▶ 0:17:03Chair Blackburn: Good morning. At the hearing will come to order. I want to thank our witnesses for being here with us today. Today's hearing comes at an important moment. Our nation's communication networks are facing rapidly evolving threats ranging from fraud and espionage to sabotage. In a few minutes we will examine and consider how government and industry can work together to strengthen network security.
▶ 0:17:34Chair Blackburn: The united states intelligence community assesses that the people's republic of china is the most active and persistent cyber threat to the united states institutions. Last year the hacking group soft italian food backed up -- soft typhoon infiltrated providers. We need a unified strategy now more than ever.
▶ 0:18:00Chair Blackburn: Threat actors are deploying technology and scale to undermine our networks at every juncture. These attacks are increasingly supercharged by an artificial intelligence as well. Our help -- while private industry innovates, collaborates and defends against these threats. The risk environment is growing more complex. Congress must coordinate with industry and ensure robust federal response. Supply chain security remains a critical part of the conversation.
▶ 0:18:32Chair Blackburn: The prc linked companies such as huawei continue to pose significant risk to allied communication infrastructure. Congress created the riff and replace program to remove those vulnerable equipment from portions of american networks, and the fcc continues to identify high-risk vendors. This committee has also advanced my bill to increase transparency around foreign owned communication licenses.
▶ 0:19:03Chair Blackburn: Earlier this congress I introduced the fact act which requires the federal communications commission to publicly identify companies that hold fcc license is that are owned by adversarial governments. I am proud that it passed the senate in october, and I look forward to it coming law. As we grow more connected, we feel the impacts of network and security globally, nationally and locally.
▶ 0:19:32Chair Blackburn: Just last month, carney public schools in kearny, nebraska experienced a major cyberattack that disrupted phone and computer systems. We also witnessed a series of 911 system outages across nebraska with multiple failures caused by a lack of network diversity and redundancy.
▶ 0:19:56Chair Blackburn: That -- as global conflict increases, networks that span international borders are prime geopolitical targets for bad actors. Seeking to create economic and political instability. Undersea cables carrying more than 95% of international internet traffic including sensitive financial and governmental data.
▶ 0:20:21Chair Blackburn: Recent physical cuts to those cables both accidental, and intentional, have caused disruptions worldwide, knocking millions in pieces -- people and businesses off-line including major cloud services. As we look to space, satellite constellations are rapidly expanding. With 10,000 active satellites in orbit.
▶ 0:20:48Chair Blackburn: Most operated by united states companies, these systems support on -- at home connectivity, national security functions and critical infrastructure. We must ensure that foreign adversaries do not infiltrate these systems for espionage or other nefarious purposes. Across all of these domains, threat actors are growing more aggressive and persistent.
▶ 0:21:13Chair Blackburn: Today's hearing allows us to deepen our understanding of these threats and ensure that our networks remain secure. There is no single solution to the network security challenges ahead. However, I hope today that we will shed light on different approaches that this committee can champion. I look forward to the discussion. Senator lujan, you are recognized.
▶ 0:21:39Sen. Ray Lujan: And I want to recognize chair fischer in her leadership for calling this hearing on a critical issue. We have seen this all across america. I want to thank our witnesses for being here. I think every member of this committee can agree that there is nothing more important than keeping our communities and country safe, which is why the security of our communication networks are vital.
▶ 0:22:04Sen. Ray Lujan: They are the foundation of our daily lives, carry our phone calls, internet tap -- traffic, emergency services and so much more. It is also a responsibility to ensure that foreign actors cannot infiltrate our infrastructure or steal data. There is clear evidence that nation state actors are escalating efforts to infiltrate and compromise our networks.
▶ 0:22:28Sen. Ray Lujan: The salt typhoon hacks exposed weaknesses. That reached major carriers such as verizon, at&t and t-mobile and compromised millions of individuals' information. This also likely represents the largest telecommunications hack in our nation's history. A year ago we examined this topic in this very committee room.
▶ 0:22:56Sen. Ray Lujan: And yet a year later our communication networks are no more secure. We can see that it is not just the major carriers. I am also concerned that schools, hospitals, libraries, police departments, and emergency responders are exposed and do not have the resources to defend themselves against foreign adversaries.
▶ 0:23:20Sen. Ray Lujan: I am concerned that the federal communications commission rushed to dismantle efforts taken under the last administration to verify the security of america's networks. The fcc stripped these protections away and replace them with voluntary pledges and companies whose networks have proven themselves to be vulnerable.
▶ 0:23:39Sen. Ray Lujan: To put it plainly, these companies are leaving their front doors unlocked after a data break in and the fcc decided to take their world -- word when they promised deadbolts and security cameras. By removing enforceable standards the fcc is weakening our national security at a time when the digital landscape is growing like never before. There is still a lot we do not know about the damage done.
▶ 0:24:06Sen. Ray Lujan: In fact, president trump fired the board investigating the attack. What we do know is that rolling back protections and requirements is putting us on a dangerous path and will not prevent and mitigate attacks like this in the future. There will be more attacks. That is certain. There should not be a partisan issue, but a matter of national security.
▶ 0:24:28Sen. Ray Lujan: We are fortunate to have an expert panel that will speak to the vulnerabilities in our communication system, and how we can address them to protect our constituents. I look forward to a productive conversation and thank you for being here.
▶ 0:24:41Chair Fischer: Thank you. I am very fortunate to have my friend as the ranking member on this committee, and I thank you for your comments and I look forward to the important work that we can do together. I would like to introduce our witnesses today. Our first witness is robert mayer, senior vice president of cybersecurity and innovation at ustelecom.
▶ 0:25:07Chair Fischer: He leads the association's efforts on cyber and national security. Our second witness is jan -- daniel gizinski, president of comtex satellite and space communication segment. He advances the strategy and growth as the company focuses on next-generation satellite solutions.
▶ 0:25:32Chair Fischer: The third witness is jamil jaffer, founder and executive director of the national security and to, and serves as assistant professor of law and the director of the national security law and policy program at the antonin scalia law school at george mason university. Our final witness is deborah jordan, the former chief of public safety and homeland security bureau at the federal communications commission.
▶ 0:26:02Chair Fischer: You are recognized to give your opening statement.
▶ 0:26:05Mr. Mayer: Chair, ranking member and members of the club -- of the subcommittee, thank you for the opportunity to appear before you today. I am the vice president of cybersecurity and innovation with ustelecom, and I serve as the chair of the communication sector with department of homeland security.
▶ 0:26:30Mr. Mayer: This subcommittee knows the economic, national sheet -- national security and social value of our nation's communication infrastructure and what we bring to communities. While we invest billions in protecting our networks and customers, nations including china, russia, and iran, leverage capabilities to infiltrate our infrastructure and the produce of -- pursuit of economical gains.
▶ 0:26:58Mr. Mayer: Defending against it requires a whole of government coordination and deep and enduring trust and government while sharing information. It also requires, when appropriate our government to push back on our adversaries by imposing costs through diplomatic cyber and military means that mirror the scale and sophistication of our adversaries.
▶ 0:27:24Mr. Mayer: Congress can help to advance this mission by pursuing several core principles and action steps. First, the public-part -- private partnership model should be strengthened. It is flexible, and supports actionable remediation and encourages early and candid reporting. Second, cybersecurity frameworks must be flexible and adaptable.
▶ 0:27:49Mr. Mayer: While there might be a natural impulse to mandate a detailed checklist, such requirements lagged behind adversaries who change their techniques faster than any rules can be written. Furthermore, they shift the attention away from managing real risk to managing paperwork while our adversaries have already moved on.
▶ 0:28:11Mr. Mayer: The goal is not less oversight, but oversight and measures whether our nation's defenses are managing risk, adapting to new intelligence and shoring up our collective defense. Those are the outcomes to strengthen national security.
▶ 0:28:30Mr. Mayer: Third, under national cyber director's leadership, the forthcoming nationals acute -- labor security strategy is expected to strengthen consequence-based responses and deepen public-private coordination, a sub -- an approach we support. We have reinforced that by ensuring durable authorities and passing a long-term reauthorization of the 2015 framework.
▶ 0:28:59Mr. Mayer: At the same time congress and federal agencies should prioritize maximizing the existing funding mechanisms, including non-deployment funds and federals stan state initiative should be strategically leveraged to strengthen the capabilities of local and regional providers including the retirement of vulnerable, end of life equipment and support for cyber workforce development, and ensuring that smaller providers have sustained access to trained personnel who can effectively
▶ 0:29:29Mr. Mayer: Manage the evolving threat environment. Congress and the administration must also accelerate efforts to speed up the deployment of more secure and resilient fiber broadband networks, and the much-needed permitting reform legislation as well as supporting efforts for entire network modernization rules.
▶ 0:29:51Mr. Mayer: Finally, cybersecurity requires a whole of society approach with shared responsibility and it must be born at all levels across the private and public sectors. The ustelecom and our members in the sector at large remain committed to working shoulder to shoulder with our government partners and congress. To outpace our adversaries and protect the infrastructure that americans rely upon every day. Thank you for the opportunity to testify and I look forward to your questions.
▶ 0:30:19Chair Fischer: Thank you. You are now recognized for your opening statement.
