Search

Search bills, members, committees and pages...

“Exploring the Use of Unmanned Aircraft Systems Across the DHS Enterprise”

HearingHomeland Security Subcommittee on Border Security and EnforcementApr 1, 2025 · 2:00 PM

Summary

Homeland Security Subcommittee on Border Security and Enforcement held a hearing on Apr 1, 2025 at 2:00 PM in Cannon House Office Building, Room 310. 4 witnesses appeared.


Record

The meeting has its video, its transcript, witnesses and documents on the record.

Video

The proceedings, as the committee streamed them.

Transcript

The transcript runs to 3,302 lines and 193,072 characters, as the Government Publishing Office printed it.

house-hearing-61302.txt
1[House Hearing, 119 Congress]2[From the U.S. Government Publishing Office]34              CYBERSECURITY IS LOCAL, TOO: ASSESSING THE STATE5                AND LOCAL CYBERSECURITY GRANT PROGRAM67=======================================================================89                                HEARING1011                               BEFORE THE1213                            SUBCOMMITTEE ON14                    CYBERSECURITY AND INFRASTRUCTURE15                               PROTECTION1617                                OF THE1819                     COMMITTEE ON HOMELAND SECURITY20                        HOUSE OF REPRESENTATIVES2122                    ONE HUNDRED NINETEENTH CONGRESS2324                             FIRST SESSION2526                               __________2728                             APRIL 1, 20252930                               __________3132                           Serial No. 119-103334                               __________3536       Printed for the use of the Committee on Homeland Security3738[GRAPHIC NOT AVAILABLE IN TIFF FORMAT]3940        Available via the World Wide Web: http://www.govinfo.gov4142                                __________4344                   U.S. GOVERNMENT PUBLISHING OFFICE4561-302 PDF                  WASHINGTON : 20254647-----------------------------------------------------------------------------------4849                     COMMITTEE ON HOMELAND SECURITY5051                 Mark E. Green, MD, Tennessee, Chairman52Michael T. McCaul, Texas, Vice       Bennie G. Thompson, Mississippi,53    Chair                                Ranking Member54Clay Higgins, Louisiana              Eric Swalwell, California55Michael Guest, Mississippi           J. Luis Correa, California56Carlos A. Gimenez, Florida           Shri Thanedar, Michigan57August Pfluger, Texas                Seth Magaziner, Rhode Island58Andrew R. Garbarino, New York        Daniel S. Goldman, New York59Marjorie Taylor Greene, Georgia      Delia C. Ramirez, Illinois60Tony Gonzales, Texas                 Timothy M. Kennedy, New York61Morgan Luttrell, Texas               LaMonica McIver, New Jersey62Dale W. Strong, Alabama              Julie Johnson, Texas, Vice Ranking63Josh Brecheen, Oklahoma                  Member64Elijah Crane, Arizona                Pablo Jose Hernandez, Puerto Rico65Andrew Ogles, Tennessee              Nellie Pou, New Jersey66Sheri Biggs, South Carolina          Troy A. Carter, Louisiana67Gabe Evans, Colorado                 Robert Garcia, California68Ryan Mackenzie, Pennsylvania         Vacant69Brad Knott, North Carolina70                    Eric Heighberger, Staff Director71                  Hope Goins, Minority Staff Director72                       Sean Corcoran, Chief Clerk73                                 ------7475      SUBCOMMITTEE ON CYBERSECURITY AND INFRASTRUCTURE PROTECTION7677                Andrew R. Garbarino, New York, Chairman78Clay Higgins, Louisiana              Eric Swalwell, California, Ranking79Carlos A. Gimenez, Florida               Member80Morgan Luttrell, Texas               Seth Magaziner, Rhode Island81Andrew Ogles, Tennessee              LaMonica McIver, New Jersey82Mark E. Green, MD, Tennessee (ex     Vacant83    officio)                         Bennie G. Thompson, Mississippi84                                         (ex officio)85             Alexandra Seymour, Subcommittee Staff Director86           Moira Bergin, Minority Subcommittee Staff Director8788                            C O N T E N T S8990                              ----------91                                                                   Page9293                               Statements9495The Honorable Andrew R. Garbarino, a Representative in Congress96  From the State of New York, and Chairman, Subcommittee on97  Cybersecurity and Infrastructure Protection:98  Oral Statement.................................................     199  Prepared Statement.............................................     2100The Honorable Eric Swalwell, a Representative in Congress From101  the State of California, and Ranking Member, Subcommittee on102  Cybersecurity and Infrastructure Protection:103  Oral Statement.................................................     3104  Prepared Statement.............................................     5105The Honorable Bennie G. Thompson, a Representative in Congress106  From the State of Mississippi, and Ranking Member, Committee on107  Homeland Security:108  Prepared Statement.............................................     6109110                               Witnesses111112Mr. Robert Huber, Chief Security Officer, Tenable, Inc.:113  Oral Statement.................................................     7114  Prepared Statement.............................................     9115Mr. Alan Fuller, Chief Information Officer, State of Utah:116  Oral Statement.................................................    16117  Prepared Statement.............................................    18118Mr. Kevin Kramer, First Vice President, National League of119  Cities; Councilman, Louisville, Kentucky:120  Oral Statement.................................................    21121  Prepared Statement.............................................    22122Mr. Mark Raymond, Chief Information Officer, State of123  Connecticut:124  Oral Statement.................................................    24125  Prepared Statement.............................................    25126127                                Appendix128129Questions From Chairman Andrew R. Garbarino for Robert Huber.....    45130Questions From Chairman Andrew R. Garbarino for Alan Fuller......    45131Questions From Chairman Andrew R. Garbarino for Kevin Kramer.....    47132Questions From Chairman Andrew R. Garbarino for Mark Raymond.....    49133134      CYBERSECURITY IS LOCAL, TOO: ASSESSING THE STATE AND LOCAL135                      CYBERSECURITY GRANT PROGRAM136137                              ----------138139                         Tuesday, April 1, 2025140141             U.S. House of Representatives,142                    Committee on Homeland Security,143                         Subcommittee on Cybersecurity and144                                 Infrastructure Protection,145                                                    Washington, DC.146    The subcommittee met, pursuant to notice, at 10:06 a.m., in147room 310, Cannon House Office Building, Hon. Andrew R.148Garbarino (Chairman of the subcommittee) presiding.149    Present: Representatives Garbarino, Luttrell, Ogles,150Swalwell, and Magaziner.151    Mr. Garbarino. The Homeland Security sub on Cybersecurity152and Infrastructure Protection will come to order. Without153objection, the Chair may declare the committee in recess at any154point.155    The purpose of this hearing is to examine the State and156Local Cybersecurity Grant Program, which is up for157reauthorization this year. Since Congress signed the program158into law 4 years ago nearly 1 billion has been allocated to159bolster the cybersecurity postures of State and local160governments. Today, we will assess the program strengths and161weaknesses as we consider next steps.162    I now recognize myself for an opening statement. The threat163of cyber attacks to the U.S. networks and critical164infrastructure is real and rising. Microsoft's 2024 digital165defense report estimates that its customers are targeted with166more than 600 million attacks per day from nation-states and167criminal actors. For years the intelligence community has168warned of the threat of state-sponsored cyber actors engaging169in malicious activities against our critical infrastructure. As170we've seen, those warnings have become a reality. With the171persistent threat that groups like Typhoons pose to IT and OTS,172any critical infrastructure sector could be the next to fall173victim to attacks or have their status seized through a174phishing scheme.175    As cyber actors become increasingly sophisticated and176persistent we can no longer be complacent when it comes to177securing our critical infrastructure. We make take all steps178necessary to ensure our Nation's cyber preparedness and179resilience.180    In doing so, it is essential that our State and local181government partners are similarly well-situated to respond to182these threats. Despite often lacking resources and qualified183talent for cybersecurity, State and local governments host the184key pieces of critical infrastructure that keep our economy185running. If left unprotected, this presents a huge186vulnerability.187    Both State and local governments improve their188cybersecurity postures, Congress passed the State and Local189Cybersecurity Grant Program in 2021. Since this program began,190$838 million has been allocated to address cybersecurity risks191and threats to information systems owned and operated by or on192behalf of State, local, and territorial governments.193    State and Local Cybersecurity Grant Program is set to194expire this September, at which point the program will not195continue to receive Federal funding unless reauthorized by196Congress. As we have heard from many stakeholders, this program197has undoubtedly improved, sometimes even established the198cybersecurity posture for our States and localities.199    I am encouraged by the progress and applaud the efforts of200our State and local governments to seize this opportunity to201prioritize cybersecurity. With that said, we know the program202does not come without its challenges. As we consider203reauthorization, we want to understand any administrative204burdens or barriers to ensure State, local, and territorial205governments can focus on cyber resilience and preparedness. To206that end, it is also Congress' responsibility to evaluate207whether State and Local Cybersecurity Grant Program is the most208efficient and effective means to strengthen the cybersecurity209posture State and local and territorial governments.210    I'm here with an open mind and vested interest in211understanding how the program is working. Cybersecurity is a212whole of a society challenge, meaning Federal Government must213continue to support and strengthen cybersecurity at the State214and local levels to protect our Nation's networks and critical215infrastructure.216    State and local governments must also continue to share217information with each other. They play an important role in218disseminating best practices which could greatly benefit219organizations with less mature cybersecurity programs.220    I want to thank our witnesses. We have all had first-hand221experience with the State and Local Cybersecurity Grant Program222for being here today. I look forward to hearing your223perspectives on the program and working with you to strengthen224our collective defense against cyber threats.225    [The statement of Chairman Garbarino follows:]226               Statement of Chairman Andrew R. Garbarino227                             April 1, 2025228    The threat of cyber attacks to U.S. networks and critical229infrastructure is real and rising. Microsoft's 2024 Digital Defense230Report estimates that its customers are targeted with more than 600231million attacks per day from nation-states and criminal actors.232    For years, the intelligence community has warned of the threat of233state-sponsored cyber actors engaging in malicious activities against234our critical infrastructure. As we've seen, these warnings have become235a reality. With the persistent threat that groups like the Typhoons236pose to IT and OT assets, any critical infrastructure sector could be237the next to fall victim to attacks, or have its data seized through a238phishing scheme.239    As cyber actors become increasingly sophisticated and persistent,240we can no longer be complacent when it comes to securing our critical241infrastructure. We must take all steps necessary to ensure our Nation's242cyber preparedness and resilience. In doing so, it is essential that243our State and local government partners are similarly well-situated to244respond to these threats. Despite often lacking resources and qualified245talent for cybersecurity, State and local governments host the key246pieces of critical infrastructure that keep our economy running. If247left unprotected, this presents a huge vulnerability.248    To help State and local governments improve their cybersecurity249postures, Congress passed the State and Local Cybersecurity Grant250Program in 2021. Since this program began, $838 million has been251allocated to address cybersecurity risks and threats to information252systems owned and operated by, or on behalf of, State, local, and253territorial governments.254    The State and Local Cybersecurity Grant Program is set to expire255this September, at which point the program will not continue to receive256Federal funding unless reauthorized by Congress. As we have heard from257many stakeholders, this program has undoubtedly improved--and sometimes258even established--the cybersecurity posture of our States and259localities. I am encouraged by the progress and applaud the efforts of260our State and local governments to seize this opportunity to prioritize261cybersecurity.262    With that said, we know that the program does not come without its263challenges. As we consider reauthorization, we want to understand any264administrative burdens or barriers to ensure State, local, and265territorial governments can focus on cyber resiliency and preparedness.266    To that end, it is also Congress's responsibility to evaluate267whether the State and Local Cybersecurity Grant Program is the most268efficient and effective means of strengthening the cybersecurity269posture of State, local, and territorial governments. I am here with an270open mind--and a vested interest--in understanding how the Program is271working.272    Cybersecurity is a whole-of-society challenge, meaning the Federal273Government must continue to support and strengthen cybersecurity at the274State and local levels to protect our Nation's networks and critical275infrastructure. State and local governments must also continue to share276information with each other. They play an important role in277disseminating best practices, which could greatly benefit organizations278with less mature cybersecurity programs.279    I want to thank our witnesses--who have had first-hand experience280with the State and Local Cybersecurity Grant Program--for being here281today. I look forward to hearing your perspectives on the program, and282to working with you to strengthen our collective defense against cyber283threats.284285    Mr. Garbarino. I now recognize the Ranking Member, the286gentleman form California, Mr. Swalwell, for his opening287statement.288    Mr. Swalwell. Morning, thank you to Chairman Garbarino for289holding this subcommittee hearing on State and Local290Cybersecurity Grant Programs. I also want to thank our291witnesses for their participation, in a nice blend of private-292sector and public-sector witnesses that we have today.293    This program was established 4 years ago as the product of294a bipartisan agreement from this committee. As we consider295further authorization, it's important to remember that cyber296attacks hit Republican districts and Democratic districts, they297are in--they are in blue States and red States, they are in298urban areas, suburban areas, and rural areas.299    In my district, the 14th District of California in the Bay300area, the city of Hayward suffered a ransomware attack in the301summer of 2023 that shut down the city's computer networks for302more than 2 weeks. Just 2 months ago Hayward began notifying303individuals that personally identifiable information, including304Social Security numbers and sensitive medical information had305been breached as a part of the ransomware incident.306    I know this story is not unusual and I'm sure my colleagues307have also heard from local governments impacted by cyber308attacks and looking for help. With cyber attacks coming from309criminal gangs and nation-state adversaries we cannot leave our310State and local governments to fend for themselves. Federal311support for State and local governments is necessary to address312the national security threat and the State and Local313Cybersecurity Grant Program has always reflected that314understanding. By providing $1 billion to State, local, Tribal,315and territorial governments Congress took a major step in316strengthening our country's cyber defenses. For example, with a317$250,000 grant from this program, a water utility can expand318real-time monitoring to better detect and respond to cyber319incidents, finally addressing a long-standing resourcing320challenge in the water sector that we've heard about on this321subcommittee for years.322    When the State and Local Cybersecurity Grant Program was323created, our primary concern was the ransomware epidemic that324was plaguing our communities. That threat remains, but China's325campaign to preposition on our critical infrastructure for326potential future destructive attacks is even more alarming.327    While much of our critical infrastructure is privately328defended, some of our most vital services are provided by the329public sector, publicly-owned and -operated water and electric330utilities, transportation systems and emergency services could331all be targets in destructive attacks by China or other332adversaries. Reauthorizing the cybersecurity grant program is333necessary to ensure we do not take our foot off the gas at this334critical time in passing a reauthorization bill before this335program expires in September is one of my top priorities on the336committee.337    What I've heard from stakeholders is an appreciation for338the tremendous value of this program. We'll hear that today339from our witnesses. But they also have a desire for sustained340predictable and consistent funding levels that will allow State341and governments to build on their progress and budget in plan342their futures.343    The program operates under a partnership between FEMA and344CISA, 2 important agencies that unfortunately have come under345attack in recent months. By leveraging FEMA's grants,346administration expertise and CISA's cybersecurity expertise347this program has been able to deliver for State and local348governments in ways that would be impossible without that349partnership.350    Trump administration plans to eliminate FEMA and further351cut CISA's work force would devastate Homeland Security's352ability to support State and local governments across a range353of threats, including cyber attacks. The Cybersecurity Grant354Program demonstrates the value of collaboration between DHS's355components and I hope we can work in a bipartisan way to356further educate Secretary Noem about the tremendous value these357agencies provide the American public.358    I am also concerned about reports that FEMA has been359pausing distributions of funding to implement cyber grants360along with other programs. China is not pausing, they continue361their efforts to target our critical infrastructure and we362cannot pause either. The Trump administration must release363cyber grant funds to States, territories, and Tribes to comply364with court orders against any illegal process.365    Again I want to thank the Chairman for holding this366hearing, the witnesses for their participation, and look367forward to expertise from both public and private sector, as we368look to reauthorize this important program.369    Thank you, Chairman. I yield back.370    [The statement of Ranking Member Swalwell follows:]371               Statement of Ranking Member Eric Swalwell372                             April 1, 2025373    Establishing this program 4 years ago was the product of bipartisan374legislation developed by this subcommittee, demonstrating how Members375can come together to develop a solution that makes a meaningful376difference in addressing a serious cybersecurity problem.377    That kind of bipartisan work is just as necessary today, and I am378confident today's hearing will help inform this subcommittee's efforts379to extend necessary support to State and local governments.380    As we consider State and local cyber grant reauthorization, it is381important to remember that cyber attacks on State and local governments382affect all our districts, whether they are in blue States or red States383and whether they are urban, suburban, or rural.384    In my district, the city of Hayward suffered a ransomware attack in385the summer of 2023 that shut down the city's computer networks for more386than 2 weeks.387    And just 2 months ago, Hayward began notifying individuals that388personally identifiable information, including social security numbers389and sensitive medical information, had been breached as part of that390ransomware incident.391    I know this story is not unusual, and I am sure my colleagues have392also heard from local governments impacted by cyber attacks and looking393for help.394    With cyber attacks coming from foreign criminal gangs and nation-395state adversaries, we cannot leave our State and local governments to396fend for themselves.397    Federal support for State and local governments is necessary to398address this national security threat, and the State and Local399Cybersecurity Grant Program reflects that understanding.400    By providing $1 billion to State, local, Tribal, and territorial401governments, Congress took a major step in strengthening cyber defenses402and bringing stakeholders together to develop and implement much-needed403cybersecurity planning by State governments.404    We are a more secure country today because of this investment.405    But as we all know, our adversaries are not stopping their efforts406to breach public-sector networks.407    When the State and Local Cyber Grant Program was created, our408primary concern was the ransomware epidemic plaguing our communities.409    Of course, that threat remains, but China's campaign to pre-410position on our critical infrastructure networks for potential future411destructive attacks is even more alarming.412    While much of our critical infrastructure is privately owned, some413of our most vital services are provided by the public sector.414    Publicly-owned and -operated water and electric utilities,415transportation systems, and emergency services could all be targets in416destructive attacks by China or other adversaries.417    Reauthorizing the cybersecurity grant program is necessary to418ensure we do not take our foot off the gas at this critical time, and419passing a reauthorization bill before the program expires in September420is one of my top priorities this year.421    What I have heard from stakeholders is appreciation for the422tremendous value of this program and a desire for sustained,423predictable, and consistent funding levels that will allow State and424local governments to build on their progress and properly budget and425plan their efforts.426    The cybersecurity grant program operates under a partnership427between FEMA and CISA, two incredibly important agencies that have428unfortunately come under attack in recent months.429    By leveraging FEMA's grants administration expertise and CISA's430cybersecurity expertise, this program has been able to deliver for431State and local governments in ways that would be impossible without432that partnership.433    Trump administration plans to eliminate FEMA and further cut CISA's434workforce would devastate DHS's ability to support State and local435governments across a range of threats, including cyber attacks.436    The cybersecurity grant program demonstrates the value of437collaboration between DHS's components, and I hope we can work in a438bipartisan way to better educate Secretary Noem about the tremendous439value these agencies provide the American public.440    Additionally, I am deeply concerned by reports that FEMA has been441pausing distributions of funding to implement cyber grants, along with442other grant programs.443    China is not pausing their efforts to target our critical444infrastructure. We should not pause our efforts to defend ourselves.445    I urge the Trump administration to release cyber grant funds to446States, territories, and Tribes and to comply with court orders against447its illegal pauses.448    Finally, I would like to thank the witnesses for appearing before449us today.450    Expertise from both the public and private sector is invaluable as451we look to reauthorize and improve the State and Local Cybersecurity452Grant Program, and I look forward to their testimony.453454    Mr. Garbarino. The gentleman yields back.455    Other Members of the committee are reminded that opening456statements may be submitted for the record.457    [The statement of Ranking Member Thompson follows:]458             Statement of Ranking Member Bennie G. Thompson459                             April 1, 2025460    Four years ago, bipartisan lawmakers led by Congresswoman Yvette461Clarke and Chairman Garbarino passed legislation to establish a State462and Local Cybersecurity Grant program.463    I am pleased to have the opportunity to hear about the program's464implementation today as we begin our important work on reauthorization.465    When the State and Local Cybersecurity Grant program was initially466enacted, the country was in the midst of a ransomware epidemic that467cost local governments across the country millions of dollars--to say468nothing of public services that couldn't be provided to taxpayers.469    No part of the country was immune. Ransomware attacks hit cities470from Atlanta to Albany, and a bipartisan consensus emerged that471investing in prevention would not only ensure the continuity of public472services but also save money in the long run.473    By all accounts, the State and Local Cybersecurity Grant program is474working.475    According to stakeholders, the FEMA and CISA have been effective476stewards of the program, soliciting and incorporating feedback from477State and local governments to improve the program and make478applications and drawdowns more efficient.479    Incorporating lessons learned from previous grant programs, the480Cybersecurity program required States to put in place governance481structures and State Cybersecurity Plans to ensure Federal dollars were482invested in a manner that would achieve the security goals set by483Congress.484    The relationships built through this process have facilitated new,485strategic State-wide collaborations.486    The most consistent piece of feedback I have received about the487State and Local Cybersecurity Grant Program is that it must be488reauthorized.489    State and local governments have made significant progress490hardening their information systems and building resilience, but there491is more work to do.492    And, unfortunately, cyber criminals continue to hold Government493services hostage in hopes of cashing in.494    Just under 2 years ago, a county in my district was hit by a495ransomware attack, crippling information systems and disrupting basic496services for the public like processing real estate transactions and497providing car tags.498    This one ransomware attack cost the county over half of a million499dollars in recovery costs alone.500    We also know that state actors are targeting publicly-owned501critical infrastructure.502    In late December 2023, Iranian hackers targeted small water503utilities across the country.504    And Volt Typhoon--a state-sponsored threat actor from China--has505sought to gain access to critical infrastructure networks in order to506execute destructive cyber attacks in the event of a U.S.