▶ 0:01:44Hi, how are you?
▶ 0:05:43Why so much? I like Randy. Let's be nice. You know what his nickname was? Hello sir, how are you? It's good to see you. I'm Eileen Grant. Yeah. Mhm.
▶ 0:07:00Good job. I love you darling.
▶ 0:07:50That's awesome somebody. Okay, I I can sure. Nice to meet you. I'm working for So we do expect Hopefully we can do good questions on So just enjoy this job. Just one year. One year of appointment.
▶ 0:08:25By the By the time I learn how it works But we don't have a continuous service So good luck. I don't think See how it How's Carson?
▶ 0:08:55He's prepared for this. So he may raise it. I'm not sure if he'll be He may raise it in the next session. But it is a big issue for him. Great. Thank you.
▶ 0:21:33Okay, good afternoon. Good afternoon everyone and welcome to this hearing on information technology posture of the Department of Defense. To quote from Donald Rumsfeld, you fight with the network you've got. We conduct command and control with the networks that we have. We pair our warfighters with the business applications we have. We plan to conduct operations on the desktops and laptops that we have.
▶ 0:21:59We fight at the speed of data and the underlying IT has never been more What I want to hear today is simple, what is the state of these critical IT I'm interested in hearing more about the Department's plans to modernize the networks process, provide access to secure cloud environments at all security levels and ensure the cybersecurity of our DoD and industrial base assets.
▶ 0:22:18While we'll be addressing DoD's major artificial intelligence developments at an upcoming research and engineering posture hearing, it is critical to note that none of that technology works without the [snorts] foundation provided by IT. If the networks don't work well, nothing else will. So, with that, we're joined today by the Department of Defense Chief of Information Officer, Ms. Kirsten Davies. I want to thank you for being so accessible. We've seen you a lot and we're grateful that you are accessible and and open to interacting with us so freely.
▶ 0:22:49You joined the who joined the Department from the industry in December. She brings two decades of experience leading large-scale cybersecurity enterprise technology efforts for major global Ms. Davies, thank you for being here and for your willingness to serve and with that, I turn to Ms. Houlahan, the ranking member, before hearing our witness. Thank you, Chairman Bacon. And I would also like to join you in welcoming Ms. Kirsten J. Davies as CIO at her very first public appearance before this subcommittee.
▶ 0:23:18You have a really challenging job, I know, and I'm looking forward very much to working with you. In the interest of time, I'm going to make keep my remarks very brief as well. Gone are the days when the Department could focus simply on buying the latest weapon systems, blindly assuming that they will work without having to focus just as much on the vital networks and the data that enable them as well. It is that network and the information infrastructure that forms the backbone and the of the capabilities that our men and women of the Department of Defense depend on every single day.
▶ 0:23:48As CIO, the key initiatives under your purview are essential to the ability of the Department to stay ahead of pacing Zero trust implementation, network modernization, enterprise cloud adoption, protection of operational technology, securing our supply chain, and retirement of technical debt debt, including cryptographic modernization, are all critical to reducing our vulnerabilities and to increasing advanced increasingly advanced adversaries.
▶ 0:24:15Establishing a clear framework for data interoperability, for modernizing defense business systems, for continuing to deploy the mission partner environment, managing the Department's spectrum assets, and overhauling the authority to operate process are also just as critical to bringing our own operations up to speed. And most importantly, we must hire and retain the skilled workforce that these challenges demand.
▶ 0:24:40This has not been a straightforward matter in recent months, so I hope that we have this discussion aiming towards current and future initiatives that we can likewise dig into the effects of the deferred resignation program and hiring freezes for the Each of these matters I mentioned have been the subject of significant attention in recent National Defense Authorization Acts, but I know our work, just like yours, isn't done. You live these critical issues every single day.
▶ 0:25:09We look forward to hearing your perspectives on the Department's progress and challenges and what we here in Congress should consider for further action. There is absolutely no alternative other than to get this right. And with that, I want to thank again our witness for appearing today. Thank you, Mr. Chair, and I yield back. Before I recognize Ms. Davies, I just want to thank Ms. Houlahan. We've worked together on this committee, but we also co-chaired the the quality of life panel, which had a tremendous success, 29 uh different issues passed into law.
▶ 0:25:38So, that was a good teamwork. Ms. Davies, you're you are now recognized. Is my microphone working? Am I good? There we go. Thank you, Good afternoon, Chairman, Congresswoman Houlahan, uh distinguished members. Uh thank you for the opportunity to speak with you today about the Department's strategy to transform technology and cybersecurity into a decisive warfighting advantage.
