▶ 0:12:09The Committee on Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection will come to order. Without objection, the chair may declare the committee in recess at any Congress plays a critical role in assessing whether state and local governments have the resources, strategies, and federal support needed to prepare for the and respond to an increasingly increasingly sophisticated cyber threat environment.
▶ 0:12:33Today's hearing examines the current threat landscape, evaluates the effectiveness of federal support programs, and explores how we can strengthen cyber resilience at every level of government. I now recognize myself for 5 minutes for an opening statement. Good afternoon and thank you all for joining us. I think we have New York, Virginia, and the great state of Tennessee represented.
▶ 0:12:59And if I messed that up, you can feel free to correct but I truly appreciate you being here, the men and women on the front lines of cybersecurity in our states and local communities for traveling here today. The cyber threat facing America's states, cities, and counties today looks nothing like it did just 5 years ago. Nation-state actors, ransomware groups, and criminal organizations have grown more capable, more persistent, and more willing to target systems Americans rely on every day.
▶ 0:13:29Artificial intelligence is changing this fight in both directions. State and local governments are beginning to use AI to detect threats faster, respond more efficiently, and do more with limited staff. But our adversaries are also using those same capabilities against us, crafting more convincing fishing attacks, finding vulnerabilities faster, and carrying out operations at once that otherwise required specific expertise or specialized.
▶ 0:13:57The witnesses with us today have played a key role in helping their states embrace digital transformation and expand access to government services. But with this increased connectivity comes a larger attack surface and a greater level of risk. Just last week a ransom attack on Canvas shut down classes for students and faculty in the middle of final exams. Hospitals have had to turn away patients and cancel surgeries when their systems were held hostage.
▶ 0:14:23State agencies have gone offline for weeks, cutting seniors off of benefits they have earned and depend on. And water utilities have had their control systems probed and in some cases compromised. Each of these incidents has a real human cost, and they're happening more and more often. The core problem is a mismatch that Congress has an obligation to address. State and local governments are expected to defend against the same adversaries our intelligence community tracks, including China, Russia, and Iran.
▶ 0:14:54But with budgets and work forces that bear no comparison to what the those nation-states deploy against us, a county government in rural America may not have a single dedicated cybersecurity professional, and yet that county holds sensitive data on its residents, runs systems that deliver essential services, and sits inside a network of American infrastructure that our adversaries are actively working to I know this from personal experience. Before I came to Congress, I served as county executive in Tennessee.
▶ 0:15:23We had no dedicated cybersecurity staff and a tight budget. And we still had an obligation to protect our residents' data and keep their keep our government running. This is in part why the testimony we will hear today matters so much to me. To their credit, states have not been waiting for Washington to figure this out. Today, we will hear about whole-of-state cybersecurity strategies that push resources and expertise down to counties and municipalities that they cannot otherwise afford.
▶ 0:15:50We will hear from about information sharing programs that give smaller jurisdictions access to threat intelligence they could never build on their own. We will hear about workforce programs developed with universities and community colleges to train the next generation of defenders. These are real solutions and they deserve real support from Congress. But state efforts can only go so far without federal support.
▶ 0:16:11Congress recognized that in 20 recognized that in 2021 when we created the State and Local Cybersecurity Grant Program and put $1 billion behind 4 years. The premise was simple. A small town faces the same threats as a large city and a rural county is not exempt from Chinese or Russian cyber actors just because it has a limited IT budget. That program helped communities that could not otherwise help themselves. Unless Congress acts, that program expires this September.
▶ 0:16:41We should not let that happen and we certainly should not let it happen at a moment when the threat is growing ever worse. That is why I'm committed to enacting the Pillar Act, which we passed and we sent to the Senate Homeland Security Committee. Reauthorization alone is not enough. We have 4 years of program history now and we owe it to taxpayers to ask whether the money's being spent well, whether the structure is right, and whether the outcomes match the investment.
▶ 0:17:06Today is an opportunity to get honest answers from people who have actually run these programs. I look forward to hearing from all of our witnesses, especially Tennessee, and he's that And he's that to drive our actions as we go forward. And I recognize the ranking member, the gentlewoman from Illinois, Ms. Ramirez, for 5 minutes for her opening statement. Thank you, Chairman.
▶ 0:17:31Well, good I want to start by expressing my solidarity with the Islamic Center of San Diego and my condolences to the families of Amin Abdullah, Mansour and Nadira Awad, who were murdered in a horrific hate-filled attack on the Muslim I I want to say this because it's really important. We have to recommit ourselves to rooting out violence and hatred in all its forms.
▶ 0:17:55Since the incident, we've learned that the two suspects espoused hateful views about Muslims, about Islam, Jewish people, LGBTQ+ community, black people, and people across the political They also expressed beliefs that white people are being eliminated, echoing the dangerous white supremacist great replacement theory. I raise these details in our subcommittee because as members of Congress, we have to remember that our words matter.
▶ 0:18:21Words matter to 6-year-old Wadea Alfayoumi of Illinois, who was murdered because of dangerous anti-Palestinian There are too many examples of children put at risk by reckless misinformation and propaganda that fuels heinous And we, as elected officials, have an obligation to hold ourselves to the highest standards, rejecting dehumanizing dehumanizing rhetoric, and working to end all forms of bigotry so that no children, no family, no community around the country has to suffer as a result.
▶ 0:18:51In addition to being responsible for our words, today we address our responsibility to address cybersecurity threats facing our state and local We are facing a rapidly evolving landscape. The administration initiated an unlawful military operation against Iran, a country with a track record of responding to military operations via cyber capabilities.
▶ 0:19:14Last month, Anthropic announced a Methus preview, a highly capable AI model that has proven to be exceptionally effective at identifying vulnerabilities in software and writing exploiting for And in less than 6 months, state and local governments will administer the midterm elections, a target of past foreign interference efforts.
▶ 0:19:36While our work should be focused on responding to the rapidly changing cyber landscape and supporting state and local governments to defend against cybersecurity threats, the administration has been doing the It's eviscerated the workforce at Cybersecurity and Infrastructure Security Agency, leaving us with 1,100 It's eliminated CISA's election security team and defunded the Multi-State Information Sharing and Analysis Center and the Election Infrastructure Information Sharing Sharing and Analysis
▶ 0:20:07It's reassigned cybersecurity professionals to ICE and even the FBI cybersecurity staff have been stretched thin. There are real consequences when the federal government cuts the personnel and the resources that we have dedicated to identifying cybersecurity risk and mitigating them. And that's why this subcommittee hearing is so important because state and local governments store significantly personally identifiable information about people in our communities.
▶ 0:20:35Information about our school children, to those receiving public benefits, to even information on our small business Failing to support cybersecurity efforts at the state and local level puts that information at risk and it actually jeopardizes the privacy of the public. State and local governments have also had the responsibility of administering free, fair, and secure elections. It is the federal government's responsibility to ensure they have the support and the resources to be able to do such this.
▶ 0:21:05And thanks to the efforts of Congresswoman Yvette Clark, uh the former chair of the subcommittee, the federal government invested over a billion dollars over the last 4 years in state and local cybersecurity through state and local cybersecurity grant programs. But the program issued its final grants in year 2025. So while I appreciate the efforts of the full and subcommittee chairman to extend this important program, I am concerned that leadership doesn't have a plan to move this bill forward.
▶ 0:21:32The officials I've spoken to have articulated frustration that so many of the CISA personnel that they relied on for so many years and trusted no longer work at the agency. And support to the MS-ISAC and the EI-ISAC was also eliminated. So if Congress doesn't reauthorize the state and local cybersecurity grant program, the message will be reinforcing that you are on your own. And I find that to be unacceptable.
▶ 0:21:58We have to change course and we need to renew the state and local cybersecurity grant program because that is a step in the right direction. I look forward to hearing the witnesses' perspectives on this point in particular. And before I close, Chairman, I'd like to submit the following statements for the record. A statement from the Center for Internet Security, which houses the MS-ISAC.
▶ 0:22:20A report from the Bipartisan Policy Center, R Street, and the Institute for Responsive Government. And the Consortium for School With that, I yield back to the chairman. Thank you. Thank you to the ranking member Ramirez.
▶ 0:22:36And I would like, if I may, to echo her Uh we can have political uh religious disagreements, but violence is never Whether it's the attacks against the president, against members of Congress, individuals in our community, or at the mosque. So with that, we'll take a quick moment of silence. Thank you.
▶ 0:23:03Members of the committee reminded that opening statements may be submitted for the record. I'm pleased to have a distinguished panel of witnesses before us today on this important topic. Pursuant to committee rule 8C, I ask our witnesses to please rise and raise their right hands. Do you solemnly swear that the testimony that you will give before the Committee on Homeland Security of the United States of the House of Representatives will be the truth, the whole truth, and nothing but the truth, so help you God?
▶ 0:23:32Let the record reflect that the witnesses have answered in the affirmative. Thank you, and please be I would like to now formally introduce our witnesses. Ms. Kristen Darby is the Chief Information Officer from the fantastic and amazing and great state of Tennessee. I may have a little bias there, where she oversees technology strategy, innovation, and solutions for government services.
▶ 0:23:54She previously served as the CIO at various health care companies and has over 25 years of experience in the public sector, health care, finance, operations, biotech, cybersecurity, and insurance. Mr. Ahearn, sir. Ahearn, thank you, sir. Is the newly appointed Director of Security and Intelligence for the State of New York, where he coordinates the state security assets on national security and intelligence matters.
▶ 0:24:24He most recently served as the first Chief Cyber Officer, held cyber leadership roles for New York City, and served in the U.S. Army. Thank you for your service, sir. Mr. Warren Sponholtz is the Chief Information Officer for the State of Florida, where he leads the Florida Digital Service in modern- modernizing IT infrastructure and strengthening the state's cybersecurity defenses.
▶ 0:24:45He previously served as Deputy Chief Information Security Officer at Florida Digital Service, as CIO of the Florida Department of Environmental Protection, and as a United States Marine. Also, sir, thank you for your service. Mr. Samir Jain is vice president of policy at the Center for Democracy and Technology, where he leads policy advocacy and guides the organization's policy agenda and strategy. Mr.
▶ 0:25:08Jain helped shape national cybersecurity strategy and coordinate cyber policy in various positions in the Obama administration, and he was a partner at two international law firms. I thank each of our distinguished witnesses for being here today. I now recognize Ms. Darby for 5 minutes to summarize her opening statement.
▶ 0:25:32Chairman O'Halleran, ranking member Ramirez, and the distinguished members of the subcommittee, thank you for the opportunity to testify today on behalf of the great state of Tennessee. I'm Kristin Darby, and I serve as chief information officer for the state of Tennessee and oversee strategic technology solutions, the state's centralized information technology supporting 21 executive branch agencies and approximately 45,000 state
▶ 0:26:02I also serve as the co-chair of Tennessee's Artificial Intelligence Council and the state's Cybersecurity Council. Cybersecurity is no longer simply a technology issue. It's a matter of public safety, economic safety, and national defense.
▶ 0:26:22State and local governments operate critical systems that citizens rely on every day, including emergency services, schools, utilities, courts, and public Those systems are increasingly targeted by criminal organizations and nation-state actors.
▶ 0:26:42In Tennessee, we are seeing rapid growth of AI-enabled attacks, ransomware activity, and exploitation of cloud and identity systems. The pace of these threats continues to At the same time, many local governments across our state have little or no dedicated cybersecurity staff.
▶ 0:27:05This creates a dangerous imbalance between highly sophisticated attackers and severely resource-constrained We are also entering a new phase of cybersecurity risks driven by advanced large language models and artificial Emerging capabilities are accelerating vulnerability discovery and compressing the time frame between identification, exploitation, and
▶ 0:27:36Tennessee has responded with a whole-of-state cybersecurity approach focused on partnership, coordination, and scalable shared services under the leadership of our state CISO, Curtis Through our statewide engagement efforts, we have engaged more than 1,500 reached over 3,000 public sector points of contact, and achieved number one ranking in the US with the nationwide cybersecurity review completions
▶ 0:28:07in both 2024 and 2025. Most importantly, we are seeing measurable results. Organizations that participated consistently over 3 years demonstrated a increase in overall cybersecurity Through the state and local cybersecurity grant program, Tennessee has secured 89,684 endpoints across local government.
