{"id":8855,"date":"2026-07-22T16:04:43","date_gmt":"2026-07-22T21:04:43","guid":{"rendered":"https:\/\/cyberscoop.com\/?p=89934"},"modified":"2026-07-22T16:04:43","modified_gmt":"2026-07-22T21:04:43","slug":"most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2026\/07\/22\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds\/","title":{"rendered":"Most federal cybersecurity reporting rules are duplicative, study finds"},"content":{"rendered":"<p><head> <meta charset=\"UTF-8\"> <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\"> <meta name=\"robots\" content=\"index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1\"> <!-- This site is optimized with the Yoast SEO Premium plugin v24.5 (Yoast SEO v27.1.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ --> <title>70% of federal cybersecurity reporting rules are duplicated, GAO finds | CyberScoop<\/title> <meta name=\"description\" content=\"A new GAO report reveals 70% of federal cybersecurity reporting rules overlap, while efforts to streamline redundant requirements continue to face delays.\"> <link rel=\"canonical\" href=\"https:\/\/cyberscoop.com\/gao-report-duplicate-cybersecurity-regulations-harmonization\/\"> <meta property=\"og:locale\" content=\"en_US\"> <meta property=\"og:type\" content=\"article\"> <meta property=\"og:title\" content=\"Most federal cybersecurity reporting rules are duplicative, study finds\"> <meta property=\"og:description\" content=\"A new GAO report reveals 70% of federal cybersecurity reporting rules overlap, while efforts to streamline redundant requirements continue to face delays.\"> <meta property=\"og:url\" content=\"https:\/\/cyberscoop.com\/gao-report-duplicate-cybersecurity-regulations-harmonization\/\"> <meta property=\"og:site_name\" content=\"CyberScoop\"> <meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/cyberscoop\/\"> <meta property=\"article:published_time\" content=\"2026-07-22T21:04:43+00:00\"> <meta property=\"article:modified_time\" content=\"2026-07-22T21:04:46+00:00\"> <meta property=\"og:image\" content=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-5.jpg\"> <meta property=\"og:image:width\" content=\"1999\"> <meta property=\"og:image:height\" content=\"1499\"> <meta property=\"og:image:type\" content=\"image\/jpeg\"> <meta name=\"author\" content=\"Tim Starks\"> <meta name=\"twitter:card\" content=\"summary_large_image\"> <meta name=\"twitter:creator\" content=\"@timstarks\"> <meta name=\"twitter:site\" content=\"@CyberScoopNews\"> <!-- \/ Yoast SEO Premium plugin. --> <link rel=\"dns-prefetch\" href=\"\/\/securepubads.g.doubleclick.net\">\n<link rel=\"dns-prefetch\" href=\"\/\/use.typekit.net\">\n<link rel=\"alternate\" type=\"application\/rss+xml\" title=\"CyberScoop \u00bb Feed\" href=\"https:\/\/cyberscoop.com\/feed\/\">\n<link rel=\"alternate\" type=\"application\/rss+xml\" title=\"CyberScoop \u00bb Comments Feed\" href=\"https:\/\/cyberscoop.com\/comments\/feed\/\"> <link rel=\"stylesheet\" id=\"all-css-2\" href=\"https:\/\/cyberscoop.com\/wp-includes\/css\/dist\/block-library\/style.min.css?m=1784312972g\" type=\"text\/css\" media=\"all\"> <link rel=\"stylesheet\" id=\"all-css-6\" href=\"https:\/\/cyberscoop.com\/wp-content\/mu-plugins\/search\/elasticpress\/dist\/css\/related-posts-block-styles.min.css?m=1784654430g\" type=\"text\/css\" media=\"all\"> <link rel=\"stylesheet\" id=\"all-css-8\" href=\"https:\/\/cyberscoop.com\/wp-content\/themes\/scoopnewsgroup\/dist\/css\/frontend.css?m=1782867887g\" type=\"text\/css\" media=\"all\">\n<link rel=\"stylesheet\" id=\"typekit-css\" href=\"https:\/\/use.typekit.net\/itk2qbh.css?ver=9519dd464d894b805a10\" media=\"all\"> <link rel=\"https:\/\/api.w.org\/\" href=\"https:\/\/cyberscoop.com\/wp-json\/\"><link rel=\"alternate\" title=\"JSON\" type=\"application\/json\" href=\"https:\/\/cyberscoop.com\/wp-json\/wp\/v2\/posts\/89934\"><meta name=\"generator\" content=\"WordPress 6.8.6\">\n<link rel=\"shortlink\" href=\"https:\/\/cyberscoop.com\/?p=89934\">\n<link rel=\"alternate\" title=\"oEmbed (JSON)\" type=\"application\/json+oembed\" href=\"https:\/\/cyberscoop.com\/wp-json\/oembed\/1.0\/embed?url=https%3A%2F%2Fcyberscoop.com%2Fgao-report-duplicate-cybersecurity-regulations-harmonization%2F\">\n<link rel=\"alternate\" title=\"oEmbed (XML)\" type=\"text\/xml+oembed\" href=\"https:\/\/cyberscoop.com\/wp-json\/oembed\/1.0\/embed?url=https%3A%2F%2Fcyberscoop.com%2Fgao-report-duplicate-cybersecurity-regulations-harmonization%2F&amp;format=xml\"> <!-- Google Tag Manager --> <!