▶ 0:26:04Our focus is to enable data supremacy and decision superiority in the contested battlefields of today and tomorrow at the speed and scale our warfighters deserve. In the latest initiative of Secretary Hagel's drive to efficiency we are undertaking a bold transformation of enterprise IT and cybersecurity program, unifying these capabilities under the Department's Chief Information Officer, myself.
▶ 0:26:31Through this effort, we we will eliminate inefficient spending, reduce technical debt, accelerate modernization, drive consistent and up-leveled cybersecurity, and unleash data and innovation from the core to the edge for our joint forces.
▶ 0:26:49Leveraging my oversight of DISA, the NSA's Cybersecurity Directorate, and the Department's Cyber Crime Center, we are working with military services, Joint Staff, combatant commands, and defense agencies across four transformative pillars. I'll provide a few highlights here.
▶ 0:27:07Under pillar one, the enduring digital foundation, we're transforming our network infrastructure and communications transport, which extend from undersea cables to terrestrial fiber to advanced satellite capabilities, connecting everything from the home front to the tactical edge. This foundation supports every warfighting system and our global installations.
▶ 0:27:29We're driving continual modernization, expansion, and hardening, as well as broad 5G usage and data center modernization. We're evolving our cloud strategy in JWCC next. We're also leading a proactive approach to spectrum management and advancing PNT, position, navigation, and timing, ensuring ready and resilient capabilities that enable American warfighting dominance.
▶ 0:27:55Under pillar two, agile digital capabilities, we're expanding and maturing digital offerings. We are accelerating delivery of software and SaaS services and streamlining data architectures for streamlined data flows. We are shifting from slow legacy software development to modern agile delivery, driving interoperability by design. And delivering applications and analytics at the speed of relevance.
▶ 0:28:24We are driving extensive defensive business systems work, whether modernizing or sunsetting old systems to enable clean audits and reduce wasteful spend. We are deploying mission partner environment, a persistent, secure environment where trusted partners can be rapidly integrated.
▶ 0:28:43Under pillar three, cybersecurity for the warfighting ecosystem, in alignment with President Trump's National Security Strategy and the National Defense Strategy, we're moving from checklist-driven compliance toward a unified, holistic, risk-based approach. We will emphasize automation and dynamic and continuous monitoring.
▶ 0:29:04We will drive risk reduction rather than burdensome paperwork, uh focusing on antifragility and resilience through a holistic blend of streamlined processes, advanced technologies, and skilled workers. We are refining the authority to operate process and accelerating our deployment of zero trust principles. We're also refining our risk management process and reigniting the DIB to align with the Secretary's Arsenal of Freedom initiatives.
▶ 0:29:32Finally, through pillar skills and partnerships, something that you mentioned in your opening comments, we recognize that people are our strategic edge. As part of our transformation, we're reviewing IT and cybersecurity roles to ensure clear responsibilities, accountability for outcomes, and a bias for action.
▶ 0:29:54We're leveraging your provisions in the fiscal year 2026 NDAA to enhance recruitment and retention of cyber professionals and expand competitive compensation. We will be launching an extended top-tier certification program in partnership with industry and academia, which will offer upskilling and cross-skilling for our warfighters from new recruits to seasoned service members.
▶ 0:30:20And because we do not fight alone, we're doubling down to influence the digital transformation efforts of our allies and partners, which will better ensure all of coalition force readiness. As we advance this bold strategy, thank you for your continued interest and support in IT and cybersecurity topics and for the resources you provide to protect national security.
▶ 0:30:44The race for data superiority and decision dominance is won or lost every day, and the strategy this strategy is a key part of how we together ensure the technology race is won by America. Together, we will ensure the resilience, readiness, and lethality of America's warfighters across every domain. I look forward to your questions. Well, thank you, Ms. Davis. I I appreciate uh your testimony. I got three questions. I'm going to recognize myself for 5 minutes.
▶ 0:31:12We're working hard to strengthen the defense of our industrial base to include Secretary of Hexeth's arsenal freedom arsenal of freedom initiative. But none of that works if the companies building our ships, muscles, and software are constantly getting hacked and losing intellectual property. Can you talk about how the department is thinking about cybersecurity not for its own IT, but as something that directly affects our supply chains and military readiness. What more does the department need to do to help improve cybersecurity across the industrial base, not just in the DOD networks?
▶ 0:31:44A great question. Thank you for that. Um you know, there's a lot that we can do. Historically speaking, um we've been focusing quite a bit in IT security across the confidentiality of data. Um from my perspective, that's bread and butter. We should be doing that across the board, across government, across industry as well. I think where we can really look to refine our focus is also in the integrity and the availability side.
▶ 0:32:09So, from the defense industrial base perspective, the arsenal of freedom is focused on munitions and advancement of of propagating more and more uh access for the DIB into our supply chain. We need to be looking much more holistically across the cybersecurity of our defense industrial base and their third parties as well. We do a lot of this work through DC3, uh which uh this body has supported in the past, and I hope you will continue to support in the future.
