Recent Bills
- H.R. 10171August 27, 2026
- H.R. 10156August 27, 2026
- H.R. 10172August 27, 2026
- H.R. 10160August 27, 2026
- H.R. 10181August 27, 2026
- H.R. 10176August 27, 2026
- H.Res. 1496August 27, 2026
- H.R. 10164August 27, 2026
- H.R. 10170August 27, 2026
- H.Res. 1494August 27, 2026
- H.R. 10163August 27, 2026
- H.R. 10157August 27, 2026
Committees
- AdministrationU.S. House
- AgricultureU.S. House
- Agriculture, Nutrition, And ForestryU.S. House
- AppropriationsU.S. House
- Armed ServicesU.S. House
- Banking, Housing, And Urban AffairsU.S. House
- BudgetU.S. House
- Commerce, Science, And TransportationU.S. House
- Education and WorkforceU.S. House
- Energy And CommerceU.S. House
- Energy And Natural ResourcesU.S. House
- Environment And Public WorksU.S. House
- EthicsU.S. House
- FinanceU.S. House
- Financial ServicesU.S. House
- Foreign AffairsU.S. House
- Foreign RelationsU.S. House
- Health, Education, Labor, And PensionsU.S. House
- Homeland SecurityU.S. House
- Homeland Security And Governmental Affa…U.S. House
- Indian AffairsU.S. House
- Indian and Insular AffairsU.S. House
- IntelligenceU.S. House
- JudiciaryU.S. House
- Natural ResourcesU.S. House
- Oversight And Government ReformU.S. House
- Permanent Select IntelligenceU.S. House
- RulesU.S. House
- Rules And AdministrationU.S. House
- Science, Space, And TechnologyU.S. House
- Select IntelligenceU.S. Senate
- Small BusinessU.S. House
- Small Business And EntrepreneurshipU.S. House
- Subcommittee on AviationU.S. House
- Subcommittee on Border Security and Enf…U.S. House
- Subcommittee on Coast Guard and Maritim…U.S. House
- Subcommittee on Commodity Markets, Digi…U.S. House
- Subcommittee on Conservation, Research,…U.S. House
- Subcommittee on Counterterrorism and In…U.S. House
- Subcommittee on Cybersecurity and Infra…U.S. House
- Subcommittee on Disability Assistance a…U.S. House
- Subcommittee on Economic Development, P…U.S. House
- Subcommittee on Economic OpportunityU.S. House
- Subcommittee on Emergency Management an…U.S. House
- Subcommittee on Energy and Mineral Reso…U.S. House
- Subcommittee on Federal LandsU.S. House
- Subcommittee on Forestry and Horticultu…U.S. House
- Subcommittee on General Farm Commoditie…U.S. House
- Subcommittee on HealthU.S. House
- Subcommittee on Highways and TransitU.S. House
- Subcommittee on Livestock, Dairy, and P…U.S. House
- Subcommittee on Nutrition and Foreign A…U.S. House
- Subcommittee on Oversight and Investiga…U.S. House
- Subcommittee on Oversight, Investigatio…U.S. House
- Subcommittee on Railroads, Pipelines, a…U.S. House
- Subcommittee on Transportation and Mari…U.S. House
- Subcommittee on Water Resources and Env…U.S. House
- Subcommittee on Water, Wildlife and Fis…U.S. House
- Transportation And InfrastructureU.S. House
- Veterans' AffairsU.S. House
- Ways And MeansU.S. House

Shaping the Future of Cyber Diplomacy: Review for State Department Reauthorization
Hearing•House Foreign Affairs Subcommittee on Europe•Apr 29, 2025 · 2:00 PM
Summary
House Foreign Affairs Subcommittee on Europe held a hearing on Apr 29, 2025 at 2:00 PM in Rayburn House Office Building, Room 2200. 3 witnesses appeared.
Record
The meeting has its video, its transcript, witnesses and documents on the record.
Video
The proceedings, as the committee streamed them.
Transcript
The transcript runs to 1,343 lines and 72,240 characters, as the Government Publishing Office printed it.
house-hearing-60593.txt1[House Hearing, 119 Congress]2[From the U.S. Government Publishing Office]34 SHAPING THE FUTURE OF CYBER DIPLOMACY: REVIEW FOR STATE DEPARTMENT5 REAUTHORIZATION67=======================================================================89 HEARING1011 OF THE1213 SUBCOMMITTEE ON EUROPE1415 BEFORE THE1617 COMMITTEE ON FOREIGN AFFAIRS18 U.S. HOUSE OF REPRESENTATIVES1920 ONE HUNDRED NINETEENTH CONGRESS2122 FIRST SESSION2324 __________2526 April 29, 20252728 __________2930 Serial No. 119-143132 __________3334 Printed for the use of the Committee on Foreign Affairs3536 [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]3738Available: http://www.foreignaffairs.house.gov, http://docs.house.gov,39 or http://www.govinfo.gov4041 _______4243 U.S. GOVERNMENT PUBLISHING OFFICE444560-593PDF WASHINGTON : 20254647 COMMITTEE ON FOREIGN AFFAIRS4849 BRIAN J. MAST, Florida, Chairman50MICHAEL T. McCAUL, Texas GREGORY W. MEEKS, New York,51CHRISTOPHER H. SMITH, New Jersey Ranking Member52JOE WILSON, South Carolina BRAD SHERMAN, California53SCOTT PERRY, Pennsylvania GERALD E. CONNOLLY, Virginia54DARRELL ISSA, California WILLIAM R. KEATING, Massachusetts55TIM BURCHETT, Tennessee AMI BERA, California56MARK E. GREEN, Tennessee JOAQUIN CASTRO, Texas57ANDY BARR, Kentucky DINA TITUS, Nevada58RONNY JACKSON, Texas TED LIEU, California59YOUNG KIM, California SARA JACOBS, California60MARIA ELVIRA SALAZAR, Florida SHEILA CHERFILUS-McCORMICK,61BILL HUIZENGA, Michigan Florida62AUMUA AMATA COLEMAN RADEWAGEN, GREG STANTON, Arizona63 American Samoa JARED MOSKOWITZ, Florida64WARREN DAVIDSON, Ohio JONATHAN L. JACKSON, Illinois65JAMES R. BAIRD, Indiana SYDNEY KAMLAGER-DOVE, California66THOMAS H. KEAN, JR, New Jersey JIM COSTA, California67MICHAEL LAWLER, New York GABE AMO, Rhode Island68CORY MILLS, Florida KWEISI MFUME, Maryland69RICHARD McCORMICK, Georgia PRAMILA JAYAPAL, Washington70KEITH SELF, Texas GEORGE LATIMER, New York71RYAN K. ZINKE, Montana JOHNNY OLSZEWSKI Jr, Maryland72JAMES C. MOYLAN, Guam JULIE JOHNSON, Texas73ANNA PAULINA LUNA, Florida SARAH McBRIDE, Delaware74JEFFERSON SHREVE, Indiana BRADLEY SCOTT SCHNEIDER, Illinois75SHERI BIGGS, South Carolina MADELEINE DEAN, Pennsylvania Q0476MICHAEL BAUMGARTNER, Washington77RYAN MACKENZIE, Pennsylvania78 James Langenderfer, Majority Staff Director79 Sajit Gandhi, Minority Staff Director80 ------8182 SUBCOMMITTEE ON EUROPE8384 KEITH SELF , Texas, Chairman85 MICHAEL T. McCAUL , Texas WILLIAM KEATING, Massachusetts,86 JOE WILSON , South Carolina T3Ranking Member K87 MARK GREEN , Tennessee DINA TITUS , Nevada88 YOUNG KIM , California JIM COSTA , California89 WARREN DAVIDSON , Ohio GABE AMO , Rhode Island90 ANNA JULIE JOHNSON , Texas91AULINA LUNA , Florida SARAH McBRIDE , Delaware9293 Michael Koren, Subcommittee Staff Director9495 C O N T E N T S9697 ----------9899 REPRESENTATIVES100101 Page102Opening Statement of Subcommittee Chairman Keith Self............ 1103Opening Statement of Subcommittee Ranking Member William Keating. 2104105 WITNESSES106107Statement of Annie Fixler, Director, Center on Cyber and108 Technology, Foundation For Defense of Democracies.............. 4109 Prepared Statement............................................. 7110Statement of Latesha Love-Grayer, Director, International Affairs111 and Trade, U.S. Government Accountability Office............... 19112 Prepared Statement............................................. 21113Statement of Theodore Nemeroff, Co-Founder and Vice President for114 Data and Compliance, Verific AI................................ 37115 Prepared Statement............................................. 39116117 APPENDIX118119Hearing Notice................................................... 60120Hearing Minutes.................................................. 62121Hearing Attendance............................................... 63122123 Questions for the Record124125Questions for the Record submitted to Ms. Latesha Love-Grayer126 from Rep. Gabe Amo............................................. 64127128 SHAPING THE FUTURE OF CYBER DIPLOMACY: REVIEW FOR STATE DEPARTMENT129 REAUTHORIZATION130131 ----------132133 Tuesday, April 29, 2025134135 House of Representatives,136 Subcommittee on Europe,137 Committee on Foreign Affairs,138 Washington, DC.139140 The subcommittee met, pursuant to notice, at 2:19 p.m., in141room 2200, Rayburn House Office Building, Hon. Keith Self142(chairman of the subcommittee) presiding.143 Mr. Self. The Subcommittee on Europe will come to order.144The purpose of this hearing is to discuss the subcommittee's145areas of jurisdiction for the State Department authorization,146which includes the Bureau of Cyberspace and Digital Policy.147 I now recognize myself for an opening statement.148149 OPENING STATEMENT OF CHAIRMAN KEITH SELF150151 I want to welcome members and witnesses to the subcommittee152on Europe's second hearing on State Department reauthorization.153Today, the subcommittee will be exploring the role of the State154Department in cyber and technology matters, and how such155policies might align with U.S. national security interests and156foreign policy objectives. In particular, we will be examining157the work of the Bureau of Cyberspace and Digital Policy, or158CDP. Across the globe malicious cyber attacks are conducted by159State and nonState actors against the United States and its160allies, including from the People's Republic of China, from161cyber criminals scamming individuals out of their savings to162large scale state-sponsored attacks from America's adversaries.163U.S. Government entities and citizens are increasingly under164siege. For years, PRC-supported hackers have buried deep into165critical infrastructure, including water transportation166networks and energy systems.167 According to the 2025 annual worldwide threats assessment168of the U.S. IC, intelligence community, the PRC remains the169most active and persistent cyber threat to U.S. Government170private sector and critical structure networks. Beijing's171campaign to preposition access on critical infrastructure for172attacks during crisis or conflict, tracking publicly as volt173typhoon, or it more recently identified compromise