-China507conflict.508    Congress would never leave State and local governments to fend for509themselves in a physical attack. We cannot leave them to fend for510themselves in cyber space.511    Before I close, I would like to express my deep concern about512recent actions the Trump administration has taken that frustrate the513effectiveness of Federal grant programs.514    I understand the President's grant freeze has interfered with the515timely drawdown of grant funds. These delays create chaos for grantees516and undermine the security goals of grant programs.517    I also would like to express my opposition to the President's518efforts to abolish FEMA and gut CISA.519    These 2 agencies play central roles in the security and resilience520of U.S. critical infrastructure, and we cannot afford to play fast and521loose with them.522    Finally, I want to be on the record objecting to CISA's cuts to the523Multi-State Information and Analysis Center (MS-ISAC).524    The MS-ISAC provides essential cybersecurity services to State and525local governments. Fewer services means less security. And that's a526price too high to pay.527528    Mr. Garbarino. I am pleased to have a distinguished panel529of witnesses before us today. I ask that our witnesses please530rise and raise their right hand.531    [Witnesses sworn.]532    Mr. Garbarino. Let the record reflect the witnesses533answered in the affirmative. Thank you and please be seated.534    I would now like to formally introduce our witnesses. Mr.535Robert Huber, he currently serves as the chief security officer536at Tenable. He oversees the organization's global security and537research teams to reduce security risks to the company, its538customers and industry. Prior to his private-sector career, Mr.539Huber served in the U.S. Air Force and National Guard for 22540years.541    Mr. Allen Fuller serves as the chief information officer542for the State of Utah. In his role he oversees all IT functions543for State executive branch agencies aiming to improve544innovation and government services through technology. He also545serves as the secretary of treasurer of the National546Association of State Chief Information Officers.547    The honorable Kevin Kramer is the first vice president of548National League of Cities where he leads efforts of city, town,549and village leaders to improve the quality of life for their550residents. Additionally, Mr. Kramer serves as councilman for551Louisville, Kentucky where he is the chair for the minority552caucus, vice chair of the budget committee, and member of the553government oversight audit appointments committee.554    Mr. Mark Raymond is chief information officer for the State555of Connecticut where he oversees the department of556administrative services, bureau of information technology557solutions, and holds operational responsibility for the State's558technology infrastructure.559    Prior to a public service career, Mr. Raymond spent 21560years in a technology consulting industry where he supported561Federal, State, and local clients.562    I thank the witness for being here today. I now recognize563Mr. Huber for 5 minutes to summarize his opening statement.564565  STATEMENT OF ROBERT HUBER, CHIEF SECURITY OFFICER, TENABLE,566                              INC.567568    Mr. Huber. Chairman Garbarino, Ranking Member Swalwell,569Members of the subcommittee, thank you for the opportunity to570testify today and for convening this important hearing. I'm Bob571Huber, chief security officer, head of research and of public572sector at Tenable, a cybersecurity exposure management company.573    Tenable serves 44,000 customers worldwide, including the574Federal Government as well as State, local, Tribal, and575territorial governments and critical infrastructure operators.576State and local governments play a crucial role in managing577protecting critical infrastructure such as water treatment578facilities, energy grids, transportation networks. They are on579the front lines of defending these systems from cyber attacks580that could disrupt vital services, erode public confidence, and581compromise national security. Protecting essential systems is582more urgent than ever. In 2023, the China-backed cyber583espionage group Volt Typhoon, known for targeting critical584infrastructure, attacked a Massachusetts utility. While585disruptions were avoided, the incident showed the growing586sophistication of adversaries who could position themselves to587perpetrate future attacks on critical infrastructure.588    In addition, ransomware attacks doubled between 2018 and5892024 causing over $1 billion in operational down time for State590and local governments. These threats highlight the need for591robust cybersecurity measures and coordinated efforts among all592levels of government and the private sector detect, mitigate,593and recover from these cyber threats.594    The State and Local Cybersecurity Grant Program, or SLCGP,595is a vital tool in addressing these challenges, providing $1596billion over 4 years to help State and local governments597address cybersecurity risks.598    To receive funds States have to follow a structured599process, including establishing a cybersecurity planning600committee to include State and local officials. Together they601must develop a State border security plan that incorporates602baseline requirements and alignment, cybersecurity best603practices, and international standards.604    States created different SLCGP programs. Some provided605competitive grants while local governments could apply for606funding for cybersecurity projects. Others provide shared607services to local governments such as multifactor608authentication, vulnerability management, or endpoint detection609services. States like Connecticut, Utah, and Virginia are610successful use cases of the SLCGP program. Virginia's whole-of-611State approach focuses on collaboration, enterprise-level612visibility, and efficient resource allocation. Virginia613provided free cybersecurity planning capability assessments to614local entities who could then apply for funding to address615identified gaps through a streamlined application process.616Eighty percent of eligible localities applied for the funding617highlighting the need for assistance. Balanced central618oversight with decentralized execution enabled Virginia to619exercise its overall cybersecurity resilience.620    SLCGP objectives include continuous monitoring, asset621inventory and vulnerability prioritization, which are all622essential components of the exposure management approach.623Exposure management shifts organizations from a reactive624approach to proactive. Risk-informed strategies across modern625attack surfaces, such as operational technology iterative626things, as well as cloud configurations. This proactive627approach helps State and local agencies anticipate and mitigate628risk before the impact vital systems.629    SLCGP has significantly contributed to enhancing630cybersecurity across State and local governments by providing631essential funding, fostering collaboration, and encouraging632strategic and proactive planning based on best practices. It633has notably strengthened relationships between State and local634officials through the cybersecurity planning committees and635their collective development of the cybersecurity plans.636    To continue and to build on SLCGP's success, Tenable637recommends reauthorizing the program with the following638improvements: ensure sustainable funding by extending the639program's duration and enable long-term planning; maintaining640alignment with recognized standards and frameworks such as the641NIST cybersecurity framework; reducing the administrative642burdens and providing clear guidance through simplified643applications; and, lowering and leveling cost-share644requirements for effective planning, continuing to encourage645whole-of-State and proactive exposure management strategies and646engaging the private sector and stakeholders to address647evolving threats and best practices.648    Continued success of the SLCGP program also depends on649having qualified cybersecurity professionals at all levels to650manage it. Tenable supports the enactment of the Cyber PIVOTT651Act to address work-force shortages, to reach steelworkers and652create diverse pathways into government cybersecurity careers.653    Thank you again for your attention to cybersecurity,654continued support of the SLCGP and for the opportunity to655testify. I look forward to working with you to secure our656Nation's cyber assets. I am happy to answer your questions.657Thank you.658    [The prepared statement of Mr. Huber follows:]659                   Prepared Statement of Robert Huber660                             April 1, 2025661                              introduction662    Chairman Garbarino, Ranking Member Swalwell, Chairman Green,663Ranking Member Thompson, and Members of the subcommittee, thank you for664the opportunity to testify before you today on the State and Local665Cybersecurity Grant Program (SLCGP). I also commend the subcommittee666for convening this important hearing and for your continued leadership667in advancing cybersecurity and safeguarding our Nation's critical668infrastructure. Your efforts are vital to strengthening the security669and resilience of our communities, and I look forward to discussing how670the SLCGP supports these priorities.671    My name is Bob Huber and I am the chief security officer, head of672research, and president of public sector at Tenable, a cybersecurity673exposure management company that provides organizations, including674Federal, State, and local governments, with an unmatched breadth of675visibility and depth of analytics to measure and communicate676cybersecurity risk. In collaboration with industry, Government, and677academia, Tenable is raising awareness of the growing security risks678impacting critical infrastructure and the need to take steps to679mitigate those risks.680    Prior to joining Tenable, I was a chief security and strategy681officer at Eastwind Networks, and the co-founder and president of682Critical Intelligence, an operational technology (OT) threat683intelligence and solutions provider, which cyber threat intelligence684leader iSIGHT Partners acquired in 2015. I served as a member of the685Lockheed Martin Computer Incident Response Team (CIRT), an OT security686researcher at Idaho National Laboratory, and was a chief security687architect for JP Morgan Chase. I am a board member and advisor to688several security start-ups and served in the U.S. Air Force and Air689National Guard for more than 22 years. As a member of the Air National690Guard, I provided support to the great State of Delaware for over 18691years, delivering security assessments of critical infrastructure692throughout the State and CTAA (coordinate, train, advise, assist) in693both title 32 and State active duty. Before retiring in 2021, I694provided offensive and defensive cyber capabilities supporting the695National Security Agency (NSA), United States Cyber Command, and State696missions.697    As Tenable's chief security officer, I oversee the company's global698security and research teams, working cross-functionally to reduce risk699to the organization, its customers, and the broader industry. This700includes directing the Tenable Security Response Team in analyzing701advanced threats like Volt Typhoon and Salt Typhoon, supporting702vulnerability and asset management, leading the Tenable secure software703development team, and promoting best practices such as Zero Trust and704cyber hygiene. I am also responsible for briefing Tenable's board of705directors on our cybersecurity program and providing an overview of our706key objectives and performance metrics.707    My work to keep Tenable secure provides a similar vantage point as708State and local government cybersecurity leaders when it comes to709protecting an organization's assets and networks. Tenable adheres to710several cybersecurity standards, frameworks and best practices to711protect its own infrastructure and data. Tenable aligns its security712program around the National Institute of Standards and Technology713(NIST) Cybersecurity Framework (CSF), and we are certified against the714International Organization for Standardization (ISO)/International715Electrotechnical Commission (IEC) 27001/27002 standard. Additionally,716Tenable products are designed to support compliance with various717security frameworks, including NIST CSF; ISO/IEC 27001/27002; and the718Center for Internet Security (CIS) Critical Security Controls.719                             about tenable720    Tenable is the exposure management company, exposing and closing721the cybersecurity gaps that erode organization value, reputation, and722trust. The company's AI-powered exposure management platform radically723unifies security visibility, insight, and action across the attack724surface, equipping modern organizations to protect against attacks from725IT infrastructure to cloud environments to critical infrastructure and726everywhere in between. By protecting enterprises from security727exposure, Tenable reduces business risk for approximately 44,000728customers around the globe.729    As the creator of Nessus, Tenable extended its expertise in730vulnerabilities to deliver the world's first platform to see and secure731nearly any digital asset on any computing platform, including732operational technology (OT) and internet of things (IoT). Tenable733customers include approximately 65 percent of the Fortune 500,734approximately 50 percent of the Global 2000, and large Government735agencies.\1\ Approximately 15 percent of Tenable's business is related736to the public sector. We collaborate with Federal agencies such as the737Cybersecurity and Infrastructure Security Agency (CISA) and advocate738for strong baseline cybersecurity standards across critical739infrastructure sectors. We are active in public-private partnerships740with the Government through the President's National Security741Telecommunications Advisory Committee (NSTAC), the IT Sector742Coordinating Council (IT-SCC), the Cybersecurity and Infrastructure743Security Agency's (CISA) Joint Cyber Defense Collaborative (JCDC), and744the NIST National Cyber Center of Excellence (NCCOE).745---------------------------------------------------------------------------746    \1\ Tenable, ``About Tenable,'' www.tenable.com.747---------------------------------------------------------------------------748    Tenable has been a long-standing strategic partner to State, local,749Tribal, and territorial governments (SLTTs), providing a proactive750risk-based approach to exposure management by helping them reduce risk751with a unified view of all assets and resulting risk exposure.752    the threat landscape for state, local, tribal, and territorial753                              governments754    State, local, Tribal, and territorial governments (SLTTs) play a755significant role in safeguarding critical infrastructure, public756services, and sensitive citizen data from an increasing array of cyber757threats. They are at the forefront of cyber defense, overseeing public758safety functions, regulating utilities, and managing essential systems759such as water treatment facilities, transportation networks, energy760grids, and communication systems. In addition to securing these761critical operations, SLTTs are responsible for protecting vast amounts762of personal data, including financial records and health information.763Ensuring the security of these systems and data is essential not only764for maintaining public trust, complying with privacy laws, and765preventing costly disruptions, but also as a matter of national766security. The stability and resilience of these systems are critical to767the Nation's economic strength, defense capabilities, and overall768safety, making SLTTs key players in the broader effort to protect the769country from evolving cyber threats.770Advanced Persistent Threat Actors771    This growing threat is exemplified by real-world cyber incidents772that highlight the vulnerabilities of critical infrastructure and the773potential consequences of such attacks. In 2023, Volt Typhoon, an774advanced persistent threat (APT) actor backed by the People's Republic775of China (PRC), launched a prolonged cyber attack on the Littleton776Electric Light and Water Departments (LELWD) in Massachusetts, the777first known strike on a U.S. power utility by the group.\2\ The attack778targeted the utility's operational technology (OT) infrastructure in an779effort to exfiltrate sensitive data. Although LELWD was able to detect780and mitigate the breach before major disruptions occurred, the incident781underscored the increasing sophistication of nation-state cyber threats782and the risks they pose to essential services.783---------------------------------------------------------------------------784    \2\ Waqas, ``Chinese Volt Typhoon Hackers Infiltrated US Electric785Utility for Nearly a Year,'' Hack Read, March 12, 2025, https://786hackread.com/chinese-volt-typhoon-hackers-infiltrated-us-electric-grid.787---------------------------------------------------------------------------788    This attack was not an isolated incident but part of a broader789pattern of cyber espionage and disruption orchestrated by Volt Typhoon.790Government officials, including former National Security Agency (NSA)791Cybersecurity Director Rob Joyce, have expressed growing concerns about792the escalating threat posed by China-backed hacking campaigns,793including Volt Typhoon. These threat actors have latched onto critical794infrastructure through compromised equipment including internet routers795and cameras. According to Joyce, the NSA continues its efforts to796eradicate such threats and the United States is still finding victims797of the Volt Typhoon hacking collective.\3\ It is encouraging to see798Members of this committee, including Chairman Mark Green, Chairman799Andrew Garbarino, and Congressman Josh Brecheen prioritize800investigations into these Chinese-backed intrusions, calling on the801Department of Homeland Security (DHS) to assess the Federal802Government's response and strengthen the resilience of America's803cybersecurity posture.\4\804---------------------------------------------------------------------------805    \3\ David DiMolfetta, ``U.S. still finding victims of advanced806China-linked hacking campaign, NSA official says,'' Nextgov/FCW, March80714, 2025, https://www.nextgov.com/cybersecurity/2024/03/us-still-808finding-victims-advanced-china-linked-hacking-campaign-nsa-official-809says.810    \4\ Chairman Mark Green, Chairman Andrew Garbarino, and Congressman811Josh Brecheen, Congressional Letter to the Department of Homeland812Security (DHS) Secretary Kristi Noem on Volt Typhoon and Salt Typhoon,813March 17, 2025, 2025-03-17-Green-Garbarino-Brecheen-to-Noem-DHS-re-814Volt-and-Salt-Typhoon.pdf.815---------------------------------------------------------------------------816    The increase in activity from APT actors targeting U.S. critical817infrastructure,\5\ as highlighted in the Office of the Director of818National Intelligence (ODNI) 2025 Annual Threat Assessment of the U.S.819intelligence community, reinforces the need for heightened vigilance at820the State and local levels.\6\ The PRC remains the most active and821persistent threat to U.S. critical infrastructure, much of which is822managed by both public and private-sector entities. Safeguarding823against such sophisticated threats demands coordinated efforts between824national intelligence agencies, Federal civilian agencies, and State825and local governments. Only through this coordinated approach can the826United States effectively detect, mitigate, and recover from these827cyber attacks, securing the Nation's critical systems and protecting828national security.829---------------------------------------------------------------------------830    \5\ CISA, PRC State-Sponsored Actors Compromise and Persistent831Access to U.S. Critical Infrastructure, Feb. 7, 2024, https://832www.cisa.gov/news-events/cybersecurity-advisories.833    \6\ ODNI, 2025 Annual Threat Assessment of the U.S. Intelligence834Community, March 2025, ATA-2025-Unclassified-Report.pdf.835---------------------------------------------------------------------------836Ransomware837    In addition to these significant threats, States also face the838growing prevalence of ransomware attacks. From 2018 to 2024, incidents839of ransomware attacks targeting State and local government840organizations have doubled. A recent study by Comparitech found that841over 500 ransomware attacks were carried out during that time,842resulting in more than $1 billion in operational downtime.\7\843---------------------------------------------------------------------------844    \7\ Comparitech, Ransomware attacks on US government organizations845have cost over $1.09 billion, March 18, 2025, https://846www.comparitech.com/blog/information-security/government-ransomware-847attacks.848---------------------------------------------------------------------------849    The Center for Internet Security`s (CIS) 2023 National850Cybersecurity Review similarly revealed a sharp rise in cyber attacks851targeting State and local government organizations during the first 8852months of 2023 compared to the same period in 2022.\8\ Malware attacks853surged by 148 percent and CIS's Review also found ransomware incidents854on the rise, climbing by 51 percent during this time period. Non-855malware attacks grew by 37 percent, encompassing activities like856command shell usage and suspicious Secure Sockets Layer (SSL)857certificate detections.\9\858---------------------------------------------------------------------------859    \8\ Center for Internet Security, Nationwide Cybersecurity Review:8602023 Summary Report, Sept. 27, 2024, https://www.cisecurity.org/861insights/white-papers/nationwide-cybersecurity-review-2023-summary-862report.863    \9\ 8. Ibid.864---------------------------------------------------------------------------865    Another concerning trend highlighted in the study was a startling866313 percent rise in endpoint security service incidents, suggesting a867significant uptick in breaches and unauthorized access attempts.