Skip to content
TECH CEO Daily

GAO panel: conflicting cyber incident reporting rules strain critical infrastructure firms

Six industry panelists told the Government Accountability Office that overlapping deadlines, thresholds and definitions make it hard to report every attack on time and fix it.

By · Editor

· 4 min read · Fact-checked

The 60-second brief

  • 1A GAO report released September 28 says energy, finance and health panelists flagged duplicative or conflicting federal cyber rules.
  • 2Finance panelists cited reporting windows of 24 to 72 hours, 72 hours and 4 business days under different rules.
  • 3Companies should build one reporting matrix covering every regulator, threshold and clock, and track the pending CIRCIA final rule.

The news

Conflicting federal cyber incident reporting rules make it hard for critical infrastructure firms to meet every deadline while also fixing an attack, industry panelists told the Government Accountability Office (GAO) in a report released on September 28.

The report, GAO-26-109197, was requested by Sen. Gary Peters, the ranking member of the Senate Homeland Security and Governmental Affairs Committee, and Rep. Andrew Garbarino, chairman of the House Homeland Security Committee. It is the third in a series and summarizes a three-hour virtual panel held on July 16 with six representatives from the energy, financial services, and healthcare and public health sectors. They came from the Edison Electric Institute, the Electric Power Supply Association, America's Credit Unions, Fiserv, the American Academy of Family Physicians and the Massachusetts Health Data Consortium. GAO notes the views are not necessarily unanimous or representative of whole sectors.

Energy participants identified eight federal cyber regulations they viewed as duplicative or conflicting, financial services participants six, and healthcare participants four. Two were cited across all three sectors: the Department of Homeland Security's proposed rule under the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) and the Securities and Exchange Commission's cybersecurity disclosure rules. Most participants said thresholds, timelines and definitions in those rules clashed with their own sector's rules.

The clocks differ sharply. A few financial services participants cited reporting windows of 72 hours under National Credit Union Administration rules, 24 to 72 hours under the proposed CIRCIA rule depending on the type of incident, and 4 business days under SEC rules. Participants said it is difficult to work with law enforcement, meet several reporting requirements and secure a breach within those windows. A few energy participants said the same incident often goes to multiple agencies under North American Electric Reliability Corporation standards, a Department of Energy form and Transportation Security Administration pipeline rules. In healthcare, one participant said confusion over possible conflicts can delay reporting at smaller practices with limited compliance staff.

Most participants saw some progress over the past year, but several said federal progress on existing duplication has been limited. Their suggested fixes: common reporting deadlines, thresholds and definitions; a single lead agency, such as the Cybersecurity and Infrastructure Security Agency (CISA), that receives reports and shares them with other regulators; and more collaboration between agencies and industry.

Industry groups used the report to push for change. Drew Maloney, president and chief executive of the Edison Electric Institute, told Cybersecurity Dive that a single cyber incident can trigger reporting requirements across multiple agencies. Henry Young of BSA said security professionals should be "staying ahead of increasingly sophisticated threats" rather than navigating conflicting requirements. Cybersecurity Dive noted that officials at the White House Office of the National Cyber Director have said little about their harmonization work in recent months.

The numbers

Federal cyber regulations for private entities (GAO, July 2026)
117 from 37 agencies
Rules flagged by energy participants
8
Rules flagged by financial services participants
6
Rules flagged by healthcare participants
4
Reporting windows cited by finance participants
24-72 hours (proposed CIRCIA), 72 hours (NCUA), 4 business days (SEC)
Panel
6 participants, 3 sectors, July 16, 2026

Why CEOs should care

For CISOs and general counsel, the practical answer is a single reporting matrix. List every regulator that could require notice after an incident, the threshold that triggers each report, the definition of a reportable incident and the clock that starts. The shortest window, as short as 24 hours under the proposed CIRCIA rule for some incidents, should set the pace for the response plan. Decide in advance who makes the reportability call, pre-draft notices, and run tabletop exercises that include legal and communications staff, not only security teams.

For CFOs and boards, the report puts a public record behind a cost many companies already carry: staff time spent on overlapping filings while an incident is still being contained. Ask management how many regulators the company would notify for a single serious incident and whether those filings could pull responders away from containment. Public companies in regulated sectors also face a tension one participant raised between confidential reports, such as suspicious activity reports, and public disclosure under SEC rules.

For companies that want a say in the fix, the timing matters. CIRCIA includes a provision that could let an entity skip a separate CISA report if it already sends substantially similar information to another agency in a similar time frame, provided the agencies have a sharing agreement. As of August, GAO said the final rule had not been released and that provision was subject to change, so trade groups and companies still have room to press regulators on it.

The bigger picture

The panel builds on a larger GAO count. In a July 2026 report, GAO identified 117 cybersecurity regulations established by 37 federal agencies for private entities across nine critical infrastructure sectors, and found most contain the same kind of reporting requirement as at least one other rule. Congress has weighed fixes before: the Streamlining Federal Cybersecurity Regulations Act was introduced in the Senate in July 2024 and again in May 2025. In June 2026 the Congressional Research Service laid out options including a harmonized reporting framework set by law and binding cross-agency authority for the Office of the National Cyber Director, according to GAO.

What’s next

As of August, GAO said the CIRCIA final rule was expected to be finalized in September 2026, and a final update to the HIPAA security rule was expected in July 2027. Watch whether the CIRCIA rule keeps its substantially similar reporting provision and whether the White House follows its March 2026 cyber strategy, which pledged to remove burdensome or ineffective regulations, with concrete harmonization steps.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

GAOCISASECCyber regulation

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.