McCrary Institute, U.S. Chamber of Commerce call for a streamlined approach to federal cyber regulations Published: Aug 31, 2026 12:40 PM By Staff report WASHINGTON – The McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University and the U.S. Chamber of Commerce released a new report on Monday, Aug. 31, calling for a more coordinated, commonsense approach to federal cybersecurity regulations arguing that the current system prioritizes compliance over security at the detriment of the nation’s cybersecurity. The new report, “From Fragmentation to Coordination: Operationalizing U.S. Cyber Incident Reporting,” argues that the federal government needs to reduce unnecessary duplication of reporting requirements and points out that the challenge is not a lack of cybersecurity authorities — Congress has granted agencies with the authorities they need. Rather, the challenge is the lack of operational coherence needed to make those authorities work together when cyber incidents demand speed, clarity and coordination. A 2023 Department of Homeland Security report identified 52 federal cyber incident reporting requirements across 22 agencies and developed model definitions and timelines to help address the problem. A more recent Government Accountability Office report from July found that there are now 117 federal cybersecurity regulations that require reporting, 48 of which apply to private industry and they’re spread across 27 different federal agencies. In case after case, a single company may need to provide the same information to multiple federal agencies and, when they’re during a cyberattack, that duplication couldn’t come at a worse time. The report released today argues that this fragmentation is more than a regulatory burden. It is a security problem. The report also notes that the federal government already has a significant foundation on which to build. The U.S. Cybersecurity and Infrastructure Agency (CISA) is finalizing a rule established in The Cyber Incident Reporting