▶ 0:30:24Mr. Gizinski: Chair and ranking member, members of the subcommittee, I appreciate the opportunity to speak before you today. America's communications in the structure is under increasing pressure from horns adversaries who are using unique techniques to exploit our networks. Satellite communications are a critical part of that infrastructure.
▶ 0:30:46Mr. Gizinski: They have served a quiet but critical role in providing communications and we have seen a tremendous pace including the emergence and buildout of non-geostationary orbit constellations such as starlink, leo and many others. We have seen the emergence of the diff -- direct to device connecting smart phones and other small devices to satellites with apple and space mobile and link global.
▶ 0:31:13Mr. Gizinski: One of the unique benefits of satellites is the global reach which also increases the attack surface of the systems. Many of the satellites providing coverage expose network traffic far outside of our borders. We have seen that the cyber security practices in the sector have not kept pace. A recent study at the university of california, san diego and university of maryland showed the ability to attract sensitive traffic.
▶ 0:31:41Mr. Gizinski: Other studies notice the risks that satellites are exposed to, each with unique considerations and complexities. Components are typically not accessible following launch, which limits the ability to field updates. There are certain fixes available for certain use cases, things like enabling encryption on the satellite modem, they serve as a low-cost and simple step and something that we recommend.
▶ 0:32:10Mr. Gizinski: Many of the existing compliance frameworks today also recommend this. Despite this, we see many networks operating without this key protection. Strong cyber posture can be built effectively with a framework that brings together government and industry to share threat intelligence, align incentives and respond quickly to emerging risks. They should be aligned with risk, understanding that not all data requires the same treatment.
▶ 0:32:37Mr. Gizinski: Our adversaries are looking forward in the approach to attacks and defense posture should reflect that. First we must promote information sharing among government and industry. Establishing a broad form that allows for free and open information sharing including from the satellite industry association which represents a number of satellite industry members. Second, how to move beyond rigid compliance only frameworks to incentive-based models. Static checklists and controls are rearward facing.
▶ 0:33:11Mr. Gizinski: Offering incentive for those who invest in proactive security measures or contribute meaningfully through work -- towards threat modifications. They shift will be key to promoting innovation and security that keeps pace with the rate of commercial innovation.
▶ 0:33:27Mr. Gizinski: Third, it must be designed from the foundation, meaning to build subcomponents secure by design including supply chain, threat sharing and mitigation planning and ensuring that the security frameworks extend to hardware and software frameworks with close attention paid to the frameworks.
▶ 0:33:45Mr. Gizinski: Satellite connectivity supports a large range of services and plays an essential role in expanding connectivity access to underserved communities and is a key enabler of defense and emergency response operations and divide dust driving innovation. The cyber threats that this face are real and evolve quickly. If we want to ensure the longtime resilience we need to give it the attention it deserves.
▶ 0:34:08Chair Fischer: Thank you. You are recognized for your opening statement.
▶ 0:34:13Mr. Jaffer: Chairman, ranking member and members of the subcommittee, thank you for giving me the time to testify today. The unfortunate fact is that we are at war in the cyber domain. It is low-level and our adversaries are coming after us day in and out. The attacks on our system and communication structure are constant.
▶ 0:34:37Mr. Jaffer: China for one has engaged in a widescale effort to penetrate every aspect of america's telecommunication infrastructure and from wireline to wireless, to undersea's cables and satellite infrastructure. Russia is similar. Since 2019, russia had the capability to conduct disruptive attacks according to the director of national intelligence and china has that capability primarily overseas, but also in the united states.
▶ 0:35:07Mr. Jaffer: This is an important point because at this time in our nation's history we know that president xi has told his armed forces to be prepared to invade by 2027. If the united states decides to get josh to push back, we might be a shooting war with china in the near future. It will not only be in that domain but also in the cyber domain as well.
▶ 0:35:32Mr. Jaffer: China will engage in efforts as well -- to avail american systems and to go after them in -- aggressively. If we have seen these capabilities, they will use them to our detriment. It is not just china and russia. Iran and north korea have built up cyber capabilities and are becoming serious actors. Unlike china and russia, it is harder to deter nations like iran and north korea.
▶ 0:36:01Mr. Jaffer: There are a lot of people that believe that deterrence is not successful or possible. The reality is that we do not practice it to defend our communications infrastructure. Our adversaries do not know where our red lines are and do not know what to do if they would cross. And to the point that we do enforce them, we do not do it no way that other adversaries can see. As a result the effect is limited.
▶ 0:36:27Mr. Jaffer: If we are going to successfully prevent china and russia and iran from taking action against the telecommunication infrastructure, we must make it clear that we will view an attack on our communications at as a tack on the nation and respond accordingly. There are big debates on what we should do on attacks where the chinese government was able to deeply penetrate our tele-communications of the structure.
▶ 0:36:52Mr. Jaffer: On the ones in hand you have the prior action seeking an effective and -- an effective regulation and on the other side -- other hand you have a volunteer approach. In the middle you have a question about what the government should have done about it. We now learned that the government identified the salt attackers before they came after the telecommunications infrastructure and we knew that for years china had been targeting our telecommunications infrastructure and not had gotten as deep as they expected.
▶ 0:37:22Mr. Jaffer: In many ways this is what happened before 9/11. We knew the attack was coming and we did not know where, and we had even identified art -- operatives but we did not know they were coming to the united states. The same was true. They knew we were coming after the infrastructure and we had seen them and did not realize that they were going to the tele-communications industry and the question is why didn't the government take more than -- aggressive efforts to protect its own infrastructure and why today is the government's
▶ 0:37:53Mr. Jaffer: Position that we should regulate -- regulate rather than partnering? These are difficult questions. The truth is is that we don't -- we did not answer those questions today and the relative peace of the current moment, even in the low level war that we are in, will face significant and effective attacks on our infrastructure by our adversaries if and when that day comes to pass. We cannot allow that to come to pass, and that is why in this moment it makes sense to find a way going forward.
▶ 0:38:23Mr. Jaffer: The most effective thing that congress can do is authorize a cyber information sharing act that was passed in 2015 and reauthorized briefly as part of the opening effort. There are those in the senate who actually reduce the effectiveness of those laws and would limit their scope. The right thing to do is to expand the scope and provide more regulatory and provide incentives for the industry to do better.
▶ 0:38:48Mr. Jaffer: If we can partner more effectively and build truly a public-private partnership that is how we will be the most successful defending our communications and technology infrastructure. Thank you for your time and I appreciate the opportunity and I look forward to your questions.
▶ 0:39:03Chair Fischer: Thank you. You are now recognized for your opening statement.
▶ 0:39:10Ms. Jordan: Good morning. Thank you for the opportunity to appear before you today. I am grateful to observe nearly 10 years at the federal communications commission as a deputy and bureau chief for the public safety and homeland security bureau. My responsibilities include national security, cybersecurity and the resilience of the communication sector.
▶ 0:39:36Ms. Jordan: As a career civil servant I was honored to have served under four commission chairs from both parties. Before joining the fcc I spent three decades as a civilian with the U.S. navy. And there he implemented the first ever cyber security framework for critical systems such as electrical, water, and wastewater. A little over a year ago when I was at the fcc the U.S. uncovered salt typhoon is a sophisticated campaign.
▶ 0:40:02Ms. Jordan: We know that they infiltrated nine of the nation's largest communication providers and 200 other U.S. organizations including government agencies. They got millions of metadata of targeted individuals including then candidates president trump, vice president vance, then vice president hannah -- harris as well as members of congress. Additionally they compromised systems that you went -- that logged U.S.
▶ 0:40:30Ms. Jordan: Law enforcement request for criminal wiretaps, potentially tipping off the investigative targets. And if that does not make you shudder, let us go back to volt typhoon. Active since 2021 but not revealed until later, it was attributed to chinese hackers who gained widespread access to critical infrastructure like water and power systems.
▶ 0:40:57Ms. Jordan: They used the tactic known as living off the land where they stole credentials and quietly used administrative costs to collect data and maintain high-level access to networks. They remain in the networks in preparation for potential armed conflict between the U.S. and china over taiwan. These attacks highlight the vulnerabilities in our communications networks which provide the foundation of trillions of dollars of economic activity.
▶ 0:41:23Ms. Jordan: How do we secure our communications networks which serve as the underpinnings of our modern digital society? We can either lean forward, leveraging flexible cyber standards to support the economy and security or sit back and wait for the inevitable next attack to happen. After the revelation of salt typhoon, the fcc leaned forward.
▶ 0:41:48Ms. Jordan: They ruled that section 105 of the communications assistance for law enforcement act requires telecom providers to secure their networks against unlawful access. In the fcc proposed rules that would require communications providers to certify that they have created and implemented an up-to-date cyber risk management plan which would strengthen network defenses from future cyber attacks.
▶ 0:42:16Ms. Jordan: On november 20 of 20 25, the fcc reversed the ruling, withdrew the proposed rules, putting the nation at risk. The fcc cited engagement with providers and "their agreement to take extensive steps to protect national security interests." however, the ftc does not cite any process by which providers will be held accountable to meet specific commitments.
