▶ 0:15:15Committee on Homeland Security subcommittee on cyber security infrastructure protection will come to order. Without objection, the chair may declare the committee in recess at any Purpose of this hearing is to examine the evolution of cyber security threats to US critical infrastructure following discovery of the stuck stucket mal malware 15 years ago. We will highlight the importance of securing operational technology or OT to bolster critical infrastructure resilience.
▶ 0:15:40I now recognize myself for an opening 15 years ago, the world learned of a computer worm that forever altered the cyber threat landscape. Regarded as the world's first digital weapon, it was designed to target industrial control systems. It was used against Iran's nuclear program reportedly destroying a thousand centrifuges at the Natan's en enrichment plant. Malware or malicious software has existed since at least 1970s.
▶ 0:16:10However, Stuckset was different from its predecessor. The discovery of it demonstrated both the physical impact of malware and raised important questions about cyber security defense and offense. These are issues we continue to face today. It revealed the significant impact that offensive cyber tools can have on critical infrastructure. It also demonstrated importance of securing operational technology by exploiting key vulnerabilities in industrial control systems. It pro it proved that cyber security is not only an IT issue.
▶ 0:16:40Cyber security threats can affect critical infrastructure we t depend on daily from water treatment to energy facilities. The cyber security threat landscape continues to expand and we need to make sure our cyber professionals are prepared to defend both IT and OT. Doing so will strengthen the public and private sector's ability to rapidly respond to threats. Since discovering suckset 15 years ago, cyber security threats to critical infrastructure have drastically evolved and spread above beyond just malware.
▶ 0:17:10We now see various CA cyber capabilities being used to hack critical infrastructure including fishing, social engineering, denial surface attacks and more. While cyber attack vectors have grown and matured, malware is still of great concern. Malware comes in many forms such as key loggers, spyware, viruses, and ransomware.
▶ 0:17:30With ransomware comprising one-third of all cyber attacks in 2024, the interconnected nature of our networks, devices, and infrastructure means that critical infrastructure owners and operators now experience far more attacks than when sucks was unleashed, and zeroday vulnerabilities are far from being eliminated. Strengthening domestic cyber security resilience remains a key priority for this committee.
▶ 0:17:53Considering the sophisticated cyber security threats we now face, we are once again reminded of the importance of reauthorizing two key authorities ahead of our their expiration this year. The cyber security information sharing act and the state and local cyber security grant program. Reauthorizing CISA 2015 will ensure we keep encouraging rapid and trusted information sharing among public and private sector entities and extending the state and local cyber security grant program will make sure that states and localities have reliable funding to strengthen their cyber security posture.
▶ 0:18:23It is all also worth examining that state of the Iranian cyber threat and potential impact stakna had on Iran cyber security posture. According to Nomi Networks labs, cyber attacks from Iranian threat actors surged by 133% in May and June of 2025. An active Department of Homeland Security National Terrorism Advisory System notice also emphasizes the need to remain on high alert to Iranian cyber security threats to US critical infrastructure.
▶ 0:18:52Iran has embraced the targeting of critical infrastructure. The Islamic Revolutionary Guards Corpse affiliated actors have recently targeted OT such as US industrial control systems in key sectors such as water and healthcare. I look forward to examining the current threats facing US critical infrastructure and during significance of SXNet with our panel of expert witnesses today. Today's witnesses represent a range of perspectives and I thank you all for contributing to our discussion about this pivotal moment in history of cyber security.
▶ 0:19:22I'm confident that your testimony will help us form a better understanding of today's digital weapons and the state of US critical infrastructure resilience. I now recognize the ranking member, the gentleman from California, Mr. Swallow for his opening statement.
▶ 0:19:35Thank you chairman and chairman. That was a eloquent, impactful, artful statement, but you buried the lead. Our chairman of the subcommittee has been selected by his colleagues to be the chairman of the full committee uh with the resignation of Chairman Green effective earlier this week. So, congratulations. I'm I'm excited for what that means for the full committee.
▶ 0:20:03You and I have worked quite well over the last three years on this committee, especially to take on our cyber challenges. And to have somebody at the full committee with your cyber knowledge and expertise as our cyber threats are only escalating and AI has made that even more challenging and the threat of quantum computing and what that means for cryptologology. Uh you're the right person uh to help lead the committee to do that.
▶ 0:20:31So looking forward to working with you and I think I speak on behalf of my colleagues uh that uh we congratulate you on that win. Earlier this summer uh chairman Mark Green uh and I went out to my congressional district and visited Lawrence Livermore National Laboratory uh and committee staff from both sides were there as well. As you know, Lawrence Livermore National Lab is the nation's premier research and development facility.
▶ 0:20:56It attracts the best and brightest minds from around the world and helps keep the United States on the cutting edge of innovation, particularly related to national security technologies. Lawrence Livermore and our national labs are indispensable partners in our national effort to defend cyerspace, keeping their finger on the pulse of our adversaries tactics and motivations while helping to develop novel technologies to detect and disrupt malicious cyber campaigns.
▶ 0:21:21We saw Lawrence Livermore works first firsthand and it's critical to national efforts to secure critical infrastructure our constituents rely on every day and the operational technology that underpins it. The lab's work is paying off dividends especially related to the Chinese threat actors like Volt Typhoon and I'm pleased that the lab today through Dr. Gleason's testimony will talk about its important work.
▶ 0:21:44Notably, the lab is a key partner in CISA's cyber century program, which places sensors on private sector networks on a voluntary basis to monitor for and detect cyber threats. The lab contextualizes data from the cyber century program with other intelligence feeds, generates unique insights into malicious cyber activity, and provides network defenders the know-how to kick out the adversaries.
▶ 0:22:09The knowledge derived through the lab's work benefits programs and activities across SISA and I'm eager to learn how Lawrence Livermore and the national lab community can continue to support federal efforts to better secure operational technology. Additionally, I'm interested to learn how other programs at sector risk management agencies and SISA like the Joint Cyber Defense Collaborative JCDC support efforts to mature our collective approach to security.
▶ 0:22:36It's incumbent on the federal government to collaborate with its private sector partners to bring security resources to bear to these underresourced sectors. Also, at this point, I want to just remind the committee and the public that SISA can only function uh when it is fully staffed. It should not be free from reforms, but currently it has lost approximately a thousand employees uh since the Doge cuts began to take place.
▶ 0:23:05that affects its ability to work with the private sector and be responsive. Fewer brains and reduced funding means less capability, less capacity, and less collaboration, which is detrimental to ongoing efforts to mature operational technology security programs. And also, I'd like to reiterate my strong support for the reauthorization of the other SISA, SISA 2015.
▶ 0:23:27Stakeholders have referred to CISA 2015 as the most successful cyber law ever passed and I was a part of writing it and passing it in 2015 as a member of both this committee and the House Intelligence Committee. We cannot allow this critical authority to lapse. Toward that end, I was pleased to see a clean 10-year extension included in the Senate Intelligence Authorization Act for fiscal year 2026. It sends a clear message to our partners and our adversaries that cyber security continues to be a bipartisan priority in Congress.
▶ 0:23:57I look forward to working with my House colleagues to provide non-federal stakeholders the certainty they need to continue their strategic collaboration with the government by passing a clean authorization before it lapses later this fall. With that, I yield back.
▶ 0:24:13Gentlemen yields back. Other members of the committee are reminded that opening statements may be submitted for the record. I am pleased to have a distinguished panel of witnesses before us today. I ask that our witnesses please rise and raise their right hand. Do you solemnly swear that the testimony you will give before the committee on homeland security of the United States House of Representatives will be the truth, the whole truth, and nothing but the truth? So, help you God. Let the record reflect that the witnesses have answered in the affirmative.
▶ 0:24:42Thank you, and uh please be I would now like to formally introduce our witnesses. Miss Kim Zeter is the author of Countdown to Zero Day, Suckset, and the launch of the world's first digital weapon and an adjunct professor at Georgetown University. She's also an award-winning investigative journalist who was was who has written on cyber security and national security for more than 20 years. Zetter began her career covering security and privacy issues for Wired where she wrote for 13 years. Mr.
▶ 0:25:12Robert Lee is the chief executive officer and co-founder of Draos, a global technology leader in cyber security for OT and ICS environments. Mr. Lee also serves as a lieutenant colonel in the Army National Guard where he designs and leads OT cyber security response efforts. He's a member of the World Economics Forum subcommittees for the oil, gas, and electricity communities and he serves on the advisory boards of the International Society of Automation and National Crypto Cryptologic Foundation.
▶ 0:25:40Miss Tatiana Bolton currently serves as executive director of the operational technology cyber security coalition where she advocates for effective OT cyber security and critical infrastructure resilience. Prior to her current role, Miss Balden served as a senior security policy manager at Google's security center of excellence. Before joining Google, Miss Balden directed the cyber security and emerging threats program at the R Street Institute and served as policy director of the cyerspace solarium commission. Dr.
▶ 0:26:10Nate Gleason is the program leader for cyber security infrastructure resilience within the energy and homeland security program at Lawrence Livermore National Laboratory. Prior to joining Lawrence Livermore, Dr. Gleason spent 12 years at Sandia National Laboratories in a variety of tech technical and management positions including deputy to the vice president for the California Laboratory and deputy program director for Sandia's homeland security program. I thank the witnesses for being here today. I now rec recognize Miss Zeder for five minutes to summarize your opening statement.
