▶ 0:10:12The Committee on Homeland Security will come to order. Without objection, the Chairman may declare the Committee in recess at any point. Without objection, the gentlewoman from New York, Ms. Clark, and gentleman from Puerto Rico, Mr. Hernandez, are permitted to sit in the days and ask questions of witnesses. Purpose of this hearing is to evaluate the effectiveness of the federal cyber regulatory regime and to identify opportunities to harmonize cyber regulations across the federal Specifically, we will examine the challenges that that private sector owners and operators of critical regulatory of
▶ 0:10:42critical infrastructure face while navigating cyber regulatory regime, including the potential impact of the final CIRCIA rule if it does not meet congressional I now recognize myself for an opening Morning. I'm honored to serve as Chairman of this subcommittee again in the 119th Congress. Ranking Member Swalwell, it's great to serve alongside you for another term. I'd also like to welcome all of our members returning and the new ones that are here.
▶ 0:11:08I'm looking forward to working with all of you and to making this a productive As cyber threats to information technology and operational technology increase, we must work hard to ensure cybersecurity is front and center on Congress's agenda. Till we change our cybersecurity posture, we'll continue to see rogue nation-state actors target our nation's critical infrastructure. In that spirit, I am pleased to give this Congress with a bipartisan priority that is vital to our nation's security, regulatory harmonization.
▶ 0:11:38For too long, we have talked about the cumbersome nature of cyber regulatory regime without seeing the changes necessary to solve it. In fact, the Biden administration tried to add more regulations on the sector on sectors such as healthcare and water. While it is important for the federal government to work with those sectors that are not as cyber mature, more regulation is not the answer. With over 50 regulations at the federal level alone, it is time to streamline requirements to ensure they promote useful, actionable, and reasonable information sharing within the time frame requested.
▶ 0:12:10When organizations face their most vulnerable moment, they should only be thinking about one thing, securing their Hours of duplicative compliance tasks and hundreds of thousands of dollars invested to navigate the landscape must come to an end. With the beginning of the new administration, we have an opportunity to reset the regulatory regime once and for all. In 2022, Congress passed landmark legislation to streamline cyber incident reporting, the Cyber Incident Reporting for Critical Infrastructure Act of 2022 or CIRCIA.
▶ 0:12:41This directed CISA to develop regulations to set an acceptable standard for cyber incident reporting across all 16 critical infrastructure Unfortunately, as many of today's witnesses reinforced last year, the scope of the proposed CIRCIA rule went far beyond congressional intent. Knowing that the deadline for the final rule is approaching, we will dig into the value of CIRCIA and what the future of the rule should look like. This new administration presents an opportunity to get cyber incident reporting right. We should seize it.
▶ 0:13:09Beyond CIRCIA, different regulatory agencies have imposed rules that directly contradict contradict congressional intent with CIRCIA. Securities and Exchange Commission's rules on cybersecurity risk management, strategy, governance, and incident disclosure are a perfect example of how rulemaking should not be done. That is without buying from their key stakeholders, industry and Congress. As we strive for regulatory harmonization, collaboration across the public and and private sector is vital.
▶ 0:13:37We cannot allow malicious cyber actors to get ahead of us because paperwork holds us back from effective cyber risk management, mitigation, and response. I look forward to hearing from our witnesses about the steps we take to finally we can take to finally achieve regulatory harmonization. I now recognize the Ranking Member for an opening statement. I thank the Chairman and excited to begin this new Congress again with the Chairman.
▶ 0:14:05It's not a great place to be in the minority, but if you have a Chairman like Mr. Garbarino on your subcommittee, it's a great place to get things done and that's our mission here is to get things done for the good of our constituents and the security of the people and companies we represent.
▶ 0:14:24This first hearing is focused on a bipartisan priority, identifying opportunities to improve implementation of the Cyber Incident Reporting for Critical Infrastructure Act, CIRCIA, and the need to harmonize cyber regulations. Before I begin though, I did want to take a moment to recognize and express my condolences to the family, friends, and constituents of Congressman Sylvester Turner who passed away last week.
▶ 0:14:49He was a member of this subcommittee and his passion for cybersecurity, whether it was as the mayor of one of America's largest cities in Houston, that was clear also as a member of Congress serving on a committee that works on that, and it was clear during his first two full committee hearings last month, and we'll miss his contributions that he made and would have made to this Turning to the subject of today's hearing, I agree that compliance
▶ 0:15:20costs can outweigh the security benefit of regulations when compliance with duplicative regulations cuts into investment in security. We should not be imposing regulations for the sake of imposing regulations. Security should be designed to achieve outcomes that are proven to reduce risk and improve resilience and security.
▶ 0:15:43Toward that end, I am pleased to support CIRCIA because it addressed a concrete security gap and will improve the government's ability to detect and disrupt malicious cyber activity. It also put in place a framework that ensures covered entities would not need to report the same cyber incidents multiple times to multiple regulators. If a hacker gets into a bank or energy company, we want them to focus on eradicating the threat as quickly as possible, not huddling the lawyers and compliance experts.
▶ 0:16:13They should be fixing the problem and reestablishing their services. I'm troubled that the proposed rule does not incorporate the feedback that the private sector provided during the RFI process. Congress puts CISA in charge of the cyber incident reporting rule because it has a record of working collaboratively with the private sector, and our intent was that CISA would engage the private sector to develop a workable rule.
▶ 0:16:37Together with Ranking Member Thompson and my colleague, Congresswoman Clark, I submitted comments on the proposed rule urging CISA to more carefully scope the entities, incidents, and information that must be reported. I've also called on CISA to establish an ex parte process to facilitate ongoing engagements with the prior with the private sector. With the fall 2025 deadline for issuing a final rule looming, I urge CISA to work quickly to reengage with the private sector and refine the scope of this rule.
▶ 0:17:07There are also three key pieces of cybersecurity legislation that I urge this Committee to pass as quickly as possible. First, we must authorize the Joint Cyber Defense Collaborative, CISA's operational and collaboration hub. Formal authorization of the JCDC will provide much-needed transparency regarding who can be a member and the activities JCDC takes on.
▶ 0:17:28We passed this in a bipartisan manner last Congress with support of the Chairman of the whole Committee, and I hope that authorization this Congress will restore trust among JCDC participants and focus JCDC on the activities most likely to drive security the Cyber Information Sharing Act of 2015 is set to expire at the end of September.
▶ 0:17:52The bill is the foundational collaboration between the government and the private sector, and it must be reauthorized. As it relates to CISA and some of the filings that we've seen I want to make sure that we get rid of waste, fraud, and abuse. The government should be efficient and not waste your money. That is a priority of mine. It's a priority of most of my colleagues.
▶ 0:18:13However, we must be especially careful when any cut goes to public safety, national security, or cybersecurity because we know that we are more vulnerable than ever to a cyber attack, and we want to make sure that we have the best folks on guard working hand-in-hand with the private sector to make sure we're best Finally, state and local cybersecurity grant programs will expire on September 30.
▶ 0:18:39The grant program has helped state and local governments across the country improve their ability to defend against and become resilient to sophisticated cyberattacks from our adversaries and other criminals. Again, I thank my colleagues for their commitment to moving the ball forward on cybersecurity, and I look forward to working with each of you and our witnesses to do that. Mr. Chairman, again, I'm looking forward to this Congress and what we can do together, and this is an appropriate way to kick off this subcommittee, and I yield back. Gentleman yields back.
▶ 0:19:07Thank I now the Chairman of the full Committee, Mr. Green, for an opening statement. Thank you, Chairman Garbarino and Ranking Member. Good to see you guys today. Today's hearing serves as a crucial opportunity to examine the effectiveness of federal cyber bureaucracy. At a time when cyberattacks are growing more frequent and sophisticated, it's imperative that our regulatory process governing cyberspace is strengthened and harmonized.
▶ 0:19:36This will promote security and cooperation while minimizing cost and confusion. Last May, this subcommittee held a hearing focused on CIRCIA, Cyber Incident Reporting for Critical Infrastructure Act of 2022. CIRCIA, among other things, directed to create and implement regulations for cyber incident reporting across 16 critical infrastructure sectors.
▶ 0:20:00Although Congress passed CIRCIA nearly 3 years ago, widespread regulatory disharmony persists throughout the cyber incident reporting and response regime. There are now at least 50 cyber incident reporting requirements in effect across the federal government. These regulations are often duplicative and complex, requiring private sector owners and operators to invest significant sums into regulatory compliance rather than security.
▶ 0:20:27This patchwork of conflicting and complex regulations place a significant burden on reporting entities. Let's be clear, improving our nation's cyber regulatory regime will bolster our nation's security. Current cyber incident reporting regulations require too much of the private sector, drawing their attention away from actually securing their networks. Federal regulations, like the SEC's public cyber disclosure rule, clearly illustrate the urgent need for harmonization.
▶ 0:20:56This rule in particular is riddled with ambiguity and sets constrictive reporting timelines for organizations that experience cyber incidents. Ambiguous and conflicting standards, like the SEC rule, are allowing compliance to take a priority over security, leaving our critical infrastructure more vulnerable to subsequent attacks. Injecting consistency and efficiency into the cyber regulatory regime is necessary to protect our nation from digital threats to our critical infrastructure.
