Recent Bills
- H.R. 10171August 27, 2026
- H.R. 10156August 27, 2026
- H.R. 10172August 27, 2026
- H.R. 10160August 27, 2026
- H.R. 10181August 27, 2026
- H.R. 10176August 27, 2026
- H.Res. 1496August 27, 2026
- H.R. 10164August 27, 2026
- H.R. 10170August 27, 2026
- H.Res. 1494August 27, 2026
- H.R. 10163August 27, 2026
- H.R. 10157August 27, 2026
Committees
- Administration
- Agriculture
- Agriculture, Nutrition, And Forestry
- Appropriations
- Armed Services
- Banking, Housing, And Urban Affairs
- Budget
- Commerce, Science, And Transportation
- Education and Workforce
- Energy And Commerce
- Energy And Natural Resources
- Environment And Public Works
- Ethics
- Finance
- Financial Services
- Foreign Affairs
- Foreign Relations
- Health, Education, Labor, And Pensions
- Homeland Security
- Homeland Security And Governmental Affa…
- Indian Affairs
- Indian and Insular Affairs
- Intelligence
- Judiciary
- Natural Resources
- Oversight And Government Reform
- Permanent Select Intelligence
- Rules
- Rules And Administration
- Science, Space, And Technology
- Select Intelligence
- Small Business
- Small Business And Entrepreneurship
- Subcommittee on Aviation
- Subcommittee on Border Security and Enf…
- Subcommittee on Coast Guard and Maritim…
- Subcommittee on Commodity Markets, Digi…
- Subcommittee on Conservation, Research,…
- Subcommittee on Counterterrorism and In…
- Subcommittee on Cybersecurity and Infra…
- Subcommittee on Disability Assistance a…
- Subcommittee on Economic Development, P…
- Subcommittee on Economic Opportunity
- Subcommittee on Emergency Management an…
- Subcommittee on Energy and Mineral Reso…
- Subcommittee on Federal Lands
- Subcommittee on Forestry and Horticultu…
- Subcommittee on General Farm Commoditie…
- Subcommittee on Health
- Subcommittee on Highways and Transit
- Subcommittee on Livestock, Dairy, and P…
- Subcommittee on Nutrition and Foreign A…
- Subcommittee on Oversight and Investiga…
- Subcommittee on Oversight, Investigatio…
- Subcommittee on Railroads, Pipelines, a…
- Subcommittee on Transportation and Mari…
- Subcommittee on Water Resources and Env…
- Subcommittee on Water, Wildlife and Fis…
- Transportation And Infrastructure
- Veterans' Affairs
- Ways And Means

“Eliminating Waste, Fraud, and Abuse at the Department of Homeland Security: Addressing the Biden-Harris Administration’s Failures.”
Hearing•Homeland Security Subcommittee on Oversight, Investigations, and Accountability•Mar 11, 2025 · 2:00 PM
Summary
Homeland Security Subcommittee on Oversight, Investigations, and Accountability held a hearing on Mar 11, 2025 at 2:00 PM in Cannon House Office Building, Room 310. 7 witnesses appeared.
Record
The meeting has its video, its transcript, witnesses and documents on the record.
Video
The proceedings, as the committee streamed them.
Transcript
The transcript runs to 4,676 lines and 273,725 characters, as the Government Publishing Office printed it.
house-hearing-60983.txt1[House Hearing, 119 Congress]2[From the U.S. Government Publishing Office]34 REGULATORY HARM OR HARMONIZATION? EXAM-5 INING THE OPPORTUNITY TO IMPROVE THE6 CYBER REGULATORY REGIME78=======================================================================910 HEARING1112 BEFORE THE1314 SUBCOMMITTEE ON15 CYBERSECURITY AND INFRASTRUCTURE16 PROTECTION1718 OF THE1920 COMMITTEE ON HOMELAND SECURITY21 HOUSE OF REPRESENTATIVES2223 ONE HUNDRED NINETEENTH CONGRESS2425 FIRST SESSION2627 __________2829 MARCH 11, 20253031 __________3233 Serial No. 119-73435 __________3637 Printed for the use of the Committee on Homeland Security3839[GRAPHIC NOT AVAILABLE IN TIFF FORMAT]4041 Available via the World Wide Web: http://www.govinfo.gov4243 __________4445 U.S. GOVERNMENT PUBLISHING OFFICE4660-983 PDF WASHINGTON : 20254748-----------------------------------------------------------------------------------4950 COMMITTEE ON HOMELAND SECURITY5152 Mark E. Green, MD, Tennessee, Chairman53Michael T. McCaul, Texas, Vice Bennie G. Thompson, Mississippi,54 Chair Ranking Member55Clay Higgins, Louisiana Eric Swalwell, California56Michael Guest, Mississippi J. Luis Correa, California57Carlos A. Gimenez, Florida Shri Thanedar, Michigan58August Pfluger, Texas Seth Magaziner, Rhode Island59Andrew R. Garbarino, New York Daniel S. Goldman, New York60Marjorie Taylor Greene, Georgia Delia C. Ramirez, Illinois61Tony Gonzales, Texas Timothy M. Kennedy, New York62Morgan Luttrell, Texas LaMonica McIver, New Jersey63Dale W. Strong, Alabama Julie Johnson, Texas, Vice Ranking64Josh Brecheen, Oklahoma Member65Elijah Crane, Arizona Pablo Jose Hernandez, Puerto Rico66Andrew Ogles, Tennessee Nellie Pou, New Jersey67Sheri Biggs, South Carolina Troy A. Carter, Louisiana68Gabe Evans, Colorado Robert Garcia, California69Ryan Mackenzie, Pennsylvania Vacant70Brad Knott, North Carolina71 Eric Heighberger, Staff Director72 Hope Goins, Minority Staff Director73 Sean Corcoran, Chief Clerk74 ------7576 SUBCOMMITTEE ON CYBERSECURITY AND INFRASTRUCTURE PROTECTION7778 Andrew R. Garbarino, New York, Chairman79Clay Higgins, Louisiana Eric Swalwell, California, Ranking80Carlos A. Gimenez, Florida Member81Morgan Luttrell, Texas Seth Magaziner, Rhode Island82Andrew Ogles, Tennessee LaMonica McIver, New Jersey83Mark E. Green, MD, Tennessee (ex Vacant84 officio) Bennie G. Thompson, Mississippi85 (ex officio)86 Alexandra Seymour, Subcommittee Staff Director87 Moira Bergin, Minority Subcommittee Staff Director8889 C O N T E N T S9091 ----------92 Page9394 Statements9596The Honorable Andrew R. Garbarino, a Representative in Congress97 From the State of New York, and Chairman, Subcommittee on98 Cybersecurity and Infrastructure Protection:99 Oral Statement................................................. 1100 Prepared Statement............................................. 2101The Honorable Eric Swalwell, a Representative in Congress From102 the State of California, and Ranking Member, Subcommittee on103 Cybersecurity and Infrastructure Protection:104 Oral Statement................................................. 3105 Prepared Statement............................................. 5106The Honorable Mark E. Green, MD, a Representative in Congress107 From the State of Tennessee, and Chairman, Committee on108 Homeland Security.............................................. 6109The Honorable Bennie G. Thompson, a Representative in Congress110 From the State of Mississippi, and Ranking Member, Committee on111 Homeland Security:112 Prepared Statement............................................. 7113114 Witnesses115116Mr. Scott I. Aaronson, Senior Vice President, Energy Security &117 Industry Operations, Edison Electric Institute:118 Oral Statement................................................. 9119 Prepared Statement............................................. 11120Ms. Heather Hogsett, Senior Vice President and Deputy Head of121 BITS, Bank Policy Institute:122 Oral Statement................................................. 14123 Prepared Statement............................................. 16124Mr. Robert Mayer, Senior Vice President, Cybersecurity and125 Innovation, USTelecom, The Broadband Association:126 Oral Statement................................................. 20127 Prepared Statement............................................. 21128Mr. Ari Schwartz, Coordinator, Cybersecurity Coalition:129 Oral Statement................................................. 23130 Prepared Statement............................................. 25131132 Appendix I133134Statement of CTIA--The Wireless Association...................... 49135136 Appendix II137138Questions From Chairman Andrew R. Garbarino for Scott I. Aaronson 55139Questions From Chairman Andrew R. Garbarino for Heather Hogsett.. 57140Questions From Chairman Andrew R. Garbarino for Robert Mayer..... 59141Questions From Chairman Andrew R. Garbarino for Ari Schwartz..... 62142143REGULATORY HARM OR HARMONIZATION? EXAMINING THE OPPORTUNITY TO IMPROVE144 THE CYBER REGULATORY REGIME145146 ----------147148 Tuesday, March 11, 2025149150 U.S. House of Representatives,151 Committee on Homeland Security,152 Subcommittee on Cybersecurity and153 Infrastructure Protection,154 Washington, DC.155 The subcommittee met, pursuant to notice, at 10:08 a.m., in156room 310, Cannon House Office Building, Hon. Andrew R.157Garbarino (Chairman of the subcommittee) presiding.158 Present: Representatives Garbarino, Higgins, Gimenez,159Ogles, Green (ex officio), Swalwell, Magaziner, McIver, Clarke,160and Hernandez.161 Mr. Garbarino. The Committee on Homeland Security will come162to order.163 Without objection, the Chair may declare the committee in164recess at any point.165 Without objection, the gentlewoman from New York, Ms.166Clarke, and the gentleman from Puerto Rico, Mr. Hernandez, are167permitted to sit on the dais and ask questions of the168witnesses.169 The purpose of this hearing is to evaluate the170effectiveness of the Federal cyber regulatory regime and to171identify opportunities to harmonize cyber regulations across172the Federal Government. Specifically, we will examine the173challenges that private-sector owners and operators of critical174regulatory--of critical infrastructure face while navigating175cyber regulatory regime, including the potential impact of the176final CIRCIA rule if it does not meet Congressional intent.177 I now recognize myself for an opening statement.178 Good morning. I am honored to serve as Chairman of this179subcommittee again in the 119th Congress.180 Ranking Member Swalwell, it's great to serve alongside you181for another term.182 I'd also like to welcome all of our Members returning and183the new ones that are here. I'm looking forward to working with184all of you and to making this a productive Congress.185 As cyber threats to information technology and operational186technology increase, we must work hard to ensure cybersecurity187is front and center on Congress' agenda. Until we change our188cybersecurity posture, we'll continue to see rogue nation-state189actors target our Nation's critical infrastructure. In that190spirit, I am pleased to kick off this Congress with a191bipartisan priority that is vital to our Nation's security,192regulatory harmonization.193 For too long we have talked about the cumbersome nature of194cyber regulatory regime without seeing the changes necessary to195solve it. In fact, the Biden administration tried to add more196regulations on this sector and sectors such as health care and197water. While it is important for the Federal Government to work198with those sectors that are not as cyber mature, more199regulation is not the answer. With over 50 regulations at the200Federal level alone, it is time to streamline requirements to201ensure they promote useful, actionable, and reasonable202information sharing within the time frame requested.203 When organizations face their most vulnerable moment, they204should only be thinking about one thing: Securing their205networks. Hours of duplicative compliance tasks and hundreds of206thousands of dollars invested to navigate the landscape must207come to an end. With the beginning of the new administration,208we have an opportunity to reset the regulatory regime once and209for all.210 In 2022, Congress passed landmark legislation to streamline211cyber incident reporting. The Cyber Incident Reporting for212Critical Infrastructure Act of 2022, or CIRCIA, has directed213CISA to develop regulations to set an acceptable standard for214cyber incident reporting across all 16 critical infrastructure215sectors.216 Unfortunately, as many of today's witnesses reinforced last217year, the scope of the proposed CIRCIA rule went far beyond218Congressional intent. Knowing that the deadline for the final219rule is approaching, we will dig into the value of CIRCIA and220what the future of the rule should look like. This new221administration presents an opportunity to get cyber incident222reporting right. We should seize it.223 Beyond CIRCIA, different regulatory agencies have imposed224rules that directly contradict Congressional intent with225CIRCIA. Securities and Exchange Commission's rules on226cybersecurity risk management, strategy, governance, and227incidents disclosure are a perfect example of how rulemaking228should not be done--that is without buy-in from their key229stakeholders, industry, and Congress.230 As we strive for regulatory harmonization, collaboration231across the public and private sector is vital. We cannot allow232malicious cyber actors to get ahead of us because paperwork233holds us back from effective cyber risk management, mitigation,234and response. I look forward to hearing from our witnesses235about the steps we take to finally--we can take to finally236achieve regulatory harmonization.237 [The statement of Chairman Garbarino follows:]238 Statement of Chairman Andrew R. Garbarino239 March 11, 2024240 Good morning.241 I am honored to serve as Chairman of this subcommittee again in the242119th Congress. Ranking Member Swalwell, it is great to serve alongside243you for another term. I'd also like to welcome all our Members,244returning and new. I'm looking forward to working with all of you, and245to making this a productive Congress.246 As cyber threats from nation-state and criminal actors to247information technology (IT) and operational technology (OT) increase,248we must work hard to ensure cybersecurity is front and center on249Congress' agenda. Until we change our cybersecurity posture, we will250keep hearing about the Typhoons--including new ones that will251inevitably emerge.252 In that spirit, I am pleased to kick off the Congress with a253bipartisan priority that is vital to our Nation's security: regulatory254harmonization.255 For too long, we have talked about the cumbersome nature of the256cyber regulatory regime without seeing the changes necessary to solve257it. In fact, the Biden administration tried to add more regulations on258sectors such as health care and water. Some sectors admittedly have a259more mature cybersecurity posture than others. While it is important260for the Federal Government to work with those entities, more regulation261is not the answer. With over 50 regulations at the Federal level alone,262it is time to streamline requirements to ensure they provide263information that is useful, actionable, and reasonable within the time264frame requested.265 When organizations face their most vulnerable moment, they should266only be thinking about one thing: securing their networks. Hours of267duplicative compliance tasks and hundreds of thousands of dollars268invested to navigate the landscape must come to an end. With President269Trump's mandate to increase Government efficiency and reduce regulatory270burden, we have an opportunity to reset the regulatory regime once and271for all.272 In 2022, Congress passed landmark legislation to streamline cyber273incident reporting. The Cyber Incident Reporting for Critical274Infrastructure Act of 2022, or CIRCIA, directed CISA to develop275regulations to set an acceptable standard for cyber incident reporting276across all 16 critical infrastructure sectors.277 Unfortunately, as many of today's witnesses reinforced last year,278the scope of the proposed CIRCIA rule went far beyond Congressional279intent. Knowing that the deadline for the final rule is approaching, we280will dig into the value of CIRCIA and what the future of the rule281should look like. This new administration presents an opportunity to282get cyber incident reporting right. We should seize it.283 Beyond CIRCIA, different regulatory agencies have imposed rules284that directly contradict Congressional intent with CIRCIA. The SEC285rules on Cybersecurity Risk Management, Strategy, Governance, and286Incident Disclosure are a perfect example of how rulemaking should not287be done--that is, without buy-in from their key stakeholders: industry288and Congress.289 As we strive for regulatory harmonization, collaboration across the290public and private sectors is vital. We cannot allow malicious cyber291actors to get ahead of us because paperwork holds us back from292effective cyber risk management, mitigation, and response.293 I look forward to hearing from our witnesses about the steps we can294take to finally achieve regulatory harmonization.295296 Mr. Garbarino. I now recognize the Ranking Member for an297opening statement.298 Mr. Swalwell. I thank the Chairman, and excited to begin299this new Congress, again, with the Chairman. It's not a great300place to be in the Minority, but if you have a Chairman like301Mr. Garbarino on your subcommittee, it's a great place to get302things done, and that's our mission here is to get things done303for the good of our constituents and the security of the people304and companies we represent.305 This first hearing is focused on a bipartisan priority,306identifying opportunities to improve implementation of the307Cyber Incident Reporting for Critical Infrastructure Act,308CIRCIA, and the need to harmonize cyber regulations.309 Before I begin though, I did want to take a moment to310recognize and express my condolences to the family, friends,311and constituents of Congressman Sylvester Turner, who passed312away last week. He was a Member of this subcommittee, and his313passion for cybersecurity, whether it was as the mayor of one314of America's largest cities in Houston, that was clear also as315a Member of Congress serving on a committee that works on that,316and it was clear during his first 2 full committee hearings317last month. We'll miss his contributions that he made and318would've made to this subcommittee.319 Turning to the subject of today's hearing, I agree that320compliance costs can outweigh the security benefit of321regulations when compliance with duplicative regulations cuts322into investment and security. We should not be imposing323regulations for the sake of imposing regulations. Security324should be designed to achieve outcomes that are proven to325reduce risk and improve resilience and security.326 Toward that end, I am pleased to support CIRCIA because it327addressed a concrete security gap and will improve the328Government's ability to detect and disrupt malicious cyber329activity. It also put in place a framework that ensures covered330entities would not need to report the same cyber incidents331multiple times to multiple regulators. If a hacker gets into a332bank or energy company, we want them to focus on eradicating333the threat as quickly as possible, not huddling the lawyers and334compliance experts. They should be fixing the problem and335reestablishing their services.336 I am troubled that the proposed rule does not incorporate337the feedback that the private sector provided during the RFI338process. Congress put CISA in charge of the cyber incident339reporting rule because it has a record of working340collaboratively with the private sector, and our intent was341that CISA would engage the private sector to develop a workable342rule.343 Together with Ranking Member Thompson and my colleague344Congresswoman Clarke, I submitted comments on the proposed rule345urging CISA to more carefully scope the entities, incidents,346and information that must be reported. I've also called on CISA347to establish an ex parte process to facilitate on-going348engagements with the prior--with the private sector.349 With the fall 2025 deadline for issuing a final rule350looming, I urge CISA to work quickly to reengage with the351private sector and refine the scope of this rule. There are352also 3 key pieces of cybersecurity legislation that I urge this353committee to pass as quickly as possible. First, we must354authorize the Joint Cyber Defense Collaborative, CISA's355operational and collaboration hub. Formal authorization of the356JCDC will provide much-needed transparency regarding who can be357a member and the activities JCDC takes on. We passed this in a358bipartisan manner last Congress with support of the Chairman of359the whole committee, and I hope that authorization this360Congress will restore trust among JCDC participants and focus361JCDC on the activities most likely to drive security benefits.362 Relatedly, the Cyber Information Sharing Act of 2015 is set363to expire at the end of September. The bill is the foundational364collaboration between the Government and the private sector,365and it must be reauthorized.366 As it relates to CISA and some of the firings that we've367seen there, I want to make sure that we get rid of waste,368fraud, and abuse. The Government should be efficient and not369waste your money. That is a priority of mine; it's a priority370of most of my colleagues. However, we must be especially371careful when any cut goes to public safety, national security,372or cybersecurity, because we know that we are more vulnerable373than ever to a cyber attack, and we want to make sure that we374have the best folks on guard working hand-in-hand with the375private sector to make sure we're best protected.376 Finally, State and local cybersecurity grant programs will377expire on September 30. The grant program has helped State and378local governments across the country improve their ability to379defend against and become resilient to sophisticated cyber380attacks from our adversaries and other criminals.381 Again, I thank my colleagues for their commitment to moving382the ball forward on cybersecurity, and I look forward to383working with each of you and our witnesses to do that.384 Mr. Chairman, again, I'm looking forward to this Congress385and what we can do together, and this is an appropriate way to386kick off this subcommittee, and I yield back.387 [The statement of Ranking Member Swalwell follows:]388 Statement of Ranking Member Eric Swalwell389 March 11, 2025390 I'm glad our subcommittee's first hearing of the Congress is391focused on a bipartisan priority: identifying opportunities to improve392implementation of the Cyber Incident Reporting for Critical393Infrastructure Act (CIRCIA) and the need to harmonize cyber regulations394more broadly.395 But before I begin, I would like to take a moment to express my396condolences to the family, friends, and constituents of Congressman397Sylvester Turner, who passed away last week. His passion for398cybersecurity was clear during his participation in the first 2 full399committee hearings last month, and we will miss the contributions he400would have made to the subcommittee.401 Turning to the subject of today's hearing, I agree that compliance402costs can outweigh the security benefit of regulations when compliance403with duplicative regulations cuts into investments in security. We404should not be imposing regulations for regulation's sake. Cybersecurity405regulations should be designed to achieve outcomes that are proven to406reduce risk and improve security and resilience.407 Toward that end, I was pleased to support CIRCIA because it408addressed a concrete security gap and will improve the Government's409ability to detect and disrupt malicious cyber campaigns faster. It also410put in place a framework to ensure that covered entities would not need411to report the same cyber incident multiple times to multiple412regulators.413 If a hacker gets into a bank or energy company, we want them to414focus on eradicating the threat and getting back up and running. Their415first step should not be bringing in a team of lawyers and compliance416experts. It should be fixing the problem and re-establishing their417services.418 I share the concerns raised by our panelists today regarding the419scope of the proposed rule that CISA issued last spring. Notably, I was420troubled that the proposed rule did not incorporate the feedback that421the private sector provided during the RFI process.422 Congress put CISA in charge of the cyber incident reporting rule423because it has a record of working collaboratively with the private424sector, and our intent was that CISA would engage the private sector to425develop a workable rule.426 Together with Ranking Member Thompson and Congresswoman Clarke, I427submitted comments on the proposed rule urging CISA to more carefully428scope the entities, incidents, and information that must be reported.429 I also called on CISA to establish an ex parte process to430facilitate on-going engagement with the private sector. With the fall4312025 deadline for issuing a final rule looming, I urge CISA to work432quickly to re-engage with the private sector and refine the scope of433the rule.434 The cyber threats we face are evolving too quickly for any435unnecessary delay. I would like to thank Chairman Garbarino and436Chairman Green for their focus on improving the Nation's cybersecurity437posture.438 Toward that end, there are at least 3 key pieces of cybersecurity439legislation that I urge the committee to begin its work on as soon as440possible.441 First, we must authorize the Joint Cyber Defense Collaborative,442CISA's operational collaboration hub. Formal authorization of the JCDC443will provide much-needed transparency regarding who can be a member of444JCDC and the activities JCDC takes on.445 Authorization will help restore trust among JCDC participants,446focus JCDC on the activities most likely to drive security benefits,447and ensure that it is accountable to both stakeholders and Congress for448delivering a return on investment. I appreciated Chairman Green's449support of the legislation last Congress and hope to work with my450colleagues on a bipartisan basis to refine the bill and broaden support451for it this Congress.452 Relatedly, the Cybersecurity Information Sharing Act of 2015 is set453to expire on September 30. The bill is the foundation of operational454collaboration between the Government and the private sector and it must455be reauthorized.456 Finally, the State and Local Cybersecurity Grant program will also457expire on September 30. The grant program has helped State and local458governments across the country improve their ability to defend against459and become resilient to sophisticated cyber attacks from our460adversaries and other cyber criminals. For months, stakeholders have461asked me to do everything in my power to reauthorize the program and I462hope my Republican colleagues will support this effort.463 Once again, I thank my colleagues for their commitment to moving464the ball forward on cybersecurity, and I look forward to working with465you to do just that.466467 Mr. Garbarino. The gentleman yields back.468 I thank--I now recognize the Chairman of the full469committee, Mr. Green, for an opening statement.470 Mr. Green. Thank you, Chairman Garbarino and Ranking471Member. Good to see you guys today.472 Today's hearing serves as a crucial opportunity to examine473the effectiveness of Federal cyber bureaucracy. At a time when474cyber attacks are growing more frequent and sophisticated, it's475imperative that our regulatory process governing cyber space is476strengthened and harmonized. This will promote security and477cooperation while minimizing cost and confusion.478 Last May, this subcommittee held a hearing focused on479CIRCIA, Cyber Incident Reporting for Critical Infrastructure480Act of 2022. CIRCIA, among other things, directed CISA to481create and implement regulations for cyber incident reporting482across 16 critical infrastructure sectors. Although Congress483passed CIRCIA nearly 3 years ago, wide-spread regulatory484disharmony persists throughout the cyber incident reporting and485response regime.486 There are now at least 50 cyber incident reporting487requirements in effect across the Federal Government. These488regulations are often duplicative and complex, requiring489private-sector owners and operators to invest significant sums490into regulatory compliance rather than security. This patchwork491of conflicting and complex regulations place a significant492burden on reporting entities.493 Let's be clear, improving our Nation's cyber regulatory494regime will bolster our Nation's security. Current cyber495incident reporting regulations require too much of the private496sector, drawing their attention away from actually securing497their networks. Federal regulations, like the SEC's public498cyber disclosure rule, clearly illustrate the urgent need for499harmonization. This rule in particular is riddled with500ambiguity and sets constrictive reporting time lines for501organizations that experience cyber incidents.502 Ambiguous and conflicting standards like the SEC rule are503allowing compliance to take a priority over security, leaving504our critical infrastructure more vulnerable to subsequent505attacks. Injecting consistency and efficiency into the cyber506regulatory regime is necessary to protect our Nation from507digital threats to our critical infrastructure. The security of508our homeland depends on effective cooperation between the509private and public sectors, and it is our duty to help remove510any unnecessary barriers to collaboration.511 Since CIRCIA is still in the rule-making process until512later this year, there is still time to ensure that regulatory513effectiveness and harmonization are core features of our514national cyber incident reporting requirements. The final rule515must not place an undue burden on private-sector entities that516are critical to our national cyber defense.517 I want to thank our witnesses, Scott Aaronson from Edison518Electric, Heather Hogsett from Bank Policy Institute, Robert519Mayer from USTelecom, and Ari Schwartz from the Cybersecurity520Coalition, for being here today. Most of you have testified521before during our hearings last May, and each provided522invaluable insight to this subcommittee. Thank you for being523here today.524 With President Trump in office, we have a unique525opportunity to create a common-sense cyber regulatory structure526that ensures compliance serves its purpose to share actionable527information with the Federal Government and with each other. As528nation-state threats rise, we must do all we can to ensure that529our cyber professionals can focus their precious time and530attention and resources on securing networks and critical531infrastructure and not on checking a box. I look forward to532working with you as we pursue this shared objective. I yield.533 Mr. Garbarino. The Chairman yields back.534 Other Members of the committee are reminded that opening535statements may be submitted for the record.536 [The statement of Ranking Member Thompson follows:]537538 Statement of Ranking Member Bennie G. Thompson539 March 11, 2025540 Every day, we face efforts by adversaries like China and Russia to541breach Government and critical infrastructure networks. To combat this542risk, we need critical infrastructure entities to strategically543increase their cyber defenses, and we need Government visibility into544the threats we are facing.545 Experience has demonstrated that a purely voluntary approach to546cybersecurity is insufficient for today's threat landscape and that547thoughtful regulations can improve security outcomes. With numerous548Government agencies having regulatory authority over different critical549infrastructure sectors, I understand the concerns from the private550sector that regulations may be duplicative or inconsistent, resulting551in unnecessarily burdensome compliance efforts.552 Additionally, regulations risk being box-checking exercises rather553than focusing on improved security outcomes. Therefore, efforts to554improve cyber regulatory harmonization are important to ensuring555regulations strengthen security and do not instead distract critical556infrastructure from their security efforts.557 The most meaningful step Congress has taken in recent years to558address duplicative cybersecurity regulations was the enactment of the559Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) in5602022. Sponsored by Congresswoman Yvette Clarke, this legislation seeks561to increase visibility into the current cyber threat landscape, by562mandating critical infrastructure entities to report substantial cyber563incidents to CISA. It also seeks to harmonize cyber incident reporting564requirements by establishing CISA as a central reporting hub that can565share cyber incident reports with other relevant agencies.566 As I emphasized in comments I submitted to CISA, along with Ranking567Member Swalwell and Representative Clarke, the proposed rule issued568last year is overly broad and needs significant refinement in order to569align with Congress's goals for the program. Additionally, I encourage570increased engagement with stakeholders so that CISA can fully571understand their concerns and can maximize the effectiveness of this572new mandatory cyber incident reporting regime.573 That being said, a final CIRCIA rule has tremendous potential to574improve the Government's understanding of the cyber threats we face and575to ultimately reduce the compliance burden on companies by harmonizing576incident reporting requirements to a new CIRCIA standard.577 By statute, CISA is required to issue a final rule by September of578this year. It is essential that CISA work expeditiously to issue a579final rule so that we can begin to see the benefits of CIRCIA580implementation and so that other agencies can begin work to align their581incident reporting regimes to CIRCIA's.582 Our adversaries are not pausing their efforts to breach our583networks, and we cannot afford to pause our efforts to better defend584them.585 Relatedly, I am deeply concerned by the new administration's anti-586regulatory attitude that risks undermining our security. While there is587a need to streamline cybersecurity regulations, arbitrary policies that588require eliminating regulations in order to issue any new ones would589prevent agencies from responding to the evolving cyber threat590landscape.591 Instead, agencies must thoughtfully evaluate how to ensure critical592infrastructure entities have the defenses in place to protect our593networks and must coordinate efforts to create a more harmonized594approach. We must avoid a simplistic discussion of more or less595regulation and instead prioritize implementing policies that maximize596security outcomes without unnecessary burdens.597 I appreciate the support for CIRCIA from our witnesses, and I look598forward to their testimony today on how to ensure proper implementation599and improved regulatory harmonization.600601 Mr. Garbarino. I am pleased to have a distinguished panel602of witnesses before us today. I ask that our witnesses please603rise and raise their right hand.604 [Witnesses sworn.]605 Mr. Garbarino. Let the record reflect that all the606witnesses have answered in the affirmative.607 Thank you. Please be seated.608 I would now like to formally introduce our witnesses. Mr.609Scott Aaronson currently serves as senior vice president for610energy security and industry operations for the Edison Electric611Institute. In this role, he focuses on industry security and612resilience initiatives establishing collaborative partnerships613between Government and electric companies and across critical614infrastructure sectors that enhance security for the energy615sector. In addition to his role at EEI, Scott also serves as616the Secretary for Electricity Subsector