▶ 0:26:41Thank you uh Chairman Garberino, ranking member Swallwell and members of the subcommittee. Thank you for this opportunity to testify about Stuckset and threats to critical infrastructure. My name is Kim Zedern and I'm a cyber security and national security journalist as well as an adjunct professor at Georgetown University and the author of the book on stuckset countdown to zero day. It was 15 years ago that stuckset was discovered on systems in Iran. But despite the passage of time, the its impact is still felt today.
▶ 0:27:06Stuckset was a digital weapon designed to sabotage Iran's nuclear program by targeting industrial control systems at its uranium enrichment plant at Natans. But these are same kinds of systems used in US critical infrastructure. I've been asked to describe how stuckset operated and the implications for US critical infrastructure and whether these systems are any more secure today than when stuckset was discovered.
▶ 0:27:27Stuckset was a first-of-its-kind attack, the first known case of malicious code designed to leap from the digital world to the physical realm to cause disruption and destruction not of the computers it infected, but of equipment and processes these computers controlled. In this case, the centrifuges at Natan.
▶ 0:27:44The same techniques stucket use can be used against critical infrastructure in the US to disrupt services the public, government and military rely on or to damage equipment that can also cause death either directly by causing passenger trains to collide or indirectly by by preventing patients from being treated at hospitals because the electricity is out. I provided in my written testimony details about how stuckset operated. So I won't go into them here, but I want to point out two things that are relevant.
▶ 0:28:09First, Stuckset spread to millions of computers, but it only unleashed its destructive payload on the specific systems its creators were targeting. It didn't sabotage other systems because Stuckset was a highly sophisticated, carefully crafted and tested precision weapon designed to avoid collateral damage. Other attacks, however, don't need to be precise or sophisticated to cause disruption or damage. This is worth noting given the recent warnings about the potential for Iran to launch cyber attacks against the US.
▶ 0:28:38Iranian hackers don't have the skills to pull off a stuckset-like attack, but they don't need them to disrupt or damage systems. Second, when stuckset was first discovered, researchers believed it was an espionage tool. This is because every time it infected a new system, it searched for the presence of Seaman's industrial control system software. Seaman software is used to control manufacturing assembly lines and other industrial processes. So, researchers believed whoever was behind the malware was trying to steal blueprints or designs for industrial plants.
▶ 0:29:07After reverse engineering the code, however, they realized it was designed for sabotage. This is significant because disruptive or damaging attacks can be indistinguishable from espionage in the initial stages of infection. Both can use the same tools and techniques to gain access and move within networks to find data or the systems they want to disrupt. What's more, intrusions done initially for intelligence purposes can morph into disruptive or destructive operations.
▶ 0:29:33I say this because a lot has been written recently about the salt and volt vault typhoon intrusions of telecoms and critical infrastructure that are attributed to China. These compromises don't appear now to be aimed at disruption or damage but could morph into such operations in the future. One of the most significant impacts of stuckset was stuckset had was to raise awareness about vulnerabilities in critical infrastructure. Prior to Stuckset, the security community was focused on IT networks, the business networks that you use to send email. But Stuckset put OT networks in the spotlight.
▶ 0:30:02And once researchers began to examine them, they discovered serious software flaws as well as architectural problems that couldn't be fixed with a software patch. They also found many systems connected to the internet. The following is a small sample of processes that industrial control systems control. opening and closing cell doors at high security prisons, operating traffic lights and HVAC systems, routing computers uh routing commuter and freight trains and to prevent collisions. Uh controlling temperature at which food is pasteurized and steel is forged.
▶ 0:30:32Operating chemical and pharmaceutical plants and control of the flow of electricity. A lot has been done since Duckset to secure critical infrastructure in the US, but many issues persist. I'll just give one example before I close. In 2009 in Washington DC, a metro train plowed into the back of another train stopped at a station during the afternoon commute. Sensors on the track should have indicated to the incoming train that a train was stopped ahead of it, but the sensors failed and the collision killed nine people and injured 80 others. This wasn't caused by a cyber attack.
▶ 0:31:02But this month, CISA issued a security alert about a decade old flaw in train braking systems that hackers could exploit to cause a collision like the one in 2009. That flaw exists in the protocol the devices located in the front and back of trains used to communicate with each other to engage the brakes. The protocol uses weak authentication which means an attacker can impersonate one of these devices to cause a train to suddenly to suddenly halt or the brakes to fail. The flaw can't be exploited over the internet.
▶ 0:31:30An attacker needs proximity to to uh send a command. But this doesn't make it any less dangerous. The researcher who discovered the flaw discovered it in 2012 and reported it to the Association of American Railroads. But the AER reportedly dismissed it, believing no one could exploit it. It was only this year after the research and SISA threatened to go public that the AR announced it would replace the protocol. A new protocol won't be ready until 2027 at the earliest. Thank you.
▶ 0:32:01Thank you, Miss Eter. I now recognize Mr. believe for 5 minutes to summarize his opening statement.
▶ 0:32:06Chairman Garbuno, ranking member Swallwell, members of the subcommittee. 15 years ago, Stuckset proved cyber attacks could cause physical destructions. Attacks on OT networks are under sustained and sophisticated assault from our adversaries today. I'm Robert Lee, CEO of Draos, a former Air Force officer and NSA and now serving since the last time we all met in this committee in my role in Lieutenant Colonel uh in the Army Guard, designing out OT defense strategies. I spent my career protecting these industrial systems that power our society. Let me be blunt.
▶ 0:32:34We are not prepared for a major attack on our critical infrastructure. We know that such an attack would be part of any major conflict with an adversary. We are not doing enough to prepare and the results of continued failure could be catastrophic, including the loss of life. At DRAOS, we track over 25 state and non-state actors that target operational technology directly. Nine different malware families have been built specifically for industrial systems. The most versatile is very opposite to stuckent where stucksent was very very targeted.
▶ 0:33:00Pipe dream can be used against everything from unmanned aerial vehicles to water systems to power systems. Increasingly homogeneous machinery and technical systems have increased the OT attack surface and raised the potential consequences of a large-scale attack. But defense is doable. One example, Littleton Electric in Massachusetts used a federal grant to install our technology on their network after FBI intel indicated to them that they were being targeted by Volt Typhoon. We detected, isolated, and mitigated the attack with their partnership.
▶ 0:33:28They were able to do this because they had visibility in their OT networks and they were proactive in their security. Most companies don't do this. We know what works. Here are a few things that I recommend that we can do. First, we must stop treating OT like it. These systems have different risks and require different defense strategies. Hearings like this one are critical to raise awareness on this distinction. A significant portion of the funding and resourcing in the community goes to it. Whereas the critical part of critical infrastructure is OT.
▶ 0:33:57Second, make public private partnerships count. At DRAOS, we uncovered pipe dream in coordination with the NSA and an undisclosed third party. We ended up coordinating with SIZA and and the electric ISAC and that allowed us to warn operators before the adversary was even allowed to deploy it against targets across the United States. Broad unfocused information sharing efforts though do not work. Targeted focus coordination does. Third, we must streamline federal guidance.
▶ 0:34:24Right now, too many agencies are sending too many messages, many of which are overlapping and often contradictory to our industry. We have to tell the industry, "Here's the threat. Here's what success looks like." We have to let them handle the how. Right now, it is extremely confusing for asset owners and operators on turning to who is going to be the one to help them, and most importantly, what the actual guidance is that they should follow beyond regulatory. Fourth, we have to let the private sector lead on technology. We already have the tools to detect advanced threats.
▶ 0:34:53Federal efforts to replicate them just waste money and slow adoption. Fund deployment, not reinvention. Government should focus on over the horizon threats. The private sector has already created the tools and techniques uh needed to deal with the threats in the here to now. It's just about execution. Government tools have consistently un underperformed in comparison to private sector tools and at a higher cost to taxpayers. Fifth, secure the supply chain. Critical infrastructure vendors must meet real security standards.
▶ 0:35:23Right now, all of the focus is placed on asset owners and operators and not the vendors. Asset operators and their vendor community should share responsibility for meeting basic security requirements for all the components that are installed into our critical infrastructure. Even the security vendors. As a CEO of DRAOS, I'm surprised that I have the amount of flexibility I do to make willfully poor security choices to increase my margins. Though we have not done that and would not do that, I'm surprised by the ability of CEOs to make that decision.
▶ 0:35:51I believe we need higher standards and more selectivity into who can sell into critical infrastructure and how. Finally, we need to fix federal response coordination. Most operators simply don't know who to turn to uh to call after an incident or what they'll get in response. And responses differ across state lines and there's no basic credentiing for who shows up and what they can do. I'm helping write a national OT response plan in my role with the 91st Cyber Brigade, but we need legislative support to cut through the bureaucracy.
▶ 0:36:19I found great partnership in this effort with SIZA, particularly strong support with Shawn Planky, and I look forward to his confirmation. We simply know what needs to be done, and it's time to stop standing in our own way. Our kids' lives depend on it. To close, our adversaries are gaining ground, but we have the tools, the knowledge, and the people to win. Now, we need large-scale execution in the public and private sectors. We know what needs to be done. We just need to do it. I'm grateful to all of you for holding this hearing and look forward to the rest of our conversation. I yield back my time.