▶ 0:32:39We have a great outreach there to the DIB on cybersecurity matters. Also, through the NSA, we have a great outreach there. Thank you. Uh my second question is on operational technology or OT cybersecurity, things like industrial control systems, shipyard systems, and energy systems. These systems uh were or often were designed to be connected to networks. Now they are, which creates vulnerabilities.
▶ 0:33:02Can you talk about how this problem is across the department and what your priorities are for improving uh the security for the OT and critical infrastructure uh for our installations and facilities? Ranking member, a topic near and dear to my heart having come from the manufacturing industry. You're absolutely right to say that these systems were never intended to be connected directly to the internet. Um they're also uh legacy systems, largely speaking. They have a lot of hard coding in them, which means they're not readily updated.
▶ 0:33:32Um part of our focus area is going to be to establishing a center of excellence with regards to OT security. It's a very bespoke, specific set of skills that are needed there. Um security controls that are needed to be wrapped around those. It's also an interaction, again, uh to my previous comments around the defense industrial base.
▶ 0:33:53So, manufacturing has a lot of this operational technology, um and we need to be working more with them so that they are upgrading their security and their security standards therein. Thank you. Uh my third question deals with quantum computing. Obviously, if we have it, that's a huge uh you know, benefit for our side. It gives us an advantage. But if our adversaries get it, our encryption systems become vulnerable.
▶ 0:34:18Uh the higher math issues underlie our security or our encryption can be uh broken. So, I understand the department and the federal government's moving towards a post- quantum cryptography or new encryption methods that are resistance to quantum computing. Can you talk about what you're working on this or where where you're at? Chairman, um this is a huge field for us. Uh cryptography is a critical cornerstone of the Department of War systems.
▶ 0:34:48It's also a critical cornerstone across all government systems uh in and of itself. Um we have significant efforts in this, some of which I will defer to a close session rather than speaking about here. Um but we look at this really quite holistically. We have targets um uh from the federal government across government for us to achieve in the post-quantum compute world. It impacts everything from high to medium to low assurance devices, PKI, SSL.
▶ 0:35:15There's a significant piece of work uh that needs to be done not only for Department of War, but across government as well. And um I I'll defer to the close session for for greater details. Thank you. I yield to uh the acting ranking member, Ms. McCollum. The acting ranking member thanks the chairman. Um So, I have a lot of questions, but I think maybe I'll start um first of all welcoming you again.
▶ 0:35:42Um I know you haven't been in this position very long, and I'm so I'm actually very interested in kind of understanding your thoughts on electromagnetic spectrum as you head into this position from your outside experience. It's something that since I've been here, which is uh been 7 years, we've talked a lot about and done little about um deconflicting the use for commerce versus DOD or uh officially use or government use versus commercial use.
▶ 0:36:10Um we know that both have a valid claim or use for the for the spectrum. In your opinion or assessment these early days, how do you feel as though the DOD is doing in terms of using the spectrum efficiently?
▶ 0:36:28Thank you for that question. Um also passionate on this topic as well. Um we do understand that uh prior to my arriving, there has been some great negotiations and laying flat in the one big beautiful bill with regards to certain bands being protected, which is is wonderful. We know that uh the US military uses spectrum for every mission across all of our domains. It is critical.
▶ 0:36:52As the CIO for the department, um it rests in in my office to be navigating this for the Department of War with regards to broader interagency discussions, um and I'm certainly involved uh and my team is involved in great detail across these discussions. We know economic security is national security, and our warfighting is national security as well. So, you have my commitment that I'll be balancing.
▶ 0:37:17you currently believe it to be being used efficiently and um cooperatively with industry? The spectrum. It It is in in my estimation, it is right now. Of course, there are ongoing There's a balancing to be had ongoing. Uh the president has been very clear about his his direction with regards to protecting national security.
▶ 0:37:41And so, what we're doing in the midst of all of this is ensuring that the warfighter needs are are appropriately represented. The other thing that we're doing is we're looking at new technologies to see how the spectrum sharing can be much more dynamic.
▶ 0:37:57Mhm. more enhanced. It could be more secure. We are definitely on top of those things. Now, I think that's definitely the key. Another thing that's happened um recently is the increased use of drones, and of course, there is a spectrum management issue there and strategy there. Uh what have we learned from Ukraine, if anything, on this issue? Um what should we be doing better to accommodate what we can only expect to be increased drone usage with spectrum issues?
▶ 0:38:28Thank you. Um I won't go sideways on on updates that are provided by my colleagues with regards to active use in in these areas. What I can say, we we have learned quite a bit um from the uh Russia-Ukraine War. Um there's significant use of of uh UASs, drones, um across uh multiple arenas, and um we are actively looking at defense measures across that.
