▶ 0:02:28for for
▶ 0:03:28spe for
▶ 0:06:58they for
▶ 0:07:47if we can get the witnesses to take their seats we'll gavlin in just a the committee on Homeland Security will come to order without objection the chair May declare the committee in recess at any point the purpose of this hearing is to examine
▶ 0:08:18the growing cyber threats to our homeland the actors the tactics and the trends specifically we're going to delve into the risk posed by the People's Republic of China which is burrowed into our critical infrastructure and compromised our telecommunications networks we will also discuss the threat posed by our other three nation state adversaries who leverage cyberspace Russia Iran and North Korea I now recognize myself for an opening
▶ 0:08:49statement good morning everyone now that we are officially organized as a committee I I'd like to welcome everybody to the 119th Congress our as we were discussing a little earlier the 119 uh we have lots of work to do uh to support and secure the Homeland and that is why cyber security is our top priority and it is why the topic of our first full Committee hearing is cyber security in today's interconnected World
▶ 0:09:20virtually every aspect of American life impacted by cyber security from our nation's Health Care system and water supply to simple internet browsing cyberspace is increasingly becoming a digital Battlefield America's adversaries use cyers space to undermine our sovereignty and threaten the services and infrastructure that America depends on the People's Republic of China Russia North Korea Iran and criminal actors weaponize
▶ 0:09:50cyberspace to harm our nation they are only getting more sophisticated and unfortunately aggressive right now the PRC is burrowed into our infrastructure let that sink in for a moment China is prepositioned in our infrastructure we know it and they have been for years should we enter into a conflict with the PRC the Chinese Communist party is ready to shut
▶ 0:10:20down our essential services our Communications our energy grid our Maritime ports and our water systems to name just a few we cannot allow this situation to continue the American economy our government the military depend upon the resilience of our networks and our infrastructure it's past time for us to get a step ahead of the typhoons a list of actors that seem to grow every day we've played defense far too long and now it's time
▶ 0:10:50to go on the offensive to do this we need prepared cyber professionals I know that some of these nation states issues go beyond what our current cyber Defenders can address and this is why one of my top priorities this Congress is to pass the Cyber pivot act which cultivates the Cyber Workforce we need at scale we pass it out of this committee unanimously last year and this year we hope to get it signed into law we also need a coordinated whole of
▶ 0:11:20government effort that can rapidly share information with the private sector since the private sector owns and operates most of the critical infrastructure in the United States the collaboration of the organizations our Witnesses represent today is essential I look forward to hearing from our panel of witnesses about how we can improve public private Partnerships for cyber and critical infrastructure issues so far I've focused on one threat actor arguably the one that poses the greatest risk to the United States in cyber
▶ 0:11:50space Beyond however there are many other threats that we must be prepared to address simultaneously for example the Iranian Revolution AR guard Corps has targeted our elections notably hacking the Trump campaign in the 2024 cycle it has also repeatedly triying to compromise us water and Waterway systems the intelligence Community indicates that Moscow uses cyber disruptions to influence the decisions of countries like the United States North Korea is a major culprit of cyber security and cyber
▶ 0:12:20crimes as well to devise strategies to address these challenges and threats in cyber space we must better understand them and that's what we're doing here today our witnesses will provide the insights we need to think critically about tackling current and emerging cyber threats to our homeland all Witnesses are private sector leaders three of whom bring key insights from their government experience thank you all for being here uh to set the scene for us as we dive into the 119th Congress
▶ 0:12:51I look forward to the discussion and to a productive Congress of enhancing our cyber security posture I now recognize the ranking member for his opening statement thank you very much Mr chairman today marks the committee's first hearing as you've already indicated of the 119th Congress and the first hearing the committee will hold during the new Trump Administration I'm encouraged by the Chairman's interest in devoting more of the committee's time to
▶ 0:13:21cyber security this Congress that said I'd be remiss if I did not express concern about what we will be able to achieve over six years ago bipartisan members of this committee came together to support legislation authored by then chairman Mcall to establish cyber security and infrastructure Security Agency now commonly referred to as sisa when he signed the bill into law president
▶ 0:13:51Trump said and I quote as a cyber battle space evolves this new agency will ensure that we confront a full range of threats from nation states cyber criminals and other malicious actors of which there are many unquote with the apparent support of President Trump members of this committee work together to pass legislation authored by both Democrats and Republicans to ensure cisa had the resources
▶ 0:14:21and authorities it needed to carry out its important Federal Network and critical infrastructure Mission unfortunately driven by false allegations and conspiracy theories president Trump and many of his many republican colleagues have soured on sisa less than a year ago over 100 of them voted to cut cis's funding by 25% some of the loudest and most influential voices on the
▶ 0:14:51other side wanted to eliminate sisa entirely entirely so even relatively minor bills that touch cisa have been difficult to advance I'm hopeful that the committee's focus on cyber security this Congress will help members understand that sisa does and does what sisa does and does not do so we can return to our bipartisan work of making the digital ecosystem safer and more secure
▶ 0:15:22bearing that in mind we have to be clear ey about the enormous task ahead Cyber attack attacks from China Russia Iran and cyber criminals are growing Bolder and more prolific last year former FBI director Christopher way Ray warned that Chinese threat actors like boat typhoon POS an emminent threat to the US critical infrastructure because they are prepositioning to physically wreak havoc on our critical
▶ 0:15:53infrastructure at a time of its choosing preparing critical infrastructure owners and operators to defend and build resilience in PRC sponsored cyber attacks requires consistent investment in sister's program and that is to say nothing of its work to help private sector defend against the Espionage threats posed by salt typhoon and silk typhoon or the threats posed by other adversaries
▶ 0:16:24during the 116th and 117th Congress this committee worked on a bipar partisan basis to right side sister's budget so it would be well positioned to defend Federal and critical infrastructure networks against these types of urgent threats in fact in 2020 the top Republican on the committee advocated that cisus should be a $5 billion agency 2025 so I was troubled by dhs's
▶ 0:16:54secretary nominees testimony last week that she wants us smaller sister because it's guiding far off Mission although it was not entirely clear what she meant by that comment committed Democrats will oppose any effort to Short Change sister's Mission or its Workforce the Biden Harris Administration left behind a solid foundation for improving the nation's cyber security that the new Administration can build
▶ 0:17:24upon its National cyber strategy put the country on P path to reduce cyber Risk systematically by Shifting the responsibility for security away from our constituents and on to technology manufacturers and by incentivizing the adoption and integration of better security practices its executive orders on cyber security modernize the federal government's approach to securing its own networks
▶ 0:17:55sought to address supply chain and thirdparty risk and harness the security benefits of new technologies for its part CIS launched the successful state and local cyber security grant program LED efforts to improve the security of the technology we use through its secure by Design program and began to mature its operational collaboration activities through the joint cyber defense collaborative the new
▶ 0:18:25Administration should not reverse course on this hard on progress before I close I'd also like to express my concern regarding the the this dismal dissemination of government members of advisor I'm sorry dismissal of non-government members of advisory committees inside the department including the Cyber safety review board and the sister advisory committee the csrb
▶ 0:18:55is in the process of investigating the typhoon hack of nine major telecommunication companies and it is a national security imperative that the investigation be completed expeditiously I'm troubled that the president's attempt to stack the csrb with laist may cause its important work on the salt typhoon campaign to be delayed the American people deserve better with that I thank the witnesses for being here
▶ 0:19:26and I'll yield back to balance of my time thank you ranking member other members of the committee are reminded that opening statements may be submitted for the record I'm pleased to have a distinguished panel of witnesses before us today and ask that our Witnesses please rise and raise your right hand do you solemnly swear that the testimony you will give before this committee on homeland security of the United
▶ 0:19:56States House of Representatives will be the truth the whole truth and nothing but the truth so help you God let the record reflect that the witnesses answered in the affirmative and thank you you may be seated I'd now like to formally introduce our Witnesses Mr Adam Myers currently serves as the senior vice president of counter adversary operations at crowd strike where he leads the company's threat intelligence line of business he also oversees the development and deployment of AI
▶ 0:20:26machine learning reverse engineering and other Technologies to detect suspicious and malicious cyber behavior before joining clown strike Mr Myers was the director for cyber security intelligence at Sr International Mr Mark Montgomery Mr Mark Montgomery serves as the senior director of the center on Cyber and technology and Innovation at the foundation of Defense of democracies Mr mcgomery also directs CSC 2.0 an initiative that works to implement the recommendations
▶ 0:20:57of the congressionally mandated ated cyers space salarium commission where he serves as an executive director previously Mr Montgomery served as policy director for the Senate armed services committee he served in the United States Navy for 32 years as a nuclear trained surface Warfare officer retiring as a rear Admiral in 2017 Mr Brandon Wales Mr Wales serves as vice president of cyber security strategy at Centennial 1
▶ 0:21:27before his current role Mr whales served as the acting executive director of sisa where he supervised the agency's operations and spearheaded its long-term strategy development Mr Wales was also appointed senior response official leading the domestic preparedness and response concerning the crisis between Russia and Ukraine he spent almost 15 years at DHS in various leadership roles Miss Kima Walden Miss Kimo Walden serves as the president of the Paladin Global
▶ 0:21:57Institute which was found Ed to bring the private Capital perspective into technology policy previously she served as the acting National cyber director and was on CD's inaugural principal Deputy prior to oncd uh Miss Walden served as assistant general counsil for Microsoft's digital crimes unit she has over a decade of experience at the Department of Homeland Security I thank all of our Witnesses for being here today and I now recognize Mr Meyers for 5 minutes
▶ 0:22:27to summarize his opening statement chairman green ranking member Thompson members of the committee thank you for the opportunity to testify today my name is Adam Myers and I serve as senior vice president for counter adversary operations to crowd strike for over a decade I've led the company's practice area monitoring and disrupting cyber threats today I will share insights into the global cyber threat landscape and highlight steps we can take to strengthen our Collective defenses as a leading us cyber security company
▶ 0:22:57crowd strike has a unique vantage point which gives us unparalleled visibility into adversaries evolving tactics and allows us to see the full scope of the threats facing our nation after over a decade of investing in programs to strengthen their cyber capabilities China has matured to achieve at least parity with other world cyber Powers they now possess a sophisticated and highly effective offensive cyber capacity targeting every region and every industry vertical across the globe
▶ 0:23:28recent campaigns demonstrate the ability to compromise large well-resourced and well- defended Enterprises operating as providers for the rest of the technology ecosystem one indicator of this maturation is recent Chinese operations aimed at conducting upstream or bulk collection and subsequent Downstream targeting of us political and National Security officials some notable China Nexus adversaries we've observed recently include vangard Panda also known as volt typhoon operator Panda which likely overlaps with an actor elsewhere
▶ 0:23:58report reported a salt typhoon and Lial Panda which heavily targets telecommunications and critical infrastructure some campaigns are suggestive of pre-positioning capabilities which could be precursors for disruptive and destructive cyber attacks over the past year cyber Nexus intrusions increased 150% across all sectors on average compared to 2023 these increases were most significant in the financial services media manufacturing and Industrials and Eng
▶ 0:24:28engineering sectors which all experienced between 2 and 300% increases compared to previous years Beyond China other threats continue to evolve North Korea has engaged in significant financially motivated threat activities since at least 2015 recently they've exploited numerous us companies by pursuing remote working opportunities earning a paycheck while occasionally stealing intellectual property Russia Nexus adversaries continue to prioritize intelligence collection against Western military
▶ 0:24:58political and diplomatic entities with their operations heavily influenced by the war in Ukraine these actors have evolved their tactics to Target mobile devices reflecting a need for Battlefield intelligence in 2024 motivated by ongoing conflicts in the Middle East Iranian Nexus adversaries continued to extensively Target Israeli entities one threat actor Charming kitten collected Intelligence on Regional policy experts While others conducted destructive operations and information operations they've also begun on
▶ 0:25:28leveraging artificial intelligence to enhance their capabilities including vulnerability research and exploit development from a criminal perspective ransomware threats continue to impact all geographic regions and industries activists for their part continue to grow in sophistication and also increasingly engage in for-profit e- crime in addition to pursuing social political and terrorist agendas the Cyber threat landscape is complex Dynamic and increasingly interconnected adversaries are constantly
▶ 0:25:58refining their tactics to exploit vulnerabilities across Industries and sectors to counter these threats we must raise the cost of cyber attacks and reduce their impact this requires investment and a collaborative effort across government industry and the cyber community cyber security Community I recommend that enterprises must take steps to defeat the threats I've outlined today these include strengthening identity protection such as through identity threat detection and response enhancing Enterprise VIs ility
▶ 0:26:28through mpoint detection and response and integrating detection and Telemetry data through next Generation Sim capabilities to enable proactive threat hunting the federal government can enhance National Security by doing cyber security well adopting best-in-class Technologies and more consistently disrupting adversary infrastructure with respect to the latter recent coordinated operations have degraded threat actor capabilities we need to increase the tempo of these operations for congress's part it's appropriate to perform oversight
▶ 0:26:59to ensure federal agencies are actively pursuing the objective outlined above as well as ensuring resource alignment and accountability further it's worth contemplating the use of tax credits rebates and other incentives to make best-in-class cyber security tools and training more accessible as the federal government takes on initiatives to modernize and create efficiencies during this period of transition as well as review and deprecate Legacy programs and systems there's a significant opportunity to move the needle in each of these areas thank you again for the opportunity to testify today and I look