▶ 0:36:53Thank you, Mr. Lee. I now recognize Miss Bolton for five minutes to summarize her opening statement.
▶ 0:36:58Thank you, Chairman. Uh, Chairman Garberino, ranking member Swallwell, and members of the subcommittee. Thank you so much for the opportunity to testify today. I commend the sub subcommittee for prioritizing critical infrastructure security and holding this hearing to discuss the heightened threat landscape. My name is Tatiana Bolton and I'm the executive director of the operational technology cyber security coalition.
▶ 0:37:18The OTCC is a coalition of OT cyber security organizations, critical infrastructure operators and thought leaders representing the entire OT life cycle and protecting our nation's critical infrastructure assets. We provide vendorneutral perspectives on securing our collective defense and advocate for improved OT security policy.
▶ 0:37:39Stuckset marked a pivotal moment in cyber warfare by demonstrating that digital tools could indeed cause real world physical destruction to systems known as operational technology or OT. OT is the technology that makes machine run machines run like pumps and valves on the manufacturing room floor. It's uh or machines that control compressors and filters in a water treatment facility. It's crucial to recognize as Rob said that operational technology OT is distinct from in information technology IT.
▶ 0:38:10Their respective security requirements differ considerably. OT cyber security must prioritize safety, reliability and physical process continuity and these systems can be older having been built to last decades and many never designed to be connected to the internet in the first place.
▶ 0:38:27Despite the elevated risks associated with attacks on OT system OT systems, this area of cyber security remains significantly underprioritized and underfunded, the OTCC is working on a number of efforts and has provided multiple recommendations to the committee and I'd like to highlight a few of them here for my written testimony. First, we need to focus on awareness. The United States must prioritize OT cyber security to prepare critical infrastructure against the growing threats.
▶ 0:38:55Our government has acknowledged that US infrastructure is at risk. However, it has not taken sufficient steps to address the growing vulnerabilities in the wake of attacks like cyber avengers or vault and salt typhoon. While securing it is important, the OT systems that if attacked turn off our lights, bring hospitals to a standstill and disrupt essential Congress must urgently answer the question of who holds responsibility for these risks as a debilitating cyber attack on our critical infrastructure would
▶ 0:39:25demand clear accountability. Second, Congress must reauthorize SIZA 2015. In May, our coalition submitted a letter to this committee urging the reauthorization of the Cyber Security and Information Sharing Act of 2015, which will expire in September of this year. As you all know, this legislation is crucial to information sharing and strengthening US collective defense. Both public and private sector security teams rely on information sharing from other organizations to strengthen their defenses.
▶ 0:39:55If the legal protections established by this act were to lapse, this flow of information would be disrupted up to 80 to 90% and national security put in jeopardy. Third, we must better resource OT security. From addressing the growing tech debt, hiring cyber security experts to procuring and building updated and secure systems, OT owners and operators don't have the necessary funding to defend their networks. And often 99 cents of every dollar is spent on physical security.
▶ 0:40:26We need to address critical infrastructure security through a whole of nation approach. Just as we wouldn't expect an individual county such as PK County in Texas to defend themselves against missile strikes from a nation state actor, we shouldn't expect them to respond to cyber attacks on their own. This is a national security priority. This is why the state and local cyber security grant program must be reauthorized.
▶ 0:40:49These resources allow underfunded critical entities to remove Chinese routers, hire cyber security staff, and replace outdated servers. Congress should also explore whether there are other opportunities to provide economic incentives to critical infrastructure owners and operators to invest in OT security. The biggest vulnerability in any of your states and all of the states is your lowest common denominator. So we must increase the security baseline across the board.
▶ 0:41:18The threat to critical infrastructure and operational technology from our adversaries, including Iran, is real and growing. OTCC aims to work with this committee and our stakeholders to achieve our common objective. With the right policies, resources, and partnerships, we can build a more resilient and secure nation. Thank you again for the opportunity to testify and I look forward to your questions.
▶ 0:41:41Thank you very much. I now rec Thank you very much. I now recognize Dr. Gleason for five minutes to summarize his opening statement.
▶ 0:41:48Chairman Garberino, Ranking Member Swallwell, and members of the subcommittee. Thank you for the opportunity to testify today. My name is Dr. Nate Gleon. I'm the program leader for the cyber and instruct resilience program at Lawrence Livermore National Laboratory in Liverour, California. I lead a multid-disciplinary team that works to develop technologies to develop to address nation state threats in the domain of grayzone conflict. Our primary emphasis is on the role of critical infrastructure in national security.
▶ 0:42:14I appreciate the committee's interest in our work, particularly your visit to the lab earlier this summer, which reflects your commitment to bolstering the nation's cyber security. I'm honored to be here on behalf of Lawrence Liverour, a National Nuclear Security Administration laboratory and proud member of DOE's network of national Nearly everything we do as a nation, from energy transmission to projecting force around the globe, depends on critical infrastructure. This makes these systems prime targets.
▶ 0:42:41Our adversaries are highly capable and invest heavily to hold our infrastructure systems and the functions that depend on them at risk. To defend against this threat, government and the private sector must partner to out innovate the competition and bring our best technology into operations. One way SISA helps address this need is through the cyber century program. Since 2020, it has looked to launch Liverour for core support for cyber centry with our role being to develop and deploy advanced analytics to monitor and hunt for threats.
▶ 0:43:09Through Cyber Century, cyber researchers gain real-time access to operational networks and can leverage significant investments in national laboratory computational and analytical capability combined with information from the intelligence community to develop and deploy tools to detect the latest attack techniques. As one example of program success, in 2022, we detected high-risisk Chinese surveillance cameras just like these on the table in front of me that were stealthily built into US infrastructure systems.
▶ 0:43:39We leveraged our Skyfall laboratory to develop an advanced beacon detection analytic that increased sensitivity to detect these threats while improving selectivity to dramatically reduce false positives. When we deployed the analytic to cyber century partners almost immediately our analysts disco detected anomalous beacons on the OT network of a participating company. Our team identified the beaconing device as a camera manufactured by the Chinese company Daha.
▶ 0:44:05Livermore developed a machine learning model to detect these devices at scale and deployed it. We found cameras on most of the participating cyber century entities. In some cases, hundreds of them. Network traffic showed that these devices were beaconing to suspected hostile overseas servers. Some appeared to be transmitting encrypted video. Reverse engineering of the devices revealed they were also capable of providing a back door to any connected network.
▶ 0:44:33Notably, these devices were mostly sitting on OT networks, providing direct access to the physical processes. We worked with CISA to create and publish a set of playbooks that went out broadly to help asset owners who are not part of cyber centry detect these devices on their own systems.
▶ 0:44:50This illustrates how the cyber century partnership between just a few dozen critical infrastructure asset owners, national labs and sysa enhances cyber security across US critical It's important to recognize detection represents just one aspect of defense against cyber threats to our infrastructure. The current threat picture demands a multi-layer approach. At Livermore, we use what we call the immune infrastructure framework.
▶ 0:45:14This four-layer approach recognizes that we can't stop all attacks and instead seeks to make it as difficult as possible for adversaries to achieve their goals. Layer one focuses on understanding critical infrastructure systems through modeling, simulation, and analysis. This essentially allows us to look at US infrastructure through the eyes of our adversaries. Layer two attempts to keep the adversary out of our systems through supply chain assurance. Layer three focuses on detecting and responding to intrusions.
▶ 0:45:41We put significant focus on addressing the previously unseen over the horizon threats that China, Russia, and Iran are developing that could hold our systems at risk. In layer four, we engineer our systems to operate through compromise by using techniques like collaborative autonomy, which are designed to provide redundant decentralized control of systems. While all 16 critical infrastructure sectors are important, we pay particular attention to energy, water, transportation, and communication because of their close connection to national security.
▶ 0:46:09The energy sector is among the most forward-leaning in cyber security. Its sector risk management agency DOE Caesar invests resources in creating capabilities for the energy sector that in coordination with SISA helps set the pace for other sectors. Caesar is currently working to ensure that AI can be sure securely integrated into energy sector operations. Livermore is leading its analysis of potential risks and benefits of AI in the energy sector. We are also developing test beds to assess the security and efficacy of various AI capabilities for the sector.
▶ 0:46:39Another way Caesar is working to enhance cyber security is through its energy cyber sense program which focuses on supply chain security. We also work closely with the defense department on defense critical infrastructure. Through this work, we have identified how adversaries with advanced knowledge of our infrastructure and interdependencies that exist between components could exploit multiple assets simultaneously to create cascading damage far worse than in a single point attack. Thank you again for the opportunity to testify. I would be happy to answer any questions.
▶ 0:47:07Thank you, Dr. Gleason. Uh members will be recognized by order of seniority for their five minutes of questioning. Uh an additional round of questioning may be called after all members have been recognized. I now recognize the gentleman uh from Florida, Mr. Jimenez, for five minutes.