-- End Google Tag Manager --> <link rel=\"icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=32\" sizes=\"32x32\">\n<link rel=\"icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=192\" sizes=\"192x192\">\n<link rel=\"apple-touch-icon\" href=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=180\">\n<meta name=\"msapplication-TileImage\" content=\"https:\/\/cyberscoop.com\/wp-content\/uploads\/sites\/3\/2023\/01\/cropped-cs_favicon-2.png?w=270\"> <\/head><body class=\"wp-singular post-template-default single single-post postid-89934 single-format-standard wp-theme-scoopnewsgroup wp-child-theme-cyberscoop\" id=\"readabilityBody\"> <a href=\"https:\/\/cyberscoop.com\/gao-report-duplicate-cybersecurity-regulations-harmonization\/#main\" class=\"skip-to-content-link visually-hidden-focusable\">Skip to main content<\/a> <\/p>\n<div class=\"ad ad--top ad--top-desktop\">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p> <main id=\"main\" role=\"main\" tabindex=\"-1\"> <\/p>\n<div class=\"ad ad--top ad--top-mobile\">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<section id=\"stickybar\" class=\"stickybar stickybar--newsletter js-stickybar\" readability=\"0.82\"> <button class=\"stickybar__close js-stickybar-close\" aria-controls=\"stickybar\"> <svg class=\"icon icon--close\" width=\"21\" height=\"22\" viewBox=\"0 0 21 22\" fill=\"none\"><path d=\"m.822.518-.805.805L9.695 11 .017 20.678l.805.805 9.678-9.678 9.677 9.678.806-.805L11.305 11l9.678-9.677-.806-.805-9.677 9.677L.822.518Z\" fill=\"currentColor\" \/><\/svg> <span class=\"visually-hidden\">Close<\/span> <\/button> <\/section>\n<article class=\"single-article content\">\n<div class=\"single-article__container js-single-article-content\">\n<header class=\"single-article__header \" readability=\"25.799173553719\">\n<div class=\"single-article__header-content\" readability=\"34.56\">\n<p> The Government Accountability Office looked at 117 rules across 37 agencies and found 70% had reporting requirements that were overlapping. <\/p>\n<p> <!-- Listen to this article section --> <!-- Audio Element --><br \/>\n<audio id=\"audio-player\" src=\"https:\/\/wp-tts-cdn.api.scpnewsgrp.com\/cyberscoop\/89934\/english.openai.mp3\"><\/audio> <\/p>\n<div readability=\"11\">\n<div>\n<p>Listen to this article<\/p>\n<p> <!-- Countdown Timer --> <\/p>\n<p>0:00<\/p>\n<\/p><\/div>\n<p> <!-- Tooltip --> <\/p>\n<p> <span id=\"tts-tooltip\">Learn more.<\/span> <span> This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment. <\/span> <\/p>\n<\/div>\n<p> <!-- End of audio player --> <\/div>\n<div class=\"single-article__cover-wrap\">\n<figure class=\"single-article__cover\"> <img data-recalc-dims=\"1\" fetchpriority=\"high\" width=\"640\" height=\"480\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds.jpg?resize=640%2C480&#038;ssl=1\" class=\"single-article__cover-image wp-post-image\" alt decoding=\"async\" fetchpriority=\"high\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-5.jpg 1999w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-5.jpg?resize=300,225 300w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-5.jpg?resize=768,576 768w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-5.jpg?resize=1024,768 1024w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-5.jpg?resize=1536,1152 1536w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-5.jpg?resize=600,450 600w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-5.jpg?resize=224,168 224w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-5.jpg?resize=449,337 449w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-5.jpg?resize=900,675 900w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-5.jpg?resize=1124,843 1124w\" sizes=\"(max-width: 900px) 100vw, 900px\"><figcaption> The GAO found 80 out of 117 rules that \u201ceither contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation.\u201d (Getty Images) <\/figcaption><\/figure>\n<\/p><\/div>\n<\/header>\n<div class=\"single-article__content\">\n<div class=\"single-article__content-inner has-drop-cap\"> <html readability=\"30.421807747489\"><body readability=\"67.378463696948\"><\/p>\n<p>Seven out of 10 federal cyber regulations requiring written reports to federal agencies are duplicated elsewhere, a report from a government watchdog found in a report to Congress Wednesday.<\/p>\n<p>And so far, efforts to de-conflict haven\u2019t had much success, <a href=\"https:\/\/www.gao.gov\/assets\/gao-26-108606.pdf\">the report<\/a> from the Government Accountability Office concluded.