▶ 0:27:29forward to your questions thank you Mr Myers I now recognize uh I guess it's rear Admiral Montgomery yes sir R Montgomery yes uh for five minutes to summarize his opening statement thank you uh thank you chairman green uh ranking member Thompson members of the committee uh for inviting me here today since 911 every president has stated the defense of the Homeland is the nation's number one priority and despite this attention as president Trump takes office this week the Homeland has never been less secure while America does remain risk from physical attack
▶ 0:27:59by terrorists and even missile attacks from Russia and China the most persistent vulnerability is a threat of Cyber attack and make no mistake China is America's most capable and opportunistic cyber adversary look China's not alone as was mentioned Russia Iran North Korea criminal actors they all had Banner years in 2024 penetrating us networks conducting Espionage extorting Ransom stealing sensitive data but of greatest concern to me is China's volt typhoon operation which involves Chinese hackers installing
▶ 0:28:29malware within infrastructures this malware lies in weight ready to disrupt and destroy us systems at a time of beijing's choosing this campaign penetrated numerous critical infrastructures in the United States including ports Energy Systems and water utilities as a military planner I used to call this operational preparation of the battlefield China's overarching goal in executing an operation like Vol typhoon is to disrupt or degrade America's Rail Port and Aviation systems
▶ 0:29:00so that the US cannot rapidly mobilize military forces and get military equipment personnel and supplies to the battlefield and addressing these cyber vulnerabilities is going to be really challenging because the defense department does not control the infrastructure on which military mobilization depends instead the US military relies on 18 commercial ports 70 civilian airports and 40,000 mies of commercial Rail lines that's how we move our troops and our Qui equipment overseas and
▶ 0:29:30these systems are largely owned by the private sector and local governments and they're often maintained with insufficient levels of cyber resilience to make matters worse the energy financial services and Manufacturing industries that drive economic productivity in our country and the water food and Health Care systems that keep Americans alive they're all equally vulnerable to this Cyber attack and both nation states and criminals out for a quick payday take advantage and while the private private sector does own this critical infrastructure
▶ 0:30:00and they've definitely not done enough to invest in cyber security the US government is also at fault for its poor performance as a partner to the private sector and many of the federal agencies that are responsible for what we call the public private collaboration some are even uninterested and many of them are underresourced in the mission so I think as we look for Solutions the key challenge for the United States is to restore deterrence in cyberspace making it too hard or too painful for an adversary
▶ 0:30:30to disrupt or exploit our networks and systems here in the United States to do this requires both deterrence by denial improving our defensive efforts and deterrence by punishment which is improving our ability to impose costs on an adversary overseas in my written testimony I provide eight recommendations but I just want to highlight four of them here given the time constraints first we need to secure the critical infrastructures that support military Mobility we have to address the V vulnerabilities in aviation Rail and Port infrastructure
▶ 0:31:01and ensure that the Coast Guard TSA and FAA had the necessary authorizations and Appropriations to execute their missions and the private sector operators of these systems will need Technical and financial assistance to combat the Chinese cyber tax and ensure the availability of essential services in a time of Crisis second we got to prioritize assets the United States cannot protect everything everywhere all at once within critical infrastructure there are assets and entities that are more critical
▶ 0:31:31to US National Security these assets need Priority Access to intelligence and incident reporting support incident response support sorry in return the American people should expect these assets to practice a higher level of cyber security third we need a better utilize the National Guard to defend our critical assets the guard uniquely Bridges military and civilian sectors as well as federal and state government authorities making it ideally suited to resp respond to a domestic cyber threat the Congress should work with the Department of Defense
▶ 0:32:02to determine the guard's long-term role in the Cyber protection of critical infrastructure and identify any new necessary authorities which I don't think are many and resources which I think will be many to do this finally we got to we have to recruit and develop an Effective Government cyber Workforce we need to hire more talent for federal state and local governments we need a program that focuses on hiring graduates from vocational schools and community colleges where students can earn skills certifications the Cyber pivot act
▶ 0:32:32from last Congress answers this Challenge and should be re attacked this Congress in the past the United States has had the luxury thinking about how to handle a threat from an adversary State over there in their backyard things are different today to make America secure we'll have to make the investments in cyber security and critical infrastructure that America has postponed for far too long again thank you for inviting me to speak and I look forward to your questions thank you
▶ 0:33:07chairman green ranking member Thompson and members of the committee thank you for the opportunity to testify today on global cyber threats a subject that I've spent nearly two decades focused on in government service and in the private sector the past few years of publicly acknowledged intrusions by China Russia Iran North Korea and cyber criminal organizations make clear that the US is facing increasingly sophisticated adversaries in ongoing cyber warfare the intensity of that threat is at an all-time high driven by a combination
▶ 0:33:38of increased geopolitical tensions and the rapid pace of technological change and it shows no signs of abating defenders in both the government and the private sector are learning from each breach however threat actors are also evolving and innovating maintaining a strategic Edge and building National cyber resilience remains a critical Challenge and will require new thinking across the public and private sector among the various cyber threat actors the People's Republic of China stands out for its persistence
▶ 0:34:09breadth of operations and capabilities and I'll Focus the remainder of my testimony here the threat posed by the PRC is nothing new in 2007 they stole the plans for the F35 in 2010 they compromised Google in 2015 they hacked OPM and the list goes on as a as a result of these and other unprecedented attacks Presidents Obama and G negotiated restrictions on Cyber enabled theft of intellectual property however in the wake of that 2015 agreement
▶ 0:34:39the PRC retooled they reorganized and now they are more dangerous than ever according to the FBI their hacking program is now larger than every other major Nation combined and over the past two years the extent of their strategy has become alarmingly clear in 2023 Microsoft and the US government uncovered that Chinese actors associated with the people's Liberation Army were pre-positioning on us critical infrastructure preparing to launch disruptive or destructive attacks
▶ 0:35:10during a crisis or in the Prelude to war that summer Chinese actors compromised Microsoft signing Keys granting them access to nearly anyone's email on Microsoft Exchange online late last year it emerged that Chinese Ministry of State security actors had breached major US Communications compan companes the prc's objective is unambiguous they are preparing for war on the networks of America's businesses infrastructure and government agencies
▶ 0:35:40their goals are to prevent the United States from defending its Partners in allies by disrupting our ability to project power into the Pacific and to weaken America's resolve by causing societal chaos inside the Homeland our response must be equally cleare eyed through a whole of society effort that combines government resources authorities and expertise with private sector Innovation insights and reach all underpinned by the support of the American people which brings me to a series of
▶ 0:36:11recommendations first the federal government should continue strengthening and centralizing critical cyber security capabilities within cisa streamlining regulatory oversight of industry and regulating smarter rather than simply more additionally the government must fully Leverage its tools alongside those of our partners and allies to disrupt and deter adversaries wherever possible second Business Leaders particularly in our nation's critical infrastructure need to understand that the government cannot save
▶ 0:36:41them from all threats cyber risks are Core Business risks and therefore companies are ultimately responsible for their security and resilience more importantly if they are not already preparing for a crisis with China they're late third the government industry and the public must collectively demand more from technology product and service providers we cannot secure our diverse infrastructure one system at a time unless the technology we depend on is secured by design
▶ 0:37:12by default and in operation we will remain at the mercy of adversaries finally we must be transparent about the sources of the Cyber threats we Face vague terms like typhoon or Panda are fine for internal actor tracking but in the broader public discourse they they obscure rather than clarify that foreign military and intelligence agencies are actively planning to attack systems critical to public health safety security and economic well-being calling these actors by name is essential to fostering public understanding and engagement
▶ 0:37:43and time is not on our side president G has instructed the pla to be ready to militarily retake Taiwan by 2027 this means the US government industry and allies have only two years to prepare to that end the actions of the 19th Congress could prove among the most consequential in modern history I applaud the committee for prioritizing this issue first and I look forward to your questions thank you thank you Mr Wales I now recognize Miss Walden for five minutes to summarize her opening
▶ 0:38:13statement chairman green ranking member Thompson distinguished members of the committee thank you for inviting me to testify today on this important topic I'm kembo Walden president of the Paladin Global Institute and co-chair of the digital us cyber security group I'm here today in my personal capacity drawing from my experience from former as former acting National cyber director and my roles at Microsoft and at the Department of Homeland Security the last year four years have seen new sophisticated cyber
▶ 0:38:43threats Each of which has highlighted why cyber remains a significant source of human caused risk to our homeland we saw the 2020 Russian attack on the solar winds Orion platform and then the 2021 ransomware attack against Colonial Pipeline and then in 2022 the first shots fired in Russia's unprovoked war of aggression in Ukraine were from a Cyber attack targeting an American satellite Communications company each of these incidents represents a clear
▶ 0:39:13national security threat in their own right and I haven't even mentioned the Microsoft Exchange service server debacle log forj or the billions of dollars spent in the aftermath of change Healthcare yet there are two campaigns in the past four years that I hope the committee will focus its attention on the first is the recently uncovered targeting of our nation's critical infrastructure by the People's Republic of China this activity dubbed volt typhoon represents a step change in the PRC cyber operational capability demonstrating their willingness
▶ 0:39:44to preposition in our critical infrastructure in preparation for a conflict second we've now witnessed the PRC snooping on our telecommunications networks salt typhoon shows the PRC Investments are paying off in truly a scary fashion as they have access to the Beating Heart of the internet itself I raise these two examples to highlight the stakes we Face the prc's capabilities are rapidly improving and we have seen from their behavior that they are ready to use cyber
▶ 0:40:14tools to attack our critical infrastructure but despite these threats there are key steps that Congress and the new Administration can take to increase our resilience and improve the nation's cyber security posture we must strengthen National cyber security by clarifying roles and responsibilities of the private sector and government upscaling our Collective Workforce and embracing technological innovation on the first the roles and responsibilities front there are three legislative
▶ 0:40:45actions that I would offer as loow hanging fruit for you to consider the cyber security and information sh sharing Act of 2015 expires in September this committee must take action to reauthorize that legislation to ensure we do not see hard one progress lost to Congressional inaction I also urge the committee to further clarify liability protections related to the defensive measures to allow for the most proactive
▶ 0:41:15defensive possible regulatory harmonization is an enormous challenge that places an untenable burden on business while H harming our cyber security last Congress senator Peter Senator Langford and Congressman Higgins introduced legislation to help bring coherence to the multitude of federal regulatory approaches by empowering the national cyber director and Cong and Congress should move swiftly to reintroduce and Advance this important
▶ 0:41:47bill this committee should also work to codify the Cyber safety review board or csrb which helps to understand the root cause of cyber incidents to keep us from making the same mistakes over and over I hope you will consider strengthening the board by making it independent and non-partisan with its own administrative
▶ 0:42:17power of course all the policies in the world are meaningless without the workforce implementing them while there are several successful programs that are helping to put a dent and the hundreds of thousands of unfilled cyber jobs we have in this country there is absolutely more we can do to remain sustainable Congress should expand Sis's current cyber Workforce programs increase the number of internships and apprenticeships available to qualifying students with or without college
▶ 0:42:47degrees and provide incentives for cyber professionals to work at underresourced Targets like hospitals and Water Systems finally I urge you to embrace technology including from venture-backed companies that are truly at The Cutting Edge and allow to be part of the solution supporting the use of artificial intelligence for example for threat detection and response can help neutralize sophisticated cyber threats more efficiently distinguishing between our digital
▶ 0:43:17presidents knowing who's who and that you are you is of Paramount importance to cyber security for the federal the federal government must update its digital identity guidelines to prevent unauthorized access fishing and email-based attacks and decrease cyber fraud of public benefit programs in conclusion the global cyber threat landscape requires a coordinated proactive approach combining legislative action technological innovation and operational collaboration acting together we can protect our national security
▶ 0:43:47interests while fostering Innovation and economic growth thank you again for the opportunity to appear before you and I look forward to your questions thank you m Walden uh members will be recognized in order of seniority for their 5 minutes of questioning I want to remind everyone to please keep their questioning to five minutes an additional round of questioning may be called after all members have been recognized I now recognize myself for five minutes of questioning over the last year the uh US government has discovered a a number of
▶ 0:44:18PRC state sponsored threat actors deeply embedded in an across the nation's critical networks F typhoon Salt typhoon flax typhoon and most most recently silk typhoon have compromised our critical infrastructure hacked sensitive Communications breached Federal Etc I appreciate Mr wal's comment about uh these names seemingly masking the real true identity of the threat and I
▶ 0:44:48I I I take that uh I take that to heart um we need to call China out aggressive I ly on this um it's alarming that most of our critical infrastructure systems have been violated right under our noses Mr Myers can you explain the prc's Playbook on how each of the typhoon operations or how China's cyber war against the United States is how they're doing it
▶ 0:45:18thank you chairman China has engaged in uh as I mentioned a maturation in how they conduct these operations today they're using exploits that Target external facing devices that are connected directly to the internet that effectively Bridge Enterprises to the internet these devices are often unmanaged uh in many cases they may be Legacy or have proprietary capabilities that means that they don't run modern
▶ 0:45:49security tools and China is uh also National you give an example of one of those like is are we talking about a fit bit on your rist or what are we talking about sure uh like a router or a VPN concentrator uh things that are meant to connect the Enterprise to the network or allow remote users to authenticate in are some of the nod so to speak between silos yes sir and and these are highly prioritized and highly valuable targets for these threat actors