▶ 0:38:54We're actively looking at those spectrum bands that do impact that. Um would be happy to come back and provide a deeper briefing if that's
▶ 0:39:01Sure, and would love, of course, to know what Congress uh can be doing to be more useful in that area. And my final uh again, regarding the uh spectrum and and data, mobile data traffic is forecasted to grow between 20 and 30% just over the next few years alone, especially with the increased uh use and growing use of 5G.
▶ 0:39:22How are you and the administration able to balance or planning to balance the significant growth that we're anticipating in commercial wireless services and spectrum use against the needs for government access to the spectrum, especially as our commercial technology is getting better and starts encroaching uh on or blurring where the DOD Uh Congresswoman, that's part of the active uh discussions around spectrum management.
▶ 0:39:47I will say that we are having incredible successes across deployment of 5G across our installations. We are currently at 88% of US military installations possessing commercial 5G infrastructure in at least one. We're diversifying that support, that backbone of 5G infrastructure as well. And those are ongoing discussions around the the use, the dynamic use of spectrum for those. Appreciate you. Thank you. I yield. Mr. Fitzpatrick, you're recognized.
▶ 0:40:18Thank you, Mr. Chair. Thank you for having this hearing today and thank you, Ms. Davis, for being here. You mentioned a couple things in your opening testimony that kind of struck I was maybe going to go a different direction, but I think I'm just going to talk a little bit about slow legacy software. So, I had the honor of being the state director for USDA Rural Development in Minnesota. And I was blown away at the archaic, slow, clumsy legacy software that our federal agencies operate under.
▶ 0:40:48And this probably isn't going to speak to maybe some of the staff, but a few of us around this table will associate with this, but I mean, this is like Oregon Trail type stuff, right? When we can't use a mouse to click from one screen to the next, we're using the F1 key and it's a black screen with green cursors. I mean, I'm thinking Oregon Trail.
▶ 0:41:06But yet, we're called and and you're called and and the agency is called to, you know, the highest level of security and you know, we look at things like some of the failures and audits in the past and how do we kind of get our head around embracing commercial you know, the commercial sector, what we've seen happen in the private sector.
▶ 0:41:26I mean, I will tell you right now, Walmart knows where every toothbrush is in that big old company of But yet, I wonder and I worry if we know where our bag of bolts are within the Department of of war. And and so, on that front you talked about modernizing legacy IT systems. You talked about the slow legacy software. What are the obstacles that you're seeing like right in front of you right now? How do we bring a Oregon Trail type platform?
▶ 0:41:55And I'm not, you know, making the assumption that you're all like the USDA, but how do you know, what are the obstacles that you see in front of you right now that can help us through that? An area I'm extraordinarily passionate about. It was a tremendous surprise to me coming into the department to to witness what what you have reflected on as well, Congressman. I think some of the first of all, the president recognizes these challenges.
▶ 0:42:20He's he's issued executive orders in support of us driving technology modernization, AI strategies moving forward. The secretary has has been very clear in his vision for us to drive through technological advancement. So, what we're doing is is really to look at where are the opportunities to streamline these efforts? Do we have old legacy systems that very few users are using? We should sunset them. We should migrate to much more consistent contiguous platforms that are there.
▶ 0:42:49I think some of the barriers are are simply that that we've never done it this way before. When we look to introduce innovation and we look to introduce modernization, there are some wonderful people in the department who really want to embrace innovation. Those are the people that I'm looking to point out and say, "Hey, come alongside and let's do this together." Um I think the the people inside the building realize that this is a big problem.
▶ 0:43:15I think in a lot of ways they've been writing for the right waiting for the right leadership to come and say, "We are now going to tackle this. Roll up your sleeves." I appreciate that. I appreciate your attitude around that. You've spent some time in the private sector. You're now in this role. You know, we we we sit around and pass a NDAA every year. We do about a trillion dollars of appropriations. I mean, this is a big deal.
▶ 0:43:40A trillion dollars in the private sector, would we be successful operating under the legacy systems that we have in the private sector at a trillion dollars a year? Um we wouldn't be spending that kind of money on legacy systems with a trillion-dollar budget. I appreciate that. So, I think that is something again, this isn't an R&D issue. This should just be a USA common sense issue. I think this is something that should bring us together.
▶ 0:44:03We we owe it to our warfighters to be you know, as lethal with our external outward-looking systems as we are with our internal. And that helps the discussions that we have around this table when we when we're talking a trillion dollars. I I I would like to know with confidence that that you all know where the bag of bolts is. Because at the end of the day, if if we don't, if you don't, our warfighters don't. And that is delay and that is cost and that is just a a real inefficiency that we should be able to fix.
