Headed into 2020, with a presidential election on the horizon, cyber concerns are certain to be in the spotlight in Washington.
Atop the list of cyber issues will be persistent questions about election security. Officials at the federal, state and local levels say they will be vigilant to any efforts to interfere in the election after 2016, even as lawmakers weigh additional actions to safeguard the vote.
But lawmakers will also be looking to tackle other issues as well, such as the ransomware attacks spreading across the country and the growing concerns over companies with foreign ties accessing Americans' data.
Here's what we are watching on the cyber front for 2020.
2020 will see a presidential election, along with nationwide elections for the House and a third of the Senate. It will be a major test for efforts to improve security after Russian interference efforts in the 2016 election.
U.S. intelligence agencies, former special counsel Robert MuellerRobert (Bob) MuellerSenate Democrats urge Garland not to fight court order to release Trump obstruction memo Why a special counsel is guaranteed if Biden chooses Yates, Cuomo or Jones as AG Barr taps attorney investigating Russia probe origins as special counsel MORE and the Senate Intelligence Committee have all concluded that Russia conducted a sweeping and systematic attack against the 2016 elections, using both hacking and disinformation campaigns.
Mueller has warned that Russia would attempt to interfere again, testifying to the House Intelligence Committee in July that the Russians were trying to interfere “as we sit here.”
Fiona Hill, the former National Security Council senior director for Europe and Russia, sounded the alarm on this issue as well, testifying during the impeachment inquiry into President TrumpDonald TrumpJan. 6 committee chair says panel will issue a 'good number' of additional subpoenas Overnight Defense & National Security — Presented by AM General — Pentagon officials prepare for grilling Biden nominates head of Africa CDC to lead global AIDS response MORE that "right now, Russia’s security services and their proxies have geared up to repeat their interference in the 2020 election.”
The years following 2016 have seen election security become a big talking point on Capitol Hill, but with Republicans and Democrats divided over what needs to be done to ensure that similar interference does not happen again.
A big step Congress has taken is appropriating funds for state and local election officials to improve election security efforts, with Congress sending $380 million to the states in 2018, and an additional $425 million to states in appropriations bills this month.
However, beyond those funds, many Democrats have complained that Congress has not done enough to address attempted Russian interference.
Senate Democrats have repeatedly tried to force Senate Majority Leader Mitch McConnellAddison (Mitch) Mitchell McConnellFord to bolster electric vehicle production in multi-billion dollar push On The Money — GOP blocks spending bill to kick off chaotic week in congress Overnight Health Care — Presented by Alrtia — Booster shots get bipartisan rollout MORE (R-Ky.) to schedule votes on a raft of various election security bills. The House has passed three major pieces of election security legislation this year that have stalled amid Republican objections in the Senate.
In 2020, there could be more focus on election security.
Sen. Ron JohnsonRonald (Ron) Harold JohnsonBiden sidesteps GOP on judicial vacancies, for now The Hill's Morning Report - Presented by Alibaba - Democrats argue price before policy amid scramble Liberal group launches campaign urging Republicans to support Biden's agenda MORE (R-Wis.), the chairman of the Senate Homeland Security and Governmental Affairs Committee, told The Hill this week that he “definitely intends” to hold a hearing on election security sometime in the new year.
“I want to take a look at the whole gamut,” Johnson said of election security issues. “I’m of the belief that we are doing a pretty good job from a cyber standpoint, it is almost impossible to get into voting machines and if you are an election official and you are not aware of the fact that you should not have your machine hooked up to the internet, shame on you.”
House Administration Committee Chairwoman Zoe LofgrenZoe Ellen LofgrenBiden to raise refugee cap to 125,000 in October Republicans keep distance from 'Justice for J6' rally Spotlight turns to GOP's McCarthy in Jan. 6 probe MORE (D-Calif.), whose committee approved the main three House election security bills this year, told The Hill that there may be “some oversight” from her committee on the subject of election security in 2020.
The Senate Intelligence Committee is also expected to drop the third of its five reports based on its investigation into Russian interference in the 2016 elections sometime in January. The third volume will look at the Obama administration’s response to Russian interference.
“We have gotten the third one back for redactions, and we have volleyed about 20 questions back to them that probably won’t get answers and vote next week, but it will be out as soon as we get back,” Senate Intelligence Committee Chairman Richard BurrRichard Mauze BurrAnti-Trump Republicans on the line in 2022 too The Hill's Morning Report - Presented by Alibaba - Biden jumps into frenzied Dem spending talks GOP senators say Biden COVID-19 strategy has 'exacerbated vaccine hesitancy' MORE (R-N.C.) told The Hill earlier this month.
Ransomware attacks, in which an attacker infiltrates a system and locks it until a ransom is paid, were endemic nationwide in 2019, hitting government entities and cities repeatedly.
