BPI Statement Before House Subcommittee on Harmonizing Cyber Regulations

Chairwoman Mace, Ranking Member Connolly and Honorable Members of the Subcommittee, thank you for inviting me to testify. My name is Pat Warren, Vice President for Regulatory Technology for BITS, the technology policy division of the Bank Policy Institute.

BPI is a nonpartisan policy, research and advocacy organization representing the nation’s leading banks. BPI members include universal banks, regional banks and major foreign banks doing business in the United States. BITS, our technology policy division, works with our member banks as well as insurance, card companies and market utilities on cyber risk management, critical infrastructure protection, fraud reduction, regulation and innovation.

As illustrated by CrowdStrike’s software update last week that caused a global IT outage, the security and resilience of the networks, systems and software that we rely on as a nation are vitally important. Cybersecurity regulations can play a key role in fostering the necessary programs and policies to protect our critical infrastructure, and they have certainly played a role in protecting banks. As new cybersecurity regulations continue to proliferate, we must be mindful that, if not properly harmonized and aligned, such requirements can place unnecessary strain on the critical cybersecurity resources we rely on to prepare for emerging threats and address incidents when they occur.

On behalf of BPI member companies, I appreciate the opportunity to provide input on the need to harmonize cybersecurity regulations and streamline existing requirements. This is a challenge for many critical infrastructure entities—financial institutions especially—as they are grappling with a significant increase in new regulations.

Like the Committee, the Office of the National Cyber Director identified cyber regulatory harmonization as a key consideration in the National Cybersecurity Strategy and issued a request for information last year to better understand how duplicative and overlapping cyber requirements affect regulated entities. BPI, along with the American Bankers Association, submitted a response discussing the current financial sector regulatory landscape and encouraging a balanced approach that considers the effect on front-line cyber personnel to ensure they can meet compliance requirements while maintaining critical day-to-day operational obligations.[1]

Congressional action is needed to ensure new and existing cybersecurity requirements accomplish the goals of better security and resilience while balancing the collective impact of these requirements on regulated entities. As Congress considers ways to better align cyber regulatory requirements, we offer the following recommendations:

  1. Regulatory harmonization efforts should be led by an entity at the national level, such as the ONCD, that can compel action and possesses government-wide visibility into the cyber regulatory requirements issued by federal agencies and independent regulators.
  2. That same national-level entity should conduct an assessment of the cyber regulations currently in effect to identify inconsistent, overlapping or contradictory requirements and develop recommendations to achieve increased harmonization.
  3. Agencies considering new cybersecurity regulations should be required to consult with the national-level entity leading harmonization efforts to limit duplication and encourage consideration for how the proposed regulation may affect other policy directives.

Financial Services Regulatory Landscape

Financial institutions are subject to numerous regulations and rigorous supervision and examinations from the prudential banking regulators—the Office of the Comptroller of the Currency, the Federal Reserve Board and the Federal Deposit Insurance Corporation—to ensure they operate in a safe and sound manner. This includes resident examiners evaluating compliance with statutory requirements and whether financial institutions implement appropriate security controls in areas including third-party risk management, operational resilience and appropriate board oversight.

Beyond the prudential banking regulators, financial institutions also comply with cyber incident reporting, incident disclosure, consumer breach notification, data security and data privacy requirements enforced by the Commodity Futures Trading Commission, the Consumer Financial Protection Bureau, the Federal Trade Commission, the Securities and Exchange Commission, the New York Department of Financial Services and forthcoming rules from the Cybersecurity and Infrastructure Security Agency.

For cyber incident reporting alone, and as noted by the Cyber Incident Reporting Council in 2023, there are eight distinct cyber incident reporting requirements applicable to financial institutions.[2] That number also doesn’t account for new requirements recently issued by the Federal Housing Administration and Ginnie Mae.[3]

This multifaceted environment was further complicated by the SEC’s recent public company disclosure rule.[4] That rule conflicts with the primary purpose of the confidential reporting requirements noted earlier because it requires companies to publicly disclose material cybersecurity incidents—even if those incidents are still ongoing. Requiring public disclosure in those circumstances exposes victim companies to additional risk while shortening the timeframe other agencies have to leverage confidential reports and warn potential downstream victims. Moreover, since the SEC rule went into effect last December, we have seen threat actors weaponize the rule as an additional ransom payment extortion method against victim companies.

To read the full statement, please click here, or click on the download button below.


[1] Bank Policy Institute & American Bankers Association, Comment Letter on Request for Information on Cybersecurity Regulatory Harmonization (Oct. 31, 2023), https://bpi.com/wp-content/uploads/2023/10/2023.10.31-BPI-ABA-ONCD-RFI-Response-2023.10.31.pdf

[2] DEP’T OF HOMELAND SEC., HARMONIZATION OF CYBER INCIDENT REPORTING TO THE FEDERAL Government 9 (2023).

[3] U.S. DEP’T OF HOUSING & URBAN DEVELOPMENT, FED. HOUSING ADMIN., MORTGAGEE LETTER 2024-10, SIGNIFICANT Cybersecurity Incident (Cyber Incident) Reporting Requirements (2024); U.S. Dep’t of Housing & Urban Development, Ginnie Mae, APM 24-02, Cybersecurity Incident Notification Requirement (2024).

[4] Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure, 88 Fed. Reg. 51896, 51944 (Aug. 4, 2023).