What This Bill Does
This bill requires a Commerce Department official to create a working group that studies cyber insurance (insurance coverage for losses from cyberattacks). The working group will analyze how cyber insurance works, explain confusing language in policies to customers, and make recommendations to improve the cyber insurance market. After the working group finishes, the government will publish educational materials about cyber insurance for the public.
##
Who It Affects
- The Assistant Secretary of Commerce for Communications and Information
- Insurance companies that sell cyber insurance
- People and organizations that buy cyber insurance
- Insurance agents and brokers
- Small businesses
- Congress
- The public and general industry
##
Key Provisions
- The Assistant Secretary must establish a working group within 90 days that includes members from the Cybersecurity and Infrastructure Security Agency, the National Institute of Standards and Technology, the Department of Treasury, and the Department of Justice. (Sec. 3(a) and 3(b))
- The working group must analyze and explain technical and legal terms used in cyber insurance policies so customers can understand them better. (Sec. 3(c)(1)(B))
- The working group must analyze cyber insurance coverage for ransomware (malicious software that locks up data) and ransom payments, and develop recommendations. (Sec. 3(c)(1)(C))
- The working group must develop recommendations for customers on how to evaluate different types and levels of insurance coverage. (Sec. 3(c)(1)(E))
- Within one year of the working group's first meeting, the working group must submit a report to Congress with findings and recommendations. (Sec. 3(d))
- Within 90 days after the report is submitted, the Assistant Secretary must publish educational resources about cyber insurance on the National Telecommunications and Information Administration's public website. (Sec. 4(a) and 4(c))
##
What Changes
If this bill becomes law, a government working group will study cyber insurance and create public educational materials. Organizations and individuals buying cyber insurance will have access to government resources explaining insurance policies in simpler language. Insurance companies will receive recommendations on how to improve coverage options and communicate policy details more clearly to customers.
##
Important Definitions
- **Customer**: An individual or organization that buys cyber insurance.
- **Cyber incident**: Not fully defined in this bill; the bill refers to the definition in another federal law (section 3552(b) of title 44, United States Code).
- **Cyber insurance**: An insurance policy that covers losses, damages, and costs from cyberattacks, whether coverage is stated explicitly or not excluded.
- **Issuer**: An organization that sells cyber insurance.
- **Small business**: Not defined in this bill; the bill refers to the definition in the Small Business Act.
##
Effective Date
Not specified in bill text
II
118TH CONGRESS
1ST SESSION
S. 513
To require the Assistant Secretary of Commerce for Communications and
Information to establish a working group on cyber insurance, to require
dissemination of informative resources for issuers and customers of cyber
insurance, and for other purposes.
IN THE SENATE OF THE UNITED STATES
FEBRUARY 16, 2023
Mr. HICKENLOOPER (for himself and Mrs. CAPITO) introduced the following
bill; which was read twice and referred to the Committee on Commerce,
Science, and Transportation
A BILL
To require the Assistant Secretary of Commerce for Commu-
nications and Information to establish a working group
on cyber insurance, to require dissemination of inform-
ative resources for issuers and customers of cyber insur-
ance, and for other purposes.
Be it enacted by the Senate and House of Representa-
1
tives of the United States of America in Congress assembled,
2
SECTION 1. SHORT TITLE.
3
This Act may be cited as the ‘‘Insure Cybersecurity
4
Act of 2023’’.
5
SEC. 2. DEFINITIONS.
6
In this Act:
7
VerDate Sep 11 2014
04:33 Mar 07, 2023
Jkt 039200
PO 00000
Frm 00001
Fmt 6652
Sfmt 6201
E:\BILLS\S513.IS
S513
kjohnson on DSK79L0C42PROD with BILLS
2
•S 513 IS
(1) ASSISTANT SECRETARY.—The term ‘‘Assist-
1
ant Secretary’’ means the Assistant Secretary of
2
Commerce for Communications and Information.
3
(2) CUSTOMER.—The term ‘‘customer’’ means
4
an individual or organization that purchases cyber
5
insurance from an issuer.
6
(3) CYBER INCIDENT.—The term ‘‘cyber inci-
7
dent’’ has the meaning given the term ‘‘incident’’ in
8
section 3552(b) of title 44, United States Code.
