<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Reported-in-Senate" dms-id="A1" public-private="public" slc-id="S1-EHF25129-877-VD-R38"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>119 S245 RS: Insure Cybersecurity Act of 2025</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2025-06-09</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><calendar>Calendar No. 90</calendar><congress>119th CONGRESS</congress><session>1st Session</session><legis-num>S. 245</legis-num><associated-doc role="report">[Report No. 119–28]</associated-doc><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20250124">January 24, 2025</action-date><action-desc><sponsor name-id="S408">Mr. Hickenlooper</sponsor> (for himself and <cosponsor name-id="S372">Mrs. Capito</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSCM00" added-display-style="italic" deleted-display-style="strikethrough">Committee on Commerce, Science, and Transportation</committee-name></action-desc></action><action stage="Reported-in-Senate"><action-date date="20250609">June 9, 2025</action-date><action-desc>Reported by <sponsor name-id="S355">Mr. Cruz</sponsor>, without amendment</action-desc></action><legis-type>A BILL</legis-type><official-title>To require the Assistant Secretary of Commerce for Communications and Information to establish a working group on cyber insurance, to require dissemination of informative resources for issuers and customers of cyber insurance, and for other purposes.</official-title></form><legis-body display-enacting-clause="yes-display-enacting-clause"><section section-type="section-one" id="S1"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Insure Cybersecurity Act of 2025</short-title></quote>.</text></section><section id="idb52842fd35e24b45a1faff43eb5b9bef"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text><paragraph id="id5d7507288f6e4964a438147af274dac6"><enum>(1)</enum><header>Assistant Secretary</header><text>The term <term>Assistant Secretary</term> means the Assistant Secretary of Commerce for Communications and Information.</text></paragraph><paragraph id="id028C865D05674A4D808C97740219AEEE"><enum>(2)</enum><header>Critical infrastructure</header><text>The term <term>critical infrastructure</term> has the meaning given the term in subsection (e) of the Critical Infrastructures Protection Act of 2001 (<external-xref legal-doc="usc" parsable-cite="usc/42/5195c">42 U.S.C. 5195c</external-xref>). </text></paragraph><paragraph commented="no" display-inline="no-display-inline" id="id53fcb5b1157140108c1db0590f4e8481"><enum>(3)</enum><header display-inline="yes-display-inline">Customer</header><text>The term <term>customer</term> means an individual or organization that purchases cyber insurance from an issuer. </text></paragraph><paragraph id="id1c8dbda3ac974f9ba5f6e7bd8e535ffe"><enum>(4)</enum><header>Cyber incident</header><text>The term <term>cyber incident</term> has the meaning given the term <term>incident</term> in section 3552(b) of title 44, United States Code. </text></paragraph><paragraph id="id1aeb63ffa5b747ff83b98faaed4f130b"><enum>(5)</enum><header>Cyber insurance</header><text>Subject to section 3(c)(1)(A), the term <term>cyber insurance</term> means an insurance policy that includes coverage for losses, damages, and costs incurred due to cyber incidents. </text></paragraph><paragraph id="idfedb085892074ee39676005bc7f37456"><enum>(6)</enum><header>Issuer</header><text>The term <term>issuer</term> means an organization that issues cyber insurance.</text></paragraph><paragraph id="idca7e6efa7c4a4bae9d2766a32c47109c"><enum>(7)</enum><header>Policy</header><text>The term <term>policy</term> means a policy for cyber insurance.</text></paragraph><paragraph id="id7c533400df22438fb064223034ddc350"><enum>(8)</enum><header>Small business</header><text>The term <term>small business</term> has the meaning given the term <term>small business concern</term> in section 3 of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632</external-xref>).</text></paragraph><paragraph id="id0326161C7556449BBB29596341626E35"><enum>(9)</enum><header>Working group</header><text>The term <term>working group</term> means the working group established under section 3(a).</text></paragraph></section><section id="id0f855e7195bd41b6836f9ecdd071471b"><enum>3.</enum><header>Working group on cyber insurance</header><subsection id="idcd2270a0eaee42e79f2566fae9ddcb97"><enum>(a)</enum><header>Establishment</header><text>Not later than 90 days after the date of enactment of this Act, the Assistant Secretary shall establish a working group on cyber insurance.</text></subsection><subsection id="idCF3EF6CF8F6E4CB2BEA5270242A934A3"><enum>(b)</enum><header>Composition</header><paragraph id="idECF9F0F18EC646B7A0D8EFEFA3AE0A57"><enum>(1)</enum><header>Membership</header><text>The working group shall be composed of the following members: </text><subparagraph commented="no" display-inline="no-display-inline" id="idbfc2e7705edc4f2a98260c79ff5e2ef2"><enum>(A)</enum><text display-inline="yes-display-inline">Not less than 1 member from each of the following:</text><clause id="id17b132cfba474c3e8283ef83c0efd093"><enum>(i)</enum><text>The Cybersecurity and Infrastructure Security Agency.