circiatrade-pressNewsThe Broadside2 min read

HackerOne urges CISA to exempt unsolicited good-faith research from CIRCIA

The legal uncertainty lands on disclosure recipients first, a bad design choice for a rule built to collect useful reports.


TL;DR

HackerOne asked the Cybersecurity and Infrastructure Security Agency (CISA) to revise its Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rule so unsolicited good-faith security research is excluded from reportable covered cyber incidents. Inside Cybersecurity reports the June 24 filing followed CISA’s June town halls. The uncertainty matters for primes, managed service providers, state chief information security officers and government operators handling vulnerability tips: a reporting rule meant to improve visibility could turn benign disclosures into compliance events.

HackerOne’s June 24 filing asks the Cybersecurity and Infrastructure Security Agency (CISA) to fix a narrow but important problem in the proposed Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) rule: the good-faith research exclusion covers activity performed in response to a specific request, such as under a vulnerability disclosure policy or bug bounty program, but does not clearly cover independent researchers who find and report vulnerabilities without being invited first. That is the part of the disclosure workflow where the law can do accidental damage. If the recipient has to ask whether a benign report is a covered cyber incident, the rule has already converted a security lead into a legal triage problem.

Inside Cybersecurity reports HackerOne made the request after CISA’s June town halls and as the agency continues to gather input on the incident reporting regime. CISA describes CIRCIA as requiring covered entities to report covered cyber incidents and ransomware payments so it can assist victims, analyze trends and warn defenders (CISA). HackerOne’s point is that reports generated by benign research activity could work against that purpose.

The firm also uses the filing to push two broader CIRCIA themes: reciprocity for reports already submitted to another federal agency, and a narrower substantial cyber incident definition tied to the National Cyber Incident Scoring System and National Critical Functions. Those are familiar burden-control asks. The researcher carveout is more concrete. It identifies a specific overreach risk in the first email from someone trying to help, before anyone knows whether the report describes an incident, a vulnerability, or a configuration mistake.

For primes, managed service providers, state chief information security officers and agency operators, the Monday problem is simple: an unsolicited vulnerability report should start validation, intake and disclosure handling. Adding a case-by-case CIRCIA analysis at intake is how a reporting regime discourages the behavior it says it wants. If CISA wants useful incident data instead of defensive paperwork, HackerOne’s requested clarification is the sort of small sentence that matters.


Published ·Deep Fathom