▶ 0:28:38We've trained more than 21,000 local government employees, and we've expanded access to endpoint detection, cybersecurity training, firewalls, disaster recovery capabilities, and managed services. Many of these local governments simply could not deploy or sustain these capabilities on their own.
▶ 0:29:01The grant program has also strengthened trust, communication, and overall coordination between state and local government in ways that continue benefiting Tennessee well beyond individual grant cycles.
▶ 0:29:15However, the demand for cybersecurity support far exceeds the current funding While Tennessee received approximately $21 million of federal funding across four grant cycles, we could have effectively utilized several times that amount to address identified needs across our local communities. Without continued funding, local governments will lose access to critical cybersecurity services. Managed protections will disappear.
▶ 0:29:46And the momentum we have built through the whole of state approach will slow at precisely the wrong time. Cyber adversaries are not slowing down, and neither can we. Based on Tennessee's experience, I respectfully encourage Congress to consider continued appropriated funding for the state and local cybersecurity grant program, lower and stabilized cost share improving real-time threat
▶ 0:30:17intelligence and establishing a rapid response funding mechanism that allows states to react quickly to emerging threats and zero-day vulnerabilities. The scale, speed, and complexity of today's threat environment requires the ability to respond at the pace of emerging threats. Thank you for the opportunity to testify today, and I I forward to participating in the questions. Thank you, Ms. Darby. I now recognize Mr. Ahearn for 5 minutes to summarize his opening statement.
▶ 0:30:47Chairman Ogles, Ranking Member Ramirez, Chairman Garbarino, Ranking Member Thompson, and distinguished members of the subcommittee, thank you for the opportunity to testify today. I am Colin Ahearn, New York's Director of Security and Intelligence. I want to thank Chairman Ogles for sponsoring the Pillar Act, Ranking Member Ramirez for the critical perspective she has brought to this subcommittee, and Chairman Garbarino and Ranking Member Thompson for their sustained focus on state and local cyber Our states are on the front lines of multiple cyber conflicts, yet we are being asked to manage nation-state risks while our federal
▶ 0:31:17partners step back. The coming expiration of the State and Local Cybersecurity Grant Program, the Cybersecurity and Infrastructure Security Agency workforce shrunk by a third with no Senate-confirmed director, and the cancellation of Multi-State Information Sharing and Analysis Center funding are dismantling tools that keep our communities safe. We are at a critical juncture. Artificial intelligence continues to collapse the technical barriers that once separated nation-state capability from everyone else.
▶ 0:31:44New tools are compressing the time of vulnerability attack to exploitation from weeks to hours, and these capabilities will soon be present in freely available open-weight models, including from The window to harden our defenses is not years, it is months. To prepare for today's and tomorrow's risks, Governor Hochul last year signed the Responsible Artificial Intelligence and Safety Act, one of the country's first state-level safety frameworks for frontier artificial intelligence models. However, we can only succeed together.
▶ 0:32:15Adversary nation-states continue pre-positioning inside critical infrastructure, stealing our intellectual property, perpetuating hybrid attacks, all while sheltering the ransomware crews that assail our communities every day. These threats are converging. The same criminal cryptocurrency infrastructure that drives billions of dollars in fraud also funds ransomware, helps bad actors evade sanctions, and lets anyone rent capabilities from professional cybercriminals. We are leaving our communities to fend for themselves against the world's most sophisticated digital adversaries.
▶ 0:32:46Federal action against that infrastructure and those adversaries reaches where state defenders in the private sector cannot. We need more of it and our defense depends on it. New York is a national leader in cyber. Under Governor Hochul's leadership, we have built a whole-of-state model, consolidated intelligence and security leadership, the nation's most robust state-level cybersecurity operations center, mandatory municipal cyber incident reporting, and critical cyber defense shared services.
▶ 0:33:14Our shared services protect over 100,000 county and local government computers in an operations center staffed by nearly 60 civil servants and six members of our National Guard. And by leveraging the state's purchasing power and economies of scale, the state is saving county and local governments over $19 million a year and providing cyber sophisticated tools that localities, frequent targets for cyber attacks, could not employ on their own.
▶ 0:33:38New York has also invested an additional $7.4 million in expanding the New York State Police Cyber Analysis Unit's Computer Crimes Unit and Internet Crimes Against Children Center. New York is committed to evolving our cyber defenses as threats evolve so that we can remain an effective partner to the federal government and the private sector. My written testimony contains six recommendations. I would like to highlight two.
▶ 0:34:02First, reauthorize and fully fund the State and Local Cybersecurity Grant Program, which is the single most consequential investment in the cyber protection of state and local governments in this country. In New York, this program is currently delivering over 112,000 multi-factor authentication hard tokens to local governments and school districts. Without reauthorization and stable long-term appropriations, the consequences for state and local cyber defense will be immediate and severe.
▶ 0:34:30To improve the program's impact, we should also reduce unnecessary burdens and restrictions that currently make it harder for states to deploy enterprise-grade software as a service shared services over multiple years. Second, end two-tiered frontier model AI access. State and local governments protect the energy grid, the drinking water supply, the public health system, and the everyday operations of government. We cannot do that while frontier defensive AI capabilities are restricted to federal partners and a handful of large enterprises.
▶ 0:35:00Cybersecurity is the silent partner of democracy. When the utilities, school districts, and state and local governments that constitute the operational fabric of American life are hollowed out by cyber attacks, the institutions that support our democratic life are hollowed out with them.
▶ 0:35:14The recommendations in my testimony are the elements of a single proposition, that the institutions of self-government in this country are worth defending against threats that do not respect state lines or international borders, and that doing so demands a federal government that is a partner to all 50 New York is ready to do its part. We want and need the federal government as our partner in this essential work. Thank you. I look forward to your questions. Thank you, Mr. Hearn. I now recognize Mr. Spano Holtz for 5 minutes to summarize his opening statement.
▶ 0:35:43Thank you, Chairman Ogles, Ranking Member Ramirez, members of the subcommittee. Thank you for the privilege to speak before you today. My name is Warren Spano Holtz, and I serve as the state chief information officer and director of the Florida Digital Service. Just like to start with uh saying that I appreciate the subcommittee's attention on existing and emerging cybersecurity threats that um that that face this nation every day. Florida is a large and attractive uh target.
▶ 0:36:10It's the third most populous state with roughly 23 million residents. Florida also includes nearly 500 counties and municipalities. It's home to major military commands, premier educational institutions, seaports, airports, and spaceports. But no matter where an attack is focused, our adversaries see us as one target, and our job is to build one coordinated defense.
▶ 0:36:32Nation-state activity has become a greater threat for state and local The adversarial use of artificial intelligence is fundamentally changing the speed and scale of cyber threats facing state and local governments. We are rapidly approaching an era of AI-driven vulnerability identification and rapid exploit development.
▶ 0:36:52Additionally, China's actions have changed the conversation around critical Campaigns commonly referred as Volt Typhoon and Salt Typhoon show that foreign adversaries are not only seeking They're positioning themselves in critical sectors in ways that would matter during a crisis. For Florida, that means we must not just monitor for obvious disruption, but also for quiet, long-term um long-term access that may be designed to remain undetected for years.
▶ 0:37:22This is changing how we conduct threat analysis, from long-term log retention and alerting thresholds to how we detect quiet persistence before it becomes an operational disruption. The center of that effort, and a priority for our Governor DeSantis, is Florida's Cyber Security Operations Center, or CSOC, housed within the Florida Digital Service.
▶ 0:37:42The CSOC serves as the state's central threat clearinghouse, monitors threats across the state enterprise, supports incident response, helps agencies and partners move from isolated alerting to coordinated detection and response. Central intelligence Sorry, threat intelligence is central to that program. Florida draws on numerous sources, including federal partners, law enforcement, multi-state coalitions, and cyber security vendors. But intelligence is only useful when it's operationally relevant.
▶ 0:38:12Agencies and local partners need timely, contextual information that matters to The federal government has been an essential partner in this work. Federal intelligence collection and sharing brings national visibility that no individual state can replicate. Florida adds state and local context to that national view. Critical infrastructure is also a major focus of Governor DeSantis' strategy.
▶ 0:38:35Florida continues to work with critical infrastructure providers to better understand the investment needed and where systemic risks exist. We use assessment data and the Department of Energy's Cybersecurity Capability Capability Maturity Model or to support consistent discussions about risk, maturity, and priority Florida's state-funded local government cybersecurity grant program is one of our most important tools for reaching local communities.
▶ 0:39:03Rather than simply issuing direct payments, the Florida Digital Service procures cybersecurity capabilities on behalf of participating governments. That model creates economies of scale, decreases procurement friction, reduces bureaucracy, and gives smaller entities access to enterprise-grade solutions. Through Governor DeSantis' leadership and in partnership with partnership with the Florida Legislature, the program has been funded at $30 million, $40 million, and $15 million over the past three funding cycles.
▶ 0:39:33This program provides seven foundational cyber capabilities across a range of solution providers. The federal, state, and local cybersecurity grant program or SLCGP complements Florida's state-funded model by addressing specific needs requested by local entities but are outside the state program. Because of this and the relationships and helped and helped foster through the program, the SLCGP should receive long-term reauthorization.
▶ 0:40:02At the same time, reauthorization must promote practical access for communities that need the program most. Higher unstable match requirements can discourage participation, especially among rural and fiscally constrained Reimbursement models can also be difficult for smaller communities that can't carry large upfront costs. Federal grant design should make it easier for the most vulnerable communities to participate. In conclusion, Florida has made meaningful process under the leadership of Governor DeSantis.
▶ 0:40:29We have built a central cybersecurity operations capability, expanded incident response support, strengthened state and local improved enterprise visibility, and created grant models to help communities obtain protections they could not acquire alone. However, cybersecurity threats transcend state lines. Continued federal partnership, information sharing, long-term reauthorization of SLCGP will help Florida and other states build a strong connected defense. Mr. Chair, thank you for the opportunity to testify. I look forward to questions.
▶ 0:41:00Thank you, Mr. Spano. I now recognize Mr. Jain for 5 minutes to summarize his opening statement. Chairwoman Ranking Member Ramirez and distinguished members of the committee, thank you for the opportunity to testify today on the cybersecurity threats facing state and local governments and the critical role of the federal government in helping to address them.
▶ 0:41:18My name is Samir Jain, and I'm the vice president of policy at the Center for Democracy and Technology, a nonpartisan, nonprofit organization that has worked for more than three decades to advance civil rights and civil liberties and to foster and promote a more secure and trustworthy digital ecosystem.
▶ 0:41:35State and local governments today are confronting serious cybersecurity threats across nearly every domain in which they operate, from the critical infrastructure that powers our communities and schools to the systems that administer our elections to the public benefit programs that millions of Americans rely on. When these systems are compromised, can lose access to critical resources and services at the moments they need them most.
▶ 0:41:59Recent ransomware and other attacks on cities and local governments have shut down a range of systems, from emergency dispatch to departments of motor vehicles to municipal courts. Each of these episodes meant real people were unable to renew a driver's license, to obtain a birth certificate, or otherwise to engage with local services to which on which they depend.
▶ 0:42:20Cyber intrusions can also mean that people's most sensitive information, social security numbers, financial data, medical information, information about their children, is exposed to criminal actors and foreign adversaries, leading to risks such as identity theft, financial fraud, harassment, and takeover of email and social media accounts.
▶ 0:42:39Just recently, for example, as Sherrod will mention, the breach of the Canvas Learning Management Platform not only disrupted essential learning activities for schools across the country, but exposed sensitive information of over 275 million users, including private messages that may contain deeply personal information. A pernicious knock-on effect of these incidents is the erosion of public trust.
▶ 0:43:03When Americans see a county hospital or their child's school district suffer a major breach, their confidence that the government can serve them effectively and protect their personal information necessarily is shaken. That erosion of trust has consequences far beyond any single incident. It can deter people from enrolling in benefits to which they're entitled, from registering to vote, or from engaging with public institutions.
▶ 0:43:28These risks are only heightened as artificial intelligence creates new opportunities for malicious actors to attack and exploit government systems at unprecedented speed and scale. The recent announcements of advanced AI systems with substantial cyber capabilities, such as the Mythos preview from Anthropic, have made clear that the offensive cyber landscape is poised to change dramatically, and small and under-resourced jurisdictions are likely to be particularly vulnerable to that Previously, the federal government has
▶ 0:43:58played an indispensable role in helping state, local, tribal, and territorial governments meet these challenges. Through the State and Local Government Grant Program Cybersecurity Grant Program, and through technical assistance the Cybersecurity and Infr- Infrastructure Security Agency, state and local officials have received targeted funding, threat intelligence, vulnerability assessments, network monitoring tools, and incident response The federal government has unique capabilities that no individual state can match.
