<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-Senate" dms-id="A1" public-private="public" slc-id="S1-EHF23112-XRR-H3-XMN"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>118 S513 IS: Insure Cybersecurity Act of 2023</dc:title>
<dc:publisher>U.S. Senate</dc:publisher>
<dc:date>2023-02-16</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">II</distribution-code><congress>118th CONGRESS</congress><session>1st Session</session><legis-num>S. 513</legis-num><current-chamber>IN THE SENATE OF THE UNITED STATES</current-chamber><action><action-date date="20230216">February 16, 2023</action-date><action-desc><sponsor name-id="S408">Mr. Hickenlooper</sponsor> (for himself and <cosponsor name-id="S372">Mrs. Capito</cosponsor>) introduced the following bill; which was read twice and referred to the <committee-name committee-id="SSCM00">Committee on Commerce, Science, and Transportation</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title>To require the Assistant Secretary of Commerce for Communications and Information to establish a working group on cyber insurance, to require dissemination of informative resources for issuers and customers of cyber insurance, and for other purposes.</official-title></form><legis-body display-enacting-clause="yes-display-enacting-clause"><section section-type="section-one" id="S1"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Insure Cybersecurity Act of 2023</short-title></quote>.</text></section><section id="idb52842fd35e24b45a1faff43eb5b9bef"><enum>2.</enum><header>Definitions</header><text display-inline="no-display-inline">In this Act:</text><paragraph id="id5d7507288f6e4964a438147af274dac6"><enum>(1)</enum><header>Assistant Secretary</header><text>The term <term>Assistant Secretary</term> means the Assistant Secretary of Commerce for Communications and Information.</text></paragraph><paragraph id="id028C865D05674A4D808C97740219AEEE"><enum>(2)</enum><header>Customer</header><text>The term <term>customer</term> means an individual or organization that purchases cyber insurance from an issuer. </text></paragraph><paragraph id="id1c8dbda3ac974f9ba5f6e7bd8e535ffe"><enum>(3)</enum><header>Cyber incident</header><text>The term <term>cyber incident</term> has the meaning given the term <term>incident</term> in section 3552(b) of title 44, United States Code. </text></paragraph><paragraph id="id1aeb63ffa5b747ff83b98faaed4f130b"><enum>(4)</enum><header>Cyber insurance</header><text>Subject to section 3(c)(1)(A), the term <term>cyber insurance</term> means an insurance policy that, whether by explicit inclusion or by lack of exclusion, offers coverage for losses, damages, and costs incurred due to cyber incidents. </text></paragraph><paragraph id="idfedb085892074ee39676005bc7f37456"><enum>(5)</enum><header>Issuer</header><text>The term <term>issuer</term> means an organization that issues cyber insurance.</text></paragraph><paragraph id="idca7e6efa7c4a4bae9d2766a32c47109c"><enum>(6)</enum><header>Policy</header><text>The term <term>policy</term> means a policy for cyber insurance.</text></paragraph><paragraph id="id7c533400df22438fb064223034ddc350"><enum>(7)</enum><header>Small business</header><text>The term <term>small business</term> has the meaning given the term <term>small business concern</term> in section 3 of the Small Business Act (<external-xref legal-doc="usc" parsable-cite="usc/15/632">15 U.S.C. 632</external-xref>).</text></paragraph><paragraph id="id0326161C7556449BBB29596341626E35"><enum>(8)</enum><header>Working group</header><text>The term <term>working group</term> means the working group established under section 3(a).</text></paragraph></section><section id="id0f855e7195bd41b6836f9ecdd071471b"><enum>3.</enum><header>Working group on cyber insurance</header><subsection id="idcd2270a0eaee42e79f2566fae9ddcb97"><enum>(a)</enum><header>Establishment</header><text>Not later than 90 days after the date of enactment of this Act, the Assistant Secretary shall establish a working group on cyber insurance.</text></subsection><subsection id="idCF3EF6CF8F6E4CB2BEA5270242A934A3"><enum>(b)</enum><header>Composition</header><paragraph id="idECF9F0F18EC646B7A0D8EFEFA3AE0A57"><enum>(1)</enum><header>Membership</header><text>The working group shall be composed of not less than 1 member from each of the following:</text><subparagraph id="id17b132cfba474c3e8283ef83c0efd093"><enum>(A)</enum><text>The Cybersecurity and Infrastructure Security Agency.