Search

Search bills, members, committees and pages...

Shaping the Future of Cyber Diplomacy: Review for State Department Reauthorization

HearingHouse Foreign Affairs Subcommittee on EuropeApr 29, 2025 · 2:00 PM

Summary

House Foreign Affairs Subcommittee on Europe held a hearing on Apr 29, 2025 at 2:00 PM in Rayburn House Office Building, Room 2200. 3 witnesses appeared.


Record

The meeting has its video, its transcript, witnesses and documents on the record.

Video

The proceedings, as the committee streamed them.

Transcript

The transcript runs to 1,343 lines and 72,240 characters, as the Government Publishing Office printed it.

house-hearing-60593.txt
1[House Hearing, 119 Congress]2[From the U.S. Government Publishing Office]34  SHAPING THE FUTURE OF CYBER DIPLOMACY: REVIEW FOR STATE DEPARTMENT5                            REAUTHORIZATION67=======================================================================89                                HEARING1011                                 OF THE1213                         SUBCOMMITTEE ON EUROPE1415                               BEFORE THE1617                      COMMITTEE ON FOREIGN AFFAIRS18                     U.S. HOUSE OF REPRESENTATIVES1920                    ONE HUNDRED NINETEENTH CONGRESS2122                             FIRST SESSION2324                               __________2526                             April 29, 20252728                               __________2930                           Serial No. 119-143132                               __________3334        Printed for the use of the Committee on Foreign Affairs3536    [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]3738Available: http://www.foreignaffairs.house.gov, http://docs.house.gov,39                       or http://www.govinfo.gov4041                                   _______4243                 U.S. GOVERNMENT PUBLISHING OFFICE444560-593PDF                   WASHINGTON : 20254647                      COMMITTEE ON FOREIGN AFFAIRS4849                    BRIAN J. MAST, Florida, Chairman50MICHAEL T. McCAUL, Texas             GREGORY W. MEEKS, New York,51CHRISTOPHER H. SMITH, New Jersey         Ranking Member52JOE WILSON, South Carolina           BRAD SHERMAN, California53SCOTT PERRY, Pennsylvania            GERALD E. CONNOLLY, Virginia54DARRELL ISSA, California             WILLIAM R. KEATING, Massachusetts55TIM BURCHETT, Tennessee              AMI BERA, California56MARK E. GREEN, Tennessee             JOAQUIN CASTRO, Texas57ANDY BARR, Kentucky                  DINA TITUS, Nevada58RONNY JACKSON, Texas                 TED LIEU, California59YOUNG KIM, California                SARA JACOBS, California60MARIA ELVIRA SALAZAR, Florida        SHEILA CHERFILUS-McCORMICK,61BILL HUIZENGA, Michigan                  Florida62AUMUA AMATA COLEMAN RADEWAGEN,       GREG STANTON, Arizona63    American Samoa                   JARED MOSKOWITZ, Florida64WARREN DAVIDSON, Ohio                JONATHAN L. JACKSON, Illinois65JAMES R. BAIRD, Indiana              SYDNEY KAMLAGER-DOVE, California66THOMAS H. KEAN, JR, New Jersey       JIM COSTA, California67MICHAEL LAWLER, New York             GABE AMO, Rhode Island68CORY MILLS, Florida                  KWEISI MFUME, Maryland69RICHARD McCORMICK, Georgia           PRAMILA JAYAPAL, Washington70KEITH SELF, Texas                    GEORGE LATIMER, New York71RYAN K. ZINKE, Montana               JOHNNY OLSZEWSKI Jr, Maryland72JAMES C. MOYLAN, Guam                JULIE JOHNSON, Texas73ANNA PAULINA LUNA, Florida           SARAH McBRIDE, Delaware74JEFFERSON SHREVE, Indiana            BRADLEY SCOTT SCHNEIDER, Illinois75SHERI BIGGS, South Carolina          MADELEINE DEAN, Pennsylvania Q0476MICHAEL BAUMGARTNER, Washington77RYAN MACKENZIE, Pennsylvania78              James Langenderfer, Majority Staff Director79                 Sajit Gandhi, Minority Staff Director80                                 ------8182                         SUBCOMMITTEE ON EUROPE8384                      KEITH SELF , Texas, Chairman85 MICHAEL T. McCAUL , Texas           WILLIAM KEATING, Massachusetts,86 JOE WILSON , South Carolina             T3Ranking Member K87 MARK GREEN , Tennessee               DINA TITUS , Nevada88 YOUNG KIM , California               JIM COSTA , California89 WARREN DAVIDSON , Ohio               GABE AMO , Rhode Island90 ANNA                                 JULIE JOHNSON , Texas91AULINA LUNA , Florida                 SARAH McBRIDE , Delaware9293              Michael Koren, Subcommittee Staff Director9495                         C  O  N  T  E  N  T  S9697                              ----------9899                            REPRESENTATIVES100101                                                                   Page102Opening Statement of Subcommittee Chairman Keith Self............     1103Opening Statement of Subcommittee Ranking Member William Keating.     2104105                               WITNESSES106107Statement of Annie Fixler, Director, Center on Cyber and108  Technology, Foundation For Defense of Democracies..............     