The U.S. Government Accountability Office said on September 28, 2026 that industry representatives from three critical infrastructure sectors identified multiple federal cybersecurity regulations as duplicative or in conflict with each other. The findings come from a panel discussion GAO convened on July 16, 2026 with six representatives from energy, financial services, and healthcare and public health organizations.
What GAO found
GAO said the industry participants identified multiple federal cybersecurity regulations within their sectors as duplicative or conflicting with other regulations. In such cases, according to GAO, participants said it could be difficult to fully satisfy all reporting requirements while remediating cyber threats.
Participants in all three sectors pointed to the Department of Homeland Security's proposed rule for cyber incident reporting or the Securities and Exchange Commission's cybersecurity disclosure rules as duplicative and in conflict with their own sector's regulations, GAO said. Participants also identified duplication or conflict in sector-specific cybersecurity reporting requirements.
GAO said participants in all three sectors noted that progress in harmonizing federal cybersecurity regulations has been made over the past year, including federal agencies providing increased regulatory guidance for financial institutions. Half the participants agreed that this progress was limited.
Fixes the panel suggested
Participants identified several opportunities for harmonizing federal cybersecurity regulations, including those related to cybersecurity incident reporting, GAO said.
According to GAO, participants stated that defining reporting timeframes and thresholds in consistent ways could streamline requirements and reduce duplication. Participants also stated that having a lead agency to coordinate and receive incident reports would increase collaboration between government agencies and industry.
Why GAO did the study
GAO said nearly all the nation's critical infrastructure is supported by computer-based information systems and is mostly owned by the private sector, making public-private cooperation vital. Federal agencies have issued numerous regulations to help protect health data and ensure smooth operation of financial systems, among other things.
The agency cited the Office of the National Cyber Director, which it said has found that subjecting critical infrastructure sectors to multiple cybersecurity regulations can lead to conflicting guidance, inconsistencies, increased compliance costs and redundancies for regulated entities.
GAO described the publication as its third report about industry views on federal efforts to use more consistent cybersecurity regulations, and said its High Risk list calls for a national cybersecurity strategy.
How the panel was assembled
The panel included six representatives from different industry organizations within three critical infrastructure sectors that GAO's prior work identified as subject to a significant number of cybersecurity regulations: energy, financial services, and healthcare and public health.
GAO said the representatives included chief and senior executives overseeing cybersecurity, medical and industry operations, as well as regulatory affairs and legal specialists. The full report runs 15 pages, and GAO listed David B. Hinchman as the contact for more information.
What to do
- Regulated organizations in energy, financial services and healthcare can review GAO's 15-page report for the specific overlaps participants identified in federal cybersecurity reporting requirements.
- GAO says participants recommended that federal agencies define incident reporting timeframes and thresholds in consistent ways to reduce duplication.
- GAO says participants recommended designating a lead agency to coordinate and receive cyber incident reports.
Key facts and where they come from
- GAO convened the panel on July 16, 2026 with six industry representatives.
GAO convened a panel discussion on July 16, 2026. The panel included six representatives from different industry organizations within three critical infrastructure sectors
- Participants said overlapping rules complicate responding to incidents.
participants said it could be difficult to fully satisfy all reporting requirements while remediating cyber threats
- DHS's proposed incident reporting rule and SEC disclosure rules were cited by all three sectors.
participants in all three sectors noted that the Department of Homeland Security’s proposed rule for cyber incident reporting or the Securities and Exchange Commission’s cybersecurity disclosure rules were duplicative and in conflict
- Half the participants said harmonization progress over the past year was limited.
half the participants agreed that this progress was limited
- Participants suggested consistent reporting timeframes and thresholds.
Participants stated that defining reporting timeframes and thresholds in consistent ways could streamline requirements and reduce duplication.
- Participants suggested a lead agency to receive incident reports.
having a lead agency to coordinate and receive incident reports would increase collaboration between government agencies and industry
- The sectors examined were energy, financial services, and healthcare and public health.
energy, financial services, and healthcare and public health