Coordinating Council,617ESCC.618 Ms. Heather Hogsett is the senior vice president and deputy619head of BITS, the technology policy division of the Bank Policy620Institute. In this position she develops and leads initiatives621on emerging technology security resilience matters facing the622Nation's largest financial firms. Ms. Hogsett also cochairs the623policy committee of the Financial Services Sector Coordinating624Council and is board member of fTLD Registry Services.625 Mr. Robert Mayer is the senior vice president of626cybersecurity innovation with the USTelecom Association. He is627responsible for leading cyber and national security policy and628strategic initiatives. In addition to this role, he serves as629chairman of the Communications Sector Coordinating Council,630which represents the broadcast, cable, satellite, wireless, and631wire line industries in connection with DHS and public/private632partnership activities across the U.S. Government. He also633serves as cochair of the Council to Secure the Digital Economy.634 Ari Schwartz currently serves as the coordinator for the635Cybersecurity Coalition. In this role, he leads consortium of636cybersecurity companies coordinating the Coalition's advocacy637and education regarding cybersecurity policies. He also serves638as the managing director of cybersecurity services for Venable639where he helps organizations develop and implement640cybersecurity risk management strategies. He was previously a641member of the White House National Security Council where he642served as special assistant to the President and senior643director for cybersecurity.644 I thank the witnesses for being here today.645 I now recognize Mr. Aaronson for 5 minutes to summarize his646opening statement.647648 STATEMENT OF SCOTT I. AARONSON, SENIOR VICE PRESIDENT, ENERGY649 SECURITY & INDUSTRY OPERATIONS, EDISON ELECTRIC INSTITUTE650651 Mr. Aaronson. Thank you, Chairman Garbarino and Ranking652Member Swalwell, Chairman Green, and to all the Members of the653subcommittee. Appreciate the opportunity to testify today on654cyber regulatory harmonization and specifically on655implementation of the Cyber Incident Reporting for Critical656Infrastructure Act of 2022, or more easily, CIRCIA.657 My name is Scott Aaronson, and as noted, I am senior vice658president for energy security and industry operations at the659Edison Electric Institute. As you know, EEI is the trade660association representing 250 million--companies that provide661electricity to nearly 250 million Americans operating in all 50662States and the District of Columbia.663 As I testified last May, EEI and its members wholly endorse664the policy objectives underpinning CIRCIA. Incident reporting665can help industry and our Government partners identify threats,666see patterns, set policies, and prioritize risks to better667protect critical infrastructure. CIRCIA is an important law668with an important goal of identifying and mitigating cyber669risks across all sectors of the economy, and I appreciate this670committee's leadership in shepherding this effort these last671several years.672 When CIRCIA was enacted, Congress emphasized that the673legislation sought to strike a balance between enabling CISA to674receive information quickly and allowing the impacted entities675to respond to an attack without imposing burdensome676requirements that prioritize paperwork over cyber defense and677response. Details matter when it comes to how CIRCIA or any new678cybersecurity policy is implemented. Nearly a year after the679subcommittee's hearing and my initial testimony on CIRCIA, we680are in a period of transition with a new administration and a681new Congress. Change brings opportunity, and I urge this682subcommittee to leverage this opportunity to help ensure CISA683is implementing CIRCIA effectively.684 Both my written testimony and comments today focus on 2685main considerations for Congress when evaluating how best to686proceed: First, the need to finalize the CIRCIA rule as687mandated by statute so that electric companies and all critical688infrastructure operators can benefit from this reporting to689mitigate attacks and the disruptions they can cause; and,690second, improving the existing proposal to better align with691Congressional intent. CISA must do more to meaningfully692incorporate industry feedback into the final rule to ensure693reporting is not duplicative and that Government is a resource694to ingest and protect this sensitive information.695 Following the hearing last May, EEI has continued to engage696with CISA on CIRCIA. In July 2024, EEI submitted 3 sets of697comments on the proposed rule. In October 2024, EEI joined more698than 20 organizations in requesting the establishment of an ex699parte process to enhance stakeholder engagement and facilitate700on-going dialog for implementation.701 As I once again testify before you alongside the financial702services and telecommunications sectors representing some of703the most sophisticated critical infrastructure operators, our704collective concern remains that even the most mature sectors705will be overburdened by the proposed rule if it were to be706finalized as is. The committee should work with CISA to reduce707this burden and focus on a few areas for improvement: First,708conduct oversight regarding the current status of CIRCIA,709including staffing levels, resource needs, projected time-line710for final rule completion, and anticipated future engagement711with industry stakeholders; second, facilitate coordination712amongst Congressional committees of jurisdiction to align CISA,713sector risk management agencies, and other regulators, and714review concerns with existing Federal reporting requirements,715including the national security concerns associated with the716public disclosure of incidents as required by the U.S.717Securities and Exchange Commission rule; third, further clarify718CISA's role in cybersecurity regulatory harmonization in719relation to other Federal entities; and, fourth, reauthorize720the Cybersecurity Information Sharing Act of 2015. Mandatory721incident reporting and voluntary information sharing both are722valuable tools in ensuring the cybersecurity of critical723infrastructure.724 EEI and its members are committed to working with both725public and private partners across all sectors to comply with726incident reporting requirements, and cyber regulations more727broadly, in a way that prioritizes and enhances critical728infrastructure security. We look forward to working with you729and CISA to finalize a rule that leverages existing regimes,730provides meaningful insights to Government and industry, and731protects sensitive information.732 I'll also take a moment here to note, a little off script,733that--the news this morning about the Critical Infrastructure734Partnership Advisory Committee Act being rethought under this735new leadership at the Department of Homeland Security. It's not736our place to decide how Government organizes, but I want to737highlight the value of industry-Government partnership, and738CIPAC provides extraordinary protections for those partnerships739and those partnership activities. Nearly 90 percent of critical740infrastructure is owned by the private sector. It's critical741because it's critical to national security, and it is critical742to the life and safety of the communities that we serve.743Industry and Government have to be working hand in glove, and,744again, CIPAC provides a really valuable mechanism to do that.745 We appreciate the bipartisan support of this committee in746ensuring we get CIRCIA right and CIPAC right, and we look747forward to continuing our collaboration to protect the safety,748security, well-being of all Americans as we face evolving cyber749risk. Thank you again for the opportunity to testify, and I750look forward to your questions.751 [The prepared statement of Mr. Aaronson follows:]752 Prepared Statement of Scott I. Aaronson753 March 11, 2025754 introduction755 Chairman Garbarino, Ranking Member Swalwell, and Members of the756subcommittee, thank you for the opportunity to testify. My name is757Scott Aaronson, and I am senior vice president for energy security &758industry operations at the Edison Electric Institute (EEI). EEI is the759association that represents all U.S. investor-owned electric companies,760which together are projected to invest more than $200 billion this year761to make the energy grid stronger, smarter, cleaner, more dynamic, and762more secure against all hazards. That includes cyber threats. EEI's763member companies provide electricity for nearly 250 million Americans764and operate in all 50 States and the District of Columbia. The electric765power industry supports more than 7 million jobs in communities across766the United States. I appreciate your invitation to discuss this767important topic on their behalf.768 We rely on safe, reliable, affordable, and resilient energy to769power our daily lives, run our Nation's economy, and support national770security. Today, demand for electricity is growing at the fastest pace771in decades, creating challenges for our Nation, as well as772opportunities to ensure America is home to the industries,773technologies, and jobs of tomorrow. America's investor-owned electric774companies are uniquely positioned to meet growing demand and to address775evolving risks, while working to keep customer bills as low as776possible.777 eei's comments on cyber regulatory harmonization778 The electricity subsector is a part of the energy sector that is779designated by National Security Memorandum/NSM-22 as one of the 16780critical infrastructure sectors whose assets, systems, and networks are781considered so vital to the United States that their incapacitation or782destruction would have a debilitating effect on national security,783economic security, or public health and safety. The reliance of784virtually all industries on electric power means that all critical785infrastructure sectors have some dependence on the energy sector.786 The electric subsector employs a risk-based, defense-in-depth787approach to cybersecurity, including employing a variety of tools and788strategies that support existing voluntary and mandatory cybersecurity789standards and regulations, both of which are valuable tools in ensuring790the cybersecurity of critical infrastructure.791 Throughout the country, investor-owned electric companies are792meeting and exceeding existing cybersecurity regulations and standards.793As the Federal Government, States, and private sector work together to794reduce risk holistically and continue to enhance cybersecurity795protections of critical infrastructure, it is important that new796cybersecurity requirements are not duplicative, conflicting,797overlapping, or inefficient. Regulations that include flexibility and798support for resilience, response, and recovery can help electric799companies protect the electric grid. We also need to have strong800partnerships in place across key sectors and with Government in order801to maintain the robust cybersecurity posture needed to face the802realities of potential cyber warfare.803 In November 2023, EEI submitted comments on the Office of the804National Cyber Director's (ONCD) Request for Information on805Cybersecurity Regulatory Harmonization.\1\ In summary, EEI's comments806recognized that cybersecurity regulations must keep pace with the807evolving threat landscape. Because industry owns, operates, and secures808the majority of the energy grid, the Federal Government should809incorporate industry's subject-matter expertise in developing and810implementing new regulations and streamline processes from which new811regulations may emerge. EEI's comments also provided examples of812cybersecurity regulatory conflicts, inconsistencies, redundancies,813challenges, and opportunities. Some of the key points that EEI made814include:815---------------------------------------------------------------------------816 \1\ Comment from Edison Electric Institute, REGULATIONS.GOV,817https://www.regula- tions.gov/comment/ONCD-2023-0001-0039 (November 1,8182023).819---------------------------------------------------------------------------820 Effective communication between Government and industry is821 paramount to reconciling existing and future cybersecurity822 regulations;823 Harmonization is needed to address the high costs and824 inefficiencies caused by existing regulations or standards, or825 both;826 Harmonization efforts also must address third-party business827 partners;828 In addition to Federal regulations, EEI members also are829 subject to (and must comply with) many State, local, Tribal,830 and territorial cybersecurity requirements and standards; and,831 Additional matters to help harmonize cybersecurity832 regulations, such as:833 Voluntary information sharing and protection;834 Privacy laws and regulations;835 Information handling;836 Cloud security;837 Contract terms; and,838 Government coordination.839 eei's engagement on circia840 While the Cyber Incident Reporting for Critical Infrastructure Act841of 2022 (CIRCIA) is the first Federal cybersecurity reporting842requirement focused specifically on reporting across all 16 critical843infrastructure sectors, electric companies have been subject to similar844Federal reporting for years pursuant to mandates imposed by the Federal845Energy Regulatory Commission (FERC), the North American Electric846Reliability Corporation (NERC), the Transportation Security847Administration (TSA), and the Department of Energy (DOE). These848existing reporting requirements should be considered by the849Cybersecurity and Infrastructure Security Agency (CISA) as it850determines how to implement its own cybersecurity and incident851reporting regulations.852 In May 2024, EEI had the opportunity to testify during this853subcommittee's hearing entitled, ``Surveying CIRCIA: Sector854Perspectives on the Notice of Proposed Rulemaking.''\2\ EEI testified855that one of our member electric companies estimated they could file856roughly 65,000 reports through 2033 under the proposed rule--vastly857exceeding CISA's estimate of more than 200,000 total reports during858that period. In addition, our testimony highlighted that the Department859of Homeland Security's (DHS) Cyber Incident Reporting Council (CIRC)860report on harmonization identified that there currently are 45861different Federal cyber incident reporting requirements administered by86222 Federal agencies.\3\ We recommended that CISA thoroughly explore863opportunities to limit duplicative reporting through the864``substantially similar'' exception of CIRCIA, and through the865establishment of CIRCIA Agreements with Federal counterparts. EEI's866testimony also identified several areas for enhancement of the proposed867rule, including:868---------------------------------------------------------------------------869 \2\ Statement of Scott Aaronson, CONGRESS.GOV, https://870www.congress.gov/118/meeting/house/117105/witnesses/HHRG-118-HM08-871WState-AaronsonS-20240501.pdf (May 1, 2024).872 \3\ Harmonization of Cyber Incident Reporting to the Federal873Government, DHS.GOV, https://www.dhs.gov/sites/default/files/2023-09/874Harmonization%20of%20Cyber%20Incident%20-875Reporting%20to%20the%20Federal%20Government.pdf (September 19, 2023).876---------------------------------------------------------------------------877 Scope of substantial cyber incident definition;878 Volume of information requested;879 Workforce burden;880 Data preservation requirements; and881 Protection of information.882 Following the hearing last May, EEI has continued to engage with883CISA on CIRCIA. In July 2024, EEI submitted 3 sets of comments on the884proposed rule. The first set of comments was sent on behalf of EEI's885member electric companies and included feedback that was discussed in886the May hearing, including:887 CISA's proposed definition of ``substantial cyber incident''888 is too broad and therefore must be narrowed in scope;889 The amount of information required under the proposed rule890 is excessive, significantly increasing a covered entity's891 reporting burden while often contributing little analytical892 value;893 CISA must do all it can to protect reported information from894 threat actors and recognize its own limitations;895 The proposed rule's data-preservation requirements are896 unduly onerous;897 The proposed rule includes contrasting interpretations of898 the term ``promptly'' as it relates to the time frame within899 which covered entities must submit supplemental reports;900 CISA's proposed marking requirements need clarifying; and901 Harmonizing existing and proposed cybersecurity requirements902 is vital.\4\903---------------------------------------------------------------------------904 \4\ Comment submitted by Edison Electric Institute,905REGULATIONS.GOV, https://www.regulations.gov/comment/CISA-2022-0010-9060452 (July 5, 2024).907---------------------------------------------------------------------------908 The second set of comments was sent on behalf of the communications909sector, electricity subsector, and financial services sector,910encouraging CISA to limit the scope and raise the threshold for911incident reporting by amending the definition of a substantial cyber912incident in the final rule.\5\ Cosigners of these comments included913some of the most sophisticated critical infrastructure owners and914operators across the United States, including the American Bankers915Association, American Public Power Association, Bank Policy Institute,916EEI, National Rural Electric Cooperative Association, NTCA--The Rural917Broadband Association, Securities Industry and Financial Markets918Association, and USTelecom--The Broadband Association.919---------------------------------------------------------------------------920 \5\ Comment submitted by ABA, APPA, BPI, EEI, NRECA, NTCA, SIFMA,921USTelecom, REGULATIONS.GOV, https://www.regulations.gov/comment/CISA-9222022-0010-0254 (June 28, 2024).923---------------------------------------------------------------------------924 The third set of comments was sent on behalf of more than 50925organizations seeking clarification on whether trade associations would926be considered ``covered entities'' that are required to report cyber927incidents to CISA under the proposed rule.\6\ The uncertainty around928the inclusion of associations, which serve members within critical929infrastructure sectors--but which do not own or operate critical930infrastructure--in the definition of a covered entity is just one931example of the ways in which CISA's proposed rule is out of scope.932These comments were intended to ensure CISA appropriately tailors933reporting requirements to provide only the most relevant information934necessary to protect homeland security.935---------------------------------------------------------------------------936 \6\ Comment submitted by National Association of Manufacturers and93750 other trade associations, REGULATIONS.GOV, https://938www.regulations.gov/comment/CISA-2022-0010-0320 (July 3, 2024).939---------------------------------------------------------------------------940 Also in July 2024, subcommittee Chairman Andrew Garbarino,\7\941subcommittee Ranking Member Eric Swalwell, full committee Ranking942Member Bennie Thompson, Rep. Yvette Clarke,\8\ (July 9, 2024). as well943as then-Senate Homeland Security and Government Affairs Committee944Chairman Gary Peters,\9\ submitted comments on the proposed rule. The945feedback provided by Congress suggested that CISA mischaracterized or946failed to meet the Congressional intent of CIRCIA. Universally,947Congressional leaders have encouraged CISA to refine the scope of948definitions and to meaningfully incorporate industry feedback in the949final rule.950---------------------------------------------------------------------------951 \7\ Comment submitted by Congressman Andrew R. Garbarino,952REGULATIONS.GOV, https://www.regulations.gov/comment/CISA-2022-0010-9530464 (July 9, 2024).954 \8\ Comment submitted by CHS--Ranking Member Bennie G. Thompson,955Ranking Member Eric Swalwell, Rep. Yvette Clarke, REGULATIONS.GOV,956https://www.regulations.gov/comment/CISA-2022-0010-0463.957 \9\ Comment submitted by Homeland Security and Government Affairs958Committee, REGULATIONS.GOV, https://www.regulations.gov/comment/CISA-9592022-0010-0424 (July 3, 2024).960---------------------------------------------------------------------------961 Finally, in October 2024, EEI, along with more than 20962organizations, sent a letter to CISA regarding the status of CIRCIA963implementation, specifically requesting the establishment of an ex964parte process to enhance stakeholder engagement and facilitate on-going965dialog for its implementation.\10\ The letter urged CISA to:966---------------------------------------------------------------------------967 \10\ Cross-sector Letter on CIRCIA Implementation, CYBERSCOOP.COM,968https://cyberscoop.com/wp-content/uploads/sites/3/2024/10/10.29.24-969Cross-sector-Letter-on-CIRCIA-Implementation68.pdf (October 29, 2024).970---------------------------------------------------------------------------971 Adopt an ex parte process for on-going stakeholder972 engagement;973 Narrow the scope of CIRCIA to enable a positive cycle of974 information sharing and actionable insights;975 Proactively harmonize CIRCIA implementation with existing976 regulatory requirements to optimize operational response; and,977 Strengthen safeguards for information and protections978 against liability to support cyber attack victims and foster979 candor in reporting.980 To date, CISA has not established an ex parte process and the981status of the remaining recommendations remains unknown.982 opportunities for circia and recommendations for congress983 Nearly a year after this subcommittee's hearing and EEI's testimony984on CIRCIA, we are in a period of transition with a new administration985and a new Congress. Change brings opportunity--and I urge this986subcommittee to leverage this opportunity to help CISA improve987implementation of CIRCIA.988 As we stated in our comments on the proposed rule, EEI and its989members wholly endorse the policy objectives underpinning CIRCIA.990CIRCIA is an important law with an important goal of identifying and991mitigating cyber risks across all sectors of the economy, and I992appreciate this committee's leadership in shepherding this effort993forward these last several years. When CIRCIA was enacted, Congress994emphasized that the legislation sought to strike a balance between995enabling CISA to receive information quickly and allowing the impacted996entity to respond to an attack without imposing burdensome997requirements. Details matter when it comes to how CIRCIA, or how any998mandatory cyber incident reporting regime, is implemented. We need our999most skilled cyber experts to be spending the majority of their time1000protecting America's critical infrastructure, not filling out1001paperwork.1002 When evaluating how best to proceed, I encourage Congress to1003consider that:1004 A final CIRCIA rule could help mitigate attacks and the1005 disruptions they cause to American individuals and businesses.1006 Therefore, improving the existing proposal and finalizing the1007 rule by the fall 2025 deadline, as mandated by statute, may be1008 preferable to issuing a new proposed rule. A new proposal may1009 cause confusion and unnecessary delays, as well as increase1010 costly paperwork for both covered entities and the Federal1011 Government.1012 CISA faces several challenges in improving the existing1013 proposal to better align with Congressional intent. These1014 include difficulties in collaborating with industry stemming1015 from the lack of an established ex parte process, as well as1016 issues related to natural attrition and staff turnover1017 following the change in administration. Additionally,1018 uncertainty around Congressional appropriations may impact1019 CISA's ability to effectively intake incident reports by the1020 end of 2025.1021 recommendations for congress1022 1. Conduct oversight regarding the current status of CIRCIA,1023 including staffing levels, resource needs, the projected time1024 line for final rule completion, and anticipated future1025 engagement with industry stakeholders.1026 2. Facilitate coordination amongst Congressional committees of1027 jurisdiction to:1028 a. Ensure alignment between CISA, Sector Risk Management1029 Agencies, and other regulators, confirming that CIRCIA1030 Agreements are developed in compliance with the law's1031 substantially similar reporting exception; and1032 b. Review concerns with existing Federal reporting requirements,1033 including the national security concerns associated with1034 the public disclosure of incidents required by the U.S.1035 Securities and Exchange Commission.1036 3. Further clarify CISA's role in cybersecurity regulatory1037 harmonization in relation to other Federal entities, such as1038 DHS and ONCD; and assess the next steps for the CIRC at DHS, as1039 well as the legislative proposals recommended by CIRC in its1040 harmonization report.1041 4. Reauthorize the Cybersecurity Information Sharing Act of 20151042 (CISA 2015), a pivotal law that encourages and protects cyber1043 threat information sharing between the Government and the1044 private sector. While CISA 2015 is more about information1045 sharing than incident reporting, both are essential to1046 strengthening our collective cyber defenses to meet the1047 evolving threat landscape.1048 conclusion1049 Thank you again to this committee for holding today's hearing and1050for your on-going efforts to strengthen America's energy security.1051EEI's member companies are committed to working with Federal partners1052and stakeholders across all sectors to achieve cyber regulatory1053harmonization that prioritizes and enhances U.S. critical1054infrastructure security. We appreciate the bipartisan support of this1055committee in ensuring we get CIRCIA right and we look forward to1056continuing our collaboration to protect the safety, security, and well-1057being of all Americans.10581059 Mr. Garbarino. Thank you, Mr. Aaronson.1060 I now recognize Ms. Hogsett for 5 minutes to summarize her1061opening statement.10621063STATEMENT OF HEATHER HOGSETT, SENIOR VICE PRESIDENT AND DEPUTY1064 HEAD OF BITS, BANK POLICY INSTITUTE10651066 Ms. Hogsett. Thank you. Good morning Chairman Garbarino,1067Ranking Member Swalwell, Chairman Green, and honorable Members1068of the subcommittee. Thank you for inviting me to testify. I'm1069Heather Hogsett, senior vice president and deputy head of BITS,1070the technology division of the Bank Policy Institute.1071 BPI is a nonpartisan policy research and advocacy1072organization representing the Nation's leading banks. On behalf1073of BPI members, we greatly appreciate this committee's1074leadership and the opportunity to provide perspective on1075cybersecurity regulations.1076 As today's national security threats increasingly target1077vital infrastructure and our economy, it is imperative that1078industry and Government work together to have an awareness of1079cyber incidents and vulnerabilities while ensuring cyber teams1080can focus on day-to-day tasks, responding to incidents when1081they occur, and implementing next-generation technologies.1082Unfortunately, the current state of cyber regulations detract1083from this vital work.1084 To support the Nation's security and resilience, we offer a1085few recommendations: First, streamline the reporting of cyber1086incidents to allow cyber teams to focus on response. I1087previously testified before this committee in support of the1088Cyber Incident Reporting for Critical Infrastructure Act,1089CIRCIA, and its goal to create a uniform incident reporting1090system. This would provide CISA with information it needs to1091have broader awareness of cyber threats and the tactics used by1092attackers. Armed with this information, CISA can better assess1093threats and provide early warning to help other entities1094protect themselves.1095 We continue to believe that CIRCIA, if properly1096implemented, will play an important role in our collective1097defense. However, as we noted in formal comments last June, it1098is critical that the final rule not extend beyond the1099authorities granted to it under the statute. Bipartisan Members1100of this committee, as well as Senator Peters, submitted1101comments emphasizing a similar view. Your comments were1102enormously helpful in reiterating Congressional intent, and we1103thank you for your continued leadership and engagement.1104 We, along with several other financial trade associations,1105recently asked that the current proposal be withdrawn and1106reissued. In particular, we encouraged CISA to significantly1107revise last year's proposed rule to reduce the scope of1108reporting to incidents affecting critical services, focus data1109collection on what companies need to know to prevent contagion,1110and reduce on-going reporting obligations.1111 At the same time, Congress and the administration should1112direct other agencies to cease issuance of bespoke reporting1113requirements. Some agencies, such as the Federal banking1114regulators, have incident notification requirements that are1115simple and serve a very specific operational or emergency1116response purpose. These requirements were developed in close1117collaboration with industry and work well in practice. Other1118agencies, however, continue to issue onerous reporting or1119disclosure requirements with different definitions, time-lines,1120and varying data elements that do not improve security1121outcomes.1122 One rule in particular is the SEC's requirement to disclose1123material cyber incidents within 4 business days, regardless of1124whether the incident has been contained or remediated. This1125rule should be rescinded as it undermines CIRCIA and1126confidential reporting and unnecessarily complicates incident1127response.1128 Second, we encourage Congress and the administration to1129consolidate industry-specific cyber regulations and regulatory1130oversight. This is a particularly acute challenge for financial1131institutions with multiple regulators. A survey of bank chief1132information security officers found that they spent 30 to 501133percent of their time on compliance and examiner management,1134and their teams can spend 70 percent of their time on those1135functions.1136 Firms receive on average 100 requests for information1137leading up to an exam, with anywhere from 75 to 1001138supplemental requests during an exam that can take weeks if not1139months to complete. Once one exam is completed, another1140regulator often comes in to examine the same or a similar1141topic. The current state risks undermining our security, and it1142is time for a reassessment.1143 Finally, we urge Congress to reauthorize cyber information1144sharing protections that expire this fall. The Cybersecurity1145Information Sharing Act of 2015 established important liability1146and antitrust protections for entities sharing cyber threat1147information, which were subsequently incorporated into CIRCIA.1148In the decades since their enactment, these protections have1149supported not only the sharing of cyber threat indicators but1150also broader awareness of vulnerabilities, knowledge of threat1151actors and their tactics, and effective defensive measures.1152 Recent attacks against public and private infrastructure1153underscore the importance of preserving these protections and1154the important information exchange they facilitate. We greatly1155appreciate this committee's thoughtful approach to these issues1156and stand ready to work with you to protect the security and1157resilience of our Nation's infrastructure. Thank you for the1158opportunity to speak today, and I'm happy to answer any1159questions.1160 [The prepared statement of Ms. Hogsett follows:]1161 Prepared Statement of Heather Hogsett1162 March 11, 20251163 Chairman Garbarino, Ranking Member Swalwell, and Honorable Members1164of the subcommittee, thank you for inviting me to testify. I am Heather1165Hogsett, senior vice president and deputy head of BITS, the technology1166policy division of the Bank Policy Institute.1167 BPI is a nonpartisan policy, research, and advocacy organization1168representing the Nation's leading banks. BPI members include universal1169banks, regional banks, and major foreign banks doing business in the1170United States. BITS, our technology policy division, works with our1171member banks as well as insurance, card companies, and market utilities1172on cyber risk management, critical infrastructure protection, fraud1173reduction, regulation, and innovation.1174 I also serve as co-chair of the Financial Services Sector1175Coordinating Council Policy Committee. The FSSCC coordinates across the1176financial sector to enhance security and resiliency and to collaborate1177with Government partners such as the U.S. Treasury and the1178Cybersecurity and Infrastructure Security Agency, as well as financial1179regulatory agencies.1180 On behalf of BPI member companies, I appreciate the opportunity to1181provide input on the status of the Cyber Incident Reporting for1182Critical Infrastructure Act, as well as the state of cybersecurity1183regulation, and ways to potentially harmonize existing requirements.1184There is an urgent need to reduce overlapping and duplicative1185regulatory requirements that present considerable challenges for many1186critical infrastructure entities. Financial institutions experience1187these challenges acutely when complying with a multitude of incident1188reporting requirements and during cyber-specific supervisory1189examinations conducted by numerous financial regulatory agencies.1190 As the Government surveys the current cyber regulatory landscape in1191search of increased efficiencies, it should prioritize: (1)1192Streamlining cyber incident reporting requirements to allow cyber1193personnel to focus on response efforts; and (2) consolidating cyber1194regulatory requirements and supervision.1195 cyber incident reporting1196 To better align incident reporting requirements, Government1197agencies should consider: (1) substantial revisions to CISA's proposed1198rule to implement the Cyber Incident Reporting for Critical1199Infrastructure Act (``CIRCIA''); (2) rescinding the SEC's Cyber1200Incident Disclosure Rule; and (3) directing Federal agencies to stop1201issuing duplicative requirements and instead leverage CIRCIA as1202Congress intended.1203Revise the CIRCIA Proposed Rule1204 Almost a year ago, I testified before this subcommittee shortly1205after CISA released its proposed rule.