▶ 0:06:11the uh committee on homeland security will come to order and without objection the chair may declare the committee in recess at any point. Today's field hearing will explore how the public and private sectors can work together to address the economic models of cyber security. To do this, we will examine the cyber threat landscape, cyber regulations, and the technology that will improve America's cyber security posture. I want to thank the members of the committee who who made it out for this and took time to join us here in Silicon Valley.
▶ 0:06:42I now recognize myself for an opening statement. Well, good afternoon and uh I want to thank all of you for coming today. The the topic is one that is incredibly important for our country. Uh, and I thank the Hoover Institution for hosting this um on such an incredibly beautiful campus. Uh, it and I don't know who brought the weather here. Is it like this all the time? I mean, it's incredible.
▶ 0:07:08Um, it's it's not a coincidence that we're holding today's hearing here in the middle of Silicon Valley. Uh, since World War II, Silicon Valley has been the world's shining example of what a nation can accomplish when innovation is unleashed. Uh, it's the home of some of America's most talented and creative minds, innovators who are spearheading major breakthroughs in technological development.
▶ 0:07:32From semiconductors to social media, Silicon Valley has produced innovations that have changed the way we work, communicate, and complete our daily tasks. As we know, great technological advancements come with great I'm here today to emphasize the importance of prioritizing our cyber security as we build new capabilities that will continue to change the world. And I have prioritize cyber security for myself in this Congress and for the Committee on Homeland Security.
▶ 0:08:01And I hope the industry partners that are here and and across the country um will join us in this mission to improve our cyber resilience against nation states as well as criminal actors. strengthen our offensive posture and develop new capabilities that incorporate security from the start. I strongly believe that allowing American innovation to flourish is critical to strengthening our national security.
▶ 0:08:29And that's why we must start by injecting some common sense into the regulatory regime. The increasingly burdensome, costly, and duplicative requirements placed on our innovators are stifling our innovation and hindering our national security. Instead, we must continue to explore technological solutions for regulatory compliance and ways that we as Congress can help deconlict and simplify cyber regulations.
▶ 0:08:56This priority pairs well with another focus of mine this Congress, changing the economic models of cyber security. The costs and incentives associated with cyber security are currently imbalanced in favor of the attacker rather than the defender. According to a report by IBM, the global average cost of a daily a data breach in 2024 was nearly $4.9 million.
▶ 0:09:20In many cases, to inflict multi-million dollar damage on US businesses, attackers only need some degree of technical knowledge and a laptop, a fraction of the costs faced by their victims. Fixing the economic models of cyber security will will require a concentrated effort across industry and our government. First, we must raise the cost of cyber attacks for our adversaries.
▶ 0:09:43From strengthening our offensive posture in cyber space to creating innovative cyber security solutions, the United States must make it more challenging and costly for adversaries to strike. Secondly, we must ensure that American businesses, especially private owners and operators of critical infrastructure, are investing heavily in cyber security.
▶ 0:10:04There needs to be a greater demand for products designed with cyber security in mind, accompanied by a supply shift toward more secure information technology and operational technology. There is an undisputed connect undisputable connection between what happens here in Silicon Valley and the security of US critical infrastructure. The technology and cyber security solutions produced here have applications across all critical infrastructure sectors.
▶ 0:10:31By improving investment in cyber security and raising costs for our adversaries, the entire nation will be more secure. Cyber security truly is a team sport. Our collective defense against cyber threats relies upon private partner private public partnerships and information sharing.
▶ 0:10:49We want to turn that information sharing into action and I'm grateful for Chairman Garberino's efforts to preserve and enhance these partnerships including through the reauthorization of CISUS 20205 and and I look forward to discussing other ways to strengthen public private partnerships in cyber security. I want to thank our witnesses for joining us today. Uh I look forward to discussing the current threat landscape with each of you and to examine ways that we can realign the economic models of cyber security.
▶ 0:11:19Our discussion will position us well to delve into finding solutions with some of our nation's most prominent innovators during the breakout session that follows this hearing. We have much more work uh to get done and to get to where we need to be, but I'm confident that if we work toward these objectives together, we will accomplish our mission. I look forward to the effort.
▶ 0:11:44I'd now like to recognize uh the chairman of the subcommittee on uh cyber security and homeland security committee, Mr. Garbarino from New York. Thank you, Mr. Chairman. Thank you very much for having this hearing. Uh good afternoon, everyone. I'm honored to join our nation's innovators today here in Silicon Valley. Thank you for your interest in our hearing and your partnership. Our enemies aggressively target US critical infrastructure through novel techniques and persistent campaigns.
▶ 0:12:10Bolton Salt Typhoon, two China backed threat actors demonstrate that America's foreign adversaries are intent on finding opportunities to exploit our cyber security weaknesses wherever they can. It is therefore crucial that America's cyber security capabilities remain ahead of our adversaries. Bolstering cyber security resilience requires a whole of society approach, one that unlocks full potential of our innovative capacity to address and prevent vulnerabilities in our IT and OT.
▶ 0:12:39The companies here in Silicon Valley are often on the front lines of cyber security defense and they will have and they will help develop solutions to bolster our ability to counter these threats. Ensuring we develop and use the right cyber security solutions requires a strong partnership between the public and private sectors. The foundation of this collaboration is information sharing a key focus for my subcommittee Congress.
▶ 0:13:04Information sharing between the public and private sectors is beneficial not only for staying ahead of threat actors but also for driving innovation to where it is needed most by sharing information about emerging threats and empowering CISA to manage cross- sectoral relationships. Information sharing will help develop the tools we need to understand how threat actors operate in cyerspace.
▶ 0:13:27Innovation plays a critical role in keeping up with new tactics, techniques, and procedures of our adversaries in an increasingly active threat environment. As part of our continued prioritization of information sharing, my subcommittee recently held a hearing on an important authority, the Cyber Security Information Sharing Act of 2015, otherwise known as CISA 2015. Information sharing between the public and private sectors heavily relies upon this act. So it's imperative that Congress reauthorizes 2015 before it expires later this year.
▶ 0:13:57I was encouraged by Secretary Gnome's statements in support of reauthorizing 2015 when she came before the full committee just a few weeks ago and look forward to working with the administration to do so in the coming months. Regulatory harmonization is another important topic that we will discuss during today's hearing.
▶ 0:14:13This is a topic which my subcommittee has explored extensively especially in the context of cersca the cy cyber incident reporting of critical in infrastructure act of 2022 industry's feedback is critical to obtain an effective final rule that meets congressional intent which is why I look forward to hearing your perspectives on the current regulatory landscape I'm also aware of the importance of providing for an exparte process as rule making moves forward this is something secretary gnome has committed to providing which will hopefully help remedy the
▶ 0:14:44rule's current shortfalls. Our expert panelists have led the charge in protecting the United States from threats to our cyber security. I look forward to hearing from your insights into what strategies we can take to promote cyber security, innovation, and breast pack best practices. Thank you, Mr. Chairman. I yield back. Thank you, uh, Mr. Garberino. And I it's always difficult to have an official hearing in your own district. Uh this happens to be Mr.
▶ 0:15:13Swallwell's district and I'm certain as I would be if we were having this hearing in my district pulled in a thousand different ways. So uh we'll have him make his opening comments uh after our witnesses if he gets here by then. Uh I'm pleased to have uh a distinguished panel of witnesses with us today.
▶ 0:15:32their incredible experience uh in in this evolving landscape of cyber whether in government or private sector will help shed a lot of light today on the challenges and solutions that we need in cyerspace. I'll ask the witnesses to stand and raise their right hand.
▶ 0:15:54Do you so solemnly swear that the testimony you will give before the committee on homeland security of the United States House of Representatives will be the truth, the whole truth, and nothing but the truth. So, help you God. Let the record reflect that the witnesses have answered in the affirmative. Thank you. Please be seated. I'd now like to formally introduce our witnesses. Uh the honorable HR McMaster is a senior fellow at the Hoover Institution at Sanford University. He's a proud graduate of West Point and served as a commissioned officer in the United States Army for 34 years.
▶ 0:16:25Uh retiring in the rank of Lieutenant General in 2018. He uh won the Silver Star as a company commander in one of the one of history's very most most famous tank battles in Desert Storm. He served as the nation's 25th National Security Adviser from 2017 to 2018. Miss Wendy Whitmore is the chief security intelligence officer at Palto Networks.
▶ 0:16:49She is a globally recognized cyber security leader with two decades of experience in building incident response and threat intelligence teams. She began her career as a special agent conducting computer crimes investigation with the United States Air Force Office of Special Investigations. Mr. Net Manfra, did I pronounce that correctly? Okay. is the global director for the security and compliance at Google cloud.
▶ 0:17:15Prior to joining Google, she served as the assistant director of for cyber security at CISA. Miss Manfro spent more than a decade serving in various roles at the Department of Homeland Security in the White House, focused on establishing the nation's first civilian cyber defense agency. Janette is a proud veteran of the US Army and I believe an army aviator. Uh Mr.
▶ 0:17:37Jack Cable is the CEO and co-founder of Corridor, an organization that helps companies performing AI powered security refac uh at scale. He previously served as a senior technical adviser at CISA where he helped lead the work on secure by design and open-source software security. I thank our witnesses for being here today and I now recognize General McMaster for five minutes to summarize his opening comments.
▶ 0:18:06Thank Chairman Green, Congressman Garberino, uh Congressman Smallwell, and members of the subcommittee. Uh it it is a privilege to testify before this committee at a critical moment for our nation and the free world.
