The bill
Widespread Information Management for the Welfare of Infrastructure and Government Act
HR. 5079, 119th Congress — read as touching Cybersecurity.
Sponsored by
Rep. Garbarino, Andrew R. [R-NY-2]
ID: G000597
Follow the money
The bill
HR. 5079, 119th Congress — read as touching Cybersecurity.
The sponsor
Every bill has someone who introduced it. That name is where the paper trail starts.
The money
22 itemised contributions to this sponsor, pulled from FEC filings.
The alignment
This bill's text tracks the "Introduction" section, p. 254-256 of the Mandate for Leadership.
Track this bill's progress through the legislative process
Latest Action
Ordered to be Reported (Amended) by the Yeas and Nays: 25 - 0.
September 2, 2025
📍 Current Status
Next: The bill will be reviewed by relevant committees who will debate, amend, and vote on it.
1. Introduction: A member of Congress introduces a bill in either the House or Senate.
2. Committee Review: The bill is sent to relevant committees for study, hearings, and revisions.
3. Floor Action: If approved by committee, the bill goes to the full chamber for debate and voting.
4. Other Chamber: If passed, the bill moves to the other chamber (House or Senate) for the same process.
5. Conference: If both chambers pass different versions, a conference committee reconciles the differences.
6. Presidential Action: The President can sign the bill into law, veto it, or take no action.
7. Became Law: If signed (or if Congress overrides a veto), the bill becomes law!
Another bill from our esteemed Congress, because what this country really needs is more bureaucratic jargon and Orwellian doublespeak. Let's dissect the "Widespread Information Management for the Welfare of Infrastructure and Government Act" (HR 5079) – a title that screams "we're trying to sound important while doing nothing."
**Main Purpose & Objectives:** The bill reauthorizes the Cybersecurity Act of 2015, because who doesn't love a good reauthorization? The main purpose is to update existing law to include new definitions and provisions related to artificial intelligence, critical infrastructure, and sector risk management agencies. Wow, I can barely contain my excitement.
**Key Provisions & Changes to Existing Law:** The bill makes several changes to the Cybersecurity Act of 2015, including:
* Redefining terms like "artificial intelligence" and "critical infrastructure" because, apparently, those definitions were too vague or didn't exist before. * Updating procedures for sharing cyber threat indicators and defensive measures between federal agencies and non-federal entities. Because sharing is caring, right? * Authorizing the use of artificial intelligence for cybersecurity purposes, but only if it's strictly deployed for that purpose. I'm sure this won't lead to any unintended consequences or mission creep. * Allowing sector risk management agencies to participate in certain activities, because who doesn't love more bureaucracy?
**Affected Parties & Stakeholders:** The usual suspects:
* Federal agencies (because they need more power and funding) * Non-federal entities that own or operate critical infrastructure (because they need more regulations and guidelines to follow) * The cybersecurity industry (because they'll be the ones selling the "solutions" to these new problems)
**Potential Impact & Implications:** This bill will likely:
* Increase government spending on cybersecurity initiatives, because throwing money at a problem always solves it. * Create new regulatory burdens for non-federal entities, which will lead to more compliance costs and potential job losses. * Expand the surveillance state by allowing for greater sharing of cyber threat indicators and defensive measures. Because who doesn't love being watched? * Provide a false sense of security, as the bill's provisions are largely cosmetic and won't address the underlying issues in our cybersecurity infrastructure.
In conclusion, HR 5079 is just another example of Congress's inability to tackle real problems with meaningful solutions. Instead, we get more bureaucratic jargon, regulatory burdens, and a further expansion of the surveillance state. Joy.
Rep. Garbarino, Andrew R. [R-NY-2]
Congress 119 • 2024 Election Cycle
No PAC contributions found
No committee contributions found
This bill has 1 cosponsors. Below are their top campaign contributors.
ID: M001157
Top Contributors
10
Hub layout: Politicians in center, donors arranged by type in rings around them.
Showing 57 nodes and 25 connections (58 secondary connections hidden)
Total contributions: $122,300
Showing top 19 donors by contribution amount
Which industries are materially affected by specific provisions in this bill. 2 helped, 1 harmed.
Section 2(a)(3)(A)(iv) adds a new subparagraph (C) to section 104(c) to preclude the use of AI developed or strictly deployed for cybersecurity purposes in carrying out authorized activities, which could be interpreted as a limitation on certain AI uses in cybersecurity, but overall the bill reauthorizes and updates cybersecurity information sharing provisions, including outreach and updates, which benefits the cybersecurity industry by enhancing federal support and coordination. Section 2(a)(4)
The bill amends Section 2200 of the Homeland Security Act of 2002 (6 U.S.C. 650) in Section 2(b)(1)(B) to include 'including a security vulnerability affecting an information system or a technology included in the critical and emerging technologies list of the Office of Science and Technology Policy or successor list, such as artificial intelligence (as such term is defined in section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401)), which may be in a Federal
Section 2(a)(3)(A)(iv) adds a new subparagraph (C) to section 104(c) to 'preclude the use of artificial intelligence that is developed or strictly deployed for cybersecurity purposes in carrying out the activities authorized under paragraph (1).' Similarly, Section 2(a)(5)(A)(iii) adds ', which may utilize artificial intelligence that is developed or strictly deployed for cybersecurity purposes,' after 'technical capability' in section 104(d)(2)(B)(iii). Section 2(a)(8)(iv) adds a new paragraph
For each industry this bill affects, here's what the sponsor (Rep. Garbarino, Andrew R. [R-NY-2])received from donors associated with that industry during the 2022–present cycles. Donations are not proof of intent — they are a record of who funds the people writing the law.