▶ 0:42:43Ms. Jordan: From my experience, I am not convinced that the providers will take sufficient and sustained actions in the wake of volt and salt-without a strong verification regime. As things stand we can hope that providers are taking appropriate steps long term and hope is not really a strategy to secure our networks. What can congress do? I have three recommendations.
▶ 0:43:07Ms. Jordan: We have tools such as cyber risk management framework, congress should encourage the fcc to require the cyber security framework or similar guidance for all telecom providers. The framework is flexible and developed in collaboration with industry around the public to manage and reduce cyber risks. Second, upgrade our communications infrastructure. Keeping communications infrastructure current is critical but costly.
▶ 0:43:35Ms. Jordan: I encourage congress to fund, fully fund communications infrastructure such as next-generation 911 and cyber funding for state, local, and territorial entities. We cannot enable modern digital act -- security wall running on old infrastructure and verification must be a part of trust. We must establish a verification regime -- regime to ensure that security of our communications infrastructure.
▶ 0:44:03Ms. Jordan: We have seen where providers have not implemented even some of the most basic cyber hygiene consistently across our networks, such as changing default passwords. The industry says they are committed to implementing extensive cyber protections, so let us establish a regime and secure setting to share their progress and further plans. Thank you and I look forward to your questions.
▶ 0:44:26Chair Fischer: Thank you. We have been joined by the chairman of the congress -- the commerce committee. Would you like to make any remarks?
▶ 0:44:35Sen. Cruz: I appreciate it and thank you for holding this hearing. We have a distinguished panel before us and I want to thank each of the witnesses for being here to share the expertise. In our digital age, communication networks form the cornerstone of our economy and national security. That makes him a top target not only for criminals, but also for adversaries.
▶ 0:45:00Sen. Cruz: America's enemies learned they do not need to launch missiles were deployed troops to harm the united states. Instead they can use teams of skilled and well resourced cyber hackers to steal our intellectual property, to gather intelligence and to hide within critical infrastructure to disrupt essential services. All while maintaining plausible deniability.
▶ 0:45:27Sen. Cruz: 2025 has been a pivotal year in network security, marked by the rise of a high powered attacks and defenses, alongside persistent risks ranging from infrastructure sabotage to increased supply chain vulnerability.
▶ 0:45:43Sen. Cruz: Incidents such as salt typhoon and the farms recently discovered near the united nations headquarters in new york have served as sobering reminders of how relentless and creative our adversaries continue to be. Unfortunately, there is no single silver bullet solution to address cybersecurity.
▶ 0:46:05Sen. Cruz: Protecting america's communication networks is a complex undertaking that demands continued diligence -- diligence and cannot be reduced to wrote box taking. The united states as a primary target for cyber threats precisely because we lead the world in technological innovation.
▶ 0:46:27Sen. Cruz: Our challenge, therefore, is to secure communications infrastructure effectively, without creating excessive and useless regulation that stifles the very innovation that gives our competitive edge. That is why I command the fcc chairman for moving last month to rescind the biden administration's misguided january 2025 declaratory ruling, which tried to shoehorn new mandates into a 1994 law about
▶ 0:46:58Sen. Cruz: Cooperating with law enforcement. The chairman's decision to shift away from ineffective and burdensome requirements is consistent with both the commission's legal authority and sound policy. Federal agencies cannot regulate their way into creating perfect network security, and attempts to do so will backfire.
▶ 0:47:21Sen. Cruz: Forcing telecom carriers to chase the false security of compliance checklists instead of engaging real-world threats, that diverts resources away from the necessary partnerships and response capabilities that actually stop intrusions.
▶ 0:47:38Sen. Cruz: Worse still, the legal risks that these impose have a chilling effect as armies of lawyers focus on avoiding lawsuits and regulatory penalties instead of information sharing and collaboration when every moment counts. To meet these evolving threats, the federal government must incentivize genuine cooperation so that the communication networks can focus on anticipating the next attack, not just responding to the last one.
▶ 0:48:07Sen. Cruz: This needs decent -- means foresight and agility and it does not come from imposing top-down regulations. It arises from a strong partnership between the private sector and the government. Working together to detect and deter attacks on the -- in real time. I am proud of this committee's progress toward strengthening network security but much work remains.
▶ 0:48:34Sen. Cruz: Effort shows that success is possible, with full funding now security, the rip and replace program is removing the remaining equipment from our networks. Gps offers another example. When threats to our positioning and timing capabilities were identified, we act of decisively bypassing the national timing resilience and security act to establish backup systems.
▶ 0:49:01Sen. Cruz: Now alternative and complementary positioning, navigation and timing systems are in development. With an tia, recently identifying 15 companies attempting to increase resilience and complements the critical system.
▶ 0:49:17Sen. Cruz: They -- this hearing is an opportunity to assess the landscape, identify where things fall short and explore how the federal government and private sector together can better protect america's communications infrastructure from both foreign and domestic threats. I look forward to a productive exchange.
▶ 0:49:35Chair Fischer: Thank you senator cruz. We will now begin our questions for the panel, and I will start and we will do a five-minute round, please. As you testified, the salt typhoon hacks proved that china obtained widescale access to our telecommunications network.
▶ 0:49:58Chair Fischer: And based on the publicly available information, what distinguishes salt typhoon from prior nationstate operations targeting telecom networks?
▶ 0:50:09Mr. Jaffer: The most distinctive thing is the breadth and the depth that was obtained to the american's telecommunication infrastructure. Only based on what we know publicly, it was clear that they were able to go after nine providers. It appears that they obtained access to either our law enforcement or foreign intelligence surveillance systems on some level, whether it was the collection or task targets, we do not know the details.
▶ 0:50:40Mr. Jaffer: That means that depth of access and sustained access to that sensitive information is massively damaging not just to our communications capabilities but national security. This is a real challenge, the depth and breadth of the access.
▶ 0:50:55Sen. Lujan: How to --
▶ 0:50:56Chair Fischer: How difficult is it to detect that and what does that tell us about the current existing capabilities that we have to monitor?
▶ 0:51:06Mr. Jaffer: Obviously, we found them. It took us too long. We assess that they were in order targeting the system since 2021 or going after them. We do not know when they got in. Once they got in, they burrowed so deep that we are not sure if we could have gotten them out completely. They might still very well be in the system. One provider suggested that they knew the actors they knew about. But the question is how deep they are and how sustained is the access.
▶ 0:51:38Mr. Jaffer: We were not able to detect them when they came in and could we have, possible. We had plenty of warning. This is what is crazy to me. The government now has admitted that it identified them in different systems and did not realize that they were hackers. -- hackers.
▶ 0:51:55Chair Fischer: Is it easier now to be able to detect from lessons learned?
▶ 0:52:00Mr. Jaffer: Every day that goes by we learn more about the adversary in our capabilities and we develop new capabilities. Ai provides a benefit to the offense and also to defenders as well. We should deploy that at scale. The challenge means that we remain in the situation blaming the victim. We are saying it is the telecom companies that did not do their part. There might be serious problems and things that need to be addressed.
▶ 0:52:27Mr. Jaffer: Beyond that what did the government know about the attacks, why did it identify them in different speed -- systems and did not take action to find them everywhere and why they did not share that information rapidly. This is like the cia identifying those two and not telling that those guys had visas to come to the united states.
▶ 0:52:50Chair Fischer: I mentioned the fact act and the bill that I passed in the senate. How concerned should we be about china and -- china in our hardware. Or in court networks, briefly?
▶ 0:53:08Mr. Jaffer: There is no question that we need to go out that the chinese and they spent a lot of time trying to get into our hardware. The fact act as a great piece of legislation that we need to get enacted as soon as possible but we need to go further. We need to get aggressive about identifying the fact that china has infiltrated -- infiltrated our infrastructure through the chips. China has a huge supply of foreign ships and they are trying to get advanced chips as well.
▶ 0:53:36Mr. Jaffer: They will not get you the as well. --euv as well.
▶ 0:53:41Chair Fischer: As we are looking in congress to remove a lot of that risky telecom gear from our networks currently, what policies do you think that we need to prioritize with regard to supporting manufacturing of our domestic or trusted ally equipment here so we do not run into a lot of the situations that was referred to?
▶ 0:54:09Mr. Mayer: To set the stage for the responding, the equipment in the telecom ecosystem is massive. It spans many continents. Overly concentrated frankly in an area of the world which we know is subject to disruption. China has expressed their interest in terms of what they want to accomplish, and there are a lot of countries that are now moving and moving their supply chain to countries in that region also.
▶ 0:54:41Mr. Mayer: I think from a policy perspective, we have to understand that there is significant technology embedded in our systems. And I think what congress did was admirable.
▶ 0:54:58Mr. Mayer: Because it recognized to vendors who we do were responsible for malicious surveillance and impacting and presented a risk from our military establishments in some areas and more importantly the overall risk to the ability to manage and control network security.
▶ 0:55:17Chair Fischer: I am out of time. So briefly, could you do a 1, 2, 3 of what we need to do with manufacturing on this?
▶ 0:55:29Mr. Mayer: We have to tighten requirements, I think the idea of security by design we have to build it in and not bolted on afterwards. And we need to have a close relationship with the government intelligence community about what they discover and what is suspicious and they have to share that with us so we can help them resolve some of these insecurities in that realm.
▶ 0:55:53Chair Fischer: Thank you. Senator lujan, you are recognized.