▶ 0:46:19um they've nationalized their vulnerability research program in 2018 for example they changed the National Security Law in China and all V vulnerability research has to be submitted through the Chinese government whereas here in the United States we follow something we call responsible disclosure where if I find a vulnerability in a product I notify that product vendor in order to try to get it fixed they're effectively nationalizing that that resource so that they can use that for exploits against American Technology and American companies
▶ 0:46:49uh once they gain that access they attempt to remain stealthy and either conduct Espionage in order order to inform political and Military decision-making or in the case of Vanguard Panda also known as volt typhoon the prepositioning that we've discussed here which would be potentially useful to bring down some of these networks that Mr Montgomery mentioned uh in time of conflict um one of the questions I have of all of you and I'm not going
▶ 0:47:20to ask for an open answer today but I'd like to ask if in right I think that's something that's really important and my uh to tackle this Congress list um I want to ask or or just I only have a minute rear Admiral Montgomery you mentioned the National Guard and their importance in the defense of the nation one of my National Defense authorization act amendments last cycle I'm going to bring It Forward again this cycle is to put a cyber defense
▶ 0:47:50unit National Guard unit in every state uh as much to help you know our own National Defense but really because the states can then you know put those guys on uh title 32 and use them in the event that because our local governments and our our uh states are getting hammered just as much as the federal government is and I I wanted to get your thoughts on that while I had a few seconds well I agree and I agree for several reasons one Governors have authorities that at the state level that the feds
▶ 0:48:21federal government doesn't have so actually having them local like that uh good two they have relation ships within the community already they come from companies there and I do think you need it spread widespread because the um state will lend you know uh Disaster Response to a state six or seven states away because they can look at a weather map and say I'm not going to have the same event but if a cyber event starts to unleash itself Governors are not going to be that comfortable lending their limited cyber to uh
▶ 0:48:51capabilities to a state that doesn't have them so I do think there's value and having a more robust National guard uh capacity and having it across all 50 states in four territories is probably the right answer thank you uh I uh my time has expired and I now recognize the ranking member for his five minutes thank you very much uh Mr chairman and I uh applaud your effort on identifying cyber uh security as a critical area
▶ 0:49:21for this committee to look at and if I would capsule the the the testimony uh we do have a problem uh the question is are we addressing it in the best manner one of the things we did was create sisa as part of the um I guess the the question is uh do you
▶ 0:49:51see a continued role for um and and is there some other roles that sisa might play uh since that's kind of where we are uh today and I I'll start with you Mr Myers and and we'll kind of go down thank you uh ranking member the um we would happily work with any federal agency that is charged with
▶ 0:50:22securing the cyber security of the United States um as far as which agency is appropriate I i' defer to the to the federal government on that one I do believe that we need a uh sisa and the specific one that you all have authorized you've worked the last four years to modify sza's actual authorities year after year uh I do think I'd like siza to focus on their role as the risk manager for the country in other words bringing together risks
▶ 0:50:52from all the different sectors and understanding which are the number one risk risk areas that we need to address I've pointed out rail ports and Aviation that cuts across multiple federal agencies so you do need one quarterback of the team to bring together all the different risks that they've assessed and provide that Guidance the current uh Brandon in his last job siza made a recommendation to the White House for that and the National Security memorandum 22 that came out gave him kind of a lukewarm
▶ 0:51:22responsibility I'd give him the full-on responsibility as a SE risk management leader for the federal government and making sure we work well in a public private collaboration so yes we do need a siza we probably need a sza that's envisioned differently than the last two presidential administrations have it uh sir I you know sis is essential both because it has unique sets of authorities and resources to tackle this problem uh only it has the the authorities
▶ 0:51:53necessary to um move the federal government in terms of protection of uh the.gov um in terms of providing both capabilities to agencies and helping departments agencies across the government move to a more common Baseline I think we have seen with Congressional support in terms of authorities and resources that since the solar winds attack in 2020 there has been a remarkable change in the degree of of of protection and security we have uh of our federal networks I think as you look
▶ 0:52:23to the private sector again cis's unique authorities in terms of engaging ING with industry to be able to have protected conversations serve as a focal point working with other sector risk management agencies those are unique authorities capabilities and expertise resident in cesa um and so that needs to continue now how do we grow it um how do we refine it to make sure that we can tackle the scale and pace of the threat we face today is a challenge that we're all going to need to Grapple with um but that all of it continues
▶ 0:52:53to point to the urgent need to continue those those capabilities and I'm going to Echo my colleagues here sisa is absolutely essential to the defense of our critical infrastructure uh this committee has done some powerful things for sisa and I think needs to continue one is what I mentioned sisa 2015 uh the superpower for information sharing that liability protection that encourages the private sector to engage um could be improved but that is a key superpower
▶ 0:53:24another is that sisa is is for formed as a national coordinator for federal civilian executive branch agency uh defense of critical infrastructure I think that needs to continue and in fact should be improved uh there is language in the Homeland Security Act that allows sisa to provide technical assistence a upon request uh to anybody that needs it prioritized by critical infrastructure uh that is key but also strengthening cis's
▶ 0:53:54ability to do that across borders recognizing that our digital infrastructure is is global in nature sisa needs maybe some clarity on how to do that provide that technical assistance when requested internationally as well thank you very much uh Mr chairman I think it's clear that uh uh whatever uh uh sisters uh end up being that it appears
▶ 0:54:24that uh at least three beautiful and maybe the fourth witness say if it's sister I'll work with sister uh that we need to make sure that uh that mission uh that sister presently undertakes is maintained and and with some of the enhancements offered the coordination and other things I think is very important so with that I yeld back I thank the gentlemen and uh I now recognize the former chairman of the
▶ 0:54:54committee and the committee of are the chairman ameritus Mr McCall from Texas for five minutes thank you Mr chairman thanks for holding uh your first hearing on this very important uh topic um and as a ranking member stated a very bipartisan issue uh the ranking member and I passed the cyber security and infrastructure Security Agency act in 2018 um because it was a civilian agency we thought best capable to
▶ 0:55:24interact with the private sector um since that time I I believe it's stood up its capabilities its credibility um but the world is on fire today it's a far more dangerous place than it was in 2018 from a cyber perspective um particularly when you look at China Russia Iran North Korea um I was a sanctioned by China I'm the target of a disinformation campaign by
▶ 0:55:54China along with three other members one of whom now is the Secretary of State Rubio um so I've kind of U firsthand witnessed this um but I think this the one of the most frightening things to think about is this ability to preposition U malware on critical infrastructure to give them the capability to turn the switch off at any given time and then uh to bring
▶ 0:56:24Darkness to the entire East Coast or to uh ports you know in New Orleans or Houston um can you maybe Admiral start with you explain how that exactly works and what can we do to um fortify and strengthen these uh these critical infrastructures thank you for the question I'm sorry I was going thank you sir um look you're
▶ 0:56:55you're you're right on that the to me this was a prompt jump in other words what we discussed previously was intellectual property theft there's been Espionage this is this operational preparation of the battlefield it is a war- making action and you know we have to take it much more seriously I think that we you know that the idea that they've pre-positioned uh malware or that they have uh capabilities that that uh lie in weight uh that can come out at the right time is as we're making a decision to move
▶ 0:57:25you know to respond into a crisis in Taiwan or crisis in the Baltic states um transcom operates on these unclassified networks with civilian systems this is why I think former representative Waltz is right in the sense that we have to go on the offensive we now have to actually publicly execute operations against Chinese cyber infrastructure to say we know you did this we know you use this infrastructure to do this and we're going to remove that infrastructure from your capability
▶ 0:57:56we may sacrifice a tool we may sacrifice an access but I think the military the Cyber command and the intelligence communities have lots of tools and lots of accesses but we need to demonstrate publicly and and we should attribute it to ourselves say we did this because of what you did otherwise the Chinese are going to keep doing what they're doing I I totally agree we need to call them out for this we know that in the event of an invasion of Taiwan they will shut down their entire grid and
▶ 0:58:26shut down all their cyber and including probably hit the west coast of the United States at at the same time how crazy would we go if we found 20 satchels of of uh explosive strapped to different electrical power grids or Port or Port cranes around our country and could attribute it to China or Russia we would we would seriously be moving forces and say this is completely unacceptable Behavior but somehow in cyberspace they get a pass that's not right we need to be
▶ 0:58:56more offensive about this we the the the the bar for taking action has got to be lowered down to one that is that makes America and our infrastructure secure right now it's too high I think that physical analogy is always accurate like for instance when the OPM hack occurred 23 million security clearances stolen I mean can you imagine if Chinese operatives were caught at OPM actually stealing that data in person and we we tend to think cyber somehow not uh that it's different and it's really
▶ 0:59:26not Mr Wales can you in my remaining time um this Unholy Alliance I call between China Russia Iran North Korea um do you see any um in this alliance any um formation of working together in the Cyber threat space so I'd say that there are um very there are some but limited connections at this point in part because there is not a significant degree of trust amongst those countries
▶ 0:59:56despite their willingness to work together in very isolated places uh theyve also been caught conducting operations against each other um which is one of the reasons why they don't have a tight of an alliance as let's say the United States does with its uh five eyes Partners uh where it's um much closer sharing of information conducting joint operations Etc we don't see that yet um amongst uh our adversaries uh but that is changing we're seeing closer Connections in places like Ukraine in terms of Russia Iran North Korea ET so
▶ 1:00:27um we obviously have to care play watch that space very carefully I pass a cyber diplomacy act to help coordinate and deal with that on the defensive side but I know my time has expired thank you Mr chairman gentleman yon I now recognized the ranking member uh of the cyber security uh and infrastructure subcommittee Mr swell the gentleman from pal Alto California Bay are reg Bay Area thank you chairman this is an important topic it's a bipartisan topic Andrew Garbarino and I were very closely together
▶ 1:00:57on the subcommittee but is the senior Californian on the committee and a committee that has jurisdiction over Emergency Management I just briefly uh wanted to express uh my heart breaks and beats for the people in the Los Angeles area where 28 have died thousands of structures have been lost Brave firefighters and First Responders continue to battle the fires today
▶ 1:01:27as unseasonable and unpredictable winds ravage the area and my ask of my colleagues is to just work with the representatives from that area as we have worked with representatives from every area in America that's been effective been affected by disaster before and we've seen in Tennessee for example since 2020 39 billion from
▶ 1:01:58disasters since 2020 Texas has had $68 billion in disaster damage Louisiana has had $34 billion uh from Hurricane Francine Mississippi has had $30 billion Florida hit by Hurricane Milton and many other uh hurricanes has billion uh New York has had $31 billion in Damages Georgia has had $49 billion
▶ 1:02:28in Damages Alabama's had $32 billion in disaster damages Oklahoma has had $30 billion in disaster damages Arizona's had $9 billion in disaster damages South Carolina has had $31 billion in disaster damage Colorado has had $22 billion in disaster damage Pennsylvania $41 billion and North Carolina $37 billion it's it's not a matter of if a disaster will hit your
▶ 1:02:58District or area if you are in Congress it's just a matter of when and the theme has always been uh that we come together and I hope that's the case now last week when I visited uh one of the affected areas uh I stood uh with a mother uh at what was once the site where she and her husband raised uh their two little kids and as she looked for any momento that she could take back to the kids she saw
▶ 1:03:29that their lives in their home had been reduced to complete Ash she found a shiny metal piece in the Ash and noticed that it was a little bowl that her daughter had played with in her makeb belief kitchen and that was all she walked away with uh to take back to her kids and she didn't point fingers she didn't put on a republican Jersey or a Democratic Jersey JY she just expects that the
▶ 1:03:59people who represent her will stand with her and help her find relief in the worst time of her life and the lives of her neighbors and that's I think why we all do this job so Mr chairman I look forward to working with the committee to make sure that wherever disaster hits uh we stand up uh for it I'm going to briefly now just pivot uh to Admiral mountgomery and and I appreciate your service sir uh to the country
▶ 1:04:29I have worked in a bipartisan way and the chairman has supported this work to try and reform uh sisa particularly as it relates uh to JC uh DC The Joint cyber defense uh collaborative and to set more structure and Scaffolding around how individuals are admitted into jcdc and and how they could exit if they're not faithful Partners to it do you see any needed reforms uh at jcdc yes sir thank you and and I do I
▶ 1:04:59appreciated the provision you put forward last Congress I I would only say I would add to it um we need to move the jcdc Beyond a slack Channel which is what it is right now you know a non-real time uh information exchange we need to get the realtime information exchange when the Congress actually passed the provision that the jcdc operates off of is called The Joint cyber planning office um we had other I was R the cyber space larning commission when we put that forward we had other elements to that that were necessary those have not yet
▶ 1:05:30been passed I think they need to be authorized because I think the jcdc to be effective needs to have a planning element a uh an information sharing element which at the speed of data so you can give threat information to to private sector companies at the speed of data and then a Intel working group together that might be at a more classified level that information sharing though has to be at the unclassified level so I think the the the uh improvements in the JC DC um through a a provision would be an excellent work uh
▶ 1:06:00assignment for the 119th Congress that's really helpful I'll take that back uh to our team thank you Admiral yield back gentlemen yields I now recognize uh former chair of the subcommittee uh Mr Clay Higgins from the state of Louisiana thank you Mr chairman gentlemen ma'am thank you for being here miss Walden in your opening in your testimony your written testimony he referenced to cyber security Bill
▶ 1:06:30he stated that uh the bill would help bring coherence to the multitude of federal regulatory approaches the bill would have empowered the national cyber director to convene all of the relevant parties including independent Regulators to develop a set of cross- sector minimum requirements that would have reciprocity baked in whereby business that operates in multiple sectors or that is in the supply chain of many
