Madam Speaker, I thank the gentlewoman from New York for her leadership, and I thank the ranking member of the full committee and the chair of the full committee for bringing these matters to the…
Madam Speaker, I thank the gentlewoman from New York for her leadership, and I thank the ranking member of the full committee and the chair of the full committee for bringing these matters to the attention of the Nation.
Madam Speaker, I rise in support of my bill, H.R. 2980, the Cybersecurity Vulnerability Remediation Act, which authorizes the Department of Homeland Security to take actions to counter cybersecurity vulnerabilities in our Nation's critical infrastructure.
Interestingly enough, when we introduced this bill some years ago, we called it the zero-day bill, which was to presuppose what would happen when everything collapsed. When we introduced it, it was before the Colonial Pipeline, it was before the Solaris attack, it was before knowing about the gangs in Russia, cyber gangs that proliferate before the activity of China.
I thank Chairman Thompson and Ranking Member Katko for their leadership in putting the security of our Nation's cyber access first, whether they are computing resources used in voting technology or industrial control systems that support delivery of electricity, oil, and gas, or management of transportation systems that are vital to our Nation's economic health.
The Cybersecurity Vulnerability Remediation Act was introduced, as I said, and passed the House during the 115th and 116th Congresses and has been updated again in the 117th Congress to meet the ever-evolving nature of cyber threats faced by Federal and private sector information systems and our Nation's critical infrastructure.
As I said before, it will be very important that the other body seriously considers the cyber threats against this Nation. This bill goes significantly further than the first cybersecurity vulnerability act that I introduced in the 115th Congress to address the instance of zero-day events that can lead to catastrophic cybersecurity failures of information and computing systems.
It is estimated that 85 percent of critical infrastructure is owned by the private sector, and for far too long this fact has hampered efforts to establish stronger requirements for cybersecurity by owners and operators.
Private sector critical infrastructure failure due to a cyberattack is no longer a private matter when it can have massive impacts on the public, such as disruption of gasoline flowing to filling stations, which we saw recently.
My bill, the Cybersecurity Vulnerability Remediation Act, will expand
the definition of security vulnerability to include cybersecurity vulnerability; add sharing mitigation protocols to counter cybersecurity vulnerabilities; establish protocols to counter cybersecurity vulnerabilities involving information system and industrial control systems, which will include vulnerabilities related to software or hardware that is no longer supported by a vendor; direct the undersecretary for DHS Office of Science and Technology to stand up a competition to find solutions to known cybersecurity vulnerabilities; provide greater transparency on how the Department of Homeland Security CISA is coordinating cybersecurity vulnerability disclosures through the sharing of actionable protocols to mitigate cybersecurity vulnerabilities with information systems and industrial control systems owners and operators.
H.R. 2980 bolsters the efforts to engage critical infrastructure owners and operators in communicating cybersecurity threats and lays the foundation for greater transparency on the real threats posed by cyberterrorists to private and government sector critical infrastructure and information systems, which impact the people of this Nation.
This legislation allows the science and technology director, in consultation with CISA, to establish an incentive-based program that allows industry, individuals, academia, and others to compete in identifying remediation solutions for cybersecurity vulnerabilities to information systems and industrial control systems, including supervisory control and data acquisition systems.
This bill, when it becomes law, will put our Nation's best minds to work on closing the vulnerabilities that cyber thieves and terrorists use to access, disrupt, corrupt, or take control of critical infrastructure information systems.
In addition to these changes, the bill requires a report to Congress that may contain a classified annex.
The report will provide information on how DHS coordinates cybersecurity vulnerability disclosures and disseminates actionable protocols to mitigate cybersecurity vulnerabilities involving information systems and industrial systems.
Congress needs to know how prevalent and persistent cybersecurity threats targeting critical infrastructure and information systems might be, especially if those threats result in a payment of ransom. They need to know about a payment of ransom.
Paying a ransom for ransomware emboldens and encourages bad cyber actors and places everyone at greater risk for the financial and societal costs of increases in threats as others seek payouts.
Madam Speaker, as long as there is silence about cyberattacks like ransomware, the criminals and terrorists will remain out of reach and continue to feel safe and emboldened in carrying out these attacks, often from the soil of our enemies or peer competitors.
I applaud and thank the Biden administration for its quick action in responding to the attack against Colonial Pipeline, but it did shut down the whole East Coast, and he did it by an executive order.
Today, our Nation is in a cybersecurity crisis. The attacks against Federal, State, local, territorial, and Tribal Governments, as well as threats posed to private information systems and critical information systems make this bill necessary.
So I am hoping, along with those who have been attacked, like the Metropolitan Police Department, the medical system in Houston--the gang known as the Babuk group released thousands of Metropolitan Police sensitive documents, and it goes on and on.
Madam Speaker, I include in the Record four articles regarding this issue.
[From the Forbes Magazine, July 20, 2021]
Turning Up The Heat: A Ransomware Attack On Critical Infrastructure Is
a Nightmare Scenario
(By Richard Tracy, Forbes Councils Member)
Ransomware attacks in 2020 were up more than 150% compared
to the previous year, while ransomware payments were up over
300%.