▶ 0:21:26The security of our homeland depends on effective cooperation between the private and public sectors, and it is our duty to help remove any unnecessary barriers to Since CIRCIA CIRCIA is still in the rulemaking process until later this year, there's still time to ensure that regulatory effectiveness and harmonization are core features of our national cyber incident reporting The final rule must not place an undue burden on private sector entities that are critical to our national cyber
▶ 0:21:56defense. I want to thank our witnesses, Scott Aronson uh from Edison Electric, uh Heather Hogsett from uh Bank Policy Institute, Robert Mayer from uh US Telecom, and Ari Schwartz from the Cybersecurity Coalition for being here today. Most of you have uh testified before during our hearings last May, and each provided invaluable insight to this subcommittee. Thank you for being here today.
▶ 0:22:23With President Trump in office, we have a unique opportunity to create a common-sense cyber regulatory structure that ensures compliance, serves its purpose to to share actionable information to with the federal government and with each other.
▶ 0:22:38As nation states As nation state threats rise, we must do all we can to ensure that our cyber professionals can focus their precious time and attention and resources on securing networks and critical infrastructure, and not on checking a I look forward to working with you as we pursue this shared objective. I yield. Chairman yields back. Other members of the committee are reminded that opening statements may be submitted for the record.
▶ 0:23:06I'm pleased to have a distinguished panel of witnesses before us today. I ask that our witnesses please rise and raise their right hand. Do you solemnly swear that the testimony you will give before the Committee on Homeland Security of the United States House of Representatives will be the truth, the whole truth, and nothing but the truth, so help you God? Let the record reflect that all the witnesses have answered in the affirmative. Thank you. Please be I mean, I'd like to formally introduce our witnesses. Mr.
▶ 0:23:32Scott Aronson currently serves as senior vice president for energy security industry operations for the Edison Electric Institute. In this role, he focuses on industry security and resilience initiatives, establishing collaborative partnerships between government and electric companies, and of course critical infrastructure sectors that enhance security for the energy sector. In addition to to his role at the EEI, Scott also serves as the secretary for electricity subsector coordinating council, ESCC. Ms.
▶ 0:23:59Heather Hogsett is the senior vice president and deputy head of BITS, the technology policy division of the Bank Policy Institute. In this position, she develops and leads initiatives on emerging technology, security resilience matters facing the nation's largest financial firms. Ms. Hogsett also co-chairs the policy committee of the Financial Services Sector Coordinating Council. And is board member of FTLD Registry Services. Mr. Robert Mayer is the senior vice president of cybersecurity innovation with the US Telecom Association.
▶ 0:24:29He is responsible for leading cyber and national security policy and strategic In addition to this role, he serves as chairman of the Communication Sector Coordinating Council, which represents the broadcast, cable, satellite, wireless, and wireline industries in connection with DHS and public-private partnership activities across the US government. He also serves as co-chair of the Council of the Secure Digital Mr.
▶ 0:24:53Ari Schwartz currently serves as the coordinator for the Cybersecurity In this role, he leads a consortium of cybersecurity companies, coordinating the coalition's advocacy and education regarding cybersecurity policies. He also serves as the managing managing director of cybersecurity services for Venable, where he helps organizations develop and implement cybersecurity risk management strategies. He was previously a member of the White House National Security Council, where he served as special assistant to the president and senior director for I thank the witnesses for being here today.
▶ 0:25:23I now recognize Mr. Aronson for 5 minutes to summarize his opening Thank you, Chairman Garbarino, and Ranking Member Swalwell, Chairman Green, and to all the members of the Appreciate the opportunity to testify today on cyber regulatory harmonization, and specifically on implementation of the Cyber Incident Reporting for Critical Infrastructure Act of 2022, or more easily CIRCIA. Uh my name is Scott Aronson, and as noted, I'm senior vice president for energy security and industry operations at the Edison Electric Institute.
▶ 0:25:51As you know, EEI is the trade association representing 250 million uh companies that provide electricity to nearly 250 million Americans, operating in all 50 states and the District of Columbia. As I testified last May, EEI and its members wholly endorse the policy objectives underpinning CIRCIA. Incident reporting can help industry and our government partners identify threats, see patterns, set policies, and prioritize risks to better protect critical infrastructure.
▶ 0:26:21CIRCIA is important law with important goal of identifying and mitigating cyber risks across all sectors of the economy, and I appreciate this committee's leadership in shepherding this effort these last several years. When CIRCIA was enacted, Congress emphasized that the legislation sought to strike a balance between enabling CISA to receive information quickly, and allowing the impacted entities to respond to an attack without imposing burdensome requirements that prioritize paperwork over cyber defense and Details matter when it comes to how CIRCIA, or
▶ 0:26:51any new cybersecurity policy, is implemented. Nearly a year after the subcommittee's and my initial testimony on CIRCIA, we are in a period of transition with the new administration and the new Congress. Change brings opportunity, and I urge this subcommittee to leverage this opportunity to help ensure CISA is implementing CIRCIA effectively.
▶ 0:27:10Both my written testimony and comments today focus on two main considerations for Congress when evaluating how best to First, the need to finalize the CIRCIA CIRCIA rule as mandated by statute, so that electric companies and all critical infrastructure operators can benefit from this reporting to this benefit from this reporting to mitigate attacks and the disruptions they can cause. And second, improving the existing proposal to better align with congressional intent.
▶ 0:27:37CISA must do more to meaningfully incorporate industry feedback into the final rule to ensure reporting is not duplicative, and the government is resourced to ingest and protect this sensitive information. Following the hearing last May, EEI has continued to engage with CISA on CIRCIA. In July 2024, EEI submitted three sets of comments on the proposed rule.
▶ 0:27:57And in October 2024, EEI joined more than 20 organizations in req- in requesting the establishment of an ex parte process to enhance stakeholder engagement and facilitate ongoing dialogue for As I once again testify before you alongside the financial services and telecommunication sectors, representing some of the most sophisticated critical infrastructure operators, our collective concern remains that even the most mature sectors will be overburdened by the proposed rule if it were to be finalized as is.
▶ 0:28:25The committee should work with CISA to reduce this burden and focus on a few areas for improvement. First, conduct oversight regarding the current status of CIRCIA, including staffing levels, resource needs, the projected timeline for final rule completion, and anticipated future engagement with industry stakeholders.
▶ 0:28:41Second, facilitate coordination amongst congressional committees of jurisdiction to align CISA, sector risk management agencies, and other regulators, and review concerns with existing federal reporting requirements, including the national security concerns associated with the public disclosure of incidents as required by the US Securities and Exchange Commission rule. Third, further clarify CISA's role in cybersecurity regulatory harmonization in relation to other federal entities.
▶ 0:29:05And fourth, reauthorize the Cybersecurity Information Sharing Act of Mandatory incident reporting and voluntary information sharing both are valuable tools in ensuring the cybersecurity of critical EEI and its members are committed to working with both public and private partners across all sectors to comply with incident reporting requirements and cyber regulations more broadly in a way that prioritizes and enhances critical infrastructure security.
▶ 0:29:29We look forward to working with you and CISA to finalize a rule that leverages existing regimes, provides meaningful insights to government and industry, and protects sensitive information. I'll also take a moment here to note, a little off script, uh that the news this morning about uh the Critical Infrastructure Partnership Advisory Committee Act uh being rethought uh under this new leadership at the Department of Homeland Security. It's not our place to decide how government organizes, but I want to highlight the value of industry-government partnership.
▶ 0:29:59And CIPAC provides extraordinary protections for those partnerships and those partnership activities. Uh Nearly 90% of critical infrastructure is owned by the private sector. It's critical because it's critical to national security and it is critical to the life and safety of the communities that we serve. Industry and government have to be working hand in glove and again, CIPAC provides a really valuable uh mechanism to do that. We appreciate the bipartisan support of this committee in ensuring we get CIRCIA right and CIPAC right.
▶ 0:30:27And we look forward to continuing our collaboration to protect the safety, security, well-being of all Americans as we face evolving cyber risk. Thank you again for the opportunity to testify and I look forward to your questions. Thank you, Ms. Aaronson. I now recognize Ms. Hogsett for 5 minutes to summarize her opening statement. Thank you. Good morning, Chairman Garbarino, Ranking Member Swalwell, Chairman Green, and honorable members of the subcommittee. Thank you for inviting me to testify.
▶ 0:30:49I'm Heather Hogsett, Senior Vice President and Deputy Head of BITS, the technology division of the Bank Policy BPI is a non-partisan policy research and advocacy organization representing the nation's leading banks. On behalf of BPI members, we greatly appreciate this committee's leadership and the opportunity to provide perspective on cybersecurity As today's national security threats increasingly target vital infrastructure and our economy, it is imperative that industry and government work together to have an awareness of cyber incidents
▶ 0:31:19and vulnerabilities while ensuring cyber teams can focus on day-to-day tasks, responding to incidents when they occur, and implementing next-generation Unfortunately, the current state of cyber regulations detract from this vital work. To support the nation's security and resilience, we offer a few First, streamline the reporting of cyber incidents to allow cyber teams to focus on response.
▶ 0:31:46I previously testified before this committee in support of the Cyber Incident Reporting for Critical Infrastructure Act, CIRCIA, and its goal to create a uniform incident reporting This would provide CISA with information it needs to have broader awareness of cyber threats and the tactics used by Armed with this information, CISA can better assess threats and provide early warning to help other entities protect We continue to believe that CIRCIA, if properly implemented, will play an important role in our collective
▶ 0:32:16However, as we noted in formal comments last June, it is critical that the final rule not extend beyond the authorities granted to it under the statute. Bipartisan members of this committee, as well as Senator Peters, submitted comments emphasizing a similar view. Your comments were enormously helpful in reiterating congressional intent and we thank you for your continued leadership and engagement.