\1\ During that hearing, I noted1206our members' concerns that CISA's proposal reflected an overly broad1207reading of the underlying statute and would add significant compliance1208obligations on front-line cyber personnel during the most critical1209incident response phase. As we move closer to the statutory deadline1210for CISA to issue its final rule, our members maintain those same1211concerns.1212---------------------------------------------------------------------------1213 \1\ Surveying CIRCIA: Sector Perspectives on the Notice of Proposed1214Rulemaking Before the Subcomm. on Cybersecurity and Infrastructure1215Protection of the H. Comm. on Homeland Security, 118th Cong. (2024)1216(Statement of Heather Hogsett, Senior Vice President, Technology & Risk1217Strategy for BITS, Bank Policy Institute).1218---------------------------------------------------------------------------1219 Financial institutions supported CIRCIA as it was being considered1220by Congress because it proposed a uniform incident reporting standard1221for critical infrastructure and sought to enhance CISA's ability to1222combat sophisticated cyber threats. Because CISA's proposal fell short1223of that aspiration, we--along with several other financial trade1224associations--recently reiterated this viewpoint in a letter to1225Department of Homeland Security Secretary Noem and Office of Management1226and Budget Director Vought requesting that they withdraw the current1227proposal and re-issue it more in line with Congressional intent.\2\1228While the current proposal is too broad in scope, we continue to1229believe that CIRCIA, if properly calibrated, can enhance our collective1230defenses and mitigate threats from foreign adversaries.1231---------------------------------------------------------------------------1232 \2\ Letter from the American Bankers Assoc., Bank Policy Inst.,1233Inst. of Int'l Bankers, & Sec. Industry & Fin. Markets Assoc., to1234Kristi Noem, Secretary, Dep't of Homeland Sec. & Russell T. Vought,1235Director, Office of Mgmt. & Budget (Feb. 28, 2025), https://bpi.com/wp-1236content/uploads/2025/02/CIRCIA-Letter-to-Noem-Vought-2.28.25.pdf.1237---------------------------------------------------------------------------1238 For that enhancement to be most effective, it is also important1239that Congress reauthorize the Cybersecurity Information Sharing Act of12402015 (``CISA 2015'').\3\ The information, antitrust, and liability1241protections in CISA 2015 are imperative for public-private information1242sharing and provide the legal clarity companies need to share1243information not only with CISA but with other companies across critical1244infrastructure. The protections in CISA 2015 are also incorporated by1245reference in CIRCIA--making their reauthorization all the more1246critical. The expiration of the legal framework provided in the Act1247could substantially disrupt information sharing--leaving us all less1248prepared to confront emerging cyber risks.1249---------------------------------------------------------------------------1250 \3\ Consolidated Appropriations Act, Pub. L. No. 114-113, Div. N,1251Title I--Cybersecurity Information Sharing Act, 129 Stat. 2935 (2015),12526 U.S.C. 1501.1253---------------------------------------------------------------------------1254 As we noted in our joint financial trades response to CISA's1255proposal last June, it is critical that CISA's final rule not extend1256beyond the authorities granted to it under the statute.\4\ Bipartisan1257Members of this committee, along with Senator Peters, submitted1258comments emphasizing that same view.\5\ These responses were enormously1259helpful for reiterating Congressional intent, and we thank you for your1260leadership.1261---------------------------------------------------------------------------1262 \4\ American Bankers Assoc., Bank Policy Institute, Institute of1263International Bankers, & Sec. Industry & Financial Markets Assoc.,1264Comment Letter on Cyber Incident Reporting for Critical Infrastructure1265Act (CIRCIA) Reporting Requirements (Jun. 28, 2024), https://bpi.com/1266wp-content/uploads/2024/06/CIRCIA-Reporting-Requirements-Comment-1267Letter.pdf.1268 \5\ Representative Andrew Garbarino, Comment Letter on Cyber1269Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting1270Requirements (Jul. 3, 2024); Representatives Bennie G. Thompson, Yvette1271D. Clarke, & Eric M. Swalwell, Comment Letter on Cyber Incident1272Reporting for Critical Infrastructure Act (CIRCIA) Reporting1273Requirements (Jul. 3, 2024); Senator Gary Peters, Comment Letter on1274Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA)1275Reporting Requirements (Jul. 2, 2024).1276---------------------------------------------------------------------------1277 To adhere more closely to the CIRCIA statute, the final rule should1278limit reporting to information directly related to an actionable1279purpose--like detecting signs of a wide-spread vulnerability. Narrowing1280reporting data elements in this way would help give life to CIRCIA's1281``substantially similar'' exception--something that would be1282unavailable to covered entities under the breadth of the current1283proposal. It would also lessen the burden of the supplemental reporting1284requirements which, as currently drafted, would likely require entities1285to file multiple additional reports during a single incident. Finally,1286CISA's rule should have reasonable thresholds for reporting above the1287standard proposed in the current substantial cyber incident definition1288that would likely cause a flood of reports on low-risk incidents.1289Rescind the SEC Cyber Incident Disclosure Rule1290 Before the SEC finalized this rule in 2023, the financial sector1291raised significant concerns with its requirement to publicly disclose1292on-going cyber incidents.\6\ Chief among those concerns was that1293publicly disclosing on-going and unremediated cyber incidents could1294impair a victim company's ability to respond or otherwise exacerbate1295harm to the company, its shareholders, and customers. Unfortunately,1296those reservations were realized in November 2023 when ransomware group1297AlphV weaponized the public disclosure requirement as an additional1298ransom payment extortion method by reporting its own victim to the1299SEC.\7\ Given the pervasiveness of ransomware attacks, it is misguided1300to provide cyber criminals with an additional means to inflict1301financial harm on victim companies.1302---------------------------------------------------------------------------1303 \6\ Bank Policy Institute, American Bankers Assoc., Independent1304Community Bankers of America, & Mid-Size Banking Coalition of America,1305Comment Letter on Proposed Rules Regarding Cybersecurity Risk1306Management, Strategy, Governance, and Incident Disclosure Requirements1307(May 9, 2022), https://bpi.com/wp-content/uploads/2022/05/05.09.22-BPI-1308ABA-ICBA-MCBA-SEC-Comment-Letter-2022.05.09.pdf; Fin. Services Sector1309Coordinating Council, Comment Letter on Cybersecurity Risk Management,1310Strategy, Governance, and Incident Disclosure, https://www.sec.gov/1311comments/s7-09-22/s70922-20128382-291285.pdf.1312 \7\ AlphV files an SEC complaint against MeridianLink for not1313disclosing a breach to the SEC, DATABREACHES.NET (Nov. 15, 2023),1314https://databreaches.net/2023/11/15/alphv-files-an-sec-complaint-1315against-meridianlink-for-not-disclosing-a-breach-to-the-sec/.1316---------------------------------------------------------------------------1317 The public disclosure element of this rule is also problematic1318because it directly conflicts with the purpose of confidential incident1319reporting requirements. Although there are numerous confidential1320reporting rules across the Government, all generally aim to limit harm1321and warn potential downstream victims. Once an incident is publicly1322disclosed, however, that task becomes much more difficult to achieve.1323Using CIRCIA as an example, CISA will only have 24 hours to1324confidentially share threat indicators before an incident is publicly1325disclosed under the SEC rule. That leaves vulnerable companies with1326virtually no time to implement those controls before the incident is1327disclosed to the world. Rescinding the requirement that companies1328publicly disclose on-going cyber incidents will help eliminate1329unnecessary exposure to these threats.1330Stop Duplicative New Requirements and Leverage CIRCIA1331 The financial sector complies with as many as 10 distinct incident1332reporting requirements in the United States alone.\8\ Many of these1333obligations were instituted over the past few years as agencies1334seemingly rushed to put out their own--and often conflicting rules. We1335understand that agencies have unique missions and therefore different1336information needs. Nonetheless, the patchwork of current requirements1337across the Government is past the point of helpful and now diverts1338finite resources away from incident response to filling out Government1339forms.1340---------------------------------------------------------------------------1341 \8\ DEP'T OF HOMELAND SEC., HARMONIZATION OF CYBER INCIDENT1342REPORTING TO THE FEDERAL GOVERNMENT 9 (2023); U.S. DEP'T OF HOUSING &1343URBAN DEVELOPMENT, FED. HOUSING ADMIN., MORTGAGEE LETTER 2024-23,1344REVISED CYBER INCIDENT REPORTING REQUIREMENTS (2024); U.S. DEP'T OF1345HOUSING & URBAN DEVELOPMENT, GINNIE MAE, APM 24-02, CYBERSECURITY1346INCIDENT NOTIFICATION REQUIREMENT (2024).1347---------------------------------------------------------------------------1348 There are 3 general categories these rules fall into: (1) Incident1349notification; (2) confidential incident reporting; and (3) public1350incident disclosure. At one end of the spectrum, incident notification1351rules tend to be early during an incident investigation and simple--1352such as a phone call or email. They are used to inform an agency of an1353issue without requiring extensive data elements. We support and1354recognize the value of incident notification requirements for agencies1355with operational responsibilities or emergency authorities within1356critical infrastructure. An example of this is the financial regulatory1357agencies' Interagency Computer-Security Incident Notification Rule1358issued after substantive consultation with financial institutions.\9\1359---------------------------------------------------------------------------1360 \9\ Computer-Security Incident Notification Requirements for1361Banking Organizations and Their Bank Service Providers, 12 C.F.R. 531362(2021).1363---------------------------------------------------------------------------1364 Confidential incident reporting requirements--like CIRCIA--involve1365more detailed responses and therefore often have slightly longer1366reporting time frames. They serve to provide Government with1367information to assess whether an incident might be wide-spread across1368different firms or sectors, to provide early warning to other entities1369or to contain an incident.1370 At the opposite end of the spectrum is the SEC disclosure rule1371which requires publicly alerting investors and others of an incident,1372regardless of whether mechanisms are in place--such as a software patch1373or the ability to disconnect from compromised networks--to prevent harm1374from spreading. As described above, this prioritization of investors'1375desire for information over critical incident response activities can1376exacerbate harm.1377 When enacting CIRCIA, Congress intended that it be ``the primary1378means for reporting of cyber incidents to the Federal Government, that1379such reporting be through CISA, and that the required rule occupy the1380space regarding cyber incident reporting.''\10\ Because Congress was1381clear on this point, other Federal agencies should not create their own1382duplicative confidential reporting requirements.\11\ Incident1383notification and disclosure requirements should also be reviewed to1384ensure they are critical to the agency requiring them and do not1385interfere with confidential reporting. Instead, agencies should1386leverage CIRCIA and enter into sharing agreements with CISA to receive1387relevant cyber threat information.1388---------------------------------------------------------------------------1389 \10\ Sen. Rob Portman, Comment Letter on SEC Proposed Rule on1390Cybersecurity Risk Management, Strategy, Governance, and Incident1391Disclosure 4 (May 9, 2022), https://www.sec.gov/comments/s7-09-22/1392s70922-20128391-291294.pdf.1393 \11\ See U.S. DEP'T OF HOUSING & URBAN DEVELOPMENT, FED. HOUSING1394ADMIN., MORTGAGEE LETTER 2024-23, REVISED CYBER INCIDENT REPORTING1395REQUIREMENTS (2024); U.S. DEP'T OF HOUSING & URBAN DEVELOPMENT, GINNIE1396MAE, APM 24-02, CYBERSECURITY INCIDENT NOTIFICATION REQUIREMENT (2024);1397CFTC Operational Resilience Framework for Futures Commission Merchants,139889 Fed. Reg. 4706 (Jan. 24, 2024).1399---------------------------------------------------------------------------1400 consolidate cyber regulatory requirements and supervision1401 Financial institutions are continuously examined by the Office of1402the Comptroller of the Currency, Federal Reserve, and Federal Deposit1403Insurance Corporation, among others,\12\ and often have hundreds of1404examiners on-site to review their cybersecurity practices. According to1405a survey of our member firms, bank chief information security officers1406now spend 30-50 percent of their time on compliance and examiner1407management. The cyber teams they oversee spend as much as 70 percent of1408their time on those same functions. In the lead-up to exams, financial1409institutions routinely receive over 100 requests for information,1410followed by 75 to 100 supplemental requests during an exam. Of those1411requests, firms report that roughly 25 percent duplicate requests from1412other agencies.1413---------------------------------------------------------------------------1414 \12\ Other U.S. financial regulators include the Commodity Futures1415Trading Commission, Consumer Financial Protection Bureau, National1416Credit Union Administration, Securities and Exchange Commission, and1417State banking agencies.1418---------------------------------------------------------------------------1419 The cumulative effect of overlapping exams and regulatory1420requirements has created numerous unintended consequences. First, and1421as noted above, front-line cyber personnel now have significantly less1422time to perform their day-to-day security responsibilities as their1423bandwidth is consumed by compliance work. Relatedly, firms have paused1424or extended time frames for completing strategic program improvements1425to prepare for emerging threats. Finally, staff retention has become an1426issue as financial institutions report morale problems and burnout1427among staff driven by excessive compliance demands and rapid response1428deadlines.1429 Looking forward, there should be a careful review of the current1430regulatory regime to ensure it is calibrated appropriately. This should1431include actively exploring how to consolidate regulatory1432responsibilities in a way that better balances the oversight1433obligations of regulators and the security realities of private1434companies. Moreover, supervisory activities should primarily focus on1435outcomes and not box-checking procedural exercises unrelated to actual1436risk. Structured accordingly, regulators will better understand the1437true cybersecurity maturity of the firms they oversee and regulated1438entities will have the time they need to defend against sophisticated1439and well-resourced foreign threat actors.1440 conclusion1441 We welcome the committee's attention to this important issue. The1442financial sector has and will continue to support confidential1443information sharing to provide early warning and help prevent malicious1444attacks. This includes CIRCIA, which, if appropriately tailored to the1445statute and Congressional intent, will substantially improve awareness1446of cyber threats across the most important sectors of our economy.1447Harmonizing regulatory requirements is not a trivial task, but we are1448committed to working with this committee and other Federal agencies1449like CISA to advance that worthwhile goal.14501451 Mr. Garbarino. Thank you, Ms. Hogsett.1452 I now recognize Mr. Mayer for 5 minutes to summarize his1453opening statement.14541455STATEMENT OF ROBERT MAYER, SENIOR VICE PRESIDENT, CYBERSECURITY1456 AND INNOVATION, US TELECOM, THE BROADBAND ASSOCIATION14571458 Mr. Mayer. Chairman Garbarino, Ranking Member Swalwell,1459Chairman Green, and all honorable Members of the subcommittee,1460thank you for the opportunity to testify today on the critical1461issues of cybersecurity incident reporting and regulatory1462harmonization. We are committed to strengthening the public/1463private partnership to bolster our national security and stay1464ahead of our adversaries. This committee has an extraordinary1465opportunity to reset our national cybersecurity policies in1466ways that directly impact security outcomes.1467 Our Nation is under constant cyber attack with estimates of1468up to $23 trillion in annual damages by 2027, increasing at a1469rate of more than 20 percent per year. We must take immediate1470action to eliminate redundant or conflicting cyber regulations,1471which can consume up to 70 percent of cybersecurity resources.1472By streamlining these requirements, we can free up critical1473resources for threat mitigation and incident response at1474virtually no cost.1475 Let me reaffirm our view that it is essential we fix how1476the Cyber Incident Reporting for Critical Infrastructure Act,1477CIRCIA, needs to be implemented. While well-intentioned, it is1478essential that we refine its execution to ensure consistency1479with the law's original intent, specifically key terms such as1480``covered incident,'' ``covered entity,'' and ``reasonable1481belief'' must be clearly defined. The liability protections1482designed to safeguard cyber attack victims and promote candid1483reporting must be strengthened. As of today, none of these1484fundamental issues have been meaningfully addressed in a manner1485visible to industry, nor has our sector been substantively1486engaged in addressing these concerns.1487 We urgently need an ex parte process, which is to say, a1488formal, transparent, and common process that encourages CISA to1489hear and consider industry perspectives. In fact, USTelecom1490spearheaded a letter of 21 organizations that formally1491requested that CISA establish such a process, a request that1492was rejected. Had this request been granted immediately, we1493would've already been working together to resolve these1494challenges. If we do not act quickly, we will end up with a1495rule that does more harm than good.1496 We must also recognize that this law does not exist in1497isolation. The patchwork of Federal, State, and sector-specific1498cyber incident reporting requirements presents an ever-growing1499burden on organizations attempting to comply with multiple,1500often conflicting mandates. Fortunately, there is strong1501lawmaker interest to harmonize cyber regulations, including1502incident reporting requirements.1503 We believe that the Office of the National Cyber Director1504should play a leading role in rationalizing cybersecurity1505regulations and incident reporting regimes. Solving the problem1506of fragmented State laws will require clear Federal preemption,1507complemented by robust safe harbor provisions. This work must1508be prioritized, as it is directly tied to our national1509security.1510 We believe it is important that Congress acts now. We do1511not have time for further studies, requests for information,1512commissions, or pilot programs. Every moment spent delaying1513reform provides adversaries with additional opportunities to1514undermine our collective security. We must move swiftly and1515decisively to enhance our cybersecurity posture.1516 Major recent cybersecurity incidents have highlighted the1517importance of stronger and more coordinated information sharing1518and incident response partnership between the Federal1519Government and the private sector. Congress advanced that1520project with the Cybersecurity Information Sharing Act of 2015,1521which set to sunset in September 2025. We ask that Congress1522extend the act and establish additional policies to improve the1523public/private partnership.1524 We must also be willing to reconsider policies that have1525failed to produce meaningful security benefits. One such1526example is the Securities and Exchange Commission's cyber1527disclosure requirements, which, rather than enhancing security,1528have inadvertently provided malicious actors with a road map to1529exploit vulnerabilities. These mandates must be reassessed to1530prevent them from serving as a tool for cyber criminals.1531 In conclusion, success in cybersecurity requires close1532collaboration between the industry and Government, including1533Congress and the Office of the National Cyber Director. We must1534act now to ensure that our cybersecurity policies are well-1535reasoned, well-informed, and designed to maximize efficiency1536and effectiveness. By fixing CIRCIA's implementation,1537harmonizing cyber regulations, and eliminating unnecessary1538burdens, we can strengthen our Nation's cybersecurity defenses1539and uphold our commitment to protecting national security.1540 Thank you for the opportunity to testify today, and I look1541forward to your questions.1542 [The prepared statement of Mr. Mayer follows:]1543 Prepared Statement of Robert Mayer1544 March 11, 20251545 Chairman Garbarino, Ranking Member Swalwell, and Members of the1546subcommittee, thank you for the opportunity to testify today on the1547critical issues of cybersecurity incident reporting and regulatory1548harmonization. We are committed to strengthening the public-private1549partnership to bolster our national security and stay ahead of our1550adversaries. This committee has an extraordinary opportunity to reset1551our national cybersecurity policy in ways that directly impact security1552outcomes.1553 Our Nation is under constant cyber attack, with estimates of up to1554$23 trillion in annual damages by 2027, increasing at a rate of more1555than 20 percent per year.\1\ We must take immediate action to eliminate1556redundant or conflicting cyber regulations, which can consume up to 701557percent of cybersecurity resources.\2\ By streamlining these1558requirements, we can free up critical resources for threat mitigation1559and incident response--at virtually no cost.1560---------------------------------------------------------------------------1561 \1\ See The Economist, ``Unexpectedly, the cost of big cyber-1562attacks is falling'' (May 17, 2024).1563 \2\ Chamber of Commerce, Briefing with Majority and Minority Staff1564of Senate Homeland Security and Government Affairs Committee (May 29,15652024).1566---------------------------------------------------------------------------1567 Let me reaffirm our view that it is essential we fix how the1568Cybersecurity Incident Reporting for Critical Infrastructure Act1569(CIRCIA) needs to be implemented. While well-intentioned, it is1570essential that we refine its execution to ensure consistency with the1571law's original intent. Specifically, key terms such as ``covered1572incident,'' ``covered entity,'' and ``reasonable belief'' must be1573clearly defined. The liability protections designed to safeguard cyber1574attack victims and promote candid reporting must be strengthened. As of1575today, none of these fundamental issues have been meaningfully1576addressed in a manner visible to industry, nor has our sector been1577substantively engaged in addressing these concerns.1578 We urgently need an ex parte process--which is to say a formal,1579transparent, and common process that encourages CISA to hear and1580consider industry perspectives. In fact, USTelecom spearheaded a letter1581by 21 organizations that formally requested that CISA establish such as1582process; a request that was rejected.1583 Had this request been granted immediately, we would have already1584been working together to resolve these challenges. If we do not act1585quickly, we will end up with a rule that does more harm than good.1586 We must also recognize that this law does not exist in isolation.1587The patchwork of Federal, State, and sector-specific cyber incident1588reporting requirements presents an ever-growing burden on organizations1589attempting to comply with multiple, often conflicting, mandates.1590Fortunately, there is a strong lawmaker interest to harmonize cyber1591regulations, including incident reporting requirements.1592 We believe the Office of the National Cyber Director (ONCD) should1593play a leading role in rationalizing cybersecurity regulations and1594incident reporting regimes. Solving the problem of fragmented State1595laws will require clear Federal preemption, complemented by robust safe1596harbor provisions. This work must be prioritized, as it is directly1597tied to our national security.1598 We believe it is important that Congress acts now. We do not have1599time for further studies, requests for information, commissions, or1600pilot programs. Every moment spent delaying reform provides adversaries1601with additional opportunities to undermine our collective security. We1602must move swiftly and decisively to enhance our cybersecurity posture.1603 Major recent cybersecurity incidents have highlighted the1604importance of a stronger and more coordinated information sharing and1605incident response partnership between the Federal Government and the1606private sector. Congress advanced that project with the Cybersecurity1607Information Sharing Act of 2015, which is set to sunset in September16082025. We ask that Congress extend the Act, and establish additional1609policies to improve the public-private partnership.1610 Key pillars for improve this partnership include:1611 There Should Be a Single Responsible Federal Agency for1612 Major Cybersecurity Incidents.--In the midst of a major1613 incident, an operator's cybersecurity team is tightly focused1614 on understanding and mitigating the challenge, and may be1615 coordinating with other affected entities and/or with one or1616 more law enforcement or national security agencies. It is1617 practically difficult and often inadvisable to pull away from1618 those operational imperatives to engage in briefings or other1619 general information sharing and analysis activities (which1620 takes substantial time and effort) with multiple Government1621 stakeholders absent concrete benefits to doing so.1622 Accordingly, Congress should ensure a unified, whole-of-1623 Government approach to major cybersecurity incidents: In1624 the wake of a major incident with national security1625 implications, a single ``Responsible Agency'' should have1626 formal responsibility for (i) coordinating with the private1627 sector and (ii) overseeing Government information sharing1628 during a cybersecurity event.1629 Power to Suspend Reporting Obligations.--Congress should1630 grant the Responsible Agency the power to suspend all Federal,1631 State, and contractual reporting obligations upon a finding1632 that doing so is in the national interest. Otherwise, the1633 existing patchwork of reporting regimes (e.g., FCC, SEC,1634 CIRCIA, Government contracts, private contracts) could cause1635 highly sensitive information to be promulgated in a haphazard1636 manner.1637 Expanded Government Sharing of Actionable Cybersecurity1638 Information.--Whether sharing information about a specific1639 incident or a potential or known threat, the Government should1640 focus on getting detailed, actionable tactical information in1641 the hands of the private-sector personnel responsible for1642 protecting communications networks.1643 Security Clearances for Private-Sector Leaders.--Private-1644 sector CISOs and other key cybersecurity professionals1645 should be granted security clearances (subject to1646 appropriate vetting). Security clearances should not be1647 tied to whether an individual is involved in a particular1648 Government project or program.1649 Secure transfer mechanisms.--Congress should fund a1650 streamlined method for Government agencies and the private1651 sector to securely transmit and receive sensitive1652 information.1653 Promote Meaningful Private-Sector Sharing of Sensitive1654 Information.--Policies for promoting information sharing need1655 to promote voluntary private-sector information sharing:1656 Confidentiality of information shared by industry.--Enact1657 legislation that would create major penalties for1658 individuals within the Government that breach1659 confidentiality or share information without authorization1660 during a national security cyber attack investigation. The1661 private sector will not share highly-sensitive information1662 with the Government if there is a risk Government employees1663 receiving the information will leak it.1664 Immunity for information shared by industry.--Establish a1665 strong ``Reverse Miranda'' regime where information shared1666 by a private actor cannot be used against it in any future1667 action or proceeding.1668 Limited number of recipients.--Private actor needs1669 assurances that sensitive information it shares will only1670 be available to a small number of Government officials and1671 companies. Operators will not meaningfully share1672 information if the pool of recipients is too large or1673 includes potentially untrusted persons/entities.1674 We must also be willing to reconsider policies that have failed to1675produce meaningful security benefits. One such example is the1676Securities and Exchange Commission's (SEC) cyber disclosure1677requirements, which, rather than enhancing security, have inadvertently1678provided malicious actors with a road map to exploit vulnerabilities.1679These mandates must be reassessed to prevent them from serving as a1680tool for cyber criminals.1681 In conclusion, success in cybersecurity requires close1682collaboration between industry and Government, including Congress and1683the Office of the National Cyber Director. We must act now to ensure1684that our cybersecurity policies are well-reasoned, well-informed, and1685designed to maximize efficiency and effectiveness. By fixing CIRCIA's1686implementation, harmonizing cyber regulations, and eliminating1687unnecessary burdens, we can strengthen our Nation's cyber defenses and1688uphold our commitment to protecting national security.1689 Thank you for the opportunity to testify today. I look forward to1690your questions.16911692 Mr. Garbarino. Thank you, Mr. Mayer.1693 I now recognize Mr. Schwartz for 5 minutes to summarize his1694opening statement.16951696STATEMENT OF ARI SCHWARTZ, COORDINATOR, CYBERSECURITY COALITION16971698 Mr. Schwartz. Thank you Chairman Garbarino, Ranking Member1699Swalwell, Chairman Green, Members of the subcommittee. Thank1700you for having me here to appear before you today. It's an1701honor to be here to discuss the widely-shared goals of1702harmonizing cybersecurity regulations.1703 My name is Ari Schwartz. I am coordinator of the1704Cybersecurity Coalition, the leading policy coalition1705representing companies that develop cybersecurity products and1706services.1707 As cybersecurity threats continue to grow, calls for1708cybersecurity regulation around the world have increased as1709well. In the United States, choices that Congress made 10 to 151710years ago led most cybersecurity regulations to be overseen by1711the current sectorial regulators. This has the convenience of1712maintaining the current relationship between the regulated1713company and the regulator. Organizations are overseen by1714agencies that know that sector.1715 But each agency is not going to have full expertise in1716cybersecurity. New cross-sector and international regulations1717have continued to grow, making harmonization difficult. But1718it's not impossible. Agencies must work extra hard to ensure1719that regulations can align so we are not overburdening1720organizations and putting so much work on compliance that we1721are draining resources that otherwise could go to actually1722improving security.1723 The example where this is most obvious today is around1724incident reporting. Incident reporting allows agencies to track1725what's happening in and across sectors, and, in the best-case1726scenario, alert potential victims before it's too late.1727However, as DHS pointed out in a report to Congress in 2023, 451728different incident reporting requirements have been created led1729by 23 different agencies. Internationally, the reporting1730regimes have grown equally large. These reports are on1731different time frames, use different types of information, and1732use different taxonomies to describe the information. This has1733led to duplication, misalignment, and general confusion.1734 In 2022, Congress passed CIRCIA, a law intended to have1735critical infrastructure standardized reporting and send it to1736CISA. CISA ran a process to receive comments on how this1737reporting should work and issued a notice of proposed1738rulemaking in 2024. It is the cybersecurity coalition's view1739that the proposed rule did not meet Congress' goal of1740adequately harmonizing incident reporting requirements.1741 First of all, there was a lack of engagement. While CISA1742clearly tried to follow the letter of the law in getting1743comments on the rule making, it failed to adequately engage the1744sectors. The open sessions that were held were rote and did not1745address known concerns of the community. The CISA1746representatives simply repeated the same questions CISA had1747originally posed.1748 Second, there is an overbroad scope in the proposed rule.1749Instead of harmonizing around existing rules or best practices1750identified by other sectors, CISA decided to create a new broad1751definition of covered entities. CISA also decided to create a1752new construct of what triggers reporting and when it needs to1753be reported.1754 Last, there is a failure to streamline the reporting. While1755CISA made some attempts to ensure that the report filed with1756CISA would be shared with others that might require it, the1757proposed rule did not go far enough to demonstrate that CISA1758was attempting to solve the problem of duplicative reporting,1759seemingly placing the onus on the reporting on the1760organizations.1761 We believe that these issues can be addressed if CISA makes1762a commitment to meeting with the sectors. We suggest this be1763done through an ex parte rule-making process using the critical1764infrastructure partnership known as CIPAC. However, we have1765heard that Secretary Noem last week shut down the CIPAC, which1766we think is a mistake for many reasons, with this process being1767a good example, where the CIPAC process can play a critical1768role in the public/private partnership.1769 Finally, while we were talking about the importance of1770sharing information with the Government, I would be remiss not1771to speak up in favor of reauthorization of the Cybersecurity1772Information Sharing Act of 2015. This law has provided the1773ability for companies to share cyber threat information among1774themselves and with Government. It has streamlined the1775definition of cyber threat information and has allowed multiple1776groups to form and to share that information to quickly stop in1777order to respond to incidents. We hope that reauthorization of1778that--of the law is a priority for this subcommittee.1779 I thank you, and I look forward to your questions.1780 [The prepared statement of Mr. Schwartz follows:]1781 Prepared Statement of Ari Schwartz1782 March 11, 20251783 introduction1784 Thank you, Chairman Garbarino, Ranking Member Swalwell, and Members1785of the subcommittee for inviting me to appear before you today. It is1786an honor to be here to discuss the critical importance of harmonizing1787cybersecurity regulations.1788 My name is Ari Schwartz, and I am the coordinator of the1789Cybersecurity Coalition, the leading policy coalition representing1790companies that develop cybersecurity products and services.