LIVE · cybersecurity feed
Live wire
security

Most federal cybersecurity reporting rules are duplicative, study finds

The Government Accountability Office looked at 117 rules across 37 agencies and found 70% had reporting requirements that were overlapping. The post Most federal cybersecurity reporting rules are duplicative, study finds appeared first on CyberScoop.

zeroday.news · 10d ago

A recent report from the Government Accountability Office (GAO) has found that a significant majority of federal cybersecurity reporting requirements are duplicative. The study, conducted at the request of House Homeland Security Chairman Andrew Garbarino and Senate Homeland Security and Governmental Affairs Committee ranking member Gary Peters, examined 117 rules across 37 federal agencies.

The GAO determined that 80 of these 117 rules, or approximately 70%, contained reporting requirements that either applied the same kind of reporting to a specific sector or were identical to requirements found in at least one other regulation. This widespread overlap creates a complex and often redundant compliance landscape for the private sector.

The report specifically scrutinized regulations that mandate private companies to submit cybersecurity incident reports, plans, and reviews to federal agencies. The GAO highlighted that efforts to harmonize these conflicting rules have largely been delayed or have made limited progress.

For instance, the Cybersecurity and Infrastructure Security Agency (CISA) is currently developing a regulation under the 2022 Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA). This forthcoming rule will require critical infrastructure owners and operators to report major cyberattacks and ransomware payments. However, the GAO noted that elements of the financial services sector, for example, could already be subject to up to 15 existing cybersecurity reporting rules, depending on their oversight agency, in addition to the impending CIRCIA requirements.

The Biden administration had initiated a push to regulate cybersecurity more aggressively and to harmonize conflicting regulations. A 2024 national security memorandum specifically tasked the Office of the National Cyber Director (ONCD) and the Department of Homeland Security (DHS) with addressing these overlaps. While both agencies made some progress, these harmonization efforts were subsequently paused after the Trump administration issued an executive order in March of the previous year to conduct a study of the 2024 memo. This study was still ongoing as of last month, according to the GAO.

The GAO's findings underscore a persistent challenge in federal cybersecurity policy, where numerous agencies have independently developed reporting requirements, leading to a fragmented and often burdensome system for regulated entities. The report focused exclusively on federal regulations, though other analyses have also considered the impact of state-level and other reporting obligations.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.