Strengthening American Cybersecurity Act of 2022


On March 15th, 2022, the White House signed into law a federal cyberattack reporting requirement aimed at protecting critical infrastructure in the United States. Key aspects of the law:
• The law impacts 16 industry sectors which include energy.
• CISA will also act as a central hub for receiving private sector incident response reports, sharing threat data, and tracking the evolution of ransomware.
• Imposes a 72 hour notification of a covered cyber security incident (SEC. 2242).
• CISA will have the authority to subpoena companies within the identified industry sectors that fail to report cybersecurity incidents or ransomware payments.
United States Congress: Strengthening American Cybersecurity Act of 2022
NPCC is publishing this security bulletin to engage and inform NPCC entities on aspects of Bulk Power System security and reliability.
TLP: WHITE
NPCC is dedicated to the continued reliability of the bulk power system in Northeastern North America
