Search

Search bills, members, committees and pages...

H.R. 5079

U.S. HouseIn House Committee

Summary

H.R. 5079, the Widespread Information Management for the Welfare of Infrastructure and Government Act, was introduced in the House on Sep 2, 2025 by Rep. Andrew Garbarino (R) with 1 co-sponsor. It last saw action on Sep 3, 2025: Ordered to be Reported (Amended) by the Yeas and Nays: 25 - 0.


Record

Text

H.R. 5079 has 1 co-sponsor.

hb5079/introduced-in-house.txt
119 HR 5079 IH: Widespread Information Management for the Welfare of Infrastructure and Government Act
U.S. House of Representatives
2025-09-02
text/xml
EN
Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.
I 119th CONGRESS 1st Session H. R. 5079 IN THE HOUSE OF REPRESENTATIVES September 2, 2025 Mr. Garbarino (for himself and Mr. McCaul ) introduced the following bill; which was referred to the Committee on Homeland Security , and in addition to the Committees on Oversight and Government Reform , Intelligence (Permanent Select) , Energy and Commerce , Armed Services , and the Judiciary , for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned A BILL
To reauthorize the Cybersecurity Act of 2015, and for other purposes.
1.
Short title
This Act may be cited as the Widespread Information Management for the Welfare of Infrastructure and Government Act .
2.
Reauthorization of Cybersecurity Act of 2015
(a)
In general
The Cybersecurity Act of 2015 ( 6 U.S.C. 1501 et seq. ; enacted as division N of the Consolidated Appropriations Act, 2016; Public Law 114–113 ) is amended—
(1)
in section 102 ( 6 U.S.C. 1501 ; relating to definitions)—
(A)
by redesignating paragraphs (4), (5), (6), (7), (8), (9), (10), (11), (12), (13), (14), (15), (16), (17), and (18) as paragraphs (6), (7), (8), (9), (10), (11), (12), (13), (14), (15), (16), (17), (19), (20), and (21), respectively;
(B)
by inserting after paragraph (3) the following new paragraphs:
(4)
Artificial intelligence
The term artificial intelligence has the meaning given such term in section 5002 of the National Artificial Intelligence Initiative Act of 2020 ( 15 U.S.C. 9401 ).
(5)
Critical infrastructure
The term critical infrastructure has the meaning given such term in section 1016(e) of Public Law 107–56 ( 42 U.S.C. 5195c(e) ).
; and
(C)
by inserting after paragraph (17), as so redesignated, the following new paragraph:
(18)
Sector Risk Management Agency
The term Sector Risk Management Agency has the meaning given such term in section 2200 of the Homeland Security Act of 2002 ( 6 U.S.C. 650 ).
;
(2)
in section 103 ( 6 U.S.C. 1502 ; relating to sharing of information by the Federal Government)—
(A)
in subsection (a), in the matter preceding paragraph (1), by striking develop and issue and inserting develop, issue, and, as appropriate, update ;
(B)
in subsection (b)—
(i)
in paragraph (1)—
(I)
in the matter preceding subparagraph (A), by inserting and, as appropriate, updated, after developed ;
(II)
by amending subparagraph (A) to read as follows:
(A)
ensure the Federal Government maintains the capability to provide technical assistance, on a voluntary basis, to non-Federal entities in utilizing cyber threat indicators and defensive measures for cybersecurity purposes;
;
(III)
in subparagraph (E)(ii), by striking and after the semicolon;
(IV)
in subparagraph (F), by striking the period and inserting ; and ; and
(V)
by adding at the end the following new subparagraph:
(G)
pursuant to section 2212 of the Homeland Security Act of 2002 ( 6 U.S.C. 662 ), provide one-time read-ins, as appropriate, to select individuals identified by non-Federal entities that own or operate critical infrastructure;
; and
(ii)
in paragraph (2)—
(I)
by inserting and, as appropriate, updating, after developing ; and
(II)
by inserting and defensive measures after promote the sharing of cyber threat indicators ; and
(C)
in subsection (c)—
(i)
by inserting and not later than 60 days after any update, as appropriate, of procedures required by subsection (a), after Act, ; and
(ii)
by inserting (or update, as appropriate) after procedures ;
(3)
in section 104 ( 6 U.S.C. 1503 ; relating to authorizations for preventing, detecting, analyzing, and mitigating cybersecurity threats)—
(A)
in subsection (c)—
(i)
in paragraph (1), by inserting , including Sector Risk Management Agencies that are agencies and the majority of the systems of which are not covered under subsection (d) or (e) of section 3553 of title 44, United States Code, after Federal Government ;
(ii)
in paragraph (3)—
(I)
in the matter preceding subparagraph (A), by striking shall be and inserting may be ;
(II)
in subparagraph (A), by striking or after the semicolon;
(III)
in subparagraph (B), by striking the period and inserting ; or ; and
(IV)
by adding at the end the following new subparagraph:
(C)
to preclude the use of artificial intelligence that is developed or strictly deployed for cybersecurity purposes in carrying out the activities authorized under paragraph (1).
; and
(iii)
in subparagraph (B) of subsection (d)(2), by inserting , which may utilize artificial intelligence that is developed or strictly deployed for cybersecurity purposes, after technical capability ;
(4)
in section 105 ( 6 U.S.C. 1504 ); relating to sharing of cyber threat indicators and defensive measures with the Federal Government—
(A)
in subsection (a)—
(i)
in paragraph (2), by adding at the end the following new sentences: As appropriate, the Attorney General and the Secretary of Homeland Security shall, in consultation with the heads of the appropriate Federal entities, jointly update such policies and procedures, and issue and make publicly available such updated policies and procedures. Such updates shall prioritize rapid dissemination to State, local, Tribal, and territorial governments and owners and operators of non-Federal critical infrastructure of relevant and actionable cyber threat indicators and defensive measures. ;
(ii)
in paragraph (3), in the matter preceding subparagraph (A), by striking developed or issued and inserting developed, issued, or, as appropriate, updated, ; and
(iii)
in paragraph (4)—
(I)
in subparagraph (A), by adding at the end the following new sentence: As appropriate, the Attorney General and the Secretary of Homeland Security shall jointly update and make publicly available such guidance to so assist entities and promote such sharing of cyber threat indicators and defensive measures with such Federal entities under this title. ; and
