specific data loss inexplicitly tied to one company&#x27;s compromise beyond a reasonable doubt when systems everywhere are &quot;leaking&quot;?<p>Having been involved in several financial compromise events dating back to the very earliest known I find more laws will in no way address the issue. Everyone drives the speed limit or under it too, correct? For those with experience in the financial banking realm the rules often &quot;apply to thee but not to me&quot; and yet companies are still hiding compromise events, even those ‘compliant’. While companies joining the fintech rush are held to standards and requirements that cost significant sums of both time and money all the while the large grandfathered entities and systems are allowed to continue not abiding by the same rules and laws those entities themselves set. Hypocrisy rolls on and exists everywhere and I welcome the changes to level the playing field but more laws are certain to not fix a problem which cannot be seen since the function of vision in our species is the primary driver for nearly all we do. If it cannot be seen then it must not be a &#x27;real&#x27; problem so let&#x27;s schedule more meetings to talk about it.<p>As the governments around the world continue to have meetings weekly, both publicly and privately, about the ever growing cyber issue I again reiterate that the problem lies at the source(code) and with those who write it. This is truly an issue that can only be solved through education of those writing code and it cannot be solved tomorrow. Let&#x27;s schedule another meeting to talk about it.
robin_realaabout 3 years ago
This is presumably based on the same reporting requirements that are stipulated in section 85 of GDPR: <a href="https:&#x2F;&#x2F;eur-lex.europa.eu&#x2F;legal-content&#x2F;EN&#x2F;TXT&#x2F;?uri=CELEX%3A32016R0679&amp;qid=1647443821579" rel="nofollow">https:&#x2F;&#x2F;eur-lex.europa.eu&#x2F;legal-content&#x2F;EN&#x2F;TXT&#x2F;?uri=CELEX%3A...</a>
tehwebguyabout 3 years ago
Is there any evidence that DHS employs anyone who would even understand a report about a breach?<p>Making a report to police about a crime they won’t understand sounds extremely risky for the reporter.
评论 #30701627 未加载
Brian_K_Whiteabout 3 years ago
Report every day because you can&#x27;t prove that you weren&#x27;t and you wouldn&#x27;t want to be accused of failing to report or failing to detect later.
评论 #30700041 未加载
评论 #30700021 未加载