▶ 0:44:28Visibility into foreign threat actors and nation-state campaigns, the ability to detect patterns of cybersecurity activity across jurisdictions, and a hub-and-spoke information sharing architecture anchored by the Multi-State and Elections Infrastructure Information Sharing and Analysis Centers, which has allowed real-time warnings, coordinated defense, and rapid response. But just as the threat environment is poised to accelerate at an exceptional rate, the federal government has dramatically pulled back.
▶ 0:44:58Over the past year, CISA has lost a third of its Federal funding for the MS-ISAC was eliminated. Key grant programs have not been funded or have been conditioned in ways that effectively block access to cybersecurity support, and long-standing institutional knowledge and relationships have been lost. The result is a widening gap between rapidly escalating threats and the diminished federal capacity to help state and local governments meet them.
▶ 0:45:25The federal government should act now to restore the funding, the programs, and the institutional capacity that have made federal-state cybersecurity cooperation work. It should reaffirm the federal government's commitment to information sharing with state and local partners, fund CISA, the ISAC ecosystem, and targeted grant programs, and reestablish the free or low-cost services on which thousands of state and local jurisdictions have come to rely.
▶ 0:45:50In short, it should renew the sense of shared responsibility that has defined constructive federal-state cooperation on cybersecurity. Thank you again for the opportunity to testify, and I look forward to your Thank you, Chairman, members will be recognized by order of seniority for their 5 minutes of questions. I now recognize myself for 5 minutes. This question would be for Ms. Darby, Mr. Spanholz.
▶ 0:46:16The integration of AI into cybersecurity practices is increasingly important as AI-enabled attacks continue to grow in frequency and sophistication. The National Association for State CIOs and Deloitte recently published a study that found that all but one security cybersecurity officer are already using or plan to use generative AI to improve cybersecurity operations.
▶ 0:46:41What successes or struggles have you experienced in your state's deployment of AI for cybersecurity? And where do you believe AI can be leveraged to enhance said security, Mr. Darby? So, AI has become a integral part of our operational readiness. The areas that we've seen successes are reducing the time to react.
▶ 0:47:09So, the speed of change is most important throughout our environment and the ability to quickly detect. And so, we have seen AI tools allow us to close that response gap in ways that exponentially increase our ability to react and cover throughout not only state government, but also local government.
▶ 0:47:35In addition to areas of challenge, I think workforce continues to be an area of challenge. Just developed talent around using AI tools and understanding how the threat landscape is changing. Things are moving at a very rapid pace.
▶ 0:47:53And so, continuing to understand that not only the state of Tennessee, but but our partners have the right resources with the right knowledge around those tool sets and how to best apply them based on the evolving threat landscape has been one of the areas of challenges that we continue to address. Which man which underscores why the pillar act needs to be passed in the Senate and why is this committee will continue to double down on this very issue Mr. Spano. Absolutely.
▶ 0:48:23Thank you Mr. Chair. In Florida, we are looking at AI from a cyber security perspective around automation of tasks for cyber security operations. So moving intelligence into platforms where we can align with vulnerabilities that are in the with indicators of compromise that show up with our telemetry analysis and our cyber analysis. That is a very resource intensive work.
▶ 0:48:52AI can not only position so we can be more efficient with our resources, but also make it happen much faster and around the clock. So we're excited about that capability around AI. More broadly for AI, we're also ensuring that sensitive data is not being shared outside our our systems and ensure that we have controls in place to be able to prevent that from happening and also ensuring that we've got the right kind of controls so we have human in the loop.
▶ 0:49:19So no AI actions are taken for for an agency and an agency action that aren't in control of a human. So we're keeping mind of those important principles as we explore the different uses and efficiencies around around AI. And my next question would be for any of the witnesses, but I'll start with you Ms. Darby is when I was county executive, we had a cyber attack.
▶ 0:49:42We were fortunate then we had had already put in place a contingency plan so we were able to shut down and boot back up, but when you look at um you know, cyber security going forward, what do What do we need to do in partnering with states to make sure the small and rural communities like Murray County when I was executive aren't left behind because again of that staffing and talent issue that you spoke of, ma'am.
▶ 0:50:06So, we take the responsibility of protecting all of our local communities very seriously in Tennessee. And one of the areas that I do think is important is participation in the grant program, but also modification of the rules to allow more flexibility.
▶ 0:50:26So, after I came into this role a few months in, we had a local community attacked and they had selected one of the services in the grant They needed the other service to respond to what the issue was and based on the grant rules, we were unable to extend that to them. That type of flexibility to allow us to come to the table with any solution to help the local communities in need in the time of an attack is absolutely essential.
▶ 0:50:56So, I think that area of flexibility is very critical. Um building the relationships with the state, uh the state um IT function, also our National Guard, uh and then many of our other um law enforcement facilities, etc. We all have a very coordinated um relationship and a lot of that was brought through the through the grant program of building those relationships and the connectivity.
▶ 0:51:24The ability to extend um high-impact, low-touch solutions to those local communities is critical because they do not have the resources that a state would have to be able to protect their communities, but their citizens have the same expectations. Yes, ma'am. My time is expired and so we'll come back. I think we'll have time for another round of questions, so we'll start with you when I when it's my turn again, but I want to recognize the ranking member, the gentlewoman from Illinois, Ms. Ramirez, for her 5 minutes of questions. Thank you, Chairman.
▶ 0:51:54It's certainly a very important conversation, so I look forward to another round. State and local governments don't just operate some of our most critical infrastructure and provide essential public services. You're also maintaining sensitive data on many of our When nation-state actors or criminal groups get access to that data, our constituents' privacy is put at risk and in danger. So, Mr. Jain, can you elaborate on the scale of sensitive information state and local governments have on Americans?
▶ 0:52:25And and I think the second part of that question that I I want to make sure we have for the record, why nation-states and criminal groups might find accessing that data particularly valuable. Uh I'm Thank you, Ranking Member Ramirez. Yeah, I mean, states and local governments have some of the most sensitive information about individuals, often even more sensitive than commercial providers have.
▶ 0:52:51And crucially, in many cases, this information that people have no choice but to provide to state and local governments to participate in getting a benefits or to get critical services. It's not a voluntary relationship necessarily in all cases. And the kind of data we're talking about is everything from medical data to financial data to your social security number to information about children and their health conditions.
▶ 0:53:17And that data is um you know, can lead Loss of that data can lead to harms from identity theft to financial fraud to impersonation. Particularly now, you know, we're talking about AI. AI The dangers that AI poses are not only that it enables or makes easier intrusions, but it also enables for the use of this data in more pernicious ways.
▶ 0:53:41You can eat more easily draft authentic sounding fishing emails to to conduct fraud and engage in other kinds of impersonation using AI in ways that you couldn't before. And so, you know, all of that is critical and you know, foreign actors want that Sometimes they're criminal in nature and they want the information just to gain money. Sometimes particularly some of our adversaries will want that information for counter intelligence type purposes.
▶ 0:54:10Particularly if you're talking about individuals who are serving in the military or in the
▶ 0:54:14Yeah. So, I think I know the end. I think you started actually answering my second question, but I want to make sure that I ask it for the record. Why is it so important that the federal government increase support to state and local governments to better protect our constituents' privacy? Because right now that we're we're they they face a real asymmetry in terms of the resources and capabilities of the attackers, not only nation-state attackers, but with the advent of AI, the ability of even criminals to have incredibly sophisticated capabilities.
▶ 0:54:45And on the other hand, you've got state and local governments that lack a lot of resources and staffing in which the government can the federal government can really help. I assume that the other three witnesses would agree you would want to see more federal support for all those reasons. Thank you.
▶ 0:54:59Let me just wrap up on a question around election Under this administration, CISA has cut its long-standing election security support to state and local election And while Congress has restored funding for CISA's election security programs, the administration does not agree in restoring these funds and CISA does not intend to be the partner to state and local elections that it has been in the So, Mr. Jain, this question's for you and then I have another question for the rest of the folks here.
▶ 0:55:27What is the impact of CISA cutting support for election security? I think it's quite critical impact for the similar reasons that we're talking about. Election officials, which you know, include, you know, in many cases just very local jurisdictions that lack a lot of resources or lack staffing, facing attack, you know, election election systems are attractive targets for nation-states.
▶ 0:55:52And um without those kind of security support, um you know, the integrity of our elections are potentially at stake. And you know, even whatever there's obviously a lot of disagreement around elections and some of the politics around it, but we should all be able to agree that we don't want nation-states or other foreign actors interfering in vote counts or voter registration databases and the like.
▶ 0:56:12Right. Well, thank you, Mr. Jane. So, Mr. Darby, Mr. Ahearn, and Mr. Spanholz, what are your states doing to ensure your elections are secure this cycle? And I'll start with Mr. Darby. So, the election systems are outside of my scope of responsibility, so I can't speak to that um directly. Mr. Ahearn. The State Board of Elections administers elections. Uh we have We're a home rule state, so county and New York City administer elections.
▶ 0:56:43I'll say a couple of things. Number one, uh with the Federal Bureau of Investigation, the Department of Homeland Security, as well as the New York State Police, uh and the New York State Division of Homeland Security and Emergency Services, we run from primary day through election certification a secure election center in person in multiple locations around the state.
▶ 0:57:05We have a deep and long-standing relationship with the Center for Internet Security, which houses both the Multi-State Information Sharing and Analysis Center, as well as the Elections and Information Sharing and Analysis Center. Uh and we're deeply committed to ensuring that the fully auditable paper ballots, which exist in New York State, uh that people are confident in the election, they're confident in the results, and they're confident
▶ 0:57:27Thank you. My My time is up. If we do that next round, we'll go to you. I appreciate it. Thank you. I yield back. The gentlewoman yields back. I now recognize the gentleman from Florida, Mr. Gimenez. Thank you very much, Mr. Mr. Chairman.
▶ 0:57:45I guess I'm going a little different different direction and and I don't know who can answer this, but would you say that our adversaries actually have a manpower advantage when it comes to our cyber attacks? That they they they far outnumber us. Their offensive capability or number of people engaged in this outnumber the number of people we have trying to defend against it. Anybody want to answer that one? Yes, sir.
▶ 0:58:12I I think one thing that I think is is to your point, sir. The Federal Bureau of Investigation last year indicted approximately 15 members of an organization called I-Soon, which is a Chinese private company that was as alleged in the indictment used by the Chinese Ministry of State Security to conduct surveillance on dissidents overseas to obtain, you know, economically and militarily important information in the United States.
▶ 0:58:40So, to your point, sir, they're using their own private sector to amplify the effects of their transnational repression, their economic espionage, and their theft of intellectual property. And did you say that they have far more people involved in that than we have defending against I think from my perspective, sir, what I could say is that while we work every day 24/7 365, the rapid amplification and nature of the threat, it's clear that
▶ 0:59:11our adversaries are extremely well resourced. Okay. What would you say that Mr. Spanshold? Would you say that I don't think we'll ever get to the point we're going to have the same, you know, you know, person-to-person, right, going at each That you say there's the advent of artificial intelligence for all intents and purposes, but I also can see that artificial intelligence can be used for defensive purposes and amplify our our our way to defend ourselves.
▶ 0:59:41And I think actually that's the only way we can go, okay, using artificial intelligence in order to combat their artificial intelligence. And I can see a day where we're attacking each other and defending each other a million times a second. where are we on artificial intelligence on the defensive side? Thank you, sir.
▶ 1:00:02This is something that the entire cybersecurity industry, whether it's uh corporate side or government side, is paying a lot of attention to because um there's a really a large pending threat around that uh vulnerability assessment and exploit uh generation that will just happen so much faster than what we're used to. So, I know uh in speaking with our uh industry friends, uh they are working on solutions to be able to incorporate within the solutions we use today.
▶ 1:00:30Uh so, be able to bake in some of the uh additional protections. Um we are looking at it as I mentioned earlier about making it so that we can operate faster, um more efficiently, but I think the real answer is collaboration between state, federal, private sector to be able to develop solutions to uh like you said, Congressman, um fight fire with fire and and use AI to be able to to defend this nation and the and the governments within it. Yeah, cuz we could we could hire as many people as you want, okay?