</text></clause><clause id="id0805E6972A3249DE9CAA3D425209F35B"><enum>(ii)</enum><text>The National Institute of Standards and Technology.</text></clause><clause id="id1059e6fa98614826a48c31bf78af6260"><enum>(iii)</enum><text>The Department of the Treasury.</text></clause><clause commented="no" display-inline="no-display-inline" id="idde81063e89c14ac9bd9ad7e91f6fd7ba"><enum>(iv)</enum><text>The Department of Justice. </text></clause><clause id="id17f8d46384314ba2a39c5eed0e0146ab"><enum>(v)</enum><text>The Federal Trade Commission.</text></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id13e544f281f04af88950ab27eff1aa34"><enum>(B)</enum><text>Not less than 1 State insurance regulator with expertise regarding cybersecurity and cyber insurance.</text></subparagraph></paragraph><paragraph id="id22FCE72854ED40209082AEC68473E641"><enum>(2)</enum><header>Chairperson</header><text>The Assistant Secretary shall be the chairperson of the working group.</text></paragraph></subsection><subsection id="idbf3f3d6d455944c6b7205f8f81711e23"><enum>(c)</enum><header>Activities</header><paragraph id="id9AB59C79AC1D4950A77F8E186BF8539E"><enum>(1)</enum><header>In general</header><text>The working group shall carry out the following activities:</text><subparagraph id="idF67CAAE725B74A27BD96DC45BBFC6FEB"><enum>(A)</enum><text>For the purposes of the activities of the working group, define the term <term>cyber insurance</term> in a manner that is different from the definition of that term under section 2(5), if the working group determines that such a modified definition is necessary.</text></subparagraph><subparagraph id="id67F2BDA790434A6B8D1060020410E72E"><enum>(B)</enum><text>Analyze and explain in a manner understandable to customers the technical and legal terminology commonly used in policies.</text></subparagraph><subparagraph id="ida60aec8db7134e8ebedaefdd9f502291"><enum>(C)</enum><text>Analyze and explain in a manner understandable to customers how provisions in policies correspond to common types of cyber incidents, including those involving ransomware.</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id9ff4ace656a54e11b1d101596d8f591b"><enum>(D)</enum><text>Analyze and explain in a manner understandable to customers how provisions in policies correspond to common customer responses to cyber incidents, including with respect to system recovery and potential ransom payments.</text></subparagraph><subparagraph id="idd6406ae08d88435fbaf9a24c0e493012"><enum>(E)</enum><text>Analyze and explain in a manner understandable to customers the terminology used in policies to include or exclude coverage for losses due to cyber incidents.</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id0c680610086d41b5b5952f1d146ec977"><enum>(F)</enum><text>Analyze and explain in a manner understandable to customers the constraints faced by issuers in covering higher amounts of losses and cyber risk areas, such as reputational damage and the loss of intellectual property.</text></subparagraph><subparagraph id="id15d92bf10e7642c5bf4fb9582bffe747"><enum>(G)</enum><text>Develop information for customers on ways to effectively evaluate the types and levels of coverage offered under a policy.</text></subparagraph><subparagraph id="idb2d9dfc75dbc420689b5a9623a77adb5"><enum>(H)</enum><text>Develop information for issuers, agents, and brokers regarding how to provide and communicate policy provisions that are clear and easy to understand for customers.</text></subparagraph><subparagraph id="id3f6bb61f1bf34883a00872db01297397"><enum>(I)</enum><text>Gather input from issuers on what measures could improve the ability of those issuers to offer additional coverage under policies, including— </text><clause commented="no" display-inline="no-display-inline" id="id2b7ba04d151c426186c43af32a5b97f5"><enum>(i)</enum><text display-inline="yes-display-inline">improvements to their actuarial data and cyber risk data; </text></clause><clause commented="no" display-inline="no-display-inline" id="id1dac9e68ada84d71b9100be8808617a8"><enum>(ii)</enum><text display-inline="yes-display-inline">the development of effective information sharing mechanisms; and </text></clause><clause commented="no" display-inline="no-display-inline" id="idbd861b01136a43c49d81b33d4c4d7487"><enum>(iii)</enum><text display-inline="yes-display-inline">accurate measurement of the cybersecurity practices of customers.</text></clause></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="id8e2f908146d843c3b3398852889f683a"><enum>(J)</enum><text>Identify what measures could reduce the cost of policies and reduce the amount of cyber risk and the number of cyber incidents.