BREAK IN TRANSCRIPT
Ms. VELAZQUEZ. Mr. Speaker, I move to suspend the rules and pass the bill (H.R. 3462) to require an annual report on the cybersecurity of the Small Business Administration, and for other purposes.
The Clerk read the title of the bill.
The text of the bill is as follows: H.R. 3462
Be it enacted by the Senate and House of Representatives of the United States of America in Congress assembled, SECTION 1. SHORT TITLE.
This Act may be cited as the ``SBA Cyber Awareness Act''. SEC. 2. CYBERSECURITY AWARENESS REPORTING.
Section 10 of the Small Business Act (15 U.S.C. 639) is amended by inserting after subsection (a) the following:
``(b) Cybersecurity Reports.--
``(1) Annual report.--Not later than 180 days after the date of enactment of this subsection, and every year thereafter, the Administrator shall submit a report to the appropriate congressional committees that includes--
``(A) an assessment of the information technology (as defined in section 11101 of title 40, United States Code) and cybersecurity infrastructure of the Administration;
``(B) a strategy to increase the cybersecurity infrastructure of the Administration;
``(C) a detailed account of any information technology equipment or interconnected system or subsystem of equipment of the Administration that was manufactured by an entity that has its principal place of business located in the People's Republic of China; and
``(D) an account of any cybersecurity risk or incident that occurred at the Administration during the 2-year period preceding the date on which the report is submitted, and any action taken by the Administrator to respond to or remediate any such cybersecurity risk or incident.
``(2) Additional reports.--If the Administrator determines that there is a reasonable basis to conclude that a cybersecurity risk or incident occurred at the Administration, the Administrator shall--
``(A) not later than 7 days after the date on which the Administrator makes that determination, notify the appropriate congressional committees of the cybersecurity risk or incident; and
``(B) not later than 30 days after the date on which the Administrator makes a determination under subparagraph (A)--
``(i) provide notice to individuals and small business concerns affected by the cybersecurity risk or incident; and
``(ii) submit to the appropriate congressional committees a report, based on information available to the Administrator as of the date which the Administrator submits the report, that includes--
``(I) a summary of information about the cybersecurity risk or incident, including how the cybersecurity risk or incident occurred; and
``(II) an estimate of the number of individuals and small business concerns affected by the cybersecurity risk or incident, including an assessment of the risk of harm to affected individuals and small business concerns.
``(3) Rule of construction.--Nothing in this subsection shall be construed to affect the reporting requirements of the Administrator under chapter 35 of title 44, United States Code, in particular the requirement to notify the Federal information security incident center under section 3554(b)(7)(C)(ii) of such title, or any other provision of law.
``(4) Definitions.--In this subsection:
``(A) Appropriate congressional committees.--The term `appropriate congressional committees' means--
``(i) the Committee on Small Business and Entrepreneurship of the Senate; and
``(ii) the Committee on Small Business of the House of Representatives.
``(B) Cybersecurity risk; incident.--The terms `cybersecurity risk' and `incident' have the meanings given such terms, respectively, under section 2209(a) of the Homeland Security Act of 2002.''.
Mr. Speaker, I rise in support of H.R. 3462, the SBA Cyber Awareness Act. This bill directs the SBA to issue reports that assess its cybersecurity infrastructure and report cyber threats, breaches, and attacks.
For more than 25 years, the SBA's Office of Inspector General has listed IT security as one of the most serious management and performance challenges facing the agency. These vulnerabilities were further exposed during the rollout of the SBA's COVID-19 relief programs. The unprecedented demand for the SBA's relief programs inundated SBA's legacy systems leading to back-end system crashes, portals operating slowly, and a glitch that led to a data breach of applicants' personal information.
SBA failed to make any public announcement about the data breach, and it took weeks for the agency to send paper notifications to affected individuals.
The SBA has taken the necessary steps to recover from these incidents, but we want a notification system in place before the next cybersecurity breach.
This bill sets new reporting requirements to ensure congressional and public awareness of cyber incidents at the SBA. I would like to thank my colleagues, Mr. Jason Crow from Colorado and Mrs. Young Kim from California, for introducing this bill.
Mr. Speaker, I urge my colleagues to support this bill, and I reserve the balance of my time.
BREAK IN TRANSCRIPT
Ms. VELAZQUEZ. Mr. Speaker, I am prepared to close, and I reserve the balance of my time.
BREAK IN TRANSCRIPT
Ms. VELAZQUEZ. Mr. Speaker, H.R. 3462 adds new layers of Congressional oversight to regularly assess SBA's IT and cybersecurity systems and controls, and it will go a long way to increase transparency in the event of another IT or cyber incident.
Congress and the American people need to know that the SBA's systems are fully operational and capable of handling the next surge. This bill takes a step towards rebuilding the trust and confidence in the SBA's IT infrastructure.
Mr. Speaker, I thank my colleagues for their work, I urge Members to vote ``yes'' on this bill, and I yield back the balance of my time.
Ms. JACKSON LEE. Mr. Speaker, I rise in support of H.R. 3462, the ``SBA Cyber Awareness Act,'' which will strengthen our knowledge of cybersecurity threats to the small businesses of America.
In short, this bill mainly requires that the Small Business Administration (SBA) conduct an annual report that assesses the cybersecurity infrastructure of the SBA.
Mr. Speaker, the unfortunate reality is that our Nation's small businesses are under attack--they are increasingly the target of cybersecurity breaches.
In fact, the SBA has listed IT security as one of the most serious management challenges facing the administration for more than twenty years.
Fifty percent of small businesses say that it is likely they will experience a cyberattack in the next twelve months.
One in four small businesses indicate that they are facing more cyberattacks compared to a year ago.
Small businesses are the backbone of this country, and we owe it to them to be diligently aware of threats to their private information and their livelihoods.
That is why I rise in ardent support of the SBA Cyber Awareness Act, and that is why the bill has bipartisan backing.
Lastly, I want to thank Congressman Crow and Congresswoman Kim for introducing and shepherding this bill.
BREAK IN TRANSCRIPT