▶ 0:55:58Sen. Lujan: You are at the fcc has chief of public safety and homeland security bureau when the fcc adopted the declaratory ruling that required telecommunication carriers to secure their networks from unlawful access and the interception of communication.
▶ 0:56:16Sen. Lujan: The fcc proposed rules to required education services providers to submit an annual certification attesting that they created updated and implemented cybersecurity and supply chain risks. And you explain briefly why the fcc move forward with the declaratory ruling and the advance proposals earlier this year?
▶ 0:56:42Ms. Jordan: Part of what it did was gain access in the law enforcement requests and records, giving china access to our administrative proceedings against adversaries. And as I mentioned, section 105 which is system security and integrity requires that they secure the systems from authorized access. It was basically reemphasizing.
▶ 0:57:10Ms. Jordan: With regard to cyber risk management framework, that was developed, I think it was referred to as a checklist. And I take exception of that. It is a risk management plan. There are a number of steps that you go through. You have governance, are you changing and not using default passwords? Are you assessing your risk against a number of things like installing patches in a timely manner.
▶ 0:57:41Ms. Jordan: The fcc just on release another warning of the eas, the alerting systems that they need to patch their systems because they have been hacked. And so, that proposal that was pulled back to implement the cybersecurity framework is already in place, voted unanimously in the past several years for portions of the communication sector, and in fact in august it was proposed for subsea cable licensees to be required to do similar cyber
▶ 0:58:13Ms. Jordan: Risk management planning. It is not a checklist, it is do your cybersecurity in a methodical and planned way, and keep track of what you are doing so you knows internally and your leadership knows and you can share it when asked, whether congress or the sec. -- fcc.
▶ 0:58:30Sen. Lujan: A couple weeks ago the proposals were off the table after the trump fcc board voted along party lines to rescind the rulings. As the fcc proposed any rules in place of what it has rescinded to make sure networks are safe and secure?
▶ 0:58:46Ms. Jordan: I have not seen anything. I have seen and heard both in robert's testimony and the statements released by the fcc and policies that industry has committed or said that they will take extensive steps, but as I mentioned during my comments, there are no assurances. We do not know what those extensive steps are.
▶ 0:59:15Ms. Jordan: Communication networks are large, complex, and they require significant measures to be taken to secure them. And so, without some sort of accountability regime we do not know what they are doing, how effective it is and how widespread those measures will be. The answer is no, there is nothing that I am aware of that they have been put in place.
▶ 0:59:38Sen. Lujan: You both stressed the importance of american leadership in emerging technologies such as ai and quan tom. In this committee this year alone we have had multiple hearings on ai and we also hear that we are racing against the chinese government. The question for both of you and if you want to editorialize, submit that into writing but yes or no please.
▶ 1:00:01Sen. Lujan: Is it possible to win a race of america is constantly leaking ip to them through hacks and the telecom network? I'll --
▶ 1:00:11Mr. Mayer: Is it possible? If there are leaks in our infrastructure?
▶ 1:00:17Sen. Lujan: That is the question? Yes or no. You can editorialize later.
▶ 1:00:26Mr. Mayer: I do not think it lends itself to a yes or no.
▶ 1:00:32Sen. Lujan: The correct answer is no. If the chinese government gets its hands on everything we are doing with ip. What are we doing, you should have open protocol and let them do what they want? How can we ensure an equally strong cybersecurity standard across our network without the proper federal regulation? Is it possible, yes or no?
▶ 1:00:57Mr. Mayer: The regulation is a prescription -- crypto -- prescriptive approach and it does not solve the environment we are in.
▶ 1:01:07Sen. Lujan: It can be done voluntarily?
▶ 1:01:09Mr. Mayer: There is a shared responsibility across all aspects of the digital ecosystem.
▶ 1:01:15Sen. Lujan: You said that there should be tightening, so there should be regulation on vendors?
▶ 1:01:22Mr. Mayer: Expectations put on vendors.
▶ 1:01:26Sen. Lujan: And expectations until communication companies.
▶ 1:01:31Mr. Mayer: There should be.
▶ 1:01:33Sen. Lujan: I appreciate that.
▶ 1:01:36Mr. Jaffer: The better way to do that is a partnership. If we incentivize the behavior we want we are more likely to get it. The more regulations we put on providers we are saying that the lawyers decide what happened and I am a recovering lawyer. We tell our clients to do the minimum necessary at the latest time possible and do only what you are required.
▶ 1:01:58Mr. Jaffer: On the others hand if you incentivize with tax benefits and access to government programs they are more likely to line up with the boards and ceos in the same room to say we get a benefit by doing these things. Give me a and regulatory protection and now I am the witness chair all the information I can because everyone is lined up in the same direction and that is a more effective way to get to the goal that we want. We cannot win the ai race if we are leaking stuff out to china. The question is how do we get there?
▶ 1:02:26Sen. Lujan: Thank you. My time has expired and if we have another round of questions I would like to go back.
▶ 1:02:32Chair Fischer: Senator blackburn, you are recognized.
▶ 1:02:38Sen. Blackburn: Thank you mattern chairman and thank you all for being here. I want to return to the subsea cable issue, which is so vitally important. And I had introduced the undersea cable protection act because of concerns over what was being done.
▶ 1:02:55Sen. Blackburn: That would really preserve and make certain that we had these cables, and of course a tax on these, tampering and cutting is something that is there. Let me come to you.
▶ 1:03:12Sen. Blackburn: I want you to talk for a minute about the vulnerability, the landing stations in the cable routes for foreign adversaries in foreign attacks and why should -- we should prioritize these protections.
▶ 1:03:28Mr. Jaffer: 93% of the world's internet traffic travels on these cables and transoceanic communications go over the cables. You are right, it is not just the cables but the landing stations. Talking about the cables you have cable cuts that have happened in taiwan and the baltics and china has been dragging anchors intentionally. Certainly may be by accident, these can happen.
▶ 1:03:54Mr. Jaffer: We know for decades that the russians have been targeting our cables and they can get devices on the cables and tap them and disrupt them. It is a huge problem with the quantity of communications. The other problem is once the cables are cut getting the capability to restore them is limited which is why legislation like yours is important. We rely on chinese company is to do a lot of the cable fixes in the pacific which is a huge problem. If they are cut we are blind.
▶ 1:04:24Mr. Jaffer: We have a lot of capabilities as well, but the adversaries are targeting the infrastructure as well.
▶ 1:04:32Sen. Blackburn: Let me get on that as well. Talk for a little bit about that. Our primary deadlifts -- delivery system is the subsea cables. And if you look at what you can do with the satellite capacity, and what we have satellites will offer about 50 terabytes.
▶ 1:05:01Sen. Blackburn: We understand how indispensable this subsea infrastructure is. So, talk with me about how we should look at the complementary roles. The subsea cables, and then also the satellite system.
▶ 1:05:16Mr. Gizinski: Thank you for the question. A couple of key points, certainly the capacity for satellite communications is lower than that, but they do provide core critical infrastructure in an ongoing basis as well as key disaster capabilities. One of the core areas of focus is the risks that are present to the subsea cables are also present to satellites.
▶ 1:05:43Mr. Gizinski: They are vulnerable to physical, electromagnetic, and cyber attacks and it is a core area of focus and something we have looked at closely. In many cases those deployed in operational systems are owned and operated underneath a foreign flag, or they have a number of foreign supply components in them and that same level of attention and focus paid to other aspects of infrastructure is important to pay so that core aspect.
▶ 1:06:12Sen. Blackburn: Have you by any chance seen or are you aware of the naval project at the port of memphis? Ok. It would be worth your time, because they are looking at the underwater and it is a wonderful project. The port of memphis. I want to come back to you.
▶ 1:06:39Sen. Blackburn: Sam farms, I think that these farms that are powering the large robo call operations and scams, and we are seeing a lot of these. There has been a lot of talk about that this week because of black friday and cyber monday. And, what are the weaknesses in our current authentication systems when it comes to isolating or actually pinpointing these farms?
▶ 1:07:08Mr. Jaffer: We saw what happened. Chairman cruz referred to it in his opening statement about the farm that we saw in new york during the u.n. Hearings. You talked about the fraud that we have seen against seniors and a lot of consumers which is hugely problematic. We need to get better on the front and the question becomes how do you do it in a way that is still deployable.
▶ 1:07:30Mr. Jaffer: I think the hard part, we have done a lot of esim, which is significantly more secure and has the ability and leveraged to be more secure. As we shift to that that would make it more effective and the challenges that the adversary will always make a move. The best you can do as a defender is to help to keep up. With the advent of modern technology and ai, people worry that the offense will get better. I believe it will allow our defense to get just as good and keep up more effectively.
▶ 1:08:03Mr. Jaffer: I think applying those capabilities and the authentication domain is important not just for sims, but for regular internet authentication as well and financial transaction. We see the pivot from pasties to passwords and that is a significant were -- move and that will be empowered by our newfound capabilities.
▶ 1:08:20Chair Fischer: Thank you senator blackburn. Senator rosen, you are recognized.
▶ 1:08:26Sen. Rosen: Thank you chair and ranking member for holding such an important hearing. It is critically important because the security of our telecom industry is not only essential for our national security, but for closing the digital divide because connectivity should be secure and resilient as we have been talking about for it to be successful.