\1\ In my1791role, I focus on advancing efforts related to regulatory harmonization,1792ensuring that cybersecurity laws and standards are streamlined,1793effective, and efficient for businesses and the public sector alike.1794---------------------------------------------------------------------------1795 \1\ Cybersecurity Coalition is dedicated to finding and advancing1796consensus policy solutions that promote the development and adoption of1797cybersecurity technologies. We seek to ensure a robust marketplace that1798will encourage companies of all sizes to take steps to improve their1799cybersecurity risk management. We are supportive of efforts to identify1800and promote the adoption of cybersecurity best practices, information1801sharing, and voluntary standards throughout the global community. Our1802members include Broadcom, Cisco, Cybastion, Google, Infoblox, Intel,1803Kyndryl, Microsoft, Palo Alto Networks, Rapid7, RedHat, Schneider1804Electric, Tenable, Trellix, Wiz, and Zscaler.1805---------------------------------------------------------------------------1806 Over the past 20 years, Congress has made significant efforts to1807ensure our Nation is protected without also overburdening the companies1808that run our critical infrastructure. Between 2011 and 2015, Congress1809debated legislation that would have centralized control of critical1810infrastructure protection regulatory efforts and instead, chose to1811leave the majority of the control to each sector's existing regulators.1812Congress decided that the sectors had inherent differences--including1813terminologies and requirements--and therefore needed to maintain1814separate regulatory regimes.1815 Meanwhile, efforts to address the evolving cyber threat landscape1816have prompted the development of new sector-specific and cross-sector1817requirements. These requirements apply not only within the private1818sector but also across all levels and branches of Government, both in1819the United States and around the world. While necessary to secure our1820Nation's critical infrastructure and systems, these requirements have1821also resulted in a complicated, fragmented, and duplicative regulatory1822regime. This has created undue burdens and pressures for critical1823infrastructure owners and operators, making compliance both difficult1824and time-consuming. For example, companies face continuous updates to1825mapping exercises for various compliance regimes. Keeping pace with the1826flood of rule making and industry feedback opportunities requires1827resources: time, tracking tools, consultants, security leaders' input,1828and more. It is simply not a good use of limited security resources.\2\1829---------------------------------------------------------------------------1830 \2\ During the last administration, several important steps were1831taken to address this issue: The White House Office of the National1832Cyber Director (ONCD) launched an initiative to review cybersecurity1833regulations, gathering input from stakeholders.1834 Request for Information Opportunities for and Obstacles to1835Harmonizing Cybersecurity Regulations, Office of the National Cyber1836Director, 88 Fed. Reg. 55694, Aug. 16, 2023, https://1837www.whitehouse.gov/wp-content/uploads/2024/06/Cybersecurity-Regulatory-1838Harmonization-RFI-Summary-ONCD.pdf.1839 Senators Peters and Lankford introduced the Streamlining Federal1840Cybersecurity Regulations Act, which sought to establish an ONCD-led1841process for developing a harmonized regulatory framework and review new1842regulations for alignment.1843 S. 4630, Streamlining Federal Cybersecurity Regulations Act, 118th1844Cong., https://www.congress.gov/bill/118th-congress/senate-bill/4630.1845 Meanwhile, across the Atlantic, the European Union has acknowledged1846that its cybersecurity rules have created overlap and burden and is1847looking to streamline existing regulations, reduce administrative1848burdens and ensure a more cohesive approach to cybersecurity. https://1849commission.europa.eu/law/law-making-process/better-regulation/1850simplification-and-implementation_en.1851---------------------------------------------------------------------------1852 cyber incident reporting1853 One area where the burden of regulatory requirements on companies1854unquestionably continues to grow is around cyber incident reporting.1855 In many ways, incident reporting is a perfect demonstration of the1856broader issue. Governments continue to seek ways to utilize incident1857data to quickly spot patterns of incidents and respond to them. In1858order to get that information, there are increasing requests and1859requirements for more detailed incident response data to be sent to a1860growing number of organizations.\3\ As more organizations build1861reporting structures for different purposes, duplication, misalignment,1862fragmentation, and other issues start to set in. This includes concerns1863around the amount and types of data fields, differing taxonomies, time1864frames for reporting, and more.1865---------------------------------------------------------------------------1866 \3\ The 2023 Department of Homeland Security Congressional Report,1867Harmonization of Cyber Incident Reporting to the Federal Government,1868``identified 45 different Federal cyber incident reporting requirements1869created by statute or regulation'' being ``administered by 22 Federal1870agencies'', with another ``7 proposed rules that would create a new1871reporting requirement or amend a current requirement, and 5 additional1872potential new requirements or amendments under consideration but not1873yet proposed.'' https://www.dhs.gov/sites/default/files/2023-09/1874Harmonization%20of%20Cyber%20Incident%20Reporting%20to%20the%20Federal%218750Govern- ment.pdf.1876---------------------------------------------------------------------------1877 Harmonizing cyber incident reporting would bring benefits to both1878public and private-sector efforts to strengthen cybersecurity. It would1879improve coordination and response capabilities, enhance data quality,1880accelerate threat detection and mitigation, and enable more effective1881policy making and resource allocation.1882 The Cyber Incident Reporting for Critical Infrastructure Act1883(CIRCIA)\4\ was enacted in 2022, requiring critical infrastructure1884owners and operators to report cyber incidents and ransomware payments1885to the Cybersecurity and Infrastructure Security Agency (CISA). CISA1886formally solicited input from industry to inform this reporting1887structure, including which entities should report and what type of data1888should be reported.1889---------------------------------------------------------------------------1890 \4\ Pub. L. 117-103 Title V, Div Y.1891---------------------------------------------------------------------------1892 The Cybersecurity Coalition is generally supportive of CIRCIA's1893objectives, and we acknowledge that CISA was given a difficult task to1894develop a reporting regime that encompasses all critical infrastructure1895sectors. Congress specifically required CISA to prioritize1896harmonization efforts to ``avoid conflicting, duplicative, or1897burdensome requirements'' across the sectors. In its proposed1898rulemaking, we do not believe CISA met this essential goal.\5\ In1899particular:1900---------------------------------------------------------------------------1901 \5\ Proposed Rule Cyber Incident Reporting for Critical1902Infrastructure Act Reporting Requirements, Cybersecurity and1903Infrastructure Security Agency, 89 Fed. Reg. 23644, Apr. 4, 2024,1904https://www.federalregister.gov/documents/2024/04/04/2024-06526/cyber-1905incident-reporting-for-critical-infrastructure-act-circia-reporting-1906requirements.1907---------------------------------------------------------------------------1908 Lack of Sectoral Engagement.--CISA did not adequately engage1909 in working with the critical infrastructure sectors to discuss1910 how to best harmonize existing efforts. In particular, despite1911 the explicit mention of the need for ``coordination'' with the1912 Critical Infrastructure Partnership Advisory Committee (CIPAC)1913 and information sharing and analysis organizations in CIRCIA,1914 CISA included almost no means of ex-parte engagement for them.1915 The Cybersecurity Coalition believes that CISA should1916 immediately begin meeting with the Sector Coordinating Councils1917 under the CIPAC and the members of the Council of Information1918 and Sharing and Analysis Center in a coordinated ex-parte1919 process that Congress intended.1920 CISA should also work more closely with the Office of Management1921 and Budget and other Federal agencies to facilitate reciprocity1922 and harmonization to streamline incident reporting under1923 CIRCIA's statutory language. This includes promoting greater1924 collaboration between DHS; Federal agencies; State, local,1925 Tribal, and territorial (SLTT) agencies; as well as1926 international partners.1927 Overbroad Scope.--In its definition of ``covered entities,''1928 rather than relying on existing definitions or trying to1929 coordinate among existing efforts, CISA decided to create a1930 complex new definition. It has two categories: those within1931 critical infrastructure sectors, with exceptions for small1932 businesses and those meeting sector-specific criteria.\6\ In1933 many cases, it may not be immediately clear whether an entity1934 is covered by the proposed reporting requirements but because1935 the requirements focus on size rather than what the company1936 actually does, it almost certainly covers companies who have1937 probably never before been considered ``critical1938 infrastructure.'' We do not think that this was Congress'1939 intent.1940---------------------------------------------------------------------------1941 \6\ 89 Fed. Reg 23644, 23660.1942---------------------------------------------------------------------------1943 Also, mixing the broad scope of covered entities with a very broad1944 definition of ``covered cyber incidents,'' the Cybersecurity1945 Coalition is concerned that this rule may lead to an1946 overwhelming number of incident reports.\7\ This influx of less1947 relevant reports could burden CISA's incident reporting system,1948 requiring significant additional resources for analysis,1949 triage, and transformation into actionable intelligence. While1950 the goal of CIRCIA is to ensure enough data is provided to1951 create a comprehensive picture to inform policy and response1952 actions, we believe that there is a point where too much data1953 creates unnecessary noise that distracts from the core mission.1954 CISA should prove they can effectively work with the enormous1955 influx of data we'd expect they would receive using the1956 existing construction of critical infrastructure and with a1957 more modest definition of types of reports requested before1958 considering expanding their scope.1959---------------------------------------------------------------------------1960 \7\ Cybersecurity Coalition Comments, Request for Information on1961the Cyber Incident Reporting for Critical Infrastructure Act, June 28,19622024, https://cdn.prod.website-files.com/660ec3caef47b817df2800ae/19636684487fa6bfce5ed0c2a12a_Cybersecurity%20Coalition%20%20-1964FINAL%20Comments%20to%20CISA%20re%20CIRCIA%20Proposed%20Rule%206.28.24%-1965 20(2).pdf.1966---------------------------------------------------------------------------1967 The Cybersecurity Coalition believes that CISA should narrow the1968 scope of ``covered entities'' under CIRCIA. Instead of applying1969 reporting requirements to all entities within critical1970 infrastructure sectors, Congress should direct CISA to ``focus1971 on Systemically Important Entities (SIEs) that own or operate1972 critical infrastructure systems and assets whose disruption1973 would have a debilitating, systemic, or cascading impact on1974 national security, the economy, public health, or public1975 safety.''\8\ This would help Congress uphold its original1976 intent to focus on the most essential infrastructure while1977 avoiding unnecessary regulatory burden on less critical1978 entities.1979---------------------------------------------------------------------------1980 \8\ Cybersecurity Coalition Comments, Request for Information on1981the Cyber Incident Reporting for Critical Infrastructure Act of 2022,1982Nov. 14, 2022, https://cdn.prod.website-files.com/1983660ec3caef47b817df2800ae/1984660ec3caef47b817df280233_Comments%20CISA%20CIRCIA-1985%20RFI%20%20Docket%20Number%202022-19551%20-%20CISA-2022-19860010%2011.14.22.pdf.1987---------------------------------------------------------------------------1988 Failure to Streamline Reporting.--The proposed rule lacks1989 clear measures to streamline reporting processes. Although the1990 idea of ``substantially similar'' reporting requirements could1991 help address duplicative reporting across different frameworks,1992 the definition of ``substantially similar'' remains unclear.1993 The proposed rule requires CISA and relevant agencies to1994 establish a ``CIRCIA Agreement'' to ensure their reporting1995 requirements align with this standard. However, CISA retains1996 the authority to limit exceptions for substantially similar1997 reports to agencies with formal agreements. The Cybersecurity1998 Coalition is concerned that this broad and prescriptive1999 approach could reduce reciprocity and create additional burdens2000 for entities striving to align with these standards.\9\2001---------------------------------------------------------------------------2002 \9\ Id.2003---------------------------------------------------------------------------2004 The Cybersecurity Coalition believes that CISA should support2005 efforts to streamline Federal cybersecurity regulations to2006 ensure businesses are not burdened by multiple, conflicting2007 obligations. By passing legislation that promotes the2008 development of standardized incident reporting processes,2009 Congress can make it easier for companies to comply with2010 regulatory requirements while limiting agency overreach.2011 The Cybersecurity Coalition would prefer to see CISA issue a new2012version of the proposed rule that addresses these concerns and then2013receive comments on that draft and issue a final rule in the time frame2014originally proposed by Congress. Unfortunately, Secretary Noem has now2015reportedly disbanded the CIPAC,\10\ which will make getting comments2016from all of the sectors much more difficult. We hope the Secretary will2017reinstate the CIPAC. If not, in order to effectively receive feedback,2018it will likely be necessary for CISA to simply rescind the rule and2019start over. This would be a disappointing outcome considering the2020amount of time already expended on this effort and the fact that CISA2021would likely miss Congress' intended time line.2022---------------------------------------------------------------------------2023 \10\ https://subscriber.politicopro.com/newsletter/2025/03/2024estonias-cyber-Ambassador-weighs-in-00220220.2025---------------------------------------------------------------------------2026 the cybersecurity information sharing act of 20152027 While we are discussing the importance of using data to address and2028prevent cyber incidents, I would be remiss not to mention the2029importance of the Cybersecurity Information Sharing Act of 2015 (CISA20302015).\11\ CISA 2015 provides companies liability protections when2031sharing a very narrowly-defined set of cyber threat information.2032---------------------------------------------------------------------------2033 \11\ 6 USC 1503.2034---------------------------------------------------------------------------2035 We can think of CISA 2015 as lowering the burden on organizations2036by simplifying the way that companies share information amongst other2037companies and with the Government and the purposes of that sharing.2038While CISA 2015 was somewhat controversial at the time of its creation,2039it has been anything but controversial in practice. CISA should be2040commended for the fine job they did with the Department of Justice in2041creating the complicated guidance necessary for CISA 2015.2042 The Cybersecurity Coalition supports the reauthorization of CISA20432015. We urge this committee to take the lead in making its2044introduction and passage a priority. We look forward to working with2045you on this effort.2046 conclusion2047 In conclusion, the path forward in strengthening our Nation's2048cybersecurity lies in harmonizing and streamlining regulations. It is2049critical that we create a regulatory environment that allows2050organizations to focus on meaningful cybersecurity practices rather2051than navigating complex, burdensome, and conflicting requirements. On2052behalf of the Cybersecurity Coalition, I strongly urge Congress to2053continue prioritizing this issue and push CISA to address key concerns2054in CIRCIA, including clarifying the definition of covered entity,2055refining the scope of covered cyber incident, and ensuring reciprocity2056across frameworks.2057 We appreciate the work Congress has done, and we are committed to2058working alongside you to ensure cybersecurity regulations are effective2059and efficient. Thank you for the opportunity to testify. I look forward2060to your questions.20612062 Mr. Gimenez [presiding]. Thank you, Mr. Schwartz.2063 Members will be recognized by order of seniority for their20645 minutes of questioning. I want to remind everyone to please2065keep their questioning to 5 minutes. An additional round of2066questioning may be called after all Members have been2067recognized.2068 I now recognize the gentleman from Tennessee, the Chairman2069of the committee, Mr. Green, for 5 minutes of questioning.2070 Mr. Green. Thank you.2071 First, let me say, the testimony today has been superb. I--2072my questions will be to reiterate points you've made. In fact,2073I just told my senior staffer for cybersecurity to get copies2074of everyone's testimony and provide it at the cyber subs2075meeting. The cyber subs committee, I started this last year,2076some of you may be aware of this, where we meet all the cyber2077subcommittees to try to get a whole-of-Government approach2078here. We're going to send copies of your testimony to every2079cyber subcommittee Member in this Congress. This was excellent.2080Thank you.2081 You know, Congress has a duty--let me make this point:2082Congress has a duty that we have shirked over 40 years in both2083parties and passed off to the bureaucracy. The Constitution is2084really clear. A lot of these things that the administration is2085now closing, Chevron deference, and the Supreme Court have2086ruled it really belonged to Congress in the first place and we2087never should have passed it off to the doggone administration2088in the bureaucracy. Right? So I get that there's some2089frustration that certain things are being closed, but, I mean,2090Constitutionally, we need to do that here. It's a part of our2091oversight obligation. It's a part of our particularly reporting2092and review boards and things like that.2093 I was told yesterday--and I don't know if it's completely2094true. I've got to fact check this, but the VA spends $1 billion2095on compliance. Does that seem reasonable, $1 billion on2096compliance? These conflicting rules and this--all this time, I2097think, Ms. Hogsett, you said 30 percent on actual just checking2098the box compliance and 70 percent on real cybersecurity. Was2099that the ratio you quoted?2100 Ms. Hogsett. Thirty to 50 percent of the chief information2101security officer's time is----2102 Mr. Green. Is on checking the box.2103 Ms. Hogsett [continuing]. Spent on that and 70 percent of2104their team's.2105 Mr. Green. Ridiculous.2106 Let me ask this question: What is the average time to close2107a vulnerability when one has been identified? I--just, give me2108a number of days. I'm going to run the--the average2109vulnerability, closing the door takes how long? Take a guess.2110 Mr. Aaronson. You're going to hate this answer: It depends.2111 Mr. Green. Great.2112 Ms. Hogsett. True. If it's a critical vulnerability firm2113has worked to close that within days if possible. It all2114depends on whether you align----2115 Mr. Green. What is it for?2116 Ms. Hogsett. It would depend on how much control you have2117over it. If it something that resides within a third party, you2118have less control and ability to move quickly to close it.2119 Mr. Green. OK.2120 Mr. Mayer. Yes. I don't want to speculate, sir, on an2121average, but I will tell you that if you look at the recent2122attacks that are coming from nation-states, it's taken weeks,2123months, and it's still a process that is under way.2124 Mr. Green. Yes. Well, I'm not sure we've patched the2125telecom breach yet.2126 Mr. Schwartz. So if we're talking about, like, browsers,2127they can close them in hours. But if you're talking operational2128technology, it takes days.2129 Mr. Green. Days?2130 Mr. Schwartz. Yes.2131 Mr. Green. Yes. SEC pulls the number 4 days out of their2132backside and thinks that they're doing shareholders a positive.2133But when they announce that they've got a hole in the door, in2134the wall, and it's not going to be closed, it invites attack2135from everybody. It's the stupidest thing I've ever heard of.2136 Let me ask this question--we've got to go and figure out2137all this list of duplicity, list of conflicting--how best do we2138as Congress, does this subcommittee and the subcommittees2139across our Congress, figure out all the lists of duplicative2140requirements and contradictory requirements? How do we go get2141this information?2142 Mr. Aaronson. So, first of all, I appreciate what you said2143about the coordination across all the committees of2144jurisdiction. I think understanding--the first thing a cyber--a2145CISA or CSO is going to do is inventory their entire system to2146understand where vulnerabilities might be. I'd say that2147Congress needs to inventory the system, understand where all of2148the regulatory requirements are so that we can start to do the2149hard work of harmonizing.2150 Just to foot-stomp something that you said about the lunacy2151of the SEC rule, adversaries--and to talk about the2152vulnerabilities and a time to patch--adversaries watch our2153response. I understand, you know, the importance of sunshine2154and transparency, but we also have to understand that2155intelligent adversaries are leveraging our transparency when2156perpetrating attacks and seeing how we respond.2157 Mr. Green. Don't we list the identified vulnerabilities2158somewhere in a database, that the bad guys can sit there and2159take a look at, and then challenge and find where that2160vulnerability is anywhere in the system?2161 Mr. Aaronson. Those vulnerabilities become a little less2162important when everybody knows about them, so there is that----2163 Mr. Green. There's always that legacy system that's still2164running, the old thing that nobody catches and it's an open2165door. That's what worries me there, Mr. Schwartz.2166 Mr. Schwartz. I was going to say, I mean, they shouldn't--2167you shouldn't post--this is one of the reasons we say don't--2168that we need a patch before you post a vulnerability. So----2169 Mr. Green. Yes, exactly.2170 Mr. Schwartz [continuing]. The patch has to exist but then2171people actually have to patch.2172 Mr. Green. We've just got to get everybody to download the2173patch.2174 Thank you. I yield.2175 Mr. Gimenez. Thank you to our Chairman.2176 Now I recognize the gentlewoman from New York, the former2177Chair, Ms. Clarke.2178 Ms. Clarke. Thank you very much, Mr. Chairman.2179 I thank Ranking Member Swalwell for letting me waive onto2180today's subcommittee hearing.2181 Thank you to our panelists of witnesses for joining us2182today.2183 Before I begin my formal comments, I'd like to associate2184myself with the sentiments of Ranking Member Swalwell regarding2185Congressman Sylvester Turner. We are grateful for his service2186to the people of Houston, Texas. To his family and loved ones,2187we extend our deepest condolences. May he rest in peace.2188 When I introduced CIRCIA back in 2021 with Ranking Member2189Thompson and Chairman Garbarino, I did so because I recognized2190the important need for increased visibility into the cyber2191incidents affecting critical infrastructure and the importance2192of a central hub for cyber incident reporting in the Federal2193enterprise. I worked with many of the witnesses here today to2194get CIRCIA across the finish line, and I appreciate their on-2195going efforts to make sure that we get the final rule right.2196 I also appreciate Mr. Swalwell's work encouraging CISA to2197effectively engage with the private sector on the rule.2198 I agree with my colleagues and the witnesses before us that2199there are necessary improvements to the proposed rule, but the2200urgency of implementing CIRCIA remains. I hope the new2201administration will work quickly to modify the proposed rule2202and publish a final one without undue delay.2203 I have 2 questions for our witnesses. First of all, to all2204of our witnesses, without a defined--well-defined cyber2205incident reporting rule and harmonization process for CISA, we2206run the risk of agencies across Government issuing a hodgepodge2207of duplicative cyber incident reporting requirements. How will2208scrambling to comply with multiple incident reporting2209requirements affect security?2210 Then, second, many stakeholders have weighed in that the2211proposed CIRCIA rule defined ``covered entities'' and ``covered2212incidents'' too broadly, unnecessarily increasing the burden on2213the private sector and potentially overwhelming CISA with too2214many reports to analyze. Indeed, CIRCIA instructed CISA to2215identify subsets of entities and incidents, instruct--excuse2216me, subject to reporting requirements to avoid that outcome.2217Can you give me your thoughts on that?2218 We'll start with Mr. Aaronson and then work our way across.2219 Mr. Aaronson. So, on the first question, I would just echo2220some of the things that Ms. Hogsett said about the time that2221information security teams are spending on compliance. It's2222somewhere between 30 and 50 percent. As you expand the2223hodgepodge--to use your word--of reporting requirements, it2224only gets more complicated.2225 To your point about the broadness of CIRCIA as it currently2226exists and the uncertainty that surrounds it, taken at its most2227sort-of broad interpretation of what is a covered entity and2228what is a covered incident, we had one of our companies report2229that they thought they would have as many as 65,000 reports2230between 2022 and 2033. I think the number that CISA had said2231would be somewhere in the 200,000 to 220,000 total in that time2232frame, so it seems to be off by--if that's just one company2233taken at a really broad interpretation, it seems to be off by2234an order of magnitude. This goes to the importance of getting2235the definitions and the details right so that we can get some2236signal from the noise and so that CISA can ingest the2237information in a meaningful way.2238 Ms. Clarke. Very well.2239 Ms. Hogsett.2240 Ms. Hogsett. Sure. Just to add to that, and thank you for2241the question, the challenge of responding to multiple2242requirements does have a direct impact on security because it2243is diverting the time and attention away from what we all want2244the cyber professionals to be doing, which is defending their2245networks, kicking out bad actors when there is an incident and2246focusing on that. Instead, they have to divert time away to2247basically make sure they're complying with different legal2248obligations.2249 With respect to the definitions and covered entities within2250CIRCIA and the proposed rule, this committee was very2251thoughtful--and Scott just alluded to it--to make sure that the2252law would be crafted in a way that we get signal from the2253noise. You wanted the incidents that were going to be most2254impactful so that CISA could very quickly have the capability2255to take that information and turn it back around to share with2256other entities that could also be a risk.2257 The very broad scope with which the proposed rule was put2258together would put a lot of noise out there and make that all2259the more challenging. For instance, the definition would2260potentially capture operational outages that have nothing to do2261with the cyber incident, and I don't think that that was really2262what you and the committee had intended in crafting that law.2263 Ms. Clarke. Very well.2264 Mr. Mayer, my time is up.2265 Mr. Mayer. Yes. Thank you, Congresswoman Clarke. I think2266that we have to deal with the fact that the reporting2267requirements right now are extraordinarily fragmented. The CIRC2268itself, Cyber Incident Reporting Council, at the time, in2269September 2023, identified 45 different reporting regimes, 222270agencies, I believe. I can only imagine that number has2271increased since then.2272 CISA has indicated that they expect 300,000 entities to be2273responding to these kind of requests. I can only imagine with--2274in the absence of clear definitions around the terms that you2275folks identified and staying close to the intent, in the2276absence of revising that and refining that and making it2277operationally practical for companies to respond, the system2278will get overwhelmed. The system in Government will get2279overwhelmed, and the system in the operating environment will2280also get overwhelmed.2281 The critical point here is that during a major cyber2282incident when we are in a--essentially in a triage mode, we2283can't take people and divert them from their front-line2284responsibilities to detect the problem, remediate it, and2285respond and recover. So we believe that this particular rule2286needs to be reconstructed to align with your intentions, and if2287it doesn't, we're going to be doing more--as I indicated, it'll2288create more harm than good.2289 Ms. Clarke. Very well.2290 Mr. Schwartz. I agree with everyone on the panel in answer2291to the first question. On the second question, I'll just2292briefly say that on the definition of covered entities, CISA2293decided to kind-of try to narrow the scope by the size of the2294company--by going to the size of the companies, which I think2295does help in terms of removing some of the small, medium-sized2296businesses that we might not want to report, but it doesn't get2297to the risk issue, right. So you're going to have a lot of2298large companies, very large companies that have a lot of2299incidents, getting--echoing what we heard from others here,2300that are going to be reporting a lot that is not of the same2301value as if we did it based on some kind of risk feature.2302 Ms. Clarke. Very well.2303 Thank you for your indulgence, Mr. Chairman. I yield back.2304 Mr. Garbarino [presiding]. The gentlelady yields back.2305 I now recognize the gentleman from Louisiana, Mr. Higgins,2306for 5 minutes of questions.2307 Mr. Higgins. Thank you, Mr. Chairman. I appreciate this2308hearing today.2309 I concur with Chairman Green; it's been excellent2310testimony, and I appreciate it. I'm going to review it very2311carefully.2312 Mr. Chairman, in the 118th Congress, last Congress, I2313introduced a bill, H.R. 101023, the Streamlining Federal2314Cybersecurity Regulations Act, which essentially cut down on2315duplicated or misaligned regulatory requirements and2316authorities on the cybersecurity industry. I'll be2317reintroducing that bill shortly in the 119th Congress, and I2318look forward to my colleagues' support on both sides of the2319aisle with that bill.2320 Because, Mr. Aaronson, how many Federal agencies, how many2321Federal cyber regulations is a typical energy company required2322to report to in a given year, just roughly?2323 Mr. Aaronson. I mean, I'll just give you the agencies that2324we definitely have reporting requirements----2325 Mr. Higgins. That list will be too long to enumerate. But2326you're talking about, just tell America, 2, 4, 10, a dozen?2327 Mr. Aaronson. More than a dozen.2328 Mr. Higgins. More than a dozen. The gentleman said more2329than a dozen cyber regulators require a report from the energy2330industry.2331 Ms. Hogsett, how many Federal agencies does a bank need to2332file away to remain in good cybersecurity standing?2333 Ms. Hogsett. We're similar and that's only at the Federal2334level. You also have States and international requirements to2335adhere to.2336 Mr. Higgins. So at the Federal level, which we control,2337would you concur, Mr. Aaronson, somewhere north of 10 or a2338dozen?2339 Ms. Hogsett. Yes.2340 Mr. Higgins. Thank you.2341 Mr. Mayer, similar question: How many Federal agencies does2342the telecommunications industry have to report to?2343 Mr. Mayer. Yes, I would agree with the number of over a2344dozen, but----2345 Mr. Higgins. Easily over a dozen.2346 Mr. Mayer. Easily over a dozen.2347 Mr. Higgins. Mr. Schwartz, do you have a comment there?2348 Mr. Schwartz. For IT, I would say that it's----2349 Mr. Higgins. It's a lot, right?2350 Mr. Schwartz [continuing]. In the same range, but it's2351spread out because it's people reporting to the different2352sectors.2353 Mr. Higgins. OK. So now that we've clarified that for2354America, the objective here for the U.S. Congress is to reduce2355that mess, so that the cybersecurity industry can actually2356perform its primary mission, which is to protect the Nation and2357the industries of the Nation from cyber attack, which we've2358become increasingly susceptible to as technologies emerge.2359While our cybersecurity industry is busy checking boxes that2360the Federal Government and bureaucracies has imposed upon the2361industry, they have that much less time to spend on that actual2362mission of protecting the Nation, the citizenry, and the2363industries of America.2364 So how many of these agencies that require a report--we've2365agreed it is over a dozen--how many of them have streamlined2366themselves, like coordinated with each other and said, let's2367eliminate this and this and this and combine it into one? Has2368that ever happened, Mr. Aaronson?2369 Mr. Aaronson. The Department of Energy has been fairly2370thoughtful. Because it's our sector risk management agency and2371it's