▶ 1:07:00regulated entities would only need to show they met the Baseline once he stated I'm very confident this approach will both meaningfully improve our cyber security posture and reduce compliance cost I hope Congress will continue last year's momentum and move swiftly swiftly to enact this legislation I thank you for that statement Miss wal because that was my bill introduced in 118th Congress uh the streamlining
▶ 1:07:31Federal cyber security regulation and we are indeed reintroducing that legislation 119th Congress Mr chairman and my colleagues on both sides of the all in this committee uh we we should move forward with that legislation because it allows the industry sector to appropriately position themselves to to to spend less time and money in compliance with regulatory oversight and more of their energy
▶ 1:08:01and focus on actually accomplishing their missions as it regards cyber security Miss Walden could you briefly discuss uh more in depth how compliance with current cyber security regulations Frameworks slows down efforts to actually counter threats thank you for that question and thank you for um reintroducing that bill it's quite an important measure I believe for the overall building of
▶ 1:08:31resilience in our cyber security infrastructure our digital infrastructure right now across the 16 critical infrastructures and I would add a few others that haven't been designated some Industries are highly regulated and also have wonderful controls they could do better but I'm I'm thinking like Finance for example and other Industries are just under the mark and those are the ones that are the most vulnerable uh and so we need to figure out a regulatory approach to bring
▶ 1:09:01the minimum Baseline up so that we're all solving the same problem and doing it in an efficient and effective way and so the the proposition that your bill uh brings forward is not only do federal departments agencies that have regulatory Authority need to fall in line but the independent agencies need to do so and they need to find areas where there's duplicity and so we can eliminate that find areas for reciprocity and then cause all of our infrastructure to have minimum
▶ 1:09:31security requirements so that we're not causing them to just spend money on yes ma'am I agree I mean the federal government should be a partner with the cyber security industry and the emerging Technologies including AI uh we should aggressively support the industry and and their ability to actually perform the mission so Reg ulations and Regulatory oversight should not get in the way of that mission um
▶ 1:10:02Mr Meyers my my own confidential uh cyber Security Consultants that have helped me through through eight years in Congressional service to We the People happen to be partners with crowd strike and they have uh they have shared with me the the their assessment that they have the best technology and their opinion
▶ 1:10:32out there and your OverWatch team is outstanding so I'd like to address to you you you're in the business of tracking criminal state sponsored and nationalist cyber adversary groups across the globe and you deploy Technologies to detect suspicious and malicious cyber behavior and stop in increasingly sophisticated adversaries your worse I would ask you to comment on
▶ 1:11:02the the lack of ability for the security sector to strike back can you would you just address that topic and I'm I yield to the gentleman's answer uh thank you sir uh the security industry I think is uh primarily meant for defensive posture uh one that we uh take very seriously and I appreciate your your support there um I think that there's a lot to be done to partner with law enforcement and those that have
▶ 1:11:32uh the intelligence Community as well and the military that have the titled authority to take those actions and to support those operations and happy to to share with you some of the previous successes in working through that and as I mentioned in the testimony I think it's time that we increase the Cadence of those operations thank you my time has expired but just yes or no if you had the legal author authority to strike back if Congress gave the cyber security industry the legal authority to strike back would you be able
▶ 1:12:02to effectively identify a bad actor and do so we have the visibility to identify many thank you sir thank you Mr chairman for the Indulgence gentleman yields I now recognize uh Mr magaziner who also is a ranking member and we appreciate uh his Service uh for five minutes of uh questioning well thank you chairman and to the ranking member as well and my colleagues it's great to be back and to be starting out uh with such an important and bipartisan topic
▶ 1:12:33uh because the United States faces an incredibly dangerous and growing uh threat landscape with regard to cyber security we Face attacks from International cyber criminal groups such as the brain Cipher Group which attacked my home state of Rhode Island last month stealing sensitive information from hundreds of thousands of Rhode Islanders and we also face increasingly Brazen attacks from adversarial Nations including China Russia Iran and North Korea
▶ 1:13:03we're all very familiar with the capabilities and increasing aggressiveness of China's cyber Warfare campaign most notably salt typhoon which impacted the data of millions Americans and volt typhoon which targets our infrastructure and it's also important that we not lose sight of Russia's aggressiveness against our country as uh this past October the justice department seized 41 internet domains being used by Russian hackers known as the Kalisto
▶ 1:13:33group attempting to infiltrate us companies and government agencies and by the way small town America is not immune from this threat either uh last year a separate Russian hacking group the so-called cyber Army of Russia reborn succeeded in disabling a water system in the town of muu Texas and a Wastewater system in Tipton Indiana among others so my first question and
▶ 1:14:03I'll I'll throw this out maybe to Admiral Montgomery or to any of you who who have this information if you had to guess how many people how many bodies is China for example putting into their cyber Warfare campaign across all of the various organizations they have so this would be a guess and I think if you go into a osed hearing you might get a more refined answer but I would say China is around 60,000 60,000 people to give you some comparison the United States uh
▶ 1:14:33cyber Mission Force our offensive side is about 6,400 so China has 10 times as many people targeting us with cyber warfare as we have trying to defend ourselves and I assume that Russia also through their assorted organizations thousands of individuals so and first I should say we have an intelligent Community intelligence Community element number that we don't discuss um but not it's not 54,000 to close the gap um Russia has a different number uh and Russia's
▶ 1:15:03is a they have both military and intelligence services that do actions and they have contractors through What's called the IRA um a a Contracting group and there's a mix of people in there who do both their number much bigger Global criminal organizations there are countless organizations and individuals targeting us with hacks with ransomware Etc during Governor gnome's confirmation hearing to be Homeland Security secretary she said that sisa needs to be quote much
▶ 1:15:34smaller to fulfill their mission do any of you agree that sisa should be smaller given the number of threat actors that are targeting the United States every day in the cyber space I will take that as a note I'll also note by the way that she was one of only two Governors who turned down federal grants for her state to strengthen cyber security as well so there's a pattern here that is concerning that I'm sure we will ask her about when she comes before this committee assuming she is
▶ 1:16:04confirmed I um also want to commend well a number of the recommendations that have been made I think are terrific and make great sense I want to commend uh you again Admiral for targeting the issue of critical infrastructure I'm the co-sponsor of uh a bill with Cong Congressman krenshaw uh called the contingency plans for critical infrastructure act to mandate that we identify and have contingency plans for critical infrastructure
▶ 1:16:34in the event of a Cyber attack uh also the role of the National Guard uh I want to give a shout out to the uh 102nd cyber operations squadron at the RO Highland National Guard who do a phenomenal job and I actually agree with I think a sentiment that the chairman raised and a number of you as well which is that we need to call cyber attacks with they are they are attacks whether they're targeting our data or our critical infrastructure and I would just suggest that when foreign
▶ 1:17:04actors put misinformation into our information sphere as well with the purpose of trying to influence elections or turn Americans against each other by racial lines or religious lines or political lines that is an attack as well and we need to call that out for what it is Americans have a First Amendment right to say whatever we want online whether it's true or divisive or not and that is a constitutionally protected right but Iran Russia China Etc do not have that First Amendment
▶ 1:17:35right when they attempt to influence our domestic condition by turning Americans against each other undermining election Integrity undermining confidence that is an attack and we need to call that out as well so I'm overtime I thank you chairman and I Y back gentleman y i now recognize the uh chairman of Transportation subcommittee Mr Jimenez from Florida for five minutes questioning thank you Mr chairman before you know I move on to cyber security um as the um only um career
▶ 1:18:05firefighter ever elected the Congress uh I want to share uh you know my colleague Mr swalwell's um um condolences to to what happened in LA but I also would like to see if you would consider doing some kind of a a fact finding trip uh by this committee to LA to determine what the condition were prior to the fire what the response to that fire was and also what strategies what mitigation strategies that we need to take in order to make sure it never happens again
▶ 1:18:35um because there there are certain certain things there that um you know that caused me a little bit of concern about that whole situation mostly was really about the fuel and the control of the fuel because fire needs three things it needs an ignition Source it needs oxygen and it needs fuel and um the ignition Source we don't haven't determined that yet but when you have hurricane force winds you certainly have enough oxygen it certainly appears that they had heck of a lot of fuel and they didn't do a very good job of U for question
▶ 1:19:06maintaining that um yeah I will for just since Mr swell isn't here I I anticipate what he would ask is would you also be interested in a fact-f finding trip or study to see if for example the State of Florida has taken adequate steps to reduce flooding in the event of a hurricane or to reduce damage oh absolutely I I think we are fantastic at what we do in the State of Florida uh and uh I just want to make sure put the same on every state I wouldn't have any problem in doing that you want to visit my town Miami dat County
▶ 1:19:36when I was the mayor sure come on be happy to to show you what we've done okay um now back to uh to artificial intelligence um um to actually cyber security does artificial intelligence have applications in cyber security and a defense mechanism and so Mr Myers or Mr Wales if you want to answer that question yes and I I actually would say that right now we're at a unique moment where artificial intelligence is being integrated into cyber
▶ 1:20:06security applications far faster than we're seeing adversaries able to weaponize artificial intelligence to launch attacks um so most companies Sentinel one uh and among others are working hard to make sure that their technology benefits from the latest and most modern uh artificial intelligence applications so so Mr Mr Myers do you agree yes absolutely we've been using machine learning and artificial intelligence for the last 14 years at crowd strike
▶ 1:20:37fantastic what do you what do you all think about yesterday's announcement of half a trillion dollar investment in artificial intelligence Stargate initiative I guess uh anyone can answer that if they they want do you know about that I I I read in the news uh what I would say is it is important uh particularly in competition Visa China that the United States be a real leader here so anything that we are doing as a nation to ensure that um uh intelligence inovation is happening
▶ 1:21:07inside the United States is going to be good for both our security and our economic wellbeing M re Admiral if we if we uh if we win that race would that supp be able to supplant the the Manpower advantage that that our adversaries may have uh in that regard in terms of Cyber attack and our ability to defend them I do believe artificial intelligence and machine learning can make a big difference in in the speed with which you find accesses and develop tools one thing I would give Congress is as as we
▶ 1:21:37see that 500 billion get invested uh the one area I'm not for regulatory environment here but the one thing I would regulate much like we do at our National Labs is I would demand a uh a level of physical and cyber security around that most important intellectual property the model we and things like that again I wouldn't heavily regulate the entrepreneurial Spirit but I would regulate the security so that we maintain any breakthroughs belong to us and belong to the United States companies and eventually to the United States military
▶ 1:22:07and aren't easily stolen by our adversaries no I believe I believe that uh you know the the artificial intelligence technology is a national security technology much as any any weapon system that we have maybe even more important than any weapon system that we have we have to maintain that advantage and keep keep it in a very very very secure place and hopefully the artificial intelligence will be able to guard itself okay um finally do we have any rebound capability in other words what I mean by rebound cap somebody attacks you and then
▶ 1:22:38the response the rebound to that is even worse than the than the attack so that you know that if you punch me in the nose I'll cut your head off do we have that capability sir that's what I was talking about with we with deterrence you know where we've talked a lot about deterrence by deny here that deterrence by postive position is the is the the punch back um and then defensively we do have to have a rapid recovery one of the things America's good at is getting back up off the mat you know when we're hit but in cyberspace I don't think we're properly organized
▶ 1:23:08for that yet and this is more than FEMA this has got to be we call it Contin the economy uh planning and we've got to get working on that so a better offense and a better ability to recover once we're punched in the face those are going to be the two things we need to win I know I know my time's up and just simple yester will artificial intelligence help us in that yes or no yes thank you and I yield back gentleman yields I now recognize Mr Goldman the gentleman from New York uh for his five minutes of questioning
▶ 1:23:38thank you Mr chairman and uh I agree I'm encouraged by the bipartisan nature um of this hearing on what is increasingly um an important and dangerous threat to our homeland and our security um I in the past though it has not been as bipartisan and in fact in September of 2023 um more than a 100 House Republicans including the
▶ 1:24:08chairman tried to slash cis's budget by $3 billion which was 25% of the budget now this is because uh many Republicans did not like the fact that that sisa the sisa head at the time said that the 2020 election uh was not stolen and quote there is no evidence that any voting system deleted or lost votes changed votes or
▶ 1:24:38was in any way compromised um that sis a director was Chris Krebs who was then immediately fired by Donald Trump and Mr Wales you took over uh Mr Wales do you agree with Mr kreb's statement that there is no evidence that any voting system deleted or lost votes changed votes or was in any way compromised and that the 2020 election uh was free and fair yes so part of the
▶ 1:25:09problem here is that even though cis's misinformation and disinformation activities represent less than onet of 1% of its budget Republicans have tried to cut 25% of the budget and Governor gome has made it clear in her hearing that she would like to uh limit and reduce the size of and role of sisa which seems odd in this time when
▶ 1:25:39all we are hearing from our Witnesses here is the increasing danger of cyber attacks and cyber infiltration exacerbated by artificial intelligence um we know Russia used cyber warfare to interfere in our 2016 election uh we know China has tried to do the same um but it's not a partisan issue because Iran tried
▶ 1:26:09to do the same thing by infiltrating Donald campaign and it is bewildering to me given the crowd strike disaster with the outage which dramatically affected my district um with the uh Microsoft hacking that gave access to uh gave China access to uh senior government information
▶ 1:26:40um that we would be reducing the budget to address our cyber security one thing I want to uh address U Mr Wales I'll ask you first is what would the impact of reducing cisa's budget or reducing the size of sisa be both in terms of our broader cyber security and infrastructure security as as the rear Admiral
