▶ 0:11:24The Committee on Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection will come to order. Without objection, the Chair may declare the committee in recess at any The purpose of this hearing is to assess the Department of Homeland Security's role as a sector risk management agency or SRMA for the communications and information technology sectors and to assess whether that role is keeping pace with the evolving threat environment facing America's digital
▶ 0:11:55This hearing will examine how infrastructure such as hyperscale data centers, telecommunications networks, subsea cable systems, and space-based communication platforms fit within the existing critical infrastructure sector construct and whether the department's resources and authorities sufficiently support its SRMA role for these sectors.
▶ 0:12:17Now, we will be having a vote series called here shortly, so I will reserve my opening statement until after that series so that we can get to the witnesses' statements. That said, I now right recognize I recognize you, sir.
▶ 0:12:32I now recognize the ranking member of the full committee, the gentleman from Mississippi, Mr. Thompson, for his opening statement.
▶ 0:12:39Thank you very much, Mr. Chairman, and I understand the sequencing of votes this morning is interrupting part of the activities of the committee. I want to welcome our newly minted ranking member, Ms. Ramirez, to the And this is her maiden voyage.
▶ 0:12:59We appreciate her leadership on the full committee and as a former uh very interested person in a lot of things. We're glad to have you. So, I'd like to thank the witnesses also for participating in today's hearing. In October 2024, we all learned about Sandworm Typhoon's successful breach of US telecommunications network.
▶ 0:13:27Chinese state-backed hackers had successfully gained access to the sensitive communications of some of the most high-profile individuals in our country and access data on a vast number of Americans.
▶ 0:13:43Undetected for months or even years, this wide-ranging incident demonstrated the sophistication of PRC hackers and the vulnerabilities in our own critical At the time, many thought Salt Typhoon would be a wake-up call about the needs to prioritize cybersecurity and invest in improving our cyber The Biden administration immediately took steps to better understand
▶ 0:14:13the incident and strengthen our defenses by launching a Cyber Safety Review Board into the incident and the FCC proposed cybersecurity requirements for telecommunications providers.
▶ 0:14:28Unfortunately, starting on January 20th of last year, President Trump's vendetta against CISA, coupled with Dozhier's slash-and-burn approach to dismantling the federal government, has taken priority over our national security. Under President Trump's leadership, CISA has forced roughly 1,000 employees, almost a third of its staff, out.
▶ 0:14:55The Cyber Safety Review Board has been disbanded, leaving Congress and the public largely in the dark about how Salt Typhoon's telecommunications breach occurred. Key public-private collaboration forums, like the Critical Infrastructure Partnership Advisory Committee, or CIPAC, has been shut down.
▶ 0:15:18And a Republican-controlled Congress has repeatedly failed to pass a long-term reauthorization of the cyber information sharing act of 2015 despite broad bipartisan support for doing so leaving the private sector in limbo as we as to whether the laws vial liability protections will remain in place going Now as we face new threats like rapidly advancing
▶ 0:15:49Frontier AI models and the war with Iran CISA's capacity to partner with critical infrastructure and fulfill [snorts] its sector risk management agencies responsibility is significantly diminished. We must work to write this ship before it's too late.
▶ 0:16:08I appreciate the witnesses for being here today to share their perspectives from the private sector on what more is needed from CISA and Congress to better defend the communications and information technology sectors. We all rely on these sectors every day and breaches of communications and IT networks put Americans privacy and our national security at risk.
▶ 0:16:35We must act quickly to rebuild CISA's capacity to serve as the sector risk management agency that these sectors need and CISA must reestablish the public-private partnerships that are necessary for the government and critical infrastructure to productively collaborate to secure the homeland.
▶ 0:16:56I hope we can have a candid conversation today about the current status of CISA's SRMA work and how CISA can better support critical infrastructure. For CISA to serve the communications and information technology sectors properly it would need to have sufficient staffing and resources to respond to the evolving threat landscape.
▶ 0:17:22I'm glad that CISA is looking to hire over 300 individuals in the near future. But I worry if qualified applicants will be interested in serving at an agency that has seen its morale destroyed by a hostile administration. Additionally, CISA must develop the capacity and leadership to not just manage day-to-day activities, but to carry out meaningful planning and operations that address new threats and technology.
▶ 0:17:52That will require restored partnerships with critical infrastructure. I know the witnesses here today have devoted their careers to improving our national security and have long histories of working with CISA and other federal agencies to better secure our critical infrastructure.
▶ 0:18:12I look forward to their testimony on what more CISA and this subcommittee can do to strengthen the security of the communications and the information technology sectors uh so vital to this country. I thank the witnesses for being here. Mr. Chair, now I yield back.
▶ 0:18:30Thank you, Ranking Member Thompson. Uh before we proceed, I would like to also uh take a moment to formally welcome Ranking Member Ramirez as the Ranking Member of the Cybersecurity and Infrastructure Protection Subcommittee. The subcommittee has often been a setting for bipartisanship and collaboration, and I look forward to working with you going forward as we examine and address key issues of cyber and national security. And just as I'm going to reserve my opening statement till after the vote series, uh would you like to do the same?
▶ 0:19:00the Ranking Member is going to reserve her opening statement as well, and then we'll proceed uh forward. Other members of the committee are reminded that opening statements may be submitted for the record. I'm pleased to have a distinguished panel of witnesses before us today on this important topic. Pursuant to committee rule 8C, I ask that our witnesses please rise and raise their right hands.
▶ 0:19:25Do you solemnly swear that the testimony you will give before the Committee on Homeland Security of the United States House of Representatives will be the truth, the whole truth, and nothing but the truth, so help you God? Let the record reflect that the witnesses have answered in the affirmative. Thank you, and please be I would like to formally introduce our witnesses, and again, thank you for being here, and my humble apologies for the disruption and flow. Make sure that's not me. Okay.
▶ 0:19:53of the proceedings, we'll get to vote, so we'll come back as quickly as possible. Mr. Robert Mayer is senior vice president of the Cybersecurity and Innovation at US Telecom, the Broadband Association, with responsibility for leading cyber and national security policy and strategic initiatives. He's the current chair of the Communications Sector Coordinating Council, and serves as co-chair of the Department of Homeland Security's ICT Supply Chain Risk Management Task Force. Mr.
▶ 0:20:19Mayer has previously served as the top telecommunications official for New York State, held various regulatory consulting and analyst roles, and served in the US Air Force supervising intelligence and communications Mr. Sam Visner is the chair of the Board of Directors for the Space Information Sharing and Analysis Center. He also serves as Security Director of NetCracker Technology, which he represents as a member of the Executive Committee of the Communications Sector Coordinating Council. Mr.