4109  Prepared Statement.............................................     7110Statement of Latesha Love-Grayer, Director, International Affairs111  and Trade, U.S. Government Accountability Office...............    19112  Prepared Statement.............................................    21113Statement of Theodore Nemeroff, Co-Founder and Vice President for114  Data and Compliance, Verific AI................................    37115  Prepared Statement.............................................    39116117                                APPENDIX118119Hearing Notice...................................................    60120Hearing Minutes..................................................    62121Hearing Attendance...............................................    63122123                        Questions for the Record124125Questions for the Record submitted to Ms. Latesha Love-Grayer126  from Rep. Gabe Amo.............................................    64127128  SHAPING THE FUTURE OF CYBER DIPLOMACY: REVIEW FOR STATE DEPARTMENT129                            REAUTHORIZATION130131                              ----------132133                        Tuesday, April 29, 2025134135                  House of Representatives,136                            Subcommittee on Europe,137                              Committee on Foreign Affairs,138                                                    Washington, DC.139140    The subcommittee met, pursuant to notice, at 2:19 p.m., in141room 2200, Rayburn House Office Building, Hon. Keith Self142(chairman of the subcommittee) presiding.143    Mr. Self. The Subcommittee on Europe will come to order.144The purpose of this hearing is to discuss the subcommittee's145areas of jurisdiction for the State Department authorization,146which includes the Bureau of Cyberspace and Digital Policy.147    I now recognize myself for an opening statement.148149            OPENING STATEMENT OF CHAIRMAN KEITH SELF150151    I want to welcome members and witnesses to the subcommittee152on Europe's second hearing on State Department reauthorization.153Today, the subcommittee will be exploring the role of the State154Department in cyber and technology matters, and how such155policies might align with U.S. national security interests and156foreign policy objectives. In particular, we will be examining157the work of the Bureau of Cyberspace and Digital Policy, or158CDP. Across the globe malicious cyber attacks are conducted by159State and nonState actors against the United States and its160allies, including from the People's Republic of China, from161cyber criminals scamming individuals out of their savings to162large scale state-sponsored attacks from America's adversaries.163U.S. Government entities and citizens are increasingly under164siege. For years, PRC-supported hackers have buried deep into165critical infrastructure, including water transportation166networks and energy systems.167    According to the 2025 annual worldwide threats assessment168of the U.S. IC, intelligence community, the PRC remains the169most active and persistent cyber threat to U.S. Government170private sector and critical structure networks. Beijing's171campaign to preposition access on critical infrastructure for172attacks during crisis or conflict, tracking publicly as volt173typhoon, or it more recently identified compromise of U.S.174telecommunications infrastructure, also referred to as Salt175Typhoon, demonstrates the growing breadth and depth of the176PRC's capability to compromise U.S. infrastructure.177    Russia also poses a significant cyber threat with its178efforts to compromise sensitive targets for intelligence179collection and to preposition access to U.S. critical180infrastructure. In addition to Beijing and Moscow, Tehran has181demonstrated an increasing willingness to carry out aggressive182cyber operations to the security of U.S. networks and data.183    Furthermore, Pyongyang's cyber program presents a highly184capable and maturing threat, including an approach to launder185and cash out cryptocurrency from the United States and other186victims to fund its nefarious activities. As cyber becomes a187growing battlefield for criminal networks and maligned actors,188the State Department must be ready to meet the challenge. The189U.S. is not facing these real and growing threats alone, it190took cooperation with our allies and our partners. The U.S.191will continue to work to combat and align cyber activities from192PRC, Iran, North Korea and Russia.193    Since the recent establishment of CDP, it has played a role194in the U.S. response to a major ransomware campaign in Costa195Rica that disrupted critical services. In particular, CDP,196alongside other Federal partners, work to strengthen Costa197Rica's cyber defenses against attacks from malicious actors198threatening the security of both our countries. It has also199worked to identify strategic opportunities to leverage partner200resources to further U.S. strategic objectives through subsea201cable projects in the Pacific Islands.202    Such