Showing posts with label S 2926. Show all posts
Showing posts with label S 2926. Show all posts

Tuesday, October 19, 2021

Review - S 2943 Introduced - Ransom Disclosure

Earlier this month, Sen Warren (D,MA) introduced S 2943, the Ransom Disclosure Act. This is very similar to S 2926 which Warren introduced two days earlier. As with the very slightly earlier bill, S 2943 would require covered individuals to report ransomware payments to DHS and require DHS to publish an annual report to Congress about such ransomware reporting.

Warren is not a member of the Senate Homeland Security and Governmental Affairs Committee to which this bill was referred. This means that there is probably insufficient influence to see this bill considered in Committee. I suspect that there would be little support for this bill in that Committee. I would not be surprised to see this bill included as a potential amendment to a larger authorization bill on the floor of the Senate.

I would like to note that I pointed out each of the three major problems corrected in this version of the bill in my post about S 2926. I cannot, however, claim to have influenced Warren’s staff to make these changes; S 2943 was introduced 5-days before I wrote my ‘influential’ post. Besides, they did not correct the most important problem, the huge definitional loophole.

For more details about the differences between the two bills, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-2943-introduced - subscription required.

Wednesday, October 13, 2021

HR 5501 Introduced – Ransom Disclosure

Last week Rep Ross (D,NC) introduced HR 5501, the Ransom Disclosure Act. This is very similar to S 2926 that was also introduced last week, but two significant differences exist. One of the changes made in the House bill modifies (reduces) the overly long reporting deadline that was found in the Senate bill.

Differences

In §2(b) the House version of the bill provides for a 48-hour time-limit for reporting ransom payments where the Senate version give the ransom payer 7-days to make the same notification.

In §2(g)(1) the House version of the bill give DHS 60-days to establish a web site for voluntary reporting of ransom payments by individuals. In the Senate bill, the same paragraph used a specific date (December 21st, 2021) as the deadline for establishing the same web site. The use of a date-certain as a requirement in a piece of legislation is fraught with difficulties since no one can predict when a bill will be taken up, or what obstacle will be encountered enroute to the President’s desk.

Moving Forward

Ross is not a member of the House Energy and Commerce Committee to which this bill was assigned for consideration. As with S 2926, this means that there is probably insufficient influence to see the bill considered in Committee. I am not sure how the Committee would vote if the bill were considered as there is little history of consideration of this type of cybersecurity related bill by this Committee. Most bills of this type are referred to the House Homeland Security Committee. The Energy and Commerce Committee might just favorably report this bill just to keep a hand in the game.

Monday, October 11, 2021

Review - S 2926 Introduction – DHS Ransom Notification

Last week, Sen Warren (D,MA) introduced S 2926 (no formal name). The bill would require broadly defined covered individuals to report ransomware payments within 7 days of the payment being made. DHS would be required to prepare annual reports about such notifications.

Warren is not a member of the Senate Homeland Security and Governmental Affairs Committee to which this bill was referred. This means that there is probably insufficient influence to see this bill considered in Committee. I suspect that there would be little support for this bill in that Committee. I would not be surprised to see this bill included as a potential amendment to a larger authorization bill on the floor of the Senate.

Commentary

So many problems, so little space… First, the problem of definitions. The ‘covered entity’ definition is the most sweeping definition I have seen to date in this space. The inclusion of ‘an individual’ exclusion is not even that important since information systems owned by a family would not technically be included in the exception. The bigger problem is the huge loophole in the ransom definition that effectively exempts all non-federal-agency entities from any reporting requirement. This is nitpicking, but lawyers get large sums of money for picking nits, and corporate lawyers do it extremely well.

The seven-day reporting deadline is the longest that I have seen in any bill. And given the very limited nature of the information being required to be reported, it is completely unjustified. Any company making a ransomware payment would easily be able to report the required information within say 30-minutes of making the payment.

And the DHS study requirements? How much studying will it take for DHS to determine the “extent to which cryptocurrency has facilitated” ransomware attacks? Popular TV shows to the contrary, the FBI figured out how to deal with large cash drops years ago.

For more details about the provisions of the bill, including a detailed look at the problems with definitions, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-2926-introduction - subscription required.

Tuesday, October 5, 2021

Bills Introduced – 10-4-21

Yesterday, with just the Senate is session, there were seven bills introduced. One of those bills may see additional coverage in this blog:

S 2926 A bill to require certain entities to disclose to the Secretary of Homeland Security ransom payments, and for other purposes. Sen. Warren, Elizabeth [D-MA]

I will be watching this bill for language and definitions that would include industrial control systems within its coverage

 
/* Use this with templates/template-twocol.html */