▶ 0:08:42Committee on Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection will come to order. That objection, the chair may declare the committee in recess at any Purpose of this hearing is to examine the Cybersecurity Information Sharing Act of 2015 or CISA 2015. Which is up for reauthorization this We will We will evaluate the voluntary cybersecurity information sharing framework established by this legislation, assessing how it has influenced the way private entities share information today.
▶ 0:09:09This hearing will highlight the need to continue cybersecurity information given an increasingly complex threat environment and will consider improvements to the legislation. And I recognize myself for an opening Information sharing is a critical component of our nation's defense against global cyber threats.
▶ 0:09:28From utility companies in rural areas to major banks on Wall Street, the private sector is on the front lines of the digital battlefield, freq- frequently defending itself from malicious cyber Securing the United States in cyberspace requires a whole-of-society approach, strong partnerships, and close coordination between industry and government at all levels. Our national resilience against cyber threats is reinforced by sharing threat information and best practices amongst all stakeholders.
▶ 0:09:56You know, 10 years ago, Congress passed the Cybersecurity Information Sharing Act of 2015, establishing a framework for the voluntary exchange of cybersecurity information between private entities and the federal By providing liability and privacy protections for information shared in accordance with the statute, CISA 2015 removed long-standing barriers to public-private collaboration in Over the past decade, the threat landscape has evolved significantly.
▶ 0:10:22With sophisticated nation-state and criminal actors increasingly exploiting cyberspace to target infrastructure and As these threats continue to rise, CISA 2015 has become more vital than ever. The law has fostered and a foundation of trust among cybersecurity stakeholders, making information sharing the default rather than an exception. A significant significant volume of critical cyber threat intelligence has been exchanged between industry and government under this law.
▶ 0:10:50For instance, just this year a major organization shared 84 formal reports, reaching thousands of partner This doesn't include the numerous informal daily exchanges that are also protected by the law. This September, CISA 2015 is set to expire unless Congress reauthorizes it. As we've heard from many stakeholders, the liability and privacy protections provided by the law have facilitated better information sharing, helped secure networks, and improved our overall cybersecurity posture.
▶ 0:11:20The Cybersecurity and Infrastructure Security Agency, which the subcommittee oversees, has played a crucial role in fostering these information sharing partnerships, a mission I look forward to continuing with the new There are valid concerns that without these protections, the private sector would be less willing to share cybersecurity information either amongst themselves or with the federal Without these safeguards, we can be certain that our nation would be more vulnerable to cyber threats.
▶ 0:11:46I strongly support reauthorizing CISA 2015 and made it a top priority this I'm encouraged that just yesterday Secretary Noem voiced similar support before the full committee. This hearing is a crucial step forward in the reauthorization process and I look forward to incorporating feedback into a reauthorization bill. I'd like to thank our expert panel for being here. Your insights on how this law has been implemented across industry are invaluable. Some of you tracked or worked directly on this law since its inception.
▶ 0:12:14I look forward to exploring ways to maintain and potentially improve voluntary cybersecurity information sharing between the public and private I now recognize the ranking member, the gentleman from California, Mr. Swalwell for his opening statement. Thank you, Chairman.
▶ 0:12:28And I was a member of the Intelligence Committee back in 2015 when the CISA 15 was enacted and it was apparent to me even in the midst of, you know, very intense, vigorous debate that we needed greater public-private cybersecurity collaboration.
▶ 0:12:49So, I want to first just thank the witnesses for coming today and sharing, you know, their perspective, their members' positions, their industries' concerns uh because we want to get this right. And we want to build on the success that we have. So, we're hearing about new cybersecurity attacks every day, yet the federal government at the time had very little visibility into what was happening on private networks. And the private sector was receiving very little information from the federal government on cyber threats.
▶ 0:13:19I would say that is probably still happening today and the biggest complaint I hear from you all, especially on JCDC, is it's a one-way relationship and I know we want to do more uh to increase what is shared with you in the private sector. But I laid out in the 2015 debate that there was a time at the time almost no cyber sharing between the public sector and the private sector. And CISA 2015 sought to change that, and it has changed that.
▶ 0:13:47It's provided the legal framework to facilitate cyber information sharing between the federal government and the private sector. It gives companies the confidence that they'll be legally protected if they voluntarily share cyber threat information with the Department of Homeland Security or with their competitors. It's rare that these days we see such a wide consensus on any topic, but on the issue of reauthorizing CISA 2015, I've received a very clear message from everyone I've talked to. Do not let it lapse.
▶ 0:14:18Stakeholders have consistently stated that CISA 2015 has drastically improved public-private collaboration, helping our cyber defenders better do their job. Of particular importance to me was that in 2015 that we addressed privacy and civil liberty protections and demonstrated that their effectiveness was in ensuring information shared with the government is protected and always used properly.
▶ 0:14:41As CISA CISA 2015 was developed, I advocated for strong privacy protections, and I'm glad to see those statutory requirements have achieved their outcomes. We must move quickly to reauthorize CISA 2015 before it expires in September. Maybe we could change the name so it's not so confusing with the other CISA that we're working on. That is one change I think we would all welcome. Yeah, a good name change.
▶ 0:15:06While it's reasonable to discuss if there are ways to strengthen the law going forward, we cannot allow such with such an imminent timeline to delay reauthorization. It's also important to remember there are steps that Congress and the administration can take in the interim after reauthorization.
▶ 0:15:23While establishing the legal regime to facilitate cyber information sharing, the maturation of Cybersecurity and Infrastructure Security Agency, the original CISA, has provided a central hub for public-private cyber collaboration across critical infrastructure sectors. If CISA lacks the people and forms necessary to receive, analyze, and share cyber threat information, CISA 2015's provisions will be rendered meaningless.
▶ 0:15:50One important step for Congress that I have been working with in this committee is to codify the Joint Cyber Defense Collaborative and better define its mission and structure. And I hope we get a vote on that again this Congress. And the administration should restore the Critical Infrastructure Partnership Advocacy Council, also known as CIPAC, or establish a similar new entity that provides a mechanism for critical infrastructure collaboration.
▶ 0:16:14Finally, we must continue to support CISA's efforts to improve automated indicator sharing and implement its threat intelligence enterprise services Again, I thank the witnesses for participating in this.
▶ 0:16:27I expect I will hear across the board uh the value of CISA, that there are reforms that we can put in place, uh but if it's deciding not authorizing and trying to find better reforms and risking this lapsing or reauthorizing something clean and then fighting and working together collaboratively ultimately to get reforms in the future, I think that you would choose the latter. With that, I yield back my time. Gentleman yields back.
▶ 0:16:54Other members of the committee are reminded that opening statements may be submitted for the I am pleased to have a distinguished panel of witnesses before us today. I ask that our witnesses please rise and raise their right hand. Do you solemnly swear that the testimony you will give before the Committee on Homeland Security of the United States House of Representatives will be the truth, the whole truth, and nothing but the truth, so help you God? Let the record reflect that the witnesses have answered in the affirmative.
▶ 0:17:22Thank you, and please be I would now like to formally introduce our witnesses. John Miller currently serves as a senior vice president policy for trust data and technology and general counsel for the Information Technology Industry Council. Mr. Miller is responsible for driving ITI's global strategy and advocacy on cybersecurity, technology, and digital policy issues, while also serving as the organization's chief legal officer.
▶ 0:17:47In addition to his work at ITI, his experience includes serving as co-chair of CISA's ICT supply chain management task force, three terms as chair of the IT Sector Coordinating Council, and co-founder of the Council to Secure Digital Economy. Ms. Diane Rinaldo previously served on the House Permanent Select Committee on the on Intelligence, where she had first-hand experience working on CISA Ms.
▶ 0:18:09Rinaldo also held senior-level roles in the executive branch serving as acting administrator of the National Telecommunications and Information Administration, and as acting assistant secretary of commerce for communications and information. She currently serves as the executive director of Open RAN Policy Coalition. Mr.