▶ 0:44:32By the time that you and I have talked here, I probably could have got a car loan on my phone. And so, there's technologies out there. And so, maybe on that front and last question for you, what are the challenges that you see in regards to that culture of the risk culture that you talked about, but also embracing some of the things that are off-the-shelf commercial products that we could bring in to make us more efficient and to really solve some of these legacy challenges that we have?
▶ 0:45:00It's part and parcel of my strategy, Congressman. What you've heard me talk about in my opening comments and the comments for the record is we need to get after this. With the secretary's leadership, we have the right leadership in place to be getting after these big problems. I've found historically, things are a little bit less of a technology problem than they are a culture problem. I think we have a little bit of both in the department.
▶ 0:45:23And what you're going to see with this leadership team, including with Honorable Michaels at R&E, myself with Honorable Duffy in ANS, we have a whole of team effort at the department. I appreciate Thank you, Mr. Chair. Thank you. I yield to Mr. Ryan. Thank you, Mr. Chair. Thank you, Ms. Davis, for being here. Two questions. The first is one that you rightly talked about in your opening statement and in your submitted testimony.
▶ 0:45:52One that a lot of us hear about and that there's strong bipartisan agreement and bicameral agreement on, which is the ATO process. And we all say the right things and put out the memos and give the speeches about speeding capabilities into Department as my colleagues talked about.
▶ 0:46:10And then over and over, those of us engaging with the best of emerging innovative companies, high-growth companies, and even our highest-performing companies all come back to the ATO process is still frustratingly slow. A lot of us worked in the last NDAA to put in section 1521 that required, you know, you and your team to create an expedited review process for ATO. So, I know we're not at the 180-day deadline yet.
▶ 0:46:36We're getting to it and I know you have a lot on your plate, but could you just give us an update on how that's going um and and what more we can do if needed to speed that up? Thank you for your passion around this issue. I think we would agree that that ATO process is much slower than it needs to be. It speaks to the risk management framework in and of itself, the ATO process being a part of it. There's a lot of managing of this by spreadsheets and emails.
▶ 0:47:04There's a lot of brokenness in the midst of inheritance process when you have one area that conducts a risk management on a piece of software or an asset, and then that that assessment, that analysis doesn't transfer over to the next ATO. These are the things that we're going to get after under my This fundamentally can be helped through technology. It can be sped up still staying in alignment with the regulatory requirements around the risk management framework.
▶ 0:47:35But speeding things up and and making this a much more dynamic and continual process as well, rather than a one-and-done checklist. Are we on time to get a update for the NDAA from your team? I will take that back for the record. We're working on it for sure, Congressman. Thank you.
▶ 0:47:54and I know you know this, but I do think a lot of it is just the inconsistency across the authorizing officials and just, you know, you just literally submit and you don't know sort of it's a a lottery who you're going to get. So, you talked about culture and I think I agree and I know you get that, but anything you need from us to reinforce that. I just think obviously given everything happening, this is this is so such an urgent priority. Um second is on the workforce building on what my colleague Ms. Wexton talked about.
▶ 0:48:22Specifically, I want to talk about and you also talked about this in your opening testimony, the our cyber workforce and the the the CES program. Can you can you talk about measurable progress you've made in closing the cyber workforce gaps we continue to hear from all the leaders of that continues to be a problem. We are underway in the midst of this. This is a This is a large problem for industry as well as for government.
▶ 0:48:52We've been seeing that there are gaps in the cyber workforce globally speaking as well as across America. So, this is a passionate area that I I draw from my experience to bring into here. To date, we have I believe over 170 scholarships. We have partnerships with over 450 academic institutions. We're working on We're announcing very soon.
▶ 0:49:13Well, I guess I'm announcing right now that we're going to be doing a rotation internship program that's going to be providing a lot more skills uplift that are there. I'm also looking to see how we can be working much more effectively with K-12 in order to be uplifting the cyber workforce of the future. And and just sorry to in the In the of time, I got to hit one more thing. I would specifically love to follow up with you and your team on the K-12 component, um if you're willing. Absolutely.
▶ 0:49:43The The last thing I just want to do bring up, which I think would almost certainly have to be addressed in the in the closed session, is just a your whatever you can share in this forum of you know, we're we're we are in a war despite what different people are calling it. And um we're testing all these systems, I know, under your purview. What can you share about how our performance has been As many know in the room, Iran actually does have a quite sophisticated offensive cyber capability.
▶ 0:50:12And so, how how are we holding up there? And And of course, defer to hearing more in the closed session. I certainly will have to defer the majority of that to a closed session. I will say that across the board, across every theater, we've been working for resilience and diversity in our long-haul transports, or our network capability, our communications capability. We've been working at resiliency and anti-fragility plans with regards to data center modernization and all of that as well.
