/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

A look at efforts to shape federal rules for companies disclosing cyberattacks, with a group representing Alphabet and Amazon pushing for a 72-hour window

David Uberti / Wall Street Journal :

Wall Street Journal David Uberti

Context & Ripple Effects

In August 2021, a trade group speaking for Alphabet and Amazon entered the rulemaking fight over federal cyberattack disclosure, arguing for a 72-hour window before companies must report an intrusion. The push was a counterbid against the direction regulators were already moving: US bank regulators had just settled on a much tighter 36-hour reporting clock for banks, effective May 2022.

The lobbying lost ground on every front that followed. The SEC moved toward a four-day requirement for public companies (floored as a consideration in early 2022 before being formally approved in July 2023), while investment funds and advisers were proposed an even stricter 48-hour clock. The industry's preferred window ended up the loosest deadline in the entire regime rather than the standard.

First-order effects

  • Alphabet, Amazon, and other members of the trade group get materially more investigation time under their proposed 72-hour window than under any rule actually adopted — the gap between their ask and the final four-day SEC rule is the direct stake in this fight.

Second-order effects

  • Companies operating across sectors now face stacked, inconsistent clocks — roughly 36 hours for banks, 48 proposed for funds and advisers, four business days for public filers — forcing compliance teams to build to the tightest applicable deadline rather than any single standard.

Third-order effects

  • Cyberattack disclosure is hardening from voluntary practice into sector-by-sector mandatory infrastructure, with the timing of each clock set through negotiation between industry groups and regulators — making lobbying on disclosure windows a recurring, structural cost of operating regulated digital businesses.

The trend: US cyberattack reporting is consolidating into mandatory, sector-specific disclosure regimes whose deadlines keep tightening relative to what industry lobbies request.

Discussion

  • @dnvolz Dustin Volz on x
    Companies are pushing to narrow legislation that would require them to report cyberattacks to the U.S. government, as a series of hacks has added momentum to a nearly decadelong effort in Congress to approve such a law. https://www.wsj.com/...
  • @weldpond Chris Wysopal on x
    The Cyber Incident Notification Act of 2021 would require federal agencies, designated critical infrastructure companies and cyber incident response firms to report hacks “not later than 24 hrs after the confirmation of a intrusion or potential intrusion.” https://www.wsj.com/...