▶ 0:47:21Thank you, Mr. Chairman, and let me congratulate you on uh on winning the chairmanship of the entire committee. It's well done and I look forward to working with you. I also share uh the concerns of the ranking member about the reauthorization of SISA 2015 and now that uh are the chairman of the subcommittee now the chair of the entire committee. I'm sure that we're going to be accelerating that uh that process and it's a clean a clean reauthorization but then eventually we're going to have to look and see how we can tweak that but first we need a clean reauthorization.
▶ 0:47:50Um, uh, Miss, uh, Miss Zetter, uh, I'm curious about the the the viruses and the malware, um, and and I'm wondering if they're starting to to act like real viruses. A real virus when they enter the body and the body starts to attack it can react. It evolves to defend itself.
▶ 0:48:14Have you seen that uh that progress with uh computer viruses with with cyber viruses ability of a virus to evolve so that it can it can protect itself from any kind of defense
▶ 0:48:27We've seen the early stages of that. I don't think that we've seen something that's fully um I would say mature and operational. Rob has a better idea of that because he deals with the malware that comes in. Um but we've seen sort of uh even sort of hints of that even years ago um just not fully developed. Obviously now with AI that opportunity exists to make something even more autonom autonomous um and also the ability to morph very rapidly to the environment.
▶ 0:48:55Interesting that that's a scary thought right that whatever we do the virus will protect itself somehow and find a new way to to do what it uh what it needs to do. And I also, you know, I I agree that the OT is actually the more important uh aspect of cyber attack. That's really the stuff that's really going to hurt us, cause accidents, kill people, um disrupt everything that we do.
▶ 0:49:20You know, I mean, if if I I can foresee a day where, you know, somebody presses a button and the next all the lights go out in North America, right? Uh and that would be a little bit disruptive, I I believe. Um, Miss Bolton, you talked about um the lack of lack of coordination here in the United States, and I and I I would think that if you if you kind of map out who's got what uh who's responsible for what, it would look like a bowl of spaghetti. Am I am I too far off?
▶ 0:49:51Uh, I'd say you're not very far off at all. Um I think there are uh a wide range of frameworks that are in place, a wide range of coordination mechanisms as Rob mentioned in his testimony. Uh also difficulty for the industry to uh come into the federal government. There's not one specific door. There's not one uh agency that's responsible for cyber incident response. And so they all work together.
▶ 0:50:19And so there but you've got local and state agencies responding to incidents. You've got vendors and industry. You've also got federal government involvement. So uh I absolutely believe that we need to streamline that process. I know uh the committee is uh is working on harmonization, cyber harmonization.
▶ 0:50:36And I very much we very much support that effort uh because we need to have one uh easy way one door for the industry to come in uh to in come into the federal government for support and then also for the response and collaboration to be more clear.
▶ 0:50:54Now you said that they work with each other but do they really don't they do you see turf guarding a lot?
▶ 0:51:00I can't say that we don't see turf
▶ 0:51:02I will say that uh there are um there are experts, national security, um, you know, professionals who are absolutely intent on securing the networks for which they're responsible.
▶ 0:51:15But a lot of people will say, "Well, really my realm?" Well, no, it's my realm and all. I mean, that look, that's that's just the norm in any bureaucracy. Okay. Uh, and so, you know, we have so many so many agencies doing the same things. That's a natural tendency of bureaucracy to try to protect themselves, okay, from and and turf guard. Um, Mr. Gleon in terms of China, I serve on on the select committee on China and and I have been calling for we cannot decouple fast enough from China.
▶ 0:51:44Uh things that may be innocuous cameras. All right. Uh there's nothing innocuous about them. They are malicious. They are in their in their attacks on on us. I mean I mean I was thinking yeah cameras is one way and then they report back to China, right? and they can also integrate themselves into the IT system. That becomes an OT problem maybe. All right.
▶ 0:52:07Um, we had issues in um at uh where I used to be the mayor in Miami Day County with cameras at our port system that was reporting back back to China. We don't know what it was reporting probably what what kind of commerce we were doing at that port. And we also found that u they had infected our systems. Um they were just they were just lying around. Okay, we don't know what they were lying around for, but I'm sure that it wasn't for a for a good purpose.
▶ 0:52:36Uh, what can we do to stop this, you know, u this relentless attacks uh that we're getting from these systems? I'm sorry, my time is up and uh and I yield back.
▶ 0:52:57Okay. I was going to say they can answer the questions if they if you had if you want I'll ask it for you about that.
▶ 0:53:03Right. I now recognize a gentleman from Texas, Mr. Latrell for five minutes.
▶ 0:53:06If you're reading my notes, sir,
▶ 0:53:08I stole it.
▶ 0:53:09Yeah, you can. Yeah. Um, what can we do I don't even know how you scale something to this size. What can we do looking forward or looking downstream? I cast that out to Mr. Glee. You can start. you there.
▶ 0:53:24Yeah, I I think um everything you are mentioning I I would uh agree with. I think uh what this phenomena that we're seeing is is China has recognized that critical infrastructure is a new domain of conflict. Um I think we are catching up to that still. Um they put a lot of energy into this. Um they are very good. Um we are not going to stop them.
▶ 0:53:49Um, one of the goals that we have with the approach we've taken, as I mentioned, the immune infrastructure framework, um, our goal is to make it as hard as possible for them to achieve their objective at each at each layer. That includes understanding what they're trying to do. It includes securing our supply chains. It includes detecting, responding, and most importantly, it includes building our systems so that we can live even if they compromise them. That doesn't make our mission fail.
▶ 0:54:15the the the cyber defense is very We have no idea what's coming at us. The the challenging part I I I think is you know and I'm not speaking for look I mean there's only four of us it is hard to dork out on cyber security, cyber risk and cyber threat.
▶ 0:54:38we really got to be passionate about this because the number of subject matter experts that walk into our offices every single day that say they're the absolute best at what they do is mind-numbing. Um the committee is very open-minded to the collective your group of saying the best way forward to defensively and offensively this is what we need. This is most likely the best way forward otit. Okay.
▶ 0:55:08Um, how do we get that done? Because it changes every single second of every minute of every hour of every day. Cyber cyber the cyber profile, the cyber technology, the cyber understanding. Everybody's trying to be to outdo somebody else. Again, very reactionary. How do you defend against something like that?
▶ 0:55:30Uh, so I would say we need to start even at the very beginning. Most agency, most sectors have not done an OT asset inventory. So they don't even know what they have.
▶ 0:55:41Scale that to the continental United
▶ 0:55:43Absolutely. Absolutely. So I'll give you an example. There was a an instant responder uh team, an instant response team that went out to a pipeline. This was several years ago. Uh they asked them how many open ports or ports they have. They said, "Well, just these that you see in this room here." And that was all their IT systems. uh by doing investigations through the internet internet billing that that pipeline had, they found they had over 10,000 open unprotected ports.
▶ 0:56:11And so that's, you know, you need to be able to at least on a some kind of spreadsheet be able to tell what you have in order to be able to start fixing it. And that includes things like putting in multiffactor authentication where it's possible. um doing supply chain security as you said uh building defense and depth and building resilience
▶ 0:56:32is that even a probability to do
▶ 0:56:36yeah if I if I could add to that we we very much know what to do um but again if you think about it from a government perspective with private sector if I'm in the water sector and I'm trying to look to SIZA EPA and all the other components and players on what should I focus on there's a lot of go be cyber safe go be cyber secure go do cyber cyber cyber something not actual guidance Not well we want to prepare for bolt typhoon this is what we're looking at here is what we think success looks like however you want to figure it out go and then resourcing it like we have the technologies that exist we have the people trained
▶ 0:57:07but there is a lot of overlapping guidance and it's paralyzing the private sector
▶ 0:57:10we weren't ready for volt typhoon I'm I'm going to shift over to you was a and I don't know how long whomever created that and handed that football off to where it landed I mean but the techn technology in the early 2000s is not the same as it is in 2025 with the use of AI AGI. I'm assuming that you can take the baseline algorithm from Stuckset because it had a few bugs in it. That's how we found it.
▶ 0:57:39If I'm if I'm if I'm speaking correctly, when they when they started digging in and found Stuckset, there were there were just a small bit of glitches in there like, "All right, here it is. Now we're tracking." And then we unpacked it and okay, here it is.
▶ 0:57:53The core I'm sorry. Yes ma'am. Go ahead.
▶ 0:57:55The core of stuckset uh did not have glitches but the um the spreading mechanisms were uh reckless and it caused stuckset to spread around the world and this is what it got caught why it got caught. Are we doing
▶ 0:58:13okay? Uh well, I'm going to make the assumption that since that thing has been handed back to us and globally that technology and AI, AGI will advance stuck snap Solar Winds in some way and we won't be able to not only keep up catch up, but I'm assuming there's a probability that's just going to outrun That fair statement?
▶ 0:58:38Yeah, I mean the details that I provided in the written testimony um goes in depth into how stuckset operated and how sophisticated it was that was state-of-the-art in 2010. Um and it was really a genius the way that it was designed. If you can imagine now 15 years later how much more advanced that that should be at this point. Yes.
▶ 0:58:57And then also with AI then yes it's going to really fast forward.
▶ 0:59:02I yield back.
▶ 0:59:03Gentleman yields back. Thank you very much. I now recognize ranking member Mr. Swallwell for 5 minutes of questioning.
