New legislation would boost the FTC's role in fighting ransomware
Full article645 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Congress is looking for ways to help agencies take on the growing threat.
A new bill could direct the Federal Trade Commission’s international efforts towards taking on ransomware.
Rep. Gus Bilirakis (R-Fla.), the top Republican on the House Energy and Commerce consumer protection subcommittee, filed legislation Tuesday that would require the agency to report the number of ransomware and cyberattack-related complaints it receives, and how it cooperated with international law enforcement to respond to those issues.
The new text would update a 2006 law enabling the agency to work with foreign law enforcement agencies on consumer protection issues. Under the amended law, the FTC would also be charged with providing recommendations for legislation and best practices to mitigate and defend against ransomware.
The FTC has always played a role in trying to mitigate data breaches and online fraud, including the enforcement of privacy policies and pursuing companies like Equifax for failing to take basic security precautions. It has in the past also offered resources to small businesses on how to prevent ransomware attacks.
But unlike the Justice Department and FBI, the FTC focuses on civil, not criminal cases. Until now, its international cooperation has largely focused on consumer protection efforts against call fraud and online scams. The new legislation could tilt those resources more heavily towards ransomware.
The proposal is just one of several lawmakers are pushing to help boost the resources of executive agencies to address the rise in ransomware attacks against U.S. companies, schools, local governments and hospitals. Since May, U.S. officials have faced three high profile ransomware attacks against fuel provider Colonial Pipeline, meat supply company JBS, and most recently Florida IT company Kaseya.
Other legislation to fortify the federal response to ransomware includes a bill introduced by Sen. Mark Warner (D-Va.) Wednesday that would require critical infrastructure owners, federal contractors and cyber response firms to notify the Department of Homeland Security’s cybersecurity agency within 24 hours of a cyber incident. Legislation that would give the Department of Energy more authority to coordinate responses to cybersecurity threats to fuel pipelines and natural gas has also been introduced.
An interagency task force convened by the White House is also pursuing an array of policy measures, including enforcing regulations against the digital currencies that cybercriminals use to collect extortion payments. A senior White House official said that agencies are exploring what they can do within existing regulations and mandates but that additional authorities aren’t out of the question.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/ftc-congress-oversight-ransomware/