<\/p>\n<p>At the request of two top lawmakers, the GAO examined federal cyber regulations at 37 agencies. <a href=\"https:\/\/www.gao.gov\/products\/gao-26-108606\">It counted<\/a> 80 out of 117 rules that \u201ceither contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation.\u201d<\/p>\n<p>The desire to <a href=\"https:\/\/cyberscoop.com\/tag\/cybersecurity-harmonization\/\">harmonize those conflicting rules<\/a> gathered steam under the Biden administration, as it undertook a more aggressive push to <a href=\"https:\/\/cyberscoop.com\/bidens-cybersecurity-legacy-a-big-shift-to-private-sector-responsibility\/\">regulate cybersecurity<\/a> than prior administrations. <a href=\"https:\/\/cyberscoop.com\/trump-cybersecurity-strategy\/\">It has continued<\/a> into the second Trump administration.<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>The GAO scrutinized regulations that required the private sector to report cybersecurity incidents, plans and reviews to federal agencies, as part of a study sought by House Homeland Security Chairman Andrew Garbarino, R-N.Y., and the top Democrat on the Senate counterpart to Garbarino\u2019s panel, Gary Peters, D-Mich.<\/p>\n<p>In some cases, a single critical infrastructure sector could have duplication with several agencies. For example, the Cybersecurity and Infrastructure Security Agency has been working on a regulation stemming from the 2022 <a href=\"https:\/\/cyberscoop.com\/tag\/circia\/\">Cyber Incident Reporting for Critical Infrastructure Act<\/a> (CIRCIA), which would require critical infrastructure owners and operators to report when they are the victims of major attacks or make ransomware payments.<\/p>\n<p>Elements of the financial services sector might fall under one of 15 preexisting cybersecurity reporting rules, depending on the agency that has oversight, but they may also be subject to the pending CIRCIA rules, GAO noted.<\/p>\n<p>A 2024 national security memorandum tasked the Office of the National Cyber Director and the Department of Homeland Security to harmonize conflicting regulations, and both agencies made some progress on those goals.<\/p>\n<p>But the executive branch paused some of those efforts after Trump issued an executive order in March of last year while the administration conducted a study of the 2024 memo, a study that was still underway as of last month, according to the GAO.<\/p>\n<div class=\"ad ad--inline_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<p>As such, on harmonization, \u201cmany past federal efforts have experienced delays and made limited progress,\u201d the GAO concluded in its report Wednesday, its latest <a href=\"https:\/\/www.gao.gov\/products\/gao-25-108436\">on the topic<\/a>.&nbsp;<\/p>\n<p>Congress has also <a href=\"https:\/\/www.congress.gov\/crs-product\/R49009\">looked at ways<\/a> to streamline cybersecurity regulations.<\/p>\n<p>GAO\u2019s study was focused only on federal rules. BreachRx, a cyber incident response firm, published its <a href=\"https:\/\/info.breachrx.com\/hubfs\/BreachRx%20Report_Regulatory%20Concurrency_Why%20Cyber%20Incident%20Reporting%20Has%20Become%20a%20System-Scale%20Problem.pdf\">own report<\/a> Wednesday looking at major cyber incidents and how overlapping regulatory reporting obligations came into play, folding in regulations from states and other sources.<\/p>\n<p><\/body> <\/p>\n<footer class=\"single-article__footer\">\n<div class=\"author-card\" readability=\"7.7216117216117\">\n<div class=\"author-card__avatar\">\n<figure class=\"author-card__image-wrap\"> <img data-recalc-dims=\"1\" decoding=\"async\" class=\"author-card__image\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-1.jpg?w=640&#038;ssl=1\" alt=\"Tim Starks\"> <\/figure>\n<\/p><\/div>\n<div class=\"author-card__details\" readability=\"10.901098901099\">\n<h4 class=\"author-card__name\">Written by Tim Starks<\/h4>\n<p> Tim Starks is senior reporter at CyberScoop. His previous stops include working at The Washington Post, POLITICO and Congressional Quarterly. An Evansville, Ind. native, he&#8217;s covered cybersecurity since 2003. Email Tim here: <a href=\"mailto:tim.starks@cyberscoop.com\">tim.starks@cyberscoop.com<\/a>. <\/div>\n<\/p><\/div>\n<div class=\"single-article__tags-container\">\n<h4 class=\"single-article__tags-title\">In This Story<\/h4>\n<\/p><\/div>\n<\/footer>\n<p> <\/html><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"single-article__ads js-single-article-sidebar\">\n<div class=\"ad ad--sidebar js-single-article-sidebar-5 ad--rightrail_1 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div class=\"ad