BREAK IN TRANSCRIPT
Mr. McCAUL. Mr. Speaker, I yield myself such time as I may consume.
Mr. Speaker, I rise today in support of H.R. 3696, the National Cybersecurity and Critical Infrastructure Protection Act of 2014. I have worked on this for a long time and introduced this bill with my good friend and colleague, the chairman of the Cybersecurity Subcommittee, the gentleman from Pennsylvania, Congressman Pat Meehan. I would also like to thank Ranking Member Thompson, as well as Ranking Member Clarke of the Cybersecurity Subcommittee, for all their hard work in forging this bipartisan bill. These efforts once again prove that we can work together, despite our differences, to craft legislation that improves our national security and helps protect American critical infrastructure from devastating cyber attacks.
Just last week, the Homeland Security Committee heard testimony that we are at a pre-9/11 mindset when it comes to cybersecurity and that the government needs to do a better job at warning the public about the dangers of attacks on networks we rely upon. That was from the 9/11 Commission itself.
Cyber vulnerabilities in our Nation's critical infrastructure are an Achilles heel in our homeland security defenses. Let me be very clear. The cyber threat is real and it is happening right now. The Internet has become the next battlefield for warfare, but unlike land, sea, and air, cyber attacks occur at the speed of light, they are global, and they are more difficult to attribute.
Criminals, hacktivists, terrorists, and nation-state actors such as Russia, China, and Iran are increasingly using malicious malware to hack into U.S. companies for espionage purposes or financial gain, our defense systems to steal our sensitive military information, and our critical infrastructure to gain access to our gas lines, power grids, and water systems.
Iranian hackers, for example, continue to attack the American financial services sector to shut down Web sites and restrict America's access to their bank accounts. Additionally, Iran continues to build more sophisticated cyber weapons to target U.S. energy companies and has demonstrated these capabilities when they attacked Saudi Arabia's national oil company, Aramco, and erased critical files on 30,000 computers. We cannot allow rogue nations like Iran to be able to shut things down and have capabilities that match our defenses. That would be a game-changer for our national security.
The Chinese, in particular, are hacking into major U.S. companies to give their industries competitive economic advantages in our global economy. I applaud the recent efforts taken by the Justice Department for indicting five members of the Chinese government for conducting cyber espionage attacks against U.S. industry, but more needs to be done. Those indictments send a clear message to our adversaries that cyber espionage and theft of American intellectual property, trade secrets, military blueprints, and jobs will not be tolerated.
A recent McAfee and Center for Strategic and International Studies report on the economic impact of cyber crime found an annual effect of roughly $455 billion globally, with 200,000 jobs lost in the United States alone as a result. In fact, former Director of the NSA, General Keith Alexander, described cyber espionage and the loss of American intellectual property and innovation as ``the greatest transfer of wealth in history.''
A recent poll conducted by Defense News revealed that our top Nation's top security analysts see cyber attacks as the greatest threat to our Nation. In fact, Director of National Intelligence, James Clapper, testified earlier this year that: ``Critical infrastructure, particularly the systems used in water management, oil, and gas pipelines, electrical power distribution, and mass transit, provides an enticing target to malicious actors.''
A cyber attack on U.S. critical infrastructure--such as gas pipelines, financial services, transportation, and communication networks--could result in catastrophic regional or national effects on public health or safety, economic security, and national security.
High-profile retail breaches like the ones at Target and Neiman Marcus that compromised the personal information of over 110 million American consumers resonate with Americans, but as bad as those breaches were, a successful cyber attack on our critical infrastructure could cause much more damage in terms of lives lost and monetary damage. We cannot and will not wait for a catastrophic 9/11-scaled cyber attack to occur before moving greatly needed cybersecurity legislation.
The National Cybersecurity and Critical Infrastructure Protection Act ensures that DHS and not the military is responsible for domestic critical infrastructure protection.
Specifically, H.R. 3696 ensures that there is a ``civilian interface'' to the private sector to share real-time cyber threat information across the critical infrastructure sectors, particularly in light of the Snowden revelations.
Importantly, the bill protects civil liberties by putting a civilian agency with the Nation's most robust privacy and civil liberties office in charge of preventing personal information from being shared. While also prohibiting any new regulatory authority, this bill builds upon the groundwork already laid by industry and DHS to facilitate critical infrastructure protection and incidence response efforts.
This bipartisan bill, which is rare in this day and age, Mr. Speaker, is a product of 19 months of extensive outreach and great collaboration with all stakeholders, including more than 300 meetings with experts, industry, government agencies, academics, privacy advocates, and other committees of jurisdiction.
We went through several drafts and countless hours of negotiations to bring this commonsense legislation to the floor with support from all of the critical infrastructure sectors.
I will enter in the Record some of the letters of support, representing over 33 trade associations from across industry sectors, U.S. businesses, national security experts, and privacy and civil liberty advocates.
