▶ 0:00:43Okay, first of all, thank you to both of our folks coming in here today. We appreciate you. But first, I got to ask unanimous consent that non-subcommittee members be allowed to participate in today's hearing after all subcommittee members have had an opportunity to ask questions. Is there objection? Okay, without objection, non-subcommittee members will be recognized at the appropriate time for 5 minutes. And I welcome everyone to today's at today's hearing on cyber posture of the Department of Defense.
▶ 0:01:10Today's hearing comes at a time of increased cyber activity targeting US infrastructure, including recent campaigns against telecommunications and critical infrastructure networks. It also comes at a time when cyber operations are being integrated into military operations more than ever before. US Cyber Command has supported recent operations, including Operation Midnight Hammer in Iran and Operation Absolute Resolve in Venezuela. The Department, with the support of Congress, has continued to develop its cyber forces.
▶ 0:01:39Over the past several years, the Cyber Mission Force has grown and matured. Cyber Command has received enhanced budget control. The role of the Assistant Secretary of the Cyber Policy has been established and filled. And the Department has stood up the Department of Defense Cyber Defense Command, DCDC, as a sub-unified command. The maturation is continuing. Cyber Command has initiated organizational and force generation reform effort known as Cyber Command 2.0.
▶ 0:02:07Focused on improving workforce management, training, readiness, and operational effectiveness. This effort is intended to create more defined career paths, enable greater specialization, and improve the Department's ability to respond to emergency emerging threats. We look forward to hearing about how these efforts are improving Department cyber posture, and where challenges remain. We are joined today by Ms. Katie Sutton, the Assistant Secretary of Defense for Cyber Policy, and Principal Cyber Advisor to the Secretary of Defense.
▶ 0:02:33Prior to her appointment, she served at Cyber Command and on the staff of both the House and Senate Armed Services Committees. Ms. Sutton, thank you for being here. We are also joined by General Joshua Rudd, who was sworn in as the Commander of US Cyber Command and Director of the National Security Agency in March. General Rudd, thank you for joining us. We'll just go ahead, okay. So, what we're going to do is just going to yield directly to the testimony. So, with uh we uh yield to Ms. Sutton, and then we'll go to General Rudd.
▶ 0:03:05Chairman Bacon, um and distinguished members of this committee, thank you for the opportunity to testify here today. I'm honored to be here with General Rudd, whose immense experience, especially in the Indo-Pacom Pacific region, will prove invaluable as we posture to implement the National Defense Strategy. I also congratulate Lieutenant General Hartman on his retirement, and thank him for his service and visionary leadership that has built the center cyber enterprise over the years, setting the stage for our future success.
▶ 0:03:36In my role, I'm responsible for overseeing the Department's cyberspace operations policy, integrating cyber activities across the Department, and exercising authority, direction, and control over US Cyber I'd like to start by highlighting today the new and ever-dynamic strategic environment that we face in the cyber The character of cyber warfare is changing rapidly, shaped by the growing threat posed by our adversaries, and accelerated by the ever-growing power of
▶ 0:04:06We must act decisively to transform our cyber enterprise and deliver the robust cyber capabilities and optionality required for the President and Secretary to defend American security, freedom, and prosperity. One major change that we're seeing is that our cyber actors are no longer just conducting espionage. They are preparing for conflict. Our adversaries have moved beyond theft and are pre-positioning disruptive capabilities inside our nation's critical infrastructure.
▶ 0:04:36This strategic shift from exploitation to effects aims to disrupt military deployments and sow chaos in crisis or conflict. Cyber threat actors like Volt Typhoon are not just a new nuance, they nuisance. They represent a significant and persistent threat to our national security. Second large change is artificial intelligence has become a powerful force multiplier, increasing the speed, scale, and sophistication of these threats.
▶ 0:05:06AI accelerates the entire attack lifestyle, creating a new dynamic where the pace of attacks challenges our ability to react, and the scale overwhelms our ability to Rapid innovation has also lowered the barrier for entry for advanced cyber capabilities, blurring the lines between nation-states and other malicious actors.
▶ 0:05:28Our adversaries are operationalizing AI to outcompete us, and we must move urgently to put these same tools in the hands of our Given these realities, a purely defensive posture is no longer sufficient. To implement the 2026 National Defense Strategy's vision of achieving peace through strength, we must pivot our approach. That pivot is guided by three core priorities.
▶ 0:05:54The first is that we must integrate cyber across all domains of Cyber is the connective tissue of modern warfare. We will integrate cyber capabilities across every warfighting domain to provide the President and Secretary with a full range of options to deter conflict and ensure the Joint Force has every advantage. Second, we must gain strategic advantage below the level of armed conflict.
▶ 0:06:20We will deny our adversaries freedom of This means not only building a resilient defense, but also empowering our world-class cyber operators to work across the full spectrum of cyber Our adversaries must be deterred in cyberspace, and we must re-evaluate our approach to contesting the growing aggression in cyberspace that threatens US interests, our national security, and our ways of Third
▶ 0:06:51priority is that our force must organize to dominate. Our strategies are only effective as the force that executes them. Through the Cyber Command 2.0 initiative, we are undertaking the most comprehensive transformation of our cyber force since its inception. This evolution transcends legacy structures to elevate our operational readiness, scale our technical advantage, and propel our force to meet the demands of modern conflict.
▶ 0:07:22We are forging a more lethal, agile, and specialized force based on domain mastery to ensure that we have the world's most talented operators to dominate in this domain. To achieve these priorities, we are leveraging the engine of American industry, harnessing the speed and innovation of the private sector to protect the cyber domain that powers our national security, our economic prosperity, and the American way of My office is leading the development of a Department of War Cyber Strategy
▶ 0:07:52to implement this pivot, and I look forward to sharing with the committee when complete. Let there be no doubt, the Department of War's commitment to the defense of this nation is absolute. We have a solemn duty to ensure our Joint Force is equipped to dominate across the spectrum of conflict and within the highly contested cyber domain. The support of this committee is fundamental to our mission success. Thank you, and I look forward to our questions here today. Thank you, Ms. Sutton. General Rudd, you're recognized.
