▶ 0:07:28The Committee on Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection will come to order. Without objection, the Chair may declare the Committee in recess at any point. The purpose of today's hearing is to examine the current state of US capabilities or how those capabilities are used to deter, disrupt, and impose real cost on foreign adversaries that target the homeland and our nation's critical infrastructure.
▶ 0:07:54The hearing will also assess the legal authorities that govern offensive cyber operations across the federal government and examining the evolving role of the private sector as the US government considers whether and under what circumstances private entities may be authorized to support or conduct offensive and disruptive cyber I now recognize myself for an opening
▶ 0:08:24Today, the Subcommittee is meeting to examine a reality that the United States can no longer afford to avoid, namely, that deterrence in cyberspace does not exist without credible, lawful, and operational offensive cyber Defense alone is not sufficient. Resilience alone is not sufficient.
▶ 0:08:45Public attribution alone is not For more than a decade, the United States has invested heavily in cyber defense, and for information sharing, and resilience. Those investments are necessary, and they have improved our ability to withstand attacks, but they have not altered adversary adversarial Malign cyber actors continue to penetrate American networks, steal sensitive data, surveil communications, and position themselves
▶ 0:09:16themselves inside critical infrastructure with little fear of meaningful consequence. That reality was reinforced again just days ago when public reporting revealed that a Chinese state-sponsored cyber actor known as Salt Typhoon compromised email systems used by staff supporting several congressional committees.
▶ 0:09:37This incident was the latest operation in a sustained campaign conducted by a broader group of Chinese cyber actors commonly referred to as the as the Typhoon cluster. These actors are not criminals acting for profit. They are instruments of state power, and that needs to be Their operations are deliberate, persistent, and strategic in nature.
▶ 0:10:02They are designed to extract intelligence, preposition access, and shape the battlefield long before a crisis or conflict emerges. I'm going to say that again. Preposition access and shape the long before a crisis or conflict They target not only the executive branch and private industry, but now once again the legislative branch itself.
▶ 0:10:30The question before this subcommittee is not whether these threats exist. That is no longer in The question is why they continue and what it will take to change the cost-benefit calculation for adversaries who believe they can operate against the United States with impunity. Currently, authorities for offensive cyber operations are dispersed across Department of War, the intelligence law enforcement, while civilian agencies like CISA play critical roles in defense, response, and resilience.
▶ 0:11:02Existing policy frameworks were developed for an earlier phase of the cyber threat environment, one that did not fully anticipate today's scale, speed, and persistence of state-sponsored activity. Again, the speed and the scale of the battlefield battlefield has changed. They're also not designed for a world in which the vast majority of digital infrastructure targeted by adversaries is owned and operated by the private The reality is forcing a broader reassessment across the federal government.
▶ 0:11:32The Trump administration has signaled its intent to pursue a more proactive and assertive cyber posture, one that emphasizes disrupting adversary capabilities before harm occurs, resetting adversarial risk calculations, and exploring new ways to integrate private sector expertise into national cyber efforts. This reflects an important recognition. The private sector is not merely a victim in cyberspace.
▶ 0:11:58American cybersecurity companies, cloud providers, telecommunications firms, and emerging technology startups are often the first to detect malicious activity, the first to analyze adversarial tradecraft, and the first to develop tools capable of disrupting hostile In many cases, they already possess visibility and technical insight that rivals or exceeds that of the federal The challenge is that much of this activity exists in legal and
▶ 0:12:28policy gray space. Companies face uncertainty about liability, retaliation, and regulatory Government agencies face constraints on how they can partner, share information, and act with speed. Adversaries exploit these seams, operating continuously below the threshold of armed conflict while benefiting from ambiguity and restraint. Today, our witnesses will help us assess how offensive cyber capabilities can be responsibly integrated into a modern homeland security framework.
▶ 0:12:58I appreciate our witnesses for being here, and I look forward to their testimony and the discussion ahead. And again, thank you all for being here. And I recognize the ranking member, the gentleman from Mississippi, Mr. Thompson, for his opening statement. Thank you, Mr. Chairman. Good morning.
▶ 0:13:20I appreciate the opportunity to discuss opportunities to disrupt and deter malicious cyber activities on domestic networks and impose costs on our adversaries, and I thank the witnesses for participating. Before I begin, however, I'd like to send my deepest condolences to the family of Renee Good, particularly her partner and 6-year-old child who's now without a mother.
▶ 0:13:49From everything I've seen, Ms. Good was attempting to de-escalate and leave the situation, and there was no reason to take her life. I support a full investigation of this shooting and justice on her behalf.
▶ 0:14:05Turning to the issue at hand, over the course of the past year, there have been increased discussions about whether the United States is using its formidable offensive cyber capabilities as effectively as it could be to deter and disrupt cyber attacks. United States offensive cyber capability is second to none, but with that awesome power comes awesome responsibility.
▶ 0:14:34As we consider whether and how to deploy offensive cyber tools differently, we must bear three points in mind. First, cyber offense is no substitute for defense and resilience. We will have to continue investing in those key capabilities.
▶ 0:14:54Second, cyber offense is one tool among many, including sanctions and other diplomatic levers that the United States can use to shape adversary behavior. The tool or combination of tools we should align with our mission objectives.
▶ 0:15:13And finally, any significant change to our approach to the use of cyber offensive cyber operations could shift global norms, and we must consult our allies.
▶ 0:15:26As a committee responsible for overseeing the cyber security and infrastructure security agency, referred to as CISA, I'm concerned that we are putting the cart before the horse with a hearing on offensive cyber activity when we could have not had a hearing on why the agency has lost 1/3 of its workforce over the last year.
▶ 0:15:52CISA is the agency responsible for helping utilities, water treatment facilities, pipelines, and other critical infrastructure entities keeping Volt Typhoon and other adversaries off our network.
▶ 0:16:07But ever since last January, the Trump administration harassed key CISA personnel into leaving their jobs, including the individuals responsible for the secure by design program, the pre-ransomware notification initiative, and individuals who work directly with critical infrastructure operators on security issues.
▶ 0:16:31We ought to be cautious about pursuing an approach involving the use of offensive cyber tools that could result in retaliation or escalation if we are not in a position to help defend US Moreover, we must bear in mind that offensive tools are one of many tools at our disposal to shape behavior in cyberspace, and we need to use them all more effectively and more deliberately.
▶ 0:17:03I understand that plans to impose sanction on China's Ministry of State for its Volt Typhoon campaigns was put on hold last year as the president negotiated a trade truce with the Our use of sanctions and other diplomatic tools to deter and impose costs on our adversaries would be more effective if the president did not start unnecessary trade wars.
▶ 0:17:33Relatedly, we should be clear-eyed about what our objectives are and how the use of offensive cyber tools align with our any change in our approach to the use of offensive cyber tools that would shift current norms must be done in consultation with our allies. We cannot afford to distance ourselves from our security partners more than this administration already has.
▶ 0:18:04Having said that, I agree there are opportunities to increase pressure and impose higher costs on adversaries for unacceptable behavior in cyberspace. We should consider whether there are many way where there are ways to more aggressively disrupt adversary infrastructure and deny them the benefits of success.
▶ 0:18:29while offensive cyber activities, by and large, is a government [snorts] function, there may be new ways for the private sector to support government efforts in this space in a manner consistent with the law. I look forward to discussing these and I yield back the balance of my time. Thank you, ranking member Thompson. Other members of the committee are reminded that opening statements may be submitted for the record.
▶ 0:18:57I'm pleased to have this a distinguished panel of witnesses before us today on this important topic. Pursuant to committee rule 8C, I ask the that our witnesses please rise and raise their right hands. Do you solemnly swear that the testimony you will give before the Committee on Homeland Security of the United States House of Representatives will be the truth, the whole truth, and nothing but the truth, so help you God? Let the record reflect that the witnesses have answered in the affirmative.
▶ 0:19:27Thank you, and please be I would like to formally introduce our witnesses. Mr. Joe Lonsdale currently serves as co-founder and CEO of 8VC, a cybersecurity company that develops AI-enabled capabilities to help government and national security partners detect, disrupt, and counter sophisticated cyber threats. In addition to his current role, he is a commissioner on the Center for Strategic and International Studies Commission on Cyber Force Generation.
▶ 0:19:57Prior to his roles at 20, Mr. Lynn served as the vice president of product management at Palo Alto Networks, where he founded and led the National Security Division. A former US Navy Reserve officer, Mr. Lynn has spent over a decade defending US military government and critical infrastructure networks. Thank you, Mr. Ms.
▶ 0:20:17Emily Harding currently serves as vice president of the Defense and Security Department and director of the Intelligence, National Security, and Technology Program at the Center for Strategic and International Studies. That's a mouthful. In these roles, she provides expert knowledge and intellectual leadership on issues shaping the future of intelligence work and national security. Prior to CSIS, Ms.
▶ 0:20:41Harding served as the deputy staff director on the Senate Select Committee on Intelligence, led analytic programs at the CIA, and contributed to the first Office of the Director of National Intelligence-led presidential transition. Mr. Frank Cilluffo serves as the director of infrastructure, critical infrastructure security at Auburn University.
▶ 0:21:04He was a member of the US Cyberspace Solarium Commission and served served as special assistant to the to President and George W. Bush's administration in the newly created White House Office of Homeland Security. Following this role, he joined George Washington University, where he established the Center for Cyber and Homeland Security. His previous experience also includes senior policy positions at the Center for Strategic and International Studies. Thank you, Ms. Harding, Mr. Cilluffo. Mr.
▶ 0:21:32Drew Bagley currently serves as the chief privacy officer at CrowdStrike, where he is responsible for leading the company's global data protection initiatives, privacy strategy, policy engagement, and policy engagement. Mr. Bagley previously worked in the Federal Bureau of Investigations Office of the General Counsel, has served as an advisor to government and non-profit groups, including the Cybersecurity and Infrastructure Security Agency's Joint Cyber Defensive Collaborative at the [snorts] US Department of State and Europol.
▶ 0:22:03In addition to his corporate leadership, Mr. Bagley serves on the faculty of American University, where he teaches cyber law and privacy. I want to thank each of our distinguished witnesses for being here today, and I'll recognize Mr. Lynn for 5 minutes to summarize his opening. Chairman, ranking member, members of the subcommittee, thank you for the opportunity to testify today. My name is Joe Lynn.