efforts ensure that the Pacific Islands rely on203trusted, primarily American businesses for their internet204connectivity while also countering the PRC's influence in the205strategically imported region. On the other hand, the206Department of State agreement on a cybercrime U.N. treaty that207conflicted with CDP policy lead and recommendations begs the208question of the actual authority wielded by CDP. This hearing209should lead us toward conclusions on how to improve CDP210efficiency and effectiveness in this vital area of national211interest and security.212    As we move through this reauthorization process, the213experience and insights from today's witnesses will help inform214this subcommittee on the State Department's cyber diplomacy215role in addressing these increasingly important challenges.216    I look forward to hearing your testimony and217recommendations. The chair now recognizes the ranking member,218the gentleman from Massachusetts, Mr. Keating, for any219statement he may have.220221      OPENING STATEMENT OF RANKING MEMBER WILLIAM KEATING222223    Mr. Keating. Thank you, Mr. Chairman and to our witnesses224for being here today. For years, bipartisan members of this225committee have recognized the necessity for the State226Department to take on the important task of cyber diplomacy. In2272021, the Biden administration announced the creation of the228Bureau of Cyberspace and Digital Policy, CDP, with bipartisan229support and the Department of State Authorization Act of 2022230authorized the CDP Bureau into statute, an important step in231recognizing the need for robust and comprehensive approach to232cyber diplomacy.233    With the CDP bureau established in statute, its work in234conjunction with this committee to lead the State Department's235diplomatic cyberspace and cybersecurity efforts encompassing236both hard security and economic policy. As our adversaries,237Russia, China, Iran and North Korea, each take different238approaches to undermining U.S. actions in cyberspace,239bolstering U.S. cyber capability through a strong CDP bureau is240more important than ever.241    The CDP bureau has worked to advanced U.S. interest in242cyberspace across multiple lines of effort. For example,243following the 2022 ransomware attack in Costa Rica by a244Russian-linked cyber crime group, the CDP bureau provided245swift, decisive, support to Costa Ricans and their authorities246to bolster the country's digital defenses and resiliency. This247emergency support was critical to ensure that a partner in our248own hemisphere was able to effectively respond to an249unprecedented attack. Similarly, the State Department worked to250strengthen Ukraine cyber defenses in the midst of Russia's251full-scale, illegal invasion of the country through the digital252connectivity cybersecurity partnership program, a joint venture253by the Department of USAID.254    These are just a few examples of the CDP bureau's important255work to bolster our allies and partners while promoting256American values and security in cyberspace.257    While I appreciate the opportunity to talk about an258important bureau, which is long maintained by partisan support,259it is unfortunately clear that neither this majority nor the260Trump administration has any interest or intent to engage261constructively on a reauthorization of the State Department.262    Last week, Secretary Rubio unveiled a proposed263reauthorization plan for the State Department without any264meaningful consultation with Congress. Reorganization would265decimate the Department's cyber policy tools by splitting it in266half. CDP's economic structures would be moved under the267economic family of the bureau and CDP's hard security offices268would be placed in a new emerging threats bureau. This move269will create exactly the duplication and the waste this270administration says it seeks to avoid. Even more concerning, it271deprioritizes a crosscutting issue that needs to be tackled272holistically and at the highest levels.273    Our witnesses here today and many experts in the field have274all pointed out the importance of capacity building in275cyberspace and maintaining and recruiting the skills required276for qualified cyber diplomacy workforce.277    Unfortunately, rather than invest in capacity building in278places like Costa Rica and Ukraine, the Trump administration279has slashed the U.S. foreign assistance budget and illegally280eliminated USAID, a chief implementer with capacity-building281programs.282    At the same time, GAO and Ms. Love-Grayer, they found out283that nonpartisan report, that while CDP is currently staffed284and fully operational, it needs to train existing staff and285hire more people to meet its growth plans. Rather than seeking286to recruit and train staff, the Trump administration has287attacked and politicized the Federal workforce, leaving a288legacy of destruction and indeed distrust.289    Finally, rather than listen to the advice of experts,290consult with industry professionals and engage with the State291Department, this