▶ 0:18:26Karl Schimmeck is currently serves as executive vice president and chief information security officer of Northern He's also here on behalf of the Securities Industry and Financial Markets Association, or SIFMA, where he previously served as the managing director of cybersecurity, business resiliency, and operational risk. At Northern Trust, he is responsible for designing and managing the strategy and operations of the bank's information security, cybersecurity, and data protection programs.
▶ 0:18:50Additionally, he serves on the board of directors of both Financial Services Information Sharing and Analysis Center and the Cyber Risk Institute. Ms. Kate Keen serves on the board of directors and is CISO in residence at the National Technology Security Coalition, where she brings experience leading and advising cybersecurity, technology, innovative AI strategies, and teams to help shape the industry with better business security and risk decisions. In addition to her work at the NTSC, Ms.
▶ 0:19:20Keen serves on the board of directors for Hiyas and Cybernetics. All right, I thank the witnesses for being here today. I now recognize Mr. Miller for 5 minutes to summarize his opening Chairman Garbarino, Ranking Member Swalwell, and distinguished members of the subcommittee, on behalf of the Information Technology Industry Council, or ITI, thank you for the opportunity to testify today on the critical need for Congress to reauthorize the Cybersecurity Information
▶ 0:19:50Sharing Act of 2015, or CISA 15, before it is set to expire in just 4 months. ITI is a global trade association representing 80 of the world's leading tech companies, and I lead ITI's Trust Data and Technology Policy team, including our work on cybersecurity, AI, and privacy in the US and globally.
▶ 0:20:08I've worked on cyber policy issues for nearly two decades, and I have extensive experience partnering with DHS, CISA, and other federal government stakeholders to improve cyber and critical infrastructure security, including currently serving in the leadership of the IT Sector Coordinating Council and ICT Supply Chain Risk Management Task Force. I've had the honor of testifying before this subcommittee previously on the related topic of security incident notification.
▶ 0:20:32So, I know you appreciate that sharing cyber threat information is vital to improving the nation's cyber resilience and security by increasing situational awareness across government and industry and driving more effective operational collaboration to prevent and respond to cyber threats. The same principles underlying CIRCIA motivated Congress to pass CISA 15, and that law is as fundamental to our collective cybersecurity today as it was back in 2015.
▶ 0:20:58I want to underscore that any lapse in CISA 15 authorities would be an unfortunate step backwards, an unforced error that only stands to benefit cybercriminals, including sophisticated nation-state threat actors such as China, Iran, and Russia. The axiom that cybersecurity is a team sport is no more self-evident than in the context of information sharing, which dictates that those experiencing or observing an incident, vulnerability, or other indicators that a network or device has been compromised should share that information.
▶ 0:21:27Sharing these indicators of compromise and other threat intelligence helps defenders team up to prevent potential targets from becoming future victims. The goal of CISA 15, and a central thrust of US cyber policy over the years, has been to foster cyber threat info sharing to increase real-time situational awareness of the threat landscape to improve threat prevention, response, and mitigation efforts.
▶ 0:21:48CISA 15 sought to accomplish this goal by incentivizing and make it easier making it easier for companies to share threat intelligence both with the government and with each other without fear of lawsuits or liability, including as related to antitrust, information disclosure, or regulatory uses. Provided the information shared adhered to privacy and civil liberties guardrails. It also required DHS to establish an automated process for sharing such information at scale. After nearly 5 years of debate and negotiation, the CISA 15 statute realized these goals.
▶ 0:22:19It included precisely scoped definitions of the information the bill authorized organizations to share and carefully negotiated and calibrated liability and privacy protections that balanced the competing and sometimes conflicting concerns of stakeholders, ranging from the intelligence community privacy advocates.
▶ 0:22:36As a cyber policy expert and lawyer working on this issue at the time, I worked along with fellow witnesses on this panel and many others to help Congress strike a winning While it was a messy and sometimes contentious process, Congress ultimately reached an effective compromise, and we are better off today from a cybersecurity standpoint than we were 10 years ago.
▶ 0:22:55The reality today is that organizations are benefiting more from cyber threat info sharing than they were before CISA 15 became law, and they are sharing and receiving via automated processes, not via spreadsheets. This is not to say that CISA 15 was perfectly designed or has been perfectly implemented, or that it cannot be improved. But, with a looming September deadline for CISA 15 reauthorization, we cannot allow the perfect to be the enemy of the good.
▶ 0:23:21Please do not jeopardize the cybersecurity improvements and partnerships that CISA 15 has catalyzed and that many now likely take for granted by letting the law lapse if that is the price of making changes. That said, the tech sector stands ready to work with Congress to update and improve upon the cyber threat info sharing ecosystem in the US at any time. Three targeted improvements worth considering include one, both the threat landscape and technology have changed over the past decade.
▶ 0:23:48From ransomware and operational technology to the explosion of generative AI, technologies and threats continue to evolve well beyond 2015, and hackers continue to adapt. One simple rubric Congress could use in considering changes to CISA 15 is to evaluate whether the statute as written effectively captures the sharing of information necessary to combat cyber threats in 2025.
▶ 0:24:10Two, given the rise of software supply chain attacks, I encourage Congress to examine whether definitions of terms such as cyber threat indicator can be updated to promote the sharing of information information useful in preventing or mitigating threats to the ICT supply chain, such as information related to suspect suppliers.
▶ 0:24:28Three, Congress could consider including adjacent authorities, which also support public-private information sharing and partnership, such as the currently suspended critical infrastructure partnership advisory council, or CIPAC, in a future iteration of CISA 15. While the administration has indicated it plans to reinstate CIPAC authorities in some form, Congress could provide certainty by firmly codifying functionality functionally equivalent authorities in statute. Thank you for the opportunity to testify today. I look forward to your questions. Thank you, Mr. Miller.
▶ 0:24:58I now recognize Ms. Rinaldo for 5 minutes to summarize her opening statement. How's this? Ah, there we go. My name is Diane Rinaldo, and by way of background, I worked on the Cybersecurity Information Sharing Act from its inception to passage into law as a staff member on the House Permanent Select Committee on Intelligence. I am grateful to speak to the urgent need for its reauthorization.
▶ 0:25:29This act remains a critical legislative framework that has enabled meaningful cooperation between the public and private sectors. Yet, the threat environment has grown dramatically more complex, and our approach must evolve accordingly. Now, when the original legislation was drafted in 2012, growing concerns about the frequency and sophistication of cyber attacks were already taking shape.
▶ 0:25:50In hindsight, those early warnings significantly underestimated the scale and complexity of today's threat Over the past decade, threat actors have become more capable and emboldened, outpacing both legislative safeguards and defensive technologies.
▶ 0:26:06High-profile attacks such as Salt Typhoon and incursions on the US government have made it abundantly clear no sector, private or public, are At the heart of the legislation, and what remains just as urgent today, is China's unrelenting assault on the US economy through cyber-enabled espionage. Chinese cyber hacking stands out as one of the most strategically dangerous and persistent threats to national security.
▶ 0:26:30For over a decade, state-sponsored actors have conducted a sweeping and coordinated cyber espionage campaign targeting US companies, research institutions, and government agencies. These operations have resulted in the theft of massive troves of intellectual property and trade secrets. This is not random or opportunistic.
▶ 0:26:50It's a deliberate strategy to fuel China's economic and military ambitions with cyber capability serving as a core instrument of statecraft and industrial In this evolving threat environment, the need for a real-time bidirectional information sharing between government and industry has never been more critical. The Cyber Information Act laid the foundation for improved collaboration between government agencies and private sector by creating a legal framework for voluntary information sharing.
▶ 0:27:20It offered liability protections to encourage private sector companies to share threat indicators and defensive measures with federal government and Our thought was simple, see something, say something. That framework helped normalize and de-stigmatize cyber threat information sharing across across industry. The Department of Homeland Security's automated indicator sharing program and the role of ISACs as a direct result and outgrowth of this legislation.