\10\868These findings further underline the escalating threat landscape for869State and local governments, emphasizing the urgent need for improved870cybersecurity measures to protect sensitive systems and data from these871increasingly complex and persistent attacks.872---------------------------------------------------------------------------873    \10\ 9. Ibid.874---------------------------------------------------------------------------875                    risk management executive order876    In an effort to empower State, local, and individual efforts in877enhancing national resilience and preparedness, the current878administration released Executive Order (EO) 14239: Achieving879Efficiency Through State and Local Preparedness, which aims to create880more resilient infrastructure and address risks, including cyber881attacks.\11\ Specifically, the EO ``calls for a review of all882infrastructure, continuity, and preparedness policies to modernize and883simplify Federal approaches, aligning them with the National Resilience884Strategy.''\12\885---------------------------------------------------------------------------886    \11\ The White House, Achieving Efficiency Through State and Local887Preparedness, March 19, 2025, https://www.whitehouse.gov/presidential-888actions/2025/03/test/.889    \12\ 11. Ibid.890---------------------------------------------------------------------------891              state and local cybersecurity grant program892    Given the on-going threats and increasing responsibilities of State893and local governments in managing cybersecurity risks, the State and894Local Cybersecurity Grant Program (SLCGP) is more important than ever.895Administered by the Cybersecurity and Infrastructure Security Agency896(CISA) in collaboration with the Federal Emergency Management Agency897(FEMA), SLCGP provides $1 billion over 4 years to help State, local,898Tribal, and territorial governments (SLTTs) enhance their cybersecurity899capabilities and protect critical infrastructure from evolving threats.900    To receive SLCGP funding, States follow a structured process,901beginning with the establishment of a Cybersecurity Planning Committee.902The committee must include representatives from various sectors, such903as State CIOs, CISOs, election infrastructure, public safety, emergency904management, and law enforcement. The committee is responsible for905developing and revising the State's Cybersecurity Plan, which must906incorporate baseline cybersecurity requirements that meet cybersecurity907best practices and recognized standards identified in the SLCGP908legislation, ensure the Plan reflects the input of local governments,909outline responsibilities for State and local entities, include metrics910to measure progress, and summarize associated projects. Additionally,911States must conduct capability assessments to evaluate their current912cybersecurity posture and meet Federal cost-share requirements.913    By reducing financial barriers, SLCGP enables State and local914governments to implement essential protections that safeguard their915networks and critical infrastructure. Reauthorization of the program is916vital to ensure that State and local governments have the resources917they need to safeguard the Nation's critical infrastructure.918Examples of State SLCGP Programs919    States have customized their SLCGP funding strategies to align with920their unique governance structures and local government needs. Some921examples include:922    Collaborative Whole-of-State Approach.--Virginia serves as a great923example of a whole-of-State approach for SLCGP, which provides924enterprise-level visibility, valuable lessons learned, and strong925collaboration among the participants. In Phase 1, Virginia offered a926``Cybersecurity Plan Capability Assessment'' at no cost to local927entities. This assessment provided baseline cybersecurity evaluations928and recommendations to address identified gaps in alignment with929Virginia's Cybersecurity Plan, such as intrusion detection and930response, vulnerability management, enhancing data recovery931capabilities, and improving cybersecurity maturity levels.932    Following the assessment, local entities could apply for Phase 2933funding to get the technology needed to increase their cybersecurity934maturity. Virginia designed the application process to be935straightforward and accessible, minimizing administrative burdens,936particularly for smaller and rural jurisdictions. To support937applicants, the State offers technical assistance and hosts information938sessions to guide them through the process. As a result, 80 percent of939eligible localities State-wide had at least one application for940cybersecurity improvements, so demand for this type of assistance is941high given the increased risk of cyber threats due to localities having942fewer resources and funding opportunities.943    By balancing centralized oversight with decentralized execution--944and leveraging shared capabilities, strategic planning, and common945technology--Virginia ensures that localities effectively utilize the946funding while maintaining alignment with its Cybersecurity Plan and947State-wide cybersecurity objectives. This whole-of-State strategy948strengthens cybersecurity resilience across all levels of government.949    Competitive Grants Model.--Some States are focused on providing950competitive grants for local government agencies and eligible entities.951Applicants apply for funding for cybersecurity projects that align with952SLCGP program requirements and the State's Cybersecurity Plan.953    Hybrid Model with Competitive Grants and Shared Services.--Other954States are adopting a hybrid model, blending competitive grant955opportunities with direct in-kind services for local and Tribal956governments. Local entities can apply for funding to support957cybersecurity initiatives. Simultaneously, the State serves as a958cybersecurity service provider, offering direct support to localities959that may lack the resources to implement these initiatives960independently. This strategy ensures that resources are distributed961equitably while fostering alignment between local implementation and962State-wide cybersecurity priorities, creating a more resilient and963collaborative cybersecurity environment.964                   state approaches to cybersecurity965    The cybersecurity of State systems and infrastructure varies widely966due to differences in resources, governance structures, and strategic967approaches. Some States have adopted a ``whole-of-State'' approach,968unifying State and local entities under a single cybersecurity969framework, often with shared service programs for local governments.970Others operate under a decentralized model, where individual State971agencies or local governments manage their own cybersecurity972infrastructure and policies independently, without centralized973coordination.974    Many States are establishing fusion centers that serve as hubs for975gathering, analyzing, and sharing threat intelligence among Federal,976State, local, Tribal, and private-sector partners. These centers often977facilitate collaboration between law enforcement and IT professionals.978Additionally, some States are creating regional security operations979centers (RSOCs) to provide centralized monitoring and incident response980capabilities, helping smaller jurisdictions with limited resources981access advanced threat detection tools.982    States are also leveraging Federal support, such as the Department983of Homeland Security's bulk purchasing agreements, which lower costs984for cybersecurity solutions. CISA offers free services, including985vulnerability scanning, penetration testing, and malicious domain986blocking, to help State and local governments mitigate cyber threats.987Despite these efforts, many States face common challenges, including988limited funding, a shortage of skilled personnel, and the absence of a989cohesive, State-wide understanding of cyber risk.990                    benefits of exposure management991    As States adopt new technologies, they are often accompanied by new992threats. In response, many security teams simply add a new siloed993security tool and team to defend that new attack surface. As a result,994security has become disjointed. The end result is fragmented visibility995with gaps that leave State and local agencies vulnerable. Exposure996management addresses this challenge by providing a more comprehensive997understanding of risk.998    Exposure management, which is aligned with the NIST Cybersecurity999Framework, supports a more cost-effective and strategic approach to1000cybersecurity, continuously assessing the accessibility,1001exploitability, and criticality of all digital assets. By implementing1002an exposure management strategy, State and local governments will be1003better-equipped to secure their expanded environment, including1004critical infrastructure, in the face of increasing cyber threats and1005campaigns from nation-state attackers. This proactive, risk-informed1006approach aligns with the Executive Order on ``Achieving Efficiency1007Through State and Local Preparedness,'' allowing State and local1008governments to take a proactive, risk-informed approach that1009prioritizes cybersecurity efforts based on actual threats, toxic risk1010combinations and attack path analysis, optimizing resource allocation1011and improving security resilience.1012    Unlike traditional cybersecurity strategies that focus solely on1013vulnerabilities, exposure management takes a broader view across the1014modern attack surface to provide a more comprehensive understanding of1015risk. It incorporates both technical and contextual factors such as1016vulnerabilities, misconfigurations, and attack paths--leveraging data1017from a spectrum of assets and technologies, including OT environments1018and IoT devices, cloud configurations, identity solutions, and web1019applications. This enables State and local agencies to prioritize1020issues that pose the most risk from across their infrastructure, making1021it easier to mitigate risks before they impact critical systems.1022    By implementing exposure management, State and local governments1023can shift from reactive to proactive security, prioritizing risks based1024on immediate threat intelligence and the attacker's perspective. This1025approach aligns with the Executive Order's efficiency goals,1026strengthening cybersecurity posture and enhancing preparedness to1027prevent attacks on critical infrastructure.1028    As State and local governments take on a more active role in cyber1029attack preparedness, it is critical to incorporate OT and IoT1030protection into an Exposure Management strategy. Most attacks on1031critical infrastructure originate in IT networks and 90 percent of1032attackers' initial access was gained via identity compromises.\13\ In1033converged environments, it is critical to include IT assets in1034discovery processes because they often interact with OT systems and can1035serve as entry points for attackers to then move laterally to disrupt1036physical processes and operations. Ensuring SLTTs have a holistic view1037of their attack surface--from IT to OT and everywhere in between--helps1038them to understand exposure, close attack paths, and reduce risk.1039Strengthening the cybersecurity of these systems not only protects1040essential services but also increases resilience with the ability to1041anticipate, withstand, and quickly recover from cyber attacks.1042---------------------------------------------------------------------------1043    \13\ CISA, CISA Analysis Fiscal Year 2022 Risk and Vulnerability1044Assessments, June 2023, https://www.cisa.gov/sites/default/files/2023-104507/FY22-RVA-Analysis%20-%20Final_508c.pdf.1046---------------------------------------------------------------------------1047          benefits of whole-of-state approach to cybersecurity1048    A whole-of-State approach fosters State-wide collaboration,1049strengthening the cybersecurity posture of all stakeholders while1050creating a unified and resilient defense strategy. By integrating the1051complex ecosystem of networks and systems under a standardized1052framework of policies, procedures, and controls, this approach enables1053State governments to optimize resources and extend cybersecurity1054support to local governments, educational institutions, and other1055organizations. The sharing of resources enhances the security of both1056State and local entities, reducing redundancies and improving overall1057efficiency. A unified approach streamlines processes, accelerates1058incident response, and facilitates reporting and compliance, ensuring a1059more proactive and coordinated cybersecurity strategy to reduce State-1060wide risk. Whole-of-State cybersecurity recognizes that SLTTs have a1061wide range of interconnected assets and systems. An attack on one part1062of the system can affect any or all of the others, compromising the1063security of the entire State, and for this reason, a coordinated and1064collaborative effort is recommended to secure the entire system.1065                       what's working with slcgp1066    The State and Local Cybersecurity Grant Program (SLCGP) has laid a1067strong foundation for improving the cybersecurity posture of State and1068local governments by fostering collaboration, enhancing cybersecurity1069strategic planning, funding priority projects, and increasing1070visibility into local government cybersecurity needs.1071    Funding.--The funding provided by SLCGP is vital for SLTTs because1072many of these entities lack sufficient resources to address the growing1073complexity and scale of cyber threats. SLTTs often operate on limited1074budgets, and prioritize essential services like public safety,1075education, and infrastructure maintenance, leaving cybersecurity1076underfunded despite its critical importance. SLCGP funding helps bridge1077this gap by providing financial support for activities such as risk1078assessments, workforce training, governance planning, and the1079implementation of cybersecurity tools. It also enables smaller1080jurisdictions to access resources they might otherwise be unable to1081afford. By addressing systemic cyber risks through these targeted1082investments, SLCGP ensures that SLTTs can better protect their1083networks, critical infrastructure, and constituents from evolving cyber1084threats.1085    Relationship Building and Collaboration.--A key benefit of SLCGP is1086the strengthened relationships between State and local officials. The1087program mandates the creation of Cybersecurity Planning Committees,1088which must include representatives from various jurisdictions--urban,1089suburban, and rural--alongside State officials, and it requires local1090governments to have meaningful input into the State's Cybersecurity1091Plan. This inclusive governance structure encourages collaboration and1092open communication, and fosters trust and alignment between State and1093local officials in addressing shared risks.1094    Development of Cybersecurity Plans Aligned with Standards and Best1095Practices.--Another advantage of SLCGP is its requirement for States to1096develop Cybersecurity Plans. These Plans must incorporate elements that1097align with recognized cybersecurity standards and best practices to1098ensure a comprehensive and effective approach to improving1099cybersecurity State-wide. These requirements promote addressing risks1100proactively while providing a clear road map for enhancing resilience1101against cybersecurity threats.1102    Visibility into Local Government Cybersecurity Needs.--SLCGP1103enhances visibility into local government cybersecurity needs by1104requiring States to engage with local entities during the planning1105process. Through assessments and feedback mechanisms, States gain a1106deeper understanding of the unique challenges faced by municipalities1107and rural areas. This enhanced visibility enables the development of1108tailored solutions that address specific vulnerabilities while aligning1109with broader State-wide priorities. By bridging the gap between State-1110level oversight and local implementation, the program ensures a1111coordinated and cohesive approach to strengthening cybersecurity1112infrastructure.1113    Encourages a whole-of-State approach to cybersecurity.--SLCGP's1114governance requirements--such as the creation of Cybersecurity Planning1115Committees and Cybersecurity Plans that involve State and local1116government officials and other stakeholders--promotes a whole-of-State1117approach to cybersecurity. As mentioned above, this approach fosters1118collaboration across the State, strengthens the cybersecurity posture1119of all parties, enables the sharing of resources, allows for economies1120of scale, reduces redundancies, improves overall efficiency, and1121creates a unified and resilient defense strategy.1122                         policy recommendations1123    Reauthorization of State and Local Cybersecurity Grant Program.--1124SLCGP has established a strong foundation for State and local1125governments to improve their cybersecurity posture. Tenable strongly1126encourages Congress to reauthorize SLCGP to ensure SLTTs continue to1127have the necessary resources and support required to address the1128increasingly sophisticated threats and increased responsibilities to1129protect their systems and critical infrastructure. Tenable also1130recommends the following improvements to the program:1131   Sustainable and Predictable Funding.--Cyber threats are1132        growing increasingly sophisticated, and critical infrastructure1133        sectors such as water utilities and public services remain1134        vulnerable. Sustained Federal investment is essential to ensure1135        these entities can continue building resilient systems capable1136        of defending against evolving risks. In addition, most1137        cybersecurity programs require at least 18 months to implement1138        and see positive effects. More predictable funding is essential1139        for building sustainable cybersecurity capabilities. The1140        current 4-year cycle creates uncertainty, discouraging States1141        from investing in multi-year projects or infrastructure that1142        may lose funding after 2026. Extending the program's duration1143        would provide States with the confidence to plan long-term1144        initiatives, maintain momentum, and develop lasting1145        cybersecurity protections.1146   Alignment with Established Cybersecurity Standards and Best1147        Practices.--State Cybersecurity Plans and projects should1148        continue to align with established cybersecurity best practices1149        and standards, such as the NIST Cybersecurity Framework, CIS1150        Critical Security Controls, and other recognized guidelines.1151        Adopting these standards ensures that State and local1152        governments leverage proven methodologies, rather than1153        reinventing processes, saving time and resources while1154        addressing systemic risks. In addition, we strongly encourage1155        SLCGP to incorporate assessments against NIST's Cybersecurity1156        Framework to identify the most significant risks, prioritize1157        them, and provide a detailed roadmap for execution.1158   Simplifying Grant Application Process.--A streamlined1159        application process for States, clear guidance for grant1160        application requirements, concise instructions, and clear1161        expectations would help States navigate the process more1162        effectively and reduce administrative burden.1163   Consistent Cost-Sharing Requirements.--The increase in cost-1164        share requirements--rising from 10 percent in fiscal year 20221165        to 40 percent by fiscal year 2025--pose significant challenges1166        for States and local governments, particularly rural areas with1167        limited budgets. This escalating financial burden can strain1168        State budgets, especially since many are planned years in1169        advance and may not accommodate these rising costs.\14\1170        Additionally, smaller and rural jurisdictions often struggle to1171        meet the match requirements, even with creative solutions like1172        in-kind contributions. Establishing a lower and consistent1173        match percentage would reduce financial strain, promote1174        equitable access to funding, and enable States to conduct long-1175        term cybersecurity planning.1176---------------------------------------------------------------------------1177    \14\ FEMA, State and Local Cybersecurity Grant Program, https://1178www.fema.gov/grants/preparedness/state-local-cybersecurity-grant-1179program.1180---------------------------------------------------------------------------1181   Risk Management Approach.--Encourage the adoption of1182        exposure management, which helps States and local governments1183        assess and mitigate risks to critical infrastructure. Exposure1184        management strategies enable a proactive, risk-informed1185        approach, improving resource allocation and security resilience1186        against evolving threats.1187   Active Stakeholder Engagement.--Active stakeholder1188        engagement is critical in both the development and1189        implementation of the SLCGP program. CISA can leverage private-1190        sector stakeholder expertise to ensure the program adapts as1191        the threat landscape evolves. States and localities can learn1192        from practitioners what processes and practices are1193        demonstrating effectiveness in mitigating risks and countering1194        threat activity.1195    By addressing these issues, a reauthorized SLCGP could better equip1196        State and local governments to manage systemic cyber risks1197        while fostering sustainability, accessibility, and resilience1198        in their cybersecurity infrastructure.1199   Workforce Development.--Tenable strongly encourages Congress1200        to enact the Cyber PIVOTT Act to help close the national1201        cybersecurity workforce gap by creating a talent pipeline for1202        government service. Modeled after the ROTC framework, the Cyber1203        PIVOTT Act offers full scholarships for 2-year degrees at1204        community colleges and technical schools in exchange for1205        government service at the Federal, State, or local level.