Regulatory Harm or Harmonization? Examining the Opportunity to Improve the Cyber Regulatory Regime

Digital Assets and Bank RegulationHomeland Security Subcommittee on Cybersecurity and Infrastructure Protection · 2025-03-11 · 119th Congress
The House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection held its first hearing of the 119th Congress to examine whether the federal cyber regulatory regime — including the pending CIRCIA final rule — helps or hinders critical infrastructure security. Begins at 0:10:12
Transcript
Highlights

Title

Harmonizing federal cyber incident reporting and CIRCIA implementation

Purpose

The House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection held its first hearing of the 119th Congress to examine whether the federal cyber regulatory regime — including the pending CIRCIA final rule — helps or hinders critical infrastructure security. Witnesses from the electric, banking, telecom, and cybersecurity sectors testified on duplicative reporting requirements, the SEC's cyber disclosure rule, and the recent disbanding of the Critical Infrastructure Partnership Advisory Committee (CIPAC). Members from both parties expressed interest in streamlining regulations while pressing witnesses on reauthorizing the Cybersecurity Information Sharing Act of 2015. Begins at0:10:12

Who spoke

Chairman Andrew Garbarino (R-NY)0:10:12: Opened the hearing on regulatory harmonization, noting over 50 federal cyber regulations exist0:11:38 and that the proposed CIRCIA rule went beyond congressional intent0:12:41; later pressed witnesses on whether an ex parte process could fix the rule and pledged to work with CISA1:15:29.

Ranking Member Eric Swalwell (D-CA)0:13:37: Said compliance costs can outweigh security benefits0:14:24, urged reauthorizing the Joint Cyber Defense Collaborative and the Cybersecurity Information Sharing Act of 20150:17:07, and asked witnesses in a second round about the impact of CIPAC's termination1:20:51 and third-party offensive cyber contractors1:24:24.

Chairman Mark Green (R-TN), full committee0:19:07: Said at least 50 cyber incident reporting requirements exist federally0:20:00 and criticized the SEC's disclosure rule as riddled with ambiguity0:20:56; in questioning, called the SEC's 4-day disclosure requirement "the stupidest thing I've ever heard"0:48:10 and pressed witnesses on how long it takes to close a vulnerability0:46:50.

Scott Aaronson, Edison Electric Institute0:25:23: Said EEI represents companies serving nearly 250 million Americans0:25:51 and urged finalizing CIRCIA while better aligning it with congressional intent0:27:10; cited one company projecting 65,000 reports over 10 years under a broad CIRCIA interpretation versus CISA's estimate of 200,000–220,000 total0:53:52; said electric companies do not want offensive cyber capability1:03:11.

Heather Hogsett, Bank Policy Institute0:30:38: Said bank CISOs spend 30-50% of time on compliance and their teams up to 70%0:34:00; urged rescinding the SEC's 4-day disclosure rule0:33:34 and warned firms receive ~100 requests for information around a single exam0:34:00; said BPI asked that the proposed CIRCIA rule be withdrawn and reissued0:32:381:15:29.

Robert Mayer, USTelecom0:35:44: Cited estimates of up to $23 trillion in annual global cyberattack damages, growing over 20% a year0:36:09, and said conflicting regulations can consume up to 70% of cybersecurity resources0:36:09; said USTelecom led a 21-organization letter requesting an ex parte process that CISA rejected0:37:22; estimated over a dozen federal agencies require reporting from telecom0:59:15.

Ari Schwartz, Cybersecurity Coalition0:40:35: Said a 2023 DHS report identified 45 different incident reporting requirements from 23 agencies0:41:58; criticized CISA's rulemaking process as inadequate engagement and an overbroad definition of covered entities0:42:28; said CISA rejected requests for an ex parte process and Secretary Noem "shut down CIPAC"0:44:00.

