Showing posts with label S 245. Show all posts
Showing posts with label S 245. Show all posts

Thursday, February 6, 2025

S 245 Ordered Reported Favorably in Senate - Insure Cybersecurity Act

Yesterday, the Senate Commerce, Science, and Transportation Committee held a business meeting to consider 17 pieces of legislation. Among those bills was S 245, the Insure Cybersecurity Act of 2025. According to yesterday’s Congressional Record the bill was ordered reported favorably without any amendments. No word is available in the CR or the meeting record about the type vote held on that order.

Once the Committee report is published (which could be months), the bill would be cleared for consideration before the full Senate. It is unlikely to be considered under regular order (too time consuming with too many nominations to consider). If it is considered it would be under the Senate’s unanimous consent process.

No committee action was taken on a similar bill, S 513, last session. This is not a Republican vs Democrat issue since the sponsor of the bill, Sen Hickenlooper (D,CO), is a Democrat. This seems more likely to be a change in focus of the new Republican Committee Chair, Sen Cruz (R,TX).

Review – S 245 Introduced – Insure Cybersecurity

Last month, Sen Hickenlooper (D,CO) introduced S 245, the Insure Cybersecurity Act of 2025. The bill would require the Department of Commerce to convene an interagency working grout to look at issues related to cyber insurance. Once a report from the working group is produced, DOC would be required to provide the public with “informative resources for cyber insurance stakeholder”. No funding is authorized by this bill.

The bill is very similar to S 513 that was introduced by Hickenlooper in January 2023. No action was taken on that bill. Significant changes were made in S 245, including adding the Federal Trade Commission and at least one State insurance regulator to the list of Working Group members. There were also numerous minor changes to the focus of listed activities for the Working Group.

Moving Forward

Both Hickenlooper and his sole cosponsor {Sen Capito (R,WV)} are both member of the Senate Commerce, Science and Transportation Committee to which this bill was assigned for consideration. This means that there should be sufficient influence to see the bill considered in Committee. I see nothing in the bill that would engender any significant opposition. I expect that the bill would receive bipartisan support.

The bill is not ‘important’ enough to be considered on the floor of the Senate under regular order. I suspect that the bill could be considered under the Senate’s unanimous consent process, but you never can tell what unrelated opposition could lead to an objection under that process.

Commentary

This bill makes no attempt at establishing any regulatory framework for cybersecurity insurance, which would probably be the death knell of bill currently containing such provisions. The crafters of this bill did do Congress a disservice, however, when they did not take advantage of this working group to outline what future regulation legislation might look like. I would have added the following subparagraph (K) to Section 3(c)(1):

(K) Identify any regulatory frameworks that may have been proposed to govern the issuance of cyber insurance.

 

For more details about the proposed legislation, see my article at CFSN Detailed Analysis - https://chemical-facility-security-news.blogspot.com/2025/02/review-s-245-introduced-insure.html [link added 2-6-25 11:50 pm EST] - subscription required.

Saturday, January 25, 2025

Review – Bills Introduced – 1-24-25

Yesterday, with the Senate in Washington, and the House meeting in pro forma session, there were 49 bills introduced. Three of those bills will receive additional coverage in this blog:

HJ Res 30 Providing for congressional disapproval under chapter 8 of title 5, United States Code, of the rule submitted by the Environmental Protection Agency relating to "Phasedown of Hydrofluorocarbons: Management of Certain Hydrofluorocarbons and Substitutes Under the American Innovation and Manufacturing Act of 2020". Dunn, Neal P. [Rep.-R-FL-2]

S 244 A bill to direct the Secretary of Commerce, acting through the Assistant Secretary of Commerce for Communications and Information, to conduct a study of the national security risks posed by consumer routers, modems, and devices that combine a modem and router, and for other purposes. Blackburn, Marsha [Sen.-R-TN]

S 245 A bill to require the Assistant Secretary of Commerce for Communications and Information to establish a working group on cyber insurance, to require dissemination of informative resources for issuers and customers of cyber insurance, and for other purposes. Hickenlooper, John W. [Sen.-D-CO]

 

For more information on these bills, including discussions about similar bills introduced in the 118th, Congress, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/bills-introduced-1-24-25 - subscription required.