\15\1206        This initiative not only reskills and upskills workers but also1207        provides a pathway for individuals from different backgrounds1208        to ``pivot'' into cybersecurity careers. By integrating such1209        programs into SLCGP-funded workforce development strategies,1210        States can build a sustainable and skilled cybersecurity1211        workforce capable of protecting critical infrastructure and1212        addressing emerging cyber threats. Additionally, expanding1213        training programs for government personnel at all levels should1214        be prioritized to ensure that employees are equipped to manage1215        evolving threats.1216---------------------------------------------------------------------------1217    \15\ Chairman Mark Green, Press Release: Chairman Green1218Reintroduces ``Cyber PIVOTT Act,'' Senator Rounds to Lead Companion1219Legislation, Feb. 5, 2025, https://homeland.house.gov/2025/02/05/1220chairman-green-reintroduces-cyber-pivott-act-senator-rounds-to-lead-1221companion-legislation/.1222---------------------------------------------------------------------------1223                               conclusion1224    Tenable recommends several key actions for Congress to strengthen1225the cybersecurity capabilities of State, local, Tribal, and territorial1226governments, including reauthorizing and improving the State and Local1227Cybersecurity Grant Program and prioritizing workforce development1228through initiatives like the Cyber PIVOTT Act. These steps will help1229enhance State, local, Tribal, and territorial governments' ability to1230protect critical infrastructure.1231    Chairman Garbarino, Ranking Member Swalwell, Chairman Green,1232Ranking Member Thompson, and Members of the subcommittee, thank you for1233the opportunity to testify before you today on the importance of the1234State and Local Cybersecurity Grant Program. I appreciate the1235committee's continued bipartisan work to address the growing1236cybersecurity challenges our Nation faces. As the threat landscape1237evolves, it is crucial that State, local, Tribal, and territorial1238governments have the support to improve their cybersecurity defenses. I1239look forward to collaborating with you all to ensure we provide the1240necessary funding and resources to protect our communities and critical1241infrastructure.12421243    Mr. Garbarino. Thank you, Mr. Huber.1244    I now recognize Mr. Fuller for 5 minutes to summarize his1245opening statement.12461247 STATEMENT OF ALAN FULLER, CHIEF INFORMATION OFFICER, STATE OF1248                              UTAH12491250    Mr. Fuller. Thank you, Chairman Garbarino, Ranking Member1251Swalwell, and Members of the subcommittee. It is a pleasure to1252be with you today. I'm Allen Fuller, chief information officer1253for the State of Utah, a role to which I was appointed by1254Governor Cox in March 2021. As the CIO for the State I lead the1255division of technology services, which is the consolidated IT1256organization for all of the executive branch agencies at the1257State. As part of my team, I oversee the cyber center, which is1258responsible for defending State IT assistance against cyber1259crime.1260    I'm also secretary-treasurer for the National Association1261of State Chief Information Officers or NASCIO. NASCIO is a1262national leader and advocate for technology policy at all1263levels of government and has championed substantial1264collaboration between States and the Federal Government to1265improve cybersecurity preparedness and protect or Nation's1266critical infrastructure. So as both CIO to the State of Utah1267and as a NASCIO officer, I hope to highlight the may successes1268of the State and local cybersecurity program or SLCGP today.1269    This program was provided significant--support the States1270in and local governments as we have worked together to improve1271cybersecurity posture and to address vulnerabilities. Over the1272past decade in Utah, State, county, city governments witness1273significant escalations and cyber incidents. Initially attacks1274were less frequent and less sophisticated, often targeting1275basic vulnerabilities. However, recent years have seen a surge1276in complex ransomware attacks, data breaches, and phishing1277campaigns, specifically designed to exploit government systems.1278This evolution reflects a broader trend where malicious actors1279increasingly target public-sector entities seeking to disrupt1280services, extort funds, and compromise sensitive data.1281    Local governments in particular face challenges in keeping1282pace with these threats due to budget constraints and limited1283cybersecurity expertise, making them more susceptible to these1284evolving cyber risks.1285    In Utah we applied for SLCGP funds in 2022 and received1286approximately $13 million of Federal funds and $4 million in1287matching State funds for local cybersecurity efforts.1288Assessments and audits were conducted to identify the strength1289that cybersecurity defenses around the State, including cities,1290counties, and higher education entities results found the1291cybersecurity systems were significantly under-developed in1292many cases, leaving local government entities at serious risks.1293    Note that many of these cities and counties have limited1294resources with very little or no IT support. The SLCGP is being1295utilized to address those concerns by providing much-needed1296tools to local entities. With funding secure through the SLCGP1297and course-aligned State appropriations, a comprehensive1298cybersecurity initiative has been deployed across 1401299governmental entities in the State. These include 23 counties,130094 municipalities, and 23 special districts. Through this1301effort endpoint security has been the provision for over 26,0001302devices. And cybersecurity awareness training is being1303delivered to 31,000 local government employees. The program1304includes scheduled engagements with local leaders to guide the1305progression of State-wide cybersecurity initiatives. The1306results have been extremely positive. We have blocked 7 major1307cyber-attack incidents in the last 6 months alone.1308    I will speak to 2 of these. Shortly before Christmas the1309CIO of the local airport urgently contacted me about a cyber1310attack in progress. The cyber criminals attempted to deploy1311ransomware on the airport's IT systems, which would have been1312disastrous, especially during the busy holiday travel season.1313Our cyber center team immediately worked with the airport's IT1314team to address the issue. Fortunately, SLCGP funds have1315provided security tools, are able to detect and interrupt the1316attack as it was happening. The common tooling and established1317relationships with local staff enabled a rapid response and1318limited the impact of the attack. As a result, the airport1319service was not interrupted and no ransom was paid.1320    Second, recently a 9-1-1 emergency dispatch center in Utah1321was a victim of ransomware attack on systems that provide 9-1-11322services. Again, SLCGP funds have provided security tools that1323detected and interrupted the attack as it was happening. Common1324tooling and established relationships enabled a rapid response1325that limited the attack's impact. Critical 9-1-1 dispatch1326services were able to continue in one of our biggest counties.1327    Utah's positive experience to this grant program is not an1328outlier. SLCGP has allowed many States to embrace a whole-of-1329State approach to cybersecurity. By approaching cybersecurity1330jointly, information is widely shared, and incident response is1331more effective. States have been able to use SLCGP to provide a1332vital technology of services and many smaller communities1333simply would not be able to implement.1334    The State and Local Cybersecurity Grant Program helps1335stakeholders developing a solid foundation on which to continue1336to strengthen their defenses and to modernize both their1337technology and their processes. I encourage the subcommittee to1338extend funding for the program.1339    I look forward to discussing it today and to answering your1340questions. Thank you very much.1341    [The prepared statement of Mr. Fuller follows:]1342                   Prepared Statement of Alan Fuller1343                             April 1, 20251344    Chairman Garbarino, Ranking Member Swalwell, and Members of the1345subcommittee: I am Alan Fuller, chief information officer for the State1346of Utah, a role to which I was appointed by Governor Cox in March 2021.1347As CIO for the State of Utah, I lead the Division of Technology1348Services, the consolidated IT organization for the executive branch1349agencies in the State government. As part of my team, I oversee the1350Cyber Center, which is responsible for defending State IT systems1351against cyber crime. The Utah Cyber Center (cybercenter.utah.gov) was1352created to coordinate efforts between State, local, and Federal1353resources to bolster State-wide security and help defend against future1354cyber attacks, by sharing cyber threat intelligence, best practices,1355and through strategic partnerships.1356    I am also the secretary-treasurer for the National Association of1357Chief Information Officers (NASCIO.) NASCIO is the collective voice of1358the Nation's State and territorial chief information officers, chief1359information security officers, and chief privacy officers. Its mission1360is to advance government excellence through trusted collaboration,1361partnerships, and technology leadership. NASCIO is a national leader1362and advocate for technology policy at all levels of government, and has1363championed substantial collaboration between States and the Federal1364Government to improve cybersecurity preparedness and protect our1365Nation's critical infrastructure.1366    It is as both CIO for the State of Utah and as a NASCIO officer1367that I hope to highlight the many successes of the State and Local1368Cybersecurity Grant Program (SLCGP) today. Though no program is1369perfect, SLCGP has provided significant support to States and local1370governments as we have worked to improve our cybersecurity posture and1371address vulnerabilities.1372                           utah's experience1373    Over the past decade in Utah, State, county, and city governments1374have witnessed significant escalations in cyber incidents. Initially,1375attacks were less frequent and sophisticated, often targeting basic1376vulnerabilities. However, recent years have seen a surge in complex1377ransomware attacks, data breaches, and phishing campaigns specifically1378designed to exploit government systems. This evolution reflects a1379broader trend where malicious actors increasingly target public-sector1380entities, seeking to disrupt services, extort funds, and compromise1381sensitive data. Local governments, in particular, face challenges in1382keeping pace with these threats due to budget constraints and limited1383cybersecurity expertise, making them more susceptible to these evolving1384cyber risks. Before implementation of the SLCGP, incidents were not1385reported to the State for fear the State's role would be punitive in1386nature. If the State was notified, options for response were very1387limited as either data had already been compromised or system damage,1388such as ransomware, had already been executed. In many instances,1389paying a ransom or providing credit monitoring for victims were the1390only recovery options.1391    In Utah, we applied for SLCGP funds in 2022 and received1392approximately $13 million Federal funds and $4 million in matching1393State funds for local cybersecurity efforts. Assessments and audits1394were conducted to identify any existing cybersecurity issues around the1395State, including cities, counties, local education agencies, and higher1396education entities. Results found that cybersecurity systems are1397significantly under-developed in many cases, leaving local government1398entities with serious risks (Image 1).13991400    Many of these cities and counties have limited resources with very1401little to no IT support. They are unable to provide adequate security1402tools and efforts to protect IT systems. The SLCGP is being utilized to1403address those concerns by providing much-needed tools to local1404entities.1405    With funding secured through the SLCGP and corresponding State1406appropriations, a comprehensive cybersecurity initiative has been1407deployed across 140 governmental bodies. This encompasses 23 counties,140894 municipalities, and 23 special districts. Consequently, endpoint1409security has been provisioned for over 26,000 devices, and1410cybersecurity awareness training, augmented with simulated phishing1411exercises, is being delivered to 31,000 local government employees. The1412whole-of-State program incorporates scheduled engagements with local1413leadership to deliberate on active projects and strategically guide the1414progression of State-wide cybersecurity initiatives.1415    The results have been extremely positive. We have blocked 7 major1416cyber-attack incidents in the last 6 months. I will speak of 2 of1417these.1418    Shortly before Christmas, the CIO of a local airport urgently1419contacted me about a cyber attack. Cyber criminals attempted to deploy1420ransomware on the airport's IT systems, which would have been1421disastrous, especially during the busy holiday travel season. Our CISO1422and Cyber Center team immediately worked with the airport's IT team to1423address the issue. Fortunately, SLCGP funds had provided security tools1424that were able to detect and interrupt the attack as it was happening.1425The common tooling and established relationships with local staff1426enabled a rapid response that limited the impact of the attack. As a1427result, the airport's service was not interrupted, and no ransom was1428paid.1429    Recently, a 9-1-1 dispatch center in Utah was the victim of a1430ransomware attack on systems that provide 9-1-1 services. SLCGP funds1431had provided security tools that detected and interrupted the attack as1432it was happening. Common tooling and established relationships enabled1433a rapid response that limited the attack's impact.1434               a whole-of-state approach to cybersecurity1435    Utah's positive experience with this grant program is not an1436outlier. SLCGP has allowed States to further embrace a ``whole-of-1437State'' approach to cybersecurity, which NASCIO defines as1438collaboration among State agencies and Federal agencies, local1439governments, the National Guard, education (K-12 and higher education),1440utilities, private companies, health care and other sectors to address1441common technology and cybersecurity challenges. NASCIO has long1442advocated for a whole-of-State approach to cybersecurity. By1443approaching cybersecurity as a team sport, information is widely shared1444and each stakeholder has a clearly-defined role to play when an1445incident occurs.1446    Under this approach and with the flexibility allowed to provide1447shared services to local governments, States have been able to use1448SLCGP to provide vital technology services that many smaller1449communities otherwise would not be able to implement. While some States1450have elected to pass SLCGP funding entirely on to local governments,1451most have either provided service only or employed a hybrid approach of1452the 2 methods. According to one State CIO, ``We are implementing (or1453trying to) a whole-of-State approach, recognizing that our weakest1454links often need the most support, particularly those under-funded1455entities that regularly deal with highly sensitive data.''1456    States are also finding a wide array of applicable uses for SLCGP1457funding. According to the NASCIO 2024 State CIO Survey, cybersecurity1458training, endpoint detection and assessments are the primary focus for1459funds, followed closely by support for migration to .gov domains and1460security monitoring. It is precisely these critically important but1461attainable basic cyber hygiene measures that the grant was designed to1462address. Additionally, almost 100 percent of survey respondents stated1463that they would like for SLCGP to continue and cited the uncertainty1464around the program's long-term future as an impediment to further1465success. As we've seen in Utah, almost every State who has implemented1466funding from this program has seen some examples of tangible success in1467improving their cybersecurity posture.1468    Perhaps most encouraging, however, has been the spirit of1469collaboration between State and local leaders that the grant has1470fostered. One requirement to receive funding, the creation of a1471cybersecurity planning committee to guide how the money will be spent,1472meaning that these individuals are able to build relationships and1473trust that will allow them to respond more effectively and successfully1474to any cybersecurity attacks. Additionally, the ``whole-of-State''1475approach has allowed local governments to learn about State services1476they can utilize, and for State technology leaders to understand where1477the greatest needs are.1478    It is this proven track record of accomplishment that led NASCIO1479and several other State and local organizations, including the National1480League of Cities, National Conference of State Legislators and National1481Governors Association to send a letter to the leaders of the House and1482Senate Appropriations committees urging them to maintain funding for1483SLCGP and to refrain from any actions that would undermine its1484continued success.1485                         suggested improvements1486    Of course, while we are encouraged by the program's accomplishments1487so far, not everything has been smooth sailing. Initial guidance was1488slow to be released, and States often received conflicting answers from1489CISA and FEMA to the same question. However, many of those early issues1490have been largely resolved.1491    As Congress begins considering reauthorization of this program,1492States have the following recommendations:1493   Reduce matching contribution for State-wide cybersecurity1494        efforts that provide shared services to local governments;1495   Stabilize the matching formula across all years of the grant1496        to simplify administration;1497   Continue local government assessment requirements for1498        participation;1499   Elevate the shared services, whole-of-State option to ensure1500        that States understand that this model is acceptable when1501        administering SLCGP funds;1502   Stress that local government cybersecurity assessments and1503        other basic cybersecurity hygiene goals are undertaken before1504        technology purchases are executed;1505   Provide long-term stability and assurance for the program1506        with a longer reauthorization.1507                               conclusion1508    The State and Local Cybersecurity Grant Program is not a ``silver1509bullet'' that can entirely solve our Nation's cybersecurity challenges.1510It does, however, help stakeholders develop a solid foundation on which1511to continue to strengthen their defenses and modernize both their1512technology and processes. I look forward to discussing it today and1513answering your questions. Thank you.15141515    Mr. Garbarino. Thank you, Mr. Fuller.1516    I now recognize Mr. Kramer for 5 minutes to summarize his1517opening statement.15181519   STATEMENT OF KEVIN KRAMER, FIRST VICE PRESIDENT, NATIONAL1520          LEAGUE OF CITIES; COUNCILMAN, LOUISVILLE, KY15211522    Mr. Kramer. Good morning, Chairman Garbarino, Ranking1523Member Swalwell, and Members of the subcommittee, thank you for1524the opportunity to testify today. I am councilman Kevin Kramer1525from Louisville Metro Government in Kentucky. I serve as the1526first vice president for the National League of Cities. I am1527honored to speak on behalf of both my city and the 19,0001528cities, towns, and villages represented by the National League1529of Cities.1530    NLC is committed to strengthen the Federal local1531partnership that supports our communities. Prior to my current1532role I chaired NLC's information technology and communications1533committee. I also work as a teacher at a small all girls high1534school. I appreciate this subcommittee's focus on reauthorizing1535the State and Local Cybersecurity Grant Program and I'm here to1536share both our local experience in Louisville and broader1537perspectives from cities across the country.1538    Local governments are frequent targets of cyber attacks.1539From both criminal organizations and nation-state actors. We1540are responsible for sensitive data, public payment systems, and1541critical infrastructure. When city networks are attacked,1542emergency services may be disrupted, personal data can be1543exposed, and entire communities can be impacted.1544    Recovering from these incidents often costs hundreds of1545thousands of dollars and hundreds of work hours. As the1546committee has noted in previous hearings, local governments1547face serious capacity constraints. This is especially true of1548small and rural communities. Of the 19,000 municipalities1549nationwide, over 16,000 have populations under 10,000 people.1550Many have no dedicated IT staff at all. Even larger cities1551often struggle to hire and retain qualified cybersecurity1552professionals. Yet, smaller size does not equal lower risk.1553Every community is vulnerable. Louisville Metro Government has1554received funding through the State and Local Cybersecurity1555Grant Program for 2 fiscal years. The most recent grant helped1556support the creation of the Kentucky Cyber Threat Intelligence1557Cooperative or KVTIC.1558    This is a new platform for sharing timely, actionable,1559cyber threat information among regional government and private-1560sector partners. We built it to address delays in the existing1561systems for threat reporting and communications. KCTIC allows1562anonymous threat data from cooperative members to be shared in1563near-real time. This grassroots, multi-sector effort1564strengthens the entire region's cyber resilience, not just1565Louisville's and it wouldn't be possible without this grant1566program.1567    The State and local cybersecurity program is a vital1568component of our national security strategy. It fosters State,1569local collaboration, builds awareness among local leaders and1570enables proactive planning. But for the program to reach its1571full potential improvements are needed. First, the one-size-1572fits-all pass-through model limits efficiency. Larger1573jurisdictions like Louisville are capable of managing direct1574Federal grants and should be able to apply without going1575through the State. We urge Congress to create a complimentary1576direct funding track for eligible larger municipalities.1577    Second, the application process must be more accessible.1578Small communities face major barriers, tight deadlines, complex1579requirements and limited staff capacity. These are often the1580very communities that would benefit the most. Simplifying the1581application process and extending time lines would make1582participation more realistic for them. We are also encouraged1583by emerging models like multijurisdictional grants, managed by1584State and municipal associations.1585    These allow technical services to be delivered to many1586communities at once and approach far more efficient than1587requiring each town to stand up its own cybersecurity team.1588Just as most people take their cars to a qualified mechanic,1589small governments need trusted partners to handle complex cyber1590tasks. Above all, we ask Congress to reauthorize and fully fund1591this program with predictability and consistency. Without that,1592local governments are less likely to make the necessary1593investments in planning and assessment that leads to strong1594applications and long-term resilience.1595    Cybersecurity is a whole-of-Nation challenge, it demands a1596true intergovernmental partnership. The State and Local1597cybersecurity Grant Program is a cornerstone of that1598partnership.1599    Thank you again for the opportunity to testify. I look1600forward to your questions.1601    [The prepared statement of Mr. Kramer follows:]1602                   Prepared Statement of Kevin Kramer1603                             April 1, 20251604    Good morning, Chairman Garbarino, Ranking Member Swalwell, and1605Members of the subcommittee.1606    I am Councilman Kevin Kramer from Louisville Metro Government in1607Kentucky, and first vice president of the National League of Cities.1608Thank you for inviting NLC to testify before the subcommittee today as1609you consider reauthorization of the State and Local Cybersecurity Grant1610Program. I am pleased to share with you my city's experience as a1611recipient of one of these grants, as well as the perspective of cities,1612towns, and villages throughout the Nation.1613    The National League of Cities represents cities, towns, and1614villages of all sizes as we work together to ensure a strong Federal-1615local partnership for our country. I am honored to speak as a1616Councilman for Louisville Metropolitan Government, as well as on behalf1617of the Nation's more than 19,000 cities, towns, and villages in each1618Congressional district in the country. Prior to serving as NLC's vice1619president, I served as chair of NLC's Information Technology and1620Communications Committee. I also am employed as a teacher at a small1621all-girls high school and am familiar with the cybersecurity capacity1622limitations of schools.1623    Local governments are high-priority targets for both criminal1624organizations and nation-state actors. Municipalities are responsible1625for sensitive data, payment systems, critical infrastructure, and1626public services that directly impact the health and safety of1627residents. Attacks on municipal networks can dangerously hamper1628emergency response, endanger resident data, bring city services to a1629halt, and cost cities hundreds of thousands of dollars and hundreds of1630work hours, if not more, to stop and recover from the damage to city1631systems. As this committee has noted in previous hearings, local1632governments of all sizes face serious capacity limitations to prepare1633for and respond to cyber threats.1634    Louisville Metro Government has a population of 622,981, but most1635municipalities are much smaller. Of the more than 19,000 cities, towns,1636and villages in the country, over 16,000 have populations below 10,0001637people. Small communities have correspondingly small budgets and staff.1638Most municipalities lack a dedicated full-time IT staff member, and1639those larger communities with full IT departments frequently struggle1640to attract workers with the appropriate levels of expertise in1641technology and cybersecurity. However, smaller size does not make a1642community any less susceptible to attack.1643               louisville metro government's perspective1644    Louisville Metro government has received awards from the State and1645Local Cybersecurity Grant Program in 2 fiscal year cycles. The latest1646grant awarded allowed our community to do 2 main things. First, it1647allowed Louisville Metro Government to perform comprehensive testing of1648critical systems, such as life-saving applications, without reliance on1649third parties which is expensive and can take months to arrange and1650execute.1651    Second, it allowed Louisville Metro Government to take in and