▶ 0:18:21I hope that my statement for the record is useful to you and the important work that this committee is undertaking to understand US cyber security posture and develop solutions to improve critical infrastructure resilience, foster technological innovation and harmonize regulations.
▶ 0:18:39It's particular privilege to be on this panel alongside three private sector innovators and great Americans who have done vital work to help maintain our competitive advantage cyerspace. This hearing is timely because as has already been mentioned in recent years responses to adversar state attacks have been slow and inadequate.
▶ 0:19:03Strengthening deterrence will require the rapid imposition of costs on cyber attackers that go far beyond those that those attackers anticipate prior to acting against us. We must also improve the resilience of our systems through a combination of defensive and as you mentioned, Mr. Chairman, offensive capabilities as well as the capacity for rapid recovery.
▶ 0:19:30We must maintain competitive advantage in artificial intelligence, quantum computing and other technologies relevant to cyber security and the associated protection of critical infrastructure. Chairman Green, as you already mentioned, particularly important are going to be removing barriers to implementation of cyerspace solutions and AI models. Uh, and I think that's a particular important aspect of of getting from information to to action as you mentioned.
▶ 0:20:00And we must improve dramatically the security of our critical technologies and research enterprises from the threat of relentless state-based espionage. Accomplishing these tasks will require close cooperation between the public and private sectors and academia and with international partners as well as investments in research and I would say especially human capital.
▶ 0:20:25Maintaining our advantage in human capital should include attracting the best talent to our universities and granting visas to graduates uh who can help grow our nation's talent base in science and engineering. Thank you. It's a real privilege to be with you. Thank you, General McMaster. And I now recognize Miss Whitmore for five minutes to summarize her opening statement.
▶ 0:20:52Chairman Green, Congressman Garino, and Congressman Swallwell. Uh thank you for the opportunity to testify today on innovation in cyber security including how our adversaries are intensifying their attacks and more importantly how we can innovate to turbocharge our defenses. My name is Wendy Whitmore and I'm the chief security intelligence officer at PaloAlto Networks.
▶ 0:21:15PaloAlto Networks is an American cyber security company founded in 2005 uh that has since become a global cyber security leader. We support 97 of the Fortune 100, the US federal government, critical infrastructure operators, and a wide range of state and local partners. The breadth and depth of the organizations that we help protect uh gives us a unique vantage point into the cyber threat landscape and what we see is very concerning.
▶ 0:21:43As recent campaigns like salt and vault typhoon have reinforced, our cyber adversaries, China, Russia, Iran, North Korea and others are more active and aggressive than ever. They are leveraging AI to increase the speed and scale of their attacks to enhance tactics like fishing, exfiltrate data faster, and execute complex multi-stage attacks that are increasingly disruptive to the American public. Consider this.
▶ 0:22:10Every single day, Palo Alto Networks blocks up to 31 billion cyber attacks. Up to nine million of those daily attacks represent novel method attack methods never previously seen. To stay a step ahead, relentless innovation must be central to our cyber defenses. Innovation with AI at its core has the potential to disrupt the legacy status quo of chasing each new threat with an isolated disjointed solution.
▶ 0:22:38Instead, we can leverage AI to analyze security data in real time and then automate our responses. This evolved approach can simultaneously one deliver transformative cyber security outcomes, two drive muchneeded cost rationalization, and three eliminate inefficient manual processes.
▶ 0:22:58Palo Alto Network supports this committee's desire to pivot away from a stale point- in time compliance first mindset for cyber resilience and radically rethink how AI and automation can modernize our cyber defenses. The potential impact here is not hypothetical. We've seen our customers dramatically improve their cyber defenses.
▶ 0:23:19With AI powered security operations centers, their average response times to cyber attacks have dropped from two or three days to under two hours. This is a transformative shift. PaloAlto Networks is proud to be an integrated national security partner with the federal government. My written testimony includes a series of recommendations policymakers should consider at this pivotal moment for our nation's cyber defense. Let me take a moment to focus on a few of those.
▶ 0:23:49First, focus on measurable cyber security outcomes. Ensure cyber security investments improve agency's basic cyber vital signs by reducing the meanantime to detect and the meantime to respond to incidents. Second, forcefully respond to salt typhoon by implementing zero trust. This evolved security approach does not implicitly grant access and it can limit the impact of these attacks.
▶ 0:24:17Third, fully embrace AI to support cyber defense. Network defenders are drowning in data as they manually triage alerts. AI has the power to modernize cyber uh security operations centers and allow analysts to be more proactive in their threat hunting. And fourth, promote secure AI by design.
▶ 0:24:36To safely harness the incredible power of AI, enterprises must have the frameworks and capabilities to discover, assess, and protect against threats to AI At the end of the day, people, processes, and technology must work in concert. PaloAlto Networks applaud Chairman Green's reintroduction of the Cyber Pivot Act to help foster a steady pipeline of trained cyber professionals and begin addressing our nation's cyber security workforce gap.
▶ 0:25:04We continue to see productive collaboration take place across a range of cyber security focused convening bodies, including CIS's joint cyber defense collaborative. We support Representative Swallwell's efforts to put wind in the sales of JCDC's mission. Critical to sustaining an enduring partnership is the free exchange of cyber threat intelligence across the public and private sector.
▶ 0:25:32To that end, we support swift reauthorization of the Cyber Information Sharing Act of 2015 and appreciate the thoughtful hearing Representative Garberino convened on this issue earlier this month. Palo Alto Networks takes our partnership with law enforcement uh and lawmakers and this committee seriously. Thank you for the opportunity to testify. I look forward to your questions. Thank you, Miss Whitmore. I now recognize Miss Manfra for five minutes to summarize her opening statement.
▶ 0:26:02Thank you, Chairman Green and Garbrino, Ranking Member Suavel. Thank you for the opportunity to appear before you today and for your focus on this important issue. As was said, my name is Janette Manfra and I'm the head of global risk and compliance for Google Cloud. We appreciate you holding this important hearing and we do look forward to sharing Google's perspective on opportunities for regulatory harmonization and compliance modernization to better enable our entire ecosystem to protect itself against the rising threats.
▶ 0:26:30Technology advances as do the threats and cyber security defenders must adapt to it all if we want their approaches to stay current. In an interconnected world facing growing cyber attacks, it is critical to ensure that technology systems are resilient and keep people safe.
▶ 0:26:46For nearly 20 years, Google has pioneered both secure by design and zero trust architectures, which means that we embed security into every approach of our software development life cycle, including looking at physical security throughout our entire stack.
▶ 0:27:02At Google Cloud, we believe in something we call shared fate, which moves beyond shared responsibility and indicates less of a transactional relationship in the security responsibilities, but it shows that we are investing in our own security, in our infrastructure, in our platforms, in our software, but we're also investing in ensuring that our customers can be secure and compliant and modernize their own systems. Regulating cyber security at the national scale though is complex, poses unique challenges and carries high stakes.
▶ 0:27:33Regulatory and compliance regimes impact the resilience of critical infrastructure, economic development, the pace of technological innovation, military deployments and capabilities in the daily lives of American citizens. As a result, cyber security regulation should be carefully balanced, promoting strong strong cyber security baseline standards while allowing flexibility to account for evolving technology and the everchanging threat landscape.
▶ 0:27:58At Google, we recommend a regulatory approach that is agile and focuses on aligning baseline requirements across sectors. The approach must also allow for additional sector specific requirements that are complementaryary to and not duplicative of or in conflict with those standard baselines. This approach would increase adoption of security principles across the federal government, critical infrastructure, and the wider private sector.
▶ 0:28:22Regulatory agility will help reduce compliance burdens, enhance coordination, build public trust, and allow for a more resilient approach as the threats change, new economic sectors emerge, and agency responsibilities change and shift over time. I believe regulations must prioritize tangible outcomes over mere checklists.
▶ 0:28:42Google's commitment to openness, interoperability, transparency, responsibility, a secure by design approach, intelligent security systems, and collaborative efforts can only be fully realized within such an adaptable regulatory environment. We urge Congress to modernize cyber security regulations and create a stable baseline that existing sectors can adhere to and future sectors can adopt as a reliable guide for improving security and resilience.
▶ 0:29:08to achieve regulatory harmonization will offer just a few central recommendations. First, leveraging wellestablished standards and processes for any contemplated security baseline approach. In our views, initiatives like the Federal Risk and Authorization Management Program or Fed Ramp is well established and um and has uh and we're very supportive of GSA's efforts to modernize this including through initiatives like Fed Ramp 20X that looks at increased autom automation and we further encouraging encourage leveraging
▶ 0:29:38uh capabilities like the open security controls assessment language or OSCAL for more streamlined Second, any harmonized standards should implement a risk-based approach, ensuring compliance options are aligned to specific risk levels or categories to maximize flexibility and efficiency commenurate with the level of risk associated with a particular technology application or use case. And finally, complement harmonization through a clear approach to reciprocity for different certification regimes.
▶ 0:30:08As the committee considers mechanisms to achieve regulatory harmonization, we also urge the members to continue to foster public private dialogue on the topic and to look at a global harmonized approach to ensure enterprise and service providers can focus on security outcomes as a top priority. We remain committed to the security of the digital ecosystem and we're pleased to continue to engage with you on future cyber security regulations. Thank you, Miss Sanford. I now recognize Mr. Cable for five minutes.
