▶ 0:00:00Madam director, u, madame ranking member, um, it's it's no, uh, surprise to anybody that that we've got both scheduled in about an hour. So, we are going to endeavor to be crisp. I'm not going to waste a bunch of time telling you how we're going to do that. Just to say that we are reducing the amount of time for questioning for members to four minutes. I was going to do it for three, but Miss Underwood basically bullied me into four and so I got bullied and so it's four.
▶ 0:00:28Um, if we when we get to the hearing, I'm not going to adjourn and come back after votes. We're going to adjourn. If members have questions that they wanted to uh to ask of of um of the uh uh cyber security folks um that they didn't get to ask and they don't feel good about um submitting them in writing, then let us know and we'll talk about maybe trying to convene another hearing before marking up the cyber security part of things.
▶ 0:00:57Um, and so with that, um, I got some nice stuff I could say here, but but I'm not gonna because I got bullied into giving members four minutes instead of three. And so with that, I recognize uh the distinguished ranking member, Miss Underwood, for her opening comments. Well, thank you, Mr. Chairman, uh, for holding this hearing to conduct oversight of the Cyber Security and Infrastructure Security Agency. I'd also like to welcome Miss Bridget Bean, the senior official performing the duties of director of SISA to her first hearing before us.
▶ 0:01:28SISA is not a large or organization, but Congress fought over the years to properly fund the critical responsibilities of your agency, growing its funding by 75% from fiscal year 2019 to fiscal year 2024. Remarkably, these increases have consistently been with bipartisan support. I don't need to tell you how rare that is these days. And I believe it reflects the scale of the catastrophic cyber threats facing our country as well as the quality of resources and support that SISA provides.
▶ 0:01:55But instead of investing in this popular, nimble, and costefficient agency that protects nearly every aspect of Americans lives, you are proposing an almost 20% cut to SISA, $491 million, and driving out the workforce through early retirement buyouts and questionable terminations. That's not cutting fat. That's a death blow.
▶ 0:02:14This reduction in force is not based on performance, but on things in CISA's congressionallymandated mission that the president is offended by, like securing America's elections from foreign adversaries like Russia. These are real threats. I represent Illinois, and during the 2016 elections, Russian hackers penetrated the state board of elections voter registration database, stealing the personal data of about 76,000 Illinois voters.
▶ 0:02:39SISA was created to protect the nation's critical infrastructure from physical and cyber threats which includes election in infrastructure. Therefore, you cannot claim to be refocusing on core missions like enhancing the security and resilience of critical infrastructure while also eliminating election security support and staff. Unfortunately, CISA is not the only area suffering as this administration weakens our nation's cyber security vulnerabilities. Cabinet secretaries are putting American lives at risk by avoiding secure communications.
▶ 0:03:08The FBI's foreign influence task force has been disbanded. The head of US Cyber Command has been fired with no replacement. This is all happening at a time when national security and cyber security experts have urged greater investments in cyber defense and offense. Particularly as cyber crime proliferates and China and Russia have sought to interfere with our economy, our elections, our health care systems, and our security.
▶ 0:03:34Our adversaries are upping their game every day, growing significantly, while this budget would take us backwards. These aren't hypothetical threats. China is ramping up attacks on our telecommunications and energy sectors. Schools and hospitals in my district have had to close after ransomware attacks. So my question is why? Why is this administration so determined to degrade the core cyber defenses that keep America safe? Is it to privatize CISA functions?
▶ 0:04:04so that the tech CEOs who sat front row at President Trump's inauguration can profit off of them and lock small competitors out? Is it to let Putin and his cronies around the world who support the president interfere in our elections? Is it to make government services more difficult and frustrating to access so Americans will support your efforts to dismantle them? Is it being driven by some ass from anonymous investors in the president's crypto scheme?
▶ 0:04:30I don't know the answer, but what I do know is that this committee will continue to fulfill our article one responsibilities under the Constitution regardless of the chaos and corruption of this administration. We will have questions for you today on your plans to improve the core functions of SISA, fulfill the mission that Congress designated, and expand much needed capabilities with the reduction in staff and resources you are requesting in this budget.
▶ 0:04:55Lastly, I'd like to thank the women and men of SISA working 247 to combat threats facing our nation's networks, critical infrastructure, elections, emergency communications, schools, hospitals, and public gatherings while a new administration creates job uncertainty and the fear of politically motivated reprisal. Thank you again, Miss Bean, for being here today, and I look forward to your testimony and answers to our questions. I yield back. Thank you, ma'am. So between the two of us with your statement, our average is pretty good.
▶ 0:05:25We're ahead of I think we're doing great. Madame Director, the floor is yours. Good morning, Chairman Amade, Ranking Member Underwood, and members of the subcommittee. Thank you for the opportunity to discuss the cyber security and infrastructure security ay's priorities and our efforts to protect our nation. I'm honored to serve as a senior official performing the duties of uh the director and the executive director of SISA.
