Cyber Incident Reporting Portal
A cyber incident reporting portal is an online system that lets organizations or individuals notify a government agency or authority when they experience a cybersecurity problem, such as a breach, phishing attempt, or malware infection. Different agencies operate their own portals, so where and how you report generally depends on who you are and which authority you fall under. A cyber incident is broadly understood as an event that could jeopardize the confidentiality, integrity, or availability of digital information or information systems.
A cyber incident reporting portal is a designated intake channel through which constituents, partners, or regulated entities submit notifications of cyber incidents, phishing, malware, or vulnerabilities to a governing body. Reporting destinations are authority- and sector-specific rather than universal: CISA provides secure means for reporting incidents at the federal level; the Commonwealth of Virginia operates a separate state-level notification form; law enforcement networks are generally directed to report through the FBI's eGuardian; and defense contractors report through DoD-designated mechanisms. As of the evidence provided, the DoD's DIBNet portal has been reported as decommissioned as part of a modernization effort, meaning defense contractors should verify the current DoD-designated reporting channel and applicable DFARS obligations against authoritative sources. Practitioners should not assume that a single portal or a single report satisfies all applicable federal civilian, defense, state, or sector-specific reporting obligations, which may run concurrently; the specific portal, timelines, and content requirements must be confirmed against current official guidance for each applicable authority.
Why it matters
Cyber incident reporting portals are the operational front door to a patchwork of overlapping reporting obligations, and getting the destination wrong can leave an organization out of compliance even when it acted in good faith. Because reporting destinations are authority- and sector-specific rather than universal, where and how you report generally depends on who you are and which authority governs your systems. CISA provides secure means for federal-level reporting of incidents, phishing, malware, and vulnerabilities; the Commonwealth of Virginia operates a separate state-level notification form; law enforcement networks are generally directed to the FBI's eGuardian; and defense contractors report through DoD-designated mechanisms. A single portal or a single report should not be assumed to satisfy every applicable obligation, because federal civilian, defense, state, and sector-specific requirements may run concurrently.
Who it's relevant to
Inside Cyber Incident Reporting Portal
Common questions
Answers to the questions practitioners most commonly ask about Cyber Incident Reporting Portal.