▶ 1:00:59But in the end, it's going to be it has to be automated cuz I don't see I don't see any way around it. Um and so, maybe the the the role of the federal government is actually to fund the research and the defensive research that we need to automate our our our defenses against against their offensive capabilities. And frankly, also develop our own offensive capabilities, which I'm sure we have. Um and and that would seem to be to be the only way that we can combat this and let machines follow, you know, fight each other at the end.
▶ 1:01:26Um, in terms of election election security, I also believe that there is no systems that are absolutely safe. And that the only way that we can get to uh verify and have election security that people are are confident is that we have some kind of paper ballot, something that you can touch. Uh, and and you can't hack.
▶ 1:01:47Uh, so there's a we, you know, you bubble it in or whatever, and that at the end you can uh, audit it and you have something some strange result, you can always go back to that precinct and say, is that is that the count that you got machine wise? Does it match up with what you got ballot wise? In state of Florida, do we have ballot paper ballots? I I I can't confirm or deny that on Congressman.
▶ 1:02:13I know the state focuses a bunch of attention through Department of State on non-repu- repudiation, excuse uh, in terms of elections, but I I just don't have that information, but I can find out and and get it to you, sir.
▶ 1:02:23In the state of New York, do you have paper ballots? Yes, sir. That's good. Excellent. So, we need to make sure that all 50 states have paper ballots and that way it's the only way that we can guarantee, absolutely guarantee, that we have election integrity cuz if there is is a question, you go back to the good old fashioned paper ballot and count them by hand. Thank you and I yield back. The gentleman yields back and now recognize the gentlewoman from New Jersey, Ms. McBath. Thank you. Thank you Thank you to our witnesses for being here today.
▶ 1:02:53Uh, local governments hold some of the important information about our constituents, such as health care, tax, and criminal history records, but have some but have some of the fewest resources to ensure that this information is secure. Their budgets and personnel are stretched thin. Few local government entities have enough resources to track such as an ever-changing threat landscape. This reality can be devastating.
▶ 1:03:18Back home in my district in New Jersey's 10th Congressional District, students at Cranford public schools had some of their personal information leaked in a nationwide cyber attack. This was alarming and challenging, but we know it could have been worse. We must act to ensure this does not become a routine part of life. However, this administration has decided to take a step backwards by putting a hiring freeze at CISA at the start of last year and pushing out over 1,000 employees.
▶ 1:03:48Trump gutted a key tool in our fight for local cybersecurity. Although the administration appears to have realized the negative impacts of these cuts and started hiring at CISA again, we must continue to demand adequate resources to ensure we are protecting every American's data at every level of government. Under the Trump administration, CISA has lost once again a thousand staff or nearly a third of its workforce.
▶ 1:04:13These cuts have impacted all its divisions, including the regional offices that provide support to state and local governments. To all the witnesses, I would love for you all if you could elaborate on how important CISA is for cybersecurity, right, and cybersecurity experts on the ground throughout the country to provide support to state and local governments.
▶ 1:04:33And also, how have CISA regional staff helped state and local governments strengthen their security and respond to Uh thank you, ma'am. Maybe just a couple of points. Uh number one, we have a close relationship with our CISA Region 2 staff. We've had the opportunity to meet multiple occasions across administrations with senior CISA leadership. We have a deep partnership with the federal government. As I said in my opening statement, we want and need more of that partnership.
▶ 1:05:00Uh and we had in 2022 a very significant cyber attack against Suffolk County, uh a county on Long Island, uh and the CISA Region 2 staff along with the local office of the FBI, along with the Secret Service, along with the state police, along with the Suffolk County Police Department, created a tiger team to help respond to that event along with the county executive and his team. Uh so, we have real-world experience of working directly in very significant cyber attacks directly with local communities.
▶ 1:05:30And that kind of team effort, I think, has given us uh a very deep appreciation for the importance of the team sport that is cybersecurity. Thank you. Anyone else care to elaborate? Miss Darby? So, with CISA, we have um seen them as an important partner in providing guidance, services, coordination, and information sharing.
▶ 1:05:53We believe the continued collaboration between federal, state, and local is critical because, often times, as has been mentioned, uh the threats and attacks are coming from outside state That being said, in Tennessee, we have certainly seen significant success with the whole-of-state approach.
▶ 1:06:13The um combination that we have with local governments, uh local school systems, and many of our municipalities being able to work with the state has built a strong awareness of not only the local needs, but what those communities have from a maturity perspective in ways that we can cross that bridge and then use CISA as an organization uh to help us correlate and understand when threats or attacks
▶ 1:06:43are occurring. Is this um broader than the state of Tennessee? Is it localized? And um they bring that intelligence that helps us connect the dots that are very important at critical times. Got it. Anyone else care to elaborate in less than a minute? I'll just echo uh Chief Darby. That's exactly right. Just like uh the Florida Sea SOC serves as a clearinghouse for threat information, CISA a something similar. There's nobody really else uh, positioned to do that. So, it's an important role and something we depend on. Thank you.
▶ 1:07:13Got it. And I'll just add, along with CISA and CISA's support and coordination with the I- MS-ISAC and that the ability to share information, to also provide monitoring tools and sensors and those kinds of tools to particularly to local jurisdictions that otherwise wouldn't have the resources to um, deploy those. Thank you. Thank you so much for each of your expertise. With that, I yield back. The gentlewoman yields back. I now recognize the gentleman from Texas. Thank you, Mr. Chairman.
▶ 1:07:43Good afternoon, Information flow is critical when you're talking about cybersecurity, cyber threat, cyber risk. You have the federal which moves at a snail's pace and anything that we can either move through committee or appropriate most likely land a few years later. Some of the challenges that I see, we only have three states. Sorry, sorry, I don't know where you're from. I apologize. Unless you're somewhere over there, not I'm just going to go with three, okay?
▶ 1:08:11Um, we have three states that have these issues and all of your opening statements, those issues were Similar, but they varied left or right. And we have to wade through the the weeds at any given level to say, "Okay, which one's right? Which one's the most And which ones are we going to address?" Now, attacks happen at the federal level from nation-state actors, from local mom and pop shops down the street and they happen to you, too.
▶ 1:08:38Problem is when they happen to you, often times that's not communicated to us and the reciprocal of that is when it happens here, it's not communicated to you. Now, we have CISA. Mr. Hearn, you you mentioned the Department of Energy. I don't know if Mr. Arbuthnot or Mr. Spano, do you does the state touch the Department of Energy in any way? I I didn't hear you say that and I don't It's remarkable how valuable of an asset the Department of Energy is when it comes to the protection of the metaverse above us. But some states do not.
▶ 1:09:07This my question concern is how do we the states, all of them, subject matters experts like yourself to address us to give us so we, the grand profile, I understand CISA very important. And I don't know if I can speak for the entire committee, but we're behind that, or at least I am. How about that?
▶ 1:09:30At least I Cuz I see the ones and the zeros and I see the problems that that is scaling itself in a way that we can't And we would I would personally love to give you everything that you need, but I have three sitting in front of me that ask different things and I have I had to have the rest of the states to come in and ask, just think of that and how challenging that is for us. Cuz if you can just convince the five of us that are in here today right now, we have to convince everyone else to get on board with that, too.
▶ 1:09:57But it's very challenging if there's so much. Do this do your counterparts short of the three sitting here collectively come together to give that to us? Or can you or will you? Ms. Darby, you can start it off, ladies I don't know why there's not somebody from Texas sitting on that row, but you know, Tennessee, we we can work with that.
▶ 1:10:27Uh thank you for that. So, I think there is um so, I'll speak first for the state CISOs. I know that there is a strong network where they have um channels where they are connected on a daily basis um around emerging threats. They don't wait for um an administrative agency or to be told about things.
▶ 1:10:47There is um certainly that informal information sharing going on in a way that um we're all Americans and we're going to make sure we're all protected regardless of state borders and we recognize that those threats don't necessarily follow certain jurisdictions, excuse me. And so with that, I think the relationships and coordinations that happen informally are often more timely and more valuable.
▶ 1:11:16It's not to say we don't need the other coordination because everyone has more formalized areas of information gathering that's being provided, but those informal networks that have already formed through the opportunities for information officers or CISOs has been extremely valuable. How about this? If I was to ask the the four of you how do we fix this problem right now?
▶ 1:11:46Would the response you're going to give me would be money? I think
▶ 1:11:51Cuz you ask for it every I'm not wire brushing you, please, but that's That's what we ask for every year and every year this problem gets worse. I think sir there's two challenges that the committee has recognized that I think we see at the state level as well. One is the shrinking of CISA's capability making attenuating the operational coordination that we undertake through both formal mechanisms like the state fusion centers. Ours is called the New York State Intelligence based in East Greenbush, New York.
▶ 1:12:20There are 50 analogies around this country. They have representatives from the FBI, the Secret Service, the alphabet soup. And so we, you know, obviously ensuring that CISA is, you know, authorized and resourced to continue to conduct that mission. So I have I have 7 seconds and I apologize for sharing, but if every state went directly to CISA and CISA was one sitting in front of us saying this is exactly what every single state needs that might be a profound leap in the right direction.
▶ 1:12:49Does Does even remotely sound like a good idea? I guess not. Thank you, Mr. Is that okay, Mr. All right, thank you. question about how do we get consensus, how do we really understand the problem, 50 states. I would leverage some of the great communities we have like through NASCIO, the National Association of State CIOs. There's great communities of practice within NASCIO including the CISO community.
▶ 1:13:15So, to be able to get somebody working like from CISA with NASCIO to help forms can some consensus on direction, I think maybe a path
▶ 1:13:23see how wide this net is being cast just in the conversation that we're having right now? I mean, again and I don't know the best way to answer it. You're the subject matter experts, but you just threw another acronym and an institution that I have never even heard of. And we have to wait through that in order to give either appropriated or regulated, correct? Thank you. I apologize, Mr. Chairman. The gentleman from Texas, Mr. Latta Latta Trail yields back.
▶ 1:13:51I go to the gentleman from Virginia, Mr. Wexton. Thank you, Chairman Ogles and Ranking Member Ramirez for convening today's hearing and for our witnesses for joining us. As we've heard at the very moment that state and local governments face more frequent and more sophisticated cyber threats, the federal government is pulling back and leaving them more and more to fend for CISA has lost a third of its workforce. I represent many of those third who have lost their jobs.
▶ 1:14:20Key programs have been eliminated or defunded. As we've heard from our witnesses, funding for the multi-state and elections infrastructure ISACs have been eliminated. The state and local cybersecurity grant program has yet to be reauthorized, although there's strong support here to do that. But, if you look at what has happened over the course of this administration we've been lowering our defenses as a while our adversaries are getting more aggressive.
▶ 1:14:49Cyber attacks against state and local governments up 50% Iranian hackers targeting small water utilities in March of this year in Iran-backed hacker caused global disruption at a major medical device recently as we all know the education platform Canvas attacked by a hacking group gained access to millions of users data including students, teachers, and staff.
▶ 1:15:14The attacks are growing in quantity and sophistication and the consequences are stacking up. And to me I think it makes one thing unmistakably clear state and local governments and critical infrastructure operators need strong steady federal support and partnership. And instead we've seen the Trump administration walking away abandoning these communities who are on the front lines of the threats.
▶ 1:15:44And I just want to ask about some of that. Uh when CISA cut support for the MS-ISAC they said there would be a quote new Um Mr. Ahern, are you can you talk us through what that new model is that CISA developed when they eliminated support for the MS-ISAC? I have not been made aware of that new model, sir.
▶ 1:16:12there isn't a new model. The new model is governments that want to participate can pay to participate. They offered no new services or new structure. Uh became a payment-based and um Mr. Jain, just under that new model there's a risk that some jurisdictions maybe lose access. Maybe they can't afford to they have a tough budget year.
▶ 1:16:42I've been in local government. uh Happened to be in one that would have the resources in most years to pay whatever the fee might be, but those jurisdictions that might not have the to pay the fee to participate, you say they're more likely to be in urban areas or rural areas? You know, I think it may vary.
▶ 1:17:05I think rural areas in particular, but it I mean, what's particularly unfortunate about that is it's the jurisdictions that most need the help that are least likely to be able to
▶ 1:17:18jurisdiction because if they don't have the resources and the money to join the ISAC, they probably also don't have the resources and the money to you know, to buy equipment, to buy network monitoring tools, to staff to have cybersecurity staff. So, in some ways it's the the ones who need it the most are the least likely to be able to get it as a result of that model. Mr.