▶ 1:27:10has talked about as well as uh election integrity and preventing foreign influence in our elections you know a lot would depend upon how that that cut was allocated but broadly it would dramatically limit ability of the agency to conduct critical missions so that would include its ability to provide technical support to critical infrastructure and um state and local governments who request assistance uh with actual cyber incidents or conducting pre-incident assessments of their vulnerabilities so they can
▶ 1:27:40be hardened uh it would compromise its ability to perform its functions across the uh Federal networks in terms of both monitoring and responding to incidents uh deploying technology to ensure that Federal networks are protected by best and breed uh technology platforms um but just across the board it would lessen its ability to respond at a time of significant cyber threats has been today and in terms of the election Integrity work
▶ 1:28:11that sisa does is it accurate that that is primarily focused on foreign actors and foreign interference the the um almost all of cis's work when when it comes to elections is actually focused on Cyber and physical security related work uh providing assistance to State and local governments who need assistance uh who request uh vulnerability assessments scanning for vulnerabilities conducting training um doing physical security assessments uh increasingly as state and local election
▶ 1:28:41officials are concerned about physical security threats they may face that is almost the entirety of the of the election security work so any cuts to the sisa budget would affect its ability to support those officials and sis is the only sort of the only Department within any executive branch agency that provides that cyber security service to State and local officials who administer our elections is that right yes thank you and I thank you chairman I yield back gentlemen Ys I now recognize the chairman of our counterterrorism
▶ 1:29:12uh subcommittee Mr fluger thank you Mr chairman and appreciate this hearing um I'll get right into it when you look back at volt typhoon storm typhoon or sorry storm 0558 salt tyon I mean you know the list goes on and on um I'm obviously worried about critical infrastructure not just in my own District that includes energy production um but every other aspect uh of our lives so I'll start with you Mr Wales um in last Congress I introduced the seven act which was and I hope that we can mark it
▶ 1:29:42up in this committee this year and send it to the floor because it's a coordinating piece of legislation that asks our federal agencies to do the hard work of coordinating so who is the lead government agency when it comes to responding immediately to a a cyber threat so um different agencies are going to bring different authorities to the table and you're going to want all those authorities to deal with the challenges that we have so sisa has certain authorities in being able to help an entity recover from an incident making sure they understand what's happened but you also want at the same
▶ 1:30:12time the FBI that has can use its law enforcement authorities to figure out who the adversary is and are the things that could be done to disrupt their infrastructure impose consequences we there's coordination with the intelligence Community that's going to be tracking adversaries overseas um so there's not necessarily going to be one person because no one agency has all the authorities resources and capabilities that we're going to need to tackle that problem and what you want are those agencies working closely together and I would argue from uh my time in and having just left the
▶ 1:30:42operational coordination amongst the agencies working on cyber security is better now than it has ever been um Miss Walden how would you grade the response to uh let's just say um salt typ to the Cyber attack and I because I want to I'm going to pull this thread just a little bit that there's no single agency that's in charge there's a lot of stakeholders but how was our response to Salt typhoon well sir I was I think the response to Sal salt typhoon was adequate and appropriate uh I
▶ 1:31:12was not in government as part of the apparatus at the time that salt typhoon was discovered but I do think it was adequate and appropriate um Admiral mcgomery get to see it do let's go on that how was our response what could be better and do we need a lead agency uh to help coordinate so hearing those answers you know as a 35 years in the military I kind of learned you need one leader uh one agency needs to be in charge uh I've never seen a military organization work with two leaders in charge
▶ 1:31:43um so the right answer is siza I think we have to create that condition look do I think other people contribute to it the sector RIS management agency that's responsible for that industry sure but there in the end there can be only one and that leader I think needs to be siza I think the B Administration missed a great opportunity to do that in National Security memorandum 22 even though siza was telling them to do it and asking for that lead responsibility they did not get it I think we need to as we redo National secur memorandums and things I think an upgrade
▶ 1:32:13to that to put s in charge this is a bipartisan issue yeah you know this Committee created siza you need siza to be the leader on the hill you know in the in the aftermath of the Loper brigh decision the Chevron Defence precedent uh Mr chairman I I think this is a perfect opportunity for us to be specific in this committee and to take what adal mcgomery is saying uh and designate a lead agency and actually tell the agencies what we want them to do not just give them the
▶ 1:32:43open blank chalkboard to to write what they think is best but for Congress to take an oversight role um in your written testimony adir mcgreer you use the term lying in waight when you were referring to the volt typhoon attack who is lying in weight now and what is the next attack that that keeps you up at night and then Mr Myers I want you to comment on the same thing I think all of the access of authoritarians could lie in weight that's China Russia India and North Korea but I think realistically the countries that are thinking
▶ 1:33:13about that they need to stop an American ability to mobilize forces are really weaken our economic productivity it's China and Russia I think China is the predominant actor right now I think Russ is distracted by the things I I have no doubt that there's Russian malware in our systems with with access with an ability to be access at a later date so it's China Russia and the we got to keep our eye on if I had to choose one I'd choose China thank you Mr Myers I'll give you the last 30 seconds thank you sir these uh incidents
▶ 1:33:43are not over salt typhoon is an ongoing activity by an adversary as is volt typhoon or what we call Vanguard Panda so this is something that we need to continuously engage we need to continuously identify root them out and put a stop to them and cut off their access so I would say that um I just want to make that point that this is something that's ongoing we need to to remain focused on it uh thank you for your testimony Mr chairman yel back gentleman yels I now recognize Miss Ramirez
▶ 1:34:14for her five minutes of testimony you chairman green thank you and thank you ring member uh truly grateful uh to be back in my second term serving in this committee that I believe will need uh the leadership of all of us and certainly those of us who have personal experiences with a lot of the work that we do here so I want to talk to you Mr Wales a little here you served as cesa executive director from 2020 until August of last year and in that capacity
▶ 1:34:45you oversaw the execution of the agency's operations so you're well aware of how cisa was investing its resources correct yes so Governor gome Trump's pick to lead DHS has stated that cisa was far off Mission from its work to combat Mis disinformation and that in quotes they were using their resources in ways that were never intended Mr Wales I want the record to be clear about how cesa spends its
▶ 1:35:15resources to the best of your recollection Mr Wales how much of cisa's budget is spent on Miss and disinformation work um at the last time we looked at this it was something less than $2 million so what would that be percent over the entire budget um far less than 1% of a$3 billion budget so less than 1% of the total budget and has cisa Miss or or disinformation work ever interfered with its ability to execute cyber security Mission
▶ 1:35:45I don't believe so thank you as part of the bipartisan infrastructure law passed in 2021 Congress provided $1 billion in New grants to State and local governments to enhance their cyber security state and local governments have struggled we know to adequately defend their networks exposing them frequently to cyber attacks and putting critical public infrastructure at risk as funding for this program flows to State and local governments we're also seeing the important progress is do is having
▶ 1:36:15an addressing and long-standing underinvestment in state and local cyber defense unfortunately this program expires in September at the same time we continue to see a rise in global cyber threats so this is a question I have to all Witnesses and the time that I have left do you agree yes or no that the state and local cyber security grant program should be reauthorized sir yes is that I can't see
▶ 1:36:45the names here so I'm yes all right yes thank you and and let me ask you a follow-up question and and this one would um get a sentence or two from each of you and we're going to be fair here so we want to make sure everyone gets a little time what are the National Security implications if we fail to adequately defend state and local government networks I'll start with you thank you threat actors Target state and local governments uh very frequently and they understand that those are accesses that can lead
▶ 1:37:16to uh strategic or or tactical objectives that will secure their their goals and so so I think that we need to make sure that we ensure that those state and local uh entities and and to include school districts are uh well protected from a cyber perspective thank you Mr Montgomery sure so State local governments are the low hanging fruit they're they usually don't have two wood nickels to rub together to increase their uh you know to spend on their utilities because we as voters don't like to in let them increase
▶ 1:37:46their rates but I will tell you the number one thing they need is Workforce the best way to get it that's the pivot act so if you bring that back this I think you're going to attack the number one issue state and local governments have Mr Wales yeah I would just say that um state and local government agencies are the closest to the American citizens so disruptions at the state and local level are ones that people feel quickly uh in their schools in their utilities that are provided uh in the public services that they often get um and so absolutely
▶ 1:38:16this is an area where adversaries Target particularly ransomware groups um but as well as nation states so it is an area that needs attention thank you Mr Wales and Miss Walden I agree with all of my colleagues I want to point out in addition to everything that they've said is that state and local entities really need to work on their technical debt figuring out how to resolve some of their legacy technology so that they are able to withstand cyber attacks that are happening in their backyards every day thank you Miss wden it's clear that reauthorizing is going to
▶ 1:38:46be critical for this moment thank you so much with that chairman I yield back the Gent lady yields I now recognize our chairman of the the cyber security subcommittee Mr Garbarino the gentleman from New York for five minutes thank you chairman thank you very much for holding Ser I love how you had him place the pivot act in his last answer and say how we had to pass it again that was H well placed there uh thank you all to the witnesses for all being here it's great to see you all again um this hearing is very important I think uh
▶ 1:39:16your focus on uh China has been you know it's just it's obvious that they are our number one adversary and if we can combat uh defend against China we can probably defend against everybody else um because they're they're they're they're the best at at what they do uh we have to be better um I want to talk about what sis should be doing um and are they doing what they're what they should be doing what else what other authorities should
▶ 1:39:46we give them uh Mr Wales you you were you were there for a very long time you were executive director and acting um what should sisa be doing that it's not doing uh and should we give them any more authorities that they don't currently have to step up their game and defend against China yeah so I would say that you know looking at Sis's two primary missions in cyber one is to help protect the federal government's networks and two to help support the security and resilience of our critical infrastructure networks
▶ 1:40:16in the federal government space thanks to a lot of resources and authorities from the government I think sisa needs to continue to momentum uh we are in a much different place than we were in 2020 during solar winds the federal government is far more secure today it's the reason why federal government agencies identified uh compromises of places like Microsoft because of the Investments that Congress has made in both sisa and across the federal government I think there it's about building momentum and keeping that going when it comes to critical infrastructure it's a much more challenging problem it's a much more crowded space um
▶ 1:40:47cis's real role is to be that focal point to coordinate amongst all of the other agencies that are working in this space um I do think sisa has uh sufficient authorities but it's really an issue of scale um can we meet the scale of the challenge with both technical assistance training um do we have the uh the right uh tools to bring to to Bear to to meet this Challenge and I do think that there are areas that need work and I'm hoping that the the Trump Administration um will focus on how do we improve the operational collaboration
▶ 1:41:17build on the framework that exists today with the joint cyber defense collaborative but take it to the next level continue to drive improve m ments in our ability to work side by side with industry on day-to-day operational um cyber threats and I think that is where uh the most urgent need is you talk about defending against the federal um networks uh the executive order that was signed I think last week tried to do that with rent hunting um a lot of agencies don't like sisa participating uh in on their
▶ 1:41:48networks is the does the executive order go far enough or is it something we have to act legislatively to tell uh and and everybody can jump in here to tell these agencies hey you have to let sisa do its job and and and thread hunt here you know this Builds on authorities that Congress gave to sisa in the fy21 National Defense authorization act that gave them the ability to threat hunt on federal agencies without permission that was important then supplemental funding allowed a deployment of endpoint detection and response technology that gave the security
▶ 1:42:18sensors the ability to actually hunt on this executive order requires agency is to actually provide that sensor information to to sisa that allows them to uh conduct that threat hunting it is absolutely essential that is the way that you spot adversary campaigns early it is the way you look consistently across agencies so you're not dependent upon the differences in uh capabilities at various agencies the amount of staff Etc um so I do think that part of the executive order is strong I don't necessarily
▶ 1:42:48know that they need additional legislative Authority um but it is something that is going to be important for the next Administration to continue uh to push agencies to ensure that sisa has the level of visibility it needs to conducting the threat hunting that gives you the cyber security outcomes that you want thank M wal did you want to add something it looked like you were getting ready and if you don't that's fine I have other questions okay um and you talked also Mr about um information sharing I think is what you were getting at between uh
▶ 1:43:18private and public sector when it comes to critical infrastructure because 80% or 85% % of critical infrastructure is controlled by uh sector do we have that type of information sharing now I don't think we do uh and I think sometimes it happens and well and sometimes it doesn't happen very well this is a you know I've been talking about information sharing since I joined the Department in 2005 for starting on counterterrorism that in cyber um there is always ways that we can improve information sharing um it has improved dramatically over the past
▶ 1:43:49eight years um but there is a long way to go uh and it's also a question of do you have the right private sector in the room are you sharing information at a speed at which uh it can be effective in the cybercity context um and are people capable of using that information to uh improve their security in real time um and I think there is a lot of work to do to make sure that that happens going both ways and I I'm out of time but I did just want to say before I end um uh your Admiral your comments on