▶ 0:08:20Chairman Bacon, Ranking Member Khanna, and distinguished members of the subcommittee, thank you for the opportunity to testify before you today. It's my distinct honor to testify beside Honorable Katie Sutton, Assistant Secretary of War for Cyber Policy. I'm honored to represent the soldiers, sailors, airmen, Marines, Guardians, Coast Guardsmen, and civilians who defend our networks and deliver effects that matter every day. I want to thank this committee for your continued support for our critical mission at US Cyber Command.
▶ 0:08:51I too want to thank and recognize Lieutenant General Joe Hartman, his wife Catherine, and their service for over three decades to this nation and their incredible contribution to Cyber Command and the National Security Agency. Cyber Command's mission is threefold: defend the homeland, defend the Department of War's information networks, and support the Joint Force. In executing these missions, we maintain a formidable partnership with the National Security Agency.
▶ 0:09:18NSA's roles, responsibilities, and capabilities complement Cyber Command's, creating a unity of effort that strengthens our common defense. Since taking command, I've I've emphasized four operating principles: speed, scale, innovation, and I'm proud to report that Cyber Command has been executing under these principles since before my arrival, which has made for a smooth transition.
▶ 0:09:45The team at Fort Meade has set the conditions for success, allowing me to hit the ground running, and I'm excited about the future of Cyber Command. Throughout 2025 and into 2026, we've quickly adapted to the fast-paced strategic environment and rapidly changing character of warfare. In 2025 alone, we executed more than 8,000 missions, an increase of over 25% compared to 2024.
▶ 0:10:11We expect to exceed that pace in 2026, and with your support, I'm certain our talented force is up to the task. Cyber Command gains experience and insights from real-world operations every day, and that experience guides our operational support to the warfighter. Our innovative activity contributes to mission outcomes, to initiatives like Cyber Command 2.0, and to the employment of technologies like AI.
▶ 0:10:37The cyber domain cuts across all war all warfighting domains, and integrating cyber into joint force operation enhances combatant command effectiveness across the board. When called upon, Cyber Command employs full-spectrum cyber operations with and on behalf of other commands to deter, and if necessary, defeat our Our participation in Operation Absolute Resolve and and Operation Epic Fury are prime examples of this integration in
▶ 0:11:08We're also executing the service-like authorities granted to us by Congress. Cyber Command 2.0, approved by the Secretary of War, is moving at pace and achieving new milestones each month. Through Cyber Command 2.0, we will deliver the capability and capacity to identify and hire a talented workforce, provide them with optimal training, and incentivize them to stay in the cyber Additionally, it will enhance our ability to work more closely with industry and academia to develop, acquire,
▶ 0:11:39and operationalize cutting-edge Cyber Command will continue to work with the cyber policy team and the services to ensure Cyber Command 2.0 is implemented effectively. Thank you for the privilege of appearing before you today. I look forward to working with you, and I look forward to your questions. Thanks to you both. Appreciate your opening comments. My first question, General Rudd, you said the third your third mission are supporting the joint force.
▶ 0:12:08You have had a lot of opportunity to do that in the last few months, uh particularly with Venezuela and now Iran. I know this is an unclassified setting, but I think it's important for the public, to the degree that you're allowed to say, talk about how you supported those the the joint force, and then we can go in more into full session. Mr. Chairman, absolutely.
▶ 0:12:29I Again, it's it's a privilege to step in at this time right now while the command is at a fight in a fight supporting a combatant command. 24/7 laser-like focus side-by-side with the men and women of NSA providing real-time support to the warfighter, and that's exactly what I would expect to out out of the combatant command that delivers the most in in this critical If I just may add, it's been impressive to to hear what the role that
▶ 0:12:59Cyber Command has had with our joint warfighters. You've done a tremendous job, the whole team. Ms. Sutton, are roles and responsibilities for the oversight of network operations and network defense across your office, the CIO, US Cyber Command, and the military services clear today, or do we need to work on further delineation? I think there's some overlap, and overlap produces friction. That's Mr. Chairman, I I appreciate the question today.
▶ 0:13:28Um as you know, I appreciate the support from Congress on the stand-up and creation of my office to consolidate some of the policy and principal cyber advisor roles. Um as you're aware, it's um we're about 2 years in the making, and have been working internally to to clarify some of those areas.
▶ 0:13:48I think as I think about network defense, I see it as a spectrum of activities, and we need to focus less on having silos across these different organizations, but how do we really bring together what we're understanding from our adversaries from an operational perspective with how we're doing cybersecurity across the department.
▶ 0:14:07And so we're really looking at taking a whole of um not only a whole of uh ASW approach, but a whole of department approach where we're really integrating the network security aspects and how we do cybersecurity with that operational aspect. And the best way that I know of to do that from my career is that to work on how we partner and how we find common areas to make sure that we are bringing that information that we have from operations to how we set the standards across the department.
▶ 0:14:36Who is ultimately accountable for the DOD securing the DOD networks? Uh the Chief Information Officer has responsibility for cybersecurity of the
▶ 0:14:48Okay, thank you. I just I know there's a little bit overlap there, so I thought I'd ask. Okay, given the pace and scale of cyber threats from countries like China and Russia, this is something we're working on in the Sunday AA and our defense approach. Are current cyber investments sufficient, and where are additional resources or authorities needed? Uh it is my impression that we may be underfunded compared to what China and Russia are doing.
▶ 0:15:14So um excited to see the or excited to be able to talk today about the budget that has been released but um I believe earlier this morning. What you'll see in that as we dig in is that there has been a substantial increase in investment for cyber priorities across the department, um across a range of activities. I think as we look at continuing to grow those, we need to also make sure that we have the that we have the right approach to talent who are going to be really the linchpin in how we accomplish those.
