In recent years, Congress has become increasingly focused on private-sector cybersecurity practices as a matter of public concern and national security, particularly as the cybersecurity threat landscape continues to evolve rapidly. Lawmakers on both sides of the aisle have demonstrated sustained interest in whether companies appropriately collect, safeguard, and respond to compromises of sensitive data and protect critical systems, and cybersecurity is likely to remain a congressional priority regardless of which party controls Congress after the midterm elections.
This means that a cybersecurity incident may lead to scrutiny from Congress in addition to regulators, shareholders, and other stakeholders, such as consumers and customers. Such scrutiny introduces an additional set of considerations distinct from the regulatory, litigation, and reputational challenges that organizations typically anticipate as part of their standard incident response plans. Congressional investigations operate under different rules and timelines than regulators, law enforcement, and private plaintiffs, and the political dynamics that animate a congressional investigation can shift rapidly.
Congressional scrutiny is not limited to incidents that have compromised sensitive information—other cybersecurity and privacy deficiencies may attract congressional notice as lawmakers have shown increased interest in the full corporate cybersecurity lifecycle as it relates to consumer, employee, government, and other sensitive data. Organizations should thus consider incorporating congressional investigation risks into their incident response and crisis management plans—not just for data breaches, but also for cybersecurity incidents and crises more broadly.
This client alert explains how cybersecurity incidents can attract congressional scrutiny, the distinct risks that arise when a cybersecurity incident draws congressional attention, and emerging areas of congressional focus that may increase scrutiny of corporate cybersecurity practices.
When a company experiences a significant cybersecurity incident, particularly one involving the compromise of sensitive data or critical infrastructure, several features of a typical incident response can place the company directly on Congress’ radar. Accordingly, companies navigating a cybersecurity incident should consider how their incident response processes might lead to congressional notice:
- Congressional notification requirements. As we recently discussed in our client alert on congressional scrutiny of government contractors, investigators in Congress have significantly expanded their oversight of private-sector entities. When a contractor’s cybersecurity incident reaches the level of a major incident, the Federal Information Security Modernization Act (“FISMA”) requires notifications to several congressional committees, including but not limited to the House Committee on Oversight and Government Reform, the House Committee on Homeland Security, and the Senate Homeland Security and Governmental Affairs Committee. These notifications place the company’s incident directly before the committees most likely to initiate an investigation, effectively ensuring that Congress is aware of the breach at an early stage. Note that FISMA does not define what constitutes a major incident, but rather it is defined in Office of Management and Budget/Cybersecurity and Infrastructure Security Agency guidance.
- Risks to government and critical infrastructure systems. Even where a company does not contract directly with the government, a cybersecurity incident may draw congressional attention if it implicates government or critical infrastructure systems. Private-sector entities may provide critical hardware and software to government entities and critical infrastructure providers or may host information relating to government employees, contractors, beneficiaries, or regulated programs. Particularly where an incident implicates government systems, lawmakers are often eager to explore whether a company has adequately protected systems and information critical to the continued operation of government and critical infrastructure. Lawmakers have been especially focused on cybersecurity risks to critical infrastructure and the broader economy, as reflected in recent congressional investigations involving telecommunications networks and the energy sector.
- Nation-state involvement. Cybersecurity incidents involving a nation-state adversary are among the most likely to attract congressional scrutiny. Congress frequently responds to incidents attributed to nation-state actors with hearings, classified briefings, and demands for information from affected companies. Where a highly publicized or particularly impactful state-sponsored campaign compromises a company’s systems, especially those that are part of critical infrastructure, the company should anticipate that congressional interest will be intense, prolonged, and bipartisan.
- Publicity of large or sensitive incidents. Companies experiencing a cybersecurity incident may be required to notify affected individuals, shareholders, state attorneys general, and other regulators under a patchwork of federal and state notification laws. These notifications may generate public and media attention, which can in turn lead to congressional interest. Even if an incident does not fall into one of the categories above, lawmakers monitoring reports of significant incidents may view an incident as warranting further inquiry, especially if an incident affects a large number of constituents or involves sensitive categories of data, a company experiences repeated incidents, or an incident overlaps with other consumer protection or safety concerns.
- Parallel proceedings. Companies experiencing a significant cybersecurity incident may face overlapping civil and criminal investigations from multiple authorities, including the Department of Justice, the Federal Trade Commission, sector-specific regulators such as the Departments of Energy and Agriculture, and state attorneys general. Cybersecurity incidents, and data breaches in particular, also frequently give rise to class action litigation. Companies headquartered or operating outside of the United States that experience a breach touching U.S. data may face additional investigations by foreign legislatures and regulatory authorities in their home jurisdictions. A congressional investigation adds yet another dimension, and a distinct set of risks, to this already complex landscape. Congressional inquiries implicate legal, regulatory, political, and public relations risks. An incident response strategy focused solely on legal exposure may therefore leave a company vulnerable elsewhere.