of U.S.174telecommunications infrastructure, also referred to as Salt175Typhoon, demonstrates the growing breadth and depth of the176PRC's capability to compromise U.S. infrastructure.177 Russia also poses a significant cyber threat with its178efforts to compromise sensitive targets for intelligence179collection and to preposition access to U.S. critical180infrastructure. In addition to Beijing and Moscow, Tehran has181demonstrated an increasing willingness to carry out aggressive182cyber operations to the security of U.S. networks and data.183 Furthermore, Pyongyang's cyber program presents a highly184capable and maturing threat, including an approach to launder185and cash out cryptocurrency from the United States and other186victims to fund its nefarious activities. As cyber becomes a187growing battlefield for criminal networks and maligned actors,188the State Department must be ready to meet the challenge. The189U.S. is not facing these real and growing threats alone, it190took cooperation with our allies and our partners. The U.S.191will continue to work to combat and align cyber activities from192PRC, Iran, North Korea and Russia.193 Since the recent establishment of CDP, it has played a role194in the U.S. response to a major ransomware campaign in Costa195Rica that disrupted critical services. In particular, CDP,196alongside other Federal partners, work to strengthen Costa197Rica's cyber defenses against attacks from malicious actors198threatening the security of both our countries. It has also199worked to identify strategic opportunities to leverage partner200resources to further U.S. strategic objectives through subsea201cable projects in the Pacific Islands.202 Such efforts ensure that the Pacific Islands rely on203trusted, primarily American businesses for their internet204connectivity while also countering the PRC's influence in the205strategically imported region. On the other hand, the206Department of State agreement on a cybercrime U.N. treaty that207conflicted with CDP policy lead and recommendations begs the208question of the actual authority wielded by CDP. This hearing209should lead us toward conclusions on how to improve CDP210efficiency and effectiveness in this vital area of national211interest and security.212 As we move through this reauthorization process, the213experience and insights from today's witnesses will help inform214this subcommittee on the State Department's cyber diplomacy215role in addressing these increasingly important challenges.216 I look forward to hearing your testimony and217recommendations. The chair now recognizes the ranking member,218the gentleman from Massachusetts, Mr. Keating, for any219statement he may have.220221 OPENING STATEMENT OF RANKING MEMBER WILLIAM KEATING222223 Mr. Keating. Thank you, Mr. Chairman and to our witnesses224for being here today. For years, bipartisan members of this225committee have recognized the necessity for the State226Department to take on the important task of cyber diplomacy. In2272021, the Biden administration announced the creation of the228Bureau of Cyberspace and Digital Policy, CDP, with bipartisan229support and the Department of State Authorization Act of 2022230authorized the CDP Bureau into statute, an important step in231recognizing the need for robust and comprehensive approach to232cyber diplomacy.233 With the CDP bureau established in statute, its work in234conjunction with this committee to lead the State Department's235diplomatic cyberspace and cybersecurity efforts encompassing236both hard security and economic policy. As our adversaries,237Russia, China, Iran and North Korea, each take different238approaches to undermining U.S. actions in cyberspace,239bolstering U.S. cyber capability through a strong CDP bureau is240more important than ever.241 The CDP bureau has worked to advanced U.S. interest in242cyberspace across multiple lines of effort. For example,243following the 2022 ransomware attack in Costa Rica by a244Russian-linked cyber crime group, the CDP bureau provided245swift, decisive, support to Costa Ricans and their authorities246to bolster the country's digital defenses and resiliency. This247emergency support was critical to ensure that a partner in our248own hemisphere was able to effectively respond to an249unprecedented attack. Similarly, the State Department worked to250strengthen Ukraine cyber defenses in the midst of Russia's251full-scale, illegal invasion of the country through the digital252connectivity cybersecurity partnership program, a joint venture253by the Department of USAID.254 These are just a few examples of the CDP bureau's important255work to bolster our allies and partners while promoting256American values and security in cyberspace.257 While I appreciate the opportunity to talk about an258important bureau, which is long maintained by partisan support,259it is unfortunately clear that neither this majority nor the260Trump administration has any interest or intent to engage261constructively on a reauthorization of the State Department.262 Last week, Secretary Rubio unveiled a proposed263reauthorization plan for the State Department without any264meaningful consultation with Congress. Reorganization would265decimate the Department's cyber policy tools by splitting it in266half. CDP's economic structures would be moved under the267economic family of the bureau and CDP's hard security offices268would be placed in a new emerging threats bureau. This move269will create exactly the duplication and the waste this270administration says it seeks to avoid. Even more concerning, it271deprioritizes a crosscutting issue that needs to be tackled272holistically and at the highest levels.273 Our witnesses here today and many experts in the field have274all pointed out the importance of capacity building in275cyberspace and maintaining and recruiting the skills required276for qualified cyber diplomacy workforce.277 Unfortunately, rather than invest in capacity building in278places like Costa Rica and Ukraine, the Trump administration279has slashed the U.S. foreign assistance budget and illegally280eliminated USAID, a chief implementer with capacity-building281programs.282 At the same time, GAO and Ms. Love-Grayer, they found out283that nonpartisan report, that while CDP is currently staffed284and fully operational, it needs to train existing staff and285hire more people to meet its growth plans. Rather than seeking286to recruit and train staff, the Trump administration has287attacked and politicized the Federal workforce, leaving a288legacy of destruction and indeed distrust.289 Finally, rather than listen to the advice of experts,290consult with industry professionals and engage with the State291Department, this committee has effectively served as a rubber292stamp for the administration's destructive actions.293 Ms. Fixler, you concluded in an article on March 17th the294capacity building program, including those implemented by295USAID, are not merely altruistic endeavors, they advance296critical U.S. interest. Ms. Love-Grayer, your nonpartisan 2024297GAO report concluded that the State Department provides foreign298assistance to strengthen partner capacity and to promote cyber299norms to achieve U.S. cyber policy objectives.300 Mr. Nemeroff, your testimony points out that a well-placed301cybersecurity foreign assistance project can make all the302difference in leveling the playing field for our companies and303private investments in countries that still deeply respect U.S.304tech leadership. Yet rather than invite administration witness305here from the CDP bureau to testify on the effectiveness of the306bureau's programming or implement the advice of experts like307our witnesses here today, the chair of the full committee and308many of my major majority colleagues have already309wholeheartedly endorsed the administration's reorganization310plans. This is a troubling abdication of the oversight311responsibilities of this committee, and an elimination of the312Article I authority of this Congress.313 I look forward to the testimony of our witnesses here314today. I would strongly urge my majority colleagues to listen315to what they have to say, work to reauthorize the State316Department in a way that serves the interest of the American317public, and move this important issue to the foreign front.318 I yield the balance of my time.319 Mr. Self. Other members of the committee are reminded that320opening statements may be submitted for the record.321 We are pleased to have a distinguished panel of witnesses322before us today on this important topic. Ms. Annie Fixler,323Director of Center on Cyber and Technology at the Foundation324for Defense of Democracies; Ms. Letesha Love-Grayer, Director325of International Affairs and Trade at the U.S. GAO; and Mr.326Theodore Nemeroff, cofounder and Vice President for Data and327Compliance at Verific AI.328 This committee recognizes the importance of the issues329before us and is grateful to have you here to speak with us330today. Thank you. Your full statements will be made part of the331record. And I will ask each of you to keep your spoken remarks332to 5 minutes in order to allow time for our member questions.333 I now recognize Ms. Fixler for your opening statement.334335 STATEMENT OF ANNIE FIXLER336337 Ms. Fixler. Thank you, Chairman Self, Ranking Member338Keating, and distinguished members of the committee, on339behalf----340 Mr. Self. Would you check your mic, or get closer to it?341 Ms. Fixler. Sorry.342 Mr. Self. Pull it close to you.343 Ms. Fixler. Better?344 Mr. Self. Try it.345 Ms. Fixler. Thank you, Chairman