▶ 0:50:41Um there's significant work being done by our colleagues across Cyber Command. Thanks. Yield back, Mr. Chair. Thank you. Mr. Crockett, you are now Thank you, Mr. Chairman. Ms. Davies, thank you for your time and your testimony today. And I'm sorry, I'm hopping back and forth between Uh congratulations on your recent confirmation. I want to ask you about the DOD's cybersecurity maturity model certification or CMMC requirements.
▶ 0:51:06I think we can all agree on the national security imperative of protecting sensitive government information from our adversaries. But when regulations created to achieve this goal are so overbearing and so restrictive that it causes important small businesses to leave the defense industrial base or decide against working with the government in the first place, that also harms our national security. And for an example, I had a recent meeting with my defense advisory board.
▶ 0:51:35I heard from one small business in my district that does not uh that they do all of their contracted work on on base and on government computers. However, the owner has to handle federal contract information on a private work laptop, which according to the program only requires CMMC level one However, the department has informed [clears throat] her that she must meet CMMC level two high requirements.
▶ 0:52:03This one requirement, which only applies to one employee who isn't even doing the sensitive work, is going to cost her company over $100,000 just to be able to do business with the department. And this is just one of the many stories I've heard from my district over the last several months while CMMC implementation begins.
▶ 0:52:23And while large primes may be able to to stomach those costs and employ dozens of employees to track compliance, these regulations and costs can easily cause a small contractor to go bankrupt or leave the industrial base, depriving our warfighters of their exceptional And a recent GAO study found that the uh had {quote} not systematically assessed and documented the external factors that could affect the department meeting its CMMC
▶ 0:52:53goals. {unquote} They suspi- specifically called out the DOD's on private stakeholders for assessing compliance, such as the Cyber AB, an independent nonprofit tasked with overseeing CMMC implementation and compliance. According to the report, the department does not adequately understand whether there are enough to handle the volume of contractors needing uh to be deemed CMMC compliant.
▶ 0:53:23uh I want to commend you first uh because one of your early actions after being confirmed was to order a dedicated review of the CMMC ecosystem and its effects on our national defense strategy. What's the status of this review and when can we expect to receive the results? Congressman, um the review is still underway, but I'm I'm happy to share with you some early observations. I think my observations are also informed by having been in industry as well and [clears throat] looking at this.
▶ 0:53:54the topic of supply chain risk management, and especially cyber risk management across the supply chain, is very important. Of course, we want the data to be safe, confidential. Of course, we want the integrity of the data to be there. But what we really also want is our defense industrial base to have availability of their systems in order to produce the things that the Department of War and our military, our warfighters need, right?
▶ 0:54:20So, part of the observation that I can share with you is what the Secretary has so wisely spoken loud and clear, which is we need to reduce the regulatory burden and offer new entrants a shot at getting in and doing business with us. I can commit to you that this is the lens through which I'm looking at CMMC. Great. Great.
▶ 0:54:40And So, what kind of oversight does the department have into the millions of dollars received by Cyber AB and C3PAOs from the frankly exorbitant fees that they're charging for their services? A lot of the supply chain risk management, and even in industry, Congressman, is conducted by third parties. The volume of it is is so enormous, we couldn't possibly hire enough people to do all of those assessments.
▶ 0:55:07That said, the oversight does come through my office, and we are having a look at that as well to see where we can be streamlining things, looking first at the totality of CMMC and and how we can be addressing the Secretary's direction of reducing regulatory burden, but then also looking to see how we can streamline these efforts, too.
▶ 0:55:29Okay. And just I've got just a couple seconds left, but let's talk about What's your office been doing to ensure the department's not over-classifying CUI basic information and data? A topic near to my heart. We are right in the thick of looking at this right now, Congressman. Great. All right. Thank you. And I yield back. Thank you. Mr. Vindman, you are now Thank you, Chairman. So, the Department of Defense, uh first of all, welcome, Ms. Davies.
▶ 0:55:59Good to see you. Uh the Department of Defense Inspector General recently found that the Department of the Navy has made minimal progress in mitigating known cyber vulnerabilities across defense critical In many cases, there was no clear ownership of systems, no defined responsibility for risk management, in some cases, no visibility into whether vulnerabilities had even been addressed. Uh that's not just a process failure, it is mission risk.
▶ 0:56:27These systems underpin our ability to deploy, support, and sustain military operations worldwide. At the same time, the threat environment is becoming more severe. The intelligence community assesses that cyber actors from China, Russia, Iran, North Korea, and criminal ransomware groups pose persistent and growing threats to US networks and critical with the capacity to preposition for or execute disruptive and destructive attacks.