- Unique challenges posed by congressional oversight. Even organizations familiar with civil litigation and government investigations may find congressional oversight unfamiliar and difficult to navigate. Committees routinely issue expansive document demands on compressed schedules, sometimes seeking an initial response within two weeks or less. Committees may provide little formal process for narrowing these requests and can move quickly from private information gathering to public letters, reports, or hearings. Conventional discovery safeguards—including judicial supervision, protective orders, and established mechanisms for protecting confidential business information—generally do not apply in congressional inquiries. Further, disputes over the scope and timing of document production, privilege, or confidentiality are typically addressed to the committee leaders that issued the request rather than to a neutral decision-maker, and Congress has long asserted substantial discretion over whether to recognize common-law protections such as the attorney-client privilege and work-product doctrine.
- Coordinating across forums. Congressional investigators may coordinate with regulators, law enforcement authorities, and other interested parties, and companies should anticipate that private plaintiffs may cite in civil complaints or discovery disputes materials produced to the Hill or statements made in connection with a congressional inquiry, while other government investigators may also access the same materials. Even absent intentional coordination, committee requests, hearings, public letters, and reports may generate additional litigation or investigations by supplying new allegations, evidence, or political momentum. Companies should develop a comprehensive strategy for managing parallel proceedings, recognizing that positions taken or disclosures made in one forum may have implications in others.
In addition to the risks described above, companies should be aware of the developing areas of congressional focus that may make certain types of cybersecurity incidents or general data practices more likely to attract scrutiny.
- Politically sensitive data. Entities storing categories of data with political salience are especially likely to draw congressional scrutiny. For example, data related to immigration enforcement, elections, and government officials (such as Members of Congress)—including demographic, behavioral, and geolocation data—has become highly politicized, and lawmakers may treat even potential privacy risks as grounds for immediate investigation regardless of whether a breach of this data has occurred.
- Health care data. Health care data remains a significant and recurring area of congressional interest. Beyond the general sensitivity of medical information, lawmakers have demonstrated particular focus on data related to reproductive health services and gender-affirming care. Companies in the health care sector, as well as technology companies that collect health-related data, should recognize that these categories of information carry elevated risk of congressional scrutiny.
- Artificial intelligence. The intersection of AI and cybersecurity is an emerging area of congressional interest. As we have discussed in our recent client alert on AI frontier models, lawmakers are focused on the relationship between AI-powered infrastructure projects and cybersecurity. Indeed, recent reporting suggests that Democratic leaders in the House of Representatives are considering creating a special committee focused exclusively on AI policy and oversight should they win control of the chamber in November. Companies developing or deploying AI systems should anticipate heightened congressional attention.
- Critical infrastructure disruptions. Cybersecurity incidents that threaten the delivery of essential services are highly likely to attract congressional attention. As mentioned above, lawmakers have expressed bipartisan interest in conducting oversight of cybersecurity risks to critical infrastructure, including through recent congressional inquiries involving critical infrastructure operators in the energy, water, transportation, and communications sectors. This area is likely to remain a focus for congressional investigators in light of continued cyber threats from foreign state actors against U.S. water systems, and operators should be prepared to explain their cybersecurity safeguards, incident response protocols, and efforts to maintain operational resilience.
- Bulk data collection and sale. Lawmakers have shown growing interest in the collection, sharing, and monetization of personal data, and the related consumer protection implications. Companies engaged in data brokerage, behavioral advertising, or other activities involving the aggregation and transfer of consumer data should prepare for heightened congressional scrutiny of their data practices.
- Scam centers. Another emerging area of congressional focus involves foreign-based scam operations that target Americans. Lawmakers have expressed bipartisan concern about the role that cybersecurity vulnerabilities and data exposure play in facilitating these schemes. Companies whose platforms, services, or data are implicated in scam operations, including as intermediaries, may face congressional scrutiny regarding their security practices and consumer protection measures.
Companies should take proactive steps to mitigate the congressional investigation risks described above, including by assessing their current incident response and notification procedures; coordinating incident response and crisis management plans to account for the possibility of congressional inquiry; and seeking the advice of experienced counsel to evaluate the adequacy of any incident or crisis management plan and address potential plan gaps. Companies may also consider including components addressing congressional investigations as part of a cybersecurity tabletop exercise. Companies should also review their cyber insurance policies to determine whether coverage extends to the costs of responding to a congressional investigation and, where necessary, consider negotiating endorsements or riders to address this increasingly common risk.
If you have any questions regarding the issues discussed in this alert, or would like assistance preparing for potential congressional inquiries, please contact any of the members of our Congressional Investigations or Data Privacy and Cybersecurity practices listed below.