The city governments of Baltimore, New Orleans and Pensacola, Fla., were hit by ransomware attacks this year, with city services affected for days afterward, while a coordinated attack hit almost two dozen small town governments in Texas in August.
School districts have also borne the brunt of ransomware attacks, with Louisiana Gov. John Bel Edwards (D) declaring a state-wide emergency in July after several school districts were hit. The school district for Flagstaff, Ariz. was forced to close for two days in August to recover from a ransomware attack, affecting almost 10,000 students.
Congress is grappling with the threat. Members of the Senate Cybersecurity Caucus received a classified briefing on the issue earlier this month from the Department of Homeland Security (DHS).
Sen. Mark WarnerMark Robert WarnerPanic begins to creep into Democratic talks on Biden agenda Democrats surprised, caught off guard by 'framework' deal Schumer announces Senate-House deal on tax 'framework' for .5T package MORE (D-Va.), co-chairman of the caucus, said in a statement that “the continued prevalence of ransomware should really capture our attention.”
Sen. Cory GardnerCory GardnerProtecting the outdoors: Three cheers for America's best idea Ex-Sen. Cory Gardner joins lobbying firm Biden administration reverses Trump changes it says 'undermined' conservation program MORE (R-Colo.), the other co-chairman, told The Hill that he thought it was “important that the American people understand what’s at risk.”
Several pieces of legislation have been introduced in the wake of the attacks, including one bipartisan Senate bill to help school districts defend against ransomware, and another bipartisan House bill to give resources to state and local governments to address the attacks.
The bipartisan Cyber Hunt and Incident Response Teams Act, another piece of legislation around this issue, was included in the 2020 appropriations bills. This will enable DHS to maintain permanent teams to help in response efforts to cyberattacks.
During a hearing on cyber threats against state and local governments earlier this year, Rep. Cedric RichmondCedric RichmondThe Memo: Biden's immigration problems reach crescendo in Del Rio Black Caucus meets with White House over treatment of Haitian migrants The Hill's Morning Report - Presented by Facebook - Questions on Biden agenda; unemployment benefits to end MORE (D-La.), the chairman of the House Homeland Security subcommittee on cybersecurity, noted that ransomware and other cyber threats are “not a state or local problem, but a national one–and we should invest accordingly, at the Federal level.”
As the attacks spread, lawmakers can expect growing pressure to act.
Recent months have seen a build-up of bipartisan concern around foreign-affiliated apps such as video sharing site TikTok and face editing app FaceApp.
These concerns look likely to intensify in 2020 as Capitol Hill grows increasingly wary of foreign-linked technology.
Senate Minority Leader Charles SchumerChuck SchumerObama says US 'desperately needs' Biden legislation ahead of key votes Congress shows signs of movement on stalled Biden agenda Schumer gets shoutout, standing ovation from crowd at Tony Awards MORE (D-N.Y.) has expressed concerns around both FaceApp, which was created by a St. Petersburg-based developer, and TikTok, which is owned by Chinese company ByteDance.
Schumer and Sen. Tom CottonTom Bryant CottonHillicon Valley — Presented by Xerox — Tech groups take aim at Texas Republican lawmakers raise security, privacy concerns over Huawei cloud services Debt ceiling fight pits corporate America against Republicans MORE (R-Ark.) requested that the U.S. intelligence community investigate TikTok in October. The lawmakers wrote to acting Director of National Intelligence Joseph MaguireJoseph MaguireJudge dismisses Nunes's defamation suit against Washington Post Retired Navy admiral behind bin Laden raid says he voted for Biden Congressional Democrats request FBI briefing on foreign election interference efforts MORE that “security experts have voiced concerns that China’s vague patchwork of intelligence, national security, and cybersecurity laws compel Chinese companies to support and cooperate with intelligence work controlled by the Chinese Communist Party.”
Both TikTok and FaceApp have pushed back against concerns over how they use and store American data, with TikTok particularly stressing that it does not store the data of Americans in China.
Rep. Stephen LynchStephen Francis LynchPelosi signals she won't move .5T bill without Senate-House deal Overnight Defense: Military justice overhaul included in defense bill | Pentagon watchdog to review security of 'nuclear football' | Pentagon carries out first air strike in Somalia under Biden Pentagon watchdog to review security of 'nuclear football' MORE (D-Mass.) added to those concerns, sending letters earlier this month to Google and Apple asking them how they vet mobile apps and safeguard data security. The companies have until Jan. 10 to respond.
“Given the pervasiveness of smartphone technology in the United States, as well as the vast amounts of information stored on those devices, foreign adversaries may be able to collect sensitive information about U.S. citizens, which presents serious and immediate risks for U.S. national security,” Lynch wrote.