Sound the Alarm: Data Breach Reporting for Critical Infrastructure
New federal requirements are reshaping how organizations respond to cyber incidents—especially those tied to critical infrastructure. This session breaks down the reporting obligations to CISA and what they mean in practice as compliance expectations take effect as early as May 2026.
McDonald Hopkins' Heather Shumaker and Lucia Argento will unpack the surprisingly broad definition of “critical infrastructure” and why many organizations may fall within scope—whether they realize it or not. From understanding who is covered to building processes that support timely reporting, they will help you cut through the ambiguity and prepare for what’s ahead with clarity and confidence.
Topics include:
- History of CISA
- Reporting requirements to CISA
- Compliance expectations
- How to manage the short notice window
- Who is defined as critical infrastructure