▶ 0:30:38his uh to summarize his opening statement. Chairman Green, Chairman Garbrino, and Ranking Member Swallwell, thank you for the opportunity to testify here today. My name is Jack Cable. I'm the CEO and co-founder of Corridor, a company using AI to make secure by design a reality. Our platform understands the security model of a codebase, refactors unsafe code, and adds guardrails around AI coding assistance. This hearing is a deeply personal topic for me. We're here at Stanford.
▶ 0:31:07my alma mater where I study computer science. Throughout my career as a self-taught ethical hacker working in the private sector, academia, and government, I've prided myself on finding innovative solutions to the hardest problems in cyber security. Most recently, I helped lead CIS's work on secure by design and open source security and created the secure by design pledge. As this committee has highlighted, state sponsored hackers from the People's Republic of China are burrowed within our critical infrastructure.
▶ 0:31:36Should China invade Taiwan, they stand to conduct destructive cyber attacks on our power grids, water systems, telecom providers, and more. But these attacks are not inevitable. Most cyber attacks exploit preventable vulnerabilities in software products or insecure default configurations. This could be as simple as a default password that sits unchanged.
▶ 0:31:58Rather than placing the burden on end users like small businesses or school systems, software manufacturers must build secure by design products, thus raising costs on our adversaries. This is our best hope to defend against PRC cyber threats and the time to act is now. Today I'll focus on three areas for urgent action. Securely adopting AI, secure by design, and strengthening security research. First, AI.
▶ 0:32:28A revolution is underway in software development. It's now possible to build a website with just a single prompt. The vast majority of developers now use AI coding assistance, enabling them to ship software faster than ever before. This will unlock tremendous innovation and advancements in productivity. At the same time, these tools can introduce vulnerabilities. Studies show that even top AI models write vulnerable code 30 to 40% of the time.
▶ 0:32:54It's only a matter of time until AI coding assistants introduce a severe vulnerability in critical software that is exploited. At Corridor, we're helping companies embrace AI securely. Our platform adds guardrails to AI assistance, preventing them from introducing vulnerabilities in the first place. As AI adoption accelerates, these kinds of protections must become the norm. And I encourage Congress to foster R&D to enable rapid software development without compromising on security. Second, secure by design.
▶ 0:33:24At SISA, we were often asked if secure by design would stifle innovation. As someone building my own company, I can say with confidence that the opposite is true. The same design decisions that make systems secure by default also produce higher quality code that costs less to maintain. The over 300 companies who voluntarily committed to SIS's pledge is another sign that security and innovation can go handinand. Buyers can also shift market incentives.
▶ 0:33:52Last month, JP Morgan Chase published a letter urging their vendors to prioritize security, noting that poor security practices are actively enabling cyber attacks. At SISA, we called this secure by demand. The US government should lead by performing procurement. Today's check the box complianceoriented processes focused more on enterprise security than the actual security of products. It's like checking that a factory has locked its doors without testing the quality of the products that it produces.
▶ 0:34:21CISA's secure software development self addestation form is a good start. Congress and the administration should build on this by incorporating more outcomes-based product security measures in procurement drawing from CIS's pledge and the product security bad practices list. Third, security research. The PRC has enacted en enacted laws requiring security researchers to report vulnerabilities to the Chinese government before disclosing to vendors.
▶ 0:34:47I recently published a piece with Jen Easterly advocating for Congress to respond by strengthening the open and transparent security research ecosystem in the United States, recognizing that security researchers like myself can play a vital role in discovering and reporting vulnerabilities before our adversaries can. While we've made progress, laws like the Computer Fraud and Abuse Act or CFAA continue to chill security research.
▶ 0:35:11Congress should reform the CFAA and associated laws to exempt good faith security research, building on DOJ's work to discourage legal action against ethical hackers. Additionally, the common vulnerabilities and exposures or CVE program is an essential resource for tracking vulnerabilities and their root causes. This program must continue and all companies should issue complete, accurate, and timely CVE records. Congress should codify under SISA the CVE program's essential mission as a national record of security flaws.
▶ 0:35:41In closing, I would be remiss not to recognize the exodus of technical talent that has occurred at SISA over the last several months. I've personally seen how SISA has lost its very best. In the face of increasing threats, we can't undermine the capacity of America's cyber defense agency and its ability to attract and retain the best technical talent. This only makes us less secure as a nation. Thank you. I look forward to your questions. Thank you for your testimony, all of you.
▶ 0:36:11And I now recognize uh my friend and uh the host here of this district or the congressman from this district uh Mr. Swallwell for five minutes. Uh, ranking member, you're recognized. Yeah. Thank you, chairman, for coming uh to the Bay Area. Yet, my district is just right across the bridge. Uh, Sam Licardo now represents this district, but the chairman uh has a deep interest in this area geographically, but also this area uh is an issue.
▶ 0:36:40And so, thank you, chairman. We've had a good visit. And I also want to thank my friend Mr. Garberino. Uh we are the quietest uh subcommittee in the Homeland Security Committee room. Uh there's a lot of news that's made in that room. Uh but when Mr. Garbino and I have our hearings, uh it's usually a snoozefest uh for anyone who wants drama uh because we're trying to get things done and and the chairman, Chairman Green has uh enabled us uh to do that. Uh thank you to our witnesses for participating, General.
▶ 0:37:09Thank you to you for your service uh to our country and and thank you to Stanford uh for hosting this. uh my interest in this area I represent Lawrence Liverour National Laboratory and Sandia National Laboratory and they work in this space and then in the private sector uh we have uh many many uh not only startups but giants uh in this space and so I'm in the solutions business and I know the two gentlemen up here are as well.
▶ 0:37:35Uh and my priority is this Congress and I want to hear from these witnesses as I juggle this hearing and a meeting uh two floors upstairs. My priority is is to really leverage the private sector, make sure that the federal government is as additive as possible.
▶ 0:37:51Uh and as you pointed out, Miss Whitmer, to reform the JCDC, uh if we can to make it, you know, uh more responsive, have more structure and scaffolding as far as criteria, and make sure it's a two-way information sharing network, not just the private sector sharing with the federal government. So, in the spirit of getting to these questions and hearing uh from the witnesses, uh I'll submit my remarks to the record, Mr. Chair, and I'll yield back. Uh thanks.
▶ 0:38:18I think uh the only uh bipartisan legislation or all the I should say all the bipartisan legislation I've done this Congress and and last Congress was with you, Eric. So, thank you. Um I want to thank our witnesses for their insightful testimony and the members uh are going to be asking a lot of questions. Um, and I'll I'll start with those questions myself and then uh we'll honestly I mean we got plenty of time so I'm going to take as long as I want to. Okay.
▶ 0:38:48Um, I interrupt. Honestly, the witnesses generated a lot more. I'm taking furious Um, one of the things that that shocks me is how uninformed the American people seem to be on just how pervasive the attacks against this nation are in cyerspace. You know, the the salt and bolt typhoon being an example.
▶ 0:39:16I I was I think I was speaking at Crowdstrike or some other someplace. uh it was in DC when I said this when I first coined this phrase, but um you having that intrusion into our cell phone systems, telecoms. Imagine if Russia placed a satchel charge next to a cell tower and had a detonator in their hand. We'd be livid.
▶ 0:39:45But essentially, that's exactly what China has done to our telecommunications systems. Right, Mr. Cable? I mean, you you brought it up very well in your testimony. And yet, there's no clamor about this on the television. There's no uh, you know, alerts reels. They literally have a kill switch in the system right now, and nobody's making a big deal out of it.
▶ 0:40:15Why do you guys think that's the case? And I I'll I'll throw that out to any one of you who wants to answer. I'll just I'll just say first of all, I think because we haven't really uh taken this to the American people to explain the gravity of it. And I think to really ask the question, okay, well, why, you know, why is China uh on on our systems? And and uh and Mr. Cable really, I think, alluded to it is because I think they're preparing for war. The Chinese Communist Party is preparing for war in a number of ways, right?
▶ 0:40:43We see it with their massive buildup of their military forces about a 44fold increase uh in their defense spending uh since the year 2000. Uh we see it in the development of weapon systems to sort of keep us at bay. But also we I think what we can do is connect what we've seen with vault typhoon to a broader range of threats including the massive buildup of their nuclear forces about a 400% increase.
▶ 0:41:09I know it's it may seem extreme to say this, but I believe that China is developing a first strike nuclear capability against us because why else would you want to all of your critical infrastructure, including including communications infrastructure and and if you look at the pattern of their intelligence collection, for example, the balloon intelligence collection was really aimed at communications intelligence that can only be picked up at that altitude. and that was the communications intelligence associated with our strategic forces.
▶ 0:41:40So I think the American people haven't really been ex have had this explained in context and maybe we need something like you know the old movie the day after you know that shows what it would look like something like uh what was done uh with the social dilemma movie you know to kind of bring it home to people but that's something uh Chairman Green I think we can take on here at the Hoover Institution is to is to sort of package you know an understanding of this threat and and and communicate that as effectively as we can.
▶ 0:42:08Yeah, I think that's uh that's something that that's part of the reason why we're here. Not only to get the information from you guys, but to to be on TV, so we can the pe the American people can hear from you guys. Deterrence uh I've always thought of deterrence as the product, not the sum of capability and will. You have all the capability in the world and zero will, you get zero deterrence. Zero times infinity is still zero.
▶ 0:42:35So, uh, if you guys could make some comments about what you think we need to do better in terms of capability and then in terms of will. I know that's a broad topic, but I'm I'm thinking about really how do we establish deterrence in the cyber space and may maybe miss Whitmore, you can take a shot at that. Absolutely.
