Showing posts with label Ag Cybersecurity. Show all posts
Showing posts with label Ag Cybersecurity. Show all posts

Thursday, July 30, 2026

Review – S 4794 Introduced – Ag Cybersecurity Report

Last month, Sen Sheehy (R,MT) introduced S 4794, the Precision Agriculture Cybersecurity Act. The bill would require two different reports to Congress on cybersecurity in precision agriculture technologies. No new spending is authorized. 

Moving Forward  

While Sheehy is not a member of the Senate Agriculture, Nutrition, and Forestry Committee to which this bill was assigned for consideration, his sole cosponsor, Sen Schiff (D,CA) is a member. This means that there may be sufficient influence to see the bill considered by that Committee. Since this is a ‘report to Congress’ bill, I see nothing that would engender any organized opposition. I suspect that there would be significant bipartisan support for the bill if it were considered by the Committee.  

This bill is not politically important enough to be considered by the full Senate under regular order. It could possibly be considered under the unanimous consent process, but that process is fraught with potential opposition for unrelated political issues. The language from this bill could be added to a spending or authorization bill. 


For more information on the provisions of this bill, as well as suggestions for vulnerability disclosure language, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-4794-introduced-ag-cybersecurity - subscription required. 

Sunday, October 26, 2025

Review - S 2866 Introduced – Ag Cybersecurity

Earlier this month Sen Budd (R,NC) introduced S 2866, the Cybersecurity in Agriculture Act of 2025. The bill would require the National Institute of Food and Agriculture (NIFA) to establish five Regional Agriculture Cybersecurity Centers (RACC) to carry out research, development, and education on agriculture cybersecurity. The bill would amend the National Agricultural Research, Extension, and Teaching Policy Act of 1977, adding a new §1473I. The bill would authorize $25 million in annual spending to support the Centers through 2030.

The bill is similar to similar to HR 4387, the Cybersecurity in Agriculture Act of 2023, that was introduced in the House in June of 2023 by Rep Nunn (R,LA). No action was taken on that bill in the 118th Congress. Most of the differences are editorial (format and word changes) in nature with the exception of the addition of paragraph (b)(9) which would require that the described cybersecurity activities are specifically designed to prevent cyberattacks from the usual nation-state suspects.

Commentary

There is one major deficiency in this bill, it lacks any mention of cybersecurity vulnerabilities in agricultural systems. The RACCs should conduct vulnerability research, act as vulnerability disclosure coordinators for agricultural systems, and coordinate with CISA’s NCCIC in publishing advisories about reported vulnerabilities.

To support those vulnerability related efforts, I would add a new §1473I(b)(9):

“(9) conduct vulnerability research on agricultural control systems, act as a coordinator between researchers and vendors, and, in coordination with CISA’s National Cybersecurity and Communications Integration Center, publish advisories describing discovered cybersecurity vulnerabilities in agricultural control systems.”


For more details about the provisions of this bill, including a discussion about the lack of definitions of cybersecurity terms, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-2866-introduced-ag-cybersecurity - subscription required.

Friday, August 29, 2025

Review – HR 4046 Introduced – Ag Cybersecurity Centers

In June Rep Nunn (R,IA) introduced HR 4046, the Cybersecurity in Agriculture Act of 2025. The bill would require the National Institute of Food and Agriculture (NIFA) to establish five Regional Agriculture Cybersecurity Centers (RACC) to carry out research, development, and education on agriculture cybersecurity. The bill would authorize $25 million in annual spending to support the Centers through 2028.

Moving Forward

Both Dunn and his sole cosponsor {Rep Davis (D,NC)} are members of the House Agriculture Committee to which this bill was assigned for consideration. This means that their may be sufficient influence to see the bill considered in Committee. I suspect that there would be some level of bipartisan support for the bill in Committee, but the new spending will run afoul of efforts of the many Republicans to radically reduce spending. The bill might be able to clear the Committee, but I doubt that there would be enough influence to see the bill overcome that objection and move to the floor of the House. I suspect that the bill could pass with bipartisan support if it were considered by the full House, but not under the suspension of the rules process; a super majority vote would be difficult to achieve.