share1652critical cyber threat information with regional and State-wide partners1653by standing up the Kentucky Cyber Threat Intelligence Cooperative1654(KCTIC). We are taking on this effort to address the latency of1655actionable threat information provided by Government entities, private1656security companies, and our regional partners.1657    We will provide a platform for non-attributable threat information1658that can be shared in near-real time. Experience has shown us that1659knowing when bad actors are attacking specific vulnerabilities or using1660particular tactics in our neighboring jurisdictions and local1661organizations gives us the opportunity to harden our own defenses. We1662have regional government partners and private companies interested in1663joining KCTIC. This effort is a grassroots program designed to1664strengthen the cyber resilience of the region and overcome1665inefficiencies of many current processes and is directly supported by1666SLCGP.1667     reauthorizing the state and local cybersecurity grant program1668    Our Nation needs a strong Federal-State-local partnership to guard1669against the rising threat of cyber attack. The State and Local1670Cybersecurity Grant Program is a crucial pillar in the country's1671security strategy. The first years of the program have created a1672pathway for partnership through the development and maintenance of1673State plans, intergovernmental collaboration through State1674cybersecurity committees, and increased education and awareness of1675cybersecurity issues among local leaders. We are beginning to see1676promising practices, as well as potential areas of improvement for1677reauthorization.1678    Funding for local government cybersecurity from multiple sources is1679crucial, particularly for smaller jurisdictions. Most municipalities1680have many competing high-priority needs in the community, as well as1681many limitations on their ability to raise revenues to fund those1682needs. It is difficult for a small community in need of new water1683pipes, a fire engine, and street repaving to prioritize budget funds1684for migration to the .gov domain or implementation of multifactor1685authentication, despite the security value of those actions. The State1686and Local Government Cybersecurity Grant Program helps alleviate some1687of that budget pressure, while also fostering a culture of1688intergovernmental collaboration and prioritization of cybersecurity1689within participating States.1690    But for the SLCGP to reach its full potential, improvements are1691needed. The one-size-fits-all pass-through model of the SLCGP limits1692the program's efficiency. Larger jurisdictions such as Louisville Metro1693Government are well-positioned to apply directly for a competitive1694Federal cybersecurity grant and requiring all municipalities to apply1695for a State pass-through only increases the amount of public dollars1696spent on program administration. NLC encourages Congress to create a1697direct competitive grant fund within the SLCGP for larger1698municipalities to apply for directly.1699    Smaller communities across a wide number of States have also raised1700concerns about both the tight application windows for SLCGP funds and1701the complexity of the application process. Small towns are poised to1702benefit the most from cybersecurity funding, yet lack the staff support1703to manage a complex grant application and administration process. A1704tight application window exacerbates this problem, as communities need1705time to assess their needs, scope out and get quotes for solutions to1706the gaps they identify, and complete all required elements of the1707application. NLC recommends that the application process be simplified1708to encourage participation by more small communities, while balancing1709that streamlining with the need to protect the program from waste,1710fraud, and abuse. We are also encouraged by States willing to explore1711multi-stakeholder grants that benefit many jurisdictions, such as a1712State municipal association managing grant application as the prime1713recipient and providing services directly to a large pool of1714communities within that State. Just as most people take their cars to a1715qualified mechanic, small governments need trusted partners to handle1716complex cyber tasks.1717    Above all, NLC strongly urges Congress to reauthorize and1718adequately and consistently fund the SLCGP. The tens of thousands of1719municipalities, counties, and special districts need strong Federal1720partnership to protect the Nation's critical infrastructure and the1721public services that protect residents' health and safety. States and1722local governments have built the framework of a system to protect1723against cyber attacks, through developing and maintaining State plans1724and raising awareness at all levels of government about threats,1725readiness gaps, and solutions. For this system to become strong and1726effective, it requires consistency from the Federal Government from1727year to year. Without consistent expectation of SLCGP's future1728availability, local governments are less likely to do the self-1729assessment and advance planning necessary for a successful grant1730application when the window opens.1731    NLC looks forward to supporting the committee in the1732reauthorization of the State and Local Cybersecurity Grant Program.1733Cybersecurity is a whole-of-nation challenge, and requires a truly1734intergovernmental partnership between Federal, State, and local1735entities to keep our Nation's infrastructure and our residents safe and1736secure. The State and Local Cybersecurity Grant Program is a crucial1737piece of this puzzle. Thank you for the opportunity to address you1738today, and I look forward to your questions.17391740    Mr. Garbarino. Thank you, Mr. Kramer.1741    I now recognize Mr. Raymond for 5 minutes to summarize his1742opening statement.17431744STATEMENT OF MARK RAYMOND, CHIEF INFORMATION OFFICER, STATE OF1745                          CONNECTICUT17461747    Mr. Raymond. Chairman Garbarino, Ranking Member Swalwell,1748and Members of the subcommittee. I am Mark Raymond, chief1749information officer for the State of Connecticut. I'm1750responsible for all the technology of 39 Executive branch1751agencies, including network and internet services for our K-121752schools, our libraries, our universities, and over two-thirds1753of the State's municipal governments. I'm an active member of1754NASCIO and the longest-serving State CIO in the country. This1755history has given me direct involvement with the long advocacy1756for dedicated cybersecurity funding.1757    The threats posed by criminal actors are numerous and1758unceasing. Each year cyber attacks become more threatening and1759the risks posed to residents become more dire. State and local1760governments serve as stewards of a civil society working to1761ensure community stability, predictability, and the well-being1762of our residents--these public servants are the teachers in our1763classrooms, the police officers who respond to distress, the1764doctors and nurses who care for our neighbors suffering with1765addiction. They protect the water we drink, the food we each1766and much more. All of these services however rely heavily on1767technology and data. However, the fast-growing cyber risks have1768found many jurisdictions unprepared. This program is a valuable1769resource in addressing this need. With this grant, Connecticut1770has expanded offerings to local governments. Equally as1771important is the spirit of trust the grant has fostered between1772State and local governments. Cyber incident responders are1773collaborating before attacks take place, instead of during them1774or after them. Preventing attacks is far better than recovering1775from them.1776    For the fiscal 2022 grant year we awarded close to $31777million, with more than $2.1 milion of that going directly to1778local governments. The awards for the fiscal year 2023 program1779year expected to be over $7 million in total with $4.3 million1780to local government.1781    One of the benefits of the program has been a systemic1782assessment of local government risks. Connecticut partnered1783with our National Guard to evaluate cybersecurity risks using1784the NIST cybersecurity framework. Sadly, only 27.7 percent of1785our municipalities were assessed at low risk.1786    These periodic assessments that are supported by this grant1787program ensure that the actions we take produce measurable risk1788responses. Those with high risks demonstrated a lack of1789vulnerability scanning, multifactor authentication, employee1790cybersecurity training, malware prevention tools, and incident1791response plans. This grant directly addresses those findings.1792    Fifty-one awards were made in Connecticut, of which 191793addressed incident planning in governance, 31 improved1794multifactor authentication and ransomware protections. The last1795award supported the Cyber Nutmeg which is a 2-day exercise1796where all municipalities and critical infrastructure operators1797are invited to participate. This unique State-level exercise1798raises awareness to the need to fill this gap. It exercises the1799incident plans that some are newly created and improves1800relationships that are needed when incidents occur.1801Unfortunately, these grant program funds for fiscal year 20221802covered less than half of the requested need. We plan to1803address this growing gap with the remaining grant year funding.1804    Though much has already been accomplished under SLCGP, more1805can be done and here are a few of our suggestions. First is the1806on-going dedicated funding for cybersecurity would be1807important, many local governments are reluctant to start a1808cybersecurity program without on-going funding to support it.1809Standardizing the matching percentage across the grant years1810would also significantly simplify grants administration.1811    Finally, making shared services a default position for1812States and local government to reduce the administrative burden1813required for each locality to sign on to the shared solution.1814This would reduce costs and improve State-wide efficiency. We1815strongly believe it is better to continue to improve this1816program rather than to allow it to expire. The grant improves1817our Nation's cybersecurity defenses, as State and local1818governments take on additional responsibilities for1819cybersecurity, supplemental funds will help meet this increased1820burden.1821    Thank you for your time today. I look forward to answering1822what questions you may have.1823    [The prepared statement of Mr. Raymond follows:]1824                   Prepared Statement of Mark Raymond1825                             April 1, 20251826    Chairman Garbarino, Ranking Member Swalwell, and Members of the1827subcommittee, I am Mark Raymond, chief information officer for the1828State of Connecticut. As CIO for Connecticut, I am responsible for the1829technology of 39 executive branch agencies, including applications,1830digital government, infrastructure, and cybersecurity through the1831Department of Administrative Services' Bureau of Information Technology1832Solutions. In my role, I also oversee the Connecticut Education1833Network, which provides networking and internet services to all K-121834public schools in the State, libraries, universities, and over two-1835thirds of the State's municipal governments. I co-chair our cyber1836security committee that brings together Federal, State, and local1837governments, along with private providers of critical infrastructure1838such as utilities and hospitals to share best practices, emerging1839issues, and on-going threat management.1840    I am also a member of the National Association of Chief Information1841Officers (NASCIO.) NASCIO represents the Nation's chief information1842officers, chief information security officers, and chief privacy1843officers and is a leading voice for States as they work to address1844critical cybersecurity threats, expand digital services to their1845constituents, and protect resident data.1846    Like my colleague Alan Fuller, CIO for the State of Utah, I am here1847before you today to speak about the importance of the State and Local1848Cybersecurity Grant Program. As a former president of NASCIO and one of1849the longest-tenured State CIOs, I can tell you that States have1850advocated for a dedicated program such as this for many years. The1851threats posed to State and local networks by nation-state actors,1852criminal networks, and natural disasters are numerous and unceasing.1853Each year, cyber attacks become more sophisticated and more1854threatening, and the risk posed to residents become even more dire.1855    State and local governments serve as stewards of civil society,1856working to ensure community stability, predictability, and the well-1857being of the residents we serve. State and local public servants are1858the teachers in our classrooms, the police officers that respond to1859distress, the doctors and nurses that care for our neighbors suffering1860with addiction. They protect the water we drink, the food we eat, and1861much more. All these services are provided with the assistance of1862technology that must also guard people's most sensitive data. These1863services are vital to protect and ensure they can continue to operate1864safely amidst an ever-increasing set of direct threats. It is important1865to note that those who deliver these services often do not have the1866appropriate funds to adequately protect the technology and data within1867their care alone.1868    While States are ready to meet this challenge, it is critical that1869they receive support from their Federal partners if they are to remain1870effective. The State and Local Cybersecurity Grant Program has already1871proven to be a valuable resource in meeting this goal. By offering both1872technology services and direct payments to local governments, States1873have been able to further the ``whole-of-State'' approach to1874cybersecurity that helps to address much of the ``low-hanging fruit''1875of cyber hygiene that many small and rural communities cannot1876accomplish on their own.1877    To that end, through the grant, we have expanded State offerings to1878local governments, including risk assessments, dot-gov domain1879expansion, multi-factor authentication, ransomware prevention software,1880employee training, and other critical services. Perhaps most important,1881however, is the spirit of trust and collaboration that the grant has1882fostered between State and local governments. The process of developing1883the cybersecurity plan required by CISA to receive grant funding has1884meant that cyber incident responders and those tasked with protecting1885critical technology infrastructure are meeting and collaborating before1886attacks take place rather than during or after. Preventing attacks is1887far better than recovering from them.1888    Like most of our fellow New England States, Connecticut does not1889provide government services through a county government structure.1890Services are only provided at the State or municipal level. The outcome1891of our structure is that our State government often must fill more gaps1892than others that provide county services. This makes collaboration and1893State-level services even more critical to our 169 cities and towns. To1894illustrate the impact of the SLCGP, I will highlight some specific1895examples of how we've put this program to work in my State of1896Connecticut.1897                         connecticut experience1898    For the fiscal year 2022 grant program year, we awarded $2,978,4321899through the SLGCP, with more than $2.1 million flowing directly to1900local governments. Awards for the fiscal year 2023 program year are1901currently under development and are expected to provide $6,832,343 in1902total and $4,372,700 to local governments.1903    One of the great benefits of the program was a systematic1904assessment and reporting of risks that our municipalities face. The1905State of Connecticut proudly partnered with our Connecticut National1906Guard to evaluate cyber risks using the NIST Cybersecurity Framework,1907which can be visualized in the following graphic.19081909    Of the 159 municipalities assessed, only 44 (27.7 percent) of1910Connecticut Municipalities were assessed as low-risk. The ultimate1911measure of success of any cybersecurity program is the reduction of1912risks in a very dangerous on-line world. The periodic assessments1913supported by the SLCGP ensure that the actions we take have measurable1914results.1915    The areas that primarily contributed to high-risk ratings were lack1916of vulnerability scanning, missing multi-factor authentication, lack of1917employee cybersecurity training, poor capability malware protection1918tools, and lack of incident response plans. The SLGCP program awards1919made in Connecticut will directly address these findings.1920    Fifty-one total awards were made, of which 19 addressed planning1921and governance, 31 addressed cyber tool improvements such as multi-1922factor authentication and ransomware protections, and the remaining1923award covered training and awareness for the entire community. The top192410 awards went to medium-sized schools and towns that have substantial1925needs for the population yet insufficient local funding to address the1926risks sustainably.1927    Unfortunately, available SLGCP funds for fiscal year 20221928improvements covered less than half of the overall need. We hope to1929continue these needed improvements utilizing the remaining grant years,1930and we expect ever-increasing demand from our local partners.1931    Of note was an award to support the Cyber Nutmeg exercise. This1932effort is a multi-stakeholder collaboration between our Division of1933Emergency Management and Homeland Security, the Department of1934Administrative Services, Connecticut National Guard, CISA, and the1935Connecticut Education Network to support a 2-day exercise where all1936municipalities and critical infrastructure operators are invited to1937participate. This unique, State-level exercise critically raises1938awareness, exercises incident management plans, and improves1939relationships that are needed when incidents occur.1940                               next steps1941    Though much has already been accomplished under SLCGP, we recognize1942that more can be done to continue this work. Many local governments1943have stated that their fear that the program may expire impedes their1944application for future funding. They are reluctant to go through the1945arduous task of standing up a new cybersecurity program and acquiring1946the matching funds needed, only to have Federal support evaporate after1947a few years. Additionally, stabilizing the matching formula across all1948grant years would help significantly simplify administration and1949attract more applicants.1950    For a State like Connecticut, where no county government exists,1951the administrative effort to demonstrate each locality has signed onto1952a shared or State-wide solution could be reduced. Flexibility to1953implement shared solutions, such as a State-wide Security Operation1954Center, would better serve States. Such solutions should be funded as a1955default offering, allowing municipal governments to opt-out. This would1956establish collaboration as the expectation in reducing cybersecurity1957risks and, therefore, reducing overall costs.1958    However, while changes and improvements are needed, we strongly1959believe that it is better to continue to improve SLCGP rather than1960allow it to expire. We have no reason to believe that States, towns,1961schools, and critical infrastructure providers will see less targeting1962by criminals, nation-states, and cyber activists. Rather, we expect1963that the threats faced by stakeholders will only increase in the coming1964years. This grant has helped to establish a solid foundation to1965continue to expand our Nation's cybersecurity defenses. As the current1966administration intends to increase the responsibility of State and1967local government to respond to cyber attacks, it is logical that the1968Federal Government provide the tools and resources needed to meet this1969increased burden.1970    Thank you for your time today. I look forward to answering your1971questions.19721973    Mr. Garbarino. Thank you very much, Mr. Raymond. I hope the1974point about preventing is better than recovering, you know. Our1975county got hit and we were down for almost a year. So it is1976very important that you are all here today and getting this1977reauthorized and fixed I think is a very important goal that we1978all have. I'm really happy that we have Members to ask1979questions.1980    We're going to start with each Member and go from1981Republican to Democrat, 5 minutes of questioning each. An1982additional round of questioning may be called after all Members1983have been recognized.1984    I now recognize the gentleman from Texas, Mr. Luttrell, for19855 minutes.1986    Mr. Luttrell. Thank you, Mr. Chairman.1987    Mr. Raymond, when it comes to local governments and their1988awareness of the grant programs and where they live and breathe1989and where they exist, how does that work? Does the Government1990itself reach down into these local governments? Which ones do1991we touch? Are we touching all of them?1992    Mr. Raymond. Thank you for the question, representative.1993They are all invited to the discussion. We have formed regional1994subcommittees that include representatives from State, local,1995school districts.1996    Mr. Luttrell. When you say regional subcommittees, can you1997elaborate on that, please?1998    Mr. Raymond. Yes, Connecticut is divided into 51999administrative regions so we do not have county government in2000Connecticut so it's just the State and then 169 municipalities.2001So we have organized our emergency response into 5 districts2002and so each one of those emergency management and cybersecurity2003groups have their own planning committee, all of the chief2004executives in emergency management and cybersecurity2005professionals in that group are invited to the table in those2006discussions.2007    Mr. Luttrell. So it makes it easier for the State to2008understand what exactly is happening in cybersecurity when it2009comes to the grant profile.2010    Mr. Raymond. Yes, sir.2011    Mr. Luttrell. Mr. Kramer, have you got something to add to2012that?2013    Mr. Kramer. Louisville is the largest city in the State of2014Kentucky. We do have counties in the commonwealth. The grant2015that we are currently using came directly to metro government2016in Louisville.2017    Mr. Luttrell. Is every county aware of the grant system2018itself and how they can grab hold of that?2019    Mr. Kramer. Those that are members of NACo, the National2020Association of Counties are well aware because NACo is pushing2021this out as an issue that they should be very much interested2022in working with.2023    In Louisville it is not just Louisville that's taking2024advantage of grant, though. We're the largest city in the2025State, we are also very near being on the river, very near2026Indiana. We are working across the entire region. We've reached2027out to the universities, both the University of Kentucky and2028the University of Louisville, we are working with the National2029Guard. So it's a program that goes beyond just what we're doing2030in Louisville. It captures a good part of our State.2031    Mr. Luttrell. Mr. Fuller.2032    Mr. Fuller. Excuse me, yes. So the city of Utah what we are2033doing----2034    Mr. Luttrell. City of Utah?2035    Mr. Fuller. State of Utah. Tools, training, and2036relationship building. So we are over 75 percent covered with2037all the cities and counties. We hope to get that closer to 1002038percent as we go.2039    Mr. Luttrell. The entire State is aware of this.2040    Mr. Fuller. Oh, yes.2041    Mr. Luttrell. That's remarkable.2042    Mr. Huber.2043    Mr. Huber. I have no comment. That is outside my area of2044expertise. I rely on these gentlemen. I'm a vendor.2045    Mr. Luttrell. Welcome to the committee, sir.2046    When it comes to the relationship between State and local2047government, would you say that the return on the investment2048from these grant programs are beneficial? I will start with2049you, Mr. Raymond, because you said you did not utilize all the2050assets that were funded, I missed the year.2051    Mr. Raymond. We had double the requests than we were able2052to fund. So we did not have any excess funds. We had double the2053requests in the first year of the grant program and we expect2054that to continue. So I think that does demonstrate both the2055awareness that we have across the State, especially for our2056municipalities and upwards--and we took very little funding at2057the State level. There is a division between what you can take2058at the State level and what is and almost all of the funds went2059to local governments.2060    Mr. Luttrell. But absolutely necessary because this2061committee is trying to maintain its footing when it comes to2062grant