▶ 0:09:22Committee on Homeland Security Subcommittee on Cyber Security and Infrastructure Protection will come to order. Without objection, the chair may declare committee in recess at any point. Purpose of this hearing is to examine the state and local cyber security grant program, which is up for reauthorization this year. Since Congress signed the program into law four years ago, nearly 1 billion has been allocated to bolster the cyber security postures of state and local governments. Today, we will assess the program strengths and weaknesses and we consider as we consider next steps. I now recognize myself for an opening statement.
▶ 0:09:52The threat of cyber attacks to US networks and critical infrastructure is real and rising. Microsoft's 2024 digital defense report estimates that it customers are targeted with more than 600 million attacks per day from nation states and criminal actors. For years, the intelligence community has warned of the threat of state sponsored cyber actors engaging in malicious activities against our critical infrastructure. As we've seen, these warnings have become a reality.
▶ 0:10:18With the persistent threat that groups like ty the typhoons pose to IT and OT assets, any critical infrastructure sector could be the next to fall victim to attacks or have its data seized through fishing through a fishing scheme. As cyber actors become increasingly sophisticated and persistent, we can no longer be complacent when it comes to securing our critical infrastructure. We must take all steps necessary to ensure our nation's cyber preparedness and resilience.
▶ 0:10:43In doing so, it is essential that our state and local government partners are similarly well situated to respond to these threats. Despite often lacking resources and qualified talent for cyber security, state and local governments host the key pieces of critical infrastructure that keep our economy running. If left unprotected, this presents a huge vulnerability. To help state and local governments improve their cyber security postures postures, Congress passed the state and local cyber security grant program in 2021.
▶ 0:11:13Since this program began, $838 million has been allocated to address cyber security risks and threats to information systems owned and operated by or on behalf of state, local, and territorial governments. The state and local cyber security grant program is set to expire this September, at which point the program will not continue to receive federal funding unless reauthorized by Congress. As we have heard from many stakeholders, this program has undoubtedly improved and sometimes even established the cyber security posture for our states and localities.
▶ 0:11:42I am encouraged by the progress and applaud the efforts of our state and local governments to seize this opportunity to prioritize cyber security. With that said, we know the program does not come without its challenges. As we consider reauthorization, we want to understand any administrative burdens or barriers to ensure state, local, and territorial governments can focus on cyber resilience and preparedness.
▶ 0:12:04To that end, it is also Congress's responsibility to evaluate whether the state and local cyber security grant program is the most efficient and effective means of strengthening cyber security posture of state, local, and territorial governments. I'm here with an open mind and a vested interest in understanding how the program is working. Cyber security is a whole of the society challenge, meaning federal government must continue to support and strengthen cyber security at the state and local levels to protect our nation's networks and critical infrastructure.
▶ 0:12:32State and local governments must also continue to share information with each other. They play an important role in disseminating best practices which could greatly benefit organizations with less mature cyber security programs. I want to thank our witnesses who have all had firsthand experience with the state and local cyber security grant program for being here today. I look forward to hearing your perspectives on the program and working with you to strengthen our collective defense against cyber threats. I now recognize the ranking member, the gentleman from California, Mr. Swallwell, for his opening statement.
▶ 0:13:02Morning and thank you to Chairman Garberino for holding uh this subcommittee hearing on state and local cyber security grant programs. Also want to thank our witnesses for their participation. A nice blend of private sector and public sector witnesses that we have today. This program was established four years ago as the product of a bipartisan agreement from this committee.
▶ 0:13:28And as we consider further authorization, it's important to remember that cyber attacks hit Republican districts and Democratic districts. They're in blue states and red states. They're in urban areas, suburban areas, and rural areas. In my district, the 14th district of California in the Bay Area, the city of Hayward suffered a ransomware attack in the summer of 2023 that shut down the city's computer networks for more than 2 weeks.
▶ 0:13:56And just two months ago, Hayward began notifying individuals that personally identifiable information, including social security numbers and sensitive medical information, had been breached as a part of the ransomware incident. I know this story is not unusual and I'm sure my colleagues have also heard from local governments impacted by cyber attacks and looking for help. With cyber attacks coming from criminal gangs and nation state adversaries, we cannot leave our state and local governments to fend for themselves.
▶ 0:14:24Federal support for state and local governments is necessary to address the national security threat and the state and local cyber security grant program has always reflected that understanding. By providing $1 billion to state, local, tribal, and territorial governments, Congress took a major step in strengthening our country's cyber defenses. For example, with a 250,000 grant from this program, a water utility can expand real-time monitoring to better detect and respond to cyber incidents.
▶ 0:14:55Finally addressing a long-standing resourcing challenge in the water sector that we've heard about on this subcommittee for years. When the state and local cyber security grant program was created, our primary concern was the ransomware epidemic that was plaguing our communities. That threat remains, but China's campaign to preposition on our critical infrastructure for potential future destructive attacks is even more alarming.
▶ 0:15:19While much of our critical infrastructure is privately defended, some of our most vital services are provided by the public sector. Publicly owned and operated water and electric utilities, transportation systems, and emergency services could all be targets in destructive attacks by China or other adversaries.
▶ 0:15:38Reauthorizing the cyber security grant program is necessary to ensure we do not take our foot off the gas at this critical time and passing a re reauthorization bill before this program expires in September is one of my top priorities on the committee. What I've heard from stakeholders is an appreciation for the tremendous value of this program, and we'll hear that today from our witnesses.
▶ 0:16:01But they also have a desire for sustained, predictable, and consistent funding levels that will allow state and local governments to build on their progress and budget and plan their futures. The program operates under a partnership between FEMA and SISA, two important agencies that unfortunately have come under attack in recent months.
▶ 0:16:21By leveraging FEMA's grants, administration expertise, and CIS's cyber security expertise, this program has been able to deliver for state and local governments in ways that would be impossible without that partnership. Trump administration plans to eliminate FEMA and further cut SIS's workforce would devastate Homeland Security's ability to support state and local governments across a range of threats, including cyber attacks.
▶ 0:16:46The cyber security grant program demonstrates the value of collaboration between DHS components, DHS's components, and I hope we can work in a bipartisan way to further educate Secretary Gnome about the tremendous value these agencies provide the American public. I'm also concerned by reports that FEMA has been pausing distributions of funding to implement cyber grants along with other programs. China is not pausing. They continue their efforts to target our critical infrastructure and we cannot pause either.
▶ 0:17:16The Trump administration must release cyber grant funds to states, territories, and tribes and comply with court orders against any illegal pauses. Again, I want to thank the chairman for holding this uh hearing uh the witnesses for their participation and look forward to expertise from both public and private sector uh as we look to reauthorize this important program. Thank you, chairman. I yield back. Gentlemen yields back. Other members of the committee are reminded that opening statements may be submitted for the record. I'm pleased to have a distinguished panel of witnesses before us today.
▶ 0:17:46I ask that our witnesses please rise and raise their right hand. Do you solemnly swear that the testimony you will give before the Committee on Homeland Security of the United States House of Representatives will be the truth, the whole truth, and nothing but the truth. So help you God. Let the record reflect that the witnesses have answered in the affirmative. Thank you. And uh please be I would now like to formally introduce our witnesses. Mr. Robert Huber currently serves as the chief security officer at Tennibal.
▶ 0:18:15He oversees the organization's global security and research teams to reduce security risks to the company, its customers, and industry. Prior to his pri prior to his private sector career, Mr. Uber um served in the US Air Force and Air National Guard for 22 years. Mr. Alan Fuller serves as the chief information officer for the state of Utah. In his role, he oversees all IT functions for state executive branch agencies aiming to improve innovation and government services through technology.