▶ 0:42:57and and Chairman Green, I think further to your earlier question as well as uh the general's commentary here, uh my viewpoint on this is has been from 20 years of responding on the ground to some of the most major breaches that have occurred uh in the last two decades and you know many of those when I started my career in the military were highly classified investigations that no one talked about and certainly couldn't be talked about in uh open dialogue and I so that certainly contributed to
▶ 0:43:27the lack of awareness from the public. I think it is a great movement in the right direction that we now can have such an open dialogue. But the reality is in addition to the lack of awareness, I think one of the things that we unfortunately do today is punish the victims.
▶ 0:43:42So, what I mean by that is when we uh you know, for example, a bank robbery, we often times don't publish that on the news and blame the bank for uh you know, having an armed robber come in at gunpoint and a teller provide them uh some funds that are in their tray. But when we the media gets hold of cases of cyber crime and these massive intrusions, we do often do that.
▶ 0:44:08And then we add regulation in that requires them to provide information uh in this most dynamic time period, the first 48 to 72 hours, very similar to traditional crimes. That's also the time that it's most dynamic in a computer intrusion. So you have a victim who is now uh potentially trying to negotiate or have communications with an attacker. They're working with law enforcement.
▶ 0:44:32They're working with outside legal counsel and they still don't have all the technical details of an investigation that are needed to fully answer these questions and understand is this a national security issue? Is this potentially a cyber criminal uh that's um could potentially be related to a terrorist or criminal organization.
▶ 0:44:52So I think that we as we're talking through solutions here there are a lot of technical recommendations which certainly Palo Alto networks would provide about hey greater capabilities in the hands of the victims so that they can get answers quickly.
▶ 0:45:07Um, but there's also the component of it of what can we do from a government lens of making sure that we're providing as much support possible to the victims so that we don't expect a small to medium business to um effectively to use, you know, your terminology go up against some of the greatest military capability that our foreign adversaries have to offer. Yeah. I I'm gonna ask I'm going to go from the 100,000 foot down to like Mr.
▶ 0:45:36cable, you talked about secure by design. Uh, and I, this is more at the tactical level and your company, if I understand it correctly, is out there trying to help other developers develop their products secure from the beginning. The the whole point of the reversing of the economic model, um, one of the questions I ask is I'm a physician. I ran a healthcare company.
▶ 0:46:02If I developed a medical device that looked really great, we we put it in 200,000 people and then it turns out to be faulty and it harms those individuals, I'm done.
▶ 0:46:17I've lost everything and uh my company's going to pay a big price, probably go out of Why is it that a software company that can put an app out there that has a vulnerability in it, no big deal? How is that fair? Can you explain something? Thank you, chairman, for the question to your point that this isn't fair.
▶ 0:46:45And to to build on what Miss Whitmore was saying, this is not a fair fight. If we look to the small businesses, the hospitals, these school systems who have been facing these attacks, whether they're ransomware attacks, whether they're SP state sponsored actors, this is not a fair fight. We cannot rely on these underresourced organizations to be able to defend against sophisticated cyber criminals and nation state threats.
▶ 0:47:12really we need to to your point take a step back and look at the security of the technology that is underpinning our critical infrastructure. The fact is that today in many ways we are leaving our doors open to our nation's adversaries. They are able to compromise our critical infrastructure through relatively simple preventable vulnerabilities in software products and the software companies are not incentivized or or held responsible for these vulnerabilities.
▶ 0:47:40At SISA, we worked to advocate for software companies to both voluntarily increase their security through the secure by design pledge with um both Google and parallel to networks for instance are signitories of we worked to make sure that companies were really pushing to the cutting edge and taking actions like reducing entire classes of vulnerabilities from their products.
▶ 0:48:03I am generally optimistic that we can root out these vulnerabilities from our software products, but this is going to take time and it's really going to take shifting incentives. So there's, I think, good room to be had for discussions around what I mentioned with secure by demand, getting private companies, getting the government to start to demand better security practices from software suppliers.
▶ 0:48:25But I do also think we need to consider a software liability regime by which manufacturers of software products are held accountable for preventable vulnerabilities in those products and and of course that we give sufficient safe harbor protections to ensure that there's a bar that software manufacturers can meet. Well, I appreciate your answer on that because that's it's a tough one.
▶ 0:48:44I you I talked to uh some of the biggest companies in the world that that makes both hardware, software, operating systems, all the the whole gamut. Uh, and it nobody wants to be they don't want product liability, you know. So, um, being a military I'm gonna ask one more question, then I'll turn it over to go. Um, we had a military guy, I think, uh, I think courses of action, right?
▶ 0:49:12And three military folks and a guy who worked in the government. So, you probably have heard that term before. Courses of action. What are the course of action? So, you look at a ransomware attack, for example. you know, if we're going to come up with solutions to how do we stop this stuff, we have to have courses of action.
▶ 0:49:27On extreme, when I've heard, which on the surface sounds sort of anti-Republican, anti-private sector, anti but on some level makes some sense to me is just outlaw the payment of a ransomware. A couple people get hit at the beginning. There's some cost of those entities because their systems are maybe we have a fund that can help cover that, but at some point the bad guys aren't going to get paid.
▶ 0:49:57They know they're not going to get paid and that would be ultimate deterrence for ransomware. What are your thoughts, Miss I I do not think it would be effective to outlaw um the payment, but I wanted to go to to your point on deterrence. Not not that. Let me make sure I I got this. Not to outlaw ransomware. Payments. Oh, you can outlawware.
▶ 0:50:22Outlaw payments of ransomware because you can outlaw drugs and they they're everywhere, right? It's ubiquitous. But I So, but I mean to outlaw the payments. The payments. Yeah. I I we should look at and and dis discuss it some more. Um for sure. But my I think it's a it's just such a complicated space right now. um and you run into scenarios where you potentially have life and safety issues without that payment.
▶ 0:50:51So there's there's lots of ways things that you would want to take into consideration. Sure. It's it's it's worth considering the continuing that conversation though. I on the higher level when you you talked about deterrence um and it's something that I've thought about a lot and we thought about as a company too is I I think that there's there's a couple of different elements of thinking about deterrence and often times they get um conflated when we're talking about cyber security and
▶ 0:51:21and you know when you're thinking about and people say deterrence by denial right you know make our defense excellent so they can't get through um and that is a a real thing that we need to continue to invest in. But then you also talked about capability and wi and will um for not just that deterrence by denial, denying their ability to get into systems, denying an ability to take the actions that they are seeking to um but I would say there's also thinking about and and
▶ 0:51:51much more cleareyed the the risks that our country faces. So we need that stable baseline. We need to raise the level of security all over. Attackers are still taking advantage of very easily known um vulnerabilities that should be fixed and and I agree that both you know software vendors and others in the community there needs to be some accountability mechanisms in place to ensure that we're delivering secure and safe software and um and then of course accountability in place to make sure that people are using it correctly.
▶ 0:52:22Um, and so I'd say there's one effort that needs to be focused on how do we stop the the just the continued poor performance in known security issues. But then there's another effort which the JCDC played some part in this and I think can continue and SISA can continue to um lean in here is there are unique national risks that um impact certain sectors more than others and um and require a different set of capabilities
▶ 0:52:52and perhaps a smaller set of actors that have capabilities in the private sector and the government coming together to identify what is the threat. How are we going to counter that threat? Who has the capabilities to do that in a collective way? And that requires a new type of um public private partnership that is just as important as raising that baseline and making sure every small business has what they need.
▶ 0:53:17But we also need to be focused very much on reducing the consequences of the next time we find China or some other actor in these critical systems. And we need to be opening up that dialogue and that operational collaboration between the companies and the entities and the government to do much more work in reducing those national risks um for those foreign actors who would hold our country at risk. Yeah.
▶ 0:53:44I I'm going to make a quick comment and then I'm going to let Mr. Garberino have a couple of minutes. Um the uh you you said something there that was very interesting to me. next time we find China in the system, so to speak. And I this is something that's been a I I my staff will tell you they've been hearing me say this for years.
▶ 0:54:07It is unfair for the federal government to expect the private sector to defend itself against a nation state. We uh particularly my side of the aisle has pushed very hard about a sovereign border, having a sovereign border that needs to be protected and that the government has a responsibility to protect uh and and you know if if China were physically driving tanks across the southern border, that's exactly what the federal government would do would be to defend against that.
▶ 0:54:37But I would submit that there is a cyber border that's just as sovereign and we can't expect uh companies to defend themselves. And I I I think it's going to take a a paradigm shift because for decades we've taken this free market approach that private sector takes care of itself, government takes care of itself. And again, I just I think that's self-defeating because the networks are so connected now.
▶ 0:55:05Wherever a person enters, they can pretty much move laterally anywhere in networks. The government shares cloud space with companies at Amazon. So, um I just want to say that I couldn't agree with you more. I I I think and I want to reiterate this to whomever's paying attention. The federal government has a responsibility and we need to step up and partner and do it more. Do it more and better. Mr. Scarbarino, you're recognized.
▶ 0:55:37Thank you, Mr. Chairman. And as I wanted to jump in a couple times because I was writing down questions too based on some of their answers. If you hear something they they say, you please jump in. Um like I said, we have we have time and sure Mr. SW will come down. He's always got great questions too when we have committee. Um but you your first um thing you brought up about why don't people care more and I feel like I think it's because we haven't really felt pain in the country. there no cyber attack. People who've gotten individual hacks have felt it. You know, companies who've gotten ransomware, they've felt it.
