Warner's Combat Emerging Threats Act mandates CISA update 16 sector plans
Some critical infrastructure cybersecurity plans haven't been updated in over a decade
Senator Mark Warner (D-Va.) introduced the Combat Emerging Threats to Critical Infrastructure Act, legislation that would compel the Cybersecurity and Infrastructure Security Agency (CISA) to overhaul cybersecurity plans for each of the nation’s 16 critical infrastructure sectors. The bill, shared first with Nextgov/FCW, gives CISA one year from enactment to work with federal sector risk management agencies on updating these plans, followed by mandatory reassessments every two years. Warner cited the rapid evolution of AI tools as a key driver, noting they can accelerate the discovery and exploitation of software vulnerabilities. The measure also requires updated plans to account for AI-enabled hacking, deepfakes, and, in the financial services sector, a process for assessing whether future quantum computers could undermine encryption protecting digital assets.
The legislation addresses a long-standing gap: while National Security Memorandum 22 in 2024 called for biennial plan updates, some sector-specific cybersecurity plans have not been revised in more than a decade, according to Warner’s office. The bill covers critical sectors such as energy, communications, transportation, and the defense industrial base. CISA would be required to send completed updated plans to relevant congressional committees within 30 days. The National Electrical Manufacturers Association (NEMA) has endorsed the bill, emphasizing the need for current security plans to address evolving cyber and supply chain threats. Separately, CISA is expected to release a binding operational directive on Wednesday that reshapes how agencies prioritize vulnerabilities on federal networks, informed in part by AI-enabled cyber threats.
- CISA must update cybersecurity plans for all 16 critical infrastructure sectors within one year, then reassess every two years.
- Legislation specifically addresses AI-enabled hacking, deepfakes, and quantum computing threats to encryption.
- Some sector plans are over a decade outdated despite 2024 NSA memo calling for biennial updates.
Why It Matters
AI-powered attacks are evolving faster than critical infrastructure defenses; this bill forces overdue, regular updates to protect essential services.