Lawmakers Push for Biotech Inclusion in Federal Cyber Defense Framework
A bipartisan group of senators and representatives has introduced legislation aimed at strengthening cybersecurity protections for the biotechnology sector, which currently does not fall under any of the 16 federally designated critical infrastructure sectors. The lawmakers argue that despite biotech’s growing importance to national and economic security, it lacks the focused federal attention needed to defend against cyber threats and other risks.
The legislation consists of two separate bills with identical cosponsors: the Protecting Biotechnology and Biomanufacturing as Critical Infrastructure Act and the Protecting Biological Data Act. Neither bill proposes creating a new critical infrastructure category for biotech. Instead, both aim to weave biotech considerations into existing federal frameworks, particularly the law that established the Department of Homeland Security (DHS).
First Bill Focuses on Biotech and Biomanufacturing Infrastructure
The Protecting Biotechnology and Biomanufacturing as Critical Infrastructure Act would direct DHS to develop plans ensuring that biotech and biomanufacturing are treated as critical infrastructure without establishing a standalone sector. These plans would include identifying key players in the industry, conducting outreach to those organizations, and updating the National Infrastructure Protection Plan later this year to incorporate input from the biotech sector.
The goal is to integrate biotech into existing resilience planning processes so that vital biological manufacturing capabilities remain protected from disruption, especially from foreign threats.
Second Bill Targets Biological Data Security
The Protecting Biological Data Act focuses specifically on safeguarding systems that handle genomic sequences and other sensitive biometric information. It would require that such systems be recognized as critical infrastructure and integrated into the national cybersecurity strategy.
Under this bill, CISA would be tasked with collaborating with biotech organizations on cybersecurity initiatives, including joint exercises, and would receive authorization to hire additional personnel dedicated to securing biological data.
Recent Cyberattacks on Biotech Firms Underscore Urgency
The push for legislative action comes after several high-profile biotech companies disclosed recent cyber incidents. In the past two months, both Boston Scientific and Amgen have reported suffering cyberattacks, highlighting the sector’s vulnerability despite its strategic importance.
Supporters of the bills point out that biotechnology currently spans multiple existing critical infrastructure sectors — including healthcare, agriculture, and industrial systems — which complicates efforts to apply unified security standards.
Backed by National Security Commission on Emerging Biotechnology
The legislation is sponsored by prominent members of the National Security Commission on Emerging Biotechnology, a congressional advisory group. Senator Todd Young (R-Ind.), the commission’s chair, emphasized that biological data and infrastructure are now vital to U.S. security and must be protected with the same rigor applied to other forms of sensitive information.
"Just as we are serious about where the sensitive data of Americans is stored and who can access it, we should be equally serious about protecting our biological data and infrastructure," Young stated. "Designating biotech as critical infrastructure is about recognizing its strategic importance and making sure the capabilities America will depend on tomorrow remain resilient and protected from foreign threats."
Representative Ro Khanna (D-Calif.), also a commission member, echoed this sentiment, stating that protecting biomanufacturing and Americans’ biological data is essential for maintaining national security and preserving U.S. leadership in biotechnology.
House and Senate Sponsors Named
In the House of Representatives, the bills are sponsored by Representatives Ro Khanna (D-Calif.), Stephanie Bice (R-Okla.), and Scott Peters (D-Calif.). In the Senate, the lead sponsors are Senator Todd Young (R-Ind.) and Senator Maggie Hassan (D-N.H.).
The sponsors note that while some industry groups have advocated for entirely new critical infrastructure sectors — such as space or artificial intelligence — these bills take a different approach by enhancing protections within the current framework rather than creating a 17th sector.
The full text of both bills is available for public review through links provided by the sponsors.
Source: CyberScoop