▶ 0:18:43He also serves as the secretary and treasur of the National Association of State Chief Information Officers. The Honorable Kevin Kramer is the first vice president of the National League of Cities where he leads efforts of city, town, and village leaders to improve the quality of life for their residents. Additionally, Mr. Kramer serves as a councilman for Louisville, Kentucky, where he's the chair for the minority caucus, vice chair of budget committee, and member of the government oversight audit appointments committee. Mr.
▶ 0:19:08Mark Raymond is chief information officer for the state of Connecticut, where he oversees the Department of Administrative Services, Bureau of Information Technology Solutions, and holds an operation and holds operational responsibilities for the state's technology infrastructure. Prior to his public service career, Mr. Raymond spent 21 years in technology consulting industry where he supported federal, state, and local clients. I thank the witnesses for being here today. I now recognize Mr. Huber for five minutes to summarize his opening statement.
▶ 0:19:35Chairman Garbrino, Rank Swall, members of the subcommittee. Thank you for the opportunity to testify today and for convening this important hearing. I'm Bob Juber, chief security officer, head of research and of public sector at Teneal, a cyber security exposure management company. Tennal serves 44,000 customers worldwide including the federal government as well as state, local, tribal and territorial governments and critical infrastructure operators.
▶ 0:20:01State and local governments play a crucial role in managing and protecting critical infrastructure such as water treatment facilities, energy grids, transportation networks. They are on the front lines of defending these systems from cyber attacks that could disrupt vital services, erode public confidence, and compromise national security. Protecting essential systems is more urgent than ever. In 2023, the China backed cyber espionage group Vault Typhoon, known for targeting critical infrastructure, attacked a Massachusetts utility.
▶ 0:20:31While disruptions were avoided, the incident showed the growing sophistication of adversaries who could position themselves to perpetrate future attacks on critical infrastructure. In addition, ransomware attacks doubled between 2018 and 2024, causing over1 $1 billion in operational downtime for state and local governments.
▶ 0:20:50These threats highlight the need for robust cyber security measures and coordinated efforts among all levels of government and the private sector to detect, mitigate, and recover from these cyber threats. The state local cyber security grant program or SLCGP is a vital tool in addressing these challenges. providing 1 billion over four years to help state and local governments address cyber security risks.
▶ 0:21:15To receive funds, states have to follow a structured process, including establishing a cyber security planning committee that includes state and local officials. Together, they must develop a state cyber security plan that incorporates baseline requirements and alignment with cyber security best practices and international standards. States created different SLCGP programs. Some provided competitive grants where local governments could apply for funding for cyber security projects.
▶ 0:21:43Others provide shared services to local governments such as multiffactor authentication, vulnerability management, or endpoint detection services. States like Connecticut, Utah, and Virginia are successful use cases of the SLCGP program.
▶ 0:21:57Virginia's whole state approach focuses on collaboration, enterprise level visibility, and efficient resource Virginia provided free cyber security plan capability assessments to local entities who could then apply for funding to address identified gaps through a streamlined application process. 80% of eligible localities applied for the funding, highlighting the need for assistance. Balanced central oversight with decentralized execution enabled Virginia to increase its overall cyber security resilience.
▶ 0:22:28SLCGP objectives include continuous monitoring, asset inventory, and vulnerability prioritization, which are all essential components of the exposure management approach. Exposure management shifts organizations from a reactive approach to proactive risk informed strategies across modern attack surfaces such as operational technology, internet of things, as well as cloud configurations. This proactive approach helps state and local agencies anticipate and mitigate risk before they impact vital systems.
▶ 0:22:58SLCGP has significantly contributed to enhancing cyber security across state and local governments by providing essential funding, fostering collaboration, and encouraging strategic and proactive planning based on best practices. It has notably strengthened relationships between state and local officials through the cyber security planning committees and their collective development of the cyber security plans to continue and to build on SLCGP success. Tenable recommends re Reauthorizing the program with the following improvements.
▶ 0:23:29Ensure sustainable funding by extending the program's duration and enable long-term planning. Maintaining alignment with recognized standards and frameworks such as the NIST cyber security framework. Reducing the administrative burdens and providing clear guidance through simplified applications and lowering and le leveling cost share requirements for effective planning.
▶ 0:23:54continuing to encourage whole of state and proactive exposure management strategies and engaging the private sector and stakeholders to address evolving threats and best practices. Continued success of the SLCGP program also depends on having qualified cyber security professionals at all levels to manage it. Tenable supports enactment the enactment of the cyber pivot act to address workforce shortages to reskill workers and create diverse pathways into government cyber security careers.
▶ 0:24:24Thank you again for your attention to cyber security, continued support of the SLCGP, and for the opportunity to testify. I look forward to working with you to secure our nation's cyber assets, and I'm happy to answer your questions. Thank you. Thank you, Mr. Uber. I now recognize Mr. Fuller for five minutes to summarize his opening statement. Thank you, Chairman Gabino, Garberino, Ranking Member Swallwell, and members of the subcommittee. It's a pleasure to be with you today.
▶ 0:24:48I'm Alan Fuller, chief information officer for the state of Utah, a role to which I was appointed by Governor Cox in March of 2021 and a CIO for the state. I lead the division of technology services, which is the consolidated IT organization for all of the executive branch agencies of the state. As part of my team, I oversee the cyber center, which is responsible for defending state IT systems against cyber crime. I'm also the secretary treasurer for the National Association of State Chief Information Officers, or NASISO.
▶ 0:25:15Nasio is a national leader and advocate for technology policy at all levels of government and has championed substantial collaboration between states and the federal government to improve cyber security preparedness and protect our nation's critical infrastructure.
▶ 0:25:28So as both CIO for the state of Utah and as a NASO officer, I hope to highlight the many successes of the state and local cyber security grow program or SLCGP This program has provided significant support to states and to local governments as we have worked together to improve our cyber security posture and to address vulnerabilities. Over the past decade in Utah, state, county, city governments have witnessed significant escalations in cyber incidents. Initially, attacks were less frequent and less sophisticated, often targeting basic vulnerabilities.
▶ 0:25:59However, recent years have seen a surge in complex ransomware attacks, data breaches, and fishing campaigns specifically designed to exploit government systems. This evolution reflects a broader trend where malicious actors increasingly target public sector entities seeking to disrupt services, extort funds, and to compromise sensitive data. Local governments in particular face challenges in keeping pace with these threats due to budget constraints and limited cyber security expertise, making them more susceptible to these evolving cyber risks.
▶ 0:26:29In Utah, we applied for SLCGP funds in 2022 and received approximately $13 million of federal funds and $4 million in matching state funds for local cyber security efforts. Assessments and audits were conducted to identify the strength of cyber security defenses around the state, including cities, counties, and higher education entities. Results found that cyber security systems were significantly underdeveloped in many cases, leaving local government entities with serious risks.
▶ 0:26:56Note that many of these cities and counties have limited resources with very little or no IT support. The SLCGP is being utilized to address those concerns by providing muchneeded tools to local entities. With funding secured through the SLCGP and corresponding state appropriations, a comprehensive cyber security initiative has been deployed across 140 governmental entities in the state. These include 23 counties, 94 municipalities, and 23 special districts.
▶ 0:27:22Through this effort, endpoint security has been provisioned for over 26,000 devices and cyber security awareness training is being delivered to 31,000 local government employees. The program includes scheduled engagements with local leaders to guide the progression of statewide cyber security initiatives. The results have been extremely positive. We have blocked seven major cyber attack incidents in the last six months alone. I will speak to two of these.