▶ 0:27:50This legislation was the product of four years of intensive effort including more than 100 meetings with stakeholders ranging from Fortune 100 companies to small and medium-sized businesses, uh advocates privacy um advocates and academic institutions. It also reflected countless consultations with government agencies and underwent three major rewrites based on the feedback that we received.
▶ 0:28:16From the outset, the committee recognized the critical need to strike the right balance between privacy and security. With so much at stake, we knew we had to get it right. However, while the law was forward-thinking at the time, the pace of technological change and the growing complexity of cyber threats have outpaced some of its provisions. Despite progress, some gaps still remain. It's limited participation, speed and relevance of information, lack of bidirectional flow, inconsistent standards, and a trust deficit.
▶ 0:28:45Reauthorizing information sharing gives Congress the opportunity to strengthen and scale its original vision. To strengthen national security, Congress should expand and clarify liability protections to encourage broader information sharing. Additionally, federal agencies such as CISA must be required, not merely allowed, to share timely, relevant, and declassified intelligence with the private sector. Trust and engagement improve significantly when companies see tangible reciprocity.
▶ 0:29:14Cybersecurity is no longer a technical issue. It's a national security imperative that requires whole-of-nation coordination. No single company, agency, or state can defend against these threats alone. The adversaries we face, whether criminal networks or foreign governments, exploit our silos. We must instead leverage our strength, the diversity of talent, innovation, and democratic collaboration. In closing, I urge the committee to quickly reauthorize this critical function.
▶ 0:29:43Let us affirm the importance of information sharing, strengthen the incentives and protections for participants, and build the trusted, interoperable, and actionable threat ecosystem our future demands. Thank you, and I look forward to your questions. Thank you, Mr. Rinaldo. I now recognize Mr.
▶ 0:29:59Shimek for 5 minutes to summarize his opening Chairman Gallagher, Ranking Member Swalwell, and distinguished members of the committee, thank you for the opportunity to testify today on a matter of critical national importance, the urgent need to reauthorize the Cybersecurity Information Sharing Act of My name is Karl Shimek. I serve as the Chief Information Security Officer at Northern Trust and serve on the Board of Directors of the Financial Services Information Sharing and Analysis Center, or the FS-ISAC.
▶ 0:30:29I'm here today on behalf of the Securities Industry and Financial Markets Association, or SIFMA, where I sit on the Cybersecurity Committee. SIFMA is the leading trade association for broker-dealers, investment banks, and asset managers operating in the US. SIFMA advocates on legislation, regulation, and business policy affecting financial markets. I spent much of my career focused on cybersecurity in the financial sector, and I was directly involved in the advocacy that helped shape CISA 2015.
▶ 0:30:57That law was a bipartisan achievement, and it remains one of the most important cybersecurity tools that we have, and a cornerstone of our nation's cyber defense strategy. The threats we face today are not They are real, growing, and increasingly dangerous. Nation-state actors are conducting relentless cyber operations against our critical infrastructure, banking systems, communication networks, energy grids, and government agencies. These attacks are not just attempts to steal data.
▶ 0:31:25They are designed to disrupt, destabilize, and undermine confidence in our institutions. Put simply, cyber is now a national security domain, and the private sector is on the front lines. CISA 2015 provides the legal foundation that enables companies like mine to share threat intelligence quickly and confidently with the federal government and with one another.
▶ 0:31:46It creates the trust, structure, and legal protections required for real-time Without the protections in the act, protections against civil liability, regulatory action, and antitrust exposure, companies would hesitate. They would share less, and they would share more slowly.
▶ 0:32:04That hesitation would be a gift to our When CISA passed, there were concerns about protecting the privacy of After 10 years of activity, there have been no known reports that PII not directly related to a cybersecurity incident has been shared. The participants in this system have a responsibility to ensure that the only information submitted is directly related to a cybersecurity threat. We take We take this responsibility seriously, and the unblemished track record demonstrates that commitment.
▶ 0:32:33Let me be clear. If the act lapses, our nation will be more vulnerable to cyber attacks the very next day. Threat sharing saves time, and in cybersecurity, time is everything. It's the difference between stopping an attack at the perimeter or watching it spread across the system. It's the difference between a minor disruption and a systemic crisis. We often say that cybersecurity is a team sport, but that's only true if the rules allow us to play together. CISA 2015 makes teamwork possible.
▶ 0:33:03Recent events, including SolarWinds and CrowdStrike, clearly evidence the the value of rapid information sharing, which helped to minimize the damage of these events. That's why we are calling on this subcommittee and the full Congress to act swiftly and decisively to reauthorize the act without delay and without changes. We cannot afford a gap in our defenses, not now, not with the threat landscape evolving by the day. We are not asking for new authorities.
▶ 0:33:29We are asking to preserve what already works, a proven framework that enables trust, protects privacy, and makes us all stronger. The act is not just a legal mechanism, it's a force multiplier. It is the It has created a trusted architecture for cyber collaboration. To let it to let it expire would would to be knowingly dismantle the critical defense layer at a precise moment we need it most. In closing, I'll leave you with this.
▶ 0:33:55Cyber threats don't take breaks, and they don't wait for legislative If we hesitate, we expose ourselves. If we act, we protect the nation. Thank you for the opportunity to speak today, and I look forward to any Thank you, Mr. Shimshock. I now recognize Ms. Keane for 5 minutes to summarize her opening statement.
▶ 0:34:14Chairman Garbarino, Ranking Member Swalwell, and members of the committee, thank you for the opportunity to testify today in support of reauthorizing the Cybersecurity Information Sharing Act of 2015 and the importance of public-private partnerships in protecting our national security. My name is Katherine Keane, and I'm a board member of the National Technology Security Coalition and serve as their CISO in residence.
▶ 0:34:37Established in 2016, the NTSC is a not-for-profit, non-partisan organization that advocates for the Chief Information Security Officers, Chief Privacy Officers, and senior security technology executives. NTSC's mission is to advance cybersecurity policies that protect critical national infrastructure and foster strong collaboration between the public and private sectors to secure our digital landscape.
▶ 0:35:03As a part of this mission, we have been deeply involved in shaping the national conservation on conversation on cybersecurity, including advocacy for the creation of the Cybersecurity Advisory Committee. The Cybersecurity Information Sharing Act of 2015 has long been a cornerstone of our national cybersecurity strategy. Since its inception, this law has fostered collaboration between industry leaders and federal agencies, enabling the identification and mitigation of cyber security threats.
▶ 0:35:33One second. Uh the legal protections offered by CISA encourage private organizations to share information without fear of repercussions, enhancing the nation's ability to respond to cyber attacks. It facilitates the exchange of critical cyber information threats between private sector companies and federal government. CISA provides incentives for companies to share cybersecurity threat indicators, such as software vulnerabilities and malware, with the Department of Homeland Security, DHS.
▶ 0:36:00This collaboration is crucial for preventing data breaches and attacks from cyber criminals and foreign adversaries. This law has been pivotal in addressing some of the most significant cyber threats over the past decade, including high-profile incidents like SolarWinds breach and more recent Volt Typhoon and Salt Typhoon campaigns. These attacks underscore the growing sophistication and scale of cyber threats we face today.
▶ 0:36:24As noted by Senators Gary Peters and Mike Rounds, allowing CISA 15 to lapse would significantly weaken our cybersecurity ecosystem and undermine the ability to address these sophisticated threats. Moreover, a lapse would remove essential liability protections and hinder defensive operations across critical sectors. The protections under CISA 15 have provided legal certainty for companies that might otherwise hesitate to share critical data threats.
▶ 0:36:52This safe harbor provision has been crucial in fostering a culture of trust and collaboration. With With this legal protection, the flow of vital threat intelligence would slow, hindering both proactive and reactive cyber defense Cybersecurity is a team sport, one that requires collaboration between government and private sector. Information sharing is essential for national security as cyber threats become increasingly sophisticated.
