What happened

The Government Accountability Office published a report on Monday that captures how critical infrastructure operators experience federal cybersecurity regulation: as a set of obligations that do not line up with each other. Executives from the Edison Electric Institute, the Electric Power Supply Association, America's Credit Unions, Fiserv, the American Academy of Family Physicians and the Massachusetts Health Data Consortium met with GAO staff for three hours on 16 July. According to the agency, all of them identified requirements they considered duplicative or conflicting in their own sector, and all of them named opportunities to harmonise them.

Two rules came up in every conversation. The first is CISA's forthcoming incident reporting rule, which Congress mandated and which could impose sweeping requirements on a broad set of infrastructure operators. The second is the SEC's public disclosure requirement. Participants told GAO that the reporting thresholds, timelines and definitions in those rules conflicted with regulations their sector regulators already applied, which made it difficult to satisfy every reporting obligation and still remediate the incident inside the required time frames.

The detail is sector specific. Energy companies raised the overlap between the Transportation Security Administration's pipeline reporting requirements and NERC's Critical Infrastructure Protection standards. Financial services firms described meeting National Credit Union Administration and Bank Secrecy Act obligations at the same time, with the FTC's Safeguards Rule and Gramm-Leach-Bliley adding further layers and different reporting thresholds. Healthcare participants pointed to differing definitions across the CISA, SEC and HIPAA regimes, and to tension between HIPAA restrictions and a Department of Health and Human Services prohibition on unreasonably limiting access to health data. One participant said even short term confusion on that point could delay reporting by small providers with limited compliance staff.

GAO also recorded what industry wants: streamlined incident reporting definitions and thresholds, oversight consolidated under one agency such as CISA, and closer collaboration between agencies and the sectors they regulate. On progress so far, the report is blunt. Participants mostly agreed that progress has been limited.

Why this is a GRC story

Effort is going into reconciliation, not control. When one incident starts four reporting clocks with four definitions, the work that follows is translation between regimes. That is time and attention not spent containing the incident or notifying the people affected.

Small organisations carry the heaviest share. A large utility has a regulatory affairs function and people who know each rule by name. A rural clinic has one person doing compliance alongside another job, and a delayed report is still a late report.

Harmonisation is a control design problem. The same incident facts are being requested in incompatible formats. Aligning the schema once would reduce effort across every sector at the same time, which is why the industry asks are so specific.

What to watch

CISA's incident reporting rule is the live variable. Watch its final definitions and thresholds, and whether the SEC disclosure timeline is reconciled with it. The Office of the National Cyber Director has listed harmonisation as a priority while saying little about it in recent months, so the practical question is whether anything concrete lands before the rule does.

A useful exercise in the meantime: take one realistic incident scenario and map it through every reporting obligation your organisation carries, in each jurisdiction, and count the clocks. If producing that map takes a week, that is the finding.

Attribution: Analysis based on Cybersecurity Dive's reporting and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News