▶ 0:09:59Subcommittee will come to order. The chair recognized himself for an opening statement. Uh, good morning. Welcome to today's subcommittee hearing on global networks at risk, securing the future of infrastructure. This topic has never been more pressing. The United States is home to the world's leading companies and innovators who are driving the development of cutting edge technologies like artificial intelligence, the internet of things, and next generation wireless technologies.
▶ 0:10:26These innovations are critical not just to our economy, but the future of global connectivity. Communications are also central to our national defense. This is a top of mind for me, especially as the representative of Fort Bragg, home of the US Army Special Forces and largest military base in the world. Connectivity and secure communication networks are vital to maintaining our defense capabilities and keeping our nation safe. Today, we rely on communications infrastructure in nearly every sector of our economy.
▶ 0:10:57As Americans become more connected, it is increasingly important the equipment we buy, the networks we rely on are secure, resilient, and protected from malicious actors. Unfortunately, the security of these networks is under threat. The Chinese Communist Party, for example, has been investing heavily to develop unsecure communications uh equipment and exported around the world to assist in their espionage activities, including in the United States.
▶ 0:11:25The known vulnerabilities and many technologies produced by foreign adversaries pose a direct threat to the national security of the United States. Last fall, we learned about Salt Typhoon, which may be the largest Chinesebacked telecommunications hack in our nation's history. These hackers infiltrated US telecommunications companies networks, impacting at least nine providers.
▶ 0:11:51This infiltration enabled the hackers to geollocate millions of individuals and record phone calls and impacted senior US officials, including then President-elect Trump and Vice President-elect Vance. In addition to these vulnerabilities, there are an increasing number of physical attacks on communications infrastructure such as undersea cables.
▶ 0:12:12These cables are responsible for carrying data traffic across oceans and are susceptible to damage by the elements and unintentional acts such as anchors dragging along the seafloor. But they've also been intentionally sabotaged and because of their physical location under the ocean, it can be difficult to monitor author unauthorized access to these cables. We must take decisive steps to address these threats.
▶ 0:12:36I was proud to support funding for the secure and trusted communications network reimbursement program which will support the removal of the remaining Chinese equipment in our communications networks. Another key aspect of securing our communications infrastructure is the review of foreign investments in US networks. Team telecom is an inter agency working group that reviews foreign investments in certain communications applications that come before the FCC.
▶ 0:13:02Team Telecom assesses the national security risks, law enforcement, and other policy considerations that may be associated with such investments. While this process is important, applications often get bogged down by delays and bureaucratic hurdles. We must find ways to make sure the national security concerns are addressed without hindering deployment. Satellite technology also plays an increasingly important role in our communications infrastructure.
▶ 0:13:29Satellites provide broadband services as well as missionritical services to critical infrastructure companies and the federal government. Yet, the regulations governing satellite operations have not kept pace with the growth in the industry. Last Congress, this committee led bipartisan legislation to streamline regulatory processes for satellite operators, and the Federal Communications Commission's adopted many of these reforms.
▶ 0:13:52But more work remains to provide clarity and more certainty in the licensing process to ensure the US remains a leader in this sector as well. We must meet these challenges head on. Innovation has provided untold benefits to Americans and to our economy. I look forward to hearing from the witnesses today about these issues. I now recognize the ranking member Doris Matsoule for her opening statement. You're recognized. Thank you very much, Mr. Chairman.
▶ 0:14:22Today's hearing comes on the heels of Salt Typhoon, one of the worst hacks of US history. Salt typhoon is a wake-up call that drives home the vulnerabilities in our communications networks. These networks are the backbone of modern life, connecting us to businesses, public safety, health care, education, and communities.
▶ 0:14:44That's what makes them such a ripe target for attack by malicious actors and why we must strengthen how we protect this critical infrastructure. Yet, I fear that we are moving backwards as the Trump administration won't even own up to its own pattern of security failures. President Trump is defending the indefensible rallying behind the blunders of his secretary of defense who lee classified war plans to his wife and brother over an unsecured signal chat.
▶ 0:15:14Likewise, he is standing blindly by his national security adviser and countless other senior officials who use signal and personal Gmail accounts to conduct sensitive government business. The Trump administration is handing highly sensitive data to deeply unserious people who can't be bothered to follow the law or basic common sense when it comes to protecting cyber security and keeping sensitive information safe.
▶ 0:15:43The world is watching. Bad actors are ready to take advantage of this administration's gross incompetence. In Congress, my Republican colleagues talk tough about protecting America against foreign adversaries, but talk is cheap. Their refusal to hold the Trump administration accountable despite serious security breaches speaks volumes.
▶ 0:16:07Republicans are also staying silent as President Trump slashes our federal cyber workforce, gutting our nation's capability to prepare for and respond to attacks on a critical As one of his earliest acts in office, President Trump disbanded the cyber safety review board, leaving the in limbo our investigation into the largest telecommunications hack in US history.
▶ 0:16:34Instead, Salt Typhoon remains active as this administration jeopardizes our government's ability to assess the damage and work on solutions. As President Trump is wrecking havoc on our critical communications infrastructure with his disruptive tariffs, rather than boosting US company, his tariffs have driven up costs and damaged supply chains at exactly the wrong time.
▶ 0:17:00Meanwhile, Democrats have been working diligently to increase network safety and pro and protect Americans information. As co-author of the Secure and Trusted Communications Network Act, I've been a staunch advocate of securing our network supply chains. Last Congress, we secured the last $3 billion to fully fund the RIP and replace program and remove vulnerable Chinese equipment from our telecommunications infrastructure.
▶ 0:17:28I urge our agencies to ensure smooth and timely completion of this national security imperative. I've been dedicated to advancing innovations such as open radio access networks or open RAN to bolster our supply chain diversity. And earlier this week, the future networks act passed the house.
▶ 0:17:47This bill will bring the brightest minds across industry, academia, and government to collaborate on the development of our next generation wireless technologies, including identifying supply chain and cyber security vulnerabilities so that we can more effectively prevent them. These are important steps to strengthen network security and we must build on this work. As America faces growing cyber threats, this is not the time for inaction.
▶ 0:18:16I urge my Republican colleagues to speak up and hold the administration accountable for security failures. We must work on bipartisan solutions to secure our communications networks as our subcommittee has historically done. I look forward to hearing from our witnesses on how we can proactively protect against future attacks. And with that, I yield the balance of my time. Thank you.
▶ 0:18:42I now recognize the chairman of the full committee, the gentleman from Kentucky for 5 minutes for his opening statement. Thank you. Uh thank you, Chair Hudson. I appreciate the opportunity to be here for this important hearing. Americans are connected to the internet in nearly every aspect of their daily lives. Whether it's work, staying in touch with loved ones, or receiving health care, reliable connectivity is essential.
▶ 0:19:04The underlying communications infrastructure is what allows Americans and businesses of all sizes to use a lot utilize the many digital services that have redefined our economy and society. And while reliable access is important, it must also be secure. That is why today's hearing is very important.
▶ 0:19:23Sophisticated cyber actors, specifically the governments of China, Russia, North Korea, and Iran, directly engage in activities aimed at infiltrating our infrastructure, especially our communications networks.
▶ 0:19:36These state adversaries and other malicious cyber actors continuously seek to exploit weaknesses in our networks, not only to steal sensitive data and commit fraud against Americans, but they also stand to gain sensitive business and government information as they seek to establish footholds for surveillance and future exploitation. We have seen these efforts play out in recent attacks. We only have to point back to October when Chinese hackers breached the American court wiretap system.
▶ 0:20:04Our adversaries could also have the capability to cut off our communication services altogether. And think about how disruptive and devastating that would be for society. Our networks are vulnerable to physical disruptions. For instance, fiber cuts can take months to repair depending on where they're located. And if we're talking about subc cables that are isolated in the ocean, these cuts can interrupt international data flows and result in degraded service for millions of people over an extended period of time.
▶ 0:20:34Given the relative difficulty of repair, increasingly satellite provided services are being used to help close the digital divide and provide positioning, navigation and timing data for government private sector uses. Foreign adversaries again like China and Russia are reportedly developing anti-at satellite capabilities which are caused serious disruption to critical services.
▶ 0:20:59And in the case of GPS, a satellite provided service, we have very few alternatives. Disruption to these critical communication services has the potential to cause chaos here in the homeland and reverberate throughout the economy. It could also give our adversaries ability to disrupt American military mobilization in the event of conflict or attack.
▶ 0:21:20Securing our communication systems from bad actors has been a long-standing priority, bipartisan priority of this committee and is essential to preserving our national economic security. This committee led the effort to rip and replace untrusted vendor equipment from our mobile networks by passing the secure and trusted telecomun communications network act.
▶ 0:21:41We built on these efforts by bypassing the USA Telecommunications Act in 2020 to foster a more competitive market for trusted equipment vendors by promoting open rand technology. More work remains to protect our critical infrastructure and harden these essential services against adversarial threats. Thank you to the witness for your participation.
▶ 0:22:05I look forward to hearing from you about how to protect our communications in future communications infrastructure and ensure that the US is prepared to defend against the CCP and any other adversaries. I really appreciate you all being here today and look forward to the discussion. And with that, Mr. Chairman, I will yield back. Gentleman yields back. I'll now recognize the gentleman from New Jersey, the ranking member for five minutes for your opening statement. Thank you, Mr. Chairman.
▶ 0:22:30While today's discussion is important and timely, I'm worried that my Republican colleagues are failing to even acknowledge the unprecedented and troubling actions of the Trump administration that are putting our national security at risk. Defending our telecommunications infrastructure from our foreign adversaries and other bad actors is critically important.
▶ 0:22:50On a daily basis, our nation's telecommunications networks carry enormous amounts of data that not only include our most personal information, but also sensitive government materials that any foreign nation would love to digest. And late last year, we learned that um SAC, no, Salt Typhoon, I'm sorry, that Salt Typhoon, a cyber espionage operation backed by China, infiltrated several American telecommunications networks to gain access to
▶ 0:23:20detailed information on President Trump, former Vice President Harris, other political figures, and American surveillance information. And that's why it's so disturbing to watch as the Trump administration has mishandled sensitive national security information. In one of the worst security failures in decades, Defense Secretary HGA last month shared highly sensitive war plans on Signal, an unofficial and unsecure messaging app.
▶ 0:23:46The unsecure group chat was created by National Security Adviser Waltz and he inadvertently included a reporter in the chat. Hegs also shared the same information in a separate chat with some family members. Now, this reckless conduct uh put the lives of American troops at risk. In my opinion, if any adversary got access to these messages, they could have shut down or they could have shot down American planes or targeted American ships. And yet, Secretary Hath continues to lead the Department of Defense.
▶ 0:24:15I don't know for how long it but it is an outrage and shows that the administration doesn't take these threats very seriously. And this is on top of the fact that Elon Musk and his Doge minions are being given access, often unauthorized, to sensitive information and undermining American security on a daily basis. And that could include our nuclear secrets.
▶ 0:24:36Musk and Doge are also haphazardly and indiscriminately cutting and slashing important government programs and experienced public servants, which is weakening our country without any push back from congressional Republicans. And while President Trump likes to act tough against China, he is blatantly violating Congress's bipartisan tick- tock legislation and continuing to allow the Chinese Communist Party to compromise American devices, harvest Americans data, promote pro-communist propaganda, and undermine American interests.
▶ 0:25:06So, securing our country's telecommunication networks and infrastructure is serious business. But the Trump administration is not taking the task seriously. Imposing arbitrary tariffs on telecommunications equipment and chips that are vital to enhancing the safety and security of our networks one day and then pausing them the next day is only causing chaos and confusion.
▶ 0:25:27The administration's actions are increasing the chances that our foreign adversaries and others attempt even larger scale attacks on our telecommunications networks, which no one wants to see. Despite President Trump's recklessness and my Republican colleague silence, today's hearing topic underpins a significant part of the American economy. From health care to energy to public safety, nearly every facet of American life relies on our nation's telecommunications networks and infrastructure.
▶ 0:25:54And while the innovations and advancement that these networks enable us to do are remarkable, it also makes them and the devices that run on top of them targets. So this will only increase as more devices than our homes are connected. If cars, television, home security systems and more are connected to the internet, they are vulnerable to attacks. The reality means that our homes can now be attacked without anyone touching a single door or window.
▶ 0:26:19So it is imperative that we understand the vulnerabilities and risks our networks and devices face to better protect our country and consumers from attack and to keep up with the rapidly evolving technological landscape our nation faces. And I urge my Republican colleagues to stop these irresponsible budget reconciliation plans as well.
▶ 0:26:38Rather than using spectrum auction proceeds to fund giant tax breaks to American billionaires and big corporations, we should use the proceeds from spectrum to help fund next generation 911, which will enhance the safety of our energy networks and save countless American lives. The Trump administration must also stop delaying sending states their funds from the bead program. These funds will ensure reliable connectivity across the country, which is crucial for our national security and economic prosperity.
▶ 0:27:07The only person who benefits from these delaying taxes, Elon Musk, who's trying to get taxpayer money funneled to his Starling service. So, I look forward, Mr. Chairman, to hearing from today's witnesses. Uh, and I do think this is an important hearing about our telecommunication infrastructure and devices. Thank you, Mr. Chairman. Yield back. Thank you. Um, we've now concluded with member opening statements. The chair reminds members that pursuant to the committee rules, all members opening statements will be made part of the record.
▶ 0:27:37We'd like to thank our witnesses for being here today to testify before this subcommittee. Our witnesses will have five minutes to provide an opening statement which will be followed by a round of questions from the members. The witnesses here before us today are Tom Stroop, president of the satellite association, David Stalin, chief executive officer, Telecommunications Association, Jamil Jafar or Jaffer Jaffer, I apologize, um, founder and executive director, National
▶ 0:28:07Security Institute, and Laura Galante, former intelligence uh, community cyber executive and director cyber threat intelligence integration. ation center office of the director of national intelligence. Mr. Troop, you're recognized for five minutes for your opening statement. Chairman Hudson, Ranking Member Matsoule, Chairman Guthrie, Ranking Member Palone, and distinguished members of the subcommittee, thank you for inviting me to testify before you today.
▶ 0:28:37I'm Tom Stout, president of the Satellite Industry Association. Satellites are the backbone of modern society. We rely on them for communications, position navigation and timing, and remote sensing across the globe. Satellites provide critical services to hundreds of millions of Americans and billions of people around the world every day.
▶ 0:28:58The companies represented by SIA are poised to provide resilient services in any situation to empower US leadership and support US citizens and allies in an interconnected and contested world. We are at a time of tremendous innovation in the space industry with over 12,000 active satellites on orbit today and plans for tens of thousands more through the end of the decade.
▶ 0:29:20Satellite services support all 16 critical infrastructures, including through communications for emergency services, position navigation and timing for agriculture, resilience for global telecommunications, and remote sensing data to improve our national security. Satellites are the fastest way to connect the unconnected.
▶ 0:29:40With multiple American companies providing high-spe speed internet and more launching in the near future, the satellite industry provides FCC defined broadband service today across the globe and is ready to bring the nation into an interconnected future as a backbone for 5G, IoT, and AI technologies. In addition, satellites play a critical role in preparation, response, and recovery from natural disasters, electrical outages, and terrorist attacks.
