BREAK IN TRANSCRIPT
Mr. SCHIFF. Mr. Chairman, I yield myself such time as I may consume.
I rise in support of H.R. 1560, the Protecting Cyber Networks Act. At some point, we need to stop just hearing about cyber attacks that steal our most valuable trade secrets and our most private information and actually do something to stop it. At some point, we need to stop talking about the next Sony, the next Anthem, the next Target, the next JPMorgan Chase, and the next State Department hack and actually pass a bill that will help ensure that there will be no next cyber attack.
A few weeks back, the House Intelligence Committee held an open hearing on the cyber threat to America's private sector. We heard from our witnesses that their businesses are cyber attacked billions of times a day--not thousands, not millions, but billions.
The threat to our economy, our jobs, and our privacy from not acting is massive, and it is certain. We see it happening all around us. So we must act now. That is why I am proud to support this bill.
The Protecting Cyber Networks Act provides for voluntary information sharing of cyber threats between and among the private and public sectors. It does what no executive order can do: it incentivizes cyber threat information sharing by providing limited liability protection. Now companies can pool their resources and say to one another: I found this malicious code or this virus in my system; you need to protect yourself against it as well. And now the government can better warn companies of an impending cyber attack, just as it can for an approaching hurricane or an impending flu outbreak.
But let me be very clear about this: to get the liability protection, a company that chooses to participate must remove any unrelated private information prior to sharing. This is something privacy advocates and I called for when previous information-sharing bills came before the House.
Unlike prior bills, this measure requires the private sector to strip out private information. In fact, the bill has two, not one, privacy scrubs. The first happens when a company shares with another company or the Federal Government, and the second happens when the Federal Government shares the information further. This bill even holds the government directly liable if it doesn't do what it is required to do.
Second, to get the liability protection, a private company wishing to share with the Federal Government must go through a civilian portal. To be clear: a company can't go directly to the DOD or NSA and get the bill's liability protection.
The lack of a civilian portal in previous bills was another key privacy group criticism, and this bill has resolved that issue, too. In fact, of the five main criticisms of prior cyber bills, this bill has resolved each of them. It has private sector privacy stripping of information. It has a civilian portal. It also has narrow restrictions on what the government can use that shared cyber threat information for. Gone is a national security use provision. Gone is a vague terrorism use provision. And what is left is only the most narrow of uses: to prevent cyber attacks, to prevent the loss of life, to prevent serious harm to a child, and to prevent other serious felonies.
Gone, too, is any question of whether offensive countermeasures or hack back is authorized. This bill makes clear that you cannot take anything but defensive actions to protect your networks and data.
And, lest anyone be confused, Mr. Chairman, this bill makes clear in black-and-white legislative text that nothing in the bill authorizes government surveillance in this act--nothing.
What this bill does is authorize voluntary, private sector sharing of cyber threat information, and it allows the government to be able to quickly share threat information with the private sector, just as we need a CDC to put out timely warnings and advice on how to counteract this year's flu strain or how to prevent a local disease from becoming an epidemic. In addition, the bill requires strong privacy and civil liberties guidelines and intense reporting requirements.
The bill before us today strikes the right balance between securing our networks and protecting our privacy, and addresses the privacy concerns that I, among others, raised last session. However, there are still some improvements that are yet to be made as the bill moves forward. In particular, we need to further clarify that our liability protection only extends to those who act, or fail to act, reasonably.
Before closing, I want to thank Chairman Nunes for his leadership and for working so hard on this bill. It has been a great pleasure to work with you, Mr. Chairman. I am grateful for all of the hours, energy, and talent that you and your staff have put in to making this bill successful. I want to thank all the members of HPSCI as well as the Judiciary Committee and the Homeland Security Committee for working together on this. We had many differences in opinion, and we still have some, but we kept our eyes firmly on what is best for the American people as a whole. With that, we found ways to come together and produce a stronger bill.
Mr. Chairman, I hope we can continue to work together as well with the Senate and with the White House and all the stakeholders to produce an even stronger bill for the President to sign into law.
I also want to acknowledge the leadership of our predecessors, Dutch Ruppersberger and former HPSCI Chairman Mike Rogers. We have come this far in part because of the good work they did in the last couple of sessions. I also want to thank all those who came in to speak with us and provide their input in making this a better bill.
Every day we delay more privacy is stolen, more jobs are lost, and more economic harm is done. Let's stop sitting by and watching all of this happen. Let's do something. Let's do what this administration has urged us to do and pass this bill. Let's do it now. I reserve the balance of my time.
BREAK IN TRANSCRIPT
Mr. SCHIFF. Madam Chair, I yield myself such time as I may consume.
Every moment we wait equals another Social Security number stolen, another checking account hacked, another invaluable trade secret pilfered, and another job lost. This is certain. We see it every day.
Many of us and our constituents, both individuals and businesses, have been the victim of a cyber crime. Whether it is identity theft, the hacking of our email or Facebook accounts, or the loss of our privacy, when our health insurance company is breached, we have our privacy invaded.
