BREAK IN TRANSCRIPT
I am pleased to bring to the floor H.R. 1731, the National Cybersecurity Protection Advancement Act, a proprivacy, prosecurity bill that we desperately need to safeguard our digital networks.
I would like to commend the subcommittee chairman, Mr. Ratcliffe, for his work on this bill as well as our minority counterparts, including Ranking Member Thompson and subcommittee Ranking Member Richmond for their joint work on this bill. This has been a noteworthy, bipartisan effort. I would also like to thank House Permanent Select Committee on Intelligence Chairman Devin Nunes and Ranking Member Adam Schiff for their input and collaboration. Lastly, I would like to thank Committee on the Judiciary Chairman Goodlatte and Ranking Member Conyers for their contribution.
Make no mistake, we are in the middle of a silent crisis. At this very moment, our Nation's businesses are being robbed, and sensitive government information is being stolen. We are under siege by a faceless enemy whose tracks are covered in cyberspace.
Sophisticated breaches at companies like Anthem, Target, Neiman Marcus, Home Depot, and JPMorgan have compromised the personal information of millions of private citizens. Nation-states like Iran and North Korea have launched digital bombs to get revenge at U.S.-based companies, while others like China are stealing intellectual property. We recently witnessed brazen cyber assaults against the White House and the State Department, which put sensitive government information at risk.
In the meantime, our adversaries have been developing the tools to shut down everything from power grids to water systems so they can cripple our economy and weaken our ability to defend the United States.
This bill will allow us to turn the tide against our enemies and ramp up our defenses by allowing for greater cyber threat information sharing. This bill will strengthen the Department of Homeland Security's National Cybersecurity and Communications Integration Center, or NCCIC. The NCCIC is a primary civilian interface for exchanging cyber threat information, and for good reason. It is not a cyber regulator. It is not looking to prosecute anyone, and it is not military or a spy agency. Its sole purpose, Mr. Chairman, is to prevent and respond to cyber attacks against our public and private networks while aggressively protecting Americans' privacy.
Right now we are in a pre-9/11 moment in cyberspace. In the same way legal barriers and turf wars kept us from connecting the dots before 9/11, the lack of cyber threat information sharing makes us vulnerable to an attack. Companies are afraid to share because they do not feel they have the adequate legal protection to do so.
H.R. 1731 removes those legal barriers and creates a safe harbor, which will encourage companies to voluntarily exchange information about attacks against their networks. This will allow both the government and private sector to spot digital attacks earlier and keep malicious actors outside of our networks and away from information that Americans expect to be defended.
This bill also puts privacy and civil liberties first. It requires that personal information of our citizens be protected before it changes hands--whether it is provided to the government or exchanged between companies--so private citizens do not have their sensitive data exposed.
Significantly, both industry and privacy groups have announced their support for this legislation because they recognize that we need to work together urgently to combat the cyber threat to this country.
Today, we have a dangerously incomplete picture of the online war being waged against us, and it is costing Americans their time, money, and jobs. It is time for us to safeguard our digital frontier. This legislation is a necessary and vital step to do exactly that.
BREAK IN TRANSCRIPT
Mr. Chair, I thank the gentleman from Mississippi for his question and would say that I do not completely share your view of that clause. I assure you that incentivizing companies to do nothing with timely threat information is certainly not the intent of this provision, as the author of this bill.
On the contrary, I believe it is important that we provide companies with legal safe harbors to encourage sharing of cyber threat information and also believe that every company that participates in this information-sharing process, especially small- and medium-sized businesses, cannot be required to act upon every piece of cyber threat information they receive.
As such, I support looking for ways to clarify that point with you, Mr. Thompson. I commit to working with you as this bill moves forward to look for ways to refine the language to ensure that it is consistent with our shared policy goal of getting timely information into the hands of businesses so that they can protect their networks and their data.
BREAK IN TRANSCRIPT