PolicyBrief
H.R. 807
119th CongressJan 28th 2025
Public and Private Sector Ransomware Response Coordination Act of 2025
IN COMMITTEE

This bill mandates a Treasury Department report evaluating and recommending improvements for public-private coordination in preventing and responding to ransomware attacks on financial institutions.

Zachary (Zach) Nunn
R

Zachary (Zach) Nunn

Representative

IA-3

LEGISLATION

Treasury to Review Ransomware Response Gaps: One-Year Deadline for New Financial Security Report

The Public and Private Sector Ransomware Response Coordination Act of 2025 orders the Secretary of the Treasury to conduct a deep dive into how the government and banks talk to each other when hackers hold financial data hostage. Within one year, the Treasury must deliver a comprehensive report to Congress detailing the current state of public-private teamwork, the speed of information sharing, and whether existing laws actually help or hinder the prosecution of cybercriminals. This isn't just a paperwork exercise; it specifically requires an analysis of why some financial institutions might be dragging their feet or withholding information after an attack. Following the report, the Treasury has 15 months to brief Congress on how to fix the cracks in the system.

The Digital Paper Trail

This bill focuses heavily on the 'utility' of information. Right now, when a bank gets hit by ransomware, they have to report it, but this bill asks a blunt question: Is that data actually helping anyone? Section 2 requires the Treasury to evaluate if law enforcement and intelligence agencies are getting 'timely access' to these reports and if the information is actually useful for 'preventing, investigating, or prosecuting' an attack. For the average person, this matters because if your local credit union or investment platform gets locked down, the speed at which the government can step in depends entirely on these communication channels. The bill looks to identify if we need new legislation to force better data sharing or if the current system just needs a tune-up.

Breaking the Silence

One of the most interesting parts of this bill is its focus on why banks stay quiet. Under Section 2, the Treasury must investigate the 'extent to which, and reasons why' financial institutions delay reporting attacks. In the real world, a company might hesitate to report a breach to avoid a PR nightmare or a drop in stock price. By digging into these delays, the bill aims to create a more transparent environment where security takes priority over optics. It also brings 'Cybersecurity and ransomware incident response entities'—the digital SWAT teams that banks hire—into the conversation, requiring the Treasury to include their feedback on how to improve response times and policy.

Mapping the Future of Financial Safety

While this bill doesn't immediately change how your bank operates, it sets the stage for major shifts in policy. The 'Medium' level of vagueness here comes from terms like 'timely access' and 'useful information,' which will be defined by the Treasury's findings. Depending on what the report uncovers, we could see future laws that mandate stricter reporting deadlines or more aggressive public-private partnerships. The goal is to move from a reactive 'oops, we got hacked' stance to a proactive defense system. By requiring specific policy recommendations and a congressional briefing, the bill ensures that the findings don't just sit on a shelf but actually lead to a more resilient financial sector.