The Cybersecurity and Infrastructure Security Agency (CISA) announced it will hold sector-by-sector virtual town halls to gather additional industry feedback on its long-delayed rulemaking under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA). The proposed regulation would require covered critical infrastructure entities to report significant cyber incidents within 72 hours and ransomware payments within 24 hours, but key details—such as which entities are covered, how to treat small businesses, what incident examples trigger reporting, and how to avoid conflicts with existing regulatory regimes—remain contentious and are a focus of the sessions.
Separately, CISA leadership briefed staff on an impending Cybersecurity Division reorganization driven by resource constraints, including plans to deprioritize or shut down some programs to concentrate on higher-profile goals such as operational technology (OT) security and core national cyber defense functions. The internal messaging emphasized doing more with fewer personnel following a period of layoffs, retirements, and other disruptions, while refocusing the division on delivering actionable cyber intelligence to partners and coordinating broader “national cybersecurity defense” planning and operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
CISA Executive Assistant Director for Cybersecurity Nick Andersen said updates on the CIRCIA rule are expected in the next couple of weeks, though he did not confirm whether the agency will continue the current rulemaking process or restart it.
CISA said it will host seven sector-by-sector virtual town halls to gather additional industry feedback on the delayed CIRCIA rule. The agency is seeking input on report contents, sector applicability, treatment of small businesses, subpoena use, and how to reduce reporting burden while preserving useful threat information.
CISA disclosed plans to reorganize its Cybersecurity Division, reducing or shutting down some programs to focus limited resources on higher-priority missions, including operational technology security. The agency said it would publish a strategy document followed roughly 60 days later by an implementation plan with timelines and performance measures.
CISA published its proposed rule to implement CIRCIA, outlining requirements for covered organizations to notify the government within 72 hours of major cyber incidents. The proposal triggered debate over which entities should be covered and what reporting thresholds should apply.
Congress enacted the Cyber Incident Reporting for Critical Infrastructure Act, requiring covered critical infrastructure entities to report significant cyber incidents to CISA within 72 hours and ransomware payments within 24 hours.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecyberscoop.com
Open sourcecybersecuritydive.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.