▶ 1:08:48Sen. Rosen: And I appreciate the discussion on salt typhoon because we need to protect ourselves in every way possible by building on our satellites and undersea. I want to move on to something that you touched on, artificial intelligence and the threat environment. Ai tools have made it easier than ever for threat actors to create realistic and sophisticated attacks to gain access to sensitive systems to valuable data. Even without the use of ai, we see cyber attacks with increasing frequency.
▶ 1:09:20Sen. Rosen: In august, nevada was hit with a devastating cyberattack and craig -- and crippling agents and fbi had to track down the criminals and secure nevada's data. The state made a full recovery. It appears that no sense of data was taken. I want to start with you.
▶ 1:09:38Sen. Rosen: In this environment with threats from cyber attacks growing every day, what is the risk of having a reactive federal response rather than proactively encouraging and requiring certain levels of cybersecurity for our critical sectors?
▶ 1:09:53Ms. Jordan: Thank you for the question. The risk is high and consequences of the year. We saw salt typhoon, and there are things that could be worse than that or it could be continuing to ask filtrate information.
▶ 1:10:08Sen. Rosen: We have resources and we disbanded the cyber safety review board. How is this impacting what we are able to do?
▶ 1:10:17Ms. Jordan: It is of great impact. With them putting offed guidelines and known exploited vulnerabilities and sharing the patches and criticality. You should do this soon because it is a high vulnerability and this one could wait longer. Without that information, that information sharing that my colleagues have been talking about is limited.
▶ 1:10:44Sen. Rosen: That is the bridge between the public and private in the grid and it is important that we do not just get rid of it.
▶ 1:10:49Ms. Jordan: I think so. Yes.
▶ 1:10:51Sen. Rosen: People of talked about the and for current companies to ensure that their networks are secure. Common sense cyber hygiene and all the things that you spoke about. Encryption, pasties, again I'm going to ask are there any federal programs that incentivize smart cyber practices, and what do you think about those, quickly because I have another question to ask.
▶ 1:11:18Ms. Jordan: I am not of -- aware of any that incentivize other than regulations that require. I think if there were incentives I would be in favor of them alongside light regulation that looked at incentiveization as well.
▶ 1:11:35Sen. Rosen: I will move on to you. In an ai enabled threat environment, what can congress do to secure networks. Some have supported additional funding for carriers and isp's to have adequate cyber security. Quickly and I have one more question for a former nevada in I believe, but, how do you think we can provide that support in congress?
▶ 1:12:00Mr. Mayer: You have to encourage innovation and not regulation. We had an incident two weeks ago of anthropic that for the first time, using commercial and off-the-shelf ai platforms they were able to initiate a cyberattack. 80% of that did not require human intervention. It was fully executed by an ai platform that is currently commercially available. Over time that 80% will move towards 100%.
▶ 1:12:31Mr. Mayer: That is the environment we are in. There is no way that a proscriptive text -- checklist regulation will allow us to innovate in the way that we need to innovate to address that threat.
▶ 1:12:41Sen. Rosen: So investing in public-private partnerships and innovations in our public research institutions and private companies would be in your advice reasonable.
▶ 1:12:51Mr. Mayer: Reasonable and vastly superior and should be encouraged by congress.
▶ 1:12:56Sen. Rosen: I have one last question about U.S. leadership in the telecom industry which is essential to securing our network. You have to be on that leading edge of innovation, maintaining U.S. leadership in international settings and standards.
▶ 1:13:11Sen. Rosen: So you worked for a defense company like sea nevada corporation, which is headquartered in nevada, can you speak to the importance of ensuring we have secure and resilient communication networks and how important is it to national security and U.S. jobs if we do not have a strong cyber posture across critical infrastructure sectors like telecom?
▶ 1:13:34Mr. Gizinski: Thank you for the question. It is critically important that we have a secure cyber infrastructure. One of the core areas that I have looked at and thought about quite a bit is promoting the culture throughout the defense industrial base of leaning forward and adopting strong cyber practices.
▶ 1:13:54Mr. Gizinski: That is something that we have seen some adoption driving towards strong incentive programs and encouraging the innovation that is being harnessed today to deliver next-generation technical innovations and what we are seeing in the satellite industry with the launch of a number of thousands of new satellites a year. And that same innovation shoulde harnessed and driven to secure our cyber posture.
▶ 1:14:30Mr. Gizinski: December I had called for an investigation into the department of war handling of the post-assault typhoon risk. In particular, the departed failure to ensure its communications video were protected from foreign espionage vulnerabilities.
▶ 1:14:48Mr. Gizinski: In your view, what are the structural problems in federal procurement that make it possible -- I should say what should congress consider as far as the federal recurrent process? >> the procurement system is one place where congress can do more to ensure effective cybersecurity. People want these contracts.
▶ 1:15:17Mr. Gizinski: We can impose whatever requirements we want that is a more preferable way to address the regulatory burden folks want to put on industry because if you want government contracts they should secure systems to government standards. We are seeing the department of war pivot to procurement, a much more commercial approach. It allows newer, better technology faster. We have to make sure we are not over imposing cybersecurity burdens that will prevent us from getting technology we want. There is a balance we can achieve.
▶ 1:15:50Sen. Schmitt: I agree and the sense that we have a lot of leverage as relates to those contracts. What are some of the minimum cybersecurity standards or audit compliance that should be included in those contracts? >> I think we should require companies that sell to the federal government to go through security audit and demonstrate to an independent third-party they have met things like cybersecurity framework, that they are applying it effectively. That is a good starting point.
▶ 1:16:21Sen. Schmitt: If they are able to show that to the government, the government does not need to do additional work to qualify them. They can become a contractor faster. That is a way to get smaller, faster companies in and not put additional regulatory burden on them while still requiring them to meet good cyber hygiene requirements.
▶ 1:16:40Sen. Schmitt: And your testimony, you emphasized prescriptive regulations cause us to lag behind for a bunch of reasons. You warned that the shift in tension from managing risk to managing paperwork means providers can be compliant but still be exposed.
▶ 1:17:03Sen. Schmitt: Can you speak to the impact we have seen from the previous administration's more prescriptive, checklist driven approach and what that has left behind and what we can learn from that moving forward?
▶ 1:17:13Mr. Mayer: We know the checklist, and we have evidence of this, has not been successful. There are examples where individuals or organizations managed by checklists missed things and in this environment where adversaries are evolving on a daily basis, using a checklist is looking in the rearview member.
▶ 1:17:42Mr. Mayer: We talk about flexibility and framework. That was designed to withstand. It has worked over a decade so I think the better approach is to engage with our government partners on a regular basis, including the intelligence along force a community, and talk about what we are observing, how to mitigate those activities, and we do hold ourselves accountable.
▶ 1:18:12Mr. Mayer: Frontline practitioners work every day to defeat these attacks. We do not hear about their success rate come but they are dedicated and passionate about security and they are held accountable within organizations to customers. I would say in the context of contracts, that is a legitimate avenue for negotiations and security requirements needed.
▶ 1:18:39Mr. Mayer: Service level agreements and other ways to reach understanding of what is expected.
▶ 1:18:43Sen. Schmitt: With the 43 seconds I have remaining, two questions for whoever wants to grab them because I think these are important. What we learned is there is deficiencies in the hardware that currently exists. Can you give me update on where that stands and why, as it relates to satellite security -- what are some -- just simple things like enabling encryption.
▶ 1:19:13Sen. Schmitt: Why are we not further along with that? So hardware issues and updating that at encryption for satellites.
▶ 1:19:24Mr. Gizinski: On the hardware side, a major area of emphasis, very important to pay attention to the supply chain and software , putting together transparent messaging around the source of all of the software aspects inc. Into systems. There are a number of explanations provided for complexities created by enabling encryption.
▶ 1:19:52Mr. Gizinski: Is a little bit of a surprise and I think there's probably further discussion needed on some of the limitations preventing encryption for being broadly used on satellite. It is something we have advocated for. We have made those tools available to many customers using those -- that equipment over satellite links and we are still seeing to this day that equipment not being enabled, features not being turned on.
▶ 1:20:19Mr. Gizinski: Part of the driver for that, the shift toward the concept of architecture where each system and subsystem is assumed to be un-trusted has not been fully adopted across the satellite industry more broadly. It appears to be potentially a misunderstanding of who is responsible for that layer of security in the system.
▶ 1:20:42Chair Fischer: Senator hickenlooper, you are recognized.
▶ 1:20:47Sen. Hickenlooper: Thank you for being here. I pretty the work you are doing and the broad context when I was finishing my first term as governor of colorado, we did an economic develop meant around asia and ended up in israel so we just saw a lot of the technologies you are all familiar with.
▶ 1:21:08Sen. Hickenlooper: We also saw israel's ability to connect military with academic research and universities with entrepreneurs and we have a national center for cybersecurity in colorado springs that tries to pick up on that. I think that is an art them as we discussed these issues. To continue what senator schmitt was asking, maybe I will turn to Ms. jordan on this.