▶ 0:32:38We, along with several other financial trade associations, recently asked that the current proposal be withdrawn and In particular, we encouraged CISA to significantly revise last year's proposed rule to reduce the scope of reporting to incidents affecting critical services, focus data collection on what companies need to know to prevent contagion, and reduce ongoing reporting obligations. At the same time, Congress and the administration should direct other agencies to cease issuance of bespoke reporting requirements.
▶ 0:33:08Some agencies, such as the federal banking regulators, have incident notification requirements that are simple and serve a very specific operational or emergency response These requirements were developed in close collaboration with industry and work well in practice. Other agencies, however, continue to issue onerous reporting or disclosure requirements with different definitions, timelines, and varying data elements that do not improve security outcomes.
▶ 0:33:34One rule in particular is the SEC's requirement to disclose material cyber incidents within four business days, regardless of whether the incident has been contained or remediated. This rule should be rescinded as it undermines CIRCIA and confidential reporting and unnecessarily complicates incident response. Second, we encourage Congress and the administration to consolidate industry-specific cyber regulations and regulatory oversight.
▶ 0:34:00This is a particularly acute challenge for financial institutions with multiple A survey of bank chief information security officers found that they spend 30 to 50% of their time on compliance and examiner management, and their teams can spend 70% of their time on those Firms receive on average 100 requests for information leading up to an exam with anywhere from 75 to 100 supplemental requests during an exam that can take weeks, if not months, to Once one exam is completed, another regulator
▶ 0:34:31often comes in to examine the same or a similar topic. The current state risks undermining our security and it is time for a Finally, we urge Congress to reauthorize cyber information sharing protections that expire this fall. The Cybersecurity Information Sharing Act of 2015 established important liability and antitrust protections for entities sharing cyber threat information, which were subsequently incorporated into CIRCIA.
▶ 0:34:58In the decades since their enactment, these protections have supported not only the sharing of cyber threat indicators, but also broader awareness of vulnerabilities, knowledge of threat actors and their tactics, and effective defensive measures. Recent attacks against public and private industry infrastructure underscore the importance of preserving these protections and the important information exchange they facilitate.
▶ 0:35:21We greatly appreciate this committee's thoughtful approach to these issues and stand ready to work with you to protect the security and resilience of our nation's infrastructure. Thank you for the opportunity to speak today and I'm happy to answer any Thank you, Ms. Hogsett. I now recognize Mr. Meyer for 5 minutes to summarize his opening Chairman Garbarino, Ranking Member Swalwell, Chairman Green, and our honorable members of the subcommittee.
▶ 0:35:45Thank you for the opportunity to testify today on the critical issues of cybersecurity incident reporting and regulatory harmonization. We are committed to strengthening the public-private partnership to bolster our national security and stay ahead of our adversaries. This committee has an extraordinary opportunity to reset our national cybersecurity policies in ways that directly impact security outcomes.
▶ 0:36:09Our nation is under constant cyber attack with estimates of up to 23 trillion dollars in annual damages by increasing at a rate of more than 20% per year. We must take immediate action to eliminate redundant or conflicting cyber regulations, which can consume up to 70% of cybersecurity resources.
▶ 0:36:33By streamlining these requirements, we can free up critical resources for threat mitigation and incident response at virtually no cost. Let me reaffirm our view that it is essential we fix how the Cyber Incident Reporting for Critical Infrastructure Act, CIRCIA, needs to be implemented. While well-intentioned, it is essential that we refine its execution to ensure consistency with the law's original intent.
▶ 0:36:57Specifically, key terms such as covered incident, covered entity, and reasonable belief must be clearly defined. The liability protections designed to safeguard cyberattack victims and promote candid reporting must be strengthened. As of today, none of these fundamental issues have been meaningfully addressed in a manner visible to industry, nor has our sector been substantively engaged in addressing these concerns.
▶ 0:37:22We urgently need an ex parte process, which is to say a formal, transparent, and common process that encourages CISA to hear and consider industry perspectives. In fact, USTelecom spearheaded a letter of 21 organizations that formally requested that CISA establish such a process, a request that was rejected. Had this request been granted immediately, we would have already been working together to resolve these challenges.
▶ 0:37:50If we do not act quickly, we will end up with a rule that does more harm than good. We must also recognize that this law does not exist in isolation. The patchwork of federal, state, sector-specific cyber incident reporting requirements presents an ever-growing burden on organizations attempting to comply with multiple, often conflicting, Fortunately, there is strong lawmaker interest to harmonize cyber regulations, including incident reporting We believe that the
▶ 0:38:20Office of the National Cyber Director should play a leading role in rationalizing cybersecurity regulations and incident reporting regimes. Solving the problem of fragmented state laws will require clear federal preemption, complemented by robust safe harbor provisions. This work must be prioritized as it directly tied to our national security. We believe it is important that Congress acts now.
▶ 0:38:45We do not have time for further studies, requests for information, commissions, or pilot programs. Every moment spent delaying reform provides adversaries with additional opportunities to undermine our collective security. We must move swiftly and decisively to enhance our cybersecurity posture. Major recent cybersecurity incidents have highlighted the importance of a stronger and more coordinated information sharing and incident response partnership between the federal government and the private sector.
▶ 0:39:15Congress advanced that project with the Cybersecurity Information Sharing Act of which is set to sunset in September of We asked that Congress extend the act and establish additional policies to improve the public-private partnership. We must also be willing to write reconsider policies that have failed to produce meaningful security benefits.
▶ 0:39:37One such example is the Security and Exchange Commission's cyber disclosure requirements, which, rather than enhancing security, have inadvertently provided malicious actors with a roadmap to exploit vulnerabilities. These mandates must be reassessed to prevent them from serving as a tool by force In conclusion, success in cybersecurity requires close collaboration between the industry and government including Congress and the office of national cyber director.
▶ 0:40:05We must act now to ensure that our cybersecurity policies are well reasoned, well informed and designed to maximize efficiency and effectiveness. By fixing CISA's implementation, harmonizing cyber regulations and eliminating unnecessary burdens, we can strengthen our nation's cybersecurity defenses and uphold our commitment to protecting to protecting national security. Thank you for the opportunity to testify today and I look forward to your questions. Thank you Mr. Mehra. I now recognize Mr.
▶ 0:40:35Schwartz for 5 minutes to summarize his opening statement. Chairman Garbarino, ranking member Swalwell, uh Chairman Green, members of the subcommittee, thank you for having me here to uh appear before you today. It's an honor to be here to discuss the widely shared goals of harmonizing cybersecurity regulations. My name is Ari Schwartz. I'm coordinator of the cybersecurity coalition. The leading policy coalition representing companies that develop cybersecurity products and services.
▶ 0:41:08As cybersecurity threats continue to grow, calls for cybersecurity regulation around the world have increased as well. In the US, choices that Congress made 10 to 15 years ago led most cybersecurity regulations to be overseen by the current sectoral regulators. This has the convenience of maintaining the current relationship between the regulated company and the regulator. Organizations are overseen by agencies that know that sector. But each agency is not going to have full expertise in cybersecurity.
▶ 0:41:34New cross-sector and international regulations have continued to to grow making harmonization difficult, but it's not impossible. Agencies must work extra hard to ensure that regulations can align so we're not overburdening organizations and putting so much work on compliance that we are draining resources that otherwise could go to actually improving security. The example where this is most obvious today is around incident reporting.
▶ 0:41:58Incident reporting allows agencies to track what's happening in and across sectors and in the best case scenario alert potential victims before it's too However, as DHS pointed out in a report to Congress in 2023, 45 different incident reporting requirements have been created led by 23 different International Internationally, the reporting regimes have grown equally These reports are on different time frames, use different types of information and use different taxonomies to describe
▶ 0:42:28the information. This has led to duplication, misalignment and general confusion. In 2022, Congress passed CISA, a law intended to have critical infrastructure standardized reporting and send it to CISA ran a process to receive comments on how to how this reporting should work and issued a notice of proposed rule making in 2024. It is the cybersecurity coalition's view that the proposed rule did not meet Congress's goal of adequately harmonizing incident reporting First of all, there was a lack of engagement.
▶ 0:42:59While CISA clearly tried to follow the letter of the law in getting comments on the rule making, it failed to adequately engage the sectors. The open sessions that were held were wrote and did not address known and concerns of the community. The CISA representatives simply simply repeated the same questions CISA had originally posed. Secondly, there's an overbroad scope in the in the in the proposed rule.
▶ 0:43:22Instead of harmonizing around existing rules or best practices identified by the sectors, CISA decided to create a new broad definition of covered entities. CISA also decided to create a new construct of what triggers reporting and what needs to be reported. Lastly, there's a failure to streamline the reporting.
▶ 0:43:39While CISA made some attempts to ensure that the report report filed with CISA would be shared with others that that might require it, the proposed rule did not go far enough to demonstrate that CISA was attempting to solve the problem of duplicative reporting seemingly placing the onus on the reporting on the organizations. We believe that these issues can be addressed if CISA makes an a commitment to meeting with the sectors.