All of us are certainly paying higher fees to compensate for the billions of dollars our businesses lose to cyber hacking and to the costs of preventing future cyber attacks. The problem is only getting worse. As our cars, our phones, our home security systems, our Internet banking, our electronic health records, our web-based baby monitors all get smarter, they also get more vulnerable.
This isn't speculation. This is happening today. It is happening right now. On the time that we have been on the floor discussing this cyber bill, billions of additional hacking attempts have been made.
Here, we have the opportunity to help stop this scourge of cyber hacking. We need to encourage cyber threat information sharing by passing the Protecting Cyber Networks Act today and then not resting until it improves on its way to the President's desk for signature.
I urge my colleagues to vote for this important measure. It is a bill that will help protect America's most valuable and private information, while itself protecting privacy and civil liberties to a degree far in advance of where prior legislation has gone. I and my colleagues have made sure of that, and we will continue to do so as the bill advances.
BREAK IN TRANSCRIPT
Mr. SCHIFF. Madam Chair, the manager's amendment makes mostly technical edits to the bill which advanced out of the Intelligence Committee unanimously. These strong edits came from our close and continuing consultations with outside groups and with the White House.
There is still work that remains to be done. In particular, we are going to work, as the bill moves forward, on the liability section. In order to benefit from the liability protection under the current language, it is necessary for companies to strictly comply with the act, which means sharing information only for a cybersecurity purpose and taking reasonable efforts to remove private information before sharing it.
I would support making further changes to the bill to make this requirement even more clear. In particular, I think it would be advantageous to strike what is, in my view, an unnecessary section on the rule of construction pertaining to willful misconduct.
Striking the rule of construction will help further clarify the intent of the bill, which is that liability protection is only available if a company or other non-Federal entity shares cyber threat information, for a cybersecurity purpose, and only after it takes reasonable steps to remove private information not directly related to the cybersecurity threat.
That is the intention of the bill, and I think striking that section will make it more clear. If a company acts unreasonably--let alone recklessly or willfully--in following these requirements, it does not get liability protection, nor should it.
That is the right result, and we have to be careful not to create any confusion about there being any immunity for people or for companies acting willfully, recklessly, or even unreasonably in disregarding private information or the requirement that it be extricated.
The manager's amendment makes positive technical changes. There are further changes that I would like to see as the bill moves forward. Confusion in any section of the bill, particularly as it pertains to liability, means litigation, and litigation means costs, so I think there is further work for us to do to make it even more clear.
In sum, I support the technical and substantive changes made in the manager's amendment, and I urge my colleagues to do the same. I join the chairman in urging support for the manager's amendment.
BREAK IN TRANSCRIPT
Mr. SCHIFF. I thank the gentleman, my colleague, for yielding.
Madam Chair, for a large business, a cyber attack can be costly and damaging. For a small business, a cyber attack can be fatal, wiping out a family's dream or a lifetime of work in a few clicks of a mouse.
Small businesses and small financial institutions also don't have the large legal shops that are sometimes necessary to keep up with the latest changes or regulations coming from Washington.
That is why I am so pleased that my California colleague offered this important amendment. While I don't expect that any sharing mechanism will ultimately be costly to maintain or to access, there will be some costs, especially in the early stages of implementation, and there will be some new procedures to navigate.
This amendment will help put the reach and authority of the Small Business Administration in the service of cybersecurity by having the agency assist in the rollout of cyber threat information sharing.
It is an important addition to the bill. I thank the gentleman for raising the issue, and I urge my colleagues to support it.
BREAK IN TRANSCRIPT
Mr. SCHIFF. I thank the gentleman for yielding.
Madam Chair, this is Mr. Carson's first year on the committee, and I appreciate his dedicated service and the interest he has taken in oversight of the intelligence community. He brings a background in law enforcement, which is a very welcome addition to our committee, and joins other colleagues with a very similar background.
He has worked closely with us to make privacy improvements throughout the process. I support his efforts here again to make a good bill even better. Mr. Carson's amendment would include a requirement to make sure the critical dual privacy scrub is working the way it should. This is very important. It is at the core of our bill and at the core of our efforts to protect privacy. So we must monitor how these requirements are working and support transparent reporting to make sure that they are working as intended.
I support the amendment and urge my colleagues to do the same.
BREAK IN TRANSCRIPT
Mr. SCHIFF. Madam Chair, I thank the gentlewoman from Texas and the gentleman from Colorado for their amendment, and I am happy to support it.
We create a lot of law in this body, and it is absolutely necessary that we establish reporting mechanisms that allow us to measure the effectiveness of the work that we do here. This is an amendment that will do just that.
By requiring regular reports on the operation of the sharing mechanism that we are creating today, we can determine whether it is working as intended or whether it needs to be tweaked or changed to be more effective. We must always ensure that the government is fulfilling its obligation under this bill to remove personal information.
Again, I want to thank Sheila Jackson Lee, as well as the gentleman from Colorado, for their efforts. I support the amendment.
BREAK IN TRANSCRIPT