Skip to main content
S. 245 Senate Science, Technology, Communications

Insure Cybersecurity Act of 2025

Introduced
Jan 24, 2025
Sponsor
Sen. Hickenlooper, John W. (D-CO)
View on Congress.gov (opens in a new tab)

STAGE 3 OF 8 — CALENDARS AND SCHEDULING

Currently in the Senate. Last action: placed on senate legislative calendar under general orders. calendar no. 90 on Jun 9, 2025.

  1. Senate Introduced in Senate Jan 24, 2025
  2. Senate Read twice and referred to the Committee on Commerce, Science, and Transportation. Jan 24, 2025
  3. Senate Committee on Commerce, Science, and Transportation. Ordered to be reported without amendment favorably. Feb 5, 2025
  4. Senate Committee on Commerce, Science, and Transportation. Reported by Senator Cruz without amendment. With written report No. 119-28. Jun 9, 2025
  5. Senate Placed on Senate Legislative Calendar under General Orders. Calendar No. 90. Jun 9, 2025

Cosponsors

1

Subjects

Advisory bodiesComputer security and identity theftComputers and information technologyCongressional oversightConsumer affairsGovernment information and archivesGovernment studies and investigationsInsurance industry and regulationPublic-private cooperation

Committees

  • Commerce, Science, and Transportation Committee
    • [Reported By, Jun 9, 2025]
    • [Markup By, Feb 5, 2025]
    • [Referred To, Jan 24, 2025]

Summary

Insure Cybersecurity Act of 2025

This bill requires the National Telecommunications and Information Administration (NTIA) to establish a working group on cyber insurance policies. Under the bill, these are defined as policies that offer coverage for losses, damages, and costs incurred due to cyberattacks and related incidents.

The working group is directed to analyze and address issues in the cyber insurance market facing both insurers and their customers. Specifically, the working group must develop information for customers on how to effectively evaluate policy options, and for insurers on how to clearly communicate with customers regarding policy provisions.

Additionally, the working group is directed to analyze and explain in layman’s terms

  • terminology commonly used in cyber insurance policies, including terminology used to include or exclude coverage for losses from cyber incidents;
  • how common policy provisions correspond to cyber incidents and potential responses, including ransomware and potential ransom payments; and
  • constraints faced by insurers in covering higher losses in cyber risk areas, such as reputational damage and loss of intellectual property.

At the conclusion of the working group's term, NTIA must publish and disseminate informative resources for cyber insurance stakeholders, including any recommendations formulated by the working group.  

[Summary as of: Introduced in Senate]

Comments · 0

Loading...

Loading comments...