Self, Ranking Member346Keating, and distinguished members of the committee, on behalf347of the Foundation for Defense of Democracies, thank you for348inviting me to testify today.349 For years, on a bipartisan basis, members of this committee350pushed the State Department to better organize itself to defend351U.S. national security in cyberspace. Two and a half years352after creating the Bureau of Cyberspace and Digital Policy,353this committee must assess its performance, expand its354successes and address its shortcomings. This hearing is355particularly timely, given the Department's proposed356reauthorization which appears to put its cybersecurity efforts357at risk and contradict congressional guidance to integrate358cybersecurity and digital economy efforts.359 In my written testimony, I describe the successes the360bureau has been able to achieve because of this integration. I361would like to take this opportunity to summarize the threat we362face and the role States cyber bureau should play.363 Every day malicious cyber operators sitting in remote364corners of the world attack our critical infrastructure. Across365energy transportation and communication systems, China has366prepositioned destructive capabilities. Beijing is prepared to367use crippling cyber attacks to induce societal panic and368interfere with our ability to project power.369 During the Biden administration, we issued stern warnings370but failed to deter Chinese aggression. Trump administration371officials and Members of Congress have rightfully articulated372that our Nation needs to go on the offense and punish those who373use cyberspace to do us harm. And we need better defense to374deny our adversaries their objectives.375 The cyber bureau plays a critical role in both. Over the376course of its short tenure it has demonstrated it understands377these priorities and can execute the mission.378 Congress tasked the bureau with managing a unique cyber379assistance fund because lawmakers recognized it took far too380long for us to respond to incidents overseas that might cascade381and hit our homeland. Now in as little as 2 days, the bureau382can airdrop expertise into partner countries.383 The Department bolsters allied law enforcement capability384to investigate cyber crime and prosecute the offenders and385convinces those same allies and partners to join us when we386call out bad behavior.387 The first step to getting our allies and partners to impose388costs on China is for them to agree that a cyber attack has389occurred and that Beijing is to blame. The bureau helps allies390and partners proactively build cyber resilience. On this, our391strategic priorities are clear: We need the countries that we392fight with and through to have resilient infrastructure.393Resilience buys America time to deploy a range of policy394responses. Had Ukraine succumbed to Russian cyber attacks,395Washington could not have provided the lethal aid that has396helped Kyiv substantially degrade the military capabilities of397a leading U.S. adversary.398 Last summer, FDD led a tabletop exercise in Taiwan,399exploring Chinese cyber enabled economic warfare against the400island. In the game, the thing that gave Beijing the greatest401pause was not U.S. countermeasures, but an assessment that402Taiwan could withstand the attack. If China believed that403Taiwan could survive, it would refrain from attacking in the404first place, lest Taiwan's strengths reveal the CCP's limits.405Resilience has a deterrent power all its own. But building the406resilience of allies and partners will be a Sisyphean task if407the telecommunications infrastructure underpinning all of it is408built by China.409 The U.S. military does not have operational security if410Beijing is listening on the line. In the CHIPS Act, Congress411tasked and funded efforts at State to secure information412communications technology. The cyber bureau is wisely using its413portion on undersea cables in the Indo-Pacific.414 When Congress created the bureau, lawmakers rightfully415articulated that its head must be a principal cybersecurity416policy official in the Department. It also needs permanent417staff billets so that the funding Congress appropriate is spent418wisely and efficiently. There is a battle underway in419cyberspace. Without a robust cyber bureau, we will not win.420 Thank you for inviting me to testify today. I look forward421to your questions.422 [The prepared statement of Ms. Fixler follows:]423424 [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]425426 Mr. Self. Thank you, Ms. Fixler.427 I now recognize Ms. Love-Grayer for your opening statement.428Welcome.429430 STATEMENT OF LATESHA LOVE-GRAYER431432 Ms. Love-Grayer. Chairman Self, Ranking Member Keating, and433members of the subcommittee, thank you for the opportunity to434discuss our work on the Bureau of Cyberspace and Digital Policy435known as CDP. As international trade communication and critical436infrastructure grow more dependent on cyberspace and digital437technology, there is an opportunity to advance U.S. interests438in this digital ecosystem. But also an increase in foreign439cyber threats. Foreign governments and nonState actors are440increasingly using cyberspace as a platform to target critical441infrastructure and our citizens, undermine democracies and442international institutions and uncut global competition by443stealing ideas when they cannot create them. These are among444the reasons that GAO has identified information security as a445high-risk issue.446 In April 2022, State established CDP to lead U.S.447Government international efforts to advance our interest in448cyberspace, which State defines as cyber diplomacy. Its449overarching objectives included building coalitions,450strengthening capacity and reinforcing alarms in cyberspace.451 State uses two main tools to implement the cyber diplomacy452mission, diplomatic engagement and leadership and multilateral453and bilateral fora and foreign assistance that provide training454and technical assistance to our international partners.455 Examples of the diplomatic efforts include engaging with456the European Union to develop shared principles in the 6G457wireless network. And supporting the negotiation process of the458U.N. cybercrime convention, which appropriately, if459appropriately ratified, would facilitate international460cooperation to combat cyber crime.461 As Congress considers State's reauthorization, my statement462today is intended to help inform the discussion about the cyber463diplomacy efforts and was based primarily on the reports that464we have issued between September 2020 and January 2024 related465to those efforts.466 State's cyber diplomacy efforts have evolved between 2011467and the present. Between 2011 and 2018, State established the468Office of the Coordinator of Cyber Issues to lead global469diplomatic engagement and developed an international cyberspace470policy strategy document among other efforts. In January 2019,471Members of Congress introduced the Cyber Diplomacy Act of 2019,472which would have established a new office to lead State's473international cyberspace efforts and consolidate a range of474crosscutting cyber issues.475 Later that year, State notified Congress of its intent to476establish a bureau that was more narrowly focused on477cybersecurity. In September 2020 and January 2021, we assessed478these efforts to establish the cyber bureau. We found that it479had not involved other Federal agencies that contributed to480international cyber diplomacy and the development of its plan481and recommended that it do so.482 We also found that State had not demonstrated that it had483used data and evidence to develop its proposal for establishing484the bureau, and therefore, lacked assurance that its proposal485would effectively set priorities and allocate resources to486achieve those goals. We recommended that it do so.487 In response, State consulted other key Federal agencies and488its plaining and collected data and evidence to inform its489approach, which resulted in changes to the final plan for the490bureau.491 Once the bureau was established, we examined how it was492structured to accomplish its goals. CDP contains four units,493including the office of the coordinator for digital freedom,494international information and communications policy,495international cyberspace security, and a strategies program in496communications unit. The new consolidated bureau and the497appointment of a Senate-confirmed Ambassador at large to lead498it elevated cyber issues in State's diplomatic engagement, that499Ambassador engaged with various other country senior leaders on500advancing cyber goals.501 As an example, in August 2023 the Ambassador headed the502U.S. delegation to the G-20 digital economy ministerial meeting503he highlighted U.S. views and priorities on digital economy504topics.505 In addition, we reported that CDP status as a bureau506provided senior-level support, resources, and involvement, that507did not exist before. Although State's efforts to promote cyber508diplomacy have evolved, challenges remained. Among them clearly509defining CDP's roles and responsibilities across overlapping510issuers with other inter, intra and inter agencies that conduct511work in cyber diplomacy, especially given the breadth of cyber512issues, as well as ensuring that the bureau has sufficient513expertise to carry out its goals.514 These are among the challenges that the bureau will still515need to effectively navigate to lead cyber diplomacy in the516future, especially a State considers streamlining