9
(4) CYBER
INSURANCE.—Subject to section
10
3(c)(1)(A), the term ‘‘cyber insurance’’ means an in-
11
surance policy that, whether by explicit inclusion or
12
by lack of exclusion, offers coverage for losses, dam-
13
ages, and costs incurred due to cyber incidents.
14
(5) ISSUER.—The term ‘‘issuer’’ means an or-
15
ganization that issues cyber insurance.
16
(6) POLICY.—The term ‘‘policy’’ means a policy
17
for cyber insurance.
18
(7) SMALL BUSINESS.—The term ‘‘small busi-
19
ness’’ has the meaning given the term ‘‘small busi-
20
ness concern’’ in section 3 of the Small Business Act
21
(15 U.S.C. 632).
22
(8) WORKING
GROUP.—The term ‘‘working
23
group’’ means the working group established under
24
section 3(a).
25
VerDate Sep 11 2014
04:33 Mar 07, 2023
Jkt 039200
PO 00000
Frm 00002
Fmt 6652
Sfmt 6201
E:\BILLS\S513.IS
S513
kjohnson on DSK79L0C42PROD with BILLS
3
•S 513 IS
SEC. 3. WORKING GROUP ON CYBER INSURANCE.
1
(a) ESTABLISHMENT.—Not later than 90 days after
2
the date of enactment of this Act, the Assistant Secretary
3
shall establish a working group on cyber insurance.
4
(b) COMPOSITION.—
5
(1) MEMBERSHIP.—The working group shall be
6
composed of not less than 1 member from each of
7
the following:
8
(A) The Cybersecurity and Infrastructure
9
Security Agency.
10
(B) The National Institute of Standards
11
and Technology.
12
(C) The Department of the Treasury.
13
(D) The Department of Justice.
14
(2) CHAIRPERSON.—The Assistant Secretary
15
shall be the chairperson of the working group.
16
(c) ACTIVITIES.—
17
(1) IN
GENERAL.—The working group shall
18
carry out the following activities:
19
(A) For the purposes of the activities of
20
the working group, define the term ‘‘cyber in-
21
surance’’ in a manner that is different from the
22
definition of that term under section 2(4), if the
23
working group determines that such a modified
24
definition is necessary.
25
VerDate Sep 11 2014
04:33 Mar 07, 2023
Jkt 039200
PO 00000
Frm 00003
Fmt 6652
Sfmt 6201
E:\BILLS\S513.IS
S513
kjohnson on DSK79L0C42PROD with BILLS
4
•S 513 IS
(B) Analyze and explain in a manner most
1
understandable to customers the technical and
2
legal terminology commonly used in policies.
3
(C) Analyze, and develop recommendations
4
regarding, provisions in policies that relate to
5
ransomware and ransom payments made in re-
6
sponse to ransomware.
7
(D) Analyze and explain in a manner most
8
understandable to customers the terminology
9
used in policies to include or exclude coverage
10
for losses due to cyber incidents that are caused
11
by cyberterrorism or acts of war.
12
(E) Develop recommendations for prospec-
13
tive customers on ways to effectively evaluate
14
the types and levels of coverage offered under
15
a policy.
16
(F) Develop recommendations for issuers,
17
agents, and brokers regarding how to provide
18
and communicate policy provisions that are
19
clear and easy to understand for customers.
20
(G) Identify the constraints of issuers in
21
covering higher amounts of losses and new
22
cyber risk areas currently not covered, including
23
reputational damage and intellectual property
24
lost.
25
VerDate Sep 11 2014
04:33 Mar 07, 2023
Jkt 039200
PO 00000
Frm 00004
Fmt 6652
Sfmt 6201
E:\BILLS\S513.IS
S513
kjohnson on DSK79L0C42PROD with BILLS
5
•S 513 IS
(H) Gather input from issuers on what
1
measures would improve the ability of those
2
issuers to offer additional coverage under poli-
3
cies, including improvements to their actuarial
4
data, cyber risk data, and information sharing
5
mechanisms and effective measurement of the
6
cybersecurity practices of consumers.