▶ 0:20:48Visner is the former director of MITRE's National Cybersecurity FFRDC, or NCF, and served as Chief of Signals Intelligence Programs at the National Security Rear Admiral Mark Montgomery is senior director of for Center on Cyber and Technology and Innovation, CCTI, and a senior fellow at the Foundation for Defense of Democracies.
▶ 0:21:13At CCTI, he leads efforts to advance US national and economic security, counter cyber threats, and combat adversary cyber-enabled economic warfare RADM Montgomery also serves also leads, rather, CSC 2.0, an initiative focused on implementing the recommendations of the Cyberspace Solarium Commission.
▶ 0:21:36Prior to these roles, he was the policy director for the Senate Armed Service Committee and served for 32 years in the US Navy. Mr. Scott Algeier is the founder, president, and CEO of cybersecurity consulting firm Conrad, Inc., executive director for of the Information Technology Information Sharing and Analysis Center, IT-ISAC, and executive director of the Food and Agriculture Information Sharing and Analysis Center.
▶ 0:22:03He has spent the past 20 years at the intersection of cybersecurity policy and operations. Previously, Scott was man- manager of Homeland Security at the US Chamber of Commerce, where he coordinated the US Chamber's Critical Infrastructure Protection, Cybersecurity, and Dis- Disaster Management Public Policy Initiatives. I want to thank each of our distinguished witnesses.
▶ 0:22:24The the amount of experience you have on this panel is a couple hundred years, and for that we thank you for your your time here. So, with that, I now recognize Mr. Mayer for 5 minutes to sum- summarize his opening statement.
▶ 0:22:43Chairman Garbarino, Ranking Member Thompson, Chairman Ogles, Ranking Member Ramirez, and members of the subcommittee, thank you for the opportunity to testify today. I'm Robert Mayer, senior vice president of cybersecurity and innovation at US Telecom and chair of the Communication Sector Coordinating Council. I I serve as co-chair of the Department of Homeland Security's ICT Supply Chain Risk Management Task Force.
▶ 0:23:07Today, I will focus my remarks on three areas: our partnership with the Cybersecurity and Information Security Agency, CISA, the importance of sustaining and modernizing authorities for public-private coordination, and the need for greater visibility and coherence in the ICT supply chain. For over six decades, the communications sector has worked hand-in-hand with the federal government to help protect the systems Americans rely on every day.
▶ 0:23:33And that partnership has become even more critical as cyber threats have grown more persistent, sophisticated, and Some of the most meaningful advances in communications security have come from sustained operational engagement between government and industry through efforts like the President's National Security Telecommunications Advisory Committee, N-STAC, the Joint Cyber Defense Collaborative, JCDC, and the Enduring Security Framework, ESF.
▶ 0:24:01We look forward to supporting the Critical Infrastructure Fortify Program, which will deepen structured engagement between CISA, allied partners, and industry to help critical infrastructure organizations rapidly respond during periods of degradation.
▶ 0:24:18We should also build on proven mechanisms for collaboration while advancing durable programs such as the proposed Alliance of National Councils for Homeland Operational Resilience, or ANCHOR Initiative, to support continuous engagement between government and industry on cybersecurity and This commitment must also extend beyond federal coordination.
▶ 0:24:40Strengthening resilience requires investment across the broader ecosystem that critical infrastructure depends on, including support for state and local cybersecurity preparedness. That is why it is essential that Chairman Ogles' bipartisan Pillar Act move swiftly through Congress to help strengthen cybersecurity capabilities at the state and local level. Congress can also help by delivering robust communications infrastructure through streamlined permitting processes and accelerate broadband deployment.
▶ 0:25:10Equally important is modernizing broadband networks. Continued investment in next generation infrastructure such as fiber deployment and data center connectivity enhances both performance and security of the communications Congress and multiple administrations have taken important steps to address legitimate national security concerns tied to the supply chain ecosystem, particularly as geopolitical threats have intensified.
▶ 0:25:37But too often these efforts develop across multiple agencies and authorities in parallel rather than in coordination. Greater alignment across agencies, clearer lines of authority, and more transparency in how supply chain related risks are identified and managed would help industry respond more effectively to emerging threats while strengthening broader national security objectives.
▶ 0:26:00As the President's cyber strategy for America strongly emphasized, strengthening strengthening the partnership between government and industry and modernizing the frameworks that support coordination will bring greater coherence to cybersecurity policy and operations. We look forward to working with our government partners as we build a more secure and resilient foundation for the systems that our nation depends on every day. Thank you and I look forward to your questions.
▶ 0:26:26Thank you, Mr. Mayor. I now recognize Mr. Visner for 5 minutes to summarize his opening statement.
▶ 0:26:33Thank you. Chairman Ogles, Ranking Member Jimenez, Mr. Thompson, and members of the Subcommittee on Cybersecurity and Infrastructure Security Protection, thank you for the opportunity to speak before your subcommittee and share with you my thoughts on the protection of a swiftly evolving telecommunications, information technology, and space ecosystems, all of which are vital to our national and economic security.
▶ 0:26:58Having failed retirement, I have the honor to serve as the chair of the board of directors of the Space Information Sharing and Analysis Center, or ISAC. We were founded in 2019, and our principal we are the principal information sharing platform for industry and between industry and government regarding threats to our space systems. And while our initial focus was on threat cyber threats to these systems, we look at a wide range of threats including cyber, jamming, spoofing, supply chain challenges, space weather, and more.
▶ 0:27:28The Space ISAC and other ISACs, as you know, are led by and funded principally by our industry and academic members. The ISAC partners, however, with the public sector. We have in place MOUs with several US government agencies as well as space and cyber security government authorities in Australia, Canada, France, Greece, Germany, Israel, Taiwan, and the United Kingdom. And more partnerships are in progress including a recent MOU we signed with NATO.
▶ 0:27:56We set up in 2023 an operational watch center in Colorado Springs, one that monitors threats to space systems using a wide range of data from our members, partners, and open sources, and we use the DHS traffic light protocol to control the dissemination of that We've also announced global hubs in Australia, Canada, Japan, and the UK.
▶ 0:28:16As these global hubs become operational and as we build watch center components in these countries, the ISAC will gain 24/7 follow the sun coverage of space of space systems environment, threats to that environment, and incidents that affect the security and resilience of that environment. Information about these and other Space ISAC developments can be found at the link that I've been play that been placed into my written testimony.
