Caleb Skeath, a partner at Covington, was quoted by Federal News Network on the Cybersecurity and Infrastructure Security Agency's (CISA) decision to postpone industry town halls on the forthcoming Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rule due to a government shutdown.
Skeath said CISA was trying to strike the right balance when it came to defining which organizations should have to report cyber incidents to the agency. "Part of the reasoning and thinking for getting this information through an incident reporting requirement is to give CISA a certain degree of visibility across the threat ecosystem, so it's not necessarily with as much of an enforcement focus as some of the other cyber incident reporting frameworks that we see," Caleb told Federal News Network. "In that regards, it's understandable there might be an interest in going fairly broad."
Caleb added that going broad can be "a double edged sword in certain respects, because if you go too broad, you might end up with more information than you can readily process or absorb."