▶ 0:37:18The current global cyber threat environment demands constant information exchange between these sectors to protect the nation's critical infrastructure. CISA 15 has been instrumental in supporting this collaboration, particularly through initiatives like the Joint Cyber Defense Collaborative, which unites federal agencies and leading private sector companies.
▶ 0:37:38Unfortunately, the recent termination of the Critical Infrastructure Partnership Advisory Council, the disbandment of the Cyber Safety Review Board, and the dismissal of members of the Cybersecurity Advisory Committee have undermined public-private cooperation in cybersecurity. These advisory bodies have played crucial roles in fostering dialogue and sharing best practices between government and industry. Their loss has created a gap and that must be addressed.
▶ 0:38:03The importance of public-private partnerships is further emphasized by the fact that critical infrastructure sectors, such as energy, finance, and health care, are predominantly managed by private companies. These industries rely on timely and accurate information to protect themselves against attacks from nation-state actors, cybercriminals. Information sharing is crucial for dependent for defending against complex state-sponsored attacks such as those originating from Russia, China, and North Korea.
▶ 0:38:33The NTSC was directly involved in creating the Cybersecurity Advisory Committee, which was introduced in 2019 through bipartisan legislation. A bill aimed at establishing an advisory committee composed of highly skilled cybersecurity professionals responsible for protecting enterprises across all primary business sectors. The advisory committee would serve as a valuable cyber resource providing unparalleled insight and expertise to the director of Cybersecurity Infrastructure Agency and Homeland Security.
▶ 0:39:03The NTSC in collaboration with these members of Congress and this committee proposed the idea for the advisory committee and played a central role in the In conclusion, the reauthorization of CISA 15 is is crucial for maintaining the nation's cybersecurity and strengthening public-private partnerships in cybersecurity. The law has fostered a collaborative environment that enables real-time sharing of cyber intelligence and defense against attacks from sophisticated adversaries.
▶ 0:39:29We urge Congress to prioritize a clean reauthorization of CISA 15 and to ensure that we continue to look at areas we can focus on joint public-private cybersecurity collaboration. I thank you for your attention to this critical issue and I look forward to addressing your questions. Thank you, Ms. Keene. Members will be recognized by order of seniority for their 5 minutes of questioning. I want to remind everyone to please keep their questioning to 5 minutes. Yeah, we sometimes we go over. It's okay. Um an additional round of questioning may be called and for all members have been recognized.
▶ 0:40:00I now recognize the gentleman from Florida, Mr. Jimenez, for 5 minutes of questioning. Thank you, Mr. Chairman. And you know, I understand the the the the importance of uh reauthorizing, you know, the that um that bill, but um what is the state of the cyber threat today compared to what it was 10 years ago? Mr. Miller.
▶ 0:40:30Uh thank you for the question, Congressman. Um you know, I think by by by any account that that the state of the cyber threat today uh is that that it is far more there are far more threats. Um we're seeing you know, we we have a a different technology environment um you know, including threats such as ransomware, which we weren't really talking about 10 years ago.
▶ 0:40:52Uh you know, threats to operational technology and artificial intelligence, which is clearly on everyone's minds and and artificial intelligence can be used both as a sword and a shield as it were. Um so, it's a it's a and and and also I I think it's fair to say that we have much more even more sophisticated a nation-state threat actors. Uh you know, the usual suspects, of course, China, Russia, North Korea, Iran.
▶ 0:41:18Um Uh you know, so I I mean I I I think when we look at it and we look at the uh the the the the cyber threat ecosystem in particular, uh there are a lot more threats but but the good news is in part in in large part because of CISA 15, we're able to share much more information at scale um to keep pace with the tech with the the various different changes in technology today than we were 10 years ago and that's why I think if you hear uh unanimity on this panel that
▶ 0:41:48we need to There are a number of uh cyber security companies, right? Um that are that are contracted by different companies, etc., right? And do you find that they share information freely or or do they try to keep their stuff proprietary and try to shield themselves from competition?
▶ 0:42:07Um well, I mean I I I don't know I don't know that I could talk about individual companies um you know, business practices, but but but I will say generally speaking that, you know, when we when we think about automated indicator sharing in particular, you know, we have Yes, there are some very large, excellent cyber threat companies who are sharing information with their customers at scale. They're plugged into the AIS That's not They're I'm not talking about their customers.
▶ 0:42:35I'm talking about sharing it, you know, throughout throughout the nation. In other words, it's not just their customers. I'm talking about sharing information with other other entities that may not be using the same company for cybersecurity. How is that? Is that Is there still a barrier there? Are there barriers there or are they freely sharing information across different companies and different platforms?
▶ 0:43:01I think when we look at the the information sharing and analysis centers, the ISACs, and you know, I can I can most speak to the IT ISAC, but there are ISACs for all 16 critical infrastructure sectors. There are thousands of companies participating in those ISACs and sharing information including the cyber threat cybersecurity companies. I mean, as far as I know, there were no barriers to to sharing there.
▶ 0:43:22And actually, the fact that we are able to share at scale amongst all these different entities, you know, is is is certainly a very good thing because the cyber companies do participate in those sorts of sharing activities. There are other others other groups like the cyber threat alliance, for instance. There are various other information and sharing and analysis organizations out there. And there's a lot of sharing going on, much much more sharing than there was pre-CISPA 15.
▶ 0:43:49I think we You talked about artificial intelligence that it could be a sword or it could be a shield. Who's winning? Um I I I mean, I I think I I I certainly like to think that uh the good guys are winning uh right now. It's probably that that's a matter of perspective. When we're trying to hack into somebody else, we're the good guys. So, that's a sword. So, who's winning? The sword or the shield?
▶ 0:44:19Who is keeping pace with who? Is the Is the shield keeping pace with the sword? Um I think it's hard I think it's hard to generalize, but I I mean I think that the the way in which artificial technology is being used by defenders is is is is proving quite effective today, but we really can't let our guard down because again the good guys are innovating, and so are the bad guys.
▶ 0:44:44So, we really need to keep think that it would be a wise move for for Congress, for the the government to invest in in artificial intelligence as a shield because we're we're never going to match our adversaries in terms of the manpower that they pour into this into this effort. The only way that we can match that is through automation. Um And do you agree with that, Mr. Schmeck? Is that Is that your name? That's correct.
▶ 0:45:10Yeah, similar to private sector companies, I think the US government should be investing in artificial intelligence, improving its Um we rely on the US government and its capabilities in both offensive and defensive in nature to support us and protect us. So, the more effective you can be, the the better protected we're going to be in the end. Thank you so much, and I yield back. Gentleman yields back. I always love when you ask questions. I never know where you're going to go. I don't I don't either until I get here. I love it.
▶ 0:45:40Uh and I recognize the gentleman from Rhode Island, Mr. Magaziner, for 5 minutes of questions. Thank you, Chairman. Uh the Cybersecurity and Infrastructure Security Agency, CISA, uh leads our nation in securing businesses, critical infrastructure, and the government from cybercriminals, hackers, and adversarial countries. When US businesses are attacked, CISA provides vital response and recovery.
▶ 0:46:05When there is an emerging cyber threat or a breach, CISA warns private industry about the threat and also provides training and education to the private critical infrastructure operators, educational partners, and the general public. Uh the absolutely vital work done at CISA makes our country safer from the growing threats on cyberspace in cyberspace.
▶ 0:46:27And I am glad that there is bipartisan interest in reauthorizing uh the Cyber Information Sharing Act of 2015 so that this work can continue. Um in part though, the continued success of CISA and the uh hopefully uh growing success of CISA uh depends not just on this legislation being reauthorized, but in making sure that CISA is adequately resourced.
▶ 0:46:56And we need to ensure that the Trump and Musk administration doesn't cut CISA to the extent that they have announced they intend to do so. We should be investing in this space, not cutting back, because our adversaries are not cutting back.
