Unconstrained Actors: Assessing Global Cyber Threats to the Homeland

Defense Posture and Global ThreatsHouse Homeland Security · 2025-01-22 · 119th Congress
The House Homeland Security Committee held its first full committee hearing of the 119th Congress to examine cyber threats to US critical infrastructure, telecommunications, and government networks from nation-state adversaries — particularly the People's Republic of China — as well as Russia, Iran, North Korea, and criminal actors. Begins at 0:07:47
Transcript
Highlights

Title

Assessing global cyber threats from China, Russia, Iran, and North Korea

Purpose

The House Homeland Security Committee held its first full committee hearing of the 119th Congress to examine cyber threats to US critical infrastructure, telecommunications, and government networks from nation-state adversaries — particularly the People's Republic of China — as well as Russia, Iran, North Korea, and criminal actors. Witnesses from CrowdStrike, SentinelOne, the Foundation for Defense of Democracies, and the Paladin Global Institute testified on Chinese pre-positioning campaigns (Volt Typhoon, Salt Typhoon), the role of CISA, workforce shortages, and legislative priorities including the Cyber PIVOTT Act and reauthorization of the Cybersecurity Information Sharing Act of 2015. Begins at0:07:47

Who spoke

Chairman Mark Green (R-TN)0:07:47: Opened by stating China is "burrowed into our infrastructure" and could shut down communications, energy, ports, and water0:09:50; named the Cyber PIVOTT Act as a top priority0:10:50; later questioned Mr. Myers on China's playbook of exploiting external-facing devices0:44:48 and Rear Admiral Montgomery on a proposal to put a cyber defense National Guard unit in every state0:47:20.

Ranking Member Bennie Thompson (D-MS)0:12:51: Noted over 100 House Republicans voted to cut CISA's funding by 25%0:14:21; criticized DHS secretary nominee Kristi Noem's comment that CISA should be "smaller"0:16:24; raised concern about the Cyber Safety Review Board's stalled Salt Typhoon investigation0:18:25.

Adam Meyers, CrowdStrike0:22:27: Said China has achieved parity with other cyber powers and cyber intrusions rose 150% across sectors compared to 2023, with 200–300% increases in some sectors0:23:28; recommended increasing the tempo of operations to disrupt adversary infrastructure0:26:28.

Rear Admiral (Ret.) Mark Montgomery, FDD0:27:29: Called Volt Typhoon "operational preparation of the battlefield" targeting US ports, rail, and aviation to disrupt military mobilization0:28:29; offered four recommendations including securing military-mobility infrastructure, prioritizing critical assets, using the National Guard, and passing the Cyber PIVOTT Act0:30:30; estimated China has ~60,000 people in its cyber force versus 6,400 in the US Cyber Mission Force1:14:03.

Brandon Wales, SentinelOne0:33:07: Said China's hacking program is now larger than every other major nation combined per the FBI0:34:39, and that Chinese actors compromised Microsoft signing keys granting access to Exchange Online email0:34:39; confirmed there is no evidence the 2020 election was stolen1:24:38; said CISA spends less than $2 million (under 1% of its ~$3 billion budget) on mis/disinformation work1:35:15.

Kemba Walden, Paladin Global Institute0:38:13: Urged reauthorizing the Cybersecurity Information Sharing Act of 2015 before its September expiration0:40:45, codifying the Cyber Safety Review Board0:41:47, and clarified she directed the Ransomware Task Force at Microsoft's Digital Crimes Unit, not the whole unit2:04:31.

Rep. Andrew Garbarino (R-NY)1:38:46: Asked what additional authorities CISA needs and about the federal thread-hunting executive order1:41:17; probed information-sharing gaps between private and public sectors1:43:18.

Rep. Eric Swalwell (D-CA)1:00:57: Cited disaster-cost figures across multiple states and asked Montgomery about reforming the Joint Cyber Defense Collaborative (JCDC)1:04:29.

Rep. Clay Higgins (R-LA)1:06:00: Discussed his regulatory-harmonization bill (streamlining federal cybersecurity regulation) with Walden1:07:00; asked Meyers about industry's ability to "strike back" against attackers1:11:02.

Rep. Seth Magaziner (D-RI)1:12:33: Cited the Brain Cipher Group's attack on Rhode Island and the Justice Department's seizure of 41 Kalisto Group domains1:13:03; asked how many people China devotes to cyber warfare1:13:33.

Rep. Carlos Gimenez (R-FL)1:18:05: Asked about AI's role in cyber defense and the $500 billion "Stargate" AI investment1:19:36; asked about US "rebound" (retaliatory) capability2:09:34.

Rep. Dan Goldman (D-NY)1:23:38: Pressed Wales on the 2020 election being free and fair1:24:38 and highlighted the CrowdStrike outage's effect on his district alongside proposed CISA budget cuts1:26:09.

Rep. August Pfluger (R-TX)1:29:12: Asked who is the lead agency for cyber incident response and pressed for CISA to be designated the lead1:29:421:31:43; asked about "what keeps you up at night" threats1:32:43.

