Law.com Subscribers SAVE 30%

Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.

Proposed Cybersecurity Rule Could Affect Many CRE Landlords

By Erik Sherman
May 01, 2024

A proposed federal cybersecurity rule from the U.S. Cybersecurity and Infrastructure Security Agency would require companies that own and operate critical infrastructure to report covered cyber incidents within 72 hours and payments made after a ransomware attack within 24 hours.

The rule broadly defines critical infrastructure. That means attacks on building systems could easily be deemed within the scope of the rule and real estate owners who lease to covered entities would likely also have to quickly report. The landlords would likely then have to monitor cybersecurity of building software — and perhaps their own internal operations software if that as well could affect the infrastructure.

The rule would apply to any entity in a critical infrastructure area that is either larger than a small business as defined by the Small Business Administration or that fits into one of many categories. Here's a list of some:

  • Owns or operates a chemical facility
  • Provides wire or radio communications
  • Owns or operates critical manufacturing, including metal; machinery; or electrical equipment, appliance, or component
  • Transportation equipment manufacturing
  • Provides critical support to or processes, stores, or transmits covered information for the Department of Defense
  • Performs emergency services, including fire and rescue, law enforcement, emergency medical services, emergency management, or public works that contribute to public health and safety
  • Bulk electric and distribution
  • Owns or operates financial services sector infrastructure
  • Banks, including all national banks, Federal savings institutions, credit unions, commodities or securities trading, Fannie Mae and Freddie Mac, and Federal branches and agencies of foreign banks
  • State, local, tribal, or territorial government agencies
  • Educational agencies
  • Those providing technology to support elections processes
  • Essential health-related services
  • Information technology entities
  • Transportation system agencies
  • Owners or operators of qualifying community water systems or publicly owned treatment works

A heck of a list and one that likely includes many tenants of CRE facilities. There are many details as to the information required in reports. All that assumes that the information is tracked, stored, and processed in a way that allows monitoring of cyber conditions and then rapid reporting.

This premium content is locked for Entertainment Law & Finance subscribers only

  • Stay current on the latest information, rulings, regulations, and trends
  • Includes practical, must-have information on copyrights, royalties, AI, and more
  • Tap into expert guidance from top entertainment lawyers and experts

For enterprise-wide or corporate acess, please contact Customer Service at [email protected] or 877-256-2473

Read These Next
Overview of Regulatory Guidance Governing the Use of AI Systems In the Workplace Image

Businesses have long embraced the use of computer technology in the workplace as a means of improving efficiency and productivity of their operations. In recent years, businesses have incorporated artificial intelligence and other automated and algorithmic technologies into their computer systems. This article provides an overview of the federal regulatory guidance and the state and local rules in place so far and suggests ways in which employers may wish to address these developments with policies and practices to reduce legal risk.

Is Google Search Dead? How AI Is Reshaping Search and SEO Image

This two-part article dives into the massive shifts AI is bringing to Google Search and SEO and why traditional searches are no longer part of the solution for marketers. It’s not theoretical, it’s happening, and firms that adapt will come out ahead.

While Federal Legislation Flounders, State Privacy Laws for Children and Teens Gain Momentum Image

For decades, the Children’s Online Privacy Protection Act has been the only law to expressly address privacy for minors’ information other than student data. In the absence of more robust federal requirements, states are stepping in to regulate not only the processing of all minors’ data, but also online platforms used by teens and children.

Revolutionizing Workplace Design: A Perspective from Gray Reed Image

In an era where the workplace is constantly evolving, law firms face unique challenges and opportunities in facilities management, real estate, and design. Across the industry, firms are reevaluating their office spaces to adapt to hybrid work models, prioritize collaboration, and enhance employee experience. Trends such as flexible seating, technology-driven planning, and the creation of multifunctional spaces are shaping the future of law firm offices.

From DeepSeek to Distillation: Protecting IP In An AI World Image

Protection against unauthorized model distillation is an emerging issue within the longstanding theme of safeguarding intellectual property. This article examines the legal protections available under the current legal framework and explore why patents may serve as a crucial safeguard against unauthorized distillation.