▶ 0:05:53My decades of civil service have well prepared me for this role. Having previously served at the Small Business Administration and at the Federal Emergency Management Agency, I joined CISA in 2022 as our first chief integration officer, leading CIS's operations integrations across the nation to deliver missionritical services more rapidly and in support of our critical infrastructure. This work made clear that cyber security and infrastructure security is national security.
▶ 0:06:22As the nation's cyber defense agency and the national coordinator for critical infrastructure and security and resilience, SISA leads the national effort to understand, manage, and reduce risk to the cyber and physical infrastructure that Americans rely on every day. SISA is committed to executing our core mission as authorized by Congress. Our agency has swiftly and responsibly implemented this administration's executive orders and supporting guidance.
▶ 0:06:49Aligned with administration priorities, we are laser focused on our statutoily authorized cyber security, infrastructure security, and emergency communications missions. The threat facing our nation, they are not hypothetical. They are real. And our adversaries are directly targeting our critical infrastructure in unprecedented ways. We know this because the talented workforce at SISA has detected these adversaries.
▶ 0:07:14SIS's workforce operating on the front line of national security is our greatest asset. I want to thank them personally, each and every one of them, for their unwavering dedication, professionalism, and service to our nation. Since January 2025, we have continued to drive vulnerability risk reduction in federal departments and critical infrastructure. We've increased visibility across networks and strengthen cyber security.
▶ 0:07:39We've released operational products with partners including the FBI and NSA, warning infrastructure of pressing threats and urging specific mitigations. We've delivered 269 terrorism mitigation courses for more than 5,000 folks across the country with 94% of those who participated responding that that training has enhanced their preparedness.
▶ 0:08:02We conducted 68 exercises, most recently the one in Philadelphia, convening hundreds of emergency managers in support of the World Cup 2026. We've completed 9,400 cyber and physical assessments and trainings for state and locals, as well as critical instructor owners and operators. We've conducted more than 4,000 notifications to warn entities of early stage ransomware activity before malicious actors could take action.
▶ 0:08:28This results in uninterrupted service and billions of dollars in estimated savings because the ransomware could not be deployed. We've expanded CISA's known exploited vulnerability catalog to over 1300 vulnerabilities. As a result of this, the private sector has remediated vulnerabilities identified by CISA an average of 15 months earlier. This is critical when we are defending against nation state actors and persistent threat of ransomware.
▶ 0:08:55State, local, and tribal territorial governments and those who have signed up for CIS's vulnerability scanning services saw a 31% reduction in exploitable vulnerabilities. We've deployed endpoint detection and response technologies across federal agencies to more than 415,000 endpoints, enabling rapid detection and response. We've blocked 700 million malicious connections across the federal government and more than 60 million across critical infrastructure. This is just in the first quarter of 2025 alone.
▶ 0:09:26These examples illustrate that CIS is operating with clear vision to defend and secure the federal civilian enterprise to strengthen the physical and cyber security of the United States critical infrastructure to incentivize the development and procurement of trustworthy technology. to lead the United States government's coordinated cyber defense operations and to unify our national response to significant cyber incidents by coordinating between government, industry, and our international partners.
▶ 0:09:51With the support of Congress, we have strengthened our ability to detect, analyze, and respond to cyber and physical threats faster and more effectively than ever before. There is no shortage of work ahead and we're committed to operating with transparency, accountability, and efficiency as we confront the threats of today and prepare for those of tomorrow. I look forward to working with all of you to strengthen CIS's capabilities to enhance the security and resilience of our nation's infrastructure. Thank you again for the opportunity to be here and I look forward to your questions.
▶ 0:10:22Thank you, Madam Director. The chair now recognizes the ranking member. The floor is yours for four minutes for your questions. Thank you, Mr. Chairman. Uh, jumping right into it, my first one should be easy. A simple yes or no. Is Russia still a cyber security threat and priority for this administration? SISA. Yes. Excellent. I'm glad to hear that. And I want to discuss with you SISA's response to a recent incident at the National Labor Relations Board, which protects the legal rights of American workers.
▶ 0:10:46Public reporting indicates that in March, a whistleblower complaint was filed against a Doge team at NLRB for removing massive amounts of sensitive data from the agency with no legitimate justification. The whistleblower reported a quote spike in data leaving the agency after Doge was granted access to it. Among other things, it's possible this data included corporate secrets and private information on union members.
▶ 0:11:11At the same time, Doge employees turned off monitoring tools, manually deleted records of what they accessed and sought to ensure their activities weren't logged in the system. As soon as Doge got there, the agency started detecting suspicious login attempts from an IP address in Russia. So NLRB's IT department launched a formal review of what it deemed a serious ongoing security breach or potentially illegal removal of personally identifiable information.
▶ 0:11:37Normally at this point computer emergency readiness team would be created to respond, but public reporting indicates this never happened because of instructions quote had come down to drop the US reporting and investigation. And the whistleblower who made the complaint found a threatening note taped to his door with sensitive personal info and a drone shot of him walking his dog. Who decided not to create a computer emergency readiness team in this instance?