▶ 1:17:38Ahearn, in March of 2025, the administration said that the Critical Infrastructure Partnership Advisory Council no longer met department priorities. Can you just talk us through in 1 minute what that was and what capability or capacity is lost with the elimination of that council? Uh yes, sir.
▶ 1:18:00In short, that Critical Infrastructure Partnership Advisory Council was a formal collaborative environment between state, local government, and the private sector. Uh and we believe as part of this effort, we should reestablish that body.
▶ 1:18:14We should bring in the cloud and other service providers on which state and local governments so dearly depend uh because those environments and that partnership framework is critical for ensuring that we have a continuous and accurate representation of the risk that these providers place to our government. Thank you. And I just you know, I really appreciated Mr. Luttrell's line of questioning and his concern that sometimes everything sounds like it's going to cost money, cost money, cost money.
▶ 1:18:42I would submit to my colleagues that one of the most cost-effective things we can do at the federal government level is play that convening role. There is no other entity that can as effectively bring together governments, the private sector, experts to share information and develop solutions together. I think that's a really, really good bang for our buck and we're losing something with the elimination of that. Thank you.
▶ 1:19:12The gentleman yields back. I recognize the gentleman from New York.
▶ 1:19:16Mr. LaLota from Florida. Thank you, Chairman. I agree with the gentleman from Virginia. We should do more about Mr. Ahearn, how you doing? Good to see you again, sir. You're from New York? Yes, sir. And in 2022, you were appointed New York's first cybersecurity officer. Yes, sir. And you were recently promoted to the director of security and intelligence in the governor's office. Yes, sir. Um so, you're in charge of cybersecurity in the great state of New York. That's Um Mr. Ahearn, is cybersecurity important to Governor Hochul?
▶ 1:19:47Yes, sir. I think Governor Hochul has proven both with our deep partnership with the legislature and the long-standing relationships we've established across the federal government uh that we take cybersecurity and cyber resilience very seriously. And demonstrating that importance, she gave you a budget of about $90 million. Yes, sir. Okay. Um earlier you mentioned a ransomware attack in my county, Suffolk County, in 2022. I want to say thanks for mentioning that.
▶ 1:20:13Um do you know about, and if you don't know specifically, no harm, but if do you know about how many ransomware incidents were reported in New York State in 2025? Um the numbers that I have is that the total complaint volume, according at least to the FBI's Internet Crime Complaint Center, was approximately You're very well prepared, sir. Thank you. Um the the one that happened in the town of Southold, a town in the North Fork of Long Island in my district.
▶ 1:20:41Um I don't know if you remember this in November of 2025, it was the week of Thanksgiving. They had an attack. Uh the the attackers wanted about $600,000 in cryptocurrency. They froze the town's email, payroll, tax collection, building permits, decades of records. It took us weeks, if not months, to get everything back online. Um we rightfully didn't pay the ransom. Uh it took us about a half a million dollars to rebuild the system.
▶ 1:21:09Um and it was a tough event for us, and we wanted more help, and uh we can have a conversation offline about more of what the state and feds could have done for us there. But back to some other issues. Governor Hochul, she's your boss? That's correct, sir. You testified a few moments ago that cybersecurity is important to your boss? That's correct, So important that you dedicated about 90 million dollars to the state's cybersecurity efforts, including the things that have happened in in my county with Suffolk County and my town for to town of Southold?
▶ 1:21:39That's correct, sir. So is protecting New Yorkers from cybersecurity threats more or less important to Governor Hochul um than the migrants who are in our country in our state illegally? Well, sir, I think that the issue of public safety is deeply important, and while we're here to talk today about the importance of cybersecurity, uh we don't believe that these are mutually exclusive concerns. Okay.
▶ 1:22:03So the question is, is cybersecurity more or less important to Governor Hochul than the migrants in New York Do you have an answer for that? Sir, I think what is important is emphasizing the deep partnership we have with the private
▶ 1:22:18I'll take it as a as a no answer. That's fine. Uh Chairman, I want to submit into the record with unanimous consent uh from the New York State Comptroller's website a report that Governor Hochul's spending 4.3 billion dollars on migrants hotels, health care, and lawyers. So, she's spending 4.3 billion on the migrants and she's spending 90 million on social security. We enumerate at least two incidents in my district that are important to my law-abiding citizen constituents who pay a lot of taxes. Do you pay taxes, sir?
▶ 1:22:49I do, sir. Do you pay state taxes? Yes, sir. Do you know that we have the worst state tax climate in the entire nation? Sir, I think that um
▶ 1:22:57So, yes or no? Do Do you know that New York is dead last? I did not know that,
▶ 1:23:01Unfortunately, it happens to be true. And yet, despite this issue and we're here talking about important issues. The gentleman from Virginia makes a good point that we should all be doing more and you're here to ask for more money. The challenge that we have here is that your governor is spending 48 times more on the migrants than we're spending on cybersecurity to protect law-abiding Is that an issue for you? Sir, I think that the issue of cybersecurity is deeply important.
▶ 1:23:28I think the issue of public safety is absolutely essential, but we don't believe that these are either mutually exclusive concerns or should be set in opposition to each other. Sure, but our budgets are reflective of priorities. Plenty of politicians that have have said that our budgets are our priorities, but when you're spending 48 times more on the migrants than you're spending on protecting law-abiding New Yorkers, that's an issue. Have you read recently about the governor giving Mayor Mandami 4 billion dollars to bail out his state budget? Yes, sir.
▶ 1:23:59Okay. And you know the the mayor wants to have free buses and government-run grocery stores and all this other nice socialist stuff in New York City. Are you aware of I am aware of the comments about the mayor's priorities. Yes, sir. Okay. So, 40 times more towards New York City's government-run grocery stores and the free buses and all the other socialist wish list, 40 times more money to that than to cybersecurity.
▶ 1:24:26So, I'll ask you, what's more important to Governor Hochul, Mondami's socialist agenda or protecting New Yorkers from the next cybersecurity I think number one, sir, that the issue of cybersecurity and the resilience of our infrastructure 40, sir. 40 times more money to one thing than the other. Is socialism more important to Governor Hochul than protecting New Yorkers from the next cyber attack? The issue of public safety
▶ 1:24:5240 times a lot of money here than over here. Which is more important? The issue of public safety is deeply important to our communities and the Gentleman I yield back. security of our our communities is is is essential. Gentleman yields back. So, we'll have time for uh additional questions and so I'll pick up kind of where we left off and and just kind of to summarize, duly noted yeah, really from everyone but specifically Mr. Darby, Mr.
▶ 1:25:20Jane about the the lower match in particular for the rural uh poorer communities. Uh grant flexibility, a response fund and like a zero-day type apparatus, but picking up with you, Mr. Hearn, um when you look at rural communities, small communities, how do we specifically address them not being left behind?
▶ 1:25:47I think number one, sir, it's the shared services that each one of our panelists have commented on. Uh as, you know, my uh the my colleagues from both uh Tennessee and and Florida have mentioned, the ability of using whole-of-state cybersecurity shared services to make sure that we can substantially mitigate both the cost and the complexity of deploying these tools as essential. One of the things I think that we've all found uh is through the grant program's current structure, it is harder to do that and we should make that easier.
▶ 1:26:17I think the comments from uh then gentlewoman from Tennessee are very important in considering how that might be done. We share those concerns. Uh and number two, we found that by engaging in statewide contracting, we're able to bring down the cost of those services. And one example is we saved county and local governments $19 million on one part of our shared services.
▶ 1:26:39And just recently, by going with a whole of state grant program, much like my colleagues, we're able to bring down the cost of multi-factor tokens by approximately 21%. Uh and that wouldn't be possible for uh a county or a local government in some cases to cover that match requirement. So, because we could lower the cost, we ended up being able to cover the cost share requirement as a state within the state budget.
▶ 1:27:05Uh and so, that could, you know, enable us to cover even more entities that would not be able to participate before. Well, and on that note, um you know, as my colleague from New York, uh obviously very passionate about the budget, um is you know, making sure that states are actually paying their fair share. And so, you have a large state like New York that is you know, the states set their priorities, right? Um obviously, cybersecurity is an important issue.
▶ 1:27:31Um and so, as we go, that's really the challenge we face is, you know, I'm sensitive to the small rural community aspect because that's where I was a county executive and we experienced a cyber attack. And we have a very forward-thinking leader, quite frankly, on cybersecurity in Tennessee, Mr. But then, we've got to figure out a way that we're helping the rural communities without propping up some of the big cities. And so, that's the challenge we face today as we go forward. And um so, to you, sir, Mr. Espinal.
▶ 1:28:02Thank you, Mr. Chair. Um completely agree. Our strategy in Florida has been to focus on the rural communities uh and the fiscally constrained communities, whether that be the state program or the federal program, Uh definitely prioritize them as well as our critical infrastructure assets throughout the state. Recognizing that they have difficulties being able to buy some of those kind of solutions that that are that are critical to protect information systems.
▶ 1:28:33And I'll just add on what Mr. was talking about in that not just driving down the cost, but a lot of times some of these solutions the rural and smaller communities are too small to even be able to be purchase some of these solutions, right? So some of these solutions expect larger implementations and larger sales and unless it's done through some larger purchasing mechanism, they won't even work with some of these smaller communities.
▶ 1:29:01So multiple benefits we've seen tremendous savings through bulk purchasing four to one savings last year, which was was just something was really um amazing for the state to be able to cover more local entities through our grant programs. Mr. Jane. I think I would add in addition to money, a lot of these jurisdictions lack staffing, lack the lack the expertise and staffing.
▶ 1:29:25Now part of that is not having the money to hire people, but it also means this is where CISA can really make a difference in terms of having being able to provide expertise to the local rural jurisdictions to conduct do things like conduct penetration testing and identify particular vulnerabilities such as that their systems may face.
▶ 1:29:45And so I think this is a place where you know, CISA where I having it the ability to join the ISAC without having to pay for it and to gain the benefit of that kind of intelligence and threat sharing is also critical. All right. What we'll do is I'll yield back. I'd like to recognize the ranking member Ms. Ramirez for five Thank you, Chairman. I I want to just respond for a moment um regarding budgets being moral documents. I couldn't agree more.
▶ 1:30:14Budgets are moral And spending a billion dollars on a ballroom, which is what the president or 1.7 billion dollars to incentivize while we still are waiting for the authorization of this critical grant program, says a lot about where priorities are right now with this administration. I just want to make sure for the record that we state that.
▶ 1:30:38While it's really easy to start um blaming immigrants for everything, I think that at the end of the day we have to ask ourselves, those of us that are actually prioritizing and have the influence over budgets, prioritizing ballrooms and incentivizing insurrectionist, while cybersecurity is not being funded at the levels necessary, says a lot about where our leadership is. With that, I want to come back to the conversation here. Rapid advances in frontier AI models are reshaping the cybersecurity landscape.
▶ 1:31:07We've heard from your own um testimony today um what is happening and the threats and the impact that your own respective states are having. For many state and local governments with limited resources, this creates many new challenges to defending your Mr. Jain, what are potential risks frontier AI models pose to state and local governments and their I think there's several different types of threats.
▶ 1:31:32One is that, you know, we've seen with Mistral's, the Anthropic model, and OpenAI's most recent model, that they're able to discover um vulnerabilities, sometimes vulnerabilities that have been embedded in systems for years without discovery. And if that those kinds of um capabilities get in the hands of other nation states or criminal actors, then they can identify vulnerabilities in state and local systems um perhaps more quickly than um those jurisdictions are able to patch them or to uh address them.
▶ 1:32:02and so there more vulnerabilities that could be exploited and can be exploited much more quickly than has happened in the past. Um, two, as state and local governments understandably and rightly use AI for more services, provide chatbots through which constituents can interact with um, and you know, use AI to help their own code coding their own systems, that use of AI itself introduces new vulnerabilities because as AI systems have access to data about people and they themselves then
▶ 1:32:32become a potential conduit for potential um, attacks. And the third point I'd make, which I mentioned earlier, is is that AI also allows for more efficient and more damaging exploitation of the data that does get taken in a breach. So it becomes much easier to draft, you know, very authentic phishing emails or to impersonate people um, using AI to generative AI to create those things.