▶ 0:47:12And if we're going to believe that the administration takes cybersecurity seriously, then we're going to need to see from them uh a reversal in their plan to cut nearly half a billion dollars from CISA's budget, which is what was proposed in the administration's fiscal 26 budget. If the administration took cybersecurity seriously, they would be investing in CISA, not cutting it. So, we need to talk about that, and then we need to talk about the alternative.
▶ 0:47:39How do we build CISA up to continue to be successful going forward in the context of a ever more complex and hostile threat environment targeting the United States. So, I'll start with Ms. Kuehn. Did I pronounce that correctly? Keohane? Keen. Keen.
▶ 0:48:00Um so in April it was reported that the administration, the Trump administration, plans to cut over a thousand jobs at CISA, which is expected to impact a myriad of programs across the agency. Can you discuss what the impact of those kinds of workforce cuts would be and whether they are a good idea or not? Am I on?
▶ 0:48:29If we talk about the threats that we're facing right now, you know, you were asking about adversaries earlier and one of the critical roles that CISA is playing right now is that we really have with the advent of AI and specifically generative and agentic AI, three types of threats right now. We have malicious, which we all understand, nation-state adversaries and and criminals. We also have malfunction and mistake. So if we think about what happened this summer with CrowdStrike from software incident perspective and then also with AI when all of a sudden an LM decides to go poorly.
▶ 0:48:57So CISA is playing a critical role. One, you know, the public partnership groups that I discussed before like JCDC and the advisory council of helping share information between the companies that are on the front line from the private sector developing technologies and the government when things happen from a threat perspective. The other thing that's really critical is, you know, we talk a lot about the private sector, but the reality is is that a huge amount of our critical national infrastructure sits within medium and small businesses.
▶ 0:49:26And they rely on CISA for things like the small company guidances that came out in the last few years with cyber. Yeah, I think that's such an important point. I mean one of the things that I think the general member of the public doesn't fully appreciate unless they're deep in this stuff is that, you know, when our adversaries, particularly the state actors, you know, China, Iran, North Korea, others are trying to hack into US systems, it's not just the big government agencies like the Pentagon or the big companies like Northern Trust, but small
▶ 0:49:56and medium-sized businesses, and also all of these local utilities and local governments all across the country. And you know, we we hear about these cases in classified settings, but there are also plenty of cases that have been publicly reported of local water systems, local airports, etc. So, again, just getting back to the issue of resources and workforce, CISA has, I mean, thousands and thousands of customers that it needs to interface with, small businesses, small localities.
▶ 0:50:26So, again, how important is it that we maintain a strong workforce at CISA uh in that light? So, I'll give you an example, and uh you know, you talk about the small businesses and the importance of CISA. Not long ago, I was on a plane chatting with the woman next to me. She was on her way to Florida because she was meeting her husband and her grandkids. And her husband was uh retiring from his job. What do you do? Well, he was a concrete distributor in Dallas.
▶ 0:50:49And she explained to me that they were selling the company, the company was going out of business basically, because he she and literally went, "There was one of those ransomware attack things. He borrowed my phone and did something for business on my phone, and we had a ransomware thing. And something There was a gang in Turkey, and this is her explaining this to me, who charged us $6 and it was just too hard to clean up.
▶ 0:51:13We don't have the ability of understanding the cybersecurity, and so we just gave up and we're closing the business, and he's going to retire." That's the issue we're facing here. Is that, you know, while we can represent large organizations that can spend, you know, millions and millions and millions on cybersecurity, there are exponentially more organizations out there, critical national infrastructure, small banks, grocery stores, you name it, uh that don't have the ability and need organizations like the program CISA provides
▶ 0:51:44in order to ensure that we have mature cybersecurity. Thank you. Gentleman yields back. I now recognize gentleman from Tennessee, Mr. Ogles, for 5 minutes of questions. Thank you, Mr. Chairman, and thank you to the witnesses. I think by and large we all agree that CISA should be So then the question becomes, how do we make it better? I know there's been some calls let's do a clean re-off and just get it out the door quickly.
▶ 0:52:09But you know, as we look at the landscape as we go forward, obviously, you know, in battlefield terms, you know, as warfare has changed, I would argue that you know, one of those battlefields is in the cyber realm. So Mr. Miller, I know you've you've had some suggestions in particular some of the definitions as it pertains to CISA. Can you any thoughts on how we can improve as we go into reauthorization to make it better, stronger, more robust?
▶ 0:52:37Thank Thank you for the question, Yeah, you know, I did include some some recommendations in in my statement. I mean, I do think in general the approach that we should be taking if if we're looking at changes is to, you know, just ask a pretty simple question. Hey, what's changed in the past 10 years from a threat standpoint, from a technology standpoint?
▶ 0:53:02Are the very very technical definitions that we have of cyber threat indicator and defensive measures in the bill, do they really account for all the different types of attacks that companies are are experiencing today? And are we sharing the types of threat information that we need to counteract those threats? You know, I think one one example of a relatively novel type of attack that's grown to prominence. I mean, someone mentioned SolarWinds earlier, right?
▶ 0:53:30You know, supply chain attacks, software supply chain attacks. You know, right now if if a company knows that there is a suspect supplier in its supply chain, it doesn't get the type of liability protections that CISA provides to share that sort of information, right?
▶ 0:53:49So, if you were thinking about making surgical precise um you know, edits uh or changes to to the bill, again, I I would not open it up entirely, but you could look at things like the definition of cyber threat indicator, which has I don't know, seven or eight subparts, and you could perhaps add something like derogatory information about a supplier in your supply chain or something like that.
▶ 0:54:12And that's just an example, but but I mean, that's the the general type of approach I would take rather than making wholesale changes to update the law. Well, kind of going back to uh Mr. Menendez's point, you know, like I think one of the the thing uh things we need to look at is better information sharing, broadening the scope of who might be included, but then with that, you probably need to to your point, the liability protections uh to protect someone if as they're sharing information that otherwise might be, you know. Uh so, what about the JCDC?
▶ 0:54:43What role might they play uh as we go forward? Yeah, I I mean, uh you know, as as as others have have have testified to, you know, the the the JCDC is is is a very valuable uh you know, newer partnership that that that CISA has led, obviously. Um you know, it's really focused on operational collaboration as opposed to to simply sharing information, right? And that And that's really what what what this is all about.
▶ 0:55:11Um you know, I I will say um it is my understanding that you really could not have JCDC still, you know, without the liability protections that exist in CISA 15 though, right? I mean, there are MOUs that companies that participate in JCDC sign, but that really deals more with information dissemination and adhering to pretty strict uh traffic light protocols.
▶ 0:55:36It doesn't have anything to do with the fundamental liability protections and authorizations that CISA provides for sharing the threat information in the first place, which at the end of the day is what underpins JCDC, I would Mr. Ronaldo, you you touched on China in rather stark terms. You just want to give us a quick brief of are we adequately protecting ourselves with CISA and the reauthorization as it pertains in you know, terms of China and their bad actions as it in terms of the Absolutely.
▶ 0:56:05And when we were doing our fact-finding mission as we were drafting the legislation, one thing that was very abundantly clear is that more than 90% of our networks are held by the private sector. So, what can we do as a government to help protect the private sector? So, the idea of information sharing and the importance of government to business and I think you know, to your question to John, how do we improve the transport of information from the government to business?
▶ 0:56:32I would say that was one part that's lacking today and not necessarily need you don't need a congressional change to make that happen, just oversight. How could we you know, stay on top of the agencies to make sure that they're pushing out information and then I would also say security clearances is a big issue. You may have people that can get a clearance, go into a room, hear the information, but do you have the engineers that can actually act on it? So, that's an important aspect as well. Mr.