▶ 0:27:47Shortly before Christmas, the CIO of a local airport urgently contacted me about a cyber attack in progress. Cyber criminals attempted to deploy ransomware on the airport's IT systems, which would have been disastrous, especially during the busy holiday travel season. Our cyber center team immediately worked with the airport's IT team to address the issue. Fortunately, SLCGP funds have provided security tools were able to detect and interrupt the attack as it was happening. The common tooling and established relationships with local staff enabled a rapid response that limited the impact of the attack.
▶ 0:28:18As a result, the airport service was not interrupted and no ransom was paid. Second, recently a 911 emergency dispatch center in Utah was the victim of ransomware attack on systems that provide 911 services. Again, SLCGP funds have provided security tools that detected and interrupted the attack as was happening. Common tooling and established relationships enabled a rapid response that limited the attack's impact. Critical 911 dispatch services were able to continue in one of our biggest counties. Utah's positive experience with this grant program is not an outlier.
▶ 0:28:48SLCGP has allowed many states to embrace a whole of state approach to cyber security. By approaching cyber security jointly, information is widely shared and incident response is more effective. States have been able to use SLCGP to provide a vital technology services that many smaller communities simply would not otherwise be able to implement. The state and local cyber security grant program helps stakeholders develop a solid foundation on which to continue to strengthen their defenses and to modernize both their technology and their processes. I encourage the subcommittee to extend funding for the program.
▶ 0:29:19I look forward to discussing discussing it today and to answering your questions. Thank you very much. Thank you, Mr. Fuller. I now recognize Mr. Kramer for five minutes to summarize his opening statement. Good morning, Chairman Garbino, Ranking Member Swallwell, and members of the subcommittee. Thank you for the opportunity to testify today. I am Councilman Kevin Kramer from Louisville Metro Government in Kentucky and I serve as the first vice president of the National League of Cities.
▶ 0:29:45I'm honored to speak on behalf of both Mass City and the 19,000 cities, towns, and villages represented by the National League of Cities. NLC is committed to strengthening the federal local partnership that supports our communities. Prior to my current role, I chaired NLC's information technology and communications committee. I also work as a teacher at a small girl all girls high school.
▶ 0:30:10I appreciate this subcommittee's focus on reauthorizing the state and local cyber security grant program and I'm here to share both our local experience in Louisville and broader perspectives from cities across the Local governments are frequent targets of cyber attacks from both criminal organizations and nation state actors. We are responsible for sensitive data, public payment systems and critical infrastructure.
▶ 0:30:40When city networks are attacked, emergency services may be disrupted, personal data can be exposed, and entire communities can be impacted. Recovering from these incidents often costs hundreds of thousands of dollars and hundreds of work hours. As the committee has noted in previous hearings, local governments face serious constraints. This is especially true of small and rural communities.
▶ 0:31:09Of the 19,000 municipalities nationwide, over 16,000 have populations under 10,000 people. Many have no dedicated IT staff at all. Even larger cities often struggle to hire and retain qualified cyber security professionals. Yet smaller size does not equal lower risk. Every community is vulnerable.
▶ 0:31:34Louisville Metro government has received funding through the state and local cyber security grant program for two fiscal years. The most recent grant helped support the creation of the Kentucky Cyber Threat Intelligence Cooperative or KCTIC. This is a new platform for sharing timely, actionable cyber threat information among regional governments and private sector partners.
▶ 0:32:01We built it to address delays in the existing systems for threat reporting and communication. KCTIC allows anonymous threat data from cooperative members to be shared in near time. This grassroots multis- sector effort strengthens the entire region's cyber resilience, not just Louisville's, and it wouldn't be possible without this program.
▶ 0:32:30The state and local cyber security grant program is a vital component of our national security It fosters state local collaboration, builds awareness among local leaders, and enables proactive planning. But for the program to reach its full potential, improvements are needed. First, the one-sizefits-all pass through model limits efficiency.
▶ 0:32:57Larger jurisdictions like Louisville are capable of managing direct federal grants and should be able to apply without going through the We urge Congress to create a complimentary direct funding track for eligible larger municipalities. Second, the application process must be more accessible. Small communities face major barriers. Tight deadlines, complex requirements, and limited staff capacity.
▶ 0:33:27These are often the very communities that would benefit the most. Simplifying the application process and extending timelines would make participation more realistic for them. We're also encouraged by emerging models like multi-jurisdictional grants managed by state municipal associations.
▶ 0:33:48These allow technical services to be delivered to many communities at once and approach far more efficient than requiring each town to stand up its own cyber security team. Just as most people take their cars to a qualified mechanic, small governments need trusted partners to handle complex cyber tasks. Above all, we ask Congress to reauthorize and fully fund this program with predictability and consistency.
▶ 0:34:18Without that, local governments are less likely to make the necessary investments in planning and assessment that lead to strong applications and long-term resilience. Cyber security is a whole of nation challenge. It demands a true intergovernmental partnership. The state and local cyber security grant program is a cornerstone of that partnership. Thank you again for the opportunity to testify. I look forward to your questions. Thank you, Mr. Kramer. I now recognize Mr. Raymond for five minutes to summarize his opening statement.
▶ 0:34:47Uh Chairman Garberino, Ranking Member Swallwell, and members of the subcommittee. I am Mark Raymond, chief information officer for the state of Connecticut. I'm responsible for all the technology of 39 executive branch agencies, including network and internet services for our K through2 schools, our libraries, our universities, and over twothirds of the state's municipal governments. I'm an active member of NASIO and the longest serving state CIO in the country.
▶ 0:35:17This history has given me direct involvement with the long advocacy for dedicated cyber security funding. The threats posed by criminal actors are numerous and unceasing. Each year, cyber attacks become more threatening and the risk posed to residents become more dire. State and local governments serve as stewards of a civil society. Working to ensure community stability, predictability, and the well-being of our residents.
▶ 0:35:46These public servants are the teachers in our classrooms, the police officers who respond to distress, the doctors and nurses that care for our neighbors suffering with addiction. They protect the water we drink, the food we eat, and much more. All of these services, however, rely heavily on technology and data. However, the fast growing cyber risks have found many jurisdictions unprepared.
▶ 0:36:15This program is a valuable resourcing in address in in addressing this need. Through this grant, Connecticut has expanded offerings to local governments. Equally as important is the spirit of trust that the grant has fostered between state and local governments. Cyber incident responders are collaborating before attacks take place instead of during them or after them.
▶ 0:36:40preventing attacks is far better than recovering from them. For the fiscal 22 grant year, we awarded close to $3 million uh with more than 2.1 million of that going directly to local governments. Awards for the FY23 program year expected to be over $7 million in total with 4.3 million to local governments. One of the benefits of the program has been a systemic assessment of local government risks.
▶ 0:37:11Connecticut partnered with our National Guard to evaluate cyber security risks using the NISK cyber security framework. Sadly, only 27.7% of our municipalities were assessed at low risk. These periodic assessments that are supported by this grant program ensure that the actions we take produce measurable risk responses.
▶ 0:37:36Those with high risks demonstrated a lack of v vulnerability scanning, multiffactor authentication, employee cyber security training, malware prevention tools, and incident response plans. This grant directly addresses those findings. 51 awards were made in Connecticut of which 19 addressed incident planning and government governance. 31 improved multiffactor authentication and ransomware protections.
▶ 0:38:07The last award also supported the cyber nutmeg which is a two-day exercise where all municipalities and critical infrastructure operators are invited to participate. This unique state level exercise raises awareness to the need to fill this gap. It exercises the incident plans that some are newly created and improves relationships that are needed when incidents occur.
▶ 0:38:35Unfortunately, these grant program funds for FY22 covered less than half of the requested need. We plan to address this growing gap with the remaining granty year funding. Though much has already been accomplished under uh SLCGP, more can be done and here are a few of our suggestions. Uh first is that ongoing dedicated funding for cyber security would be important.