▶ 0:28:40We also convene task forces and working groups to examine and propose challenges and uh, approaches to key space systems security challenges, including space system governance analysis, quantum security, and now the security of cis-lunar operations and other, uh, and and other domains. Um, the ISAC has grown rapidly. We have over 120 members. We're a member of the National Council of ISACs in the US and the EU Council of ISACs as well.
▶ 0:29:08From this foregoing, I hope to make clear a few key points. First, the speed and scope with which we have operated and will continue to operate, uh, reflect our view that all critical infrastructures depend on space. While in 2019, there were about 2,000 active active satellites, today we count over 500, with estimates ranging from 30,000 to as many as 60,000 by uh, 2030.
▶ 0:29:35Surface and air transportation systems depend on space-based navigation. Maritime fleets use space systems for navigation as well as communications. Space systems provide timing data for our power grid. Space-based remote sensing is vital to farming, including what we call precision agriculture, which allows which uses space-based systems to pinpoint areas for cultivation and fertilization.
▶ 0:29:59Financial systems depend on space infrastructure with satellite technology providing precision timing for transaction timestamps, GPS for global synchronization and secure data connectivity, even for remote ATMs and high-frequency trading. Space-based communications link remote locations, and commercial space systems are being used by our government for national security and civil government. Industry now leads government in the number of space-based imagery platforms.
▶ 0:30:26Global 5G networks using thousands of satellites are providing worldwide 5G IT backplanes. So, Space ISACs members and partners regard space systems absolutely as critical. Second, much of the space systems domain is comprised of unique infrastructure, including manufacturing, launch, ground segment, user segment, and now cislunar These uh infrastructures are growing rapidly, and our members and partners believe we can brook no delay in the protection, security, and resilience of these supply
▶ 0:30:56chains. Cislunar operations are going to have their own unique infrastructures, including their own navigation satellites, and planning for the security of these new infrastructures should start now. Uh next space system missions are evolving. We're likely to see cislunar and asteroid mining, uh new commercial space stations, um energy production, orbital cloud, and data centers. And all of these, securing all of these, will pose their own challenges.
▶ 0:31:23Um and I'm going to abbreviate my comments because we are running out of time. Um from the uh we we believe that that these the security of these systems must be a global endeavor. To that end, the Space ISAC has been from its inception a global effort that includes our allies and partners.
▶ 0:31:41We should remind each other that prior to Russia's attack on Ukraine, the first thing they did the day before they crossed that border was in fact an attack on a commercial space uh space-based satellite communication system. And we have continued to track and report to our members and partners attacks by our adversaries on the space systems on which uh on which we depend. Let me at this point abbreviate my comments and thank you very much. I look forward to your questions. Thank you.
▶ 0:32:10Thank you, Mr. Visner. I now recognize Rear Admiral Montgomery for 5 minutes to summarize his opening statement.
▶ 0:32:17Uh thank you, Chairman Rogers, Ranking Members Thompson and Ramirez, and distinguished members of the subcommittee. On behalf of the Foundation for Defense of Democracies, thank you for the opportunity to testify The subject of this hearing is timely. You know, our nation is under attack in cyberspace. Our adversaries are increasingly seeing our communications networks as a US vulnerability, and China, particularly, is conducting operational preparation of the battlefield, activities that attack and put malware into our systems.
▶ 0:32:46They also do espionage and intellectual property theft against companies and critical infrastructure. At the same time, we appear to be reducing our investments in cyber I think America's national cyber resilience rests on three legs. The first is a capable federal government able to mitigate, thwart, deter, and punish attackers. The second is an informed private sector properly resourced to defend itself from these attacks.
▶ 0:33:09And third is a robust public-private collaboration together that facilitates the collective defense of the US economy and national security. Surprisingly, over the past year, the administration's reduced funding for key offices and decommissioned collaboration mechanisms such as CPAC, which I think are critical to our cyber defense. But honestly, Congress hasn't done much better. While this committee has shown important leadership on cybersecurity issues, unrelated partisan fights and interchamber disagreements have blocked the passage of important legislation.
▶ 0:33:40And while we fumble this ball, our adversaries are advancing. As I said, China continues to preposition destructive capabilities on our critical infrastructure. They use covert compromised networks strategically and at scale to conduct their malicious campaigns. Countering these threats is going to require reinforcing the three legs of that national cyber resilience table. A critical component of that reinforcement is what this committee is looking at today. How the federal government fulfills its commitments to the private sector.
▶ 0:34:09Most specifically, how does DHS support the resilience of the rapidly expanding and evolving components of the communications and information technology sectors, data centers, telecommunication networks, and space-based systems? If our nation does not properly secure these assets, our adversaries will steal, corrupt, and disrupt the data and communications that allow our economy to function.
▶ 0:34:30You know, data centers and cloud infrastructure are becoming more vital to the American economic prosperity in our society due to their important role in enabling online services and telecommunication The explosion of AI innovation has catapulted debates about the construction of data centers in the national spotlight, but I believe the cyber and physical resilience of those data centers merits an equal level of The proliferation of data centers is also increasing the demand for electricity and it's also leading to digitization
▶ 0:35:01of the grid. We got to make sure that in the pursuit of cost savings, we don't embed Chinese-made components in critical control layers of the grid. You know, understanding these sorts of risks and prioritizing mitigations requires a collaboration between the hyperscalers, the energy providers, and the federal government. And And within the gov- government, between the Department of Energy and CISA. You know, over the past year, there have been some bright spots.
▶ 0:35:27The FCC has supercharged its efforts to ban Chinese state-owned emerging technology from critical infrastructures. And specifically, the FCC leveraged its regulatory authority to prohibit the sale of Chinese-made connected devices in the United States.
▶ 0:35:42This is vital national security work, but it should not diminish what CISA needs to do as the sector risk management agency for the communications You know, and in fact, banning Chinese telecommunications equipment is important, but in the case of Volt Typhoon that uh Ranking Member Thompson the access vector was American Cisco So, really, critical infrastructure is not just about who manufactures the hardware, but also about whether the manufacturers and the operators properly maintain it.
▶ 0:36:10In this regard, the administration's recent dissolving of Cyberspace Solarium Commission and disbanding of the Cyber Safety Review Board were both unhelpful I'm concerned that these failures are symptomatic of a greater problem in CISA's ability to carry out its SMA duties for the communications sector sector writ large. And within that sector, it's the security of the satellite communications and other space-based assets that gives me the greatest heartburn.
▶ 0:36:35As Sam mentioned, uh one of the first volleys in the Ukraine war was a Russian cyber attack against an American satellite communications company. You know, the consequences of failing to protect US space systems and seeding space superiority to adversaries would be detrimental to national security. That's why I continue to endorse designating space systems as a US critical infrastructure sector so that space-based assets receive the policy attention and risk management support they deserve.