▶ 0:15:44And so making sure that we have that right balance of being able to grow and train, and then also looking at where we can gain some efficiencies of implementing technology rather than just continuing to grow what had we potentially adopted in our posture before that we might be able to improve with something else and then phase out the original approach.
▶ 0:16:04One of the tasks I have from the chairman of the overall committee is compared to look at the investments of Russia and China, and that's are we doing at adequate level to counter that. And I it's a little bit ambiguous right now what that data is showing. So your help your all's help will be needed. My last question, then I'm going to uh yield to the ranking member. Cyber Command 2.0 is intended to drive toward more specialized and mission-ready cyber teams across the services.
▶ 0:16:33How are you ensuring the services are delivering a consistently trained and ready cyber Uh appreciate that question and appreciate the opportunity to have done the deep dive with uh committee earlier this year.
▶ 0:16:47One of the key thing elements that you mentioned is that consistency, and how we're addressing that is by setting the responsibilities of the services at the basic trained and qualified level, and then a lot of the advanced training that we need driving that into the responsibilities of Cyber Command through things like the Advanced Cyber Training and Education Center, so that we can have that unified approach and can also move at a speed that's easier to do within one organization and is operationally tied
▶ 0:17:17to our cyber mission force. Okay, thank you. I yield now to my colleague and friend and ranking member Ro Khanna. Thank you, Mr. Chairman, and thank you both for your I want to understand whatever can be explained in a non-classified setting in the shooting that happened in Iran of the school. Did was AI used at all for that?
▶ 0:17:47Ranking member, I I don't know that I have any information related to that. I'd defer to Honorable Sutton on that. I I would need to take that as a question for action. I also am not tracking the specifics of that. How would though a strike or nearly like that take place? I mean, just in in terms of targets in Iran. I mean, what is the role of the different intelligence agencies? How does the process work?
▶ 0:18:13So my roles and responsibilities are in the cyber domain, so unfortunately, I I don't have the details on the specifics of how the kinetic targeting was done. What do you know, General, of how it Ranking member, the my previous experience not within this command and not related to that operation, uh it's a very deliberate process that is uh again, it it it would involve a tremendous amount of intelligence, it would involve a tremendous
▶ 0:18:44amount of expertise, it would involve experts that would analyze and assess weaponizing. Again, outside of my current role, um but uh the other thing that's consistent throughout all targeting processes consistent legal How uh how do you think we deal though with AI and and lethal autonomy? I mean, in in terms of uh your general views.
▶ 0:19:14Con- uh Ranking member, I think this is a really important policy question that as we look forward to the speed of how technology is moving, there's a couple things that we're going to need to move quickly with the technology. The first is accountability. As we start looking at how AI gets integrated into different aspects of warfighting, really making sure we take the accountability that we've thought through from the kinetic domain and making sure that we're applying that to AI.
▶ 0:19:42I think this also highlights the importance of also how we secure these technologies to make sure that they aren't available for anybody else to have access to going forward. And we continue here that there's a shortage of qualified red team talent. Do you agree and what can we do to address that? So I I share your concern and I would actually broaden your statement to say that there is a shortage of cyber talent.
▶ 0:20:09Red teaming is a specific element that I'm actually very personally familiar with in my previous capacities have actually been responsible for red teaming. I think this is an area where we're seeing a lot of opportunity for AI use and how we can use AI from a red teaming perspective that we'll have to aggressively adopt going forward.
▶ 0:20:31And the last question is do you think that the current cyber security service provider model is adequate to today's I think that as we go forward we're going to have to look at how AI is going to change how we do that and that will likely need to take a look at how we organize as I mentioned to most effectively use the resources that we have to be able to get at this problem.
▶ 0:20:55The scope and scale as you know of the Department of War information network is pretty extreme and making sure we have the right team able to defend that quickly is going to be important and that's something we'll be in partnership with the Chief Information Officer looking at very closely particularly as we continue to stand up the DCDC sub unified command. Thank you Mr. Fallon you are recognized for 5 minutes. Thank you Mr. Chairman. You know obviously
▶ 0:21:24cyber works we we can't take this for granted and if you look just recently at absolute resolve and operation midnight hammer operation epic fury cyber com was in the fight. And one of the things that I wanted to mention too and I would be remiss if I didn't is this is a testament to the men and women of this command and Secretary Sutton's office has been really instrumental and congrats on that. We have but we can't stand still the threat isn't going to and Iran is a sophisticated cyber actor as you all know.
▶ 0:21:54And we don't know what the leadership in that country is going to look like here shortly but it may be something that they might double down on this because it's they can hit us you know half a world away and we we all know this.
▶ 0:22:07One of the things that I'm most concerned about and and Secretary when we were visiting is and in retention and particularly the recruitment because the civilian sector can pay so much more and but much like our CIA as we that they can the folks that want to serve do so because it's such a gratifying and significant contribution you can make to the republic and so is this incidentally.
▶ 0:22:31So wanted to touch on if you could for the record what's the rough breakdown between military uniform members opposed to civilian because I just want talented folks. And it might be easier for us to recruit talented folks that aren't in uniform because they might just have a little bit you know longer hair they might have some tats whatever I don't care they can hit those computer keys in a very adroit fashion we need to we need to recruit them and bring them in and keep Congressman thanks for the question
▶ 0:23:01and I really appreciate our discussion last week. As you mentioned this is a fundamental problem that we need to look at and today the varies by service but it's approximately 80 to 90% uniformed within our cyber mission force.
▶ 0:23:17As we look at cyber command 2.0 going forward one of the key pillars is how do evaluate that balance so that as you mentioned we can bring in a wider pool of talent from civilians from contractors and then we also need to look at how we're going to leverage industry because there is tremendous innovation and talent in industry and we're going to have to figure out how we can leverage that through different mechanisms. So that is something that we are going to continue to focus on and need to be pretty aggressive going forward to make sure we have the talent that we need.