(II)
in subparagraph (B), in the matter preceding clause (i), by inserting and, as appropriate, updated, after developed ;
(B)
in subsection (b)—
(i)
in paragraph (2)(B), by inserting , and, as appropriate, update, after review ; and
(ii)
in paragraph (3), in the matter preceding subparagraph (A), by inserting and, as appropriate, updated, after required ;
(C)
in subsection (c)—
(i)
in paragraph (1)(D), by inserting , including if such capability and process employs artificial intelligence before the semicolon;
(ii)
in paragraph (2), by adding at the end the following new subparagraph:
(C)
Outreach
Not later than 90 days after the date of the enactment of this subparagraph, the Secretary of Homeland Security shall develop and continuously implement an outreach plan, including targeted engagement, to ensure Federal and non-Federal entities, particularly small or rural owners or operators of critical infrastructure which often lack dedicated cybersecurity staff but remain vital to national security—
(i)
are aware of the capability and process required by paragraph (1) to share cyber threat indicators and defensive measures, including the benefits real-time information sharing provides;
(ii)
understand how to share cyber threat indicators and defensive measures;
(iii)
understand the obligation to remove certain personal information in accordance with section 104(d)(7) prior to sharing a cyber threat indicator;
(iv)
understand how cyber threat indicators and defensive measures are received, processed, used, and protected;
(v)
understand the protections they are afforded in sharing any cyber threat indicators and defensive measures; and
(vi)
can provide feedback to the Secretary when policies, procedures, and guidelines that are unclear or unintentionally prohibitive to sharing cyber threat indicators and defensive measures.
; and
(iii)
by adding at the end the following new subparagraph:
(D)
Briefings on outreach
The Secretary of Homeland Security shall annually provide to the Committee on Homeland Security of the House of Representatives and the Committee on Homeland Security and Governmental Affairs of the Senate a briefing on the implementation of outreach pursuant to subparagraph (B).
; and
(D)
in subsection (d)—
(i)
in paragraph (1), by inserting copyright or before trade secret protection ; and
(ii)
in paragraph (5)(A),
(I)
in clause (iv), by striking or after the semicolon;
(II)
in clause (v)(III), by striking the period and inserting ; or ; and
(III)
by adding at the end the following new clause:
(vi)
the purpose of rapidly providing other Federal entities, including Sector Risk Management Agencies, awareness of a cybersecurity threat that may impact the information systems of such Agencies.
;
(5)
in section 108 ( 6 U.S.C. 1507 ; relating to construction and preemption)—
(A)
in subsection (c)—
(i)
in the matter preceding paragraph (1), by striking shall be and inserting may be ;
(ii)
in paragraph (2), by striking or after the semicolon;
(iii)
in paragraph (3), by striking the period and inserting ; or ; and
(iv)
by adding at the end the following new paragraph:
(4)
to preclude the use of artificial intelligence that is developed or strictly deployed for cybersecurity purposes in carrying out activities authorized by this title.
; and
(B)
in subsection (f)—
(i)
in paragraph (3)—
(I)
by inserting to share cyber threat indicators or defensive measures after relationship ; and
(II)
by striking or after the semicolon;
(ii)
in paragraph (4), by striking the period and inserting ; or ; and
(iii)
by adding at the end the following new paragraph:
(5)
to limit or modify, notwithstanding any other provision of law, the authorization to share pursuant to section 104(c)(1) with Sector Risk Management Agencies described in such section.
;
(6)
in section 109 ( 6 U.S.C. 1508 ; relating to report on cybersecurity threats)—
(A)
in subsection (a)—
(i)
by inserting and not later than September 30 of every two years thereafter, after Act, ;
(ii)
by inserting the Secretary of Homeland Security and after in coordination with ;
(iii)
by inserting and the Committee on Homeland Security and Governmental Affairs before of the Senate ;
(iv)
by inserting and the Committee on Homeland Security before of the House ; and
(v)
by inserting prepositioning activities, ransomware, after attacks, ; and
(B)
in subsection (b)—
(i)
in paragraph (1), by inserting prepositioning activities, ransomware, after attacks, ;
(i)
in paragraph (2), by inserting prepositioning activity, ransomware, after attack, ;
(i)
in paragraph (3), by inserting prepositioning activities, ransomware, after attacks, each place it appears; and
(i)
in paragraph (4), by inserting prepositioning activities, ransomware, after attacks, ; and
(7)
in section 111(a) ( 6 U.S.C. 1510(a) , relating to effective period), by striking 2025 and inserting 2035 .
(b)
Conforming amendments
Section 2200 of the Homeland Security Act of 2002 ( 6 U.S.C. 650 ; relating to definitions) is amended—
(1)
in paragraph (5)—
(A)
in subparagraph (B), by inserting or compromising after defeating ;
(B)
in subparagraph (C), by inserting including a security vulnerability affecting an information system or a technology included in the critical and emerging technologies list of the Office of Science and Technology Policy or successor list, such as artificial intelligence (as such term is defined in section 5002 of the National Artificial Intelligence Initiative Act of 2020 ( 15 U.S.C. 9401 )), which may be in a Federal entity’s or non-Federal entity’s software or hardware supply chain, after security vulnerability, ;
(C)
in subparagraph (D), by inserting or compromise after defeat ; and
(D)
in subparagraph (F), by inserting or compromised after exfiltrated ;
(2)
in paragraph (14), by amending subparagraph (B) to read as follows:
(B)
includes, in accordance with section 104(d)(2) of the Cybersecurity Sharing Act of 2015 ( 6 U.S.C. 1503(d)(2) )—
(i)
operational technology, including industrial control systems, such as supervisory control and data acquisition systems, distributed control systems, and programmable logic controllers;
(ii)
edge devices; and
(iii)
internet of things devices, including digital and physical infrastructure impacted by ransomware.
; and
(3)
in paragraph (25), by inserting or compromise after defeat .