its functions517and addressing any new priorities of the administration.518 Chairman Self, Ranking Member Keating and members of the519subcommittee, this concludes my oral statement. I would be520happy to take questions at this time.521 [The prepared statement of Ms. Love-Grayer follows:]522523 [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]524525 Mr. Self. Thank you, Ms. Love-Grayer.526 I now recognize Mr. Nemeroff for his opening statement,527welcome.528529 STATEMENT OF THEODORE NEMEROFF530531 Mr. Nemeroff. Chairman Self, Ranking Member Keating,532distinguished members of the subcommittee, thank you for the533opportunity to testify today. My remarks are drawn from my534written testimony and offered in my personal capacity.535 This subcommittee is reviewing the Cyber Diplomacy Act at a536critical time. American leadership and key technologies,537especially AI, positions us to shape the global technological538ecosystem in ways that align with our values and benefit U.S.539national and economic security. But our vision is contested, as540my colleagues here has really effectively outlined. China poses541the greatest and most comprehensive challenge to U.S.542leadership, leveraging both economic and security tools to543advance its goals. Russia, Iran and North Korea also pose544significant threats and ransomware actors operating with545impunity from Russian territory routinely disrupt our546businesses, our hospitals and our schools.547 Through the Cyber Diplomacy Act. This committee has helped548ensure the State Department is better prepared to meet these549challenges. A key strength of Congress' vision was to integrate550national security, economic and human rights equities in CDP.551This has increased efficiency and reduced redundancy within the552Department, and unlocked opportunities to face the challenge553posed by China in particular in more comprehensive and554strategic ways. But we can always do better. I recommend going555forward focusing on four areas: First, CDP should take further556steps to organize itself around a full-stack approach to cyber557and digital diplomacy. Whether our adversaries gain access to558critical systems through hacking or by selling untrusted559undersea cables data centers or 5G, it all harms our national560security, and the Department needs to think about this all561together.562 A full stack approach enables us to see the full picture563and leverage engagements at one layer to have influence at564others. For example, the way that our cyber support to Costa565Rica, which has been cited several times already, has, since5662022, opened the door to deeper cooperation with the country on567telecom issues.568 Second, CDP should continue to lead efforts to deter569adversaries that behave irresponsibly. Cyber deterrence is not570like nuclear deterrence. It requires a dynamic and constant571effort, warning adversaries about activities we won't accept572and then swiftly, preferably with allies, responding to573activities that cross our lines by imposing meaningful574consequences.575 This effort started in the first Trump administration with576coordinated international responses to incidents like Russia's5772017 NotPetya cyber attack, and it continued in the Biden578administration with actions like our response to Iran's brazen5792022 cyber attack against Albania, attempting to coerce a NATO580ally.581 Third, CDP should continue to take on a more operational582role, especially in incident response, and by using diplomatic583channels to support whole-of-government adversary disruption584campaigns. These activities show clear gaps in interagency585capabilities that I saw when I was at NSC working on issues586around Ukraine and others.587 I want to particularly highlight the potential for CDP's588recently piloted falcon capability which allows State to589rapidly deploy private sector incident responders to countries590in need.591 Finally, I want to emphasize the importance of foreign592assistance and development finance. We are in a global tech593competition with China. We need every tool possible to level594the playing field for our companies against China's subsidies595and hardball tactics. And a well-placed cyber assistance596project, or a well-timed loan can make all the difference. CDP597needs funding to provide specialized foreign assistance where598it is most needed, and it should be empowered to build a599coordinated, full-stack investment strategy across the600interagency, including with institutions like development601finance corporation.602 This subcommittee has been--we will be reauthorized in the603Cyber Diplomacy Act, alongside the administration's recently604announced plans to reorganize the Department.605 I offer four key questions to consider as you decide on the606way ahead: First, does the proposed restructuring enable the607type of integrated approach I have discussed today? Second,608does it maintain the requisite attention authority and609responsibility of the Department's most senior leaders, the610ones who can make this a priority in States regionally oriented611work?612 Third, does it sustain and ideally accelerate efforts to613bill a technology savvy workforce? And fourth, does the614proposed budget provide the resources required for this615critical mission set?616 I want to thank this subcommittee for its continuing617leadership and I look forward to your questions.618 [The prepared statement of Mr. Nemeroff follows:]619620 [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]621622 Mr. Self. Thank you, Mr. Nemeroff.623 I now recognize myself for 5 minutes of questioning. A624series of questions, Ms. Fixler. You say Taiwan survived the625attack. What did you mean when you say, survived the attack? Is626that physical or is that cyber? What are you referring to?627 Ms. Fixler. Sure so in the tabletop exercise we did, it was628a series of economic and cyber attacks that were testing the629societal resilience of Taiwan to withstand Chinese aggression630and withstand efforts to coerce its policy to agree to a631reunification with the mainland, so it was a societal and cyber632resilience. And if the CPP judged that Taiwan could survive the633pressure campaign, it might actually----634 Mr. Self. By not go kinetic.635 Ms. Fixler. Yes.636 Mr. Self. Okay. I want to read something to you. Yesterday,637probably everyone in this room was aware of the three-nation638outage in Europe. I got back from Europe a week ago Saturday,639so this is from the Siemens Security Advisory, just to show you640how important this issue is, the point of origin for the641blackout possibly originated--when they say possibly, they are642not definitively saying something, but I believe that they643believe this, possibly originated in a high-voltage substation644in the Basque region of northern Spain specifically near Balboa645at the substation that they named. The potential method of646sabotage was a sophisticated cyber attack targeting the647substation SCADA system, injecting malware that overloaded648transformers and triggered a cascading failure across the649European grid. The malware exploited a known vulnerability in650the Siemens system and they listed that.651 So Ms. Fixler, you, in your testimony you mentioned the652need for partners and allies to be cyber resilient. When I was653in Europe, I talked to both politicals in Europe and to our654U.S. military, and they made the U.S. military from the SAC655(ph) on down said that we need to be aware that their656infrastructure to include cyber needs to support our war plans.657Can you elaborate on what you said about their vulnerable658infrastructure impacts our national security?659 Ms. Fixler. Sure, thank you so much for the question. So we660recently at FDD issued a report looking at military mobility,661specifically the way that U.S. military forces rely on civilian662critical infrastructure to move men and material in the United663States. That is true as well overseas, and we intend to look664more closely at the infrastructure in our NATO allies and how665it must be secure so that our troops have secure transportation666infrastructure, telecommunications infrastructure, because all667of our forces rely not on infrastructure-owned and operated668exclusively by the Defense Department, but by civilian-owned669infrastructure. So that infrastructure must be resilient to670secure our forces overseas.671 Mr. Self. Thank you. Ms. Love-Grayer, in what way has the672CDP worked with other agencies to advance cyber diplomacy? How673does that impact national interest, defense interest? And where674is the coordination point? And who holds the big stick, I will675call it, in this area, cyber diplomacy?676 Ms. Love-Grayer. Thank you for that question. I actually677have several examples. But I want to use one that connects to678what you just mentioned. So the DOD has an operation called679Hunt Forward, where they assist our partner countries by680assessing their vulnerabilities in their cyber systems. CDP681partners with them by going in afterward and actually providing682the technical assistance and capacity building needed to683address the vulnerability that they have identified. And so684again, if we are partners with those countries and we are685working with them closely, we may even have our own troops in686those countries. It is important to not only identify the687vulnerabilities, but to help them to address it.688 In terms of the coordination, there are various ways that689CDP coordinates that we found in our audit. There is informal690regular meetings between the heads of corporations and the691agencies