WASHINGTON, DC – U.S. Senators Gary Peters (D-MI), Ranking Member of the Senate Homeland Security and Governmental Affairs Committee, and Rob Portman (R-OH) introduced bipartisan legislation to promote stronger cybersecurity coordination between the Department of Homeland Security (DHS) and state and local governments to safeguard against cyber threats. The State and Local Government Cybersecurity Act would encourage national cybersecurity watchdogs to share information regarding cybersecurity threats, vulnerabilities, breaches and resources to prevent and recover from cyber-attacks with states and localities who are increasingly targeted by bad actors.
“State and local governments are responsible for safeguarding everything from election systems to an increasing amount of sensitive personal data – from social security numbers and credit card information to detailed medical records,” said Senator Peters. “Despite being targeted by hackers and bad actors, states and local communities don’t always have access to the resources and expertise needed to protect your information from a breach. This bill will help strengthen coordination between federal cybersecurity professionals and state and local governments to address emerging threats and help keep Americans’ information safe.”
“Hackers with malicious intent can and do attack state and local cyber infrastructure consistently. Sometimes, state and local governments need some additional help or access to expertise to mitigate these threats,” said Senator Portman. “This bill will strengthen an existing relationship between the Department of Homeland Security and state and local partners to improve coordination and information sharing to help protect our IT infrastructure at all levels of government.”
“The Center for Internet Security commends Senators Peters and Portman for introducing the State and Local Government Cybersecurity Act of 2019. This important legislation will help to enhance the cybersecurity infrastructure of U.S. state, local, tribal, and territorial governments, which is consistently reported as their least proficient capability,” said John Gilligan, Center for Internet Security, Inc. (CIS®) CIS President and CEO. “We also applaud DHS’ continued leadership role in improving our country’s cybersecurity.”
“Every day our state and local government networks experience millions of intrusion attempts by those looking to do harm,” said Chris DeRusha, Chief Security Officer for the State of Michigan. “This bill will help the state of Michigan access resources, tools and expertise developed by Federal government and national cybersecurity experts, which will enhance the security of the information Michiganders have entrusted us to keep safe.”
“This cooperation with federal, state, and local agencies will advance our abilities to fight off cyber threats,” said Mark A. Hackel, Macomb County Executive. “In Macomb County, we have been working diligently with our academic partners to train the next generation cybersecurity professional to stay ahead of vulnerabilities and cyber breaches. This next step in collaboration will ensure that knowledge-sharing occurs at all levels of government and is key to our defense against attacks.”
In recent years, several state and local governments have been targeted by high-profile cyber-attacks, costing taxpayers millions of dollars and threatening the data privacy of millions of Americans. Hackers have exposed cybersecurity vulnerabilities in the city of Atlanta and at the Colorado Department of Transportation, and more recently seized control over parts of the computer systems for the City of Baltimore. State and local governments are an attractive target because they possess a broad array of information about their citizens but often do not have the tools to adequately safeguard their systems. Financial constraints, limited resources and outdated equipment can all hinder local governments’ efforts to safeguard the personal data they collect.
The Multi-State Information Sharing and Analysis Center (MS-ISAC) works with DHS’s 24-hour watch floor, the National Cybersecurity and Communications Integration Center (NCCIC) to coordinate information sharing and help states and localities stay on top of emerging and evolving cyber threats. MS-ISAC’s membership includes all 50 states and 6 territories.
The State and Local Government Cybersecurity Act would facilitate coordination between DHS and state and local governments in several key areas. The legislation would permit the NICCIC to provide guidance and training, upon request, to state and local governments on combatting cybersecurity threats and safeguarding critical infrastructure. The bill authorizes the NCCIC to provide state and local actors with access to improved security tools, policies and procedures, and encourages collaboration for the effective implementation of those resources, including the ability to conduct joint cyber exercises to test cybersecurity systems. The legislation would also build on previous efforts by the MS-ISAC that identified Russian attempts to interfere in American elections systems, and strengthen collaboration to prevent, protect, and respond to future cybersecurity incidents. These changes would support the cybersecurity needs of election officials and their staffs, providing access to hardware and software products that will allow states and localities to bolster their cyber defenses.