▶ 0:30:07Remote sensing data and analytics can help pinpoint and quantify initial damage assessments in the immediate aftermath of a disaster. Synthetic aperture radar satellites can see through clouds and allow the mapping of damaged regions when storms are still overhead. Furthermore, unlike terrestrial communications counterparts, satellite networks are not susceptible to damage from such disasters because the primary repeaters are on board the spacecraft and not part of the ground infrastructure.
▶ 0:30:35In addition to the benefit of having its primary infrastructure in space, many communication satellite operators provide customer connectivity through multi-orbit services. These services marry the low latency of LEO systems with the ability of geo systems to deliver large amounts of capacity in hightra areas. While both geo and nono systems have the ability to provide large amounts of capacity, the combined solutions offer the best of both systems, enhancing the resiliency and reliability of services.
▶ 0:31:05Another recent development furthering network resiliency is the deployment of directtomo satellite connectivity led through major partnerships between satellite operators and both wireless carriers and manufacturers which greatly expand the range of communications available to mobile customers. The satellite industry today is investing continuously to ensure it can it can address the challenges of the future and to make its technologies available to every American.
▶ 0:31:32Satellite companies are working to optimize the use of spectrum by investing in high throughput satellites and flexible softwaredefined payloads that allow for instantaneous reallocation of spectrum resources and the mitigation of harmful interference. Satellite system operators are continuing to invest in network cyber security including including using AI for vulnerability testing. Launch costs have also declined dramatically providing opportunities for rapid replenishment of satellite constellations.
▶ 0:32:01While the US has long led the space sector, China is closing the gap with similar investments in space technologies that will n challenge our national security community while also undermining democracy around the globe. It is critical for Congress to support continued domestic innovation and avoid regulations that put US providers on an unequal playing field internationally.
▶ 0:32:22Our members are dedicated to advancing the national interests, ensuring competitiveness of satellite companies in the US and globally and driving progress for the benefit of all Americans. In furtherance of these goals, we have five priorities. Number one, promote American space innovation through streamlined regulations without unnecessary red tape and bureaucracy. Two, lead standards development internationally.
▶ 0:32:47Third, enact effective space debris policies and rigorously advocate for adoption of similar policies in other countries and an international fora. Fourth, streamline space systems procurement for greater efficiency and government acquisition. And finally, spur development and investment through access to sufficient spectrum resources. I appreciate the opportunity to appear before you today on behalf of the satellite industry and I look forward to your questions. Thank you. Uh Mr.
▶ 0:33:16Stalen, you're recognized for five minutes for your opening statement. Hudson, that's on Vice Chair Allen, Ranking Member Matts Suie, and members of the subcommittee. My name is Dave Stalin. I'm the CEO of TIA, the Telecommunications Industry Association. And I appreciate the opportunity to speak about this important subject, securing the future of telecommunications infrastructure, so that Americans can depend on trusted, secure, resilient, high-speed networks.
▶ 0:33:44For more than 85 years, TIA has with our 400 member organizations developed technical and process improvement standards and advanced new technologies that drive our economy and improve the lives of our citizens.
▶ 0:33:57TIA's current standards cover a wide range of areas including data center infrastructure, cell tower structures, structured cabling, public safety and emergency responder radios, hearing aid compatibility with mobile devices, telecom quality management, and our most recent focus on cyber and supply chain security. We're a technology agnostic organization, meaning that we support all Wline, wireless, and satellite trusted technologies.
▶ 0:34:25In short, TIA has nearly a century of experience in ensuring that communications networks are built efficiently efficiently and resiliently with trusted suppliers. I've been the CEO of TIA for the past five plus years and have run both publicly traded and venture-backed telecom technology companies for the past 40 years. I've seen tremendous change in technology improvement, but I also recognize that security improvements always lag behind technology advancements.
▶ 0:34:52I've experienced firsthand how state-owned entities like Huawei operate on a global stage, undermining a competitive market of trusted ICT vendors. As a graduate of the Naval Academy and former Marine officer, I take national security very seriously, and I understand that the national security threat posed by entities controlled by our adversaries uh can cause dramatic and significant long-asting effects uh to our communications networks.
▶ 0:35:20Every type of critical infrastructure from electrical grid to water systems to emergency responders to the internet all use similar information communications technologies and systems. Potential vulnerabilities in these systems have a broad impact due to due to the unique role played by communications networks in our infrastructure. Every one of CIS's 16 identified critical infrastructures uh uses fundamental ICT networks.
▶ 0:35:50Network attacks come from many directions, including state sponsored enemies, criminals, and terrorists. And while the attack possibilities are endless, we must have a defense in depth, which starts with supply chain security. We must ensure that the products and services that make up our networks are coming from trusted suppliers who can demonstrate that security is designed in. We must verify before trusting. All of this is critical to the success of building trusted, resilient, and secure global networks.
▶ 0:36:19In this context, subc cable systems are an area of growing concern across the globe. nefarious actors are increasingly disrupting networks by cutting cables and damaging the points where the cables come ashore. These subc cable uh cable systems carry more than 99% of internet traffic across the continents and more than 10 trillion dollars of financial transactions. These cables are irreplaceable backbones of the global internet.
▶ 0:36:47And while satellite communications plays an integral role in our networks, the data capacities of subc cables cannot be overstated. Of course, in addition to these physical threats to our communication networks are the is the fundamental threat from untrusted software, hardware, and suppliers. As network architectures continue to advance and become more complex, the potential attack surface grows and expands as well.
▶ 0:37:12This gives bad actors, including those who are state sponsored by foreign adversaries such as the CCP, more targets, for example, the recent salt typhoon attack. The US government has a long and bipartisan recognition of the supply chain threat vulnerabilities posed to our nation's infrastructure.
▶ 0:37:32The industry recognizes this and that is one of the reasons we at TIA initiated and developed the industry's first supply chain security standard SCS 901 about three years ago. This standard was designed with input from our members and both the US government and trusted allied governments and aligns and operationalizes the NIST cyber security framework, the Prague principles and many other guidelines.
▶ 0:37:56SCS 901 is a supply chain security management system intended to define and measure the requirements and controls for the design, development, production and operations of ICT products and services. This is an effort that reaches beyond our domestic infrastructure and TIA has been working with the Department of Commerce and the Department of State to help allied countries build trusted wireless fiber and satellite networks.
▶ 0:38:21We appreciate the leadership that this committee brings us and has demonstrated by holding this hearing and I would like to thank you for your time. Thank you, Mr. Jeffrey. You are recognized for five minutes for an opening statement. Chairman Hudson, ranking member Matsui, members of the subcommittee. Thank you for inviting me here today to discuss the threats facing our global networks and the telecommunications infrastructure of our nation, its allies, and its partners.
▶ 0:38:47I want to thank the chairman and the and the ranking member for holding this hearing particularly given the major threats that we face today against our global telecommunications infrastructure from China, Russia, Iran, and North Korea. While recent reports have come to light about the major hacks of the United States telecommunications infrastructure and the deployment of destructive capabilities within our infrastructure by China, these are only a small part of a much larger effort architected by our adversaries.
▶ 0:39:16These adversaries include not just the nations of China, Russia, Iran, North Korea, but their proxies as well. And they're aimed not just at collecting information and intelligence on American on the American government and our federal policies and priorities, but on our citizens and putting in place capabilities that if they decide to use could take down significant parts of our financial system, our energy infrastructure and the like.
▶ 0:39:41And of course, our entire nation and all of its capabilities, including the modern AI revolution runs on top of the global telecommunications infrastructure that we're talking about today. And so, while our hearing today is focused on this global infrastructure, we need to think about in the context of two major issues. the larger national security and economic competition with China and the key and its key economic and technological elements and the increasing robust collaboration between China, Russia, Iran and North Korea.
▶ 0:40:12We know the director of national intelligence told us that China presents the most comprehensive and robust military threat to US national security with a joint force capable of full spectrum warfare. This is true in the cyber domain as well where the director of national intelligence has told us that China remains the most active and persistent cyber threat to the US government, private sector and critical infrastructure networks and that China's demonstrated the ability not just to compromise US infrastructure through formidable cyber capabilities but also that
▶ 0:40:42it has the ability to conduct destructive and disruptive activities. And this is where volt typhoon and salt typhoon come into play. Now, none of this is particularly new when it comes to China. Since at least 2019, we've known that the director of national intelligence told us that China's improving its cyber attack capabilities and that it had the ability back in 2019, six years ago, to launch cyber attacks that could cause localized temporary disruptions and disruptive effects on our critical infrastructure, including the disruption of natural gas pipelines for days to weeks.
▶ 0:41:12That was six years ago. And so we think about what their capabilities look like today and we realize that this threat is much larger and much more significant than we think. And so let's talk about one particular example of how this plays out. We look at the salt typhoon hacks of the US telecommunications infrastructure. In that effort, the FBI has told us that China targeted commercial telecommunications infrastructure and had a broad and significant cyber espionage campaign. They had compromised networks at multiple telecommunications companies.
▶ 0:41:40The chairman mentioned nine of them to enable the theft of customer call records, the compromise of private communications, actual content on a number of individuals while primarily focused on US government political activity and the copying of information subject to US law enforcement requests. Let me say it again. The Chinese government was able to hack not just our call records, not just the communications of American government political officials, but the records of US law enforcement requests.
▶ 0:42:07That means people that we have on collection, whether for criminal purposes, maybe even for intelligence purposes, are now in the hands of the Chinese government. And if the Chinese have it, they're almost certainly going to share with the Russians, potentially with the Iranians, and potentially with the North Koreans. And don't believe me, chairman then then chairman of the Senate Intelligence Committee, John Warner, sorry, pardon me, Mark Warner, said it was the worst telecom hack in our nation's history.
▶ 0:42:33The current Secretary of State, Marco Rubio, referred to it as an egregious, outrageous, and dangerous breach of our telecommunication systems across multiple companies. So, what can we do? In the last minute I have remaining, I want to stress one thing we should not do. We should not blame the private sector standing alone. The idea that we would expect the private sector to defend against nation state attacks standing alone makes no sense. We don't expect Target and Walmart to put surface air missiles on on the tops of their warehouses to defend against Russian bear bombers.
▶ 0:43:04Why should we expect any of our telecommunications companies to be able to effectively defend against committed nation state attackers who have virtually unlimited resources of national governments? It doesn't make sense. At the same time, we have to look internally at the government to say what did the government know? When did it know about it? And why didn't it take action to protect its own data residing on these networks? So, there's a lot of work to be done here. There are a lot of things we could talk about. I appreciate the opportunity to be here and I look forward to your questions. Thank you.
▶ 0:43:31Miss Glante, you are recognized for five minutes for your opening statement. Thank you. Telecommunications fell. Okay. Right. Good morning, honorable chair, ranking member, esteemed members of the committee. Thanks for the opportunity to testify. I'm Laura Galante.
▶ 0:43:56I served as the intelligence community cyber exe executive and the director of the cyber threat intelligence integration center at ODNI. I was also the intelligence community's lead for what's called the unified coordination group which responded to salt typhoon. I'll focus my remarks today on the national security considerations for the US telecom sector whose growth has closely mirrored the digital transformation of our economy.
▶ 0:44:19Over the past 25 years, telco companies have evolved from phone service providers to complex multi-service digital organizations navigating the convergence of communications, media, and technology. As with so many major digital shifts during this period, intelligence services have also become increasingly adept at targeting the immensely valuable data that telos manage through their vast networks of digital roads.
▶ 0:44:46In short, companies in this sector have become key targets for foreign adversaries operations. This leads us to the recent Chinese government sponsored operation Salt Typhoon, regarded as the most expansive and consequential cyber espionage ever conducted against the US. Sponsored by the Chinese government and executed by contractors working for Beijing's Ministry of State Security, their intelligence bureau. This operation was first publicly detailed last fall in 2024.
▶ 0:45:15At least nine US Telos, that number was again confirmed by the by the FBI yesterday, and wireless communication companies were the victim of this extensive intelligence gathering operation. The actors breached multiple layers of major telecoms networks. They gained unprecedented access to US mobile communications across different carriers and various wireless technologies. The access enabled them to compromise voice and text communications of key political figures and national security officials.
▶ 0:45:43Salt Typhoon gives us a window into three major issues. The first is the increased scale of adversary intelligence operations. Rather than focusing just on the communications of specific high-target individuals, what these China what these Chinese actors did was they went after multiple data and access points through different victim companies in order to have this broadscoped approach in a persistent intelligence capability to get after highv value information for a period of time.
▶ 0:46:13This wasn't a smash and grab in-n-out type of cyber operation that we saw for years in the past. This was much larger. Second was the delayed detection of salt typhoon across the sector. Despite the telco's significant cyber security programs, detecting salt typhoon required and still requires an extensive joint government and industry effort to respond.
▶ 0:46:34The ability to detect and then rapidly remediate and respond to these compromises against our most high-value networks which we've all discussed must be a core capability for companies in the sector. Third is that AI is rapidly expanding our adversaries ability to process data.
▶ 0:46:51Rapid break breakthroughs in AI have now equipped these actors with the capability to make sense of large and disperate data sets that previously required immense amounts of time and resources to understand what the data they collected meant and what to do with it. AI has supercharged their ability to analyze this. These capabilities enable even less sophisticated actors.
▶ 0:47:12We've been talking about highly sophisticated ones with China, but now less sophisticated actors will be able to extract key insights from vast amounts of data collected in different sectors and different industries. The hard question that this committee faces is how to strike that balance between securing these digital roads and everyday life with the enormous and growing demand for digital connectivity. We're not going to regulate our way out to find an enduring answer. The technology changes too quickly. The ingenuity of our adversaries is relentless.
▶ 0:47:41We have to build a better dynamic operational security model than what we have today. That model requires bringing threat intelligence and national security expertise, the intelligence community, together with private sector representatives in the telco and secure technology sectors. This intelligence-driven approach is what will drive an operationally sound set of practices that companies can continue to implement and refine in their own infrastructure. The good news is we've done this before.
▶ 0:48:08One of the mechanisms available to drive this process until it was dissolved last month was called the enduring security framework founded in 2007 imple implemented by the national security agency along with the office of the director of national intelligence and then DHS's CISA's uh critical infrastructure partnership advisory council. This frame framework proved successful enough that British intelligence and Australian intelligence used it as their model for their national cyber centers.
▶ 0:48:37In this model, security practitioners in government and industry alike used this to come up with dynamic processes about how you rearchitected secure infrastructure for the future. Other boards that have also been dissolved including the cyber safety review board also worked to get to root causes of hard security and technical problems and they investig investigated major cyber incidents like salt typhoon.
▶ 0:49:01These are the joint efforts that created evidence-based approaches to address major security breaches and threats in coordination with the private sector who owns the critical infrastructure in this country. This collaborative security and intelligence work has been America's differentiator in our global secure technology market.
▶ 0:49:18It's an ecosystem of security professionals, intelligence officials, analysts, and operators who work together to track vulnerabilities and threats as quickly as they spread and that's fast in cyerspace and deploy the patches and fixes and new security paradigms that we that we need to stay ahead of these threats. Dismantling this security ecosystem weakens our collective defense and our national security posture. It's not a risk we can afford at this moment. I look forward to your questions. Thank you.
▶ 0:49:48We'll now begin questioning. I recognize myself for five minutes. Uh Mr. Jaffer, I I represent, as I mentioned, Fort Bragg. We like to call it the epicenter of the universe. Uh home of our special forces um and airborne. Um, why is maintaining the security of our communication networks essential to protecting our war fighters and our national security especially as it relates to our adversaries as you mentioned? Well, Mr. Chairman, it's hard to uh overstate how critical it is to protect our global telecommunications infrastructure.