▶ 0:56:07But, you know, I I went to Estonia. You uh you uh approved a trip for us to go a cyber trip to Estonia two years ago and uh they had the major cyber attacks I think back in 2007. Yeah. And uh they all take cyber security uh very seriously there. And now we haven't had that yet. Uh but for a few and again, but um we you know, we missed you know G there were gas lines on the east coast for a couple days. I mean, we haven't felt real pain. So, I think um that's a problem.
▶ 0:56:33I I really appreciate what we're doing here and and and our and the the witnesses they're doing here because we're trying to be preemptive and or proactive here and trying to fix something before we actually feel real pain. Um so, I do appreciate you all being here and Mr. Gab, I want to go back to something you said and talking about um designers accountable. How how would you because I love the idea of secure by design. I love the work that CISA did.
▶ 0:57:03I love the work that the the the all the companies that uh took that pledge. I think that's great. I think there should be there should be a you know a reliance when somebody buys something that there is at least some security especially when you're talking about whether it's a phone or a computer program or a computer whatever there should be some reliance that there is some security there um and that they can then they and they can depend on that uh without having to pay extra.
▶ 0:57:31Um but then you also have to go back and you have to weigh that against user error um or you I mean somebody clicks on something not supposed to click on it. That's yours is only as strong as your weakest link. So, you know, you can hold a a company accountable for its design and and um up to a point, I believe, but at some point it it it the balance tips and goes to well, yeah, but people are al automatically think, okay, this is secure. I can just do whatever I want.
▶ 0:58:00I still don't have to be I I I get to act. I mean, there still has to be some reliance on the individual. So how do we weigh that and how do you and who holds the companies accountable if we hold them accountable and how do you hold them accountable? Is it financial? What is it? And I'd love to hear from everybody on this actually. Thank you congressman for the question. I agree that there is a balance to be struck and this is an area that we focused on through the secure by design work at CISA. One aspect of secure by design we call it secure by default.
▶ 0:58:27This idea that the configuration out of the box of a software product should be a secure one. Just like when you buy a car and it comes with seat belts, airbags by default, you don't have to to pay extra for those. We should also expect that security features are really built into software products.
▶ 0:58:46In my opening statement, I mentioned the def example of a default password where there are still products on the market that come out with a default password and the expectation is that the end user of that product goes and changes the password. I'm sure we've all been there. We know that that doesn't always happen. And the question that we asked at CISA is why does that responsibility have to be on the end user?
▶ 0:59:10Why doesn't the manufacturer of the product as many do ship the product with say a random password so that it is more secure by default? So that's really what we're we're talking about when we mean secure by default. And I agree that there's an extent where users can go and change configurations and at some point it does go out of the manufacturer's control. But often what we're talking about aren't complicated scenarios.
▶ 0:59:33It's where a user takes the product out of the box, deploys it, and it's susceptible to some vulnerability that um is enabled by default. Um so so really when it comes to shifting incentives um to what I was saying earlier I I think it is essential to consider how we can help take this burden off of end users off of small businesses hospitals and others who really don't have the capacity nor should they uh to defend against these attacks
▶ 1:00:03and see how software manufacturers can assume more of this responsibility. That was a focus with the secure by design pledge where companies now over 300 companies who committed to that committed to taking action in areas like reducing default passwords across their products, increasing the use of multifactor authentication such as by enabling that by default which we know can prevent cyber attacks and reducing common classes of vulnerabilities.
▶ 1:00:28So I I think there's lots of areas and potential really for software manufacturers to innovate on the basis of security to compete based on that and I I encourage this committee to think about how it can help to shape some of those market but what's the incentive I mean does it is it the government pushing say okay these are all sec these have met the secure by design standard uh so what are we saying like okay in order for a financial institution to take part in the FDIC protection you have to have
▶ 1:00:58this I mean what's the incentive I mean is it are we is it carrot is it state I mean what what are we doing to make sure that these things and and please everybody jump in yeah one thing that I would note is I I think today when we look at the cyber security regulations and requirements those are almost always placed on the endusers of technology products it's requirements on financial companies or hospitals or others who who really kind of I think to the point of this discussion aren't the most resourced or the most
▶ 1:01:29um capable of applying those. Um and really where where I think we need to go is to look at okay, how can we help shift some of those requirements off of those least responsible off of those who really um are are no fit to to go up against a nation state and help to rebalance the the responsibilities so that they are placed on the the software manufacturers who are most capable and the best position to to bear that.
▶ 1:01:54So I think that could be done through the federal purchasing power, through private sector purchasing power, through uh software liability regime really with the end goal of not moving to an unreasonable standard but at least having some baseline by which we can make sure the software products we rely on throughout our critical infrastructure are more secure by design. Miss Vamper. Sure.
▶ 1:02:16And if and if I could I I agree and if I could add that um the the clarity of the standard and the requirement for transparency too right all it's security is very hard for um users customers and and so there's I do think there's incentives in the software industry to make security easier naturally but and um but we need to increase the demand for that and the federal government has an opportunity through their purchasing power to do that through standards,
▶ 1:02:47whether that's through certification regimes or or others. Um, but then also mandating uh transparency. And so, you know, at Google, we've been pushing things like um salsa, we call it salsa, um but where you have um artifacts that say this is how, you know, the the code was tested. So, you can see the provenence of the code and you can have a higher level of assurance of the integrity of that.
▶ 1:03:11making sure that there's, you know, every time you buy a microwave, right, you know that it's gone through testing and you understand and you may not know every single detail of what that testing was, but you know that it's received um a certification and it's been allowed to be to sold to you. And so there's there's more work that could be done there for sure in establishing what those baseline standards are and then and the federal government has a real opportunity to drive that um what those standards are, driving more certifications around it.
▶ 1:03:40But then I would just say there needs to be much more transparency and it needs to be just easier for a procurement official um for that end user to be able to understand what they're buying and that it that it's clear how it's meeting their security requirements. So the government also has an obligation to set I would say clearer security standards that are more consistent across the government. Those are all opportunities I think that uh all companies uh would would welcome that that participation with the government on.
▶ 1:04:10Any other any other addition that just a just a quick comment because uh this goes to chairman Gre's comment earlier about about how so much of our tax service is in in the dot and in the in the in the uh in the public sector rather than in the government sector. I think there should be a convergence of standards between.gov and and uh and com. uh all companies should strive for that.
▶ 1:04:32I think there are also some best practices that should that should be followed that that everybody should share with one another as we create this community of of of really companies or anybody who touches critical infrastructure with their products.
▶ 1:04:44And that's kind of a holistic approach to security involving we're talking a lot about, you know, about it, but it's OT, it's it's hardware, it's supply chain, and then it won't be until we're all together on these standards that you can really reduce what is really critical, which is that third party risk, you know, which we've seen really go through the roof in recent in recent years uh in terms of uh software and and supply chains that can have a devastating effect if if uh if they're compromised.
▶ 1:05:11And I think that uh what's really key and what I think what we're talking about I'd love to hear the fellow panelist thoughts about this. There is a tension between setting a standard and holding companies accountable for it and not treating the company like a victim because you want them to report and really what you want is the government and that company to be working together when something bad happens. And overall I mean companies I think have to kind of adopt the attitude of try to envision like what we do do in the military. what's the worst thing that could happen to you, right?
▶ 1:05:41And then and then take action to prevent that, right? What you would do the day after a massive attack is what you should do right now, you know, and and uh and so I think how to think about these complex challenges and then the melding together of of.gov and.com standards and this holistic approach to security which I would say and I mentioned in the statement for the record includes not just you know threats in cyerspace but insider threats as well because you know the CCP I mean you close the front door they're coming through the window if you know
▶ 1:06:11you put bars on the window they're they're putting a ladder to the second floor you close that down they're tunneling into your basement and they will do it in the physical world uh through espionage as well as in cyerspace I I I certainly agree with so much of the commentary that you know my fellow witnesses have shared uh and PaloAlto Networks is strong supporter and signatory of secure by design as well and I think something that has been resonating here is just how challenging it is to maintain visibility
▶ 1:06:41into the attack surface as it continues to expand. Um, so we're looking at supply chain vulnerabilities, right? Really figuring out how do we manage every single software provider that anyone in the organization may have procured software through. That's very challenging.
▶ 1:06:56I think we need to continue and further dis the discussion to secure AI by design because we are very concerned that as we move forward to more organizations uh just really ubiquitously deploying AI that we are going to have an even larger expanded attack surface and more of these challenges.
▶ 1:07:14So that's my I mean mind chairman that's my follow-up question I mean because we talked about I secure by design um I've heard it multiple times now um specifically you know when it comes to legislation you know we're looking at how to regulate and you just talked about a study that said 40% of code written by AI is coming up with vulnerabilities or could have vulnerabilities um you know when we write when government takes action doing uh you know zoning they look at a environmental study.
▶ 1:07:44You know, they look at the effects uh as on out on they look at the effects of what the project will do. You know, we're looking at regulating AI and and it's now been brought up to me twice in the last week how nobody's looking at the nobody's doing a cyber security review of what what Congress is contemplating when we're talking about regulating AI. And I'm and that sounds like that's what you're all talking about here. this nobody's looking at whether the AI product is going to have data protections or or cyber security built into it.
▶ 1:08:14So I'd love to hear more of your thoughts about how you know everything we have now is it's out there you know secure by design got to go back and fix it. AI is still being developed. So what do we do? Um Miss Ber can I just defer to my panelists on that because washed up general shouldn't be talking about all this technology. I I will tell I will I will say quickly though there's going to be a tension between rapid model uh adoption uh and whatever kind of security protocol we put into place.
