top of page


CIRCIA UPDATE: Cyber Incident Reporting for Critical Infrastructure Act 2022
UPDATE - Due to a lapse in appropriations for the United States Department of Homeland Security (DHS), the Cybersecurity and Infrastructure Security Agency (CISA) will be unable to hold the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) town hall meetings as scheduled for March 9 through April 2, 2026. Once DHS is re-opened, CISA will issue an updated notice with a revised town hall schedule and share the schedule on cisa.gov/circia. The continued delays as
Apr 174 min read


CIRCIA Operational Deep Dive
72 Hours to Report: Mastering the CIRCIA Reporting Windows In the world of cybersecurity, 72 hours is an eternity for a hacker, but a heartbeat for a compliance officer. Under CIRCIA, the clock starts the moment an organization "reasonably believes" a substantial cyber incident has occurred. The Dual Deadlines The mandate is specific and unforgiving: 72 Hours: To report a substantial cyber incident. 24 Hours: To report a ransomware payment, regardless of whether the inciden
Apr 141 min read


CIRCIA 2026 Reporting
CIRCIA 2026: Why the Governance Landscape for Critical Infrastructure is Changing Forever The countdown to 2026 has officially begun. For leaders across the 16 critical infrastructure sectors—from financial services to energy—the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) represents more than just another regulatory hurdle. It is a fundamental shift in how the federal government and the private sector communicate during a crisis. What is CIRCIA? Passed
Apr 141 min read
bottom of page