</text></subparagraph><subparagraph id="id0805E6972A3249DE9CAA3D425209F35B"><enum>(B)</enum><text>The National Institute of Standards and Technology.</text></subparagraph><subparagraph id="id1059e6fa98614826a48c31bf78af6260"><enum>(C)</enum><text>The Department of the Treasury.</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idde81063e89c14ac9bd9ad7e91f6fd7ba"><enum>(D)</enum><text>The Department of Justice. </text></subparagraph></paragraph><paragraph id="id22FCE72854ED40209082AEC68473E641"><enum>(2)</enum><header>Chairperson</header><text>The Assistant Secretary shall be the chairperson of the working group.</text></paragraph></subsection><subsection id="idbf3f3d6d455944c6b7205f8f81711e23"><enum>(c)</enum><header>Activities</header><paragraph id="id9AB59C79AC1D4950A77F8E186BF8539E"><enum>(1)</enum><header>In general</header><text>The working group shall carry out the following activities:</text><subparagraph id="idF67CAAE725B74A27BD96DC45BBFC6FEB"><enum>(A)</enum><text>For the purposes of the activities of the working group, define the term <term>cyber insurance</term> in a manner that is different from the definition of that term under section 2(4), if the working group determines that such a modified definition is necessary.</text></subparagraph><subparagraph id="id67F2BDA790434A6B8D1060020410E72E"><enum>(B)</enum><text>Analyze and explain in a manner most understandable to customers the technical and legal terminology commonly used in policies.</text></subparagraph><subparagraph id="ida60aec8db7134e8ebedaefdd9f502291"><enum>(C)</enum><text>Analyze, and develop recommendations regarding, provisions in policies that relate to ransomware and ransom payments made in response to ransomware.</text></subparagraph><subparagraph id="idd6406ae08d88435fbaf9a24c0e493012"><enum>(D)</enum><text>Analyze and explain in a manner most understandable to customers the terminology used in policies to include or exclude coverage for losses due to cyber incidents that are caused by cyberterrorism or acts of war.</text></subparagraph><subparagraph id="id15d92bf10e7642c5bf4fb9582bffe747"><enum>(E)</enum><text>Develop recommendations for prospective customers on ways to effectively evaluate the types and levels of coverage offered under a policy.</text></subparagraph><subparagraph id="idb2d9dfc75dbc420689b5a9623a77adb5"><enum>(F)</enum><text>Develop recommendations for issuers, agents, and brokers regarding how to provide and communicate policy provisions that are clear and easy to understand for customers.</text></subparagraph><subparagraph id="idbaa1539aacf343e79c15cf9c70fdbfd1"><enum>(G)</enum><text>Identify the constraints of issuers in covering higher amounts of losses and new cyber risk areas currently not covered, including reputational damage and intellectual property lost.</text></subparagraph><subparagraph id="id3f6bb61f1bf34883a00872db01297397"><enum>(H)</enum><text>Gather input from issuers on what measures would improve the ability of those issuers to offer additional coverage under policies, including improvements to their actuarial data, cyber risk data, and information sharing mechanisms and effective measurement of the cybersecurity practices of consumers.</text></subparagraph><subparagraph id="idb062861916ac49f0937b4d8c14894c99"><enum>(I)</enum><text>Identify the constraints of the market and why more organizations do not use cyber insurance as a risk response mechanism.</text></subparagraph><subparagraph id="ida72c2a63e8e041369ff4aeb686277676"><enum>(J)</enum><text>Develop recommendations for customers on how best to use cyber insurance as a risk response mechanism for cyber risk and incentives for doing so. </text></subparagraph></paragraph><paragraph id="id5c130262e81e4522977a99c9aa059405"><enum>(2)</enum><header>Consultation</header><text>In carrying out the activities of the working group under paragraph (1), the working group shall consult with the public in an open and transparent manner, including by consulting with the following stakeholders:</text><subparagraph id="id3dca62220d1e433888805569d7d4bb80"><enum>(A)</enum><text>Issuers.