Commentary

There is one major deficiency in this bill, it lacks any mention of cybersecurity vulnerabilities in agricultural systems. The RACCs should be conducting vulnerability research, act as vulnerability disclosure coordinators for agricultural systems, and coordinate with CISA’s NCCIC in publishing advisories about reported vulnerabilities.

To support those vulnerability related efforts, I would add a new §2(b)(9):

“(9) conduct vulnerability research on agricultural control system, act as a coordinator between researchers and vendors, and, in coordination with CISA’s National Cybersecurity and Communications Integration Center, publish advisories describing discovered cybersecurity vulnerabilities in agricultural control systems.

 

For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-4046-introduced-ag-cybersecurity - Subscription required.


Monday, February 12, 2024

Review - S 3661 Introduced – Food & Ag Cybersecurity

Last month, Sen Cotton (R,AR) introduced S 3661, the Farm and Food Cybersecurity Act of 2024. The bill would require USDA to periodically assess cybersecurity threats to, and vulnerabilities in, the agriculture and food critical infrastructure sector. Additionally, it would be required to conduct an annual cross-sector simulation exercise relating to a food-related emergency or disruption, and for other purposes. The bill would authorize $1 million per year through 2028 to fund such activities.

This bill is very similar to HR 7062, which was introduced shortly before this legislation. These are not technically companion measures as there are three significant differences between the two bills. First, the study to be conducted by USDA in both bills would be required to be conducted “in coordination with the Cybersecurity and Infrastructure Security Agency” in this version. The other two changes apply to the cross-sector exercise outline in §4. Both would add requirements to include “including sector-relevant information sharing and analysis centers” in the development and execution of those exercises. There was no mention of ISACS in the House bill.

Moving Forward

Cotton is not a member of the Senate Agriculture, Nutrition, and Forestry Committee to which this bill was assigned for consideration, but one of his seven cosponsors {Sen Gillibrand (D,NY)} is a member. This means that there may be sufficient influence to see the bill considered in Committee. Beyond, the spending issue, I see nothing in the bill that would engender any organized opposition to the bill. I suspect that there would be bipartisan support in the Committee for the bill, but I am not sure that it would be enough to overcome the opposition to the additional spending.

Commentary

As with HR 7062, I find it odd that this bill fails to mention the Food and Agriculture Sector Coordinating Council (FASCC). This group is a well-established public-private partnership designed to assist the USDA in their oversight of the Food and Agriculture Sector. They would be an invaluable asset to the USDA in developing and executing the requirements of this legislation. I would like to see language inserted in §3(a) and §4(a) requiring coordination with the FASCC for execution of both the study and the exercises.

 

For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-3661-introduced - subscription required.

Friday, February 9, 2024

Review - HR 7062 Introduced – Food & Ag Cybersecurity

Last month Rep Finstad (R,MN) introduced HR 7062, the Farm and Food Cybersecurity Act of 2024. The bill would require USDA to periodically assess cybersecurity threats to, and vulnerabilities in, the agriculture and food critical infrastructure sector. Additionally, it would be required to conduct an annual cross-sector simulation exercise relating to a food-related emergency or disruption, and for other purposes. The bill would authorize $1 million per year through 2028 to fund such activities.

Moving Forward

Finstad, and 12 of his 13 bipartisan cosponsors, are members of the House Agriculture Committee to which this bill was assigned for consideration. This means that there should be sufficient influence to see this bill considered in Committee. I suspect that, even with the $1 million price tag, this bill will have significant bipartisan support. There is a good chance that the language would be added to the farm bill.

Commentary

I find it odd that this bill fails to mention the Food and Agriculture Sector Coordinating Council (FASCC). This group is a well-established public-private partnership designed to assist the USDA in their oversight of the Food and Agriculture Sector. They would be an invaluable asset to the USDA in developing and executing the requirements of this legislation. I would like to see language inserted in §3(a) and §4(a) requiring coordination with the FASCC for execution of both the study and the exercises.

 

For more details about the provisions of this bill see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-7062-introduced - subscription required.

 
/* Use this with templates/template-twocol.html */