▶ 0:12:04And was it someone at SISA or elsewhere in the So what what I can tell you is that SISA supports all of our uh federal civilian agencies, right? through protection of s sensitive data and sensitive systems uh through targeting uh capabilities, products, hands-on technical assistance uh and collaboration providing resources and we would be happy to work with the uh NLRB uh when asked but we have not you know and we're happy to do that.
▶ 0:12:33So you did not receive a request? Not to my knowledge. Okay. So what's the standard procedure at CISA now for investigations involving the misuse of sensitive data and incursions by ban actors like Russia? So I think that there's uh what I'd like to point out is that we are on the cyber security uh side of the house, right? So we are helping agencies to protect their systems and their sensitive information. So we you know we can h we're happy to help with some forensics uh with NLRB.
▶ 0:13:00Uh, the other thing is, you know, I think Doge the Doge employees are federal employees and, you know, they're held to the same rules of behavior and engagement and I have every reason to believe that that they're doing that. Can you commit to providing us regular and timely updates into the investigation into what happened with NLRB? So, as you do your forensics and the other um, if we're investigations, Yes, ma'am. If we are asked to do so, we will we will provide updates. Okay. I yield back. Thank you. Thank you, ma'am. Three minutes, Mr. Chairman. Thank you very much.
▶ 0:13:31That's what they call a leader in my state. Good for you. Um, if at any point in time during the questioning the answer is appropriately, I'd love to talk to you guys in a skiff about it. Let us know and we'll arrange that. Miss Henson, you are recognized for four minutes of questioning. Thank you, Mr. Chairman, and thank you to our ranking member for holding this hearing. Um, acting director, thank you so much for being here today. Um, as a member of the China Select Committee, I have seen firsthand obviously many of the threats that face our country.
▶ 0:13:59um the work there, the adversaries, the tools that they are using to come after um the United States and target our citizens. Um so agencies like yours are very very important. The CCP is actively exploiting gaps in infrastructure to sew that chaos and instability um embedding within our critical systems and positioning to strike when it suits them. As we know, we saw with the recent bolt and salt typhoon campaigns, obviously operations that were carefully planned, well resourced, and executed with precision.
▶ 0:14:27um they make the strategic intent and long-term capabilities of CCP state sponsored actors to carry out covert attacks on us and um this is a threat not only to our national security but to every American's life. So I think it's a threat we cannot ignore and I know you're taking it very seriously. So um I want to talk about um a a program that I think is absolutely essential in this and it's the attack surface management program.
▶ 0:14:49Um, obviously this is about not only identifying and and going in forensically like you said, auditing this and catching it, but patching the vulnerabilities before our adversaries can exploit them. So, do you consider this program to be one of CIS's core cyber security capabilities? How are you leveraging this program to really help our partners defend against these sophisticated nation state actors? Uh, very important question. You're absolutely right. So, this attack surface management uh is one of our core capabilities.
▶ 0:15:18It is a pivotal it is a critical pillar of our cyber defense program at SISA and it's unique in as much as it's one of the most scalable programs we have uh and it takes an attacker's approach. So it's looking from the outside in. Most sizos and CIOS are looking at their environment from the inside.
▶ 0:15:37This is a way to scan across the horizon across the network across the internet and see what are those vulnerabilities, where are they and with that information we actually are able to go to uh critical infrastructure and private sector and say hey you have this vulnerability but the good news is you can patch it and you can protect yourself.
▶ 0:15:56So the um the attack surf management uh not only is it one of our most scalable uh coste effective tools we have it's the most effective in identif identifying vulnerabilities and providing uh an entity to fix that to mitigate that challenge. Uh it reduces risks. It enables proactive measures.
▶ 0:16:17Uh and as entities continue to build their attack surf, you know, you add a device, you add a software, you have cloud, you've got mobile devices, all of that expands the the attack surface that an adversary can can capitalize on. This tool really allows through partnership between the government, SISA, and private entity to identify those vulnerabilities and to fix them. Yeah.
▶ 0:16:42Well, certainly I think the the partnerships that you have at the state and local level too all the way down to the business community, it's it's critical and I think that the strike teams as they were called and uh you know getting out and actually communicating that is is critically important. One follow-up last question. Um you know your predecessor was really outspoken about the national security risks associated with Tik Tok um as well um regarding that access to personal devices data harvesting that comes from that. Do you share that assessment and how are you at CISA evaluating or responding to those risks? Uh absolutely.
▶ 0:17:11I think as you know Tik Tok's not authorized on any federal network and what we're also trying to do is make sure that we're raising the awareness that cyber security is everyone's concern and you mentioned it earlier right it's it's a team sport it's the federal state local but also individuals and so making sure that our small businesses our K12 our students understand the risk and how it really plays into their everyday life that's an important role we play to help educate the the community on the threats and the risks. Thank you.
▶ 0:17:41Um I yield back, Mr. Thank you, Miss Henson. Uh Mr. Quay, you have the floor for four minutes. Uh thank you, uh Mr. Chairman. First of all, uh Director Bean, I want to wish you a happy Mother's Day. Uh all of y'all also happy Mother's Day. And and guys, please don't forget buy your card, your flowers, and whatever you need to do for Sunday. Um uh so uh so with that, I just say happy Mother's Day on Sunday.