Rep. Delia Ramirez (D-IL)1:34:14: Confirmed with Wales that CISA spends under 1% of its budget on disinformation work1:35:45; asked witnesses to support reauthorizing the State and Local Cybersecurity Grant Program1:36:15.

Rep. Dale Strong (R-AL)2:10:35: Described a Madison County ransomware attack he oversaw as county commission chairman2:11:05; asked about a "cyber axis of evil"2:12:37.

Rep. Mark Green [second recognition as chairman self] — (already listed above).

Rep. Mark Harris/Rep. from Tennessee [unidentified by name in transcript, referred to via chair] — not separately named; omitted per name guard.

Rep. from Tennessee (self-identified opening on Israel cooperation)2:15:40: Asked Montgomery about US-Israel cyber cooperation against Iran2:15:40 and Wales about the Treasury/BeyondTrust (Silk Typhoon-related) intrusion2:18:14.

Rep. Josh Brecheen (R-OK)2:20:15: Proposed using constitutional "letters of marque and reprisal" to let private cyber firms "hack back" against foreign attackers2:21:16, drawing pushback from Montgomery, who favored building a dedicated military cyber force instead2:22:47.

Rep. Clay Higgins [return, on rural healthcare] — see above2:00:29 regarding a nursing home ransomware case and coordination conflicts between CISA and the FBI.

Rep. Nellie Pou (D-NJ)1:44:49: Asked all four witnesses whether the Cybersecurity Information Sharing Act of 2015 should be reauthorized; all answered yes1:46:21.

Rep. Marjorie Taylor Greene (R-GA)1:48:53: Cited a $9.36 million average US data-breach cost and $12.5 billion in 2023 FBI-reported cyber crime losses, a 20% increase over 20221:49:53; asked about AI's dual-use role1:52:55.

Rep. Troy Nehls (R-TX)? — not confirmed by name in transcript; described as "Mr. Turner from Texas" per transcript2:15:10: Asked Wales about the adequacy of Treasury's cybersecurity posture after the Silk Typhoon-linked intrusion2:18:14.

Rep. from Texas ("Mr. Latrell")2:00:29: Described a nursing home ransomware attack and jurisdictional conflict between CISA and FBI response teams2:00:29; asked Walden about combating domestic bad actors including sex trafficking networks2:03:30.

Rep. from New Jersey ("Miss Mciver")2:06:02: Asked how Congress can help local governments and private-sector stakeholders in districts with ports and energy facilities2:06:32.

Key moments

Wales testified that China's hacking program is now larger than every other major nation's combined, according to the FBI, and that Chinese actors compromised Microsoft's signing keys, giving access to nearly anyone's email on Microsoft Exchange Online0:34:39.

Montgomery said Chinese President Xi has instructed the PLA to be ready to militarily retake Taiwan by 2027, leaving the US roughly two years to prepare0:37:43.

Montgomery estimated China fields about 60,000 people in cyber operations versus the US's 6,400-person Cyber Mission Force — roughly a 10-to-1 gap1:14:03.

Wales confirmed under oath there is no evidence the 2020 election was stolen, addressing former CISA director Chris Krebs's statement and firing1:24:38.

Wales and Ramirez established that CISA spends less than $2 million — under 1% of its roughly $3 billion budget — on mis/disinformation work, despite over 100 House Republicans voting to cut CISA's budget 25%1:35:151:35:45.

Meyers said cyber intrusions increased 150% across all sectors compared to 2023, with financial services, media, manufacturing, and industrials/engineering seeing 200–300% increases0:23:28.

Rep. Brecheen proposed reviving constitutional "letters of marque and reprisal" to let private firms hack back against attackers; Montgomery pushed back, preferring a dedicated military cyber force over private actors2:21:162:22:47.

Rep. Higgins described a small-town nursing home ransomware incident where CISA and the FBI clashed over who was in charge, delaying resolution; Montgomery said unity of command is essential and CISA should be the designated lead2:00:292:01:30.

Chairman Green noted the US has no declared cyber retaliation strategy comparable to its chemical- or nuclear-response doctrines, and urged the new administration to establish one2:39:57.

Rep. Green (self-questioning) and Meyers discussed China's 2018 nationalization of vulnerability research, requiring all Chinese vulnerability findings to be submitted to the government rather than disclosed to vendors0:46:19.

Metadata

CommitteeHouse Homeland Security
Chamber / CongressHouse · 119th Congress
Date2025-01-22
TypeHearing
Witnesses
Mr. Brandon Wales — Vice President of Cybersecurity Strategy, SentinelOne
Mr. Adam Meyers — Senior Vice President of Counter Adversary Operations, CrowdStrike
Rear Admiral Upper Half Mark Montgomery — Senior Director of the Center on Cyber and Technology Innovation, Foundation for Defense of Democracies
Ms. Kemba Walden — Private Citizen
Videoyoutube
Transcript308 caption blocks · 24,888 words · 2:41:51 runtime
EventCongress.gov 117770