Chairman Garbarino, Ranking Member Swalwell and Honorable Members of the Subcommittee, thank you for inviting me to testify. I am Heather Hogsett, Senior Vice President and Deputy Head of BITS, the technology policy division of the Bank Policy Institute.
BPI is a nonpartisan policy, research and advocacy organization representing the nation’s leading banks. BPI members include universal banks, regional banks and major foreign banks doing business in the United States. BITS, our technology policy division, works with our member banks as well as insurance, card companies and market utilities on cyber risk management, critical infrastructure protection, fraud reduction, regulation and innovation.
I also serve as Co-Chair of the Financial Services Sector Coordinating Council Policy Committee. The FSSCC coordinates across the financial sector to enhance security and resiliency and to collaborate with government partners such as the U.S. Treasury and the Cybersecurity and Infrastructure Security Agency, as well as financial regulatory agencies.
On behalf of BPI member companies, I appreciate the opportunity to provide input on the status of the Cyber Incident Reporting for Critical Infrastructure Act, as well as the state of cybersecurity regulation, and ways to potentially harmonize existing requirements. There is an urgent need to reduce overlapping and duplicative regulatory requirements that present considerable challenges for many critical infrastructure entities. Financial institutions experience these challenges acutely when complying with a multitude of incident reporting requirements and during cyber-specific supervisory examinations conducted by numerous financial regulatory agencies.
As the government surveys the current cyber regulatory landscape in search of increased efficiencies, it should prioritize: (1) streamlining cyber incident reporting requirements to allow cyber personnel to focus on response efforts; and (2) consolidating cyber regulatory requirements and supervision.
Cyber Incident Reporting
To better align incident reporting requirements, government agencies should consider: (1) substantial revisions to CISA’s proposed rule to implement the Cyber Incident Reporting for Critical Infrastructure Act (“CIRCIA”); (2) rescinding the SEC’s Cyber Incident Disclosure Rule; and (3) directing federal agencies to stop issuing duplicative requirements and instead leverage CIRCIA as Congress intended.
Revise the CIRCIA Proposed Rule
Almost a year ago, I testified before this Subcommittee shortly after CISA released its proposed rule.[1] During that hearing, I noted our members’ concerns that CISA’s proposal reflected an overly broad reading of the underlying statute and would add significant compliance obligations on frontline cyber personnel during the most critical incident response phase. As we move closer to the statutory deadline for CISA to issue its final rule, our members maintain those same concerns.
Financial institutions supported CIRCIA as it was being considered by Congress because it proposed a uniform incident reporting standard for critical infrastructure and sought to enhance CISA’s ability to combat sophisticated cyber threats. Because CISA’s proposal fell short of that aspiration, we—along with several other financial trade associations—recently reiterated this viewpoint in a letter to Department of Homeland Security Secretary Noem and Office of Management and Budget Director Vought requesting that they withdraw the current proposal and re-issue it more in line with congressional intent.[2] While the current proposal is too broad in scope, we continue to believe that CIRCIA, if properly calibrated, can enhance our collective defenses and mitigate threats from foreign adversaries.
For that enhancement to be most effective, it is also important that Congress reauthorize the Cybersecurity Information Sharing Act of 2015 (“CISA 2015”).[3] The information, antitrust, and liability protections in CISA 2015 are imperative for public-private information sharing and provide the legal clarity companies need to share information not only with CISA but with other companies across critical infrastructure. The protections in CISA 2015 are also incorporated by reference in CIRCIA—making their reauthorization all the more critical. The expiration of the legal framework provided in the Act could substantially disrupt information sharing—leaving us all less prepared to confront emerging cyber risks.
As we noted in our joint financial trades response to CISA’s proposal last June, it is critical that CISA’s final rule not extend beyond the authorities granted to it under the statute.[4] Bipartisan members of this Committee, along with Senator Peters, submitted comments emphasizing that same view.[5] These responses were enormously helpful for reiterating congressional intent, and we thank you for your leadership.
To adhere more closely to the CIRCIA statute, the final rule should limit reporting to information directly related to an actionable purpose—like detecting signs of a widespread vulnerability. Narrowing reporting data elements in this way would help give life to CIRCIA’s “substantially similar” exception—something that would be unavailable to covered entities under the breadth of the current proposal. It would also lessen the burden of the supplemental reporting requirements which, as currently drafted, would likely require entities to file multiple additional reports during a single incident. Finally, CISA’s rule should have reasonable thresholds for reporting above the standard proposed in the current substantial cyber incident definition that would likely cause a flood of reports on low-risk incidents.
