Since September 11, companies have been subject to the 24-hour reporting requirement for IT security vulnerabilities and cyber incidents. While the deadline has been known for some time, there is still heated debate over how practical such a short reporting window really is.
The 24-hour deadline is manageable when considering when the clock actually starts ticking: only after an organization becomes aware of an incident. The more complicated question is determining exactly when that awareness begins. That depends on how the flow of information within the detection process is documented and tracked.
An incident may have been detected four days earlier, for example, but it may not be recognized as a threat until day five, even if there is still no confirmation that an actual attack has taken place. Today’s cybersecurity landscape is already saturated with noise, including countless alerts and other sources of disruption, despite ongoing efforts to streamline processes with AI and accelerate cyber operations.
This raises another question: What happens when fully autonomous AI workflows are involved? An AI agent could already be working on resolving an issue without anyone being aware of it until the risk has already been mitigated.
I firmly believe that accountability and reporting benefit everyone involved, particularly when it comes to securely sharing information and preventing large-scale problems. Sanctions can also serve as a useful enforcement mechanism to encourage organizations to comply with these requirements.
However, it is reasonable to expect that the information available after just 24 hours will still be highly incomplete. It can take days or even weeks to develop a comprehensive picture of an incident. Even AI companies have needed days to conduct a thorough analysis of AI attack vectors and fully understand what was happening within their own environments, despite having access to the full capabilities of AI.