▶ 1:08:42We still have we have the best AI models from what I learned from people who know this business. But the the the friction and the difficulty is in is is in uh adopting those models and what the CCP's advantage is is that they can adopt those models much more quickly than we can. So I would just say whatever we do maybe think in terms of incentivizing the kind of security uh but but not delaying the adoption of these models. Thank you.
▶ 1:09:07That's really well said and I'll maybe I'll kick it off here is on the one hand we have to recognize that there's competition and we want um American companies and American economic uh leadership in AI. And so we have to ensure that that is continued to in be incentivized. And at the same time AI has a lot of potential for improving our cyber security capabilities.
▶ 1:09:33There's a tremendous amount of noise that cyber security defenders have to deal with. I think you talked about this a lot. And so using AI to be able to help them sift that signal out of the noise. um we have security operators that spend lots of time doing things that could be automated instead of you know taking that to the next level of critical thinking of what could be done. So there's a lot of opportunity with AI to improve security.
▶ 1:10:00What I would just offer is um so at at Google we've um put out we call secure AI framework which was um based off of our own internal work in both leveraging AI for ourselves um but also understanding and learning a lot of lessons about securing AI.
▶ 1:10:17So, we've we've put that out and we're working and built a coalition with a lot of other companies um for the use of secure AI in open-sourcing solutions to help organizations protect against some unique areas of AI that sometimes cross over also into safe use of AI. Recognize that a lot of AI security is still the same security. You still need to do the same things that need to do in general, but there are some novel things um for AI.
▶ 1:10:44So, I'd offer that the um the work that the coalition is doing and some of the standards that try attempting to drive through um Oasis and other foundations might be a good place to start if you're thinking about what those standards should look like for AI. I would uh first like to start by really echoing Miss Manford's comments that AI is enabling tremendous innovation. We're here at Stanford. This hearing is on innovation. We're here in Silicon Valley.
▶ 1:11:12I I live in San Francisco and see every day how AI, let's focus for instance in the role of writing software is vastly changing how that looks. I think we can reasonably expect if not today that within one or two years AI will be writing the vast majority of code that is in use. We can see how AI can accelerate building software for cyber security products. We're doing some of that ourselves, but also for scientific discoveries and many other fields.
▶ 1:11:40And I think this unlocks a lot of new exciting possibilities. But um to the discussion here, we do have to recognize that much like humans writing code can introduce vulnerabilities, so can AI. And I think we have a really great opportunity to get in at the start at the point when these models are being trained at the point where these tools are just starting to take off and build safeguards in place.
▶ 1:12:05So I think for instance we're focusing um particularly on the case of helping secure as companies are adopting AI for writing code and enabling them to write code 5 10 many times faster to have some guardrails in place to Miss Manford's point um both in terms of the security of AI systems but also the vulnerabilities that AI can introduce the vast majority of the time this isn't going to be anything new it's going to be the same classes of vulnerabilities that we've
▶ 1:12:35known about for decades, we've been struggling with for decades and yet we've known how to prevent them at scale. So I think this gives us a really great opportunity to begin to put some of the actions that for instance Google, other companies have really pioneered to root out entire classes of vulnerabilities and make sure that AI is designing software that is secure by design and is more resilient to these attacks from our adversaries. Back. Gentleman yields. Uh, I now recognize Mr.
▶ 1:13:04Swallwell for his time and questioning and we're not really keeping a clock, Eric, so take take all time you need. Well, Mr. Cable, you mentioned that, you know, we are obviously at Stanford, your alma mater and general, I think you're affiliated now uh with this great institution.
▶ 1:13:22uh could you speak to the role that the federal support for technology has had on cyber security innovation particularly as it relates to academic research and if anyone else wants to add to that. Well obviously the research programs in our universities have been one of our greatest competitive advantages uh our ability to develop technologies but then spin those technologies out so entrepreneurs can take those technologies and and and put them into action.
▶ 1:13:51uh in in terms of real capabilities that give us our greatest differential advantage. It's our innovation and then our ability to combine that innovation with our unbridled entrepreneurship and and so the universities enable our free market advantages. The other critical aspect of it is the the development of of human capital. And I think one of the most disappointing things that that we've seen uh recently is the degree to which we've lost a lot of critical expertise within the government.
▶ 1:14:19Expertise that was developed in institutions like this that was serving with great distinction in in the government. Mr. Cable uh mentioned this me mentioned this already. uh but then also where there is a tremendous opportunity here in in the academy uh is to attract the the best talent from within our country certainly but internationally as well. So the impediments we've seen to to bringing in you know the best minds to and and then to to uh provide them with the kind of education that can help give us a differential advantage.
▶ 1:14:47And then of course the other part of that is uh is the visa process and and immigration reform that would allow us to to take advantage of I think you know nobody's trying to immigrate to China right so so this is one of our greatest competitive advantages so I'm concerned of course there are a lot of efficiencies to be gained probably in academia in research you know maybe too much overhead uh I think there's reform is necessary but but certainly we don't want to give up that differential advantage in human capital uh technology and innovation Yeah,
▶ 1:15:17thank you. Well said. Anyone else want to add to that? I have a practical question. As a a parent to an 8-year-old, a six-year-old, and a three-year-old, um when should our children start to be taught AI? And are you thinking about this as an industry as you prepare for the workforce? Because I think the general is right.
▶ 1:15:38We want to attract the best and brightest around the world, but I still want to look my constituents in the eyes and say, I'm doing everything to make sure that your own kid is going to have the best shot to compete for that job as well. So, like when when should we start to prepare our kids to use it? I can start as the mother of a 13-year-old.
▶ 1:15:58Um I think uh I believe the approach to technology and and cyber security in in general is early awareness and um and of course you know you you have to moderate you know within your own sort of risk construct of um the level of engagement that you allow the the young children to have. But helping them understand um how they keep their information private, how these systems work.
▶ 1:16:26um so it's not just a black box for them is is really important. Um and and also allowing them to um learn about AI and what AI can offer them um and but understand um and I think children at a pretty young age um can can understand some of these complexities but helping them see both the benefits and the cons I think is is really important. Um so that's my personal experience on the Google side.
▶ 1:16:54Um, we invest a lot in educating um and um in really trying to raise that next generation of um computer scientists and security engineers um all the way from elementary school through through college. And so I absolutely believe it's really important. Yeah. I don't know if you're like me, but I get fact checked by Alexa like four times a day by my eight-year-old. Yeah. I just have he'll ask me something and he'll he'll compare Alexa's answer to Yeah. I tell him that he can do it as long as it's Gemini. Yeah. Right.
▶ 1:17:25Right. Mr. Cable, I would agree with that and I would really add that at at the core to a lot of this is this idea of digital literacy and I think um in addition to understanding AI for instance, I I think it is going to be more important than ever that uh children understand the basics of areas like computer science and can really begin to know how these systems work so so that they're um able to to navigate them.
▶ 1:17:53I myself start coding when I was 11 and really um had a journey teaching myself how to build websites and apps and saw a lot of the potential in in computer science. Uh to Miss Manfred's point, I I think there's also a critical area where we need to pay attention to our current and future software developers.
▶ 1:18:14Um, one area that that I'll note, and I saw this when I was an undergrad here at Stanford, is that across the top 20 universities in computer science today in America, not one of them requires students who are getting a computer science degree to take a security course or to learn about security.
▶ 1:18:31If we think about security being really core to the the future of software development, as we've discussed in this hearing today, I think it's essential that current and future software developers know a thing or two about security, much like we would expect, say civil engineers to understand how to ensure that that bridges can be built securely.
▶ 1:18:51So I would encourage this committee to explore how we can really make sure that computer scientists are considered a core part of the software and cyber workforce and to ensure that they have a baseline understanding of security. Great. And to all of the witnesses, what is your assessment of the current state of preparedness in the US for quantum threats and how can we expedite efforts to prepare for quantum computing particularly h as it would relate to, you know, decrypting our data?
▶ 1:19:27I don't know. I mean, maybe just a general comment. uh you know China is is uh attempting to surpass us in in in quantum technologies. Uh you may you may say they've already done that in capacity but not yet in capability. So uh obviously it's very important for us to invest in it because we can use those same kind of capabilities to defeat the encryption. Uh and so I but I'll turn it over to the real experts here.
▶ 1:19:52I will not pretend to be an expert in quantum computing but what I can say is um well I guess how is Google preparing for there is there is a need for people to take this more seriously um there's um the the postquantum crypto um world is is going to be very real soon um if I recall correctly the um NIST NSA timelines to nav to make sure that you've adopted postquantum in crypto
▶ 1:20:22is 2035 I believe. Um and I still think that is a good target. Um Google has been investing a ton in um both postquantum cryptography capabilities but also quantum computing. Um we just released a paper uh a couple days ago about this. Um the thing though is people think well that's 10 years away. Um but it takes a while to implement these capabilities.
▶ 1:20:47And so I would just encourage organizations in this committee as you're looking at this is it's not just something that's an organization can figure out in six months and we they need to be taking it seriously. They need to understand um what their capabilities are. Um we've been working on it in implementing um postquantum crypto capabilities for a few years now um including in our internal communications.
