Incident Response

DHS Publishes New Recommendations on Cyber Incident Reporting

DHS has published a new set of recommendations to help federal agencies better report cyber incidents and protect critical infrastructure.

DHS has published a new set of recommendations to help federal agencies better report cyber incidents and protect critical infrastructure.

The US Department of Homeland Security (DHS) on Tuesday published a new document containing recommendations on how federal agencies can streamline cyber incident reporting, to help protect critical infrastructure entities.

Titled Harmonization of Cyber Incident Reporting to the Federal Government (PDF), the document offers a definition of reportable cyber incidents and of reporting timeline, and recommends the adoption of a model reporting form within federal agencies.

Additionally, the document details when incident reporting might be delayed, including situations when this action would pose a risk to “critical infrastructure, national security, public safety, or an ongoing law enforcement investigation”.

According to the DHS, federal agencies should find ways to streamline the receipt and sharing of incident reports and threat intelligence, by improving existing practices and by creating a single reporting portal, and by engaging with victims following initial incident reporting.

“The recommendations that DHS is issuing today provide needed clarity for our partners. They streamline and harmonize reporting requirements for critical infrastructure, including by clearly defining a reportable cyber incident, establishing the timeline for reporting, and adopting a model incident reporting form. These recommendations can improve our understanding of the cyber threat landscape, help victims recover from disruptions, and prevent future attacks,” Secretary of Homeland Security Alejandro N. Mayorkas said.

Developed in coordination with the Cyber Incident Reporting Council (CIRC), the document also outlines actions that the cybersecurity agency CISA should take to harmonize cyber incident reporting as it implements the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), and proposes legislative changes regarding incident reporting.

Advertisement. Scroll to continue reading.

Following the release of this document, CIRC will take steps to implement these recommendations and will continue to coordinate and harmonize the cyber incident reporting requirements for federal agencies, while DHS will coordinate with the agencies participating in the CIRC to keep the Congress informed of advancements.

“To develop these recommendations, the Cyber Incident Reporting Council analyzed over 50 different federal cyber incident reporting requirements and engaged with numerous industry and private sector stakeholders. It is imperative that we streamline these requirements. Federal agencies should be able to receive the information they need without creating duplicative burdens on victim companies that need to focus on responding to incidents and taking care of their customers,” DHS Under Secretary for Policy and CIRC Chair Robert Silvers said.

Related: DHS Develops Baseline Cybersecurity Goals for Critical Infrastructure

Related: DHS Tells Federal Agencies to Improve Asset Visibility, Vulnerability Detection

Related: DHS Connects Government, Private Sector in New Cyber Safety Review Board

Related Content

Incident Response

Police in Germany physically warned organizations about the critical PTC Windchill vulnerability tracked as CVE-2026-4681.

Government

CISA is currently operating at roughly 38% capacity (888 out of 2,341 staff) due to the DHS shutdown that began February 14, 2026.

Cybersecurity Funding

The startup’s platform leverages AI to automate forensic investigations, accelerating incident response.

Government

The government has announced a support package, but a cybersecurity expert has raised some concerns.

Incident Response

The tool includes resources to help organizations during the containment and eviction stages of incident response.

Incident Response

Ransomware is a major threat to the enterprise. Tools and training help, but survival depends on one thing: your organization’s muscle memory to respond...

Government

The proposed $491 million cut is being positioned as a “refocusing”of CISA on its core mission “while eliminating weaponization and waste.”

Government

The Trump administration has disbanded the Cyber Safety Review Board (CSRB), ending one of the few bright spots at CISA.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version