▶ 1:21:36Sen. Hickenlooper: Colorado's critical infrastructure from energy facilities to militarist deletions top to bottom depends on secure communication links and we know that adversaries are constantly trying to interrupt and disrupt our communications and penetrate national security. In your view, what are the largest gaps in federal and state information sharing on security as threats to our communication?
▶ 1:22:10Ms. Jordan: Information sharing in general is important among industry and government and should include state and local centers along with a federal intelligence community. Where that is not happening, that is a big gap. I think understanding what threats are, and for venting -- implementing even the most basic security hygiene is critical.
▶ 1:22:38Sen. Hickenlooper: So those are the easy parts. We turn the page and look at, as quantum advances, certainly encryptions systems, protecting commute occasion networks are going to become vulnerable to rapid -- can you say decryption? Is that the right word? This is a future threat window that is immense by most measures.
▶ 1:23:10Sen. Hickenlooper: We recently published the first post quantum cryptography standards that can be adopted by the U.S. government. What you're describing is pretty basic tackling to go to the next level so given your experience with public safety and homeland security bureau, how should the fcc begin incorporating quantum resisting and post quantum transition planning into its network security? >> it is an area that needs to be looked at.
▶ 1:23:40Sen. Hickenlooper: I agree with my colleagues on collaboration. I think having those discussions with industry on how that is being rolled out, the pace at which it is rolled out, and looking at what needs regulation, where there should be secure by design, things that are built into products before they are deployed, and then where is there a need for -- the fcc hosts the communications security interoperability council.
▶ 1:24:08Sen. Hickenlooper: It is a partnership and they come up with best practices so that is like -- riep for a committee but when those best practices are put out they have to be used.
▶ 1:24:20Sen. Hickenlooper: Mr. mayer, as you know, colorado is helping many entrepreneurs and research labs up and down the front range and definitely on the front lines of 5g and nexgen wireless communications, but we have been working on a bipartisan fashion to close the shortage of funding for the rip and replace.
▶ 1:24:47Sen. Hickenlooper: Where we found we had a lot of infrastructure that was not secure as we would like. The salt typhoon showed how deeply adversaries can burrow into our commute occasion networks. How can colorado's rural broadband providers, which operate on then margins, benefit from additional federal guardrails or security baselines to make sure we do not have similar breaches?
▶ 1:25:14Mr. Mayer: The notion of doing things like hygiene is important. My experience is companies understand that. The challenge for rural providers is not having resources. So you are asking basically, local telephone operation to be able to compete against a nationstate everywhere all the time on these networks.
▶ 1:25:41Mr. Mayer: They view those providers as access points to the ecosystem and they exploit that. We have seen that with salt typhoon, how that works. I think the other opportunity for us is there is $20 billion in funding. Cybersecurity would be an excellent way to invest that money in cybersecurity workforce development, training, and the fact that there are legacy technologies.
▶ 1:26:12Mr. Mayer: The list is getting bigger.
▶ 1:26:14Sen. Hickenlooper: I'm out of time. Mr. gizinski, I have questions for you I will put in the written questions. I appreciate all of you being here. Thank you for your service. I yield back the floor.
▶ 1:26:29Chair Fischer: Thank you, senator hickenlooper. As a senator, you do not have to yield back time when you are finished. Thank you works.
▶ 1:26:39Sen. Hickenlooper: Well, I was out of time, so thank you.
▶ 1:26:43Chair Fischer: I am doing rules now, too. Senator l, you are recognized.
▶ 1:26:51Sen. Capito: Thank you for holding this hearing. You kind of got into what one of my questions was going to be, but let me begin with this. The program that was just -- the west virginia application which was okayed several weeks ago, if you followed it he probably now the original 1.2 billion that was allotted for west virginia, which was large for a small state, is now $600 million to
▶ 1:27:22Sen. Capito: Deliver the program in west virginia after it had been rebid and everything. In my opinion come out do you think -- I think you mentioned this, but with those extra dollars that are allotted for broadband, it seems to me that cybersecurity and other areas -- you mentioned workforce training .
▶ 1:27:46Sen. Capito: Where would you see -- I would like to keep those dollars captured for the deployment and safety of broadband. If you could expound on that a little more. >> I think we can do both. It is important to use that money for broadband deployment especially in rural areas. We need to make sure the citizens are not left out of the revolution that is underway.
▶ 1:28:12Sen. Capito: There is general understanding that the nature of the threat environment now is different. It is becoming more urgent. We have resources available to support that community so I think what we are talking about is targeted funding with full accountability in areas that these companies can -- and they know we need this system and we can use this mechanism or these professionals to support.
▶ 1:28:41Sen. Capito: Have them be able to access those funds for purposes of increasing cyber and protecting customers and networks. That is how we view it.
▶ 1:28:52Sen. Capito: For small systems in a small state like ours, some of them are small and some are major. They do not have the money to do that, so what are you going to do? Are you going to not deploy service in a rural area? You have to make a choice and it would be nice since $600 million is not going to be spent where it was initially intended to commit would be a source of funds.
▶ 1:29:19Sen. Capito: I would like to see more funds still deployed because there will still be people left out even after the program and those are difficult areas but it sounds like we are saying the same thing in terms of affordability of a rural broadband deployment company to be able to do this. If you think of it in terms of 9/11, where did they get in? In small airports where there were vulnerabilities.
▶ 1:29:50Sen. Capito: Same thing with cybersecurity, to take the whole system down, which rings me to another issue. There's a lot of talk about data centers and deployment of data centers and how critical they are in the race for ai and critical for us to be able to take advantage of the great technologies we have, but those are vulnerabilities that will be presented. I am thinking about undersea cables and other things.
▶ 1:30:15Sen. Capito: Is this something that should we be designating data centers as critical infrastructure so they can be part of how cisa and others look at our critical and restructure? I don't know if you have thoughts on that.
▶ 1:30:29Mr. Mayer: To a large extent, datacenter and restructure already looks like critical infrastructure, whether in manufacturing, the I.t. Sector, the communications sector. It is there. It is something we take seriously because we are seeing evidence the data centers or targets.
▶ 1:30:50Mr. Mayer: And we also see this week or two weeks ago a situation where a cooling device in a datacenter resulted in massive disruption, affecting major e-commerce platforms and social media platforms across the globe so there's an element built into a complicated network ecosystem.
▶ 1:31:17Mr. Mayer: And I thing that understanding that we are talking about attacks that are everywhere all the time -- I like to talk about the fact there are 22,300 feet in the sky, four miles underneath the surface of the sea, and everything in between.
▶ 1:31:33Mr. Mayer: That is the attack vector and for us as network service providers we are concerned that the ability to infiltrate devices that do not have the appropriate security built in -- they want to go to market quickly. They want to go with cheap prices.
▶ 1:31:52Mr. Mayer: That is why the fcc action around clean cars, which would impose expectations on retailers to not make those faulty devices available to the public, that is a step going forward recognizing that issue.
▶ 1:32:08Sen. Capito: Thank you, madam chair.
▶ 1:32:10Chair Fischer: Thank you, senator l. Thank you for bringing up the program which we worked on in the infrastructure bill and the importance of that and making sure areas are connected and hopefully that funding provided to our states will remain there and be able to be used for things, not just conductivity but also security needed.
▶ 1:32:37Sen. Capito: That will be a well-placed use of the funds and it is so necessary in light of testimony we have heard today.
▶ 1:32:46Chair Fischer: Thank you. Senator cantwell has joined us. Welcome. Do you have any opening comments?
▶ 1:32:59Sen. Cantwell: I will make a few comments and then get to questions. Thank you for holding this hearing. To you and to ranking member lujan, I want to focus on salt typhoon, the chinese government espionage operation that deeply penetrated networks of it least nine U.S. telecom companies, including at&t and verizon. It has been described as the worst telecom pack in our nation's history.
▶ 1:33:30Sen. Cantwell: The hackers broke into our telecommunications backbone and excluded the system lawn force relies on. These systems became an open door for chinese intelligence. It allowed the chinese operation to track millions of americans' locations cannot record phone calls, and read text messages.
▶ 1:33:53Sen. Cantwell: There targets included then candidates trump and vp vance -- vice president vance and hackers were able to determine who the U.S. government was wiretapping them including suspected chinese spies, telling aging which operatives might be compromised. How did this happen?
▶ 1:34:14Sen. Cantwell: Senior national security official said the breach occurred because to look munication's companies failed to implement rudimentary -- telecommunications companies failed to implement rudimentary security. And hackers acquiring credentials through week passwords.
▶ 1:34:39Sen. Cantwell: Security professionals across the industry were shocked because this kind of basic failure would not be acceptable in health care or banking or technology firms, yet here we are. The telecom system, basically the most sensitive communications. At&t and verizon claimed they were -- contained the attack, but government officials and cyber security experts remain skeptical.
▶ 1:35:05Sen. Cantwell: The fbi said cannot predict when we will have a full eviction of these bad actors and even chairman carr acknowledged when he was rolling back the rules that protected them, we are still being excluded. Earlier this year, I wrote to the ceos of at&t and verizon demanding that they provide documentation of remedies. Both companies refused. I believe the american people deserve to know whether china is still inside our telecom networks.