▶ 1:44:19the continuation of the economy and your written statement is 100% I think on point uh we directed the B Administration to come up with a plan they failed uh and I think this is a huge thing that we need to work on with the Trump Administration we have to come up with a real continuation of the economy plan just like Congress bipartisanly directed the administration to do so with that I yield back J uh the gentleman yields I now recognize Miss Poe for five minutes of questioning and welcome to the committee thank you thank you uh chairman green
▶ 1:44:49and ranking member Topson for holding uh today's hearing I am proud to be among the newest members uh of the committee on homeland security my North Jersey district is just across the river from New York city so many constituents remember well the horrific unprecedented terrorist attack that occurred there two decades ago I take my appointment to this committee
▶ 1:45:19very seriously and I am excited to work with my colleagues on both sides of the aisles and collaborate with stakeholders and experts to advance solutions to improve the Safety and Security of New Jersey and our nation the cyber security information sharing Act of 2015 is set to expire this year since its enactment 10 years ago this law has created critical information sharing Partnerships and collaboration
▶ 1:45:50between the government and the private sector these relationships have have enabled America to be to better respond to rapidly uh evolving cyber threats making the country safer to each of our four witnesses can you please describe the benefit of the Cyber information uh sharing act but please uh detail if you would how would a lapse in this Authority affect our nation's security
▶ 1:46:21Mr Myers or did okay I can start so the importance of the cybercity information Security Act unfortunately the same name acronym sisa 2015 uh is Paramount because what it does is it gives liability protections to Industry to share with DHS and through sisa to share amongst each other in order to be able to at least at a minimum get rid of the lwh hanging fruit they are allowed to share cyber threat indicators and defensive measures for a cyber security purpose
▶ 1:46:51uh they are protect from Foya they're protected from antitrust uh litigation they're protected from Sunshine laws and Etc and Etc this is key this is a key underpinning law that enables the jcdc for example that enables other vulnerability assessments that take place that enables us to be able the government to be able to interface with industry at at the speed of data thank you I would I would just add that most importantly it provides Assurance to
▶ 1:47:22the industry that they will be protected some people may be willing to share without this law but the reality is many won't because they don't have 100% certainty that they're not going to have suffer any consequences whether through um some type of litigation or suit and so ensuring that it is reauthorized is critical for enabling cyber information sharing to happen between the private sector and the federal government as a whole thank you I I would support his reauthorization I'd also remind that uh back you know nine years ago it was weakened significantly
▶ 1:47:52in the Senate uh before it was passed I think you should take a look at strengthening the liability protections for the companies in that legislation at the same time I would take advantage of the opportunity to integrate siza the cyber security infu security agency into it strengthen its ability as I said earlier we have to get off a slack Channel we have to get into a we have to have authorized a system for actual speed of data transmission we've got to push the intelligence communities to figure out how to get that down to the unclassified level so
▶ 1:48:22that there's a benefit and burden to this to the private sector they both benefit from much better intelligence from the government and the burden is they've got to rep you know they've got to report what they're seeing uh and work closely with the government to pass on their information thank you very quickly Mr Meyers thank you um information sharing is critical for our success it's it's us it's the vendors it's our customers it is our partners and the government um versus the adversaries it's versus China Iran North Korea and so information sharing is really
▶ 1:48:53the essential building block of how we secure our infrastructure thank you thank you so very much I you back the general lady yields I now recognize the gentle lady from Georgia Miss green for uh five minutes of questioning thank you Mr chairman before I get into some questions I'd just like to point out that Mr Wales in your testimony you talked about Iran's cyber hacking attempts against the president Trump's campaign this past election cycle aimed at undermining
▶ 1:49:23president Trump's candidacy and sewing Discord within the United States electoral process so thank you for pointing that out while cyber threats from our foreign adversaries must absolutely uh be protected against we also can't forget that our own independent cyber security agency cisa was more focused on conducting its own large scale election interference campaign through it censorship laundering complex against our own people rather than bolstering our cyber
▶ 1:49:53security efforts and working to protect our critical infrastructure um just some just some brief stats the average cost of a data breach in the US amounts to 9.36 million almost double that of the global average as you Mr mcgomery testified the FBI received reports of 12.5 billion in cyber crime losses in the United States 2023 an increase of nearly 20% over 2022 which is definitely alarming ransomware
▶ 1:50:23attacks Rose 74% from 2022 to 2023 cyber attacks on critical infrastructure globally increased 30% in 2023 one in3 Americans and this is shocking were affected by healthc care data breaches last year government agencies were the third most targeted sector from ransomware attacks in 2023 and there are roughly 500,000 vacant cyber security jobs in the United United States Mr chairman
▶ 1:50:54that is a serious issue most cyber attacks fall into a never-ending pattern a threat actor often sponsored by a nation state exploits vulnerabilities in the system they exfiltrate sensitive data or encrypt it for ransom then there is an investigation into how it happened who was involved and what measures should be taken to prevent it from happening again and then it happens again and the cycle repeats and and we're all in a very serious dilemma
▶ 1:51:24Mr Montgomery in your testimony you talk about some specific offensive and defensive solutions that we can take to address the needs of our cyber security shortfalls could you could you elaborate a little more on that please sure thank you um you know I would highlight in that first we absolutely have to in invest in our sector risk management agencies to make sure they're doing their job I was it's shocking sometimes when you look at a department of energy spends what I think is probably the right amount
▶ 1:51:54somewhere between 50 And1 million do a year on being a sector risk managed agency helping energy companies protect themselves then you go to the Department of Agriculture and they're spending $500,000 or Department of Education they're spending $250,000 most of us understand that's two full-time equivalents or one full-time you know it's one human or two humans and that's just website management you're not helping the 8,000 farms and food distribution networks out there with one person Manning a a website and you're not helping the arc through 9,000
▶ 1:52:25districts out there with one person Manning a website we need more consistent um focus leadership from the top down cabinet members down on cyber security is a responsibility they have as a Cabinet member and then when appropriate the funding to do to do that kind of thing so to me that's the number one and I I spoke earlier about military Mobility if I could only focus on three things it would be rail AV Aviation and because if we don't get that right
▶ 1:52:55China Russia doesn't matter if they initiate combat operations that we're going to be involved in we won't get there fast enough oh thank you Mr Montgomery I completely agree with you those those are very critical infrastructure things that we have to protect um with AI being the the biggest emerging uh industry in in the technology uh industry I'd like to ask each of you how how can we protect Americans protect our government protect ourselves from
▶ 1:53:25cyber attacks and how do you see AI playing a role in that maybe for the good or for the bad I'll start thank you yeah Mr Myers artificial intelligence can be uh one of the solutions to a lot of the problems that you highlighted um when we think about the Cyber Workforce artificial intelligence can take more Junior analysts and make them more senior analysts by automating and helping them deal with complex problems at uh scale and its speed I'll also say that artificial
▶ 1:53:55intelligence in the security domain can be used to identify and quickly remediate these attacks so there is a huge opportunity there uh the one caution I'll say is that I think in the next one to three years we'll be seeing more and more organizations and businesses employing their own artificial intelligence and that will create a situation where there's what we would call AI workloads that need to be protected so we need to be thinking about how can we proactively start talking about protecting those AI workloads today before they
▶ 1:54:26become a problem in the future that makes sense thank you Mr chairman can we allow our witnesses to each answer very quickly a yes no but that that we need to move on so if you've got a quick yes no you can do a quick yes no yes okay yes okay thank you so much uh thank you for coming to the committee today thank you Mr chairman I yield back the gentle lady yields and uh I now recognize is Mr Turner from Texas also welcome to the committee sir
▶ 1:54:56for your five minutes question thank you chairman green and ranking member Thompson it's good to be with everyone um what I've noticed is that they're same running themes from each and every one of you let me just say that um this m city of Houston we Face thousands of cyber threats um every every year and cyber Workforce critical um the Grants State and local government
▶ 1:55:26critical um and cities and states on the C attack uh a coordinated approach collaboration um all important and that's why I'm a strong supporter of cesa um in fact when it came into existence we went thumbs up um Aviation the port uh utilities of water systems are under constant threat and as a mayor that is something that kept me up every night
▶ 1:55:56when we saw what happened in Atlanta when the ransomware gangs took over Municipal Police cost in the city great deal um we all tried to intensify our efforts built layers and layers uh but we simply didn't have enough money to do enough um so let me applaud each and every one of you uh because uh each one of you said I think Mr Myers the threat has increased 200 300% um
▶ 1:56:26I think R Admiral you indicated a persistence vulnerability that exists U each one of you the same things over and over again let me just go uh directly to the office of national cyber security director um Miss Walden and during your time at oncd both as a principal Deputy National cyber director and as acting National cyber director you were part of the development of this new office
▶ 1:56:57how has the creation of oncd uh strengthen our national cyber security and what additional steps should the new Administration take for a coordinated approach to cyber security across the federal government thank you so the national cyber director's office was created to provide strategic cybercity advice to the president so that just as Admiral Montgomery said we have some accountability and some responsibility from the very top all the way down uh and that should be true
▶ 1:57:27in the federal government as well and there were a couple of things that we sought to achieve the first is to make sure that we have a more defensible more resilient digital ecosystem and that includes state and local entities that means that we needed to do two things one shift cyber security risks so that it is not solely the burden of cities and counties and Educators and shift that so that it's more the burden of the federal government of large Enterprises of of producers Etc um and then with that
▶ 1:57:57residual risk once we buy it down to to build in resilience not just in uh the technology but the technology is important the backbone of the internet salt tyoon showed us is important but in the workforce and the people and and the ability to be able to maintain all the new technology uh and doctrinally who's in charge of what when how so that the work that we did there came with it uh that strategic work came with it a full action plan and that full
▶ 1:58:27action plan allowed each department and agency to take on responsibility for a a particular provision of that strategy that allowed state and local governments to plug in that allowed uh companies to plug in and to move the needle forward that was the strength of the national cyber director's office and I'll point out the national cyber director was able to with the Office of Management and budget prioritize for federal departments and agencies how to ask for federal funding in order to be able to pursue that mission um that kind
▶ 1:58:58of central activity within the White House was important in the last Administration and I see it going forward thank you and um Mr mcgomery in your role with the cyber space Solarium commission you advocated for the creation of oncd uh what success have you seen from this new office and how important is it that the new Administration empower oncd going forward well look I think um Kemba did a great job as uh acting NA national cyber director
▶ 1:59:28and uh and I think as did Chris englas as and um Harry Coker as National cyber directors so I think the most important things are the budget control in the end we all know resources or what Drive things so having maintaining that budget control what I wish I could do is expand it to make sure that the sector risk management agency functions are being paid for the second thing I think they're really good at is the workforce you know uh protecting those again they'll be critical when we do get the pivot Act passed and the third thing I the third thing I think they're most important for is getting this harmonization
▶ 1:59:59of Regulation we've got to reduce the regulation on our Industries and so I think if they're able to do all three of those things the the uh the next administration's now director will be successful thank you very much I Y back gentleman yields I now recognize uh Mr Latrell from Texas for his five minutes of uh questioning thank you Mr adal I've got a small nursing home that's located one of my little small towns in my district and they they had a Cyber attack
▶ 2:00:29and we we called in we called in sisa we started going through the checking the boxes and the FBI came in and what ended up happening is when the FBI came on board and sist working in parallel with each other uh it turned into kind of into a proverbial fist fight that who was in charge and as this thing kind of inched along the one the result was that the nursing home didn't get results and you mentioned earlier if you follow the the chain of command inevitably has to be one leader one person in charge and the net has been cast out
▶ 2:01:00very wide given just kind of the proverbial threat when it comes to cyber risk cyber threat cyber attacks can you give me some refinement on the best course of action on how to decrease that problem set first thanks for bringing that up but I think you you highlight that rural health care right now and and small Health uh uh small Healthcare facilities are probably the greatest risk we have in the utility area and the reason I say that is that what if if uh they get a ransomware
▶ 2:01:30attack most of them have about five or six weeks of float that is if they don't end the ransomware attack and fully recover their systems within four five six weeks they could be out of business and then the community loses its health care so the first thing I tell you is HHS health and has to do a much better job supporting these guys left to boom and one of the things we're pushing hard there is like a fractional sizzo Pro uh sizo program what that means is I guarantee that hospital that you're talking about or clinic could not afford a full-time sizzo to
▶ 2:02:00prevent this rans and recover from it correct what we need to do is have a you know a program where they can access a a a pot of scios who come in who've done ransomware hundreds of times help that hospital get back on its feet and recover not just pay the ransomware that's the easy part it's restructuring the systems but you need specific sios to do that but you can only afford about 10 days of that sizzo not 365 days of his or her $400,000 salary so to do this
▶ 2:02:30we need a a virtual fractional sizzo sizzo program for um rural Healthcare so that's the first thing I do that stuff youd plan left of Boom once the right and you're asking me about the cluster that was right of Boom yes sir that cluster right or boom has got to that starts with the White House that starts with the National Security memorandum that clearly states who's responsible and who's in charge at a very localized one like that it you know it can be done by who you know there'll be some who have a better Regional footprint but a larger one
