BREAK IN TRANSCRIPT
Mr. DELGADO. Mr. Speaker, I move to suspend the rules and pass the bill (H.R. 2331) to require an annual report on the cybersecurity of the Small Business Administration, and for other purposes.
The Clerk read the title of the bill.
The text of the bill is as follows: H.R. 2331
Be it enacted by the Senate and House of Representatives of the United States of America in Congress assembled, SECTION 1. SHORT TITLE.
This Act may be cited as the ``SBA Cyber Awareness Act''. SEC. 2. CYBERSECURITY AWARENESS REPORTING.
Section 10 of the Small Business Act (15 U.S.C. 639) is amended by inserting after subsection (a) the following:
``(b) Cybersecurity Reports.--
``(1) Annual report.--Not later than 180 days after the date of enactment of this subsection, and every year thereafter, the Administrator shall submit a report to the appropriate congressional committees that includes--
``(A) an assessment of the information technology (as defined in section 11101 of title 40, United States Code) and cybersecurity infrastructure of the Administration;
``(B) a strategy to increase the cybersecurity infrastructure of the Administration;
``(C) a detailed account of any information technology equipment or interconnected system or subsystem of equipment of the Administration that was manufactured by an entity that has its principal place of business located in the People's Republic of China; and
``(D) an account of any cybersecurity risk or incident that occurred at the Administration during the 2-year period preceding the date on which the report is submitted, and any action taken by the Administrator to respond to or remediate any such cybersecurity risk or incident.
``(2) Additional reports.--If the Administrator determines that there is a reasonable basis to conclude that a cybersecurity risk or incident occurred at the Administration, the Administrator shall--
``(A) not later than 7 days after the date on which the Administrator makes that determination, notify the appropriate congressional committees of the cybersecurity risk or incident; and
``(B) not later than 30 days after the date on which the Administrator makes a determination under subparagraph (A)--
``(i) provide notice to individuals and small business concerns affected by the cybersecurity risk or incident; and
``(ii) submit to the appropriate congressional committees a report, based on information available to the Administrator as of the date which the Administrator submits the report, that includes--
``(I) a summary of information about the cybersecurity risk or incident, including how the cybersecurity risk or incident occurred; and
``(II) an estimate of the number of individuals and small business concerns affected by the cybersecurity risk or incident, including an assessment of the risk of harm to affected individuals and small business concerns.
``(3) Rule of construction.--Nothing in this subsection shall be construed to affect the reporting requirements of the Administrator under chapter 35 of title 44, United States Code, in particular the requirement to notify the Federal information security incident center under section 3554(b)(7)(C)(ii) of such title, or any other provision of law.
``(4) Definitions.--In this subsection:
``(A) Appropriate congressional committees.--The term `appropriate congressional committees' means--
``(i) the Committee on Small Business and Entrepreneurship of the Senate; and
``(ii) the Committee on Small Business of the House of Representatives.
``(B) Cybersecurity risk; incident.--The terms `cybersecurity risk' and `incident' have the meanings given such terms, respectively, under section 2209(a) of the Homeland Security Act of 2002.''.
I rise in support of H.R. 2331, the SBA Cyber Awareness Act of 2019, which strengthens the Small Business Administration's cybersecurity infrastructure to handle and report cyber threats that affect small businesses.
The Small Business Administration processes a significant amount of small business data, and protecting these businesses is essential to its mission. That is why they must protect its precious digital networks from cyberattacks. But after the massive data breach at the U.S. Office of Personnel Management, 75 percent of Americans are doubtful that the government can protect their personal information.
With 28 million small business owners in the U.S. that provide 64 percent of new private-sector jobs, America cannot afford for small businesses to lose faith in the SBA. Today, we take an important step to restore American confidence in the SBA's cybersecurity protections and prevent the harmful results of cyberattacks.
H.R. 2331 ensures that the SBA has an effective cyber strategy and requires timely reporting of cyber incidents to Congress and affected individuals. Through these measures, the SBA will better serve the American small businesses that support the U.S. economy.
I thank Congressman Crow and Congressman Balderson for working so diligently to strengthen the agency we oversee and protect the Nation's small business community that utilizes its services.
I ask my fellow Members to support this bill, and I reserve the balance of my time.
BREAK IN TRANSCRIPT
Mr. DELGADO. Mr. Speaker, the Small Business Administration fuels the U.S. economy, and through its lending and contracting programs, helps Americans start, build, and grow small businesses, but in doing so, the agency is tasked with handling vital information.
As we all know, cyberattacks are very real, and nobody, not even the Federal Government, is immune.
That is why this piece of legislation, H.R. 2331, is fundamental to the health of our national cyber infrastructure as it relates to small firms.
The SBA must protect its digital networks from cyberattacks and collaborate more with Congress. Modernizing the agency's IT infrastructure and implementing an effective cyber strategy is the key component of this bill. Doing so guarantees the SBA can adequately and effectively defend its digital network.
This bill also requires timely reporting of cyber incidents to Congress and affected individuals in the unfortunate event of a breach. The sharing of this information allows us to collaborate with the SBA to better address vulnerabilities in the system.
Mr. Speaker, H.R. 2331 has bipartisan support, so I once again want to urge my colleagues to support the measure. I yield back the balance of my time.
BREAK IN TRANSCRIPT