Mr. President, I came to the floor to introduce the Cyber Security Act of 2012. I am here with Senator Susan Collins. I thank her for all the work we have done together in what has been a wonderfully…
Mr. President, I came to the floor to introduce the Cyber Security Act of 2012. I am here with Senator Susan Collins. I thank her for all the work we have done together in what has been a wonderfully bipartisan, nonpartisan relationship to deal with a very serious national problem. I am honored that we are joined in introducing this bill by the chairs of the two committees that have been most involved in questions of cyber security, chairman of the Commerce Committee, Senator Rockefeller, and the chair of the Intelligence Committee of the Senate, Senator Feinstein of California. We have also had the involvement of the chairs and others on the Foreign Relations Committee, Judiciary Committee, and Energy Committee. I am very proud this is a bill that Senators Collins and Rockefeller and Feinstein and I introduced today.
I wish to give particular thanks to the majority leader, Senator Reid, for his unflagging support, based on his personal concern about cyber defenses and based on classified briefings he received on this problem. He pushed us to work across party and committee lines to pull the bill together that we are introducing today.
It is interesting to note--since there has been a lot of commentary in the last 24 hours about President Obama's budget--that President Obama has recognized, in the most tangible terms, the danger that confronts us by recommending adding at least $300 million in the coming year to our cyber security effort.
Still, I know that while it is February 14, 2012, those of us who have worked on this problem fear that when it comes to protecting America from cyber attack, it may be September 10, 2001, all over again. The question is whether America will confront this grave threat to our security before it happens, before our enemies attack.
We are being bled of our intellectual property every day by cyber thieves. The consequences of their thievery are very real to America's economy, our prosperity, and indeed our capacity to create jobs and hold the ones we have.
Enemies probe the weaknesses in our critical national assets every day, waiting until the time is right, through cyber attack, to cripple our economy or attack, for instance, a city's electric grid with the touch of a key on the other side of the world.
The fact is our cyber defenses are not what they should be, but such as they are they are blinking red. Yet, again, I fear we will not be able to connect the dots to prevent a 9/11-type cyber attack on America before it happens. The aim of this bill is to make sure we don't scramble here in Congress after such an attack to do what we can and should do today.
Intellectual property worth billions of dollars has already been stolen, giving our international competitors access in the global marketplace without ever having to invest a dime in research.
The fact is that even the most sophisticated companies are being penetrated, and our adversaries are using information learned in one intrusion to plan the next more sophisticated one.
Last year, the computer security firm McAfee conducted a study of 70 specific instances of data theft, and they issued a report on those instances. They included 13 defense contractors, 6 industrial plants, and 8 American and Canadian Government networks. Based on that report, the former vice president of McAfee, Dmitri Alperovitch, issued this ominous warning:
I am convinced that every company in every conceivable
industry with significant size and valuable intellectual
property and trade secrets has been compromised--or will be
shortly--with the great majority of the victims rarely
discovering the intrusion or its impact.
In fact, I divide this entire set of Fortune Global 2000 firms into two categories: those that know they've been compromised and those that don't yet know.
These examples, of course, are deeply alarming, but in addition, lurking out in the ether are computer worms such as Stuxnet that can commandeer the computers that control heavy machinery and potentially allow an intruder to open and close key valves and switches in pipelines, refineries, factories, water and sewer systems, and electric plants in our country without detection by their operators.
Obviously, this capacity could be used by an enemy to attack our country and do damage not only comparable to 9/11 but far in excess of it. Depending on the target or targets, these kinds of cyber attacks could lead to terrible physical destruction, massive loss of life, massive evacuations, and, of course, widespread economic disruption.
Owners of these critical systems; that is, private sector owners-- and, remember, most of private infrastructure in America is privately owned and is what this bill is talking about--have sometimes told us we don't need to worry about the security of their systems because they are not connected to the Internet. But the reality today is that is simply not correct. The experts have told us that a truly air-gapped system, as they call it; that is, one not connected to the Internet--is as rare as a blizzard in the Caribbean. If it exists, our best cyber experts have yet to see it. And Stuxnet has shown us it doesn't matter if a system is air gapped, because one thumb drive plugged into a computer can lead to an infection that spreads.
If we don't act now to secure our computer network, sometime in the future--and I believe it will be in the near future--we will be forced to act in the middle of a mega cyber crisis or right after one that has had an enormous, perhaps catastrophic, effect on our country. That is why we introduced this bill, and that is why we look forward to the debate on it, and why we hope it will pass and be enacted before a cyber catastrophe occurs in America.
