McCrary Institute, U.S. Chamber of Commerce call for a streamlined approach to federal cyber regulations

Published: Aug 31, 2026 12:40 PM

By Staff report

The new report, “From Fragmentation to Coordination: Operationalizing U.S. Cyber Incident Reporting,” argues that the federal government needs to reduce unnecessary duplication of reporting requirements and points out that the challenge is not a lack of cybersecurity authorities — Congress has granted agencies with the authorities they need. The new report, “From Fragmentation to Coordination: Operationalizing U.S. Cyber Incident Reporting,” argues that the federal government needs to reduce unnecessary duplication of reporting requirements and points out that the challenge is not a lack of cybersecurity authorities — Congress has granted agencies with the authorities they need.

WASHINGTON – The McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University and the U.S. Chamber of Commerce released a new report on Monday, Aug. 31, calling for a more coordinated, commonsense approach to federal cybersecurity regulations arguing that the current system prioritizes compliance over security at the detriment of the nation’s cybersecurity.

The new report, “From Fragmentation to Coordination: Operationalizing U.S. Cyber Incident Reporting,” argues that the federal government needs to reduce unnecessary duplication of reporting requirements and points out that the challenge is not a lack of cybersecurity authorities — Congress has granted agencies with the authorities they need. Rather, the challenge is the lack of operational coherence needed to make those authorities work together when cyber incidents demand speed, clarity and coordination. 

A 2023 Department of Homeland Security report identified 52 federal cyber incident reporting requirements across 22 agencies and developed model definitions and timelines to help address the problem. A more recent Government Accountability Office report from July found that there are now 117 federal cybersecurity regulations that require reporting, 48 of which apply to private industry and they’re spread across 27 different federal agencies. 

In case after case, a single company may need to provide the same information to multiple federal agencies and, when they’re during a cyberattack, that duplication couldn’t come at a worse time. 

The report released today argues that this fragmentation is more than a regulatory burden. It is a security problem.

The report also notes that the federal government already has a significant foundation on which to build. The U.S. Cybersecurity and Infrastructure Agency (CISA) is finalizing a rule established in The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA). It established the Cyber Incident Reporting Council to coordinate, deconflict and harmonize federal incident reporting requirements across 33 federal departments and agencies. Using CIRCIA as a common mechanism to let organizations report once, but have that information used many times, is a natural path forward.

“Companies didn’t go into businesses thinking they’d have to defend themselves against nation-states and ransomware gangs. Federal requirements that insist that entities report cyber incidents and encourage good cyber hygiene practices are all important, but these well-intentioned requirements from dozens of federal agencies have layered on top of each other and created a system where some organizations are spending more time proving they’ve complied with security requirements than on actually securing their systems,” said Frank Cilluffo, director of the McCrary Institute. “When the threat is accelerating every day, organizations should be able to count on the fact that when they share information with the federal government its shared appropriately and efficiently. As CISA finalizes the CIRCIA rule-making process, they have an opportunity to streamline the reporting mechanisms allowing our nation’s cyber defenders to allocate their resources adapting to fast-moving, increasingly AI-driven threats.”

“When a company is responding to a critical cyber incident, every second counts. This report offers a practical path forward: leveraging relationships with government while reducing unnecessary duplication and complexity,” said Christopher D. Roberti, senior Vice president for cyber, space, and national security policy, the U.S. Chamber of Commerce, and McCrary Institute senior fellow. “By improving coordination across agencies and building on the work of the cyber community, we can ensure America’s cyber defenders stay focused on what matters most: defending their attack surfaces and stopping America’s adversaries.” 

The report recommends:

  • Establishing a single federal intake process for cyber incident reporting, led by the Cybersecurity and Infrastructure Security Agency (CISA), to the maximum extent permitted by law.
  • Use CIRCIA’s existing “substantially similar” authority to allow a single report to satisfy multiple comparable federal reporting requirements where legally permissible.
  • Standardize definitions, thresholds, data elements and reporting timelines across federal agencies where appropriate.
  • Affirming the role of the Cyber Incident Reporting Council as the existing interagency mechanism for coordinating and harmonizing federal cyber incident reporting requirements.
  • Having the Office of the National Cyber Director help drive alignment across the federal government and establish measures of success focused on speed, completeness and usability of information.
  • Preserving sector-specific expertise and statutory requirements where they serve distinct national security and privacy purposes.

In May, Cilluffo and Roberti outlined the current status of cyber regulations in a blog post saying, “At best, companies are spending precious resources demonstrating compliance rather than strengthening security; at worst, some are left without a clear, consistent understanding sense of what good security requires. Taken together, the lack of clarity and an overemphasis on procedural form rather than security outcomes and substance puts businesses, their customers, and our nation’s critical infrastructure at risk.”

 

Media Contact: Victoria Dillon, vnd0003@auburn.edu,

To fix accessibility issues

Recent Headlines