▶ 1:21:12We do have some capabilities that we offer customers as well, but that I I would say hard to make a broad estimate on um preparedness. Um but I I would say generally or we do need to take it more seriously as a community. Okay. I'd echo Miss Manfred's comments just in terms of Palo Alto Networks. Our approach uh has also been for years being concerned about what happens with postquantum ability to decrypt information that today is protected.
▶ 1:21:40And so uh we've focused on that particularly with our network security products as well as our endpoint security products uh that today uh you know are able to withstand what we believe to be uh you know postquantum attacks moving forward and then also offer some options for our clients as well to help them implement those strategies. Um but it you couldn't have said it better I think in terms of the 2035 deadline I think is far uh you know too distant in the future.
▶ 1:22:07I think we need as a government in particular to be attacking that is if it's more near-term. Great. Thank you. And and Miss Whitmer, you had mentioned uh support for the JCTC bill that the chairman and I uh were able to pass together out of the committee last year. Can you speak also uh Miss Man for both of your companies are a part of JCDC.
▶ 1:22:31Can you just speak to like any reforms that you would like to see or you know what we could do to make it more agile and you know a better neighborhood watch like program?
▶ 1:22:45I I think uh your earlier congre uh comments uh commented on the need for you know a very effective two-way street and when we see information sharing of any kind whether it's public between public and private partners or uh smaller industry-ledd groups the challenge is oftentimes there's organizations who provide a lot of information and then organizations who don't share as much and the uh you know information in those type of settings is only as effective at it as it is incredibly actionable.
▶ 1:23:15and contextualized and timely. And so I think the need to further encourage that effective sharing as you know on two-way street and make sure that from the timeliness perspective the types of data we're focusing on are going to drive the outcomes we're looking for. Thank you. I would agree.
▶ 1:23:35I would I would add that it's it's a real opportunity to focus on, you know, we've been talking a lot about baseline standards and raising the baseline, but there's this other really important area of the the sectors and the, you know, that higher level threat.
▶ 1:23:50And so SISA, I think, has a real opportunity to deeply understand national risk and using the JCDC to bring those private sector and government entities together that have unique capabilities to um to reduce those those risks. I think needing it's important to be very focused, right? And we talk a lot about information sharing, but information sharing for what purpose and just generally reducing cyber risk is is too broad.
▶ 1:24:18And um and so what specifically are we focused on? What specific threat are we working to um reduce the risk of? Which sector are we focused on? There's a lot of companies participating that have a lot of amazing intelligence. Um and you know the government brings a lot of amazing intelligence. And so how do we focus that work more on disrupting those highest threats and reducing those most significant risks to the country? I think that's an really big area they could focus on. Great. Thank you, chairman. I yield back.
▶ 1:24:47So I I I know there are probably some other questions. You have a few and uh Mr. Swallowwell may generate one or two as we're continuing. I did want to say a couple of things and and had a question. Um I'll let Mr. Garberino ask one or two and then if you if one pops up um we have some time. Y'all doing okay? Anybody need a break? All right.
▶ 1:25:14Um, you know, we we talk about this economic model and I mentioned it where where we we talked about the victim versus the villain and there being a very low cost of entry for the villain and a very high cost. Uh, I think there's another economic model and that is that first to market which results in vulnerabilities and and I get the competitive advantage of first to market.
▶ 1:25:39I ran a healthcare company and u you know always wanted to beat my competitor market because it it did give you a financial advantage but I'm just making an observation here. This is something that we have to figure out and I do think liability has to play a role in it and I I you know here I am an an ER physician suggesting that liability is a good thing.
▶ 1:26:05Um my uh lawyer buddies are all um their jaws are on the on the floor. But no, I do believe that it is it is the path or a path certainly a course of action that we have to consider. One of the questions that I that kind of came to my mind as I'm listening to the witnesses and we've got this u incredible panel here uh someone from academia now and uh but who spent a lot of time in the military.
▶ 1:26:32We've got two of our nation's greatest companies. I mean, really, we've got a startup, a guy who was in government who's now starting up, a young entrepreneur who So, the question comes to mind about education and the talent pipeline. And I my my question is, you know, we train cyber folks in the military.
▶ 1:26:57I think you helped uh if I remember this correctly start Army Futures Command and get all that going. We educate cyber professionals in the civilian sector. We educate cyber professionals. You know, in the in the military to get people excited about the military, we have these these simulators that go around and you got a young 12-year-old who hops in and flies an Apache helicopter. It's the coolest thing. Gets them excited at a very young age.
▶ 1:27:23You know, what are some ideas on how we can do that for the cyber space and how can we collaborate on military education in cyber, our military guys and our academic centers in preparing sort of this workforce of the future for cyber and and you know anybody all of you uh feel free to to answer. So one recruiting and two how do we work together to collaborate to get get to where we need to go?
▶ 1:27:51I'm happy to to kick this off. Um and thank you chairman for the question. I would maybe start with um to your point that it's not just about the the victims or the the villains, but really that the the vendors, the manufacturers of software products have a key role to play here. And I think we can extend that to the cyber workforce, recognizing that cyber security professionals alone aren't going to be able to solve the cyber security problems of today.
▶ 1:28:20And that's because we really need to work back to the point where software is developed. So where I was saying earlier that we need to ensure that every current and future software developer has a solid understanding of the security baseline um and knows particularly as they're using more and more AI tools, writing less code themselves and more so instructing AI assistants to write code that they know how to identify vulnerabilities and to produce more
▶ 1:28:50secure software. But that's also an area where technology can help and that we can leverage artificial intelligence for instance to help educate software developers to help flag security issues as they pop up and and make sure that ultimately we can really build products that are more secure by design. I've seen firsthand the impact that um really real world experience can have when it comes to getting into cyber security.
▶ 1:29:17I when I was 15 found my first vulnerability in a bug bounty program participated in many more had reported vulnerabilities to to companies like Google and there's many companies out there today that embrace security researchers with open arms the US government does as well that's how I found my path into working in the US government after placing first in the hack the air force competition so I think we really need to build up more of these initiatives as well to get young people excited to get young people participating.
▶ 1:29:48When I came to Stanford my freshman year, I helped create a bug bounty for Stanford and then spent the following several years identifying vulnerabilities in Stanford systems. So, the more we can do to really give young people hands-on experience and cool technical challenges, I think we can really motivate people to join the cyber world. I hope they reduced your tuition for that. It certainly helped. Yeah. Good. I think that's that's so well said.
▶ 1:30:13And I would I would also just add that I think Google has proven that you don't have to sacrifice velocity for security. And and so it's to what Mr. Cable was saying, a lot of this comes back to do the software developers have the tools and the practices built that allows them to code in a secure way.
▶ 1:30:37Do you have, you know, do you make security hard uh for your developers uh and your users or do you um innovate in tools and capabilities that make it a pleasure to develop on your system in addition to it being secure and reliable and and so I think we need to be looking at more of those instead of um continuing in these sort of false choices that you have to either have velocity or security and um it it does take a different mindset um and sometimes that might need to be imposed externally.
▶ 1:31:07internally um on organizations but I I absolutely think it's possible on the other side on on the workforce I think there's both developing a workforce of um individuals who are going to be focused on cyber security absolutely and entice them into the government um for as long as as long as we can keep them there government's got so many interesting problems that people can't find outside in the private sector so I think there's a lot of opportunities to do that and continue to invest there but I would also say we
▶ 1:31:37shouldn't just focus on um teaching cyber to cyber professionals. Uh lawyers need to understand it, doctors need to understand it, uh teachers need to understand it. And so building more interdisciplinary programs um organizations like Stanford and others throughout the country are doing this. But bringing people together so that a lawyer can understand the technical aspects of a situation in cyber security, an engineer can understand even potentially some of the legal aspects.
▶ 1:32:03So cyber security I think is a really um important from an interdisciplinary perspective um and being able to bring these different disciplines uh together um whether that's an anthropologist we've hired anthropologists who bring like an amazing viewpoint into this area um or making sure our engineers understand secure coding practices. I think there's lots of opportunities in that space as well.
▶ 1:32:27you you generated a a thought and I don't know maybe this is what you were saying and I just thought it was novel in my brain but um you know we have history 101 when you go to college yes it's a required I mean most colleges required but there there is a required basic curriculum to get an undergraduate degree at just about every university I mean why not a cyber 101 as a part of the required curriculum at university if you're going to school here you're you know you're going to take cyber 101 I Yeah,
▶ 1:32:57I I I certainly second or third the commentary that's that's been said. I think it's critical that we continue to work with universities to shift the curriculum. Mr. Cable mentioned that uh you know just as recently as when he had received a computer science degree security classes weren't mandatory.
▶ 1:33:13Um I personally work with both Duke University as well as University of San Diego um which was my undergraduate alma mater uh in their computer security programs and so we are actively shifting a lot of the curriculum to ensure that those programs in ensure uh include security. I think the cross-disciplinary commentary uh is critical. It's certainly critical in business when we see uh you know these attacks occur. Uh I think too we've got to make it easier for people to cross trainin into this work.
▶ 1:33:42So the cyber pivot act is a great example of that where you're not just looking at traditional four-year degrees but shortening those time frames. Three, I think we must create competition. Uh and that's not just uh you know college competitions or hack the air force which are great but you know our adversaries are creating uh elementary school competitions where uh cyber competitions are as critical as uh you know ice skating and football is. And so I think that's an area that we really need to look at bringing uh into.
▶ 1:34:12And then fourth I think is with technology. I don't think it's u the right approach is going to be for us to only look at this as a people workforce challenge. We've got to be able to leverage technology and in particular AI to start closing that gap in order to make uh you know one the work that people are doing really make them feel like they're having more of an impact.