▶ 0:44:00We suggest this be done through an ex parte rule making process using the critical infrastructure partnership known as However, we have heard that Secretary Noem last week shut down CIPAC. Which we think is a mistake for many reasons with this process being a good example where the CIPAC process can play a critical role in the public-private Finally, while we were taking talking about the importance of sharing information with the government, I would be remiss not to speak up in favor of reauthorization of the Cybersecurity Information Sharing Act of 2015.
▶ 0:44:31This law has provided the ability for companies to share cyber threat information among themselves and with It has streamlined the definition of what cyber threat information of of cyber threat information and has allowed multiple groups to form and to share that information to quickly stop and or to respond to incidents. We hope that reauthorization of the of that of the law is a priority for this subcommittee. I thank you and I look forward to your questions. Thank you Mr. Schwartz. Uh members will be recognized by order seniority for their 5 minutes of questioning.
▶ 0:45:01I want to remind everyone to please keep their questioning to 5 minutes. An additional round of questioning may be called after all members have been recognized. I now recognize the gentleman from Tennessee, the chairman of the committee, Mr. Green for 5 minutes of questioning. Thank you. Uh first let me say the testimony today has been superb. Um I I my questions will be to reiterate points you've made.
▶ 0:45:25Uh in fact, I just told my senior staffer for cybersecurity to get copies of everyone's testimony and provide it at the cyber subs meeting. The cyber subs committee I I started this last year. Some of you may be aware of this where we meet all the cyber subcommittees to try to get a whole of government approach here. Uh we're going to send copies of your testimony to every cyber subcommittee member in this Congress. This was excellent. Thank you. You know, Congress has a duty.
▶ 0:45:55Let me let me make this point. Congress has a that we have shirked over 40 years in both parties and passed off to the The Constitution's really clear. A lot of these things that the administration is now closing, Chevron deference uh and the Supreme Court have ruled it really belonged to Congress in the first place and we never should have passed it off to the doggone administration and the bureaucracy.
▶ 0:46:20And so I get that there's some frustration that certain things are being closed, but I mean constitutionally, we need to do that here. It's a part of our oversight obligation. It's a part of our particularly reporting and review boards and things like that. I was told yesterday and I don't know if it's completely true. I got to fact-check this, but the VA spends a billion dollars on compliance. Does that seem reasonable? Billion dollars on compliance?
▶ 0:46:50These conflicting rules in this all this time I think Miss Hack, said you said 30% on actual uh just checking the box compliance and 70% on real cybersecurity. Was that the ratio you quoted? 30 to 50% of the chief information security officer's time is on checking the box and 70% of their Let me ask this question.
▶ 0:47:17What is the average time to close a vulnerability when one's been identified? And I just Give me a number of days and I'm going to run the average vulnerability closing the door takes how long? Take a take a guess. You're going to hate this answer. It True. If it's a critical vulnerability, firms work to close that within days if possible.
▶ 0:47:43It all depends on whether you It would depend on how much control you have over it. If it's something that resides within a third party, you have less control and ability to move quickly to close it. Yeah, I don't want to speculate sir on an on an average, but I will tell you that if you look at the recent attacks that are coming from nation states, it's taken weeks, months Yeah. and it's still a process underway. Yeah, well I'm not sure we've patched the telecom breach yet.
▶ 0:48:10we're talking about like browsers, they can close them in hours, but if we're talking about operational technology, it takes days. Days? Yeah. Yeah, and and SEC pulls the number 4 days out of their backside uh and thinks that they're doing shareholders a uh uh a positive, but when they announce that they've got a hole in the door or in the wall and uh you it's not going to be closed, it invites attack from everybody. It's the stupidest thing I I've ever heard of.
▶ 0:48:40Let me ask this question. We've got to go and figure out all this list of uh list of conflicting How best do we as Congress, does this subcommittee and the subcommittees across our our figure out all the list of duplicative and contradictory requirements? How do how do we go get this information?
▶ 0:49:05So, first of all, I appreciate what you said about the coordination across all the committees of jurisdiction. I think understanding The first thing a cyber uh a CISO or a CSO is going to do is inventory their entire system to understand where vulnerabilities might be. I'd say that Congress needs to inventory the system, understand where all of the regulatory requirements are so that we can start to work do the hard work of harmonizing.
▶ 0:49:31And just to foot-stomp something that you said about the lunacy of the SEC rule adversaries and and to talk about the uh vulnerabilities and the time to patch, adversaries watch our response. And I understand, you know, the importance of sunshine and and transparency, but we also have to understand that intelligent adversaries are leveraging our transparency when perpetrating attacks and seeing how we respond.
▶ 0:50:00And don't we list vulnerable the identified vulnerability somewhere in a database that the bad guys can sit there and take a look at and then challenge and find where that vulnerability is anywhere in the system? Those Those vulnerabilities become a little less important when everybody knows about them. So, there there is that that There's always that legacy system that's still running the old thing that nobody catches and it's an open door. That's what worries me there, Mr. Schwartz.
▶ 0:50:27going to say, I mean, they shouldn't You shouldn't post This is This is one of the reasons we say, don't we need a patch before you post a Yeah, exactly. Patch has to exist, but then people actually have to patch. We just got to get everybody to download the patch. Thank you. I yield. Thank you to to our chairman. Now, I recognize the gentlewoman from New York, the former chair, Ms. Clark. Thank you very much, Mr.
▶ 0:50:53Chairman, and I thank ranking member Swalwell for letting me wave on to today's subcommittee hearing. And thank you to our panelists of witnesses for Excuse me, joining us today. I'll be Before I begin my comments, I'd like to associate myself with the sentiments of ranking member Swalwell regarding Congressman Sylvester Turner. We are grateful for his service to the people of Houston, Texas and to his family and loved ones, we extend our deepest condolences.
▶ 0:51:24May he rest in peace. When I introduced CIRCIA back in 2021 with Ranking Member Thompson and Chairman Garbarino, I did so because I recognized the important need for increased visibility into the cyber incidents affecting critical infrastructure and the importance of a central hub for cyber incident reporting in the federal enterprise.
▶ 0:51:47I worked with many of the witnesses here today to get CIRCIA across the finish line and I appreciate their ongoing efforts to make sure that we get the final rule right. I also appreciate Mr. Swalwell's work encouraging CISA to effectively engage with the private sector on the rule. I agree with my colleagues and the witnesses before us that there are necessary improvements to the proposed rule, but the urgency of implementing CIRCIA remains.
▶ 0:52:15And I hope the new administration will work quickly to modify the proposed rule and publish a final one without undue delay. I have two questions for our witnesses. First of all, to all of our witnesses, without a defined well-defined cyber incident reporting rule and harmonization process for CISA we run the risk of agencies across government issuing a hodgepodge of duplicative cyber incident reporting
▶ 0:52:45How will scrambling to comply with multiple incident reporting requirements affect security? And then secondly many stakeholders have weighed in that the proposed CIRCIA rule defined covered entities and covered incidents too broadly unnecessarily increasing the burden on the private sector and potentially overwhelming CISA with too many reports to analyze.
▶ 0:53:11Indeed, CIRCIA instructed CISA to identify subsets of entities and incidents uh instruct Excuse me, subject to reporting requirements to avoid that outcome. Can give me your thoughts on that? We We'll We'll start with Mr. Aaronson and then work our way across. So, on the first question, we'll just echo some of the things that uh Ms.
▶ 0:53:36about the time that uh information security teams are spending on compliance. Uh it's somewhere between 30 and 50% and as you expand the hodgepodge, to use your word, of reporting requirements, it only gets more complicated.
▶ 0:53:52To your point about the broadness of CIRCIA as it currently exists and the uncertainty that surrounds it taken at its most sort of broad interpretation of what is a covered entity and what is a covered incident, we had one of our companies report that they thought they would have as many as 65,000 reports between 2022 and 2033. Um I think the number that CISA had said would be somewhere in the 200 to 220,000 total in that timeframe.
▶ 0:54:22So, it seems to be off by if that's just one company taken at a really broad interpretation, seems to be off by an order of magnitude. This goes to the importance of getting the definitions and the details right so that we can get some signal from the noise and so that CISA can ingest the information in a meaningful way. Very well, Ms. Sure, just to add to that and thank you for the question.
▶ 0:54:44The challenge of responding to multiple requirements does have a direct impact on security because it is diverting the time and attention away from what we all want the cyber professionals to be doing, which is defending their networks, kicking out bad actors when there is an incident, and focusing on that.
▶ 0:54:58Instead, they have to divert time away to basically make sure they're complying with different legal Um With respect to the definitions and covered entities within CIRCIA and the proposed rule this committee was very thoughtful and and Scott just alluded to it to make sure that the the law would be crafted in a way that we get signal from the noise.
▶ 0:55:19You wanted the incidents that were going to be most impactful so that CISA could very quickly have the capability to take that information and turn it back around to share with other entities that could also be at risk. The very broad scope with which the proposed rule was put together would put a lot of noise out there and make that all the more challenging.
▶ 0:55:41For instance, the definition would potentially capture operational outages that have nothing to do with a cyber incident and I don't think that that was really what you and the committee had intended in crafting that law. Very well, Ms. Demings. My time's up. Yes, thank you.
▶ 0:55:57Congresswoman Clark, I think that we have to deal with the fact that the reporting requirements right now are extraordinarily Um and the CIRC itself, Cyber Incident Reporting Council, at the time in September '23 identified 45 different reporting regimes, 22 agencies, I believe. I can only imagine that number has increased since then. CISA has indicated that they expect three 300,000 entities to be responding to these kind of requests.
