Commerce Dept. to create plain-language cyber insurance guide for small businesses
S. 245 — Insure Cybersecurity Act of 2025 · Filed by John Hickenlooper (D-CO) · 1 cosponsor · Introduced Jan 24, 2025 · Reported out
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill directs the Commerce Department's Assistant Secretary for Communications and Information to establish a working group within 90 days to study cyber insurance markets and develop plain-language educational resources. The working group—composed of representatives from CISA, NIST, Treasury, Justice, the FTC, and state insurance regulators—will analyze policy terminology, explain coverage gaps, gather data from insurers on barriers to offering broader coverage, and recommend ways to reduce cyber risk and insurance costs. Within one year, the group submits a report to Congress; the Assistant Secretary then has 90 days to publish voluntary educational materials on the NTIA website. No federal regulation of insurance is created, and use of the resources is entirely voluntary.
Why we flagged it
The bill's operative mechanism is information dissemination and stakeholder coordination—not regulation, subsidy, or liability shield. It aims to reduce information asymmetry in cyber insurance markets by requiring plain-language analysis and public education, with no mandate on insurers or customers.
What the text implies
- The working group may redefine 'cyber insurance' differently from the statutory definition (Section 3(a)(1)), potentially creating two competing definitions—one for the bill's purposes and one for the working group's analysis. This could create confusion if the redefined term is later adopted in other legislation or regulation.
- The bill requires the working group to 'gather input from issuers on what measures could improve the ability of those issuers to offer additional coverage,' including 'improvements to their actuarial data and cyber risk data.' This may indirectly influence future regulatory or legislative proposals favoring data-sharing mechanisms or actuarial standardization that benefit insurers' underwriting ca
The full analysis lists 3 implications of this text.
Who stands to gain
Cyber insurance issuers (improved market clarity and customer education may expand addressable marke; Insurance agents and brokers (better tools to explain and sell policies)