▶ 2:03:00it's clearly to me it's siza but we you have to have a rule set for it just like you and I had rule sets operating in the Navy and with that kind of like structured command um I think we're we're we're going to continue to have failures like you saw but I would say there's things we can do left to Boom to prevent these from being the uh small business killing events that they are yeah because facility was networked so not only did it touch the it touched them all it took and took them to a knee and um thank you for that uh Miss Walden I thought your opening statement was amazing very
▶ 2:03:30Point driven and I and I appreciate that you were digital crimes unit you oversaw digital crimes unit can you give me some background and flying information on exactly what that entailed because where I'm going with this is we talk about Russia China Iran North Korea but I make no mistake about there's some there's some proverbial Bad actors in the continental United States as well and and in my district and I represent a small portion of Harris County and sex trafficking is is actually in Houston sex trafficking is the number one city in the country
▶ 2:04:01um can you kind of talk me through because what I would like to do is I we're in 2025 there's just no way in help we're going to go back to analog I mean the digital Revolution is here we're not going to get away from it and it's it's as as great as it is it's terrifying in a sense um can you give me a course of action moving forward that that this committee and this Administration can jump on top of to decrease that problem set sure first I want to correct something for the record you've given me a promotion I was not in charge of the digital crimes unit but I was you're welcome
▶ 2:04:31Happy Birthday um and I was responsible specifically for going after the ransom or threat okay I'm sorry platform which was an incredible Mission set um if you can imagine the large Enterprises like Microsoft like Google like Etc um see millions of signals a day and they have within that that their data set a lot of information that allows us to see when there's a threat actor crowdstrike can do the same thing but uh and we can go after them using legal means
▶ 2:05:01as which is what I was in charge for but also technical means cleaning up our own networks because cyber security risk was born by the larger Enterprises should be and they need to buy them down for all of its customers uh so what I would suggest is that we employ policy Solutions or this committee can employ policy solutions to shift that cyber security risk burden to those that are more capable of buying them down that means uh microsofts of the world should be coordinating with sisa and sharing
▶ 2:05:31information back and forth microsofts of the world should be able to identify when there are threat actors to to immediately deliver that information and I don't mean to just pick on I got it but you know what I mean thank you thank you Mr chairman I bet gentleman yields I now recognize the new ranking member of I think Transportation right Miss mver uh congratulations and you're recognized for 5 minutes for your question thank you uh Mr chairman uh thank you ranking
▶ 2:06:02member and to our Witnesses for joining us today uh cyber security is no longer just a technical issue it is a critical National Security challenge that touches every part of our daily lives I represent New Jersey's 10th congressional district and I first and I see firsthand the importance of protecting our communities whether it's safeguarding sensitive information for small businesses securing local hospitals or ensuring that critical infrastructure like power grids and transportation systems
▶ 2:06:32remain resilient against cyber attacks with that being said in my district which is home to critical infrastructure such as ports Transportation hubs and energy facilities that are vital not only to our state but also to our entire nation can you elaborate on what Congress can do to better protect and work with local governments and private sector stakeholders and districts like mine to secure these critical assets from cyber threats that's to anyone
▶ 2:07:02who would like answer I can start um I would I would recommend that Congress continue to explore state and local Grant giving opportunities to be able to reduce some of the Legacy technical debt that exists across critical infrastructure I would also encourage that you to explore opportunities to expand internships uh externships to to qualifying students and and uh SFS programs for example or cyber core
▶ 2:07:32to be able to deliver to State and locals the talent that they need in order to maintain systems to vent systems and respond incidents thank you ma'am can I add on to that uh two things one um uh we need um bottom up uh support and what I mean by that is uh there are places where the Eder agencies are just too small or too underresourced to regulate um we've noticed this in water uh the 55,000 water so we've been pushing for something called a water risk and resilience organization representative
▶ 2:08:03Crawford introduced it in the last legislation what that does is allow um trade associations to work with like federal agencies in order to establish the right level of Standards if I could give one more ma' it's clinics we've seen this at a uh go for example Google sponsors them but in addition other areas of spending and what that does is allow local community colleges and vocational schools to run programs where their cyber security profession uh uh future professionals can work with the local governments and authority and utilities
▶ 2:08:33to improve cyber security you if I may also um as we just heard about the the clinic or the uh the nursing facility in Texas and um similar to the small businesses and the the critical parts of the transportation infrastructure that you just mentioned there is uh two issues that I think we we can address one is that there is a a lack of cyber Workforce which we've also heard about earlier today um some of this can be countered by relying on technology like artificial intelligence
▶ 2:09:04but we can also work to bring uh more interns and bringing more uh uh stem into the to the to the lower levels uh of schools down to the junior high school level even to start to train the next wave of of Workforce and also as mentioned in uh my recommendations I think there is things we can do to incentivize these businesses to invest in the right cyber security um by incentivizing them to use managed Security Services that can help protect them left of Boom
▶ 2:09:34as as we've heard uh there's a lot of work that can be done today that we'll we'll have payoff in dividends yes thank you thank you for that uh it's interesting that you brought up the idea about the talent you know making sure that we have folks in the pipeline um who are you know trained in this field especially as in jit which is a large you know University in my um District they you know have wonderful programs and I'm sure would love to partner and collaborate any way to make sure that we're pumping
▶ 2:10:04out you know the future um future employees to be able to you know work in this you know field uh thank you so much for answering those questions with that Mr chairman and rink member I yield back thank you the general uh woman um yields I'd like to thank uh chairman green uh ranking member Thompson our Witnesses for being here today uh I'd like to recognize myself for 5 minutes as my colleagues have discussed the threats of our nation uh our nation's security
▶ 2:10:35and how it has evolved over time becoming more sophisticated and in many cases more dangerous most alarming is the ability of cyber adversaries to cause chaos without even stepping foot on American Soul we have seen reports of adversarial Nations State hackers such as China and North Korea working together to conduct ransomware attacks against Global infrastructure I saw it firsthand as the chairman of the Madison County Commission
▶ 2:11:05in Huntsville Alabama um creating total chaos and you think about a multi-million dollar option that we ended up rebuilding our system more cost effective than paying ransomware Mr Montgomery are you concerned about the cooperation among cyber actors who use the same tactics I am I'm I'm not as concerned about the access of aggressors yet sharing tools with each other like we see
▶ 2:11:36with North Korea providing Munitions or troops to uh to Russia and Ukraine I am very worried that the uh that the the sophisticated nation state tools are becoming increasingly available to non-state actors and uh and um criminal actors both in the United States and overseas I mean it's not lost on us that uh Russia's ransomware went down uh Russia's ransomware attacks against the rest of the world went
▶ 2:12:06down for three months after the invasion of Ukraine because those same ransomware criminals were actually nation state actors and and and started to attack Ukraine instead of attack us companies that's since returned with a Vengeance but what it means is is that the nation state and the criminal actors share tools pretty effectively and that and that makes it much tougher on our companies thank you all although all um cyber actors have their own objectives there's one goal they share
▶ 2:12:37and that's harming the United States of America Mr Montgomery do you uh foresee the emergence of a cyber AIS of evil why or why not so as I as I just mentioned I I do think you're seeing it with the criminal actors starting to get tools that the nation state actors have do I think over time they'll share yes you'd have never if you'd ask me as a military officer 10 years ago would North Korea send troops to Ukraine and I said no would North Korea give up 20 or 30% of its artillery
▶ 2:13:07to the Russians no the rules have changed the axis of authoritarians are clearly operating and a much more integrated and aggressive way it's only natural that this will eventually devolve down to cyber tools and cyber techniques and the and the sharing of best you know of worst practices in that case nation state actors appear to be unded uh from um targeting Us in cyers space whether it's Iran hackers on water systems or PRC state sponsored threats
▶ 2:13:38to critical infrastructure uh it is time our national security advisor um you think about it Mr Walt says and I quote start going on offense and start imposing higher cost and consequences close quote given the severity and scope of these threats is it clear that cyber security must be at the heart of our homeland security strategy yes I mean
▶ 2:14:09I think all four of us in our testimony said that cyber security is is rapidly becoming the most significant threat to our homeland and look there's stri there's stiff competition there missile attacks physical attacks but cyber attacks are clear and present danger today to our industry to our government and to our military thank you Mr Welles how can the United States better harness its cyber tool kit to go in offense sure so um us has some amazing capabilities
▶ 2:14:39in this in this area um and I think what we have seen is it works best when it's done in tandem with defensive operations where we see what the adversary is doing domestically that information is fed into cyber command and that allows them to Target adversaries um in a more precise way it has worked best in places uh where cyber command is targeting for example ransomware operators uh because of the number of those attacks we can quickly provide uh um defensive operators can quickly provide them information
▶ 2:15:10on additional targets to go after um but we need to find ways to make sure that that integration is happening so that what they're learning overseas is being fed to defensive operators and what defensive operators are learning here is being fed offensive operations thank you thank you all the gentleman from Tennessee is recognized for five minutes thank you Mr chairman uh Admiral mcgomery you note that Iran and specifically the Iranian revolutionary guard guard Corp is aggressive
▶ 2:15:40in its cyber attacks of Israeli networks they're also among the primary threats to our networks here how robust is our coop cooperation with Israel to assist each other in protecting against this enemy yeah thanks for asking that because you know Congress did pass the Cyber a uh an act directing increased and improved cyber security cooperation between the United States and Israel about four years ago and we've seen significant improvements I would say there there's tiers of cooperation
▶ 2:16:11probably the top tier is the United States the United Kingdom through five eyes we have an extensive level very integrated level cooperation both in cyber and cryptographic um intelligence sharing but i' put Israel very high on the list I think we share threat information smoothly and fluidly um tools that we see uh that we detect we share with each other again probably not on the same level as United States United Kingdom but very close we have a very a common shared threat in Iran um thankfully
▶ 2:16:41the Iranians have the Israelis have done a lot to deter Iranian action over the last 6 months with their extensive strikes into Israel both contic into Iran both Connecticut non-kinetic um but yes uh our cooperation with them is at the highest level I was going to say you know I think arguably Israel is in some ways our eyes and ears on the ground uh and arguably the the roughest neighborhood in the world and so as you look at our relationship with the United Kingdom what could or should we be doing with Israel to enhance increase
▶ 2:17:11that partnership understanding we have that common and shared enemy so I do think that there's there there's probably a level of classification we can increase our you know of sharing that we could increase ourselves to even higher but I would say I think we do a very good job and frankly the Israelis do a great job providing information to us on what they see look this is a mut this is a this is an alliance in all but um you know paper uh we we we share information closely we share a common
▶ 2:17:41threat we provide weapons uh to Israel in a very useful way so I think we're doing great work the the real order in there is continue what we're doing yes sir I I'll just add from a defensive perspective in the PO post October 7th uh when I was uh in cisa we were sharing every single day with the Israeli National cyber directorate uh information on what we were observing in terms of potential uh actors looking to Target Israel uh those were from nation
▶ 2:18:14non-national on and that information sharing was consistent and it was built on uh decades long relationship ship that we had established well Mr well since you you jumped in here uh in light of the silk typhoon intrusion at the treasury Department how would you assess the adequacy of Treasury cyber security posture so you know I think the the compromise of Treasury was interesting because again using going after a third party uh in this case going after a third party uh Security application Beyond trust
▶ 2:18:44um I think it uh treasury's uh security has dramatically improved just like much of the federal government over the past uh past eight years but what I would say is um we're forcing adversaries to go um after more complex targets launch more complex operations in this case again using a third party supply chain attack um which is good but it also puts increased burden on us uh as a country to make sure that we're looking for um those more complex attacks that we're managing third party risk that we're understanding how they can
▶ 2:19:15use Supply chains to Target our most critical systems and what we what we can and what we should expect from technology providers to ensure that their software and the technology that they provide to both government and Industry is as secure as possible well in that context when we look at the third party providers and obviously there's no vulnerability there in respect to Treasury and other agencies how do they compare and mitigating that risk as they as you're as you're forced to integrate and provide Technologies for the consumer and for governments Etc I I you know
▶ 2:19:45I would refer you to people who are in government now who have may have a better sense of where our treasury Stacks up but I will say that um I was when I last in was impressed with their level of of capability yes sir with that Mr chairman I'll yield back I want to recognize Mr Beren from Oklahoma thank you Mr chairman I thank you to the witnesses I I want to just lay out some numbers I think it's intriguing cyber security hacks are
▶ 2:20:15costing us According to some reports $320 billion a year that's under US citizens that's about1 % of our GDP our gross domestic product um as it's been talked about Iran China uh Russia North Korea and at the individual level people have to worry about their bank accounts you have uh statistics that say that one in three Americans have been affected by healthare data breaches alone just in 2024 and so there's so much to to gain not only from our national security being hindered
▶ 2:20:46um but as um Mr Waller Mr Wells you said in your testimony that um they are preparing for war talking about China and their their desire as it pertains to Taiwan I want to throw an interesting concept out the Constitution actually talks about in Article 1 Section 8 something called letters of Marquee and reprisal this is something that's not I I alone am talking about this is something that goes back to even legislation that was filed a few years ago
▶ 2:21:16and if you think about when you all have been talking about we've got to go on the offensive we all recognize we've got a massive debt there's a limitation to how much we can spend and throughout our nation's history um letters of Marquee and reprisal were the opportunity for people that knowing that private entities were being attacked our government would issue very limited in scope information for private entities to go out and be able to capture to hack back and this it was applied to to to this scenario versus waiting on government