▶ 0:56:27I can only imagine with in the absence of clear definitions around the terms that you folks identified um and staying close to the intent in the absence of revising that and refining that and making it operationally practical for companies to respond, the system will get overwhelmed. The system in government will get overwhelmed and the system in the in the operating environment will also get overwhelmed.
▶ 0:56:52The critical point here is that during a a major cyber incident when we are in essentially in a triage mode um we can't take people and divert them from their frontline responsibilities to identify the problem, remediate it, and respond and recover.
▶ 0:57:10So um we believe that this this particular rule needs to be reconstructed to align with your intentions um and if it doesn't, we're going to be doing more as I indicated, it'll create more harm than good. Very well. Um I agree with everyone on the panel has said on the answer to the first question.
▶ 0:57:28On the second question, I'll just briefly say that on the idea of the definition covered entities, CISA decided to to kind of narrow try to narrow the scope by the size of the company by going to the size of the companies, which I think does help in terms of removing some of the small medium small medium-sized businesses that we might not want to report, but it doesn't get to the risk issue, right?
▶ 0:57:49So, you're going to have a lot of large company very large companies that have a lot of incidents getting echoing what what we heard from from from others here that are going to be reporting a lot that is not of the same value as if we did it based on some kind of risk feature. Very well. Thank you for your indulgence, Mr. Chairman. I yield back. Gentlewoman yields back. I now recognize the gentleman from Louisiana, Mr. Higgins, for 5 minutes of questions. Thank you, Mr. Chairman.
▶ 0:58:16I appreciate this hearing today and I I concur with Chairman Green. It's been excellent testimony and I appreciate it. I'm going to review it very carefully. Mr. Chairman, in the 118th Congress, last Congress, I introduced a bill HR 10123 to streamline the Federal Cybersecurity Regulations Act uh which essentially cut down on duplicated or misaligned
▶ 0:58:47regulatory requirements and authorities on the cybersecurity industry. I'll be reintroducing that bill shortly in the 119th Congress and I look look forward to my colleagues' support on both sides of the aisle with that bill because Mr. Aaronson, how many federal agencies how many federal cyber regulations is a typical energy company required to report to in a given year? Just roughly.
▶ 0:59:15I mean, I'll just give you the agencies that we definitely have reporting That list would be too long to enumerate, but but you're talking about Just tell America two, four, 10, a dozen? More than a dozen. More than a The The gentleman said more than a dozen cyber regulators require a report from the energy industry. Ms.
▶ 0:59:40Hogg said, how many federal agencies does a bank need to file with to remain in good cyber security standing? We're similar and that's only at the federal level. You also have states and international um requirements to adhere to. So, at the federal level, which we control, would you concur, Ms. Aaronson, somewhere north of 10 or a dozen? Thank you. Mr. Mayor, similar question. Uh how many federal agencies does the telecommunications industry have to report to?
▶ 1:00:09I would agree with the number of over a dozen. Ea- easily over a dozen. Mr. Schwartz, you have a comment there? For IT, I would say that it's it's uh It's a lot, right? range, but it's spread out because it's people reporting We're reporting to the different sectors.
▶ 1:00:24So, now that we've clarified that for America, the the the objective here for the for United States Congress is to reduce that mess so that the cyber security industry can actually perform its its primary mission, which is to protect the nation and the industries of the nation from cyber attack, which we we've become increasingly uh susceptible to as technologies emerge, and while our cyber security industry is busy checking boxes that the federal
▶ 1:00:55government and bureaucracies has imposed upon the industry, they have that much less time to spend on that actual mission of protecting the nation, the citizenry, and the industries of America. So, how many of these agencies that require report, we've agreed it's over a dozen. How many of them have streamlined themselves, like coordinated with each said, let's eliminate this and this and this and and combine it into one.
▶ 1:01:24Has that ever happened, Ms. Aaronson? The Department of Energy has been fairly thoughtful because it's a it's our sector risk management agency and it's non-regulatory. That has actually helped So, within themselves, they've done some streamlining. To help people across the the departments and agencies, have you seen a similar effort just organically? No, certainly not. I think your oversight has helped. Ms. Ms. Hogg said, has there been any organic effort from the bureaucracies to streamline and reduce themselves? Yes and no.
▶ 1:01:54The yes is when it comes to incident notification, we have good coordination across three of our primary banking Um they aligned, there's a single standard, single definition, um and you provide information to one for common definitions. Yes. This is a good sign. It is. the banking industry, but there's a however here. There is That is with respect to incident reporting specifically. Uh for an incident report.
▶ 1:02:20Broader cyber security, we have even overlap and duplication among them. Roger that. Mr. Mayor. Uh same story. I'm not aware of any major or Thank you, Mayor. It was good to hear about the banking industry, but that's for incident reports. That's different. That's not total regulatory authority being streamlined. Mr. Schwartz. No, no, there's just been work Okay. So, so Mr.
▶ 1:02:43Chairman, this this is why Congress must act to bring clarity to the regulatory authority, and uh I will will hand you for your review, Mr. Chairman, the bill from last year. I intend to introduce it in the 119th in a a slightly refined iteration, and I would appreciate your support. Mr. Aaronson, you had mentioned Maybe I had time for this question.
▶ 1:03:11You uh you you you said that adversaries watch our response. Is it possible at all for the cyber security industry to strike back? If you said the adversaries are watching you, you must be able to identify the bad actor. Can you strike back at all against a bad actor? The private sector, well, I don't want to speak for the whole private Private sector. Electric companies do not want to be in offensive cyber engagements. Well, we can we can probably give you that opportunity. Mr.
▶ 1:03:40Chairman, my time has expired. Uh we'll have questions to submit in writing to each of these witnesses, and I appreciate this hearing, sir. Gentlemen, is that right? We probably will have a second round of questions if you do if you have time, but uh we will take them in writing as well. They have to be in writing. Thank you. Thank you, the gentleman. Uh I now recognize the ranking member, gentleman from California, Mr. Swalwell, for 5 minutes of questions. Mr.
▶ 1:04:04Schwartz, how should CISA revise its comment process to better engage stakeholders, and how would you recommend CISA structure additional feedback opportunities to maximize stakeholder input without unduly delaying issuing a final rule?
▶ 1:04:20Yeah, CISA has the tools today to do this, and Congress gave them the tools to to engage with uh the private sector in a way that they can get uh direct advice uh on issues uh and do it under uh uh protected from FOIA, protected from Freedom of Information Act, so that companies can feel free to share, and that it only goes into the process of writing this rule. Uh and they should use that as a as to to define their ex parte process.
▶ 1:04:50It is the CPAC authority that that provides them to do that, and that's exactly what we recommend that they do. Great. Thank you. To each witness, and feel free to jump in. I'll start. A decade ago, actually, sorry, a new question for each witness. Congress passed the Cybersecurity Information Sharing Act of 2015, which facilitates the voluntary sharing of cybersecurity between the private sector and the government. It expires, as I noted in my opening remarks, in September.
▶ 1:05:19What are the consequences of CISA expiring? Ms. Hogg. I'll start. So, the CISA 2015 protections really form the foundation for how we collaborate not just with government, but also across industry to ensure that we are sharing um necessary information to protect everybody. So, it's a key foundation for our collective defense.
▶ 1:05:44It provides information sharing protections, liability protections, antitrust protections, and we've now had the benefit of that for the last 10 years, and I think over that time, we've certainly seen an increase in collaboration. I think our sector has always collaborated well within itself, but the expansion to across sectors and with other companies has been very valuable. We would hate to see that disappear and that we walk back some of the gains that we've made in that space.
▶ 1:06:10And also, as we noted earlier, CIRCIA itself, with respect to incident reporting, refers back to the CISA 2015 protections. So, as we're getting ready to share more sensitive information, more detailed information to the government, we do want to make sure that it is well protected. Yeah, Mr. Magou. Thank you. So, um at a minimum, we think it's absolutely essential that the CISA 2015 Act be reauthorized.
▶ 1:06:36Um as pointed out, I think we've learned things in the last 10 years, what has encouraged additional information sharing, what has constrained it. So, there are opportunities to make enhancements, improvements in the law. The cost of not doing this is monumental.
▶ 1:06:51It'll cause companies to be very careful about what they submit, uh reluctant to submit with uh the protections that uh Heather alluded to, um and we'll be undermining our national security if we don't have something in place to either continue it in its current form, but ideally to reflect what we've learned over the past decade. Yeah, Mr. Yeah, so we've we've seen uh information sharing organizations grow around this law.
▶ 1:07:19And that they are specifically created, the Cyber Threat Alliance, for example, is is specifically built around this law. Um that the way that the the financial sector ISAC shares out with other groups, not internal, but with other organizations, is built around the the thing the pieces of this law. If If this law disappears, they will have to redo what they how they are structured.
▶ 1:07:41So, we and we will lose critical time just doing that, I'm okay I would just say this, I'm okay with like I believe in like sunk the principles of sunk cost, and like just because you've been doing it doesn't mean that's the best way to do it. But like, is it beneficial is the But it will it will definitely slow, and and in some cases totally stop information sharing that has prevented threats from and prevented incidents from happening. Great. So, I I want to spike in here. I agree with everything that my fellow panelists have said, so I'll just associate myself with that.