▶ 0:59:08Thank you. As part of the fiscal year 2022 NDAA, the National Defense Authorization Act, Congress authorized the cyber century program which deploys sensors on a voluntary basis on critical infrastructure partners in order to detect malicious activity. As I noted in my opening statement, a critical part of that program is the role that Lawrence Livermore National Laboratory plays in analyzing cyber century data. Dr.
▶ 0:59:36Gleason, what is the current status of Lawrence Livermore's partnership with SISA on cyber century? We've supported SISA in various aspects of critical infrastructure security for for about a decade. Um, currently we have agreements that are making our funding agreements are making their way through DHS processes. Uh unfortunately the those are still making their way through DHS processes and our work with SISA expired uh last Sunday.
▶ 1:00:04What what does it mean that it expired? Is is it turned off? Are you able to operate without authorities or funding like what what is the posture right now uh for this important work?
▶ 1:00:18Yeah, national laboratories are not legally able to operate without being funded by a government agency. So, our threat hunters uh stopped monitoring networks on Sunday.
▶ 1:00:29Who needs to turn it back on?
▶ 1:00:31Uh we need the uh the inter agency agreement between DHS and DOE uh to to be completed.
▶ 1:00:38Would this be a signoff from the secretaries of both energy and homeland
▶ 1:00:42Um somewhere in that chain. Yes. I'm not completely familiar with the funding processes that exist those agencies uh right now. Uh but yes, it needs to be signed off by both both organizations.
▶ 1:00:54And earlier in your testimony, you alluded to some uh cameras and malicious activity that you had found that had been Chineseplaced. Is that the type of work that the Century program does? Absolutely. We're looking for for threats that haven't been seen before. Um we're looking for threats that exist right now in our in our infrastructure.
▶ 1:01:18One of the great things about the cyber century program is it takes the research and marries it with what is actually happening on the real networks. So we're not just doing science projects, we're deploying that technology out in the real world detecting real threats.
▶ 1:01:35And just so I understand, you have so you now with a program that has at least lapsed or hopefully temporarily lapsed, the sensors are still deployed. Is that right? That's correct. The sensors are still deployed. Uh they're still gathering data. Um we just aren't analyzing the data that's coming in. I guess you're telling me you're because you don't have the funding, you're not allowed to look at the data legally. That's the problem.
▶ 1:02:06That's correct. So theoretically we have deployed sensors on critical infrastructure and there could be a malicious attack occurring right now that you are not legally able to see until the program is refunded.
▶ 1:02:21That is correct. Lawrence Livermore analysts are not able to monitor that data right now.
▶ 1:02:26What is the risk of you being blind to what these sensors are detecting? Um, I think everything that we've talked about in this hearing, we've seen how important uh critical infrastructure is to everything we do as a country. I think I'll echo a talking point I frequently hear from Draos. One of the most important things is getting visibility into what's happening on our OT networks. We don't have enough of that.
▶ 1:02:49And so losing this visibility uh through this program um is a significant A major priority of mine has been to improve operational collaboration between the federal government and the private sector. To do so, CISA must have the appropriate forums for such collaboration, including the JCDC and CPAC.
▶ 1:03:11Um, Miss Bolton, how can JCDC be strengthened so that it can better facilitate OT security collaboration and why is it important that CPAC be Uh thank you for the question.
▶ 1:03:25I think CPAC is a is an uh an organization that allows industry to talk to the government and right now uh industry is not able to convene with the liability protections that come or the information sharing protections that come with CPAC authorities and so that becomes a bit of a that becomes a problem and it's a national security concern when uh operational collaboration can't happen between those two entities.
▶ 1:03:52Uh it's I I believe it's very important for CPAC authorities to come back. Um I think as much as possible industry is continuing to try to work uh with through other mechanisms but there was nothing specifically like CPAC. Um and we uh and we also are uh we're continuing to work with JCDC and other areas within SISA to uh on OT security issues.
▶ 1:04:19I think what we'd like to see from JCDC if if we're talking about additional work is more concrete OT uh efforts that industry can get involved with uh from the ground up.
▶ 1:04:30Great. Thank you. Yield back.
▶ 1:04:32Gentleman yields back. I now recognize the gentleman from Tennessee, Mr. Ogles. Five minutes questions.
▶ 1:04:37Thank you, Mr. Chairman, and thank you to your witnesses for being here. Um obviously, this is a high stakes issue. I mean, it's the next battlefront, if not the battlefront as we as we move forward. And when you look at the the China threat that Miss Zetter, I think you know you've touched on or all of you have touched on, but specifically I want to I want to start with Miss Bolton. So formerly I was county executive uh in my community.
▶ 1:05:02Um, and what I can say is that, you know, although we were one of the fastest growing counties in the state of Tennessee, number one producer for manufacturing jobs in the state of Tennessee while I was a county executive, I can tell you that from a cyber and IT OT perspective, we were arguably vulnerable.
▶ 1:05:21Please expand on that vulnerability when you look at bad actors uh as it relates to kind of you know just our infrastructure security and and what the consequences uh might be if there was a coordinated systematic attack against those local communities.
▶ 1:05:36So a lot of what we see and you're completely right a lot of what we see is that the threat actors are targeting the the most vulnerable organizations right many times that those are smaller organizations without cyber security expertise they're at the county level they're at the local level um and you see uh actors either targeting those for you know for target practice learning and then moving to bigger systems or they're doing it in a coordinated manner across Ross a number of different
▶ 1:06:07states and localities particularly we see that in the energy sector um and they're using that uh as a means to prepare the prepare the battlefield if you will for if they're in the in a contingency for if it's China for example uh if they're sitting on our networks that is extremely dangerous even if they're not conducting any particular operations right now one we can't guarantee that they're off the networks even when we find them we find them too late we find them three years after the
▶ 1:06:37fact. And um and what we don't want to have happen, if for example, we're planning for a 2027 contingency, then we need to start doing the work now to build resiliency, defense, and depth, the ability for those smaller local and county uh entities to be able to secure their uh to secure all of those ports, right?
▶ 1:06:58secure the remote access, put in stronger multiffactor authentication, um modernize their legacy IT, and that's why I think it's so important to reauthorize the state and local cyber grant program because without those resources, like I said, most of those lo localities are using all the funding for physical security and not OT.
▶ 1:07:20And Mr. chairman. You know, again, coming from that that local governance background, county executive, um, and I can I'll speak for Tennessee. Obviously, everybody knows Nashville and and knows Memphis, larger cities with more arguably or hopefully more robust systems, but a lot of Tennessee is rural, just like a lot of states across the country. And what you see are electric cooperatives.
▶ 1:07:44So just like the county may be vulnerable to that infrastructure attack, my guess is in most cases so are those local cooperatives, so is some of the water cooperatives as well. And so as we look forward to again the next battlefield and what keeps me up at night and quite frankly, Mr. Chairman, what I would argue the the the most important some of the most important work that we'll do on this committee, this whole committee is what we're doing in cyber as we prepare this country for that next battle.
▶ 1:08:13And it's going to be on our computers. It's going to be across our networks. And I would argue it's going to be in our local rural communities that they're going to hit first because then they can Swiss cheese our electrical grids and our water systems and our water treatment plants, etc. That's what keeps me up at night. So with that, uh, I'd love to stay on this topic and just kind of go down the line. We'll start with you, Miss Zeder, to see what you might want to add to this, uh, subject matter, please. I think you're absolutely right in terms of the small utilities and cooperatives like that.
▶ 1:08:42They don't have the money, they don't have the resources, they don't have um the expertise on staff. They don't even hire security people. But I want to also say that you know we sort of anticipate that the large uh organizations um would be more secure. And if you look at what happened to Colonial Pipeline in 2021, we see that this was really a major organization critical infrastructure supplying a lot of gasoline uh to the east coast.
▶ 1:09:10And yet Colonial Pipeline at the time that it was attacked did not have a CISO on staff. Uh they also had a legacy system that the attackers got in an old VPN account. They were no longer using but hadn't bothered to um disable. Uh and they came in through a password that potentially was uh well it was it was leaked on the internet. Uh so the employee who had the password had used it for other accounts and then it was leaked on the internet in in in other breaches.
▶ 1:09:36One other um point about that was the attackers uh we think only got to the IT network. didn't actually make it to the OT network, but Colonial Pipeline shut down the pipeline because they feared that the attackers would get to the OT network and then encrypt it and lock it. But when the CEO of Colonial Pipeline testified to Congress, he testified that they had uh very secure, highly segmented uh OT and IT networks.
▶ 1:10:04But if they were that confident that the networks were segmented, then they wouldn't have had to shut down the pipeline as a precaution. So, I just want to say that yes, those smaller uh entities are um a big issue um and a prime concern, but also the larger entities are having the same problems and not keeping up.
▶ 1:10:21Yeah. Thank you, ma'am. I apologize, Mr. Chairman. I'm over time, but I yield
▶ 1:10:24Not a problem. Gentleman yields back. I recognize myself for five minutes of questions. Um we all know CISA plays an important role. uh sector risk management agency for eight of the 16 critical infrastructure sectors as well as the national coordinator of the sector risk management agencies. They do a lot of work. Uh I I'd like to hear from you all. What do you what do you think how would you assess CIS's effectiveness is uh as a partner when it comes to OT cyber security.