programs for cybersecurity, cyber threat. We need to hear2063from those on the other side to say, yes, this is an absolute2064lead because in my personal opinion, this is the next phase of2065evolution when it comes to warfare and protecting our citizens2066is absolute. As the meta verse is pulling, pulling or cutting2067or freezing grant programs currently I would hate to see this2068happen in such an important space.2069    Mr. Kramer, I'll go to you, if not, Mr. Fuller.2070    Mr. Kramer. Thank you. I would argue that yes, it is2071essential. In Louisville we hired 2 people to do the work, we2072were hoping for 4. The work that needs to be done is broader2073than the work we are able to accomplish under the current2074program so absolutely want to see this going forward. The plan2075is to reach out again to the major universities in town and2076then ultimately to filter down even to the public school2077systems. It is amazing how much data is held in the school2078systems and how much that data is compromised.2079    As everyone knows, the bad actors are looking for the easy2080access. So we're doing our best to reach down to the level2081where we can improve security at that lowest level.2082    Mr. Luttrell. Mr. Chairman, I yield back. Thank you.2083    Mr. Garbarino. The gentleman yields back. I now recognize2084the Ranking Member, Mr. Swalwell from California, for 5 minutes2085of questioning.2086    Mr. Swalwell. Thank you.2087    Councilmember Kramer of Louisville you have one of the most2088important jobs here, you are protecting the Nation's bourbon2089supply so thank you. I know our Chairman and many of my2090colleagues thank you. But you did, in all seriousness, mention2091the weakness of the program as it exists right now, which is it2092doesn't have much agility or maybe you said bandwidth to2093understand the differences between sizes of cities. Like, how2094would you structure a future reauthorization to better reflect2095that, and better target where the need is?2096    Mr. Kramer. Thank you for the question. I really appreciate2097that. The first bit of the answer is we need to recognize that2098larger cities like Louisville, for example, we do have the2099resources. We have a person on staff who his primary2100responsibility is cybersecurity. But we're a half-an-hour drive2101from Elizabethtown--there was a movie made about that place--it2102is a fairly small town out in the middle of bourbon country.2103They don't have the resources to do this. But we do have a very2104active stately city, an organization of municipalities.2105    Allowing the grant to go through them instead of through2106the State would assure that that money actually made its way to2107local governments and it also allow the State league to work2108together with those other cities and hire a person that would2109be able to work with all of them and not just with one city2110like our own. Again, it reaches into the school systems. There2111are some school systems in the State of Kentucky that the2112highest-paid positions in the county are in the school system.2113    I just want to drill home that's an area that I think folks2114overlook. There's a lot of data that's handled there and we2115need to do the best we can to reach out to that community as2116well.2117    Mr. Swalwell. Absolutely.2118    Mr. Raymond, can I ask, as somebody who has administered2119millions of dollars of these grants to many jurisdictions,2120municipalities, agencies, what are some of the weaknesses that2121you've seen among some of the recipients?2122    If you had a new tranche or a new reauthorization, what2123have you learned from this that makes a candidate more eligible2124or makes a candidate least eligible as you're thinking about2125where these funds should go?2126    Mr. Raymond. Well, admittedly the program did have a slow2127start, right? I think any kind of new grant program, the2128clarity around getting people to understand what it is to be2129eligible and what people really needed within their environment2130was probably the most difficult challenge for us.2131    Again the assessment, the cybersecurity assessments that2132were part of the first year were absolutely critical for2133building, for all of our municipalities and understanding of2134what their risks were and how we would address it. I think it2135goes to the earlier question of, did they know? When we have2136these assessments, they now know.2137    So I would say that continuing that to demonstrate the2138improvements would be absolutely critical. For additional2139funding, I do think that--I understand the desire in the2140construct of the program to have--to wean States off the2141program with the declining match or the increasing State match.2142However, that's complicated with the change in the funding as2143well. I think having a stable match over the life of the2144program makes it far easier to administer as people are working2145across the different grant years.2146    Should the desire be to still shift some of that burden2147back to the States through the funding, you can do that through2148the overall funding of the program and not the mix of the 2. I2149think that we had a lot of people applying for the first year2150and a 90 percent reimbursement rate and then we're looking at2151will we get that same kind of participation as the rates fall2152and local governments' budgets remain tight.2153    Mr. Swalwell. Thank you. I yield back.2154    Mr. Garbarino. The gentleman yields back. I now recognize2155the gentleman from Tennessee, Mr. Ogles, for 5 minutes of2156questions.2157    Mr. Ogles. Thank you, Mr. Chairman, to the witness.2158    I believe strongly in federalism, fiscal responsibility,2159the importance of empowering local communities and not2160expanding the bureaucracies of, quite frankly, the Federal2161Government.2162    As we assist the State and local cybersecurity grant2163program we need to ensure that our limited Federal resources2164are being used effectively are actually reaching the2165communities most at risk. I say that in the context of being a2166former county executive in Tennessee, serves as the CEO of the2167county.2168    So I can attest to the fact that some of these pass-through2169grants administered by the States were incredibly important to2170my county which is a rural county, emergency services, fire and2171cyber were all my departments.2172    So again, I get your perspective on the stable match2173because again as a rural county where we have limited funding2174mechanisms and quite frankly an ever-growing school system2175where there is a friction there of how do you fund these2176mechanisms which, as my colleague stated, the future of warfare2177is on the cyber battlefield.2178    That being said, Mr. Huber, you worked to secure systems2179against the threat from Volt Typhoon, the CCP, that group of2180hackers who both have sophisticated abilities and specialized2181in targeting the most vulnerable points in its target system.2182    In your testimony you mentioned an attack on Littleton2183Electric and Light & Water Department in Massachusetts. My2184district and across the country where a diverse range of2185electric providers, large corporations, rural providers as I2186mentioned.2187    In your experience how strong is the awareness of cyber2188threats among smaller, less-resourced organizations that2189provide critical infrastructure? Again, I go back to Tennessee,2190but probably much like rural Kentucky where we have a patchwork2191of these smaller communities, where we are scrapping for2192resources, to figure out how do we quite frankly protect not2193only our infrastructure but our citizens, sir?2194    Mr. Huber. Yes, I thank you for the question. So having had2195the pleasure of working with--that the IT person was the IT2196person, and the database administrator, and the assistant2197administrator, and responsible for security, at a part-time2198job.2199    So as you might imagine, any administrative burden that2200might be involved in applying for the grant would be2201significant for an entity such as that smaller size. But make2202no mistake, those smaller rural entities that could be the2203hydro station that fuels a larger municipality. That's a2204national security and economic impact in the region.2205    So as we heard from a gentlemen here educational awareness2206is key to educating those folks who have probably dual roles,2207or multi-hat roles from protecting that piece of critical2208information from nation-state attackers.2209    As one who has been in the trenches and a National Guard2210member in Title 32 and State Active Duty supporting State2211credit infrastructure components. There is a significant2212shortage of resources and knowledge about nation-state-level2213attackers.2214    So think it is important to recognize that this funding is2215key in raising the bar of foundational cyber controls for all2216of those entities.2217    Mr. Ogles. I want to focus primarily with the other 32218witnesses on rural communities. One of my concerns, again my2219background coming from a rural community is that competition2220that you see between say a Nashville and my community. But yet2221from an assessment standpoint, I would argue some of your rural2222communities are your most vulnerable points of intrigue.2223    So how do we make sure that we're prioritizing, basically--2224take size out of it for a moment--but a needs assessment,2225understanding that again whether it is distribution of2226broadband, whether it is protecting points of entry, et cetera.2227Mr. Fuller.2228    Mr. Fuller. Thank you very much.2229    Let me just say I really appreciate your comment that these2230attacks are very much like war. This committee knows very well2231that we live in a very, very dangerous world and we were2232constantly under attack including our smallest and most rural2233community.2234    So with the program that we rolled out, we rolled out tools2235that all of our communities, including the rural communities2236and the most rural that don't even have section IT resources,2237we are able to make resources available to help them install2238those tools and then we are also able to provide training for2239those people. So we're absolutely committed to getting this2240program to our small cities and counties in special districts.2241    Mr. Ogles. Mr. Kramer.2242    Mr. Kramer. Thank you again, it is a great question.2243    I think one of the things that we need to recognize is it a2244matter of how quickly we share that information as well. When a2245cyber attack happens what they are trying to do in one place,2246one community is likely happening somewhere else. Again, I2247think the smaller communities, the rural communities where my2248colleagues have testified that you've got a person who has 32249different jobs.2250    If they aren't aware of what to look for it makes it much2251more difficult. They often don't find out until it is too late.2252So one of the things we are hoping we can get the Federal2253Government to do is recognize that they collect up a lot of2254data about cyber attacks, but they collect it up and hold it.2255    It would be very useful to us at the local level if as soon2256as they knew about a cyber attack they shared that information2257with entities as quickly as they could so that folks at the2258local level could start looking at their own systems and see if2259someone is trying to get in the same way.2260    Mr. Ogles. Yes, sir. I am out of time, but Mr. Raymond a2261final thought.2262    Mr. Raymond. I would just say that we view cybersecurity as2263a team sport. We view those that are better-resourced in a good2264position to help those that aren't. So we do have2265municipalities who help each other, larger ones helping smaller2266ones and smaller ones who are relying on the State to help2267deliver services.2268    We do run all of the network services so it provides a2269unique ability for us to provide specialized security services2270to everyone in our jurisdiction, which is one way to make the2271limited dollars we have left to go a lot further.2272    Mr. Ogles. Thank you, to the witnesses. Mr. Chairman,2273apologies for going over.2274    Mr. Garbarino. Of course, no problem. The gentleman yields2275back.2276    I recognize the gentleman from Rhode Island, Mr. Magaziner2277for 5 minutes of questions.2278    Mr. Magaziner. Thank you, Mr. Chairman.2279    The State and Local Cybersecurity Grant Program is an2280essential resource to help States and municipalities protect2281themselves against cyber attacks. This grant program helps2282secure critical infrastructure like schools, hospitals,2283electric grids, water systems.2284    My home State of Rhode Island has been instrumental in2285providing cybersecurity training for example for staff at State2286agency municipalities so they can better protect taxpayer data,2287securing schools and academic institutions from ransomware2288attacks and protecting critical infrastructure from being2289infiltrated by hackers.2290    I am concerned by reports of potential delays and cuts to2291these grants by the Trump and Musk administration. I'm glad to2292see that at least in this subcommittee there appears to be2293bipartisan support for continuing the program in a robust form.2294    But you would forgive us for being concerned because in2295addition to the reports of delays, we have heard that the Trump2296and Musk administration has been firing staff at CISA and at2297FEMA, the 2 agencies responsible for administering this2298program.2299    We have also heard from Secretary Noem herself that she2300plans to ``eliminate FEMA and significantly shrink CISA.'' She2301said that in her Senate confirmation hearing. This would be a2302tremendous mistake. The threats that we face from foreign2303maligned actors, from criminal organizations, to critical2304infrastructure, to our cybersecurity are a mix.2305    The Chinese are working overtime putting tens of thousands2306of people toward trying to infiltrate every system, even in the2307smallest towns in this country, same with the Russians, same2308with the Iranians, the North Koreans, and of course criminal2309cyber gangs as well.2310    We've had significant breaches in Rhode Island as a result.2311This is not the time to take our foot off the gas as the2312Secretary said was her intention during her Senate confirmation2313hearing. Unfortunately this is part of a pattern because when2314she was Governor of North Dakota, Secretary Noem was 1 of only23152 Governors in the entire country who refused to accept State2316cybersecurity grants in 2022.2317    Her administration called it wasteful spending. In 2023,2318yet again, she was the only Governor in the entire country who2319refused these grants for her own State. Of course we have seen2320that the administration is not off to a great start with its2321own cybersecurity practices, with service members' lives being2322put the risk from confidence information being discussed in an2323unsecured group chat.2324    Of course Elon Musk's army of unvetted interns going2325through everybody's data with very little transparency. But2326given that backdrop, it is more important than ever that2327Congress send the message that cybersecurity still matters to2328us, that we do not consider it to be wasteful spending, and2329particularly we want to continue to support States,2330municipalities, utilities in our home States with this program.2331    So I have limited time, but Mr. Fuller, can you elaborate2332on any reports of delays, cuts, or pauses to this program? What2333have you seen so far? What would the negative consequences be?2334    Mr. Fuller. Thank you. I appreciate your point that there2335is a lot of bipartisan support for this program to continue.2336Certainly the risk doesn't take politics into account.2337    One of the concerns we have about the program is some of2338our States chose not to participate because they were afraid2339the funding would not continue on and they were afraid to2340launch a program that might then get cut. That created some2341hesitation for some States.2342    First, we're all in with the program. It has been extremely2343beneficial, that's been my testimony, we blocked 7 major2344attacks in the last 6 months alone.2345    So we would hope that we could extend the funding, could be2346extended by Congress without delays. Those delays could cause2347serious problems in adoption of the program.2348    Mr. Magaziner. Thank you. Mr. Raymond, even if eliminated2349and CISA is significantly cut as Secretary Noem has promised,2350what impact would that have on the ability of your State and2351others to maintain strong cybersecurity and take advantage of2352programs like this one?2353    Mr. Raymond. I do believe that FEMA and our emergency2354management in Connecticut along with CISA on the securities2355side have been great partners with us on this cyber battle.2356State and local governments are not prepared to fight this kind2357of cyber engagement with foreign nations.2358    I would say in combination with the reduction to the MS-2359ISAC and CISA support additional responsibilities are falling2360on the States to fight these battles.2361    Should further CISA reductions or FEMA reduction for that2362matter be put in place, I would say it would diminish our2363ability to help the municipalities that are part of our2364jurisdiction and defend on behalf of the State.2365    Mr. Magaziner. Thank you. I'm over time so I yield back.2366    Mr. Garbarino. The gentleman yields back.2367    I now recognize myself for 5 minutes of questions.2368    Gentlemen, we have heard from you all today. There is2369definitely a need for the program. I want to focus on No. 1,2370has it been successful so far? No. 2, what changes would we2371make?--and you have all suggested a couple.2372    Mr. Raymond you started by saying when you first did the--2373in your statement there was 27 percent of the municipalities2374were low-risk so 73 percent were not low-risk. Now that this2375program's in place, have you done another review? What number's2376low-risk now?2377    Mr. Raymond. We are currently doing the reassessment now.2378We do not have an updated set of numbers on this. We do know2379that the implementation of the 51 grants that we have would2380directly raise the ratings and lower the risk for folks around.2381    Mr. Garbarino. Mr. Huber, you're a vendor so you're dealing2382with all these municipalities. You know what they are using,2383what they needed. Can you please just describe what these2384grants have been able to help some of the municipalities that2385you've dealt with, like, what systems have been put in place?2386What they had and now what they have. I think people really--we2387need to hear the actual benefit of what you've done with this2388grant money.2389    Mr. Huber. Sure thank you for the question.2390    Yes, so one of the first foundational components any2391cybersecurity program is having awareness of what you have. You2392have to know what you have to be able to defend it. It sounds2393easy, a significant challenge for most organizations, even2394mature organizations, that's a challenge. To understand the2395breadth of the footprints certainly at the State level, let2396alone rural areas as well.2397    So what we've seen folks do is deploy solutions without2398understanding what they have in their purview, what's exposed.2399So to the gentleman's point regarding risk assessments. You2400have to know what you have to conduct that risk assessment so2401that is step No. 1. We have seen them deploying that2402successfully.2403    Then you want to take that just a step further. Now I know2404what I have what am I vulnerable to? What misconfigurations,2405weakness, vulnerabilities do I have there? How do I prioritize2406those from a response perspective? Because I have limited2407resources to go and mitigate and reduce those risks.2408    So now I'm looking at what are my resources available to go2409and reduce the risks across the entire enterprise without2410regard to the size of the municipalities evolved, right?2411Because it could be when they do these risk assessments some2412smaller or rural regions might have the highest risk compared2413to larger metros. What we have seen successful organizations2414assess what they have, being able to analyze them and look for2415exposures across the attack footprint and then focused on a2416prioritized cause addressing vulnerabilities.2417    Mr. Garbarino. That's great. So you are using the grant2418money to map the system because and now--it a multi-year grant2419so they are mapping their system, they are funding out what2420doors need locks and now they are implementing it and using2421technology to protect those doors into their system.2422    Mr. Huber. Yes, I think a great point is sustainable2423funding, you know, I hate to use this example, some people when2424they wake up they have a day job, it is not to fix2425vulnerabilities, that is not their job. Their job is to make2426the systems run.2427    They go patch the systems and they are like, mission2428accomplished, we're done here and tomorrow morning you get up2429and read the news and you are, like, more vulnerabilities you2430have to do this again.2431    It is a hamster wheel--so people have to have not only2432resource and fun for that, it is now a part of your job or some2433percentage of your time beyond what your day job is. People2434need to understand that's how life is.2435    Mr. Garbarino. Thank you very much. So under the grant2436program there is some requirements in the law, one of them is2437for there to be a submission of a cybersecurity plan. This is2438for the 3 gentlemen on the right who actually had to determine2439the cybersecurity plans.2440    There's a lot that's going to be part of it. What is2441working as part of the plans, is there something that we should2442include that is not in it or is the law overburdensome by2443including too many things in the plan that's not necessary?2444What do you all think? Mr. Fuller, we can start with you.2445    Mr. Fuller. Thank you. I think the good thing about the2446plan is that it gave States some flexibility to each create2447their own plan. You can see between Connecticut and Utah, 22448very separate plans, where they primarily put funds down to2449local entities and we primarily provide tools, training, and2450relationships down to local entities. So I feel like that part2451of the law was successful good.2452    Mr. Garbarino. It should not be changed.2453    Mr. Kramer.2454    Mr. Kramer. I am going to leave that to the folks who2455actually do the cybersecurity stuff.2456    Mr. Garbarino. OK. Mr. Raymond.2457    Mr. Raymond. I would say the formation of the cyber plan2458was really hopeful to focus in a structured way on what the2459risks were and what we can do together to lower those risks.2460There was a tremendous amount of collaboration in the2461development of the plan which I think furthered the mission of2462hey, we're all in this together and hope to get the message out2463to all of the municipalities that this was important for their2464success.2465    So I think the combination of collaboration and structure2466in those plans and the direction that set was very hopeful for2467State-wide efforts.2468    Mr. Garbarino. Sounds like that part of the statute is2469something that should not change.2470    OK, we're going to start a second round of questions. I now2471recognize the gentleman from Texas, Mr. Luttrell, for his2472second round.2473    Mr. Luttrell. Mr. Huber, I think you hit the nail on the2474head explaining exactly how the process should work. Is that2475even a possibility or a probability, remember you're talking to2476the United States of America right now. I want you to think2477about that I don't where you're from. Kentucky, I'm from Texas,2478obviously. A little bitty town.2479    We hate the Federal Government. I can throw that out there.2480Honestly, we don't want them in and around us at all. However,2481with the threat or the risk to threat when it comes to2482cybersecurity space, how do we make this work? The plan that2483Mr. Raymond laid out piggy-backs exactly what you said.2484    But we have to touch every single person in the United2485States of America and I can assure you the 4 of you sit in2486front us, you're not the first 4 that's ever sat in front of us2487and laid this out. This is almost the simplest question, how do2488we fix this problem or is it a possibility?2489    We can just keep talking about it all day long. We can keep2490funding these grants and throwing it out there and we're just2491going to get attack after attack. You said the problem is when2492the attack happens, we're retrospective. It's a done deal. Then2493we have to raise awareness to those that didn't get hit. Who's2494doing that?2495    Well I've had CISA come out to my district. I've had the2496FBI come out to my district and talk to the nursing homes and2497schools. Guess what? The things they laid out, a month later,2498something else showed up. Literally, how do we fix this?2499    Mr. Huber. Yes. Thank you for the