▶ 0:39:00Many local governments are reluctant to start a cyber security program without ongoing funding to support it. Standardizing the matching percentage across all of the grant years would also simp sign significantly simplify grants administration. And fi finally making shared services a default position for states and local government to reduce the administrative burden required for each locality to sign on to the shared solution.
▶ 0:39:31This would reduce costs and improve statewide efficiency. We strongly believe that it is better to continue to improve this program rather than to allow it to expire. The grant improves our nation's cyber security defenses as state and local governments take on additional responsibilities for cyber security. Supplemental funds will help meet this increased burden. Thank you for your time today and I look forward to answering what questions you may have. Thank you very much, Mr. Raymond.
▶ 0:39:59I your point about preventing is better than recovering. You know, I had a c our county got hit. They were down for almost a year. Um, so, uh, I'm so it's very important that you're all here today and this getting this reauthorized and fixed, I think, is a very important, uh, goal that we all have and I'm I'm really happy that we have members here to ask questions. Uh, we're going to start with each members go from Republican to Democrat. Five minutes of questioning each. Uh, an additional round of questioning may be called after all members have been recognized.
▶ 0:40:28I now recognize the gentleman from Texas, Mr. Latrell, for five minutes. Thank you, Mr. Chairman. Mr. Raymond, when it comes to to local governments and their awareness of the grant programs and where they live and breathe or where they exist, how does that work? Does the government itself reach down into these local governments? And if which ones are we touching? Are we touching all of them? Uh thank you for the question, Representative. They're all invited to the discussion.
▶ 0:40:52We have formed regional subcommittees uh that include representatives from state, local, uh school districts. When you say regional subcommittees, can you elaborate on that please? Yeah, Connecticut is divided into five uh administrative regions. So we do not have county government in Connecticut. So it's just the state and then 169 municipalities. So we have organized our emergency response into five districts.
▶ 0:41:21And so each one of those emergency management and cyber security groups have their own planning committee uh that is all of the chief executives and emergency management and cyber security professionals in that group are invited to the table in those discussions. So it makes it easier for the state to understand what exactly is happening in cyber security when it comes to the grant profile. Yes, sir. That Mr. Kramer, you got something to add to Louisville is the largest city in the state of Kentucky. Um we do have counties in the Commonwealth.
▶ 0:41:50Um, and the grant that we are currently using came directly to uh, metro government in Louisville and is every county aware of the grant the grant system itself and how and how they can grab a hold of that? Uh there those that are members of NATO, the National Association of Counties are well aware because NATO is pushing this out as an issue that um that they should be very much interested in in working with um in Louisville.
▶ 0:42:21It's not just Louisville that's that's taking advantage of the grant though. We're the largest city in the state. We're also very near being on the river, very near Indiana. Um we are working across the entire region. Um we've reached out to the universities, both the University of Kentucky and the University of Louisville. We're working with the National Guard. Um, and so it's a it's a program that goes beyond just what we're doing in Louisville. It it captures a good part of our state. Mr. excuse me. Yes.
▶ 0:42:49Uh, so in the state of Utah, what we're doing is uh tools, the city of Utah, state of Utah. Ah, okay. Tools, training, and uh relationship building. And so, uh, we're we're over 75% coverage with all the cities and counties, and we hope to get that closer to 100% as we go. The entire state is aware of this. Oh, yeah. That's that's remarkable. Mr. Mr. Hubber, I I have no comment. That's outside my expertise. I rely on these gentlemen. I'm a vendor.
▶ 0:43:21Welcome to the committee, sir. when it comes to state and so the relationship between state and local government and the are you would you say that the return on the investment from these grant programs are beneficial and Mr. I'll start with you Mr. because you said that you did not utilize all the assets that were funded. I missed the year. We had double the requests than we were able to fund. So we did not have any excess funds.
▶ 0:43:49We had double the requests in the first year of the grant program and we expect that to continue. So uh I I think that does demonstrate both the awareness that we have in across the state especially for our municipalities and uh upwards uh you know we had we took very little funding at the state level.
▶ 0:44:10There is a division between what you can take at the state level and what what is and almost all of the funds went to uh local governments but absolutely necessary because this committee is trying to maintain its footing when it comes to grant programs for cyber security, cyber risk, cyber threat. We need to hear from those on the other side to say yes this is an absolute need because in my personal opinion this is the next phase of evolution when it comes to warfare. So, and protecting our citizens is absolute.
▶ 0:44:40And as the the metaverse is pulling pulling or cutting or freezing grant programs currently, I would hate to see this happen in such an important space. Yeah, Mr. Kramer, did I go to you? If not, Mr. F. Thank you. Um, I would argue that yes, it is uh essential. We in in Louisville, um, we hired two people to do the work. We were hoping for four.
▶ 0:45:05um the work that needs to be done is broader than the work we're able to accomplish under the current um program. So absolutely uh want to see this go forward. The plan is to reach out again to the major universities in town um and then ultimately to filter down even to the public school systems.
▶ 0:45:23Um it's amazing how much data uh is held in the school systems and how much that data is compromised and and as everyone knows you know the bad actors are looking for the easy access and so we're doing our best to reach down to the to the level where we can improve security at that lowest level. Mr. Chairman I yield back. Thank you. Gentleman yields back. I now recognize the ranking member Mr. Swallow from California for five minutes of question. Great. Thank you.
▶ 0:45:52Uh, Council Member Kramer of Louisville, you have one of the most important jobs here. You are protecting the nation's bourbon supply. So, uh, thank you. I know our chairman, uh, and many of my colleagues, thank you.
▶ 0:46:07Um but you did in all seriousness mention a weakness of the program as it exists right now which is it doesn't have much agility or I would maybe you said like bandwidth to understand like the differences between sizes of cities like how would you structure a future reauthorization to better reflect that and better target where the need is? Thank you for that question. Um I really appreciate that.
▶ 0:46:36Um I think the first bit of the answer is we need to recognize that the larger cities like Louisville for example um we do have the resources. Um we have a person on staff who his primary responsibility is cyber security. Um but we're a half an hour drive from Elizabeth Town. Uh there was a movie made about that place. Um it's fairly small town out in middle Bourbon country.
▶ 0:47:02um and they don't have the resources to do this, but we do have a very active state league of cities, a municipal, an organization of municipalities. Um, allowing the grant to go through them instead of through the state would assure that that money actually made its way to local governments.
▶ 0:47:20And it would also allow the municipal the the state league um to to work together with those other cities and hire a person that would be able to work with all of them and not just with one city like our own. And again, it reaches into the school systems. There are some school systems in the state of Kentucky um that the highest paid positions in in the county are in the school system. Um and I I I just want to drill home that's a that's an area that I think folks overlook.
▶ 0:47:50Um there's a lot of data that's handled there and we need to do the best we can to reach out to that community as well. Absolutely. And uh Mr. Raymond, could I ask, you know, as somebody who has administered millions of dollars of these grants to many uh jurisdictions, municipalities, agencies? What are some of the weaknesses that you've seen among some of the recipients?
▶ 0:48:19Like if you had a new trunch or a new uh reauthorization, like what have you learned from this that makes a candidate more eligible or makes a candidate least eligible as you're thinking about where these funds should go? Well, I admittedly the the program did have a slow start, right?
▶ 0:48:42And and I think any kind of new grant program, the clarity around getting people to understand what it is to be uh eligible uh and and what people really needed within their environment was probably the most difficult challenge for us.
▶ 0:48:58And and again the the assessment the cyber security assessments that were part of the first year were absolutely critical for building for all of our municipalities an understanding of what their risks were and how we would address it. Uh you know I think it goes to the earlier question of did they know when we have these assessments they now know.