nonregulatory, that has actually helped them to----2372 Mr. Higgins. So within themselves, they've done some2373streamlining.2374 Mr. Aaronson. To help----2375 Mr. Higgins. Across the departments and agencies, have you2376seen a similar effort just organically?2377 Mr. Aaronson. No, certainly not.2378 Mr. Higgins. Thank you.2379 Mr. Aaronson. Your oversight has helped.2380 Mr. Higgins. Ms. Hogsett, has there been any organic effort2381from the bureaucracies to streamline and reduce themselves?2382 Ms. Hogsett. Yes and no. The yes is, when it comes to2383incident notification, we have good coordination across 3 of2384our primary banking regulators. They aligned. There is a single2385standard, single definition, and you provide information to2386one----2387 Mr. Higgins. They look for common definitions?2388 Ms. Hogsett. Yes.2389 Mr. Higgins. This is a good sign----2390 Ms. Hogsett. It is. However----2391 Mr. Higgins [continuing]. Within the banking industry.2392 Ms. Hogsett. It is.2393 Mr. Higgins. But there's a ``however'' here.2394 Ms. Hogsett. There is. That is with respect to incident2395reporting specifically.2396 Mr. Higgins. Ah, for an incident report.2397 Ms. Hogsett. Broader cybersecurity we have even overlap and2398duplication among those agencies.2399 Mr. Higgins. Roger that.2400 Mr. Mayer.2401 Mr. Mayer. Same story. I'm not aware of any major or2402significant----2403 Mr. Higgins. Thank you. It was good to hear about the2404banking industry, but that's per incident reports. That's2405different. That's not total regulatory authority being2406streamlined.2407 Mr. Schwartz.2408 Mr. Schwartz. No. It's just been work to gather that.2409 Mr. Higgins. OK. So, Mr. Chairman, this is why Congress2410must act to bring clarity to the regulatory authority. I will2411hand you for your review, Mr. Chairman, the bill from last2412year. I intend to introduce it in the 119th Congress in a2413slightly refined iteration, and I would appreciate your2414support.2415 Mr. Aaronson, you had mentioned--we haven't had time for2416this question. You said that adversaries watch our response. Is2417it possible at all for the cybersecurity industry to strike2418back? If you said the adversaries are watching you, you must be2419able to identify the bad actor. Can you strike back at all2420against a bad actor?2421 Mr. Aaronson. The private sector--well, I don't want to2422speak for the whole private sector.2423 Mr. Higgins. Private sector.2424 Mr. Aaronson. Electric companies do not want to be in2425offensive cyber engagements. That is the purview of the2426Government.2427 Mr. Higgins. Well, we are going to probably give you that2428opportunity.2429 Mr. Chairman, my time has expired. I will have questions to2430submit in writing to each of these witnesses, and I appreciate2431this hearing, sir.2432 Mr. Garbarino. The gentleman yields back. We probably will2433have a second round of questions if you do--if you have time,2434but we will take them in writing, as well.2435 Mr. Higgins. Thank you. They have to be in writing. I've2436got another committee.2437 Mr. Garbarino. I thank the gentleman.2438 I now recognize the Ranking Member, the gentleman from2439California, Mr. Swalwell, for 5 minutes of questions.2440 Mr. Swalwell. Mr. Schwartz, how should CISA revise its2441comment process to better engage stakeholders, and how would2442you recommend CISA structure additional feedback opportunities2443to maximize stakeholder input without unduly delaying issuing a2444final rule?2445 Mr. Schwartz. Yes. CISA has the tools today to do this, and2446Congress gave them the tools to engage with the private sector2447in a way that they can get direct advice on issues and do it2448under--protected from FACA, protected from Freedom of2449Information Act, so that companies can feel free to share and2450that it only goes into the process of writing this rule. They2451should use that as--to define their ex parte process. It is the2452CIPAC authority that provides them to do that, and that's2453exactly what we recommend that they do.2454 Mr. Swalwell. To each witness--and feel free to jump in----2455 Mr. Mayer. I'll start.2456 Mr. Swalwell [continuing]. A decade ago--actually, sorry, a2457new question for each witness--Congress passed the2458Cybersecurity Information Sharing Act of 2015, which2459facilitates the voluntary sharing of cybersecurity information2460between the private sector and the Government. It expires, as I2461noted in my opening remarks, in September. What are the2462consequences of CISA expiring?2463 Ms. Hogsett.2464 Ms. Hogsett. I'll start. So the CISA 2015 protections2465really forming the foundation for how we collaborate not just2466with Government but also across industry to ensure that we are2467sharing necessary information to protect everybody. So it's a2468key foundation for our collective defense. It provides2469information-sharing protections, liability protections,2470antitrust protections. We've now had the benefit of that for2471the last 10 years, and I think over that time, we've certainly2472seen an increase in collaboration.2473 I think our sector has always collaborated well within2474itself, but the expansion to across sectors and with other2475companies has been very valuable. We would hate to see that2476disappear and that we walk back some of the gains that we've2477made in that space. Also, as we noted earlier, CIRCIA itself2478with respect to incident reporting, refers back to the CISA24792015 protections.2480 Mr. Swalwell. Right.2481 Ms. Hogsett. So as we're getting ready to share more2482sensitive information, more detailed information to the2483Government, we do want to make sure that it is well-protected.2484 Mr. Swalwell. Yes, Mr. Mayer.2485 Mr. Mayer. I'll go. Thank you. So at a minimum, we think2486it's absolutely essential that the CISA 2015 Act be2487reauthorized. As pointed out, I think we've learned things in2488the last 10 years, what has encouraged additional information2489sharing, what has constrained it, so there are opportunities to2490make enhancements improvements in the law.2491 The cost of not doing this is monumental. It will cause2492companies to be very careful about what they submit, reluctant2493to submit with the protections that Heather alluded to, and2494we'll be undermining our national security if we don't have2495something in place to either continue it in its current form,2496but ideally to reflect what we've learned over the past decade.2497 Mr. Swalwell. Yes, Mr. Schwartz.2498 Mr. Schwartz. Yes. We've seen information sharing2499organizations grow around this law, and that they are2500specifically created--the Cyber Threat Alliance, for example,2501is specifically built around this law, that the way that the2502financial sector ISAC shares out with other groups, not2503internally but with other organizations is built around the2504pieces of this law. If this law disappears, they will have to2505redo what they--how they are structured, so we--and we will2506lose critical time just doing that. Then, as well----2507 Mr. Swalwell. I'm OK--I would just say this, I'm OK with2508like--I believe in like the principles of sunk costs, and,2509like, just because you've been doing it doesn't mean that's----2510 Mr. Schwartz. Yes.2511 Mr. Swalwell [continuing]. The best way to do it. But,2512like, is it beneficial is my----2513 Mr. Schwartz. But it will--it will definitely slow and, in2514some cases, totally stop information sharing that has prevented2515threats----2516 Mr. Swalwell. Got it.2517 Mr. Schwartz [continuing]. From--and prevented incidents2518from happening.2519 Mr. Swalwell. Great.2520 Mr. Schwartz. Thank you.2521 Mr. Aaronson. So I want to slide in here. I agree with2522everything that my fellow panelists have said, so I would just2523associate myself with that. Those protections, the--I sort-of2524think of it north/south industry and Government sharing2525information. East/west across critical sectors has really grown2526up because of those protections in CISA.2527 I also want to respond a little bit to something that Mr.2528Higgins was saying. Incident reporting and information sharing2529are both incredibly valuable, but understanding what the2530difference between those 2 things is. Information sharing is2531about on-going threats where we don't have full certainty of2532what an adversary might be doing. Sharing tactics, techniques,2533and procedures across critical sectors so we can all2534collectively defend is incredibly valuable.2535 Incident reporting has value too. Once we know what that2536risk was, helping identify those patterns, helping to socialize2537those broadly, helping Government to set priorities, helping to2538set policy that is informed by what is actually happening in2539cyber space is incredibly valuable. So we like incident2540reporting. We like information sharing. It just needs to be2541done with protections and in an effective way that, again,2542Government can ingest all of this and not put undue burden on2543the people who are just trying to defend networks.2544 Mr. Swalwell. I appreciate that.2545 Yield back.2546 Mr. Garbarino. The gentleman yields back.2547 I now recognize the gentleman from Florida, Mr. Gimenez,2548for 5 minutes of questions.2549 Mr. Gimenez. Thank you very much, Mr. Chairman.2550 Today I had actually a meeting with the airline industry2551and we talked about this issue. We asked about, OK, when they2552have an incident how many different reporting requirements.2553They have at least 10 different agencies that they have to2554report the same incident to, which seems a little bit2555inefficient.2556 So--and I--you know, Mr.--you know, Representative Higgins2557asked the same question. You were saying it's 10, 12, et2558cetera.2559 Would it make sense to have 1 form sent to 1 place and then2560that 1 place disseminate that information?2561 Mr. Mayer. Can I start? It would absolutely make sense.2562It's critical----2563 Mr. Gimenez. We're not going to do it then. OK, thanks.2564You're asking us to do the impossible.2565 So, moving on, how many reportable incidents do you think2566there are? I guess you would know in your particular case, but2567across the United States how many reportable incidents do you2568think there are per day?2569 Mr. Mayer. Per day?2570 Mr. Gimenez. Per day, yes.2571 Ms. Hogsett. What definition are you using, and what2572threshold?2573 Mr. Gimenez. I mean something that requires a report,2574something that requires an industry to write a report. How many2575of those incidents occur per day here in the United States?2576Does anybody have any idea?2577 Mr. Mayer. I would speculate--I'd take a guess here. I2578think over a thousand incidents would be reported daily.2579 Mr. Gimenez. Over a thousand?2580 Mr. Mayer. Over a thousand collectively across the entire--2581our sector.2582 Mr. Gimenez. Just your sector?2583 Mr. Mayer. Just my sector.2584 Mr. Gimenez. His sector. How about banking?2585 Ms. Hogsett. I struggle to answer that because of the2586threshold. You have incidents or events that might occur2587constantly, but they don't necessarily rise----2588 Mr. Gimenez. No, I'm saying report--I'm saying reportable.2589You have to report.2590 Ms. Hogsett. We have notification requirements that are2591private, so I wouldn't even know. A firm wouldn't be able to2592tell me because they're not allowed to.2593 Mr. Gimenez. Can you give me a guess?2594 Ms. Hogsett. I would have to get back to you to have an2595informed response on that.2596 Mr. Gimenez. OK. How about an uninformed response? Just,2597you know, give me a swag, OK?2598 Ms. Hogsett. Honestly, I hesitate.2599 Mr. Gimenez. OK. What about--OK. And energy?2600 Mr. Aaronson. So the same thing Ms. Hogsett said. There are2601wildly different reporting requirements. There are some that,2602you know, a pretty low bar. There are some that have an2603extremely high bar.2604 I can go back to the statistics that I know from one2605company that did a relatively deep dive on its reporting2606requirements, especially pursuant to CIRCIA's broadest2607definitions, and that was going to be 65,000 over 10 years.2608 So that's one company, 65,000 incidents over 10 years. Six2609thousand five hundred a year, that's 500 a month. Trying to do2610the math here.2611 Mr. Gimenez. Just one company?2612 Mr. Aaronson. That's just one company.2613 Mr. Gimenez. How many companies do you have?2614 Mr. Aaronson. EEI represents 62 investor-owned electric2615companies.2616 Mr. Gimenez. Sixty-two?2617 Mr. Aaronson. That's right.2618 Mr. Gimenez. So could I assume 62 times 500?2619 Mr. Aaronson. Sure.2620 Mr. Gimenez. Per day?2621 Mr. Aaronson. Sure.2622 Mr. Gimenez. Or is that a month?2623 Mr. Aaronson. Well----2624 Mr. Gimenez. Is that a month?2625 Mr. Aaronson. That's also--that's one of our larger2626companies, and that was 500 a month. So maybe it might be easy2627to get to several thousand a month.2628 Mr. Gimenez. Several thousand a month? OK. Does anybody2629know how this data is analyzed? No, nobody knows how it's2630analyzed. So we require you to send a bunch of stuff, but you2631guys don't know how it's analyzed by wherever it is we send it2632to. OK. I'll bet you it's not because of the overwhelming2633volume, all right?2634 So we need to look at that, Mr. Chairman, OK? If you2635require them to do something and then we don't use the data for2636anything, then it's actually worse, right, because you're2637making them do stuff that nobody looks at.2638 So we need to bring some other folks and say, how do you2639analyze all the data that you're getting that you require from2640everybody else to see that actually we're doing any good?2641 Mr. Aaronson, you talked about--we asked about offensive2642capability. You don't have an offensive capability. You don't2643want to use offensive. You don't want to use offensive2644capability.2645 Mr. Aaronson. So that's a pretty thorny topic. I'll go----2646 Mr. Gimenez. No, I just want to ask would you like to use2647offensive capability?2648 Mr. Aaronson. No, the private sector would not like--the2649electric companies would not like to get into----2650 Mr. Gimenez. You just want to get punched over and over2651again, just get punched once and punched again and punched2652again.2653 Mr. Aaronson. Well, this is where the Government comes in.2654So there are 2 ways you deter, right? Deterring, the attack2655does not have the intended consequence. That's on the private2656sector to protect its systems in a way that we can withstand a2657lot of punches.2658 The other way you deter is an attack has a consequence, and2659we would believe that that is fully the purview of our2660intelligence and national security apparatus.2661 Mr. Gimenez. But we don't have the resources to do that, I2662mean, all the time. So we would--what if we charged the--or2663allowed the private sector, with all their resources, et2664cetera, to allow to counter-punch. You wouldn't want that?2665 Mr. Aaronson. So it depends how you define counter-punch. I2666don't want to speak for the banks, but this notion of inking2667the money bag, that could be construed as----2668 Mr. Gimenez. My time is up, and hopefully we'll have2669another round because I really want to get into that one, OK?2670 Thank you, and I yield back.2671 Mr. Garbarino. The gentleman yields back. We will have2672another round.2673 I now recognize myself for 5 minutes of questions.2674 Thank you all for being here today, back again, I guess.2675 In my submitted comment to former CISA Director Easterly on2676the CIRCIA notice of proposed rulemaking, I highlighted that2677Congress did not intend for CISA to subject numerous entities2678to its reporting requirements. Rather, Congress intended for2679CIRCIA to facilitate rapid information sharing, and I--that's2680not being achieved.2681 So we're all here talking about it and what should happen2682with future CIRCIA.2683 Ms. Hogsett, you said BPI sent a letter saying withdraw and2684reissue the rule. Mr. Aaronson and Mr. Mayer both said ex parte2685could be a way to do it.2686 Mr. Schwartz, I'm sorry, I had to leave in the middle of2687your testimony so I don't know what position you took. What2688was----2689 Mr. Schwartz. I'm with ex parte, yes.2690 Mr. Garbarino. Ex parte. So do you believe--I mean, Ms.2691Hogsett, do you believe an ex parte could work? I understand we2692have a timing issue, which is the problem under the law.2693There's a timing issue, and I'm not sure we could meet the2694timing that the law requires if we fully withdraw and reissue.2695 Can ex parte fix the issues?2696 Ms. Hogsett. We would very much support an ex parte2697process. We asked for further engagement and never got it,2698frankly, through the process thus far.2699 We believe that that rule, as proposed, should not be2700implemented, and we would rather take additional time. We are2701prepared to work with CISA and would like an iterative dialog2702to make sure that we get this right. It's too important.2703 We stand ready. We want to see this be successful. So we--I2704think the stakeholder engagement, given the complexities of the2705issue here, we do need that. We just--that rule, as proposed,2706please do not implement that.2707 Mr. Mayer. Mr. Chairman, I think that this committee can be2708very helpful in urging CISA to grant our request for ex parte,2709starting tomorrow. If we can work with the agency and provide2710our expertise and the information about how we operationalize2711incident reporting, that can be integrated into their rules in2712the fall. But if we don't have that possibility to engage with2713them, which they clearly rejected--time and time again we've2714made the request--I think this is going to go down a path2715that's going to be very problematic for CISA and2716extraordinarily burdensome and costly for our sector.2717 Mr. Garbarino. As you said in your testimony, this will be2718more harm than good here.2719 Mr. Mayer. Yes.2720 Mr. Garbarino. I agree with all of you that this rule2721should not be implemented as currently presented, and if it was2722I would lead the effort to CRA it.2723 But it's good to hear that you all think an ex parte could2724work, because I want this to work. I know the Ranking Member2725and the former Chair, Clarke, all want--they want this rule to2726work.2727 This is a big focus of mine, a big focus of now Chairman2728Green's--I'm happy he was here today--harmonization, making2729sure incident and information sharing happens and happens in2730the correct way.2731 So I want this rule to work, and I will be--following this2732hearing I'll work with committee staff on both sides to make2733sure that we reach out to CISA. I know they just nominated a2734new potential director this morning. I'm excited--no, not you.2735But Mr. Plankey I think could do a very good job. I've met with2736him. Director Easterly had very nice things to say about him.2737So I think--I think they may be willing to relook at this and2738move into an ex parte.2739 One of you mentioned something, and I want to go with this2740because we talk about harmonization and how agencies don't2741listen to you all. One of you brought up the SEC rule. Maybe2742all of you brought up the SEC rule, which I've been fighting.2743We passed the CRA out of committee, but because the Senate2744moved so slow our time clock ran out over there. I know the2745Ranking Member was also against it.2746 But one of you brought up the national security concerns,2747ONCD I think has national security concerns with that rule in2748your testimony. Can you speak to those, please? It might have2749been all of you that talked about it.2750 Mr. Mayer. It may have been me who brought that up.2751 So it's a perfect example of rules that don't add to2752security and, in fact, create vulnerabilities, as I mentioned.2753Bad guys, cyber criminals, enterprises can manipulate the2754process of disclosure in ways that certainly were not intended2755and will not be helpful.2756 So, from a national security perspective, that particular2757rule, I am not sure it does anything to enhance our national2758security.2759 Mr. Garbarino. Ms. Hogsett.2760 Ms. Hogsett. I would actually say it probably harms our2761national security. I think this is the challenge that we've2762kind-of talked about now here is you have independent agencies2763that are doing something within their narrow lane. So for the2764SEC, they think that investors need to know this information.2765 I think we would argue that investors aren't really2766utilizing this information. It's not helpful to them. It's2767actually putting them at greater risk. But because an agency2768continues to look without somebody at the top sitting across2769and exercising oversight to say, does this really make sense,2770is it in the best interests of the Nation, we wind up with a2771lot of these duplicative, overlapping, deeply harmful rules.2772 So, to the extent that Congress and this committee is ready2773to engage and help lead this effort, we do need an overall view2774to look at what is helpful versus what is harmful, and the SEC2775rule is classic of what is harmful.2776 Mr. Garbarino. I appreciate that. When I had Chairman2777Gensler in front of Financial Services, I asked him which was2778more important, investor knowledge or--if investor information2779was more important than national security. He said no.2780 So I think now it's time for the new SEC to look at this2781rule and correct it, because I've been told by people at CISA2782and industry that they've had to stop sharing information2783before, timely information, in order to comply with the SEC2784rule. That is not good for anybody.2785 I believe everybody who's been here for first round is2786done, so we're going to start a second round of questions.2787 I recognize the Ranking Member from California, Swalwell,2788for his second round.2789 Mr. Swalwell. I appreciate that, Chairman.2790 Last week, the Secretary of Homeland Security disbanded2791more advisory committees at the Department, including CIPAC,2792the Critical Infrastructure Partnership Advisory Committee. For2793over 15 years, CIPAC has played a significant role in the2794implementation of the National Infrastructure Protection Plan2795and has facilitated coordination of critical infrastructure2796protection and resilience activities across all levels of2797Government and in partnership with the private sector.2798 How will a termination of CIPAC affect the coordination of2799critical infrastructure protection activities? I'll just go2800across the witness table.2801 Mr. Aaronson.2802 Mr. Aaronson. Thank you, Ranking Member Swalwell.2803 So the answer is it will depend on what it ultimately is2804replaced with. I understand every new administration gets the2805privilege of populating advisory committees. CIPAC is not an2806advisory committee. It is an authority that the Secretary of2807Homeland Security has to facilitate public-private partnership.2808 To all the discussion we had about offensive versus2809defensive capabilities and resilience and the fact that2810industry and Government, again, 90 percent--as I mentioned in2811my opening comments, 90 percent, give or take, of critical2812infrastructure is owned by the private sector, this is a team2813sport.2814 CIPAC is the rule book for how that--how those teams,2815industry and Government, can work collaboratively with2816protections, with the ability to have on-going dialogs, with2817sector coordinating councils that facilitate information2818sharing to prepare for and respond to all of these hazards.2819 I will say the Electricity Subsector Coordinating Council2820has been a CEO-led body since after Superstorm Sandy in 2012.2821This isn't just about cyber. This is about storms and physical2822threats and all the things that can impact critical2823infrastructure, which impact our ability to provide services to2824customers and communities across the United States and be2825prepared for all of these risks. CIPAC or something like it is2826vital to our ability to use that partnership effectively.2827 Mr. Swalwell. Does anyone have an answer different than2828that that they want to add?2829 Mr. Schwartz. I'll just add that CIPAC is different. I2830strongly agree with Chairman Green's comments. There are too2831many advisory committees, and DHS has too many advisory2832committees. Getting rid of some of them made sense. As Mr.2833Aaronson said, this is not an advisory committee, right? It has2834the word ``Advisory Council,'' but it's not an advisory2835committee.2836 The sectors organized themselves, right, and have their own2837bodies that then meet with the Government. That comes with the2838protections that that can happen in a way that provides for2839open discussions. We get more information from the Government2840because it exists. It is a good two-way conversation. It's been2841successful.2842 All the nice things you've said about JCDC earlier, I agree2843with those. This is the policy equivalent of that, and it goes2844back even further and it's in some ways--we can talk about more2845success stories from it. That's all.2846 Mr. Swalwell. Mr. Aaronson, I want to go back to something2847that Mr. Gimenez brought up, because I've thought about this2848for many years. I have a Congressional district that has a lot2849of tech and biotech companies, large and small, headquartered2850there, and they get hit all the time. I have Cowbell Cyber2851headquartered there. They do cyber insurance.2852 It's long frustrated me knowing the limited resources that2853we have at Cyber Command and at the Bureau and at the NSA and2854CIA. I get the hesitancy for a business, even a large energy2855company, to go on offense. I'm imagining the concern is that if2856you do that, you're still going up against a large nation-state2857that could take you out. But--and then you're looking at forced2858retirements at some of these agencies that are happening right2859now, and so the resources are going to get even thinner.2860 Is there an environment where we could credential third-2861party cybersecurity contractors who could be offensive, and2862that could be utilized by small- and medium-size businesses,2863again, credentialed by the Government, bonded and insured, but2864also with liability protections that they would probably need2865to operate.2866 It just seems, as Mr. Gimenez said, you're just getting2867punched in the face right now, and the best you can do is put2868up your hands and like protect yourself, but you're not really2869able to punch back. I don't know what the deterrent is on the2870other side if the U.S. Government isn't able to punch back2871against all those entities.2872 If the Chairman would indulge me for his answer.2873 Mr. Garbarino. Absolutely.2874 Mr. Aaronson. It's something I'd want to take back to the2875sector. I think there's 2 concerns. You highlighted 1 of them,2876which is if you are punching back, now you are in effectively a2877fight with a potentially very well-resourced nation-state. As2878we've talked about, we're--many electric companies are2879resource-constrained even on defense. EEI's member companies,2880investor-owned electric companies, have a little bit better2881resource, but there's cooperatives and municipals across the2882sector as well. It could be--that's daunting. So that's one set2883of concerns.2884 The other is not quite in response to what you said, but an2885escalating cyber war perpetrated by the private sector might2886have some unintended consequences. So it goes back to this2887being the team sport and the value of CIPAC and the value of2888CISA 2015 and the value of industry-Government partnership.2889 Industry can be both defensive and resilient. So that the2890attack may happen, but we'll still be operational. We would2891really rely, much like we would in any land war, on our2892Government for it to be responsible for national security.2893 Mr. Swalwell. I understand that concern. I guess the way I2894look at it, though, is it's not as if the resources that we2895have in the Federal Government are decreasing cyber attacks.2896It's actually going in the opposite direction. More and more2897people are getting hit.2898 I'll yield back. I imagine Mr. Gimenez may go back.2899 Mr. Garbarino. The gentleman yields back.2900 I now recognize Mr. Gimenez from Florida for a second2901round.2902 Mr. Gimenez. Thank you. Thank you for the tag team. Here we2903go. OK.2904 Look, the only way that you're going to stop this is if the2905offensive party fears more the retaliation than what we do is2906just put up our hands and, gee, I hope you don't hurt me too2907bad.2908 If you do that, just like nations, nations go to war. When2909they find somebody weaker, they're going to go to war and take2910it over. They find you just sitting there, OK, please don't hit2911me, they're going to hit you because there's no repercussion2912for it. There's no consequences for their action.2913 So everything we've done, have cyber attacks been reduced?2914Are they going down or are they going up?2915 Mr. Mayer. They're going up.2916 Mr. Gimenez. They're going up. So whatever we're doing2917isn't working. Why? Because there's no consequences to their2918action.2919 So eventually, we're going to have to go on offensive, and2920it's going to have to hurt them as much as it hurts you or2921actually maybe hurt them worse than what they hurt you.2922 Yeah, you know, we in the Federal Government, we are not2923sourcing or putting up the necessary folks that it needs in2924order to protect you, because it's such a big domain. I think2925that the private sector, with its resources, both in terms of2926people and money, is going to have to be the way to go.2927 How much is cyber attack, how much is that costing you? How2928much is it costing you all to protect against it or the damages2929caused by cyber attacks?2930 Mr. Mayer. We're in the hundreds of millions of dollars of2931investment in cybersecurity technology and defensive2932capabilities.2933 I will say that on the issue of what comes under the2934umbrella of active defense, there's a range of options. The2935most extreme one is letting private sector engage in hack2936backs.2937 I think the issue is Government is doing something. They2938empowered U.S. Cyber Command to engage in offensive2939capabilities. We would support them in any effort where we have2940certain assurances and there are guardrails.2941 What we don't want to do is deputize a front-line2942practitioner to respond in haste to an attack where we may not2943have the right attribution or there could be substantial2944repercussions.2945 So this is an area that requires real close collaboration2946with Congress, with the intelligence community, with U.S. Cyber2947Command. I mean, we have to do that. I know----2948 Mr. Gimenez. The only way that you're ever going to be2949assured, OK, that you're not--it's not going to have dire2950consequences is that you have to have a mutually assured2951destruction, OK?2952 Mr. Mayer. The Government can do that.2953 Mr. Gimenez. Well, I'm not sure they can, OK? So, you know,2954that's what worked. That was--you know, the MAD theory actually2955kind-of worked, because if you know that I can take you--if you2956do something to me I can destroy you too, you probably aren't2957going to pull that trigger, all right?2958 If the other side feels that they can continually just2959hammer you and keep you in business, because they want you in2960business because they want to have the revenue and all that,2961but eventually when a nation-state says, OK, we're going to do2962the knockout blow and we don't have a knockout blow in2963response, they're going to knock you out, all right?2964 So I don't know the best way. Maybe it is that we do2965something where we have this Cyber Force. You know, we have the2966Space Force now, now we have the Cyber Force that has offensive2967capabilities somehow funded through industry, or we have a2968third-party, you know, entity funded by industry that is2969deputized or given a warrant whenever there is--a retaliatory2970strike is authorized. Because, frankly, I just see this2971spiraling completely out of control.2972 So anybody have any comments on that?2973 Ms. Hogsett. I'll comment. I think what you're getting at2974is the need to use all the tools we have in the toolbox,2975whether that's offensive, defensive, diplomacy.2976 Mr. Gimenez. Yes.2977 Ms. Hogsett. One of the things Robert actually noted is the2978need for greater operational collaboration between industry and2979Government. Our firms will see things on their networks, but2980they don't necessarily have attribution that it is a specific2981national security threat actor. They would welcome a greater2982ability to work and share that with the appropriate authorities2983in Government to get feedback on that.2984 Oftentimes, we think that there are things we see, there2985are things that Government sees that if we both knew what was2986happening we could better direct some of our activities. I2987think that would be to us the next step to really try to drive2988at combating this where it's happening.2989 Mr. Gimenez. Mr. Chairman, my last comment--and I'm a2990little bit over time--is that this is--it's going to be an2991everybody, you know, on board effort, the Government and the2992private sector.2993 Just like we fought the last world war, right? Everybody2994got on board and we're fighting, we're going in the same2995direction. I think that this is where it's heading, anyway.2996 I yield back.2997 Mr. Garbarino. The gentleman yields back.2998 I now recognize the gentlelady from New Jersey, Mrs.2999McIver, for 5 minutes of questions.3000 Mrs. McIver. Thank you, Mr. Chairman. Thank you, Ranking3001Member, and to the witnesses for joining us today on a nice3002day. Thank you for being here.3003 A strong and timely cyber incident reporting framework is3004critical to our national security, which I'm sure you've heard3005multiple times and has been mentioned multiple times in today's3006committee hearing.3007 CISA must move quickly to establish a process that engages3008the private sector, aligns with the distinct regulations and3009meets Congressional intent, all without delay. But we cannot3010achieve this without a robust Federal work force.3011 With staff and resources being cut each and every minute,3012it's crucial we support the personnel needed to get this done.3013In order to properly implement CIRCIA--make sure, because3014CIRCIA and CISA kind-of gets me tied up--we'll need to have the3015staff and resources to process and analyze incident reports.3016 I am concerned that any cuts to CISA's funding or staffing3017could leave it without the capacity to properly implement this3018crucial new program. To each witness, how important is it that3019CISA be adequately staffed and resourced to implement CIRCIA?3020What kind of funding and staffing is most important to properly3021implement?3022 Mr. Schwartz. I would say it's taken a long time to get up3023to this point where we have adequate staffing at CISA, and we3024are concerned about cuts to CISA and what the impact will be,3025especially as they get more information like this.3026 