▶ 0:37:03And I also support making NASA the sector risk management agency. You know, we need to act now as our adversaries pursue these deliberate efforts to erode US space superiority. In my written testimony, I provided six good recommendations. Uh I'll just say the one that I really want to emphasize is fully funding CISA and ensuring that CISA conducts an effective force structure assessment. Thank you for the invitation to testify, and I look forward to your questions.
▶ 0:37:28Thank you, Admiral. I now recognize Mr. Alger for 5 minutes to summarize his opening statement.
▶ 0:37:35Thank you, Mr. Chairman. Um thank Thank you, Ranking Member Thompson. Thank you, Ranking Member Ramirez. Um members of the committee, I thank you for the opportunity to be here today. Uh as mentioned, my name is Scott Alger. For nearly 21 years, I have served as the executive director of the Information Technology Information Sharing and Analysis Center. The IT-ISAC is a not-for-profit, non-partisan industry association formed in 2000 with a simple premise that we're all stronger together.
▶ 0:38:06At a time when well-resourced and highly skilled nation-state actors are targeting industry, the IT-ISAC helps companies make informed risk management decisions through voluntary threat intelligence sharing. Our members span almost every segment of the IT sector that propels today's global economy. The IT-ISAC has long considered CISA to be a key partner. We value the relationships we have built with CISA, and we have always engaged in an honest and non-partisan way, and will continue to do so.
▶ 0:38:36The threats facing critical infrastructure have never been more serious, and the ability to defend against them are strained. Capabilities, partnerships, and programs that industry depend on have been reduced or eliminated. Engagement with industry on operational threat intelligence matters is also reduced. The good news is that there is a path to renew and strengthen CISA. Uh this could be achieved through the following actions. Implement a replacement for the for CPAC.
▶ 0:39:04When CPAC um when DHS disbanded CPAC, it removed the legal framework that enabled and protected strategic engagement between CISA and industry. As a result, most of the work with CISA is at a standstill. Our adversaries have have not paused, they have not stopped.
▶ 0:39:21They are continuing to attack with Provide for a long-term extension of the Cybersecurity Information Sharing Act of Uh CISA 2015 is a critical tool that provides liability and anti-trust and for your protections for sharing cyber threat intelligence. It's important to maintain a trusted legal framework that incentivizes and protects companies who voluntarily share threat intelligence. Confirm uh a CISA director.
▶ 0:39:49While this is not the purview of the House, uh the absence of a Senate-confirmed director creates a leadership gap and makes it harder for CISA to advocate for resources and priorities. While Nick Anderson is doing an admirable job as acting director, the agency will benefit from having a Senate-confirmed director. Prioritize resources through Resources, time, money, and people are limited and must be leveraged to maximum effect.
▶ 0:40:14Collabora- collaboratively developing prior- priorities can help industry and government allocate resources more effectively. Analyze the impacts of CISA staff funding reductions. Changing staffing levels based on organization priorities is a common management practice, but to ensure CISA can maintain its vital core functions, it should engage with industry partners to understand the impact reductions are having and evaluate whether any adjustments are warranted.
▶ 0:40:42Enhance analytical engagement with industry. CISA should designate cybersecurity analysts to support specific sectors. The analyst would build relationships with sector ISACs and their members to know and understand their specific industries and threats to them. This will create trusted relationships, better analysis, and improved threat Create common situational awareness.
▶ 0:41:08CISA currently sends alerts on specific incidents, but this is a whack-a-mole approach that is not suitable for a sustained capability that provides near real-time strategic and tactical threat intelligence. It doesn't create shared situational awareness to inform Vulnerability management modernization. Are vulnerability disclosure and patch management processes already struggling with today's pace of disclosures? AI threatens to further stress this.
▶ 0:41:37CISA can convene relevant communities to address this. Refining SoCEA. The IT-ISAC and the IT sector coordinating council have expressed concern that the proposed SoCEA regulations were too broad and would result in it receiving more information than it could process. Limiting SoCEA's scope and scale to more closely align with legislative intent will not only reduce the reporting burden on industry, but help CISA develop and distribute more meaningful threat intelligence.
▶ 0:42:05We applaud CISA for planning a series of town halls to receive additional input. Implement effective partnership principles. In In 2012, the IT Sector Coordinating Council identified 12 partnership practices that lead to successful outcomes. Um, CISA should review and renew these. Um, I would um, like to reiterate our support and appreciation for the everyone at CISA who works tirelessly tirelessly to protect our country.
▶ 0:42:32Um, I thank you all for the opportunity and I welcome any questions you have.
▶ 0:42:38Thank you, Mr. Alger. As they have called votes, we will take a brief recess and reconvene promptly thereafter. Again, thank you to the witnesses for your patience. Uh, pursuant to committee rules, the committee stands in recess.
▶ 1:57:47We're going to reconvene uh this committee hearing. Um I know the votes are still uh ongoing, so we're going to jump right into questions. Uh and so I'll recognize uh myself for 5 minutes of questioning, and then I'll turn it over to the ranking member for questions as well. Um uh uh I thank you all for being here. Uh thank you for the information that you provided. Um my first question is uh to Mr.
▶ 1:58:09Mayor, uh how can CISA better facilitate intelligence and information sharing with the private sector, especially when it comes to the the communications and information technology sectors? Uh read your testimony, but can you get can you dive down a little more specific?
▶ 1:58:23Sure. So, I would say that over the last 2 years, we've seen a marked um increase in the quality and the frequency of intelligence briefings, classified information on all of the major major attacks were discussed in those Uh we we shared with CISA what we were seeing on our networks. They were sharing with us what the intelligence community was seeing. Um and I think we've made a lot of progress in this in that area.
▶ 1:58:53I think one area that uh deserves greater attention is the ability to convey that information to the local and regional providers in the communication sector. they they're hundreds of such providers and getting very quick uh uh information is very important to them, but I also will say that CISA has done a better job in terms of releasing um cybersecurity advisories at the unclassified level, and that has been very helpful as well.
