Showing posts with label SBA. Show all posts
Showing posts with label SBA. Show all posts

Monday, May 22, 2023

Review - S 1458 Introduced – SECURE Small Business Act

NOTE: Corrected bill number in title 0642 EST 5-28-23

Earlier this month, Sen Cortez-Masto introduced S 1458, the Strengthening and Enhancing Cybersecurity Usage to Reach Every (SECURE) Small Business Act. The bill would require the Small Business Administration to establish a program to assist small business concerns with purchasing cybersecurity products and services. No funding authorization is included in this legislation.

Moving Forward

While Cortez-Masto is not a member of the Senate Small Business and Entrepreneurship Committee to which this bill was assigned for consideration, her sole co-sponsor {Sen Risch (R,ID)} is a member. This means that there may be sufficient influence to see the bill considered in Committee. I see nothing in this bill that would engender any organized opposition. I suspect that there will be substantial bipartisan support for the bill if it were considered.

As with most bills in the Senate, this legislation is not important enough to be considered under regular order. If it were to be considered by the full Senate, it would most likely be as an amendment to an authorization or spending bill.

Commentary

The wording for the sunset provision in the bill is more than a little odd. Even if the bill were enacted next month (extremely unlikely) the SBA is given six months to establish the marketplace, which means some time in December (and few programs get established in the congressionally mandated timeframe). This means that in an unrealistic world, the program would be in existence for little more than nine months, hardly enough time to see if the program were effective, and certainly not time enough for congress to reauthorize if it were even overwhelmingly effective. These sunset provisions are not usually tied to a date certain, but rather they are typically expressed in a period of 2 to 5 years from the date of enactment.

 

For more details about the provisions of this bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/s-1459-introduced - subscription required.

Monday, March 14, 2022

Review - HR 6812 Introduced – SBA Cybersecurity Grant Pilot

Last month, Rep Joyce (R,OH) introduced HR 6812, the Small Business Cybersecurity Assistance Pilot Program Act. The bill would provide continued funding for the Cybersecurity Assistance Pilot Program through 2025 at the rate of $3 million per year. The bill also contains congressional reporting requirements.

Moving Forward

While Joyce is not a member of the House Small Business Committee to which this bill was assigned for consideration, one of his cosponsors {Rep Garbarino (R,NY)} is a member. This means that there may be sufficient influence to see this bill considered in Committee. I see nothing in this bill that would engender any organized opposition. Even the authorization provision, which frequently impedes consideration of bills like this, should not be a problem since the Appropriations Committee is obviously already on board.

I suspect that the bill would receive significant bipartisan support in Committee and that that support should be large enough to allow this bill to be considered under the suspension of the rules process.

Commentary

This is a rather small ‘pilot’ grant program, but it still deserves better documentation of the purpose and scope of the program than the mention in passing in two separate spending bill explanatory statements that has been the sole documentation of the authorization of this program.

For more details on the history of this program and provisions of the bill, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-6812-introduced - subscription required.

Wednesday, November 3, 2021

House Passes Two SBA Cybersecurity Bills – 11-2-21

Yesterday the House took up two bills related to cybersecurity support to small businesses by the Small Business Administration. Both bills were considered under the suspension of the rules process and passed with very strong bipartisan support in recorded votes.

The two bills were:

• HR 3462, the SBA Cyber Awareness Act, and

HR 4515, the Small Business Development Center Cyber Training Act of 2021

I have not covered HR 3462. This bill addresses the internal cybersecurity operations of the SBA. The final vote on this bill was 423 to 0.

There was only about 10 minutes of debate on HR 4515. There were no speakers in opposition to the bill. The final vote was 409 to 14 with all of the Nay votes coming from Republicans.

NOTE: Corrected title 11-4-21 0705 EDT

Thursday, August 19, 2021

Review - HR 4513 Introduced – Small Business Advanced Cybersecurity

Last month, Rep Donalds (R,FL) introduce HR 4513, the Small Business Advanced Cybersecurity Enhancements Act of 2021. The bill would amend 15 USC 648. It would require the Small Business Administration (SBA) to establish cybersecurity assistance units in each small business development center as well as a central small business cybersecurity assistance unit to inform and coordinate the activities of the regional centers. The bill would require the SBA to allocate $1 million each year from existing funding for those regional assistance units.

The House Small Business Committee held a markup hearing on July 29th, 2021 and considered HR 4513, along with six other bills. The bill passed on a voice vote, indicating there was at least some bipartisan support for the bill. I suspect that the bill will be considered by the full House under the suspension of the rules process, and it would probably pass.

For more detailed information on the provisions of this bill, including my suggestions to ensure that the information sharing is a two-way process, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/hr-4513-introduced - subscription required.

Monday, March 1, 2021

S 161 Introduced – SECURE Small Business Act

Last month Sen Cortez-Masto introduced S 161, the Strengthening and Enhancing Cybersecurity Usage to Reach Every (SECURE) Small Business Act. The bill would require the Small Business Administration (SBA) to “establish a program to assist small business concerns with purchasing cybersecurity products and services” {§3(a)}.

Definitions

Section 2 of the bill provides definitions of the following key terms:

• Administrator,

• Covered Industry Sector,

• Covered Vendor,

• Cybersecurity,

• Cybersecurity Threat, and

• Small Business Concern

The term ‘Cybersecurity Threat’ is defined as “the possibility of a malicious attempt to infiltrate, damage, disrupt, or destroy computer networks or systems” {§2(5)}.

