HR-7272-119
Forwarded by Subcommittee to Full Committee by Voice Vote.
Sponsored by Randy Weber (R-TX)
What it does
This bill would require the Secretary of Energy to run a program focused on physical security and cybersecurity for natural gas pipelines, hazardous liquid pipelines, and liquefied natural gas (LNG) facilities. The program would coordinate federal, state, and industry responses to security incidents; develop voluntary cybersecurity tools and technologies; conduct pilot demonstration projects; and create workforce training curricula. A savings clause specifies that the bill does not change the existing authority of any other federal agency over pipeline security.
Who benefits
Pipeline and LNG facility operators who would gain access to voluntary cybersecurity tools, technical assessments, and pilot projects at no direct cost to them. Energy sector workers who would benefit from new workforce development and training curricula. State governments that would gain a clearer federal coordination partner for incident response. Consumers and communities near pipeline infrastructure who could benefit from reduced risk of disruptions like the 2021 Colonial Pipeline ransomware attack. Cybersecurity contractors and technology firms that may be engaged to develop and test new applications.
Who is hurt
Taxpayers who would bear the cost of funding the program, though no specific appropriation amount is stated in the bill. Other federal agencies — particularly the Transportation Security Administration (TSA), which currently holds primary pipeline cybersecurity authority — may see their relative influence reduced through DOE's expanded coordination role, even though the savings clause preserves their formal authority. Competing energy infrastructure sectors (e.g., electric grid, water systems) that do not receive equivalent new program resources may face relative disadvantage in federal attention and funding.
Supporters argue
Supporters argue that the 2021 Colonial Pipeline ransomware attack — which disrupted fuel supplies across the Eastern Seaboard and triggered a federal emergency declaration — demonstrated a critical gap in coordinated federal cybersecurity response for pipeline infrastructure. They contend that the bill's voluntary, collaborative approach avoids heavy-handed mandates while building the technical capacity and inter-agency coordination needed to prevent or rapidly recover from future incidents that could affect millions of Americans' access to fuel and heating.
Opponents argue
Opponents argue that voluntary programs without enforceable standards have a poor track record of achieving meaningful security improvements, pointing to years of voluntary cybersecurity guidance that failed to prevent the Colonial Pipeline attack. They contend that layering a new DOE coordination program on top of existing TSA and CISA pipeline security authorities risks duplicating bureaucratic effort, creating jurisdictional confusion, and consuming resources without producing measurable security gains — particularly given the savings clause that leaves all existing agency authorities unchanged.