◦ Reference · Sector
PUBLIC
Federal, state, and local government entities and the contractors that run their systems. CIRCIA reporting sits alongside the patchwork of state breach laws, TSA Security Directives for pipelines and rail, FedRAMP for federal cloud workloads, and NIST CSF adoption programmes. Attention is triggered by a ransomware outage that interrupts resident services, by a vendor incident at a managed-service provider, or by a CISA "must patch" directive on a known exploited vulnerability.
/public