Rescind the SEC Cyber Incident Disclosure Rule
Before the SEC finalized this rule in 2023, the financial sector raised significant concerns with its requirement to publicly disclose ongoing cyber incidents.[6] Chief among those concerns was that publicly disclosing ongoing and unremediated cyber incidents could impair a victim company’s ability to respond or otherwise exacerbate harm to the company, its shareholders, and customers. Unfortunately, those reservations were realized in November 2023 when ransomware group AlphV weaponized the public disclosure requirement as an additional ransom payment extortion method by reporting its own victim to the SEC.[7] Given the pervasiveness of ransomware attacks, it is misguided to provide cybercriminals with an additional means to inflict financial harm on victim companies.
The public disclosure element of this rule is also problematic because it directly conflicts with the purpose of confidential incident reporting requirements. Although there are numerous confidential reporting rules across the government, all generally aim to limit harm and warn potential downstream victims. Once an incident is publicly disclosed, however, that task becomes much more difficult to achieve. Using CIRCIA as an example, CISA will only have 24 hours to confidentially share threat indicators before an incident is publicly disclosed under the SEC rule. That leaves vulnerable companies with virtually no time to implement those controls before the incident is disclosed to the world. Rescinding the requirement that companies publicly disclose ongoing cyber incidents will help eliminate unnecessary exposure to these threats.
Stop Duplicative New Requirements and Leverage CIRCIA
The financial sector complies with as many as ten distinct incident reporting requirements in the U.S. alone.[8] Many of these obligations were instituted over the past few years as agencies seemingly rushed to put out their own—and often conflicting rules. We understand that agencies have unique missions and therefore different information needs. Nonetheless, the patchwork of current requirements across the government is past the point of helpful and now diverts finite resources away from incident response to filling out government forms.
There are three general categories these rules fall into: (1) incident notification; (2) confidential incident reporting; and (3) public incident disclosure. At one end of the spectrum, incident notification rules tend to be early during an incident investigation and simple—such as a phone call or email. They are used to inform an agency of an issue without requiring extensive data elements. We support and recognize the value of incident notification requirements for agencies with operational responsibilities or emergency authorities within critical infrastructure. An example of this is the financial regulatory agencies’ Interagency Computer-Security Incident Notification Rule issued after substantive consultation with financial institutions.[9]
Confidential incident reporting requirements—like CIRCIA—involve more detailed responses and therefore often have slightly longer reporting timeframes. They serve to provide government with information to assess whether an incident might be widespread across different firms or sectors, to provide early warning to other entities or to contain an incident.
At the opposite end of the spectrum is the SEC disclosure rule which requires publicly alerting investors and others of an incident, regardless of whether mechanisms are in place—such as a software patch or the ability to disconnect from compromised networks—to prevent harm from spreading. As described above, this prioritization of investors’ desire for information over critical incident response activities can exacerbate harm.
When enacting CIRCIA, Congress intended that it be “the primary means for reporting of cyber incidents to the Federal Government, that such reporting be through CISA, and that the required rule occupy the space regarding cyber incident reporting.”[10] Because Congress was clear on this point, other federal agencies should not create their own duplicative confidential reporting requirements.[11] Incident notification and disclosure requirements should also be reviewed to ensure they are critical to the agency requiring them and do not interfere with confidential reporting. Instead, agencies should leverage CIRCIA and enter into sharing agreements with CISA to receive relevant cyber threat information.
Consolidate Cyber Regulatory Requirements and Supervision
Financial institutions are continuously examined by the Office of the Comptroller of the Currency, Federal Reserve and Federal Deposit Insurance Corporation, among others,[12] and often have hundreds of examiners on site to review their cybersecurity practices. According to a survey of our member firms, bank Chief Information Security Officers now spend 30-50 percent of their time on compliance and examiner management. The cyber teams they oversee spend as much as 70 percent of their time on those same functions. In the leadup to exams, financial institutions routinely receive over 100 requests for information, followed by 75 to 100 supplemental requests during an exam. Of those requests, firms report that roughly 25 percent duplicate requests from other agencies.
The cumulative effect of overlapping exams and regulatory requirements has created numerous unintended consequences. First, and as noted above, frontline cyber personnel now have significantly less time to perform their day-to-day security responsibilities as their bandwidth is consumed by compliance work. Relatedly, firms have paused or extended timeframes for completing strategic program improvements to prepare for emerging threats. Finally, staff retention has become an issue as financial institutions report morale problems and burnout among staff driven by excessive compliance demands and rapid response deadlines.
Looking forward, there should be a careful review of the current regulatory regime to ensure it is calibrated appropriately. This should include actively exploring how to consolidate regulatory responsibilities in a way that better balances the oversight obligations of regulators and the security realities of private companies. Moreover, supervisory activities should primarily focus on outcomes and not box-checking procedural exercises unrelated to actual risk. Structured accordingly, regulators will better understand the true cybersecurity maturity of the firms they oversee and regulated entities will have the time they need to defend against sophisticated and well-resourced foreign threat actors.