▶ 0:18:08But let me uh uh talk a little bit about efficiency, effectiveness, and accountability. Look, I think we're all on the same page. We want to get rid of uh inefficiencies and and and waste and all that. It's how we get there is where, you know, we've seen it.
▶ 0:18:24I know in Texas uh working with um uh then controller John Sharp and the legislature in the 1990s we did this uh doggy I think is what they call it but uh Doge uh without cutting people and without cutting services but we found billions and billions of dollars of savings without cutting services and personnel. So there's a way of doing this.
▶ 0:18:49Uh from there uh years later the Congress in a bipartisan way passed a law uh back in 2010 uh government performance and results modernization act and there's another law that's there and you know it it calls for annual operational reviews um uh uh to make sure that you know we get this efficiencies. It it calls for regulatory modernization.
▶ 0:19:16That is anything that um rules that are obsolete or or or costly. It calls for that. That's the law already. Uh it uh calls for development and performance measures. You know, the problem is you all develop the performance measures in a vacuum and I'm talking about just the executive branch uh without sending anything over to us. They're put on a web page and I'm sure yours is in a web page.
▶ 0:19:42Um and then the other thing uh tied up is uh calling for competitive contracting. That's a different law. um you know budgets and I think every agency uh that has any contract has a problem with on budget and on time and there are penalties that you can enforce under the law where somebody doesn't do the contract after you get a competitive contract if they're not on time or or they're not on budget there are penalties
▶ 0:20:12but the federal government I still haven't found one where we are on time and and and and on budget. I'm sure there is an example somewhere out there, but we need to enforce that a lot more. And and finally, just the uh quarterly oversight reporting uh which is for us article one. Um you know, you you do that, report to us under article one and and under the law that we passed in 2010, a lot of that is supposed to be done.
▶ 0:20:41The only thing that wasn't added was reporting back to Congress. It was the compromise unfortunately was to put it on a website, but we're hoping that committees and appropriations will start just at that little thing to the uh to the government uh modernization act that I talked about. But I think we're all on the same page. We want to find efficiencies, effectiveness uh and we want to work with you without cutting personnel and services.
▶ 0:21:10So we look forward working with you. With that, I yield back the back of my time. Mr. Chairman, don't forget Mother's Day, sir. Thank you, sir. I knew about that. Thank you for the reminder. That's kind of redundant, but that's good. We're good. Mr. Gonzalez, the floor is yours for four minutes. Uh, thank you, director, for your service to our country, and thank you for all the men and women at SISA for everything that y'all do. I I want to first start, we always talk about ecosystem and, you know, all these threats and how we we grow this out. I want to talk about uh universities and, you know, I'm blessed to be in Texas. We have some amazing universities.
▶ 0:21:40I was just speaking with Heather Wilson doing a great job, president of UT. Are you or what can we do more to work with some of the universities? Are are you doing is SISA doing anything in particular with UT one and then are you doing anything with any other universities? So CISA is all about partnerships understanding that cyber security is a team sport.
▶ 0:22:02We can't do it by ourselves and universities and institutions of higher learning play a critical role and we do we work with we work with them at multiple levels at the national level we have engagement with universities but also at the local level our whole regional force is on the ground in those communities working with universities to do three things right one is to make sure that we are highlighting the importance of cyber security in the curriculum and getting folks to to go to school to learn that to build the next generation of cyber defenders.
▶ 0:22:32Secondly, to make sure that uh we're learning from them. Some of the best and brightest ideas about how to defend our critical infrastructure is coming out of those institutions. So, our regional staff is working with them to make sure that we're getting that information, feeding it back up, uh you know, really trying to be efficient and cost-effective and and leveraging that which is being done there.
▶ 0:22:51Uh and lastly, the third one is just to make sure that we have um academia, international partners, the federal government and state and local governments communicating so that we are leveraging resources and not duplicating them. I I tell you what, as we as we go through this budget process, that could be a sweet spot. Every all all the members in here, we have uh in some form or fashion colleges and universities, you know, my good friend Juan Ciscomani has University of Arizona there.
▶ 0:23:17there's all these opportunities and if SISA is just partnering with all these places, it's going to be very hard for us to say we want less of that and it's going to be very easy for us to say more of that. I'm going to switch gears a little bit on international um kind of discussion. Uh a lot of us saw what happened in Spain and Portugal about a week ago and that concerns me. You know, anytime the power goes out, I think we're still trying to figure that out. But I'm going to ask two questions. One, do you have any details on that situation? Absolutely.
▶ 0:23:46As soon as we we became aware of it, we reached out to our partners uh to find out what was going on and could we render assistance. Uh we were soon told that it was not a cyber nexus um cyber related but we remain uh committed to our international partner as the US C uh you know we have hundreds of international partners and it's you know governmentto really and our team works around the clock.
