Showing posts with label Grant Program. Show all posts
Showing posts with label Grant Program. Show all posts

Monday, February 16, 2026

Review - HR 7266 Introduced – Utility Cybersecurity Grants

Last month Rep Miller-Meeks (R,IA) introduced HR 7266, the Rural and Municipal Utility Cybersecurity Act. The bill would rewrite 42 USC 18723, the Rural and municipal utility advanced cybersecurity grant and technical assistance program, to update and reauthorize that program. The existing $250 million annual authorization for the program would be extended through 2030.

The existing Rural And Municipal Utility Advances Cybersecurity Grant And Technical Assistance Program was authorized in 2021 by §40124 of the Infrastructure Investment and Jobs Act (PL 117-58, 135 STAT 953). There is no sunset provision in this statute, but the spending authorization is only included through FY 2026.

Moving Forward  

Miller-Meeks, and her two cosponsors, are all members of the House Energy and Commerce Committee to which this bill was assigned for consideration. This means that there may be sufficient influence to see the bill considered in Committee. I see nothing in the bill that would engender any organized opposition. I suspect that there would be significant bipartisan support for this bill, which should allow for it to be considered by the full House under the suspension of the rules process. That would mean limited debate, no floor amendments, and it would require a super majority for passage.

 

For more details about the provisions of the bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-7266-introduced-utility-cybersecurity - subscription required.

Thursday, March 3, 2022

Review - HR 6825 Introduced – Nonprofit Grant Program

Last month, Rep Thompson (D,MS) introduced HR 6825, the Nonprofit Security Grant Program Improvement Act of 2022. The bill would amend 6 USC 609a, the Nonprofit Security Grant Program. The amendments include adding new allowed uses of the funds and requires FEMA to establish a program office to administer the grant program. The bill would increase the funding for the program and extends that funding through 2028.

The bill was approved yesterday by a voice vote in the House Homeland Security Committee after substitute language was approved. Among the changes made by the substitute is a provision that specifically includes the risk of “extremist attacks other than terrorist attacks and threats’ in the coverage of the grant program.

Moving Forward

Passage by voice vote in Committee indicates that there is at least some measure of bipartisan support for this bill. There was an attempt by Rep Higgins (R,LA) to express some concerns with this bill, but there was no follow-up at the end of the hearing. I suspect that the legislation will be considered in the Full House under the suspension of the rules process. It will probably pass with bipartisan support.

Commentary

While §609a does currently allow for the use of grant funds for cybersecurity training {§609a(c)(2)} and ‘cybersecurity resilience activities’ {§609a(c)(2)}, that funding only extends to protection against terrorist attacks or threats of such attacks. The substitute language addition of ‘extremist attacks’ allows DHS to include threats from domestic groups without the political baggage of trying to identify domestic terrorist groups. This is almost certainly why there is no definition of the term ‘extremist attacks’.

Still, this does not address the expanding need for protection against non-terrorist (or even extremist) cyberattacks like ransomware attacks. This bill would have been an ideal place to include protection against ransomware attacks as an allowed use of grant funds. With this bill probably going to the Full House under the suspension of the rules process, the chances for amending the bill have essentially passed.

Perhaps it is time to change the definition of ‘terrorism’ to specifically include ransomware attacks.

 

For more details about the provisions of the bill and the substitute language, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-6825-introduced - subscription required.

Tuesday, September 7, 2021

Review - S 2585 Introduced - State and Local Cybersecurity Improvement

Last month, Sen Hassan (D,NH) introduced S 2585, the State and Local Cybersecurity Improvement Act. The bill is similar to HR 3138 that was passed in the House in July in that it would require State and local government entities to formulate a cybersecurity plan to support their funding requests through a grant program established by the bill. It does not include any of the other provisions in the House bill amending the Homeland Security Act of 2002. Monies are appropriated to support the grant program at lower rates than in the House bill.

Hassan is the chair of the Emerging Threats and Spending Oversight Subcommittee of the Senate Homeland Security and Governmental Affairs Committee, the Committee to which this bill was assigned for consideration. That would be sufficient influence to see this bill considered in Committee. If considered, the bill would probably receive bipartisan support.

The Senate included a version of this bill (Division G, Title VI, Subtitle B) in the Infrastructure Investment and Jobs Act (HR 3684) passed last month. The House is scheduled to take up that bill on or before September 27th. If the House passes that bill, further action on S 2585 will obviously be unnecessary. If it fails in the House, I suspect that the Committee would take up and pass this bill. The Senate could then take up HR 3138 either as is or substitute the language from this bill (the usual procedure).

For more details about the differences between this bill and HR 3138, including the differences in the authorized funding for the grant program, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-2585-introduced - subscription required.

Tuesday, June 25, 2019

HR 3261 Introduced – Smart Signals Grants


Earlier this month Rep. Cardenas (D,CA) introduced HR 3261, the Less Traffic with Smart Stop Lights Act of 2019. The bill would require DOT to establish the Smart Technology Traffic Signals Grant Program. Funding would come from existing DOT grant programs.

Grant Program


The new grant program would provide monies to State, local and Tribal governments to improve the functioning of traffic signal in a way that would {§2(a)}:

Reduce traffic congestion;
Improve the safety and effectiveness of roadways;
Reduce fuel costs for drivers; and
Reduce air pollution.

The monies would be used to improve traffic signals through the implementation of innovative technology, including {§2(c)}:

Adaptive signal control technology; and
Real-time data measurement technology

Funding would come from two existing DOT grant programs; the surface transportation block grant program (23 USC 133) and the congestion mitigation and air quality improvement program (23 USC 149).

Moving Forward


Cardenas is a member of the House Energy and Commerce Committee, one of the two committees to which this bill was assigned for consideration. Rep. Espaillat (D,CA), a cosponsor of the bill is a member of the House Transportation and Infrastructure Committee, the other committee to which the bill was assigned. This means that the bill could be considered by both relevant committees.

There is nothing in the bill that would drive any ideological opposition to its passage. The funding provisions help to overcome the added spending issue, but it will effectively reduce the funding available for grants in the other programs by some undetermined amount.

Commentary


The biggest shortfall in the language in the bill is that it contains no provisions for requiring grantees to address cybersecurity issues with these innovative technology solutions. With that lack of cybersecurity language in mind, I would like to suggest the following two modifications to the language in the bill.

First, I would add a new clause to §2(c) that would specifically allow grants to be used for improving cybersecurity of existing traffic control systems:

(3) defensive measures (as defined in 6 USC 1501) to protect new or existing traffic control systems from cybersecurity threats (as defined in 6 USC 1501).

Second, I would rewrite §2(f) to read:

(f) APPLICATIONS.—To be eligible for a grant under the Program, a State, local, or Tribal government entity shall submit to the Secretary an application at such time, in such form, and containing:
(1) An analysis of the cybersecurity threats (as defined in 6 USC 1501) that would affect the traffic control systems to be funded by the grant being requested;
(2) A description of the defensive measures that would be used to address the potential threats described in (1); and
(3) Any other information as the Secretary determines appropriate.

NOTE: The definitions in §1501 use the control system inclusive definition of ‘information system’.

 
/* Use this with templates/template-twocol.html */