Conclusion
We welcome the Committee’s attention to this important issue. The financial sector has and will continue to support confidential information sharing to provide early warning and help prevent malicious attacks. This includes CIRCIA, which, if appropriately tailored to the statute and congressional intent, will substantially improve awareness of cyber threats across the most important sectors of our economy. Harmonizing regulatory requirements is not a trivial task, but we are committed to working with this Committee and other federal agencies like CISA to advance that worthwhile goal.
[1] Surveying CIRCIA: Sector Perspectives on the Notice of Proposed Rulemaking Before the Subcomm. on Cybersecurity and Infrastructure Protection of the H. Comm. on Homeland Security, 118th Cong. (2024) (statement of Heather Hogsett, Senior Vice President, Technology & Risk Strategy for BITS, Bank Policy Institute).
[2] Letter from the American Bankers Assoc., Bank Policy Inst., Inst. of Int’l Bankers, & Sec. Industry & Fin. Markets Assoc., to Kristi Noem, Secretary, Dep’t of Homeland Sec. & Russell T. Vought, Director, Office of Mgmt. & Budget (Feb. 28, 2025), https://bpi.com/wp-content/uploads/2025/02/CIRCIA-Letter-to-Noem-Vought-2.28.25.pdf.
[3] Consolidated Appropriations Act, Pub. L. No. 114-113, Div. N, Title I—Cybersecurity Information Sharing Act, 129 Stat. 2935 (2015), 6 U.S.C. § 1501.
[4] American Bankers Assoc., Bank Policy Institute, Institute of International Bankers, & Sec. Industry & Financial Markets Assoc., Comment Letter on Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements (Jun. 28, 2024), https://bpi.com/wp-content/uploads/2024/06/CIRCIA-Reporting-Requirements-Comment-Letter.pdf.
[5] Representative Andrew Garbarino, Comment Letter on Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements (Jul. 3, 2024); Representatives Bennie G. Thompson, Yvette D. Clarke, & Eric M. Swalwell, Comment Letter on Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements (Jul. 3, 2024); Senator Gary Peters, Comment Letter on Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting Requirements (Jul. 2, 2024).
[6] Bank Policy Institute, American Bankers Assoc., Independent Community Bankers of America, & Mid-Size Banking Coalition of America, Comment Letter on Proposed Rules Regarding Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure Requirements (May 9, 2022), https://bpi.com/wp-content/uploads/2022/05/05.09.22-BPI-ABA-ICBA-MCBA-SEC-Comment-Letter-2022.05.09.pdf; Fin. Services Sector Coordinating Council, Comment Letter on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure, https://www.sec.gov/comments/s7-09-22/s70922-20128382-291285.pdf.
[7] AlphV files an SEC complaint against MeridianLink for not disclosing a breach to the SEC, DataBreaches.Net (Nov. 15, 2023), https://databreaches.net/2023/11/15/alphv-files-an-sec-complaint-against-meridianlink-for-not-disclosing-a-breach-to-the-sec/.
[8] Dep’t of Homeland Sec., Harmonization of Cyber Incident Reporting to the Federal Government 9 (2023); U.S. Dep’t of Housing & Urban Development, Fed. Housing Admin., Mortgagee Letter 2024-23, Revised Cyber Incident Reporting Requirements (2024); U.S. Dep’t of Housing & Urban Development, Ginnie Mae, APM 24-02, Cybersecurity Incident Notification Requirement (2024).
[9] Computer-Security Incident Notification Requirements for Banking Organizations and Their Bank Service Providers, 12 C.F.R. § 53 (2021).
[10] Sen. Rob Portman, Comment Letter on SEC Proposed Rule on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure 4 (May 9, 2022), https://www.sec.gov/comments/s7-09-22/s70922-20128391-291294.pdf.
[11] See U.S. Dep’t of Housing & Urban Development, Fed. Housing Admin., Mortgagee Letter 2024-23, Revised Cyber Incident Reporting Requirements (2024); U.S. Dep’t of Housing & Urban Development, Ginnie Mae, APM 24-02, Cybersecurity Incident Notification Requirement (2024); CFTC Operational Resilience Framework for Futures Commission Merchants, 89 Fed. Reg. 4706 (Jan. 24, 2024).
[12] Other U.S. financial regulators include the Commodity Futures Trading Commission, Consumer Financial Protection Bureau, National Credit Union Administration, Securities and Exchange Commission, and state banking agencies.