Specifically, we have received support letters from the American Civil Liberties Union, the American Chemistry Council, AT&T, Boeing, Con Edison, the Depository Trust and Clearing Corporation, GridWise Alliance, and multiple trade associations in the energy sector and the financial services sector, Information Technology Industry Council, the Internet Security Alliance, Rapid7, National Defense Industrial Association, Professional Services Council, Oracle, Entergy, Pepco, Verizon, and Symantec.
I believe that is a very impressive showing on behalf of the privacy advocates and also the private sector.
BREAK IN TRANSCRIPT
Mr. McCAUL. I want to give a great deal of thanks not only to the Members involved, but to the staff on this committee on both sides of the aisle who have worked countless hours to bring this bill to its fruition on the floor of the House.
I also would like to bring special attention to the endorsement from the ACLU. They refer to H.R. 3696 as ``both pro-security and pro-privacy.'' When have we heard these two coming together?
Striking a balance between security and privacy, I believe, is one of the most difficult challenges in developing cybersecurity legislation, and I am so very proud that this committee and this bill achieves that goal.
I want to close with the threat that I see out there from cyber. People ask me: What keeps you up at night? We can talk about al Qaeda, Mr. Putin, or
ISIS in Iraq and Syria, we can talk about our border and the threats south of the border, but when I see our offensive capability and what we can do offensively, knowing at night that we don't have the defensive capability to stop attacks not only to steal things, not only criminal IP theft, not just espionage, but the power to shut things down and to bring this country to its knees with a cyber 9/11, Mr. Speaker, is really what keeps me up at night.
My father was a World War II bombardier on a B-17. He flew over 32 missions in Europe in support of the D-day invasion and the Battle of the Bulge. In his days, bombs won that war.
We have a new kind of warfare out there. It is a digital warfare, and the game has changed. It is done anonymously. There are no boundaries to this cyber threat any more. It can come from anywhere, at any time, without being able to attribute it back to the source from where the attack came from.
This bill will for the first time codify DHS' ability--and the NCCIC, which is their cyber command, to better defend and support critical infrastructure in the United States that we so heavily depend on, and it will ultimately protect not only our economy and our infrastructure, but ultimately protect the American people.
With that, Mr. Speaker, I ask my colleagues to support this important legislation to protect America, and I reserve the balance of my time.
BREAK IN TRANSCRIPT
Mr. McCAUL. Mr. Speaker, in closing, let me echo the sentiments of the gentlewoman from New York.
I want to thank you and Mr. Meehan for your work on this bill. You are truly the workhorses--the engines--behind this bill, and I want to thank you for helping us get to this point where we are today.
Congressman Langevin, we were talking about cybersecurity before it was cool to talk about cybersecurity.
Forming the Cybersecurity Caucus, I think, raises awareness of Members of Congress about how important this issue really is, because, I think, when you talk about this issue, Mr. Speaker, people's eyes tend to glaze over. They don't understand how important this is in protecting the American people.
This is a national security bill. I don't believe partisan politics has a place in that. I was at The Aspen Institute with Jane Harman, who served on our committee and on the Intelligence Committee for many years, who also believes that our adversaries don't care whether we are Democrat or Republican. They care about the fact that we are Americans, and they want to hit us. We have adversaries who want to hit us--China, Russia, Iran, and countless others--in the cybersecurity space.
This is a pro-security and pro-privacy bill. I had a reporter ask me, How could you possibly get the ACLU to agree on any security bill? It protects Americans' privacy but also their security through the private civilian interface to the private sector, and that is how we do it. It is not through the military. The NSA has a foreign intelligence role, and the DHS has a domestic critical infrastructure role. Of course, Director Alexander called cybersecurity and what has happened in recent years the largest transfer of wealth in history.
So when the American people say: Why is this so important; the largest transfer of wealth in American history? Why is this so important? Because cyber can bring down things, can shut down things in a 9/11 style.
We have a historical moment in this Congress to pass the first cybersecurity bill through the House and Senate and be signed into law in the history of the Congress. As this bill passes--I hope, in a few minutes--and we send it over to the Senate, I hope our colleagues on the Senate side will respond to this.
They have made great progress on the Senate side in getting work done on cybersecurity. We have a unique opportunity and a great moment here to pass this bill out of the House, get it married with the Senate bill in a bipartisan way to protect the American people, and get it signed into law by the President, something that we very rarely have seen in this Congress. So I think it is a very historic moment.
To close, Mr. Speaker, when 9/11 happened, a lot of people did a lot of finger pointing around here and pointed to Members of Congress and to the executive branch and said: What did you do to stop this? What did you do to stop this?
We had a 9/11 Commission that pointed out all the vulnerabilities and the things that we didn't do as Members of Congress. I don't want that to happen again today. I want to be able to say, Mr. Speaker, if, God forbid, we get hit, and we get hit hard in a cyber attack against the United States of America, that we as Members of Congress and members of this committee did everything within our power to stop it.
Mr. Speaker, I am proud of the great work we have done together. I look forward to the passage of this bill.
I yield back the balance of my time.
BREAK IN TRANSCRIPT