In a new article, Managing Director and Energy, Oil & Gas Sector Lead Jerome Farquharson examines why compliance-focused cybersecurity oversight is no longer sufficient to protect America’s critical infrastructure. Harmonizing compliance: How oversight modernization can strengthen America’s cyber resilience argues that fragmented, sector-specific mandates have created governance gaps that adversaries increasingly exploit as operational technology and information technology converge.
The article outlines how initiatives such as CIRCIA and NIST’s Cybersecurity Framework 2.0 create an opportunity to shift federal oversight from checkbox compliance to measurable resilience — emphasizing harmonized governance, outcome-based metrics, and shared accountability across sectors.