There is an effort to tie all the information together that3027they're getting from inside the Government, from contractors,3028and this information together.3029 Being able to analyze that is going to be a big. It's going3030to take a lot--it's going to use a lot of AI, but it's also3031going to use a lot of human resources as well.3032 Mrs. McIver. Thank you.3033 Mr. Mayer. I would say it's not in my purview in terms of3034telling the Federal Government how to organize themselves right3035now. But we will continue to engage them. I think, for example,3036the partnership, if the rules are written in a way that is3037consistent with the intent of Congress, we could significantly3038reduce the amount of noise that would be generated in this3039information-sharing process. I think there would be3040opportunities for efficiency associated with getting back to3041that original intent.3042 The other thing I'm just going to use this as an3043opportunity to share with you, that we talk about incident3044reporting, but it's connected to incident response and it's3045connected to how we engage in this process.3046 One of the things I think we need help from you and3047potentially with ONCD is to have a single point of contact3048during a major crisis. Because right now the experience has3049been we're getting inundated with multiple agency requests3050during the crisis. We're even getting multiple requests within3051the Department, and then we're getting multiple requests to3052different pieces, parts of our operators or service providers.3053 That has to stop. We have to really rationalize that and3054ask ourselves some serious questions here about how to organize3055this effort, how to engage in the appropriate information3056sharing.3057 The last thing I'll say is, when it comes to CIRCIA, there3058was an assumption that there would be reciprocity, and we still3059have that assumption. So the benefit of submitting information3060is so the Government in real time or as quickly as possible3061comes back to us with mitigation guidance, new information on3062how to protect our networks.3063 There's a lot of work to do here. I'm hearing that there's3064a lot of alignment in this subcommittee around how to reduce3065the inefficiencies associated with all of this.3066 So we look forward to working with you, and hopefully we'll3067be working with CISA shortly on how to remedy some of the3068infirmities in the CIRCIA rule making.3069 Mrs. McIver. Thank you so much for that, Mr. Mayer.3070 I would assume that getting 1 point of contact would not be3071that difficult. Thank you.3072 Mr. Mayer. You would think.3073 Ms. Hogsett. We certainly want CISA and CIRCIA to be3074successful, and we are committed to that.3075 For CIRCIA to work, CISA will need certain capabilities.3076That's not only technological, but also there is a human3077element to that. So we look forward to engaging with the new3078leadership once it is--once they are appointed and confirmed.3079 Mrs. McIver. Thank you for that.3080 Mr. Aaronson. The only thing I'd add, so people, processes,3081technology are going to be critical to the success of CIRCIA3082being implemented effectively. Let's not forget about the3083security of this really critical information.3084 As incident reports are shared, that can be a road map to a3085potential threat actor. So we need to make sure that we're not3086just collecting this information but protecting it as well.3087 Mrs. McIver. Thank you so much to each of you for those3088responses.3089 With that, I yield back, Mr. Chairman.3090 Mr. Garbarino. The gentlelady yields back.3091 I now recognize myself for a second round of questions.3092 Chairman Gimenez brought up before attacks are going up and3093you agreed, but are successful attacks going up or is the work3094that you all are doing on the Sector Coordinating Councils and3095preparation and work with CISA--I know attacks are going up,3096but are we seeing positive results from all the information3097sharing and the work that you're doing amongst each other?3098 Mr. Schwartz. There are a lot of reports out there and they3099say different things. So some reports I've seen tend to suggest3100that we are being--that we are more successful and that the bad3101guys, there's just a lot more attacks so, therefore, the number3102of incidents goes up with it.3103 Some have shown that in certain areas there are more3104successful attacks than there used to be, and so then we have3105to move more resources over to those.3106 Mr. Mayer. What you propose and what you're discussing is3107there's a counterfactual element here in that we don't know3108what would happen in the absence of doing some of these3109activities.3110 But I would say there's a lot of redundancy. There are a3111lot of reports that are produced within the Government that, in3112our view, don't lend themselves to security improvements. So we3113have to get better at thinking about how we use Government3114resources, how we use industry resources, focusing on what is3115the expected outcome that we're looking for. That will fix, I3116think, a lot of the noise in the system.3117 Ms. Hogsett. I think there are mixed signals. I think it's3118hard not to overlook the fact that we are increasingly being3119attacked by nation-states.3120 You have private industry that has very strong, very3121powerful nation-state actors infiltrating their systems. Even3122the best, most sophisticated private firm is going to struggle3123to deal with that.3124 So I will say I think our capabilities have certainly3125improved. Our information sharing has improved. We can respond3126faster when things occur.3127 We within the banking sector continue to see certain3128challenges and weak spots with third parties or vendors that we3129rely on, things that cut across multiple sectors and can be3130embedded in your infrastructure. Those areas can still be very3131challenging to deal with.3132 Mr. Aaronson. I think Ms. Hogsett put it really well there,3133so I'll just associate with that.3134 I'll give another example, though, of some really effective3135coordination that's happening where a nation-state may be3136responsible for an attack, private sector sees it, develops3137mitigation strategies, socializes those, and then works with3138Government to kind-of load the gun back for potential offensive3139operations should it become necessary.3140 We've heard about all the different typhoons that are out3141there. Volt Typhoon was something that was impactful to--could3142have been impactful to the electric power sector; but because3143of industry being on the defensive and working with and across3144the Energy Threat Analysis Center and a lot of our partners in3145Government, we were able to identify that, develop a3146remediation strategy and socialize those for the benefit of all3147electric power sector participants.3148 Mr. Garbarino. Thank you very much. I just want to say for3149the record I am supportive of Extending the Cyber Information3150Sharing Act of 2015, however we get that done, whether we3151include CISA actually in the legislation of the text, who is3152the priority lead. I just want to make sure we get it in front3153of the right committee in the Senate so it doesn't get bogged3154up like CIPAC did.3155 I also want to say that you all brought--you listed some3156grave concerns today with CIPAC being disbanded. I mean, I've3157met with--Mr. Mayer, we've met and you've testified twice. You3158are the head of the Sector Coordinating Council. I have met3159with Ron Green, who's Financial Services, and Pedro Pizarro.3160They've already reached out. Edison International has already3161reached out to have a meeting.3162 So I'm going to look into this and hopefully speak to the3163administration and try to fix this, because this is something3164we don't want industry not sharing information with us. We3165don't want industry not sharing information with each other,3166because when that happens it just increases the vulnerabilities3167that are out there.3168 This is where I want to get to. There is a lot of--Mr.3169Mayer, you said it. There is a lot of duplicative paperwork and3170rules out there. You know, the idea behind CIRCIA was to get3171some harmonization on incident reporting, but that's not all we3172deal with.3173 CIRCIA doesn't really have the teeth, though, to force3174other agencies to do it. Who does? I mean, who do we have run3175the harmonization effort? I think you said ONCD before, but3176who's got the actual juice to make these agencies fall in line?3177 Mr. Mayer. That's a great question.3178 Mr. Garbarino. You can all go.3179 Mr. Mayer. Quickly. So this is the problem. We have3180multiple agencies committed to a mission. Cybersecurity has3181become an interesting area for their involvement. A lot of it3182is duplicative.3183 We think that the was Office of the National Cyber3184Director, consistent with its statutory responsibility to3185coordinate some of these responsibilities, can play a3186significant role going forward in rationalizing this effort.3187 In the absence of that, we're going to be still dealing3188with all of these silos, multiple reporting requirements, and3189they're just going to be duplicative and not effective.3190 Ms. Hogsett. At this point, I think we need White House-3191level leadership, because that's really the top-down to really3192effect change here. We are seeing some signs that it looks like3193the Office of Management and Budget may get more involved in3194this.3195 So I think between OMB, Office of the National Cyber3196Director, which did do quite a bit of work on this to sort-of3197socialize the problem, the Cyber Incident Reporting Council3198that you all authorized in CIRCIA has put a lot of information3199out there. We just need someone sitting at the top to say, you3200guys need to rethink this.3201 Mr. Aaronson. Congressional oversight is incredibly3202valuable. I don't know what the number is these days, but at3203one point it was like 37 different committees and subcommittees3204had responsibility for cyber in some way.3205 I think that work that you guys are doing to coordinate the3206cyber subcommittees across Congress and then work with the3207agencies of jurisdiction to also harmonize, there's value there3208too.3209 Mr. Schwartz. I agree on the OMB and ONCD approach. I think3210that's the way to go.3211 Mr. Garbarino. Chairman Green is doing a great job, working3212with the--getting the committees of jurisdiction together. But,3213yes, I agree with you all. We need someone to be able to tell3214these guys to fall in line. We didn't really see that. We3215haven't seen that since I've been here.3216 We need to keep up our oversight, but I promise we're going3217to work on ex parte for the CIRCIA rule, hopefully get that3218fixed. We will continue working on harmonization. I know the3219committee is working on a report that we can hopefully get to3220the administration, and they can start acting on making your3221lives more focused on cybersecurity and not finishing a report.3222 So, with that, I want to thank the witnesses for their3223valuable testimony and the Members for their questions.3224 The Members of the committee may have some additional3225questions for the witnesses, and we would ask the witnesses to3226respond to these in writing. Pursuant to committee rule VII(E),3227the hearing record will remain open for 10 days.3228 Without objection, the committee stands adjourned.3229 [Whereupon, at 11:43 a.m., the subcommittee was adjourned.]32303231 A P P E N D I X I32323233 ----------32343235 Statement of CTIA--The Wireless Association3236 March 11, 20253237 CTIA--The Wireless Association (``CTIA'')\1\ is pleased to submit3238this statement for the record in the hearing of the Subcommittee on3239Cybersecurity and Infrastructure Protection, Regulatory Harm or3240Harmonization? Examining the Opportunity to Improve the Cyber3241Regulatory Regime.\2\ This hearing is timely and of critical3242importance, given that there is much work to be done before the3243Cybersecurity and Infrastructure Security Agency's (``CISA'' or3244``agency'') can address stakeholder concerns and finalize its proposed3245Cyber Incident Reporting for Critical Infrastructure Act3246(``CIRCIA'')\3\ regulations.3247---------------------------------------------------------------------------3248 \1\ CTIA--The Wireless Association (www.ctia.org) represents the3249U.S. wireless communications industry and the companies throughout the3250mobile ecosystem that enable Americans to lead a 21st-Century connected3251life. The association's members include wireless providers, device3252manufacturers, suppliers as well as apps and content companies. CTIA3253vigorously advocates at all levels of government for policies that3254foster continued wireless innovation and investment. CTIA represents a3255broad diversity of stakeholders, and the specific positions outlined in3256these comments may not reflect the views of all individual members. The3257association also coordinates the industry's voluntary best practices,3258hosts educational events that promote the wireless industry, and co-3259produces the industry's leading wireless tradeshow. CTIA was founded in32601984 and is based in Washington, DC.3261 \2\ Regulatory Harm or Harmonization? Examining the Opportunity to3262Improve the Cyber Regulatory Regime: Hearing Before the H. Homeland3263Sec. Subcomm. on Cybersecurity and Infras. Prot., 118th Cong. 1 (2025)3264(``Regulatory Harm or Harmonization'').3265 \3\ Consolidated Appropriations Act, 2022, Pub. L. No. 117-103,3266div. Y, Cyber Incident Reporting for Critical Infrastructure Act, 1363267Stat. 49, 1038-59 (2022), https://www.congress.gov/117/plaws/publ103/3268PLAW-117publ103.pdf (codified at 6 U.S.C. 681b et. seq).3269---------------------------------------------------------------------------3270 CTIA welcomes this opportunity to provide input to the committee to3271add the perspective of the wireless industry on CIRCIA specifically and3272cybersecurity policy more generally. CTIA and its members are invested3273partners with the Federal Government, developing operational and policy3274solutions on cybersecurity for decades. And CTIA members contend with3275duplicative, inconsistent, or contradictory incident reporting and3276other cybersecurity requirements and regulatory frameworks from3277multiple Federal agencies and an array of State entities. Based on this3278experience and expertise, CTIA urges Congress to consider how CISA can3279better fulfill its mission to help critical infrastructure owners and3280operators prepare for and respond to significant cyber incidents in an3281environment marked by serious nation-state adversary activity. In3282particular, we encourage Congress to:3283 Help facilitate a forward-looking, stronger, and more3284 coordinated approach for the U.S. Government to respond to3285 serious cybersecurity incidents that have national security3286 implications, including promoting meaningful and actionable3287 information sharing on these sophisticated and sustained cyber3288 intrusions and attacks between industry and Government, without3289 undue regulatory requirements or liability exposure for3290 industry.3291 With respect to the on-going CIRCIA rule making, carefully3292 evaluate and oversee the agency's decisions to: (1) Ensure a3293 more focused and harmonized cyber incident reporting framework3294 that allows companies that are victims of cyber incidents in3295 this growing threat landscape to focus on critical remediation3296 and response activities, rather than navigating overbroad3297 reporting requirements; and (2) enable stakeholder engagement3298 and collaboration through an ex parte process to reorient the3299 direction contemplated in CISA's Notice of Proposed Rulemaking3300 (``NPRM'').\4\3301---------------------------------------------------------------------------3302 \4\ CISA, Cyber Incident Reporting for Critical Infrastructure Act3303(CIRCIA) Reporting Requirements, Notice of Proposed Rulemaking, 89 Fed.3304Reg. 23644 (Apr. 4, 2024) (``CISA NPRM'').3305---------------------------------------------------------------------------3306 the wireless industry has been a leader on cybersecurity enhancement3307 and collaboration3308 CTIA has been engaged on cybersecurity policy for decades, bringing3309together industry stakeholders to address issues in multiple fora.3310CTIA's Cybersecurity Working Group (``CSWG'') convenes all parts of3311wireless--service providers, manufacturers, and wireless data,3312internet, and applications companies--to facilitate innovation,3313research, and cooperation in response to threats.\5\3314---------------------------------------------------------------------------3315 \5\ See CTIA, About CTIA: Cybersecurity Working Group, https://3316www.ctia.org/cybersecurity-working-group (last visited Mar. 11, 2025).3317---------------------------------------------------------------------------3318 Through the CSWG, CTIA and its members have been leaders in3319partnering with the Government. For example, the Department of Homeland3320Security (``DHS'') has long been the sector risk management agency3321(``SRMA'') for the Communications Sector,\6\ and CTIA members have3322worked with CISA and its predecessor agencies for years, including on3323developing cross-sector cybersecurity performance goals (``CPGs'')\7\3324and identifying critical functions and assets for the Communications3325Sector.\8\ CTIA and its members collaborate with a wide array of other3326Federal partners, including the Federal Communications Commission3327(``FCC'') and its Communications Security, Reliability, and3328Interoperability Council (``CSRIC''), the National Institute for3329Standards and Technology (``NIST''), and the White House.3330---------------------------------------------------------------------------3331 \6\ See CISA, Sector Risk Management Agencies, https://3332www.cisa.gov/topics/critical-infrastructure-security-and-resilience/3333critical-infrastructure-sectors/sector-risk-management-agencies (last3334visited Mar. 11, 2025).3335 \7\ Comments of CTIA, Cross-Sector Cybersecurity Performance Goals3336and Objectives, Final CPGs, GitHub Submission (filed Feb. 15, 2023),3337https://github.com/cisagov/cybersecurity-performance-goals/discussions/333840.3339 \8\ CISA, Executive Order 13873 Response: Methodology for Assessing3340the Most Critical Information and Communications Technologies and3341Services (Apr. 2020), https://www.cisa.gov/sites/default/files/3342publications/eo-response-methodology-for-assessing-ict_v2_508.pdf3343(``CISA EO 13873 Response'').3344---------------------------------------------------------------------------3345 CTIA is also a leader in operationalizing security standards for3346the benefit of consumers, manufacturers, and operators. As key3347examples:3348 CTIA manages a 5G Security Test Bed, which brings together3349 ``wireless providers, equipment manufacturers, cybersecurity3350 experts, and academia to demonstrate and validate how 5G3351 security will work, using real 5G networks.''\9\3352---------------------------------------------------------------------------3353 \9\ 5G Security Test Bed, LLC, 5G Security Test Bed, https://33545gsecuritytestbed.com/ (last visited Mar. 11, 2025).3355---------------------------------------------------------------------------3356 CTIA's Internet of Things (``IoT'') Cybersecurity3357 Certification Program establishes a baseline for IoT device3358 security on wireless networks and uses widely adopted standards3359 from NIST, among others.\10\3360---------------------------------------------------------------------------3361 \10\ CTIA Certification, IoT Cybersecurity Certification, https://3362ctiacertification.org/program/iot-cybersecurity-certification/ (last3363visited Mar. 11, 2025).3364---------------------------------------------------------------------------3365 CTIA has been engaged in every major Federal cybersecurity3366rulemaking and policy issue for the last 15 years, including but not3367limited to proceedings at the FCC, the Securities and Exchange3368Commission (``SEC''), the Federal Trade Commission (``FTC''), and the3369Department of Defense (``DoD''). CTIA members know first-hand how the3370agencies are approaching complex questions of cybersecurity and data3371governance in regulation and other activity.3372 Likewise, for more than a decade, CTIA has been engaged in3373legislative discussions about cybersecurity impacting wireless, urging3374Congress for years to preserve and enhance the vital partnerships that3375make effective cyber readiness and response possible. For example, CTIA3376supported the landmark Cybersecurity Information Sharing Act of 20153377(``CISA 2015''), which provides an essential foundation for voluntary3378collaboration on cybersecurity and includes important liability and3379confidentiality protections for private companies who volunteer3380information to DHS.\11\3381---------------------------------------------------------------------------3382 \11\ 6 U.S.C. 681b. CISA 2015 sunsets in October 2025. CTIA3383supports reauthorization of the CISA 2015 with an expansion of the3384range of information and activities protected and additional liability3385protections.3386---------------------------------------------------------------------------3387 As Congress considered cyber incident reporting requirements in3388what became CIRCIA, CTIA, like others in the private sector, urged3389Congress to take a targeted and risk-based approach to reporting that3390focused on the most impactful incidents affecting the most critical3391companies.\12\ CTIA and other stakeholders have called on CISA to do3392the same.3393---------------------------------------------------------------------------3394 \12\ CISA EO 13873 Response, supra note 8.3395---------------------------------------------------------------------------3396 congress has an important role to play to ensure a stronger and more3397 coordinated approach for responding to national security incidents3398 As sophisticated cybersecurity threats--including but not limited3399to threats from nation-state adversaries--continue to pose serious3400cybersecurity and national security risks to the Communications Sector3401and others throughout critical infrastructure, it is critical that the3402Federal Government iterate its deterrence and response approaches and3403establish processes that meet the evolving threats our Nation is facing3404now and will continue to face in the future. Key principles that should3405guide this forward-looking approach include:3406 Coordination among Federal agencies and between Federal3407 agencies and industry must be improved.--CTIA agrees with3408 USTelecom's testimony calling for a single ``Responsible3409 Agency'' that in the wake of a national security event will be3410 responsible for coordinating with the private sector and3411 overseeing Government information sharing with respect to that3412 event.\13\ While the current structure for invoking the Unified3413 Coordination Group (``UCG'') is intended to achieve this goal,3414 there continue to be significant challenges with interagency3415 coordination in the wake of major incidents. Congress should3416 work with the administration to (1) establish a single3417 Responsible Agency when an incident rises to the level of3418 forming a UCG; (2) prohibit duplicative and contradictory3419 requests or investigations from other Government agencies; and3420 (3) establish stronger protections for information that is3421 shared with the Responsible Agency and tighter parameters for3422 how information is shared between the Responsible Agency and3423 other agencies, to ensure that such information is not leaked3424 and is not subject to disclosure under the Freedom of3425 Information Act (FOIA) or State laws.3426---------------------------------------------------------------------------3427 \13\ Regulatory Harm or Harmonization, supra note 2 (Statement of3428Robert Mayer, Senior Vice President, Cybersecurity and Innovation,3429USTelecom, The Broadband Association) (``Mayer Testimony'').3430---------------------------------------------------------------------------3431 Victim companies should not face undue regulatory3432 requirements or liability exposure.--Further, Congress should3433 ensure that victim companies do not face undue, burdensome3434 requirements, which only serve to divert resources away from3435 responding to and mitigating the impacts from the incident. To3436 this end, and as USTelecom testified,\14\ Congress should3437 ensure that the Responsible Agency has the authority to suspend3438 all Federal and State reporting requirements, upon finding that3439 doing so in the wake of a national security incident serves the3440 national interest. This will reduce the risk that highly3441 sensitive information is disseminated haphazardly across3442 various Federal and State agencies, and will address the3443 fundamental flaws with the current fragmented reporting3444 ecosystem--described in more detail below--at a time when3445 harmonization is critically necessary, in the wake of a serious3446 national security incident. Further, Congress should ensure3447 that victim companies are not subject to liability for such3448 national security incidents. To this end, Congress should3449 consider establishing a safe harbor for companies that have3450 reasonable cybersecurity risk management programs that are3451 consistent with NIST's Cybersecurity Framework 2.0, and it3452 should ensure that information that companies share with the3453 Responsible Agency cannot be used against such companies in3454 regulatory enforcement or civil litigation.3455---------------------------------------------------------------------------3456 \14\ Mayer Testimony (Mar. 11, 2025).3457---------------------------------------------------------------------------3458 The Federal Government should establish a National3459 Deterrence Strategy. There is a need to increase the cost on3460 the People's Republic of China and other foreign adversaries so3461 they cannot operate with impunity. To this end, the White3462 House, in consultation with relevant agencies, should develop a3463 National Deterrence Strategy with the goal of leveraging an3464 all-of-Government approach to increase the costs for these bad3465 actors, including but not limited to diplomatic, financial, and3466 other means.3467 The Federal Government should harmonize the development and3468 imposition of baseline cybersecurity requirements. Across the3469 Federal Government, agencies have sought to address3470 cybersecurity by imposing a patchwork of extensive, often3471 conflicting or duplicative, baseline cybersecurity3472 requirements. These are in addition to the extensive patchwork3473 of incident-reporting requirements at the Federal and State3474 levels. At the FCC alone, CTIA addressed 4 different regulatory3475 proceedings over the last 2 years that proposed 4 different3476 approaches to cybersecurity baseline requirements.\15\ Last3477 session, Senators Peters and Lankford and Representative3478 Higgins proposed legislation in an effort to address this3479 whole-of-Government challenge through the creation of a3480 harmonization committee to study and implement a pilot3481 program.\16\ In the wake of increasing threats, it is3482 imperative that Congress consider approaches that will speedily3483 and effectively ameliorate this regulatory blind spot,3484 compelling executive and independent agencies to harmonize3485 their cybersecurity requirements, including by instructing them3486 to use the NIST Cybersecurity Framework 2.0, which would3487 collectively increase our national security and ensure the use3488 of resources for security instead of compliance.3489---------------------------------------------------------------------------3490 \15\ See, e.g., Comments of CTIA, Protecting the Nation's3491Communications Systems from Cybersecurity Threats, PS Docket No. 22-3492329, (filed. Jan. 24, 2023), https://www.fcc.gov/ecfs/search/search-3493filings/filing/1012468668036; Comments of CTIA, Review of International3494Section 214 Authorizations to Assess Evolving National Security, Law3495Enforcement, Foreign Policy, and Trade Policy Risks, Order and NPRM, IB3496Docket No. 23-119 (filed Aug. 31 2023), https://www.fcc.gov/ecfs/3497document/108311863500689/1; Comments of CTIA, Connect America Fund: A3498National Broadband Plan for Our Future High-Cost Universal Service3499Support, WC Docket No. 10-90 et. al., (filed Dec. 12, 2023) https://3500www.fcc.gov/ecfs/document/1212267425956/1; Comments of CTIA,3501Establishing a 5G Fund for Rural America, GN Docket No. 20-32, (filed3502Oct. 23, 2024) https://www.fcc.gov/ecfs/document/102322146024/1.3503 \16\ Streamlining Federal Cybersecurity Regulations Act, S. 4630,3504118th Cong. (2024), https://www.congress.gov/bill/118th-congress/3505senate-bill/4630; H.R. 10123, 118th Cong. (2024), https://3506www.congress.gov/bill/118th-congress/house-bill/10123?s=1&r=13507(companion bill).3508---------------------------------------------------------------------------3509congress should ensure that cisa's implementation of circia honors the3510 direction of congress3511 As CTIA has advised CISA, the agency's CIRCIA rules should focus on3512the most serious incidents and should take concrete steps to harmonize3513the deeply fragmented Federal incident reporting landscape. There are3514several important areas where CISA can address these and other critical3515issues.3516 CISA Should Take a More Targeted Approach to the CIRCIA3517Rulemaking--Heeding Its Statutory Mandate to Focus on Substantial3518Incidents and Avoiding Rules that Will Result in Overreporting.--Taken3519together, CISA's proposed rules to implement CIRCIA raise serious3520issues. If adopted, they would impose enormous costs on the private3521sector and inundate CISA with information of limited value and utility.3522Accordingly, as many stakeholders have consistently urged, CISA should3523take the opportunity to adapt and adjust its proposal, honor the3524direction of Congress in CIRCIA, and minimize disruption to existing3525public-private partnerships. CTIA is optimistic that CISA wants to get3526this right and will heed the numerous public comments submitted in3527response to its NPRM to ensure that covered entities can provide3528meaningful, actionable information, while minimizing the burden on3529victims of cybersecurity incidents to generate, report, and update3530voluminous and ever-changing information. Toward this goal, there are3531several areas of concern that the committee should work with CISA to3532improve:3533 CISA should revisit its overly broad proposed definition of3534 substantial cyber incident.\17\ Unfortunately, in the NPRM,3535 CISA proposed an economy-wide incident reporting regime that3536 would inundate the agency with reports about an array of events3537 that extend well beyond what is needed for CISA to satisfy its3538 statutory directives to render assistance to victims of serious3539 incidents and share information with network defenders to warn3540 other potential victims of serious threats. Consistent with3541 stakeholder feedback from CTIA and others to take a more3542 focused approach, and consistent with the statutory guidance3543 requiring consideration of the impact of an incident, CISA3544 should rethink its definition of substantial cyber incident and3545 adopt a definition that ties a substantial cyber incident to an3546 impact on critical infrastructure that harms national or3547 economic security.\18\ Further, CISA should limit the3548 definition of substantial cyber incident to the system or3549 network that a covered entity needs to provide the products or3550 services that make it a part of critical infrastructure, and3551 CISA should exclude any incidents that do not involve the U.S.3552 critical infrastructure facility or function.3553---------------------------------------------------------------------------3554 \17\ CISA NPRM at 23767, Proposed 226.1.3555 \18\ CTIA proposed edits to the definition of ``substantial3556incident'' in Appendix A of its comments. Comments of CTIA, Cyber3557Incident Reporting for Critical Infrastructure Act (CIRCIA) Reporting3558Requirements, Dkt. No. CISA-2022-0010, at App. A (July 3, 2024),3559https://www.regulations.gov/comment/CISA-2022-0010-0422.3560---------------------------------------------------------------------------3561 CISA should also reframe its definition of covered entity,3562 which is similarly too broad and will result in over-3563 reporting.\19\ CISA should limit mandatory reporting to a3564 critical infrastructure facility or function and not require3565 reports from the entire entity, as CISA proposed to do in its3566 NPRM.\20\ Failure to limit the definition of covered entity3567 will substantially increase the volume of reportable incidents3568 because incidents affecting non-critical business units or3569 operations will be swept into the CIRCIA framework. Further,3570 CISA should clearly define ``entity'' to clarify a parent3571 company may not be a ``covered entity'' if it has a sub-entity3572 that is distinct from the parent company, has ``legal standing3573 and is uniquely identifiable from other entities,''\21\ and3574 meets the definition of ``covered entity.''3575---------------------------------------------------------------------------3576 \19\ CISA NPRM at 23684, Proposed 226.2.3577 \20\ Id.3578 \21\ Id. at 23676.3579---------------------------------------------------------------------------3580 CISA Has the Opportunity to Make Meaningful Progress Toward3581Harmonization and Deconfliction, Consistent with Congress's Direction3582in CIRCIA.--Congress emphasized harmonization in the passage of CIRCIA,3583launching substantial work through the Cyber Incident Reporting Council3584(``CIRC'') to identify opportunities to address the problematic3585fragmentation of cyber incident reporting obligations. This makes sense3586and is good government. In the Communications Sector alone, companies3587are subject to multiple overlapping incident reporting obligations that3588can include rules from the SEC, FCC, DoD, FTC, and more. These Federal3589rules are in addition to State regulations that include data breach3590notice obligations in all States and territories, as well as cyber3591incident reporting requirements like those required by the New York3592Department of Financial Services.3593 The CIRC issued a report in 2023 that identified the multiplicity3594of cyber incident reporting requirements and offered ``key3595recommendations'' including creating a model cyber incident reporting3596form that Federal agencies can adopt; and streamlining the reporting3597and sharing of information about cyber incidents, and a potential3598single reporting web portal.