▶ 0:23:47I just say aggressively recruit and we also need to let the young people know that if you come and you serve for even four or five years you don't have to go career and then go out into the civilian workforce. Think it's going to add tremendous value to their resumes. I think the ranking member you know in the previous life he led could attest to that as well.
▶ 0:24:09One of the I think most compelling things to recruiting and retaining retaining our force is our mission and the things that we allow our really talented service members and civilians to do. One of the things we need to work harder at is allowing them to keep on keyboard and do and stay on mission and then as you mentioned the experiences that they gain for that will be highly valuable both in other roles in the government and in the private sector. So how do we leverage that throughout their life?
▶ 0:24:38And and Secretary you also mentioned that I got the quote the quote here and that the current force is insufficiently scaled for the threat environment and then I see the administration's FY27 budget request for cyber on really doesn't reflect that urgency or its sourcing. So what I want to ask you is what is the delta between cyber com 2.0 you know the needs to execute and what the president's budget request provides?
▶ 0:25:03So one of the concepts of cyber command 2.0 is that instead of continuing to just grow the numbers of the force to work on building the mastery of the force so that the capabilities of the people that we have are deeper and have that longer time on keyboard. And so that's really where we think we're going to get a lot of outsized impacts rather than just continuing to grow the level of the force that we have today. Thank you. General thanks for your testimony today.
▶ 0:25:30I wanted to just visit real quick if you could in the time I have remaining talk about timelines because you were talking about new entities like the cyber talent management organization and advanced cyber training and education. Love all these ideas and even the innovation
▶ 0:25:46warfare center and you say that they're under construction and slated to be operational in your term. Can you talk more about the specifics on the Congressman uh I would tell you just in to to lead with again going back to the principles against which we need to operate speed scale innovation Um time's of the essence so we need to move as fast as we can.
▶ 0:26:13what what I what I think I can provide you maybe a follow-up for the record is how we see those timelines being progressed and where we see opportunities to accelerate. Perfect. Thank you General. Mr. Chairman I yield. One quick follow-up question. Do we ever hire folks who are experts in the cyber field at a private company and bring them in civilian or military? Just following up on his question. I I I believe we have. I can I can verify that.
▶ 0:26:41I'm pretty certain we have and again to me that question speaks to a tremendous opportunity to get after scale and innovation. Again doesn't have to necessarily be in uniform all the time there's other options I think where we can look creatively where we can hire we can maybe make them reservist or I think there's tremendous opportunity to be innovative here.
▶ 0:27:04We have a lot of cyber experts in our private industry in Omaha and I think bringing them in would be a would be helpful to just have that Yeah Chairman I I don't disagree with you at all. Ms. Houlahan you are recognized for 5 minutes ma'am. Thank you Mr. Chair and General it's nice to see you. Thanks for joining me in my office and Secretary it's also nice to be with you today too. Time is of the essence and speed and scale is really important so I'll try to do my best with my 5 minutes to ask all these questions.
▶ 0:27:33As we know cyber com 2.0 is supposed to fix a number of problems but one of them is around cyber com structure which is supposed to now be modeled after SOCOM correct? The cyber command 2.0 model was actually built on a blend of models within the department. So it included many elements of the special operations force but also things like the medical community and others as well. Excellent excellent.
▶ 0:27:58And so General Rudd speaking would you consider special operations a domain like the land air sea space and cyber space area or is it just unique operations that are are shared with air sea and land domains? Congresswoman the special operations force is applied across all domains. So it's not its own domain. It is shared across all domains as they are defined land air sea space.
▶ 0:28:30The the specific forces within SOCOM span land sea and air and interoperate with cyber and space force.
▶ 0:28:39So Secretary Sutton would you say that the cyber domain and the need for cyber operations will increase or reduce or hold steady over the next few decades? I think we've seen a very consistent upward trend that I don't anticipate to slow down anytime.
▶ 0:28:54Me too and that's why speed matters and also frankly why I believe that this is its own domain that needs to be addressed in its in its own way with its own force to be honest. I'll move on and say that I believe that some of the issues that are confronting cyber com are not just a cyber com issue they are coming from how our services our individual services are prioritizing cyber forces among their other requirements and responsibilities.
▶ 0:29:21So as an example I would find it hard to believe that the Air Force would legitimately support a cyber wing over a fighter wing as an example or the Navy support a cyber group over a ship or the Army potentially supporting a cyber unit over an artillery battery as an example.
▶ 0:29:36I know General Rudd in your new job that you obviously will in are very interested in valuing cyber very highly it's because you're culturally incentivized to do that but I believe that the Army is not necessarily incentivized to care about things like that, but rather infantry, artillery, tanks. And if you're a young cyber officer in the Army, I don't believe that you are thinking about your career in that way, but rather you're thinking about your career in Army operations terms that are more traditionally written.
▶ 0:30:06Would you assess that that might be true as well, General? Well, Congresswoman, what I would expect that in this role I'll have the opportunity to work with all of the services to express the importance of talent management of the cyber force and advocate for advancement across all services.
▶ 0:30:23And I know that Mr. Bacon asked you, Secretary Sutton, a lot of good questions about incentivizing people and and pay scales and recruiting and a lot of really innovative ideas of how to do I would, I guess, argue my position is that we, just as much as we needed to separate the Air Force out in 1947 and just as much as we needed to separate out the Space Force in 2017, that there may indeed be a need to separate out the cyber force sooner rather than later.
▶ 0:30:52Assistant Secretary Sutton and General Rudd, do you think that Congress has made the right decision to establish an Air Force, even though the Army and the Navy opposed that? I second the motion, by the way. Um so, I appreciate all the questions about the cyber force.