▶ 0:50:15It is the backbone on which everything else runs whether it's war fighter activities uh communications with with families and spouses um and the collection and analysis of all of our intelligence. While we do have highly classified systems that run on separate networks, that communications grid is connected and if we don't if that communication grid doesn't operate, it simply doesn't work. And fundamentally, our entire economic system turns on this global telecommunications infrastructure as well.
▶ 0:50:42The United States is so successful particularly because we built the system. It runs on our equipment. It runs on our capabilities and that of our allies. And the day it doesn't and as it has transitioned over to equipment run by adversaries, the more vulnerable it's become, the less secure we become, the less secure our war fighters are, and the less secure our entire economy is. Appreciate that. Uh Mr. Stalin, do you have anything to add to that? I would 100% agree with everything that's uh going on there. We we do need the public private connection uh to make sure we address this.
▶ 0:51:13uh everything we do from the military to our home lives uses ICT networks and fundamentally they're all based on the same set of uh technologies and architectures and we have to verify that those technologies and architectures are secure emerging technologies have the potential to both enhance cyber security of our networks but also threaten their security. It's kind of a double-edged sword. Um Mr.
▶ 0:51:39Stra uh in your testimony you talk about how AI can be harnessed uh to do vulnerability testing. Can you tell us more about how this is being deployed in the satellite industry? Yes, thank you for the question. There are a number of ways in which it's being deployed. Um first is for anomaly detection being able to identify if there is a different type of uh data uh that is coming into a network being able to identify that in advance.
▶ 0:52:04Another is being able to take advantage of cyber security enhancements, being able to detect and uh uh respond to uh to threats in real time. Uh also being able to address signal jamming detection and mitigation. And then finally, I'd also like to emphasize it's important in space situational awareness. Uh there are so many objects in space and the opportunity to be able to identify, analyze, and determine whether they're going to pose a thrisk a a threat uh or risk to uh to satellites or one of the uses of of AI.
▶ 0:52:34Appreciate that. Uh Mr. Jaffer, how can AI be used in the communication networks to enhance security? Well, look, I there's a lot of opportunities we have. These LLMs can identify threats and vulnerabilities. We just saw in the last few months the discovery of brand new vulnerabilities that we weren't aware of discovered by LLM models running over network data, right? So, there's a big debate about will will AI improve the attacker more or improve the defender more. And I actually think it's a mixed bag, right?
▶ 0:53:01In some ways, it will definitely as as Miss Galante pointed out, uh enable attackers who don't have capabilities today to have more capabilities. At the same time, the defender will have an edge as well because they'll be able to get ahead of the threats, identify vulnerabilities, cut them off at the pass, and go after the attackers. So, while the offense, like in football, has always has a little bit of an edge, right? And AI will enhance that, AI is going to enhance defenders as well. and it's expanded use and ensuring that we don't overregulate it and crush it with unnecessary regulation will ensure that we maintain the edge.
▶ 0:53:30The reality is our adversaries are going to use it on the offense. If we overregulate it and don't use on defense, we will fail. I agree. Um Mr. Stalin, economic security is national security. One of President Trump's top priorities is reshoring American manufacturing as the United States continues to reshore critical manufacturing and expand domestic data center capacity. uh secure high-speed connectivity will be essential.
▶ 0:53:55Uh what specific policy actions do you believe are necessary to ensure our communications infrastructure can meet these increasing demands without compromising on supply chain security or network resiliency? Yeah, two things come to mind. First of all, we need to reshore as much as possible uh the active components that make up our ICT networks, whether it be a core router or a a base station or even a home IoT device.
▶ 0:54:21uh these uh devices have semiconductors which are not made for the most part in the United States. Major security shortfall uh that is not an something that can change overnight. It's something that will take a long time. And it's not only that moving the fabs and things like that back here, but it's the whole ecosystem moving that back here. And that's why uh many parts of Asia are successful in this area because the whole ecosystem is closely located to each other.
▶ 0:54:47So that whole supply chain needs to be both uh closely located with each other but also based in the United States. That's a fundamental strategic change uh and a long-term investment that we need to make. Uh and I would refer back to something I mentioned before, supply chain security. You have to ensure that the supply chain itself is secure. Not only that ecosystem, but all the devices that make up a product. And the only way to do that is ensure that the processes that are used to make a product are verified to be trusted.
▶ 0:55:18So that's something that this uh standard does is it verifies trust. Uh you have to verify it before giving trust out. Got it. Thank you. My time is expired. I'll now recognize the ranking member, Mr. Matsui, for five minutes to ask your questions. Thank you very much, Mr. Um, this assault typhoon attack exemplifies how expansive cyber operations against the US have become.
▶ 0:55:44In an increasingly digital era where artificial intelligence and emerging technologies can increase the capabilities of bad actors, we must address how America stays ahead of our adversaries. Miss Galante, what is the most pressing issue this committee must resolve to prevent major cyber attacks like salt typhoon? Security pro mature security programs in cyerspace are really important for major organizations especially in the telco sector to continue to refine and improve.
▶ 0:56:13There are some basic pillars of what a strong security program looks like. Identity and access management, the tools and infrastructure to make sure they can look at their network and really log events that are happening, incident preparedness, risk and governance, and then their thirdparty vendor risk which has been articulated quite a bit and how to manage that.
▶ 0:56:33But one of the key performance measures that I look to when I'm talking with SISO's chief information security officers and others who have to secure these networks and are in charge of that edge of American security and competitiveness is their time to detect malicious activity and their time to respond. And it's those two measures that are key that we drive across critical industries like this so that we aren't caught with multi-year major operations that have the scale and impact like Salt Typhoon. Okay.
▶ 0:57:01Now you mentioned SISA and um obviously it provides crucial support also to the states and localities at the front lines for protecting critical infrastructure. Now what does this administration risk when it downsizes our federal cyber workforce that puts more burdens on states and local Cyber security is inherently a federal issue. The internet doesn't know state boundaries to put it mildly, right?
▶ 0:57:29And what SISA does and what other federal cyber security and national cyber security agencies do is they're able to articulate the risk to networks out in states, critical infrastructure providers, energy companies, banks, and get that information out to them so that they can employ it in their security programs. We have to take a federal approach to do this because inherently the threat is one that goes after us at a national level. Okay.
▶ 0:57:54Now, I think it was mentioned before too, but as more smart devices known as the internet of things are adopted into Americans homes. We need to help consumers make informed choices and decisions about the technology products that they purchase. Those interconnected smart devices can be an entry point also for cyber attacks. That's why supported steps like the FCC's US Cyber Trust Mark, a labeling program that identifies trustworthy and secure products in the marketplace.
▶ 0:58:24Miss Galante, how do voluntary measures like this instill trust and security in our technologies? I like the cyber trust mark program a lot. If people haven't seen it yet, it is a sticker. It's a badge and a QR code. And what it is is it's a shorthand to the consumer that says the product that you're buying here has a security management program behind it. It's going to get patched. There's going to be data protection, some of the key standards that we want behind that product.
▶ 0:58:52It's a little bit like when you turn your microwave around and there's that metallic sticker that you can't pull off that says you can plug this in and you're not going to get shocked. It's the same concept for interconnected devices. I think it should catch on. Okay, great. And um talking more about standards, I've long championed that the US leadership and global technology standards and uh that the next generation reflect only American values including open markets, transparency and democracy. Mr. Stalin, you mentioned SCS 901.
▶ 0:59:22It's a supply chain security standard for information and communications technology industry. How can this and other standards ensure a communications infrastructure is resilient against attacks from malicious actors? Yes. 9001 uses uh looking at not only the the vendor or the supplier of the equipment. Is it a trusted vendor? But it looks at the hardware and the software used in a product. uh every single product out there uses open source software for example. Yeah.
▶ 0:59:51How do we trust that that open- source software is coming from an organization that can be trusted? Is there provenence that we can prove? Can we do things like incident management and move more quickly? We need to speak in one voice when it comes to cyber and supply chain security and SCS allows the ability for both uh public networks and private networks to do so all the way down to IoT devices like the FCC is working on with uh the cyber labeling program. Well, I I consider that very important.
▶ 1:00:20The standards that we set in our country for US leadership in particular because we understand that the um the actors the the unfortunate actors are against us are going to be uh going out there and doing their own thing. Um I want to talk more about Oh, I think I'm out of time already, right, Mr. Jared? Time flies. Follow up later. Okay. Thank you very Thank you. I'll now recognize um Dun Dr. Dunn uh from Florida for five minutes to ask your questions.
▶ 1:00:51Thank you very much, Mr. Chairman. Uh uh you know, I would say that Americans have every form of technology at their fingertips for broadband uh deployment, fiber optic cable, fixed wireless and particularly important where I live in rural Florida is satellite uh uh systems.
▶ 1:01:10Historically, our country's done very well They've done a stellar job in fact at building our telecom's infrastructure and and I think that under US leadership that industry is flourishing. Uh despite many challenges the the marketplace is providing responsive innovative uh capabilities for commercial use research intelligence and national security.
▶ 1:01:34But to sustain that dominance, we must invest in the infrastructure necessary to continue that rapid expansion in the future. That's just basic infrastructure investment. Accordingly, this week, Representative Carbajal and I are reintroducing the bipartisan bill securing the United States leadership in uh Space Act, which enables the taxexempt status of private bonds on FAA licensed spaceports.
▶ 1:02:04Pretty basic stuff. It's like, you know, highways and sea, you know, seapports and whatnot. And what makes uh this bill impactful is that it empowers the growth of the spaceport infrastructure that is so essential to nation's enterprise uh you know to be funded more by private capital than in fact by the taxpayers and this plays into the strengths of course of the US system in our competition with China.
▶ 1:02:33As a member of this committee for many years, I've continued to work on legislation to streamline and secure our telecoms networks. Last year, Congress passed and the president signed into law uh with my friend Daryl Darren Sto the launch communications act that addresses the satellite launch uh communications spectrum. So, very outdated regulations at the FCC and they're currently implementing those now. this year.
▶ 1:03:00We'll continue to prioritize that uh all those efforts. Mr. Mr. Stroop, um uh do you believe that the tax exempt bonding rights for our uh our spaceports uh can help secure US leadership in uh in space and space infrastructure uh and engage the private markets? Does that does that help the taxpayers?
▶ 1:03:25Yes, our industry is most dependent upon spaceports and having access to as many spaceports as possible uh will benefit the industry. So while uh SIA does not represent the spaceport industry, our members are very dependent upon them. So I'm from Florida. We we have at least as many spaceports as most states and I'm very pleased with that. I sat on the board of Space Florida for a number of years. I I I'm I'm really really proud of uh the efforts in in our in our state on that.
▶ 1:03:54Um again, Mr. Street, you mentioned your testimony, access to sufficient spectrum resources is necessary to secure infrastructure. Can you briefly elaborate on this and share what kind of spectrum authorities you think would make the most sense right now for space industry? Yes, our industry is growing substantially.
▶ 1:04:23That's just to give you a sense of industry. We provide a wide range of services and we're increasingly share spectrum with other industries wireless industry industry satellite industry for a long time as well.
▶ 1:04:46But there is a contin77 over 85% of the issues that are on the agenda many of them
▶ 1:05:24access the United States. Well, thank you for that. I I spent a lot of time speak on focusing on space, but let's let's be honest, there's a lot of information flowing through the fiber optic cables and in a few seconds left of us, I'm hoping Mr. Stellin can can address the resilience and of the cables, undersea cables. What can we do to protect these things? We've really nothing but interruptions of these cables lately.
▶ 1:05:51Seems like anybody with a motorboat can interfere. You can you give us some confidence? Yeah. Well, um first of all, it's uh there are somewhere in the range of 600 cable undersea cable systems around the globe. 1,700 landing points. More landing points will help for sure. Uh more repair ships very much needed. Uh if you if it takes a month or two to find a repair ship, you have a problem. So we need to rebuild the the whole shipping side of things.
▶ 1:06:21Well, thank you very much, Mr. Chairman. My time is uh has elapsed, but I would love to talk to these people for the rest of the day. Thank you. I thank the gentleman for yielding. Now I'll turn it over to uh ranking member Palone for five minutes for your questioning. Thank you, Mr. Chairman. As I mentioned earlier, it's critically important that our country's telecommunication networks have the capabilities to effectively defend against foreign adversaries and other bad actors.
▶ 1:06:50But given the Trump administration's mishandling of sensitive sensitive information on Signal and Musk and DOA's access to se sensitive government information, it's clear that it's not just our telecommunications infrastructure that needs updated security standards and protocols.
▶ 1:07:08So I want to ask um Miss Galante, are Signal, Gmail, and other commercial services the proper channels and tools for government officials to use in making national security National security decisions and deliberations from our adversaries standpoint are intelligence gold. This is what they seek out and it's for this reason that we've got classified communications channels. Okay.
▶ 1:07:34Now, under I have a bill, bipartisan bill, the Secure and Trusted Communications Networks Act, and the FCC must place communications equipment or services that have been deemed a national security threat on its covered list, which effectively removes the equipment or services from our country's supply chain.
▶ 1:07:55So again, Miss Galante, will broadening the types of communications technology that can be placed on the FCC's covered list help us better secure our country's telecommunications networks and data from foreign adversaries? It will help us. The FCC's covered list goes a long way to give predictability and clarity about what products are insecure and what technologies shouldn't be used in our telecommunications technology. Okay.
▶ 1:08:22Um, and I, you know, the frequency of cyber attacks on our telecommunications networks, I think, shines a bright spotlight on the amount of personal data that these networks carry day in and day out. And it's imperative that our networks have strong security protocols uh in place so that our data is not an easy target for our foreign adversaries. But let me issue again uh or let let me issue this question.
▶ 1:08:46What types of capabilities should be built into our telecommunications networks to ensure they can successfully protect our data from the uh increasingly sophisticated cyber attacks and espionage we see from foreign adversaries. And if if if you if there's time I'd ask the others the same Telecommunications networks are incredibly complex. They're dealing with a stack of technologies that ranges from literally the ground up.
▶ 1:09:14And these are tough to and they require really advanced security programs to do it the right way. Two of the measures that a secure program should be looking for though in how they perform, how the people and the tools and the team around this work is their time to detect malicious activity and their ability to respond to it. And the faster both of those things can happen, the more secure the program is going to be and the more resilient our entire sector will be. Okay.
▶ 1:09:41You know, I I I I don't want I wanted to ask others to comment on it, but I'm still not sure when I asked the first question about signal and email and you said that um you know uh I asked whether um you know those are commercial services or the proper channels for government officials to use in making national security decisions. What what was your response again? Classified channels are the right place for national security deliberations.
▶ 1:10:10And these are not these are not classified channels. They're okay. All right. Anyone else want to um comment on the types of capabilities that should be built into the networks? We still got another minute. Yes. Yes sir. Um we should look at the entire makeup of the vendor base. Uh it's one of the challenges we have around the world is as we try to bring Western technology to friendly countries.
▶ 1:10:33Uh we know that the Chinese will and and have for years worked their way in there by offering way underpriced product offering the ability to uh to fund the development and management of these networks and then they work really hard with the legislative branch of many countries around the world. We have an uphill battle. Uh and one of the challenges we have is as uh China has often sold products way under cost.