▶ 1:32:56And so it makes the consequences and the harms of the breaches even worse um, when the bad actors have AI. Yeah. So my last question comes back to Mr. What does your state need from the federal government and from AI model developers to better secure your I think number one, we want the reauthorization of this grant program. As has been said before, we think it should be more straightforward to use them for shared services.
▶ 1:33:24Number two, we think that the cuts to CISA should be reversed. We think that some of the important convening mechanisms, uh, as as the representative said, are deeply important and there isn't another secret team that can do that convening. The Office of the National Cyber Director, the Cybersecurity Infrastructure Security Agency and the federal government is the essential partner in ensuring that we remain united against these threats. Thank you.
▶ 1:33:50So I heard you say the reauthorization of the grant program, that the cuts to CISA be be reversed and that we be the ones who are convening public and private partners to ensure that cybersecurity is top priority for us. Thank you. With that, uh Chairman, I yield back. The gentlewoman yields. I'd like to recognize the gentleman uh from Virginia, Mr. Watkinshaw. Thank you, Mr. Chairman. Um I'm sorry Mr. Lhota left, but Mr.
▶ 1:34:18Ahearn, uh during Governor Hochul's tenure, has the budget in New York for cybersecurity gone up or down? Up. Okay. Um do you know what CISA's budget was in FY 2025? I do not, sir. Okay, it was $3 billion. Do you know, or any of our panelists know, what President Trump requested in his budget for CISA in fiscal year 2027?
▶ 1:34:52$2 billion. So, we So, we we are looking at a cut in 1/3, a 1/3 cut in federal funding for cybersecurity. And as the ranking member noted, if President Trump gets his way in all ways, we'd be spending a billion dollars for the ballroom, $1.8 billion for the January 6th slush fund, $2.8 billion just
▶ 1:35:22on those two items. $800 million more than his total commitment to cybersecurity. I'm sure Mr. Lhota knows those numbers as well. Um I did want to ask all of you, I think one of the challenges we have in this conversation is how do you measure And it's certainly a challenge we've had in federal agencies. And typically the numbers we hear, we've heard some of it today.
▶ 1:35:52Uh the number of attacks has increased, right? It's 50,000 attacks in New York millions and millions of attacks. I don't know if that's a useful number other than to help us understand that the scope of the challenge is is significant. But I'm interested for each of you in your respective states, Ms. Darby and and Mr. Ahearn, Mr. Spano perhaps, how do you measure success?
▶ 1:36:17How do you determine whether your posture, set aside the attacks that come in, maybe out of your control, but how do you measure whether your posture is stronger today than it was yesterday? Maybe we'll start with Ms. Darby. Thank you for the question. So, in Tennessee, we have specific outcomes around every measure.
▶ 1:36:40So, it's number of endpoints uh protected, it is um cybersecurity training, and uh is that reducing uh whether it's phishing attacks uh or or and resulting attacks as a result of that. So, we have specific outcomes where um we focus on each of those.
▶ 1:37:01One of the the other areas that I would I would just offer in reflection of what's been discussed here today is um we've all expressed our um desire for the grant program to be renewed and believe it has provided significant but it was designed 4 to 5 years ago, and the climate has transitioned and I do believe scarcity often ignites and using this as an
▶ 1:37:31opportunity that if the grant program is renewed, do we look at different ways to identify what those outcome measures are that you're asking about, but also look at um for for a central convening organization, I think it also provides an opportunity to bring together national experts in ways that can help all the states leapfrog the capabilities that AI has introduced.
▶ 1:37:58We are all trying to figure out how to pivot traditional operations to future and there's a real opportunity here to do things differently. Thank you, Mr. Ahearn. Metrics of success for you all? Yeah, I think number one is we know that bad things are going to happen. There's, you know, there's adversaries on the other side of the world, on the other side of the keyboard. But number one from us is the time from from detection to confirmed remediation.
▶ 1:38:23And just one statistic we shared in our testimony with the state shared services program when you're you know, the state's program, it is 37 minutes from detection to confirmed remediation on average. Whereas without that shared services enabled in part by this grant program, it is 2,880 minutes or two full days.
▶ 1:38:44And that's the difference between using automation, cloud delivered services, 24/7 security operations center to Obviously, the attacker can do a lot more damage in that much longer time period. Yeah. Okay, Mr. Spano. Uh thank you for the question. So, just briefly, a couple ways beyond what's been discussed already is being able to measure the impact of a of an incident where we have protections, right?
▶ 1:39:12So, we expect that where we have better protections, better solutions, better training, we're going to have reduced impact and effects to the to the organization. A little bit easier to measure Excuse me, a little bit more difficult to measure, but something that's important to see how well our controls are working. And then secondly is time to provide contextualized information to locals and state agency partners.
▶ 1:39:38So, if we find something, getting that information to them as quickly as possible with good context on what the problem is, why it matters to them, and how they need to Thank you. Mr. If the chairman will allow, Mr. Jain, if you have any any thoughts on that? I think the only thing I other thing I'd add is another measure of success is really to what degree are constituents being harmed or not harmed in terms of are they suffering identity theft or some of the harms that can come from theft of personal information?
▶ 1:40:06To what degree are our critical services offline and not available to them over the course as a result of a cyber attack? So, I think looking at it from the point of view of constituents and consumers and what harms they are aren't suffering and minimizing those is really an important measure of success. Thank you. Yield back. You know, John Quincy Adams loved the House of Representatives cuz it's where you argue and debate. And and so, we can argue about the numbers. You know, the House appropriation for CISA's FY27 is 2.5 billion.
▶ 1:40:37There's an 185.8 billion cut over this 26 fiscal year. There is a 5.1 million specification there for additional security advisors and specifies 53 personnel in particular. So, that being to the idea of scarcity. So, we're seeing cuts and we can agree or disagree whether that's a productive thing, but we also know the government can't do this alone.
▶ 1:41:00That we need to have integration with the private sector and some of these NGOs that dabble, if you will, or pioneer in AI. And so, as you look at coordination and as you look at response time, Mr.
▶ 1:41:14Hearn, we sit down at a table and setting everything else aside, CISA, whatever other alphabet agency that might be there, and we were to create a construct of how do we make sure that breach in New York or Florida or is instantly known in Tennessee or vice versa cuz we're second seconds. It's kind of like a 911 call, you know, where a minute matters.
▶ 1:41:41And I would think arguably in this space, in this environment, because it is so rapid, and the data is so portable, that seconds matter. So, how do we fix it? So, I think it, you know, because of the amount of time we have left, I think this is an opportunity to, and obviously we'll be respectful of one another's times and such, but to create more of a this back and forth round table approach of like, how do we fix this? Cuz we know it's a problem. We can't just throw money at it if we don't have all the partners at the table.
▶ 1:42:11So, we've we've picked on you, Mr. Darby. You've had to lead off every time. So, why don't we go this at this end of the table, we'll go that direction. Uh, so, Mr. Jane. Sure. So, I mean, I think this is where constructs like the ISACs are really important in terms of being more of a hub and spoke kind of a model, because you're right that you need the information sharing really flowing in both direction in three directions from states, you have states, private sector, and you have the federal government, and you need information flowing bidirectionally from both.
▶ 1:42:40In other words, when one state suffers an attack, communicating that to the hub so that other states become aware of it and can become alert to the possibility that they're going to suffer the same kind of attack. So, that kind of bidirectional information sharing, obviously the private sector has insights and information that the governments are not. They're going to see things um that the government's not. And the federal government has unique visibility into things like nation-state campaigns. What are their objectives? What are What are What are they trying to accomplish?
▶ 1:43:07So, I think you're certainly right that you need the private sector at the table as well. In that, um but I do think then you need a hub or a place or a mechanism for that information both to get ingested and then um propagated back out. Thank you, Mr. Chair. Um I think I mean, I know we have the technology today, so we have great tools and solutions to be able to do rapid intelligence sharing.
▶ 1:43:32Um I believe it's a matter of priority to some degree to be able to focus in on that mission and do it and do it well. Um mission before about our communities of practice uh such as the ones that exist in the National Association of uh state CIOs to be able to generate support for that kind of information sharing. I think it uh would be a a great path to be able to uh get a coalition of states uh across the nation to to participate in information sharing.
▶ 1:43:58And I just believe that information sharing um is one of the most critical things we can do to to stay ahead of uh some of the threats we face today. Uh and I'll just just close um with this as far as some sort of federal guidance around working with our commercial partners to figure out what's the solution to some of these pending um AI AI threats that are that are around the corner for us is critically important and I don't know who else is doing that if it's not going to be the federal government.
▶ 1:44:28So, it's important that they stay in that fight. Thank you. Yeah, I think just a couple of other thoughts I think from the fine you know from the great panelists here. Number one, I think you know, authorities, appropriations, and capabilities. Authorities, we have the CISA 2015 Information Sharing Act uh which is really you know, bipartisan support uh is also expiring uh relatively soon and should be reauthorized. That's one of the fundamental mechanisms that enables information sharing from the private sector to the federal government.
▶ 1:44:57Uh appropriations uh sir, as you mentioned, uh appropriations are a part of this, but the capabilities that we have at the state level, at the federal government level, and within the private sector, uh I think we want to be uh even more pointed about using the state fusion centers, which are already situated at the intersection between the private sector, the federal agencies, and the state and local governments.
▶ 1:45:22Uh and those capabilities moving beyond just throwing emails over the wall, but into operational collaboration that I think unfortunately we tend only to see, uh, you know, when there are gray skies or black skies, uh, but we want to extend that operational coordination, that capability development in across the operational spectrum, uh, and that will only happen with, um, you know, with all of these elements in place.
▶ 1:45:49Uh, but sir, I think that as we've seen in New York, it is possible to do that, uh, and we are eager to partner with the federal government and the private sector in that effort. Mr. Arbuthnot. So, Tennessee, I think has remarkable, um, cybersecurity maturity and has done well in this particular positioning, but I do think the, uh, environment that we are in right now has created new dynamics that are significant and And would challenge that, um,
▶ 1:46:20you know, when we think of kinetic situations, the, the federal government has, um, large tentacles and intelligence that start to lead and allow reactions. In the cybersecurity area, it feels like often times we're getting intelligence after things have occurred versus proactively.
▶ 1:46:37And so, maybe it's a, um, what comes to mind is just a, um, a think tank of national experts that are positioning the states to be able to leapfrog their level of expertise around this changing dynamic. States often struggle with, um, attracting the best talent. I'm sure the federal government has a common issue.
▶ 1:47:01Part of this grant program redesign perhaps is a way to create an opportunity for an innovations, uh, group that attracts the nation's best leaders that will allow us to understand how do we start to understand that these models are going to be democratized with access, that it is no longer just nation-state leaders we have to be concerned about.
▶ 1:47:23It is local, very intelligent, maybe um individuals that are focused on doing harm that now have access to these tools and they can scale in ways and speed that were not present in the past. if I may if a ransomware attack were to shut down a major healthcare system in Tennessee tomorrow disabling electronic health record systems, medical devices, communication systems, etc.
▶ 1:47:53billing, and respectively teach your states whether it's healthcare or water infrastructure, etc. You know, walk us through and I think it's important the reason why I pose this question is for those watching the community at large to understand on the record that what's at stake. So, when you when you talk about the Salt Typhoon Typhoon and Volt Typhoon attacks, the pre-positioning of software and critical infrastructure that essentially with the flip of a switch that could be turned on or off.
▶ 1:48:21Um what happens in that moment and then what are the repercussions especially with you know, Tennessee's Music City USA, but it's also considered by many as Healthcare USA because of Nashville. Mr. So, in that particular situation we would certainly work with the um appropriate individuals at the hospital to be able to understand the situation, offer resources immediately, which um would certainly include the state cybersecurity resources, but also the connection with our
▶ 1:48:51law enforcement agencies um TBI being one of our most prominent uh partners that is uh very responsive to ensure that we are doing everything we can to make sure the threat is isolated and then mitigating any further damage. Um with that we would then um focus on investigation and recovery with them.
▶ 1:49:14Uh the hospitals also are well prepared for those types of scenarios to be able to ensure patient safety and mitigation and we would support those efforts from a state perspective in any way that is necessary. And and to the rest of the panelists, you know, do you have whether it's a hypothetical hypothetical situation, but moreover, do you have a real world example of what happened in say New York where you had some sort of critical infrastructure situation, there was a response, but what what what did that mean for the community at large?