▶ 1:08:12Um those protections, the I sort of think of it north-south, industry and government sharing information east-west across critical sectors, has really grown up because of those protections in CISA. I also want to respond a little bit to something that Mr. Higgins was saying. Incident reporting and information sharing are both incredibly valuable, but understanding what the difference between those two things is.
▶ 1:08:33Information sharing is about ongoing threats, where we don't have full certainty of what an adversary might be doing, and sharing tactics, techniques, and procedures across critical sectors so we can all collectively defend is incredibly valuable. Incident reporting has value, too. Once we know what that risk was, um helping identify those patterns, helping to socialize those broadly, helping government to set priorities, helping to set policy that is informed by what is actually happening in cyberspace is incredibly valuable.
▶ 1:09:01So, we like incident share incident reporting, we like information sharing, it just needs to be done with protections and uh in an effective way that again, government can ingest all of this and and not put undue burden on the people who are just trying to defend networks. Great. Appreciate that, and yield back. Gentleman yields back. I now recognize the gentleman from Florida, Mr. Gimenez, for 5 minutes of questions. Thank you very much, Chairman.
▶ 1:09:25And uh today I had actually a a meeting with the airline industry and then we talked about this issue and and we asked about okay when they have an incident how many different reporting requirements they have they they have at least 10 different agencies that they have to report the same incident to seems a little bit inefficient all right and so and I you know Mr you know the representative
▶ 1:09:56Higgins asked same question you're saying it's 10 12 etc um would it make sense to have one form sent to one place and then that one place disseminate that information and I you start would absolutely make sense it's yeah we're not going to do it then yeah you're you're asking us to do the so um moving on
▶ 1:10:26um how many reportable incidents do you think there are I I guess you would know in your particular case but across United States how many reportable incidents do you think they are per day per day what definition are you using and what's something something that requires a report well something that requires an industry to to write a report how many of those incidents
▶ 1:10:57occur per day here in the United States do you anybody have any any idea I I would expect I'm take a guess here I think over a thousand incidents could be reported daily over a thousand over a thousand collectively across the entire our sector just your sector just my sector just sector how about banking I struggle to answer that because of the threshold you have incidents or events that might occur constantly but they don't necessarily I'm saying reportable I'm saying reportable you have
▶ 1:11:27to report we have notification requirements that are private so I wouldn't even know and a firm wouldn't be able to tell me because they're not allowed to can you give me a guess I would I would have to get back to you to be have an informed response on that okay how about an uninformed response just a why you know give me a swag okay honestly I hesitate okay what about okay and energy so to something Ms Hogsett saying there are wildly different reporting requirements there are some that you know pretty
▶ 1:11:57low bar there's some that have extremely high bar I can go back to the statistic that I know from one company that did a relatively deep dive on its reporting requirements especially with pursuant to CISA's broadest definitions and that was going to be 65,000 over 10 years so that's one company 65,000 incidents over 10 years 6,500 a year that's 500 a month just one company that's just one company company how many companies do you have I I represent 62
▶ 1:12:28investor owned electric companies 62 that's right so could I assume 62 times 500 sure per day sure or is that a month well that a month that's also that's one of our larger companies and that was 500 a month so it might be easy to get to several thousand a month okay okay several thousand a month okay does anybody know how these this data is no nobody knows how it's analyzed so we we require you to send a bunch of stuff
▶ 1:12:58but you guys don't know how it's analyzed by wherever it is we send it to I'll bet you it's not because the over overwhelming volume right and so we need to look at that Mr Chairman okay if you if you require me to do something and then we don't use the data for then it's actually worse all right cuz you're making them do stuff that nobody looks at so we need to bring some other folks and say how do you analyze all the data that you're getting from that you
▶ 1:13:28require from everybody else to see they're actually we're doing any Mr Aronson you talked about we we asked about offensive capability you don't have offensive capability you don't want to use offensive you don't want to use offensive capability so that's a pretty thorny topic I'll I'll go no I just want to ask what would you like to use offensive capability private sector would not like to electric companies would not like to get want to get punched over and over again just get punched once and well this is where government
▶ 1:13:58comes in so there are two ways you deter right deterring the attack does not have the intended consequence that's on the private sector to protect its systems in a way that we can withstand a lot of the other way you deter is an attack has a consequence and we would believe it that is fully the purview of our intelligence and national security but we don't have the resources to do that all I mean all the time but so we what if we what if we charge the the or allow the private sector with their all all their
▶ 1:14:29resources etc to allow to counter punch you wouldn't want that so depends how you define counter punch I do not I don't want to speak for the banks but this notion of inking the money bag that could be construed as my my time is up and hopefully we have another round cuz I really want to get into that one okay thank you and you'll gentlemen yields back we will have another another another round I now recognize myself for five minutes of thank you all for for being here today
▶ 1:14:59back again I guess in my submitted comment to former CISA director Easterly on the CISA notice of proposed rulemaking I highlighted that Congress did not intend for CISA to subject numerous entities to its reporting requirements rather Congress intended for CISA to facilitate rapid information sharing and I that's not being achieved so we're we're we're all here talking about it and what should happen with the future Hogsett you said BPI is once a you sent
▶ 1:15:29a letter saying with withdraw and reissue the rule Mr Aronson Mr Maybury you both said ex parte could could be a way to do it Schwartz I'm sorry I had to leave in the middle of your testimony so I don't know what position you took what what was I'm with the ex parte ex parte so do you believe I mean Ms Hogsett do you believe an ex parte could work I understand we have a timing issue which is the problem under the law there's a timing issue and I'm not sure we could we could meet the timing that the law if we fully withdraw and reissue
▶ 1:16:00can ex parte fix the issues that you're we would very much support an ex parte process we asked for further engagement and never got it frankly through the process thus far we believe that that rule as proposed should not be implemented and we would rather take additional time and we are prepared to work with CISA and would like an iterative dialogue to make sure that we get this right it's too and we stand ready we want to see this be successful so we I think the the stakeholder engagement given the complexities of the issue here we do need that
▶ 1:16:30we just that rule as proposed please do not implement that Mr Chairman I think that this committee can be very helpful in urging CISA to grant our request for ex parte starting tomorrow if we can work with the agency and provide our expertise and information about how we operationalized incident reporting that can be integrated into their rules
▶ 1:17:01in the fall but if we don't have that possibility to engage with them which they clearly rejected time and time again we've made the request I think this is going to go down a path that's going to be very problematic for CISA and extraordinarily burdensome and costly for our sector as you said in your testimony this will be more harm than good here yes listen I agree with all of you that this should this rule should not be implemented as as currently presented and if it was we would I would lead the effort to CRA
▶ 1:17:31it but it's it's good to hear that you all believe I think an ex parte could work cuz I want this to work I know the ranking member and the and and the chair former chair Clark all want they want this rule to work this is a big focus of mine a big focus of now Chairman Green this is I'm happy he was here today harmonization making sure in incident and information sharing happens and happens in the correct way so I want this rule
▶ 1:18:01to work and I will be following this hearing I'll work with committee staff on both sides to make sure that we reach out to CISA I know they just nominated a new potential director this morning I'm excited to see not you but Mr Plankey I think we'll could do a very good job I've met with director Easterly had very nice things to say about him so I think I think they're they may be willing to to relook at this and and move into an ex parte one of
▶ 1:18:31you mentioned something and I want to go with this cuz we talk about harmonization and how agencies don't listen to you all and one of you brought up the SEC rule maybe all of you brought it up the SEC rule which I've been fighting and we passed the CRA out of committee but because the Senate moves so slow our time clock ran out over there and I know the ranking member was also against it one of you brought up the the national security concerns ONCD I think has national security concerns with that rule in your testimony can what can you speak to those please
▶ 1:19:02I think might have been all of you that talked about may have been may have been me who brought that up so it's a perfect example of rules that don't add to security and in fact create vulnerabilities as I mentioned bad guys the cyber criminals enterprises can manipulate the process of disclosure in ways that certainly were not intended and will not be helpful.
▶ 1:19:24So, from a national security perspective, that particular rule, I'm not sure it does anything to enhance our national I would actually say it probably harms our national security. Um, I think this is the challenge that we've kind of talked a bit about now here is you have independent agencies that are doing something within their narrow lane. And so for the SEC, they think that investors need to know this information. I think we would argue that investors aren't really utilizing this information. It's not helpful to them. It's actually putting them at greater risk.
▶ 1:19:54But because an agency continues to look without somebody at the top sitting across and exercising oversight to say, does this really make sense? Is it in the best interest of the nation? We wind up with a lot of these duplicative, overlapping, deeply harmful rules. So, to the extent that Congress and this committee is ready to engage and help lead this effort, we do need an overall view to look at what is helpful versus what is harmful. And the SEC rule is classic of what is harmful at this point. And I I appreciate that.
▶ 1:20:21And when I had Chairman Gensler in front of Financial Services, I asked him which was more important, investor knowledge or national if if investor information was more important than national security. He said, "No." So, I think now it's time for the new SEC look at this rule and and correct it cuz I I've been told by people at CISA and and industry that they've had to stop sharing information timely information in order
▶ 1:20:51with the SEC rule. And that is not good for anybody. Um, I believe everybody who's been here for the first round is done. So, we're going to start a second round of questions and I recognize the ranking member from California, Mr. Swalwell, for his second round. Great. Appreciate that, Chairman. Last week, the Secretary of Homeland Security disbanded more advisory committees at the department, including CIPAC, the Critical Infrastructure Partnership Advisory Committee.