The term ‘Covered Sector’ includes 10 of the 16 Critical Infrastructure Sectors defined under Presidential Policy Directive #21. It does not include the Chemical or Energy Sectors.

The definition of ‘Covered Vendor’ specifically includes “cybersecurity risk insurance” {§2(3)}.

Cooperative Market Place

A key portion of the program required under this bill would be the establishment of the “Cooperative Marketplace For Purchasing Cybersecurity Products And Services” {§3(c)}. The Cooperative Marketplace would facilitate the “creation of mutual agreements under which small business concerns cooperatively purchase cybersecurity products and services from covered vendor” {3(c)(1)(B)}. The CM would be free to use for small businesses and covered vendors.

GAO Study

The bill would also require the Government Accountability Office to conduct a study on existing Federal cybersecurity initiatives that “train small business concerns how to avoid cybersecurity threats” {§4(a)(1)}. The GAO would be required to provide a report to Congress within one year of the enactment of the bill.

Moving Forward

Cortez-Masto is not a member of the Senate Small Business and Entrepreneurship Committee to which this bill was assigned for consideration. Both of her cosponsors {Sen Risch (R,ID) and Sen Rosen (D,NV), however, are members. This means that there should be adequate influence available to have this bill considered in Committee. I see nothing in the language of this bill that would engender any significant opposition.

The bill should receive bipartisan support if it is considered by the Committee. If this bill makes it to the floor of the Senate, it will most likely be considered under the Senate’s unanimous consent process; the bill is not important enough to be considered under the normal debate/amend process.

Commentary

First off, the failure to include the Chemical and Energy sectors in the definition of the ‘Covered Sector’ bothers me. Both sectors have numerous small business concerns that form important pieces of the supply chains larger companies. The cybersecurity of those small businesses deserves the same coverage as the listed sectors in the bill. I would suggest changing the definition in §2(2) to read:

(2) COVERED INDUSTRY SECTORS.—The term “covered industry sectors” means those critical infrastructure sectors defined in  Presidential Policy Directive 21 (PPD-21): Critical Infrastructure Security and Resilience or successor documents,

The definition of ‘Cybersecurity Threat’ is weak and looks to exclude the threat to industrial control systems and Internet-of-Things systems that are forming an increasingly threatened portion of the cyber landscape. A better choice would have been to use the definition from 6 USC 1501 since that definition is based on the ICS inclusive definition of ‘Information System’ in the same section. Thus, I would change §2(5) to read:

(5) CYBERSECURITY THREAT.—The term “cybersecurity threat” as that term is defined in 6 USC 1501,

Sunday, April 21, 2019

HR 1648 Introduced – SBA Security Assistance


Last Month Rep. Chabot (R,OH) introduced HR 1648, the Small Business Advanced Cybersecurity Enhancements Act of 2019. The bill would require the Small Business Administration to establish a Central Small Business Cybersecurity Assistance Unit as well as regional cybersecurity assistance units.

Cybersecurity Assistance Units


The CSBCAU would be collocated with the DHS National Cybersecurity and Communications Integration Center (NCCIC) and would serve as a conduit for sharing cybersecurity threat information between small businesses and the federal government. All of the information sharing protections provided under the CISA legislation {6 USC 1503(c)} would apply to information sharing via the CSBCAU {new 15 USC 648(a)(9)(B)(iii)}. Information on cyberthreat indicators or defensive measures shared through the CSBCAU will not be subject to the narrow regulatory exemption found in 6 USC 1504(d) (5)(D)(ii)(I).

The regional small business cybersecurity assistance units will be part of each Small Business Administration (SBA) small business development center. The bill would require the SBA to set aside $1 million from the monies authorized for small business development centers for the operation of regional SBCAU’s.

Moving Forward


Chabot and both of his cosponsors {Rep. Balderson (R,OH) and Rep. Velasquez (D,NY)} are members of the House Small Business Committee, the Committee to which this bill was assigned for consideration. This means that there is a good chance that this bill will be considered in Committee.

There is nothing in this bill that would incur any significant opposition. I suspect that if it is considered in committee that it would pass with significant bipartisan support. If considered by the full House it would likely be considered under the suspension of the rules process with limited debate and no floor amendments. Again, it would probably pass with substantial bipartisan support.

Commentary


This bill is an attempt to encourage small business owners to participate in the existing cybersecurity information sharing program with CISA by using familiar SBA channels of communication. Unfortunately, it does not address the underlying issues that appear to be hindering businesses in general from participating in the information sharing process. That is the appearance that the information sharing process is a one-way street with little useable information flowing back to the private sector.

The one small sop thrown to the small business community, the §1504 exception will do little to add encouragement for small businesses to participate in the CISA information sharing process. Section 1504 allows units of the federal government to use information shared with NCCIC to be used to fine tune existing cybersecurity regulations. Since there are few areas of the federal regulatory system that are specifically allowed to regulate cybersecurity, this is a fairly unimportant exception.

There is no mention in this bill of industrial control system security issues. The findings section of the bill only mentions information technology security concerns. Fortunately, since this bill attempts to supplement the CISA information sharing process, it uses control system friendly definitions from 6 USC 1501 that are based on the definition of ‘information system’ that specifically includes control systems. Unfortunately, this is as unlikely to encourage small businesses to share control system security threat information with CISA as it is purely IT threat information. Congress needs to clearly identify the existing impediments to information sharing and rectify those before they can expect small businesses to become part of the process.

 
/* Use this with templates/template-twocol.html */