7 Takeaways from the House Hearing on Cyber Regulatory Reporting

Today, the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection held a hearing to examine cyber regulatory reporting. Heather Hogsett, senior vice president and deputy head of BITS — the technology policy division of BPI — testified before the committee on the need to address duplicative and conflicting reporting requirements that stretch bank cybersecurity teams thin and hinder their ability to protect the nation’s financial system.

Here are some takeaways from the hearing:

1. Bank cyber defense teams are spending a growing amount of time on compliance exercises.

Heather Hogsett, BPI: “A survey of bank chief information security officers found that they spend 30 to 50% of their time on compliance and examiner management and their teams can spend 70% of their time on those functions. Firms receive, on average, 100 requests for information leading up to an exam with anywhere from 75 to 100 supplemental requests during an exam that can take weeks, if not months, to complete. Once one exam is completed, another regulator often comes in to examine the same or a similar topic. The current state risks undermining our security, and it is time for a reassessment.”


2. Duplicative regulatory compliance costs imposed on businesses are outweighing the security benefits.

Rep. Eric Swalwell (D-CA): “I agree that compliance costs can outweigh the security benefit of regulations when compliance with duplicative regulations cuts into investment and security. We should not be imposing regulations for the sake of imposing regulations. Security should be designed to achieve outcomes that are proven to reduce risk and improve resilience and security. Toward that end, I am pleased to support CIRCIA because it addressed a concrete security gap and will improve the government’s ability to detect and disrupt malicious cyber activity. It also put in place a framework that ensures covered entities would not need to report the same cyber incidents multiple times to multiple regulators. If a hacker gets into a bank or energy company, we want them to focus on eradicating the threat as quickly as possible — not huddling the lawyers and compliance experts. They should be fixing the problem and re-establishing their services.”


3. This duplication diverts cyber defenders toward compliance and away from the job of protecting the bank and its customers.

Heather Hogsett, BPI: “The challenge of responding to multiple requirements does have a direct impact on security, because it is diverting the time and attention away from what we all want the cyber professionals to be doing, which is defending their networks, kicking out bad actors when there is an incident and focusing on that. Instead, they have to divert time away to basically make sure they’re complying with different legal obligations.”


4. Regulatory blind spots and lack of coordination among government agencies exacerbate this problem.

Heather Hogsett, BPI: “I think this is the challenge that we’ve kind of talked a bit about now here. You have independent agencies that are doing something within their narrow lane. And so for the SEC, they think that investors need to know this information. I think we would argue that investors aren’t really utilizing this information. It’s not helpful to them. It’s actually putting them at greater risk. But because an agency continues to look, without somebody at the top, sitting across and exercising oversight, to say, ‘does this really make sense? Is it in the best interest of the nation?’ We wind up with a lot of these duplicative, overlapping, deeply harmful rules. So, to the extent that Congress and this committee [are] ready to engage and help lead this effort, we do need an overall view to look at what is helpful versus what is harmful and the SEC Rule is classic ‘what is harmful’ at this point.”


5. While the bipartisan Cyber Incident Reporting for Critical Infrastructure Act was meant to improve coordination and address these concerns, CISA’s proposed implementation is overly broad.

Heather Hogsett, BPI: “[T]he law would be crafted in a way that we get signal from the noise. You wanted the incidents that were going to be most impactful, so that CISA could very quickly have the capability to take that information and turn it back around to share with other entities that could also be at risk. The very broad scope with which the proposed rule was put together would put a lot of noise out there and make that all the more challenging. For instance, the definition would potentially capture operational outages that have nothing to do with a cyber incident. And I don’t think that that was really what you and the committee had intended in crafting that law.”


6. CISA’s proposal also exceeds congressional intent and has failed to incorporate industry feedback.

Rep. Andrew Garbarino (R-NY): “Unfortunately, as many of today’s witnesses reinforced last year, the scope of the proposed CIRCIA rule went far beyond Congressional intent. Knowing that the deadline for the final rule is approaching we will dig into the value of CIRCIA and what the future of the rule should look like. This new administration presents an opportunity to get cyber-reporting right. We should seize it.”

Additional Background: CIRCIA, signed into law in March 2022, was championed by bipartisan lawmakers to strengthen cyber incident reporting without creating undue burdens. However, key congressional leaders now express concern that CISA’s proposed rule exceeds its mandate:

“[I]t is very important that the regulation is well-crafted and reflects both Congressional intent and the public’s recommendations. As currently written, I have concerns that the effect of this proposed rule fails to hit this mark.” – Sen. Gary Peters (D-MI)

“The NPRM ignores the burden to industry by asserting that technology will process the amount of information it requests . . . [The proposal would] undoubtedly skyrocket[] compliance work and clashes with congressional intent.” – Rep. Andrew Garbarino (R-NY)

“The NPRM appears to, at times, mischaracterize or dismiss Congressional intent” – Reps. Bennie Thompson (D-MS), Yvette Clarke (D-NY) and Eric Swalwell (D-CA)


7. Fixing CIRCIA is a necessary action. But greater information sharing between industry and the government could also help to address threats at the source.

Heather Hogsett, BPI: “Our firms will see things on their networks, but they don’t necessarily have attribution that it is a specific national security threat actor. They would welcome a greater ability to work and share that with the appropriate authorities in government to get feedback on that. Oftentimes, we think that there are things we see, there are things that government sees, that if we both knew what was happening, we could better direct some of our activities. I think that would be to us, the next step to really try to drive at combating this where it’s happening.”