Over the past six months, we've seen a number of ransomware
attacks against critical infrastructure--from a water
treatment facility to a gas pipeline and multiple food
distribution companies--all of which present clear and
present danger to society. The impact was so dire--with
recent research finding over seven ransomware attacks per
hour--that the Department of Justice elevated ransomware
attacks to a similar priority as terrorism.
The recent Colonial Pipeline hack, in particular, appears
to have struck a nerve, as there is finally discussion about
cybersecurity standards for the pipeline industry. That would
be a good start and one that is long overdue considering the
importance of fuel distribution for our economy and overall
way of life.
However, the oil and gas industry is just one element in a
single critical infrastructure sector--the energy sector. DHS
has defined sixteen critical infrastructure sectors, and each
is deemed critical for the proper functioning of our society.
Due to the connected nature of everything these days, each
sector is a potential cyber target. Disruption to any
critical infrastructure segment has potentially dire
economic, safety and national security consequences. As such,
it only makes sense to address cybersecurity risk management
for all sectors, not just oil and gas.
The threat goes beyond the pipeline.
To better understand the need to focus on all critical
infrastructure, let's look at the power grid. Imagine a
ransomware attack against the power grid that services highly
populated areas in the desert southwest. Now, imagine this
attack takes place during the hottest part of the summer.
Think about the heat-related deaths that would likely occur
and the impact on medical supplies that require
refrigeration. Yes, there are generator backups in hospitals
where supplies are stored, but we already know from the
pipeline hack that the fuel needed to run these generators
can be disrupted too. It's also important to note that
hospitals, also considered critical infrastructure, have also
suffered from ransomware attacks. In fact, hospitals have had
an even bigger target on their backs in recent months. The
connected nature of our critical infrastructure compounds the
problem and potential impacts.
To further illustrate how important the power grid is to
our citizens, Protect Our Power, an independent, non-profit
advocacy and educational organization focused solely on
driving increased resilience of the U.S. electric grid to
attacks, recently conducted a public opinion poll of 1,095
Americans. Most notably, the study found:
86 percent of Americans are concerned that the grid is
vulnerable to a serious cyberattack.
70 percent say they would feel unsafe in the event of an
extended power outage of two weeks or more.
66 percent believe their quality of life will suffer from
an outage lasting more than seven days.
64 percent say they are unprepared for an extended power
outage that will last more than two weeks.
70 percent say the infrastructure bill should include
funding to address this important issue.
Only 16 percent believe the federal government is doing all
it can to prevent an attack on the grid.
As most Americans agree, the federal government can and
should do more to help secure all of our critical
infrastructures.
Recent ransomware attacks against critical infrastructure
help us understand standards and practices that would have
helped. For example, multi-factor authentication (MFA), a
widely recognized best practice, may have prevented the
Colonial Pipeline hack. According to GAO, greater and more
consistent adoption of the NIST CSF, which was specifically
developed to help critical infrastructure manage cyber risk,
would benefit cyber risk management efforts across all
critical infrastructure sectors.
In summary, we need to secure all critical infrastructure
sectors. The power grid example used here illustrates how
dire the consequences could be. It's time to move. Summer is
upon us, and the desert southwest is getting hot.
Madam Speaker, I ask my colleagues to support this legislation because there is a known list of these attacks from the ISS World to the $50 million paid. I ask my colleagues to support this legislation, and I ask my friends in the other body, to pass this legislation so it becomes law.
Madam Speaker, I rise in support of H.R. 2980, ``The Cybersecurity Vulnerability Remediation Act,'' which authorizes the Department of Homeland Security to take actions to counter cybersecurity vulnerabilities in our nation's critical infrastructure.
I thank Chairman Thompson and Ranking Member Katko for their leadership in putting the security of our nation's cyber assets first, whether they are computing resources used in voting technology or industrial control systems that support the delivery of electricity, oil and gas, or management of transportation systems that are vital to our nation's economic health.
The Cybersecurity Vulnerability Remediation Act was introduced and passed the House during the 115th and 116th Congresses and has been updated again in the 117th Congress to meet the ever-evolving nature of cyber threats faced by federal and private sector information systems and our nation's critical infrastructure.
This bill goes significantly further than the first Cybersecurity Vulnerability bill that I introduced in the 115th Congress, to address the instance of Zero Day Events that can lead to catastrophic cybersecurity failures of information and computing systems.
It is estimated that eighty-five percent of critical infrastructure is owned by the private sector and for far too long this fact has hampered efforts to establish stronger requirements for cybersecurity by owners and operators.
Private sector critical infrastructure failure due to a cyberattack is no longer a private matter when it can have massive impacts on the public such as the disruption of gasoline flowing to filling stations.