▶ 0:49:22And so I I I would say that continuing that to demonstrate the improvements would be absolutely critical uh for additional funding. I I do think that the I understand the desire to in the construct of the program to have um to wean states off the program with the declining match or the increasing state match.
▶ 0:49:48Um, however, that that that's complicated with the change in the funding as well. I think it having a stable match over the life of the program makes it far easier to administer as people are working across the different grant years. Uh, should the desire be to still shift some of that burden back to the states that through funding, you can do that through the overall funding of the program and not the mix of the two.
▶ 0:50:16And and I think that um you know we had a lot of people applying for the first year at a 90% reimbursement rate and then you know we're looking at will will we get that same kind of participation as the rates fall and uh local government's budgets remain tight. Thanks. Yield back. Gentleman yields back. I now recognize the gentleman from Tennessee, Mr. Ogles for five minutes of questions. Thank you, Mr. Chairman. um to the witnesses.
▶ 0:50:44I believe strongly in federalism, fiscal responsibility, and the importance of empowering local communities and not expanding the bureaucracies of quite frankly the federal government. As we assess the state and local cyber security grant program, we need to ensure that our limit limited federal resources are being used effectively and are actually reaching the communities most at risk. And I say that in the context of being a former county executive and Tennessee serves as the CEO of the county.
▶ 0:51:10And so I can attest to the fact that uh some of these pass through grants administered by the states were incredibly important to my county which was a rural county. Um emergency services, fire and cyber were all my departments.
▶ 0:51:22And so again, and I get your your perspective on the stable match because again, as a rural county where we have limited funding mechanisms and quite frankly, an ever growing school system there there's a there's a friction there of how do you fund this uh these mechanisms which as my my colleague stated, the future of warfare is on this the cyber battlefield. But u that being said, Mr.
▶ 0:51:45Huber, you've worked to secure systems against the threat from Vault Typhoon, a CCPbacked group of hackers who both have sophisticated abilities and specialize in targeting the most vulnerable points in its target systems. In your testimony, you mentioned their attack on Littleton Electric Light and Water Department in Massachusetts. My district and across the country, we have diverse range of electric providers, large corporations, rural providers as I mentioned.
▶ 0:52:10uh in your experience, how strong is the awareness of cyber threats among smaller, less resource organizations that provide critical infrastructure? And again, I go back to Tennessee, but probably much like rural Kentucky where we have a patchwork of these smaller communities where we're scrapping for resources to figure out how do we, you know, quite quite frankly protect not only our infrastructure but our citizens. Sir, yeah, thank you for the question.
▶ 0:52:34So, I've uh had the the pleasure of working with municipalities that the IT person was the IT person and the database administrator and the system administrator and responsible for security as part-time job. So, as you might imagine, any administrative burden that might be involved in applying for the grant would be significant for an entity such as that uh smaller size. But make no mistake, those smaller rural entities that could be the high jurisdiction that fuels a larger municipality. That's a national security and an economic impact to the region.
▶ 0:53:02So as we heard from uh gentleman here, education and awareness is key to educating those folks who have probably dual roles or multi hat roles for protecting that piece of crit critical infrastructure from nation state attackers. As someone who's been in in the trenches and a national guard member in title 32 and state active duty supporting state critical infrastructure components, uh there's significant shortage of resources and knowledge about nation state level attackers.
▶ 0:53:31So, I think it's important to recognize that uh this funding is key in raising the bar of foundational cyber controls for all of those entities. And and I want to focus primarily with with the other three witnesses uh on on rural communities. And one of my concerns, again, my background coming from a rural community is that competition that you see between say a Nashville and and my community. and but yet from an assessment standpoint, I would argue some of your rural communities are your most vulnerable points of entry.
▶ 0:54:02So, how do we make sure that we're prioritizing basically not and take size out of it for a moment, but a needs assessment understanding that again uh whether it's uh distribution of broadband, whether it's uh protecting points of entry, etc. Mr. Fuller, thank you very much. So, let me just say I really appreciate your comment that these attacks are very much like war and uh this committee does knows very well that we live in a very very dangerous world. Uh that we're constantly under attack including our smallest and most rural communities.
▶ 0:54:32So, with the program that we rolled out, we rolled out tools uh to all of our communities including the rural communities and for the most rural who don't even have sufficient IT resources, we're able to make resources available to help them install those tools. And then we're also able to provide training for those people. So we are absolutely committed to getting this uh program to our small cities and counties and special districts. Mr. Kramer, thank you. Again, it's a great question.
▶ 0:55:00Um I think one of the things that we need to recognize it's it's a matter of how quickly we share that information as um when a when a cyber attack happens, what they're trying to do in one place, one community is likely happening somewhere else. And again, I think the smaller communities, the rural communities where um you know, my colleagues have testified that you've got a person who has three different jobs. Um if they aren't aware of what to look for, uh it makes it much more difficult.
▶ 0:55:30They often don't find out until it's too late. So, one of the things we're hoping we can get the federal government to do is recognize that they collect up a lot of this data about cyber attacks, but they collect it up and hold it. Um, it would be very useful to us at the local level if as soon as they knew about a cyber attack, they shared that information with entities as quickly as they could so that folks at the local level could start looking at their own systems and see if someone's trying to get in the same way. Yes, sir. And I'm out of time, but Mr. Raymond, a final thought.
▶ 0:56:00I I would just say that we view cyber security as a team sport. We view those that are better resourced in a good position to help those that aren't. Uh so we do have municipalities who help each other like larger ones helping smaller ones and smaller ones who are relying upon the state to to help deliver services. Uh we do run all of the network services. So, it provides a unique ability for us to provide specialized security services to everyone in our jurisdiction.
▶ 0:56:30Uh, which is one way to make the limited dollars we have go a lot further. Sir, thank you to the witness, Mr. Chairman. Apologies for going over. Oh, of course. Not a problem. Gentleman yields back. Uh, I now recognize the gentleman from Rhode Island, Mr. Magazer, for five minutes of questions. Thank you, chairman. Uh the state and local cyber security grant program is an essential resource to help states and municipalities protect themselves against cyber attacks.
▶ 0:56:55This grant program helps secure critical infrastructure like schools, hospitals, electric grids, water systems. And in my home state of Rhode Island, it has been instrumental uh in providing cyber security training, for example, for staff at state agencies and municipalities so they can better protect taxpayer data, securing schools and academic institutions from ransomware attacks, and protecting critical infrastructure from being infiltrated by hackers.
▶ 0:57:22Uh I am concerned by reports of potential delays and cuts to these grants by the Trump and Musk administration and I'm glad to see that at least on this subcommittee there appears to be bipartisan support for continuing the program uh in a robust form.
▶ 0:57:38Uh but you would forgive us for being concerned uh because in addition to the reports of delays uh we have heard uh that the Trump and Musk administration has been firing staff uh at SISA and at FEMA, the two agencies responsible for administering this program. And we have also heard from Secretary Gnome herself that she plans to quote eliminate FEMA and significantly shrink SISA. She said that in her Senate confirmation hearing.
▶ 0:58:07This would be a tremendous mistake. Uh the threat that we face from foreign malign actors from uh from criminal organizations uh to critical infrastructure to cyber security uh to our cyber security are immense. Uh the Chinese are working overtime putting tens of thousands of people toward trying to infiltrate every system even in the smallest towns in this country. Same with the Russians, same with the Iranians, the North Koreans, and of course, criminal cyber gangs.
▶ 0:58:37Uh, as well, uh, we've had significant breaches in Rhode Island as a result. This is not the time to take our foot off the gas, as the secretary said was her intention during her Senate confirmation hearing. And unfortunately, this is part of a pattern because when she was governor of North Dakota, Secretary Gnome was one of only two governors in the entire country to refuse to accept state cyber security grants in 2022. Her administration called them quote wasteful spending.
