BREAK IN TRANSCRIPT
Mr. COLLINS of Georgia. Mr. Speaker, I am pleased to bring this rule forward on behalf of the Rules Committee. It is a rule that respects the legislative process and reflects the responsibility of Congress to address a critical deficit in the infrastructure of our Nation.
This rule provides for consideration of both cybersecurity measures under a structured amendment process. As a result of a thorough and deliberative committee hearing yesterday evening, there are five amendments to H.R. 1560 and 11 amendments to H.R. 1731 that this body will have the opportunity to debate and ultimately vote for or against.
The bipartisan nature of these bills speaks to the critical need for this legislation. Both bills passed their respective committees with bipartisan support, and I am hopeful this rule will enjoy similar overwhelming support.
For each bill, amendments offered by Democrats exceeded those offered by Republicans. I would like to thank Chairman Nunes and also Chairman McCaul for their work, both within our conference and across the aisle, to ultimately bring forward two bills that reflect compromise, consistency, and a deep understanding of the dangers that cyber attacks pose every day.
If both bills are adopted, this rule combines the bills and sends them to the Senate as a package in an effort to work with the other Chamber, go to conference, and to produce a product that will be signed into law. This is a fair rule that respects this body, the importance of this issue, and the legislative process as a whole.
The world has changed greatly since this body last discussed cybersecurity. The ``Internet of Things'' has created unforeseen risks and exposed vulnerabilities and defects in the ability of companies to even simply talk to each other without fear of frivolous litigation.
Our enemy is adapting, growing bolder and more sophisticated. North Korea, Iran, Russia, and China seek to exploit and devastate our economic security as a nation and our data security as individuals through cyber attacks that we cannot adequately anticipate, respond, or even communicate about.
Foreign governments aren't the only ones who wish to do Americans harm. Terrorists and criminal enterprises have also recognized that American companies are crippled by the ambiguity in our law as it relates to sharing cyber threat information.
The cyber attack surface has expanded. Wearables, connected vehicles, and embedded devices have made it possible for cyber attacks to literally be driven into the parking lot or walked through doors.
The traditional ways of responding to cyber threats and recovering from them are not sufficient to safeguard the data privacy of Americans and the economic security of our Nation. The scope of these attacks and devastating damages are increasing as rapidly as the attackers are themselves.
These bills are not a magic pill. They will not render inoperable the scores of foreign countries and enterprises that want to see American exceptionalism brought to its knees; but they do give clear, positive legal authority to American companies to allow them to protect their own and to appropriately share cyber threats with other countries and, in certain cases, Federal agencies.
Let me be clear. These are not surveillance bills. These are not data collection bills. This is not the PATRIOT Act or FISA. This body will debate intelligence gathering, collecting, sharing, and using at some point in the future, but today is not that day.
I know those rightly concerned with government surveillance, like myself, would like to use this rule for that purpose and the underlying measures as a platform to debate that, but I urge them to refrain. We will have that debate.
Today's focus is on the perpetrating of the thousands of cyber threats American businesses face every single day. Let the attention be on North Korea. Let it be on Iran. Let it be on the countless enemies of the United States who want to destroy this Nation. For today, we speak with a united voice that they will fail.
We declare with one voice that American companies have the right to protect their own, to protect and defend their own networks, to share technical information with the appropriate agencies on a voluntary basis if they so choose.
I thank the Intelligence and Homeland Security Committees and their staff for their tireless work they have done to ensure that we can protect our economy, our infrastructure, and our private information.
I know detractors of the legislation may attempt to paint this rule and underlying measures in a different light, so let's allow the facts to speak for themselves.
These bills have three key components. First, they provide for completely voluntary participation by private companies in a program with positive legal authority. This program allows three kinds of sharing--private company to private company, government to private company, and private company to government--but this sharing of information is limited only to cyber threat indicators.
Second, they require the removal of all unrelated personal information. It is the technical cyber threat information that is being shared, zeros and ones. In fact, there is a requirement that both the government and the private entity remove personally identifiable information when the information is shared and also when it is received.
Third, the legislation expressly prohibits the cyber threat indicators from being used for surveillance.
These bills will benefit all Americans by helping businesses better protect sensitive information. Attacks against our network often seek to steal Americans' personal information. This can include credit and debit card information, medical records, or even Social Security numbers.
Many of the recent attacks that we have all read about in the news were specifically aimed at stealing the personal information of Americans. Cyber attackers are also increasingly targeting small businesses. In fact, in 2014, 60 percent of all targeted attacks struck at small- and medium-sized businesses.
The underlying legislation will also help protect American jobs by protecting the intellectual property of American businesses. It is estimated that cyber attacks cost Americans roughly 500,000 jobs a year. Foreign companies often use cyber attacks to target the trade secrets of U.S. companies and then use the information to produce their own competing product.
The threat is real, both to our economic security as a nation and our personal information as individuals. If we fail to act and pass this rule and the underlying bills, our Nation and our personal privacy is more at risk than ever before.
BREAK IN TRANSCRIPT
Mr. COLLINS of Georgia. Mr. Speaker, again, I want to focus this debate. There are many things my friend from Colorado brought up that will be debated, that are coming up, I think, as early, frankly, as tomorrow in some committees and will be debated on this floor. This is about sharing. This is about information protection.
BREAK IN TRANSCRIPT
Mr. COLLINS of Georgia. I want to thank my colleague from Georgia who sits on the Homeland Security Committee for his passion and his commitment to addressing these critical defects in the laws governing this voluntary sharing of cyber threat information. The legislation before us today is good policy reflective of the hard work of the committees on which you sit, Homeland Security and the Intelligence Committee, as well as input from a vast array of stakeholders. It is important to know that the legislation is supported by every sector of the economy.
