The proposed rule under the Cyber Incident Reporting for Critical Infrastructure Act will require covered entities to promptly disclose major cyber incidents and ransomware payments.