US cyber leadership signaled near-term movement on national cybersecurity strategy and critical-infrastructure cyber regulation, emphasizing closer industry-government coordination. National Cyber Director Sean Cairncross said the forthcoming national cyber strategy aims to streamline overlapping regulations away from checklist compliance, while strengthening information-sharing mechanisms, federal modernization, critical infrastructure protection, workforce development, emerging technologies, and deterrence of foreign cyberattacks; he also highlighted work on an AI security framework and urged support for reauthorizing the 2015 Cybersecurity Information Sharing Act.
CISA indicated an update is imminent on implementing the 2022 Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) after delays and industry backlash to an earlier approach. CISA executive assistant director Nick Andersen said news is expected “in the next couple of weeks” on how the rulemaking will proceed; the final rule deadline has slipped to May 2026. CIRCIA would require critical infrastructure entities to report major cyber incidents within 72 hours and ransomware payments within 24 hours to CISA, reflecting federal efforts to standardize incident reporting and improve national visibility into significant attacks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Cairncross said the forthcoming strategy will be released 'sooner rather than later' and will address areas including federal modernization, critical infrastructure protection, workforce development, emerging technologies, and cyber deterrence.
Sean Cairncross said the U.S. government needs business help to identify regulatory friction points and improve information sharing as it develops a new national cyber strategy.
Nick Andersen, CISA's executive assistant director for cybersecurity, told reporters that news on the delayed CIRCIA rulemaking should come within weeks, though he did not say whether the process would be restarted or modified.
Following criticism from industry of an earlier draft of the CIRCIA rule, the implementation timeline slipped, with the final rule now expected in May 2026.
Although CIRCIA required CISA to publish a final implementing rule by October, the agency did not meet that deadline.
The Cyber Incident Reporting for Critical Infrastructure Act was enacted in 2022, requiring covered entities to report major cyber incidents within 72 hours and ransomware payments within 24 hours.
The 2021 Colonial Pipeline cyberattack was cited as a major incident that helped spur U.S. efforts to mandate cyber incident reporting for critical infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.