[Congressional Record Volume 161, Number 125 (Tuesday, August 4, 2015)]
[Senate]
[Pages S6310-S6311]
From the Congressional Record Online through the Government Publishing Office [www.gpo.gov]

  SA 2579. Mr. VITTER submitted an amendment intended to be proposed by 
him to the bill S. 754, to improve cybersecurity in the United States 
through enhanced sharing of information about cybersecurity threats, 
and for other purposes; which was ordered to lie on the table; as 
follows:

       At the appropriate place, insert the following:

     SEC. ___. SMALL BUSINESS CYBER SECURITY OPERATIONS CENTER.

       (a) Findings.--Congress finds the following:
       (1) The Federal Government has been hit by a barrage of 
     high-profile cyber assaults over the past year, including the 
     attacks on the Office of Personnel Management and the 
     Department of State.
       (2) These attacks exposed the most sensitive personal 
     information of millions of Federal employees and their 
     families.
       (3) The President has instituted emergency procedures to 
     immediately deploy so-called indicators, or tell-tale signs 
     of cybercrime operations, into agency anti-malware tools.
       (4) According to the Federal Bureau of Investigation, small 
     business concerns have lost more than $1,000,000,000 during 
     the period beginning October 2013 and ending June 2015 as a 
     result of cyber corporate account takeover and business email 
     fraud.
       (5) The Federal Government leverages the creative genius of 
     small business concerns across the country to accomplish its 
     missions.
       (6) The Federal Acquisition Regulations dictates that a 
     percentage of all Federal Government acquisition be set aside 
     for small business concerns.
       (7) Over 90 percent of small business concerns use the 
     Internet through the course of their activities to conduct 
     business.
       (8) Small business concerns tend to have weaker online 
     security and do not have necessary funding for high-end 
     encryption technology or staff expertise.
       (9) Industry reports indicate that 30 percent of cyber 
     attacks target small business concerns and of those 
     businesses that are attacked, 59 percent have no contingency 
     plan, while according to a First Data report, the average 
     cost for a data breach at a small business concern is $36,000 
     and rising annually.
       (10) A 2012 Verizon study shows that in 855 data breaches 
     examined, 71 percent occurred in businesses with fewer than 
     100 employees.
       (11) Small business concerns are increasingly attacked with 
     data breaches and ransomware, where an attacker encrypts the 
     businesses data until a ransom is paid to the attacker.
       (12) It is imperative that small business concerns are 
     provided improved secured guidance to limit negative impacts 
     on the economy of the United States.
       (13) There is a vast cyber threat facing the business 
     sector of the United States, which poses a direct threat 
     against the national security of the United States, the 
     Department of Defense, private industry, and critical 
     infrastructure components.
       (14) The current layer of protection from cyber threats 
     does not exist for small business concerns.
       (b) Definitions.--In this section--
       (1) the term ``Center'' means the Small Business Cyber 
     Security Operations Center established under subsection (c);
       (2) the term ``cyber lab'' means--
       (A) a Joint Cyber Training Lab; and
       (B) a facility that works in conjunction with the National 
     Guard Cyber Teams;
       (3) the term ``Secretary'' means the Secretary of Homeland 
     Security; and
       (4) the term ``small business concern'' has the meaning 
     given that term under section 3 of the Small Business Act (15 
     U.S.C. 632).
       (c) Establishment.--Not later than 1 year after the date of 
     enactment of this Act, the Secretary shall begin carrying out 
     a 3-year pilot program to establish a cybersecurity 
     operations center for small business concerns, to be known as 
     the Small Business Cyber Security Operations Center.
       (d) Part of Existing Center.--The Secretary shall establish 
     the Center as part of and co-locate the Center with a center 
     providing situational awareness information to businesses on 
     the date of enactment of this Act.
       (e) Duties.--The Center shall--
       (1) work with cyber labs to provide realistic scenario 
     based training to network managers and security personnel of 
     small business concerns, including monitoring, detection, 
     analysis (such as trend and pattern analysis), and response 
     and restoration activities;
       (2) provide periodic sharing, through publication and 
     targeted outreach, of cybersecurity best practices that are 
     developed based on ongoing analysis of cyber threat 
     indicators and information in possession of--
       (A) the Federal Government;
       (B) the Business Emergency Operations Center operated by 
     the Federal Emergency Management Agency; and
       (C) other technology and cyber research centers, as 
     determined appropriate by the Secretary;

[[Page S6311]]

       (3) collaborate with private industry, academia, and the 
     Department of Defense to develop a secure business supply 
     chain which is capable of adapting, evolving, and responding 
     to emergent cybersecurity threats;
       (4) review and develop the necessary tools to--
       (A) facilitate security information flow and mitigation 
     actions;
       (B) provide cyber attack sensing, warning, and response 
     services;
       (5) place an emphasis on accessibility and relevance to 
     small business concerns; and
       (6) review the policy limitations and restrictions on 
     information sharing relating to cybersecurity.
       (f) Authorization of Appropriations.--
       (1) In general.--There is authorized to be appropriated to 
     carry out this section $2,000,000 for each of fiscal years 
     2016 through 2019, to remain available until expended.
       (2) Offset.--Section 21(a)(4)(C)(vii) of the Small Business 
     Act (15 U.S.C. 648(a)(4)(C)(vii)) is amended--
       (A) in subclause (I), by striking ``and'' at the end;
       (B) in subclause (II), by striking the period at the end 
     and inserting ``; and''; and
       (C) by adding at the end the following:

       ``(III) $133,000,000 for each of fiscal years 2016 through 
     2019.''.

                                 ______