▶ 0:31:10I actually think this is a really important debate that as policy makers we look forward to This is a very rapidly evolving domain and making sure that we're organized appropriately is something that we really need to address going forward.
▶ 0:31:23I agree. This and we'll conclude by saying this domain is clearly growing, not shrinking, and at some point the cyber forces that we have, generated by services that deliberately don't prioritize cyber for practical and cultural reasons, won't be enough to meet our future cyber demands. And any significant change to our military structure up until up and until we actually have a brand new service, believe will be difficult.
▶ 0:31:48So, all I'm asking you both and us here is that we have an open mind to the idea of a cyber force. While I very much welcome cyber 2.0 and its recommendations, I genuinely worry that it's just not enough. So, all I'm asking is, Secretary and General, will you commit to keeping an open mind on this issue? So, yes.
▶ 0:32:09I I also appreciate the opportunity that you highlighted to articulate that Cyber Command 2.0 in a cyber force aren't a competing interest. We need to focus on the talent management of our force and then we need to look at the organizational structure. I appreciate Congress's interest in this. We, my office and the department have been supporting the National Academy study that I think was formed to do an independent look.
▶ 0:32:36We, I've testified twice in front of that committee and look forward to their report this summer.
▶ 0:32:40Thank you, Secretary. I've run out of time. I also support a cyber academy as well. And General, just yes or no, do you support keeping an open mind on having an independent cyber force? Yeah, Congresswoman, again, I align with the department and honorable Sutton on this topic. And again, appreciate the fact that they're they're not in competition. It's it's not a either or, it's a Thank you. And Thank you. I yield and I appreciate the indulgence of the chair. Mr. McCormack, you're recognized for 5 minutes, sir. Thank you, Mr. Chairman.
▶ 0:33:07First of all, I kind of like the idea of multiple academies and multiple schools. Uh University of North Georgia is one of those schools that competes across the nation. Actually dominates. A little school in Georgia actually dominating in the cyber intelligence community. Uh it's been great to see. I think it's also an elite Army school. Uh for you Army guys out there. I see you've got a Marine here and the cyber is just kind of amazing leap of uh of technology when we used to eat crayons. Well, we still eat crayons, but we're doing a little bit of things in uh now.
▶ 0:33:36Really excited to see the evolution from a guy who literally learned how to use a computer in the Marine Corps, which is kind of a scary thought at that. Um one of the things I I've noticed uh that's maybe a great recruiting tool I wanted to kind of get your affirmation, maybe expand upon. Just like we recruit lawyers. And one of the reasons we're great at recruiting lawyers cuz we give them real trial trial uh experience. Uh most people in the cyber community can't go out there and practice this offensively unless they work for the government.
▶ 0:34:04So, this is a great opportunity not just to develop something, but to actually apply it, which is a great selling tool. But what else can we do to not only um train people, but recruit them and retain them in the cyber commands, which I think is essentially all in the same arena of being competitive in this in this very world competitive market. So, I I appreciate the highlighting you started out with with the talent that we get from a pretty wide variety of universities.
▶ 0:34:34I'm many of which are the NSA Cyber Centers of Excellence school. This has been a great program to be able to get that pipeline in. The challenge that we're really now faced with is how do we recruit them in full time and how do we retain them? And I think there's the primary thing that we've seen from our force over the last few years is the importance of keeping them on mission and giving them the opportunities to build that talent that as you very accurately highlight is something they can only do in our force.
▶ 0:35:01And then also making sure that we have the right incentive structure, we have the right career paths, so that they can grow and they can succeed in their service, but do it in a way that is meaningful for building that mastery into the skill that we have today. Fantastic. General Rudd, you know, yesterday we had a great opportunity to speak in person, kind of talk about the futures. We talked about a united command, which is going to be a central focus, I think, of this committee. It's kind of do we do this combined or do we do this separate? And I've seen heard arguments on both.
▶ 0:35:28I'm kind of open-minded and I'm I'm forming an opinion every single day, trying to be more educated. Uh specifically to the Marine Corps, though, I was going to ask when we first got computers and we broke a bunch on the along the way and we we learned in in service. Now we're out service and we're learning all these people. How does the Marine Forces Cyber, also known as MarFor Cyber, uh currently support the joint force? What role do they play in the future fight?
▶ 0:35:55As far as the difference between the separation as an independent entity, kind of like we did with the EA-6Bs, where we use it as a purple force, or is it is it used specifically for a Marine Corps mission, which is kind of a tough question, I know, but if you could just tell me the difference between the applications, which will help me make up my mind as to how we form the future. So, this is it right here, Congresswoman, right? No pressure.
▶ 0:36:18Hey, just one point on the recruiting, if I if I could go back to that Uh I I think there's tremendous opportunity to tell the cyber story maybe in a different way, maybe in a more open way than what we've done previously, that it's going to generate interest around. I I don't know that I can recall a time in our history where we've talked more about it openly, perhaps because maybe we're not doing We've never done as much as we have done in in recent history. But that's one point.
▶ 0:36:44On on the the question with regard to support to the joint force, MarFor Cyber is doing a tremendous job across a number of commands. And again, in support of the joint force, integrating really seamlessly, whether it's a combatant command or special operations command, they do tremendous work. Again, in real time, 24/7 commitment.
▶ 0:37:10The the integration is really dependent upon culture, communication, and co-location in many cases. If they can be side by side, doesn't always have to be. Obviously, there's there's a tremendous power in the remote aspect of of the cyber force, but that's those are kind of key aspects that I'd highlight to your question. So, specifically, do you think, both of you, I'm just curious, what is the main advantage of having each service have their own cyber command versus a combined?
▶ 0:37:42So, I think one of the things that is important to discuss as we think about a cyber service is where the boundary of things and services, like defending their networks and defending the weapon systems and ensuring cyber security in the weapon systems systems they build, how that would separate out from things like a cyber mission force that would conduct operations in support of the joint force. And ensuring that that boundaries are well defined as you would think about different organizational constructs going forward.