and with private sector corporations. But also, there692is formal interagency agreements. So CDP at the time that we693conducted our audit had 11 different agreements with different694agencies such as DOD, Department of Commerce, the FCC, DHS,695USAID and others. And these interagency agreements allowed them696to partner with these other agencies who have specific697capabilities and skill sets that could be used to provide,698again, technical assistance and capacity building to other699countries.700 Who has the big stick? At the moment, it depends on--I701would say, depending on what you call the big stick. I think702who has the mandate for cyber diplomacy is CDP. Sometimes it is703the other agencies who might have the technical expertise or704even the funding. CDP does provide foreign-assistance funding,705but in other cases they may just partner. So CDP has the706mandate and there are a number of other players who have707different types of capabilities that they bring to the table.708 Mr. Self. Very good. I now recognize Ranking Member Keating709for 5 minutes.710 Mr. Keating. Thank you, Mr. Chairman.711 I think when we use terms like cyber diplomacy and other712terms like that, it really doesn't give us back to the real713threat that we have. It sounds something that wouldn't be like714a direct kinetic attack or something that we had.715 But cyber, unlike other kinds of warfare, or other kinds of716threats, there is no barriers there, there is no wall that can717be built, there is no ocean that stands between these threats.718They are global and they have to be approached globally. And719so, we really rely had on our allies in this area even more in720some respects than we would through conventional kinds of721threats that we deal with. So how important is it to have us722make sure we are working in these areas, making sure we are723funding the cuts to USAID and the other things that could have724an effect on our ability to work with our allies? Because if we725are working America alone will just not work when it comes to726cyber. So how great a threat is that and what should we be727looking for? Mr. Nemeroff.728 Mr. Nemeroff. Thank you. I think it is a long old saying729that cybersecurity is a team sport, both within the interagency730and with our allies and partners. The key thing is to be able731to work with allies and partners at different levels of cyber732capacity and cyber capability. So in NATO, for example, we work733across the board to try to raise the level of cyber hygiene and734cyber capability. And then with particular countries,735particularly those that are foreign-assistance eligible,736foreign assistance is a fantastic lever to be able to help them737help themselves. I think that is the key piece of this. Albania738is a NATO ally. Albania was targeted by Iran by a major cyber739attack that I think really implicated alliance-wide issues, and740having foreign assistance as a way to get them to raise their741capability was an important way of achieving our policy goals742and to make the alliance safer.743 Mr. Keating. I think readiness is a really clear744comparative here too, because timing is so important. Ms.745Fixler, you mentioned how quickly the response has to be, and746that is critical to being able to deal with this. And it has to747be in place ahead of time.748 So another question I have, in our own internal domestic749workforces there to support this, I am concerned with a lot of750these cuts that are going on and the effects on the workforce751and the expertise that could be walking out the door here, how752important is it to have a workforce that is already trained,753experienced, in place? And what would happen through754reorganization or cuts, that that was reduced and we lost that?755How much of a threat would that create?756 Ms. Fixler. I would just say that thank you for the757question. Recruiting and retaining technical talent is a758persistent problem in the Federal Government across the Federal759Government. At least part of it is a pipeline problem. We need760a lot more STEM graduates. We need a lot more folks focused and761pursuing cybersecurity degrees. Not all of them need to be 4-762year degrees, associates degrees are great, on-the-job training763is great, apprenticeships are great. And so I am particularly764heartened by some of the efforts in this Congress to focus on765cyber workforce, including things like the PIVOT Act providing766a faster way for community college graduates to get into the767Federal Government with cyber degrees, because we need a lot of768cyber professionals in our government to focus on cybersecurity769and the intersection between cybersecurity and national770security.771 Ms. Love-Grayer. I will just add a few thoughts to this.772One of the concerns that we had after we conducted our review773on CDP is that they did need to recruit a specific type of774official. They needed someone who had not just technical775capability, but also diplomacy skills. And competing for that,776as we spoke with the former Ambassador of CDP, he noted it is777very hard to compete with the private sector for individuals778who can harness both of those skill sets. And so having the779staff is once you get them on board keeping them and helping780them to grow and understand the issues is important, but also781having staff who can really cover the range. There is a broad782spectrum of issues involved in cyber diplomacy.783 Mr. Keating. Yes, with 30 seconds left too, Mr. Nemeroff784mentioned AI, and this is just going to accentuate and785geometrically affect our ability to respond in any timely786fashion. And one of my concerns is with the reorganization,787there could be siloing of different functions. And the whole788point is to bring it all together and perhaps any kind of789written responses that you might have, since my time is running790out, you could really comment in greater detail on the threat791of that siloing and how--we should be looking at792reorganizations so that there is not greater difficulty in793being able to respond to these really critical threats. I yield794back.795 Mr. Self. I now recognize Mr. Davidson for 5 minutes.796 Mr. Davidson. Thank you, Chairman. Thanks to our witnesses797for your testimony and your preparation for this hearing.798 Ms. Fixler, you argued in a March 17 op-ed that cuts to799USAID harm our cyber assistance to allies and partners. I mean,800by definition, if we don't give them money, we are harming the801assistance, but are they really harmed? And I guess to what802extent do we want to preserve it? I think you make the case803that this could and should be consolidated under CDP. What is804the appropriate amount and kind of cyber assistance that the805United States should be distributing?806 Ms. Fixler. Sure, thank you for the question. So I think807one of the things that CDP has demonstrated it is good at is808using a little bit of U.S. foreign assistance, marrying that809with assistance from U.S. partners and allies and private810sector investment. So I will talk about the undersea cables811area because that I think is where this shines. U.S. technology812companies, communications companies are making major813investments in undersea cables. They are interested in814connecting major population centers because that makes sense815from a market perspective.816 When CDP is able to get involved, it can use a little bit817of foreign assistance, find U.S. partners and allies who are818interested in the issue, and then combine that with the private819sector investment so that we look at it from a strategic820perspective. And we don't just focus on the market, but also on821where it matters for U.S. military capabilities, particularly822in the south--the Indo-Pacific, but that is applicable in other823areas as well.824 Mr. Davidson. Yes, thank you for a very concrete825illustration. And as you talk about blending public sector work826to try to foster some private sector investment, one of the big827things that we are trying to do as a Congress, really as a828country, but we need a law that my other subcommittee might as829chairman of the national security, I went to finance, we are830working on outbound investment. So I wonder, Mr. Nemeroff, as831you think about AI, in particular, one of the most rapidly832changing tech sectors and you think about cyber and other833factors, what kinds of things ought we to consider within834cybersecurity? I think the real tension comes between one835approach that says, we don't want American companies investing836in AI outside of America, or maybe a more concrete example that837uses kind of the financial services' Treasury thing and saying,838Here is specifically who we don't want you investing with. What839are the tradeoffs there and what is your view?840 Mr. Nemeroff. Thank you. So there was a hot AI competition841happening right now among companies and among countries. And we842have to think very strategically about that. Cybersecurity843comes into it in a lot of different places, but critically in844this area in protecting the hard one IP that our companies845produce in developing AI models. And so, I think it is846important to be thoughtful when one is building data centers847anywhere, whether it is here in the United States or elsewhere,848how do we build in the right cybersecurity systems in order to849protect--and protect our assets from others who might try to850steal them for advantage?851 Mr. Davidson. Yes, nation states that might use their852intelligence services to steal American intellectual property.853 Mr. Nemeroff. Absolutely.854 