Let me briefly describe some of the important work this bill does. First, it ensures the computer systems--private systems--that control our most critical infrastructure that are currently not secure are made secure. Our bill defines critical infrastructure narrowly to include those systems that, if brought down, or commandeered in a cyber attack would lead to mass casualties, evacuations of major population centers, the collapse of financial markets, or degradation of our national security. This is critical infrastructure. After identifying the precise systems that meet the definition of high risk, the Secretary of Homeland Security would, under our legislation, then work with the private sector operators of those systems to develop cyber security performance requirements based on risk assessments of those sectors. The private sector owners would then have some flexibility to meet those performance requirements with hardware or software they choose so long as it achieves the required level of security.
The Department of Homeland Security will not be picking technological winners and losers, so there is nothing in this bill that would stifle innovation. In fact, I think quite the contrary. If a company can show it already has met high security standards, it will be exempt from these requirements. The bill focuses on securing that which is not secure today, not on putting new requirements on industries that are doing everything they should be doing to protect themselves and our national security.
Once these improved security systems come on line, I think many companies will want to apply them to noncritical systems that are not covered by this bill as a way to protect the privacy of their employees and customers, as well as giving these companies the chance to offer secure e-commerce services. But that will be up to each company.
This bill also seeks to make compliance easier, more rational for covered critical infrastructure operators by creating a more streamlined and efficient cyber organization within the Department of Homeland Security. And at each step in the process created by our bill, the Department of Homeland Security must work with existing Federal regulators and the private sector they regulate to ensure no rules or regulations are put in place that duplicate or conflict with existing requirements. If a company feels the designation of its networks as critical infrastructure is somehow wrong, it has the right to appeal that decision through a system that the law requires DHS to set up or they can go to Federal district court.
This bill also establishes mechanisms for information sharing between the private sector and the Federal Government and among the private sector operators themselves.
Senator Feinstein and her committee made a significant contribution to this part of our bill. This is important because computer security experts in the private and public sectors need to be able to share information, compare notes, in order to protect us against the evolving cyber threat.
Our proposal also creates appropriate security measures and oversight to protect privacy and preserve civil liberties. In fact, I was pleased to read recently that the American Civil Liberties Union said it had studied our bill and found it offers the greatest privacy protections of all the cyber security legislation that has been proposed.
I am going to jump forward a little so I can yield to my distinguished ranking member in a moment.
I have discussed some of the things the bill does, but I want to mention two it doesn't do.
One myth about this bill is that it contains a kill switch that would allow the President of the United States in an emergency to seize control of the Internet. There is nothing remotely like that in this bill. At one time we had considered language that would, in fact, have limited powers the President has under the Communications Act of 1934 to take over electronic communications in times of war. But that provision was so widely misunderstood or misrepresented that we dropped it rather than risk losing the chance to pass the rest of this urgently needed legislation.
I also want to make clear that nothing in this bill touches on any of the issues that quite recently have inflamed our consideration of the Stop Online Piracy Act or the Protect IP Act, known as PIPA. Many Members in the Chamber have, metaphorically speaking, scars that still show from that experience. No need to fear this bill. This bill does nothing to affect the day-to-day workings of the Internet. Internet piracy and copyright protections are important concerns in the digital age. We have to deal with that at some point, but they are simply not part of this bill.
One final thing I do want to deal with is a complaint from, among others, our Chamber of Commerce that we are ``rushing forward with legislation that has not been fully vetted.'' Not true. This bipartisan legislation has been 3 years in the making, and its outlines have not only been shared with stakeholders and the public but their input has helped shape this final version of the bill we are introducing today.
More than 20 hearings on cyber security have been held across seven different Senate committees, with dozens more held on questions related to cyber security. In fact, our own committee, since 2005, has held nine hearings on the subject and will hold another one
this Thursday where we will hear reactions to this bill.
I am very pleased to say that Senator Reid continues to be very committed to seeing us do everything we can to adopt legislation to protect our American cyber systems. I believe it is the leader's intent to bring up this bill in the next work period. I hope so. Because the truth is, time is not on our side. We are not adequately protected at this moment, and the capabilities of those who are attacking us for economic reasons or who prepare to attack us for strategic reasons grows larger and larger.
I do want to say we have a growing number of companies in the private sector--information technology, cyber security and other companies in critical infrastructure areas--that are coming to support this bill. Two I want to mention are SISCO and Oracle, which gives you some sense of the range of support for the bill.
Bottom line, I think this is a subject around which we should have a good healthy debate, an open amendment process, and a bipartisan agreement, because this is not at all about regulation, it is about our most fundamental national economic security and public safety.
With that, I yield the floor to my distinguished ranking member, Senator Collins.