▶ 1:21:18For over 15 years, CIPAC has played a significant role in the implementation of the National Infrastructure Protection Plan and has facilitated coordination of critical infrastructure protection and resilience activities across all levels of government and in partnership with the private sector. How will the termination of CIPAC affect the coordination of critical infrastructure protection activities? And I'll just go across the witness table, Mr. Aaronson. Thank you, Ranking Member Swalwell.
▶ 1:21:45Um, so the answer is it will depend on what it ultimately is replaced with. I I understand every new administration gets privilege of um populating advisory committees. CIPAC is not an advisory committee. It is an authority that the Secretary of Department of Homeland Security has to facilitate public-private partnership.
▶ 1:22:10And to all the discussion we had about offensive versus defensive capabilities and resilience and the fact that industry and government, again, 90% as I mentioned in my opening comments, 90% give or take of critical infrastructures owned by the private sector.
▶ 1:22:24This is a team sport and CIPAC is the rulebook for how that how those teams, industry and government, can work collaboratively with protections, with the ability to have ongoing dialogues with sector coordinating councils that facilitate information sharing to prepare for and respond to all of these hazards. And I will say the electricity subsector coordinating council has been a CEO-led since after Superstorm Sandy in 2012. This isn't just about cyber.
▶ 1:22:54This is about storms and physical threats and all of the things that can impact critical infrastructure, which impact our ability to provide services to customers and communities across the United States and be prepared for all of these risks. CIPAC or something like it is vital to our ability to to to use that partnership effectively. Does anyone have an answer different than that that they want to add? Just for the sake of a I I just want to I I'll just add that that that CIPAC's different. I I strongly agree with Chairman Green's comments.
▶ 1:23:24There are too many advisory committees and DHS had too many advisory committees. Getting rid of some of them made sense. As as Mr. Aaronson said, this is not an advisory committee, right? It has the word advisory council on it, but it's not an advisory committee. The sectors organized themselves, right? And have their own bodies that then meet with the government. And that and that comes with the protections that that can happen in a in a way that provides for open discussions. And we get more information from the government because it exists.
▶ 1:23:55And and it is a good two-way conversation. It's been successful. All the nice things you've said about JCDC earlier, I agree with those. This is the policy equivalent of that and it goes back even further and it's in some ways we could talk about more success stories from it. Sure. That's all that I'll add. Let me ask Mr. Aaronson, I want to go back to something that Mr. Jimenez brought up because I've thought about for many years and I have a congressional district that has a lot of tech and biotech companies, large and small, headquartered there.
▶ 1:24:24And they get hit all the time. I have Cowbell Cyber headquartered there. They do cyber insurance. And it's long frustrated me knowing the limited re- resources that we have at Cyber Command and at the Bureau and at the NSA and CIA. And I get the hesitancy for a business, even a large energy company, to go on offense.
▶ 1:24:49I'm imagining the concern is that if you do that, you're still going up against a large nation-state that could take you out. and and then you're looking at, you know, forced retirements at some of these agencies that are happening right now. And so the resources are going to get even thinner.
▶ 1:25:05Is there a environment where you we could credential third-party cybersecurity contractors who could be offensive and and that could be utilized by small and medium-size businesses, again, credentialed by the government, bonded and insured, but also with liability protections that they would probably need to operate. It just seems, as Mr.
▶ 1:25:34Jimenez said, you're just getting punched in the face right now and the best you can do is put up your hands and like protect yourself, but you're not really able to punch back. And I don't know what the deterrent is on the other side if the US government isn't able to punch back against all those entities. If the chairman would indulge me for two seconds. Absolutely. this is something I'd want to take back to the sector. I think there's two concerns.
▶ 1:25:59You've highlighted one of them, which is um if you are punching back, now you are in effectively a fight with a potentially very well-resourced nation-state. And as we talked about, we're many electric companies are resource-constrained even on defense. in EEI's member companies, investor electric companies have to be a little bit better resourced, but there's cooperatives and municipals across the sector as well. Um, it could be that that that's daunting.
▶ 1:26:28Uh, so that's one set of concerns. The other is not quite in response to what you said, an escalating cyber war perpetrated by the private sector might have some unintended consequences. And so, it goes back to this being a team sport and the value of CIPAC and the value of CISA 2015 and the value of industry-government partnership.
▶ 1:26:54Industry can be both defensive and resilient so that the attack may happen, but we'll still be operational. Uh, we would really rely, much like we would in any, you know, a land war, on our government for it to to be responsible for national security. And I understand that concern. I guess the way I look at it though is it's not as if the resources that we have in the federal government are decreasing cyber attacks. It's actually going in the opposite direction. More and more people are getting hit.
▶ 1:27:23And I'll I'll yield back and I imagine Mr. Jimenez may go back to this. Yield means back. I now recognize Mr. Jimenez from Florida for a second round. Thank you and and thank you for the tag team. Here we go. Okay. Um, look, the only way that you're going to stop this is if if the offensive um fears more the retaliation than what we do is just put up our hands and gee,
▶ 1:27:53I hope they don't you don't hurt me too bad. If you do that, just like nations, nations go to war when they find somebody weaker, they're going to go to war and take it over. And they find you just sitting there, okay, please don't hit me, they're going to hit you. Because there's no there's no repercussion for it. There's no consequences for their action. So, everything we've done, have cyber been reduced? Are they going down or they going up?
▶ 1:28:23They're going up. So, whatever we're doing isn't working. Why? Because there's no consequences to their action. And so, eventually we're going to have to go on offense and it's going to have to hurt them as bad as much as it hurts you or actually make it maybe hurt them worse than what they hurt you.
▶ 1:28:42And yeah, you know, we we in the federal government, we are not sourcing or or or putting up the necessary folks that it needs in order to protect you because it's such a big domain. I think that the private sector with its resources, both in terms of people and money, uh, is going to have to be the way to go. Um, how much is how much is cyber attack? How much how much is that costing you?
▶ 1:29:11How much is it costing you to to protect against it or the damage is caused by cyber attacks. We're in the hundreds of millions of dollars of investment in cybersecurity technology and defensive capabilities. I will say that on the issue of what comes under the umbrella of active defense, there's a range of options. The most extreme one is letting private sector engage in uh hack backs.
▶ 1:29:39I think the the issue is government is doing something. They are They are empowered US Cyber Command to engage in offensive uh capabilities. Um we would support them in any effort that where we have certain assurances and there are guardrails. What we we What what we don't want to do is deputize a frontline practitioner to respond in haste to an attack where we may not have the right attribution where there could be substantial repercussions.
▶ 1:30:08So, this is an area that requires real close collaboration with Congress, with the intelligence community, with US Cyber Command. I mean, we have to do that. I know The only way that you're ever going to assured, okay, that you're not it's not going to have dire consequences is you have to have mutually assured Okay? The government can do that. Well, I'm not sure they can, okay? And so, and so, you know, that's that's what worked.
▶ 1:30:37That was, you know, the the the MAD theory actually kind of worked because if you know that I can take you If you do something to me, I can destroy you, too. Probably I'm not going to pull that trigger, all right? The If the other side feels that they can continually just hammer you and keep you in business cuz they want you in business cuz eventually they want they they want to have the the revenue and all that. But eventually, when a when a nation-state says, "Okay, we're going to do the knockout blow and we don't have a knockout blow in response," they're going to knock you out.
▶ 1:31:07All right? And so, I don't know the best way. Maybe Maybe it is that we do something where we we have this cyber force. You know, we have a space force now.
▶ 1:31:21Now we have cyber force that has offensive capabilities somehow funded through industry or we we have a third-party, you know, entities funded by industry that is deputized or given a warrant whenever, you know, there is a retaliatory strike is is authorized. Um cuz frankly, I I just I just see this spiraling completely out of control. So, anybody have any comments on that? I'll comment.
▶ 1:31:49I I think what you're getting at is the need to use all the tools we have in the toolbox, whether that's offensive, defensive, diplomacy. Yeah. Um one of the things Robert actually noted is the need for greater operational collaboration between industry and government. Our firms will see things on their networks, but they don't necessarily have attribution that it is a specific national security threat actor. They would welcome a greater ability to work and share that with the appropriate authorities in government to get feedback on that.
▶ 1:32:19Oftentimes, we think that there are things we see, there are things that government sees that if we both knew what was happening, we could better direct some of our activities. I think that would be to us the next step to really try to drive at combating this where it's happening. Mr. Chairman, my last comment, I know I'm a little bit over time, is that is that it this is it's going to be a everybody, you know, on board uh effort.
▶ 1:32:45Uh the government and the private sector, just like we fought the last World War, all right? Everybody got on board and we're fighting and going in the same direction. I think that this is where it's heading anyway. I I yield Gentleman yields back. I now recognize the gentlelady from New Jersey, Ms. McIver, for 5 minutes of questions. Thank you, uh Mr. Chairman, and thank you, Ranking Member, and to the witnesses for joining us today um on a nice day. Thank you for being here.
▶ 1:33:11Um a strong and time timely cyber incident reporting framework is critical to our national security, which I'm sure you've heard multiple multiple times and it's been mentioned multiple times in today's committee hearing. CISA must move quickly to establish a process that engages the private sector, aligns with existing regulations, and meets congressional intent, all without delay. But we cannot achieve this without a robust federal workforce.
