Congress orders audit of bank-government ransomware coordination
H.R. 807 — Public and Private Sector Ransomware Response Coordination Act of 2025 · Filed by Zachary (Zach) Nunn (R-IA) · 2 cosponsors · Introduced Jan 28, 2025 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill requires the Treasury Secretary to study and report on how well the government and private financial institutions coordinate to prevent and respond to ransomware attacks. The report will examine what information banks share with federal agencies, whether that information is useful, and whether new laws are needed to improve coordination and speed up incident reporting.
Why we flagged it
The bill is fundamentally a fact-finding and reporting mandate. It does not create new regulatory requirements or direct spending; instead, it directs the Treasury Secretary to assess the current state of public-private ransomware coordination and recommend improvements.
What the text implies
- The report may reveal that financial institutions are withholding ransomware incident data from government agencies, potentially exposing a gap in national cybersecurity visibility that could inform future mandatory-disclosure legislation.
- By studying the 'utility' of reported information to law enforcement and prosecutors, the bill may lay groundwork for future requirements that banks share more granular attack data, which could increase compliance costs for smaller institutions.
The full analysis lists 3 implications of this text.
Who stands to gain
cybersecurity service providers (incident response, managed services, advisory firms); financial institutions (may benefit from clearer reporting standards and reduced compliance ambiguit; technology vendors serving the financial sector