1 | 1 | | I |
---|
2 | 2 | | 119THCONGRESS |
---|
3 | 3 | | 1 |
---|
4 | 4 | | STSESSION H. R. 807 |
---|
5 | 5 | | To direct the Secretary of the Treasury to submit a report on coordination |
---|
6 | 6 | | in the public and private sectors in responding to ransomware attacks |
---|
7 | 7 | | on financial institutions, and for other purposes. |
---|
8 | 8 | | IN THE HOUSE OF REPRESENTATIVES |
---|
9 | 9 | | JANUARY28, 2025 |
---|
10 | 10 | | Mr. N |
---|
11 | 11 | | UNNof Iowa (for himself and Mr. GOTTHEIMER) introduced the |
---|
12 | 12 | | following bill; which was referred to the Committee on Financial Services |
---|
13 | 13 | | A BILL |
---|
14 | 14 | | To direct the Secretary of the Treasury to submit a report |
---|
15 | 15 | | on coordination in the public and private sectors in re- |
---|
16 | 16 | | sponding to ransomware attacks on financial institutions, |
---|
17 | 17 | | and for other purposes. |
---|
18 | 18 | | Be it enacted by the Senate and House of Representa-1 |
---|
19 | 19 | | tives of the United States of America in Congress assembled, 2 |
---|
20 | 20 | | SECTION 1. SHORT TITLE. 3 |
---|
21 | 21 | | This Act may be cited as the ‘‘Public and Private 4 |
---|
22 | 22 | | Sector Ransomware Response Coordination Act of 2025’’. 5 |
---|
23 | 23 | | VerDate Sep 11 2014 22:46 Feb 24, 2025 Jkt 059200 PO 00000 Frm 00001 Fmt 6652 Sfmt 6201 E:\BILLS\H807.IH H807 |
---|
24 | 24 | | kjohnson on DSK7ZCZBW3PROD with $$_JOB 2 |
---|
25 | 25 | | •HR 807 IH |
---|
26 | 26 | | SEC. 2. REPORT ON COORDINATION IN THE PUBLIC AND 1 |
---|
27 | 27 | | PRIVATE SECTORS IN RESPONDING TO 2 |
---|
28 | 28 | | RANSOMWARE ATTACKS ON FINANCIAL IN-3 |
---|
29 | 29 | | STITUTIONS. 4 |
---|
30 | 30 | | (a) I |
---|
31 | 31 | | NGENERAL.—Not later than one year after the 5 |
---|
32 | 32 | | date of the enactment of this section, the Secretary of the 6 |
---|
33 | 33 | | Treasury shall submit to the appropriate congressional 7 |
---|
34 | 34 | | committees a report that describes the following: 8 |
---|
35 | 35 | | (1) The current level of coordination and col-9 |
---|
36 | 36 | | laboration between the public and private sectors, in-10 |
---|
37 | 37 | | cluding entities in the public and private sectors that 11 |
---|
38 | 38 | | manage cybersecurity, in response to, and for the 12 |
---|
39 | 39 | | prevention of, a ransomware attack on a financial 13 |
---|
40 | 40 | | institution. 14 |
---|
41 | 41 | | (2) The coordination among relevant govern-15 |
---|
42 | 42 | | mental agencies in response to, and for the preven-16 |
---|
43 | 43 | | tion of, a ransomware attack on a financial institu-17 |
---|
44 | 44 | | tion. 18 |
---|
45 | 45 | | (3) Whether relevant governmental agencies 19 |
---|
46 | 46 | | have timely access to relevant information reported 20 |
---|
47 | 47 | | by a financial institution following a ransomware at-21 |
---|
48 | 48 | | tack on the financial institution. 22 |
---|
49 | 49 | | (4) The utility of such information to any rel-23 |
---|
50 | 50 | | evant governmental agency in the prevention or in-24 |
---|
51 | 51 | | vestigation of a ransomware attack on a financial in-25 |
---|
52 | 52 | | VerDate Sep 11 2014 22:46 Feb 24, 2025 Jkt 059200 PO 00000 Frm 00002 Fmt 6652 Sfmt 6201 E:\BILLS\H807.IH H807 |
---|
53 | 53 | | kjohnson on DSK7ZCZBW3PROD with $$_JOB 3 |
---|
54 | 54 | | •HR 807 IH |
---|
55 | 55 | | stitution, or the prosecution of a person responsible 1 |
---|
56 | 56 | | for such attack. 2 |
---|
57 | 57 | | (5) An analysis of reporting requirements appli-3 |
---|
58 | 58 | | cable to a financial institution with respect to a 4 |
---|
59 | 59 | | ransomware attack in relation to the utility to any 5 |
---|
60 | 60 | | relevant governmental agency of the reported infor-6 |
---|
61 | 61 | | mation in the prevention or investigation of a 7 |
---|
62 | 62 | | ransomware attack on a financial institution, or the 8 |
---|
63 | 63 | | prosecution of a person responsible for such attack. 9 |
---|
64 | 64 | | (6) Whether further legislation is required to 10 |
---|
65 | 65 | | increase the utility and timely access of such infor-11 |
---|
66 | 66 | | mation to any relevant governmental agency fol-12 |