▶ 0:22:27I'm the co-founder and CEO of 10 Technologies, where we build industrial-scale cyber warfare capabilities for the United States. I want to be direct. The United States is not postured to deter or defeat its adversaries in Our adversaries, most notably the People's Republic of China, are running persistent, large-scale cyber campaigns against US critical infrastructure, telecommunications, the defense industrial base, and government These are not episodic breaches.
▶ 0:22:56These are not just thefts of intellectual They are continuous, increasingly automated shaping operations designed to hold our society at risk at peacetime and to preposition for conflict. These campaigns have been effective. They have imposed real and growing costs on the United States. By contrast, our response is unnecessarily constrained, particularly in the use of offensive cyber. This restraint has not prevented It has encouraged it.
▶ 0:23:27When adversaries escalate and face little or no cost, they learn that it works, and over time, that becomes an incentive to push In effect, we have created a one-way dynamic. They escalate and we absorb, and because we absorb, they keep Yet, the United States government continues to treat offensive cyber as a bespoke capability, slow to generate, difficult to scale, and constrained by processes built for a different era.
▶ 0:23:54We rely on small numbers of elite teams executing one-off operations, while our adversaries operate at machine speed across hundreds or thousands of targets. That mismatch is the core problem. Deterrence in cyberspace does not come from symbolic gestures or isolated tactical wins. It comes from the demonstrated ability to impose sustained asymmetric cost at scale, to make adversary campaigns fail repeatedly and faster than they can This is not just a talent problem. This is a structural one.
▶ 0:24:23Our cyber forces are asked to confront an industrial-scale threat with bespoke tools and processes. We have not built cyber capabilities for sustained campaigns, operational tempo, or mass effects. Cyberspace is now a primary domain of conflict, where speed, scale, and persistence determine real-world outcomes. Offensive cyber must therefore be treated as a core instrument of national power, and that requires three shifts. First, we must industrialize offensive cyber capabilities.
▶ 0:24:54Elite operator tradecraft must be turned into software, codified, testable, repeatable systems that execute under human authorization at machine speed. This is not about removing humans from the loop. It is about leverage. One operator should be able to direct efforts across hundreds of targets, not Second, we must align authorities, acquisition, and operational concepts to sustained campaigns, not single Our adversaries are persistent.
▶ 0:25:23We need capabilities that are continuously operating, adapting, and imposing friction, built as operational software, not legacy government programs designed for peacetime procurement. Third, we must be honest about the role of offense in defense. Critical infrastructure security will not be solved through patching alone.
▶ 0:25:43Against persistent, state-directed actors, defensive measures are Deterrence requires credible offensive cyber operations that disrupt and impose cost upstream. This may be uncomfortable culturally, but unavoidable strategically. Effective offensive cyber is not reckless.
▶ 0:26:04It is disciplined, tested, authorized, and aligned with government In fact, the absence of scalable, well-engineered offensive capability increases risk by ceding initiative to our adversaries and forcing reactive, crisis-driven responses. The United States has faced industrial-scale threats before. Each time, we built industrial-scale Cyber is no different, except that time is not on our side.
▶ 0:26:33The campaigns underway today are shaping the battle space for tomorrow. Every delay compounds the problem. This subcommittee has a critical role to play, clarifying mission ownership, enabling acquisition pathways for commercial offensive cyber capabilities, and treating offensive cyber operations as a decisive element of homeland security, not a niche activity. If we want deterrence, we must build the capabilities that make deterrence real.
▶ 0:26:59Thank you, and I look forward to your Thank you, Mr. Lynn, and I agree, the best defense is an aggressive offense. And I'll recognize Ms. Harding for 5 minutes to summarize her opening statement. Thank you for this opportunity. I suspect I'm going to find myself in fierce agreement with most of my panelists here, but I'll try to add a little bit. Uh first, I want to walk a bit through the problem, and then talk about the war games that we ran to fully diagnose that problem, and then a minute on how to fix So, the problem.
▶ 0:27:28Washington has failed to establish deterrence in the cyber domain, and our adversaries right now control the escalation ladder. Historically, US foreign policy has rested on deterrence with implied escalation dominance in any domain, but that foundation has failed in the context of cyber. US responses to cyber attacks have been muted. Escalation dominance does not exist. To actually achieve this deterrence, we need a mindset shift.
▶ 0:27:53We need to stop thinking about cyber attacks as inevitable nuisances, and start seeing them for what they really are, hostile actions against the United States. China, Russia, Iran, and North Korea do not see a bright line between war and peace. Instead, they view cyber attacks as fitting on a spectrum of warfare. For them, competition with the US is ongoing.
▶ 0:28:14Low-level elements of cyber warfare are not only acceptable, they're In 2023, both Iran and China pushed the boundaries with attacks on critical In November of 2023, the Islamic Revolutionary Guard Corps of Iran attacked US water plants. While the intent was to embarrass Israel, the facts are undeniable. A terrorist group attempted to impair water delivery to civilians in the United States.
▶ 0:28:42Also in late 2023, NSA and cybersecurity researchers raised renewed alarm about China's Volt Typhoon group. The attackers burrowed into US water, power, port systems in the mainland and on These accesses could give Beijing the capability to disrupt daily life. This was the prepositioning you were talking about in your opening statement, Mr. Particularly around US military bases that would serve as launching pads for US troops in a Pacific fight. So, let's talk a little bit about the war games we used to diagnose this problem fully.
▶ 0:29:12This is a dangerous new phase in cyber warfare. We suspected that US policymakers had not fully wrapped their heads around what it means, and so we pulled together some senior folks who had served in many previous administrations to walk them through the these scenarios. One scenario, an adversary conducted an attack on critical infrastructure in the homeland, where a dam malfunctioned and hundreds died. Other scenarios were more complex. We had attacks on water systems leading [clears throat] to sickness.
▶ 0:29:39We had attacks on power plants leading to deaths at hospitals and from exposure to These games revealed a stark conclusion. Our participants were confused, spinning their wheels. They had comments like, "Well, we should use a proportional response as soon as we figure out what a proportional response is." These are very smart people who have served at high levels of government. This is just a hard problem they were trying to grapple with.
▶ 0:30:03They lack a shared framework and a coherent viewpoint on what constitutes an act of war and a proportional response in the cyber domain. In other words, while our adversaries have fully incorporated cyber into their foreign policy playbook, we are still struggling to understand what cyber is and what it should do. So, how do we fix it? The US government needs to establish a new framework for conceptualizing and responding to cyber attacks. To address this need, we wrote a recent tome of a project called a playbook for winning the cyber war. It's available on CSIS's website.
▶ 0:30:33But, here are five key points and recommendations. Number one, cyber attacks are attacks. If they imperil life, health, safety, and particularly if they threaten critical infrastructure in a way that could create a mass casualty event, the US government will treat them as they would any other attack on civilians. Number two, we need to adjust our risk 10 years ago, it made sense to require high-level approval for offensive cyber action.
▶ 0:30:58The tool was new, we didn't really understand it, but now we have talented, brilliant cyber operators and we need to let them have their heads. It's really important to flip the risk calculus. The default answer to a proposed proposed operation should be yes, and a naysayer should have to prove it is too risky instead of asking the operators to prove the operation is Number three, we need to collaborate early. Cyber tools can be very effective in disrupting an adversary. We saw some of this in Venezuela just recently, but operators need time to plan.
▶ 0:31:28This is not a tool that just sits on the shelf and you reach out and grab it when you need it. They need to be incorporated from the very early stages of planning. Number four, run the playbook. The report lays out these steps in detail, but here's the key point, be bold. We can retaliate cyber for cyber, but we don't need to stop there. We need to match creative policy responses to the pain points of the particular attacker. And then number five, Congress should create and fully fund a cyber force.
▶ 0:31:55I know my colleagues are going to have other things to say about that, but this is something that I believe will actually close the gap faster than pretty much anything. In conclusion, a dramatic change is needed in the cyber domain. The Trump administration's recently released national security strategy did mention offensive cyber operations. I think that's a positive development. I would suggest a new policy, cyber first, cyber op- cyber optional. We are redefining proportionality in the cyber domain. Thank you. Thank you, Ms. Harding, and I now recognize Mr.
▶ 0:32:23Sill It's a mouthful, sir. Sillufo. My apologies for a uh 5 minutes. I'm in violent agreement with that with my fellow panelists here and uh uh really happy to see that you are proposing uh such an important uh topic and and one that I think is going to generate a lot more attention in the days ahead.
▶ 0:32:53Um in addition to this question, the fundamental one, we really do have to start answering what that requires of our authorities, institutions, capabilities, and partnerships. Uh just last month, my institute released a significant report on many of these topics on offense, deterrence, and strategic competition. Um I co-chaired that uh had the privilege of co-chairing that alongside uh Chris Inglis and General Frank McKenzie, as well as uh Tom Bossert.
▶ 0:33:21Uh suggest everyone take a take a look at that when you get a chance. The the the summary, the conclusion was pretty straightforward. The status quo ain't cutting it. Um and our adversaries are not operating episodically, they are operating persistently and cyberspace is an always-on, always-contested domain. Uh China in particular, as my panelists have mentioned and you, Mr. Chairman, uh teed up in the very beginning, demonstrated this long-term strategic intent.
▶ 0:33:51Uh campaigns such as Flax, Volt, and Salt Typhoon are all really serious on their own. Taken together, however, they they form a perfect storm. And it's the pre-positioning at a time of their choosing that I think uh in US critical infrastructure, that is a line that has been crossed. Russia's experience in Ukraine reinforces the point, underscoring a hard truth. Our adversaries already view cyberspace as a domain of continuous engagement.
▶ 0:34:19Some of our approaches to tackle this, uh I I'm a big proponent of National Security Presidential Memorandum 13, N SPM 13, and the adoption of the defend forward uh approach was an important shift enabling greater agility and allowing US Cyber Command to disrupt adversary campaigns before they reach our shores. It's generated some genuine, real operational benefits, but in itself, it's not enough.
▶ 0:34:48We've also seen how uh more recently how cyber capabilities can be integrated with other instruments of national power for strategic effect and signaling. Uh the Chairman of the Joint Chiefs publicly discussing the role cyber played in Absolute Resolve, uh by all accounts an exquisite operation targeting the Maduro regime in Venezuela, makes this clear. While public acknowledgement is relatively new, it is consequential.