ad--sidebar js-single-article-sidebar-4 ad--rightrail_2 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div class=\"ad ad--sidebar js-single-article-sidebar-3 ad--rightrail_3 \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div><\/div>\n<\/article>\n<div class=\"popular-stories popular-stories--single-post\">\n<div class=\"popular-stories__container\">\n<h2 class=\"popular-stories__title\"> More Scoops <\/h2>\n<div class=\"popular-stories__stories\">\n<div class=\"popular-stories__cards\">\n<article class=\"post-item post-item--popular-stories-cards \" readability=\"21.283163265306\">\n<figure class=\"post-item__thumbnail\"> <a class=\"post-item__thumbnail-link\" href=\"https:\/\/cyberscoop.com\/opm-federal-rotational-cyber-workforce-program-gao\/\" tabindex=\"-1\"> <img data-recalc-dims=\"1\" loading=\"lazy\" width=\"505\" height=\"337\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-2.jpg?resize=505%2C337&#038;ssl=1\" class=\"attachment-ratio-16-9-md size-ratio-16-9-md wp-post-image\" alt decoding=\"async\" loading=\"lazy\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-6.jpg 7582w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-6.jpg?resize=300,200 300w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-6.jpg?resize=768,512 768w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-6.jpg?resize=1024,683 1024w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-6.jpg?resize=1536,1024 1536w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-6.jpg?resize=2048,1365 2048w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-6.jpg?resize=600,400 600w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-6.jpg?resize=252,168 252w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-6.jpg?resize=505,337 505w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-6.jpg?resize=1012,675 1012w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-6.jpg?resize=1264,843 1264w\" sizes=\"auto, (max-width: 505px) 100vw, 505px\"> <\/a><figcaption class=\"screen-reader-text\"> A sign marks the location of the U.S. Office of Personnel Management (OPM) headquarters building on January 29, 2025, in Washington, DC. (Photo by J. David Ake\/Getty Images) <\/figcaption><\/figure>\n<header class=\"post-item__meta\" readability=\"2.4770642201835\">\n<h3 class=\"post-item__title\"> <a class=\"post-item__title-link\" href=\"https:\/\/cyberscoop.com\/opm-federal-rotational-cyber-workforce-program-gao\/\"> Program to rotate cyber personnel through federal agencies saw little use <\/a> <\/h3>\n<p> The number of people who got approval to be in the Federal Rotational Cyber Workforce program was in the single digits, GAO found. <\/p>\n<div class=\"post-item__byline\"> <span class=\"post-item__author\"> <span>By <\/span> <a class=\"post-item__author-link\" href=\"https:\/\/cyberscoop.com\/author\/tim-starkscyberscoop-com\/\"> Tim Starks <\/a> <\/span> <\/div>\n<p><!-- .byline --> <\/header>\n<p><!-- .post-item__meta --> <\/article>\n<article class=\"post-item post-item--popular-stories-cards \">\n<figure class=\"post-item__thumbnail\"> <a class=\"post-item__thumbnail-link\" href=\"https:\/\/cyberscoop.com\/dhs-anchor-ci-cybersecurity-information-sharing\/\" tabindex=\"-1\"> <img data-recalc-dims=\"1\" loading=\"lazy\" width=\"252\" height=\"168\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-3.jpg?resize=252%2C168&#038;ssl=1\" class=\"attachment-ratio-16-9-sm size-ratio-16-9-sm wp-post-image\" alt decoding=\"async\" loading=\"lazy\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-7.jpg 5760w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-7.jpg?resize=300,200 300w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-7.jpg?resize=768,512 768w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-7.jpg?resize=1024,683 1024w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-7.jpg?resize=1536,1024 1536w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-7.jpg?resize=2048,1365 2048w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-7.jpg?resize=600,400 600w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-7.jpg?resize=252,168 252w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-7.jpg?resize=506,337 506w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-7.jpg?resize=1013,675 1013w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-7.jpg?resize=1265,843 1265w\" sizes=\"auto, (max-width: 252px) 100vw, 252px\"> <\/a><figcaption class=\"screen-reader-text\"> The information sharing effort will allow intelligence community agencies to interact with key owners and operators of water, power, internet and telecommunications to coordinate on cyberattacks and digital vulnerabilities. (Getty Images) <\/figcaption><\/figure>\n<header class=\"post-item__meta\">\n<h3 class=\"post-item__title\"> <a class=\"post-item__title-link\" href=\"https:\/\/cyberscoop.com\/dhs-anchor-ci-cybersecurity-information-sharing\/\"> DHS to unveil replacement council for critical infrastructure cybersecurity <\/a> <\/h3>\n<div class=\"post-item__byline\"> <span class=\"post-item__author\"> <span>By <\/span> <a class=\"post-item__author-link\" href=\"https:\/\/cyberscoop.com\/author\/derek-johnson\/\"> Derek B. Johnson <\/a> <\/span> <\/div>\n<p><!