▶ 1:49:42Yeah, I think it's a great question, sir, and I think, you know, we had one Brooklyn Health which is a a hospital system in Brooklyn which serves primarily underserved communities in that, you know, in in that area. And it means going on diversion as you prob- as everyone is aware, you know, telehealth, you know, radiology delivered over the internet, stroke, emergency rooms, you know, those are all things that run on computers.
▶ 1:50:08I would note that New York is to our knowledge the only state that has enforceable minimum standards for hospitals, what we call Article 28 In November of 2023, the governor directed the Department of Health to not only enforce minimum standards which, you know, we think are important like multi-factor authentication, like hardening, but also having paper plans for going on diversion so that we can minimize the impact to our communities when these unfortunate incidents do
▶ 1:50:39And so we have a reporting regime through the Department of Health through New York State local health administrators association and with, you know, our federal partners to ensure that we understand the ramifications especially for our rural hospitals who might be one of the only emergency rooms within a 30-mile radius.
▶ 1:51:02So we have developed plans with our office of fire prevention services and others to make sure that we can uh, allocate the appropriate emergency resources when these incidents do occur because as you said, sir, these incidents are unfortunately uh, picking up in pace. Thank you, Mr. Chairman.
▶ 1:51:23So, continuing with the um, hospital scenario, so uh, we did have a fairly recent uh, incident with a hospital and uh, we work closely with the Agency for Health Care Administration, which is a Florida agency that um, helps administer and oversees hospital operations throughout the state and care centers throughout the state. Uh, they have a good handle on the uh, communication channels uh, that exist between state, other hospitals.
▶ 1:51:49So, we work closely with them to ensure um, Chief Darby said isolation happens so that things don't continue to spread across the health care system, uh, which is very important. And uh, Mr. Chair, you mentioned about the impacts to uh, the communities and the people who use these services. So, um, when a a ransomware attack happens, you're also breached at the same time, you can count on that.
▶ 1:52:12Um, and the the the terrible thing about that is that information is not just used um, as as leverage for for some sort of payout, uh, but it's also used in subsequent attacks. So, they use that information to be able to do uh, fraud against people and affecting their lives. Uh, they use that to try to break into other people's accounts and they use that uh, just to to to formulate enough information to build uh, future attacks.
▶ 1:52:38So, not only does it have the immediate effect of breaking operations, it has the longer effect of impact impacting people's lives and the further impact of setting up tomorrow's attack. So, uh, something that um, is just another uh, example and reason why uh, the investment and the attention to cyber security protections uh, so Mr. Jane. Fortunately, I'm not in a position of having to respond to those kinds of attacks, but you know, I think picking up on the point that uh Ms.
▶ 1:53:08Darby made earlier about innovation, I think um you know, we've talked a little bit about the use of AI in defense in terms of preventing attacks, but I think AI also has the potential for helping with incident response itself and um being able to process data, being able to um figure out how to respond more quickly. And you know, we have the AI labs who have a lot of expertise in terms of how to use their systems.
▶ 1:53:32And I think, you know, we're talking about you know, glass swing in these collaborations that the AI labs are doing in terms of um cybersecurity, I think turning a little bit of that to incident response would be useful as well. So, as we start to close out the hearing, what I would love to get uh one from you in writing so you can have time to think about it would be just sort of a best practices uh that you might recommend.
▶ 1:53:58As we've said, we've passed um the Pillar Act here in the House, which authorizes it uh the the grant program through uh fiscal year '33. We're waiting on action in the Senate. So, as we go forward, there may be the opportunity to make some revisions. And if no, we can have another piece of legislation that really perhaps, as Mr. Darby Darby, I do believe you said, gives that flexibility as you're trying to help St. Mary County with the grant program sort of thing.
▶ 1:54:23So, I would love to get those uh so we can compile kind of what are the next steps because I I I I I fear this will be an ongoing uh conversation where every every so often we're having to revisit this type of how do we respond to that next level attack? Because when you look at like Chad or Brock year and a half ago, that was a that was a a a search engine on steroids, right? Now you have the these agents that are almost thinking, if you will, at least in from a computer uh standpoint, but they're very dynamic.
▶ 1:54:52And so, what does 18 months look from now or 6 months from now? So, we'll start with you, Mr. Jane. Mr. Darby, I'll give you the final word. Uh but what are your closing thoughts? Anything that you want to reiterate, understand that we we need to address CISA, make some revisions there, but I like the idea of scarcity because we're trying to get the private and the and the non-profit sector involved in this conversation because the government is not the the the 100% solution. It's got to be this coordinated effort, Mr.
▶ 1:55:22Yeah, I mean, I certainly agree that it needs to be a coordinated effort among all stakeholders. And, you know, part of the private sector now that needs to be more involved, I think, is not just the cybersecurity companies, but the AI companies themselves because they're bringing to the table these new capabilities, um, both offensive, but defensive as well I think potentially defensive as well. So, I agree with that.
▶ 1:55:44You know, beyond that, I think, you know, resources aren't going to be enough, but you do I mean, the the resources are sort of a base level that you need, um, in order to, um, be able to deal with cybersecurity cuz without those resources, particularly when we're talking about the smaller jurisdictions or those without the staffing or the if they don't have that minimally, it really doesn't matter what you have in the way of capabilities cuz they're not going to be able to utilize them.
▶ 1:56:10Well, I to that point, you know, I I I won't say his last name, but Bill who was was my IT director, you know, he was also the guy that was plugging in your keyboard and changing out the monitors and resetting passwords and, you know, building the network for the county and helping the hospital, uh, but he was also the guy that would had to have to defend the the county and the hospital and the school system in coordination with the schools' resources from a cyber attack, right?
▶ 1:56:35And so, like, you had one and a half individuals uh, having to defend a county and a community from perhaps a nation-state actor or today from an agent, you know, AI agent. So, uh, do know we have another member coming, but we'll go ahead and up to you, Mr. Spoonholtz. Thank you, Mr. Chairman. So, I'd say a couple things.
▶ 1:56:52One is to, um, continue on with leadership around um, exploring solutions to the the coming threats around AI and vulnerability development with with AI companies as mentioned as well as with the federal government just taking the lead there.
▶ 1:57:13Secondly, I'd say in respect to the federal grant, as much flexibility as would be well used just because every state's So different needs, different ways that that state's going to be able to execute with that money and those kind of things are really hard to dictate or to specify at a federal level, but if states are given the freedom and flexibility to be able to tailor how that money is used within the respective states to as much as possible, I think
▶ 1:57:43you'll get a more efficient use of those funds and more protection for for every dollar with that flexibility. When you look at the grant program in the deployment of AI agents, is there enough flexibility in there for the training for your staff or future staff? But because, you know, I've had the the the privilege or misfortune of being able to use jailbroken AI.
▶ 1:58:11And the [snorts] prompts that I was able to put in and get a very detailed answer on are horrifying to include how to construct a weapon of mass destruction, a bomb, from hardware How to what was the ideal vehicle to put it in. What would be the blast radius? So as to not be injured myself, how to build a remote detonator from off-the-shelf items.
▶ 1:58:41And so people need to understand that this is coming down the pipe. And when you have countries like China, whereas we try to have guardrails here in the US, You have a threat actor, a nation-state that isn't as concerned with safety. So, when you go back to the Cold War, we had this arms race with Russia. It was about who had the most nuclear weapons.
▶ 1:59:05It came to a point of mutual destruction where we could all blow up the uh world many times over. So, then it became about delivery systems and who could do it the fastest. But, whether is it 8 minutes, 10 minutes, or 12 minutes, it's still just minutes. With AI, this horizon doesn't exist. And the speed at which the capabilities are accelerating is almost unfathomable or unfollowable.
▶ 1:59:30Even then, though, it was between two Now, you can have some knucklehead in a basement somewhere, if they get the right technology, can do this. And so, I want to make sure as you move forward in any that next piece of legislation as we're looking to defend states and communities from this type of threat, that we're actually equipping you with the tools that are going to be So, as we go forward, I I would love I'll give each of you my number to stay in touch to make sure
▶ 2:00:00that as we apply some sort of grants or pool or resource available to the states, that it's actually in real time, like in the in the labs of deployment, which would be the states, that it's effective. So, I will pause there and recognize the gentleman. You ready? Or do you need a moment? Thank you, Mr. Chairman. Mr. Fong from California, 5 minutes.
▶ 2:00:28without objection, I'm entering into the record a letter from the Operational Technology Cybersecurity Coalition, the Alliance for Digital Innovation, the Cybersecurity Coalition, and the Information Technology Industry Council dated uh May 20th, 2026. Uh this letter urges continued support for the state and local cybersecurity grant program and highlights the the for continued cooperation by federal entities with state and local governments. Um Apologize for being a little late.
▶ 2:00:51Uh transportation markup is still going, but um Uh earlier this year I hosted a round table along with along with Chairman Carbino in my district where we discussed the importance of current and future cyber security challenges facing the Central Valley and across California.
▶ 2:01:06I have a lot of rural communities, military installations, um and so um the soft targets around those installations such as water, power, um health care infrastructure remains a top Within your state's critical infrastructure sectors, how have you all worked uh to update uh the cyber security capabilities, especially with what's going on with Methos and everything else? And I apologize if it's repeating, but I I I'd like to get your Yes, sir. I'll start.
▶ 2:01:31I think number one, uh in 2022 Governor Hochul signed first-in-the-nation legislation giving our Public Service Commission the authority to regulate cyber hazards on par with other hazards. That resulted in rule making, uh which we believe has materially advanced the cyber security posture of electrical distribution Uh number two, uh in 2023, as I mentioned previously, uh our Department of Health enacted first-in-the-nation cyber security standards along with a significant grant program to update
▶ 2:02:02uh the technology posture of hospitals in the state, in particular rural hospitals, uh which has I think we all understand are particularly important targets for our communities. Uh and number three, uh actually just last month our Department of Environmental Conservation, our Department of Health, and uh our Public Service Commission are moving forward with water and waste water cyber security minimum standards, as well as a grant program and technical assistance program, uh which is built upon the cyber security
▶ 2:02:32performance goals shared by the Environmental Protection Agency and the Cybersecurity Information uh Security Agency. Um and so we think that our approach by, you know, risk-centric, and cost-conscious minimum standards paired with technical assistance and grant programs, the likes of which are are deeply and importantly integrated with the state and local cybersecurity grant program, uh, are important for especially rural communities in in those those areas.
▶ 2:03:04If I can follow up and and any of you guys can jump in, uh, the rural community part you mentioned, how do you How should rural communities, um, it with build out their their their capacity, uh, especially? I I I I would like you to kind of dive into that a little bit. Yeah, and I think, um, as my co-panelists have all said, we need to make our shared services easy to consume for a person who, uh, has a lot of other jobs.
▶ 2:03:30We also have, uh, Ed, uh, who is the deputy county executive of a real county. He's also a full-time exterminator, father of three, and the IT guy. So, this has to work for Ed. Ed is a Ed is a smart guy. It's not that Ed is not a smart guy and Ed doesn't care, that's not true. It's that he is very busy. So, sending Ed a PDF isn't going to help Ed.
▶ 2:03:52Sending Ed something he can double-click, that's, you know, more like a sandwich than a puppy, uh, I think is has been our approach and has been one that has led to 55 counties, 34 cities, villages, and towns, dozens of sheriff's offices across the state participating in our shared services Anyone else want to jump in to to this conversation?
▶ 2:04:12Yeah, I would just reiterate that, um, uh, low-touch, high-impact solutions of what we have seen be successful across Uh, the rural communities, um, uh, are have a strong commitment to increasing their cyber protection, but they don't have the manpower. And so, managed solutions and different types of automated solutions are going to be critical for those areas.
▶ 2:04:41And just to triple stomp it, um we include uh managed services along with all the shared services that we provide. So, um they'll have assistance from the uh from either our third-party uh managed service provider or from the solution provider itself to help install and configure and get these solutions set up right um because um just as stated by Mr. Ahern um Ahern, sorry. Um these people have lots of different roles, very very busy. Um they really need help to be able to get this stuff going or it'll just sit on the shelf.
▶ 2:05:11My time is running out, but I I do want to highlight the fact that we have we're we're also focused on workforce, and I think that's an area that we need to create pathways into uh the cybersecurity space uh as to build out capacity uh not only in the urban centers, but in the rural community as well. I'd love to to to follow up with you and partner with you on that. Thank you, Mr. Chairman, for the the time. Gentleman yields back. I'll recognize the ranking member uh member, Mrs. Ramirez for 5 minutes. Thank you, Chairman. Well, this is certainly a really critical conversation.