▶ 0:35:16It underscores that cyber is no longer peripheral, but integrated, operational, and central to modern deterrence and can shape the behavior not only of those targeted, but all those watching. At the same time, these advances surface unresolved questions about oversight, interagency coordination, escalation risk, and I'm very much with Dr.
▶ 0:35:37Lynn is in terms of escalation, uh as well as the interaction between cyber operations abroad and defensive responsibilities at home. These are not academic debates. They go to the heart of democratic accountability and strategic stability. One point bears emphasis. Offensive cyber cyber operations alone are not sufficient to protect the homeland.
▶ 0:36:01When cyber action is taken abroad, it must be paired with strong domestic defense led by DHS and CISA, working with SLTT and private sector partners to improve resilience across our critical But, a purely defensive posture is equally insufficient, if not more so. Simply put, we cannot firewall our way out of this problem.
▶ 0:36:23Deterrence in cyber depends on the interaction between offense, defense, resilience, and credibility over time, uh not reactive, episodic responses built for a different era. In essence, we've let the adversaries define our strategy. We react, and that becomes our strategy. That's unacceptable. Uh this brings me to the private sector. The vast majority, as we know, of critical infrastructure is owned and operated by the private sector.
▶ 0:36:49These entities are already on the front lines, yet are too often treated as passive victims rather than essential partners. Many of the most relevant capabilities from threat intelligence, rapid response, large-scale mitigation reside in technology companies, cloud providers, and infrastructure In practice, the private sector already conducts elements of active defense.
▶ 0:37:12What remains unresolved is how far they should be permitted to go, under what legal authorities, and with what Clarifying the legal and policy boundaries around lawful, proportionate, and well-governed active cyber defense would strengthen collective defense, raise adversary costs, and reduce ambiguity while preserving oversight and civil liberties. Um there are a number of promising steps underway from CISA's JCDC to NSA's CCC.
▶ 0:37:43Um but, these efforts have to be reinforced reinforced by clear doctrine, modernized authorities, and governance Net-net, stakes are high. As adversaries deepen their access into American networks, the United States must decide whether to remain constrained by outdated frameworks or adapt to realities of 21st century conflict.
▶ 0:38:05Congress has a critical role to play in that recalibration by modernizing authorities, strengthening oversight, and ensuring our institutions can operate with both agility and accountability. Mr. Chairman, thank you for the opportunity to join you today. Thank you, Mr. Sillufo. I recognize Mr. Bagley to summarize his opening statement. 5 minutes. Chairman Rogers, Ranking Member Thompson, members of the subcommittee, thank you for the opportunity to testify before you once again.
▶ 0:38:32Throughout my career, I've seen firsthand the challenges and opportunities of improving American cybersecurity from my work in the private sector, government, and For more than a decade at CrowdStrike, I've had a front-row seat to our defense of critical entities. This includes many components of the US federal government, major technology companies, financial services firms, 43 of 50 US states, critical infrastructure, and thousands of small and medium-sized businesses. We defend America.
▶ 0:39:02unfortunately, many organizations remain undefended, vulnerable to cyber attacks, the scope and severity of which continues to increase. Simply put, threat actors are still operating at scale, still operating with limited consequences, and still all too often achieving their objectives. They are seeing a clear return on Their risk calculus still shows favorable outcomes.
▶ 0:39:28To make durable progress, we must work in a concerted fashion to change each of these The role for offense in confronting cyber threats is textured. I've outlined several elements in my written testimony, including the enterprise defenders threat hunt across their own systems, resources, and data. This is a proactive approach, sometimes called active defense, rather than offense per se, but it's one of the most effective techniques to confront targeted attacks.
▶ 0:39:57Some suggest victims or their representatives should hack back. I've shared the history of this debate in my written testimony, but in short, hack back operations risk revictimization and collateral damage. Ongoing investigations could be disrupted, and retaliation could lead to waves of geopolitical escalation. For these reasons, offense is best left to professionals with relevant authorities, deconfliction processes, and clear oversight.
▶ 0:40:23A federated regime for hacking back that lacks these attributes probably creates more problems than it Let me state plainly that defense remains foundational. Even those who wish to increase offense must recognize the value of robust defenses. New threat actors emerge routinely with different different capabilities and motivations. Economic and geopolitical conditions change, often for the worse.
▶ 0:40:49Having defenses in place amid this changing terrain is essential and A core prescription for better confronting cyber threats is more focused, more persistent, and more tightly orchestrated campaigns disrupting threat actors and those who support them. JCDC in concert with industry should establish a most wanted style list. As a community, we should work our way down that list rapidly.
▶ 0:41:15Performing disruptions and takedowns to frustrate adversaries' objectives and prevent them from reaching scale. For criminal activities, we should apply laser focus on preventing monetization. Terrific work is done today, just not at a high enough tempo. Still, there remains a role for deterrence. Cyber attacks are caused by Threats themselves are not the terrible. The people, institutions, and nations behind them often are.
▶ 0:41:42Given that their motivations vary so widely, there is no singular approach to deterrence that could succeed. But we should still use all available tools, including non-cyber tools. Policy makers face challenges in considering how to resource defense versus offense. Ultimately, it's probably reasonable to conceive of security investments as a portion of overall IT spending, and reasonable to align offensive investments as a portion of overall military spending.
▶ 0:42:11AI impacts these considerations. AI provides threat actors with a new class of systems to target and acts as an accelerant to automate their TTPs. AI itself is under threat from adversaries, meaningfully increasing the attack surface when left unprotected. Fortunately, AI detection response solutions can prevent prompt injection, jailbreaks, and model manipulat- manipulation attempts, and agentic AI is already revolutionizing security operations to assist defenders.
▶ 0:42:41To confront these challenges, I recommend the following. First, public and private organizations must take reasonable actions to defend themselves with a focus on threat hunting and identity security. Second, the cybersecurity community should radically increase the operational tempo of malicious infrastructure disruptions and takedowns. Given its stakeholder engagement functions, CISA should be central to coordinating public and private actors to this end.
▶ 0:43:07Third, federal law enforcement, along with Title 10 and Title 50 entities, should work to increase deterrence. we must defend AI systems and leverage AI to defend enterprises. Thank you again for the opportunity to testify today, and I look forward to your questions. Thank you, Mr. Bagley. Members will be recognized by order of seniority for their 5 minutes of questioning. I now recognize myself for 5 minutes.
▶ 0:43:36Uh again, I want to thank the panelists uh for being here. This is an important topic for us to be uh really bringing to the forefront of kind of the the today's conversations and quite frankly the the onslaught of media that we see every single day. And when you look at the Monroe Doctrine, um you know, our dominance in the Western Hemisphere, that is seen in the context of borders and boundaries.
▶ 0:44:02But now with the cyber and the AI landscapes, that would also include those boundaries and those borders. And so as we look to our capabilities, clearly, Mr. Bagley, we need a great defense, threat hunting, and all all the such. But when you look at the Typhoon clusters, we now are going to have to go on offense.
▶ 0:44:21We have to make the pain point significant for our adversaries to understand that if you breach the Monroe Doctrine, that if you break our hemisphere, our borders, our boundaries, there will be a price. Mr. Lennon, I want to start the with the start of the current state of play. Today, offensive cyber capabilities exist across multiple parts of the US government under different authorities like Title 10 and 50 with varying degrees of integration with the private sector.
▶ 0:44:51As we look ahead, as the US government considers a more forward-leaning posture in cyberspace, what actually exists today in terms of offensive cyber capability, who currently has the authority to employ it, and what are the most important questions Congress should be prioritizing right now if we are to consider whether and how the private sector could be empowered to play a more direct role in offensive or cost-imposing cyber uh operations. Thank you, Chairman.
▶ 0:45:19Um you know, I I'll answer your question in two ways. Number one is around authorities. Um I think it's im- important and critical that A, as my some of my co-panelists have said, um that we are cooperating hand in hand uh with the the authority holders of Title 10 and Title 50, but it's important forget to remember that uh uh DHS uh have authorities of their own that ought to be used as well and used aggressively here. We're talking about Title 18, we're talk- talking about Tit- Title 14, right?
▶ 0:45:48And so the ability to use law enforcement authorities in combination, in concert with Title 18 uh Title 10 and Title 50 is absolutely critical. But number two, um I think what needs to shift here is a mindset, not just around doing episodic one-off operations of disruption, which are important and critical and can be successful, have been proven to be successful, much like the KBotnet takedown that the FBI led um uh recently.
▶ 0:46:10But what does it take to match the speed and scale of our adversaries, to match the scope of what it is that they are conducting against One-off episodic operations, while important for deterrence, will never be enough to change the cost calculus of our adversaries. Exactly. Mr. Harding, recent reporting indicates that a PRC-linked cyber actor, commonly referred to as Salt Typhoon, targeted uh systems supporting congressional committees.
▶ 0:46:40This was not a private company or an executive agency. It was the legislative branch of the US government. From a strategic standpoint, what message does it send when a nation-state is willing to target Congress directly, and uh and should this committee view that as a clear evidence uh that current approach to deterrence in cyberspace uh cyberspace is insufficient? In a word, yes. Um I would want to draw a distinction, however, between an intelligence operation and a disruptive operation.
▶ 0:47:10Uh as a former intelligence officer myself, uh I have to sort of tip my hat to Salt Typhoon. They have been very clever, very talented. They have proven just how good China is at its current cyber activities. Um going after congressional staff from a intelligence perspective is a logical target. In my last role on the Senate Intelligence Committee, we frequently gave defensive briefings to our fellow staff and to members of Congress to explain just how much they would be targeted and how sophisticated the adversaries were who were coming after them.
▶ 0:47:40Ideally, yes, you'd be able to establish deterrence in an intelligent sense, and you'd be able to say, "Okay, if you penetrate our networks, then you will feel consequences for that." It also is sort of a normal spy versus spy, A very clear distinction, however, is between the Salt Typhoon kind of activity and the Volt Typhoon kind of activity. There is zero intelligence value in penetrating water networks, power networks, especially around military bases.
▶ 0:48:08That is there for one reason and one reason only, to disrupt the United States military in the case that we had to deploy suddenly. Uh if there were to be a Pacific contingency, a 6-hour delay, an 8-hour delay, a 12-hour delay could be definitive. And if sailors can't get to their ships, if you can't load the ships full of equipment, then that is a 6-hour delay, an 8-hour delay, a 12-hour delay. Um it's a smart act for, I think, a potential adversary to take, but it is one we may not allow.