Thursday, May 30, 2019

S 1589 Reported in the Senate – FY 2018, 2019, and 2020 Intel Authorization


Last week Sen. Burr (R,NC) introduced (and the Senate Intelligence Committee reported – without a written report) S 1589, the Damon Paul Nelson and Matthew Young Pollard Intelligence Authorization Act for Fiscal Years 2018, 2019, and 2020. This bill is essentially S 245 (introduced earlier this year) as division B with a relatively short Division A tacked onto the front for FY 2020.

Moving Forward


Okay, I have no clue. The Senate has not taken up an intelligence authorization bill since Trump came into office. This bill has been one of the annual ‘must pass’ bills for as long as I remember, but that is apparently no longer true.

Commentary


There is nothing in the new Division A language that I would care to take time to comment upon. See my comments on S 245 for the cybersecurity provisions in Division B.

Friday, February 15, 2019

S 245 Introduced – FY 2019 Intel Authorization

Last month Sen. Burr (R,NC) introduced S 245, the Damon Paul Nelson and Matthew Young Pollard Intelligence Authorization Act for Fiscal Years 2018 and 2019. Intel authorization bills were introduced last session (HR 6237 and S 3153), but only the House bill received any action; it passed by a vote of 363 to 54. No action was taken in the Senate on either bill.

Cybersecurity Provisions


There are a number of cybersecurity related provisions in this bill, but only one of potential specific interest to the industrial control system community. The cybersecurity sections of note include:

§303. Modification of special pay authority for science, technology, engineering, or mathematics positions and addition of special pay authority for cyber positions.
§307. Consideration of adversarial telecommunications and cybersecurity infrastructure when sharing intelligence with foreign governments and entities.
§308. Cyber protection support for the personnel of the intelligence community in positions highly vulnerable to cyber attack.
§309. Modification of authority relating to management of supply-chain risk.
§422. Establishment of Energy Infrastructure Security Center.
§701. Limitation relating to establishment or support of cybersecurity unit with the Russian Federation.

EISC


The potentially interesting ICS provision is, of course, §422 establishing the EISC. A nearly identical provision (different section/paragraph numbers is the only difference) was included in HR 6237. I covered that issue in my post on the introduction of the earlier bill.

Missing Provision


Last year Burr’s authorization bill included a section on energy sector cybersecurity. This was taken almost in whole cloth from last session’s S 79. A bill similar to S 79 was introduced earlier this session; S 174. It is not clear if Burr left this out because he felt that S 174 had a good chance to pass on its own (not likely in my opinion) or whether he got push-back from including the costly provisions in last year’s intel bill.

Moving Forward


Burr’s bill will move forward in Committee, he is after all the Chair of the Senate Select Committee on Intelligence. Getting it to the floor of the Senate may prove to be a bigger problem; he has not had an intel authorization bill on the floor since the FY 2017 bill passed.

Commentary


This used to be considered one of the ‘must pass’ annual authorization bills, but since Trump came to town that does not seem to be the case. Spending bills continue to be approved, but the general Congressional oversight provided through the authorization bills seems to be less important as the community status has waned under Trump. This is doubly unfortunate given the cybersecurity troubles being seen in the world.

Tuesday, January 29, 2019

Bills Introduced – 01-28-19


Yesterday with both the House and Senate back in Washington, there were 51 bills introduced. One of these may see additional coverage in this blog:

S 245 A bill to authorize appropriations for fiscal year 2019 for intelligence and intelligence-related activities of the United States Government, the Community Management Account, and the Central Intelligence Agency Retirement and Disability System. Sen. Burr, Richard [R-NC]

The Senate looks to be trying to clear up some business from the 115th Congress where they never took action on either version (S 3153 or HR 6237) of the FY 2018/2019 intel authorization bill. Better luck in this session; who knows?

 
/* Use this with templates/template-twocol.html */