Rep. Yvette Clark (D-NY)0:50:53: Noted she co-introduced CIRCIA in 20210:51:24 and asked witnesses how multiple, uncoordinated reporting requirements affect security and whether the rule's covered-entity definitions are too broad0:52:15.

Rep. Clay Higgins (R-LA)0:58:16: Said he is reintroducing his Streamline Federal Cybersecurity Regulations Act (HR 10123 in the 118th Congress)0:58:16; got witnesses to confirm energy, banking, and telecom sectors each report to more than a dozen federal agencies0:59:15; asked whether the private sector could "strike back" offensively against attackers1:03:11.

Rep. Carlos Gimenez (R-FL)1:09:25: Said the airline industry reports the same incident to at least 10 agencies [0:09:25 est./1:09:25]; pressed witnesses for estimates of daily reportable incidents, getting a guess of "over a thousand" per sector per day1:10:57 and Aaronson's estimate of several thousand a month across EEI's 62 member companies1:12:28; returned in round two to argue the U.S. needs offensive deterrence1:27:53.

Rep. LaMonica McIver (D-NJ)1:33:11: Asked how important adequate CISA staffing and funding is to implementing CIRCIA properly, amid workforce cuts1:33:38.

Key moments

Aaronson said one company alone projected 65,000 CIRCIA reports over ten years under the rule's broadest interpretation, while CISA estimated 200,000–220,000 total across all covered entities — an apparent order-of-magnitude gap0:53:52.

Chairman Green called the SEC's 4-business-day cyber disclosure requirement "the stupidest thing I've ever heard," arguing it tips off attackers before vulnerabilities are patched0:48:10.

Witnesses unanimously confirmed their sectors each report to more than a dozen federal agencies, with no organic streamlining across agencies except limited alignment among banking regulators on incident notification1:01:24.

Schwartz revealed Secretary Noem shut down the Critical Infrastructure Partnership Advisory Committee (CIPAC) the prior week, which witnesses said was not merely an advisory body but the legal mechanism enabling protected industry-government information sharing0:44:001:21:18.

USTelecom and 20 other organizations formally requested CISA establish an ex parte engagement process on the CIRCIA rule in October 2024; the request was rejected0:37:22.

Rep. Gimenez pressed witnesses on how reported incident data is actually analyzed by the government and got no clear answer, prompting him to suggest oversight of the analysis process itself1:12:58.

Sharp exchange on offensive cyber: Reps. Gimenez and Swalwell pushed witnesses on why the private sector can't "punch back," while Aaronson and Mayer said electric and telecom firms want no part of offensive operations, citing escalation risk against nation-states and preferring deterrence to remain a government/Cyber Command function1:03:111:13:281:29:11.

Aaronson estimated the VA spends roughly $1 billion on compliance, a figure Chairman Green called into question as symptomatic of the broader regulatory burden0:46:20.

Multiple witnesses said the CISA 2015 information-sharing law, expiring in September, underpins liability and antitrust protections essential to threat-sharing groups like the Cyber Threat Alliance, and its lapse would slow or halt sharing1:04:581:07:19.

Mayer said DHS's Cyber Incident Reporting Council counted 45 reporting regimes across 22 agencies as of September 2023, with CISA expecting roughly 300,000 entities to respond to CIRCIA requirements0:55:57.

Metadata

CommitteeHomeland Security Subcommittee on Cybersecurity and Infrastructure Protection
Chamber / CongressHouse · 119th Congress
Date2025-03-11
TypeHearing
Witnesses
Mr. Scott Aaronson — Senior Vice President, Security and Preparedness, Edison Electric Institute
Ms. Heather Hogsett — Senior Vice President and Deputy Head of BITS, Bank Policy institute
Mr. Robert Mayer — Senior Vice President, Cybersecurity and Innovation, Cybersecurity and Innovation
Mr. Ari Schwartz — Coordinator, Cybersecurity Coalition
Videoyoutube
Transcript215 caption blocks · 15,835 words · 1:45:06 runtime
EventCongress.gov 117906