Security News

Lawmakers Push to Classify Biotech as Critical Infrastructure After Cyberattacks

CyberScoop · 25 Sept 2026
Key Takeaway Australian businesses in biotech, health, or research supply chains should treat sensitive genomic and biometric data with the same rigour as financial or personal information, since regulatory attention on this sector is increasing globally.

Biotechnology currently falls outside the 16 official critical infrastructure sectors that receive dedicated federal cybersecurity attention in the United States. A bipartisan group of senators and representatives has introduced two bills aimed at changing that: the Protecting Biotechnology and Biomanufacturing as Critical Infrastructure Act and the Protecting Biological Data Act.

The first bill would direct the Department of Homeland Security to develop plans identifying key biotech organisations, engaging with them, and updating national infrastructure protection planning to reflect biotech sector needs. The second bill focuses specifically on genomic and biometric data, aiming to integrate it into national cyber strategy, encourage joint security exercises between CISA and biotech firms, and add specialised personnel to handle biometric data protection.

The push comes after biotech giants Boston Scientific and Amgen both disclosed cyberattacks in the past two months. Senator Todd Young, who chairs the National Security Commission on Emerging Biotechnology, said biotech infrastructure and data are increasingly vital to economic and national security and deserve the same level of protection as other sensitive systems.

Summarised by CISO AI from CyberScoop. We link back to every original so you can read it yourself.