▶ 1:59:23Uh thank you. Um, I'll go to Admiral Montgomery. Uh it with the rapid increase in reliance on hyperscale data centers, which enable cloud services like Amazon Web Services, uh what safeguards are necessary to ensure uh these facilities are protected against adversarial threats? What are the consequences of leaving these facilities
▶ 1:59:43Yeah, thanks for asking that. It's exactly my greatest concern is that in our in our rush to build them or to have the environmental discussions about them, we're missing the really important physical and cybersecurity discussions. We have to make sure that they're both physically secure, but then we um and there I think about drone attacks as you probably have been briefed in or in the uh Iran the recent conflict with Iran, the Iranians directly attacked uh US-owned data centers in the uh
▶ 2:00:14you know, within our Arab partners. But, the second part cybersecurity, and this has to do with both the supply chain of the parts you have in the data center, making sure that they're uh not from countries of concern like China. But, secondly, that you're doing the proper level of you've set up the proper standards for security on them and that you have the proper operational environment. One thing I'd recommend is we should there should be a strong consideration of whether data centers and cloud need to be a separate critical in national critical infrastructure. There's been a push for that in the past.
▶ 2:00:44Um, it fell short with the cloud, but now that you have the data centers as well, and we can all see the dynamic the the the large role they're going to play in the United States, possibly an independent national critical infrastructure that handles data center and clouds separate from communications.
▶ 2:01:01So, you you may have answered my my next question, but the UK has designated data centers as critical national Do you believe that the United States should follow suit, and and that I'll open that question up to the rest of the panel, but Admiral?
▶ 2:01:13I do. In fact, of the things we're talking about today, data center, space, and telecommunications, I think they're three separate critical infrastructure. So, I don't I don't know if Sam joins me with this, but I think space is a critical infrastructure, and I think data centers are a critical
▶ 2:01:26Mr. Mr. Mayor, I'll start with you, and we'll go around down the
▶ 2:01:28Yeah, I look, given the exponential growth in data centers, we're going to see more of that. Um, connectivity is going to be a major aspect to that, so there are links to the communications sector. Um, but I think given the um, scrutiny that is required to make sure that those data centers are secure, um, there would be a benefit, I think, in uh, having them work together as a unique coordinating council.
▶ 2:01:54Mr. Minor.
▶ 2:01:54I Thank you. Thank you for the question, Congressman. I'd have to agree. Um, if you take a look at what's happening with data centers, the infrastructure that data centers are are building, and that they're going to be driving with energy, you're going to have massive data hyperscalers, data centers that are going to be powered independently by small and modular nuclear reactors. That infrastructure is going to become an important part of the national landscape. It's going to employ thousands of people.
▶ 2:02:23It's going to contri- contribute hundreds of billions and eventually trillions of dollars to the national economy. Our national defense will depend on these data centers. Our economic security will depend on these data centers. Much of our critical infrastructure, particularly as we use AI-enabled smart cities and infrastructures that they're going to depend on on these data centers.
▶ 2:02:45So, finding a way to regard them as part of our critical infrastructure and to protect them accordingly, I think is is is sine qua non. I think it's absolutely required.
▶ 2:02:57Mr. Chairman. yes, [clears throat] Mr. Chairman, thank you for the question. Um I would like to just note that the data center community is currently represented within the Information Technology ISAC. We have a number of data center providers who are members.
▶ 2:03:13Uh we've formed a what we call a special interest group for the data center providers so that they can communicate with other data center providers and share threat intelligence, uh share mitigation practices, share um policies on on both cyber and physical security. So, that the data centers are integrated already into uh the critical infrastructure discussions and we they we serve them through the Information Technology ISAC.
▶ 2:03:40Uh thank you ma'am. Thank you very much. I now recognize ranking member, the gentlewoman from Illinois, Ms. Ramirez for five for five minutes of questions.
▶ 2:03:47Uh thank you, Chair. I want to thank the four witnesses for being here. I know that it's been a little untraditional uh having the votes in between our committee session. I want to also thank uh Chairman Ogles uh for his warm welcome today. I look forward to the work that we do in this subcommittee, particularly as we improve the cybersecurity posture of federal networks and critical infrastructure.
▶ 2:04:08Since today is my first hearing after being appointed to the ranking member of the Cybersecurity Infrastructure Protection Subcommittee, I do think it's important for me to share my perspective on this work. Under this administration, it's clear that the security of our communities, information, federal networks, and critical infrastructure have not been prioritized in the way that they should.
▶ 2:04:30Between the security failures of DoJ, the abuses of immigrant families' data, and and decimation of CISA's workforce and resources, my colleagues here have demonstrated a lack of interest in safeguarding our nation's cybersecurity and our residents' civil rights and privacy. In neglecting necessary oversight, Republicans have deregulated emerging technologies, allowed bad actors to profit from violations of our civil rights, and consented to the weaponization of government systems.
▶ 2:04:58It's more critical than ever that we assert our congressional authority and that we disrupt the the the the dereliction of duty and plain corruption making us all less So, I'm clear. There's a lot of work that we have to do, especially in the subcommittee.
▶ 2:05:14And I'm ready to roll up my sleeves and get to work to protect the data, the rights and privacy, to defend CISA's mission, and to do so, I want to talk a little bit about where we You see, it's ironic to talk about modernizing DHS as a sector risk management agency when Trump has been on a vindictive campaign to dismantle CISA, the very agency he established, but started attacking them the minute it became an obstruction to his interest.
▶ 2:05:39CISA serving as a sector risk management agency requires adequately resourcing and staffing the agency's critical infrastructure. That includes checks and balances and policy solutions that make us all more secure. So, I want to establish some facts. Since January 2025, CISA has lost nearly 1/3 of its workforce through terminations, involuntary assignments, or deferred resignations that workers were harassed to accepting.
▶ 2:06:06The stakeholder engagement division, which conducts CISA's sector risk management work, was cut nearly in half. Between January 2025 and December 13, 2025, CISA's stakeholder engagement division, SED, lost 96 of its 189 When you look at that math, that's half of the workforce. And during the Republican shutdown last year, CISA attempted to illegally fire additional staff at CISA.
▶ 2:06:32Under the President's proposed budget of 2027, funding for CISA's International Affairs, Council Management, and Strategic Relations units would be eliminated eliminated, only leaving CISA's Sector Risk Management Agency unit still funded. These facts make it clear we're not just talking about a personnel loss. We're actually talking about a loss in institutional knowledge, sector-specific expertise, and trusted relationships that we've built over time. So, my question is for Mr. Montgomery.
▶ 2:07:03How has the loss of key CISA personnel affected the agency's ability to execute its Sector Risk Management Agency responsibilities? In particular, Mr. Montgomery, can you talk to me about how the loss of individuals with institutional knowledge undermines CISA's ability to carry out its mission?
▶ 2:07:24First, congratulations on your selection as ranking member, and I I share your concerns about the loss of personnel. You know, I served 36 years in the military, and I never once had a subordinate say to me, "Sir, the the right way forward is to cut 35% of my and I'll get the mission done." I'm sorry. I love I do like Nick Anderson, the acting director, but I believe we're doing him a great disservice with these personnel cuts.
