Cybersecurity Information Sharing Act of 2015

Floor Speech

Date: Oct. 22, 2015
Location: Washington, DC

BREAK IN TRANSCRIPT

Mr. President, I rise to support the Cybersecurity Information Sharing Act, long overdue and vital legislation designed to reduce our Nation's vulnerability to cyber attacks.

I want to commend the ranking member of my committee, Senator Tom Carper, and Senator Burr and Senator Feinstein, for their collaborative effort. This is an example of when we actually seek to find the areas of agreement that unify us versus exploit our divisions, then we can actually accomplish some pretty good things. This bill is one of those examples.

The cyber threat we face today is real and it is growing. Sophisticated nation-state adversaries such as China and North Korea are constantly probing American companies' and Federal agencies' computer networks to steal valuable and sensitive data. International criminal organizations are exploiting our networks to commit financial fraud and health fraud. Cyber crime is so pervasive that the former Director of the National Security Agency described it as the ``greatest transfer of wealth in human history.'' Cyber terrorists are trying to attack cyber-connected critical infrastructure, thereby threatening our very way of life.

We have already experienced the impact of this threat. Within the last year and a half alone, more than 20 top American companies and Federal agencies have experienced major breaches. A breach of the Office of Personnel Management allowed a foreign adversary to steal 19.7 million Federal employees' background checks, over 5 million fingerprint files, and 4 million personnel records. A breach at IRS allowed cyber criminals abroad to access over 330,000 taxpayer financial records. A destructive cyber attack from North Korea on Sony Pictures resulted in the destruction of thousands of computers and theft of the company's most valuable intellectual property. Data breaches at both Anthem and JP Morgan resulted in the theft of 80 million health care subscribers' personal data and 83 million banking customers' personal information. Even the White House is not immune from attack. Six months ago, foreign adversaries breached White House networks, compromising the President's nonpublic schedule.

Federal agencies are neglecting to protect Americans' data and Federal law is preventing companies from defending their networks. Congressional oversight, including hearings held by my committee, the Senate Committee on Homeland Security and Governmental Affairs, has shown agencies are not doing enough to protect their sensitive data. Our committee's oversight hearings of the IRS and OPM data breaches revealed that basic cyber security hygiene and best practices would have stopped attackers in their tracks had they been in place at these agencies. The Department of Homeland Security has not yet fully implemented the cyber security programs we need to protect Federal agencies' networks.

Meanwhile, current law hinders private companies from sharing indicators that can be used to detect and stop attacks against their networks. To be effective, cyber threat indicators must be shared very quickly. The 2015 Verizon data breach investigation report revealed that 75 percent of attacks spread within 24 hours, and 40 percent spread within just 1 hour. Yet our current network of anti-trust and wiretap loss hampers companies from sharing that information quickly, creating a threat of lawsuit and prosecution for sharing that the information companies can use to identify and stop attacks.

There is no easy solution, but there are things Congress can do to improve cyber security that might make cyber attacks more difficult. That is why I am proud to have worked with Senator Burr and Senator Feinstein to create the Cybersecurity Information Sharing Act, which takes a significant first step in addressing both of these issues.

First, it enables information sharing to improve cyber security within private companies.

Second, it improves cyber security at Federal agencies.

I especially appreciate the collaboration of Senator Carper in working with me to help craft title II of the bill--the Federal Cybersecurity Enhancement Act--which was unanimously reported out of our committee. This bill will put Federal agencies on track to implement commonsense cyber security solutions already in use in many companies, thereby improving the security of Americans' data at the Federal agencies.

BREAK IN TRANSCRIPT

First, it will mandate deployment and implementation of a government-wide intrusion detection and prevention system for Federal networks.

Second, it will require OMB to develop an intrusion assessment plan so government agencies can hunt down and eradicate attackers already in their networks.

Third, it requires agencies to implement specific cyber security practices, such as multifactor authentication and encryption of sensitive data, which would have stopped previous attacks.

Fourth, and finally, it will give the Secretary of Homeland Security and the Director of the Office of Management and Budget the authority they need to oversee cyber security across the Federal Government.

In short, the Cybersecurity Information Sharing Act, with the inclusion of the Federal Cybersecurity Enhancement Act, will significantly improve our cyber security posture. This bill will not solve all of our cyber security woes, but it is an important step in the right direction, and I am glad to support it.

BREAK IN TRANSCRIPT


Source
arrow_upward