▶ 0:38:12All right, with that I'm out of time and I yield. Thank you, Mr. Chairman. Thank you. Mr. Ryan, you are recognized, sir, for 5 minutes. Thank you, Mr. Chairman. Thank you both for for being here. Uh Assistant Secretary, thanks for the time. Uh is that last week or this week, whenever it was? Thank you. Um General, thanks twice in one week. Sorry about that.
▶ 0:38:31Um Uh I want to build on really good, I think, encouraging bipartisan discussion about broadening the base and the foundation of our cyber talent force as a nation, not just whatever we end up however end up organizing within and across the services and within DOD. Really thinking about this as a national problem. Um and General Rudd, you talked about this and sort of alluded to it earlier and you talked about it in your written testimony.
▶ 0:38:57I think you described it as a a joint cyber reserve component or funded reimbursable authority in your in your um uh submitted statement. General Hartman, on his departure, talked about a cyber We talked a little bit as well, Assistant Secretary. I think would love to hear both of your thoughts on this. This is something I've been working on the last few years. We've had multiple attempts in the NDAA to introduce this concept.
▶ 0:39:23Specifically, how do we get the full breadth of our cyber force engaged at various levels of you know, if one level is I'm doing a PT test every month and I'm in uniform and the other level is no engagement, how do we broaden that out and create multiple avenues for people to plug in um, and serve a whole host of missions. So, General, starting with you, if you wouldn't mind expanding on your testimony and sharing any thoughts Sure, Congressman.
▶ 0:39:51Yeah, I I think there's tremendous opportunity with this idea, whether it's Reserve, Auxiliary, or all of the above. I think we don't need to limit, the manner in which we approach this, because again, the the talent is so unique, and there's such tremendous opportunity in the commercial sector to leverage expertise, and and by, again, by extension, you're going to force multiply. Um, we can be more creative.
▶ 0:40:19We can figure out, I think, you know, we may be some of our own impediments in terms of process, speed at which we can grant clearances, etc. I think we need to be more creative about that. It's definitely something that I'm, uh, interested in taking a deep look at as part of my initial assessment.
▶ 0:40:37I know Honorable Sutton and and her team have looked at it, uh, in depth, but, uh, again, I just don't think we can afford to limit, uh, the, uh, the creative solutions to expanding the the cyber workforce, and in doing so, leverage tremendous talent that's out there. And maybe just to lead into to you, Assistant Secretary, agree, more is always better generally, but I think particularly every dollar we can spend on cyber, the ROI is dramatically higher than a lot of our uh, other opportunity costs.
▶ 0:41:06But, what would you see as a first step or two? Um, and I ask this because I think coming into this NDAA, we we want to be aligned with with you all as you're rolling out your changes. Is there anything any first initial steps, either for you, Assistant Secretary, or back to you, General, in terms of, you know, does does the idea of some sort of joint reserve component resonate with you? Has your team been able to look at that with any great depth yet? Um, thank you again for meeting last week.
▶ 0:41:35It really, um, appreciate the discussion and the ability to talk through some of these topics in depth. Um, as we mentioned, I completely concur with everything General Rudd said. I think this is not a place for us to limit ourselves. We have to open up the talent pool that we are that we can recruit from, and I think there's different models to look at. One of the things that my team has been focused on over the last year, um, at the direction of this committee, was to look at the, civilian reserve model.
▶ 0:42:06That study has been completed. I think there's a lot of really good recommendations that we need to start looking at what what the first steps would be to move forward with how we might implement pieces of that, and particularly how that can support also, not just the Department of War, but the whole of government effort that's going to be, uh, a large-scale problem, where civilians might have a really great tie into other areas as well. And and we talked about this a little in my office.
▶ 0:42:31As a former local elected official, imagine major debilitating cyberattack of some kind on the nation, the ability at local government level to answer that is just very limited, and I think folks would naturally look towards, um, some some ability to extend the the very unique high-end capabilities right now out across the nation. So, that's part of the the thinking here as well, to to some degree, to to provide capacity and and expertise there. Um, I only have a few seconds left.
▶ 0:42:59Anything you want to add, General Rudd, before I yield back? The only thing I'd add, Congressman, is I think the same, uh, idea applies to National Guard as well. I mean, look at localized state protection in these domains, especially when you talk about critical infrastructure, um, tremendous Thank you, and I yield back, Mr. Thank you. Mr. Vindman, you are recognized for 5 minutes. Thank you, Chairman. Thank you to the witnesses.
▶ 0:43:26Thank you, uh, Honorable Sutton, for your engagement today, and also for your engagement, uh, prior to this. I think that's a good model for, uh, the relationship we should have in Congress. So, um, are there any key policy, legal, or bureaucratic constraints limiting Cyber Command's ability or agility? Um, and, for example, in authorities, data sharing, or acquisition. And, uh, what specific statutory or policy changes are needed to make a more effective Cyber Command 2.0?
▶ 0:43:59So, thanks again for the meeting. I also agree that that's a great model, um, to use going forward to make sure that we're in lockstep. Um, I think as we dive into the implementation, and as General Rudd mentioned in his statement, every month we have outcomes that we're starting to deliver, we are going to start uncovering some of these, um, statutory and policy hurdles, and that's the role of my office is to identify those. If they're statutory, to bring them to the committee and let them know some of the challenges we're facing.
▶ 0:44:27If they're policy internal to the department, figuring out how we can fix those. Um, and then I think as we think about, so that's from a talent perspective, and then as far as a technology perspective, one of the things as we think about AI and moving forward is that the technology's moving very quickly, much faster than we traditionally move as a policy perspective.