▶ 0:24:16I mean just recently someone was telling me that they were getting up at four o'clock in the morning to have a international call. So we are extremely committed to that continued sharing of information across what we call theerts. Um but your but your question is very timely and very important because regardless of whether or not it was a cyber event uh it really demonstrates the importance of critical infrastructure and critical infrastructure is the backbone of our national security and our economic security.
▶ 0:24:43So we want to make sure at CISA that we are working with the critical infrastructure in our country whether it's whether it's the electrical grid whether it's wa clean drinking water whether it's our healthcare right so it's our communications making sure that they're both secure and resilient so that you know our American citizens can depend on having that operational infrastructure. Yeah, thank you for that answer and thank you for working with our partners. Uh you know we've got we've got military bases in Spain. They're a close ally. Today it's Spain, tomorrow it's somewhere else.
▶ 0:25:12But when I think of CISA, I always think is the expert in that area, not only for the United States, but for the world. So, it's great that you're working on that. My last question is is going to critical infrastructure. Uh oil and gas industry is is very important not only to my district, not only to Texas, but the United States. The Colonial Pipeline is is something very much on our mind.
▶ 0:25:33Can you briefly talk a little bit about what you're doing to to harden and and and make sure that our energy industry is ready for that next attack that's First, we're working with the Department of Energy. We're working with uh all of the um sector risk management agencies, but we're working with the oil and gas companies specifically to make sure that they're understanding what is the threat to them, who is targeting them, and what can they do to help better secure themselves.
▶ 0:26:03What we're finding is that our nation state actors are not using any novel uh techniques. They're exploiting known vulnerabilities. They are searching the internet looking for misconfigurations and they're getting in and they're going undetected because these living off the land kind of techniques don't leave a footprint.
▶ 0:26:23Um and so what we're trying to work with um you know the oil and gas companies as well as all the rest is to understand we need to make the adversary work harder to get in and that there are things that they can do to significantly and I mean drastically reduce their risk.
▶ 0:26:39Uh we're also providing intelligence briefings so that they better understand what exactly are we seeing so that if we're able to give them a bit more information uh we're doing that and again our folks on the ground who are working with those companies to understand the uh and lastly making sure that those who rely on the oil and natural gas understand that if something should happen what are their contingency plans what are those cascading impacts so we're trying to take a holistic approach to make sure that they are
▶ 0:27:09are hardened and have a really good resiliency plan so that they can re um restart operations as soon as possible. Great. Thank you, director. I yield back. Miss Escobar, floor is yours for four minutes. Not an Arizona four minutes or I mean a Texas four minutes, but first Hawaii high altitude. A high altitude Arizona. I'm going to call you a Mother's Day for sure.
▶ 0:27:34And well, I'm I'm a little rattled because when I hear the director talk about getting up at 4 in the morning for an international call and know that she's thinking about calling Nevada, it it it kind of, you know, has a negative impact on me. But I'm wasting the committee's time. Please proceed. Thank you, Mr. Chairman. Thank you, ranking member. Thank you so much, Miss Bean, for your work and for being here.
▶ 0:27:56I have been so profoundly concerned about the reports of what Doge or Chairman Doggy, apologies, chairman, uh has been doing. Uh we you're not going to find anyone who disagrees with rooting out waste, fraud, and abuse. We all want that. But the unlawful ways that Doge has been engaging with sensitive data has been alarming. And it's it's alarming to my constituents as well.
▶ 0:28:24I've gotten innumerable questions about it and we've read reports about the staffers at Doge um sharing sensitive information via unsecured email accounts. Uh there was just a Washington Post article yesterday about their desire to create a centralized um account for all of Americans sensitive data.
▶ 0:28:49So I'm and and obviously we are all concerned about the access to this data by adversaries. We don't want adversaries getting their hands on this data. So I I'm wondering if SISA was consulted as Doge staffers accessed this data. So I I don't have any knowledge that SISA was consulted. What I can say uh is two things that I think are worth highlighting.
▶ 0:29:16One is SISA has worked through Congress's both direction and support to build tools that better protect the security on every federal agency uh network and we continue to do that. Uh and it's a top top priority for us as directed by Congress and funded by Congress.
▶ 0:29:34Uh secondly, um we are as you mentioned you know we're looking for efficiencies but we're you know we're doing it as we do with every transition right you look at organizations you look at spending I've been in government um a number of years hardly worth quantifying uh but I've seen this again and again and we do you know at every transition you're looking at your staffing you're looking at your budget you're looking at your contracts you're looking at your organizational structure and that's what we're doing at SISA to try and find efficiencies and make sure that we are still delivering on our core missions
▶ 0:30:05while eliminating duplication um and increasing efficiency which will really enhance um the security of our citizens. The I'm all for efficiencies, but my concern is in the data that was accessed by these employees and potentially shared on unsecured networks. Um I've I've read that they've shared information via Gmail, personal Gmail accounts.
▶ 0:30:30Have you all had a chance to go in and provide any oversight over what data was accessed, where it went, how it was shared? I I don't have that here today, but I'm happy to go back and get some information and try and provide you a more wholesome answer. I am very very interested in that. Um I and I I think there are other members of the committee who would be interested in that. And as the chairman mentioned, if we've got to do that in a skiff, we are we we are at the ready. Mr. Mr.