Mr. Davidson. Like China?855 Mr. Nemeroff. Like China.856 Mr. Davidson. All right. So that is exactly what we are857trying to cutoff. And of course they don't say, Hey, we are858with the Chinese intelligence service, they set up companies859and they use it to steal it. That is why we really want to go860with a sanctioned-oriented approach. I think where you go named861individuals and named companies that basically you create a862burn list and which keep it going.863 So we will see where that goes but hopefully, we will get864that done.865 You know, one of the tradeoffs there is always civil866liberties, so we find people that say, You know, we are really867concerned about freedom of speech, Congress, of course, isn't.868According to the First Amendment supposed to make any laws869abridging the freedom of speech. What can our committee do by870working with CDP, because that was the claim that they were871just combating misinformation and disinformation. When CISA was872frankly it seemed pretty Orwellian, I mean a lot of my873constituents had a lot of concerns about an American Big874Government agency saying what an American citizen is saying is875somehow foreign misinformation. How do we get that right?876 Mr. Nemeroff. Fundamentally, the First Amendment kind of877has to be at the bedrock of everything that we do. We do have a878challenge that adversaries seek to use the openness of our879system to exploit and disrupt or cause--to advance their880agenda, that has got to be a part of the consideration. CDP's881focus primarily has been on promoting freedom of expression and882digital freedom abroad, and in particular, safeguarding our883networks and other people's networks from cyber threats.884 Mr. Davidson. I that is the proper focus. I think CISA885definitely got it wrong and frankly some of these agencies that886were created to defend America were weaponized against American887citizens. We want to make sure that we prevent that from888happening. Maybe the best way to do that is to hold some of889those former officials accountable.890 Thanks. My time has expired. I yield back.891 Mr. Self. I now recognize Representative Amo, Mr. Amo?892 Mr. Amo. Thank you, Chairman Self. And thank you to our893witnesses for being here. Look, it is no secret that digital894technologies are quickly evolving, brain--greater connectivity895and new and emerging threats. And these threats are not unique896to the United States. They transcend borders and affect their897allies from across the world. They require close collaboration898and global solutions. And starting under the first Trump899administration there was bipartisan consensus that America900needed a crosscutting bureau, reporting directly to senior901State Department leadership that could coordinate the various902elements of cyberspace, digital technologies and global digital903governance.904 The Bureau of Cyberspace and Digital Policy, and I know we905are all associated with the acronym CDP now was born in 2022.906And its mission, I think, is one to come back to, to907underscore, to ensure an open, secure, and reliable internet, a908necessity to promote democratic values like privacy, freedom of909expression, access through information.910 CDP made our foreign cyber policy more efficient and911streamline our cyber diplomacy. But Secretary Rubio's new912reorganization plan for the State Department breaks CDP. And I913think it is important to highlight these changes. It is914separating its economic functions and moving cybersecurity into915the new emerging threats branch. This plan undermines the core916reason CDP was created, again streamlining international cyber917policy.918 It is not efficient to create overlapping and redundant919mandates. It is not efficient to jeopardize how CDP coordinates920cyber policy with the Department of Defense, Homeland Security921and the intelligence community. And it is not efficient to922jeopardize the essential work that CDP does, alongside the923cybersecurity and infrastructure security agency or CISA,924because we know that CDP manages programs for CISA that925provides training and resources to protect targeted countries926from cyber attacks. And given that CISA already faces drastic927cuts to their programs, thanks to the actions of President928Trump and Elon Musk, ending coordination with CDP could cause929tremendous harm in keeping Americans safe.930 So Ms. Love-Grayer, how does CDP coordinate with CISA to931ensure that we have a comprehensive strategy for cyber932diplomacy? And how would the plan on the table from Secretary933Rubio split up--splits up CDP, affect their collaboration with934agencies like CISA?935 Ms. Love-Grayer. In the past we found that CDP, and in936particular, the Ambassador-at-large who led it, coordinated937very closely with CISA, with the Office of the National Cyber938Director to ensure that our domestic policy and our foreign939policy, our foreign facing policy aligned so that our views,940our perspectives, our policy interests, and our values would be941represented in the foreign policy that we had as we faced and942engaged with our multilateral organizations. So there was a lot943of coordination there.944 At the same time, the views and the interests and the945issues that the Ambassador heard out in the world, he would946bring back to our leaders here on the domestic side to ensure947that we could learn from that as well, that we were using that948to inform our strategies and our own protections at home. So949that collaboration we found to be pretty important.950 In terms of where they sat, it was very important that the951Ambassador did report to the deputy secretary because he had952more direct influence and the ability to get leadership support953on major decisions. That coordination sat above all the other954bureaus, and so there was a higher level of gravitas that was955given to CDP in being able to garner resources and support956across the Department is what we found. So breaking that up957could look different in the future.958 Mr. Amo. And no better time to elevate and make sure that959gravitas of that coordination is central while the threats grow960by the day.961 Before I wrap up here, last week back at home in Rhode962Island, I joined Rhode Island College to recognize their963designation as a National Security Agency center of academic964excellence. And during that time we spent together, we965discussed the need for a well-trained and stable cybersecurity966workforce and a pipeline. And one of the things that I967certainly would welcome your responses in writing as my time968wraps up, we have seen this disdain from a President for public969service and Federal workers and firing employees. And so, I970want to ask a different version of what the ranking member971asked previously just to assess the firing and how it has--of972workers and how it has affected our future ability to attract.973And I know that might require you to speculate a little bit,974but clearly, there is an impact, a lasting impact that in the975termination of employees, you know, for no reason will have on976the cybersecurity workforce. It will make us less safe. And I977welcome your thoughts on that in the future. With that, I yield978back.979 Mr. Self. Thank you. Before I introduce our next speaker,980the ranking member has asked for a comment.981 Mr. Keating. Thank you, Mr. Chairman.982 As you are aware, since our last hearing, we had a983discussion, and you expressed that you intend to continue a984manner of introduction of a member that at a minimum, is not985becoming of this committee. I hope you reconsider. I want to986make clear my objection to the harmful, wrong-minded language987of the chairman's introduction. It is the wrong way to treat988duly elected Members of Congress. It is the wrong way to treat989a colleague. The wrong way to treat any individual. The990chairman knows, I suggested to both maintain dignity and991respect the committee, while continuing our committee's focus992on policy issues, that the chairman simply address members by993their title if he wants, Representative. But the chairman has994said to me that he can't do that because it is just not him.995 Representative McBride, on the other hand, has publicly996indicated this had he wants to focus on committee policy at997hand. Representative McBride has identified who she is, the998chairman has identified who he is. And I think it is something999to reflect on each time her introduction is disrespectfully1000invoked.1001 I yield back.1002 Mr. Self. With that, in order--I find myself in the1003position in order to maintain the parliamentary integrity of1004this hearing with being the lone majority member here, I would1005like to recognize Representative McBride.1006 Ms. McBride. Thank you, Mr. Chairman. I appreciate that,1007thank you. That means a lot. And thank you, Ranking Member1008Keating, for your friendship and your support. Thank you so1009much to our witnesses for joining us today for your1010perseverance through a hearing.1011 Cyber diplomacy has never been more important to American1012national security interests, and it will continue to grow in1013its significance in the years to come. This is why the1014administration's proposal to reorganize the Bureau of1015Cyberspace and Digital Policy deserves serious consideration1016and security. And today, we should be asking ourselves does the1017proposal by the administration make America safer, stronger and1018more prosperous?1019 Unfortunately, in just 100 days, the Trump administration1020has attempted to undertake massive and disruptive changes in1021how