▶ 1:10:58uh it's put so much pricing pressure on western technology that R&D investment has gone way down. So the things we can do to help R&D rebuild in the United States would make a big difference. Anyone else want to comment? Mr. Ricky member, I think the other uh important thing to keep in mind is that the government has a role to play here too. The government needs to partner tightly and collaborate with industry to defend against these threats. If we leave the private sector alone to defend against these threats, we will fail every time. These private sector companies are not in the business of defending against cyber threats.
▶ 1:11:28They're in the business of providing telecommunication services and capabilities to our citizens, to our allies, and to partners around the globe. And so, if they're going to do it effectively, the government has to take the information it knows about and has. For example, in the Salt Typhoon case, it turns out we found out 5 days before the administration ended that we had detected the Salt Typhoon attackers on US government networks, hadn't realized who they were, and hadn't shared that information. It's almost like before 911 where we knew the attackers, some of the terrorists were in Malaysia in Koala Lumpur.
▶ 1:11:57The CIA saw them there and then didn't bother to tell the FBI. That is a massive, massive failure of the government to do its job to share information with industry, help industry protect itself, and take accountability for the fact that we had that information, didn't know what to do with it. Thank you. Thank you, Mr. Chairman. I thank the gentleman for yielding. And now I'll recognize myself for five minutes for questioning. I want to thank our w expert witnesses uh for joining us here today.
▶ 1:12:27As home to the Arbory Cyber Command in Augusta, Georgia, my district is a hub for cyber security expertise and we hear signific significant concerns about federal agency roles and regulatory burdens hindering our ability to secure critical infrastructure. Mr. Jeffer Jeffer uh cyber security uh And you've already started to comment on this.
▶ 1:12:50Cyber security professionals in my district highlight confusion over confusion over which agency CISA the Department of Defense FCC or others has primary jurisdiction over securing critical infrastructure w which would include telecommunications satellites and undersea cables. This lack of clarity can impede responses to threats like you mentioned the salt typhoon brereeach. Mr.
▶ 1:13:15Jeffrey, h how how are the roles of CISA, DoD, and FCC currently defined and what steps can reduce confusion to enhance coordination and protect our infrastructure? Well, uh, thanks, Mr. Vice Chairman. I mean, the challenge here is that there is no one agency in the government today responsible for defending our entire global cyber infrastructure, the US's, which we've built around the globe. And that the problem is that if you expect private industry to do it, it won't succeed.
▶ 1:13:44If you don't tacate the government and give them the resources and the authorities to do it, it won't succeed. Now, in theory, we've said to US Cyber Command, it's your job to defend the infrastructure against nation states. But of course, US Cyber Command isn't resourced, doesn't authorities, and I'm not sure there's a consensus amongst uh Congress and the administration about whether the Department of Defense should do that defense. And in the absence of that consensus, the only way in which we can have the government work effectively with industry is to share information at scale.
▶ 1:14:12We have legislation today, the cyber information sharing act that was passed in 2015, set to expire in the next in the next few months that needs to be reauthorized. But more importantly, we need actually incentivize the sharing information. We pass that authority, but we didn't provide the necessary regulatory and liability protections to encourage industry to actually share. And so their lawyers are telling them do the minimum amount necessary. You what you want to do is you want to line up boards of directors, you want to line up the lawyers, and you line up industry with government. Government wants information. It has information. Both need to share.
▶ 1:14:40neither are doing it effectively because the incentives aren't there. And the government says, "Well, we're not going to share our all class of information with industry." Well, if we're not going to do it, no one's going to do it. They're not going to know what the threat is. They're not going to defend well. And then we'll all be looking back and saying, "Why do they defend themselves better?" And we'll have no one to blame but ourselves. Thank you, sir. Uh the cyber incident reporting for critical infrastructure act aimed to streamline reporting to CISH.
▶ 1:15:04Yet stakeholders note persistent issues with duplicative requirements across other agencies including varying definitions and timelines. The very things that you've talking about uh inconsistent incident incident definitions like substantial loss versus potential adverse effects and a lack of reciprocity diverting resources from mitigating threats like those from the Chinese Communist Party. Uh Mr. Stroop and Mr. Stelling.
▶ 1:15:35Uh, how do these challenges impact the communication sector ability to secure infrastructure and what can the FCC's new council for national security do alongside CISA to harmonize reporting standardize definitions and establish reciprocity to strengthen resilience? Mr. Stru, thank you for the question.
▶ 1:15:58So most satellite systems are dual use and as a result many of the issues that we're talking about are addressed through our supply chain because for a long time um the security of supply chain has been important. There's a certification process that satellite companies need to go through in order to provide service to the US military.
▶ 1:16:16But I think that getting to the cyber security issue uh uh in terms of sharing information, I think that the key is that the points that have been made by uh other members of the panel today, ensuring that there's a means of sharing the threats uh giving companies an opportunity to address it and whether that's uh um done through SISA, the FCC, I think making sure that there is a single point uh where members of our industry and other industries have access to that information is key to being able to address them. Mr. down. Thank you, sir.
▶ 1:16:46Uh, yeah, I would agree. We have to speak in one voice. Um, we have to send clear messages across the country for on both the public and the private side. We have to send clear messages to our international partners that we speak in one voice. And then we have to use things like benchmarking and continuous improvement to to measure how we're doing and how we do things like incident reporting. How do we do more quickly deal with problems like that to more quickly identify these incidences and and to fix them? Good.
▶ 1:17:15Uh well, I hear that we've got to centralize this issue uh and and we've got multiple agencies involved. So, uh thank you so much for uh sharing your expertise with us. Uh now, let's see who do we go to next? Representative Representative Sto, I yield to you five minutes for questioning. Thank you, Chairman.
▶ 1:17:39From satellites to cell phones, Wi-Fi to the internet, there's so much information, communications, commerce, learning, tele health, streaming, and other daily activities that go through our telecommunications system. We saw with Solar Wind, Salt Typhoon, and other cyber attacks. These were a huge warning across multiple administrations. uh and we're going to continue to work with you all on resiliency.
▶ 1:18:06Unfortunately, we still can't uh protect ourselves from stupidity as we see with the signal gate scandal. Um but there have been efforts uh under the chips act with $3 billion for RIP and replace to help with uh both US telecom manufacturing, microchip manufacturing and uh trying to replace a lot of the this uh these this equipment made in China that we have no faith in anymore.
▶ 1:18:34Uh US telecom equipment will strengthen our network against attacks. Mr. Stelling, we we've seen some increase in manufacturing in the US for telecom equipment and microchips. How's it going so far and what can we do to improve it? Uh I would say at at best it's going okay. Uh we have a long way to go. Uh as I mentioned before, this is a strategic multi-deade change that has to occur. We have to build the whole ecosystem for the supply chain for the ICT networks.
▶ 1:19:05uh fundamentally 50 to 60% of the cost of every uh active device is the chip itself and those chips are not made in the United States. Uh and if we can solve that problem, we'll go a long way to having much more success in rebuilding our infrastructure uh making sure that it's secure and also adding jobs.
▶ 1:19:24And since you're from Florida, sir, I want to mention that uh uh we recently started a program called Broadband Nation, which is a program to attract, train, and deliver the next generation of talent in the broadband space from cyber security to installers. And the state of Florida is the first to sign up with us. We're working with uh Miami Dade College, uh the Secretary of Commerce in Florida, uh to help push this across your state. Well, we're thrilled about that.
▶ 1:19:50I realize as we're doing US and manufacturing, there's still going to be some inputs from abroad, whether it's metals or other things. How uh are tariffs affecting our ability to um bring back and manufacture telecom equipment? Tariffs will only raise prices at the end of the day, that's the problem. Uh fundamentally, uh it makes sense to find ways to bring things back to the US, but if over a long period of time, uh those prices are raised, fewer networks are going to get built, and that's a problem.
▶ 1:20:18And how would a potential recession affect investment to bring more manufacturing back? We saw a negative first quarter, first one since 2022. Um, do you see investments slowing or are things moving along steadily? Haven't seen investments slowing yet, but fundamentally that's an issue. As a as somebody that's run a publicly traded company, I recognize that capex is critical and that's one of the first things that you want to squeeze is capex. Mr. Stup, we're proud to have Cape Canaveral in Central Florida. You know, my colleague Dr.
▶ 1:20:48Dunn mentioned already the launch communications act that we passed last term. We've seen 34 launches so far, mostly for satellites, right? Uh what are some of the strengths and advantages of satellite internet against cyber Thank you for the the question. And I think that one of the key strengths of the industry is the uh the number of companies that are providing service and the ability to be able to provide service from from multiple paths.
▶ 1:21:16Um most satellite companies have multiple satellites whether they're in geo or or non- geo orbits. Um and as a result if there's an attack on one of them one of the satellites there's an ability to be able to provide service from from another satellite. In many cases, companies are also have also deployed multi-orbit capabilities. Um, so they're bringing to to bear um service from both geo and non-jeo systems. And of course, it's not just the satellites that are key in making this work.
▶ 1:21:44Terminals that operate across multiple operate on multiple operators, multiple frequencies are some of the means that the industry has to be able to address those kinds of of attacks on their systems. So you mentioned that hive technology where if you take out one satellite, the rest still operate as a network. Uh we we've seen that um be a strength so far in some areas like in Ukraine. Um Miss Galante, uh we we saw the review board for cyber safety uh terminated before the end of the salt typhoon investigation.
▶ 1:22:13What effect does this have on learning from what happened with that cyber hack? The cyber safety re the cyber safety review board functioned like the national transportation safety board and then it root caused major cyber security incidents to figure out what went wrong and then build a path towards a better remediation plan for others to learn from.
▶ 1:22:31Cutting off that investigation into assault typhoon early really limits the telco sectors ability to understand from all the different sides of the house the intelligence side law enforcement and then victim networks how we can improve. So it it really short changes our national security to not have that investigative board available to learn from. Thank you. My time's expired. Uh thank you Mr. Sto. Appreciate your line of questioning.
▶ 1:23:00Uh he yields back and we recognize Representative Lada for five minutes of questions. Well well thank you very much Mr. Chairman and thanks very much for our witnesses for appearing today. Mr. Stalin we know that communist Chinese flag vessels have been suspected in cutting undersea cables across the uh the globe but particularly those connected to Taiwan.
▶ 1:23:23Taiwan has reported five cases of seabed cable damage this year alone compared with just three each in 2023 and 24. Is the answer to this growing problem more cable redundancy or are there other technologies that can provide more reliable communications in the case of a coordinated attack? Uh thank you for that question sir. The the answer is more redundancy.
▶ 1:23:48We're not going to and find a way to find a more efficient and bandwidth capable technology than fiber optics. So there are 600 or so cable systems, subc cable systems in operation today. Uh on average 200 have a are damaged per year. Uh and the great majority of those are mother nature or an anchor or something like that that's just an accident. But more and more, as you say, are coming from nefarious actors. It could be the Taiwan Strait.
▶ 1:24:17It could be the Baltic Sea where we've seen uh those in the past six months or or 12 months. Uh and it takes a long time to first find the problem, where is the break and then fix it. And as I mentioned earlier, we don't have enough ships out there to fix uh one of the three biggest uh repair and installation companies is uh called WN Technologies, which used to be called Huawei Marine Network Technologies.
▶ 1:24:43So they're the ones that drive a lot of this activity uh in the far east. In the US we have subcom uh and and uh in Japan we have NEC as other examples for for friendly countries. But this is a big issue that needs to be addressed. More redundancy. Yes. But we've got to find ways to more quickly repair issues. Just a quick follow up what you just said. How long does it take to usually fix a cable? Uh a subcable depending on where it is. If it's close to the shore, it's a lot quicker than if it's in the middle of the ocean.
▶ 1:25:11Um, so it could take upwards of two months. Thank you. Yeah, let me follow up. Um, you know, I've been really impressed by the technological innovation that's happened the last several years as it relates to the internet and cellular connectivity using satellites. Are satellites at a point that they can provide backup for large amounts of data processing in case of widespread physical cable outage? Just Yeah, good followup. Sure.
▶ 1:25:39Um satellites can certainly help and support but the bandwidth capability and the latency uh low latency of fiber cables uh can't be replaced. Okay. Thank you. And I hope I pronounced is it Galant? Galante. Galante. I'm sorry.
▶ 1:25:54Uh uh, Miss Galante, I'm always I've really been alarmed when a business in my district says that they've had their cyber security handled because and hit because of bad actors and they're always changing taxes and becoming more increasingly skilled at targeting our networks. As soon as you get one thing done, you find out somebody's figured a way around it.
▶ 1:26:15Many small businesses and particularly small telecommunication companies in my district across the country are unlikely to have in-house personnel, let alone teams of professionals with cyber security expertise. You say in your written testimony that we can't regulate our way to securing our digital networks. So what role can the federal government play in ensuring that the private sector has those tools to secure our communications infrastructure?
▶ 1:26:40I think we need a focused effort with telco security companies and that's really a range of different types of companies to focus on what the goals need to be for their specific technology stacks and systems. We've done this in a large way in the banking sector and also in the energy sector. In both of those areas, there's a level of predictability and an increased ability to find malicious activity and remediate it quickly.
▶ 1:27:04Those performance measures are what we need to implement and think through and make real for implementation with these variety of uh companies in the telco sector. Thank you. Um Mr. Ding, going back to you, I have legislation on the routers act which passed the house earlier this week to study the threat of certain routers built by our adversaries. What should we be looking at to make uh Americanmade or routers made by our allies a better choice?
▶ 1:27:33We need to eliminate those that are bad choices first of all and we have to do quick evaluations of those companies uh and their history and the products that they develop and remove those bad choices from the consumer. Uh probably uh there's an investigation underway right now uh for a company that is probably a bad choice but is the most frequently used home router out there. Well, thank you very much, Mr. Chairman. and uh we have a lot of work to do in this area and I want to thank our witnesses for appearing today and I yield back the balance of my time.
▶ 1:28:03We thank the chairman for his comments and we represent the gentle lady from Michigan, Representative Dinkle. Thank you, Mr. Chair. This committee has led bipartisan efforts to secure our communications network, strengthen resiliency, and work closely with both federal agencies and industry. We know threats are evolving and that we've got to continue to adapt. And now is the time to address additional risks across our communications technology networks.
▶ 1:28:30From vulnerabilities in our global supply chains and weaknesses in domestic critical infrastructure to the risks emerging from new technologies now maintain uh mainstream in sectors like the automotive industry. To meet this moment, we must boost competition, continue to invest in domestic innovation and manufacturing, and ensure the integrity of systems Americans rely on daily from wireless networks broad to broadband and cloud infrastructure.
▶ 1:28:59We're also seeing growing national security concerns from companies like BYD, a leading Chinese EV manufacturer, and Deep Seek, an emerging Chinese AI firm, raising alarms about how data is collected, transmitted, and exploited. We have to be proactive in addressing this. We've got to secure our critical infrastructure to ensure we outpace those who seek to undermine our national security and exploit our vulnerabilities.
▶ 1:29:29And we must also ensure that our government officials are using basic security protocols for national security matters as we've discussed instead of commercial apps like Signal and Gmail. Um but um Miss Galante, as all of you know, China doesn't play by the rules, especially in the auto sector.
▶ 1:29:50China's propped up electric vehicle and battery manufacturers with state subsidies subsidies, allowing them to undercut global competitors, flood international markets, and distort This not only threatens American jobs and undercuts domestic manufacturing, but it also raises serious concerns about the security and the integrity of vehicles as connected vehicles collect vast amounts of sensitive personal and location data as well as the autonomous
▶ 1:30:20vehicles do that they're testing here. How can we ensure that foreign adversaries, especially those with ties to China, are not exploiting these technologies to access and misuse American data? Thank you, Congresswoman Dingle. Really appreciate your question on connected vehicle security.