question. Great question.2500We have to raise the bar across the board. There is2501foundational cyber----2502    Mr. Luttrell. What does the bar even look like?2503    Mr. Huber. I think in this cybersecurity----2504    Mr. Luttrell. You and I are going to have a pretty good2505healthy debate here in 3:16. Every time--you see where I'm2506going with this.2507    Mr. Huber. I do, absolutely. This cybersecurity framework2508provides excellent foundational controls, but to your point, AI2509was not on my list of risk 3 years ago, and now it is. Guess2510what we're doing. We're developing those foundational2511components for artificial intelligence and how we defend and2512how we detect for that type of capability, so we're always2513going to be in that race of emerging technology, unfortunately2514for us.2515    What those foundational components still hold true for the2516vast majority of threats that exist today, and I think what we2517heard is very key of getting the message out, which is that2518communication and collaboration, whether that's through JCDC,2519under CISA, or whether that's through some of these fusion2520centers we heard of at the State level where they're2521disseminating information, it is a collective sport at the end2522of the day, and we all need that information to be able to2523respond as quickly as possible.2524    Mr. Luttrell. The sheer processing speed, we're past excess2525scale computing. Magnolia, Texas can't defend against that. We2526have a--we have nefarious actors that have the computational2527capabilities to destroy a country. How do I protect District 82528in Texas?2529    Mr. Huber. I think--and this is not normally how you start2530the security program, but you should start with instant2531response. You need to have search capabilities and resources to2532respond to an incident. To your point, unfortunately, it will2533happen. We have data that shows it will happen to even the most2534mature organizations, so having those capabilities, a lot of2535times those search capabilities, and I've been in this role,2536they come from the National Guard, they come from CISA and2537other organizations to provide us intelligence we don't have to2538collectively respond as an industry, and that also raises the2539bar.2540    Mr. Luttrell. I mean, how much--I can't even repave the2541roads in my forest right now, so now here we're talking about2542dollar bills, and I can only imagine that protective layer is2543going--help me fix this problem. I mean, what----2544    Mr. Huber. Yes. There's certainly data points available of2545known exported vulnerabilities. It's something we use in an2546industry to prioritize. Like, we know these are actively2547exporting against these organizations. You want to make sure2548that when you're applying resources against the problem it's a2549prioritized approach, whether it's through the program2550assessments that these organizations complete to identify the2551highest risk or whether it's vulnerabilities that you see day-2552in and day-out to prioritize those first.2553    I know within Tenable we have data that says,2554unfortunately, if a new vulnerability comes out that affects2555major operating systems as an example, it takes most2556organizations a few weeks to address those vulnerabilities. By2557the way, they only fix about half of them during the course of2558that 2 weeks, so there is a known exposure that we all accept.2559Like I said, to foot-stomp this, having a good response plan of2560how you coordinate reaction to those events becomes critical.2561    Mr. Luttrell. Thank you. I yield back, sir.2562    Mr. Garbarino. Gentleman yields back. I get the gentleman's2563point about there might not be a way to stop this, how do we2564stop this? I don't know if we can stop it, but being able to2565respond and get things back on-line I think is what--is at2566least part of the goal here.2567    I now recognize the gentleman from California, the Ranking2568Member Mr. Swalwell, for his second 5 minutes.2569    Mr. Swalwell. Thank you.2570    I'd welcome the opportunity with the 4 of you here to give2571us a real-time update on the threat environment and what you're2572seeing as to the type of the attack, the ask of the attack, if2573it's ransom wear, your ability to work with the Federal2574Government, for example, the bureau when an attack occurs, and2575the origin of the attack. Is it still primarily Russia, eastern2576Europe, criminal gangs for ransomware? Then as far as phishing2577attacks and intellectual property theft, is that primarily2578China?2579    So, Mr. Huber, start with you. If you each spent about a2580minute on this I think we would get a good cross-sector update.2581    Mr. Huber. Yes. I think it's heavily dependent on the2582sector the entity operates in. You do see all those actors2583across all sectors, and unfortunately, you know, it has become2584easier. There's things such as ransomware as a service as an2585example. You can buy access to systems and companies at your2586will without having to conduct any actual tax themselves, and2587then, of course, we always have the nation-state actors.2588    Mr. Swalwell. So it's like investing in the stock market.2589You just, like, buy an index fund of ransomware attacks?2590    Mr. Huber. That's exactly it. So if I wanted to compromise2591your machine, I might buy access from somebody who already has2592access to your machine, so I'm going to actual conduct the2593activity myself.2594    Mr. Swalwell. Sorry. Continue.2595    Mr. Huber. So I think we're seeing a mixed bag, and the2596problem becomes to Congressman Luttrell's point is, you know,2597trying to defense against all of those different types of2598actors, whether it's, you know, financially-motivated,2599ideology-motivated, nation-state-motivated, they all have2600different intents for what their targets are, so you have to2601understand to a great extent what your attackers look like, and2602that's, again, where some of that information through law2603enforcement or CISA or JCDC is very useful.2604    JCDC as a part of CISA, we used--they coordinated responses2605for log per day, massive vulnerability. It affected the economy2606and the world for that matter, one of the largest ones of my2607career. They did a fantastic job of sharing what works, what2608doesn't, and getting us intel quickly that we can action.2609    Mr. Swalwell. Great. Thank you.2610    Mr. Fuller.2611    Mr. Fuller. Thank you so much for the opportunity. So the2612types of attacks, first of all, the end-users are typically the2613biggest vulnerabilities, so we see things like phishing2614attacks, business email compromise. I'd like to give you a very2615specific example that we just had the last few weeks. Utah is2616an alcohol-controlled State. We have retail stores that sell2617alcohol.2618    We had criminals calling these liquor stores representing2619themselves as members of the government and saying that they2620need to change settings in their credit card readers. The2621credit card readers, they were trying--the settings they were2622trying to change were trying to make it so the card haven't2623have to be present, it was a blatant attempt to try to hack the2624credit card readers of our liquor stores.2625    We've seen just in the recent past a business email2626compromise has been very damaging. We've seen--they try to do2627things like convince State employees to change bank routing2628numbers to redirect funds so it goes to the criminals instead2629of to the place it's supposed to go. The primary attackers come2630from Russia, China, North Korea, Iran, and we've seen quite a2631bit from Nigeria.2632    I would also just mention that to some of the comments2633before that with artificial intelligence technology,2634unfortunately, I see the problem getting worse, not better. It2635used to be with phishing type emails, you would see typos,2636incorrect grammar. You could kind-of spot that something wasn't2637quite right.2638    Unfortunately, the criminals know how to use artificial2639intelligence as well. We just had an incident where we had over2640400 phishing emails, every one a different subject line, every2641one a different text, all written beautifully. Unfortunately,2642all bearing malware that could compromise systems. So2643unfortunately, the world is getting more dangerous, not less.2644    Mr. Swalwell. Thank you. That's helpful.2645    Councilmember Kramer.2646    Mr. Kramer. So in talking to James Meece, our cybersecurity2647guy back home, he mentioned some of the same things that have2648been testified to here. There are certain localities that we2649know when something is coming in. It's probably suspect just2650because of where it's coming from.2651    In 2023, we had a nation-state cyber actor get access to2652one of our network devices through a provider's chat. You2653wouldn't think that's a big deal, but in the process of2654chatting back and forth with other folks on that same system,2655they were able to get passwords, user names, and later were2656able to go in and try to--they got into the network where they2657could see what was going on. Fortunately, we were able to catch2658that before they were able to do anything, so it only cost us2659about 100 hours to fix it. We were grateful.2660    Typically, these things--the problem is, as you guys well2661understand, if you don't spend the money up front to know2662what's coming, you're going to spend the money on the back end.2663You know, we talked earlier about local governments and rural2664communities. The real issue there is a lot of the rural2665communities, they don't have the resources to spend up front,2666and so they don't, and you don't have a choice about spending2667on the back end.2668    Mr. Swalwell. Time expired. Would you indulge me and allow2669the CISO from Connecticut, please, Mr. Raymond.2670    Mr. Raymond. Thank you. I would say very similar answer.2671We're seeing global interest in things that we do. If we put a2672new device on a network, 5 minutes it is being scanned by2673someone, so they are looking for the vulnerabilities that were2674being described for scanning earlier.2675    The threats are data exfiltration, stealing of data, of2676intellectual property, ransomware, extortion of data, business2677email compromise. It's a phishing targeting of leaders for2678passwords, and those kinds of things are very common things2679that we see.2680    Mr. Swalwell. Thank you. That was helpful across the board.2681    Chairman, I yield back.2682    Mr. Garbarino. Gentleman yields back. I'm going to continue2683along my line of question from before about changes. CISA and2684FEMA's role, are they good partners? Are they the ones who2685should be running this program? I mean, has it worked? Has it2686not? Jump in.2687    Mr. Fuller. If I may, Mr. Chair, CISA has been an2688outstanding partner for us. We're really grateful for them and2689their commitment. We use them in a number of ways. They are2690active members of our cyber center as well as the Federal2691Bureau of Investigation. Those relationships are extremely2692important. When a bad thing happens, it is so good to be able2693to have experts to reach out to and know who to call. CISA and2694FBI help provide that role for us. We're very grateful for2695their support.2696    We also use CISA's services to do cybersecurity assessments2697of each of our agencies in the State across the board. We do2698that once every 3 years for all agencies, and they've been a2699tremendous partner for us.2700    Mr. Garbarino. Mr. Raymond. Kramer.2701    Mr. Raymond. Yes, I completely agree. The CISA team has2702brought great leadership and insight and expertise in terms of2703both what we can leverage. But to the earlier question, they've2704been fantastic in getting out to the local governments in2705being--helping them raise the understanding of what's available2706and how they need to be thinking about it. FEMA has been sort-2707of a back office partner for the grant administration. I'd say2708less active in the delivery of the technology, but they've--2709they've also been a great partner.2710    Mr. Kramer. I'd say baseline been a great partner. Really2711happy about what's going on so far. The one-size-fits-all2712approach has been somewhat limiting. It limits some of the2713efficiencies. We would hope that Congress would create a more2714direct competitive grant fund with SLCGP for larger2715municipalities who can afford to take care of that on their2716own. I think that would be helpful.2717    The other is we recommend an application process to be2718simplified to encourage participation by some of our smaller2719communities.2720    Mr. Garbarino. Simplified how?2721    Mr. Kramer. The reporting processes are somewhat2722burdensome. Again, keep in mind, and some of my colleagues have2723already testified, very often these aren't full-time employees2724who are focused on, (A), applying for grants in the first2725place, and (B), just the technical nature of it alone. So if we2726could make it such that some of our less technical folks who2727are responsible for these highly technical responsibilities2728would be able to report more easily.2729    Mr. Garbarino. Currently, Louisville--the city of2730Louisville has to go through the State to get its grant,2731correct? It's administered by the State?2732    Mr. Kramer. I don't believe so. I'd have to check. I think2733ours came directly to metro local, although it may have come2734through the State. I'll withhold on that one.2735    Mr. Garbarino. But you're saying part of this pot of money2736would be--instead of having--it might be worthwhile to have2737some of the larger cities and municipalities be able to go2738directly to----2739    Mr. Kramer. Yes.2740    Mr. Garbarino. Directly to FEMA to get--have some of the2741grants come instead of----2742    Mr. Kramer. Yes.2743    Mr. Garbarino. OK. You mentioned something about for rural,2744the cost. They can't even come up with a cost share. How would2745we fix that?2746    Mr. Kramer. Again, I think that the program the way that2747it's designed, if we could get that more quickly, more easily2748to municipalities, to the--and again, we talk about cities and2749rural, municipalities are still in those rural areas. They're2750just much smaller municipalities.2751    In the State of Kentucky, and all the States, actually,2752there's leagues of cities, and the Kentucky League of Cities2753has been awesome to work with. It would be beneficial to local2754governments if the grant money were funneled or moved through2755that organization. They're more directly connected to what's2756going on in cities than the State is.2757    Mr. Garbarino. OK. Mr. Raymond, Fuller, you both have rural2758areas. What could we do more to help there? Because, again,2759those are the municipalities that don't have the expertise,2760even though the Pivot Act the Chairman is leading would put--2761would allow people to hire and be part of the service. That's2762great. Nice little plug for the Chairman's bill. Hopefully2763passes, but go ahead.2764    Mr. Fuller. Mr. Chair, so I felt like it was kind-of2765ingenuous to run it through the States, because 80 percent2766was--80 percent of the funding came through the States, but 802767percent of the funding to go to locals, and that allowed us,2768the State, to directly help those rural cities and counties and2769give them the help that they need.2770    In some cases, we believe even to hire technical resources2771to help them implement the endpoint software, and we've been2772able to provide the training that they wouldn't have otherwise2773needed to do, so we've been able to--we as a State have been2774able to make it super easy.2775    We've just packaged it up and given it to them and even2776helped them implement it, so the way it's worked for us has2777been beautiful.2778    Mr. Raymond. I would add that the match allows for a2779waiver, depending on certain financial conditions, so I do2780believe that if people can't come up with the money to meet the2781match, they have a way to respond to that. However, I think2782people have been reluctant to use that in the expectation that2783that will slow down their award or perhaps not get it--it2784wouldn't be granted the match. So I think there's some2785trepidation for people to put in for that match waiver that's2786preventing some of the uptake of it.2787    Mr. Garbarino. Wonderful.2788    Mr. Huber, you mentioned something in your opening2789statement that lowers the cost-sharing requirements. Is that--2790did you say that?2791    Mr. Huber. I did, yes. I think there was opportunity2792certainly with State municipalities where it makes sense to2793provide shared services, so it increases the ROI for those2794services provided. As Mr. Fuller mentioned as well, you have2795expertise at the State level that can also be shared. They can2796hire additional resources there, so you have a known capacity2797providing resources to certainly rural and municipalities. I2798think that makes them more effective.2799    Then the cost-share component, which I mentioned earlier2800is, like, you don't want to put so much pressure on a small2801organization that doesn't have somebody whose full-time job2802applying for grants trying to do that, right? Justifying that2803resource to do that. You want to put them in the best position2804to be successful, to deploy the technology to protect the2805organization.2806    Mr. Garbarino. Wonderful. I'm out of time, but I'm the2807Chairman, so I'm just going to ask one more question. So now2808we've had this hearing. It's our job to come back and to2809reauthorize this if we want to make any changes, so you're all2810the experts. You've all been dealing with this bill or this2811program. If you could all have--I want to hear from each one of2812you. If there was one change or fix made to this, what would it2813be? We'll start with you, Mr. Huber.2814    Mr. Huber. I think you'd want to ensure that there's2815harmonization of any standards and compliance. You want this to2816be a cybersecurity exercise, raise the bar for cybersecurity,2817not a compliance exercise. Simple as that.2818    Mr. Garbarino. Thank you.2819    Mr. Fuller.2820    Mr. Fuller. I would just say continuity of funding. That2821would be the main thing. People feel hesitant that if the2822funding is not going to be there that they're going to start in2823with the program and then the funding gets cut and then they2824are left holding the bag, and that makes them hesitant to2825adopt.2826    Mr. Garbarino. So the authorization should be longer than 42827years.2828    Mr. Fuller. Yes, please.2829    Mr. Garbarino. OK.2830    Mr. Kramer. I concur with both of my colleagues. Then I2831would add back in what I mentioned a moment ago. For large2832municipalities, if we could apply directly, I think that would2833be helpful. Then allow that organizations like municipal2834leagues would have an opportunity to work together as well.2835    Mr. Garbarino. Mr. Raymond.2836    Mr. Raymond. I would say that on-going sustainable funding2837and then on-going assessments. You cannot manage what you don't2838measure, and so understanding what that cyber risk looks like2839is critical to this on-going success.2840    Mr. Garbarino. Great. Well, I want to thank the witnesses2841for their valuable testimony today and the Members for their2842questions. The Members of the committee may have some2843additional questions for all of you, and we would ask that you2844all respond to these in writing.2845    Pursuant to committee rule VII(E), the hearing record will2846be held open for 10 days. Without objection, this committee2847stands adjourned.2848    [Whereupon, at 12:43 p.m., the subcommittee was adjourned.]28492850                            A P P E N D I X28512852                              ----------28532854      Questions From Chairman Andrew R. Garbarino for Robert Huber2855    Question 1. Are you aware of any instances in which the State and2856Local Cybersecurity Grant Program (SLCGP) has not been fully utilized2857in a given fiscal year? If so, how can we eliminate waste?2858    Answer. Response was not received at the time of publication.2859    Question 2. What challenges do States face in implementing SLCGP2860funds?2861    Answer. Response was not received at the time of publication.2862    Question 3. The SLCGP's statutory authorization permits the2863Secretary of the Department of Homeland Security (DHS) to take action2864to ensure compliance. How has DHS--or the Cybersecurity and2865Infrastructure Security Agency (CISA) and the Federal Emergency2866Management Agency (FEMA)--ensured compliance with the grant program's2867requirements?2868    Answer. Response was not received at the time of publication.2869    Question 4. On average, how long does it take for a State or2870locality to start a cybersecurity program?2871    Answer. Response was not received at the time of publication.2872    Question 5a. Of the States and localities you have worked with, how2873many of them opted to apply for SLCGP funding as a multi-entity group?2874    Answer. Response was not received at the time of publication.2875    Question 5b. Was implementation of multi-entity group projects2876smoother or more challenging? Please explain.2877    Answer. Response was not received at the time of publication.2878      Questions From Chairman Andrew R. Garbarino for Alan Fuller2879    Question 1. In reviewing your Cybersecurity Plan, did the2880Cybersecurity and Infrastructure Security Agency (CISA) help ensure2881your plan was implementable and reflective of the needs of your State?2882Please explain.2883    Answer. Yes. Initially, CISA provided us with guidance, resources,2884and possible templates to use in the creation of our Cybersecurity2885Plan. Those resources were aimed at ensuring we had a good, successful,2886and usable plan. We were required to submit our completed Cybersecurity2887Plan to CISA for review and approval prior to the submission of any2888projects or receipt of any funds. CISA reviewed the plan to make sure2889that it seemed reasonable and implementable. As part of the plan, we2890performed some assessments and looked at information from cybersecurity2891audits and surveys to point our plan toward what was needed in Utah as2892requested in the instructions for creating the plan. In the third and2893fourth year of the grant, we are required to review the plan and submit2894any changes for review and approval by CISA. Our understanding is that2895CISA is reviewing the plan to make sure it and future spending of grant2896funds and projects meet the goals of the grant requirements, are2897reasonable expenditures, and can reasonably be implemented to improve2898cybersecurity in the State. CISA personnel have been a valuable2899resource during the cybersecurity planning phase and throughout the2900SLCGP process.2901    Question 2. Are you aware of any instances in which the State and2902Local Cybersecurity Grant Program (SLCGP) has not been fully utilized2903in a given fiscal year? If so, how can we eliminate waste?2904    Answer. In Utah's case, there are no instances where the SLCGP has2905not been fully utilized each year. We have also not heard of any2906instances outside of our State. The parameters and guidance of the2907SLCGP give sufficient latitude in the time frame for spending and using2908the grant funds as intended. Since there is a several-year span in2909which to expend each fiscal year's funds, it provides the appropriate2910time to plan and implement good cybersecurity programs properly. If the2911time lines were shorter, it could lead to pressure to expend funds too2912quickly and without proper planning.2913    Keeping the current system in place, where the State receives the2914funds and can administer the programs and award subgrants, provides an2915excellent process to eliminate waste. There is strong oversight of the2916grant and expenses, a set focus for helping locals as percentages of2917the funds must be expended on locals, and an ability to purchase2918products at a mass scale to save money and ensure that they are being2919provided to as many entities as possible. If other entities within the2920State could apply directly for funds, it could cut into the ability to2921use economies of scale, create consensus and collaboration on2922cybersecurity projects, make it so smaller communities who need help2923were not served properly, and manage projects to ensure an effective2924distribution and implementation, which in turn would lead to waste. In2925addition, the SLCGP has guidelines to direct the spending of resources2926specifically on cybersecurity to avoid wasteful spending.2927    Continuing the program can eliminate the waste that occurs with2928prematurely starting and stopping the implementation of programs.2929    Question 3. Can you please describe how you track funding to ensure2930that the SLCGP's allocation requirements for local and rural entities2931are met?2932    Answer. With Utah's model, we have committed to ensuring all the2933funds go to help local governments and rural entities. The 20 percent2934of funds allocated to the State