---|
67 | 67 | | lowing a ransomware attack on a financial institu-13 |
---|
68 | 68 | | tion. 14 |
---|
69 | 69 | | (7) Any recommended policy initiatives to bol-15 |
---|
70 | 70 | | ster public-private partnerships, increase incident re-16 |
---|
71 | 71 | | port sharing, and decrease incident response time. 17 |
---|
72 | 72 | | (8) The extent to which, and reasons that, fi-18 |
---|
73 | 73 | | nancial institutions withhold or delay reporting to 19 |
---|
74 | 74 | | relevant governmental agencies information about a 20 |
---|
75 | 75 | | ransomware attack. 21 |
---|
76 | 76 | | (9) Any feedback on the contents of the report 22 |
---|
77 | 77 | | received from cybersecurity and ransomware re-23 |
---|
78 | 78 | | sponse entities that provide services to financial in-24 |
---|
79 | 79 | | stitutions. 25 |
---|
80 | 80 | | VerDate Sep 11 2014 22:46 Feb 24, 2025 Jkt 059200 PO 00000 Frm 00003 Fmt 6652 Sfmt 6201 E:\BILLS\H807.IH H807 |
---|
81 | 81 | | kjohnson on DSK7ZCZBW3PROD with $$_JOB 4 |
---|
82 | 82 | | •HR 807 IH |
---|
83 | 83 | | (b) FORM OFREPORT.—The report described in sub-1 |
---|
84 | 84 | | section (a) shall be submitted in unclassified form, but 2 |
---|
85 | 85 | | may include a classified annex. 3 |
---|
86 | 86 | | (c) B |
---|
87 | 87 | | RIEFING.—Not later than 15 months after the 4 |
---|
88 | 88 | | date of the enactment of this section, the Secretary of the 5 |
---|
89 | 89 | | Treasury shall brief the appropriate congressional commit-6 |
---|
90 | 90 | | tees on the findings of the report described in subsection 7 |
---|
91 | 91 | | (a). 8 |
---|
92 | 92 | | (d) D |
---|
93 | 93 | | EFINITIONS.—In this section: 9 |
---|
94 | 94 | | (1) A |
---|
95 | 95 | | PPROPRIATE CONGRESSIONAL COMMIT -10 |
---|
96 | 96 | | TEES.—The term ‘‘appropriate congressional com-11 |
---|
97 | 97 | | mittees’’ means— 12 |
---|
98 | 98 | | (A) the Committee on Financial Services 13 |
---|
99 | 99 | | of the House of Representatives; 14 |
---|
100 | 100 | | (B) the Permanent Select Committee on 15 |
---|
101 | 101 | | Intelligence of the House of Representatives; 16 |
---|
102 | 102 | | (C) the Committee on Banking, Housing, 17 |
---|
103 | 103 | | and Urban Affairs of the Senate; and 18 |
---|
104 | 104 | | (D) the Select Committee on Intelligence 19 |
---|
105 | 105 | | of the Senate. 20 |
---|
106 | 106 | | (2) C |
---|
107 | 107 | | YBERSECURITY AND RANSOMWARE INCI -21 |
---|
108 | 108 | | DENT RESPONSE ENTITY .—The term ‘‘cybersecurity 22 |
---|
109 | 109 | | and ransomware incident response entity’’ means an 23 |
---|
110 | 110 | | entity that provides incident responses, managed 24 |
---|
111 | 111 | | services, or advisory services that— 25 |
---|
112 | 112 | | VerDate Sep 11 2014 22:46 Feb 24, 2025 Jkt 059200 PO 00000 Frm 00004 Fmt 6652 Sfmt 6201 E:\BILLS\H807.IH H807 |
---|
113 | 113 | | kjohnson on DSK7ZCZBW3PROD with $$_JOB 5 |
---|
114 | 114 | | •HR 807 IH |
---|
115 | 115 | | (A) supports investigation and risk man-1 |
---|
116 | 116 | | agement related to ransomware attacks in the 2 |
---|
117 | 117 | | public and private sectors; 3 |
---|
118 | 118 | | (B) strengthens cybersecurity technology 4 |
---|
119 | 119 | | in the financial sector; and 5 |
---|
120 | 120 | | (C) reduces overall cyber risk in the finan-6 |
---|
121 | 121 | | cial sector by assessing the security posture of 7 |
---|
122 | 122 | | a financial institution, assisting a financial in-8 |
---|
123 | 123 | | stitution with regulatory compliance, and pro-9 |
---|
124 | 124 | | viding recommendations to a financial institu-10 |
---|
125 | 125 | | tion for recovery after a ransomware attack and 11 |
---|
126 | 126 | | prevention of any future attacks. 12 |
---|
127 | 127 | | (3) F |
---|
128 | 128 | | INANCIAL INSTITUTION.—The term ‘‘fi-13 |
---|
129 | 129 | | nancial institution’’ has the meaning given that term 14 |
---|
130 | 130 | | under section 5312(a) of title 31, United States 15 |
---|
131 | 131 | | Code. 16 |
---|
132 | 132 | | Æ |
---|
133 | 133 | | VerDate Sep 11 2014 22:46 Feb 24, 2025 Jkt 059200 PO 00000 Frm 00005 Fmt 6652 Sfmt 6301 E:\BILLS\H807.IH H807 |
---|
134 | 134 | | kjohnson on DSK7ZCZBW3PROD with $$_JOB |
---|