▶ 1:30:38This is a critical area and you can't think of one where there's more of a combination of data privacy issues, potentially GPS and other location uh security needs in addition to all of the different metrics that are used and will increasingly be used to have these autonomous vehicles and connected vehicles work. Security is critical here and we can't tack it on after the fact. We've got to build this in in what we call in the security industry by design. Security by design.
▶ 1:31:06And one of the engineering principles that has to be at the center of how Detroit and others are focused on security in this area is called dev sec ops development security operations. Right? We need to make sure that we've got the minds across companies and across this sector who are focused on the security implementations working together on this. And the security concerns need to outweigh some of the competitive concerns here because a secure auto industry is good for America and it's good for our allies as well.
▶ 1:31:35We have to be the leaders on that and we need to take it from the design level up. Well, I agree. As you know, I'm working with a group. I'm got I'm going to go to a 5G question for Mr. Stella very quickly. Can you speak to the importance of beginning now to plan to invest and lead in the next generation of advanced wireless technologies? Thank you for that question. Uh typically these uh advancements take a decade.
▶ 1:32:01So we are starting to work on 6G even though 5G has just been rolled out over the past couple years. One of the challenges is we need 5G to be financially successful or the CFOs at the big ISPs are not going to want to invest in 6G. So it's really critical that these technologies are successful. Uh it takes a long time to make them strong. But uh yeah we are working now on things like 6G that will affect everything from the home to the business uh to uh automated cars.
▶ 1:32:30So in 40 seconds, what specific steps should Congress take to better align its effort efforts to help you and ensure US leadership stays? R&D tax credits. Let's start there. Uh let's find ways to uh increase uh the investment in the United States so that we can spend more money in R&D. That innovation is something that's been a hallmark of our industry. Look at how your price per uh megabit has come down over the past 10 or 20 years as compared to your cost per kilowatt hours.
▶ 1:33:00Uh we've gone down by 95% because of innovation. Thank you, Mr. Chair, and I yield back. Thank you, Representative Dingle. We now give five minutes to Rep. Dr. John Joyce from Pennsylvania. Thank you, Mr. Chairman, and Ranking Member Matsui for holding today's hearing. Thank you also to our witnesses for agreeing to be present with us. We all know it's no secret that we are living in a world where our communications infrastructure is increasingly at risk.
▶ 1:33:28Between cyber attacks from foreign entities such as the Chinese Communist Party to targeted network infiltration, it is more important than ever that the United States is more vigilant and prepared to defend itself against these multiple bad actors. That is why along with representative Susie Lee that I HR2061, the information and communication technology strategy act.
▶ 1:33:56This important legislation will impour will develop that the department of commerce is consistently updating Congress on what needs to be done to adequately secure our communications systems through our supply chains. This will be one step in a long list of necessary actions that the US government needs to be taking to adequately protect our critical networks. Mr.
▶ 1:34:20Jaffer, how would you evaluate the readiness of our current telecommunication systems against these identifiable and well-known bad actors? And I will elicit them. Specifically, how are we prepared when it comes to China, when it comes to Iran, and when it comes to North Korea, who we recognize are repeat offenders? Well, you know, uh uh Dr. Joyce, we are very we're illprepared. Our telecommunication infrastructure is vulnerable. We know it.
▶ 1:34:50Our government is not effective at deterring bad activity by our adversaries. Um and we're not working together collaboratively to defend that piece of critical infrastructure. There are other pieces of critical infrastructure as well that we're not good at defending, but that's one area where we need to work more effectively as a government and industry together. There are a few things we could do in the immediate term to address some of these issues. One, to your point about supply chains. We know today that we rely massively on China for things like semiconductors, critical minerals.
▶ 1:35:18We're seeing it today in the in the tariff wars where China's cutting us off for critical minerals. We need to develop a domestic and allied capability to to to refine to extract and refine those. We have critical minerals here in the United States. We have the ability to obtain them for our allies and partners abroad. We simply send 96% upwards of that material in in key areas over to China to refine. It makes no sense. The same is true with semiconductors. We see the situation in Taiwan.
▶ 1:35:45If we're going to survive on on our current technology basis, we've got to be able to defend Taiwan. China's threatening it. It's not clear that if today China were to go across the Taiwan Straits that the United States would do anything or that we could get there in time to effectively defend our friends in Taiwan. Mr. Jaffer, can you help me understand a different issue? How has Huawei become the global behemoth that it is today?
▶ 1:36:08And what more do we need to do to counter Huawei and the spread of untrusted telecommunications equipment, especially when we see allies and partners using equipment from Huawei? Dr. Joyce, it's it's a great question. The way they've obtained this advantage is they've done it on the backs of stolen intellectual property from American companies, including Cisco. They've built routers that look a lot like a Cisco router, because they stole that technology. Now, they've improved on it. They've modified it over time, but that's where they stole it from in the beginning.
▶ 1:36:37On top of that, they've depended on low interest loans and no interest grants from the Chinese government. The Chinese government goes around the globe subsidizing their purchases, giving countries other stuff, other benefits for taking Huawei equipment. And so we've got to compete in a world in which China is acting non-economically to put their surveillance gear in place in allied countries and countries around the globe. Not just allies, but partners as well. We can't do that effectively until we partner with our friends who make telecommunications equipment.
▶ 1:37:05We don't make a ton of of of of handsets. We make a lot of routers. We make a lot of core network gear. Then we got to get that into those networks. We did rip and replace at home. That's amazing. That's the right thing to do. We've got to do global rip and replace. And that means putting some of our money and incentivizing our manufacturers and giving them the capabilities to go abroad and deliver that capabilities to our friends the way the Chinese are doing against us with Huawei and ZTE. Mr. Stalin, in the moments that are remaining, first of all, thank you for your leadership and your advocacy at SIA.
▶ 1:37:35But what specific actions have your member organizations taken to protect themselves against the attacks and strengthen the supply chain? Yeah. So, uh we are and our members are very much focused on uh the processes that are used to develop new products. Uh it is as you mentioned a minute ago a big challenge with companies companies like Huawei that undercut us financially often selling below cost just to win the business and to hang on to it.
▶ 1:38:02We need to rebuild our infrastructure here in the US. We need to rebuild our vendor base in the US and it starts with the ICT space specifically uh with semiconductors. And I thank you and I think you I and President Trump all recognize that building that infrastructure that supply chain right here in the US is is important and actually paramount for our success. I thank all of our witnesses for being with us here today. And Mr. Chair, I yield. Gentleman yields.
▶ 1:38:31The chair now recognizes the gentle lady from California, Miss Baragon. Uh thank you, Mr. Chairman, um we just heard that it's important to build the infrastructure here, chips made in the US, develop a domestic capability. I've kind of heard this. Um Mr. Style, you brought this up. Um and this hearing, by the way, is called uh securing the future of communications infrastructure. If we repeal chips, if we repeal the chips act, would that be helpful?
▶ 1:39:01No. Okay. Why would not be helpful? It would not be helpful because we need more capital investment in the United States. It needs to be a strategic investment. Uh I I I won't address the some of the specifics of the chips act, but fundamentally and strategically it is critical that these skills be brought back to the United States as quickly as possible. Well, thank you. I also disagree with the president that we should repeal and end chips act.
▶ 1:39:26Um, Miss Galante, in 2017, the San Pedro Bay port complex, the busiest in the nation and located in my district in Southern California, experienced a major ransomware attack that forced the shipping company MK to halt port operations for several days and ultimately cost the company over $300 million. This cyber attack prompted the port to establish a cyber resilience center which monitors the port's technology environment and now fans off 80 million cyber attacks per month.
▶ 1:39:56Uh, Miss Galante, from a national security standpoint, how vulnerable are ports to cyber attacks from foreign adversaries and other bad actors, especially if cyber security has not been prioritized in these sectors? Port security is national security and this area and the technology underneath of it is incredibly reliant on digital technology and ever more so each year. We've also seen you mentioned a recent ransomware attack. There's been a variety of targeting at ports in the US but also globally.
▶ 1:40:24We have to up cyber security in this space. Last February there was an EO on maritime cyber security. It put $20 billion into this and I think that was an important investment and it gave the Coast Guard additional authorities in responsibilities in cyber security. We have to take port security seriously. Uh thank you. Uh cyber attacks often also hit marginalized communities the hardest with disruptions to hospitals, schools and public uh services and communities of color that have already uh seen less resources and support.
▶ 1:40:55In fact, people of color have a 12% greater chance of experiencing some sort of financial damage resulting from a cyber crime incident or and are 6% more likely to have their identity stolen. Miss Galante, what steps um should Congress take to ensure our national cyber security strategy prioritizes the protection of these vulnerable communities? You mentioned two sectors specifically, health care and education and schools. These areas have been really hard hit by ransomware attacks over the last few years.
▶ 1:41:25And one of the reasons is because their security posture is incredibly weak. Schools don't have the funding to put in place the types of security measures that the banks, for example, do. We need to find some middle ground that makes these targets more secure. The other piece here that we haven't talked about, but is an enormous problem across the country are cyber scams. I bet everyone in this room has gotten some text saying an errant Amazon package is headed their way or double click or message me back. I have a great offer for you. Um, even love scams.
▶ 1:41:55This is a real epidemic that we have here. And the the term in the cyber security community is called pig butchering. What they'll do is use social engineering, use a conversation to aggregate and get people to put their funds, sometimes student loan debt, other places where they have money and exposure, um, and are really looking for a way to make money and get out of a bad situation, and they'll go and invest it in a fake crypto scheme. A lot of these criminals behind this activity are in Southeast Asia. They're in Eastern Europe, and they're profiting from it.
▶ 1:42:25We need more exposure, and we need to shine a light on these cyber scams and what they're doing to everyday Americans. Great. Thank you, Mr. Mr. Jaffer. Um, when I got to Congress, I had two phones. One's my personal phone and one's a governmentissued phone. If I'm going to have a conversation with somebody on one of these phones that has classified information, which one should I use? Neither one. Okay. But but this one has signal on it. Are you telling me that signal I shouldn't be having conver classified conversations on signal?
▶ 1:42:55No. As as Miss Galante correctly laid out, we have systems for classified communications. today where the only places you have classified communications. The problem of course is those devices particularly if you're talking about TSSCI data are in skiffs right there. You can't have classified communications outside of a skiff at the TSSCI level. So if you want to communicate about an ongoing activity, you've got to figure out a way to do it. Signal is not a good way to do it.
▶ 1:43:18At the same time, if we don't give our government officials capable ways of communicating on the fly, the reality is everyone expects instantaneous communication today. That's just the world we live in. And so if you're a government official, you're in a tough position of saying, "Do I have to go to a skiff? How do I do that?" Using signal is not the right answer. But we've got to give our our our our senior leaders and our government officials a way to communicate that works on the fly on the run that doesn't force them to go into a room and hide out there.
▶ 1:43:45Otherwise, they'll never use it and they'll find workarounds and then we'll have bad situations where they're doing having communication over systems that are not they're not authorized to have them over. Thank you. You would think the Secretary of the Department of Defense would know that. I yield back. Gentle lady yields. The chair now recognizes the gentleman from Florida, Mr. Bill Rockus. Thank you. Uh I appreciate very much. I thank the witnesses for their testimony today. I want to start off with Mr. uh Stalin.
▶ 1:44:10Uh in your written testimony, you mentioned your organization developed the SCS 901 supply chain security standard. I'm a big uh proponent for uh industry-led standards generally but of course there has to be uh something in it for the participants to work.
▶ 1:44:32What fundamental um what fundamental elements does a company's product have to show to receive a uh certific certification under your system and what benefits result from achieving certification? Thank you for that question. Uh yeah, the the benefits are tremendous in that you can verify trust and you can prove that your product, hardware, software, as well as the company itself is a trusted supplier.
▶ 1:45:00And a a service provider or a government or a a critical network operator is going to want to buy from companies that have proven that their products are trusted. And then we use continuous improvement to constantly upgrade the processes. We don't tell a company through the standard how they develop a product. They just have to have certain processes and controls in place and verify that those are there. Thank you very much. Uh Mr.
▶ 1:45:29Jaffer, uh when talking about the the salt typhoon, much is said about how data political figures and corporations were compromised and that the threats that can pose to national security and business interests. However, less is said about how the privacy and data for of everyday Americans was compromised and is impacted.
▶ 1:45:54Why should the uh the average American be concerned about the salt typhoon attacks on their own data and what threats does China pose to them by having this individual data? Well, Congressman Bill Rakis, it's a great question. Um the challenge that we have today is that the Chinese deeply infiltrated our telecommunications networks. That means they had access to massive amounts of metadata of ordinary Americans.
▶ 1:46:20The communications that you and I have a phone call the the date time and duration of that phone call potentially the same date time and duration of emails uh that we that we engage in. And then they can choose who to go after. So we know they can get both metadata and content. So average Americans should be worried that they have all their metadata and then on top of that if the government if the Chinese government chooses to they can go collect the content of those communications as well. So it's a full spectrum capability. If we had that capability on Chinese networks, we would be thrilled.
▶ 1:46:47The Chinese achieved on our networks and yet today we're we're not focused on this problem, right? We're we're talking about signal chats and like and no doubt that's a big problem. But the real threat is that our entire telecommunication infrastructure was compromised and the US government has not responded to it, has not taken accountability for its own failures in detecting that threat and helping our telecommunication system defend it. Instead, our government has said, "We'll blame the telecommunication providers." Look, you you're never going to beat China if you're a private sector company. You've got to have the government's help.
▶ 1:47:16The government's not doing its job. This is never going to work. On top of that, the American people should also be worried about apps they have on their phones like Tik Tok, which collect massive amounts of data on them. People think, well, you know, these are just videos of kids and dogs and but the reality is that it's collecting a tremendous amount of information, not just who you're communicating with, but your voice as well numerous times. And it passed that data back to Chinese Communist Party. We have a law, the Congress passed a law in a bipartisan way.
▶ 1:47:43That law has yet to be implemented because we, you know, we made a political call that it's better to have Tik Tok running. We need to enforce the law that's in place today, Tik Tok should be banned in this country. And to the extent that American people have access to it, they should take it off their phones because they're voluntarily letting the Chinese government onto their devices to collect data on them. And when you combine that data with all the other information Chinese government has, that's going to allow them to conduct very significant intelligence and offensive operations against American citizens around the globe. That's a bad day for America.
▶ 1:48:12Thank you very much. I appreciate that. Yel back, Mr. Chairman. Gentleman yields. The chair now recognizes the gentleman from Louisiana, Mr. Carter. Thank you, Mr. Chairman, and thank you witnesses for being here today. Today's hearing addresses a matter of urgent national importance. I believe this is an important hearing and the security challenges we face are real and they can be met with bipartisan cooperation and I'm uh enthusiastic that this committee can do just that.
▶ 1:48:40Our telecommunications infrastructure faces daily threats from hostile foreign actors, cyber criminals, and even policy failures here at home that we just heard of moments ago. While adversaries like the Chinese Communist Party exploit vulnerabilities in our networks to spy, disrupt, and steal, the American people are also endangered by reckless behaviors within our own government.