our Nation conducts our diplomacy, throwing our entire1022national diplomatic ecosystem into upheaval. While serious and1023thoughtful reforms on how the U.S. can best defend our1024interests abroad should always be welcome, far too many of this1025administration's actions have been rushed, misinformed and1026often downright incoherent.1027 America's diplomatic and soft power is one of our most1028valuable assets. And Congress' role is to ensure our foreign1029policy continues to align with our national interests. I1030promised I would work with anyone who is willing to work with1031me to deliver for Delawareans so I am looking forward to1032learning more about this administration's plans.1033 My first question is for you, Mr. Nemeroff. As emerging1034technologies transform global digital infrastructure, how can1035CDP stay ahead of the curve? And what resources or capabilities1036do you think CDP needs to stay competitive?1037 Mr. Nemeroff. Thank you for the question. I am going to1038come back to the idea of looking at this from a full-stack1039approach. This isn't a matter of us competing with one1040technology, but thinking about how we are working to promote a1041trusted technology ecosystem around the world. Undersea cables,1042older technology like undersea cables and data centers, and1043then 5G networks, that is going to shape a lot of what then1044gets rolled out in terms of AI in different countries as well.1045 We have stiff competition from models like DeepSeek that1046are open source and low cost. And so a key piece, in my view of1047what our strategy needs to be, is thinking about how are we1048building that entire stack to enable our technology to get out1049there. And then how were we using cybersecurity? In our1050remarkable capabilities as a government and a society and our1051private sector to secure all of those pieces so that we can1052trust that our information and our ideas can be used safely and1053without causing harm to our national security.1054 Ms. McBride. Thank you. Ms. Love-Grayer, how does the Trump1055administration shuttering of U.S. foreign assistance writ large1056impact the ability of the CDP bureau to effectively conduct1057outreach to allies and partners? What impact do you think the1058cessation of cyber-related foreign assistance has on CDP's1059ability to carry out its mission?1060 Ms.Love-Grayer. We haven't yet assessed the effects of1061these changes, especially since they are not formalized. But I1062will say we do have a request, a congressional request to look1063at the impact of foreign assistance changes, including to the1064workforce and so we plan to do that soon.1065 Ms. McBride. Thank you very much.1066 I want to reiterate the comments of my colleague,1067Representative Amo and the ranking member made earlier about1068the importance for us to provide a respectful, predictable,1069sustainable career option for public servants across the1070Federal Government. And this is an area that obviously requires1071specific training, specific skills, which makes it that much1072more difficult to recruit for and retain in, especially when1073competing with the private sector. And I think it is important1074as we have these conversations to recognize the importance of1075protecting our Federal workforce and treating them with respect1076as we seek to fill these positions and have the best and1077brightest working in this critical capacity so thank you very1078much.1079 Mr. Chairman, I yield back.1080 Mr. Self. Thank you, I recognize myself for 5 minutes.1081 We are leading on this CDP reauthorization. I have several1082questions, for everyone's information here, we have1083nongovernmental witnesses here because we don't have a lot of1084people confirmed yet. So that is why we have you. And I1085appreciate you all filling in the gaps while we can.1086 So a couple of--first of all, for you, Ms. Fixler, undersea1087cable routing, because we have seen undersea cables being torn1088up in several different theaters of the world. Is this an area1089that we ought to be engaging with our allies? Because--is there1090any way to protect the undersea cables or route them which1091would help national security?1092 Ms. Fixler. Sure. Thank you for the question. Undersea1093cables are a critical issue. And it is both the physical1094resilience and the cyber resilience of that infrastructure. And1095the ownership and operation of that infrastructure.1096 China and Russia have demonstrated they are interested in1097disrupting that infrastructure. And China has also demonstrated1098that it is interested in owning operating that infrastructure1099so that it can route and control the flow of communications.1100And so, it is concerning when our adversaries are trying to1101disrupt the infrastructure, and when they are trying to control1102the infrastructure.1103 Mr. Self. Okay, thank you.1104 I just want to get to the specifics here. We are talking1105about cybersecurity professionals. Give me a range of--first of1106all, what level to we need in the CDP and what would be a range1107of salaries? Who wants to tackle that? Ms. Love-Grayer?1108 Ms. Love-Grayer. Well, I think I will tackle part of this1109question. We are talking about cybersecurity, but also beyond1110cybersecurity, there are a range of cyber issues and technical1111capacities that are needed, and you need diplomacy skills as1112well. One of the things we heard from CDP after our review is1113that they had trained about 250 diplomats on cyber issues. So1114there is internal training you can do, as well as hiring, and I1115think we need to use both capabilities.1116 Mr. Self. So what about salary range? Who wants to tackle1117that? Because we are competing with a growth industry here.1118 Mr. Nemeroff. I can start. The one piece I would emphasize,1119I am a lawyer by training----1120 Mr. Self. I am sorry.1121 Mr. Nemeroff. Yes. And I think what I learned in legal1122cyber practice has also been true in diplomatic cyber practice,1123which is that you take the old skills and you apply it to a new1124technology. And so that is a lot of what CDP does really well,1125it brings in diplomatic whizzes who can learn the technology1126and apply it. And it brings in tech whizzes who can learn the1127diplomacy and do that too.1128 Salary is a problem, we operate on the normal GS-15 scale1129so there is no special cyber pay at the State Department, and I1130do think that is an issue that you have colleagues who can----1131 Mr. Self. No, I am asking, what are we competing against?1132 Mr. Nemeroff. In the private sector?1133 Mr. Self. Right.1134 Mr. Nemeroff. Hundreds of thousands of dollars.1135 Mr. Self. Okay. I do want to get to because several1136mentions have been made of the new org chart. I want to just1137hear briefly--I have less than 2 minutes here. Let's go down1138the line, what do you recommend? I think part of it was in your1139written testimoneys, part of it was in your verbal testimoneys,1140but I want to hear specifically what do you recommend for CDP1141in the reauthorization, quickly.1142 Ms. Fixler. I will jump in. I think Congress had it right1143on a bipartisan basis, you created the cyber bureau and you1144understood the importance of the integration between the1145different components of the cyber mission, the cybersecurity1146mission, the digital economy mission, the emerging threats1147mission. All of those work hand in hand. And so, seeing that1148integration remain I think is a wise decision Congress1149previously made. I look forward to Congress continuing to weigh1150in on that.1151 Mr. Self. But now, it is directly underneath the deputy1152secretary. It is probably not going to stay under the deputy1153secretary.1154 Ms. Fixler. Yes, or maybe. I mean, you are going to1155reauthorize right it. Thank you for the question, though. I1156think the integration of the bureau is where I would focus.1157Whether--the head of the bureau needs to have the authority in1158crosscutting authorities, but whether exactly where you1159position the bureau I think may be less important than the1160integration of the different capabilities within the bureau.1161 Mr. Self. Thank you.1162 Ms. Love-Grayer. Actually I really agree with this point. I1163think integration is really critical even as we interface with1164other governments who are structured differently. However, I do1165think that where it sits plays an important role as well,1166because depending on where it sits it may have to compete with1167others for resources. And it also needs the ability to have the1168leader communicate with the most senior leaders at State in1169order make some pretty important decisions.1170 I would consider where it is placed. It also says something1171about what where the focus is. If it is in the E bureau versus1172the T bureau, it sends a signal about what the focus of the1173bureau will be, or the E family versus the T family.1174 Mr. Self. Out of time. But quickly, Mr. Nemeroff, I very1175much agree with the point about maintaining integration. There1176is no perfect answer, if you are going to try to put it under E1177or T, I think you need to make sure that whoever it is1178reporting to cares about the whole mission and that senior1179leaders at the top of the department the deputy secretary are1180still going to be representing all the equities that deputies1181committee meetings and diplomatic engagement.1182 Mr. Self. Thank you, I recognize our ranking member.1183 Mr. Keating. Ms. Fixer mentioned the tabletop exercise that1184occurred. I am just curious as part of that, since I am also in1185the