▶ 0:48:37We have to be able to deter that kind of activity and strike back. Thank you. I now recognize the ranking member of the member of the gentleman for uh from Mississippi for 5 minutes. Thank you very much, Mr. Chairman. Uh very rarely do I find witnesses uh with very little difference in testimony. So I I compliment you on that.
▶ 0:49:04but in our national cybersecurity strategy is going to shift toward a a more aggressive offensive cyber we'll need to ensure that the agencies responsible for such efforts, such as US Cyber Command and the National Security Agency, have the staff and the resources necessary to carry out offensive cyber Yet both Cyber Command and
▶ 0:49:34have had personnel reductions over the last year. And all of you've talked about capabilities. I mean, if you're going to fight an enemy, you the ability to to do that.
▶ 0:49:50So, in your analysis, uh we in a position given the current staff staffing to say that uh we're at a point where uh we're good or the cuts vulnerabilities that we should address uh at this point. Now, start with you, Mr. Lynn, and we'll go down the line. Thank you, sir.
▶ 0:50:16I can't comment on the specific force structure or even the numbers that we necessarily need in each of these organizations, but what I can say is Um we will never have enough people if we're simply trying to throw more people at the problem against our adversaries. Our our adversaries outnumber us 50 to 1 or in some cases 100 to 1.
▶ 0:50:33So, when we think about what is the future of staffing structures, force structures, uh whether we're talking about for Cyber Command, for NSA, for uh DHS, um we have to approach this problem from the perspective, of course, of thinking about what's the level of human expertise and oversight and control that's needed.
▶ 0:50:52But also, what are the technologies that are needed that enable our people, our warfighters, our officers to uh operate at scale against an adversary that has a quantitative advantage against us and that that that that that exceeds orders of magnitude.
▶ 0:51:11Ms. Harding. Thank you, sir. Um you're absolutely right that a lot of very talented people have left the government and there is concern there. I think the question is right-sizing and having the right talent in place to be able to fight back against these particularly talented and committed adversaries. Cyber Force, so I think at least three of us up here are in favor of the creation of a Cyber Force, and that is because we need to think about this talent differently. We need to think about this force structure differently.
▶ 0:51:41Um this is not necessarily, you know, picking up a heavy rucksack and 100 lbs of batteries and and running through a field. Instead, this is a very specific set of skills, and we do want to lean heavily into a reserve cadre for Cyber Force. We have lots of talented people in the private sector, two of whom are sitting right here at the table with me, who can contribute both to the US government in a military sense and also in their private day jobs. Um Israel's perhaps an example to look at for this.
▶ 0:52:07They do this exceptionally well, where they blend together their private sector and their military activity so that both benefit, frankly. I would also encourage, especially given this committee's jurisdiction, to take a hard look at the Coast Guard. They have a spectacular set of authorities and a really interesting cadre of cyber operators that can do all kinds of things that you wouldn't necessarily expect. Um it's kind of a latent cyber power that I don't think we give enough credit to right now. Um also, the National Guard.
▶ 0:52:34There are quite a few National Guard units, especially in places that are obvious like Maryland, um that that have real talent in this space. They have clearances, they have um and they could play a much bigger role, especially in homeland defense, than we're currently allowing them. Uh Mr. Thompson, just very briefly, I would uh support Emily's uh comments there. Yes, we've lost some people.
▶ 0:52:56We're never going to have enough people, but I think there's some issues we need to get our arms around quickly, and some of them may not be sexy, but they're actually important. Cyber is not its It is its own domain, but it transcends all other domains, air, land, sea, space. And until we integrate computer network attack and cyber into our warfighting strategy and doctrine, we're going to be hamstrung.
▶ 0:53:20So, part of that is making sure we have the structural capabilities, that we have the the women and men that uh can can help make that happen. Uh and part of that is ensuring we have the political will, cuz uh deterrence only works if it's consistent and if it's credible. And and here's the truth. We if you look at how we've responded thus far, we've in essence been blaming the victim. An incident occurs, who do you blame? You blame the company, you blame the critical infrastructure owner operator.
▶ 0:53:49Yes, they need to do more, but how many of these companies went into business thinking they had to defend themselves against foreign militaries and foreign intelligence services? It's an unlevel playing field. So, I think consistency consistency credibility, and signaling that there will be consequences for bad behavior is essential. Thank you, and I appreciate the chair allowing Mr. Bagley to answer the question. thank you, Mr. Chair, and thank you, Ranking Member Thompson.
▶ 0:54:18Um I think fundamentally we should think about what we all discussed today as being a call for cross-domain responses at times. Sometimes we'll confront cyber with cyber, sometimes it'll be cross-domain responses. So, in terms of resourcing, I can't speak to the appropriate number of personnel.
▶ 0:54:35I think those in charge of agencies are best able to speak to that, but I can say we should want CISA to succeed, for example, and to have the processes and the technology they need, and then to make sure this subcommittee, through its oversight powers, is ensuring they have the personnel they need to succeed in that mission.
▶ 0:54:52But we should also be thinking expansively, as my colleagues have suggested, about other capabilities and other agencies throughout the government, because when we are trying to change adversary behavior, sometimes it's going to take authorities that are outside of the realm of what we think about with CISA or or DHS in general, and instead we're going to be thinking about diplomatic tools, economic tools, law enforcement tools, or even military tools. And so, I think we should think expansively about that and work backwards from that problem set. Thank you.
▶ 0:55:22I yield back, Mr. Chair. Thank you, Ranking Member. I now recognize Mr. Fang for his 5 minutes of Uh thank you, Mr. Chairman. Um Uh I want to thank the panelists. This certainly builds upon the previous committee hearing that we had um uh when we talk about how we're seeing our foreign adversaries weaponizing AI and quantum tools uh to automate cyber espionage campaigns against the United States and and soft targets, as mentioned before.
▶ 0:55:48Um I do want to delve into this cyber force uh cyber talent conversation. Um you know, certainly we are seeing um universities and and and we're seeing uh we're seeing community colleges try to develop a pipeline um when it comes to um teaching students a cybersecurity um tools and the technology. I kind of want to get your thought um um Ms. Harding in terms of um you know, as Mr.
▶ 0:56:18Lynn had talked about, we can't we don't have enough people compared to to our adversaries, but how do you uh what's your perspective on how we need to invest in in our universities and community colleges in terms of developing that cyber talent? So, universities and community colleges are are very important.
▶ 0:56:34Um I think we have focused a lot on, you know, certifications for cybersecurity, and that's important, but what we really want to push forward in the future is capabilities in AI, um understanding how that's going to really change the landscape, and then also just sort of a creative thinking. Some of the best cyber operators are not the ones who are the best coders, they're the ones who have the best ideas. And the the guys who who think like the adversary, the guys who can come up with creative ways to get around obstacles that they find.
▶ 0:57:01Like, these are the people who do the biggest, baddest cyber operations, and it's a thing of beauty to watch. Um I think that, you know, we can think about the talent pipeline in the kids who are coming up now. We also really need to think hard, especially in this moment where we do have this meeting of the minds between Silicon Valley and Austin, Texas, and Washington, D.C., where this is an important skill set, to welcome people into the government in a part-time capacity. Um you know, you were a Navy reservist.
▶ 0:57:31This is a great model. If you have people who can serve in the military reserves, serve in a cyber capacity, take the skills they've learned in their private sector positions, and then pull them into the government. Like, that is And I think that's an important point, which is if we need to be training um and teaching students differently in terms of not just on the on just a a cybersecurity defensive posture, but to to look at how do we uh make our our technologies more robust.
▶ 0:58:00Um this is something that as universities and community colleges start developing the curriculum, uh we might need to have a conversation about how we get uh if if universities and community colleges are going to develop these programs, uh actually have them train uh students to actually meet and uh the demand and and the needs that that that that our country needs. Um so, I'd love to continue that conversation. Um would like to ask Mr.
▶ 0:58:22Lynn, um when it comes to information sharing, uh certainly with your expertise, uh private sector cybersecurity firms often possess uh earlier and deeper visibility into in into our adversaries' infrastructure, attack paths, operational patterns uh than the government uh systems alone. Based on your experience, uh how is information sharing uh now, and and what barriers uh exist currently uh that we need to address to ensure that we have more robust um coordination?
▶ 0:58:53Thank you, sir. let me answer your last question first, which is how is it now? It's certainly improved considerably from 10 years ago or even 15 years ago. Um what you alluded to is spot-on, which is that uh these days, uh private sector companies, especially those uh in in the cybersecurity domain, um have extraordinary global sensor networks that rival those of even other intelligence signals intelligence Uh and so, it makes enormous sense for
▶ 0:59:23there to be very robust information sharing um both and bidirectionally, and it has to be bidirectionally. Um we have to have we have to make it possible, easy, uh and we have to encourage private sector companies to share what their sensors are seeing as holistically as possible with our intelligence agencies and it has to go and and vice versa.
▶ 0:59:45When we are able to downgrade intelligence that we're seeing through our robust signals intelligence we have to be willing to share that with our private sector companies as well. I'll go ahead. Yes, Mr. Mr. Fong, I I just cuz I I I think the committee itself should be applauded for the Pillar Act pivot.
▶ 1:00:07I mean, these are essential to to be able to move forward, but I think to your point earlier, it's not just the traditional rote learning in a classroom. You need to give students opportunities to be in applied environments where they're actually engaged cuz I'm telling you most of the best in the cyber community are not learning it in the classroom.
▶ 1:00:29They're learning it in in the real world and and I think looking to ways where we can build co-ops, we can build new opportunities with both industry and government will be absolutely essential for success. And I would just add on the information sharing question. We've been around this issue for 25 years. Here's the the truth. We've got to move beyond information sharing to operational collaboration.
▶ 1:00:56Until we get to that stage, we're always going to be marching into the future backwards. That is always by definition reactive. We need to get to the point where it's combined, you're in the same foxhole and you're fighting the same fight and you build the trust which is everything. It takes years to build, nanoseconds to lose. So, I just needed to jump on that. I'm sorry for jumping in here. I I appreciate that. That this is a very
▶ 1:01:22unspoken thoughts. Sorry. This is a very important topic and we need to continue the conversation. Thank you, Mr. Chairman, for your leadership in in putting this panel together. Thank you. I'll yield back. The gentleman yields back. I now recognize the member from New Jersey, Ms. McEachin. Thank you, Mr. Chair and ranking member, and thank you to our witnesses for being here today. I just want to quickly express my condolences to the family of Renee Good as well. What happened in Minneapolis where she was fatally shot by an ICE agent is horrific and deeply troubling.