▶ 1:49:04However, I must echo many of my colleagues comments who are concerned about recent security failures where senior defense officials using unofficial and unsecure messaging apps like Signal to share sensitive and classified information that should have been put in a skiff or some much more secure place for communications.
▶ 1:49:29We cannot have an important hearing like this and ignore irresponsible and dangerous lapses of judgment like this. As President Trump shifts responsibility for cyber defense to underfunded localities, dismantling national protections and disregarding bipartisan security legislation, our country is left more vulnerable. Meanwhile, Democrats are always willing to work across the aisle to modernize and secure our communications.
▶ 1:49:58My home state of Louisiana and the nation must have the resources necessary to make sure we have the capacity to update our networks and provide for expanded broadband access. Funding from bead programs have been vital have been a vital component to the state's initiative to reduce the digital divide.
▶ 1:50:18Yet in Louisiana, abruptly before just as we were completing our final stage, this administration froze those funds, negating all the work that had been done to advance this vital tool in our cyber sec cyber security. This was a problem passed and implemented by a bipartisan Congress, a program that was passed, implemented by a bipartisan Congress. I can't say that enough.
▶ 1:50:47Um, as we look forward to working with my colleagues across the aisle to pass the next generation 911 act, we must not allow our public safety telecommunications and telecom communicators and first responders to do their jobs with outdated equipment and technologies. It's a must. I've heard each of you speak. You've spoken eloquently on the needs that we as members of Congress can do and how we can listen better.
▶ 1:51:17Some things are political and most things are not. This clearly is one that should not be. Miss Galante, in your testimony, you discussed the salt typhoon attack that was unprecedented in scope. What risk are we taking by not moving to provide adequate funding to update the 911 network infrastructure around the country and to to a more IPbased technology like NG 911?
▶ 1:51:42The emergency response and 911 networks are incredibly critical to secure and we have to up the posture on these different organizations and provide the funding to do it. In fact, over the last several years, emergency response centers and 911 lines have been widely targeted, especially by ransomware groups who look to freeze those networks and then get a payment in return. We've seen this happen in Texas and Pennsylvania and Florida, and there's probably many unreported instances of this as well.
▶ 1:52:12This is critical. We don't want to be in manual dispatch mode when you have ambulances going out. Um, Mr. Um, Stellin Open RAN allows different parts of our network to be supplied by different equipment and software vendors. My understanding is this plug-and-play approach means that no one vendor has the lock on any component within the network. How does this plug-and-play approach promote competition among vendors while benefits to everyday consumers like we see with other emerging technologies?
▶ 1:52:43Thank you for that question. Yeah, open RAN is a excellent technology that allows various aspects of a wireless network uh to be purchased from various vendors. So, uh if you have common uh uh continuity between the various parts, if the connections between a RAND device and a base station router are opened up, it allows more competition. Uh so, can you leave me about six seconds? Go on. Yep.
▶ 1:53:10Uh the the last thing I would say there is uh it's a challenging game to build wireless networks. Thank you. Mr. Joffrey, you mentioned just a moment ago about Tik Tok and the fact that this bipartisan body passed a ban on dict on Tik Tok because of the massive breach and threat that it has for our cyber security. It has been extended 90 days and now gone beyond that 90 days. Every day that goes by that the Communist China party continues to collect their data.
▶ 1:53:39What kind of risk does that put our cyber security and our country in? Mr. Carter, uh, that allowing Tik Tok to remain on American phones creates a massive unprecedented risk to America's national security and the privacy and security of every single American citizen who has that who has that app on their phone. It should be rem people should voluntarily remove it immediately. The law should be enforced. There is no provision of the law that allows it to be extended beyond 90 days. There's one 90-day extension allowed by law.
▶ 1:54:07If in fact there's a deal in process, there's no provision for an IDA extension. The law should be being enforced today. And it's worth noting that even if the administration chooses to voluntarily not enforce the law against providers who allow Tik Tok to remain on their networks in the app stores and the like, those app providers and app store providers can be held liable in a future administration if uh it's within the statute of limitations.
▶ 1:54:32So everybody who's allowing to to remain on their devices should know that they are potentially exposing themselves of liability even if this administration chooses not to enforce the law in a future administration. Thank you. The gentleman's time is expired. The chair now recognizes the gentleman from Georgia, Mr. Carter. The other Carter from the right coast. Thank you all for being here. Appreciate it very much.
▶ 1:54:56Let's talk about subc cables because we know they're the uh backbone of the internet and we know that they're critical for for intercontinental communication and transactions. In fact, it's estimated that $10 trillion of financial transfers occur daily as a result of the C of the subc cables. 10 trillion dollar daily. That's that's a lot of money. That's a lot of transfers.
▶ 1:55:21Anybody who's read the news lately understands that um in the past six months, our adversaries have been using and targeting these cables and cutting them to to the economic um and national security of countries around the world. Obviously, an easy target. We understand that.
▶ 1:55:40Let's talk about the the the importance of redundancy because redundancy is extremely important and the resilience of our cables and the diversity of routes that are needed to ensure we limit our vulnerability whenever we're talking about these cables. I've been working to try to expedite the permitting process of of cables through the in the national marine sanctuaries with my bill HR261, the undersea cable protection act. And I think we need to think about ways to expedite the permitting process more generally too.
▶ 1:56:10We need to get more cables deployed as quickly as possible and ensure that we can meet the capacity needs. Mr. Stalin, I want to ask you, can you explain why re redundantness redundancy is so important for subc cables and how important it is from a national security perspective that that we don't have one single point of failure? Thank you for that question. Uh yeah, it's really critical that you don't have a single point of failure.
▶ 1:56:35Uh as I mentioned earlier, there are about 600 subc cables in operation today around the world, but something like 1,700 landing points. So as a cable gets closer to shore, it'll split and have multiple landing points. Uh we need to increase the number of cables, yes, but we also need to increase uh the number of landing points here in the United States. There may be 90 or so landing points in the United States. As you mentioned, permitting is a major issue.
▶ 1:57:02Uh, in some cases, it can take 400 days on average to get a permit and sometimes up to 900 days to get a permit. 900 days. 900 days. Uh, and so I I would argue that perhaps we uh we put NTIA, which is the president's adviser for telecom issues, in charge of team telecom instead of the DOJ. They look at it from a different perspective. DOJ absolutely should be on the committee, but perhaps not have the lead.
▶ 1:57:29So, I mentioned my bill HR261, which also aims to prohibit duplicate um permits that are currently being required by Noah and marine sanctuaries especially. I know that there are other areas where there are duplicate permitting reviews that are delaying the deployment of cables. Can you suggest u Mr. Stalin um where the committee might be able to work to streamline the permitting process for subc cables? Yeah, a great example might be a trusted partner framework.
▶ 1:57:59So if somebody has built a cable in the past and has proven themselves, should they have to go through every single step yet again or can they get fasttracked because they are have proven themselves to be a trusted partner? Good. Good. Excellent. The special use permits that are issued by Noah are are limited to a five-year license term, which is in stark contrast to the 25-year FCC license term.
▶ 1:58:25Well, can you speak to the justification of possibly having a 25-year license term for subse cables and the importance of a guaranteed 25-year term from an investment perspective? Yeah, typical payback uh for these subc cables might be seven years just to break even uh because you're talking hundreds of millions of dollars of investment upfront uh and then you have to go through this permitting process, it might be pulled out, etc.
▶ 1:58:49So by uh having a longer term uh uh license, it ensures that the company's going to make that investment. If you have seven years payback just to break even, that's a tough business decision. You know, I want to talk in general terms right now. And when I say general terms, I do mean general. I don't care what sector of our economy you're talking about. When people come into my offices, when businesses men come into my business people come into my office, it's always the same story.
▶ 1:59:18Whether it be uh whether it be communications, healthc care, energy, permitting, regulations, crushing us, crushing us. We've got to do something about this. Thank you'all all for being here. Very, very important. Now, I yield Gentleman yields. Uh the chair now recognizes the gentleman from New Jersey, Mr. Menendez. Thank you, Mr. Chairman. With international cyber security threats on the rise, we are facing increasing threats to our critical infrastructure and our economy.
▶ 1:59:46This past fall, the US experienced a devastating Chinese state sponsored attack on our telecommunications networks, stealing sensitive geoloccation data and targeting both Democratic and Republican- elected officials. We have heard throughout this hearing about bipartisan support for defending our country against cyber threats as we should.
▶ 2:00:04But the Trump administration has been weakening our country's cyber security defense system by slashing our cyber workforce and recklessly transmitting sensitive information, making it easier for our foreign adversaries to access Americans Americans most sensitive personal data. Uh, Miss Galante, just yes or no. Will the Trump administration dismantling CISA's cyber safety review board weaken collaborative security and intelligence work? Yes.
▶ 2:00:30Miss Galante, is a public private security ecosystem necessary for a strong collective defense and national security posture? Yes, it's critical. Mr. Jeffrey, you even said yourself private companies cannot compete with China alone. So, it seemed that a public private security ecosystem is essential for our national security. Would you agree with that? Yes or no? Absolutely. Thank you, Miss Galante.
▶ 2:00:52Going back to you, with China investing heavily in recruiting and training their cyber workforce, is it important to our national security for the US government to maintain a robust cyber workforce capable of defending against cyber attacks? Incredibly important. And not just maintain it, but we should be growing it. That's right. And doing everything we possibly can to get more people at community colleges, universities across the country to begin their their career in cyber security. Is that correct? Especially at this moment. Thank you.
▶ 2:01:17That's why I'm concerned about reports that Doge plans to cut 1,300 jobs from the cyber security workforce at SISA. In fact, even the former head of SISA under the first Trump administration said that he is outraged by these cuts. And I look forward to all my rep Republican colleagues joining me on a letter to the administration on this issue. Sticking with the theme of Doge cuts, I want to ask a few questions about the increasing number of reports that Doge has been leaking and weaponizing Americans personal data.
▶ 2:01:43It seems like every day we hear another report about the mishandling of our personal information, and this is just the first hundred days. From individuals with Russian IP addresses attempting to log into federal databases at the NLRB to Doge employees gaining access to networks that hold nuclear secrets. It has become clear that the Trump administration cannot be trusted with our personal information.
▶ 2:02:07Miss Galante, should Americans be concerned about reports that individuals with Russian IP addresses have attempted to log into a federal database that holds our personal information? Yes, IP addresses coming from Russia and network traffic coming from Russia is typically blocked. So, I'm surprised that this isn't already getting filtered There have also been reports that ICE is in the process of pulling together data from across federal agencies for a database they call the alien tracker in order to facilitate mass deportations.
▶ 2:02:38Miss Galante, just yes or no. Would a database that stores personal data from multiple agencies across the federal government such as the alien tracker be a targetrich environment for our foreign adversaries to attack? It would be a prime target. And once we accept that this administration is going to collect our personal information and put it into a database, whether it's for immigrants or any other group of Americans, it makes it highly susceptible to foreign attacks and puts all of our personal information at jeopardy.
▶ 2:03:08Would you agree with that? Highly valuable in our adversaries hands. So let's turn to AI quickly because I believe you would agree that AI has increased the sophistication of cyber attacks against targetri data sets. Yes. And can you just briefly explain empowering AI? There's two components as I understand it. Downstairs we're on the energy subcommittee talking about the energy that goes into AI. The other is the collecting and use of data. Is that correct? And can you speak to that? Sure.
▶ 2:03:36On the collecting and use of data, your processing powers are incredibly multiplied. Uh when you're looking at data sets, you're able to find patterns. You're able to find um different insights within large data sets. You're able to cross different modalities. This is the sort of way that highly um analytic endeavors are shorthanded and quickly given to our adversaries so that they can figure out how to make sense out of the noise in huge data sets and deploy them against stuff. And this goes back to why we originally banned Tik Tok. Is that correct?
▶ 2:04:06It's one of the reasons why Tik Tok could provide a powerful data set to our adversaries. So while AI is strengthening our enemy's cyber cyber capabilities, the Trump administration is leaving us vulnerable to attacks and weaponizing our data against us. This is not a Democrat or Republican issue. Any administration should prioritize protecting American sensitive data.
▶ 2:04:25And my Republican colleagues cannot pretend to take threats from foreign actors seriously while the Trump administration is slashing systems workforce and allowing unauthorized Doge employees to access Americans data on demand. This should be a bipartisan issue. It's one I am concerned about. I dealt with it on Homeland Security with Mr. Fluger. Sorry, the clock went off so I couldn't tell. Um that we should all be in lock step on. But that means we have to speak out when our when our administration, Democrat, Democrat or Republican, are failing us.
▶ 2:04:54This administration is failing us on this critical issue. Thank you. And I gentlemen yields. The chair now recognizes the real chair, Mr. Guthrie from Kentucky. Not the real chair, the other chair. So, hey, thanks a lot. I appreciate you guys being here. And uh first of Mr. Troop, I'm kind of concerned about satellite GPS. And I'm an old artilleryman. Old artillerymen. my day, you actually had to use binoculars and see where where a round landed and then you would call it back in and somebody use that literally a slide rule to calculate what the firing data was.
▶ 2:05:23You had to walk a you had to you had to bracket the target as you say or walk it on and and now this has been years so I don't even know what they do now but they shot shoot a shot they las the bur well they las the target sends a GPS code to the guns they shoot las the burst send a GPS code to the gun and the guns adjust and it's one round fire for effect now that depends on satellites so my big concern on satellite security I mean what just walk through the the the national security That's just
▶ 2:05:53shooting artillery. That's a whole lot of things that our satellites depend on in the civilian world, but also particularly our military world. I used to be the the proverbial lieutenant with a map. Now you get a eightdigit zip code, but grid code just by knowing what your watch tells you. So how do we do that? How do we fix the map? Mr. Sh, I guess I was looking I couldn't see you for Mr. Fluger's a tall guy. Sorry. So thank you for the question.
▶ 2:06:22So yeah, obviously adversaries can use location information. The key from our perspective is ensuring that um they're they are not subject to spoofing and to uh uh and to jamming. Um so the next generation of of GPS satellites have increased capabilities against them. Um and actually I think it's important to note that there is already a redundant uh system for for navigation system. Yeah. How do you make it redundant? for stuff like I know you got navigation, you've got I mean that's as simple as like low artillery.
▶ 2:06:51You're talking about two or three miles communication to each other. So So GPS is a free system provided by the government. There's also another system operating off of a constellation of satellites. There are also studies underway to look at other systems but uh certainly for the importance of of all of the uses whether it's military or or commercial we do have redundancy built into the system. Okay. Thank you. I was looking Mr. I was looking at you because I couldn't see Mr. uh Stroop. So I'll ask you this. I I mentioned my opening statement concern for subc cables.
▶ 2:07:22I mean gosh we have so much to protect. How what are the threat to subc cables and how can we be less have to be less susceptible to damage? Redundancy number one. Uh number two is having a repair system that's very quick and accurate meaning more ships a big shortage of ships more landing points adds redundancy in the United States. uh and and working with friendly governments to ensure the equipment they're using is trusted equipment. Okay, thanks.
▶ 2:07:50I'm not sure how much time I have, but uh Mr. uh Jeffer, the on rip and replace uh we we led that effort and when we're thinking about supply chains. What else do we need to do? Well, Mr. Chairman, I think certainly rip and replace going global is going to be critical, right? Because what's happening is our adversaries are putting this Huawei and ZTE and other Chinese gear in around the globe. So it's important to expand that broadly. Beyond that, we need to look at other core supply chains, semiconductors, critical minerals.