were used to assist locals and2935implement the programs. We purchase licensing and advertise it to our2936target audience of counties, municipalities, and local special service2937districts. We track interest and eligibility through an interest2938submission form. We then organize those responses according to need and2939engage with those entities. We track each onboarding and implementation2940and their progress in a separate software program, as well as the2941distribution of the licensing and costs of those services, backed up by2942the data in the software platforms to ensure that we are meeting the 802943percent to locals and 25 percent to rural communities. We constantly2944check those numbers to ensure we hit the required target percentages.2945    Question 4. What challenges do States face in implementing SLCGP2946funds?2947    Answer. One of the biggest challenges is the continuity of funds.2948The cybersecurity risk is prevalent and communities are undermanned and2949underfunded for the fight against cyber attacks. The grants help2950kickstart programs, but without continued funds it will be hard to2951sustain programs or expand into other needed areas of cybersecurity2952protection. In some cases locals see that the funds are only for a2953limited time, which can cause hesitation in adoption because they know2954those programs could cease, leaving them trying to fill a gap they2955don't have the resources to fill.2956    Through funds allocated by the Utah Legislature, the State of Utah2957funded the entirety of the required match funds. Had that not been the2958case, it would have presented a challenge to local entities2959participating in the program, as they did not have the funds to meet2960the match requirements.2961    With the first round of funding, the State pursued a whole-of-State2962model and provided services to the local entities. At the same time, we2963carved out some funds to award directly to small or a handful of local2964entities as sub-recipients for their own cybersecurity projects. We2965found the sub-recipient process to be quite challenging from the2966standpoint of ensuring compliance with the SLCGP standards and funding2967quality projects. Though projects that met the SLCGP standards were2968implemented, we found that the quality of the implemented programs and2969funding did not go as far and was not as impactful on the overall need2970and the State cybersecurity risk that exists. In the end, we were able2971to stretch funds more efficiently and effectively and create more2972impact by purchasing and saving at the State level and providing those2973services to local entities.2974    Another big challenge is simply communicating and building trust2975with all eligible entities and ensuring they know the programs, what2976they are, and why they need them.2977    Question 5. The SLCGP's statutory authorization permits the2978Secretary of the Department of Homeland Security (DHS) to take action2979to ensure compliance. How has DHS--or CISA and the Federal Emergency2980Management Agency (FEMA)--ensured compliance with the grant program's2981requirements?2982    Answer. Initially, they have ensured compliance with the2983cybersecurity plan and its approval, in addition to submitting and2984approving projects and specific funds tied directly to those projects2985before releasing any funds. There is also the requirement locally for a2986cybersecurity commission, which helps CISA and FEMA tangentially with2987the compliance and proper use of the grant program. We must provide2988certain attestations and agreements to comply with certain requirements2989properly. After projects are started, they ensure compliance through2990our required quarterly financial reporting and yearly performance2991reporting on the progress of projects. These reports include narratives2992on progress, challenges, and proof of expenditures and use of funds in2993the previously-approved areas. They also do remote and site audits and2994monitoring. The State of Utah had what CISA/FEMA called a Desk Review2995completed of our SLCGP program in May 2024. Personnel from DHS CISA and2996FEMA attended and asked various questions about the progress of our2997programs and were provided with evidence of progress.2998    Question 6. On average, how long does it take for a State or2999locality to start a cybersecurity program?3000    Answer. Depending on the methodology and implementation, it can3001take anywhere from 6 months to a year or more. Utah had a good process,3002which took around 6 months for the initial phase. We anticipated the3003SLCGP by hiring personnel, forming a Cybersecurity Commission, and then3004performing assessments to identify gaps. We coupled that with data from3005other State surveys and cybersecurity audits previously completed. We3006ensured consensus by reaching out to entities such as the League of3007Cities and Towns and the Association of Counties through presentations,3008visits, and various meetings. We built our plan and provided it to the3009Security Commission for approval. All of that took approximately 63010months. We then started an evaluation process of toolsets, using3011subsets of local governments as testers of the software and programs.3012We worked with the State legislature on needed bills and policy action3013during this process. Since we built it into our process from the3014beginning, it did not add significant time to the building of our3015cybersecurity program. Additional time could be added based on3016legislative cycles and the need for legislation. Adding all of this to3017our initial time frame of assessments and relationship building, it3018took 9 months for the program to be fully operational.3019    Because of the great community and already-established avenues of3020trust, we feel that Utah was able to move steadily and more quickly3021than perhaps some might be able to in establishing their programs. The3022centralized oversight provided by the SLCGP to the State helped speed3023up the creation and successful implementation of the cybersecurity3024program. There are many variables that could significantly increase or3025decrease the time it takes to implement a successful program, such as3026the support mechanisms and budget, additional personnel, travel,3027engagement time, and security awareness.3028    Question 7. If funding for this program is not reauthorized, are3029there Federal- or State-level funding alternatives you can pursue? If3030so, what are they and how do they compare with the SLCGP?3031    Answer. The State of Utah pursued and received all of the needed3032match funds for this program from the State legislature. We are3033currently pursuing State-level consensus for continued funding,3034anticipating the possible conclusion of the SLCGP program. We have not3035yet received permanent funding, but we continue to work the State3036legislature to help understand the need. We anticipate the State3037legislature will consider additional funding during the next3038legislative session in January 2026. Beyond this, there are no other3039alternatives that exist for appropriately funding these cybersecurity3040programs. At the local level, they have been unable to adequately find3041and fund proper cybersecurity, both from the standpoint of tool sets3042and trained personnel.3043    Even with the success or failure of receiving funding at a State3044level for the programs created through the SLCGP program, the3045cybersecurity risk is still present and more significant than what we3046can cover with SLCGP funds or State dollars alone. We do not currently3047cover all possible government entities with our programs, such as K-123048schools. We are providing only a small sliver of the possible baseline3049security needs that exist to protect an entity properly. We are hoping3050for a combination of both to maintain current programs and expand in3051other areas of security need.3052      Questions From Chairman Andrew R. Garbarino for Kevin Kramer3053    Question 1. Are you aware of any instances in which the State and3054Local Cybersecurity Grant Program (SLCGP) has not been fully utilized3055in a given fiscal year? If so, how can we eliminate waste?3056    Answer. The National League of Cities is not aware of specific3057instances of underutilization by participants in the SLCGP. Generally3058speaking, NLC believes that one key way to improve the efficiency of3059SLCGP would be to reduce the number of intermediaries needed to manage3060each dollar. For that reason, NLC urges Congress to include a direct3061grant fund within the reauthorization of SLCGP, to allow larger3062jurisdictions such as Louisville Metro Government to directly apply3063for, access, and manage a direct Federal grant.3064    Question 2. What challenges do States face in implementing SLCGP3065funds?3066    Answer. The biggest challenge in implementing SLCGP for localities3067has been any delay or unpredictability in releasing SLCGP funds to3068States and the resulting compressions in State application time lines.3069Short application windows are challenging for smaller jurisdictions to3070manage, and a lack of predictability in funding availability between3071fiscal years, as well as the program's titration of match requirements,3072makes the program more difficult to participate in and less appealing3073to potential grantees. Creating a consistent match requirement across3074grant years will help to alleviate some of this uncertainty. In3075Louisville Metro Government, while our staff were familiar with State3076and Federal grants, it still took several weeks to ensure compliance3077with internal processes for coding and disbursing funds.3078    Question 3. The SLCGP's statutory authorization permits the3079Secretary of the Department of Homeland Security (DHS) to take action3080to ensure compliance. How has DHS--or the Cybersecurity and3081Infrastructure Security Agency (CISA) and the Federal Emergency3082Management Agency (FEMA)--ensured compliance with the grant program's3083requirements?3084    Answer. DHS, via CISA and FEMA, require grantees to provide3085quarterly reports on progress, as well as annual participation in the3086nationwide Cybersecurity Review (NCSR) assessment process.3087Participation in NCSR is open to all State, local, Tribal, and3088territorial entities on a free, voluntary basis through the Center for3089Internet Security, and is mandatory for recipients of Homeland Security3090Grant Program and SLCGP funds. NCSR is based on the NIST Cybersecurity3091Framework and is intended to assess program maturity. Use of the NCSR3092can help localities identify gaps, benchmark progress, assess program3093performance, and provides valuable information to the larger government3094cybersecurity community about needs and overall preparedness.3095    Question 4. On average, how long does it take for a State or3096locality to start a cybersecurity program?3097    Answer. Depending on what elements are being considered, it could3098take a local government a year to several years to stand up meaningful,3099well-planned cyber defenses. Local cybersecurity is an evolving target,3100even for well-resourced jurisdictions. For a smaller entity with an IT3101department but no dedicated full time cybersecurity staff, this process3102might look like conducting initial assessments against metrics such as3103the NIST Cybersecurity Framework or the National Cybersecurity Review,3104procuring network monitoring and other services from a vendor, and3105addressing any major low-hanging targets, such as switching the3106jurisdiction to the .gov domain, creating an incident response plan,3107implementing across-the-board two-factor authentication, moving to the3108cloud, establishing regular network backups, or other actions.3109Implementation of several of any combination of the above, when3110accounting for planning, procurement, and implementation, which impact3111many city departments, could easily take multiple years.3112    For a single, relatively simple grant-funded objective, such as3113implementation of email filtering or antivirus protection for municipal3114networks, individual jurisdictions may be able to accomplish that goal3115within a couple of years, depending on the alignment of Federal funding3116cycles, local fiscal years, calendar years, and procurement processes,3117as well as demands on internal staff capacity.3118    Question 5. If funding for this program is not reauthorized, are3119there Federal- or State-level funding alternatives you can pursue? If3120so, what are they and how do they compare with the SLCGP?3121    Answer. There are no direct replacements at the State or Federal3122level for SLCGP. At the Federal level, while other homeland security3123grant programs allow for some use for cybersecurity, there is no3124comparable grant program dedicated to State and local cybersecurity3125capacity. Local governments benefit from a dedicated funding stream for3126cybersecurity needs. State and local governments have also benefited3127from the framework SLCGP has created for more holistic3128intergovernmental coordination on cybersecurity. A fragmented approach3129to funding across multiple other grant programs, in addition to not3130replacing the actual resources provided by SLCGP, would not provide3131this supportive framework to the local cybersecurity effort. SLCGP is3132uniquely tailored to address the needs of rural communities in3133particular, and smaller and rural jurisdictions would be3134disproportionately affected by the loss of SLCGP.3135    Question 6. Do you share cybersecurity best practices and/or3136services with surrounding communities? If so, please explain how you do3137this.3138    Answer. Louisville Metro Government shares both cybersecurity best3139practices and services with other jurisdictions throughout the3140Commonwealth of Kentucky. LMG participates in a number of State and3141regional working groups focused on cybersecurity. LMG staff also3142present educational material to local government-focused groups such as3143the Kentucky Association of Counties and the Jefferson County League of3144Cities, which helps us provide support to smaller jurisdictions.3145Louisville Metro Government also provides pro bono services directly to3146smaller municipalities in the region.3147    As part of LMG's SLCGP grant expenditure, we are establishing the3148Kentucky Cyber Threat Intelligence Cooperative (KCTIC). Through this3149effort, we are addressing the latency of actionable threat information3150provided by government entities, private security companies, and our3151regional partners.3152    We will provide a platform for non-attributable threat information3153that can be shared in near-real time. Experience has shown us that3154knowing when bad actors are attacking specific vulnerabilities or using3155particular tactics in our neighboring jurisdictions and local3156organizations gives us the opportunity to harden our own defenses. We3157have regional government partners and private companies interested in3158joining KCTIC and we anticipate this project having benefits for3159communities throughout the region and the Commonwealth.3160    The testimony by all witnesses during the April 1 hearing supports3161timely reauthorization of the State and Local Government Cybersecurity3162Grant Program. The National League of Cities thanks the subcommittee3163for its consideration and for the opportunity to respond to its3164questions for the record.3165      Questions From Chairman Andrew R. Garbarino for Mark Raymond3166    Question 1. In reviewing your Cybersecurity Plan, did the3167Cybersecurity and Infrastructure Security Agency (CISA) help ensure3168your plan was implementable and reflective of the needs of your State?3169Please explain.3170    Answer. Yes, our CISA representative was a foundational resource3171for the State's efforts in developing and reviewing our Cyber Plan.3172Connecticut formed a multi-stakeholder committee to perform overall3173cybersecurity review. Our Cybersecurity Advisor, David Palmbach,3174participated in that committee. Through David, CISA provided insight3175into what threats were happening nationally and how our State compared3176to those threats. CISA provided context about what other States and3177local governments were experiencing related to cyber responses and3178organization structures. Finally, CISA ensured that all the3179capabilities of CISA and MS-ISAC are being utilized appropriately3180within the Cybersecurity Plan. This included items such as cyber-3181hygiene, DOT GOV implementation services, on-going vulnerability3182scanning and education services such as table-top exercises.3183    Question 2. Are you aware of any instances in which the State and3184Local Cybersecurity Grant Program (SLCGP) has not been fully utilized3185in a given fiscal year? If so, how can we eliminate waste?3186    Answer. We are not aware of any instances where the SLCGP funds3187have not been fully utilized. Since each award year of the grant3188program has a 4-year period of performance, we do not expect to see3189this in the future. Looking forward, availability of match funding will3190continue to be a struggle for governments; however, the 4-year period3191creates several options in which to arrange for match funds and3192successfully utilize all grant awards.3193    In 2022, which was the first offering of the program in3194Connecticut, we received 100 applications (97 from local entities)3195totaling over $13.7 million ($12.3 Federal share) of which we only had3196$2.9 million ($2.6 Federal) to subgrant. The rural share of this3197totaled over $7 million. We ended up prioritizing projects based on3198recommendations from the chartered planning subcommittee, and3199subgranted to 45 entities. We expect the 2023 round to be the same3200which shows the importance of the grants to our entities.3201    Question 3. Can you please describe how you track funding to ensure3202that the SLCGP's allocation requirements for local and rural entities3203are met?3204    Answer. Through our sub-application process and data collection, we3205ask entities to identify if they are rural (based on the Federal grant3206definition). Using the fiscal year 2022 funds, we subgranted $2,071,2433207to rural entities.3208    Question 4. What challenges do States face in implementing SLCGP3209funds?3210    Answer. One common refrain is the changing match rates across the3211life of the grant. As each yearly award has a multi-year period of3212performance, the State granting agency and many subgrantees will face3213the complexity of managing different fiscal formulas for the same3214program.3215    Additionally, rising technology costs for equipment can diminish3216the overall effectiveness of any individual grant. This will be3217particularly acute in the last 2 years of the program as the funds3218identified for the grant are projected to be drop lower than Year 23219funds.3220    In resource-constrained environments, emerging threats often drive3221a rearrangement of priorities. State and local governments are expected3222to be under additional fiscal stress in cyber as greater responsibility3223is being passed to the State level.3224    Operationally, the State has only identified minor challenges to3225implementing the grant program. There was a delay in opening the sub-3226application period due to the need to have a CISA-approved3227Cybersecurity Plan, but the 4-year period of performance allows ample3228time for awarded entities to complete projects.3229    Question 5. The SLCGP's statutory authorization permits the3230Secretary of the Department of Homeland Security (DHS) to take action3231to ensure compliance. How has DHS--or CISA and the Federal Emergency3232Management Agency (FEMA)--ensured compliance with the grant program's3233requirements?3234    Answer. FEMA/CISA provide extensive guidance through the notice of3235funding opportunity, technical assistance, and webinars and grant3236support. The assigned SLCGP program officer from FEMA has been a great3237resource for grant eligibility and guidance. Additionally, Connecticut3238participated in a monitoring visit from SLCGP staff for compliance and3239to explain the State's implementation process.3240    Question 6. On average, how long does it take for a State or3241locality to start a cybersecurity program?3242    Answer. Launching a cybersecurity program generally involves3243assessment, planning, procurement, staffing, implementation and3244maintenance phases, and generally, with steady resourcing and funding3245it takes 3-5 years as an iterative, consistent effort for a large3246entity to establish program fundamentals. For localities with limited3247staff, the process can stretch longer or proceed in smaller steps. In3248theory a smaller municipality could implement the basics but in3249practice many small municipalities lack the manpower, expertise, and3250continuity of personnel, funding, and experience to focus on3251cybersecurity full-time.3252    Progress at the municipal level has been incremental. Since 2023,3253Connecticut localities & school districts have been taking advantage of3254a free municipal cyber assessment program as planning groundwork in3255risk identification and improvement plans. Connecticut is using these3256plans to create a ``menu'' of cybersecurity projects & areas of focus3257for towns and to prioritize SLCGP funding efforts.3258    With the continued infusion of Federal funds and State of3259Connecticut coordination, the hope is that even the smallest3260municipalities will have at least a baseline cybersecurity framework in3261place within a few years. The on-going audits and assessments will3262continue to highlight gaps, but they also show that progress is being3263made--on a realistic, phased time line--toward standardized cyber3264defenses across Connecticut's State, city, and town governments.3265    Equally important to starting a cyber program is the need to both3266sustain and advance these programs. While we have imperfect views of3267what lies ahead, most professionals in this area expect the maturation3268of artificial intelligence to greatly increase the capabilities of3269cybersecurity threat actors. State and local governments must continue3270to address overall risk reductions in the face of sophisticated and3271ever-evolving threats and adversaries.3272    Question 7. If funding for this program is not reauthorized, are3273there Federal- or State-level funding alternatives you can pursue? If3274so, what are they and how do they compare with the SLCGP?3275    Answer. State and local government budgets remain under pressure3276from rising costs that push up against Constitutional spending caps and3277balanced budget requirements. These pressures could intensify if3278Congress enacts changes to mandatory programs that increase the State's3279share of funding beyond current levels.3280    Connecticut does not have a dedicated source of funding for3281cybersecurity initiatives that could be used to replace this program.3282Cybersecurity is an eligible expense under the FEMA Homeland Security3283Grant Program (HSGP) and Connecticut has leveraged that program for3284vital cybersecurity training and assessment programs to local entities.3285If SLCGP was cut, and HSGP also, that would leave a gap in providing3286funding support to local entities. HSGP funds have been used for3287cybersecurity training personnel, subgrants to local jurisdictions for3288cybersecurity training, and fully funded cybersecurity risk3289assessments. Revisiting that source may provide a modest amount to make3290incremental improvement. This would not be a substantive way to reduce3291State and local cyber risk.3292    One suggestion that might help sustain cybersecurity improvements3293would be to include State-wide cybersecurity as a cost that did not3294require cost allocation under the larger Federal programs (Medicaid,3295Income Security, Transportation, Education). Cost allocation of3296cybersecurity costs represents a complicated limitation on the whole-3297of-government cyber approach. The ability to use a small percentage of3298the existing funds that flow to States as a mechanism to improve3299cybersecurity outcomes on a systemic basis may allow States to fill3300critical gaps at the State and local government level.33013302                                 [all]

Witnesses

4 witnesses appeared, with 13 papers on file.

NamePositionPapers
Mr. Michael LedbetterExecutive Vice President and Chief Operating Officer, COLSA CorporationTruth in Testimony · Biography · Testimony
Mr. Bryan FarrellInterim Director, Raspet Flight Research Laboratory, Mississippi State UniversityBiography · Testimony · Truth in Testimony
Chief Kevin FettermanFire Division Chief, Division 4, Orange County Fire AuthorityTruth in Testimony · Biography · Testimony
Mr. Jerry HendrixExecutive Director, Rotorcraft Systems Engineering and Simulation Center, University of Alabama in HuntsvilleTruth in Testimony · Testimony · Witness Support Document · Biography

Documents

The committee filed 2 documents for the meeting.

DocumentKindFormat
Hearing NoticeSupport DocumentPDF
Hearing: Witness ListHearing: Witness ListPDF