-- .byline --> <\/header>\n<p><!-- .post-item__meta --> <\/article>\n<article class=\"post-item post-item--popular-stories-cards \">\n<figure class=\"post-item__thumbnail\"> <a class=\"post-item__thumbnail-link\" href=\"https:\/\/cyberscoop.com\/fcc-undersea-cable-regulations-national-security\/\" tabindex=\"-1\"> <img data-recalc-dims=\"1\" loading=\"lazy\" width=\"253\" height=\"168\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-4.jpg?resize=253%2C168&#038;ssl=1\" class=\"attachment-ratio-16-9-sm size-ratio-16-9-sm wp-post-image\" alt decoding=\"async\" loading=\"lazy\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-8.jpg 6048w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-8.jpg?resize=300,200 300w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-8.jpg?resize=768,511 768w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-8.jpg?resize=1024,681 1024w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-8.jpg?resize=1536,1022 1536w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-8.jpg?resize=2048,1363 2048w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-8.jpg?resize=600,399 600w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-8.jpg?resize=253,168 253w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-8.jpg?resize=507,337 507w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-8.jpg?resize=1015,675 1015w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2026\/07\/most-federal-cybersecurity-reporting-rules-are-duplicative-study-finds-8.jpg?resize=1267,843 1267w\" sizes=\"auto, (max-width: 253px) 100vw, 253px\"> <\/a><figcaption class=\"screen-reader-text\"> LONDON, ENGLAND \u2013 APRIL 14: SubConnect display a cable-mounted wet instrament sensor pod enabling remote monitoring away from the main sensor for subsea fibre optic cables during the UDT, Undersea Defence Technology 2026 at ExCel London on April 14, 2026 in London, England. Part of the Global Marine Group, SubConnect is a market leader in fibre-based cable jointing technology and subsea fibre optic cables from the design, testing, and supply of subsea joints and interconnectors, to their deployment, installation and maintenance operations. UDT 2026 brings together defence experts, industry leaders and innovators to address the challenges of the undersea domain, highlighting advanced technologies, including autonomous systems, sonar and secure communication networks. (Photo by John Keeble\/Getty Images) <\/figcaption><\/figure>\n<header class=\"post-item__meta\">\n<h3 class=\"post-item__title\"> <a class=\"post-item__title-link\" href=\"https:\/\/cyberscoop.com\/fcc-undersea-cable-regulations-national-security\/\"> FCC passes new cybersecurity rules for emergency systems, undersea cables <\/a> <\/h3>\n<div class=\"post-item__byline\"> <span class=\"post-item__author\"> <span>By <\/span> <a class=\"post-item__author-link\" href=\"https:\/\/cyberscoop.com\/author\/derek-johnson\/\"> Derek B. Johnson <\/a> <\/span> <\/div>\n<p><!-- .byline --> <\/header>\n<p><!-- .post-item__meta --> <\/article>\n<\/p><\/div>\n<\/p><\/div>\n<p><!-- .popular-stories__stories --> <\/div>\n<p><!-- .popular-stories__inner -->\n<\/div>\n<p><!-- .popular-stories --> <\/p>\n<section class=\"latest-podcasts\">\n<h2 class=\"latest-podcasts__title\"> Latest Podcasts\t<\/h2>\n<\/section>\n<div class=\"top-categories\">\n<div class=\"top-categories__container\">\n<h3 class=\"top-categories__category-title\">Government<\/h3>\n<\/p><\/div>\n<div class=\"top-categories__container\">\n<h3 class=\"top-categories__category-title\">Technology<\/h3>\n<\/p><\/div>\n<\/p><\/div>\n<p> <\/main> <\/p>\n<div class=\"ad ad--bottom \">\n<div class=\"ad__inner\"> <span class=\"screen-reader-text\">Advertisement<\/span> <\/div>\n<\/div>\n<div id=\"interstitial\" class=\"welcome__container\"> <button id=\"close-modal-1\" class=\"welcome__clickable_area\"><\/button> <\/p>\n<div class=\"welcome__ad_wrapper\">\n<p> <button id=\"close-modal-3\" class=\"welcome__continue-button\">Continue to CyberScoop<\/button> <\/p>\n<\/p><\/div>\n<\/p><\/div>\n<p> <!