▶ 2:07:47Having said that, how it specifically impacts is the without the Stakeholder Engagement Division, you don't have the ability to set up the information sharing agreements, to do the engagement with the sector. You know, when I said there's three legs to the to the uh National Cyber Resilience, it's how the government does, how the private sector does, and how we collaborate together. It's that collaboration together that gets lost.
▶ 2:08:08And I'd emphasize the removal of the CPAC, the Critical Infrastructure uh Partnership Advisory Council, and most importantly, the removal of the Multi-State ISAC, and the um and the loss of its funding.
▶ 2:08:20That's how we get funding down to our public utilities, and our and our um our uh local hospitals because I'm very concerned that the lack of that these are two these organizations in rural hospitals and in and in underserved communities where the medical centers don't have the money to pay for the basic IT services themselves.
▶ 2:08:44So without those programs running properly I think the the most likely to be ill-served are underserved communities that are in our rural public public health utilities.
▶ 2:08:56Thank you. I'll ask a follow-up question in the next round. Thank you.
▶ 2:08:59We're going to do a second round of questions. So I'll I'll I'll start my my with myself. I wanted to follow up with you Admiral Montgomery and and others can can can jump in as well on you mentioned the the supply chain risk with components manufactured by the PRC including chips, power systems and cooling infrastructure.
▶ 2:09:20Uh and how would you or is it possible to harden our supply chain and and become less reliant on on on the PRC for these parts and
▶ 2:09:33Yeah, thanks for asking. You know, I did a report and testified to Congress last year to the China Select Committee about something called Illuminations where we illuminated 180 US weapon systems. The vast vast majority of which had Chinese parts only two or three levels down the supply chain. So even our military does has a hard time with this and I in my testimony I mentioned the Federal Communications Commission.
▶ 2:09:57Among among the many things it's doing, one of the things that I can really support is their the national security effort to remove China from our emerging technologies. So when you ask how do we get our supply chain right, we have to decide what are emerging technologies, you know, 5G, drones, motor cellular modems. You know, we need to get the we need to not have Chinese state-owned enterprises providing products to the US military and to the dot gov.
▶ 2:10:28And so, what I've noticed Congress does is they first pass a law to remove these components from the dot Then the next year we pass a law to remove them from the dot gov. And then the next year we'd move them from the critical infrastructure. And that's a nice sequence way. And if I were to recommend an area to do it right now, it's cellular modems which are in all our operational technology and communicate back and forth to their point of origin, which tends to be China.
▶ 2:10:52I'm not sure we want our cranes, our tractors, our planes all communicating back to China each night with different different material. Even if it's innocuous at first, it be it could become completely sensitive later.
▶ 2:11:08Is uh is anyone else want to chime in?
▶ 2:11:10I'd like to. Thank you. I I agree with Admiral Montgomery's comments, but I want to add a point. If you take if one takes a look um at the space at space systems, at the whole ecosystem, it's very much a commoditized industry now. Going back in time to the early days of NASA, you know, where'd you get this you know, where'd you get this part? I want to see the factory. Where'd you get the bolt? I want to see the people who made the bolt. Where'd you get the the the steel? I want to see where the steel was made.
▶ 2:11:40Where'd you get the iron ore? I want to see the vein of iron. So, you had a great deal of visibility. That's not true anymore necessarily. And we have a global supply chain. It's not just China for space systems. And since we're going to be depending not only on our space systems, but on those produced by allies and partners, better technology and better means to find vulnerabilities in space systems regardless of where they're manufactured.
▶ 2:12:05And I think one of the our my the other panelists here talked about well, there were problems with with domestically manufactured routers in which we found vulnerabilities. So, it's not just yes, we should be worried about uh infiltration of the of the supply chain, but we also need better technology and better understanding of how vulnerabilities can be introduced into any of our systems, particularly given the commoditized nature of this where you don't necessarily have the same level
▶ 2:12:35of visibility. I think we're all aware of what's happening right now with the undetected vulnerabilities in operating systems which are now only being uncovered by the by by the you know, by the mythos tool. We need to understand that we're likely to have vulnerabilities that have existed in some of these systems for many years and the commoditization of the supply chain is something is a challenge that we're not going to we're not going to be able to to to overcome simply by eliminating one country.
▶ 2:13:04We might that will help, but it won't be enough. The the means to detect vulnerabilities and to mitigate them on anything that's manufactured wherever it occurs. And that's one of the reasons why I've been pushing for a national R&D strategy on cybersecurity and particularly one for the for an R&D strategy on the security of our space systems.
▶ 2:13:26Thank you.
▶ 2:13:27Thank you.
▶ 2:13:27Mr. Mayor, I'll give you 36 seconds.
▶ 2:13:29Yeah, I'll I'll be real quick real quick. As I mentioned in my testimony, there has to be coherent policy across the government agencies with respect to supply chain risk management. Right now, we have Commerce BIS, we have the FCC, we have CISA. We have federal acquisition security We want to see a coherent approach to supply chain. We also want to see the intelligence community be more forthcoming with us with respect to supply chain risk that they've identified.
▶ 2:13:58And lastly, I would say the DHS ICT task force that I co-chair has been an excellent venue for working with our IT partners, the entire com sector including the vendors as well as government uh We did for example, work on a hardware bill of materials to identify what the criteria needs to be for evaluating your your supply chain.
▶ 2:14:22So, there's a lot of activity that can be rationalized, but it should continue with co- coordination with the IT sector, the comm sector, uh and government uh participants as
▶ 2:14:33Thank you. I'll I'll let I'll let you go a little bit over, but uh let me uh go back to the second round. Let me yield and and recognize the the ranking member again for the for 5 minutes of
▶ 2:14:44Thank you. I I want to come back to Admiral Montgomery. Um in the first round, we talked a little bit about the impact that the cut in workforce has had on CISA. Now, I want to also ask you to comment on how the administration's actions cutting CISA more broadly undermine its ability to support SMAs that are building capacity, building capacity like EPA and the Department of Agriculture. Can you talk a little bit more about that?
▶ 2:15:10Uh thank you. You know, one of the responsibilities is that the national CISA should be the national coordinator for our our resilience effort. Um in the in the cuts that have occurred, their ability I I would not have given them high grades previously on their ability to work with EPA, um Health and Human Services, Agriculture, you know, the uh those are the three the water, health care, and food and food and agriculture are three of our worst-performing uh critical infrastructures,
▶ 2:15:40and yet three of the most important to public health and safety. So, they were poor before. It has only gotten worse under this. And as I said, it's a combination of cutting the people and then cutting the programs. And and in Congress, you all have the the state and local cybersecurity grant program, which you've been unable to reauthorize for an extended period of time.