</text></subparagraph><subparagraph id="ida72c2a63e8e041369ff4aeb686277676"><enum>(K)</enum><text>Develop recommendations for customers on how best to use cyber insurance and the benefits of doing so. </text></subparagraph></paragraph><paragraph id="id5c130262e81e4522977a99c9aa059405"><enum>(2)</enum><header>Consultation</header><text>In carrying out the activities of the working group under paragraph (1), the working group shall consult with the public in an open and transparent manner, including by consulting with the following stakeholders:</text><subparagraph id="id3dca62220d1e433888805569d7d4bb80"><enum>(A)</enum><text>Issuers.</text></subparagraph><subparagraph id="idd11b1cc2922d4d0bb143cdf69bf59447"><enum>(B)</enum><text>Insurance agents and brokers with experience in the sale and distribution of cyber insurance.</text></subparagraph><subparagraph id="id50c51b54b577451aaabbab64fcc2a7b1"><enum>(C)</enum><text>Representatives of business customers from multiple sectors and representatives of small businesses.</text></subparagraph><subparagraph id="id539F7B21A3E147ECB9BD3C0962BECC5F"><enum>(D)</enum><text>Academia.</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idcdfe3dd0dbd843f8a080e442d449b2fa"><enum>(E)</enum><text>State insurance regulators with expertise regarding cybersecurity and cyber insurance.</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idEA5AEE955143412580AC2E60FE401CC0"><enum>(F)</enum><text>Owners and operators of critical infrastructure.</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="ide5057007d7cd4693b5acc5be1d3e197a"><enum>(G)</enum><text display-inline="yes-display-inline">Other individuals or entities with cybersecurity and cyber insurance expertise as the Assistant Secretary considers appropriate. </text></subparagraph></paragraph></subsection><subsection id="id0733750849f14b72802eb2f787b5f102"><enum>(d)</enum><header>Report</header><text>Not later than 1 year after the date on which the working group first convenes, the working group shall submit to Congress a report regarding the activities of the working group under subsection (c) and any recommendations of the working group.</text></subsection><subsection id="id172919279E5B4B15A52E0584781484E1"><enum>(e)</enum><header>Termination</header><text>The working group shall terminate upon submission of the report required under subsection (d).</text></subsection><subsection id="id6E6432188F39425B8F959145ABB2878F"><enum>(f)</enum><header>Rule of construction</header><text>Nothing in this section shall be construed to—</text><paragraph id="idA98B91270D3F43FE809C471D88BD9C2E"><enum>(1)</enum><text>require adoption of the recommendations of the working group; or</text></paragraph><paragraph id="id8E2A3D3124DE4133BA2352E2C55DCD80"><enum>(2)</enum><text>provide any authority to any member of the working group or any other individual to regulate the business of insurance that is not already provided under any other provision of law. </text></paragraph></subsection></section><section id="id8eacb15a536b4368a956bc8f89456014"><enum>4.</enum><header>Dissemination of informative resources for cyber insurance stakeholders</header><subsection id="ida2dd3591b45648fe893a48c6254abc9d"><enum>(a)</enum><header>In general</header><text>Not later than 90 days after the date on which the working group submits the report required under section 3(d), the Assistant Secretary shall disseminate and make publicly available informative resources for cyber insurance stakeholders.</text></subsection><subsection id="id08c80eb0e70e42989cd53e1190d69b8a"><enum>(b)</enum><header>Requirements</header><text>The Assistant Secretary shall ensure that the resources disseminated under subsection (a)—</text><paragraph id="idcd63bb2cb18d42a8a3b17042255a000a"><enum>(1)</enum><text>incorporate the recommendations included in the report submitted under section 3(d);</text></paragraph><paragraph id="idc22464a0d4594755b2d81b5f7501e70b"><enum>(2)</enum><text>are generally applicable and usable by a wide range of cyber insurance stakeholders, including issuers, agents, brokers, and customers; and</text></paragraph><paragraph id="idb203065b50814b8bbea7d7de6dbf4d99"><enum>(3)</enum><text>include case studies and specific examples, where appropriate.</text></paragraph></subsection><subsection id="id36c44e73a76a42a5ab92cb05e67be64d"><enum>(c)</enum><header>Publication</header><text>The resources disseminated under subsection (a) shall be published on the public website of the National Telecommunications and Information Administration.</text></subsection><subsection id="id91a6ab2814464aaca13f7719d69cb126"><enum>(d)</enum><header>Outreach</header><text>The Assistant Secretary shall conduct outreach and coordination activities to promote the availability of the resources disseminated under subsection (a) to relevant industry stakeholders and the general public.</text></subsection><subsection id="ided6ecb0337aa456aa4dedb6c0d7882a1"><enum>(e)</enum><header>Voluntary use</header><text>Nothing in this section may be construed to require the use of the resources disseminated under subsection (a). </text></subsection></section></legis-body><endorsement display="yes"><action-date date="20250609">June 9, 2025</action-date><action-desc>Reported without amendment</action-desc></endorsement></bill> 