▶ 2:08:16We know the Chinese have a chokeold on these things, whether it's the processing critical minerals or the like. We need to get ahead of that and and get ourselves out of that. And then finally, we need to look at our entirety of the American supply chain. We realized during COVID that we have this dependency on China on pharmaceutical precursors, and yet we continue to maintain and allow ourselves to be addicted to Chinese goods of all sorts. It's one thing to buy t-shirts from China. It's a whole another to buy critical minerals, semiconductors and and and routing.
▶ 2:08:43Yeah, we had a hearing on uh on medical devices and and we found in the medical device because it was investigation oversight hearing they had uh connections to the URL at the University of Beijing in medical device just collecting massive amounts of data that Mr. M is talking about. So they use it in their AI and and just think about connected cars. Think about the havoc you could cause if instead of having a bunch of whether it's Teslas or Slates or whatever American EV manufacturer you want, Chevy, right?
▶ 2:09:10Ford, if we had a bunch of BYD cars running around the running around the United States, which is what, by the way, China wants us to do. Part of the reason they're cutting us off for Google Minerals is they want us to buy their electric cars so that those electric cars are connected. They can turn off when the time is right. Well, thanks. I'm not sure. I don't see the clock. I got a couple minutes. So um so I was in Europe was on a NATO meeting and we were talking about all the privacy we have to deal with privacy on this committee as well.
▶ 2:09:33So very interested in that and and my question was if you have a system of Huawei and ZTE so you worry about your privacy reg do you have privacy even if you regulate privacy doesn't it seem kind of inconsistent to say we're going to have all these privacy laws but then we're going to let all the Chinese equipment on in our country. It is astounding to watch the Europeans come after American companies because they're concerned about our privacy rules and our privacy regulations. And yet, one, they buy tremendous amounts of Chinese gear and are willing to give their privacy up to the Chinese.
▶ 2:10:01We also note that, you know, the Europeans have massive surveillance capabilities internally. They never talk about those. They talk about our industry and our companies. They don't talk about their own government surveillance capabilities. So I think it's really important to think look at the end of the day if you have to make a decision you could be like the Europeans and you can regulate first and innovate second or you could be like the Americans and innovate first. That's what we do. I think I didn't I can't see a clock but I think they just gave me me down. So thank you for your answers. I appreciate it very much. Thanks.
▶ 2:10:26The gentleman yields uh before we uh recognize the next person. We're going to try to reset this clock. There we go. There we go. The chair now recognizes the gentleman from Ohio, Mr. Lansman.
▶ 2:10:56Thank you, Mr. Chair. I appreciate all of you. So, um I want to get into the um uh the under cc cable issue and I we've talked about this extensively, rightfully so, and would ask uh Mr. Chair that uh uh for unanimous consent to enter into the record an article in Newsweek about China, China unveils game-changing weapon that could decide future wars.
▶ 2:11:26It just speaks to the fact that cyber security is national security, national security, cyber security. And the article goes into obviously everything that China is doing uh with their submarine technology to uh disrupt these cables. The vast majority of communications goes through this these cables. 95% of of everything that we do and your uh testimony today suggests there are several things that we have to do.
▶ 2:11:56One is the redundancy work. Uh two is the ships. Uh three I I'm assuming is part of the repair work, but uh the technologies, the sensors. I mean I and and maybe I'm jumping to a conclusion here that that doesn't exist, but I I assume that there are early detection work that we could be doing the or do we find out immediately when these things happen?
▶ 2:12:21So I I'm wondering if you can say a little bit more about or speak to existing legislation. I know Mr. Carter has a bill around permitting and that's something that I think we should all jump on uh and and support uh especially to your point about trusted uh partners who who are already doing this. Can you talk a little bit about the ships, what we would need to do, what does that look like?
▶ 2:12:47Yeah, there are certain ships that are designed to lay and repair cables. Um uh you can go to Baltimore Harbor and see them from time to time. Yeah, that's that's one place to to see them. And these these ships lay out the cable. They're specifically designed to do this. Finding the problem. Uh it can get isolated fairly quickly because once you lose a signal, you can identify where the problem is using something called an OTDR, optical time domain refleter. All right. So, that's something that you can use to find out where the problem is.
▶ 2:13:16But then you've got an issue of what are the seas like? Uh has the cable moved or uh shifted around because of tides and currents and things like that. Uh so adding more ships and having this be a uh a better and bigger industry is really important on top of ensuring that western technology and western companies take back the lead in this rather than How many ships do we have now? How many do we need?
▶ 2:13:45I I I can't answer specifically, but it's uh it's single digits to low maybe perhaps a dozen. Yeah. Go ahead, sir. If I may, since the issue of of redundancy for undersea fiber cables has come up, I want to stress the importance of satellite, the ability to be able to transition immediately.
▶ 2:14:03And while we certainly don't have the ability to carry all of the traffic uh as an example that is um uh carried into Taiwan, uh what they're doing, I think, is a good example of how we prepare for the potential of an undersea cut undersea cable cut. and that is putting in place arrangements with multiple satellite companies um obtaining the terminals so that they they do have true redundancy in real time.
▶ 2:14:26Yeah, I I think that makes sense and I think that the only point you were making sir is that it's it's not it's good for redundancy and for those moments of acute need but not necessarily an alternative um to the fiber optics the the want to get back to the ship. Sorry. Uh if if it's single digits, I mean, do we need twice as many? Um the more landing points, the more cables we have, definitely the more ships you need. Yeah, there's no doubt about it. Okay.
▶ 2:14:55Um so is there anything else? I mean, if we if if between Mr. Carter's bill, getting additional ships, the satellite partnerships that, you know, would would expand our capacity. Uh, is there anything missing in terms of Yeah, I would I would reiterate the permitting process needs to be sped up. Uh, and again, I think NTIA ought to have the lead. Oh, NTIA, that was the other piece. Um, NTIA. Got it. And and then I know that Mr.
▶ 2:15:23Carter's bill does the permitting, or at least that's sounds like it does. Uh, but the NTIA piece I'm not sure is we'll I'll look into that. I appreciate that. That makes sense. And I yield back. The gentleman yields. The chair now recognizes the gentleman from Ohio or Ohio. Idaho, Mr. Fulture. Thank you, Mr. Chairman. Uh, Mr.
▶ 2:15:49Stalen, I represent the great state of Idaho and there is a lot of rural space there and um a lot of the ISPs don't have a tremendous number of cyber security resources but yet they will often times be integrated with major infrastructure uh components whether it be a power plant or a grid or flood control or some of those major things and oftentimes can have an impact there without necessarily the infrastructure
▶ 2:16:19or the cyber security expertise to um uh fend off some of these new threats that are on the way. I'd like to get any suggestions or comments from you on how CES might be a resource for that or other sources of accounts through your role at TIA. Thank you for that. Uh yeah, it Idaho is a a tremendous opportunity to take advantage of the monies put forth with RIP and replace for example.
▶ 2:16:48Uh you know, these rural operators have a hard time making money running a business when you're so spread out. So uh removing things untrusted gear like Huawei or ZTE gear critically important. Number two, the bead money very important uh for for states like Idaho to help those unserved and underserved. So finding ways to uh continue to push that money out to rural America is very very critical.
▶ 2:17:15Uh and the way that it's connected to your industry, not just uh to the consumer. Uh all that is uh especially interwoven in rural America. So industry as well as rural America consumers are tightly connected and therefore the uh the networks need to be tightly connected. Thank you for that. I want to do a follow-up question. uh same general subject matter, but having to do with cyber security incident reporting requirements.
▶ 2:17:42That's another one of those things that um can be cumbersome, especially if you're a small uh ISP and uh I wanted to get your comments on that as well. Is harmonizing maybe an option or other forms of report sharing uh something that we should be looking at a little bit deeper? Absolutely. We need to speak in one voice. We need to have one way of reporting incidents.
▶ 2:18:08Uh right now every company and many agencies and departments in the in the government and in state governments have different ways of reporting things. So the with all these different requirements and you're in a small rural company, who do you respond to? How do you uh quickly identify the problem, quickly resolve the problem?
▶ 2:18:28If we speak in one voice and have one voice of mitigation and incident reporting, we'll more more quickly fix the problem and then we'll continually improve because that's what a good benchmarking system does. It allows you to get better and better. Thank you for that as well. Going to shift to Mr. Jaffer and going to magically make you king for a day. Okay. I love that vulture. Um undersea cables.
▶ 2:18:53We've been talking about that a lot and uh I don't want to regurgitate what others have brought up or similar questions. I know that I've made notes of the patrolling issues, satellite monitoring, the permitting issues that we've got, the need for redundancy. Uh what we haven't talked about is penalties for nefarious actors or at least that I've heard. But uh as king for a day, could you hit that topic again? What are the steps we need to be taking?
▶ 2:19:21Look, we have to make it clear to our adversaries, Russia and China primarily when it comes to undersea cables that we we view those as part of our critical infrastructure and if those are hit and we know it's them, we will make them pay a price. That price could be economic, it might be sanctions, it might be military. The truth is that we rely so much on these networks and by the way they have similar capabilities to counter space as well. So it's both our satellites and our undersea cables that are at risk when it comes to China and Russia.
▶ 2:19:47they take out those systems and we have to make clear to them you will pay a price and then when they do it we have to exact that cost. If we don't have credibility deterrence doesn't work and that's one of the fundamental problems is we don't we don't talk about where our red lines are. We don't talk about what our capabilities are to respond and then when the bad thing happens we don't respond. So it's no surprise our adversaries aren't deterred whether it's the cyber domain whether it's undersea cables or it's counter space. These are all vulnerabilities and our adversaries has gotten too used to coming after us and not paying a price.
▶ 2:20:19Mr. Chairman, uh I think I'm gonna wrap with that. I do have another question or two about Miss Smith that Thank you, Mr. Jaffer, Mr. Salem for your comments for the entire panel for joining us today. Also, please note that some of us have dueling committees. So, if you got repeat questions, you understand why. Mr. Chairman, with that, I yield back. Gentleman yields. Uh the chair now recognizes the gentle lady from New York, Mrs. Thank you very much, Mr. Chairman. Good afternoon, everyone.
▶ 2:20:45And I thank our uh panelists for their expertise uh this afternoon. Uh the security of our communications network is one of the utmost importance to America's national security and continued global economic leadership.
▶ 2:21:01Securing our critical infrastructure against cyber attacks has been a top priority of mine since entering Congress and I'm proud to have served as chair of the cyber security infrastructure protection subcommittee of the homeland security committee in previous congresses where I was able to pass legislation to stand up a national reporting infrastructure for cyber attacks on critical infrastructure uh uh regime.
▶ 2:21:27We have seen an uptick in cyber attacks in recent years fueled by advances in technology including artificial intelligence. Further advances in consumer and commercial technologies alike have helped spur innovation across industries particularly within respect to the IoT devices but also have the potential to create new vulnerabilities that must be addressed.
▶ 2:21:51The varied threat vectors which we now face require a serious focused effort on the part of our federal government. And sadly, our current administration has not proven up to the task. Last month's executive order on cyber security preparedness will weaken our defenses at a time when we face more threats than ever by shifting the responsibility of defending critical infrastructure to state and local governments which too often lack the funding and expertise to take on
▶ 2:22:22this role. This decision leaves schools, emergency service providers, local governments, and others at risk by shifting the burden of warding off attacks from hostile foreign actors onto their backs. Additionally, this administration's inane halfbaked tariff policy will devastate supply chains and drive up the cost related to defending our communications infrastructure. Further securing communications infrastructure begins with practicing good personal cyber hygiene.
▶ 2:22:50Something the current defense secretary and national security advisor seems almost unwillfully aware of unaware of their re their reliance on unofficial and unsecure messaging apps risk the lives of American troops and warrants a serious bipartisan investigation.
▶ 2:23:09It is extremely unfortunate that the current administration has consistently sought to dismantle tools and programs meant to protect our critical infrastructure from cyber attacks while senior officials ignore laws and best practices. We in Congress must however continue to uh to our work to increase network and supply chain safety to allow consumers and business alike to be to make informed decisions impacting the security of our communications networks.
▶ 2:23:37Recent breaches have shown that vulnerabilities in communication networks stem not just from telecommunications infrastructure, but also from compromised end devices and personal behavior. To that end, the FCC under the Biden administration adopted a voluntary cyber security labeling program in March of last year so that approved devices would bear the US cyber trust mark to help consumers identify trustworthy and secure products in the IoT
▶ 2:24:08IoT marketplace while encouraging manufacturers to meet higher standards in product development. My question is to Miss Galante, but uh other panelists may weigh in as well. How could the implementation and possible expansion of the cyber trust mark program help address the risk of communication network our communication networks face? Thank you, Congresswoman Clark.
▶ 2:24:33The cyber security the cyber trust mark cyber security mark on internet of things connected devices is an important step in getting a baseline so consumers know what products are secure. It's similar to the UL, that Underwriter Laboratories metallic uh sticker that we all have on our different appliances.
▶ 2:24:52And I hope that Cyber Trustmart goes the same way, which is to give consumers confidence that the company behind that product is following basic rules in cyber security that will make that product safer for their own personal use and also so that they have some reliability that it's going to be patched and updated over time. Very well. Anyone else want to add Mr. Let's do it.
▶ 2:25:26Right now it's focusing on smart Yes. Very well. Well, listen, my time is up. I thank you all so much for uh adding your expertise to this very important conversation. And with that, Mr. Chairman, I yield back. The gentle lady yields. Mr. Chairman. Mr. Chairman. Yes, sir. Uh, thank you, Mr. Chairman. Uh, at the request of my colleague, uh, Mr.
▶ 2:25:52Fluger, I'd like to request uh, the committee's permission to enter into the record a letter to the honorable Brendan Carr, chairman of the FCC, for from a number of us on this committee. It has to do with recommendations on network and cyber security. So, with the permission of the committee, I'd like to submit that into the record. Without objection, chair now recognizes the gentleman from New Jersey, Mr. King.
▶ 2:26:22Uh, and thank you to our witnesses being here today. As a member of this committee and the foreign affairs committee, I have have a strong interest in identifying and advancing common sense measures that strengthen our communications infrastructure and counter the threats posed by adversaries like China, Russia, and Iran. Uh, Mr. Stalin, uh, first of all, welcome south.
▶ 2:26:48It's it's I'm happy to have a resident of New Jersey's seventh congressional district here and I'm glad you're here to share your expertise. Um I understand that team telecom process can be burdensome and cause delays. What are the obstacles that burden the uh or delay deployment of additional undersea cables? Thank you sir for that question and uh I've been a longtime resident of uh East Amwell in the seventh district 32 years in the same house.
▶ 2:27:18Um so NTIA should be uh the lead in team telecom. They are the president's adviser for all telecom issues. Uh absolutely the DOJ, Department of Defense, Department of State, DHS ought to be involved as well. But looking at it from the perspective of how we improve our telecom systems ought to be the first and lead uh of any type of evaluation. So that type of change would improve the permitting uh duration.
▶ 2:27:48Today it averages over 400 days, some cases as long as 900 days to get a permit. U and often before it even gets to the FCC for the final approval. So this long drawn out process occurs before the FCC even sees the application. uh by fundamentally changing that and looking at it from the perspective of how can we improve our economy rather than a justice department that maybe has a different perspective on things I think that would go a long way to improving it. Okay.