▶ 1:35:36Sen. Cantwell: Perhaps the most telling response in the breach came from the fbi in an unprecedented step last december. The fbi and cisa urged americans to use encrypted messaging, basically to protect communications. Interesting. Encryption is your friend, they said. Think about that. Our federal law-enforcement agencies are telling americans you cannot trust the security of your own telephone networks.
▶ 1:36:05Sen. Cantwell: And you should use encrypted communication. So what level of requirements should we be putting on our wireless providers to make sure that we are getting a level of security that americans deserve.
▶ 1:36:25Sen. Cantwell: And when we are handing over such valuable resources like spectrum and they are trying to constantly run important initiatives, what requirements should we put in place? That really do make americans more secure in munication's? >> there must be structured cybersecurity requirements. I am not talking about a checklist.
▶ 1:36:54Sen. Cantwell: The cyber mismanagement planning and getting those plans has to be put in place and it should be a requirement. The fcc has required it of certain subsections of the committee cases sector. In august, the ministration proposed it so continuing along that path the continued partnership of industry with government, the intelligence sector, others who know of the
▶ 1:37:25Sen. Cantwell: Recent threats, and as he mentioned doing a sick cyber hygiene. I would never let my iphone go seven years without a patch update. Ordering a pizza sometimes requires two factor authentication. Why are our providers not implemented basic hygiene? They should be doing a structured plan and held to a verification regime that would give you the information you asked for and did not receive.
▶ 1:37:56Sen. Cantwell: What about the fcc walking back requirements additionally? They are supposed to be the entity that says here is how you have these communications licenses to provide communication, yet if you are not going to do good hygiene why should we keep your license?
▶ 1:38:11Ms. Jordan: I do not believe a fallback of enforcement action is appropriate because that is after the fact so again they should be leveraging this requirement to use cybersecurity framework or something similar to do structured planning and execution of cyber risk management across the entire sector. They should not do it in pieces. It should be done pervasively.
▶ 1:38:39Sen. Cantwell: The grid is a similar organization that does this for the grid itself. Do you think that is what we need, something like that where at least? There is a dynamic input? Personally, I think we know this is the information age.
▶ 1:39:02Sen. Cantwell: We know this is what is going to happen, so letting these guys off the hook when there's so much a vulnerability for americans that are fbi and law enforcement are telling us use encrypted networks, it has gotten to a point where we have to do something to better help the public or why have -- basically you are just setting them up to say you are going to be a target.
▶ 1:39:28Ms. Jordan: I agree. I think there are some aspects of what china is doing that our nationstate and therefore even the telecom providers might not be able to save them off, but if the providers are not doing basic hygiene across their networks consistently, they should be held accountable.
▶ 1:39:50Ms. Jordan: They are not saying if a nationstate comes in a does something that we cannot predict -- that is a different scenario come but they should be held accountable to basic hygiene, patching, not default passwords, those kind of things.
▶ 1:40:03Sen. Cantwell: I think that is the most shocking thing. There was another big break that was the same issue. There was a patch available. We have looked at privacy laws and what you need to do if you are providing some sort of system.
▶ 1:40:19Sen. Cantwell: Nothing against 21-year-old administrators but you have to have more hierarchy to your enforcement on security than just hiring a bunch of very smart, talented people when you have consumers who are going to be vulnerable to these kind of things. We look forward to working with the subcommittee and figuring out what we can do to better protect americans.
▶ 1:40:46Chair Fischer: Senator peters, you are recognized.
▶ 1:40:51Sen. Peters: Thank you. Mr. mayer, as ranking member of the home on security and governmental affairs committee, one of my concerns and focuses has been on long-term extension of authorities contained in the cybersecurity information sharing act of 2015, which I know you are familiar with.
▶ 1:41:13Sen. Peters: Over 80 companies now and organizations or legislation I am working on entitled protecting america from cybersecurity threats act, which would extend those cybersecurity threat information sharing to parties for an additional 10 years, we all know the last 10 years have been successful. We need to make sure industry and others can rely on them.
▶ 1:41:41Sen. Peters: I appreciate how vocal ustelecom has been about extending this authority. Can you explain to the committee how cyber threat information sharing is critical for defending telecommunications networks and what more you think the trump administration should do to help us extend this essential authority? I hope my colleagues on the panel will support that. Give more reasons why it is important. >> is critical.
▶ 1:42:11Sen. Peters: We will not be successful in addressing the thoughts -- threats we face. It has been invaluable in terms of ability to share information without concerns about liability, about punishment and enforcement. We have an excellent relationship with government partners. The intelligence community, cisa , all these organizations, it is grounded in the ability to have conversations about what we are seeing and what we are doing to mitigate risk.
▶ 1:42:42Sen. Peters: These conversations are happening constantly and I think it speaks to broad consensus that this act has worked for 10 years. It is lapsing at the end of january if we do not deal with it. I would say probably the number one issue in the short term is improved cybersecurity writ large.
▶ 1:43:06Sen. Peters: Is along the cr, which would expire in january. Why do we need the 10 year extension?
▶ 1:43:15Mr. Mayer: Because we do not want to do this every few years or every few months. That is not good policy, so this is a cornerstone of our ability to collaborate with government.
▶ 1:43:28Sen. Peters: I'm also concerned, and we heard from my colleague, about the decision last month to rollback what are basically common sense cybersecurity rules to safeguard american data. These rules were announced in the wake of salt typhoon.
▶ 1:43:52Sen. Peters: I will not go into all the challenges there, but I think the rollback of these rules leaves americans exposed and erodes ability to prevent future attacks. I think this is even more concerning when you look at the rollback as part of a broader trend being carried out by the trump administration now where officials say -- they talk a good game and say cybersecurity is a priority, but they are getting --g
▶ 1:44:22Sen. Peters: Getting -- gutting cybersecurity institutions. As well as pushing out cybersecurity experts across government, firing people who know what needs to be done.
▶ 1:44:38Sen. Peters: My question for you is, the fcc rule to require telecommunications providers to have a cybersecurity plan and stick to it, pretty commonsense step forward to ensuring cybersecurity, why did ustelecom push the fcc to rollback these efforts in this case? Are you confident salt typhoon will not occur again? Why pushed rollers back?
▶ 1:45:09Mr. Mayer: Because they were not effective. We are not going to regular our way out of this issue. We have to innovate our way. We have an adversary using the most sophisticated techniques possible. It was not a checklist or compliance that was bypassed. It was advanced defensive capabilities been deployed by member companies that were bypassed. Why? Because the chinese are masters at stealth.
▶ 1:45:35Mr. Mayer: They used -- you talk about salt typhoon. It was identified in 2021 and 2020. They used the asia specific reason -- region as a testing ground for the stealth techniques with countries and organizations that were less hardened and then they perfected it. They came to the united states and used stealth technology that is anti-forensic. The breadcrumbs disappear.
▶ 1:46:03Mr. Mayer: Once they are in a network, it does not take more -- in some cases, less than a minute to move through the networks so we have a sophisticated adversary and the way to deal with this is collaboration, partnership with government, accountability absolutely. I am in the conversations. I know how much we are talking to these entities in classified and unclassified settings.
▶ 1:46:32Mr. Mayer: Numerous venues where we are making progress and we should not kill that with a compliance regime where you have your -- doing paperwork. We need to focus on the threat, on triage when it happens, and we are supportive of things like congress passed.
▶ 1:46:53Sen. Peters: My time is expired. I'm going to ask you a question related to this, as to wait -- why you may think the fcc actions were appropriate and white may have been wrong to hand this rollback but I will ask that in writing. Thank you.
▶ 1:47:10Chair Fischer: Senator young, you are recognized.
▶ 1:47:14Sen. Young: Thank you, madam chair, for your interest in this topic and I want to thank our panel is here today. Thank you for your contribution as a release to policymaking on this host of issues. You mentioned your testimony, Mr.
▶ 1:47:29Sen. Young: Jaffer, that china is engaged in undersea cable cutting activities, something for a couple years running I have had interest in and as a member of the intelligence committee I'm trying to find countermeasures that might help us address this growing challenge.
▶ 1:47:49Sen. Young: Subsea cables serve as the backbone to today's communication system so we are going to have to come up with checks and I believe we must adequately address these broader challenges in the coming months and years.
▶ 1:48:05Sen. Young: Earlier this year, the fcc put forward rules to streamline submarine cable application reviews to protect submarine cables against national security risks and incentivize cable buildout. In those rules, one requirement was for applicants to create cybersecurity and physical security risk management plans.
▶ 1:48:34Sen. Young: Can you identify other areas that should be a focus for strengthening our resiliency of subsea cable infrastructure? Especially as her adversaries continue to advance tactics to do harm.
▶ 1:48:49Mr. Jaffer: I think the most effective way we can prevent adversaries from cutting cables is to create more cables and have them owned by american companies, have warships able to fix them, and make clear to adversaries that if they cut our cables we will treated as an attack on our critical infrastructure because that is what it is.
▶ 1:49:11Mr. Jaffer: Today, adversaries largely get away with it because it is an accident, a mistake, we did not know it was you, but we have watched russians surveilled our cables. We have seen the chinese actually do it in taiwan and the baltics. One might be an accident. Three in a row is a pattern.
