Small Business Cyber Resiliency Act
A BILL
To help small businesses prepare for and combat cybersecurity threats, and for other purposes.
Sec. 2 Small business cybersecurity
“49. Small business cybersecurity
“(a) Definitions—In this section:
“(1) Cybersecurity risk; cyber threat indicator; defensive measure; incident—The terms cybersecurity risk, cyber threat indicator, defense measure, and incident have the meanings given those terms in section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650).
“(2) Resource partner—The term resource partner means—
“(A) a small business development center;
“(B) a women’s business center described in section 29; and
“(C) a chapter of the Service Corps of Retired Executives described in section 8(a)(1)(A).
“(b) Interagency agreement—The Administration shall enter into an interagency agreement with the Cybersecurity and Infrastructure Security Agency to collaborate and increase information sharing with the Administration to improve cybersecurity resources and defenses for small business concerns, including cybersecurity products tailored to the needs of small business concerns.
“(c) Assistance through resource partners
“(1) In general—The Department of Homeland Security, and any other Federal agency in coordination with the Department of Homeland Security, shall leverage resource partners to provide assistance to small business concerns with cybersecurity tools, such as the Cyber Security Evaluation Tool and the Cyber Resilience Review, and by disseminating information relating to cybersecurity risks and other homeland security matters to help small business concerns in developing or enhancing cybersecurity infrastructure, awareness of cyber threat indicators, cybersecurity incident response planning, and cyber training programs for employees.
“(2) Annual publication—Not later than 1 year after the date of enactment of the Small Business Cyber Resiliency Act and annually thereafter, the Administrator shall publish on the website of the Administration the number of small business concerns that resource partners assisted in providing assistance described in paragraph (1) during the year covered by the publication.
“(d) Central small business cybersecurity assistance unit
“(1) Establishment—The Administrator, in coordination with the Secretary of Commerce, and in consultation with the Secretary of Homeland Security and the Attorney General, shall establish a central small business cybersecurity assistance unit within the Administration, which shall serve as a central clearinghouse for cybersecurity resources for small business concerns across the Federal Government, such as those developed by the Department of Homeland Security.
“(2) Duties—The central small business cybersecurity assistance unit established under paragraph (1) shall—
“(A) coordinate internal cybersecurity efforts within the Administration to reduce duplication of effort and resources;
“(B) establish and maintain a publicly available website that is a clearinghouse of cybersecurity information for small business concerns, including information on—
“(i) how to find guidance material on best cyber hygiene practices;
“(ii) where to report cybersecurity breaches or incidents;
“(iii) how to respond to cybersecurity breaches or incidents;
“(iv) the cybersecurity efforts of the Administration;
“(v) how to contact the certified employees described in section 21(o); and
“(vi) standard incident response procedures for leading cyber crimes;
“(C) work with the certified employees described in section 21(o) to provide cybersecurity assistance to small business concerns;
“(D) coordinate with the Department of Homeland Security and any other Federal agency as the Administrator determines appropriate to identify and disseminate cybersecurity information and resources to small business concerns in a form that is accessible and actionable by small business concerns;
“(E) redirect small business cybersecurity inquiries, such as reporting of cyber threat indicators and defensive measures, to the appropriate Federal agencies;
“(F) coordinate with the National Institute of Standards and Technology to identify and disseminate information to small business concerns on the most cost-effective methods for implementing elements of the cybersecurity framework of the National Institute of Standards and Technology applicable to improving the cybersecurity posture of small business concerns;
“(G) coordinate with the Department of Defense to identify and disseminate information to small business concerns on satisfying the applicable requirements of the Cybersecurity Maturity Model Certification of the Department of Defense or any other successor cybersecurity requirements as established by the Department of Defense; and
“(H) seek input from the Office of Advocacy of the Administration to identify any policies or procedures adopted by any department, agency, or instrumentality of the Federal Government that will hamper the improvement of the cybersecurity posture of those small business concerns.
“(3) Enhanced cybersecurity protections for small businesses
“(A) In general—Notwithstanding any other provision of law, no cause of action shall lie or be maintained in any court against any small business concern, and such action shall be promptly dismissed, if such action is related to or arises out of—
“(i) any activity authorized under this paragraph or the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501 et seq.); or
“(ii) any action or inaction in response to any cyber threat indicator, defensive measure, or other information shared or received pursuant to this paragraph or the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501 et seq.).
“(B) Rule of construction—Nothing in this paragraph shall be construed to affect the applicability or merits of any defense, motion, or argument in any cause of action in a court brought against an entity that is not a small business concern.
“(e) Report
“(1) In general—Not later than 1 year after the date of enactment of the Small Business Cyber Resiliency Act, and every year thereafter, the Administrator and the head of each Federal agency that collects or shares information under this section shall submit to the Committee on Small Business and Entrepreneurship of the Senate and the Committee on Small Business of the House of Representatives a joint report on actions taken by the Administration and relevant Federal agencies to protect personally identifiable information, business identifiable information, sensitive financial information, and cybersecurity information received by those Federal agencies as a result of the requirements under this section.
“(2) Form—Each report required under paragraph (1) shall be unclassified, but may include a classified annex.”