▶ 1:33:38With staff and resources being cut each and every minute, it's crucial we support the personnel needed to get this done. In order to properly implement CIRCIA, make sure I cuz the CIRCIA and CISA kind of gets me tied up, we'll need to have the staff and resources to process and analyze incident reports.
▶ 1:34:00I am concerned that any cuts to CISA's funding or staffing could leave it without the capacity to properly implement this crucial new program. To each witness, how important is it that CISA be adequately staffed and resourced to implement CIRCIA? What kind of funding and staffing is most important to properly implement? I can go first, sir.
▶ 1:34:28Um I would say we've it's taken a long time to get up to this point where we have adequate staffing at uh at CISA and uh we're concerned about cuts to to CISA and what the impact will be, especially as they get more information like this. And as they There is an an effort to tie all the information together they're getting from inside the government, from contractors, and this information together. Being able to analyze that is going to be a a big tall and it's going to take a lot of It's going to use a lot of AI, but it's also going to use a lot of human resources as well.
▶ 1:34:59Thank you. Uh I would say it's beyond my purview in terms of telling the federal government how to organize themselves right now. Um but we will continue to engage them and I think, for example, the partnership if the rules are written in a way that is consistent with the intent of Congress, we could significantly reduce the amount of noise that would be generated in this information sharing Um and I think there would be opportunities for efficiency associated with getting getting back to that
▶ 1:35:30um original intent. The other thing I'm just going to use this as an opportunity to share with you that we talk about incident reporting, but it's connected to incident response, and it's it's connected to how we engage on this in this process. One of the things I think we need and help with from you and potentially with ONC D is to have a single point of contact during a major crisis. Because right now, uh the experience has been we're getting inundated with multiple agency requests during the crisis.
▶ 1:36:00We're even getting multiple requests within a department. And then we're getting multiple requests to different pieces parts of our our our operators, our network service providers. And that has to stop. We have to really rationalize that and ask ourselves some serious questions here about how to organize this effort, how to engage in the appropriate information sharing. And the last thing I'll say is when it comes to CIRCIA, there was an assumption that there would be reciprocity. And we still have that assumption.
▶ 1:36:28So, the benefit of submitting information is for the government in real time or as quickly as possible to come back to us with mitigation guidance, new information on how to protect our networks. Um there's a lot of work to do here. Um and I'm hearing that there's a lot of alignment in this subcommittee around how to reduce the inefficiencies associated with all of this.
▶ 1:36:50So, we look forward to working with you, and hopefully we'll be working with CISA shortly on how to remedy some of the infirmities and associated reporting. Thank you so much for that, Mr. Mayor. I would assume that getting one point of contact would not be that difficult. Thank you. You think. We certainly want CISA and CIRCIA to be successful, and we are committed to that.
▶ 1:37:14Uh for CIRCIA to work, CISA will need certain capabilities, and that's not only technological, but also there is a human element to that. So, we look forward to engaging with the new leadership once it is once they are appointed and confirmed. Thank you for The only thing I'd add, so people, processes, technology are going to be critical to the success the success of uh CIRCIA being implemented effectively. Uh and let's not forget about the security of this really critical information as incident reports are shared.
▶ 1:37:43That can be a roadmap to a potential threat actor, and so we need to make sure that we're not just collecting this information, but protecting it as well. Thank you so much to each of you for those responses. With that, I yield back, Mr. Chairman. Gentlelady yields back. I now recognize myself for a second round of questions. Chairman Menendez brought up before the attacks are going up, and you agreed.
▶ 1:38:07But are successful attacks going up, or is the work that you all are doing on the sector coordinating councils and preparation and work with CISA is I I know attacks are going up, but are we seeing positive results from all the information sharing and and the work that you're doing amongst each other? There are a lot of reports out there, and they say different things.
▶ 1:38:28So, uh I tend to some reports I've seen tend to suggest that we are being that we are more successful, uh and that the bad guys are there's just a lot more attacks, so the therefore the number of incidents goes up with it. Some have shown that uh in certain areas, there are more successful attacks than there used to be. And so then we have to move more resources over to those.
▶ 1:38:49The What you propose and what you're discussing is there's a counterfactual element here in that we don't know what would happen in the absence of doing some of these these activities. But I would say there's a lot of redundancy. There are a lot of reports that are produced within the government um that in our view don't lend themselves to security improvements.
▶ 1:39:11So, we have to get better at thinking about how we use government resources, how we use industry resources, focusing on what is the expected outcome that we're looking for. And that will fix, I think, a lot of the the noise in the system. Yeah, I think there are mixed signals. I think it's hard not to overlook the fact that we are increasingly being attacked by nation states. You have a private industry that has very strong, very powerful nation state actors infiltrating their systems.
▶ 1:39:41Even the best, most sophisticated private firm is going to struggle to deal with that. Um, so we'll say I think our capabilities have certainly improved, our information sharing has improved, we can respond faster when things occur. We within the banking sector continue to see certain challenges and weak spots with um third parties or vendors that we rely on, things that cut across multiple sectors and can be embedded in your infrastructure. Those areas can still be very challenging to deal with. I think Ms.
▶ 1:40:09Apple put it really well there, so I'll just associate with that. I'll I'll give um another example though of some really effective coordination that's happening where a nation state may be responsible for an attack, uh private sector sees it, develops mitigation strategy, socializes those, uh and then works with government to kind of load the gun uh back for uh potential offensive operations should it become necessary.
▶ 1:40:34We've heard about all the different typhoons that are at the Volt Typhoon was something uh that was impactful to could have been impactful to the electric power sector, but because of industry being on the defensive and working with uh and across uh the uh Energy Threat Analysis Center and a lot of our partners in government, we're able to identify that, uh develop remediation strategies, and socialize those for the benefit of all uh electric power sector uh part participants. Thank you very much.
▶ 1:41:01I just want to say for the record I am supportive of extending cyber information sharing act of 2015. Uh however we get that done, whether we include CISA actually in the the legislation of the text, who's the priority lead, I'm just want to make sure we get it in the front of the right committee in the Senate so it doesn't get bogged up like CFATS did. Um, I also want to say that you all you lifted some grave concerns today with uh CPAC um being disbanded. I mean, I've met with Ms.
▶ 1:41:31Mayor, we've met on and you've testified twice. You're the sector the head of the sector coordinating council. I've met with Ron Green, who's financial services and and Pedro Bizarro. They they've already reached out, Edison International has already reached out to have a meeting. Um, so I'm going to look into this and and hopefully speak to the administration and and uh uh try to fix this cuz this is something we don't want industry not sharing information with us.
▶ 1:41:56We don't want industry not sharing information with each other cuz when that happens, uh it just increases the vulnerabilities that are out there. and this is where I want to get to there there is a lot of as Mary you said it, there is a lot of dupli- duplicative paperwork and and and rules out there. You know, the idea under behind CIRCIA was to get some harmonization on incident reporting, but that's not all we we deal with. CISA doesn't really have the teeth though to force other agencies to do it.
▶ 1:42:26who do who does? I mean, where who do we have run the harmonization effort? I think you said ONCD before, but who's got the actual juice to make these agencies fall in line? That's a great question. I'm going to You can all go. quickly. So, um this is the problem. We have multiple agencies committed to a mission. Cybersecurity has become an interesting area for their involvement. Um, a lot of it is duplicative.
▶ 1:42:53We think that the um Office of National Cyber Director, consistent with its statutory responsibility to coordinate some of these responsibilities, can play a significant role going forward in rationalizing this effort. In the absence of that, we're going to be still dealing with all of these silos, uh multiple reporting requirements, and just going to be duplicative and not effec- effective.
▶ 1:43:18Yeah, at this point I think we need White House level leadership because that's really the top-down to really affect change here. Um, we are seeing some signs that it looks like the Office of Management and Budget may get more involved in this. So, I think between OMB, Office of the National Cyber Director, which did do quite a bit of work on this to sort of socialize the problem, the Cyber Incident Reporting Council that you all authorized in CIRCIA has put a lot of information out there. We just need someone sitting at the top to say, "You guys need to rethink this." And I and congressional oversight is incredibly valuable.
▶ 1:43:48I don't know what the number is these days, but at one point it was like 37 different committees and subcommittees had responsibility for cyber in some way. I think that work that you guys are doing to coordinate the cyber subcommittees across uh Congress and then work with uh agencies of jurisdiction to also harmonize, there's there's value there, I agree on the OMB and ONCD approach. I think that's the way to go. And Chairman Green's done a great job working with the again the the committees of jurisdiction together. but yeah, I agree with you all, we need someone to be able to tell these guys to fall in line.
▶ 1:44:18Uh we didn't really see that we haven't seen that since I've been here. Uh we need to keep up our oversight. Um, but uh you know, I'll promise we're going to work on ex parte for the CIRCIA rule, hopefully get that fixed. Uh and we will continue working on harmonization. I know the committee is working on a report uh that we can hopefully get to the administration and they can start acting on making your making your lives more focused on cybersecurity and not not not finishing a a report.
▶ 1:44:45Um, so with that I want to thank the witness witnesses for their valuable testimony and for the members for their questions. Uh the members of the committee may have some additional questions for the witnesses and we would ask the witnesses to respond to these in writing. Pursuant to committee rule 7E, the hearing record will be remain open for 10 days. Without objection, the committee stands