▶ 0:44:48And so, making sure we're thinking about policies in the right way, so that we can, um, have all the authorities we need to use these in ways that allow us to have the advantage that we'll need going forward. Yeah, and especially as you as it relates to AI, and obviously there are concerns and potential dangers that is important for us to have a dialogue on the authorities are and what some of the constraints are to make sure we have the balance right.
▶ 0:45:16Um, General Rudd, what are the biggest challenges in recruitment, retention, and proper utilization of the Reserve and Guard cyber talent? Well, Congressman, I I think I owe you a little bit deeper study on that before I can give you a very definitive answer.
▶ 0:45:33Um, but what I would expect is a little bit of what we're we're already discussing is competition for incentives with the, uh, you know, commercial sector, but then also, where do we have our own obstacles within our own process? Does it take too long to onboard somebody? Are the requirements, you know, either medical or physical antiquated and/or don't apply?
▶ 0:45:58I'm not implying that we reduce standards, um, but what what I am suggesting is maybe we just need to look at how we move quickly through barriers. If that is a competition, and adds to the compet- competition for talent, um, maybe it's something we need to relook. But, I think I I owe you a little bit deeper look on that before I can give you a a better answer, Congressman.
▶ 0:46:19I appreciate that, and I look forward to, uh, a deeper dive on that. And obviously, uh, thinking through also what standards, uh, ought to apply to the types of folks that we want to be our cyber warriors, I think is important as well. how would a joint cyber reserve component resolve underlying issues? I don't know if you've thought about that Are there any statutory or funding challenges that require this committee's assistance in that regard?
▶ 0:46:52I suspect Honorable Sutton put a little bit of thought to it, but I can tell you right now, just on the the the topic of reserves writ large, uh, the funding goes through the services right now. So, we're challenged at Cyber Command to move quickly to leverage resources to activate Reserve, uh, in a manner that would, uh, sometimes be late to need and/or in competition. But, I'll I'll defer to Honorable Sutton.
▶ 0:47:20I I think General Rudd has really hit hit the nail on the head here, um, that this is something we need to look at from a joint perspective, and something with Cyber Command authorities, we need to continually evaluate what those look like. Um, as appreciate all the support from the committee on getting many of those authorities into law. As we start implementing those, for example, enhanced budget control, understanding where some of these lines need to settle out now that we have a couple years in the budget.
▶ 0:47:48As my role as, um, Assistant Secretary, and in my service secretary-like role, I think those are exactly the questions we need to ask is, what is the structure in the department we would need to fund a joint reserve? Is that part of Cyber Command's service-like authorities? And how do we get after that pretty quickly, because as General Rudd alluded, there's significant talent in our reserves, and I think that's a nut we just haven't fully cracked yet. Thank you, I yield back.
▶ 0:48:20Thank you. Mr. Whitesides, you're you are recognized for 5 minutes. Thank you, Mr. Chairman. thank you both for your service. Cyber Command DOD generally have supported Ukraine against Russian hacking attempts, which has been effective at keeping Ukrainians with power and heat, uh, intermittently throughout the war with Russia. How is Cyber Command using lessons learned from that conflict to support protection of our own infrastructure?
▶ 0:48:51I I can go first, but I you look like you're going to lean in. Um, so, as I mentioned earlier, I think one of the keys to our success is going to be able to identify adversary threat activity, and then do exactly what you said, which is how do we learn from that, and how do we implement that on our own critical infrastructure?
▶ 0:49:10Bringing that offensive and defensive perspective is really important, and I think one of the key steps of how we're starting to get after that, and getting a need to continue to accelerate, is the elevation of the subordinate DCDC Defense Command under Cyber Command. So, we have the offensive cyber national mission force, now we have the defensive, all under one commander, um, who might be sitting next to me.
▶ 0:49:33And so, I think there's a lot of opportunity to take those lessons learned from where we've seen adversary activity and really make sure we're quickly operationalizing it from a defensive perspective. And and Congressman, I'd I'll build on that.
▶ 0:49:48It even starts further left with the unique relationship with the NSA and the insights that we gain through intelligence that then inform the techniques and the the locations and then to honorable sudden's point, moving through with the expertise of Cyber Command then in coordination and then distributed to the DCDC for the defensive activities that need to take place across the network.
▶ 0:50:14That is an example of where a multifaceted command structure under one authority, well, different authorities but one one person enables speed and agility to put us put ourselves in a better position to defend our critical Thank you, General.
▶ 0:50:32Um General, I was glad to see your testimony emphasize the workforce development efforts you're making to build your team in this rapidly evolving threat environment and the emphasis on building partnerships with other agencies, academia, and I I did want to express my concerns, it's not directly with your responsibility, but I think it's an important thing to say in this setting that uh certain actions that the depart- department is taking unnecessarily put those good efforts at risk.
▶ 0:50:59For example, by label- labeling a leading supplier a supply chain risk just as we are wanting to increase the number and types of non-traditional defense suppliers with in cybersecurity and data analysis. I don't know if you have any comments on that general subject.
▶ 0:51:19So, um I think what is really where there's a tremendous opportunity in front of us is figuring out how we are going to approach what is a very uh momentous time where we're seeing a very rapid transition from uh human speed to machine speed. And we're going to need to make sure that we're really looking across the department and how we address that. Um it's not going to be a single solution of a single model or single company.
▶ 0:51:47Um as I mentioned, the technology is not what scares me the most from a policy perspective. It's how are we going to change TPs of how we operate in the department. We're no longer going to be able to patch where we identify a patch, we have a lot of time to uh test it and then we can issue an order and then have a lot of time to patch it. We're going to have to really compress that.
▶ 0:52:10And I think that's where from a policy perspective, um not being in charge of acquisitions, but from a policy perspective, really looking at making sure that those um things don't get lost as we see a lot of capabilities coming forward really across the entire frontier model ecosystem, making sure that we're ready for that going forward. Do you want to add to that?
