Defense through Offense: Examining U.S. Cyber Capabilities to Deter and Disrupt Malign Foreign Activity Targeting the Homeland

Defense Posture and Global ThreatsHomeland Security Subcommittee on Cybersecurity and Infrastructure Protection · 2026-01-13 · 119th Congress
The Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection convened this hearing to examine the state of U.S. Begins at 0:07:28
Transcript
Highlights

Title

Offensive cyber capabilities to deter foreign threats to critical infrastructure

Purpose

The Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection convened this hearing to examine the state of U.S. offensive cyber capabilities, the legal authorities governing them across agencies, and whether the private sector should play a larger role in disrupting foreign cyber threats to the homeland. Four witnesses—Joe Lynn (Twenty Technologies), Emily Harding (CSIS), Frank Cilluffo (McCrary Institute), and Drew Bagley (CrowdStrike)—testified amid recent reporting that Chinese state-sponsored actors (the "Typhoon" cluster, including Salt Typhoon and Volt Typhoon) compromised congressional email systems and prepositioned inside U.S. critical infrastructure. Begins at0:07:28

Who spoke

Chairman (Rep. Mike Rogers, R-AL)0:07:28: Opened by arguing deterrence in cyberspace "does not exist" without credible offensive capability0:08:24, noted Salt Typhoon's recent compromise of congressional committee email systems0:09:16, and framed the hearing around a "Monroe Doctrine" for cyberspace0:44:02.

Ranking Member Bennie Thompson (D-MS)0:12:58: Opened with condolences for Renee Good0:13:20, warned against "putting the cart before the horse" on offense while CISA has lost a third of its workforce0:15:26, and said sanctions on China's Ministry of State Security over Volt Typhoon were paused amid trade negotiations0:17:03.

Joe Lynn, CEO, Twenty Technologies0:22:03: Testified U.S. offense is not postured to deter China's "industrial-scale" campaigns0:22:27 and called for industrializing offensive cyber into software-based, scalable systems rather than bespoke elite-team operations0:24:230:24:54.

Emily Harding, CSIS0:26:59: Said Washington has failed to establish deterrence and adversaries control the "escalation ladder"0:27:28; described CSIS war games in which senior officials couldn't agree on what constitutes a proportional cyber response0:29:39; recommended flipping the risk calculus so operators don't need pre-approval and creating a funded Cyber Force0:30:580:31:28.

Frank Cilluffo, McCrary Institute0:32:23: Said "the status quo ain't cutting it" and that Flax, Volt, and Salt Typhoon together form "a perfect storm"0:33:210:33:51; cited NSPM-13 and "defend forward" as important but insufficient shifts0:34:19, and referenced cyber's public role in the Venezuela operation against the Maduro regime0:34:48.

Drew Bagley, CrowdStrike0:38:05: Warned that "hack back" by private victims risks revictimization and escalation and should be left to professionals with oversight0:39:57; proposed a JCDC-coordinated "most wanted" list for disruption campaigns0:40:49.

Rep. Al Green / member questioning on staffing (Ranking-adjacent Q&A)0:49:04: Pressed witnesses on whether Cyber Command and NSA staffing cuts leave the U.S. under-resourced for a more offensive posture.

Rep. Fong0:55:22: Asked about building a cyber workforce pipeline through universities and community colleges0:56:01 and about private-sector information sharing barriers0:58:22.

Rep. McEachin (D-NJ)1:01:22: Offered condolences for Renee Good1:01:53 and asked witnesses how to remove barriers to entering the cybersecurity workforce1:02:47.

Rep. Gimenez (R-FL)1:06:38: Asked whether large corporations could be authorized to conduct their own offensive "hack back" operations1:07:03 and whether adversarial states profit from criminal hacking groups1:09:43.

Rep. Wexton (D-VA)1:11:54: Cited the illegal RIF notices that cut CISA staff by a third and criticized elimination of the Multi-State ISAC1:13:351:14:28; asked Lynn and Harding to reconcile differing assessments of U.S. offensive capability1:15:20.

Chairman of the full committee (Rep. Andrew Garbarino, R-NY)1:17:44: Asked what DHS/CISA's operational role should be if retaliatory attacks hit the homeland, and pressed on two-way information sharing with the private sector1:18:081:19:30.

Rep. Magaziner (D-RI)1:23:27: Offered condolences for Renee Good1:23:27, raised concerns about DHS field tactics1:24:16, and asked panelists what boundaries the U.S. should project for offensive cyber actions, suggesting a classified follow-up session1:25:301:26:00.

Rep. Luttrell (R-TX)1:33:01: Asked which agency is responsible for defending undersea cables carrying over 90% of U.S. data traffic and how repair/redundancy capacity works1:33:291:36:38.

Key moments

The Chairman revealed that public reporting had just confirmed Salt Typhoon compromised email systems supporting several congressional committees, the first known targeting of the legislative branch itself0:09:16.

Thompson disclosed that planned sanctions on China's Ministry of State Security over Volt Typhoon were shelved as the administration pursued a trade truce with China0:17:03.

Harding distinguished Salt Typhoon (intelligence-gathering, "spy versus spy") from Volt Typhoon, which she said has "zero intelligence value" and exists solely to delay U.S. military deployment by 6–12 hours in a Pacific contingency0:47:400:48:08.

Harding described CSIS war games in which senior former officials, given scenarios like a dam failure killing hundreds, could not agree on what constitutes an act of war or a proportional cyber response0:29:120:30:03.

Lynn disclosed Congress passed $1 billion for offensive cyber plus $250 million for AI in offensive cyber in the reconciliation bill, calling it "an amazing down payment"1:45:13.

Bagley and Cilluffo both rejected private "hack back," warning it risks revictimization, disrupted investigations, and geopolitical escalation; Cilluffo proposed channeling private-sector targets through JCDC as a government-controlled "bounty" nomination process instead0:39:571:07:32.

Lynn and Harding gave seemingly divergent assessments — Lynn called U.S. offense "bespoke" and non-industrial while Harding called it "unmatched" — but reconciled that talent is excellent while approval processes (citing the multi-layered "Symphony" exercise against ISIS) are too slow to seize fleeting opportunities1:15:201:16:261:17:04.

Thompson and Wexton noted roughly a third of CISA's workforce was cut over the past year via since-ruled-illegal RIF notices, with staff reassigned to ICE/CBP immigration enforcement0:15:261:13:05.

Luttrell pressed the panel on who is responsible for undersea cable security — over 90% of global data flows through these cables — and none of the witnesses could identify a single government owner of the issue; Harding said "there's no one good home"1:33:291:39:51.

The Chairman closed by asking the panel to unite behind one concrete, consensus recommendation for Congress rather than individually pitching large budget requests1:50:41.

Metadata

CommitteeHomeland Security Subcommittee on Cybersecurity and Infrastructure Protection
Chamber / CongressHouse · 119th Congress
Date2026-01-13
TypeHearing
Witnesses
Ms. Emily Harding — Vice President, Defense and Security Department, Center for Strategic and International Studies
Mr. Drew Bagley — Chief Privacy Officer, Crowdstrike
Mr. Joe Lin — Co-Founder and Chief Executive Officer, Twenty Technologies, Inc.
Mr. Frank Cilluffo — Director, McCrary Institute for Cyber and Critical Infrastructure Security
Videoyoutube
Transcript252 caption blocks · 17,641 words · 1:53:12 runtime
EventCongress.gov 118791