US critical infrastructure firms are obliged to report ransomware payments to the government within 72 hours, according to a new law signed by president Joe Biden in March.