Skip to Main Content
ICBA
  • Member Login
  • Member Login

GAO report flags 15 duplicative cyber incident regulations for banks


July 24, 2026 / By ICBA

A new report from the Government Accountability Office shows the banking industry must comply with 15 duplicative cyber incident reporting requirements.

Details: According to the GAO report:

  • Banks may have to comply with cyber incident reporting requirements from agencies including the FDIC, OCC, Federal Reserve, Treasury Department, Securities and Exchange Commission, Commodity Futures Trading Commission, and Federal Trade Commission.

  • The 15 regulations mark a significant amount of regulatory duplication for community banks.

  • Banks may also be subject to pending regulation from the Cybersecurity and Infrastructure Security Agency on cyber incident and ransomware payment reporting pursuant to the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA).

ICBA Advocacy:

  • ICBA last month told federal regulators that community banks support strong cybersecurity while advocating for information sharing across federal agencies. ICBA also encouraged CISA to look for opportunities to streamline, harmonize, and eliminate duplicative reporting requirements wherever possible as it finishes CIRCIA.

  • ICBA and other groups in April called on the SEC to rescind its cybersecurity risk management governance and incident disclosure requirements, saying they would disproportionately burden community banks.

Join ICBA Community

Interested in discussing this and other topics? Network with and learn from your peers with the app designed for community bankers. 

Join the community Example Text