7
(I) Identify the constraints of the market
8
and why more organizations do not use cyber
9
insurance as a risk response mechanism.
10
(J) Develop recommendations for cus-
11
tomers on how best to use cyber insurance as
12
a risk response mechanism for cyber risk and
13
incentives for doing so.
14
(2) CONSULTATION.—In carrying out the activi-
15
ties of the working group under paragraph (1), the
16
working group shall consult with the public in an
17
open and transparent manner, including by con-
18
sulting with the following stakeholders:
19
(A) Issuers.
20
(B) Insurance agents and brokers with ex-
21
perience in the sale and distribution of cyber in-
22
surance.
23
VerDate Sep 11 2014
04:33 Mar 07, 2023
Jkt 039200
PO 00000
Frm 00005
Fmt 6652
Sfmt 6201
E:\BILLS\S513.IS
S513
kjohnson on DSK79L0C42PROD with BILLS
6
•S 513 IS
(C) Representatives of business customers
1
from multiple sectors and representatives of
2
small businesses.
3
(D) Academia.
4
(E) State insurance regulators with exper-
5
tise regarding cybersecurity and cyber insur-
6
ance.
7
(F) Other individuals or entities with cy-
8
bersecurity and cyber insurance expertise as the
9
Assistant Secretary considers appropriate.
10
(d) REPORT.—Not later than 1 year after the date
11
on which the working group first convenes, the working
12
group shall submit to Congress a report regarding the ac-
13
tivities of the working group under subsection (c) and any
14
recommendations of the working group.
15
(e) TERMINATION.—The working group shall termi-
16
nate upon submission of the report required under sub-
17
section (d).
18
(f) RULE OF CONSTRUCTION.—Nothing in this sec-
19
tion shall be construed to—
20
(1) require adoption of the recommendations of
21
the working group; or
22
(2) provide any authority to any member of the
23
working group or any other individual to regulate
24
VerDate Sep 11 2014
04:33 Mar 07, 2023
Jkt 039200
PO 00000
Frm 00006
Fmt 6652
Sfmt 6201
E:\BILLS\S513.IS
S513
kjohnson on DSK79L0C42PROD with BILLS
7
•S 513 IS
the business of insurance that is not already pro-
1
vided under any other provision of law.
2
SEC. 4. DISSEMINATION OF INFORMATIVE RESOURCES FOR
3
CYBER INSURANCE STAKEHOLDERS.
4
(a) IN GENERAL.—Not later than 90 days after the
5
date on which the working group submits the report re-
6
quired under section 3(d), the Assistant Secretary shall
7
disseminate and make publicly available informative re-
8
sources for cyber insurance stakeholders.
9
(b) REQUIREMENTS.—The Assistant Secretary shall
10
ensure that the resources disseminated under subsection
11
(a)—
12
(1) incorporate the recommendations included
13
in the report submitted under section 3(d);
14
(2) are generally applicable and usable by a
15
wide range of cyber insurance stakeholders, includ-
16
ing issuers, agents, brokers, and customers; and
17
(3) include case studies and specific examples,
18
where appropriate.
19
(c)
PUBLICATION.—The
resources
disseminated
20
under subsection (a) shall be published on the public
21
website of the National Telecommunications and Informa-
22
tion Administration.
23
(d) OUTREACH.—The Assistant Secretary shall con-
24
duct outreach and coordination activities to promote the
25
VerDate Sep 11 2014
04:33 Mar 07, 2023
Jkt 039200
PO 00000
Frm 00007
Fmt 6652
Sfmt 6201
E:\BILLS\S513.IS
S513
kjohnson on DSK79L0C42PROD with BILLS
8
•S 513 IS
availability of the resources disseminated under subsection
1
(a) to relevant industry stakeholders and the general pub-
2
lic.
3
(e) VOLUNTARY USE.—Nothing in this section may
4
be construed to require the use of the resources dissemi-
5
nated under subsection (a).
6
Æ
VerDate Sep 11 2014
04:33 Mar 07, 2023
Jkt 039200
PO 00000
Frm 00008
Fmt 6652
Sfmt 6301
E:\BILLS\S513.IS
S513
kjohnson on DSK79L0C42PROD with BILLS