▶ 0:59:05In 2023, yet again, she was now the only governor in the entire country to refuse these grants for her home state. And of course, we have seen that the administration is not off to a great start with its own cyber security practices. Uh with service members lives being put at risk from confidential information being discussed in an unsecured group chat.
▶ 0:59:31And of course, Elon Musk's army of unvetted interns going through everybody's personal data with very little transparency. But given that backdrop, it is more important than ever that Congress send the message that cyber security still matters to us, that we do not consider it to be wasteful spending. And particularly, we want to continue to support states, utilities uh in our home states with this program.
▶ 1:00:02So uh I have limited time, but um Mr. Fuller, can you elaborate uh on any reports of delays, puts or uh cuts or pauses to this program? Uh what have you seen so far and what would the negative consequences be? Thank you. And I I appreciate your uh point that this there's a lot of bipartisan support for this program to continue. Certainly the the risk doesn't take politics into account.
▶ 1:00:28Um, one of the concerns we have about the program is some of our uh some of our states chose not to participate because they were afraid that the funding would not continue on and they were afraid to launch a program that might then get cut and that created some hesitation for some states. Uh, for us, we're all in with the program and it has been extremely beneficial. I mentioned in my testimony, we've blocked seven major attacks in the last six months alone.
▶ 1:00:53Um and so we uh we would hope that we could uh uh extend the the funding could be extended by Congress without delays. Those delays could cause serious problems in adoption of the program. Thank you. And Mr.
▶ 1:01:06Raymond, if FEMA is eliminated and CISA is significantly cut, as Secretary Gnome has promised, what impact would that have on the ability of of your state and others uh to maintain strong cyber security and take advantage of programs like this I do believe that uh FEMA and our emergency management in Connecticut along with SISA on the security side have been great partners with us uh on this cyber battle.
▶ 1:01:36Um the state and local governments are not prepared to fight this kind of cyber uh engagement with with foreign nations. Uh I I would say uh with in combination with the reductions to MSISAC and SISA support uh additional responsibilities are falling on the states to to fight these battles.
▶ 1:01:58Uh should you know further SISA reductions or or FEMA reductions for that matter uh be put in place, I would say it would diminish uh our ability to help the municipalities that are part of our jurisdiction and defend on behalf of the state. All right. Thank you. I'm over time, so I'll yield back. Gentleman yields back. I now recognize myself for 5 minutes of questions. Uh gentlemen, we've heard from you all today. Uh there's definitely a need for the program.
▶ 1:02:27Uh I want to focus on one, uh is it has it been successful so far? And two, what challen what changes would we make? And you've also suggested a couple. And Mr. Mr. Raymond, you started by saying when you first did the uh with the um with this in your state, there were 27% of the of the municipalities were low risk. So 73 uh% were were not risk.
▶ 1:02:54Now that this program is in place, have you done another uh have you done another review? What's uh what number is low risk? Now uh we are currently reassessment now. We do not have an updated set of numbers on that. Uh we do know that the implementation of the the 51 grants that we have would directly raise the the ratings and lower the risk for folks who are out there. Wonderful. Uh Mr. Huber, you you're a vendor, so you're dealing with all these municipalities.
▶ 1:03:23You know uh what they're using, what they needed. Can you please just describe what these grants have been able to help uh some of the municipalities you've you've you've dealt with? uh like what uh what systems have been put in place, you know, what they had and now what they have. I mean, I I think people really we need to hear, you know, the actual benefit of of what you've done with this grant uh with this grant money. Sure. Thank you for the question. Yeah.
▶ 1:03:50So, you know, one of the first uh foundational components of any cyber security program is having awareness of what you have. You have to know what you have to be able to defend it. U sounds easy, significant challenge for most organizations, even mature organizations. That's a challenge to understand the breadth of the footprint certainly at a state level, let alone rural areas as well. So what we've seen folks do is deploy solutions that allow them to understand what they have in their purview, what's exposed. And to the gentleman's point regarding risk assessments, you have to know what you have to conduct that risk assessment.
▶ 1:04:20So that's step one. We've seen them deploying that successfully. And then you want to take that just a step further. Now I know what I have. What am I vulnerable to? What misconfigurations, weaknesses, and vulnerabilities do I have there? and how do I prioritize those from a response perspective? Because I have limited resources to go and mitigate or reduce those risks. So now I'm looking at, you know, what are my resources available to go and reduce the risk across the entire enterprise without regard to the size of the municipality involved, right?
▶ 1:04:46Because it could be that when they do these risk assessments, some smaller rural regions might have the highest risk compared to larger metros. And what we've seen is successfully organizations assess what they have, being able to analyze them, look for exposures across the attack footprint, and then focus on a prioritized process of addressing these That's great. So, they're using the grant money to map their system, and now they're starting because it's a multi-year uh grant, so they're mapping their system.
▶ 1:05:15and they're finding out what what doors need locks and now they're implementing it and and using technology for uh you know to protect those those doors into their system. Yeah. And I think uh a great point is sustainable funding. Uh you know I hate to say to use as example but some people when they wake up they have a day job. It's not to fix vulnerabilities. That's not their job. Their job is to make the systems run. And you know they go patch the systems and they're like hey mission accomplished. We're done here. And tomorrow you get up and read the news and you're like more vulnerabilities. You have to do this again. It's a hamster wheel to to an effect.
▶ 1:05:44Uh so people have to have not only resource and funded for that it's now a part of your job for some percentage of your time beyond what your day job is and people just understand that's how life Um thank you very much. So under the grant program there's there's some requirements in the in the law. Um one of them is for there to be a submission of a cyber security plan and this is for uh the three gentlemen on the right who actually I think had to determine these cyber security plans. Um there's a lot that's that's got to be part of it.
▶ 1:06:14uh what's you know what is working as part of the uh the plans is there something that we should include that's not in the or is there is the is the the law overburdensome by including too many things in the plan that's not necessary what do you all think Mr. F, we can start with you. Thank you.
▶ 1:06:30I I think the the the the good thing about the plan is that it gave states some flexibility to create each create their own plan and you can see between Connecticut and Utah two very separate plans where they primarily put funds down to local entities and we primarily provided tools, training and relationships down to local entities. So I feel like that part of the law was successful and good. Should not be changed. Yeah, Mr. Kramer, I'm going to leave that to the folks who actually do the cyber security stuff. Okay, Mr.
▶ 1:07:01Raymond, I' I'd say uh the the formation of the cyber plan was really helpful to focus in a in a structured way on what the risks were and what we could do together to to lower those risks. there was a tremendous amount of collaboration in the development of the plan which I think furthered the mission of hey we're all in this together and helped to get the message out to all of the municipalities that this was important for their success.
▶ 1:07:30So I think the combination of collaboration and structure in those plans and the direction that set was very hopeful for statewide efforts. Sounds like that part of the statute is something that uh we should not change and should be wonderful. All right, we're going to start a second round of questions. I now recognize the gentleman from Texas, Mr. Latrell, for his second round of five minutes. Mr. Hoover, you I think you hit the nail on the head explaining exactly the how the process should work.
▶ 1:08:00Is that even a possibility or a probability? Because remember, you're talking to the United States of America right now. And I want you to think about that. I don't know where you're from. Kentucky probably. I'm from Texas, obviously. Little bitty town. And the reach and we hate the federal government. I could throw that out there. Honestly, we don't want them in in and around us at all. However, with the threat or the the risk to threat when it comes to cyber security, cyber threat um the cyber space, how do we make this work?
