Innovation Nation: Leveraging Technology to Secure Cyberspace and Streamline Compliance

US-China Technology CompetitionHouse Homeland Security · 2025-05-28 · 119th Congress
The House Homeland Security Committee held this field hearing at the Hoover Institution at Stanford to examine how to rebalance the economic incentives of cyber security in favor of defenders, streamline overlapping compliance regulations, and leverage private-sector innovation against nation-state threats. Begins at 0:06:11
Transcript
Highlights

Title

Cyber security economic incentives, secure-by-design, and regulatory harmonization

Purpose

The House Homeland Security Committee held this field hearing at the Hoover Institution at Stanford to examine how to rebalance the economic incentives of cyber security in favor of defenders, streamline overlapping compliance regulations, and leverage private-sector innovation against nation-state threats. Chairman Mark Green and Cybersecurity Subcommittee Chairman Andrew Garbarino led the session with witnesses from the Hoover Institution, Palo Alto Networks, Google Cloud, and the security startup Corridor, focusing on Salt Typhoon and Volt Typhoon intrusions, secure-by-design software, AI adoption, and reauthorization of the Cybersecurity Information Sharing Act of 2015. Begins at0:06:11

Who spoke

Chairman Mark Green (R-TN)0:06:11: Opened by framing the hearing around fixing cyber security's economic model, citing IBM's $4.9 million average data-breach cost in 20240:08:56; later compared China's telecom intrusions to a satchel charge next to a cell tower0:09:200:39:16 and argued the federal government, not private companies alone, must defend against nation-state cyber attacks the way it would a physical border incursion0:54:07.

Rep. Andrew Garbarino (R-NY), Cybersecurity Subcommittee Chairman0:11:44: Highlighted Salt Typhoon and Volt Typhoon as evidence adversaries are targeting critical infrastructure0:12:10, urged reauthorization of CISA 2015 before it expires0:13:27, and pressed witnesses on how to hold software makers accountable for security without over-penalizing user error0:57:03.

The Hon. HR McMaster, Hoover Institution0:18:06: Argued deterrence requires rapidly imposing costs on attackers beyond what they anticipate0:19:03, warned China's military and nuclear buildup suggests preparation for a first-strike capability tied to its infrastructure intrusions0:41:09, and stressed human-capital investment and visas to retain top science and engineering talent0:20:25.

Wendi Whitmore, Palo Alto Networks0:20:52: Said Palo Alto blocks up to 31 billion cyber attacks daily, 9 million of them novel0:22:10, and that AI-powered security operations centers have cut response times from days to under two hours0:23:19; argued the public often unfairly "punishes the victims" of breaches rather than the attackers0:43:27.

Jeanette Manfra, Google Cloud0:26:02: Advocated a harmonized, risk-based regulatory baseline built on FedRAMP and OSCAL with reciprocity across certification regimes0:29:08; described Google's "shared fate" security model0:27:02 and its Secure AI Framework for AI-specific risks1:09:33.

Jack Cable, Corridor CEO/co-founder0:30:38: Testified that top AI models write vulnerable code 30–40% of the time0:32:28 and pushed for a software liability regime with safe-harbor protections for compliant manufacturers0:48:25; also flagged CISA's loss of top technical talent in recent months0:35:41 and noted no top-20 CS program requires a security course1:18:14.

Rep. Eric Swalwell (D-CA), Ranking Member0:36:11: Welcomed the panel to his district and pressed for reforming the Joint Cyber Defense Collaborative (JCDC) into a more agile, genuinely two-way information-sharing network0:37:351:22:31; asked witnesses about federal research funding's role in cyber innovation1:13:04 and quantum-computing preparedness1:18:51.

Key moments

Chairman Green likened China's access to U.S. telecom infrastructure to "a satchel charge next to a cell tower," and McMaster said the buildup reflects a possible first-strike nuclear posture, citing a roughly 44-fold rise in Chinese defense spending since 2000 and a 400% increase in nuclear forces0:39:451:41:09.

Green proposed outlawing ransomware payments as an extreme but potentially effective deterrent; Manfra said she does not believe outlawing payments would be effective given life-safety scenarios0:49:270:50:22.

Cable testified that over 300 companies have voluntarily signed CISA's secure-by-design pledge, including Google and Palo Alto Networks, and cited JPMorgan Chase's letter urging vendors to prioritize security ("secure by demand")0:33:240:33:52.

Manfra said NIST/NSA guidance targets 2035 for adopting post-quantum cryptography, while Whitmore and McMaster argued that timeline is too distant given the pace of quantum advances1:20:221:22:07.

Cable disclosed that not one of the top 20 U.S. computer-science programs requires a security course for a CS degree1:18:14.

Garbarino and witnesses debated accountability for software vulnerabilities versus user error, with Cable proposing a liability regime paired with safe-harbor protections and "secure by default" shipping practices like randomized default passwords0:58:271:01:54.

Manfra and Whitmore both endorsed swift reauthorization of the Cyber Information Sharing Act of 2015, with Cable citing CISA's pre-ransomware notification initiative as an example of trust built under the act's protections1:40:421:41:07.

McMaster and Green discussed reforming visa and immigration pathways to retain top international STEM talent, with McMaster noting "nobody's trying to immigrate to China"1:14:47.

Manfra described Google's "shared fate" model and called for outcome-based rather than checklist-based regulation, while Cable warned checklist compliance resembles "checking that a factory has locked its doors without testing the quality of the products"0:27:020:34:21.

Green closed by framing the committee's regulatory-harmonization goal as eventually achieving real-time, AI-driven compliance requiring no human effort, freeing resources for actual security work1:45:00.

Metadata

CommitteeHouse Homeland Security
Chamber / CongressHouse · 119th Congress
Date2025-05-28
TypeHearing
Witnesses
The Honorable Herbert McMaster — Fouad and Michelle Ajami Senior Fellow, The Hoover Institution
Ms. Wendi Whitmore — Chief Security Intelligence Officer, Palo Alto Networks
Ms. Jeanette Manfra — Global Director of Security and Compliance, Google Cloud
Mr. Jack Cable — Chief Executive Officer and Co-Founder, Corridor
Videoyoutube
Transcript234 caption blocks · 17,134 words · 1:46:43 runtime
EventCongress.gov 118140