▶ 2:28:17Uh and and what steps can we take to keep the US as an attractive place for vendors and suppliers cross communications technology sector to do business create jobs and innovate here in the United States. We ought to reward trust, re reward investment, uh and we ought to point out with a big spotlight those that are not trusted and encourage uh both the United States and our friends around the world uh to not buy from folks that are not trusted. Yeah, thank you.
▶ 2:28:48Um Mr. Sharp, I agree that it's important to maintain leadership with an international standard setting bodies. In your view, what should American leadership and investment in these international bodies look like to best counter China's efforts to to advance its own agenda, particularly in the satellite industry? Thank you for the question.
▶ 2:29:09I think one of the first opportunities is relating to WRC27, making sure that the United States has positions that are supportive of the satellite industry and that they advocate them um with their international counterparts at WRC27. uh if there is a void, China most definitely will step in. The same is true with respect to other standard setting opportunities. Um if we are not participants, uh China will definitely take advantage of the opportunity.
▶ 2:29:34And can you talk about whether satellites could play a role potentially as a redundancy in the event of or failure of attack on undersea cables? Yes, absolutely. So um I I gave as an example previously uh the government of Taiwan is making arrangements um with multiple satellite operators bringing in the terminals so that should there be a cut um there is an immediate transition to uh to satellite capability.
▶ 2:30:00So the good you know the the benefit of satellite uh uh capabilities are our infrastructures in the sky so they're not subject to something like a cable cut. Thank you. And Mr. Stalen, I I appreciate your discussion of strong supply chain security. What are the safeguards against hypothetically a previously trusted supplier or vendor suddenly being compromised by an adversarial actor? In other words, how can we make sure that trusted suppliers stay trusted?
▶ 2:30:31Continuous uh verification of trust. So having a certification program that a company has to go through on a regular basis to ensure that the processes they're using uh are trusted and ensure that the company itself doesn't have injunctions against it since the last time it got certified. Those types of things are really important. Uh thank you all for your testimony and I yield back. The gentleman yields. The chair now recognizes the gentle lady from Virginia, Miss McClean. Perfect timing.
▶ 2:31:02Thank you. Thank you, Mr. Chairman and Ranking Matt Sui. Member Matt Suie, and I apologize for my timing. Um, but uh given the increased number of cyber security threats threatening our critical infrastructure, this hearing is incredibly important. And the irony of this hearing is not lost on me.
▶ 2:31:26um that while we scramble to catch up in the increasingly intense cyber security arms race, uh some of my colleagues ignore that one of our nation's biggest cyber vulnerabilities is the current um and its drastic cuts to the cyber security and infrastructure security agency, a national security team that prefers to coordinate via unsecure messaging apps instead of following standard security protocols.
▶ 2:31:56And it seems that the biggest step that we could take towards safeguarding our critical telecom's infrastructure is to hold the administration accountable for reckless behavior and unfunded unwarranted funding cuts that have made us more vulnerable. Um, I want to start with Miss Galante.
▶ 2:32:16Can you uh expand on what you mentioned in your testimony regarding the availability of AI to improve data processing capabilities uh to allow even unsophisticated advers adversaries to more effectively extract key insights from stolen data? and how worried we should be that AI will also greatly expand the availability uh ability of adversaries to get around our cyber defenses and commit even more devastating cyber attacks.
▶ 2:32:47Thank you, Congresswoman Mlullen. AI is a double-edged sword. You can use it for security purposes. You can use it for data exploitation and a whole myriad of other other things. Specifically when it relates to how our adversaries are able to advance their skill set quickly when it comes to the excfiltration and the capture of large data sets. This is an area where we really need to focus on what the counter intelligence gain can be to them and what the vulnerability is to us.
▶ 2:33:17When you're able to sweep up huge amounts of data, whether it's from a telecom's network or another source, and then aggregate those data points, you get valuable patterns of life. you get valuable data sets and insights that can be used against us. It's critical that we understand how our adversaries use this. Thank you for that.
▶ 2:33:35And um also for for you Miss Galante, given the growing cooperation that we have witnessed between Russia, Iran, China, and the DPRK in kinetic warfare uh against Ukraine to the extent possible in an unclassified setting.
▶ 2:33:52Can you elaborate on how concerned we should be about the possibility of greater cooperation among our adversaries to engage in cyber attacks against us and to what extent do you believe that type of cooperation has already begun? I am particularly concerned about the sharing especially of vulnerabilities in widely used software in the US that our adversaries could share between each other.
▶ 2:34:15China, for example, has national laws that require that vulnerabilities found by Chinese researchers or Chinese citizens are first given to the government. That's really important. That in a way gives them the Chinese government an advantage on the zero days, the unexploited vulnerabilities that are typically at the core of many of the products or a potential vulnerability in many many of our products and critical infrastructure across the US. If those are shared broadly, this becomes an avenue for a scout attack against the US.
▶ 2:34:44And how should uh the United States be preparing itself for both the potential of AI enhanced um cyber attacks on critical infrastructure and the possibility of more coordinated cyber attacks amongst multiple uh hostile foreign adversar adversaries.
▶ 2:35:02We have to continue to invest in the ecosystem of security industry researchers in intelligence operatives with our US intelligence and law enforcement, national security agencies who together put together the picture of what our adversaries are doing next in the next edge of attacks that are going to be hitting us. It's that combination that's going to keep us ahead of the threat. Thank you. And I yield back. The gentle lady yields. The chair now recognizes himself for five minutes.
▶ 2:35:31The systems that connect us, our networks, our satellites, cables, towers, and data centers form the invisible architecture of 21st century life. Um, safeguarding that infrastructure, as you've all talked about, is not just a matter of technology. It's a matter of strategy, security, and sovereignty. The demand for our networks has exploded. Obviously, every year more devices connect uh to US networks, more data flows and more critical services depend on uninterrupted and secure access.
▶ 2:36:01Our systems are under strain not only from increased usage uh but geopolitical risks, supply chain disruptions and escalating cyber threats particularly from nation states like China as you have talked about. Uh this isn't only about protecting websites or cell towers. It's about protecting hospitals from ransomware, grid systems from blackouts, and first responders from dropped phone calls. Telecommunications is infrastructure. It's also national defense and its economic security. So, let's treat it like that. It's a national priority. Uh, Mr.
▶ 2:36:30Stout, uh, you mentioned rapid expansion and innovation of the satellite industry. Can you elaborate on the most transformative advances that we've seen in maybe the last 5 to 10 years and what they mean for our national Thank you for the question. I believe that uh uh it starts with reusable launch capability. We have much more rapid launch than ever before. Uh that has allowed many more companies to be able to launch their systems into space.
▶ 2:36:58I I think in addition in terms of capabilities, the uh utilization of high throughput uh capacity capabilities uh has allowed expansion for broadband services. Uh so in terms of services, that's something that I would emphasize. the rapid growth of uh of satellite broadband is really dependent upon that. In addition with it within respect to the u remote sensing sector of the industry, the ability to manufacture and launch uh sensors into space has opened up a a completely new industry.
▶ 2:37:26So I would say those are those are just some of the uh uh the points that I would emphasize. And then we've also seen within manufacturing utilization of um of um mass manufacturing techniques just given the increase in the number of satellites that are being manufactured uh changing from bespoke uh manufacturing of large bussiz satellites to uh hundreds of thousands of satellites being launched into into space each year.
▶ 2:37:50Can you can you point to we've talked about this broadly um some of the other witnesses but specific policies that put uh your industry at a competitive disadvantage compared to say foreign competitors? Yeah, certainly I think that the the ease of licensing within the United States is extremely important and we've made a number of recommendations to the FCC uh and we also work with Noah uh on remote sensing to be able to streamline the licensing process.
▶ 2:38:16We've seen uh fortunately a great deal of of investment that has made it been made in the industry. Um but certainly we don't want to push any of the the licensing opportunities offshore because that is something that I hear about from our members. Um in the past it has taken a long time to be able to to get a a license approved. I will note that um in the last few years we saw the creation of the space bureau at the FCC. At the time there were 64,000 pending applications and that has gone a great way to be able to address that.
▶ 2:38:44But um that has been one of the key points that I've heard from our members is being able to get a license quickly. Thank you for that. Mr. Stalin, uh you talked about how vulnerable the US telecom supply chain is today um to foreign interference and dependency. What specific areas concern you the most? Uh specifically the lack of strategic investment in the United States in the ICT space.
▶ 2:39:08We have to pull back as much as possible uh the development of semiconductors and that entire ecosystem around semiconductor development. That's number one. Number two, the lack of overall R&D investment. Uh we have to encourage companies, incentivize them uh to spend more money on R&D and uh we can do that through tax credits. So reauthorizing that's critical. Okay.
▶ 2:39:34uh what what key technical or architectural decisions uh must we make now to ensure that our networks can withstand cyber attacks or disruptions? We need to speak in one voice. Uh right now uh ISPs each have their own methodology for managing uh cyber security and supply chain security. Uh the government has multiple ways of managing that. Uh so we need to speak in one voice which will allow us to react more quickly uh to evaluate performance more quickly and to continuously improve.
▶ 2:40:03We have to have a defense in depth and speaking in one voice certainly helps. Thank you for that. Uh Mr. Jaffer, uh you talked about our allies. This actually intrigued me a little bit. Um I assume that our allies are aware of the risks of of of buying this material from communist China. Uh, and so if they're aware of that, what what's causing them to continue to perpetuate the problem? It's it's a it's a great question. I mean, two things. One, you know, our allies, take Europe for example.
▶ 2:40:30They've known long about their addiction to Russian gas now that caused them problems. And yet, they continue to buy it and buy it. We tried to build them a pipeline back in the Bush administration. They wouldn't do it. They built a pipeline to Russia instead. Uh, they're building a second one now. Um, it makes no sense. Uh, the same they have the same attitude towards China. Uh you look at the even the United Kingdom, our closest partner or the special relationship, they British Telecom built Huawei routers into their core networks. And when we went to them and told them this is a real problem, it took us a while to convince them. It took us a while to go around the globe.
▶ 2:40:59The the first Trump administration spent lots of hours and days and months and weeks convincing our allies around the globe that this was a real threat. And that was only a decade after the House Intelligence Committee wrote a report about the threat from Huawei and ZTE. So we've known about this problem. We've been telling our friends and allies. And then of course we've had to pay rip and replace to take it out of our state and local networks as well. There's a coming threat though. DJI drones being used by state and local law enforcement. Crazy for Americans to be buying that. We should not allow that to happen.
▶ 2:41:28It is it is a huge mistake for American law enforcement to have those drones in their networks. Thank you for that. Um I see my time has expired. The chair now recognizes the gentleman from California, Mr. Opinos. Uh thank you very much much Mr. Chairman. Uh and thanks to our witnesses. This has been a really important uh really interesting hearing. Uh Miss Galante, I'd like to start with you if I could.
▶ 2:41:49I found your testimony very interesting and particularly the ways that foreign intelligence services are uh using uh security vulnerabilities at Telos to gather information on US infrastructure and building the capacity to disrupt that infrastructure. I'm wondering about your thoughts about to what level that uh comp constitutes more than just an unfriendly act.
▶ 2:42:13You know, we we have kind of an informal understanding that intelligence gathering is something that all countries do, but building the capability to disrupt our infrastructure, I think, maybe goes beyond that. And I mean, for example, if a if a foreign country did something that was overt, like came into on US territory, kidnapped American citizens, and took them back to uh Iran or China, for example. I mean, obviously that would be tantamount to an act of war that has started wars.
▶ 2:42:38Uh do we need to uh rep prioritize our international reaction to acts like this? Thanks for the question, Mr. say, um, one of the one of the key distinctions that made this more than a sort of standard act of espionage, if you can think of it that way, is the level of access that these actors had within the telco networks.
▶ 2:43:03And with telco networks especially, you can almost think of it as sort of a multi-prong tool. You're able to disrupt traffic. you would be able to take almost kinetic like steps in a network because of the types of tech that are there that would cause an effect that everyone would agree is far beyond espionage. That hasn't happened yet as far as we know in these cases. It has just been an intelligence gathering effort and the access that these actors had presented additional opportunities.
▶ 2:43:32So that might be an area where you can really drive a distinction between what is traditionally known as espionage and what is largely considered prepositioning for an attack. Right. That that's I think you've illustrated the key distinction there. I mean there's there's information gathering which is what espionage is uh is geared towards. But then building a destructive capability is something I think might go beyond that. And if someone did something overt like kidnapping US citizens, we would say that's not all right. That's not okay.
▶ 2:44:02We would take a stand. I'm wondering if maybe as an international community we need to set new norms uh about that behavior. And I think the discussion has to happen with our allies, right? This is not just a US problem that Chinese access into Telos. We need to look at countries and allies in Southeast Asia. We also need to look at some of our European friends who have been dealing with this as well. This is not just a US problem and we need to come together to be able to show where the real lines are here that we're not willing to tolerate. Right. Thank you.
▶ 2:44:32U Mr. Stalin, you uh highlighted the vulnerability of some of our subc cables and uh you which I was very appreciative of because a lot of people don't realize that vulnerability. Uh could you talk a little bit about what the the uh backup might be to that and how do we protect against that vulnerability because it it's the problem is we're uniquely vulnerable in that way. Uh and I I just don't see an easy way around that. There is no easy way around it other than having more cables and more landing points and quicker responses.
▶ 2:45:02because of the volume of bandwidth, the volume of traffic that goes across these cables. So that that's really important. But we also need to be more on the offense and as was described earlier, we need to tell our adversaries, don't do this. There will be a significant action on our part if you continue uh to uh conduct nefarious acts. Right.
▶ 2:45:24Well, I'm I'm hopeful that we can also do some modeling about how much of that international traffic uh would be debilitating because it would be you never know how debilitating it's going to be until it happens. But if you've done some modeling and you've done some exercises, uh you can kind of predict some of those failures. Yeah. To build on that, uh the the Houthis uh uh took out some cables in the Red Sea last year and between Asia and Africa, more than 50% of the traffic went down. Right. And Mr.
▶ 2:45:53Stout with my remaining 47 seconds Um, appreciate your testimony. One of the things that you didn't mention when you're talking about disaster modeling is the really innovative way that satellites are being used for early detection of wildfires. That's critically important to my district. Uh, if we can put these fires out with fast aerial resources before we need boots on the ground, it could be a total gamecher. Could you give us a quick update on how that's going? Yes, I've actually seen a company just announced that they're providing that service.
▶ 2:46:22um that uh as a service. Uh a couple years ago when I had the pleasure of testifying, you'd asked a question about that capability and I identified a a manufacturer of that capability and the last two years we've seen companies moving forward with offering that as a service. Right. Well, we have as you know pilot programs uh including some legislation that I offered to build out that capability because I am absolutely convinced it's going to be a gamecher for us in the West. Well, thank you very much for your testimony. See you out of time. Mr. Chairman, I yield back.
▶ 2:46:49Gentleman yields and uh uh the purpose of this hearing now being concluded. I want to thank the witnesses for being here. I appreciate the professionalism uh the expertise. I appreciate your testimony. Um and we are adjourned. Good job. Oh, hold on.
▶ 2:47:15Uh just as a reminder, I remind all members that they have 10 business days to submit questions for the record and I ask that witnesses to respond to the questions promptly. Uh members should submit their questions by the close of business on Wednesday, May 14th. This is this hearing is adjourned. I also ask unanimous consent to insert into the record the documents included on the staff hearing document list without objection.
▶ 2:47:44That will be in All
▶ 2:49:08right.