▶ 0:30:59Chairman, I yield back a little over three minutes. Thank you for being an all-star member of the committee. Mr. Sisammani, the floor is yours for four minutes. I'll represent Arizona well and stick to the time, Mr. Chairman. Um, uh, thank you, Miss Bean, for being here with us today. Really appreciate your feedback.
▶ 0:31:21Um you know we all know quite well that uh in our increasingly interconnected world uh where there's so much information lives on the cloud and communications are done electronically the cyber threat environment is dynamic and changing on daily basis. Um adversarial nations and criminals take advantage of any weakness and perceived weakness and will continue to do so. That's that's how they operate. This happens not only at the federal level but also at a state and the local level as well.
▶ 0:31:46Can can you speak to the resources that you have available for state and local governments and and how you anticipate the budget requests changing if at all the availability the availability of these resources for for state and local entities.
▶ 0:32:00So um at CISO we have a what we call our regional delivery model and that means having security adviserss in every state territory and those are discipline specific experts on security cyber security physical security emergency communications and it's that team on the ground that's working with local governments local critical infrastructure um uh in in those communities and and they work and they live in those communities.
▶ 0:32:28So this is the way we deliver many of our scalable uh products and services is down through our regional security adviserss and um you know this administration is committed to making sure that we are as close to the American people delivering those services as possible. So I can promise you that will continue. Great. You know, on that same topic of of closeness of closeness to the community, kind of like boots on the ground kind of thing.
▶ 0:32:51Small businesses are a perfect representation of that and they depend a lot on the resources also that you can provide uh for their security both uh cyber mainly but but also in other aspects. Can you speak to a little bit to that to the small business resources? Absolutely. You know, you're making my heart sing. having worked at the SBA for many many years. Uh we know that small business is the, you know, the engine of our economy.
▶ 0:33:16And so making sure that they're doing everything they can in this highly competitive, highly connected uh environment is really important. And there's things that they can do immediately that will help better secure them. One is to get to know their SISA uh security advisor. Two is to sign up for our cyber hygiene program which is a continuous monitoring of what's happening uh on their uh what vulnerabilities they're exposed to. Uh thirdly is to patch those vulnerabilities, right?
▶ 0:33:43Uh another thing that they can do is um make sure that their their employees understand the threat that you know fishing attempts and those kinds of things. So internal education. The other thing that I really think bears special attention is small businesses are critical to the supply chain of our national security and as such whether they may not be prime contractors they may be they may be subcontractors or they may be supplying to those people it is important that the
▶ 0:34:14products uh that they purchase are secure and so they have the power of both their voice and their purse and what we're really trying to do is um drive secure by design so that the product that a small business buys is secure by design. There should not be known vulnerabilities. There should they shouldn't have to turn on security features. They shouldn't have to go and figure out how do I do this.
▶ 0:34:39Those products that they are buying and they're installing to drive their business which creates jobs and economic revenue. They should be secure by design. They can have their voices heard talking through membership through their congressional members to have industry develop and deploy secure technology. So there's things they can do immediately and then there's things that they can do uh that will have a longer term impact but they are very powerful. Great. Thank you so much. Thank you for that chairman. I yield back.
▶ 0:35:10Thank you sir. Uh Mr. G. Floor is yours for four minutes. Thank you Mr. Chairman and Director Bane. Thank you for joining us this morning. I want to talk a little bit about public private partnerships. something I know that CISA has uh done extremely well particularly with things such as the JCDC um and we know that these public private partnerships uh they promote shared situational awareness faster response some more unified um front against cyber attacks and so
▶ 0:35:40uh just uh with the agency going forward can you talk a little bit about one the importance of these public private partnerships how we can grow and expand those and maybe maybe a a little more particularly about some of the great work that the JCDC has been doing. Well, hotty toty, I just love that question. Um, CIS is built on public private partnerships. I mean, we're not regulatory. Everything we do is through trusted established relationships.
▶ 0:36:11Um, and that is truly, you know, the mandate that you've given us is to build public private partnerships. And that's what that's what we're doing. But it's critically important. We just talked about the Spain incident. Without those existing relationships and partnerships, we would not have been able to reach out immediately to get the information. Had it been a cyber incident, we would have been able to get uh indicators of compromise, all kinds of things that we could have then brought home and worked on our own networks.
▶ 0:36:39Um we are we are uniquely positioned the authorities that you have given us uniquely position us between the private sector the public sector our international partners and through through that place where we sit we are able to share and get information that's critically important that we can then share with all 16 critical infrastructures.
▶ 0:37:01Um the JCDC is um you know it is it is by nature a partnership building organization and it is through that trusted relationship that people share information with us. You know those who are competitors uh on the P&L sheet are collaborators in the SISA world because they know and there's trusted and they know that this information is going to be used to secure our homeland. So they are sharing information that they would not share with competitors otherwise.
