Oversight Hearing – The Cybersecurity and Infrastructure Security Agency

DHS Budget and Border OversightHouse Appropriations Subcommittee on Department of Homeland Security · 2025-05-08 · 119th Congress
The House Appropriations Subcommittee on Homeland Security held an oversight hearing on the Cybersecurity and Infrastructure Security Agency (CISA), examining the agency's fiscal year 2026 budget request, a proposed reduction in force, and its response to recent cyber incidents including a data-security episode at the National Labor Relations Board. Begins at 0:00:57
Transcript
Highlights

Title

CISA oversight hearing on budget cuts, staffing, and cyber threats

Purpose

The House Appropriations Subcommittee on Homeland Security held an oversight hearing on the Cybersecurity and Infrastructure Security Agency (CISA), examining the agency's fiscal year 2026 budget request, a proposed reduction in force, and its response to recent cyber incidents including a data-security episode at the National Labor Relations Board. Acting Director Bridget Bean testified about CISA's core missions, threat trends from China and Russia, and public-private partnerships, while members pressed her on proposed funding cuts, election-security staffing, and DOGE-related data access concerns. Begins at0:00:57

Who spoke

Subcommittee Chairman (presiding, unnamed in transcript)0:00:00: Opened by limiting member questioning to four minutes0:00:00; later pressed Bean directly on a $139 million reprogramming request and a roughly half-billion-dollar cut, asking for detailed justification before markup0:45:540:46:24; adjourned the hearing thanking Bean for her work0:49:57.

Ranking Member Lauren Underwood (D-IL)0:00:57: Said CISA funding grew 75% from FY2019–2024 with bipartisan support but the administration proposes an almost 20% cut ($491 million)0:01:280:01:55; cited 2016 Russian hackers stealing data on about 76,000 Illinois voters0:02:14; questioned Bean at length about a whistleblower complaint alleging a DOGE team removed sensitive data from the NLRB and suspicious login attempts from a Russian IP address0:10:46.

Bridget Bean, Acting Director, CISA0:05:25: Outlined CISA's mission and cited metrics including 1,300+ known exploited vulnerabilities catalogued0:08:28, 4,000+ ransomware notifications0:08:02, and 700 million malicious connections blocked in Q1 20250:08:55; confirmed Russia remains a cyber priority0:10:22 and that CISA was not asked to assist with the NLRB incident0:12:04.

Rep. Henson0:13:31: Asked about CISA's attack surface management program as a core capability against nation-state actors like China0:14:49 and about TikTok's ban from federal networks0:16:42.

Mr. Quay0:17:41: Discussed government efficiency reforms, citing a 1990s Texas "doggy" cost-cutting effort and the 2010 Government Performance and Results Modernization Act's reporting requirements0:18:240:19:16.

Rep. Gonzalez0:21:10: Asked about CISA partnerships with universities like UT0:21:40 and about the April power outage in Spain and Portugal, which Bean said was not cyber-related0:23:170:23:46; also asked about oil-and-gas sector hardening after Colonial Pipeline0:25:33.

Rep. Veronica Escobar (D-TX)0:27:34: Pressed Bean on whether CISA was consulted as DOGE staffers accessed sensitive data and reports of data shared via personal Gmail accounts0:28:240:30:05; Bean said she lacked information but would follow up0:30:30.

Rep. Juan Ciscomani (R-AZ)0:30:59: Asked about resources for state, local, and small-business cybersecurity, prompting Bean's explanation of regional security advisors and "secure by design" principles0:32:000:33:43.

Mr. G0:35:10: Asked about public-private partnerships and the Joint Cyber Defense Collaborative (JCDC)0:35:40, and about incentivizing timely patching without government mandates0:38:24.

Rep. Newhouse0:40:30: Praised CISA training for agricultural and food-sector cybersecurity in his district0:40:56; asked whether CISA has adequate structure to counter China, which Bean called "the most prolific dominant threat"0:41:560:42:24.

Key moments

Underwood: SISA funding rose 75% from FY2019–2024 with bipartisan support, but the administration proposes a near-20% cut of $491 million0:01:280:01:55.

Underwood cited the 2016 Illinois election hack, in which Russian actors stole personal data of about 76,000 voters0:02:14.

Underwood detailed a whistleblower complaint alleging a DOGE team at the NLRB removed sensitive data, disabled monitoring, and that suspicious login attempts then came from a Russian IP address; a formal computer emergency readiness team response was allegedly blocked0:10:46.

Bean confirmed CISA was never asked to assist with the NLRB incident and has no knowledge of who declined to create a response team0:12:040:12:33.

Bean reported CISA blocked 700 million malicious connections across the federal government and 60 million across critical infrastructure in Q1 2025 alone0:08:55.

Bean said CISA's known exploited vulnerabilities catalog now exceeds 1,300 entries, with private-sector remediation occurring an average 15 months earlier as a result0:08:28.

Escobar pressed on reports that DOGE staffers shared sensitive data via personal Gmail accounts; Bean said she had no information on whether CISA reviewed what data was accessed or how it was shared, and pledged to follow up0:28:240:30:30.

The chairman pressed Bean on a $139 million reprogramming request and an approximately half-billion-dollar budget cut, asking for a detailed accounting before the subcommittee marks up the bill0:45:540:46:24.

Bean described China as the "most prolific dominant threat," pursuing espionage, IP theft, and pre-positioning in critical infrastructure to disrupt it at a time of its choosing, including over a potential Taiwan conflict0:41:560:42:24.

Bean said nation-state actors increasingly use "living off the land" techniques exploiting known misconfigurations rather than novel tools, making detection harder0:26:03.

Metadata

CommitteeHouse Appropriations Subcommittee on Department of Homeland Security
Chamber / CongressHouse · 119th Congress
Date2025-05-08
TypeHearing
Witnesses
Bridget Bean — Acting Director, Cybersecurity and Infrastructure Security Agency
Videoyoutube
Transcript117 caption blocks · 8,882 words · 0:51:21 runtime
EventCongress.gov 118194