Caleb Skeath, a partner and cybersecurity attorney at Covington, was quoted in a FinXTech article examining how banks and credit unions already required to urgently report cybersecurity incidents to multiple regulators will soon have to add another federal agency to the list, as CISA is expected in September to implement a final rule for the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA).
Discussing a recent U.S. Government Accountability Office report that found nearly 70% of federal cybersecurity regulations across nine industries contained redundant reporting requirements, Caleb said it was a source of frustration for the financial institutions he represents. "I think the top line message is that there are a lot of reporting frameworks and regulations out there, and that the financial sector is one of the more heavily regulated ones in terms of security requirements and breach reporting requirements — something that has been consistent across the years," Caleb said.
On why reporting was especially stressful for teams that had never experienced an actual cyber attack, Caleb said, "I think that is because it's really hard to anticipate how an actual incident is going to unfold, who is going to be involved in that process and what challenges you might have to deal with."
Regarding the feedback CISA received during its town halls, Caleb said, "There was a lot of feedback from those town halls about the overlap from these CIRCIA reporting requirements with other preexisting reporting requirements. And does that lead to CISA revisiting anything that had been previously proposed, or adjusting how they might be approaching that framework overall? I think that'll be very interesting to at least keep an eye on over the next couple months."
Caleb said it was important to have a reporting plan not only to guarantee timely reporting but also to ensure a company is only sharing information that is absolutely required, advising his clients to identify one person or a few key people who can be trusted to carry out that task without saying something that could be used against the institution in a future lawsuit or regulatory investigation. "And making sure that the other relevant stakeholders who are involved know who that person is, that can really help things flow a lot more smoothly in the event of an actual incident," he said.