<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" dms-id="H65EB4D9441444843A3B5D96EEAC75600" public-private="public" key="H" bill-type="olc"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 HR 9315 IH: Public and Private Sector Ransomware Response Coordination Act of 2024</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2024-08-06</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">118th CONGRESS</congress><session display="yes">2d Session</session><legis-num display="yes">H. R. 9315</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20240806">August 6, 2024</action-date><action-desc><sponsor name-id="N000193">Mr. Nunn of Iowa</sponsor> (for himself and <cosponsor name-id="G000583">Mr. Gottheimer</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HBA00">Committee on Financial Services</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To direct the Secretary of the Treasury to submit a report on coordination in the public and private sectors in responding to ransomware attacks on financial institutions, and for other purposes.</official-title></form><legis-body id="H33A51DF6D16744DCB9B7A4FB74F5EE2B" style="OLC"><section id="H398A93F693CA4CA4AA132EAFBE1D186D" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Public and Private Sector Ransomware Response Coordination Act of 2024</short-title></quote>.</text></section><section id="HB3562448033D4E6C901646EA175B0D8B"><enum>2.</enum><header>Report on coordination in the public and private sectors in responding to ransomware attacks on financial institutions</header><subsection id="H508DC70974B448F2A77496F0CA25D635"><enum>(a)</enum><header>In general</header><text display-inline="yes-display-inline">Not later than one year after the date of the enactment of this section, the Secretary of the Treasury shall submit to the appropriate congressional committees a report that describes the following:</text><paragraph id="H72AF9AAF92054D81B8AC5163BA382789"><enum>(1)</enum><text display-inline="yes-display-inline">The current level of coordination and collaboration between the public and private sectors, including entities in the public and private sectors that manage cybersecurity, in response to, and for the prevention of, a ransomware attack on a financial institution.</text></paragraph><paragraph id="H421B979E67B54E3D9C51D2B293BDAAAA"><enum>(2)</enum><text display-inline="yes-display-inline">The coordination among relevant governmental agencies in response to, and for the prevention of, a ransomware attack on a financial institution.</text></paragraph><paragraph id="H76681766A817453F80F82153BE241733"><enum>(3)</enum><text display-inline="yes-display-inline">Whether relevant governmental agencies have timely access to relevant information reported by a financial institution following a ransomware attack on the financial institution. </text></paragraph><paragraph id="H6A1AD6E0909449AA8696F77C91B57B30"><enum>(4)</enum><text display-inline="yes-display-inline">The utility of such information to any relevant governmental agency in the prevention or investigation of a ransomware attack on a financial institution, or the prosecution of a person responsible for such attack.</text></paragraph><paragraph id="H1C64064630A4488695BC6B03DF91F660"><enum>(5)</enum><text display-inline="yes-display-inline">An analysis of reporting requirements applicable to a financial institution with respect to a ransomware attack in relation to the utility to any relevant governmental agency of the reported information in the prevention or investigation of a ransomware attack on a financial institution, or the prosecution of a person responsible for such attack.</text></paragraph><paragraph id="HC5B81303D37546B3BB6C4591BBA7FC15"><enum>(6)</enum><text display-inline="yes-display-inline">Whether further legislation is required to increase the utility and timely access of such information to any relevant governmental agency following a ransomware attack on a financial institution.</text></paragraph><paragraph id="H7F91CB31C94B47E6AD86FBE94F812FB6"><enum>(7)</enum><text display-inline="yes-display-inline">Any recommended policy initiatives to bolster public-private partnerships, increase incident report sharing, and decrease incident response time.</text></paragraph><paragraph id="HBB25D2FB1C0C4EF1B429C8EB41907ED7"><enum>(8)</enum><text display-inline="yes-display-inline">The extent to which, and reasons that, financial institutions withhold or delay reporting to relevant governmental agencies information about a ransomware attack.</text></paragraph><paragraph id="HD682BC56D80441C0B2DA8CAF992B911C"><enum>(9)</enum><text display-inline="yes-display-inline">Any feedback on the contents of the report received from cybersecurity and ransomware response entities that provide services to financial institutions.</text></paragraph></subsection><subsection id="H0CBD815E0A5B40C9BDDB04067E5C5D19"><enum>(b)</enum><header>Form of report</header><text>The report described in subsection (a) shall be submitted in unclassified form, but may include a classified annex.</text></subsection><subsection id="H10515A0D224343DCBC9BB05D295F0D21"><enum>(c)</enum><header>Briefing</header><text>Not later than 15 months after the date of the enactment of this section, the Secretary of the Treasury shall brief the appropriate congressional committees on the findings of the report described in subsection (a).</text></subsection><subsection id="H16153FFDD34D4320B2286AC32045BF5E"><enum>(d)</enum><header>Definitions</header><text>In this section:</text><paragraph id="H14D77241659846C9B03367AC8DDC0135"><enum>(1)</enum><header>Appropriate congressional committees</header><text>The term <term>appropriate congressional committees</term> means—</text><subparagraph id="H2ADDC2C0F260489498B493877642885F"><enum>(A)</enum><text display-inline="yes-display-inline">the Committee on Financial Services of the House of Representatives;</text></subparagraph><subparagraph id="H0CB3E1925BBA40A492E76E8A82B5542D"><enum>(B)</enum><text display-inline="yes-display-inline">the Permanent Select Committee on Intelligence of the House of Representatives; </text></subparagraph><subparagraph id="HD0B74B9EF5B744ADACAD7295743DB108"><enum>(C)</enum><text display-inline="yes-display-inline">the Committee on Banking, Housing, and Urban Affairs of the Senate; and</text></subparagraph><subparagraph id="H8A4DABF733164DF280D88B03E91801B1"><enum>(D)</enum><text display-inline="yes-display-inline">the Select Committee on Intelligence of the Senate.</text></subparagraph></paragraph><paragraph id="H647EFA9749004079B91A2583C02739DD"><enum>(2)</enum><header>Cybersecurity and ransomware incident response entity</header><text display-inline="yes-display-inline">The term <term>cybersecurity and ransomware incident response entity</term> means an entity that provides incident responses, managed services, or advisory services that—</text><subparagraph id="H09CDEB8D17804F77A17F63F7193120A8"><enum>(A)</enum><text display-inline="yes-display-inline">supports investigation and risk management related to ransomware attacks in the public and private sectors;</text></subparagraph><subparagraph id="H09C22BAE31E9417B836CF668DF66A838"><enum>(B)</enum><text display-inline="yes-display-inline">strengthens cybersecurity technology in the financial sector; and</text></subparagraph><subparagraph id="H98A652A3E571479CB07CDAC58FE15E5A"><enum>(C)</enum><text display-inline="yes-display-inline">reduces overall cyber risk in the financial sector by assessing the security posture of a financial institution, assisting a financial institution with regulatory compliance, and providing recommendations to a financial institution for recovery after a ransomware attack and prevention of any future attacks.</text></subparagraph></paragraph><paragraph id="HBDB454DC1AD54806AA9ABDF899E46F77"><enum>(3)</enum><header>Financial institution</header><text display-inline="yes-display-inline">The term <term>financial institution</term> has the meaning given that term under section 5312(a) of title 31, United States Code.</text></paragraph></subsection></section></legis-body></bill> 