-- Start of HubSpot Embed Code --> <!-- End of HubSpot Embed Code --> <\/body> <a href=\"https:\/\/cyberscoop.com\/gao-report-duplicate-cybersecurity-regulations-harmonization\/\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>70% of federal cybersecurity reporting rules are duplicated, GAO finds<\/p>\n","protected":false},"author":11,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1092,622,7134,1794,2178,293,1901,1379,117,2012,1093,521,439,817,1380,290],"tags":[1094,627,7135,1795,2179,299,1902,1382,119,2013,1095,524,443,821,1383,296],"class_list":["post-8855","post","type-post","status-publish","format-standard","hentry","category-andrew-garbarino","category-biden-administration","category-breachrx","category-circia","category-cybersecurity-harmonization","category-department-of-homeland-security-dhs","category-financial-sector","category-gary-peters","category-government","category-government-accountability-office","category-house-homeland-security-committee","category-office-of-the-national-cyber-director","category-policy","category-regulation","category-senate-homeland-security-and-governmental-affairs-committee","category-trump-administration","tag-andrew-garbarino","tag-biden-administration","tag-breachrx","tag-circia","tag-cybersecurity-harmonization","tag-department-of-homeland-security-dhs","tag-financial-sector","tag-gary-peters","tag-government","tag-government-accountability-office","tag-house-homeland-security-committee","tag-office-of-the-national-cyber-director","tag-policy","tag-regulation","tag-senate-homeland-security-and-governmental-affairs-committee","tag-trump-administration"],"featured_image_urls":{"full":"","thumbnail":"","medium":"","medium_large":"","large":"","1536x1536":"","2048x2048":"","chromenews-featured":"","chromenews-large":"","chromenews-medium":""},"author_info":{"display_name":"Cyber Scoop","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/cyberscoop\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/andrew-garbarino\/\" rel=\"category tag\">Andrew Garbarino<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/biden-administration\/\" rel=\"category tag\">Biden administration<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/breachrx\/\" rel=\"category tag\">BreachRx<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/circia\/\" rel=\"category tag\">CIRCIA<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/cybersecurity-harmonization\/\" rel=\"category tag\">cybersecurity harmonization<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/department-of-homeland-security-dhs\/\" rel=\"category tag\">Department of Homeland Security (DHS)<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/financial-sector\/\" rel=\"category tag\">financial sector<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/gary-peters\/\" rel=\"category tag\">Gary Peters<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/government\/\" rel=\"category tag\">Government<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/government-accountability-office\/\" rel=\"category tag\">Government Accountability Office<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/house-homeland-security-committee\/\" rel=\"category tag\">House Homeland Security Committee<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/office-of-the-national-cyber-director\/\" rel=\"category tag\">Office of the National Cyber Director<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/policy\/\" rel=\"category tag\">Policy<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/regulation\/\" rel=\"category tag\">regulation<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/senate-homeland-security-and-governmental-affairs-committee\/\" rel=\"category tag\">Senate Homeland Security and Governmental Affairs Committee<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/trump-administration\/\" rel=\"category tag\">Trump administration<\/a>","tag_info":"Trump administration","comment_count":"0","jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/8855","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=8855"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/8855\/revisions"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=8855"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=8855"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=8855"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}