▶ 2:16:00When you combine those three efforts together, the cutting of the multi-state ISAC, the cutting of the personnel, and the cutting of the cybersecurity state and local cybersecurity grant programs, there's no way that these small public utilities who don't have two wood nickels to rub together normally in their budget for cybersecurity are able to make the proper investments to protect those utilities against ransomware and against nation-state actors. And so our our public health and safety at the very core at our at our most vulnerable level is weak.
▶ 2:16:30Yeah. Well, thank you, Adam Borough. Look, I I hear you loud and clear and this this has been a concern for us here in the committee for for a while now. Cutting people, cutting programs in a time where we should be investing in the infrastructure of CISA is really detrimental to the security and safety of every single person in this country.
▶ 2:16:50So, I'm committed as ranking member as new ranking member to make sure that CISA is resourced and it's capable of working with the critical infrastructure owners and operators so that we can keep our network secure. And I look forward to the work that we do in this subcommittee in the upcoming months. With that, I want to thank the witnesses for being here today and I want to yield back to the chairman.
▶ 2:17:10Uh I now want to recognize my colleague from Rhode Island, Mr. Mr. Langevin for his 5 minutes of
▶ 2:17:17Thank you to the chair and to the new ranking member. Congratulations. Um I have to say cybersecurity is one of the issues here in Congress where I think there's the biggest disconnect between the rhetoric and the reality.
▶ 2:17:35The rhetoric is always very positive that this is a bipartisan issue that everyone agrees that we need to do more to protect our country against cyber threats from state actors, from international criminal organizations and the like.
▶ 2:17:50But the reality is that the administration with the complicity of the majority party in Congress continues to cut our cyber defense capabilities at the worst possible time and in fact even does things that undercut our defenses.
▶ 2:18:11And so I just want to make sure everybody who's watching at home understands that the Trump administration has already eliminated a third of the entire CISA workforce, 1,000 employees. These are the people whose job is to keep our country safe from cyber attacks. And has proposed an additional 800 cuts uh at CISA in their fiscal 27 budget.
▶ 2:18:41The leadership at CISA has been a mess under the administration. last acting director was a disaster. He failed a counterintelligence polygraph test. He was caught uploading sensitive government documents into chat GPT um before he ultimately was removed from his position.
▶ 2:19:05Now the next guy, the appointee, just withdrew himself from consideration because he couldn't get confirmed by the Senate. And so the administration is not acting like they are taking cybersecurity seriously. And frankly, our colleagues in the are not doing anything about it, either. The rhetoric is there. The rhetoric's always very positive, but the reality has been woefully lacking.
▶ 2:19:27So I'll ask all four of our expert witnesses here, do any of you think that the huge staffing cuts at CISA are making our country safer?
▶ 2:19:40I'll go ahead and start. I already cuz I already said no. First I want to do say your predecessor, Representative Jim Langevin, absolutely did uh with Representative Mike Gallagher from Wisconsin a significant amount of bipartisan work both in this committee and in the House Armed Services Committee. So it is absolutely achievable. Whether it can get done now, I would leave to your judgment. Um I do want to say that Nick Anderson, the current acting administrator, is a humble, professional uh cyber uh leader at CISA, and I think he'll do well.
▶ 2:20:11But, you're absolutely right. As I said, 35 years in the military, nobody ever came up to me and said, "The next move is cut 35% of my workforce and I'll do better." So, no, they're not going to do better with a 35% cut. They've got a that 300% addition that uh Ranking Member Thompson mentioned in his opening remarks uh is just a down payment on what we need to do to recover CISA, to get it to get it to a place uh where it's useful.
▶ 2:20:36I want to say one other thing, you know, my I graded the Biden I'm a lax grader at Georgetown, but I would I still would give the Biden administration a D, and I'd give this administration an F on their performance at CISA. It's completely unacceptable that our civilian cyber defense agency is treated like this. We would never treat the National Security Agency or US Cyber Command the same way.
▶ 2:20:56Yeah, I agree. And just because I have limited time, I I have to move to a different topic. So, I still have not had anyone give me a good reason why we should allow the administration to sell uh the H200 AI chips, the Nvidia chips, to China. Like to a country that is actively engaging in cyber warfare against us, and we are apparently now selling them the tools to do it.
▶ 2:21:22So, I'll ask you all would anyone like to take a crack at explaining why we should allow these chips to be sold to China? There's There's no good No one has been able to give me a good answer. There is no good answer. Congress is not powerless here. We could pass a bill to stop it today. As a matter of fact, a bill already passed out of committee over in Foreign Affairs, but it's been sitting on Speaker Johnson's desk for We We ought to do something about this.
▶ 2:21:50Um And with that, I I'm just about out of time, but I do want to elevate the point I think it was Mr. Visner made. Um, you know, the mythos um, technology from from Anthropic, we're still learning about it, but I think it does speak to the need to have some sort of a consumer safety test for AI products before they are released to the market because Anthropic is doing the right thing by voluntarily holding back on releasing it until the big players can be warned about
▶ 2:22:20about what their vulnerabilities are, but they didn't have to do that. There was no law that required them to. And so, there is a I think a desperate need for Congress to step up and ensure that there's some safety uh, in these products before they go to market. With that, I'll yield
▶ 2:22:33Uh, thank you. Uh, we'll do one last round of questions and then um, we'll conclude this um, this hearing. Uh, let me go to Mr. Visner. Um, you know, clearly there's a an intense threat environment when it comes to our um, our our our space systems. What specifically is missing uh, from the current US approach to space infrastructure security and what changes to law, policy, or federal organization would meaningfully improve our ability to defend these systems?
▶ 2:23:00Thank you Mr. Chairman for the question. I don't know that I'm going to be in a position to propose any legislative remedies, but there are some things that I think we ought to do. First, we need to recognize that space systems are in fact critical to every aspect of our national security, every aspect of our economic security, and every aspect of the security of our critical infrastructure. And we need to say so.
▶ 2:23:23We need to say so to ourselves, we need to say so to our people, we need to say so to our partners and our allies, and we need to say so to our adversaries as well, that this is a line you may not cross. That's a a first Um, I would refer you as well to a report done last year by the Council on Foreign Relations, and I was a um, a member of the task force that produced that report.