▶ 0:52:33Congressman, I would just add that we need to anticipate the speed to the extent we can and be in position to be able to leverage technology as it happens ahead of commercial and adversary potential uses of it. Yeah, I couldn't agree more. And I think just, you know, as a almost editorial comment, we need to take the best of American innovation and integrate that into our national security.
▶ 0:52:58And so I hope that we can sort of work as adults to do that across the ecosystem of of private industry. Thanks for your service and I yield back. Thank you, Ms. Slotkin. You're Thank you, Mr. Chair. Thank you for allowing me to wave onto the subcommittee today. Thank you, um Madam Secretary. I I appreciate your career's long career long focus on on this issue.
▶ 0:53:20I was a little bit disappointed to see in the National Defense Strategy just kind of a handful of references to Uh you know, I think everybody here and on full committee fully appreciates General, you you said how Cyber Command enhances combatant command effectiveness. I mean, I think we could all agree with you and I think it's we wouldn't be essential it's so essential we wouldn't be successful. Um I think it's it's that critical at this point in in this era of of warfare.
▶ 0:53:47But I'm I'm I'm concerned by the lack of stress in the National Defense Strategy, but I'm curious you mentioned soon to be coming out with the new Cyber Command Strategy. What is the timeline for that and and are you going to get that to us as soon as possible? Absolutely. Um so, one of the primary goals of the um Department of War Cyber Strategy that we're working on is to take sort of those higher level guidelines and really get specific about what that means in cyber.
▶ 0:54:14Um so, there's a few things just to sort of broaden where we're looking at. Obviously, the National Security Strategy and the National Defense Strategy, but the recently released Cyber Strategy for America is also an area that provides pretty um consistent guidance of where we need to go. We're taking all of those and really making it an integrated approach that's going to be a very bold transformation of how we think about cyberspace. Um we're working at very quickly. The anticipation would be to have that completed this summer so that we can move out on implementation.
▶ 0:54:44And absolutely, we will be um happy to not only provide with the committee, but come and um have any discussions or go through any questions that you might want. I appreciate that. I hope I do get invited back, Mr. Chair, for that for that important discussion. I do want to briefly touch the last time I was I waved onto this committee, it was kind of peak dodge and significant riffs uh particularly in the civilian side.
▶ 0:55:05Can you give us an update on I believe I don't want to say a number here in an open session, but were the proposed reductions in force actually executed So, I would need to take that as a question for the record. I think largely most of that happened before I came in as Assistant Secretary. Okay. I appreciate that. Um General, so excited to have you. Welcome to the committee. Welcome to Maryland. Welcome to Fort Meade. Uh it's exciting to have a uh uh combatant commander here um and and ready to take Cyber Command to the to the next level.
▶ 0:55:36I I do as this is such a healthy discussion about, you know, 16 years into this Cyber Command exercise uh what we've done well, what we can do better, how other countries are kicking our butts a little bit here and there. I I also think as we're talking about, you know, thankfully how essential Cyber Command is, I'm not seeing that necessarily and and for Secretary Sutton, I'm not necessarily seeing that and how we are resourcing all of our installations that are essential to to Cyber Command.
▶ 0:56:07You know, representing the defense line of Fort Meade, a lot of money has gone onto the NSA side, which is wonderful. Garrison side needs I think some greater support, particularly because it does support the incredible work on the NSA side. And and I I I just I'm not seeing as essential as cyber is, I would like to see DOD investment a little more in all of the the whole of the installation.
▶ 0:56:29So, I I guess my question is despite its operational it's not even significance, critical nature, Fort Meade is not formally designated or resourced as a traditional power projection platform. I'd like your thoughts on that because I I think we can do better.
▶ 0:56:45I will admit I'm not familiar with what it takes to get that designation, so would like to take that for the record, but um share your sentiment, I believe, which is if we're going to build the world's most talented cyber force, we need to have facilities that they can operate in that meet those needs and where we aren't putting artificial burdens up with their facilities or their ability to do the you know, come to work and do what they need.
▶ 0:57:09And and to be clear, we we've made tre- tremendous investment in the infrastructure of Fort Meade on on both sides, Garrison side and and NSA side. I just think there's as considering how um how it's expanded, General, you're speaking about all the operations percent increase over the years, I think we just need to have a different kind of focus on in our MILCON on the support of this essential uh essential operation. General, I only have a couple seconds left. Do you have any thoughts here?
▶ 0:57:37Congresswoman, you're not going to get anything except tremendous support and agreement on doing everything we can to put our facilities in a position that offer world-class support to world-class cyber operators, warriors, and more importantly, their families. I appreciate that. Couple seconds left. Last year uh well, you weren't here, we we did talk about the emphasis needed on mental health support for our cyber warriors. They're dealing with a unique uh pressure um and I just want to make sure that we're doing everything we can.
▶ 0:58:07Perhaps we can talk about it more in closed session, but it's something I know I hope you both are taking very seriously and and we can continue to build out the support system necessary for our cyber warriors. Thank you, Mr. Thank you. I appreciate all the discussions too on the separate cyber force I think it merits I for one I'm a little bit skeptical. Just to just to say I my concerns are I think we just add more general officers, more administrative costs. I like the SOCOM model that we have now.
▶ 0:58:35I think we got to give it time to see it works and if see if we how we can fine-tune it. I also fear that if you had a separate cyber force, it would maybe break that linkage with NSA that I find so valuable that we have today with the dual hat. I think that that's what gives us real power with Cyber Command is this sy- synergy that we have formed with NSA and you don't want to I want I don't want to disturb that, but that's just my my perspective and welcome those discussions.
▶ 0:59:03But at this time, we're going to conclude the open portion of today's subcommittee hearing. For members who will not be joining us, questions for the record will be due to the committee within a week after the conclusion of the hearing. And with that, I want to thank you for this open session. We will convene now in the SCIF in Rayburn 2337 for the classified portion and the subcommittee is