Tracker

The tracker indicates the progress of this legislation as it moves through the legislative process.

  1. Introduced2025-09-02
  2. Passed House
  3. Passed Senate
  4. Conference
  5. To President
  6. Became Law

To reauthorize the Cybersecurity Act of 2015, and for other purposes.

Sponsors

Rep. Andrew Garbarino (R) sponsors H.R. 5079, and 1 member has co-sponsored it from the day it was introduced.

Committees

H.R. 5079 went before 7 committees: Homeland Security, Cybersecurity and Infrastructure Protection Subcommittee, Judiciary, Armed Services, Energy and Commerce, Intelligence (Permanent Select) and Oversight and Government Reform.

Homeland Security
Homeland Security
Markup By · Sep 3, 2025 · 6 Bills
Cybersecurity and Infrastructure Protection Subcommittee
Cybersecurity and Infrastructure Protection Subcommittee
Referred to · Sep 2, 2025 · 13 Bills
Judiciary
Judiciary
Referred To · Sep 2, 2025 · 2,181 Bills
Armed Services
Armed Services
Referred To · Sep 2, 2025 · 581 Bills
Energy and Commerce
Energy and Commerce
Referred To · Sep 2, 2025 · 1,636 Bills
Intelligence (Permanent Select)
Intelligence (Permanent Select)
Referred To · Sep 2, 2025 · 6 Bills
Oversight and Government Reform
Oversight and Government Reform
Referred To · Sep 2, 2025 · 696 Bills

Actions

H.R. 5079 has taken 6 actions since Sep 2, 2025, the latest on Sep 3, 2025.