▶ 1:08:29The plan that Mr. Raymond laid out piggybacks exactly what you said, but we have to touch every single person in the United States of America. And I can assure you the four of you sitting in front of us, you're not the first for it's ever sat in front of us and laid this out. But it keeps how do we I mean this is almost the simplest question I ask is how do we fix this problem or is is it a possibility?
▶ 1:08:55Because we could just keep talking about it all day long and we could keep funding these grants and throwing it out there and we're just going to get attack after attack. You said the problem is when the attack happens, we don't we're retrospective. It's done deal. And then we have to raise awareness of those that didn't get hit. Who's doing that? Well, I've had SISA come out to my district. I've had the FBI come out to my district, talk to the nursing homes, the schools, and guess what? The things that they laid out, a month later, something else up. How do I literally How do we fix this? Yeah, thank you for the question.
▶ 1:09:24A great question. We have to raise the bar across the board. There's foundational cy cyber uh comp. What does the bar even look like? I think the NIS cyber security and you and I are gonna have a pretty healthy debate here in 3 minutes and 16 seconds because every time you know you see where I'm going with this. I do. Absolutely. Yeah. So the the NIS cyber security framework provides excellent foundational controls. But to your point AI was not on my list of risks three years ago and now it is. And guess what we're doing?
▶ 1:09:53We're developing those foundational components for artificial intelligence and how we defend and how we detect for that type of capability. So we're always going to be in that race of emerging technology. unfortunately for us, but those found foundational components still hold true for the vast majority of threats that exist today. And I think what we heard is very key of getting the message out, which is that communication and collaboration, whether that's through uh JCDC under SISA or whether that's through some of these fusion centers we heard of at the state level where they're disseminating information.
▶ 1:10:19It is a collective sport at the end of the day and we all need that information to be able to respond as quickly as possible. the the the sheer processing speed. Now we're like past exascale computing. Magnolia, Texas can't defend that. We have a we have nefarious actors that have the computational capabilities to destroy a country.
▶ 1:10:44How do I protect District 8 in I think and this is not normally how you start a streety program but you should start with incident response. You need to have surge capabilities and re resources to respond to an incident and to your point unfortunately it will happen. We have data that shows it will happen to even the most mature organizations.
▶ 1:11:05So having those capabilities and a lot of times those surge capabilities and I've been in this role come from the national guard they come from CIS and other organizations to provide us intelligence we don't have to collectively respond as an industry and that also raises the bar. I mean, but how much is that that I can't even I can't even repave the roads in my forest right now. So now here we're talking about dollar bills and I can only imagine that protective layer is going help me fix this problem.
▶ 1:11:34I mean what yeah there's there's certainly data points available of known exploited vulnerabilities. That's something we use as an industry to prioritize like we know these are actively being exploited against these organizations. You want to make sure that when you're applying resources against the problem, it's a prioritized approach. Whether it's through the the program assessments that these organizations complete to identify the highest risk or whether it's vulnerabilities that you see day in and day out to prioritize those source.
▶ 1:11:59I know within tennel we have data that says unfortunately if a new vulnerability comes out that affects major operating systems as an example, it takes most organizations a few weeks to address those vulnerabilities. And by the way, they only fix about half of them during the course of that two weeks. So there's a known exposure that we all accept and like I said, I'll foot stop this. Having that good response plan of how you coordinate reaction to those events becomes critical. Thank you. I yield back, sir. Gentleman yields back.
▶ 1:12:28And I I I get the gentleman's point about there might not be a way to stop uh to stop these. How do we stop them? I don't know if we can stop him, but being able to respond and and get things back online, I think is uh is what is is at least part of the the goal here. I now recognize the gentleman from California, the ranking member, Mr. Swallwell, for his second five minutes. Thank you.
▶ 1:12:48I'd welcome the opportunity with the four of you here to give us a real-time update on the threat environment and what you're seeing as to the the type of the attack, the the ask of the attack, if it's ransomware, your ability to work with the federal government, uh, for example, the bureau when an attack occurs, and the origin of the attack, uh, is it still primarily
▶ 1:13:19Russia, Eastern Europe, criminal gangs for ransomware, and then as far as fishing attacks and intellectual property theft, is that primarily China? So, I'll just Mr. Hebra start with you. If you each spend about a minute on this, I think we'd get a good cross- sector update. Yeah, I think it's heavily dependent on the sector the entity operates in.
▶ 1:13:46UDC all those actors across all sectors and unfortunately you know it's become easier. There's things such as ransomware as a service as an example. You can buy access to systems and companies at your will without having to conduct any actual attacks themselves. And then of course we always have the nation state actors in there. So it's like investing in the stock market. You just like buy an index fund of ransomware attacks. That's that's exactly it. Yeah. So if I wanted to compromise your machine, I might buy access from somebody who already has access to your machine. So I'm not actually conducting the activity myself.
▶ 1:14:16Sorry, continue. Yeah. So, so I think, you know, we're seeing a mixed bag and the problem becomes to Congressman Latrrell's point is, you know, trying to defend against all of those different types of actors, whether it's, you know, financially motivated, ideology motivated, nation state motivated, they all have different intents for what their targets are. So, you have to understand to a great extent what your attackers look like. And that's again where some of that information through law enforcement or SIS or JCDC is very useful. JCDC is a part of SISO.
▶ 1:14:42used they coordinated responses for log forj massive vulnerability that affected the economy in the world for that matter one of the largest ones in my career they did a fantastic job of sharing what works what doesn't and getting us intel quickly that we can action great thank you Mr. Thank you so much for the opportunity. So the types of attacks, first of all, the end users are typically the the biggest vulnerability. So we see things like fishing attacks, business email compromise. I'll I'd like to give you a very specific example that we just had the last few weeks.
▶ 1:15:10Um Utah's an alcohol alcohol control state. We have retail stores that uh uh that sell alcohol. We had uh uh criminals calling these liquor stores representing themselves as members of the government and and saying that they needed to change settings in their credit card readers. The credit card readers they were trying to the settings they were trying to change were trying to make it so the card didn't have to be present. It was a blatant attempt to try to hack the credit card readers of our liquor stores.
▶ 1:15:38We've seen just in the recent past some business email compromise has been very damaging. We've seen um they they try to do things like convince uh state employees to change bank routing numbers to redirect funds so it goes to the criminals instead of to the uh the place it's supposed to go and the the primary uh attackers come from Russia, China, North Korea, Iran and we've seen uh quite a bit from Nigeria.
▶ 1:16:07I would also just mention to some of the comments before that uh with artificial intelligence technology unfortunately I see the problem getting worse not better. Um it used to be with fishing type emails you would see typos incorrect grammar you could kind of spot that something wasn't quite right. Unfortunately the criminals know how to use artificial intelligence as well. And we just had an incident where we had over 400 uh fishing emails.
▶ 1:16:34everyone a different subject line, everyone a different text, all written beautifully and uh unfortunately uh all bearing malware that could compromise systems. So unfortunately uh the world's getting more dangerous, not less. Thank you. That's helpful. Council member Kramer. So in talking to James M, our cyber security guy back home, he mentioned some of the things same things have been testified to here.
▶ 1:16:59Um there are certain uh localities that we know when something's coming in, it's probably suspect just because of where it's coming from. Um in 2023, we had a nation state um cyber actor get access to one of our network devices through a a provider's chat.
▶ 1:17:18um you wouldn't think that's a big deal, but in the process of chatting back and forth with other folks on that same system, um they were able to get passwords, uh usernames, and later were able to go in and try to they got into the network where they could see what was going on. Um fortunately, we were able to catch that before they were able to do anything. So, it only cost us about 100 hours to fix it. Um we were grateful.