▶ 2:21:46to respond that sometimes if you're a security firm trying to defend a private company and as the saying goes if in terms of companies right now there's two types of companies in this world those that have been hacked and those that will be hacked there's a delay why would we not empower the free market to hack back under very specified regulated rules constitutional in every manner letters of Marquee and reprisal go on the offense and employ what we know are really intelligent people and the
▶ 2:22:17technology entity and we make it hard for people to want to go after America that they know that they hack Americans under these very specific details having to identify where the hack came from that sisa could be involved with we immediately hit back and is a great deterrent for aggression from foreign Nations I got about two minutes left who would like to speak to that well I'll start only because I'm from the Navy in the last like uh Letter You Know The Last Ship seizure was I think by the Navy on World War II
▶ 2:22:47um under that under a similar uh Theory what I'll say is um I I would prefer that we actually developed a cyber force that could do this where we were robust enough so I first have to acknowledge that the right long-term answer just like it was with special forces after 9/11 was to grow our special forces to be the force we needed uh in the short term on occasion you know you may need to use contractors to get yourself to bridge yourself to that point but I think the long-term preference is that we have military actors now to get at
▶ 2:23:17your point those military actors in a cyber force don't have to be wearing uniform and and we don't have to recruit people that look like chairman crane looked like when he was uh when he first joined the Navy they could be a little overweight they can have unusual drug usage recently I've got limited time so so I would say I would go for that in in the absence of that we need to look at the use of contractor of contractor do this I would not go to Independent companies all right let me let me because this has been SED people say well that you would open up the Wild West it's already the wild west already
▶ 2:23:47and and somebody would say well you don't know what would happen if you did that that don't you think that's what the founding era when they issued letters with Marquee and razel had to worry about is somebody unintentionally that shouldn't be impacted of course they did So for anybody that says there's a risk of this you're right but our Founders knew on open Waters there was the same amount of risk the problem is I contend we're in a place where we think government is the solution to everything and that's why we have a $36 trillion do gross national debt and we've got a limitation on fiscal resources I love what you're saying some of you come from a government background but maybe
▶ 2:24:18we don't need to just be looking at the status quo our founding fathers knew there were risk with this but they put it in our Constitution and they were brilliant anybody else want to talk about this uh just uh agreeing with uh with Mr Montgomery here I I would caution that there is uh potential higher potential collateral damage uh as a result of unco I can interrupt you is there anybody who's willing to think outside the box on this not from a
▶ 2:24:48background do you not think they in fathers also thought this thing through and knew oh it could be dangerous to empower privateers to go do this but they did it think about dunk there's a time when government can't solve all your problems and they hire or ask 800 boats to go help out Dunkirk would have been a collapse AB utilizing the free market I think I'm far enough outside the back box recommending for a seventh military service a cyber for so I'm going to leave myself I'm pushing pretty hard but we've got to think outside the box
▶ 2:25:18the limitation of federal expenditure with that Mr chairman I yield thank you I now recognize myself for 5 minutes thank you guys for showing up today um it's unfortunate that we don't have the FBI and anybody from Homeland Security here to testify before committee you guys have all discussed numerous attempts to and even successfully infiltrate by our adversaries to hack into our critical infrastructure we've been talking about our Health Care system today
▶ 2:25:48the power grid water infrastructure corporate infrastructure federal agencies Etc I know director Ray of the FBI has even been up here in front of Congress testifying along these lines I believe his quote was Chinese hackers are positioned on American infrastructure and preparation to wreak havoc and cause real world harm to American citizens and communities if and when China decides the time has come to strike
▶ 2:26:20one thing that my constituents often ask me is why is nobody in the federal government ever held accountable for for their failures and I want to point out that I believe it was you Mr Myers from strike you actually appeared before this very Committee in the last Congress and actually took accountability some for some of your company's failures is that sir yes sir knowing knowing that and that's one of the things that the the American people are
▶ 2:26:51so frustrated about what the federal government nobody ever gets accountable rarely does anybody take any ownership of their failures Mr Myers do you think some of your counterparts from the federal government today should take some ownership of some of the failures that have led to many of our adversaries acquiring access to our critical infrastructure that we've been talking about today would you like to see would you like to see that I
▶ 2:27:21I would like to see us move to a position where we're able to stop these things before they happen Okay so you don't want to see any accountability Mr Myers you don't want to see any government officials maybe sitting on this panel today take some ownership my my my role here is to gotcha thank you to that point I want to give some of the other members on this panel the opportunity to take some ownership of some of the failures that have allowed the Chinese and others to hack in to some of our critical
▶ 2:27:51infrastructure does anybody want to take any ownership since you guys have been doing this for a very long time I'll start with you Mr Wales so I I would say that um when I was in government we were very clear about where um we needed to make improvements where there were failings where we had not invested enough in the right areas where we needed to make changes I would say if I look back at um because I was acting director at the time as the solar winds campaign um had emerged was discovered um we identified that that the federal government for
▶ 2:28:21too long had overinvestment um in the overall level of security so I think where we've needed to be honest about the the lack of capability in certain areas that has allowed certain uh attacks to happen we've been clear about that Miss Walden how about you
▶ 2:28:52I was part of the apparatus that created the Office of national cyber director so that in the famous words of Senator King Congress would have one choke to or one throat to choke when something went down um I think what Mr whale said was absolutely true we made movements to make sure that we are all uh singing off the same sheet of music playing the same soccer game whatever analogy you want but I think the failure
▶ 2:29:23was a lack of coordination uh for some time do you take any ownership in that Miss Walden in the lack of coordination yeah I I will own that I've worked to make sure that we had better coordination so none okay thank you um are you guys M Mr Wells are you familiar with this report the weaponization of sisa how a cyber security agency colluded with big Tech and disinformation partners to censor Americans I believe this was the Committee
▶ 2:29:53yes Mr Wells do you think it's appropriate to silence Americans for pointing out anomalies data and policy changes in you know our last election or any election do you think it's do you think that's appropriate for you guys to silence Americans I think Americans have free spe Free Speech rights and they can say what they want okay when you were in charge of sisa did you ever oversee the censorship of any Americans for whatever views they might have held whether you agreed
▶ 2:30:23with them or not no no okay um we've been talking today about some of the uh things that we can do um to increase and bolster our cyber security efforts um and I agree I do think that we need to go on the offensive um I believe it was you Mr Montgomery you talked about um you know if we had had foreign State actors
▶ 2:30:53placing satchel charges and explosives on our energy Grid or anywhere else you know we would raise holy hell and it would be an act of War my question to you guys my final question is why why aren't we doing it well sir I think uh for too long we've seen cyber is a nonmilitary tool and we just you know we we saw it as a nuisance and criminal actor um uh uh tool and that's that has temp dampened our response
▶ 2:31:24as I you know as you I pointed out satchel charges you and I'd be leading the charge to go find out who did this and hold them accountable I just think with cyber we take on this tempered approach that it doesn't kill people even though we now know it does kill people there are morbidity rates at hospitals that increase because of ransomware attacks we know this look it's it's a attitudinal change I think on a bipartisan basis five or six years ago we didn't see things this way I hope on a bipartisan basis going forward we can see that we need to
▶ 2:31:54go on the offensive and hold these country and hold a country that does this kind of operational preparation of the battlefield against the United States accountable for their actions I got one more followup question um Mr Wells if this if you weren't censoring American citizens in in sisa why was it going on I don't believe it was so you you completely disagree with this report is that what you're saying yes and you're under
▶ 2:32:24oath today yes okay thank you I yield back the real chairman is now back thanks first let me uh say thanks to the witnesses for
▶ 2:32:54being here uh ranking member I think uh it's time to recognize you for a closing statement I mean is there something yeah I'd like to enter something into oh yeah absolutely well uh Mr chairman I ask unanimous consent to enter into the record a report entitled cyber security policy recommendations for the new Administration from the Aspen Institute so order and let me just as a final
▶ 2:33:24point Thank our Witnesses uh it's been very good um uh we're almost on track but we're getting there I want you all to work with us uh again I compliment the chairman on uh looking at this as a priority for the committee uh we will get there and um I just think that we have to plow through it uh in order to get to the finish line and
▶ 2:33:55and we ask your Indulgence and if you have something that I think is uh of note for the committee to consider I'd encourage you to share it with us I yeld back Mr chairman uh thank you ranking member and thank you for uh your comments on just the bipartisan nature of this it is really one team on this one because this is this is critically important I I want to thank the witnesses all of you have been fantastic pretty
▶ 2:34:25much echoing each other's comments which that that's a good uh a good slate of witnesses when that happens um I I also want to thank the members for their thoughtful comments on both sides um I I have stated my priorities on the Cyber uh Arena and I want to since this is our first hearing and because it's our first hearing on Cyber I want to restate those you I think our greatest issue our greatest threat
▶ 2:34:55to the country is the workforce shortage and when we have 500,000 empty jobs when the FBI director comes in front of our committee and testifies that if he took every single cyber person he had put him on the China desk he'd still be outnumbered 50 to one that circumstance can't continue and that's why I will be reintroducing the pivot act and I really appreciate many of you have mentioned it and if not by name you've talked all of you have talked about it uh the need for that and
▶ 2:35:25then this harmonization of go of what's out there in the government I think we're spending a lot of time especially our private industry and we all know that much of our infrastructure is managed by our private businesses um I think the re Admiral mentioned that specifically in his testimony you know we ask of our of our private businesses all these different things and every agency publishes things and often times they contradict one another
▶ 2:35:55and there's this compliance checklist in this compliance checklist and they wind up spending all this time on compliance when they really should be spending time on cyber security and so finding a way forward to harmonize the um government regulations that are in this space I think will free up a lot of energy and money to do cyber security and I can give example after example but you know we talked about the liability issue I think Miss Walden you brought that piece of it up
▶ 2:36:25you on the one hand we're granting one group liability and then the SEC is telling people yeah okay it takes seven days to repair a breach but you have to tell your shareholders and make it an Public Announcement in four days well why would you announce in four days that you got to breach when it takes seven to fix it you just this some of this stuff that's coming out of the bureaucracy and and maybe even out of Congress too just has to
▶ 2:36:55be harmonized and synchronized and that's my second priority my third priority is we've got to rethink and this is why I asked each of you this and I'm reiterating my question for your written feedback on how we address the economic models in the production of our software and our technology because First Market is creating vulnerabilities that are costing the government right as a vendor and costing Private Industry
▶ 2:37:26billions of dollars a year and we have to get to the to a place I don't know if it's certification I don't know there are many multiple courses of action here liability could be one and I know the businesses don't want to hear that right Myers it's okay I I'm it's my turn but I understand I I ran a Healthcare company I get being first to Market you it's competitive Advantage but man if you throw that
▶ 2:37:56piece of software out there and you rushed it to Market and man it's got a hole in it we could all be screwed so we have to figure out how to reverse this economic model and another Converse economic model is the fact that it takes $3,000 in a laptop in Russia for a punk kid to get $5 million out of a rural nursing home you know that economic he has no risk he's not going to be extradited to the United States we have to fix that economic model and make it more
▶ 2:38:26expensive for him or her to hack us than a $3,000 laptop in the security of a foreign country that isn't friendly to the United States so the economic models have to be adjusted we will reenact the Cyber subcommittees thing that I started last cycle where we get the various subcommittees of each of we're siloed in Congress the government siloed we're siloed in this whole cyber thing we got cyber subcommittees in financial services we got cyber subcommittees
▶ 2:38:56in you know H we got our cyber we get try to get those together we got them together last year on about a quarterly basis we'll try that again we're going to start that process again and start thinking a whole of government approach to cyber and I might ask all of you at some point to come back and talk and present what you did today to that cyber Subs group group because we really do need a ho of government approach and I agree on the unity of command issue uh that you mentioned
▶ 2:39:27uh Admiral that that is critical I spent 24 years in the military and studied the principles of War at West Point so I get that and you're right uh clearly defining who's charge that that's really us right in Congress defining those authorities and so we're we'll work on that too um one of the things that kind of worries me a little bit is you know we if you use chemical weapons against the United States we have a written
▶ 2:39:57strategic response to that if you use nuclear weap I me we have a first use nuclear right so we don't have a cyber response strategy if you hit the United States this is what's going to happen to you and I hope the new Administration will take that issue on and come out with a statement that says if you do X we will do why and it's well known and articulated throughout the world because you can have all the capability in the world if you don't have will power
▶ 2:40:27to use it then it just doesn't matter there were some comments made about secretary gnomes refusal to take some federal dollars I just want to mention uh that that is not a reflection of her uh you know commitment to cyber security she just believes in federalism and she spent millions of South dakotan dollars to create this program of cyber in her own State um implying that she somehow is opposed to cyber security protection because she chose
▶ 2:40:58not to take federal dollars I think is a mistake uh the members of the committee can also ask additional questions to you and they have a few days to do so and I ask that you guys respond in writing um pursu pursuant to committee rule 7D the hearing record will be held open for such for 10 days than thank you again and without objection this committee
▶ 2:41:48adjourned for