This bill shows semantic similarity to the following sections of the Project 2025 policy document.
— 222 — Mandate for Leadership: The Conservative Promise forward-leaning in sharing cyber threat intelligence with private-sector partners and the public, emphasizing that the protective nature of such information is of value only if put into the right hands at the right time. Since critical infrastructure and services are overwhelmingly owned, managed, and defended by the private sector in the United States, there has been an increasing emphasis on declassify- ing intelligence and sharing actionable information with private-sector partners, often through industry-specific Information Sharing and Analysis Centers (ISACs); regional meetings of government and private-sector experts called InfraGard, run by the FBI; direct public notification from the Department of Homeland Security, the FBI, and (increasingly) the NSA; and more discreet one-on-one engagements led by the collecting agencies. These programs properly recognize the private sector’s role in providing cyber- security for Americans; in practice, however, the intelligence shared by the U.S. government through these venues is too often already known or no longer relevant by the time it makes its way through the downgrade process for sharing. In addition, government-shared information often needs to take advantage of the opportunity to provide contexts, such as attribution, trends, and size of the observed cyber problem. As warranted, additional context should be provided to the private sector as a matter of routine. To continue improving the U.S. government’s ability to defend the country’s most vital networks, the IC must adopt an “obligation to share” policy process, including the capacity for “write to release” intelligence products whereby newly discovered technical indicators, targeting, and other intelligence relevant to cyber defense are automatically provided either to the public or to targeted entities within 48 hours of their collection—which is how counterterrorism intel- ligence has been managed for years when it comes to a “duty to warn.” Under this policy, agency heads should still have the flexibility to withhold intelligence for operational or counterintelligence reasons but would need to report regularly to Congress on the number of and justification for exceptions. This policy would make sharing intelligence and defending networks the default, as it already is in the rest of the cybersecurity community outside the IC, to improve the quantity, relevance, and timeliness of defensive information while ensuring accountability for top leaders when they must withhold this information. One of the most significant challenges within the IC is presented by the need to share information promptly among the 18 elements of the intelligence enterprise. The only long-term solution to the understandable tension between the need to share information and the need to protect intelligence sources and methods is a robust real-time auditing capability that electronically flags unauthorized access. Under an identity management system with real-time audit, even the most sensi- tive information acquired by America’s intelligence agencies can be shared, and the access to and use of that information are appropriately monitored. Establishing — 223 — Intelligence Community a real-time auditing capability is essential to decreasing the risk for the heads of intelligence agencies in meeting their statutory requirements to ensure that they protect sources and methods associated with the classified information their agen- cies collect. Overclassification. There is broad consensus across the U.S. government and among stakeholders that the system for classifying, declassifying, and otherwise marking and handling sensitive information is at a crossroads. Exorbitant amounts of classified data are created daily, and agency personnel often mistakenly choose classification as the default selection to ensure national security. At the same time, the effectiveness of downgraded and carefully declassified information to support foreign policy efforts has been borne out in, for example, alerting the broader world of Russia’s buildup and likely plans for its invasion of Ukraine. Two executive orders principally govern how the U.S. government handles clas- sified and sensitive information. l Executive Order 13526, “Classified National Security Information,” issued in 2009,38 prescribes the classification levels and procedures for declassification. l Executive Order 13556, “Controlled Unclassified Information,” issued in 2010,39 aimed to establish a uniform program for managing all unclassified information that requires safeguarding or dissemination controls. The current system for declassifying classified national security information (CNSI) is extraordinarily analog, requiring experts’ review of individual records. Declassification policies are based on human review of paper and need to con- template and handle the proliferation and volume of digital records created by agencies. The U.S. government will soon reach the point at which manual review is impossible. The declassification of CNSI should support key U.S. national security objectives, reflect mission priorities, and not serve solely as a necessary procedural function. Reforms should include: l Tighter definitions and greater specificity for categories of information requiring protection. l More stringent policies to effect significant reductions in the number of Original Classification Authorities (OCAs). l Stricter accountability measures at the OCA level and more detailed security classification guides.
Policy matches are calculated using semantic similarity between bill summaries and Project 2025 policy text. A score of 60% or higher indicates meaningful thematic overlap. This does not imply direct causation or intent, but highlights areas where legislation aligns with Project 2025 policy objectives.