ChamberAction
Sep 3, 2025
House
Subcommittee on Cybersecurity and Infrastructure Protection DischargedHomeland Security Committee
Sep 3, 2025
House
Committee Consideration and Mark-up Session HeldHomeland Security Committee
Sep 3, 2025
House
Ordered to be Reported (Amended) by the Yeas and Nays: 25 - 0.Homeland Security Committee
Sep 2, 2025
House
Introduced in House
Sep 2, 2025
House
Referred to the Committee on Homeland Security, and in addition to the Committees on Oversight and Government Reform, Intelligence (Permanent Select), Energy and Commerce, Armed Services, and the Judiciary, for a period to be subsequently determined by the Speaker, in each case for consideration of such provisions as fall within the jurisdiction of the committee concerned.Homeland Security Committee

Votes

H.R. 5079 has not gone to a roll call.

Titles

H.R. 5079 goes by 3 titles, 1 of them short titles.

  • Widespread Information Management for the Welfare of Infrastructure and Government Act — Display Title
  • Widespread Information Management for the Welfare of Infrastructure and Government Act — Short Title(s) as Introduced
  • To reauthorize the Cybersecurity Act of 2015, and for other purposes. — Official Title as Introduced

Cost estimate

The Congressional Budget Office has filed 1 estimate for H.R. 5079, the latest on Sep 25, 2025.


Lobbying

61 clients hired 60 firms and 496 registered lobbyists who named H.R. 5079 in 209 quarterly filings, 2025 to 2026. Reported under the Lobbying Disclosure Act; a filing’s income covers everything its registrant worked that quarter, so the amounts below are the filings’, not this bill’s.

Filed under Taxation/Internal Revenue Code, Homeland Security, Budget/Appropriations, Energy/Nuclear, Transportation, Trade (domestic/foreign), Environment/Superfund, Defense.

Clients

Who paid to be heard, by how many filings named the bill. The 20 that filed most often, of 61.

ClientBusinessStateFirmsFilingsReported
INFORMATION TECHNOLOGY INDUSTRY COUNCILTechnology industry association.District of Columbia39$250K
AT&T SERVICES INC AND ITS AFFILIATESDistrict of Columbia28$200K
VISA, INC.Financial ServicesDistrict of Columbia28$200K
AMERICAN PROPERTY CASUALTY INSURANCE ASSOCIATIONDistrict of Columbia28$150K
ENTERGY SERVICES LLCEnergy company.District of Columbia26$240K
DOW CHEMICAL COMPANY DBA DOWDistrict of Columbia16
CROWDSTRIKE, INC.Cyber technology companyTexas25$90K
AMERICAN EXPRESS COMPANYDistrict of Columbia15
AMERICAN GAS ASSOCIATIONDistrict of Columbia15
CHAMBER OF COMMERCE OF THE U.S.A.District of Columbia15
INTERSTATE NATURAL GAS ASSOCIATION OF AMERICADistrict of Columbia15
PACIFIC GAS AND ELECTRIC COMPANYCalifornia15
REINSURANCE ASSN OF AMERICADistrict of Columbia15
BUSINESS ROUNDTABLETrade AssociationDistrict of Columbia14$240K
HALCYON TECH, INC.Anti-ransomware software platformTexas14$160K
VERIZON COMMUNICATIONS INC AND ITS SUBSIDIARIESDistrict of Columbia14$80K
AIR TRANSPORT ASSOCIATION OF AMERICA, INC. (D/B/A AIRLINES FOR AMERICA)District of Columbia14
BLACK HILLS CORPORATIONSouth Dakota14
BUSINESS ROUNDTABLE INCDistrict of Columbia14
COMPETITIVE CARRIERS ASSOCIATIONDistrict of Columbia14

Firms

Registrants who filed on the bill, by filings.

Lobbyists

Named on the filings that cite the bill. The 20 named most often, of 496.

Filings

The documents themselves, on the Senate’s Lobbying Disclosure site, largest reported first.

