Dev48
Language
  • About
  • Services
  • Industries
  • Technologies
  • Articles
  • Contacts
Book a call
    Home/Articles/Circia cyber incident reporting hackerones recommendations
Dev48

© 2026 · All rights reserved.

CIRCIA Cyber Incident Reporting: HackerOne's Recommendations

Источник: HackerOne

CIRCIA Cyber Incident Reporting: HackerOne's Recommendations

Source: HackerOne

HackerOne ubmitted comment to CISA on CIRCIA' propo ed rule . Here' what need to change to make federal cyber incident reporting focu ed, fair, and workable.

September 26, 2026

When a cyberattack hits a hospital, a power grid, or a financial institution, speed and clarity matter. Responders need to know what happened, how serious it is, and what it means for the broader national security picture. That's the core promise of the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA): a federal law requiring companies in critical sectors to report significant cybersecurity incidents to the government so threats can be better understood and stopped.

CIRCIA contains good ideas that HackerOne supports. But getting the details right matters enormously, and right now, some of those details need work.

The Cybersecurity and Infrastructure Security Agency (CISA) has been holding a series of town hall meetings this spring and summer to gather input before finalizing the rules that will implement CIRCIA. HackerOne participated in the IT services sector town hall on June 18 and submitted written comments to CISA on June 24. We made three core recommendations.

Focus on the Incidents that Actually Matter

Under the proposed rule, companies would be required to report any "substantial" cyber incident. But the current definition of "substantial" is too broad. As drafted, it could capture almost any loss of access to, or compromise of, a company's systems, regardless of how minor or routine. Think of it as a fire alarm calibrated to go off every time someone burns toast, not just when a building is on fire.

The practical consequence is predictable: CISA could be flooded with reports about low-severity events while analysts strain to find the signals that actually matter. We urged CISA to anchor the definition to real-world impact. Incidents should only be reportable when they cause meaningful harm to operations, end users, public health, national security, economic stability, or civil liberties. CISA already has tools designed for exactly this kind of risk-based assessment, including its own National Cyber Incident Scoring System. Using them to set the reporting threshold would concentrate both government and industry resources where they’re most useful.

Protect Independent Security Researchers

The proposed rule includes a welcome carve-out: cybersecurity testing done at the request of a company, such as through a bug bounty program or a formal vulnerability disclosure policy, would not count as a reportable incident. The gap is what happens when a researcher acts independently, finding and reporting a vulnerability without being formally invited to do so. This kind of unsolicited, good-faith research is routine and valuable. Researchers do it all the time, often to protect organizations that don't yet know they have a problem.

If that research can trigger a CIRCIA reporting obligation for the organization being researched, companies will be less willing to engage constructively with outside researchers, and researchers will think twice before flagging vulnerabilities at all. We asked CISA to close this gap with a simple clarification: good-faith security research should be protected whether or not it was formally requested.

Stop Asking Companies to File the Same report twice

A Department of Homeland Security council identified at least 52 separate federal cyber incident reporting requirements already on the books or in development, not counting state and local obligations. When a company is actively managing an incident, filing separate reports with multiple federal agencies simultaneously doesn't improve the government's visibility. It splits focus and burns resources that should be going toward containment and recovery.

CIRCIA was designed to be the unifying framework that simplifies this landscape. The final rule should adopt a reciprocity principle: if a company has already reported an incident to another federal agency, that report should satisfy CIRCIA's requirements by default, with CISA following up for any additional information it needs. We also renewed our recommendation that CISA publish clear, objective criteria for when another reporting requirement counts as "substantially similar" to CIRCIA's, so companies can reliably know whether they're compliant.

The Bottom Line

CIRCIA can be a genuine asset for national cybersecurity. But achieving that requires a rule that is focused on what matters, fair to the security research community, and realistic about the compliance burden companies face during an active incident. We remain committed to working with CISA to get this right. You can read our full written comments here.

Follow the HackerOne policy blog for expert insights and updates that matter to security leaders.

About the Author

Michael Woolslayer

Policy Counsel

Michael is Policy Counsel at HackerOne, where he supports public policy efforts to address cybersecurity and AI security challenges and enable good faith security and safety research.

← All articles

More in Cybersecurity

All →
The Infostealer Incursion: How Stolen Credentials Breach Cloud, Code, and AI Environments
Wiz

The Infostealer Incursion: How Stolen Credentials Breach Cloud, Code, and AI Environments

Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?
Rapid7

Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?

Wiz Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 2026
Wiz

Wiz Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 2026

Protéger votre téléviseur connecté et votre boîtier contre le piratage
Kaspersky

Protéger votre téléviseur connecté et votre boîtier contre le piratage

Key source of economic growth in Canada may be overlooked, new research reveals
PwC

Key source of economic growth in Canada may be overlooked, new research reveals

Building trust and governance as agentic AI scales
PwC

Building trust and governance as agentic AI scales

More from HackerOne

CTEM for Enterprise: Scaling Continuous Exposure Management
HackerOne

CTEM for Enterprise: Scaling Continuous Exposure Management

EU CRA Reporting Goes Live This Friday. Are You Ready?
HackerOne

EU CRA Reporting Goes Live This Friday. Are You Ready?

Return on Mitigation
HackerOne

Return on Mitigation

Project Glasswing: Running a Frontier AI Model on Our Codebase
HackerOne

Project Glasswing: Running a Frontier AI Model on Our Codebase