▶ 0:56:58Chairman, I know I'm out of time, but I would just say to all the witnesses, if you have any suggestions or recommendations that might be specific as to how we make it better, now would be the time to provide that input. So, if you would like to send that to my office or of course to anyone on the committee, the chairman, happy to take a look at that look at that, incorporate it because obviously as again, as we look to the future, as we look to the future of warfare, this is one of those battlefronts and we need to be ready, we need to be proactive, we need to be ahead of the AI curve. Mr.
▶ 0:57:27Chairman, I yield back. Thank you for your Gentleman yields back. I said I second that so that's great. I now recognize the uh ranking member, the gentleman from California, Mr. Swalwell, for 5 minutes of questions. Thank you. And to follow what Ms. Rinaldi was saying about JCDC, Ms. Kim, can you discuss how JCDC facilitates information sharing? And to Ms.
▶ 0:57:53Rinaldi's point, how important is it for CISA 2015 to be effective that we have a mechanism like JCDC that facilitates cross-sector information sharing? I think, you know, how JCDC, you know, disseminates today and the critical importance of it and and to your point that it's a relatively new program, one of the things about it is it allows for rapid distribution when threats happens between industry and government so that we have, in essence, a real-time channel of things that are going on.
▶ 0:58:22From an industry perspective, you know, it's it's really important that we even broaden the scope of it to work closer with the ISACs and to think about how we can distribute not just to, you know, the top level of industry, but actually pull it down. From a JCDC perspective, I think it's one of the the best things we've seen come out of CISA so far and it's still evolving. Um but that ability to have information sharing without repercussion, I think it's one of the areas that we really need to focus on.
▶ 0:58:49And so that's why, you know, looking at the at the the, in essence, reauthorization of this act is so important because we're just at the beginning of where JCDC could go. Um and as we start to think about we mentioned China, but, you know, if we think about the Chinese threats that have come in from Volt Typhoon, Assault Typhoon, Black Typhoon, Nylon Typhoon, there's a lot of typhoons right now. We're going to see, in essence, cross-pollination of those critical vulnerabilities exploits, and JCDC is going to be incredibly important to ensure we disseminate rapidly through that.
▶ 0:59:19And to Ms. Rinaldi's point about security clearances, it's a frustration I share as well. You know, my district is high-tech and two nuclear labs, and often I hear what Ms.
▶ 0:59:35Reno was saying, which is like, yeah, the CEO is cleared, but like he's not the engineer, and he doesn't under- one, he his time is limited, or her time is and two, like he or she doesn't have the skill set to receive and understand the threat, but the problem on the government side is they're not really willing to clear that many individuals.
▶ 1:00:01And I I just welcome your feedback on if you're seeing that, because I If you remember like 2 years it was like like a 19-year-old who was like caught leaking like Ukraine war plans, and it was like a military service member, and you're like, wait, we give a 19-year-old like basically the war plans for Ukraine, but we have like 20-year professionals who we could give like one-day passes or more information to better protect critical and we're like cautious about that.
▶ 1:00:30So, it it just seems like we've got the priorities uh crosswise, but I I'd welcome feedback from you, Ms. Keene, on It It's interesting, you know, I've been in cybersecurity for over 25 years, and some of the first um attacks or hacks I dealt with were nation-state level attacks um going around the financial services network. If you can imagine, I was 23 years old walking roofs with Scotland Yard and looking at data center Um and then some of the first financial services attacks. Uh I have never held security clearance in the United States.
▶ 1:00:59Um you know, been a risk executive of two Fortune, you know, 25 companies. The reality is is that we do need to reexamine how we look at clearance, but we also have to think about the fact that, you know, cybersecurity is to some degree, and we talked about it, a team sport. You know, I've known 15-year-olds who've had, you know, inventions become state secrets and, you know, housed in the NSA. And I've known, you know, 90-year-olds who still sit on boards and talk about cybersecurity. We need to make it that the reality of today's risk is that cyber risk is now business risk.
▶ 1:01:29And it's a question of how we look at protecting all the different areas companies look at risk from, from financial, operational, you know, resilience perspective, everything. And so from a clearance perspective, it's getting the right individuals in an organization cleared to ensure they understand, but also to make it more of a common language so we understand the impact risk has on organizations. And you know, I just as Mr. Ogle said, like I welcome ideas, feedback.
▶ 1:01:55I I'm a hesitant to want to like amend this at all at this point at this late hour risking that opening this up would not see it reauthorized. Um but I I do agree that with Mr.
▶ 1:02:09Ogle's that we need your feedback and just because we reauthorize it, if we do it in a clean way, it doesn't mean we can't down the road like even like right after reauthorization, have hearings and markups to make it even better, but avoiding a lapse is my priority and it sounds like Ms. Kelly, you agree. That would actually be my recommendation. I think that a reauthorization cleanly and then look at how we optimize and and look at things down the road for a couple reasons. We're at the beginning of AI.
▶ 1:02:38We're still trying to figure out some things regarding um you know, the different types of attacks. Like I said, we have malicious mistake and malfunction. And I think there's a way we can um strengthen public-private um on the back of it, but I would recommend a clean authorization. Great. Thank you. You're back. Gentleman yields back. I now recognize for 5 minutes of questions. I just want to say since the beginning of Congress, we have been approached by countless stakeholders about the need to reauthorize this as of 2015.
▶ 1:03:08In fact, we have eight statements uh that we will be submitting for the record, one of which has 52 organizations as signatories. So, I would like to uh without objections add these to the record. So So done. Okay, wonderful. Uh, so ordered. Yeah. That's great. I can do this by myself. Wonderful. Um You know, you all have said reauth has to happen. So I'm not even going to start with that question. Uh, everybody's saying that it's the it has to happen.
▶ 1:03:34Um And it sounds like clean reauth is, everybody thinks is the best way to do it, just to get it make sure it it's What would happen if the if this did not get reauthorized? You can all jump in. I want to hear from everybody. I want I feel like we need to get on the record why it's so important this has to be reauthorized. What would happen if it wasn't reauthorized? We'll start, uh, Mr. Miller. Uh, yeah, thank thank you for the for the question, Chairman.
▶ 1:04:04Um Uh, you know, I mean, I I I think if it if it was not reauthorized, uh, there would be an immediate chilling effect at least for for for some organizations on their their willingness and ability to share because those express authorizations in the bill and those attendant liability protections uh, would go away. I I I mean, it's this is not to say that information sharing itself would completely stop.
▶ 1:04:31Um, information sharing did occur before CISA 15, but a lot more of it is occurring, uh, after CISA 15. And in particular, uh you know, automated sharing at scale, again, as as I understand it as as as a lawyer, not as a cybersecurity operator, didn't really exist in nearly the same way that it does today. And the bill should be credited for that.
▶ 1:04:53I I personally think it's an open question given, um, you know, what exactly the fate of, for instance, the automated indicator sharing, uh, program at CISA would be if the bill went away because their authorization to run it would go away. It doesn't mean they would necessarily stop doing it. We don't have Homeland authorizations every year as as as you know, but it would put things into question.
▶ 1:05:16And so I think this would undermine a lot of certainty across industry and government and thus undermine the the certainty that we have with the trusted sharing partnerships that have been built since this of 15. Mr. Ronaldo. You're taking the decision from the CISO to the general counsel's office and that is going to slow everything. I know us attorneys are the worst. I wasn't I didn't say that. I can say that's okay. Uh Mr. Shimek. Yeah, I reiterate that. It's it's basically firms would immediately hesitate. There'd be uncertainty and what would be shared.
▶ 1:05:47Um things would slow down. The other thing is you would very much be locking out the small and medium-sized businesses and companies and vendors. Like this would be a big firm only play because we would be the only ones willing to try it, willing to evaluate it. Um and then you'd also I think you'd start to see what we saw previously which is every firm building bilateral craters with the US government instead of going through this uh through this uh framework. It's a very key point. Thank you for making that. Ms. Keane. It just to reaffirm everything that everyone else has said, but you're right.
