Featured Posts
The Government Accountability Office (GAO) released on July 22 a comprehensive assessment of federal cybersecurity requirements, and its conclusion will sound familiar to many regulated companies: overlapping requirements are widespread, reporting obligations are duplicative, and harmonization efforts have not worked.
In its report, Cybersecurity Regulations: Multiple Sectors Are Subject to Potentially Duplicative Reporting Requirements (GAO-26-108606), GAO examined cybersecurity regulations affecting private sector entities across critical infrastructure and found a substantial amount of potential for duplication and conflict across the federal government. The report arrives at a particularly apt time, as the Cybersecurity and Infrastructure Security Agency (CISA) moves toward finalizing new reporting regulations under the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA).
Subscribe to receive the latest updates from Wiley Connect