▶ 0:37:30And so we build it at the national level, at the international, but also at the local level. And so our field forces are in constant communication with JCDC. JCDC asks our regional folks to get with their the people they know and trust on the ground. It is quintessential to our success to make sure that these public partnerships continue and that we grow them. Yes, ma'am. And then let me ask, you talked a little bit about cyber criminals, cyber attacks, exploiting known vulnerabilities.
▶ 0:37:59Um, you know, I think one of the ways that we can harden our systems is uh patching vulnerabilities within operational systems. And we've had public service efforts and we're trying we always try to encourage people, you know, get the newest and latest uh security update. Um, uh, and it seems like that so many of us don't and and I'm probably one of those that probably doesn't update my phone as as often as I need to.
▶ 0:38:24uh so some of this may be talking to me but without government heavy-handedness uh and mandating these sorts of things what can we do uh either through policies or incentives or standards to encourage more people to stay ahead of these cyber attacks um by timely patching of operational systems within their uh with within their business community and their business model. Yeah. Um, you know, the patch Tuesdays just don't work anymore.
▶ 0:38:54Um, and you know, you as we look across the whole ecosystem of cyber security, uh, companies, businesses, small businesses, the burden shouldn't be on them. And again, I'm going to go back and and foot stomp secure by design. Uh, but these patches need to be done and, you know, forcing those installation.
▶ 0:39:14I am really encouraged though that as I look at at my children, my grandchildren and and and the and the workforce we have, this digital interconnectivity is just a way of life. And so I think that they will be the driving force just to have it in our DNA. That's just going to be a standard operating procedure.
▶ 0:39:35also to raise the awareness that if you don't, you're not just opening yourself up to uh a cyber attack, but because you're so connected to everybody else, you are then the weakest link in the chain. And I think most Americans don't want to be that. And so to the extent that we can help people understand how connected they are and that your family, your friends, your business partners, and the nation, our security depends on you doing this. But we also have to make it simple and easy.
▶ 0:40:03And I think that our technology companies need to do their fair share. One, that they don't exist when the product is released and then making sure that those patches are done timely and make it easy for folks to install them. Thank you, Mr. Chairman. I yield back. uh the grandmaster of questioning on the committee, Mr. New House, the floor is yours for four minutes. 14.
▶ 0:40:30I want to thank all the other committee members for saving time so that Mr. New House can be himself. Thank you, Mr. Chairman. You're too generous. You really are. Um, Miss Bean, thank you for being with us today. Um, I was going to bring this up anyway, but for sure after Mr. Guest's point, his question in in your testimony, you talked about the the number of trainings offered to uh support the private sector as well as local governments.
▶ 0:40:56and um they they truly are a critical function of what what the agency does. I just wanted to say that last summer, this is a plug for you I guess that CISA provided some of my constituents with a briefing during an agricultural threats roundt and also just in March protecting food from farm to table with cyber security and protective emphasis workshop and I just want to say it was highly regarded very well received Chad Hudson just to give him a call out the regional
▶ 0:41:27uh affairs officer was very helpful so I'd encourage you to keep that up and it helps all of us be stronger. But I want to real quickly in the time I have left just you know the the the threats from China are huge. I just came from the a select committee on China and now I won't be able to sleep tonight because of some of the things I learned there but but the they're moving from economic and intelligence espionage to threatening our infrastructure things that you know keeping the lights on and all that kind of stuff.
▶ 0:41:56At least that's my understanding. So in your gut, do you feel that do you believe that you've got the structure that's adequate for defending the US against these kind of things? And if not, what can what can we do to help? Um, you're right. I mean, China is the most prolific dominant threat we have. And they are doing it for three reasons, right? They are doing it for espionage. They're doing to steal our intellectual property.
▶ 0:42:24And they are getting into our critical infrastructure and they are waiting. They are patient. They're persistent. They have decades of experience. And they are waiting to disrupt or destroy our critical infrastructure at the time and place of their choosing. That's right. And they want to do they want to do it to either discourage us should there be a conflict with China over Taiwan.
▶ 0:42:52and two things. We are not making them work hard enough. make it harder for them. We need to make it harder for them. And so the work that we're doing and and I this is all part of the answer. Our known vulnerabilities catalog and helping making sure that there's mitigating strategies, that's a huge way. The more we can make it hard for them to get into our critical infrastructure, the better it is. Okay, we have the tools to do what we need to do.
▶ 0:43:20We need to make sure that we are leveraging every partnership we have, that we're making sure that people understand the threat, that everybody is doing what they need to do. I don't know if you saw, but uh two weeks ago, Secretary Gnome went out to the RSA conference, which is one of the leading cyber security conferences. Thanks so uh out in San Francisco. And I think she went for two reasons.
▶ 0:43:42One, I think she wanted to let uh the world know that cyber security is part of our national security plan, right? We're going to defend our homeland on land, air, border, sea, uh, and cyber. So, she was she was putting that call out there. Yeah.