ClientRegistrantPeriodReportedDocument
CHAMBER OF COMMERCE OF THE U.S.A.CHAMBER OF COMMERCE OF THE U.S.A.2026 first_quarter$19.8M1st Quarter - Amendme…
CHAMBER OF COMMERCE OF THE U.S.A.CHAMBER OF COMMERCE OF THE U.S.A.2026 first_quarter$19.8M1st Quarter - Report
CHAMBER OF COMMERCE OF THE U.S.A.CHAMBER OF COMMERCE OF THE U.S.A.2025 fourth_quarter$18M4th Quarter - Report
CHAMBER OF COMMERCE OF THE U.S.A.CHAMBER OF COMMERCE OF THE U.S.A.2026 second_quarter$17M2nd Quarter - Report
CHAMBER OF COMMERCE OF THE U.S.A.CHAMBER OF COMMERCE OF THE U.S.A.2025 third_quarter$13.7M3rd Quarter - Report
BUSINESS ROUNDTABLE INCTHE BUSINESS ROUNDTABLE, INC.2025 fourth_quarter$9.9M4th Quarter - Report
BUSINESS ROUNDTABLE INCTHE BUSINESS ROUNDTABLE, INC.2026 first_quarter$7.6M1st Quarter - Report
BUSINESS ROUNDTABLE INCTHE BUSINESS ROUNDTABLE, INC.2025 third_quarter$7.5M3rd Quarter - Report
BUSINESS ROUNDTABLE INCTHE BUSINESS ROUNDTABLE, INC.2026 second_quarter$7M2nd Quarter - Report
CTIA-THE WIRELESS ASSOCIATIONCTIA-THE WIRELESS ASSOCIATION2025 fourth_quarter$5.5M4th Quarter - Report
VISA, INC.VISA INC.2025 third_quarter$4.8M3rd Quarter - Report
CTIA-THE WIRELESS ASSOCIATIONCTIA-THE WIRELESS ASSOCIATION2025 third_quarter$3.9M3rd Quarter - Report
NCTA - THE INTERNET & TELEVISION ASSOCIATIONNCTA - THE INTERNET & TELEVISION ASSOCIATION2025 fourth_quarter$3.7M4th Quarter - Report
GOOGLE CLIENT SERVICES LLCGOOGLE CLIENT SERVICES LLC2026 second_quarter$3.6M2nd Quarter - Report
PACIFIC GAS AND ELECTRIC COMPANYPACIFIC GAS AND ELECTRIC COMPANY2026 second_quarter$3.5M2nd Quarter - Report
AMERICAN BANKERS ASSOCIATIONAMERICAN BANKERS ASSOCIATION2026 second_quarter$3.5M2nd Quarter - Report
NCTA - THE INTERNET & TELEVISION ASSOCIATIONNCTA - THE INTERNET & TELEVISION ASSOCIATION2025 third_quarter$3.5M3rd Quarter - Report
AMERICAN CHEMISTRY COUNCILAMERICAN CHEMISTRY COUNCIL2025 third_quarter$3.5M3rd Quarter - Report
VERIZON COMMUNICATIONS INC AND VARIOUS SUBSIDIARIESVERIZON COMMUNICATIONS INC. AND VARIOUS SUBSIDIARIES2026 first_quarter$3.4M1st Quarter - Report
VERIZON COMMUNICATIONS INC AND VARIOUS SUBSIDIARIESVERIZON COMMUNICATIONS INC. AND VARIOUS SUBSIDIARIES2025 fourth_quarter$3.4M4th Quarter - Report

Classification

The Congressional Research Service files H.R. 5079 under Science, Technology, Communications, one of its 31 policy areas, and gives it 7 legislative subjects.

CRS Subjects

CRS assigns every bill one policy area from its 31; H.R. 5079’s is Science, Technology, Communications.

hr5079/policy-areas.txt
Science, Technology, CommunicationsAgriculture and FoodAnimalsArmed Forces and National SecurityArts, Culture, ReligionCivil Rights and Liberties, Minority IssuesCommerceCongressCrime and Law EnforcementEconomics and Public FinanceEducationEmergency ManagementEnergyEnvironmental ProtectionFamiliesFinance and Financial SectorForeign Trade and International FinanceGovernment Operations and PoliticsHealthHousing and Community DevelopmentImmigrationInternational AffairsLabor and EmploymentLawNative AmericansPublic Lands and Natural ResourcesSocial WelfareSports and RecreationTaxationTransportation and Public WorksWater Resources Development

Legislative Subjects

H.R. 5079 carries 7 of CRS’s legislative subjects, from Advanced technology and technological innovations to Subversive activities.

hr5079/subjects.txt
Advanced technology and technological innovationsComputers and information technologyComputer security and identity theftInfrastructure developmentIntergovernmental relationsState and local government operationsSubversive activities

Source: congress.gov · legiscan.com