The Jackson Lee Cybersecurity Vulnerability Remediation Act will:
Expand the definition of security vulnerability to include cybersecurity vulnerability;
Adds sharing mitigation protocols to counter cybersecurity vulnerabilities;
Establish protocols to counter cybersecurity vulnerabilities involving information systems and industrial control systems, which will include vulnerabilities related to software, or hardware that is no longer supported by a vendor;
Direct the Under Secretary for the DHS Office of Science and Technology to standup a competition to find solutions to known cybersecurity vulnerabilities; and
Provide greater transparency on how the Department of Homeland Security's Cybersecurity and Information Security Agency (CISA) is coordinating cybersecurity vulnerability disclosures through the sharing of actionable protocols to mitigate cybersecurity vulnerabilities with information systems and industrial control systems owners and operators.
H.R. 2890 bolsters the efforts to engage critical infrastructure owners and operators in communicating cybersecurity threats; and lays the foundation for greater transparency on the real threats posed by cyberterrorist to private and government sector critical infrastructure and information systems.
The legislation allows the Science the Technology Directorate in consultation with CISA to establish an incentive based program that allows industry, individuals, academia, and others to compete in identifying remediation solutions for cybersecurity vulnerabilities to information systems and industrial control systems including supervisory control and data acquisition systems.
This bill when it becomes law would put our nation's best minds to work on closing the vulnerabilities that cyber-thieves and terrorists to use them to access, disrupt, corrupt, or take control of critical infrastructure and information systems.
In addition to these changes, the bill requires a report to Congress that may contain a classified annex.
The report will provide information on how DHS:
Coordinates cybersecurity vulnerability disclosures; and
Disseminates actionable protocols to mitigate cybersecurity vulnerabilities involving information system and industrial systems.
Congress needs to know how prevalent and persistent cybersecurity threats targeting critical infrastructure and information systems might be, especially if those threats result in a payment of ransom.
Paying a ransom for ransomware emboldens and encourages bad cyber actors and places everyone at greater risk for the financial and societal costs of increases in threats as other seek payouts.
As long as there is silence about cyber-attacks like ransomware the criminals and terrorists will remain out of reach and continue to feel safe in carrying out these attacks often from the soil of our enemies or peer competitors.
A company cannot stand up to Russia or China, but the United States can and has done so to protect our national interest.
I applaud and thank the Biden Administration for its quick action to respond to the attack against Colonial Pipeline in issuing a new Executive Order.
Today, our nation is in a cybersecurity crisis.
My concern regarding the security of information networks began in 2015 when the Office of Personnel Management's data breach resulted in the theft of millions of sensitive personnel records on federal employees.
The attacks against federal, state, local, territorial, and tribal governments, as well as threats posed to private information systems, and critical infrastructure systems makes this bill necessary.
On May 13, 2021 it was reported that the DC Metropolitan Police Department had experienced the worst reported cyberattack against a police department in the United States.
The gang, known as the Babuk group, released thousands of the Metropolitan Police Department's sensitive documents on the dark web because the department would not pay.
Cyberthreats are not limited to information related to government employees.
In February 2021, a cyberattack on an Oldsmar, Florida water treatment facility involved increasing the levels of sodium hydroxide from 100 parts per million to 11,100 parts per million in drinking water.
However, the levels of this chemical in the water produced by Oldsmar, Florida was increased to levels that would cause harm to people if they drank or used it.
This is just one example of how terrorists can attack critical infrastructure and cause threats to health, safety and life.
Cyber terrorists and cyber criminals are also motivated to attack information networks in exchange for money.
The sources of revenue from cyberattacks has moved from demands of payment for thieves not to release information--to the sale of stolen information on the dark web and now to a sophisticated denial of service attack in the form of ransomware that locks a system using encryption until the victim pays.
A list of known ransomware attacks in 2020 that are suspected of paying ransoms, included:
ISS World (Denmark) paid an estimated cost: $74 million;
Cognizant (US) paid an estimated $50 million;
Sopra Steria (French) paid estimated $50 million;
Redcar and Cleveland Council (UK) paid an estimated $14 million; and
University of California San Francisco (US) paid an estimated $1.14 million.
There are likely many other attacks that are not publicly known and this must change if we are to defeat this threat.
Ransomware is becoming the tool of choice for those seeking a payout because it can be carried out against anyone or any entity by perpetrators who are far from U.S. shores.
The Colonial Pipeline incident is just one in a long line of successful attacks or infiltrations carried out against domestic information systems and critical infrastructure with increasing consequences for the life, health, safety, and economic security of our citizens.
CEO Joseph Blount testified before the U.S. Senate that the attack occurred using a legacy Virtual Private Network (VPN) system that did not have multifactor authentication.
In other words, hackers were able to gain access to this critical infrastructure as a result of a single compromised password.
There would be no need for the Cybersecurity Vulnerability Remediation Act if owners and operators were succeeding in meeting the cybersecurity needs of critical infrastructure.
I know that there is more that should and ought to be done to address the issue of cybercrime and I will be pursuing this avenue under the jurisdiction of the House Judiciary Committee, as the chair of the Subcommittee on Crime, Terrorism and Homeland Security.
Madam Speaker, I ask that my colleagues vote in support of H.R. 2890.