Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Congress’s current proposal on ransomware and financial institutions would require the Treasury Department to assess how government agencies and private firms coordinate—not ban ransom payments or impose a new, universal incident-reporting deadline. The 2025 measure, H.R. 807, the Public and Private Sector Ransomware Response Coordination Act of 2025, was introduced on January 28, 2025, and referred to the House Financial Services Committee. It remains an introduced bill, not law.
What H.R. 807 would do
Sponsored by Rep. Zach Nunn (R-Iowa), with Rep. Josh Gottheimer (D-New Jersey) as an original cosponsor, H.R. 807 would direct the Treasury secretary to examine how public agencies and financial institutions prevent and respond to ransomware attacks. Rep. Eugene Vindman (D-Virginia) was later added as a cosponsor, according to the Congress.gov cosponsor record.
The measure would require a report to four committees: the House Financial Services Committee, the House Permanent Select Committee on Intelligence, the Senate Banking, Housing, and Urban Affairs Committee, and the Senate Select Committee on Intelligence. The report would be due within one year after enactment. Treasury would also brief those committees within 15 months of enactment. The report would be unclassified, with the option of a classified annex.
The review would cover:
- How financial institutions, Treasury and other relevant agencies coordinate to prevent and respond to ransomware attacks.
- Whether agencies receive incident information promptly and whether it is useful for prevention, investigations and prosecutions.
- What existing reporting requirements ask of institutions and whether those requirements generate useful information.
- Why institutions may delay or withhold reports, and how information sharing or response times could improve.
- Whether additional legislation is needed, including feedback from cybersecurity and ransomware-response service providers.
The introduced text is available on Congress.gov. The 2025 bill follows a similar proposal, H.R. 9315, introduced in 2024. That earlier bill did not advance beyond referral to the House Financial Services Committee; its text and legislative record show the same basic report-and-briefing approach.
What it would not require
H.R. 807 is an information-gathering and coordination proposal, not a new operational rulebook for banks and other financial institutions. Its introduced text does not:
#1 Best Overall
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
- Ban ransomware payments or make paying a ransom illegal.
- Set a new, general incident-reporting deadline for financial institutions.
- Require particular security controls, such as specified backup, encryption or network-segmentation standards.
- Create an automatic enforcement or funding program.
That distinction matters: the bill asks Treasury to assess existing reporting requirements and examine why information may be delayed or withheld. It does not itself establish a new universal duty to report ransomware incidents immediately. Other federal or sector-specific reporting rules may apply to an institution; H.R. 807 would not replace or summarize all of them.
Why focus on financial institutions?
A ransomware incident at a financial firm can threaten more than the victim’s files. Institutions handle sensitive personal and transactional information and support payments, lending, trading and customer access. An outage or data theft at a bank, payment processor, cloud provider or other service firm could affect customers and connected businesses beyond the organization first hit.
Rank #2
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
That interconnectedness makes ransomware a potential operational and confidence problem as well as a cybersecurity one. But the bill’s focus on financial institutions does not mean every incident at a vendor or supplier is automatically covered. The text uses a statutory definition of “financial institution,” and the practical treatment of incidents involving outsourced infrastructure would depend on the facts and any applicable interpretation. Modern attacks can also combine encryption with data theft, extortion, credential compromise or disruption, complicating the question of how an event is classified.
The reporting dilemma behind the proposal
Faster, more useful reports can help government agencies connect attacks, identify criminal infrastructure, investigate payment flows and warn other potential victims. But disclosure during an active incident can be difficult. A firm may be trying to restore systems, preserve evidence and protect customers while weighing legal duties, reputational risk, market effects and the sensitivity of information about vulnerabilities or operations.
Rank #3
- World’s First 6TB 2.5” Portable Hard Drive
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
More reporting can also mean duplicated requests or uncertainty about which agency needs what information and when. H.R. 807 asks Treasury to examine these obstacles; it does not resolve them. It also does not establish a single lead agency for every incident, promise a safe harbor for early disclosure, or specify a common reporting portal. Those are possible policy choices, not provisions of the bill.
Other approaches Congress could consider include harmonizing existing reporting rules, creating a shared reporting channel, offering protections for good-faith early reporting, setting a defined mandatory deadline, restricting ransom payments, or establishing minimum resilience requirements. Each would raise different questions about burden, privacy, enforcement and incident response. H.R. 807’s narrower first step is to ask what is working and what is not.
Rank #4
- SonicWall Advanced Protection Service Suite for NSA3700 - 3 Year License (02-SSC-6910)
- Capture ATP with RTDMI for Enterprise: Defend against zero-day exploits and ransomware using multi-engine cloud sandboxing and advanced memory inspection.
- Full Threat Protection Stack: Includes Gateway AV, Intrusion Prevention, Anti-Spyware, Application Control, and Content Filtering for layered defense.
- 24x7 Global Support & Firmware Updates: Keep your firewall protected and operational with continuous technical assistance and critical firmware upgrades.
- Application Intelligence & Network Control: Identify and control network activity with deep traffic analytics and reporting features.
What supporters say
The sponsors have framed the proposal around rising ransomware costs, fragmented public-private response and the need for timely information. In 2024 coverage of the earlier bill, Nunn cited more than $1 billion in ransomware “bounties” paid by American businesses over the prior year; that figure was his stated rationale, not an independently verified total in the bill itself. CyberScoop’s report covered the original proposal and the sponsors’ comments.
Bipartisan sponsorship signals support from lawmakers of both parties, but it does not establish broad congressional backing or committee approval. A report requirement could give lawmakers a clearer basis for further action, but a report alone would not improve defenses, speed incident response or ensure that recommendations become law. The introduced text also contains no appropriations for carrying out a new program.
Best Value
- Slim durable design to help take your important files with you
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Legislative timeline and status
- August 6, 2024: H.R. 9315, the 2024 version, was introduced by Nunn and referred to the House Financial Services Committee.
- January 28, 2025: Nunn introduced H.R. 807, the successor proposal, which was referred to the same committee.
- September 11, 2025: Vindman was added as a cosponsor.
- Current record: Congress.gov lists H.R. 807 as introduced and referred. The retrieved legislative record shows no House or Senate passage, enactment, or amendments.
Because H.R. 807 has not been enacted, its one-year reporting and 15-month briefing deadlines have not begun. Treasury has not been required by this proposal to produce the report.
What to watch next
The next meaningful step would be committee action. If Congress advances the bill, the questions for financial firms will include which reporting regimes Treasury should assess, how sensitive customer and market information would be protected, and whether any recommendations would reduce duplicate reporting without slowing response. The proposal’s practical effect would ultimately depend on enactment, Treasury’s implementation and whether Congress acts on the findings.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

