Skip to main content
CybersecurityInfrastructure

Lawmakers Push CISA to Bolster Biotech Cyber Defenses

Biotech laboratory with scientists working, equipment, and computer terminals.

“Biotechnology infrastructure and data are becoming vital to America’s economic and national security,” said Commission Chair Senator Todd Young, R-Ind., as lawmakers on both sides of the aisle unveiled parallel bills that would push the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Homeland Security (DHS) to beef up protections for biotech, biomanufacturing and sensitive biological data.

Protecting Biotechnology and Biomanufacturing as Critical Infrastructure Act

The House and Senate sponsors introduced a bill that would task DHS with producing concrete plans to ensure biotechnology and biomanufacturing receive focused protection within existing federal structures — but explicitly not by creating an eighteenth formal critical infrastructure sector. Under the Protecting Biotechnology and Biomanufacturing as Critical Infrastructure Act, DHS would be directed to identify key biotech players, conduct outreach to those entities, and develop steps to update the National Infrastructure Protection Plan (NIPP) this year so that input from biotech actors is incorporated.

Protecting Biological Data Act: genomic sequences, biometrics, and CISA activity

The companion bill, the Protecting Biological Data Act, targets systems that handle genomic sequences and sensitive biometric data. Texts of the bill would require those systems to be covered as critical infrastructure and integrated into the national cyber strategy. The measure would also direct CISA to work directly with biotech organizations on security measures such as joint exercises, and to add personnel focused on biometric data security.

Sponsors, the National Security Commission on Emerging Biotechnology, and the bills’ bipartisan framing

Both bills share the same group of cosponsors and were announced as bipartisan measures. In the House the sponsors named are Rep. Ro Khanna, D-Calif.; Stephanie Bice, R-Okla.; and Scott Peters, D-Calif. In the Senate the sponsors are Senator Todd Young and Senator Maggie Hassan, D-N.H. The source notes that sponsors include leaders and members of the National Security Commission on Emerging Biotechnology — a legislative advisory group — and the bills were presented with public statements tying the measures to economic and national security concerns. “Protecting biomanufacturing infrastructure and the most sensitive biological data of Americans is essential for our national security,” said commissioner Rep. Ro Khanna, D-Calif.

Recent attacks and where biotech sits in the nation’s critical infrastructure map

The bills arrive after recent, high-profile incidents: in the last two months, Boston Scientific and Amgen each revealed they suffered cyberattacks, underscoring the vulnerability of medical and life‑science companies. The legislation’s architects point to a gap in federal focus caused by biotech’s cross-cutting nature: biotechnology does not fit neatly into any single one of the 16 government-designated critical infrastructure sectors, and today it spans the health, agricultural and industrial sectors. The proposed bills stop short of adding a new, standalone sector; instead they seek to weave biotech-specific protections and planning requirements into the DHS law that governs critical infrastructure protection. The source also notes that some industry groups and experts have separately lobbied for new critical infrastructure sectors such as space or artificial intelligence, highlighting a broader debate over the scope of sector designations.

What this means for technologists, policymakers, and affected enterprises

  • Technologists and security teams: Expect CISA to be asked to run more joint exercises and to coordinate outreach; systems that handle genomic and biometric data would face new scrutiny if the bills’ requirements are enacted.
  • Policymakers and regulators: DHS would be tasked with updating the National Infrastructure Protection Plan this year to incorporate biotech input, and CISA would be directed to add personnel specifically for biometric data security.
  • Affected enterprises and biomanufacturers: Companies identified as “key biotech players” could be the immediate focus of outreach and planning efforts, and recent incidents at Boston Scientific and Amgen provide concrete examples sponsors cite when arguing for accelerated protections.

The two bills — titled Protecting Biological Data as Critical Infrastructure (sponsored in the Senate by Senator Young) and Protecting Biotechnology and Biomanufacturing as Critical Infrastructure Act (sponsored in the Senate by Senator Hassan and advanced in the House by Representatives Khanna, Bice and Peters) — would together change how biotech and biological data are folded into the nation’s infrastructure and cyberstrategy without creating a separate critical-infrastructure category. Texts of both measures are publicly available from the sponsors; the source includes downloads of the bill language.

Whether DHS and CISA embrace the structured outreach, planning and personnel changes the bills propose will be a consequential test of how federal planners adapt existing critical infrastructure tools to a sector that, by the lawmakers’ account, increasingly underpins economic and national security.

https://cyberscoop.com/biotech-critical-infrastructure-cybersecurity-legislation/