BREAK IN TRANSCRIPT
Mr. COTTON. Mr. President, today I speak in support of the Cotton amendment to the Cybersecurity Information Sharing Act. My amendment is straightforward. It simply would provide liability protection to any business or other private organization that shares cyber threat indicators to the FBI or the Secret Service.
In its current form, the Cybersecurity Information Sharing Act would require entities to submit these cyber threat indicators through a portal created and run by the Department of Homeland Security in order to receive liability protection. But there are also two exceptions that would allow entities to receive liability protection outside the DHS portal: first, if a submission was related to a previously shared cyber threat indicator, and second, if the submitting entity is sharing information with its Federal regulatory authority. But not every private entity has a Federal regulatory authority, thank goodness, so where a cable company can share with the FCC or an energy company can go to the Department of Energy or FERC, other businesses are forced to go to the DHS portal. Good examples are retailers such as JCPenney, Walmart, Target, and Home Depot.
When the trade associations for two victims of the biggest cyber attacks in recent memory--Target and Home Depot--are pleading for this language, we should take notice and incorporate it. Anything else would be unfair, inequitable, and unwise.
We ought to give these companies an alternative to the DHS portal. One simple reason is that nobody knows what the portal will look like, how it will function, or how much it will cost companies to interact with it. The Federal Government, after all, doesn't have the best track record for designing and deploying IT systems. Healthcare.gov was not exactly a resounding success. One could easily imagine a company trying to share a cyber threat indicator and getting an error message from the portal, just as millions of Americans received when they tried to sign up for ObamaCare.
In this case, regulated businesses can just go to their regulator. Private and small businesses will be out of luck, though. This is the primary reason my amendment has such strong private support. Organizations such as the National Retail Federation, the chamber of commerce, the National Cable & Telecommunications Association, and many others support this commonsense amendment.
The second main reason that entities should be able to share directly with the FBI and the Secret Service is that the bill is about promoting collaboration between the government and the private sector, as the National Security Council says that we should in this tweet: ``More than any other national security topic, effective cybersecurity requires the US gov't & private sector to work together.'' I agree.
As Director Comey recently told the Senate Intelligence Committee, the FBI has redoubled its efforts to reach out to private businesses in this area. This has paid dividends. And there is no entity in the Federal Government that the private sector trusts more on cyber security than the FBI. That is why Sony Pictures called the FBI when it was hacked by North Koreans last year.
I also have to imagine that is the main reason the White House endorsed my amendment over the weekend when they sent out this very helpful tweet: ``If you are a victim of a major cyber incident, a call to @FBI, @SecretService, or @DHSgov is a call to all.'' My goodness, Susan Rice and I stand together in agreement that if you are a victim of a cyber incident, you should be able to call the FBI, the Secret Service, or the DHS. I thank the National Security Advisor and the White House for their support for the concept behind my amendment.
I would also like to take a few moments to dispel a few myths about this amendment. The first myth is that the Cybersecurity Information Sharing Act creates a single portal at DHS for liability-protected information sharing with the Federal Government and that the Cotton amendment would create an unprecedented second channel.
This is false. The bill authorizes multiple liability-protected sharing channels with the Federal Government, not just one, through a broad exception to the DHS portal that permits certain regulated businesses to engage in liability-protected sharing of cyber threat information directly with any Federal regulators without requiring that it first pass through DHS. The Cotton amendment simply provides the same flexibility for businesses that already have established threat-sharing relationships with the FBI or the Secret Service to maintain their existing channels for sharing and not incur significant costs and delays to establish new ones with DHS. My amendment is consistent with this multichannel sharing approach.
The second myth is that my amendment would harm privacy as it would allow the sharing of cyber threat indicators with the FBI and the Secret Service and that the sharing with these agencies wouldn't happen under the bill in its current form.
This is also false. Under the current version of the bill, if an entity shares information through the DHS portal, the FBI and Secret Service will receive it. My amendment doesn't change that or the privacy protections in the bill. Both with and without my amendment, the FBI and Secret Service will get cyber threat indicators.
The third myth is that the scrub DHS would have to conduct for personally identifiable information is not as rigorous under my amendment.
Again, this is not true. The Cybersecurity Information Sharing Act requires all Federal entities receiving threat indicators to protect privacy by removing personal information that may still be contained in them before sharing with other entities. My amendment does not eliminate or weaken any of the bill's privacy requirements, as the FBI and Secret Service are required to protect privacy in the same way all other Federal entities receiving threat indicators.
Finally, I simply want to note that the House-passed version of the bill contains a nearly identical provision, and that bill passed with overwhelming bipartisan support on a 307-to-116 vote.
To sum up, the Cotton amendment has overwhelming support in the private sector, including companies that have been victims of cyber crimes. It would lead to greater information sharing between the private sector and the Federal Government. It preserves the privacy protections in the bill. When it was included in the House bill, both Republicans and Democrats voted yes. I therefore ask my colleagues on both sides of the aisle to support this amendment.
I yield the floor.
BREAK IN TRANSCRIPT