▶ 1:34:32We're taking away some of the repetitive tasks that drive people out of the career field and creating new opportunities to have General, I don't know if you want to comment on collaborating military and uh civilian universities together on this issue, but that's the one piece of this that hasn't been commented on. Yeah. Hey, thank you, Mr. Chairman.
▶ 1:34:53I would you when I first arrived here in 2018 uh just having left uh Washington um I was struck by the degree to which there was a degree of suspicion really almost between the you know the public sector and and and the private sector.
▶ 1:35:08uh it was the post Snowden kind of hangover and and uh and Raj Shaw and Amy Ziggart and I put together what we called a tech track 2 dialogue which is now going strong and I've seen a tremendous shift in attitude uh I think maybe almost especially after the massive reinvasion of Ukraine in uh in in 2022 recognition that that there are really still you know real threats in the world we have to be concerned about and and so the attitude I think is right to maybe uh to to maybe take this to the next level.
▶ 1:35:37one of our first TechTrack 2 dialogues, we focused on getting pledges from the private sector and from the military services to vastly increase their exchanges. That happened and I think that momentum has continued. I think what the Trump administration is doing now and the Department of Defense to make it easier for people who have these extraordinary capabilities to get direct commissions uh in in in our services and and contribute continue to contribute to their companies but also contribute uh to security within government.
▶ 1:36:06But of course, we still need really some of our best people, you know, in in government, and we have them already. I I'm I'm concerned about sort of this shift uh in in a perception of service that like it's not quite as hip as being, you know, out here in Silicon Valley. Well, you know, actually the real hard problems, a lot of the real hard problems are in government and and it's exciting and challenging.
▶ 1:36:29So, I think what we have to do is talk to our young people about the tremendous rewards of service and then make that gateway easier with internships, which you I encourage our students here uh to engage in. Many of them have done that. many of them are now working for the government in many capacities and self-actualizing and and feeling like they're making a contribution. So, it's internships, exchanges, these are things we can measure. But also, I think the the military model of the reserves is really critical here.
▶ 1:36:57We've seen this happen now in terms of our cyber capabilities within cyber units. One of them is at Moffett Field right here. and it allows some of our top people to also contribute in in uniform and then to go back to their to their private sector. So, I feel good about that. There is a there are a number of programs here that I've highlighted uh in inside of our my uh statement for the record so I won't go through all the details or I mentioned Tech Track 2.
▶ 1:37:24There's also a tech policy accelerator here at the Hoover Institution where we are bringing together government, private sector and and figuring out these policy solutions, recommending them. I hope that you'll you'll consider us an extension of or your staffers will you'll consider us an extension of of of your staff and and we we want to help with this.
▶ 1:37:44Also in terms of educating people, there's the Stanford emerging technology review which is meant to make the critical technologies many of which we're talking about here accessible to the American public. And then in the area of education, I'll provide I'll provide you uh uh some some uh examples of you know because education our country is very very decentralized. There are some really best practices on getting young people uh involved in and educated in in this area of cyber security.
▶ 1:38:15Many of them are feeding high school graduates like in the San Jose area directly into into companies here in Silicon Valley and uh and uh and so I I feel optimistic about it. I think everybody wants this to work. And then and then the last comment I would make is on on education and uh Mr. Garbino mentioned already, Congressman Garbino mentioned already uh his trip to Estonia. This whole idea of like the digital citizen. It's tough.
▶ 1:38:40I mean, Estonia is a pretty small country compared to ours, but I think but there are best practices there that I think could be scaled up as well. thank you. Chairman, um General, I wanted to ask you, you were national security adviser back in 2017 2018. I don't I know you can can't get into specifics, but can you talk about the benefits of the Cyber Information Sharing Act of 2015 and and um and why it why you think it's probably necessary that it gets renewed um just the importance of that collaboration.
▶ 1:39:11Yes, it's it's vitally important. I mean, there's no way as we already mentioned, you can't have all this expertise in in house across the private sector and all these companies that touch uh that touch critical infrastructure. It's important that when there are breaches of security that our government is aware of those immediately so we can work together not only to you know to spread the warning about that but to help develop the those solutions. So I think that's was extremely important development.
▶ 1:39:34I would also say in that same period 2017 to 2018, we made we made some adjustments which I think really helped us tremendously along with inspired leadership at NSA under uh General Nakason uh to be much more responsive in recognizing that a good defense requires a good offense.
▶ 1:39:53And so whereas our private sector companies, hey, we can defend all day, you know, uh but even if you have the best layer defense, if you've got, you know, the the, you know, the the uh you know, least privilege uh in place, if you're if you're if you're in security by design, they're still going to get at you somehow. So every good defense yet has to allow you to shoot down the arrows coming at your service area, but also to go in and kill the archer. And you can only really get help in doing that by a good partnership uh and reporting.
▶ 1:40:23uh between the the uh the public sector and and the private sector. Yeah. And if any of the other w if any of the other witnesses want to talk about the importance of CISA 2015 being renewed um reauthorized that uh it's great to have it for the record so when we go to do it we have all these people saying wonderful things. I I would certainly agree.
▶ 1:40:42Speaking from my time at SISA, I can attest to the importance of making sure that the private sector can collaborate closely with SISA and protections like in SISA 2015 are essential in making sure that private companies uh feel comfortable providing that information. Uh one of these initiatives that that I'll mention is the pre-ransomware notification initiative that I had the privilege to assist with when I was at SISA.
▶ 1:41:07That's one instance where security researchers are sharing tips with SISA of impending ransomware attacks such that SISA can notify critical infrastructure owners and operators ahead of those attacks to prevent them from occurring.
▶ 1:41:22SISA has prevented thousands of incidents through the pre-ransomware notification initiative and this really is only possible due to the trust that SISA has built with security researchers with private companies and is enabled by acts like the the SISA 2015. So, so I do believe that it's essential that that this gets renewed. Great. I do have a follow-up question for you, Miss Aner, but if you all want to talk about CISA real quick, that's fine.
▶ 1:41:48Just join and say I agree that it's important to reauthorize And also for the record, Palo Alto Networks is supportive of CISA 2015 as well. Wonderful. And um the second part of our title of the hearing was streamline compliance. And uh Manfer, you brought it up in your opening um testimony about uh compliance reciprocity. And I really what did you I mean what do you mean by that? Um because it's something that the committee and the chairman has been great.
▶ 1:42:17I think he's got the whole committee working on a uh a compliance uh a regulatory compliance memo that's going to be released hopefully soon. But uh it's been a big focus of of the committees for harmonization harmonization. Harmonization. Yeah. Harmonization, but it's still part of the So, yeah. Well, absolutely. So, from a harmonization perspective on the regulatory side, um both, you know, for for what we see and for for our customers, um it is a complicated area that people have to operate in.
▶ 1:42:46Um and so being clear on you know thresholds and requirements and making those common as much as possible and then having that common standard is important. The specific thing that you were asking about with the reciprocity is ensuring that if you know you have programs like fed ramp certification regimes for civilian you have DoD in their impact levels um and other emerging certifications. We want to make sure that there's reciprocity.
▶ 1:43:14it is a fair amount of investment for companies to go through these processes and um and so you want to make sure that if you go through one and it's the same standard that that is then recognized by those other programs. That's what I was referring to. Okay. Very cool. Thank you very much. Y back chairman. Well, I uh deeply appreciate all of you for coming today.
▶ 1:43:34um you know the unipolar moment is gone and uh we sit in about a battle between you know two countries really but I mean there are other players that are very important but um and it's I think it's about three things I think I think it's about talent management I mean if you go and study confucianism neo confucutionism and SunSu and all that I mean they had these tests for government service And it's all
▶ 1:44:04about talent management for us. It's talent management and the cyerspace is really really that's very important. It's also about alliances and friends when the world becomes a bipolar world and we have a lot of work to do there. Um and we have to be very careful about some of the things that we're doing in that regard. Um and then it's about our economy and how we make our economy powerful.
▶ 1:44:30can't buy tanks and you buy tanks with GDP and so you know how we spend and how we work as a government all these things are very very important we're doing our best to juggle all of these balls and keep government out of the way and and partner where we can but in the in the in this space in the cyber space um I'm I'm very focused on harmonizing and getting government out of the way u and getting to a vision
▶ 1:45:00where compliance is really done in real time with AI and no human has to put a single effort toward it because companies like y'alls can do it for us instantaneously. Uh and um all that effort and energy in the private sector going toward checking the box goes toward real cyber security and protecting those entities. So that's something that I'm very passionate about and all these other things we've talked about today.
▶ 1:45:29So again, thank you. What we're going to do now is uh take a break and I know there are probably folks in the room who will be joining us for the next phase of this. But the next phase is really about the you know critical components to so that we can develop courses of action. What can we do? Do we want to outlaw ransomware payments?
▶ 1:45:55I mean, I threw that out there not because I was convinced that's the right thing to do, but I mean, we have to have these dialogues when we sit down and war plan a battle, whether it's taking a hill or, you know, destroying a bridge or denying an enemy this, we sit down and we just brainstorm. I mean, that's what course of action development is. It's it's what could we possibly do? And that's what I hope to do in the next section is sit down and ask some hard questions. What should compliance really look like?
▶ 1:46:24what should we not be worried about? Um, and things like that. So, I'm hopeful that our next session will will walk away with action steps for for us and for yourselves. So, again, thank you for being here today. The committee now stands adjourned.