▶ 0:56:53China in particular is identified as the most active and persistent cyber threat, while Russia continues to field advanced cyber capabilities, and non-state actors are increasing the speed and scale of attacks against critical infrastructure. This means we're facing a reality where adversaries are not just probing our systems, they're actively preparing the battlefield in cyberspace.
▶ 0:57:15Concurrently, advances in digital twin technology, which creates virtual and data-driven representation of real-world systems, allows operators to model infrastructure, simulate disruptions, and test mitigation strategies in real These systems integrate sensor data from physical assets and run simulations that generate actionable insights back to the real world. This matters for cybersecurity.
▶ 0:57:40Instead of reacting to vulnerabilities after they are discovered, digital twins allows us to anticipate failure points, model cyber attacks in infrastructures on infrastructure systems and identify cascading effects before they occur. In particular, dig- digital twins would prove especially helpful in identifying risks for critical infrastructure attached to military bases, especially bases that rely on local energy and water infrastructure.
▶ 0:58:07For the NDAA, I'm considering language to help implement this technology. Given the IG's findings and IC threats assessment, IC threat assessment, do you support implementing a digital twin model pilot program at military installations to provide real-time visibility and improve risk management? Absolutely, Congressman. I think this is fabulous. I've been working with digital twin technology across my commercial career.
▶ 0:58:33Um and I think that the the availability, the the potential of that usage for simulating attacks, simulating patching across these brittle systems is is actually quite profound. Do you have any current plans to implement digital twin uh systems or
▶ 0:58:51We're working on um a design around this right now. Of course, we're we've been working through and we've published out of my office uh OT playbook guidance around OT security, industrial control systems, um a lot of those areas. We've also had um a very strong target for zero trust principles across OT. Um in my background, bringing this with me into the department, I have established a very clear focus that we want to get after this. So, we're looking at piloting that. Wonderful.
▶ 0:59:21And then um I have a little bit more time, so let me ask you uh from the Ukraine conflict, what um are there lessons that have been learned? I mean, Russia has persistently been attacking uh Ukrainian systems for years. Obviously, this is their number one priority. What have we learned that we can adapt, adopt in the United States? I won't speak specific to the Ukraine conflict.
▶ 0:59:49I'll defer to my colleagues who are much more vocal and fluent in in those topics. What I will speak about though is much more broadly what we've learned across time is we need much more resilience and modernization across across our systems. In the network refreshes and modernization that we're doing across and the Dizzin the information security network itself.
▶ 1:00:13We're looking at how we can deploy develop and deploy alternate satcom usage and and things like that that will that will promote resiliency and anti-fragility across not only our network and our comms transports but also our systems themselves.
▶ 1:00:31I'll just say in the remaining seconds that we have obviously we have friends and allies all around the world and that we should be able to leverage their experience into our own systems and our own Thank you. I yield back. I thank you Mr. Chairman. I just have I think just one question. Actually following up on what my colleague Mr. Krank had said.
▶ 1:01:00I too have met with small businesses some of them working in the in defense space and they have brought to me concerns about the cost of complying with the with the C um the CMMC and um you know, how do you intend to balance the need for um you know, really exquisite security given our adversaries who are trying every way they can to to break into systems often through vendors
▶ 1:01:30uh outside of the government to get at the critical information with the concerns that that we should have and we do have about um our um our defense industrial complex. How how do you intend to balance the interest of security and making sure that we have a defense industrial base? This is the balance to be had Congressman. Thank you for this question.
▶ 1:01:56Um we already provide quite a few things across the department that I believe are great benefit for the defense industrial base through NSA's C3. Um they for members who sign up for this, they provide um threat intelligence, they provide um indicators of compromise so that so that the DIB can uplift their own security.
▶ 1:02:15Um through our DC3, we're also working with them on forensic investigations when there is an issue um that they are then of course required to report back to us through their contract uh terms themselves. So we provide a lot of this information for them right now. Um we we also have uh quite a few provisions that uh that US Congress have authorized for us between the supply chain risk management or the supply cyber supply chain risk management. We look to those all the time.
▶ 1:02:45Um I have direct engagement back with the with the defense industrial base as well as the CIO and we are looking to create greater partnerships there in order for them to uplift their security. Do you think we ought to be providing grants or low interest loans to small businesses such as in my district and uh that my colleague Mr.
▶ 1:03:06Krank mentioned so that they can upgrade their systems uh they're critical that they're in providing a service to the government uh and the costs are are not really questioned so much it's certainly expensive for a small business can put them out of business can discourage them from engaging with the government. Shouldn't we be granting uh you know, financial assistance to these businesses so that they can comply and provide us all the information we need in the most uh protected way as possible?