▶ 1:06:17There was information sharing before 2015. You know, we did have it, but it was picking up the phone and kind of chatting in behind closed doors. And that's going to hinder, you know, from a both a proactive and a reactive, you know, cyber defense strategy if we don't have those safe harbors and to to my um fellow committee's point, it it puts it in the hands of the lawyers. And the reality is is that with AI coming in with what we're seeing with the rapid the rapid spread of threat, um we don't have time for it to go to the lawyers at this point. We have to be able to share information quickly.
▶ 1:06:48Yeah, the slower we are the the more exposed we are. And that information sharing is very Mr. Shimek, I want to ask you at at you know, you you both you work at um you work with SIFMA for a while. Uh and I wanted to know if you could specifically share some information with uh or some anecdotal um information about how your, uh, your companies or other companies you've worked with have shared information under this law. Sure.
▶ 1:07:15So, what we use this for typically is we will provide the information via AIS. So, we we have that path of sharing information with DHS when we need to. We also use other mechanisms, um, phone calls, email. There's DHS provides multiple ways for us to submit information. So, it provides, um, you know, maximum flexibility for firms to go do that. But then it also enables us to go peer-to-peer.
▶ 1:07:36There is probably not a day that goes by that I'm not talking to a peer CISO out there on some issue that's going on either emerging or, um, or on a an active threat that we're dealing with. And this just provides us that flexibility to make sure that, you know, anything we're sharing we're protected. Um, we're doing it under the best intentions. Um, and so it really allows us to, you know, as we say in financial, non-com- This is a non-competitive topic for us. We want to make sure that the entire system is protected because if there's an attack against one bank, it calls into question the entire system.
▶ 1:08:07And and financial services more than anything else is built on trust. I appreciate that. My time has expired. Uh, we're going to start a second round of question and I'm going to I'm going to recognize for a second round of questioning the gentleman from Florida, Mr. Gimenez. I minutes. Trying to figure out where I'm going to Watch out. I'm not so sure, you know, I I share the, uh, the ranking members, um, uh, um, problems with the 19-year-old.
▶ 1:08:33You know, in Ender's Game, the guy was like 12 years old and he defeated an entire alien race. So, you know, maybe the Ukrainians are onto something, you know. So, there, that's where I was going. Um, my question is, uh, anybody can answer this, uh, are we as a country spending enough?
▶ 1:08:53Cuz I do believe that at the end that the solution is not going to be Yeah, we we need a number of people, with artificial intelligence, I can see the day that you're that you're going to be both on the offense and on the defensive side, you will have literally millions of per minute being launched and counter-launched and and defended against.
▶ 1:09:18And they And then the system's learning from each other and probing and defending, probing, probing like and then basically almost at the speed of light, right? No, we can't have There's no way we can ever fund that many people, right?
▶ 1:09:31And are we investing enough as a country um in artificial intelligence in order to protect us from what we know is going to be the threat, which is really artificially artificial intelligence-launched uh cyberattacks, you know, on our country and our infrastructure and everything. Are we investing enough in artificial intelligence that will counter that?
▶ 1:10:01I think, you know, first of all, from the investment question, you know, my other role is I'm head of global advocacy for a you know, cyber advocacy for a privately-held company. And from a AI perspective, we've invested over half a billion dollars and a billion in lab just to look at all the different technologies that are coming in right now both from a proactive and a reactive AI perspective. What I would say is I think that we do need to invest more, but I think one of the critical areas is in public-private partnership.
▶ 1:10:29It's getting closer with the organizations like Nvidia and others that are on the front lines of creating AI and also then the companies that are defending AI, which many of them are early-stage organizations. So, the more we can strengthen the public-private partnership from government and and industry to approach how we look at AI, how we look at like I said, malicious malfunction mistake going in the future, it's going to have benefit across all areas of industry.
▶ 1:10:57Are we um Are we unified in an approach or or is everybody just doing their own thing as as individual companies? Is CISA doing its own thing? Is DOD doing its own you know, Oracle doing its own thing? or or would it be beneficial to maybe have some other different kind of of legislation that kind of starts to focus focus it all because it's it's a mutual defense system um that we really have to build here.
▶ 1:11:25Uh not just G, okay, DOD's protected but G, it's too bad that our critical infrastructure wasn't. Right? So, are we there? Where are we with that? Is everybody just developing their own or or do we have some kind of strategy to kind of focus in on that uh to develop instead of golden, you know, the golden shield, right? This will be the cyber shield, right? Which is it's going to be artificial intelligence. That's the way it's going to be. Where are we on that? So, I would say that different agencies are focusing on it for their specific needs.
▶ 1:11:55There's not one holistic approach to it, but more of a a buckshot, if you Um I think there is more of a holistic approach to how we manage um AI moving forward, but I think there's a lot of exciting applications. In my day job, I run a telecom trade association and we're really focusing on 6G and how AI is going to shape um sensing communications moving forward.
▶ 1:12:18So, you're able to detect uh anomalies in a network, whether it be security, whether it be weather related, you could tell a an uh certain portion of the network is down and that's all going to be done by AI. So, there are a lot of great aspects of it um and I think it's really important for the different agencies to kind of focus and and really hone in on their uh particular function. Do you think our adversaries are somewhat scattered like we are or do you think they're more focused on their on on their goals?
▶ 1:12:48I think China remains an existential threat to us on on these issues. Are they focused or do they have a scattershot kind of approach to their their development of AI? So, what we've seen in from my work at the House Intel Committee on Huawei is that China is especially focused on certain individual companies as opposed to we support sectors. And so, they will watch a see one individual company succeed globally while we push a sector. So, in that instance, they are honed in. Should we match that?
▶ 1:13:19No. Okay. I don't My time's up. I wish I could go further, but I'm done. Thank True innovation happens when you have multiple different companies competing. Gentleman yields back and consent of the rank member now recognize the gentleman from Tennessee, Mr. Ogles. 5 minutes. Thank you again, Mr. Chairman. I also sit on the Financial Services Committee and Mr.
▶ 1:13:42Schmick, I'd love to hear from you as one of the things that concerns me is the sophistication of of AI and how we're seeing that play out in the financial sector and just the risks that, you know, that are involved there. And so, what are the next phases? Does this Does this go far enough again if we we're going to come back and do a a cleanup or revision of this at some later date, what needs to be included?
▶ 1:14:08Yeah, so so AI obviously it's an area of investment for financial services both on the business side, but also on the security on the security side as well. Very much still early days in regards to how we're how we're going to embed that within our operations, but pretty much every firm has got a strategy around this and are making significant investments, you know, to Mr. Hemant's point.
▶ 1:14:30The in regards to how this is going to affect CISA, I think we're not really sure how this is going to play out and how we're going to want to share information whether it's going to be in agentic AI within a financial services agency and financial services firm sharing with another agentic AI DHS or within another agency. So, I think that's something we'll have to work out. And then it goes to maybe some of the improvements we can have on the AIS system. The AIS system was probably designed 10 years ago.
▶ 1:15:00It's operational, it accomplishes the mission, um but it's definitely something that could be modernized, um you know, both with AI or even, you know, other opportunities to uh to just improve the the level of detail um and to just make it more consumable for us as a as a a as both a submitter and a consumer of that information. Ms. Keene, you you mentioned the Typhoon attacks. As a former county executive, you know, one of the things that concerns me across our landscape isn't the larger companies.
▶ 1:15:30Obviously, they're a target and there's risk associated with it, but it's that critical infrastructure in rural Tennessee that supports hundreds of thousands, if not millions, of people across this network. what's the end game there? Um how do we help these smaller communities that quite frankly, so I'll give you an example, take, you know, Metro Nashville or Memphis or even the suburb Williamson County, which is a very affluent county, they have the resources to have an IT department, right?
▶ 1:15:59If you go a little further south, east, or west, the IT guys probably also uh the HR guy. And uh they don't they're not equipped uh to defend a county, the water system, the electrical grid from these types of attacks. So, what do we do going forward? I think part of it is again, you know, and I I sound like a broken record, it's public-private partnerships. So, the two attacks you just mentioned, so I'll use Salt and and Flocks.