▶ 1:49:33Mr. Jaffer: When our adversaries realize we are actually watching them and are going to do something about it, they will stop doing it and we build enough cables and enough access that we can rely on our own systems and then there are things you can do. You can do physical security. You can put them in more robust casings. You can have surveillance measures. If you are going to push back against nationstate action, it has to be nationstate response.
▶ 1:49:57Sen. Young: We will have to come up with protocols or expectations that we will treat this almost like a strict liability situation or the burden of proof or production will be on whomever supposedly accidentally cut a cable. >> that is exactly right.
▶ 1:50:22Sen. Young: Same question to you. Are there other areas that should be a focus for strengthening resiliency as it relates to subsea cables?
▶ 1:50:32Mr. Mayer: I think so. We are an important stakeholder. The transmissions are often transmissions that we are generating nationally and internationally so we are aware of what the fcc is doing.
▶ 1:50:52Mr. Mayer: We have had conversations with the fcc national security council about cybersecurity practices related to protecting practices, to how we can support enhancing and making systems less vulnerable. There is an inherent risk when there are so many -- almost 500 and 700 submarine cables, many of these in the end of pacific region.
▶ 1:51:22Mr. Mayer: The ability for them to disrupt communications at a time that suits their needs is real and serious and this really requires federal engagement and activities. We are willing and ready to collaborate with any government partner and organizations to make sure these systems are more secure.
▶ 1:51:51Sen. Young: Who should bear the cost of redundancy? These are expensive capital investments. Would it be rational from an economic standpoint for us to say we have an idea who the greatest users of these cables are because they sent data across them, across the ocean. Ab we should put it on companies. What would you say to that line of economic argument?
▶ 1:52:17Mr. Mayer: The argot would be you can impose costs that are going to make the business not attract investors. You need big investment, huge investment amount to deploy and maintain and install these. The economic problem with dealing with asymmetrical issues is serious.
▶ 1:52:40Mr. Mayer: And I think that this is a question for national policy in terms of what kind of assistance we can do to safeguard our infrastructure against what we are experiencing today and what we know is possible tomorrow.
▶ 1:52:58Sen. Young: Coming up with a doctrine of deterrence will be come as a matter of politics and with the broader public of telecom consumers, that will be an easier sell so maybe we should focus in the near term on what is achievable and it seems to me a deterrence approach is achievable, so thank you all.
▶ 1:53:27Chair Fischer: Thank you, senator young. As I put out a last call for senators trying to get to this hearing to ask questions, senator lujan and I will each ask a final question. Mr. gizinski, you stated many of the satellites providing coverage to the united states exposed network traffic outside of our borders.
▶ 1:53:47Chair Fischer: How do we meaningfully improve encryption and security protocols across our satellite infrastructure, and inconsistency you highlighted?
▶ 1:54:02Mr. Gizinski: Excellent question. A few key points that are critical -- first as we see consistently a true point across telecom and the saddle industry. Most of the operators are not vertically degraded so they rely on the supply chain to build subsystems that go in and the things that enable encryption capabilities.
▶ 1:54:23Mr. Gizinski: It is important we extend threat sharing information into the supply chain and ensure we are building secure by design subsystems with flexible encryption protocols and other appropriate security considerations from the ground up. We have seen some of the examples where that has gone poorly am aware security vulnerabilities were present from the initial delivery. I'm encouraging that same approach through the satellite industry.
▶ 1:54:54Mr. Gizinski: The second point is recognizing in most cases folks designing and building the systems have the best view of what vulnerabilities are and maybe. They can be a great partner in closing those. We have seen application of well intended checklists on defense systems often are not designed with system architecture in mind. Having that in-depth, open conversation has been valuable in securing other systems over the years. That is a great model to follow.
▶ 1:55:24Chair Fischer: How severe do you think the threat is to our space systems that we have?
▶ 1:55:30Mr. Jaffer: I think the threat is severe. Look at the capability china has. They have a satellite, a repair satellite designed to remove debris. It demonstrated the ability to grapple another satellite and move to different organ -- orbit. That is a huge problem. The threat to our infrastructure is huge and they do not even have to take out a satellite directly.
▶ 1:55:58Mr. Jaffer: They could destroy one satellite and the debris field can cause problems for our satellites. It is a huge issue in outer space. Part of it is having a diversity of systems. If you and have more satellites going up faster, that will create a more resilient and more capable system and make it more technologically efficient so the better we can get at building smaller and faster and more capable satellites, the better off we will be.
▶ 1:56:28Sen. Lee: -- Sen. lee: lujan you sent any cybersecurity framework needs to be flexible and adapt. Do you agree the fcc has a role to play in ensuring communication networks are protected against cyber security threats?
▶ 1:56:47Mr. Mayer: Absolutely.
▶ 1:56:49Sen. Lujan: Senator peters asked a question around ustelecom, their role and advocacy to reverse the fcc actions in response to salt typhoon. If you things the fcc required was changing default passwords, requiring minimum password strength, and patching known vulnerabilities.
▶ 1:57:15Sen. Lujan: Congress has constantly been told we are behind the curve on technology even if we have these basic protections in place. Which of these basic protections was too burdensome for your organizations?
▶ 1:57:27Mr. Mayer: These are not what you are describing are not burdensome.
▶ 1:57:32Mr. Mayer: I appreciate that. That said, do your member companies have cybersecurity risk management?
▶ 1:57:39Mr. Mayer: Absolutely. They have in working on this for many years. They are evolving their risk management. >> are you willing to share those with the committee?
▶ 1:57:52Mr. Mayer: We are a trade association. I cannot say what our members are willing to share. I'm telling you we are doing a lot and we have been doing a lot and you can ask our government partners whether they think we're are doing a lot.
▶ 1:58:06Mr. Mayer: I will follow up there as well. You of all the panelists today -- my constituents depend on your members everyday around the clock. All day long. Most of my small businesses now rely on services your member companies provide, so I'm picking on you. I apologize for that, but it matters to my constituents.
▶ 1:58:29Mr. Mayer: There was a question asked by senator schmitt about requirements for contracts of the federal government around taxpayer dollars and I heard at least two panelists suggest that might be a good idea, to require anyone doing work with the federal government to meet a floor of standards to safeguard taxpayer dollars. With that be fair? That is my assumption.
▶ 1:58:58Mr. Mayer: If I'm incorrect, I invite you to submit into the record where I got that wrong. I asked my staff to let me know how much money the federal government or the last fiscal years has spent in a specific area, in telecommute acacian contracts.
▶ 1:59:15Mr. Mayer: They told me gao says 2014 and 2018 the government spent $30 billion for telecommunication contracts, $6 billion -- $14.3 billion for I.t. Services, $3.2 billion in I.t. And telecom products for fy 24. I look forward to working with you all to have requirements.
▶ 1:59:45Mr. Mayer: I look forward to working with you all. There is a floor of cyber requirements -- that is a lot of money. And we talk about national security vulnerabilities and how we outsource all our work to call centers. The smallest of the small and the most rural part of america but allow someone in, and after in? It infects the whole system so I hope these are areas we can get together appeared the last question I have is to Mr. jaffer.
▶ 2:00:16Mr. Mayer: You served on the cyber safety review board, which was under the department for less security. Was it a mistake to disband this board?
▶ 2:00:26Mr. Jaffer: We were asked to look at the salt typhoon hack because of internal government bureaucracy decisions. We were unable to get off the ground. We were not able to get clearances in time. We were not able to do any questioning of commit occasions companies so we were tasked with review months in advance. We took months and did not get anything done and then the board was disbanded. Should it be back?
▶ 2:00:56Mr. Jaffer: Absolutely. Even when it was in place, we got nothing effectively done because it was not allowed to do its work. There was a long force investigation, industry was partnering with government, they could talk to us. Even providers who said they were not affected by salt typhoon, we were not able to do that the board was not used effectively. If it is going to be back in place, he needs to be effectively.
▶ 2:01:26Mr. Jaffer: Congress ought to impanel an outside commission to look at what happened and make recommendations like the 9/11 commission did about what we should do to get the executive branch and industry back together and work on this issue.
▶ 2:01:38Sen. Lujan: If that body is brought back, he needs to be fixed and effective and tools into be in place to discover all the information to congress. In addition to that, your recommendation now is an outside commission as well. Thank you.
▶ 2:01:56Chair Fischer: Thank you, senator lujan. I would say the problem with any commissions is by the time we get the report is past due. It is really difficult to be able to get any movement forward from the recommendations put in place, so I look forward to working with you, senator lujan, and trying to figure out how we cut through things and try and
▶ 2:02:26Chair Fischer: Move quicker so we can have private industry able to work with the federal government to get us the information we need.
▶ 2:02:36Sen. Lujan: The other committees , the senate intelligence committee has a group that brings industry and government together. It is something the commerce committee could consider doing and bring a pound together and you can do it on your own time and not worry about getting authorized by law and we can advise the committee itself.
▶ 2:02:54Chair Fischer: A lot of the issues we have our jurisdictional as well whether with intel, with armed services committee, intersecting with commerce committee, and it just -- the time it takes is very frustrating. Thank you, senator lujan. Thank you to our panel today for the good information you have provided to this committee. With that, we are adjourned.
▶ 2:03:27Chair Fischer: [captioning performed by the national captioning institute, which is responsible for its caption content and accuracy. Visit ncicap.org]