▶ 2:05:39I just want to thank our witnesses for being here and the work that you're doing. The cost of keeping up with the growing cyber attacks and the threats that we see every single day, while as Mr. Jain was sharing um these technologies continue to advance at rates that we didn't even imagine a year ago, mean that you're going to need more resources to do so. And as you've heard from both sides here as we've had this discussion today, the reality is that um we don't want to talk about funding, but we need funding in order to be able to do this work.
▶ 2:06:09And so, I do think it's really important for us to uh make the connections between what level funding we need and what it's actually going to do. Uh because I think that for our colleagues as we leave this committee and talk to our colleagues um within our within Congress, it's important for them to understand clearly what this additional funding would do and how it would actually expand your structures in order to provide the protections necessary.
▶ 2:06:40So, I want to in some ways follow up to what Congressman Lieu Trau and I think others have have brought back here. Mr. Arby, Mr. Ahern and Mr. Spanholtz, what would your state's priorities be if provided additional, not cuts because we just talked about the reductions that you weren't aware of, but if you were able to receive additional state and local cybersecurity grants, what level of funding would you be able to make in meaningful improvement improvements
▶ 2:07:10to your cybersecurity? And I'll start with you cuz ladies Thank you. So, I would say um it's hard to put an exact number on it because I think the what I would say is in our previous grant process, which was 21 million of federal funds and the state matched 6.8, bringing us roughly to 28 billion for that grant. My CISO would say we could have spent four times I do think
▶ 2:07:39meaningful improvements and maybe specifics. So so specifically in the future, the the approaches that we took, while are still grounded and effective today, I think have to pivot to an AI enabled world. And so part of that may be workforce expansion, part of it may be digital agent expansion because that is what our adversaries will be leveraging.
▶ 2:08:03And so the ability to have the flexibility to understand what is needed this year may be different than next year based on the exponential rate of change. So that flexibility is going to be important, but also the capability to be able to attract the appropriate level of talent and expertise to be able to identify those scalable solutions. The pace of change, uh it is here and things um are rapid.
▶ 2:08:31We need um agent-enabled solutions that are scalable. And so, um anomalies, both for internal threats and external threats, need to be able to be detected and we need to be able to rapidly respond 24/7. Um so, those are the areas of focus that we would look for uh related to the emerging risks that we are facing currently. Thank you.
▶ 2:09:00Thank you, Ms. Ms. Darby. Mr. Ahearn. I think three things, ma'am. Number one is defensibility, number two is resilience, and number three is legacy technology. With regards to defensibility, shared services that are easy to consume, that are delivered by top-tier uh enterprise technology partners, things like multi-factor authentication, like network defenses, like we've heard. Number two, resilience. We know bad things are going to happen, so having backups, cloud-based backups, business continuity planning, and other things are very, very important.
▶ 2:09:29And with regards to legacy technology, these are systems that have been built over multiple decades by multiple vendors, uh and if something is old, it is harder to secure, it is harder to maintain, uh and if something's not reliable, it doesn't matter if it's secure. And obviously, if something isn't secure, you know, it doesn't matter if it's reliable.
▶ 2:09:48Uh and so, when the technology debt that we have, I think we're going to be under a margin call, uh if you'll excuse a finance metaphor, because this technology debt is going to come due with these AI threats and the you know, ever-increasing um you know, scope of our adversaries. Uh so, you know, I believe that these three things are the things that we all need to do, and obviously, underpinning all of this is falling in love with the basics every single day.
▶ 2:10:13That's This is a services business, and these services are delivered by, with, and through Thank you, Mr. Ahearn. Anything else that you want to add, Mr. Sponholtz?
▶ 2:10:24I'll just say super briefly that um whenever we get an incident in the state, it's usually because we left a door or window open. We've got some sort of vulnerability that should have been taken care of. So, using some of these technologies to better identify the critical vulnerabilities that can really cause a big problem is imperative and then providing the support to the locals to be able to remediate those quickly uh so we won't have another incident uh as a pathway to just better um continuity of services. I really appreciate that.
▶ 2:10:50I think as we are looking to reauthorize the state and local cyber cyber security grant program, hearing these specifics from all of you are really critical uh in order to ensure that we do so and we do so providing you the resources necessary to do your work. So, thank you and with that I yield back. The gentlewoman yields back. I go to the gentleman from California, Mr. Khanna. Uh thank you for the second round. Um as I wanted to follow up on on on the workforce uh issue that I I just mentioned earlier.
▶ 2:11:17Um I'm working with my community college to set up um a a certificate program uh to um allow uh our students to to go into the cybersecurity um uh industry and and world. Um we've had hearings in the past about how there's this a challenge and and as we mentioned before uh the rural communities uh definitely uh have have a a a more uh challenging uh need when it comes to workforce.
▶ 2:11:43I'm curious uh if you could share uh maybe your your work in Tennessee or New York or in Florida about how you're how you're addressing the workforce challenge of of those in the cybersecurity space. A quick story for Florida.
▶ 2:12:00So, uh we spend about $35 million a year on a education workforce development program to be able to provide uh certifications, uh training, um lots of different uh education opportunities for all public uh, employees, whether it's education, state, local, across the Uh, seeing had a lot of great participation with that. Uh, and that's been effective to be able to upskill um, the workforce around the state um, have us better prepared.
▶ 2:12:31Uh, I think a couple of things. Number one is we have a deep and long-standing relationship with our community Uh, we have numerous cyber clinics across the state, including several that are part of the National Security Agency Cyber Clinics program, which is fantastic.
▶ 2:12:46I was fortunate enough actually 2 months ago to be at Utica University uh, outside of Rome, New York, uh, where they inaugurated a cyber range, which is an avenue in which both at the associates and the bachelors and the graduate level, students and community members can participate in real-life cyber exercises, but in a safe and controlled environment. Uh, and third thing I'd mention, sir, is curriculum.
▶ 2:13:09In New York State, through our partners in the legislature and our state education department, we have a K-12 computer science for all curriculum, which includes cyber bullying, social media awareness, uh, banking online, and cybersecurity best practices. I have two kids in public school and to hear my daughter ask me if my Gmail had multi-factor warmed my heart, sir. Yes, in uh, Tennessee, we've taken a multi-pronged approach.
▶ 2:13:37Um, so I will start with uh, the AI council that the state has. We have this year set up a um, two different subcommittees. One focused specifically on uh, education, which is both K-12 and higher ed. And part of that focus is not only um, cybersecurity, but also AI education and the convergence of both.
▶ 2:14:01Um, so focusing on bringing practical applied learning solutions to individuals and leveraging vocational uh, schools that exist across the state. We are also um, focusing on workforce development. So, how do we start to proactively develop programs around particular job areas that we expect may have disruption?
▶ 2:14:26How do we upskill and employees and workforces to be ready for the future and the expectations of those roles? So, there's work groups focusing on that. We have also through grants supported innovation schools.
▶ 2:14:43And so, we have a high school in Williamson County that's actually opening in August that is a I I think will is well positioned to be a national landmark of vocational schools, but one of the areas of focus is AI and cybersecurity. So, through dual enrollments with Tennessee universities, they will graduate from high school with certifications where they are employable at the day of graduation.
▶ 2:15:11And then at the state we have a cybersecurity internship program. And so, we are on our third year with that program, but have seen great success where the graduates of our program after they have completed their college education have 100% been employable in the cybersecurity field with employers in Tennessee or And then the last I would just say there was a question earlier is are any of the states working with the Department of Energy?
▶ 2:15:41So, we are blessed to have Oak Ridge National Lab as a asset within the state of Tennessee. We have a very strong partnership with them. They also serve on the AI Council and are active participants in many of the programs that I just mentioned. Thank you very much.
▶ 2:15:58I I I think there's a a lot of best practices I think I've maybe I know the chairman and I have talked about our community colleges and and and how we uh enhance those pathways and so maybe we can uh have a further a further discussion about how we uh address this and go, you know, learn for my state California how we can learn from you and vice versa. Thank you very much. Uh Mr. Chairman, I yield back. Gentlemen, he yields back and as we're closing out and I do I do we got the both you gentlemen had some closing remarks. We'll get to you.
▶ 2:16:26I I do want to just touch on the the recent NASCIO Deloitte survey talking about workforce uh in your margin call, sir, shows that only one in five state CISOs believes their cyber workforce has the skills to meet the threats that they're facing. And then that's which is just a that's a huge drop from just 2 years ago. And then additionally that NASCIO Deloitte survey found that state CISO confidence in protecting state information assets has dropped by more than half in 4 years.
▶ 2:16:56And that zero state CISOs are very confident in the cybersecurity practices of the local local governments which somewhat touches on Mr. Arby on this idea of digital agents uh in protecting one's infrastructure. And so part of my question as you as the two of each of you close out is when you think about that toolbox that uh you know, when essentially needs to be created in coordination with the federal government, with some of our state leaders and agencies and nonprofits etc.
▶ 2:17:28is do you see those agents being created by us? Are we partnering with, you know, Grock or whomever, but then again, we're housing it so we can share it cuz it's got to be easily consumable, right? Click it and deploy it because again, Bill, who's a fantastic guy, am- amazing American, great at his job, he's also one guy. Mr. Hearn.
▶ 2:17:51I think it's a great point, sir, and I think we need to think laterally with regards to how we're approaching these problems because one of the other things that we're seeing is in addition to this continued uptick, you know, the water continue to boil ever faster, uh we're seeing the um you know, the collapse of deterrence, as you mentioned, sir. When you want with an individual on a laptop can have the same capability as the MSS.
▶ 2:18:19Uh you know, that fundamentally changes how we as a government, as a people, as a civil society need to think about these risks. Uh so, things like infrastructure as code, using vendor best practices, obviously we talked about some of the enhancements to the operationalization of the grant program. These I think, sir, are all part of a story where how we deliver these services is not going to look, like you said, 5 years from now like it looked 5 years before.
▶ 2:18:47And that's both because the expectations of our citizens are changing, but also because the risk that these systems are facing are changing so fundamentally and changing so quickly. Yes. Um so, in closing, I would say preventive, not reactive, is really the theme that Tennessee has adopted.
▶ 2:19:06And we've discussed here that the the pace of change has exponentially um shifted, and we're seeing increasingly sophisticated adversaries leveraging automation and artificial intelligence to accelerate attacks and reduce time available for defenders to respond.
▶ 2:19:25So, Tennessee plans to continue to build on the whole-of-state approach and the improvements that we have made, which were 19.2% maturity over the last 3 years that we have reported. With that, we also need um to continue to partner with private sector. We also uh meet regularly with our model uh around how do we get AI agents um created in ways that will help us accelerate.
▶ 2:19:54So, from Tennessee's approach, we think it's a mix of partnering with the private sector to ensure that they have solutions within the tools that we use that can be rapidly deployed to continue to keep state assets and our communities and our private entities protected.
▶ 2:20:12The other element is we recognize within the state, but also many of our private organizations that operate within the state of Tennessee also have their own proprietary solutions and architectures and will be building their own agents. We need access from a model perspective to be able to also respond, not just rely on vendor tools.
▶ 2:20:35Um for those organizations that have that sophistication and it also better positions Tennessee to be able to help the local communities, municipalities, law enforcement, etc. if they have proprietary solutions that are not dependent on private sector uh tools that might be available. So, with that, um the last thing I would mention is we talked about um AR AI governance and and bad actors.
▶ 2:21:03Do they follow the same rules that we do? And we have positioned ourselves through the AI Council as being very focused on AI governance, transparency, and safety, but we recognize that our adversaries don't respect the same rules and do not possess the same values.
▶ 2:21:21We must be positioned in Tennessee and across the nation to respond at the speed of this technology and that requires that we have frameworks that are nimble, adaptable, and rules within programs that allow us to adapt based on the threat landscape to protect our states, but also the nation. I want to say thank you to all the witnesses for their testimony and and the members for their questions.
▶ 2:21:51Members of the subcommittee may have some additional questions for the witnesses and we would ask the witnesses to respond to these in writing pursuant to committee rule 7e. The hearing record will be open for 10 days. Without objection, I'm entering into the record a letter from the Consortium for School Networking dated May 18th, 2026 and a letter from the Software Information Industry Association dated May 19th, 2026. And as they are about to call votes, without objection, this committee and the subcommittee stands adjourned.