</text></subparagraph><subparagraph id="idd11b1cc2922d4d0bb143cdf69bf59447"><enum>(B)</enum><text>Insurance agents and brokers with experience in the sale and distribution of cyber insurance.</text></subparagraph><subparagraph id="id50c51b54b577451aaabbab64fcc2a7b1"><enum>(C)</enum><text>Representatives of business customers from multiple sectors and representatives of small businesses.</text></subparagraph><subparagraph id="id539F7B21A3E147ECB9BD3C0962BECC5F"><enum>(D)</enum><text>Academia.</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idcdfe3dd0dbd843f8a080e442d449b2fa"><enum>(E)</enum><text>State insurance regulators with expertise regarding cybersecurity and cyber insurance.</text></subparagraph><subparagraph commented="no" display-inline="no-display-inline" id="idEA5AEE955143412580AC2E60FE401CC0"><enum>(F)</enum><text>Other individuals or entities with cybersecurity and cyber insurance expertise as the Assistant Secretary considers appropriate. </text></subparagraph></paragraph></subsection><subsection id="id0733750849f14b72802eb2f787b5f102"><enum>(d)</enum><header>Report</header><text>Not later than 1 year after the date on which the working group first convenes, the working group shall submit to Congress a report regarding the activities of the working group under subsection (c) and any recommendations of the working group.</text></subsection><subsection id="id172919279E5B4B15A52E0584781484E1"><enum>(e)</enum><header>Termination</header><text>The working group shall terminate upon submission of the report required under subsection (d).</text></subsection><subsection id="id6E6432188F39425B8F959145ABB2878F"><enum>(f)</enum><header>Rule of construction</header><text>Nothing in this section shall be construed to—</text><paragraph id="idA98B91270D3F43FE809C471D88BD9C2E"><enum>(1)</enum><text>require adoption of the recommendations of the working group; or</text></paragraph><paragraph id="id8E2A3D3124DE4133BA2352E2C55DCD80"><enum>(2)</enum><text>provide any authority to any member of the working group or any other individual to regulate the business of insurance that is not already provided under any other provision of law. </text></paragraph></subsection></section><section id="id8eacb15a536b4368a956bc8f89456014"><enum>4.</enum><header>Dissemination of informative resources for cyber insurance stakeholders</header><subsection id="ida2dd3591b45648fe893a48c6254abc9d"><enum>(a)</enum><header>In general</header><text>Not later than 90 days after the date on which the working group submits the report required under section 3(d), the Assistant Secretary shall disseminate and make publicly available informative resources for cyber insurance stakeholders.</text></subsection><subsection id="id08c80eb0e70e42989cd53e1190d69b8a"><enum>(b)</enum><header>Requirements</header><text>The Assistant Secretary shall ensure that the resources disseminated under subsection (a)—</text><paragraph id="idcd63bb2cb18d42a8a3b17042255a000a"><enum>(1)</enum><text>incorporate the recommendations included in the report submitted under section 3(d);</text></paragraph><paragraph id="idc22464a0d4594755b2d81b5f7501e70b"><enum>(2)</enum><text>are generally applicable and usable by a wide range of cyber insurance stakeholders, including issuers, agents, brokers, and customers; and</text></paragraph><paragraph id="idb203065b50814b8bbea7d7de6dbf4d99"><enum>(3)</enum><text>include case studies and specific examples, where appropriate.</text></paragraph></subsection><subsection id="id36c44e73a76a42a5ab92cb05e67be64d"><enum>(c)</enum><header>Publication</header><text>The resources disseminated under subsection (a) shall be published on the public website of the National Telecommunications and Information Administration.</text></subsection><subsection id="id91a6ab2814464aaca13f7719d69cb126"><enum>(d)</enum><header>Outreach</header><text>The Assistant Secretary shall conduct outreach and coordination activities to promote the availability of the resources disseminated under subsection (a) to relevant industry stakeholders and the general public.</text></subsection><subsection id="ided6ecb0337aa456aa4dedb6c0d7882a1"><enum>(e)</enum><header>Voluntary use</header><text>Nothing in this section may be construed to require the use of the resources disseminated under subsection (a). </text></subsection></section></legis-body></bill> 

