Strengthening Cyber Resilience Against State-Sponsored Threats Act
HB2659, titled the Strengthening Cyber Resilience Against State-Sponsored Threats Act, would create a joint interagency task force led by the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA), with the FBI as vice chair, to coordinate federal efforts against cybersecurity threats to U.S. critical infrastructure posed by state-sponsored cyber actors from the People’s Republic of China, especially Volt Typhoon. The task force would bring together relevant sector risk management agencies and other federal partners to align detection, analysis, and response efforts, and it could coordinate with existing task forces or intelligence efforts to avoid duplication.
The bill also requires the task force to produce an initial report and then annual reports for five years, along with classified briefings to Congress. Those reports must assess sector-specific risks, tactics and techniques used by the threat actors, needed resources and authorities, potential disruption to critical infrastructure and the armed forces in a crisis or conflict, economic and social impacts, and recommendations for improving detection and mitigation. It also requires a one-time awareness campaign for critical infrastructure owners and operators and mandates that unclassified executive summaries be published publicly on DHS’s website.
The bill would not directly regulate private entities or amend existing cybersecurity standards, but it would add a new federal coordination and reporting structure within DHS/CISA and related agencies. It directs information sharing among DHS, CISA, DOJ, FBI, and sector risk management agencies, while exempting the task force from the Federal Advisory Committee Act and the Paperwork Reduction Act. In practical terms, it would expand federal interagency coordination, formalize congressional oversight, and likely influence future cybersecurity policy, resource allocation, and guidance for critical infrastructure owners and operators.
The bill appears to have broad bipartisan support. It passed the House overwhelmingly by a vote of 400-8 under suspension of the rules, indicating strong agreement on the need to address Chinese state-sponsored cyber threats to critical infrastructure. The available context shows no committee transcript debate, and the Senate referral suggests the measure was treated as a serious national security and cybersecurity response rather than a partisan issue.
The main substantive issue is the focus on the People’s Republic of China and Volt Typhoon, which may raise concerns about attribution, intelligence sensitivity, and the scope of classified reporting. The bill also requires extensive classified assessments about potential disruption to infrastructure, military mobility, and crisis scenarios, which could be viewed as broad or sensitive in scope. Any contention would likely center on whether the task force duplicates existing efforts, how much authority and information sharing should be required, and whether the reporting requirements are sufficiently actionable without imposing unnecessary bureaucracy.