Government-imposed rules on incident reporting by organizations impacted by cyber attacks are not new – many critical infrastructure sectors have been subjected to them for decades. What is new, though, is the recent and marked acceleration in the rate at which governments are introducing new, more stringent, incident reporting rules; the widening of the scope of those rules to include new, previously unregulated industry sectors; and the broadening of the coverage of those rules to embrace smaller companies - not just the largest, dominant players, in those industries.
Whereas two of the examples cited are updating the rules applicable to sectors and organizations that are already subject to regulation, three examples of new legislation in the pipeline extend reporting rules to organizations that were previously exempt.