▶ 1:01:53My thoughts are with her loved ones, especially her children, and with those affected by this tragedy as many in this country continue to mourn and seek As we discuss Trump's reliance on offensive cybersecurity tools, we must ask whether we are prepared to use these tools responsibly. Cyber offen- offense depends on a strong, well-trained workforce not only to conduct operations, but to manage consequences and defend against a counterattack.
▶ 1:02:24Today, we face a serious cybersecurity workforce gap which has been discussed in deepness by many of our witnesses. We lack enough individuals to protect our infrastructure, economy, and national security. Expanded offensive tools without the people to to sustain and defend ourselves is not deterrence. It is a risk. We must ensure that our home is secure.
▶ 1:02:47We must have the personnel and resources to fight any cyber threat before we dedicate time and resources to provoking malicious actors in cyber offense offense. With that, many of our witnesses, especially Ms. Harding and Mr. Backley, talked a lot about what we need to do in order to increase workforce. Would love to give you all guys a few moments just to talk about some of the barriers.
▶ 1:03:12How do we remove some of the barriers that we see right now with folks trying to join the cybersecurity workforce? I can start with Ms. Harding. Ladies first.
▶ 1:03:24Well, thank you, ma'am. Um, so some of the barriers that we see, number one is a barrier of imagination. I think there are people who think, you know, oh, that's going to be technical, that's going to be hard, I can't do it. There's some great programs to reach out to communities that maybe don't see themselves in this world and those should definitely continue. There's some women in STEM programs, for example, that are really tremendous.
▶ 1:03:46I think also, you know, when people think about the intelligence community, they they think about that as a certain type of person that you've got to be really straight-laced, you've got to be, you know, the kind of person that that has a buzz cut as opposed to the kind of person who has purple hair. It's just not true and I think welcoming a wide variety of talent into the government is really important. You know, I say to people all the time, are you interested in doing really really sneaky and sometimes illegal things in the cyber world? Join NSA.
▶ 1:04:13This is what they do and they do it very I think there's some real opportunity out there that maybe it just doesn't occur to people. Another one of the the barriers that we should really think through, I think is going to be this coders to the AI space. So, it's going to be a sea change and I I know that you'll have more to say about this, but you know, we've we've trained people to do really excellent jobs coding.
▶ 1:04:35In this strange new world, we're going to have AI doing a lot of this work for us and we're going to have a dearth of talent that really understands the way that AI works both for offense and defense. One of the things that I would really love to see the government put in place as well on the defensive front that you were talking about that we really need to secure, be more resilient at home, is to create kind of a teach for America, but in the cyber realm.
▶ 1:04:57So, the government perhaps funds some training for people and in return, you give two years back where you work in a school system. You work in a rural area. You're responsible for cybersecurity in a whole raft of, you know, rural water treatment facilities and you then repay what the loan you got basically to to go to school and you give to communities that are desperately in need of strong cyber talent to build a better defense. Yeah, thank you for mentioning that. I am a big supporter of Teach for America.
▶ 1:05:27Coming from a school district and working, it is a great program and offers great incentives that brings many talents from across the world to work in a school district. So, thank you for that. Mr. Backley. Thank you. I think with my limited time, two primary ways we should think about this are one with pathways, but we shouldn't think about pathways only being at the beginning of the career cycle.
▶ 1:05:48Instead, there should be more return-to-work programs where those who have taken time out of the workforce, such as to be a caretaker or those who have taken a different career path, still have a path back into cybersecurity. And the second, and I think that enables the first, is really this upskilling we're seeing with AI.
▶ 1:06:06Now that we have this notion where a lot of automation can occur and we're really relying upon talent to make have wisdom and do good decision-making, we're no longer relying upon the same set of skills that would have taken years and years to learn when we were talking about coding from scratch. And so, I think that's something we should really leverage as an opportunity to bring more into the workforce. Thank you so much with that. Mr. Chairman, with that, I yield back. The gentlewoman yields back. I now recognize the gentleman from Florida, Mr. Gimenez, for his 5 minutes.
▶ 1:06:38Thank you very much, Mr. Chairman. I'm I'm sorry I wasn't here for the testimonies, so maybe some of these things have been have been answered. You know, if I were if I were a CEO of a a large corporation constantly being attacked and constantly being attacked, you know, from what I'm reading is I have limited capability of of hitting back. Yeah. That would be an itch that I really want to scratch, okay?
▶ 1:07:03And so, has there been any thought of creating I mean, some of our corporations have billions and billions of dollars, you know, probably way more capable than we are, okay, in terms of resources, of creating some kind of a private government, you know, offensive that would allow me to satisfy my itch, okay, and and hit back at some of these people that are hitting me all the time? Has there been a thought to do that?
▶ 1:07:32Do we have something like that? Anybody can answer. Thank you for the question, Congressman. Good to see you again. I think importantly, JCDC does possess the ability to nominate campaigns. And to nominate campaigns to those with Title 10 and Title 50 capabilities to be able to engage in appropriate activities such as taking down adversary infrastructure, such as doing some sort of activity that would hopefully deter and change that behavior.
▶ 1:08:02And so, I think that's the appropriate mechanism. So, I think if anything, this is something where there should be, as I noted in my written testimony, there should be something akin to a top 10, a most wanted list. Perhaps it's more than 10, but a most wanted list and that's the mechanism by which companies, organizations, nonprofits, academia, those affected, those impacted can work through JCDC, get those that have a high impact nominated and then using existing capabilities can at a high tempo go after these
▶ 1:08:32sorts of adversaries. So, that we can control that who it is that we're going after. The government controls who who we're going after. It's like a bounty. You're a bounty hunter. It's a public-private collaboration. Okay. All right. Mr. Gimenez, if I could just expand on that, I I think this is a significant issue and an important issue and I think time to really address this particular matter. In addition to JCDC, the National Security Agency has its its cybersecurity collaboration center which coordinates with the defense industrial base.
▶ 1:09:03I think there is an opportunity to get to genuine operational collaboration. I don't want I don't want Yosemite Sam shooting all over the place, but at the end of the day, think about it as suppressive fire. Think about it in a football context. You you have offense, you have defense, you have linebackers who blitz the adversary the the other team's quarterback.
▶ 1:09:24So, all things said and done, I think we need to get to that point and I think there are some authorities questions that need to be answered, but your itch is my itch and it's been there for a long time. I like your football analogy since I'm a big Cane fan, okay? And and we're in the
▶ 1:09:43two daughters who went to Miami, so I know they've got their NIL money. question that I have is that, you know, we have a criminal element that's a lot of it's based overseas, a lot of it based in some adversarial What is Do we have Do we have evidence that the those adversarial countries are actually working with those criminal elements inside to hit us?
▶ 1:10:09And do we have any evidence that they actually get a cut of whatever it is that those criminal elements do get? Open-ended question, anybody wish to I'll I'll start on that one briefly. Um it's a complicated answer to what seems like a very straight-forward question. Uh in the sense of China, we are seeing more sort of popping up of criminal networks that seem to be, you know, government people who are moonlighting on the side at night doing criminal activity.
▶ 1:10:37But China's pretty locked down, you know, they they like to control their people and what they're doing, so it's a sort of a tight ship that they run. Russia, on the other hand, is a very different story. We see more of a an atmosphere where there's a commander's intent. You know, Putin wants this particular adversary to have problems, go forth and make it happen.
▶ 1:10:57There's kind of a a deal that happens between a lot of Russian criminal networks and the Russian state, where the Russian state says, "You're going to operate outside of Russia, you're going to make life hard for our adversaries, we're going to ignore the criminal activity that you're doing and allow you to operate. But if you get crossed with us, then we will come after you and arrest you on a moment's notice." Do they get a cut? I'm sorry? Does the government get a cut of the profit of the criminal activity? There's probably some interesting work to be done following the money there.
▶ 1:11:26I mean, in Russia in particular, there's a lot of corruption, right? So yes, you know, do you do you get a kickback for allowing criminal activity to go on? I would assume so, but you'd want somebody to really get in deep and follow the money there. My final comment is going to be if we continue just to play defense and play defense and play defense, we're just inviting attacks. And so we need to go on the offensive and really whack them as as hard as they whack us, we need to whack them twice as hard so that the the stuff stops.
▶ 1:11:54Um and with that, my time is up and I yield back. Thank you. The gentleman yields back. I now recognize the gentleman from Virginia, Mr. Wexton, for his 5 minutes. Thank you, Mr. Chairman. I want to add to the condolences for the family and loved ones of Renee Good. She had three children, including a 6-year-old, who are all without their mother today. Uh Mr.
▶ 1:12:18Chairman, thank you for convening today's hearing and you beat me to the punch on the sports analogies. You're I think it's still the case, however, maybe arguable that defense wins championships. The Commanders have no offense and no defense, but I think I think both are still both are still important. Yeah.
▶ 1:12:45Yeah, a talented workforce combined with a a federal IT infrastructure that embraces cutting-edge technologies, I think should be the foundation of our efforts to counter cyber threats and to maintain a an offensive cyber posture or grow our offensive cyber posture.
▶ 1:13:05It does trouble me that last year a third of the workforce, and this has been noted by others already, at CISA, which is our leading agency to deter threats to both our cyber and physical infrastructure, was wiped out uh by DOJ in the recent shutdown. Staff at CISA received RIF notices, turned out those notices were illegal according to the courts. And a lot of them were moved to ICE and CBP to engage in immigration enforcement efforts.
▶ 1:13:35So these staffing cuts have left a big hole in our cyber defenses, our ability to combat attacks from Iran, Russia, the PRC has been noted. Uh Mr.
▶ 1:13:48Bagley, in your written testimony, cyber security to physical security and you made the point that in a city, even with a very successful crackdown on crime where law enforcement is going out and arresting the bad guys, still prudent to lock your door at night.
▶ 1:14:14And unfortunately, in my view, the firing of many of our cyber experts unlocks and and opens some of our doors. So I'm I'm hopeful that will be reversed.