▶ 1:03:38I think Congressman that is that is an idea of many perhaps. I know with the uh defense industrial base companies that work with NSA's C3, um they have the ability to work on their um on on several of their systems. There's 11 different capabilities that are offered for the small businesses themselves. So I think it's probably a a combination of several efforts where we can support them and help them and guide them. I thank you Mr. Chairman. I yield back. Thank you.
▶ 1:04:08I have a one more question here and then I'll see if Ms. Houlahan has any follow-ups. One thing we hear frequently is that the department is still operating a large number of legacy systems and networks are very difficult to secure and expensive to maintain. Can you talk about how much of the department's cybersecurity challenge is really a legacy IT problem and whether modernization of networks and enterprise services is keeping pace with the cyber A question dear to my heart. If there's always a challenge with legacy IT.
▶ 1:04:38It is usually quite sprawling it just generic comments from me. Sprawling technology that is not kept up to date or is out of service by the main providers themselves which in and of itself means it's not being patched. It doesn't have updated software on it. So legacy IT does pose quite a significant problem.
▶ 1:04:58One ends up designing security controls around allowing those systems to exist and remain rather than investing the time, the resources, the budget that are necessary to not just replace the systems but also train people on how to use new and modernized techniques. I'd say there's a direct correlation with the cybersecurity with regards to those legacy IT systems.
▶ 1:05:24It's something Chairman we are getting after with quite fervor under my Thank you. Ms. Houlahan, do you have a closing question or comments? I I have a real quick one. You you mentioned a little bit about zero trust and specifically about OT and or operational technology zero trust initiatives.
▶ 1:05:44My understanding is that um zero trust uh strategy prior to you coming has a a deadline of September 30th, 2027 uh to be implemented across DOD. With this OT uh addition, do you anticipate an extension of that deadline, an additional deadline or is this integrated into the existing strategy?
▶ 1:06:08Um the existing strategy includes an IT deadline which is the one that you referred to and then there's a secondary OT deadline that is there. Um I've been taking the time to assess that and look to see where we can pull that in. I think that this is the OT side is is direct impacting to our supply chain. It's direct impacting to our war fighters uh the distribution of all all of the materials that they need.
▶ 1:06:33It's direct impacting to weapon systems as well and so we're looking to see where we can pull that deadline in.
▶ 1:06:38So right now there isn't one and you're hoping to have established one or Uh there is one right now. I can take that one back for you. I don't have the date in my notebook probably because I've determined to pull the date in. And will that could that be affected by workforce reductions that may be happening either in the past or in the future? Um I wouldn't say that that's that there's a correlation there Congresswoman. I think it's a matter of prioritization that is needed.
▶ 1:07:07So the work needs to be prioritized in order to get after it and with the leadership that we have now from the secretary on down, we're seeing that there's a priority of an action a bias for action and results oriented. So we'll we'll start to see a lot more progress in that area. And finally, is there anything that you need from Congress for this?
▶ 1:07:29Um your continued attention to these matters without sounding uh sycophantic is actually really quite important and I appreciate the attention on these matters. I think sometimes IT is when indeed we power a lot of what's happening for our war fighters and that is our primary mission is to empower them, embolden them and give them all the resources that they need. So thank you for your continued attention.
▶ 1:07:56I yield. Thank you. Mr. Veasey says he has one more question. I do. Thank you and and this is a little bit of a follow-up on what Representative Houlahan was just getting at. And your comment that under this administration and and your interest is a bias for action. What's the most radical idea or plan you have to address you know, the issues that you see are as most problematic.
▶ 1:08:21So from your own perspective, like what's the most um radical idea or plan that you have and then how can we help you execute that? Um I have not fully formulated the intricacies of the strategy but I will tell you uh the office of the CIO has not been reorged since it was established back in 2012, 2014.
▶ 1:08:47Um we have uh looked at things through um lenses that I think are outdated. And so what you will see from from my office Congressman is you're going to see an operational mindset which is radical for some people to think that a CIO's office would be much more operational. That's not radical in industry by the way. Um it is uh that's one of the areas that we're looking at.
▶ 1:09:13I think in some of these places where we're looking to set up sandbox ideas not unlike yours. I I feel like Congressman you might have read my um on leveraging digital twin technologies. These are some of the things that we're looking um after. Some of the radical plans will be in using commercial technology um to support the work and leapfrog in the modernization effort. So, more to come on that one, Congressman.
▶ 1:09:43Thank you. At this time, we will conclude the open portion of today's subcommittee hearing. For members who will not be joining us, questions for the record will be due to the committee within a week after the conclusion of this hearing. With that, I want to thank you for this open session. We appreciate you being here uh sharing your your expertise and We will now reconvene in the SCIF in Rayburn 2337 for the classified portion. The subcommittee hearing is adjourned. We think 10 minutes?