▶ 1:10:53You can start with Miss Zetter if you
▶ 1:10:56Um I don't have direct as as I'm because I'm not a practitioner. So I don't have that assessment to know firsthand. But what I do know is that CISA in the past um had uh I would say in the last decade really um a lot of um expertise that they were able to give to critical infrastructure either to go out into the field and do critical assessments of the networks uh give them risk assessments about what they needed to do and then also they had flyaway teams that when a system was compromised
▶ 1:11:26that they would be able to go out and assist directly in doing some kind of remediation. So I think that the impact of CISA has been really great. Um but of course they're limited in their resources and who they can operate, who they can give assistance to.
▶ 1:11:41I I would say that my commentary about SIZA probably is reflective of a number of government agencies uh that deal in this space which is really good Americans trying really hard to do good work that have very talented people but are hardly being effective for the amount of money we're spending on it uh in comparison to what's happening elsewhere. as an example, flyaway teams, the instant response teams, etc. There's absolutely nothing unique happening there in comparison already in the private sector.
▶ 1:12:05I think there's a very important role and responsibility for government to play and I think a focused SIZA would be extremely impactful and I I've, you know, in passing talked to Shan Blankie. I'm really excited about the way they're looking at it now. Um, but I think a lot of times we overstate the effectiveness and I'm sure that this is not going to earn me any friends uh at my at SIZA and many of my friends are there. Um, but I will say that we've got a couple of years before we have significant issues and I'm very concerned about next couple years going to war with China and it being focused on our OT and I would really like to move past pleasantries.
▶ 1:12:35So, we should focus them a heck of a lot more.
▶ 1:12:38Thank you.
▶ 1:12:40I I would say that I think SIZA, you know, can certainly grow in its effectiveness and I think we're uh we will see that under Sean Planky. Uh I think things like automated information sharing, the Einstein program, cyber centry, I think there's a number of places there where we can modernize some some of that legacy infrastructure. They're they're operating not necessarily with the most updated sensors and I understand that it is expensive to upgrade the systems.
▶ 1:13:08But if we want CISA to be acting as the, you know, the frontline defense for cyber security and as an expert, they need to have, you know, up-to-date systems. They need to have sensors on the networks that are that are the mo what what is modern right now. Um, but I think that'll been it.
▶ 1:13:30Dr. Please,
▶ 1:13:32I would say some of our best and most effective work with SISA has been when they've worked in partnership with some of the other federal departments with stake in the space in particular with the Department of Energy um looking at threats to the energy sector and the Department of Defense looking at defense critical infrastructure. Uh just to echo on um some earlier comments, I think SISA also works best when they do work that is appropriate to the government to do um and not trying to do what the private sector is already taking care of.
▶ 1:13:59uh the government has specific advantages uh in our access to uh the intelligence community in uh the ability to do things that the private sector um is not or or or shouldn't be doing. Um I think the more that the government sticks to that space, the more effective um that uh that those programs will be. Um and I also want to echo definitely look forward to Sean Planky coming in uh and very excited about uh Nick Anderson coming in.
▶ 1:14:26We've had great experiences working with him previously uh and think their leadership will be very effective.
▶ 1:14:31I think we can all agree that we're very excited to see Shan Planky get confirmed as as soon as possible. Uh it'll be it'll be a good day for I think for CIS to have him in there. Uh Mr. Lee, I want to go back to because you were very passionate in your hands today and you really want to get him focus. Can you go a little more in depth because this is like this is the stuff we're going to have to work on. Stans Institute um which is the leading cyber security provider analyzed every single industrial cyber attack that's ever taken place and just asked the basic question of what security controls actually worked.
▶ 1:15:00It was five and we know exactly what those five are. We know exactly how to do it and if you look at regulation standards and everything else it's not five. Um further when you look at um our rural communities as mentioned about 98% of this country is in that sort of below the cyber poverty line discussion and they're not doing pretty much anything unless it's really passionate members there are trying to help but going back to what Kim said as well you've got a large number of companies that will stand up and say how robust their security programs are and I'm in a lot of those environments and they're terrifying.
▶ 1:15:30So I have three kids I did not really want to go back in the army for you know extra time. was I really want to get this right and I think if we're going to be serious about the conversation it's focus on what we can actually do across the next couple years pick a point of view you're going to upset some people in doing so but we need to do it and at the same time I would say you can roll out quickly I think about 95% anecdotally about 95% of all cyber spend goes to enterprise IT about 5% to OT that is where your national security is your
▶ 1:16:00environments your local communities and all of your ability to generate revenue you look at uh sort of the visibility in this country. If you actually want to monitor your OT infrastructure, figure out is China already there, I would say probably about 10% of the infrastructure around the country is being monitored. So when we're having big discussions about what comes next, I would just highlight that we're not even really being serious about what we know today.
▶ 1:16:22I appreciate that. Thank you very much. Uh we're going to start our second round of questions. Uh so I recognize second round the gentleman from Florida, Mr. Jimenez, for five minutes.
▶ 1:16:32Thank you, Mr. Chairman. And I'm I'm going to pivot a little bit. Uh so do you all know what MAD is? Mutually assured destruction. MAD is not really all that mad. MAD kept us safe for about you know 50 years, 60 years, right? And where yeah, the Soviet Union had uh a you know thousands of nuclear weapons, but so did we. And if they ever used it, then we would use it on them. And that that kept us safe in a frightening kind of way, but it did. It kept us safe. All right.
▶ 1:17:01And so my question to you is is um there is the Department of Defense, but part of the Department of Defense is the Department of Offense. Uh so it's uh if we were just a well, we're we're here to defend the homeland and we're going to play defense. Well, you're inviting attacks because there's no there's no counter punch. What's our offensive capability? Where's your assessment of our offensive capability uh in this realm?
▶ 1:17:31I I'll take first pass that we are very very good at our offensive capability. I think some concerns I have you have to be able to get to root cause analysis on determining if we were attacked for us to go back and do something. I'm aware of numerous cases the government is currently tracking as maintenance issues for explosions otherwise that were actually cyber attacks. Um if we're not detecting what's happening then we're just going to say oh it must have been something random and we're never going to get offensive.
▶ 1:17:56Um, but serve, you know, putting my military hat on now, I even just down the 91st Brigade alone, we've got a lot of offensive capability, and I would not want to be on the other side of us, but we also have to make it extremely hard for our competition to come back at us and at least know when they do it so that we can unleash our
▶ 1:18:12Do we do that often enough? Do we flex our muscle often enough?
▶ 1:18:16Uh, I think just looking back to testimony and commentary from Joe Nason, General Hawk, and others, I would say that we do not. Uh, I do not want to see an offensive world. I do not want to see targeted civilian infrastructure, but when our adversaries make it very clear that they want to hurt us and hurt our families, I think we have to be very serious about showing them that we can do the same.
▶ 1:18:34I agree. So, I mean, if we actually flexed our muscle every once in a while, I mean, the DoD flexes its muscle every once in a while, right? Uh, so do I guess you're saying we don't flex our muscle often?
▶ 1:18:47We're saying we don't flex it enough, but I would also advise that we have to be very serious on defense because we will see things back. um even if one agency in a government authorizes something at us and we are doing something that we view to be retaliatory, other agencies in that same government may not be aware of it unless we're able to call it out and then all of a sudden you have a very escalatory
▶ 1:19:07You know, we have a new realm of uh of warfare. I guess defense and offenses of space and so we created the space force, right? Should we create a cyber force?
▶ 1:19:18I'll stick with it and then open up to the other panelists. I I think it's time. I was very against it when I was in the Air Force. I was very against it for the years after looking at how it was going to be orchestrated. I think it's time to do it sticking to its OT mission of organizing, training, equipping. Let Cyber Command and the combatant commands be the actual title 10 authorities that we have. Um, but we definitely need a dedicated service. But I think if you're going to do it right, you have to do it extremely big and right because the problem that you'll have is all that infighting and the stuff that people say, "Oh, we politely work together in inter agency." No, we don't.
▶ 1:19:48People are very territorial and people will keep their best cyber warriors themselves and others. Going back to my first round of of questioning, right, that uh there's turf
▶ 1:19:56There's a lot of turf.
▶ 1:19:57Oh, there is a lot of turf guarding. And so, um, and so I would figure that now with Space Force and the Air Force, there's probably a lot of turf guarding there, right? I don't see it as much myself. Um, but I did leave the Air Force a while ago. I will say the Army would be very happy to have a cyber force under it from a department level, but I'm not so sure that it shouldn't just be banned at department level service.
▶ 1:20:17Okay, fair enough. okay. That's uh that's uh all the questions I have and I yield back the rest of my time. Thank you.
▶ 1:20:27Gentleman yields back. I now recognize the gentleman from Texas, Mr. Latrell, for my minutes questions.
▶ 1:20:32Good to hear you say that I've been working on that cyber force idea for a while and General Hall and I had some pretty interesting conversations behind closed doors. um absolutely a brilliant guy um in his stance but I think he was trying to protect the nest but I think we're far enough along where a cyber force should be absolutely the conversation should be had to your to the conversations that you were having with the the chairman and you listed five thing I come from a very rural district
▶ 1:21:05and I've had SISA out to the out to the district to talk to our our business owners But get where's the piece of paper at? Where is what can I hand off to everybody that that that is in my district and and to my state and say here implementation of these five things will get you to a better place. And of course, as you said, everybody's going to beat it up because they're they're not going to be the ones that are involved in it or or or whatever.
