Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Critical Infrastructure Security topic
No spam. Unsubscribe anytime.
Committee advances bill to bar foreign-adversary technology from critical infrastructure, adopts amendment
Summary
House Bill 2696, as amended, would bar certain software and equipment produced or controlled by a designated foreign adversary from being used in critical infrastructure and require reporting and replacement plans; the committee adopted an amendment and returned the bill with a due-pass recommendation.
Get email alerts on the Critical Infrastructure Security topic
No spam. Unsubscribe anytime.
House Bill 2696, as amended, would prohibit critical-infrastructure operators in Arizona from using software or equipment produced or controlled by a designated foreign adversary and would require reporting to the attorney general and the Arizona Commerce Authority when proposed transfers or investments by foreign adversaries affect critical infrastructure.
Representative Nick Kupfer (District 25), the bill sponsor, framed the measure as a protection for state and national security: "I think it's extremely important to protect our nation and protect our state from bad foreign actors," he said, citing concerns about technological vulnerabilities during potential future conflicts.
The committee adopted an amendment (Biyasuchi amendment, dated Feb. 4) that changed several implementation details, including: a requirement that critical-communications equipment manufactured by a federally banned corporation be replaced with equipment not manufactured by a federally banned corporation (rather than explicitly requiring U.S.-made replacements); expanded reporting and certification requirements for providers in the secure-and-trusted communications networks reimbursement program; and a requirement that the Arizona Commerce Authority establish a secure communications channel for critical infrastructure providers and military installations to report emergency damage.
Industry and cybersecurity witnesses described specific risks and examples. Michael Lucci of StateArmor testified that routers with known security risks are widespread and cited open-source reporting on router supply concentrations; he warned that connected devices and modules can provide remote access and manipulation of systems. He said some instances involve equipment now sanctioned or blacklisted at the federal level. Cybersecurity witness Jackie Deal described Chinese "military-civil fusion" strategy and said recent events show persistent, sophisticated cyber threats to Internet-connected devices that could be used to disrupt U.S. infrastructure.
Committee members raised questions about transition timelines, replacement availability and costs. Sponsor Kupfer acknowledged that some existing equipment would need replacement or contract nonrenewal and said he planned to offer a floor amendment establishing time frames for identifying and replacing affected components; he also said he had engaged stakeholders but expected further negotiation.
Formal action: The committee adopted the Biyasuchi amendment and then returned HB 2696 as amended with a due-pass recommendation. The committee recorded a vote of 4 ayes, 2 nays, 1 present (no absent votes).
Why it matters: Witnesses and the sponsor described the bill as a state-level effort to reduce exposure to remote-access vulnerabilities and to require visibility, reporting and coordinated responses for equipment that could function as an attack vector on power, water, communications and other critical systems.
Next steps: HB 2696 will proceed with the adopted amendment; the sponsor indicated he expects to offer a timeline amendment on replacement obligations as the bill moves forward.
