The Data Infrastructure Risk Reduction Act would direct the Secretary of Homeland Security, through the Cybersecurity and Infrastructure Security Agency and in consultation with the Secretary of Defense as appropriate, to develop a strategy for protecting certain data centers and the communities around them. Within 180 days of enactment, DHS would be required to identify which data centers should be treated as critical infrastructure and to assess the security of related power and water systems, with particular attention to above-ground transmission lines and electrical substations.
The bill also requires DHS to consider the risks posed when data centers are located near communities or residential areas, and to submit to Congress a strategy with recommendations for defending data centers against external breaches and protecting nearby communities. The measure is framed as a federal planning and coordination requirement rather than a direct regulatory program or funding authorization.
Impact
If enacted, the bill would add a new federal mandate for DHS/CISA to study and report on data center security and adjacent community risks, potentially influencing how data centers are classified and protected under federal critical infrastructure policy. It would not itself impose operational security standards, but it could shape future federal guidance, interagency coordination, and possible legislative or regulatory action affecting data center operators, utilities, and local communities near large facilities.
Sentiment
The available record suggests a generally precautionary and security-focused posture toward the bill, with the measure being referred to the House Committee on Homeland Security and then to the Subcommittee on Cybersecurity and Infrastructure Protection. No votes or committee transcript excerpts are available, so there is no recorded floor debate or formal opposition in the provided materials. Overall, the bill appears to be presented as a proactive infrastructure protection measure.
Contention
The main policy issues embedded in the bill are whether data centers should be treated as critical infrastructure, how far federal responsibility should extend into the security of associated power and water systems, and how to balance data center siting with protections for nearby residential communities. Potential points of contention include the scope of DHS authority, the inclusion of above-ground transmission lines and substations in the assessment, and whether the federal government should focus on cybersecurity, physical security, or land-use/community impacts. No specific opposing members or stakeholder positions are identified in the provided context.