▶ 1:14:28One of my concerns is the administration's elimination of the Multi-State Information Sharing and Analysis Center, which is a critical tool for decades for state and local governments, especially small rural local governments who maybe didn't have their own resources or capacity to have visibility into the cyber threats that they face.
▶ 1:14:54And I think it's the case that even if we want to be more aggressive in terms of our offensive cyber posture, we have to start from a place of visibility into the threats and cyber attacks that we're facing, especially state and local governments, which, as a former local government official know, a lot of the personally identifiable information of every single American is held by state and local government.
▶ 1:15:20So the loss of that capacity uh concerns me. I want to I want to just um dig in a little bit and there's been a lot of agreement, but Mr. Lynn, you said in your testimony our offensive cyber utilizes bespoke teams, not at an industrial level, kind of limited in your view. Ms. Harding, you said the US offensive cyber capabilities are strong, perhaps unmatched in the world.
▶ 1:15:49A little bit different analysis there. I only have 1 minute, so maybe I'll give you each 30 seconds to let me know whether you all disagree or agree. Yes, sir. Um not contradictory. Okay.
▶ 1:16:04Um what I would say is this, which is yes, uh we have some of the most talented cyber operators in the world. Uh highly committed to the mission, uh very, very creative in terms of what they're able to pull off. I think we've seen perhaps a little bit of a evidence of that in the last couple months. Um however, to what extent can they actually conduct those types of operations at scale? That is fundamentally what we're talking about here.
▶ 1:16:26Can they conduct those operations at speed and scale versus episodically and in cases uh where uh in those cases, does it take months or perhaps even years of planning to be able to pull off what they did?
▶ 1:16:38Okay, Ms. Harding. Again, not contradictory, right? I think one interesting case study was the the Symphony exercise that we did a few years ago against ISIS in Syria. You can read through that and see just how many layers of approvals had to take place in order for that operation to come off. Now things have changed since then, but it's really important to note that it's not necessarily I mean, you could have 100 people or you could have 10 people running an operation.
▶ 1:17:04If it takes them 4 months to get the approvals they need to actually execute on the operation, then the the opportunity is going to go, they they're going to miss it. So it's we are the most talented. We also, I think, need a more robust
▶ 1:17:18Thank you. Thank you, Mr. Chairman. The gentleman yields back and you have to continue the the sports analogy. You know, I think we are when you look at cyber capabilities in this rebuilding phase, where we need that better collaboration. We need quality versus quantity. We need those force multipliers, which includes the private sector. That is the way forward. And with that, I recognize the gentleman from New York, the chairman of the full committee, to use as much time as he
▶ 1:17:44I wish that was the case. Thank you very much, Chairman. Thank you very much for witnessing for being here and to admit you're a Jets fan is very I mean, it's it's a difficult It's a difficult thing to do every year. watch them every year, it's very but uh yeah. Uh Mr. Ms. Harding, I have a question with you.
▶ 1:18:08If the United States adopts a more forward-leaning cyber posture, including the use of private sector capabilities to disrupt or impose costs on foreign adversaries, what should the operational role of DHS and CISA be when retaliatory cyber activities targets the homeland? Right. So what we've heard from the private sector through through the evolution of CISA and and DHS is that they see them as the good guys.
▶ 1:18:34When FBI shows up and asks a lot of questions, you know, they they want to be helpful, but they're also there to look for criminal activity and to prosecute the criminals. That's a very specific skill set. When they talk to CISA and when they talk to DHS, what they're really feeling like they're getting is more of a partner. Um and I think that, you know, the JCDC had its upsides and its downsides, but it was in fact doing a lot of good trust-building with the private sector. Um and it was a place to collaborate. I think that trying to adapt that, to adjust that, to moderate it for the future is really important.
▶ 1:19:04And then what we were talking about with the two-way information sharing is absolutely critical. I think that the one of the criticisms that DHS frequently gets is that, you know, you you have your one person who you get cleared at the secret level and they go in and they get a briefing and they're like, "That's it? That's all you're giving me? I You read that in the New York Times. Um, so we need to be more aggressive in sharing some intelligence information that we have and that's hard for me to say as a former intelligence officer, but I do think it's important.
▶ 1:19:30No, absolutely. That's one of the, you know, I've been between ranking member and chairman for the last five years on this uh committee. The one thing I have heard repeatedly from our partners, private sector and allies overseas is um, we're very good at taking information, we're very not good we're very not it's a lot of one-way street. We're not good at sharing information. Just a follow up on that. Does Does DHS and CISA currently have the authorities or network access or operational agility required to move in that direction if that's where we go?
▶ 1:20:01I'm sorry, you're you're asking if DHS has the capabilities to conduct offensive cyber actions. Well, I mean, does CISA have the authorities necessary to do it or do we have to give them more authorities? Do we Do we have to give them more access to Is there some Is there action that we need to do so the private sector can work with this uh their these partners in CISA?
▶ 1:20:20Yes, I mean, I think that there there's a sort of patchwork of authorities out there that you can cobble together to do some pretty impressive things, but I think looking at it from a zero-based standpoint and saying what we want to achieve here is really tight collaboration between the government and the private sector and what we want to do is take the best athlete from each team to sort of continue the analysis. What can we do to to make that happen and to really um let the private sector shine in the things that they're very good at. I suspect my my co-panelists might have some other thoughts about the specific authorities of DHS, though. Sure.
▶ 1:20:51I'm paying if you want. If I may. Um, one of the other things that I would add, right, is that we have to start thinking about cyber as a core element of multi-domain operations. So when HSIs conducting investigations, they should have the ability, the authority, the resources needed to be able to leverage cyber capabilities as part of their work.
▶ 1:21:09When Coast Guard is conducting missions, given their unique authorities as my panelists have said, they should be able to leverage they should have the capabilities and the tool sets needed to be able to leverage cyber offensive cyber as part of their core And and just to build on that, Mr. Chairman, is I mean Emily brought up JCDC. I I think JCDC again, pros, cons, but in the event of a crisis, they're actually quite good.
▶ 1:21:34Bombs stop drop Bombs stop start dropping in Ukraine, they can get critical infrastructure owner operators together, they can start sharing information, but it's episodic. It's only when there is a big event. What is that daily battle rhythm? I mean go with the sports analogies which I started, sorry, but at the end of the day, you got to put the reps in. You're not going suddenly become a five-star recruit if if you haven't been in the gym and on the field for for years.
▶ 1:22:03So I think there needs to be something there that allows it to succeed not only in a bad day, but every day, so you're ready for that bad day. And and I think Mr. Jimenez, I I am very much at the point where I think there are some authorities and some protections that are needed. Firstly, WINWEG, you got to get that over the goal line. That is essential. You can't trust the government's going to lose all confidence of the private sector if we can't even get the basics.
▶ 1:22:32Imagine kicking us back a decade. That's what we're we're looking at here. That's unacceptable, so thank you for your leadership there, but I think just as importantly, you do need to also look to what that combined operation could look from a collaboration standpoint. Not industry on its own in conjunction with Absolutely. I ran out of time. Mr.
▶ 1:22:57Magaziner, I will let you uh add on and I'll I'll I'll yield back, but as for WINWEG and Pillar, those are two things that that we're we're making a hard push and I I believe the minority is also making a hard push uh as well as the Senate minority to to get included in our final package next instead of just a blank extender or short-term extender to get actually uh the bills done in next week's um final package, but uh we will see and uh with that uh Chairman, I yield back.
▶ 1:23:27The Chairman yields back and I'll recognize the gentleman from Rhode Island, Mr. Magaziner, for his five minutes. Thank you, Mr. Chairman. I I also want to start by offering my condolences to the family of Renee Good, especially her children, uh who are going to have to live the rest of their lives without their You know, we have a long history in this country of protest and civil disobedience and those who engage in protest know that uh there can be consequences for doing so, but those consequences shouldn't be
▶ 1:23:57a death I had an opportunity uh to attend an event over the weekend with all the police chiefs across Rhode Island. Uh several of whom came up to me and said that the tactics that they are seeing increasingly being employed uh by federal agents of immigration enforcement are tactics that police departments stopped using years ago.
▶ 1:24:16And one of the things that I think we need to do as a committee is exercise our oversight responsibilities to see what leadership level what the leadership level at DHS is instructing its agents and officers in the field to do because if they are not getting the proper training and guidance, not only does it do a disservice to the civilians who are being put at risk, but also to the officers and agents themselves.
▶ 1:24:42Now that being said, um I'm very glad that we're having a hearing today on this topic and I thank you, Mr. Chairman. Uh on on topic of uh how we deter and disrupt uh cyber attacks in the United States because it has often occurred to me that these attacks are happening at increasing frequency and increasing brazenness uh and when I ask what the consequences are when foreign actors and other adversaries conduct these attacks, uh there don't seem to be any.
▶ 1:25:09And we do need to have I think a serious retooling of the way that we think about this and uh if there are malign actors out there that continue to attack us in the cyber domain, we need to have the ability and the intent uh to uh disrupt their ability to continue to do so. Period.
▶ 1:25:30Um this is a little bit of a difficult conversation to have in an open setting and one of the things that I was going to suggest, Chairman, is perhaps we could continue this conversation in a in a classified setting at some point so we can get into the weeds of what some of the different offensive deterrents could be um in a way that that we don't want to project publicly, but I just want to ask our panelists at a high level, when we think about what the parameters should be uh in terms of our offensive cyber actions uh
▶ 1:26:00to to disrupt these threats, um what are the sort of boundaries that we want to give not just to our cyber warriors, but that we want to project to the rest of the world, keeping in mind that we're in an open setting here. I noticed, for example, uh Ms. Harding, uh you wrote in your testimony the US prides itself on protecting innocent civilians, not targeting them. Therefore, a proportional response to a cyber attack on our critical infrastructure would be severe and likely include economic or military measures.
▶ 1:26:31So like I'll start with you and I'll give the others a chance to weigh in. When you think about what the the boundaries should be, what should be off-limits, what we want to project our boundaries as being, how how do we think about that? So we have always prided ourselves in trying to protect civilian life. You know, if you're an innocent bystander, you shouldn't be wrapped into the the political fighting that's going on and then the actual fighting that's going on. So I think that a clear bright line is civilian critical infrastructure.
