ZeroHour
CyberScooppublished ()ingested @timstarks

Most federal cybersecurity reporting rules are duplicative, study finds

criticalRansomware exploited in the wildimportance 60
Full article920 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The Government Accountability Office looked at 117 rules across 37 agencies and found 70% had reporting requirements that were overlapping.

Listen to this article

0:00

Learn more.

The GAO found 80 out of 117 rules that “either contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation.” (Getty Images)

Seven out of 10 federal cyber regulations requiring written reports to federal agencies are duplicated elsewhere, a report from a government watchdog found in a report to Congress Wednesday.

And so far, efforts to de-conflict haven’t had much success, the report from the Government Accountability Office concluded.

At the request of two top lawmakers, the GAO examined federal cyber regulations at 37 agencies. It counted 80 out of 117 rules that “either contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation.”

The desire to harmonize those conflicting rules gathered steam under the Biden administration, as it undertook a more aggressive push to regulate cybersecurity than prior administrations. It has continued into the second Trump administration.

The GAO scrutinized regulations that required the private sector to report cybersecurity incidents, plans and reviews to federal agencies, as part of a study sought by House Homeland Security Chairman Andrew Garbarino, R-N.Y., and the top Democrat on the Senate counterpart to Garbarino’s panel, Gary Peters, D-Mich.

In some cases, a single critical infrastructure sector could have duplication with several agencies. For example, the Cybersecurity and Infrastructure Security Agency has been working on a regulation stemming from the 2022 Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), which would require critical infrastructure owners and operators to report when they are the victims of major attacks or make ransomware payments.

Elements of the financial services sector might fall under one of 15 preexisting cybersecurity reporting rules, depending on the agency that has oversight, but they may also be subject to the pending CIRCIA rules, GAO noted.

A 2024 national security memorandum tasked the Office of the National Cyber Director and the Department of Homeland Security to harmonize conflicting regulations, and both agencies made some progress on those goals.

But the executive branch paused some of those efforts after Trump issued an executive order in March of last year while the administration conducted a study of the 2024 memo, a study that was still underway as of last month, according to the GAO.

As such, on harmonization, “many past federal efforts have experienced delays and made limited progress,” the GAO concluded in its report Wednesday, its latest on the topic

Congress has also looked at ways to streamline cybersecurity regulations.

GAO’s study was focused only on federal rules. BreachRx, a cyber incident response firm, published its own report Wednesday looking at major cyber incidents and how overlapping regulatory reporting obligations came into play, folding in regulations from states and other sources.

More Scoops

An election worker processes mail-in ballots at the Los Angeles County Ballot Processing Center during California’s state primary election in the City of Industry, California, on June 2, 2026. Californians go to the polls Tuesday in the first round of voting for a new governor, with a tight three-way race for two run-off spots, while people in Los Angeles will also be voting for a new mayor. The state’s so-called “jungle primary” pits all comers against each other — regardless of party — with the top two vote-getters advancing to the November general election to replace term-limited Governor Gavin Newsom. (Photo by Patrick T. Fallon / AFP via Getty Images)

SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules

The 6-3 decision dismisses one lawsuit brought by states, saying they have no standing to sue because the disputed sections “neither requires nor forbids anything of anyone outside…

Digital legal compliance and government regulation concept with security icons, creative graphic style, on blurred US flag background. 3D Rendering. ismagilov, istock/Getty Images Plus

Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks

A sign marks the location of the U.S. Office of Personnel Management (OPM) headquarters building on January 29, 2025, in Washington, DC. (Photo by J. David Ake/Getty Images)

Program to rotate cyber personnel through federal agencies saw little use

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/gao-report-duplicate-cybersecurity-regulations-harmonization/