As my friend so eloquently noted, the legislative process will rightly continue after these bills are considered by the full House this week and for years to come as we revisit and reassess the needs of Americans' privacy and also the laws governing cybersecurity.
Mr. Speaker, I agree with my friend that if there is a conference committee on this bill, we should encourage them to seek additional clarification language as needed to ensure that companies are appropriately incentivized to share cyber threat information.
I just want to say personally that I appreciate all the hard work that you have done on this issue bringing this forward and continuing to work for not only the companies in Georgia but across this Nation who depend on a safe and secure cyber network.
BREAK IN TRANSCRIPT
Mr. COLLINS of Georgia. Mr. Speaker, I yield myself such time as I may consume.
As we move forward, I think one of the things--and there are many things that are going to be discussed, and I encourage all Members to vote for this rule. As we move into general debate, there will be a lot of discussion that talks about what we are moving forward; but, also, I want to bring forward that we are--as is seemingly not discussed bringing forth, there are amendments being brought forth on both of these bills.
There also were 20-something amendments in Homeland Security; there was also an amendment in Intelligence. These are vetted bills. This is a proper role with what we are doing in Congress in bringing these to the floor.
Are there times that someone may want others? Yes; but, at this point, we are going to have that debate here on the floor. That is why voting for this rule and moving this forward is the proper thing to do.
Before we also move back from this, I want to talk about this need and why we are here even to start with. Most Americans recognize and understand that the growing attacks against our cyber networks and critical infrastructure and our laws fail to provide proper legal authority for information regarding cyber threats to be shared.
In fact, when I am back home in the Ninth District of Georgia discussing this, most people don't realize there is this barrier, and especially everything that is going on, they don't understand why some of these impediments were put into place that keeps companies from protecting their own, but also protecting their own personal information.
One of the things that is missing in this debate is the discussion of what has actually happened and the personal information that is shared by these hackers who are getting into our system.
Some of the latest attacks perpetrated by North Korea and other criminal enterprises on Sony Pictures and health insurance providers Anthem and Blue Cross Blue Shield speak to the type of attacks that occur on a daily basis that target the backbone of American business and the privacy of America's most sensitive data.
As we look to constrain this, as we look to put in proper safeguards, we have to realize that doing nothing exposes more and more of our American citizens to personal information being shared. If we don't believe it, just read the headlines from Sony, Anthem, and these others that have come out recently.
According to the Department of Homeland Security, in 2014 alone, they received almost 100,000 cyber incident reports and detected 64,000 cyber vulnerabilities, and these numbers are just based on information given to DHS and does not reflect the full scope of the attacks on our Nation.
When we look at this and we talk about the personal information, the FBI Director James Comey said:
There are two kinds of big companies in the United States. There are those who have been hacked ..... and those who don't know they have been hacked.
A recent survey by the Ponemon Institute showed an average cost of a cyber crime for U.S. retail stores more than doubled from 2013 to an annual average of 8.6 million per company in 2014.
The annual average cost for a company of a successful cyber attack in 2014 increased to 20.8 million in financial services, 14.5 million in the technology sector, and 12.7 million in the communications industry.
The scope of many attacks are not fully known. For example, in July of 2014, the U.S. Computer Emergency Readiness Team issued an advisory that more than 1,000 U.S. businesses have been affected by the Backoff malware, which targets point-of-sale systems used by most retail industries. These attacks targeted administrative and customer data and, in many cases, financial data. Most companies encounter multiple cyber attacks every day, many unknown to the public and many unknown to the companies themselves even.
Again, as we look back over the attacks of just the past year, Target announced an additional 70 million individual contact information was taken during the December 2013 breach in which 40 million customers' credit and debit information was stolen.
Between May 2013 and January 2014, the payment cards of 2.6 million Michaels customers were affected. Attackers targeted the Michaels POS system to gain access to their systems.
The email service Yahoo! Mail was reportedly hacked in for 273 million users, although the specific number of accounts affected was not released.
For 2 weeks, AT&T was hacked from the inside by personnel who accessed user information, including Social Security information.
Foreign nationals from China have been indicted for computer hacking and economic espionage. We have seen these attacks all over the board.
Looking at this, the real issue that comes to mind is if we sit back and are not productive and not proactive as the Intelligence Committee and the Homeland Security Committee have been here, we are putting in danger more personal information being exposed in ways that no American needs to have their personal information exposed and are being targeted in the process.
This is good legislation that needs to stay on the floor, and that is why we are here today to support this rule and to look forward to that debate that has already happened and will continue to happen.
I appreciate the discussion we have had over the past hour. Although we may have some differences, our unity should be clear against the cyber attacks and our resolve to prevent them and show their success is strong.
This rule provides for ample debate on the floor, the opportunity to debate and to vote on 16 amendments, and a smooth and deliberative process for sending one bill to the Senate. These bills will help protect American consumers, jobs, and small businesses.
Allowing companies, again, to voluntarily share cyber threat indicators with other companies and government agencies will help bring awareness to new threats and vulnerabilities.
If businesses can learn about a new threat from another business or from the government before they are targeted themselves, they can better act to protect their customers' personal information from a similar attack.
I would like to thank Intel, Homeland Security, Judiciary, and Rules Committee members and staff for the thoughtful and involved processes that have brought us to this point.
I urge my colleagues to support the rule and these two cybersecurity bills.
BREAK IN TRANSCRIPT
Mr. COLLINS of Georgia. Mr. Speaker, House Report 114-88, the report to accompany H. Res. 212, the special rule governing consideration of H.R. 1731, does not reflect a request by Mr. Mulvaney of South Carolina to add Mr. Thompson of Mississippi as a cosponsor of his amendment, number 8 printed in part B of the report.
BREAK IN TRANSCRIPT