BREAK IN TRANSCRIPT
Mr. THOMPSON of Mississippi. Mr. Chairman, I yield myself such time as I may consume.
I rise in support of H.R. 1731, the National Cybersecurity Protection Advancement Act of 2015.
Mr. Chairman, every day U.S. networks face hundreds of millions of cyber hacking attempts and attacks. Many of these attacks target large corporations and negatively impact consumers. They are launched by common hackers as well as nation-states. As the Sony attack last year demonstrated, they have a great potential for harm and put our economy and homeland security at risk.
Last week, it was reported that attacks against SCADA industrial control systems rose 100 percent between 2013 and 2014. Given that SCADA systems are essential to running our power plants, factories, and refineries, this is a very troubling trend.
Just yesterday, we learned about an advanced persistent threat that has targeted high-profile individuals at the White House and State Department since last year. According to an industry expert, this cyber threat--nicknamed CozyDuke--includes malware, information-stealing programs, and antivirus back doors that bear the hallmarks of Russian cyber espionage tools.
Mr. Chairman, cyber terrorists and cyber criminals are constantly innovating. Their success is dependent on their victims not being vigilant and protecting their systems. Cyber terrorists and cyber criminals exploit bad practices, like opening attachments and clicking links from unknown senders. That is why I am pleased that H.R. 1731 includes a provision authored by Representative Watson Coleman to authorize a national cyber public awareness campaign to promote greater cyber hygiene.
Another key element of cybersecurity is, of course, information sharing about cyber threats. We have seen that when companies come forward and share their knowledge about imminent cyber threats, timely actions can be taken to prevent damage to vital IT networks. Thus, cybersecurity is one of those places where the old adage ``knowledge is power'' applies.
That is why I am pleased H.R. 1731 authorizes private companies to voluntarily share timely cyber threat information and malware with DHS or other impacted companies. Under H.R. 1731, companies may voluntarily choose to share threat information to prevent future attacks to other systems.
I am also pleased that the bill authorizes companies to monitor their own IT networks to identify penetrations and take steps to protect their networks from cyber threats. H.R. 1731 builds on bipartisan legislation enacted last year that authorized the Department of Homeland Security's National Cybersecurity and Communications Integration Center, commonly referred to as NCCIC.
H.R. 1731 was unanimously approved by the committee last week and represents months of outreach to a diverse array of stakeholders from the private sector and the privacy community. Importantly, H.R. 1731 requires participating companies to make reasonable efforts prior to sharing to scrub the data to remove information that could identify a person when that person is not believed to be related to the threat.
H.R. 1731 also directs DHS to scrub the data it receives and add an additional layer of privacy protection. Additionally, it requires the NCCIC to have strong procedures for protecting privacy, and calls for robust oversight by the Department's chief privacy officer, its chief civil rights and civil liberties officer, and inspector general, and the Privacy and Civil Liberties Oversight Board.
I am a cosponsor of H.R. 1731, but as the White House observed earlier this week, improvements are needed to ensure that its liability protections are appropriately targeted. In its current form, it would potentially protect companies that are negligent in how they carry out authorized activities under the act.
Mr. Chairman, before reserving the balance of my time, I wish to engage in a colloquy with the gentleman from Texas (Mr. McCaul) regarding the liability protection provisions of H.R. 1731.
At the outset, I would like to express my appreciation for the gentleman's willingness to work with me and the other Democrats on the committee to develop this bipartisan legislation. We have a shared goal of bolstering cybersecurity and improving the quality of information that the private sector receives about timely cyber threats so that they can act to protect their networks and the valuable data stored on them.
Therefore, it is concerning that the liability protection provision appears to undermine this shared goal insofar as it includes language that on its face incentivizes companies to do nothing about actionable cyber information. Specifically, I am speaking of the language on page 36, line 18, that extends liability protections to a company that fails to act on timely threat information provided by DHS or another impacted company.
I would ask the gentleman from Texas to work with me to clarify the language as it moves through the legislative process to underscore that it is not Congress' intent to promote inaction by companies who have timely threat information.
BREAK IN TRANSCRIPT