Armed Services Committee, we are boosting our undersea1186autonomous vehicles, and we have been doing it every year1187because of threats like this.1188 Did you--is any of that considered, I know it is not1189strictly cyber, but we have been talking about the integrity of1190undersea cables?1191 Ms. Fixler. Yes. Thank you for the question. I am happy to1192provide more information about the exercise that we conducted.1193We have an after-action report, I am happy to share that with1194the committee.1195 The exercise looked at a number of different attacks that1196China could conduct. Some of them were cyber-related. Some of1197them were sort of more in the economic realm. And they looked1198also at undersea cables, mostly the disruption and the need to1199be able to quickly repair that infrastructure.1200 Mr. Keating. The other thing is, I remember my time in1201homeland security, how we were trying to deal with cyber1202threats and the importance of dealing with the private sector,1203because many of the countries that are represented, as well as1204our own, that is done on the private side and has an enormous1205impact to our safety and economy.1206 The same is true for the other countries that we are trying1207to make more resilient and make sure we are not affected by1208things that affect them.1209 So when you are looking at that situation and you are1210dealing with a private side, can you explain advantages there1211might be with the fact that we can deal with other countries to1212deal with their own private sector instances in terms of1213getting that kind of cooperation, particularly in revealing a1214cyber attack, you know, just minutes, hours make a difference1215in the ability to contain that. Perhaps anyone might want to1216address that.1217 Mr. Nemeroff. It was particularly breathtaking, I thought,1218to see the scale and speed and agility of the private sector in1219the days after the Russian invasion of Ukraine. They were able1220to move at a speed I wish governments could move at, and so,1221they are a critical partner wherever you are operating.1222 I found that foreign assistance is a part of it, but1223another part of it is maintaining a shared situational1224awareness.1225 The reporting that you referred to that they often issue is1226really an early warning often of incidents that we need to1227respond to quickly, and so they are a critical partner.1228 Mr. Keating. Great. Thank you. I notice we have another1229member who has come for a first line of questioning, so I yield1230back.1231 Mr. Self. I now recognize Mrs. Kim.1232 Mrs. Kim. Thank you, Chairman Self. Thank you. I want to1233thank our witnesses for being here today. You know, let me go1234right into questions like, how can private sectors'1235technological expertise such as that from organizations like1236very fake AI be leveraged to enhance the resilience of ally1237infrastructure against the response of a cyber attack?1238 Mr. Nemeroff. Thank you. I think it is a critical thing1239that every country in government needs to recognize that this1240has to be a public-private partnership, and that governments1241need to rely and use private sector capabilities to secure1242their networks.1243 We have made important strides within the U.S. Government,1244for example, moving to cloud as a place to store our data in1245order to help take cybersecurity out of the hands of individual1246offices and place it higher up.1247 We have also found that when incidents happen, private1248sectors are often the most agile in investigating and1249remediating, and so, it is very important as we talk to our1250allies and partners to make sure that they are thinking about1251this as a team sport as, well working with their own companies,1252or working with capable U.S. cybersecurity providers in order1253to provide these kinds of services and support.1254 Ms. Fixler. I would just add as well, CDP maintains some of1255those relationships, and its incident response capability, the1256foreign assistance funding that you all authorized to focus on1257rapid response and rapid deployment of resources, that is a1258partnership with private sector companies. It is not deploying1259U.S. Government personnel, but it is the relationship with1260private sector cybersecurity incident response professionals.1261 Ms. Love-Grayer. I will add just one note, which is, CDP's1262foreign assistance also sometimes makes it capable--or makes1263the environment possible for private sector companies to come1264in. And we saw that with Costa Rica, because they changed their1265environment based on CDP assistance, Intel felt more secure in1266being able to go in and make a $1.2 billion investment that1267they probably would not have made if Costa Rica had not changed1268many of its cyber norms and policies as a result of its1269interactions and engagement with CDP.1270 Ms. Kim. Thank you. You know, Ms. Fixler, from your1271perspective, how should the CDP bureau foster such partnerships1272to enhance cybersecurity in ally infrastructure, and what1273challenges must be addressed to ensure effective cooperation1274across the borders?1275 Ms. Fixler. Thank you for the question. I will focus1276specifically on the challenge. I think there is a challenge to1277think about things strategically. When it comes to critical1278infrastructure, everything is critical, but, frankly, there are1279things that are more critical, and we need to focus on that1280systemically important infrastructure in our own country and1281abroad to think about what do we most need to protect against.1282So if we can think about that strategically, I think that is a1283challenge, but a real opportunity for us to do better.1284 Mrs. Kim. Ms. Love-Grayer, can you provide which offices1285GAO found to have overlapped with CDP, and how the bureau works1286to ensure clear delineation between responsibilities with other1287offices that have cyber equities?1288 Ms. Love-Grayer. Within State, we found that the Bureau of1289Democracy and Human Rights and Labor, DRL, as well as INL,1290which focuses on international law enforcement, both of those1291bureaus also have equities in cyber diplomacy.1292 DRL, in particular, works on freedom, internet freedom1293issues, and they engage in multilateral foreign--they provide1294foreign assistance.1295 INL works on combating cyber crime. And they also lead a1296lot of the foreign assistance initiatives with other foreign1297governments, as well as multilateral diplomacy efforts.1298 So the coordination between all three of them are1299important. We found that they do have regular meetings and1300conversations, but they were still facing challenges defining1301who should take the lead on certain initiatives given the1302expertise that already exists in these other bureaus.1303 Mrs. Kim. Let's talk about that, so can you talk about the1304steps that CDP can take to mitigate risk of the overlap or1305redundancy that you are talking about in existing cybersecurity1306efforts across the Federal agencies, and how has CDP improved1307collaboration with key partners like DHS, DOJ, DOD and1308Treasury?1309 Ms. Love-Grayer. Within the Department, one of the things1310they--I believe they have started to do and they can continue1311to do is ensure that there is constant communication between1312all of the bureaus and they are well aware of which partners1313they are working with and where the focus ought to be for each1314one of them.1315 There is still some overlap in the missions, and I think1316there could be greater delineation between who is taking the1317lead on certain issues if they are not going to be consolidated1318in any kind of way.1319 In terms of the interagency, currently they have formal1320interagency agreements with several agencies, DHS, DOD, FTC,1321Department of Commerce, those do seem to be working well1322because they outline the parameters of those relationships and1323who is taking the lead.1324 Mrs. Kim. Thank you. Chairman, I yield back.1325 Mr. Self. I thank the witnesses for their testimony, and1326the members for their questions. The members of the1327subcommittee may have some additional questions for you, and we1328would ask you to respond to those in writing.1329 Pursuant to committee rules, all members may have 5 days to1330submit statements, questions and extraneous materials for the1331record subject to the length of limitations. Without objection,1332the committee stands adjourned. Thank you very much.1333 [Whereupon, at 3:27 p.m., the subcommittee was adjourned.]13341335 APPENDIX13361337 ----------13381339 Material Submitted for the Hearing Record13401341 [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]13421343 [all]Witnesses
3 witnesses appeared, with 9 papers on file.
| Name | Position | Papers |
|---|---|---|
| Ms. Latesha Love-Grayer | Director, International Affairs and Trade, U.S. Government Accountability Office | — |
| Ms. Annie Fixler | Director, Center on Cyber and Technology, Foundation for Defense of Democracies | Biography · Testimony · Truth in Testimony |
| Mr. Theodore Nemeroff | Co-Founder and Vice President for Data and Compliance, Verific AI | Truth in Testimony · Biography · Testimony |
- Witness Truth in Testimony — HHRG-119-FA14-TTF-Love-GrayerL-20250429.pdf
- Witness Statement — HHRG-119-FA14-Wstate-Love-GrayerL-20250429.pdf
- Witness Biography — HHRG-119-FA14-Bio-Love-GrayerL-20250429.pdf
Documents
The committee filed 2 documents for the meeting.
| Document | Kind | Format |
|---|---|---|
| Member Attendance | Hearing: Member Roster | |
| Hearing Notice | Support Document |