▶ 1:26:56You know, if if you are shutting off the lights in a city, hypothetically, for a military action, that's one thing, but the lights came back on. This is not, you know, dropping Kyiv into winter um without any power and without any heat. That should be a very clear bright line. And I think that part of what we're all saying here is that we need to stop thinking about cyber as this thing that's over here in a silo. We need to think about it as fully integrated in the full range of policy measures.
▶ 1:27:23And we don't necessarily have to respond to an attack on critical infrastructure with an attack on critical infrastructure. We're the United States of America. We have We have other Would anyone else like to weigh in on this question? Yeah, Mr. Lin. Yeah. Thanks, sir. Uh if I may, two thoughts. One, um I would like for us to get to a place where we're not thinking about retaliation because we have done such a good job of being proactive in disrupting adversary operations well before they're able they're able to conduct attacks against us. That's number one.
▶ 1:27:50Um number two, what you were alluding to, sir, is the fact that there is this very perverse cost calculus for our adversaries. They have every incentive to go on the offense against us. There is no punishment. There is no cost. And so the question that we should be asking, the objective is how do we insert enough friction to drive up the cost, to change their cost calculus such that they're not thinking about offensive cyber operations as something that is easy to do, that they reap all the benefits from and suffer no consequences. Yeah, that makes sense.
▶ 1:28:20And I'm my time is is running out, so I'll just say this. Um I agree and I think this is an important conversation for us to be having. We also have to anticipate that our actions could provoke reactions and so we will need to harden our defensive cyber capabilities as well. That is why it is so important that we staff up and fund CISA and other agencies tasked with cyber defenses, not defund them, not shift resources away from them as unfortunately I think has been happening over the last year or so.
▶ 1:28:50Um but but directionally I think everything that you all are saying makes a lot of sense. And with that, I yield The gentleman yields back and and uh Mr. Magaziner, uh to your point, one of the things that I am working on is a round table approach where we can gather industry experts and then we would have that in a SCIF to allow for more
▶ 1:29:15you know, as as you see the kinetic action that took place with Maduro. I think we unveiled technologies that probably caught our adversaries off guard. Which means that the cyber attacks are going to escalate now. And so there has to be that cost-benefit analysis of if you move ahead, what is the penalty for your country, for your you know, whatever group or organization that is attached to Russia or China.
▶ 1:29:42But you know, sticking with that, when you look at our current, you know, we've relied on attribution, sanctions, indictments, defensive improvements, which is critically important to respond to state-sponsored activity. You will see Chinese and Russian campaigns continue with increasing persistence and confidence. In your judgment, what actually changes adversarial behavior in the cyberspace? And so we'll just go down the line, you know, Mr. Lynn, we put you in charge of cyber force.
▶ 1:30:09Your job in charge is to protect United States of America, to implement the Monroe Doctrine, to make it clear that the Western Hemisphere includes the cyber realm. What do you do next, sir?
▶ 1:30:24Miss Harding's ready. A couple things. Um let me start by adding an additional observation, which is that what we're seeing from our adversaries is wholesale adoption of artificial intelligence for the purpose of offensive cyber.
▶ 1:30:40Uh you can be to hearing, sir, uh previously uh where uh that was uh soon after this was disclosed by Anthropic, where they discovered that uh state-directed PRC threat actors were abusing their models to be able to conduct operations uh against American targets, uh both government and commercial. There has to be wholesale adoption on our end.
▶ 1:31:03Smart, well-regulated, governed, thoughtful, but wholesale adoption of artificial intelligence capabilities merged in with modern software that we're using to equip first equip our soldiers, our warfighters with the capabilities to be able to operate at the speed and scale that's needed in order to compete in this domain. If we're single If we're single-threading operations, we will be losing. That's number one. Number two, um we have a lot of authorities in place.
▶ 1:31:29Again, I think some of my panelists have mentioned this before, which is there has to be a will, uh a political will to employ these capabilities against our adversaries. Miss Harding. Uh so I love thinking like the adversary, and I like trying to figure out how we can hold to American values and morals, but still really mess with the other guys. Um disruption, I think is the the number one point. If you unleash our cyber operators, where the minute they see some adversary activity on a particular node, they can go after that node and shut it down. That's key.
▶ 1:32:00A critical point in this is actually incorporating our allies. As you know, the internet is global. It's not just one point, right? It actually touches on a lot of different things. You need to have a bunch of allies in place that can say, "Yes, I'm in favor of this. Let's go do it." Number two, we've gotten really good at very targeted activity. There's no real reason to go after an entire network if you know exactly where the bad guys are operating and you can mess with them specifically. I think more about that in closed session would be good. And then finally, rapid response is really important.
▶ 1:32:30Right now, our cyber operators are frequently asked to do things on a time scale that's just impossible because they haven't been given the time and the opportunity to actually build a toolkit. I think we do need more people, and we also need more authorities to go and build those things ahead of time so that when something happens, there can be a very quick punishing response to create that deterrence. Um basically, to sum it up, unleash the cyber operators.
▶ 1:32:53Let them We'll pause there, and we'll come back to you, sir, in just a moment, but I'd like to recognize the gentleman from Texas, Mr. Luttrell, first.
▶ 1:33:01Thank you, Mr. Chairman, for giving me my tardiness. Morning, [snorts] I will throw this one uh probably Mr. Bagley, but Miss Harding, you can jump in on as well. I'm I like to talk on undersea Defensive, offensive posturing on our undersea cabling system, which remarkably, as most of you probably know, that over 90% of all of our information flows through these cabling systems that we have, the three different the varying types that we have.
▶ 1:33:29The organizations that sit on top that provide us those cabling capabilities, who protects the system itself, which department that may be, whether it's Homeland Security, DOJ, or Department of War? If you guys have an answer for me on that one, that'd be amazing, cuz I can't seem to figure that one out. And how do we release our our our our frontline operators, if necessary?
▶ 1:33:56How do we defend against the bad actors globally that most likely know where our cabling systems lie, how to attack them? And then I don't I really don't really care how much redundancy we have in anything. One good one, it's it's kind of a showstopper. So, I threw that one at you, Mr. Bagley, but absolutely anybody on the panel, if you are educated in this in any way, please share that information with me. Uh thank you, Mr. Congressman, for the question.
▶ 1:34:22I think fundamentally, as you're noting, one of the risks of uh posed to undersea cables comes from the physical realm and the ability to actually uh cut cables, to splice cables, and ultimately to redirect traffic, right? We've seen this time and time again where adversaries have been able to do that, redirect traffic. Part of that actually goes to the network design of the internet itself, of the domain name system, and the ways in which, by design, it redirects when it when it reaches [clears throat] a dead end. Um so
▶ 1:34:52have enough redundancy in place to do a redirect? Cuz these cables are on average, what, twice a week, possibly, are hit, and then it takes months to fix it if we can figure out who which shore line's going to be responsible for it. Yeah, that it it's it's a great example of a cross-domain style attack in many ways that then also uh needs a cross-domain response.
▶ 1:35:15So, the US Navy, naturally, is going to own part of that, but also network operators and those who own the cables themselves, as the majority of infrastructure is owned by by the private sector. So, a lot of what we've talked about today that I think is very important here is how to deter adversary behavior, how to make it so that their risk calculus changes when they decide that they're going to splice a cable, cut a cable.
▶ 1:35:40And I think that's something that we should see as going well beyond just the cyber domain and thinking about all of our capabilities, including those uh again with the US Navy as far as undersea cables uh you know
▶ 1:35:51Physical security is one aspect of it. I mean, there's so many of them, and when it when it when it's onshore, it's even worse considering the threat levels that exist in the metaverse that sit above our head. Putting a I don't think that globally we agree on what prosecution looks like for those that are cutting these cables, whether or not it's an accident, whether or not it's by anchor, a fishing vessel that drags their or it's a nefarious.
▶ 1:36:20I don't know if we can have where we need to be, because oddly enough, what we're receiving from the private sector is very different than what we kind of see here in where do we basically go from here is my question, Miss Harding. Thank you. Um so, one of my folks on staff is our Coast Guard fellow actually right now who just wrote a really excellent piece on this, uh Joe Coido, on the undersea cables and legal prosecution options for this.
▶ 1:36:48that from you guys, please?
▶ 1:36:49Absolutely, sir. I'll I'll be sure to send it to you. Um I would also say, just for for really precise recommendations, more repair ships so they can get back up and running quickly. I would like to know how many Okay. and what that looks like. That's information that we need to know. We will get you that, sir. Uh and then I do have a lot of hope here for AI surveillance. So, a lot of the ships that are accidentally, with air quotes, going after these cables are operating in very strange patterns on top of them.
▶ 1:37:15And if you can get eyes on that target and you can identify a pattern of behavior that's anomalous, that really doesn't look much like fishing, um then you can get on scene quickly and then hopefully deter that activity by interrupting it. Mr. Luttrell, if I could just We recently hosted a lengthy podcast specifically on this issue, and I think you're right to underscore.
▶ 1:37:36If you were to compare the intelligence, without getting into anything classified, capabilities we'd have for space, for cyber, for land, sea is actually we have very little visibility.
▶ 1:37:48Very little. Correct. Yes. And the scale and scope and just distance is massive, and the dependencies are are essential. But I think here what we're really getting at, and and and again, this isn't to punt on your question, but it is multi-domain. We need all the intelligence disciplines to merge, and we need to invest more in undersea.
▶ 1:38:09It seems like the multi-discipline domains that live and breathe don't pay attention to everything in the middle.
▶ 1:38:17Cuz it goes underwater, nobody sees it. Absolutely right. I You can It's fine. Okay, thank you. When we talk about the the agencies and then we we inject the Navy.
▶ 1:38:30Now, I don't know if you can really move through silos very well on your side, but I'll tell you what, getting Department of Department of War to talk to Department of State or whomever up there, I was in the military, it was very challenging But since we have so much of this information that lives and breathes, do we need to increase and I don't have a name for it, I'm just kind of making this up as I go.
▶ 1:38:51Do we need to increase kind of our undersea cabling fleet, as you mentioned, Miss Harding, but I think we we have two two vessels, two companies that kind of touch this, and then if you and then of course, China and France and whomeever else is really kind of Italy's getting really getting into this. Is that something that we in Congress need to talk to the Department of of the Navy because honestly the chairman I really paying attention this but I don't think that like enough folks are paying attention to this.