▶ 0:44:01And I think to the SISA family, she was saying, "I support you, that you are part of this national security and that you that we play a critical role in that plan and that she supports us." So, we have the tools. What we need to be able to do is be um more streamlined, more efficient, make sure that we are looking at the highest threats and the most vulnerable entities and taking our precious resources and driving them to buy down that risk in that area that we know the adversaries are targeting. Good.
▶ 0:44:29So, it's working with the IC community to understand who are the targets, understanding the tools that will best address it, and then deploying it and working in partnership with those to make sure that they take those actions needed to drive down the risk. Good. Thank you very much. Thank you, sir. and yield back to the best subcommittee chairman on the entire Well, is there any more time you'd like, Mr. New House? We can call you Mr. Rutherford and use his.
▶ 0:44:57Well, first of all, I want to thank the committee for being true leaders in every stretch of the word in terms of trying to be efficient with our use of time today with other schedules and stuff like that. Uh, Madame Director, um, thank you very much for appearing here today with your folks. I am going to ask a couple of questions, but go ahead start this for me, too. You know, I mean, I'm not a hypocrite most of the time. Um, so a couple of things.
▶ 0:45:25First of all, some people have talked with you about outreach. So, when we uh work up the bill, I think it's not news that outreach is phenomenally important to everybody on the committee. I think it's a very good thing that you do. And so we're going to be looking specifically at I mean, let's face it, the context that we will be marking up the bill for your budget is one that frankly has some challenges for us in terms of what may be asked for.
▶ 0:45:54Nobody leave the room saying that I'm challenging you on it. But please leave the room and and if you think there's a message there, here it is. You guys have been asked to transfer $139 million in in a reprogramming request and you've also been cut a half a billion dollars or whatever it is numbers we would like to know. So before the markup in a timely manner before the markup it's like so how's this affect things? You say what the heck did he just ask?
▶ 0:46:24I'm not a guy that believes more money is the answer to everything, but I am all but I am very definitely. I don't speak for anybody but me, but I think there's a theme here, which is um I want to know where the 139 million's coming from in the reprogramming before we act on that. And the second thing is I want to know how the 150 the half a billion basically comes out of that in the context of your mission. Um, and I get that in the past that there was like, well, they were doing stuff they shouldn't have been doing.
▶ 0:46:54I'm not concerned with any of that right now. I'm concerned in what we're doing now in doggy and I'm concerned with what we're doing in fiscal year 26. And when I hear people like the subcommittee chairman from New York uh on on the policy committee and the chairman of the policy committee talking about China's eating our lunch, my words, not theirs.
▶ 0:47:13But in other words, and I know you can never say mission accomplished, but we want to know specifically, it's like, so I I know you're being reorganized and all that other sort of stuff, but at the end of the day, if there's a big meltdown and and somebody's going to go, well, how come you folks approved cutting a bunch of stuff? And it's like, I at least want to be in the position. We asked the questions. We looked at the data. We thought we had done the right thing. I mean, perfection is the standard, and we're all human.
▶ 0:47:43So that's not going to be achieved. What I don't want to be in the position at the end of this is, oh yeah, go ahead and all that when it might be kind of obvious. It's like, well, you get what you pay for. More money is not automatically the answer, but I'm not talking about more money. I'm talking about approaching threequarters of a billion dollars between reprogramming and and and the cuts based on the skinny budget.
▶ 0:48:11And you say, "What the heck's the question?" The question is this. Why shouldn't I be worried about where we're sitting in terms of of all the issues that you've talked about as a result of those cuts? And if the only thing that's going to come back is a general, well, we're reorganizing and refocusing, please pass up the chain, ma'am, that that dog won't hunt. And it ought to scare the heck out of everybody in this room to think that these people sitting around this table are going to do your budget for you if we don't get something.
▶ 0:48:42So, you know, I mean, I would be scared if I was doing my own budget even. So, um, we would like that feedback from you folks, uh, in in a pretty timely manner and, uh, um, and we also look forward to hear to hearing as it goes forward what's going on in the reorganization because I'm guessing we're going to have to do this budget before the reorganization's done.
▶ 0:49:06And so if that's a big unknown out there, that's going to be a problem for these people being able to say that they had a pretty good snapshot of what the facts were and and what we Uh I'm being bullied up here about stuff that I guess I'm supposed to read. Not your fault, Madam Ringham.
▶ 0:49:28Um, so I'm going to start about uh I already said that I look forward to continuing the discussion on how we refocus CISA but still maintain our core cyber defenses. I think I said that. Um, here's the part. We won't surprise you. Don't you surprise us. Um, for the get back questions the members uh had today, we ask that you respond within 15 days.
▶ 0:49:57There may be some additional questions members provide in writing. We ask you to respond to those in a timely manner. Thank you, ma'am. Uh you and your agency, your professionalism and whatever are noted. Uh I want to make that specifically part of the record today. We look forward to working with you. Um and with that subcommittee stands ajourned. Thank you. Great job. Thank you so much. Look forward to working with you. Enjoy your weekend.
▶ 0:50:27Yes, you do. Same. Thank you so much. Thank you so much. I really you must be very thankful.
▶ 0:51:10Did you make it down to football? We need you to