Back to dashboard Read module

Quiz reading view

Quiz 01L — Cyber Incident Reporting: Multi-Framework Comparison

Use this quiz to check whether you can spot the controlling doctrine, procedural hinge, and practical move before treating Cyber Incident Reporting: Multi-Framework Comparison as learned.

Use this quiz to check whether you can spot the controlling doctrine, procedural hinge, and practical move before treating Cyber Incident Reporting: Multi-Framework Comparison as learned.

Type Quiz
Updated 2026-04-17
Reading time 6 min read
Questions 10

Check the reading before you move on.

01l-incident-reporting.md | Last updated: 2026-04-17

**DISCLAIMER:** Educational purposes only. Not legal advice.

Question 1

CIRCIA's ransomware payment reporting deadline is the tightest cybersecurity reporting clock in U.S. law. How long does a covered entity have to report a ransom payment to CISA?

Question 2

A publicly traded hospital chain suffers a ransomware attack affecting patient PHI and causing material disruption to operations. Which of the following clocks does NOT apply to this scenario?

Question 3

What is the defining feature of CIRCIA's safe harbor that distinguishes it from all other U.S. incident reporting frameworks?

Question 4

Under the SEC's cybersecurity disclosure rule (adopted July 2023, effective December 18, 2023), when does the 4-business-day clock for Form 8-K disclosure begin to run?

Question 5

NIS2 establishes a three-stage reporting structure for significant incidents. Which stage requires a 24-hour early warning to the national competent authority or CSIRT?

Question 6

Under DORA, which incident classification triggers the tightest reporting deadline of 4 hours from classification?

Question 7

The FRB/OCC/FDIC joint banking notification rule requires U.S. banking organizations to report "notification incidents" to their primary federal regulator within what timeframe?

Question 8

California's amended breach notification law (Civil Code § 1798.82), effective January 1, 2026, requires companies to notify affected California residents within how many days of discovering a breach?

Question 9

Under GDPR Article 33, when a personal data breach occurs, the data controller must notify the supervisory authority within 72 hours. The clock starts from which moment?

Question 10

A practitioner advising a client that is simultaneously subject to CIRCIA, the SEC 8-K rule, and HIPAA receives notice of a confirmed ransomware attack at 9:00 AM Monday. Ordering obligations strictly by deadline, which clock must be satisfied first?