Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks

A Growing Pileup of Concerns Over Cyber Incident Reporting Regulation

The US government’s attempt to regulate how companies report significant cyberattacks has hit a snag, with industry groups expressing frustration over the scope and complexity of the proposed rule. The Cybersecurity and Infrastructure Security Agency (CISA) held town halls in June to gather feedback on the pending regulation, but instead of finding common ground, many companies walked away feeling overwhelmed by the sheer number of entities affected and the volume of information required.

The 2022 Cyber Incident Reporting for Critical Infrastructure Act was designed to help prevent similar attacks from happening again by allowing the government to share critical information with other industries that may be vulnerable. However, the proposed rule has been criticized by industry groups for being overly broad, requiring too many companies to report even minor incidents and providing an excessive amount of sensitive data.

CISA estimates that over 300,000 entities will be subject to the requirements, including small businesses that are worried about the financial burden of compliance. Some industries have called for their entire sector to be exempt from the rule, while others want the list of affected companies to be reduced or modified to exclude those already regulated by other agencies.

Critics argue that the current approach, which applies to both large and small companies based on size or sector, will lead to over-reporting and an excessive burden on businesses. As Douglas Leigh, vice president of legislative affairs for the Alliance for Chemical Distribution, pointed out, even small entities in chemical distribution could be swept up under multiple cyber categories.

Industry groups also want CISA to rethink what information should be reported in a major incident. Many argue that sensitive details about security measures and affected entities’ systems are unnecessary and could hinder reporting speed and accuracy. Samantha Burch, vice president of technology public policy at government affairs for AHIP, a health insurance industry trade association, suggested collecting the least amount of information possible to facilitate accurate and timely reporting.

Some companies worry about the definition of what constitutes a reportable incident, fearing that minor events such as “foreign entities tickling our firewall” could trigger requirements. This concern highlights the tension between providing enough information for effective prevention and avoiding unnecessary burdens on businesses.

While some industry representatives express optimism about CISA’s intentions to create a more streamlined regulation, others are skeptical about the agency’s willingness to make changes based on town hall feedback. With the rule still pending after multiple delays, it remains to be seen whether the final product will address these concerns or exacerbate them.

Practically speaking, this saga highlights the importance of clear and effective communication between regulatory agencies and industry stakeholders. As companies navigate the complex landscape of cybersecurity regulations, they should remain vigilant about advocating for reasonable requirements that balance public safety with business needs.


Source: CyberScoop — 2026-07-24