▶ 1:39:21I 100% agree that not enough people are paying attention to this and because it is such a a complicated set of actors that need to be involved and yes a lot of attention a lot of focus across disciplinary effort is important. Talk to the Navy absolutely. I think it's also about creating the incentive structures for some folks in the private sector to really invest more in the capability to protect the technology and then also to repair it.
▶ 1:39:42Well, I think they would if it wasn't so complicated to get that done because you now you're dealing with the government. Who do you think is in charge? Of undersea cables? Yeah. Who's the subject matter expert? Inside the government? Or anybody? Well,
▶ 1:39:57I know I have some at CSIS but inside the government I would say that there's no one good home. Okay, thank you. Thank you Mr. Chairman. You know, as fate would have it all three of us have had these conversations about undersea cables uh and the vulnerabilities that they that they create. But uh so if if we will we're we're getting near the end we'll pick up with you're in charge of the cyber force what's your next step then it once Mr.
▶ 1:40:25Bagley goes we can simply go down the line uh one after another for kind of closing remarks uh anything that you want to emphasize that we missed or quite frankly that we got wrong. That's what this hearing is for. You are the uh subject matter experts and we need and want to hear from you because part of my job and our job collectively is to bring this to the forefront because we are literally under attack and quite frankly I don't think enough agencies and departments are working together that one-way street of information and we're not fully prepared. Mr. Sloat.
▶ 1:40:55Uh Chairman O'Halleran thank you and uh God help us all if I were uh leading a uh cyber force. But uh firstly I think uh Mr. Lynn captured the end state well. I don't want to be reacting. We're always marching into the future in in essence we've literally seeded the battlefield to our enemy. They do something we respond. We need to be able to shape that environment and and I think I mentioned suppressive fire is sort of a tactical set of issues adding friction into the system.
▶ 1:41:26I don't want to get to that point where it is already too late. If that's the time we're demonstrating our capability game over we've already uh lost to one extent or another. So how do we do this in a proactive environment? I I I hate to say it I think political will is essential here. Again to have a deterrent it has to be credible. It has to be consistent. If a line is crossed you have to respond. How many more darn lines have to be crossed?
▶ 1:41:56I I I feel like uh uh we we've we've had this discussion for a while. So I think political will demonstrating capabilities um differentiating between salt and volt typhoon. I'm very much where Emily is here. Uh salt typhoon it it's awful but hats off. I I mean I'm shocked there's gambling going on in the casino uh to take from Casablanca. I mean truth is is that's what they're doing they're doing well.
▶ 1:42:22Volt typhoon on the other hand is a clear line that has been crossed and there were zero consequences. So I think uh ultimately it's uh it's bringing all instruments of uh of national power of which cyber is a big one and quite honestly I think it's unleashing some of the capabilities of not only our operators but also our front line uh owner operator critical infrastructure Uh
▶ 1:42:52thank you Mr. Chairman. I think fundamentally you know, when we think about what's been previewed so far with the forthcoming national cybersecurity from Director Kierancross and specifically pillar one which focuses on this notion of changing adversary behavior I think some core objectives that should just be baseline really are that we need to be changing behavior so that we're diminishing the ability of the adversary to scale and diminishing the ability
▶ 1:43:22of the adversary to repeat. Those two basic things alone are fundamentally important when we're talking about the rate at which adversaries are adapting the rate at which technologies evolving and and machine speed is now the the speed at which we're all moving at.
▶ 1:43:38And so I think that in doing that you know, as as as Frank was noting I I think there is a distinction of course between espionage used to collect information and actual cyber attacks that are attacks or that are prepositioning for attacks. And I think that's what need to be needs to be prioritized fundamentally prioritized where we are changing behavior so that there are costs for attacking the United States.
▶ 1:44:05There are costs for attacking our allies and that fundamentally there is a risk calculus that the adversary is going to have to Mr. Lynn closing thoughts? Thank you, sir. Um just three.
▶ 1:44:19Uh number one um again I think it's absolutely critical as you alluded to sir that we understand the escalation dynamics that are at play Uh that the escalation dynamics are such that right now currently there is little to no cost for our adversaries to hold our society our country at risk to place the digital equivalent of explosives uh into our critical infrastructure networks right uh in order to preposition for war and to hold that sword over our heads.
▶ 1:44:49We have to change that. Playing defense simply is not enough. Number two um we really do have to start moving at machine speed. So while I appreciate the fact that we certainly need uh more talented people we need to have the right talent pipeline going into government uh going into cyber command going to DHS uh going to NSA. At the end of the day we we we simply cannot be throwing more people at the problem.
▶ 1:45:13And so that brings me to my last point which is that um we have to be smart about how we are investing in our offensive cyber capabilities. We have to make sure not just that it's resourced. So Congress passed as you will know sir um uh Congress passed a billion dollars for offensive cyber in the reconciliation bill plus another quarter billion dollars for artificial intelligence to be used in offensive cyber in the reconciliation bill. That's an amazing down payment.
▶ 1:45:38We need to make sure that resourcing uh is not just spent on more bodies or on legacy government programs but on the types of capabilities that enable our people to operate at 100X of where they are today. So two points. Uh number one intel collection in the private sector. We need to take a hard look at the way we do contracting with the private sector.
▶ 1:46:01They have an intelligence collection network that does in fact rival the US government's and it is tapped but only in a patchwork sense. This is their lifeblood this is how they make money. So the government does need to work with them to actually pay for that information but there are much more efficient ways of bringing it into the system and using it across the US government for better indications and Number two I think this is a more strategic point. I've heard a lot today that sounds like defense defense and offense in the cyber realm are in opposition to each other.
▶ 1:46:30That's not the way to look at it. It really is both. It's a both and. In fact our offensive capability is severely hamstrung by our lack of good defense. A lot of times what we see playing out in government discussions is there's a great idea for a cyber operation and then the policy decision is well if we do that then they're going to hit us back and we're weaker than they are defensively. So in fact we're deterring ourselves. We have to fix that defensive picture so that we can unleash on the offensive front.
▶ 1:47:02Again the challenge of going after two panelists that I agree with 100%. So I'll I'll go back with the the football analogy. We actually need a head coach where both the offensive and defensive coordinators feed the playbooks into and and that I think should be the national cyber director.
▶ 1:47:21Because ultimately if and to to to pivot to another sports analogy if we're going to be punching we've got to be able to absorb the punches and and and the reality is is we have a whole lot more to lose than uh some of our adversaries. The flip side is as you hear a lot of people saying oh it's going to create escalation. I don't know what more escalation could can happen before we recognize there has to be uh consequence for uh uh inducing change in in in bad behavior.
▶ 1:47:50The public-private partnership long on nouns short on verbs. Time we finally get to what is operational collaboration. Move beyond the information sharing questions which are essential. If we really want to be creative there why doesn't critical infrastructure have the ability to levy intelligence requirements? Maybe the national intelligence priority framework should be open to some of our most essential critical infrastructure owner operators.
▶ 1:48:17There are some creative things we can do there but ultimately it can't be if you don't have the trust that we currently do not fully have at the at the scale we need. If you're not in the foxhole fighting the same fight on every day you're always going to plug and play in the midst of a crisis and that's not the time to be exchanging business cards. That's not the time to get to know one another. You got to do it in advance. Mr. Bagley.
▶ 1:48:47Thank you. Couldn't agree more that defense is fundamental for anything we're going to do that would be more aggressive in trying to change adversary behavior. Defense is foundational and the two should not be viewed as some sort of dichotomy that resources allocated for defense are at the expense of offense or vice versa. It's two two different two different um But defense fundamentally is something that should always be viewed as something that is ever evolving.
▶ 1:49:17We should never think that you can make a one-time investment or choose a number that is the same number for years of investment and that that will be sufficient in protecting our federal systems and protecting our critical infrastructure or in organizations protecting themselves around the country. And so it's fundamental to note that as adversaries evolve, defenders must adapt. As new technologies are deployed, they need to be deployed with security so that they can be deployed with confidence.
▶ 1:49:45Because if they're not, then they'll just increase the attack surface. And this is fundamental as we as a country innovate with AI, adopt AI quickly, and also want to leverage the benefits from AI. So I would implore the committee to continue the great oversight work it's doing to think about the US government is using these technologies, but also how the US government is increasing its own defense as it looks to change the risk calculus for adversaries. Thank you.
▶ 1:50:13Let me ask you something.
▶ 1:50:16Very well spoken, all four of you. I would hate for all of you to walk out that door and then what you recommended to Congress never shows up again. The the presentation outlined if I was to ask all four of you, do you agree on one specific thing that you can push up to this committee that we can help you? That might be challenging.
▶ 1:50:41If you're counting on Congress to write out what the internal infrastructure looks like defensively and offensively, it will That's why we're that's why you're here. But on you need to be on send while we're on receive and say, "Hey, through heavy negotiation, a large amount of debate, this is what we think is the baseline assessment and this we progressively move forward." Cuz we're happy.
▶ 1:51:07This committee and I would assume more the majority members of Congress understand the threat, the viable threat and risk to cyber cyber attacks. We do. And even more so we're getting there. You'd be surprised how many people walk into our offices with the great idea that needs $20 billion dollars every day. It would be nice if the collective whole of the most brilliant operators that this country has would show up with like, "This is what we've come up with.
▶ 1:51:35This is the best way forward and it will flex left, right of center." It does not have a hardcore left or right flex. You cannot do that in the digital space. But what we understand, what we know now and where we're going downstream, this is this is our starting point. Okay? Fair enough? Thank you, Mr. Chairman. I want to thank you all uh for your testimony today.
▶ 1:51:56And I think when you look at some of the conflict and the the partisan nature of that is Congress, that you you see a great deal of agreement amongst the panelists, but also the members. And I think that underscores the urgency of the topic and the subject you know, nature of the We are under attack. The war has begun. And we are fighting it from multiple adversaries.
▶ 1:52:23We have Russia, we have malign actors, we have Iran, we have North Korea, and of course we have And let me be clear. We are the United States of America. We have been alerted, we are aware, and we are watching. And if I have my will, we are going on offense. We're going to strengthen our defense. And there is going to be a price to pay when you incur, infringe on our borders, whether that's in the Western Hemisphere or in the cyberspace.
▶ 1:52:55I thank the witnesses. Members of the subcommittee may have some additional questions for the witnesses and we would ask that the witnesses to respond to these in writing. Pursuant to committee rule 7E, the hearing uh record will be open for 10 days without objection. The subcommittee is stands uh stands