▶ 1:17:42Typically these things the problem is as you guys well understand um if you don't spend the money upfront to know what's coming you're going to spend the money on the back end and you know we talked earlier about local governments and rural communities um the real issue there is a lot of the rural communities they don't have the resources to spend upfront and so they don't and you don't have a choice about spending on the back end. Uh my time expired. Would you indulge me to allow the CISO from Connecticut please Mr. very much.
▶ 1:18:12Uh, thank you. I I would say that sim very similar answer. We're seeing global interest in things that we do. If we put a new a device on the network, five minutes, it's being scanned by someone. So, they they're looking for the vulnerabilities that uh were being described for scanning earlier. The the threats are data exfiltration, right? Stealing of data of intellectual property, ransomware, uh extortion of data, uh business email compromise.
▶ 1:18:40I'd say fishing, targeting of leaders for passwords and those kinds of things are very common things that we Thank you. That was helpful across the board. Chairman, I yield back. Gentleman yields back. I'm going to continue along my line of question from before about changes. Um, SISA and FEMA's role, are they good partners? Should they are they the ones who should be running this program? I mean, has it worked? Has it not? Jump in. Sure.
▶ 1:19:11If I may, Mr. Chair, CIS has been an outstanding partner for us. We're really grateful for them and their commitment. We use them in a number of ways. Uh they are active members of our cyber center as well as the Federal Bureau of Investigation. Those relationships are extremely important. When when a bad thing happens, it is so good to be able to have experts to reach out to and and and know who to call. SISA and FBI help provide that role for us. We're very grateful for their support.
▶ 1:19:38We also use CISA services to do cyber security assessments of each of our agent agencies in the state across the board. We do that once every three years for all agencies and they've been a tremendous partner for us. Kramer whoever I yeah I completely agree the um you know the SISA team has brought great leadership and insight and expertise uh in terms of both what we can leverage but uh to the earlier question they've been fantastic
▶ 1:20:08in getting out to the local governments in being helping them raise the understanding of what's available and how they need to be thinking about it. Um, you know, A FEMA has been sort of a a back office partner for the grant administration. I'd say less active in, you know, in the delivery of the technology, but they've been they've also been a great partner. Yeah, I'd say Baseline been a great partner. Really happy about what's going on so far.
▶ 1:20:36Um, but the one-sizefits-all approach um has been somewhat limiting. It limits some of the efficiencies. Um, we would hope that Congress would create a more direct competitive grant fund um with SLCGP for larger municipalities who can afford to to take care of that on their own. Um, I think that would be helpful. The other is um we recommend an application process to be simplified to encourage participation by some of our smaller communities.
▶ 1:21:03Simplified how the the the uh reporting processes are are somewhat burdensome. Um, again, keep in mind, and some of my colleagues have already testified, very often these aren't full-time employees who are focused on a applying for grants in the first place and and b just this the um technical nature of it alone.
▶ 1:21:24And so, if we could make it such that some of our less technical folks who are responsible for these highly technical um would be able to report more easily. And currently currently Louisville, the city of Louisville, has to go through the state to get its grant. Correct. It can't or it's it's it's administered by the state. I don't believe so. I I'd have to check. I think ours came directly to Metro, although it may have come through the states. Okay. Um I'll withhold on that one.
▶ 1:21:52But there you're saying part of this pot of money would be instead of instead of having to go it might be worthwhile to have some of this lower larger cities and municipalities be able to go go directly to Yes. uh directly to FEMA to get uh have some of the grants come instead of Okay. Now, you you mentioned something about for rural uh the cost they they they don't have they can't even come up with the cost share. How would we fix that?
▶ 1:22:18Again, I think the the the program the way that it's designed, if we could get that more quickly, more easily to municipalities, to the and again, when we talk about cities and and rural um municipalities are still in those rural areas. They're just much smaller municipalities. Um in the state of Kentucky and all the states actually, there's a there's a leagues of cities and the Kentucky League of Cities has been awesome to work with.
▶ 1:22:45Um it would be it would be beneficial to local governments if the grant money were funneled or moved through that organization. They're more directly connected to what's going on in cities than the state is. Okay. Mr. Raymond Fuller, you both have rural areas. I mean, what could we do uh more to help there? Because again, those are the those are the municipalities that don't have the expertise even though the pivot act the chairman is leading uh wouldput would uh would allow people to hire and be part of the service. So that's great.
▶ 1:23:14So, nice little plug for the chairman's bill. Hopefully, it passes. But go ahead, Mr. Chair, if I may, that uh so I I felt like it was kind of ingenious to run it through the states because uh and 80% was direct 80% of the funding, it was came through the states, but 80% of the funding to go to to locals and that allowed us the state to directly help those rural cities and counties and give them the help that they need.
▶ 1:23:35In some cases, we've been able even to hire technical resources to help them implement the endpoint software and we've been able to provide the training that they wouldn't uh have otherwise needed to do. So, we've been able to we as a state have been able to make it super easy. Uh we've just packaged it up and given it to them and even helped them implement it. So, the way it's worked for us has has been beautiful. I I would add that the the match allows for a waiver depending on certain financial conditions.
▶ 1:24:01Um, so I I do believe that if people can't come up with the money to meet the match, they have a way to respond to that. However, I I think people uh have been reluctant to use that and the uh expectation that that will slow down their award uh or perhaps not get it. They wouldn't be granted the the match. And so I I think there's some trepidation for people to put in for that match waiver um that's preventing some of the uptake of it. Wonderful. Um Mr. Mr.
▶ 1:24:30Huber, you mentioned something in your opening statement about lower the cost sharing requirements. Is that did you say that? I did. Yeah, I think there's opportunity certainly with state municipalities where it makes sense to provide shared services. So it increases the ROI for those service provided as Mr. Fuller mentioned as well. You have expertise at the state level that can also be shared. They can hire additional resources there. So you have a known capacity providing resources to certainly rural and municipalities. I think that makes more effective.
▶ 1:24:58And then the the cost share component which I mentioned earlier is like you don't want to put so much pressure on a small organization that doesn't have somebody whose full-time job is applying for grants trying to do that right justifying that uh that resource to do that. You want to put them in the best position to be successful deploy the technology to protect your organization. Wonderful. And I'm out of time but I have I'm the chairman so I'm just going to ask one more question. Um so now we've had this hearing.
▶ 1:25:24it's our job to come back and uh to to reauthorize this if we want and make any changes. So, uh you're all the experts. You all been dealing with this this bill or this uh this program. If you could all have I want to hear from each one of you. If if there was one change or fix made to this, what would it be? And we'll start with uh you Mr. Huber. I think you'd want to ensure that there's harmonization of any standards and compliance. You want this to be a cyber security exercise.
▶ 1:25:52raise the bar for cyber security, not a compliance exercise. Simple as that. Thank you, Mr. Fuller. I would just say continuity of funding. That would be the main thing. The uh it got too uh people feel hesitant that if the funding is not going to be there that they're going to start into the program and then the funding gets cut and then they're left holding the bag and that that makes them uh hesitant to adopt. So, the authorization should be longer than for four years. Yes, please. Okay.
▶ 1:26:23I concur um with both my colleagues. Um and then I would add back in the one I mentioned a moment ago and um for larger municipalities if we could apply directly I think that would be helpful and then um allow that that organizations like municipal leagues would have an opportunity to work together as well. Mr. Raymond, I would say the ongoing sustainable funding and then ongoing assessments. You cannot manage what you don't measure.
▶ 1:26:52And so understanding what that cyber risk looks like is critical to this ongoing success. Great. Well, I want to thank the witnesses for their valuable testimony today and the members for their questions. The members of the committee may have some additional questions uh for all of you and we would ask that you all respond to these in writing. Pursuing to committee rule 7E, the hearing record will be held open for 10 days. Without objection, this committee stands adjourned.