▶ 2:23:44It's called Securing Space, and it said that the White House should in fact um declare that that um that uh that space is a top priority for this country. Um it recommended that the White House convene a space summit in the first year of the administration or as soon as possible.
▶ 2:24:03Um and it also said that we ought to launch an assessment of the vulnerability of space vulnerability remediation and deterrence that included the participation of the Department of War, the intelligence community, the private sector, representatives of civil space organizations, academia.
▶ 2:24:19And I would add, by the way, that it certainly should include DHS, which despite its its the decrement in its in its staffing, there have been people at DHS who at CISA who have worked very closely um with with the Space ISAC and with the Space Systems Domain um and have shown a a great deal of interest. So, I do think that before we do anything else, we ought to get our act together.
▶ 2:24:44And one of the things that I would ask that we look at is um the National Security Council could play a role in coordinating the various stakeholders in the federal government to coordinate space system security. And that would include the the the uh the National Space Council, which I think um could and and hopefully will be reconstituted. Um that's something I think that could be done. Thank you.
▶ 2:25:09Sir, can I add one thing to that? You actually Congressman Lieu has twice tabled a bill to make space a critical infrastructure and a bipartisan bill. You should recon- you should retake that bill up and pass it. That if Congress wants to impact things, you force the government to make it a national critical infrastructure, treat it that way, and the the challenging part will be across congressional you know, kind of uh not partisanship, but parochialism about who should be the sector risk management agency.
▶ 2:25:39My strongest recommendation is NASA. Uh Representative Lou left it to the government to determine.
▶ 2:25:46I thank you for that. Um, I'll I'll stay with you, Admiral. You also mentioned the the threat to subsea cable infrastructure. We did have a hearing on that previously on this by the full committee. How serious is this threat? And how would a successful attack on a major cable route affect connectivity? How would it impact our security, the financial system? Um, and the government's ability to operate. I would like to just like to hear your perspective on this.
▶ 2:26:13I'm glad you mentioned that. It's absolutely a the most significant kinetic threat to the communications network. In other words, if I went after the satellites, I could attack ground stations, I could take out 5% of data flow. If I went after the submarine cables and cut the cables, I could cut 95% of data flow. So, it's it's obviously critical that we defend these. They are generally undefended assets.
▶ 2:26:40We know both Russia and China are aggressively designing weapon systems to attack them. Less sophisticated countries like Iran or North Korea can drop anchors on those cables. That does less damage, but can still have an effect. So, my my recommendations are is that we take we take a look at how we defend those cables, how we empower the Coast Guard to do it, and then I would step even one further back.
▶ 2:27:03What is the supply chain for those cables to ensure that there isn't a a pre-existing flaw inserted in them. So, I'm glad you brought that up. It's well worth the Congress's Congress's attention.
▶ 2:27:15Thank you very much. I'll conclude my questioning. I'll I'll recognize the gentlewoman from New Jersey, Ms. Sherrill.
▶ 2:27:24Thank you so much, Chairman and ranking Look, AI data centers are reshaping American cities, and they may be doing more harm than good. For many, an AI data center in your area means a decline in quality of life. It can mean higher utility costs, sometimes up to 300% more a month. It means air pollution already causing up to 100 million a year in health damages and a strain on water supply with numerous reports of contaminated well water.
▶ 2:27:54This reality is especially true for lower-income communities and communities of color. My neighbors back home know this very well. A plant data center in Kenilworth, New Jersey in my district has received major pushback just in a few in the last couple of days from the community. These constituents deserve to be heard. That is why I introduced the AI Data Center Site Selection Transparency Act of 2026.
▶ 2:28:20This bill would ensure communities are informed at least 180 days in advance before any major step toward developing an AI data center. So, communities have a real chance to organize, raise concern, and demand accountability. It will be impossible to regulate AI data centers if they are forced onto people with no community input, which makes things a lot worse.
▶ 2:28:45We know that they that the future is coming quickly and we need to make sure people are prepared to thrive, not ignored or harmed. With that, Mr. Montgomery, first of all, I want to thank each of the witnesses for your testimony today and for coming here to be with us even in our tricky schedules here in this place. Um Mr. Montgomery, as AI data centers rapidly expand across the country, how should we be thinking about ensuring both the cyber and physical security of these facilities as they are built within our communities?
▶ 2:29:16Uh thank you for that question. Of course, I'm never going to be opposed to transparency, so that's always a good thing. Um what we've what I've argued for here is that we need to make data centers and cloud a independent critical infrastructure, one with which a federal agency is charged with coordinating across other agencies to make sure that sort of transparency is clear.
▶ 2:29:38That the whoever the agency in charge is understands what the Department of Energy is setting for standards, what the Homeland Security setting for standards, when they're on military bases with the Department of Defense is setting for standards, and we have consistency across those. And then most importantly, it sets what are the physical standards in terms of it might be in terms of pollution, but it also could be in terms of physical security and what the cyber standards are for the security that whether it's the actual cyber security or the supply chain.
▶ 2:30:05So, if we do that and make it a independent critical infrastructure sector, I think we'll begin to get the kind of transparency, consistency, and security that you're demanding.
▶ 2:30:16Got it. Thank you so much for that. You've also noted that the cyber and physical resilience of these facilities merits the same level of attention. And we've already seen real-world risks, including reported attacks on data centers abroad that disrupted essential services for millions. Given those vulnerabilities, what baseline security standards or planning consideration should be in place before a data center is approved or constructed?
▶ 2:30:41Well, I think the physical security ones would begin with standoff distances. Uh so, you I get that you traditionally have for military facilities against explosive devices. Uh we're going to start thinking about drone security for these uh as we look at what's happened not just in uh Iran, but in your own state
▶ 2:30:58in your own state of New Jersey. Um and then we're going to as I mentioned earlier, we're going to need cyber standards both in terms of the supply chain and the actual operational technology running on the systems. Look, in I would hope that NIST, which is also we've talked about funding challenges, I think NIST's cybersecurity division has been cut too far, but it needs to become more involved in this and start setting the NIST the NIST 800 series uh for data centers to establish the proper level of cybersecurity on those centers.
▶ 2:31:28Thank you so much for that, Mr. McCrum. With that, I yield back.
▶ 2:31:31Uh thank you very much. Uh I want to congratulate uh the new ranking member. Uh look forward to working with you. Uh I want to thank the witnesses for their testimony and the members for their questions. Members of of the subcommittee may have uh some additional questions for the witnesses, and we would ask the witnesses to respond to these in writing. Pursuant to committee rule 7E, the hearing record will be held open for 10 days. Without objection, the sub- subcommittee stands adjourned.
▶ 2:31:55Thank you.