▶ 1:21:34But I mean from our nursing homes to our banks to our school districts, they've all been hit and we have those convers again, you heard me say it my in my last line of question, very reactionary because we don't know what we don't know. Um where does that live? H hand it to me. I mean help me out here.
▶ 1:21:51Yes, sir. Yeah, the SANS Institute published the five critical controls. It's been backed by other governments as
▶ 1:21:56What the what did
▶ 1:21:57the SANS SANS Institute
▶ 1:21:59does. Where does that live? Because if I walked if I walked into Conro, Texas and said, "Hey, go visit this place." They're going to look I mean, they're look at me like I'm crazy.
▶ 1:22:07Something that the legislation
▶ 1:22:09all the way up needs to be talking about. I mean, I like to say we need to Facebook this thing so everybody and
▶ 1:22:15and their cousin knows about it.
▶ 1:22:17Yes, sir. Yeah. I would love to see again government have a single voice to say here's actually what's working. And as a rural guy from Alabama who joined the military, if I can figure it out, I promise everyone in your district can as well. Um but we need to speak again with one voice of government. If SIZA had a single page of here is the resources available to you, this is what you can do and every agency around supported it instead of their own thing, I think you'd see a lot more outcomes.
▶ 1:22:38And if we do do that, will the bad actors globally pinpoint those specific
▶ 1:22:50No, I I don't think it would work in that such way. Um, even if you advertise broadly what your strategy for security is, it's the fact that you're actually doing and implementing it that makes you defended. The fact that your adversary knows you want to invest in secure remote monitoring or secure remote access or monitoring that doesn't make you any less uh secure.
▶ 1:23:05They're well, they'll most likely look somewhere else is
▶ 1:23:08I hope so. Right now it is way too easy to target our systems and right now we are doing very little. I would love to raise the bar where they actually have to come up with something creative.
▶ 1:23:16Raise it. I mean, you're sitting in front of the group that's sitting here. Hey, we're asking you to uh I won't speak for my colleague, but hey, I'm asking you right now on on record. Do it. Bring it to us.
▶ 1:23:25Yes, sir. I provided some written testimony. I'm happy to brief you at any time. And uh I am trying my best.
▶ 1:23:30I will absolutely see you after class, sir. With that, Mr. Chairman, I I yield
▶ 1:23:35Gentleman yields back. I now recognize the gentle lady from New Jersey, Miss MacGyver, for five minutes of questions.
▶ 1:23:41Thank you so much, uh chairman, and thank you to our ranking member. Uh my district uh sits at the heart of our nation's largest metropolitan area and is home to a major airport, one of our nation's busiest ports, numerous railroads and pipelines, and key industrial facilities among other critical infrastructure. Securing these facilities requires resources and for publiclyowned critical infrastructure, those resources have often been lacking.
▶ 1:24:10As part of the infrastructure investment and jobs act, Congress provided 1 billion to establish the state and local cyber security grant program. State and local governments can use this funding to strengthen the OT security of publicly owned critical infrastructure. Unfortunately, under current law, the program is set to inspire to expire in just over two months. Miss Bolton, I have a question for you.
▶ 1:24:34How important how important is it to continue funding for the state and local cyber security grant program?
▶ 1:24:43I think it's critical to continue that funding. Uh I mentioned in my testimony that uh most a third of districts around the country are rural districts and obviously that's not the case for your district, but I think it's still incredibly important. there are not only large ports and airports in your district but also smaller uh smaller entities and those are the ones that really desperately need help.
▶ 1:25:06Uh I will add uh to your question earlier as well that uh SIZA has released a top five OT uh cyber security guy guide. So I think that uh also can help to uh to provide uh guidance to those entities as to what they can use their cyber security spend on. Uh and at OTCC we're also working on uh guidance as well.
▶ 1:25:30Thank you. Can you just elaborate a little bit more on how should state and local governments prioritize their resources to strengthen their OT
▶ 1:25:40So uh I think it's very important to start at the very beginning. Um we do know some of the controls that work and so we should put those in place. Uh multiffactor authentication, segmenting, even micro segmentation of networks. uh making sure that we are securing remote access. Um and also I'd add that you know most of the attacks that are happening on our critical infrastructure aren't zero days. They're not the most sophisticated vulnerability or the most uh sophisticated um uh attacks.
▶ 1:26:10They are using things that we've seen before. Sometimes not changed at all, sometimes mildly changed. Uh and we continue to be hit by these uh by these attacks. Uh I think for example, SIZA releases a top 12 uh cyber vulnerabilities uh top 12 routinely exploited vulnerabilities list.
▶ 1:26:31Why would the government or any state entity still be able to buy those products off of that list if the if one side of the government is saying these are commonly and routinely exploited, we should never be allowed to buy those. Uh so things like that I think are extremely important.
▶ 1:26:49Thank you so much. I want to thank the witnesses for being here today for providing testimony and I really do appreciate the chairman and the ranking members um you know uh steadfast um focus on this issue and also being supporters of the reauthorizing of the state and local cyber security grant program. So I look forward to continuing to work with both of you and this committee um to provide state and local governments the resources they so desperately need to sec to secure their critical infrastructure. With that, I yield back.
▶ 1:27:19Will the Will the gentleoman yield? Can I Can I borrow your minute?
▶ 1:27:23This is piggybacking off one of the questions you asked. You said CISA listed five things as well. Is it the exact same list is what you're saying?
▶ 1:27:34It is not. This is another issue that we
▶ 1:27:37Okay. So there's there's a problem. I I had now I'm taking two lists.
▶ 1:27:42And saying here you go. And then that that is an issue.
▶ 1:27:47On top of those two. and the 10,00 million that everybody else brings to you and for a poor poor district like ours like I mean
▶ 1:27:56here we go thank you very much
▶ 1:27:58well and I will say this um the cyber security industry as a whole is aligned on things like implementing multiffactor authentication network segmentation continuous monitoring and detection uh but there are sort of these um there are sort of these conflicting guidances that do exist same with frameworks conflicting frameworks for OT So the the people in your district or the operators in your district that are trying to just do the the right thing, they don't know where to start. Correct.
▶ 1:28:25And especially when it's like NIST uh cyber security framework uh 2.0 um there's like 80 pages, right? People who are running these OT networks don't have don't have the knowledge to read through an 80page document and know where to start. So one of the things is like NIST is creating some uh quick start guides. I think that would be very important to do for OT security.
▶ 1:28:48Thank you. I yield back. Thank you,
▶ 1:28:51General yields. Um and thank you very much for your enthusiasm about state local uh the grant program. I I I hope it's something that we can get reauthorized right away. I think it's could be a very big bipartisan issue. I now recognize the gentleman from Tennessee, Mr. Ogles, for his second five minutes of questions.
▶ 1:29:06Thank you, Mr. Chairman. Uh Mr. Lee, I think you said 98% of communities were below the cyber poverty line.
▶ 1:29:13Uh yes, Congressman. about if you look at companies under about 100 million in revenue across all of our electric and water utilities, that's about 95 to 98% of them.
▶ 1:29:21Goodness gracious.
▶ 1:29:23Uh and so I I want to go back and just double down on this issue again coming from the county executive level and and you know to my good friend to my left here, you know, his his district as well. I'm sure he's seeing the same thing is that, you know, your IT director is also the guy that's setting up emails and plugging in keyboards and probably spends 60 80% of his time not in his office, not at his desk, not being offensive because a good defense is a good offense, you know, looking for those weaknesses, looking for those back doors, looking for those
▶ 1:29:53left passwords and and such. And so, uh, and I'll use the word framework um, in the context is more like a toolbox. And you know and I want to be careful here because you know borrowing from Reagan you know he said the scariest lang phrase in the English language is I'm from the government and I'm here to help. And what we don't want to do is create a monster that suddenly is nothing more than a big bureaucracy that is designed to grow and gobble up resources.
▶ 1:30:21But what what I do see here and again coming from that local background is there is a vacuum here. there is a void and quite frankly our communities don't have the expert expertise and even if they do have the expertise I'm not sure they have the bandwidth bandwidth in the context of man or woman hours and so we've got to figure out how we move forward and how we quite frankly equip uh some of our local communities because again if I'm on the other side of the pond and I'm seeing the opportunity that moment to
▶ 1:30:51seize I'm going after the locals I'm going after those water systems and you want to talk about creating pandemonium. S suddenly your your small rural cooperative electric or water system goes down and it's not working and it's not coming back online for a few weeks and that's been Swiss cheese across the country. That's what again I go back having been the county executive that's what keeps me up at night and Mr. Chairman, I think my challenge to the committee is that's something that we need to work on.
▶ 1:31:18Being careful not to create again a monster that that that grows and grows and feeds at the trough that that that government trough. And then back to the whole idea of creating a department level service with cyber force. I think that's incredibly incredibly incredibly important because cyber is is not just across the networks. It it touches into the drones and the capability of jamming and all sorts of things.