\22\3599---------------------------------------------------------------------------3600 \22\ DHS, Harmonization of Cyber Incident Reporting to the Federal3601Government, (Sept. 19, 2023), https://www.dhs.gov/sites/default/files/36022023-09/Harmonization%20of%20Cyber%20-3603Incident%20Reporting%20to%20the%20Federal%20Government.pdf.3604---------------------------------------------------------------------------3605 Unfortunately, however, CISA missed the opportunity to make3606progress to address fragmentation with its NPRM. Indeed, CISA received3607comments from the Congressional sponsors of CIRCIA and critical3608infrastructure stakeholders in response to its NPRM that were critical3609of the agency's failure to promote and pursue meaningful harmonization3610of incident reporting obligations.\23\ To help address this, CISA3611should take the opportunity now to fulfill the harmonization promise of3612CIRCIA. In particular:3613---------------------------------------------------------------------------3614 \23\ Comments of Andrew Garbarino (R-NY), Chairman, H. Homeland3615Sec. Subcomm. on Cybersecurity and Infras. Prot., Dkt. No. CISA-2022-36160010 (July 3, 2024), https://www.regulations.gov/comment/CISA-2022-36170010-0464; Comments from Bennie Thompson (D-MS), Ranking Member, H.3618Homeland Sec. Comm., Eric Swalwell (D-CA), Ranking Member, H. Homeland3619Sec. Subcomm. on Cybersecurity and Infras. Prot. & Yvette Clarke (D-3620NY), Dkt. No. CISA-2022-0010 (Jul. 3, 2024), https://3621www.regulations.gov/comment/CISA-2022-0010-0463; Comments of Gary3622Peters (D-MI), Chairman, S. Homeland Sec. and Gov't Aff. Comm., Dkt.3623No. CISA-2022-0010 (Jul. 2, 2024), https://www.regulations.gov/comment/3624CISA-2022-0010-0424.3625---------------------------------------------------------------------------3626 CISA should reconsider its proposed approach to addressing3627 reporting regimes that are ``substantially similar.''\24\3628 Harmonization should not be limited to formal agreements with3629 other agencies that are predicated on their adoption of the3630 same demands that CISA included in its NPRM.3631---------------------------------------------------------------------------3632 \24\ 6 U.S.C. 681b(a)(5)(B)(i) (creating an exception for a3633covered entity ``required by law, regulation, or contract to report3634substantially similar information to another Federal agency within a3635substantially similar time frame.'').3636---------------------------------------------------------------------------3637 CISA should create a voluntary option for covered entities3638 to use a single point of entry and single Common Form for3639 Federally-mandated cyber incident reports. Having a single3640 Federal agency to report to during substantial cyber incidents3641 with national security implications is essential for critical3642 infrastructure organizations who will have ``all hands on3643 deck'' dedicated to incident response with the priority to3644 secure networks and systems. Requiring victim companies to3645 report to multiple Government agencies with disparate3646 requirements within condensed time frames would be detrimental3647 to these efforts, requiring redirection of vital security3648 resources away from incident response. Accordingly, harmonizing3649 these requirements through reporting to a single agency via a3650 single Common Form will provide meaningful relief to victim3651 organizations struggling with incident response.3652 There Are Other Important Steps CISA Should Take to Improve and3653Focus the Incident Reporting Requirement.--Although not an exhaustive3654list, there are a number of other aspects of CISA's proposed rules that3655should be re-evaluated.3656 CISA should streamline the information required in reports3657 because as drafted, the NPRM would mandate far too much3658 information with too little clarity. The proposed reporting3659 fields in the NPRM call for too much detail, including3660 information that is not relevant or actionable, such as the3661 name and role of third-party vendors helping with the3662 incident.\25\ The NPRM also uses vague, undefined terms and3663 calls for details that are unclear or indeterminate. The3664 proposed on-going supplementation of an initial incident report3665 will be burdensome and may not provide additional information3666 of value.3667---------------------------------------------------------------------------3668 \25\ CISA NPRM at 23722.3669---------------------------------------------------------------------------3670 The proposed data retention obligations are drafted broadly3671 and will be burdensome in scope, duration, and governance3672 obligations.\26\ Because of the vast amounts of network traffic3673 that communications providers transmit, retention for 2 years3674 of information may make the retention obligations untenable.3675---------------------------------------------------------------------------3676 \26\ Id., Proposed 226.13.3677---------------------------------------------------------------------------3678 CISA's enforcement approach misses an opportunity to protect3679 victims and promote partnerships. It would substitute the3680 collaborative relationship CISA currently has with critical3681 infrastructure for what the NPRM suggests may be the agency's3682 predisposition to take a punitive or adversarial approach.3683 CISA should adopt adequate protections for all information3684 submitted to the agency under CIRCIA including information in3685 response to a request for information or subpoena. Further, the3686 existence of such a request for information or subpoena itself3687 should be treated as confidential.3688 Congress Should Encourage CISA To Establish Processes to Solicit3689and Meaningfully Incorporate Public Feedback.--To date, there has not3690been ample opportunity for stakeholders to meaningfully engage with3691CISA in developing the CIRCIA rules. Given the breadth and detail of3692the NPRM, a single opportunity for comment on the proposed rules is not3693sufficient to provide CISA with public input. Among other things, CISA3694should create a process for ex parte communications in the CIRCIA rule-3695making proceeding--as is common practice for other regulatory3696agencies.\27\3697---------------------------------------------------------------------------3698 \27\ Chairman Garbarino and Ranking Member Swalwell both spoke in3699support of the adoption of an ex parte process for the CIRCIA rule3700making during the March 11 hearing. ``I promise we're going to work on3701ex-parte through the CIRCIA rule, hopefully get that fixed.''3702Regulatory Harm or Harmonization, supra note 2. (Statement by Chairman3703Garbarino). ``I also called on CISA [in comments on the NPRM] to3704establish an ex parte process to facilitate on-going engagement with3705the private sector.'' Id. (Statement by Ranking Member Swalwell).3706---------------------------------------------------------------------------3707 ______37083709 CTIA and its members look forward to working with this committee,3710as well as the administration, to develop a more coordinated, forward-3711looking approach to responding to serious national security incidents,3712a more workable reporting regime, and a more harmonized cybersecurity3713landscape across the Federal Government.37143715 A P P E N D I X I I37163717 ----------37183719 Questions From Chairman Andrew R. Garbarino for Scott I. Aaronson3720 Question 1. How does your sector view the role of regulation? What3721is the importance of regulation for your industry?3722 Answer. The electricity subsector employs a risk-based, defense-in-3723depth approach to cybersecurity, which includes a variety of tools and3724strategies that support existing voluntary and mandatory cybersecurity3725standards and regulations. These regulatory standards are valuable3726tools that set a baseline for cybersecurity of critical infrastructure3727for all jurisdictional owners and operators of the Bulk Power System3728that supports the interconnected North American energy grid. Electric3729companies work closely with the Federal Energy Regulatory Commission3730(FERC), the North American Electric Reliability Corporation (NERC), the3731Transportation Security Administration (TSA), and the Department of3732Energy (DOE) to comply with various sector regulations and reporting3733requirements.3734 Throughout the country, investor-owned electric companies are3735meeting and exceeding existing cybersecurity regulations and standards.3736As the Federal Government, States, and private sector work together to3737reduce risk holistically and continue to enhance cybersecurity3738protections of critical infrastructure, it is important that new3739cybersecurity requirements are not duplicative, conflicting,3740overlapping, or inefficient.3741 Regulations that are risk-based, while important, are only one part3742of this defense-in-depth strategy. EEI's members also focus on3743resilience, response, and recovery as strategies that help electric3744companies protect the electric grid. We also need to have strong3745partnerships in place across key, interdependent sectors and with3746Government in order to maintain the robust cybersecurity posture needed3747to face the realities of potential cyber warfare.3748 Question 2. How can the Trump administration ensure it incorporates3749industry feedback as it seeks to streamline the cyber reporting regime?3750 Answer. The Trump administration may consider existing public3751comments made on behalf of industry as it seeks to streamline cyber3752reporting. As mentioned in my testimony, EEI submitted comments on the3753Office of the National Cyber Director's (ONCD) Request for Information3754on Cybersecurity Regulatory Harmonization. In summary, EEI's comments3755recognized that cybersecurity regulations must keep pace with the3756evolving threat landscape but must also be developed in close3757coordination with the private sector to ensure we can implement them3758effectively.3759 EEI also submitted 3 sets of comments on the proposed rule for the3760Cyber Incident Reporting for Critical Infrastructure Act of 20223761(CIRCIA). In summary, these comments requested that the Cybersecurity3762and Infrastructure Security Agency (CISA) raise the threshold and limit3763the scope of the definition of a ``substantial cyber incident.'' In3764addition, EEI and several other critical infrastructure sectors also3765requested CISA implement an ex parte process for the CIRCIA rule3766making.3767 In addition to these public comments, the administration may3768consider the recommendations in Cyber Incident Reporting Council's3769(CIRC) Report on Harmonization of Cyber Incident Reporting to the3770Federal Government when incorporating feedback on streamlining3771reporting.3772 Question 3a. How has the cyber incident reporting process helped or3773hindered your ability to effectively respond to nation-state threats3774such as Volt Typhoon?3775 Question 3b. What changes, if any, to cyber incident reporting3776would improve your ability to respond to nation-state threats?3777 Question 3c. Can cyber incident reporting serve as a tool for3778understanding cross-sector trends for actors such as Volt Typhoon? If3779yes, how so?3780 Answer. Both the cyber incident-reporting process and the cyber3781information-sharing process have helped the electric power sector3782implement successful mitigation efforts in the face of threats such as3783Volt Typhoon. Specifically, the Energy Threat Analysis Center (ETAC)3784has proven its capabilities by enabling critical information sharing3785following the Federal Government's release of threat intelligence3786related to Volt Typhoon. The expertise of the private sector was3787leveraged to develop mitigation strategies quickly that ultimately3788helped members of the electricity subsector, and other critical3789infrastructure operators, to address the threats from Volt Typhoon.3790This model is critical to our success in combatting sophisticated cyber3791adversaries and is helped by open lines of communication, highlighting3792the difference between threat information sharing and regulatory3793reporting requirements.3794 Streamlining Federal cyber incident reporting requirements through3795fewer agencies would allow our most skilled cyber experts to spend3796their time responding to nation-state threats rather than filling out3797paperwork.3798 One of the stated goals of the original CIRCIA legislation was to3799strengthen national security, including through rapidly deploying3800resources to victims, analyzing reporting across sectors to spot3801trends, and then quickly sharing that information to warn other3802potential victims. The final CIRCIA rule has the potential to create3803greater visibility into cross-sector risk, however, the proposed rule3804as written does not sufficiently separate the signal from the noise and3805thus would not be useful in understanding cross-sector trends for3806actors such as Volt Typhoon. CISA, as the national coordinator, should3807amend the definition of a substantial cyber incident in the proposed3808CIRCIA rule in order to glean greater insight into cross-sector risk.3809 Question 4. According to CISA, the total estimated cost of3810completing incident reports from 2024 to 2033 is approximately $79.13811million--just short of $8 million per year. Please explain whether you3812agree with CISA's estimate.3813 Answer. Redundant regulations add to electric companies'3814operational costs and misallocate limited resources from the industry's3815core obligation--namely, to provide safe, reliable, and affordable3816service to customers. EEI testified that one of our member electric3817companies estimated they could file roughly 65,000 reports through 20333818under the proposed rule--vastly exceeding CISA's estimate of more than3819200,000 total reports during that period. Accordingly, CISA's cost3820estimate of approximately $79.1 million from 2024 to 2033 is far too3821low.3822 Question 5. How can Congress ensure CISA has the tools it needs to3823manage the information received from CIRCIA requirements if/when the3824rule goes into effect?3825 Answer. CISA faces several challenges in improving the existing3826proposal to better align with Congressional intent. These include3827difficulties in collaborating with industry stemming from the lack of3828an established ex parte process, as well as issues related to natural3829attrition and staff turnover following the change in administration.3830Additionally, uncertainty around Congressional appropriations may3831impact CISA's ability to effectively intake incident reports by the end3832of 2025.3833 To ensure CISA is well-equipped to manage the information received3834from CIRCIA, Congress may consider conducting oversight regarding its3835current status--including staffing levels, resource needs, the3836projected time line for final rule completion, and anticipated future3837engagement with industry stakeholders. Specifically, Congress should3838pursue oversight to ensure that CISA has the appropriate infrastructure3839in place to intake a high volume of incident reports and secure this3840sensitive information accordingly.3841 Question 6. How can Congress support cyber risk management3842regulatory harmonization?3843 Answer. As stated in my testimony, Congress should work with CISA3844to reduce the burden of the proposed CIRCIA rule and focus on a few3845areas for improvements.3846 First, conduct oversight regarding the current status of CIRCIA,3847including staffing levels, resource needs, the projected time line for3848final rule completion, and anticipated future engagement with industry3849stakeholders.3850 Second, facilitate coordination amongst Congressional committees of3851jurisdiction to align CISA, Sector Risk Management Agencies, and other3852regulators, and to review concerns with existing Federal reporting3853requirements, including the national security concerns associated with3854the public disclosure of incidents required by the U.S. Securities and3855Exchange Commission (SEC).3856 Third, further clarify CISA's role in cybersecurity regulatory3857harmonization in relation to other Federal entities.3858 Fourth, reauthorize the Cybersecurity Information Sharing Act of38592015. Mandatory incident reporting and voluntary information sharing3860both are valuable tools in ensuring the cybersecurity of critical3861infrastructure.3862 Question 7. Is there a need to ensure cybersecurity regulations3863impacting one sector do not negatively impact other dependent sectors?3864Please explain.3865 Answer. Currently, CISA serves as the National Coordinator for the3866Security and Resilience of Critical Infrastructure, pursuant to3867Presidential Policy Directive-21 and its successor document, National3868Security Memorandum-22. As national coordinator, CISA is charged with3869leading a whole-of-Government effort to secure U.S. critical3870infrastructure. As part of this role, CISA has a duty and an obligation3871to ensure any new or existing regulations do not negatively impact3872other dependent sectors.3873 In addition, ONCD has a role to play in ensuring cybersecurity3874regulations do not negatively impact other dependent sectors. As an3875office within the White House, ONCD has a unique role in bringing3876independent regulators and other Federal agencies to the table to3877streamline regulations. ONCD may consider reviewing the negative3878impacts associated with existing cross-sector Federal reporting3879requirements, including the national security concerns associated with3880the public disclosure of incidents required by the SEC.3881 Question 8. What are the challenges to harmonization and3882reciprocity in the energy sector?3883 Answer. For years, EEI members have worked with Federal, State, and3884local governments to protect and defend the electric grid from cyber-3885related disruptions. Through various cyber initiatives, information-3886sharing activities, and exercises, EEI members have strengthened their3887resilience to cyber attacks because they understand that a reliable and3888secure supply of electricity is necessary to power the U.S. economy and3889safeguard this country's national security.3890 The energy sector has been subject to NERC's Reliability Standards3891(including its Critical Infrastructure Protection (CIP) Standards), as3892approved and enforced by the Federal Energy Regulatory Commission3893(FERC), for years. One of the greatest challenges to harmonization is3894that any new proposed cybersecurity and voluntary standards must be3895developed in harmony with these existing standards to ensure as little3896conflict as possible. To avoid confusion and challenges during a3897cybersecurity incident, EEI members believe it would be valuable to3898designate one Government agency that would be responsible for3899coordinating with other agencies. In addition, it is important to3900remember that electric companies exist in diverse, ever-changing3901operating environments and therefore need to have the ability to tailor3902each of their individual preparation, response, and recovery activities3903accordingly.3904 Questions From Chairman Andrew R. Garbarino for Heather Hogsett3905 Question 1. How does your sector view the role of regulation? What3906is the importance of regulation for your industry?3907 Answer. Financial institutions are subject to complex and3908multifaceted regulatory requirements from the Office of the Comptroller3909of the Currency (OCC), the Federal Reserve Board (FRB), the Federal3910Deposit Insurance Corporation (FDIC), the Consumer Financial Protection3911Bureau (CFPB), the Securities and Exchange Commission (SEC), and the3912Commodity Futures Trading Commission (CFTC), among others at the State3913and international levels. Included in the regulatory regime is rigorous3914supervision and examinations from the prudential banking regulators--3915the OCC, FRB, and FDIC. Supervision by the banking agencies seeks to3916ensure that financial institutions operate in a safe and sound manner.3917During these reviews, on-site examiners evaluate compliance with3918statutory requirements and whether firms implement appropriate controls3919in areas such as information security, third-party risk management,3920operational resilience, capital and liquidity management, and3921appropriate board oversight.3922 The financial sector has been highly regulated for many years and3923firms have established governance and compliance teams to engage with3924regulators. In a number of areas, cybersecurity included, there is3925significant overlap between agencies that diverts attention of critical3926staff toward compliance. A reassessment of this approach is warranted3927to ensure the overall regulatory regime appropriately balances3928compliance demands with security realities. For instance, examiners3929should focus on enhancing security outcomes rather than requiring3930extensive documentation of processes and procedures.3931 Question 2. How can the Trump administration ensure it incorporates3932industry feedback as it seeks to streamline the cyber reporting regime?3933 Answer. The best way to incorporate industry feedback and3934streamline cyber reporting is to have an active and iterative dialog3935with critical infrastructure sectors. This is particularly true for3936CIRCIA, where close collaboration with industry is necessary not only3937to inform the final rule and achieve the balanced reporting structure3938contemplated by the underlying statute, but also to monitor3939implementation and determine if adjustments are necessary.3940 The Trump administration could also leverage the authorities3941outlined in Executive Order 142151 \1\ to limit the ability of3942independent agencies to promulgate duplicative rules. This could help3943prevent unhelpful regulatory requirements--like the SEC's cyber3944incident disclosure rule--that directly conflicts with the intent3945behind CIRCIA and arms cyber criminals with information they can3946leverage to inflict further harm on victim companies.3947---------------------------------------------------------------------------3948 \1\ Executive Order No. 14,215, Ensuring Accountability for All3949Agencies, 90 Fed. Reg. 10447 (Feb. 24, 2025).3950---------------------------------------------------------------------------3951 Question 3. According to CISA, the total estimated cost of3952completing incident reports from 2024 to 2033 is approximately $79.13953million--just short of $8 million per year. Please explain whether you3954agree with CISA's estimate.3955 Answer. In its proposed rule, CISA calculated that $79.1 million3956figure by estimating that cyber incident and ransom payment reports3957would take 3 hours to complete respectively, joint cyber incident and3958ransom payment reports would take 4.25 hours, and supplemental reports3959would take 7.5 hours.\2\ CISA then assumed a weighted average3960compensation rate of $86.29 for the staff compiling the reports.\3\3961---------------------------------------------------------------------------3962 \2\ Cyber Incident Reporting for Critical Infrastructure Act3963(CIRCIA) Reporting Requirements, 89 Fed. Reg. 23644, 23745 (Apr. 4,39642024).3965 \3\ Id.3966---------------------------------------------------------------------------3967 Because CIRCIA has not yet gone into effect, it is difficult to say3968with certainty whether CISA's estimate is accurate. Nevertheless, 13969financial institution noted it takes them an average of 20.5 hours to3970complete reporting requirements associated with the European Union's3971Digital Operational Resilience Act. Moreover, another firm noted that3972the average compensation rate for personnel responsible for completing3973reports was $100--up from $75 several years ago. Both data points3974indicate that CISA likely underestimated the time and cost it will take3975firms to complete required reports.3976 Question 4. How can Congress support cyber risk management3977regulatory harmonization?3978 Answer. The central challenge for most financial institutions is3979the collective impact of overlapping cyber examinations by multiple3980regulators. Compliance obligations associated with exams now consume up3981to 70 percent of cyber teams' time. During exams, which can take weeks,3982firms frequently produce hundreds, and sometimes thousands, of pages of3983documents responding to regulators' requests.3984 Congressional action is needed to help ensure new and existing3985cybersecurity requirements support better security and resilience3986outcomes instead of simply adding additional procedural mandates3987unrelated to real risk. To realize this goal, it is imperative that3988regulators enhance their coordination and not duplicate efforts by3989better leveraging each other's documentation, tests, evaluations, and3990findings.3991 Leadership from 1 or more White House offices (e.g., Office of the3992National Cyber Director, Office of Management and Budget, etc.) would3993help ensure independent regulatory agencies work together to avoid3994duplication and conflict among their respective requirements. Agencies3995should be required to take into consideration the full scope and impact3996of regulatory requirements that firms adhere to rather than only3997looking at a subset. While each individual regulatory requirement3998(including rules, supervision, examination, and enforcement) may be3999well-intended, the collective impact of multiple requirements can4000interfere with a firm's ability to operate and focus on security4001improvements. Congressional attention and oversight on this vital issue4002can help inform a streamlined approach and hold regulatory agencies4003accountable.4004 Question 5. Is there a need to ensure cybersecurity regulations4005impacting 1 sector do not negatively impact other dependent sectors?4006Please explain.4007 Answer. Numerous large-scale cyber incidents over the last several4008years demonstrate the interconnected nature of our systems and the need4009for all critical infrastructure sectors to implement appropriate4010security controls. For cyber incident reporting requirements, it is4011particularly important that those obligations be appropriately tailored4012and do not detract from response efforts.4013 Without proper streamlining, the purpose behind many reporting4014mandates--to improve information sharing, prevent harm from spreading,4015and help impacted entities resume operations quickly--will be4016undermined as victim companies are consumed by filling out Government4017forms and reducing litigation and compliance risks. This can lead to4018delays and a reticence to share information confidentially and risks4019cascading harm between and across critical infrastructure sectors.4020 Question 6. What are the challenges to harmonization and4021reciprocity in the financial sector?4022 Answer. Achieving regulatory harmonization and reciprocity in the4023financial sector is challenging due to slight variations in the4024authorities of each banking regulator. Despite those modest4025differences, each agency's cybersecurity requirements generally apply4026to the same activities, policies, and procedures within firms.4027Therefore, it is the cumulative effect of overlapping requirements that4028leads to the unintended consequence of diverting resources away from4029security operations. For example, financial institutions reported that4030roughly 25 percent of regulatory requests during an exam are4031duplicative of those already received from other agencies.4032 A more effective approach would be to have banking agencies conduct4033a single coordinated cyber review each year and leverage existing4034documentation to fulfill those obligations rather than creating unique4035work product for each evaluation.4036 Question 7. Are financial institutions utilizing artificial4037intelligence and automation to reduce compliance burdens and help their4038security teams focus on incident response and threat mitigation?4039 Answer. Financial institutions have used AI tools for threat4040detection and mitigation for more than a decade and continue to expand4041its use to better serve and protect customers and improve internal4042efficiencies. Machine learning models have been used for several years4043to detect fraud in credit and debit card transactions, check4044transactions, digital payments, and account openings. AI-driven network4045security systems are employed to continuously monitor both incoming and4046outgoing network traffic and detect anomalies (such as unusual login4047times, atypical data transfers, or irregular access patterns) that may4048signify a breach attempt. As another example, AI is also used to4049automate responses to spam and phishing attempts, mitigating risks4050before they escalate.4051 Firms also use AI to reduce regulatory compliance burdens, freeing4052personnel and resources to better focus on security risks. For example,4053a BPI member bank has used generative AI to complete a preliminary4054review of third-party cybersecurity assurance responses and4055subsequently direct relevant human reviewers to potential gaps in4056response completeness against the bank's requirements.4057 Questions From Chairman Andrew R. Garbarino for Robert Mayer4058 Question 1. How does your sector view the role of regulation? What4059is the importance of regulation for your industry?4060 Answer. USTelecom and its members are steadfast in their commitment4061to cybersecurity. Our members meet--and very often exceed--4062cybersecurity requirements as conditions for authorization to provide4063services, receive Government funding, bid on Government contracts, and4064participate in Government programs, as well as to ensure customer trust4065in the competitive global marketplace. USTelecom's Cybersecurity4066Culture Report, focusing on small and medium enterprises, found that4067telecom providers of all sizes, including smaller ones, have a mature4068cybersecurity culture--along with financial services and IT4069respondents--when compared to other critical infrastructure sectors.\1\4070---------------------------------------------------------------------------4071 \1\ Cybersecurity Culture Report: The State of Small and Medium-4072Sized Critical Infrastructure Enterprises 4, USTelecom (Feb. 15, 2023),4073https://www.ustelecom.org/research/2023-cybersecurity-culture-report4074(``The IT and Communications (Comms) sectors stood out as having the4075strongest cybersecurity cultures, with the Comms sector scoring most4076consistently high across the 5 dimensions. The IT, Comms, and Financial4077Services sectors were the most likely to perform important4078cybersecurity culture practices including performance appraisals,4079rewards for proactive behavior, training initiatives, and routine4080communications with internal stakeholders.'').4081---------------------------------------------------------------------------4082 The majority of cybersecurity regulations applicable to our sector4083generally fall into 1 of 2 principal categories: (1) baseline4084cybersecurity requirements; (2) cyber incident reporting requirements.4085 Baseline Cybersecurity Requirements.--Currently, the broadband4086industry contends with cybersecurity baselines across various programs4087and initiatives, including multiple FCC cybersecurity proceedings--such4088as those addressing the Emergency Alert System/Wireless Emergency4089Alerts system, section 214 authorizations, the Uniendo a Puerto Rico4090Fund, the Connect USVI Fund, and the Connect America Fund--as well as4091the Broadband Equity, Access, and Deployment (``BEAD'') Program4092administered by the National Telecommunications and Information4093Administration (``NTIA''), and the Department of Justice (``DOJ'') U.S.4094Bulk Sensitive Data regulation.4095 There is a relatively easy way for policy makers to bring4096consistency to these proceedings: by grounding all cybersecurity4097baselines for our sector in the bipartisan requirements adopted by the4098Federal Communications Commission (``FCC'') as conditions for receiving40995G funding--an approach firmly grounded in the broadly utilized4100National Institute of Standards and Technology (``NIST'') Cybersecurity4101Framework (``CSF'').4102 Specifically, we would propose that broadband providers'4103``cybersecurity risk management plans must reflect at least the [NIST4104Framework], or any successor version of the NIST Framework'' and these4105plans ``must reflect established cybersecurity best practices that4106address each of the Core Functions described in the NIST4107Framework''.\2\ These core functions, which were updated in 2024 to4108include governance, would ensure companies are implementing practices4109necessary to Govern, Identify, Protect, Detect, Respond, and Recover.4110---------------------------------------------------------------------------4111 \2\ Establishing a 5G Fund for Rural America, FCC 24-89, at 122.4112---------------------------------------------------------------------------4113 Importantly, in the above-mentioned proceeding, the FCC had the4114foresight to avoid picking winners and losers among competing sets of4115best practices, and also avoiding practices that, due to their4116prescriptiveness and inflexibility, would not stand the test of time.4117For example, according to CISA, their Cybersecurity Performance Goals4118(``CPGs'') require revisions on a frequent basis ``with a targeted4119revision cycle of at least every 6 to 12 months''.\3\ A given company's4120practices may need to change even more quickly in response to real-4121world developments, with shifts measured in hours and minutes--not4122months. Nobody on the industry or Government side of the public-private4123partnership can predict with certainty today which cybersecurity4124practices will best serve the ecosystem long-term, which is why the4125private sector needs the flexibility to innovate.4126---------------------------------------------------------------------------4127 \3\ CISA, Cross-Sector Cybersecurity Performance Goals (2023) at412814, https://www.cisa.gov/sites/default/files/2023-03/4129CISA_CPG_REPORT_v1.0.1_FINAL.pdf.4130---------------------------------------------------------------------------4131 Congress should, at a minimum, encourage all current and4132prospective Federal agencies with jurisdiction over the communications4133sector to align with this approach. Moreover, this framework may prove4134adaptable to other sectors as well. Such harmonization would streamline4135compliance efforts, reduce administrative burdens, and allow providers4136to direct resources toward meaningful, risk-based security initiatives4137that genuinely strengthen the Nation's critical communications4138infrastructure.4139 Cyber Incident Reporting.