Insure Cybersecurity Act of 2025
Click any stage to learn more about the legislative process.
Would require the National Telecommunications and Information Administration (NTIA) to establish a working group on cyber insurance, tasked with analyzing policy terminology, coverage gaps, and market constraints — then publishing plain-English guidance for businesses and consumers navigating the cyber insurance market.
Cyber insurance has become a critical but often confusing tool for organizations facing ransomware and other digital threats; the bill aims to improve transparency between insurers and customers without creating new regulatory mandates.
What this bill would do
What it would do
The bill would direct the Assistant Secretary of Commerce for Communications and Information (who leads NTIA) to establish a working group on cyber insurance within 90 days of enactment. The group — drawing members from CISA, NIST, the Treasury, the Department of Justice, the FTC, and at least one state insurance regulator — would analyze and explain in plain language the technical and legal terms used in cyber insurance policies, how policy provisions map to common cyber incidents such as ransomware, what constraints insurers face in covering losses like reputational damage or stolen intellectual property, and what measures could reduce costs and cyber risk. The group would also gather input from insurers, brokers, small businesses, and critical infrastructure operators.
Within one year of its first meeting, the working group would submit a report to Congress. No later than 90 days after that, NTIA would publish and promote publicly available guidance resources for insurers, agents, brokers, and customers. The bill explicitly states that nothing in it requires adoption of the working group's recommendations or grants any member authority to regulate the insurance industry.
Key provisions
- 1Would require NTIA's Assistant Secretary to establish a cyber insurance working group within 90 days of enactment, chaired by the Assistant Secretary.
- 2Would direct the working group to include members from CISA, NIST, Treasury, Justice, the FTC, and at least one state insurance regulator with cybersecurity expertise.
- 3Would direct the working group to analyze and explain in plain language policy terminology, coverage provisions, ransomware-related responses, insurer constraints, and cost-reduction measures.
- 4Would require the working group to submit a report to Congress within one year of its first meeting, after which it would terminate.
- 5Would require NTIA to publish and promote publicly available informative resources — incorporating working group recommendations, with case studies — within 90 days of the report.
- 6Would clarify that nothing in the bill requires adoption of working group recommendations or grants any member new authority to regulate the insurance industry.
Who would be affected
Businesses and individuals who purchase cyber insurance, particularly small businesses and critical infrastructure operators who may struggle to understand complex policy language. Insurance companies, agents, and brokers who issue and sell cyber insurance policies. Federal agencies including CISA, NIST, the Department of the Treasury, the Department of Justice, and the FTC, which would staff the working group. State insurance regulators would also participate.
Why it matters
Organizations of all sizes increasingly rely on cyber insurance but often struggle to understand what their policies actually cover — especially for incidents like ransomware, reputational harm, or intellectual property theft. If enacted, the bill would produce standardized, plain-English resources to help buyers make more informed choices and encourage insurers to communicate more clearly, potentially reducing costly coverage mismatches after a cyberattack.
What would change
Agencies directed to act
Effective dates
- Deadline to establish the cyber insurance working group
- Deadline for the working group to submit its report to Congress
- Deadline to publish informative resources for cyber insurance stakeholders
Funding and costs
Congressional Budget Office estimate
CBO estimates that S. 245, the Insure Cybersecurity Act of 2025, would have no significant effect on the federal budget.
S. 245 would direct the National Telecommunications and Information Administration (NTIA) to establish an interagency working group on cyber insurance, drawing members from the Cybersecurity and Infrastructure Security Agency, the Departments of Justice and Treasury, the National Institute of Standards and Technology, and the FTC. The working group would be required to report to Congress within one year of its formation. CBO found that any costs associated with staff time and administrative work to form the group and produce the report would be small and could be covered within existing agency appropriations (discretionary funds already approved by Congress). CBO identified no intergovernmental or private-sector mandates in the bill.
How implementation would work
NTIA's Assistant Secretary would chair the working group and convene it within 90 days of enactment. The group would conduct open, transparent public consultations with insurers, brokers, business groups, academia, state regulators, and critical infrastructure operators. After up to one year of activity, it would report to Congress, then dissolve. Within 90 days of that report, NTIA would publish case-study-inclusive guidance resources on its public website and conduct outreach to industry and the public. Use of the resources would be entirely voluntary.
Legislative status & sources
Latest action
Placed on Senate Legislative Calendar under General Orders. Calendar No. 90.
Official CRS summary
Show the CRS summaryHide the CRS summary
This bill requires the National Telecommunications and Information Administration (NTIA) to establish a working group on cyber insurance policies. Under the bill, these are defined as policies that offer coverage for losses, damages, and costs incurred due to cyberattacks and related incidents.
The working group is directed to analyze and address issues in the cyber insurance market facing both insurers and their customers. Specifically, the working group must develop information for customers on how to effectively evaluate policy options, and for insurers on how to clearly communicate with customers regarding policy provisions.
Additionally, the working group is directed to analyze and explain in layman’s terms
- terminology commonly used in cyber insurance policies, including terminology used to include or exclude coverage for losses from cyber incidents;
- how common policy provisions correspond to cyber incidents and potential responses, including ransomware and potential ransom payments; and
- constraints faced by insurers in covering higher losses in cyber risk areas, such as reputational damage and loss of intellectual property.
At the conclusion of the working group's term, NTIA must publish and disseminate informative resources for cyber insurance stakeholders, including any recommendations formulated by the working group.
Legislative subjects
Advisory bodies; Computer security and identity theft; Computers and information technology; Congressional oversight; Consumer affairs; Government information and archives; Government studies and investigations; Insurance industry and regulation; Public-private cooperation; Science, Technology, Communications
Committee report
S. Rept. 119-28