Widespread Information Management for the Welfare of Infrastructure and Government Act
HB5079 reauthorizes and updates the Cybersecurity Act of 2015 through 2035. The bill revises definitions and authorities in the existing federal cyber information-sharing framework to account for artificial intelligence, critical infrastructure, sector risk management agencies, operational technology, edge devices, and internet of things devices. It also expands and modernizes federal procedures for sharing cyber threat indicators and defensive measures, including updated policies, guidance, and technical assistance.
The bill places greater emphasis on rapid, practical information sharing between the federal government and non-federal entities, especially state, local, tribal, and territorial governments and owners and operators of non-federal critical infrastructure. It directs the Department of Homeland Security and the Attorney General to update policies and outreach efforts, requires briefings to Congress on outreach implementation, and adds reporting on threats such as ransomware and prepositioning activities. It also clarifies that the cybersecurity-sharing authorities may use artificial intelligence when it is developed or deployed strictly for cybersecurity purposes.
The bill would amend multiple provisions of the Cybersecurity Act of 2015 and related Homeland Security Act definitions, extending the law’s effective period from 2025 to 2035. It would broaden the statutory framework for cyber threat information sharing, update federal reporting and outreach requirements, and expand the scope of covered infrastructure and technologies, including AI, industrial control systems, edge devices, and IoT devices. The changes would affect federal agencies, sector risk management agencies, and public and private critical infrastructure owners by increasing expectations for coordination, dissemination, and participation in cyber threat sharing programs.
The available voting history shows strong bipartisan or at least unanimous committee support: the bill was ordered reported by a 25-0 vote. No committee transcript is provided, but the text and context suggest a generally favorable view of the bill as a modernization and reauthorization measure. The emphasis on updating existing authorities, improving outreach, and addressing current threats such as ransomware and AI appears designed to build broad support across security and infrastructure stakeholders.
No specific objections are reflected in the provided materials, and the unanimous committee vote suggests limited visible contention at markup. The main policy choices embedded in the bill are the expansion of information-sharing authorities, the inclusion of artificial intelligence in cybersecurity operations, and the broader reach to critical infrastructure sectors and smaller operators. Potential points of concern, though not documented in the record provided, could include privacy, operational burden on non-federal entities, and the scope of federal authority over information sharing and AI-enabled cybersecurity tools.