--USTelecom's members are or soon will be4140subject to incident reporting rules or requirements promulgated by the4141SEC, FCC, FTC, DOJ (Team Telecom), FAR Council, FISMA, and State4142governments. In addition, our members have voluntary information-4143sharing relationships with a broad array of Government agencies,4144including the intelligence community, and of course DHS. Put simply,4145the need for harmonization has never been greater.4146 When incident reporting guidelines are harmonized, response efforts4147can be more coordinated and efficient. This streamlining is critical4148during cyber crises, where the speed and accuracy of information4149sharing and response can determine the severity of impact. A unified4150reporting framework enables faster mobilization of resources, clearer4151communication, and more effective incident resolution.4152 Harmonized reporting requirements are easier for entities to follow4153and for regulators to enforce. This clarity can lead to higher4154compliance rates, as entities are less likely to be overwhelmed by4155complex and conflicting requirements. In turn, better compliance4156enhances the overall security posture of critical infrastructure4157sectors. Moreover, a unified approach to data collection can improve4158the quality and security of the data submitted. With standardized4159protocols, security measures can be more robustly implemented and4160maintained. This is crucial in a field where data sensitivity and4161integrity are paramount.4162 Given the importance of harmonization, our members find it very4163concerning that the harmonization that CISA is trying to accomplish4164will be effectively null because covered entities will still be subject4165to a multitude of conflicting and duplicative reporting requirements4166across Federal agencies. This is due to the rule making not4167sufficiently addressing Congress's directive to solve for this issue.4168If CISA is serious about harmonizing reporting requirements, it must4169work to mitigate this challenge and address it in the rules.4170 Question 2. How can the Trump administration ensure it incorporates4171industry feedback as it seeks to streamline the cyber reporting regime?4172 Answer. USTelecom, joined by 20 other organizations, previously4173submitted a letter urging the establishment of an ex parte process to4174facilitate further stakeholder engagement and dialog on the4175implementation of CIRCIA. Although this request was declined by prior4176CISA leadership, we remain convinced that such a process is essential4177to correcting course.4178 As the implementation deadline nears, we are deeply concerned that4179the rule, as currently proposed, deviates substantially from4180Congressional intent and would, if finalized, do more harm than good to4181our national security. Without immediate action to initiate an ex parte4182process, it may fall to Congress and CISA to consider all available4183remedies--including potential rescission--to ensure the rule aligns4184with the statute and serves the national interest.4185 Question 3a. How has the cyber incident reporting process helped or4186hindered your ability to effectively respond to nation-state threats4187such as Volt and Salt Typhoon?4188 Answer. The current incident reporting landscape, which lacks4189harmonization across agencies and frameworks, can increase the4190complexity of responding to cyber incidents, including those involving4191nation-state actors.4192 Question 3b. What changes, if any, to cyber incident reporting4193would improve your ability to respond to nation-state threats?4194 Answer. A single, streamlined point of contact during incidents4195would help reduce operational friction and support more effective4196coordination.4197 Question 3c. Can cyber incident reporting serve as a tool for4198understanding cross-sector trends for actors such as Volt and Salt4199Typhoon? If yes, how so?4200 Answer. Potentially, yes. Incident reporting, when aggregated and4201appropriately shared, can offer insights into broader threat patterns.4202This kind of visibility may help inform risk management decisions4203across sectors. We appreciate efforts by Government partners to analyze4204and contextualize threat data in support of shared security objectives.4205 Question 4. According to CISA, the total estimated cost of4206completing incident reports from 2024 to 2033 is approximately $79.14207million--just short of $8 million per year. Please explain whether you4208agree with CISA's estimate.4209 Answer. While we appreciate CISA's effort to provide a cost4210estimate, we respectfully disagree that the projected figure accurately4211reflects the true burden of compliance under the proposed rule.4212 First, the proposed reporting requirements, as currently drafted,4213lack sufficient clarity regarding critical thresholds, definitions, and4214triggering events. Without a more precise understanding of what4215constitutes a ``covered cyber incident'' or the scope of entities4216subject to reporting, it is not possible to develop a reliable estimate4217of reporting frequency or the corresponding financial and4218administrative burden.4219 Second, even under conservative assumptions, the volume of reports4220that CISA may receive--particularly during and immediately after high-4221impact events--could far exceed what its current infrastructure is4222equipped to manage. This raises substantial concerns about both the4223Government's capacity to process, analyze, and respond to the4224information in a timely manner, and the costs that private entities4225will incur to ensure compliance in the face of ambiguity.4226 In short, while the $79.1 million estimate may serve as a starting4227point for discussion, it does not, in our view, reflect the scale,4228complexity, or fluidity of the real-world costs associated with the4229rule as proposed. Any meaningful assessment of compliance burden must4230await further clarity around key definitional elements and4231implementation thresholds.4232 Question 5. How can Congress support cyber risk management4233regulatory harmonization?4234 Answer. Congress has a critical role in reinforcing agency4235harmonization efforts through strategic oversight and, if necessary,4236legislative support, as well as by tackling the problem of State-level4237fragmentation. We are increasingly concerned about the proliferation of4238inconsistent State-level cyber regulations, which risk fragmenting the4239national cybersecurity landscape. To preserve coherence and legal4240certainty in this domain, Congress should explore policy mechanisms4241such as Federal preemption and safe harbor provisions, thereby ensuring4242that State actions do not undermine the development of a unified and4243effective national cybersecurity framework.4244 Question 6. Is there a need to ensure cybersecurity regulations4245impacting 1 sector do not negatively impact other dependent sectors?4246Please explain.4247 Answer. Yes, it is important to ensure that cybersecurity4248regulations directed at 1 sector do not create unintended legal or4249operational consequences for other, interdependent sectors. From a4250regulatory design perspective, clarity and precision are essential.4251Cross-sector dependencies are complex, and imposing obligations on 14252industry without a clear understanding of how those rules interact with4253adjacent systems can lead to conflicting requirements, duplicative4254compliance regimes, and operational inefficiencies. In the case of4255telecommunications, which frequently supports--but does not control--4256the systems of other sectors, regulatory spillover can result in4257unnecessary friction without materially advancing cybersecurity4258outcomes.4259 Question 7. What are the challenges to harmonization and4260reciprocity in the communications sector?4261 Answer. The core obstacle is that regulators act independently,4262with no binding framework or mechanism for alignment. Compounding this4263is a lack of centralized strategic direction--there's no top-down4264leadership driving coherence across jurisdictions. That is why the4265Office of the National Cyber Director (``ONCD'') needs to lead: not4266just as a facilitator, but as the central thought leader ensuring4267national alignment in cyber policy.4268 Question 8. Would more voluntary reporting encourage more4269information sharing from regulated entities? Why or why not?4270 Answer. More voluntary reporting could encourage increased4271information sharing from regulated entities--but only if there are4272sufficient legal protections in place for the information shared.4273Entities are often reluctant to report cybersecurity incidents or4274vulnerabilities voluntarily due to concerns about legal liability,4275regulatory consequences, or reputational harm. Therefore, the presence4276of robust protections is critical to fostering trust and cooperation.4277 This is why it is essential that Congress reauthorize the4278Cybersecurity Information Sharing Act of 2015 (CISA 2015) and also4279consider mechanisms to enhance its protections. CISA 2015 established4280important liability, regulatory, and FOIA protections for entities that4281voluntarily share cyber threat indicators and defensive measures with4282the Federal Government. However, under the current law, these4283protections typically are more difficult to obtain, or are less4284certain, unless information is shared directly with the Department of4285Homeland Security.4286 To truly encourage broad and timely information sharing,4287protections should follow the information, not just the pathway. For4288example, entities should receive the same legal safeguards if they4289share cyber threat information with any relevant Federal agency4290involved in cybersecurity, such as the FBI, NSA, or sector-specific4291agencies like the Department of Energy or the FDA. This would reduce4292confusion about the ``correct'' reporting pathway and lower barriers to4293voluntary participation.4294 In short, more voluntary reporting can lead to greater information4295sharing--but only if the legal framework makes that sharing safe and4296practical. Strengthening and updating CISA 2015 is a necessary step in4297that direction.4298 Questions From Chairman Andrew R. Garbarino for Ari Schwartz4299 Question 1. What can the Federal Government do to ensure businesses4300do not need to choose between regulatory compliance and cybersecurity?4301 Answer. As this question suggests, too frequently, governments are4302requiring organizations to follow a set of rote and static checkbox4303assessments or audit standards that are often duplicative and not4304dynamic enough to address current and future cyber threats. Several4305approaches that the Federal Government should consider are streamlining4306cybersecurity regulations, facilitating regulatory harmonization and4307reciprocity, pivoting from compliance to risk management, and providing4308clear implementation and compliance guidance and tools.4309Regulatory Streamlining4310 Regulatory streamlining can be accomplished in 2 ways. First and4311foremost, the Federal Government should strive to ensure that4312cybersecurity regulations only include controls that have demonstrably4313provided resilience for the sector in question. This approach will4314allow entities to focus limited resources on ensuring the timely and4315comprehensive implementation of controls known to improve security and4316resiliency. An excellent example of this approach is the Cyber Risk4317Institute's (``CRI'') development of the financial sector profile \1\4318for the National Institute of Standards and Technology's (``NIST'')4319Framework for Improving Critical Infrastructure Cybersecurity4320(``CSF'').\2\ Additionally, the Federal Government can achieve a4321measure of regulatory streamlining by ensuring the processes required4322to be compliant with cybersecurity regulations are as clear and simple4323as possible.4324---------------------------------------------------------------------------4325 \1\ Cyber Risk Institute, CRI Profile. https://4326cyberriskinstitute.org/the-profile/.4327 \2\ NIST, Cybersecurity Framework. https://www.nist.gov/4328cyberframework.4329---------------------------------------------------------------------------4330Regulatory Harmonization4331 As I detailed in my testimony, cyber incident reporting is an4332excellent example of how similar but disparate requirements across a4333growing number of reporting regimes has become burdensome for4334businesses. ``As more organizations build reporting structures for4335different purposes, duplication, misalignment, fragmentation, and other4336issues start to set in. This includes concerns around the amount and4337types of data fields, differing taxonomies, time frames for reporting,4338and more.''\3\4339---------------------------------------------------------------------------4340 \3\ Cybersecurity Coalition, Testimony Before the U.S. House of4341Representatives Homeland Security Committee Cybersecurity and4342Infrastructure Protection Subcommittee on ``Regulatory Harm or4343Harmonization? Examining the Opportunity to Improve the Cyber4344Regulatory Regime,'' March 11, 2025. https://homeland.house.gov/wp-4345content/uploads/2025/03/2025-03-11-CIP-HRG-Testimony.pdf.4346---------------------------------------------------------------------------4347 While there are understandable motivations for Federal regulators4348of different sectors to approach cybersecurity regulations with a4349nuanced, sector-specific lens, the Federal Government should encourage4350as much regulatory harmonization across regimes as is practicable. As4351the Cybersecurity Coalition has previously stated on this topic, we4352believe that ``building compliance schemes that focus on consistent4353standards, and that enable automation and reuse of compliance artifacts4354would create meaningful efficiencies.''\4\4355---------------------------------------------------------------------------4356 \4\ Cybersecurity Coalition, Response to the Office of the National4357Cyber Director. RE: Request for Information on Cybersecurity Regulatory4358Harmonization https://cdn.prod.website-files.com/4359660ec3caef47b817df2800ae/4360660ec3caef47b817df28023f_Cybersecurity%20Coalition%20Com-4361ments%20to%20ONCD%20RFI%20on%20Cybersecurity%20Regulatory%20Harmonizatio4362n%- 2020231031.pdf.4363---------------------------------------------------------------------------4364 One method that the Cybersecurity Coalition has previously4365advocated for consideration as a means to providing regulatory4366harmonization is a co-regulatory model.\5\ We consider ``coregulatory4367models such as Federal Financial Institutions Examination Council4368(``FFIEC'') to be a potentially effective method to establish uniform4369requirements and oversight across multiple regulatory regimes and4370supervisory agencies.''\6\4371---------------------------------------------------------------------------4372 \5\ Ibid.4373 \6\ Ibid.4374---------------------------------------------------------------------------4375Regulatory Reciprocity4376 The Federal Government should also look to support cyber regulatory4377reciprocity. At a high level, cyber regulatory reciprocity would enable4378a business to have their existing certification of compliance with one4379regulation be considered proof of meeting overlapping requirements from4380other regulations.4381 The Coalition has previously pointed to the Federal Risk and4382Authorization Management Program (``FedRAMP''), which was established4383to provide a cost-effective, risk-based approach for the adoption and4384use of cloud services by the Federal Government, as a potential4385model.\7\ As the Cybersecurity Coalition has previously noted,4386``FedRAMP's legal and governance structure, as well as FedRAMP's4387principle of `reusability,' are designed to enable compliance with less4388redundancy,'' and that ``elements of the FedRAMP model could be4389leveraged as the basis for coregulatory approaches that encompass a4390broader set of cybersecurity issues.''\8\ While we acknowledge that4391there are well-known challenges and implementation issues facing4392FedRAMP itself, the reciprocity principles at the core of the program4393are sound.4394---------------------------------------------------------------------------4395 \7\ Ibid.4396 \8\ Ibid.4397---------------------------------------------------------------------------4398Pivoting to Risk Management4399 As was mentioned at the beginning, many current Federal regulatory4400compliance regimes are static checkbox assessments or audit standards4401that often fail to keep pace with evolutions within the technological4402and threat landscape. Furthermore, this type of compliance regime is4403prone to giving a false sense of security and maturity. This is often a4404result of binary ``yes/no'' questions that fail to adequately4405interrogate cybersecurity complexity and that can often be successfully4406complied with despite failing to actually achieve an intended4407underlying security goal.4408 The Federal Government can address these shortcomings and better4409harmonize the cyber regulatory environment by pivoting existing regimes4410toward alignment with a single framework that is centered on cyber risk4411management. Cyber risk management and risk-based approaches enable4412businesses to better understand their security posture, prioritize4413risks based on their unique environment and mission, and ensure their4414security investments are effective.4415 The Cybersecurity Coalition urges Congress and the administration4416to embrace a risk management approach. Such a transition would be eased4417by the fact that NIST has been a global leader in cyber risk management4418for years. The constellation of frameworks they have developed in4419conjunction with industry includes the aforementioned CSF, the Privacy4420Framework,\9\ the Risk Management Framework,\10\ the Cybersecurity4421Supply Chain Risk Management,\11\ and, most recently, the Artificial4422Intelligence Risk Management Framework.\12\4423---------------------------------------------------------------------------4424 \9\ NIST, Privacy Framework. https://www.nist.gov/privacy-4425framework.4426 \10\ NIST, Risk Management Framework. https://csrc.nist.gov/4427projects/risk-management/about-rmf.4428 \11\ NIST, Cybersecurity Supply Chain Risk Management (C-SCRM).4429https://csrc.nist.gov/projects/cyber-supply-chain-risk-management.4430 \12\ NIST, AI Risk Management Framework. https://www.nist.gov/itl/4431ai-risk-management-framework.4432---------------------------------------------------------------------------4433 In particular, we would urge the Federal Government to ensure that4434regulatory regimes are aligned with the NIST CSF. The CSF is4435particularly well-regarded, is applicable across sectors, agnostic to4436size and structure, and is already widely adopted. The CSF is also seen4437as a model for partner nations, which is helpful for U.S. companies4438conducting business in other regions. Regulatory alignment with the CSF4439would minimize regulatory duplication and fragmentation through an4440existing industry-approved framework.4441Tools and Guidance4442 Streamlining, harmonization, and reciprocity would be the most4443impactful approaches to ensuring that businesses do not have to choose4444between regulatory compliance and cybersecurity. However, additional4445efficiency can be found by ensuring that regulatory requirements and4446processes are accompanied by clear implementation and compliance4447guidance and tools. Less time spent on understanding what is being4448asked of businesses and more tools being available to simplify and ease4449compliance means more time and resources actually being dedicated to4450cybersecurity.4451 Question 2. How would you evaluate interagency cooperation in4452regard to cyber incident reporting? Do Federal agencies adequately4453collaborate and share information? Please explain.4454 Answer. Currently, there is a patchwork of voluntary and required4455cyber incident reporting from private-sector entities to Federal4456departments and agencies. For example, the Transportation Security4457Administration's Security Directives for surface transportation, rail,4458and pipelines require covered entities to report to CISA Central within445924 hours. Within the financial sector, covered entities are required to4460directly notify their regulators--the Office of the Comptroller of the4461Currency, the Federal Reserve System, and Federal Deposit Insurance4462Corporation--of a computer-security incident within 36 hours.4463Contractors within the Defense Industrial Base report to the Department4464of Defense's Cyber Crime Center using an on-line portal. This is all on4465top of the Federal Government's push for voluntary cyber incident4466reporting to either CISA Central or to a local FBI Field Office. Once4467received by the Government agencies through these various means, there4468is not a routinized method or process for sharing cyber incident4469reports among the relevant agencies. Rather, the experience of4470Coalition members is that information is shared ad-hoc or specific to a4471single incident. Furthermore, there is little bi-directional4472information sharing. Coalition members often don't know what happens4473with the information they provide to the Government--with whom it was4474shared or what was even done with the information. To the greatest4475extent possible, Federal entities receiving cyber incident information4476should collect, analyze, contextualize, and enrich that data; and then4477share it back into the larger community along with any mitigation4478techniques and strategies in order to prevent additional, similar4479incidents.4480 This perspective appears to be supported by Government reports. The4481Cybersecurity Coalition's previous comments to the Office of the4482National Cyber Director (``ONCD'') on this issue cited ``a 20204483Government Accountability Office report reviewed the assessment4484processes employed by several large Federal agencies for security of4485data provided to States.''\13\ The report found that none of the4486agencies had policies for coordinating assessments with each other4487despite OMB requirements under Circular A-130 requiring agencies to4488coordinate.\14\ While this report was ``focused on State assessments,4489it demonstrates coordination challenges among Federal agencies and4490highlights the potential value in streamlined regulatory models that4491incorporate multiple levels of agency communication.''\15\4492---------------------------------------------------------------------------4493 \13\ GAO, Selected Federal Agencies Need to Coordinate on4494Requirements and Assessments of States, May 2020, https://www.gao.gov/4495assets/gao-20-123.pdf.4496 \14\ OMB Circular A-130, Managing Information as a Strategic4497Resource, Jul. 28, 2016, https://www.federalregister.gov/documents/44982016/07/28/2016-17872/revision-of-omb-circular-no-a-130-managing-4499information-as-a-strategic-resource.4500 \15\ Cybersecurity Coalition, Response to the Office of the4501National Cyber Director. RE: Request for Information on Cybersecurity4502Regulatory Harmonization https://cdn.prod.website-files.com/4503660ec3caef47b817df2800ae/4504660ec3caef47b817df28023f_Cybersecurity%20Coalition%20-4505Comments%20to%20ONCD%20RFI%20on%20Cybersecurity%20Regulatory%20Harmoniza4506tion%- 2020231031.pdf.4507---------------------------------------------------------------------------4508 Without established processes that can be tracked against security4509outcomes, it is difficult, if not impossible, to evaluate the4510effectiveness of interagency sharing of cyber incident reports.4511 Question 13. According to CISA, the total estimated cost of4512completing incident reports from 2024 to 2033 is approximately $79.14513million--just short of $80 million per year. Please explain whether you4514agree with CISA's estimate.4515 Answer. The Cybersecurity Coalition has not thoroughly evaluated4516CISA's estimate and is not in a position to comment on the potential4517cost of completing cyber incident reporting. It is difficult to assess4518how the constantly-changing legal and regulatory environment, threat4519environment, and the industry's growing cybersecurity maturity and4520resiliency all contribute to incident reporting costs over an extended4521period. Additionally, it is not clear if this estimate represents the4522cost for victims to report incidents, and/or the cost for CISA to4523ingest and take action on incident reports. There are associated costs4524on both ends of cyber incident reporting.4525 Question 4. How can Congress ensure CISA has the tools it needs to4526manage the information received from CIRCIA requirements if/when the4527rule goes into effect?4528 Answer. CISA's ability to manage the information received from4529CIRCIA's requirements once it goes into effect will be largely4530dependent on the volume of reporting that they must contend with. As I4531noted in my testimony, the Cybersecurity Coalition feels that CISA's4532scope in the breadth of covered entities and covered incidents is too4533broad.4534 CISA would be in a far better position to manage the information4535they receive through CIRCIA if they narrow the scope of entities. The4536Cybersecurity Coalition advocates for abandoning the approach of4537applying reporting requirements to all entities within critical4538infrastructure sectors and instead have them ``focus on Systemically4539Important Entities (SIEs) that own or operate critical infrastructure4540systems and assets whose disruption would have a debilitating,4541systemic, or cascading impact on national security, the economy, public4542health, or public safety.''\16\ Additionally, we would advocate for a4543more modest definition of types of reports requested.4544---------------------------------------------------------------------------4545 \16\ Cybersecurity Coalition, Comments to CISA: Re: Request for4546Information on the Cyber Incident Reporting for Critical Infrastructure4547Act of 2022. https://www.cybersecuritycoalition.org/filings/comments-4548to-cisa-circia-rfi-docket-number-2022-19551-cisa-2022-0110.4549---------------------------------------------------------------------------4550 Question 5. How can Congress support cyber risk management4551regulatory harmonization?4552 Answer. Congress can support cyber risk management regulatory4553harmonization by bolstering on-going Governmental efforts. In4554particular, the Cybersecurity Coalition would again highlight NIST's4555work in this field.4556 Among their many important cybersecurity contributions, the NIST4557CSF is likely the most domestically and internationally successful. For4558over a decade, the NIST CSF has showcased American leadership in cyber4559risk management by providing a framework to help organizations4560identify, manage, and reduce cyber risk. Wide-spread adoption of the4561NIST CSF has helped create a common perspective and language through4562which organizations can understand this issue. The proven track record4563and wide-spread adoption of the CSF makes it an ideal candidate as the4564basis for the Federal Government to align existing and future cyber4565regulatory regimes. The Cybersecurity Coalition would encourage the4566Federal Government to continue to support the development and4567maintenance of the CSF alongside such alignment as a way to improve4568cyber risk management harmonization while generally improving the U.S.4569cybersecurity ecosystem.4570 Question 6. How is the private sector using AI-enabled and4571automation software to improve their cyber defense posture and make4572compliance easier and more effective?4573 Answer. The private sector has long used AI-enabled and automation4574technologies to strengthen cybersecurity and streamline compliance4575processes, and new advancements in AI have quickly become part of4576industry's toolkit. These tools are enhancing existing capabilities for4577threat detection, response, and vulnerability management, but also have4578the potential to change how organizations approach risk management and4579compliance.4580 Artificial intelligence has long been used to detect threats with4581more precision and speed than traditional tools or human analysts can4582do alone. By analyzing vast amounts of data--network traffic, user4583behavior, system logs--AI systems can identify anomalies and potential4584threats that might otherwise go unnoticed. Behavioral analytics, in4585particular, allow organizations to detect insider threats and subtle4586indicators of compromise, such as lateral movement or privilege4587escalation, with a level of context-aware insight that manual methods4588cannot achieve.4589 Once certain kinds of threats are detected, automation can be used4590to isolate endpoints, disable accounts, or block malicious IP addresses4591within seconds. These security orchestration platforms can integrate4592with other parts of the IT stack to ensure a coordinated, organization-4593wide response that dramatically reduces the time it takes to contain4594incidents.4595 In parallel, AI is playing a growing role in vulnerability4596management. Rather than relying solely on scheduled scans and manual4597prioritization, modern systems use machine learning to continuously4598monitor codebases, applications, and infrastructure for4599vulnerabilities. They assess each issue in terms of exploitability and4600business impact, allowing organizations to prioritize patching efforts4601in a more strategic way. This integration of AI into operations4602(devops) practices also enables real-time code scanning during4603development, reducing the risk of deploying insecure software.4604 Compliance--once viewed as a burdensome and reactive function--is4605also being reshaped by AI. Natural language processing tools can now4606analyze regulatory texts and map them to internal controls,4607highlighting gaps and inconsistencies automatically. Instead of4608assembling audit evidence manually, compliance platforms that are4609powered by automation can collect logs, access records, and other4610necessary documentation in real time. This not only reduces labor, but4611also improves the accuracy and timeliness of reporting.4612 Identity and access management has similarly benefited from AI4613integration. Traditional access control models are being replaced or4614supplemented by dynamic, risk-based systems that adapt to contextual4615factors such as location, device health, and user behavior. These4616systems can detect and respond to anomalies that suggest compromised4617credentials or unauthorized activity, strengthening defenses without4618impeding legitimate workflows.4619 Data protection and privacy compliance--particularly important4620under regulations like GDPR and CCPA--have also become more manageable4621through AI. Automated data discovery and classification tools can4622identify sensitive information across disparate systems, even in4623environments with limited visibility or extensive use of shadow IT.4624Combined with AI-enhanced data loss prevention tools, organizations are4625better equipped to enforce policies around data handling and respond4626quickly to potential breaches.4627 The cumulative effect of these technologies is a more proactive,4628scalable, and resilient security and compliance posture. Organizations4629are no longer solely reacting to threats and regulations--they are4630leveraging automation to anticipate risks, enforce policies4631consistently, and maintain continuous audit readiness. While no4632technology eliminates the need for skilled human oversight, AI and4633automation are significantly enhancing the capabilities of security and4634compliance teams and enabling them to operate at a strategic level.4635 Question 7. How can the Trump administration ensure it incorporates4636industry feedback as it seeks to streamline the cyber reporting regime?4637 Answer. Providing ample opportunity for industry feedback and then4638adequately incorporating that feedback is critical to ensuring cyber4639incident reporting streamlining and harmonization efforts are as4640successful as possible. The insight gained through feedback from4641businesses that are required to implement and comply with these various4642reporting regimes is valuable and often nuanced.4643 Despite this, and as I testified, there was a distinct lack of4644industry engagement by CISA under the previous administration when4645contemplating this aspect of CIRCIA. This was a mistake that the Trump4646administration should rectify. We would encourage the Trump4647administration to work both inside and outside the existing regulatory4648structures to achieve this.4649 From inside the existing regulatory structures, this feedback can4650be ensured through a process that places emphasis on broad engagement.4651This may include holding appropriately numerous and lengthy Request for4652Information (``RFI'') or Request for Comment (``RFC'') periods and4653listening sessions. In addition, we would encourage the Trump4654administration to ensure there are appropriately lengthy opportunities4655for industry to review and submit comments on public drafts of proposed4656cyber incident reporting regimes. Additionally, the Cybersecurity4657Coalition advocates for the use of ex-parte processes, where necessary,4658to fill in areas that are necessary but weren't addressed in the4659regular APA rule-making process.4660 While this can be achieved within existing regulatory structures,4661it is easier to do so from the outside. The Cybersecurity Coalition has4662generally supported the ONCD as taking the lead on regulatory4663harmonization efforts up to this point. The Cybersecurity Coalition4664recommends that the committee review comments that were submitted to4665ONCD on this issue in 2023 that remain relevant today.\17\4666---------------------------------------------------------------------------4667 \17\ Cybersecurity Coalition, Response to the Office of the4668National Cyber Director. RE: Request for Information on Cybersecurity4669Regulatory Harmonization https://cdn.prod.website-files.com/4670660ec3caef47b817df2800ae/4671660ec3caef47b817df28023f_Cybersecurity%20Coalition%20-4672Comments%20to%20ONCD%20RFI%20on%20Cybersecurity%20Regulatory%20Harmoniza4673tion%- 2020231031.pdf.4674---------------------------------------------------------------------------46754676 [all]Witnesses
7 witnesses appeared, with 17 papers on file.
| Name | Position | Papers |
|---|---|---|
| Mr. Chris Currie | Director, Homeland Security and Justice Team, U.S. Government Accountability Office | Testimony · Biography · Truth in Testimony |
| Ms. Kristen Bernard | Deputy Inspector General, Office of Audits, U.S. Department of Homeland Security Office of the Inspector General | Testimony · Truth in Testimony |
| Ms. Erika Lang | Assistant Inspector General, Office of Inspections and Evaluations, U.S. Department of Homeland Security Office of the Inspector General | Testimony · Truth in Testimony |
| Mr. Andrew Block | Legal Senior Counsel, America First Legal Foundation | Testimony · Truth in Testimony |
| Mr. Curtis Schube | Executive Director, Council to Modernize Government | Testimony · Biography · Truth in Testimony |
| Mr. Mike Howell | Executive Director, Oversight Project, The Heritage Foundation | Testimony · Truth in Testimony |
| The Honorable John Roth | Private Citizen, Former Department of Homeland Security Inspector General | Testimony · Biography · Truth in Testimony |
Documents
The committee filed 2 documents for the meeting.
| Document | Kind | Format |
|---|---|---|
| Hearing Notice | Support Document | |
| Hearing: Witness List | Hearing: Witness List |