Policymakers should fix duplicative and contradictory regulations that currently impede the government’s ability to oversee the cybersecurity of critical infrastructure, industry representatives told the Government Accountability Office during a recent panel discussion.
The industry feedback, revealed in a GAO report published on Monday, is the latest evidence that the private sector is deeply unsatisfied with the patchwork of rules governing infrastructure security in the U.S. The new report also comes as the Cybersecurity and Infrastructure Security Agency (CISA) works to finish a congressionally mandated cybersecurity incident reporting rule that could impose sweeping requirements on a broad swath of infrastructure operators.
Executives from the Edison Electric Institute (EEI), the Electric Power Supply Association, America’s Credit Unions, Fiserv, the American Academy of Family Physicians and the Massachusetts Health Data Consortium met with GAO for three hours on July 16 to discuss the regulatory environment, and the agency said all of them “identified potentially duplicative or conflicting federal cybersecurity regulations related to their sector and identified opportunities to harmonize them.”
The executives mostly identified different problematic regulations depending on their sector, but all of them named the forthcoming CISA rule and the Securities and Exchange Commission’s public disclosure requirement.
“Most participants noted that reporting thresholds, timelines, and definitions in these rules conflicted with regulations from their sector,” GAO said, “making it difficult to fully satisfy all reporting requirements and remediate cyber threats within the required time frames.”
John Miller, the executive vice president of global policy at the Information Technology Industry Council, a leading technology trade group, said the GAO report highlighted a longstanding consensus that the U.S.’s “growing patchwork of conflicting, duplicative, and excessive cybersecurity regulations demands urgent action and a more coordinated approach.”
“Policymakers must act now to strengthen cybersecurity outcomes while allowing organizations to focus resources on managing real-world threats rather than navigating unnecessary compliance complexity,” Miller said.
Infrastructure sectors grapple with unique cyber reporting burdens
In the GAO report, the energy-sector participants voiced concerns about overlap between the Transportation Security Administration’s cybersecurity reporting requirements for pipelines and the North American Electric Reliability Corporation’s Critical Infrastructure Protection standards.
Drew Maloney, EEI’s president and CEO, said electric power providers “navigate a complex mix of federal, state, and sector-specific cybersecurity regulations, where a single cyber incident can trigger reporting requirements across multiple agencies.” Maloney said lawmakers should reduce regulatory redundancy to “enable America's electric companies to focus on addressing threats to the grid and keeping the lights on for customers."
The financial-services executives interviewed by GAO said they had to meet overlapping requirements from the National Credit Union Administration and the Bank Secrecy Act, with one speaker also mentioning overlapping requirements in the Federal Trade Commission’s Safeguards Rule and the Gramm-Leach-Bliley Act. In some cases, these rules established different reporting thresholds and timelines.
Meanwhile, healthcare executives pointed to differing definitions in the CISA, SEC, and Health Insurance Portability and Accountability Act (HIPAA) reporting rules. The healthcare sector, with its vast databases of sensitive medical data, must also balance reporting requirements with information protection. Executives said HIPAA’s security and privacy restrictions appeared to conflict with the Department of Health and Human Services’ prohibition against unreasonably limiting access to health data. According to one participant, even short-term confusion over how to reconcile those two regulatory edicts could delay reporting by small healthcare providers with “limited compliance staff.”
Opportunities to rationalize rules
The executives who met with GAO staff said lawmakers and regulators had many options for reconciling the cyber regulatory patchwork, but according to the agency, they mostly agreed that “progress has been limited.”
Participants suggested streamlining incident-reporting definitions and thresholds, consolidating cybersecurity oversight under one agency such as CISA and pushing agencies to collaborate more closely with industry.
The Trump administration, like its predecessor, has declared that it wants to free companies from unnecessary cyber regulatory burdens, and the White House’s Office of the National Cyber Director (ONCD) has touted regulatory harmonization as one of its top priorities. But ONCD officials have said little about those efforts in recent months.
Industry leaders who shared comments with Cybersecurity Dive expressed a combination of support for the administration’s rhetoric and restlessness about the slow pace of progress.
Agencies “are moving in the right direction,” but “this work is far from over,” said Mike Ward, senior vice president for federal policy and government relations at the trade group TechNet.
Henry Young, senior director of policy at the software industry group BSA, said clarifying the rules was important so companies didn’t get bogged down in compliance at a time of growing digital dangers.
“Cybersecurity professionals should be focused on staying ahead of increasingly sophisticated threats — not spending scarce time and resources navigating conflicting and duplicative requirements,” Young said. “That need is only growing as frontier AI security models create powerful new capabilities for defenders and adversaries alike.”