▶ 1:16:23Both of them are exploiting, you know, critical vulnerability exploits that were back from like 2018-2021 unknown basically antiquated network and technology gear. So, it's again educating, you know, smaller and mid-size businesses and to your point, I saw a statistic recently that 80% of critical national infrastructure sitting in small and medium business.
▶ 1:16:43So, working with those organizations to create modernization plans, working with the organizations that have the CVEs to help with creating, you know, in essence, modernization, technology upgrade, helping small to medium businesses and critical national infrastructure organizations upgrade to technology that is not vulnerable anymore, and putting action plans together to do so. You know, that the typhoons are they're not going to care whether you're a large or a small organization. They're going to care about the disruption that it causes to your critical national infrastructure.
▶ 1:17:13And so, it's going to take a shoulder-to-shoulder proactive measure between public and private to ensure that we don't have disruptive behavior from them. And not not that I want to be one of the members of Congress that authorizes CIGNET, but it's almost like we need a cyber shield that is better equips our private and public partners in this space, but again, proceed with caution. Gentleman yields back. I now recognize the ranking member, Mr.
▶ 1:17:40Swalwell from California, for 5 second 5 minutes of Great. Thank you, Chair. Uh Ms. Keene, how has the loss of C-CPA impacted information sharing? I think when you look at, you know, the loss of C-CPA is there's kind of two things, whether you're talking about C-CPA or any of the councils. So, from the advisory council perspective and then the safety review board, the work that it does is the education that we need.
▶ 1:18:06So, from a C-CPA perspective, having that collaboration of experts both from, you know, public and private, and being able to look and give advice on things like we've talked about, the typhoons, about agentic AI, about even quant that are going on. Where should we be pointing our arrows? That's incredibly important for us to rely on. You know, if we talk about the safety board, getting the revisions and understanding what happened on critical attacks, you know, like the work that was being done on salt typhoon, there was the Microsoft vulnerabilities, there were others.
▶ 1:18:33You know, it's a question of those type of of information sharing allows us to go a step further than JCDC and really disseminate critical information about where we want to focus our attentions from public and private and then also how we better protect Are you aware as to whether DHS has provided a timeline for when a CPAC replacement will be established or a process for how the private sector can provide feedback? I'm not aware at this point. How would you structure a new CPAC?
▶ 1:19:05From a CPAC perspective, you know, I think that you have to look at there's there's practitioners and operators in cybersecurity and in AI. And you know, as we think about it, we need a blend of, you know, government, former government, um the practitioner side like the CSOs and the risk executives sitting here today and then also operators who are the business risk side from boards and CEOs and understanding the cyber perspective from the business side because we're seeing we're in the middle of a digital revolution. Cyber touches every area.
▶ 1:19:36Traditional technology, everything we do has technology in it and there's a cyber component. So as we look at the new CPAC, we have to take into consideration that we're no longer just looking from an adversarial perspective, it's a business operational resiliency perspective and we need to adjust Mr. Yel back. Gentleman yields back. I now recognize myself for my second 5 minutes of questions.
▶ 1:20:01When the original CISA 2015 law was negotiated, significant privacy concerns were raised. As far as I'm aware, these concerns did not come to fruition. Uh Mr. Ronaldo, you were there. Will you please walk us through the initial debates and how they were resolved dealing with privacy? Absolutely. So um during the four years we had uh three different bills that were introduced.
▶ 1:20:25And from the first bill, which was a couple of pages, um to the one that was signed into law, which was much much bigger, we took a lot of the feedback from privacy industry, um privacy groups and industry. John was instrumental in a lot of this work that we did. Um and we we made changes. Um the information has to be anonymized. You know, we want to make sure that what is actually being what is actually being shared is the zeros and ones of it.
▶ 1:20:51And I I know that the Inspector General has done a report recently and has determined that no privacy um issues have been um that have arisen in the past 10 years. So, the language and and all the protections that we put in have have been working. That's great. Uh cuz I'll tell you other than the name, uh privacy concerns it might be the biggest obstacle to uh to getting this um reauthorized. Um so, the fact that you haven't the the that report has zero reports of privacy uh breaches is great.
▶ 1:21:21Um Mr. Miller, you were also instrumental as we all just heard Ms. Naldo say, have you heard of any privacy-related concerns over the last 10 years the law has been in effect? no. Um you know, and I think that's a pretty uh compelling evidence that the bill itself and the structure and the protections that were put in place to protect privacy and civil liberties worked.
▶ 1:21:46Uh you know, if I could add one other protection that I think was very important to what uh Diane said, you know, actually having DHS serve as the central hub, you know, what we kind of called the civilian interface at the time, was very important.
▶ 1:22:01You know, if you think about what was what else was going on during this time, there was a lot of um suspicion about sharing and in particular about um you know, uh surveillance uh agencies in the in light of the, you know, Snowden disclosures, for instance.
▶ 1:22:17Um and so, I think that that um you know, the uh protections that Diane mentioned, you know, requiring the stripping out of of PII was was very important, but also sharing through DHS and then having DHS share across the federal government was a was a good innovation, I think, of the time as Mr. Shebeck, anything to add there? Regarding privacy?
▶ 1:22:43Uh just the only thing I would add to it number one is my made my statement, you know, we have not had anything realized in regards to any disclosures. Also, from a financial services industry standpoint, we take privacy extremely seriously. It's at its core to how we how our business operates. So, having those protections in there and really the focus on it in the in the in the act and the bill is really important. Ms. Keene. I I would agree. I think, you know, that they've summed it up.
▶ 1:23:12There There really has not been any, to my knowledge, concerns from a privacy perspective. And I think that that's one of the reasons that a clean authorization, from a renewal standpoint, is just critical. We can change what we need to change later, but what's working right now from a fundamental perspective is working. That was my follow-up question. You said clean re-off, which means you would all agree that there was no need to change the language when it comes to privacy, They all said yes, for the record.
▶ 1:23:41thank you very much for that. Um I do want to get to one more because we talk we're talking about information sharing with the government, private to private to government, but can you all talk about some reflections on how this legislation changed information sharing amongst private to private entities and how it fostered that information sharing. Feel free to jump in, whoever wants to. I I I mean, I'll I'll I'll I'll jump in.
▶ 1:24:11You know, I I talking to you know, for instance, you know, the executive director of the of the IT-ISAC you know, it it it it does seem like and talking about some of the the the types of things that CISA 15 really has has allowed the private sector to do. I mean, I think there were there are criticisms of whether the private government sharing can be better.
▶ 1:24:40I mean, we've heard some of those already today, but the private private private to private sharing is really a critical and maybe sometimes overlooked aspect of what CISA 15 really enabled. You know, again, if you look at the at the ISACs, again, some of the ISACs have less than 100 people, some of them have thousands of of of of companies involved.
▶ 1:25:01You look at the National Council of ISACs, you know, the state and local tribal and territorial ISAC, you know, all of these ISACs are allow, you know, it's kind of a concept of the the few protecting the many. And and they're in you know, very important in particular for those small and medium-sized businesses who can perhaps participate through ISACs because they don't have, you know, million-dollar budgets to to spend on cybersecurity.
▶ 1:25:27So, I think there's really been a pretty dramatic increase in private-to-private sharing that has been enabled because of CISA 15. All right. Well, I'm now out of time. I really want to thank you all for being here and I think you can tell by the fact that we all stayed for our second and we have such a big crowd in the back that this is a very important hearing and people understand its its Again, I said that it was it was wonderful that the secretary mentioned it yesterday
▶ 1:25:57that she wants to see reauthorization. That's the second time I've heard her publicly say that, which is great. So, I want to thank you all for your valuable testimony and for the members for their questions. Members of the committee may have some additional questions for you all and we would ask to respond to these in writing pursuant to committee rule 7E, the hearing record will be held open for 7 days. Without objection, the committee stands