▶ 1:31:42So those cap capabilities have to become we have we have to lead on that frontier and quite frankly become untouchable in the same way we're untouchable uh in airspace and communications. With that, Mr. Chairman, I yield back.
▶ 1:31:59Gentleman yields back. I now recognize the ranking member, gentleman from California, Mr. Swallwell, for his second five minutes questions.
▶ 1:32:08Dr. Gleon, what is the status of Lawrence Livermore's other partnerships, including its support for the National Infrastructure Simulation and Analysis Uh those are in a similar status to our our support for cyber centry. Our our work for uh National Risk Management Center again looking at infrastructure interdependencies and cascading consequences of disruption to infrastructure um has been going on for a decade. um our inter agency agreement uh expired in March uh for that work.
▶ 1:32:40What is the risk to what you're able to see or what you were able to see and what you don't see now as far as cyber vulnerabilities that are out there?
▶ 1:32:52I think one of the the the big things that we miss and and I want to emphasize the the the idea of cascading consequences. Um, a lot of times when we're thinking about cyber attacks on critical infrastructure, the target may not be that infrastructure system itself. It may be what is supported by that infrastructure system. Um, and when we fail to understand those inter um, we are opening up avenues for our adversaries to disrupt key national security capabilities.
▶ 1:33:21A great example of this is, uh, some of the capabilities on on the territory of Guam. Um this is a a small very hardworking very dedicated uh uh you know power company um but very underresourced uh and some of our most important capabilities for defending against a potential China uh invasion scenario um are based in Guam.
▶ 1:33:45Um there are ways to defeat those capabilities um that go through, you know, for lack of a better word, the back door uh by exploiting kind of the the the weak underbelly, the undefend undefended uh part underdefended part of our critical infrastructure because those are very small systems. Um by not understanding those interdependencies, um it's not that they don't exist, our adversaries know them. Um if we don't, um we're not looking in the right place for our defense.
▶ 1:34:16In just over two months, the I'm sorry, did someone else you're good? In just over two months, the Cyber Security Information Sharing Act of 2015, the other SISA is set to expire. And Mr. Gimenez alluded to this. It's essential that we act promptly to reauthorize it uh in a clean way. And I'm open to any reforms that we could discuss down the lo the road under the chairman's leadership of the full committee.
▶ 1:34:45But I think there is a wide consensus that we don't have time to do that now. Congress will be in recess uh effective this week until after Labor Day and then we will be right up against SISA's expiration. Miss Bolton, your testimony discusses the importance of reauthorizing SISA 2015. What would be the national security impact if the law lapses?
▶ 1:35:09The estimates are that about 80 to 90% of information sharing would be cut off from the federal government. Uh when I was at the cyerspace solarium commission, one of the main things that we tried to give tried to do was to make sure that the federal government at least had a full threat picture. And this uh this uh authority is part of that work, a significant part of that work and we we must reauthorize it.
▶ 1:35:37Um there are if we are about two years away from a contingency with China in 2027 um as ODNI has said then we have to be fully prepared. We have to be taking steps now and not just addressing you know the information sharing piece. That should be a baseline. It should be a given and we should be focused on the additional uh steps that we need to take.
▶ 1:36:04So I I hope that that gets reauthorized uh quickly and that we can move on to some of these other topics that we've been discussing and addressing some of the other extremely serious issues because China is not waiting. China is preparing now and so and so are all our other adversaries.
▶ 1:36:20And Mr. your experience in the private sector. Is there any world where SISA lapses and a private sector company that has been hit would still be willing to come forward and share information with the Department of Homeland Security?
▶ 1:36:41No, I think it's incredibly important to reauthorize it and the birectional communication from government to private sector especially on the threat picture overall is exactly one of the roles and responsibilities that makes a lot of sense
▶ 1:36:51and then that's because no CISO would be able to go to the DHS without liability protection
▶ 1:37:02and their fidiciary duty to the shareholders. I mean they would be exposing themselves to a lot of risk. Is that right?
▶ 1:37:08Absolutely. And that's actually a broader issue. Even looking from a National Guard perspective of could we go in and respond to utility gets hit. We have no identification to give utilities. So they're not going to let us touch anything and do any action on it. There are very simple bureaucratic things that can be fixed to increase national security tomorrow.
▶ 1:37:24Thank you. Y back.
▶ 1:37:26Gentleman yields back and I can't agree with him and uh the witnesses that witnesses more and my other colleagues that we have to uh reauthorize. We do have to change the name though. Yeah. Okay. That's got to be at least one change we have to do. Um, and and you know, I understand people want to do clean and and we have to get done. Um, but I I do want to hear from you all u because I think there should be changes.
▶ 1:37:51There should be uh it's a 10-year-old law and you know clean reauth it doesn't include things that we've learned over the last 10 years. So I would like to hear from you all. Is there language or are there changes or focuses that we should implement into law uh that we should consider to ensure OT is better uh protected or covered?
▶ 1:38:12Well, I would just add that and I think you all are already considering this but including OT much more directly within the language uh it's currently not in the bill uh or not in the legislation. Um and I would also say that identifying DHS and CISA as the main sort of gateway for sharing would be ideal.
▶ 1:38:34uh because as we've spoken before the the the con the confusion for industry of coming into the and and uh talking with the federal government sharing information with the federal government um that remains a problem and we hear that all the time from our member companies and from other companies that I work with that they don't know where to go. They they say well I need to talk to maybe I should talk to TSA.
▶ 1:38:57Maybe I need to talk to FBI and then maybe FBI will tell that can't be assumed and so we need to make sure that uh we need to make sure that that language is clear within the
▶ 1:39:10Yeah, I would completely agree with that and also there needs to be here's what you get in return. Here is what we can do to help you because you gave us this information. A lot of times a lot of asset owners and operators feel that it's a one-way communication into government with no expectation of what comes out of it. You want somebody to go through the risk of sharing information. There's got to be a very clear and here's the rules of the road of what we can provide for you as a result cross agency without any drama. We talked about turf wars. I led the OT portion of the instant response for Colonial Pipeline. I witnessed a lot of turf wars between FBI and SIZA.
▶ 1:39:40It needs to be very clean or no asset owner operator will want to work with them. They view them as children.
▶ 1:39:47Yeah, I've heard from I've heard from a bunch of uh it's very important. This was this was a a major part of my uh by the way my presentation to become chair of the full committee was making sure that this does not lapse. So it is a a a a top priority for me and as I know for the other members on the committee and I have spoken to many people in the private sector that said it would be devastating and they would not uh they would not be able to uh talk to the government uh if this expires and it would be devastating for us.
▶ 1:40:15Um I do want to get back to the uh stucks stuckset. Um and I you know we're very privileged to have missed here uh to talk about it. So I I want to get it back into the what is it significance significance of stuckset today and what lessons did we learn what lessons should we have learned that we have not learned yet from it?
▶ 1:40:40Uh I I mean the primary lesson is the focus on on OT uh systems that um stuckset showed the danger that the that weapons like this can have against critical infrastructure and of course not just doing what a normal virus does but causing destruction. Um I think also the uh basically the small utilities and the small organizations. I I just want to emphasize that because it's been brought up a lot.
▶ 1:41:07I talked about uh when you asked me how effective SISA has been and I said that they've been effective in terms of um providing these small organizations with a service that they can't otherwise get and the panelists had said that the SISA shouldn't be doing what local or what private industry can be doing. The problem is is that those small utilities and small organizations don't have the funds or haven't had the funds in many cases to actually get it privately. So they have relied on CISA for that kind of service.
▶ 1:41:34Um, and I think that when we have legislation of course that has that that that that ability to provide the funds that's really significant for those organizations and that shouldn't go away. So I think that the overall lesson from stuckset is that the capabilities out there are really uh sophisticated really advanced and we haven't seen the full use of the capabilities that stuckset showed um for various reasons probably deterrence is one
▶ 1:42:05of the good ones at least from the US perspective that um adversaries are um you know having second thoughts about targeting US infrastructure but also there's a I I sort of make a distinction between those who have the will and those who have the ability. And those who have the ability um haven't until now really had the will to go after US critical infrastructure. And those who have had the will, perhaps maybe terrorist groups, others um haven't necessarily had the ability. It doesn't take much to marry those two together.
▶ 1:42:33Even someone that has will and doesn't have ability can purchase that ability, can purchase that capability. And now we're entering into a a phase where even we've relied on the large nation states, China and Russia. We've relied on them not having the will to target US infrastructure. And I think what we're talking about and going into potential uh conflict with China, uh we've reduced we've eliminated that that um that gate now and and they do have the will potentially to go after US infrastructure.
▶ 1:43:02So I think that that's the lesson learned from Stuckset.
▶ 1:43:05That's a scary way to end this. Uh committee hearing. Um, but I appreciate it and that it's a big concern for me is when the people with the will and the ability are are the same person because uh that's a scary thought and that's what we have to be prepared for. Um, I want to thank all the witnesses and all the members. This is I mean the fact that so many people stuck around for second round of questionings just shows you how uh important this topic is. So I want to thank you all for your valuable testimony, the members for their questions.
▶ 1:43:32Uh the members of the committee may have additional questions for the witnesses and we ask that you all respond to those uh in writing. Pursuant to committee rule 7E, the hearing record will be held open for 10 days. Without objection, this committee stands adjourned.