committee has effectively served as a rubber292stamp for the administration's destructive actions.293    Ms. Fixler, you concluded in an article on March 17th the294capacity building program, including those implemented by295USAID, are not merely altruistic endeavors, they advance296critical U.S. interest. Ms. Love-Grayer, your nonpartisan 2024297GAO report concluded that the State Department provides foreign298assistance to strengthen partner capacity and to promote cyber299norms to achieve U.S. cyber policy objectives.300    Mr. Nemeroff, your testimony points out that a well-placed301cybersecurity foreign assistance project can make all the302difference in leveling the playing field for our companies and303private investments in countries that still deeply respect U.S.304tech leadership. Yet rather than invite administration witness305here from the CDP bureau to testify on the effectiveness of the306bureau's programming or implement the advice of experts like307our witnesses here today, the chair of the full committee and308many of my major majority colleagues have already309wholeheartedly endorsed the administration's reorganization310plans. This is a troubling abdication of the oversight311responsibilities of this committee, and an elimination of the312Article I authority of this Congress.313    I look forward to the testimony of our witnesses here314today. I would strongly urge my majority colleagues to listen315to what they have to say, work to reauthorize the State316Department in a way that serves the interest of the American317public, and move this important issue to the foreign front.318    I yield the balance of my time.319    Mr. Self. Other members of the committee are reminded that320opening statements may be submitted for the record.321    We are pleased to have a distinguished panel of witnesses322before us today on this important topic. Ms. Annie Fixler,323Director of Center on Cyber and Technology at the Foundation324for Defense of Democracies; Ms. Letesha Love-Grayer, Director325of International Affairs and Trade at the U.S. GAO; and Mr.326Theodore Nemeroff, cofounder and Vice President for Data and327Compliance at Verific AI.328    This committee recognizes the importance of the issues329before us and is grateful to have you here to speak with us330today. Thank you. Your full statements will be made part of the331record. And I will ask each of you to keep your spoken remarks332to 5 minutes in order to allow time for our member questions.333    I now recognize Ms. Fixler for your opening statement.334335                   STATEMENT OF ANNIE FIXLER336337    Ms. Fixler. Thank you, Chairman Self, Ranking Member338Keating, and distinguished members of the committee, on339behalf----340    Mr. Self. Would you check your mic, or get closer to it?341    Ms. Fixler. Sorry.342    Mr. Self. Pull it close to you.343    Ms. Fixler. Better?344    Mr. Self. Try it.345    Ms. Fixler. Thank you, Chairman Self, Ranking Member346Keating, and distinguished members of the committee, on behalf347of the Foundation for Defense of Democracies, thank you for348inviting me to testify today.349    For years, on a bipartisan basis, members of this committee350pushed the State Department to better organize itself to defend351U.S. national security in cyberspace. Two and a half years352after creating the Bureau of Cyberspace and Digital Policy,353this committee must assess its performance, expand its354successes and address its shortcomings. This hearing is355particularly timely, given the Department's proposed356reauthorization which appears to put its cybersecurity efforts357at risk and contradict congressional guidance to integrate358cybersecurity and digital economy efforts.359    In my written testimony, I describe the successes the360bureau has been able to achieve because of this integration. I361would like to take this opportunity to summarize the threat we362face and the role States cyber bureau should play.363    Every day malicious cyber operators sitting in remote364corners of the world attack our critical infrastructure. Across365energy transportation and communication systems, China has366prepositioned destructive capabilities. Beijing is prepared to367use crippling cyber attacks to induce societal panic and368interfere with our ability to project power.369    During the Biden administration, we issued stern warnings370but failed to deter Chinese aggression. Trump administration371officials and Members of Congress have rightfully articulated372that our Nation needs to go on the offense and punish those who373use cyberspace to do us harm. And we need better defense to374deny our adversaries their objectives.375    The cyber bureau plays a critical role in both. Over the376course of its short tenure it has demonstrated it understands377these priorities and can execute the mission.378    Congress tasked the bureau with managing a unique cyber379assistance fund because lawmakers recognized it took far too380long for us to respond to incidents overseas that might cascade381and hit our homeland. Now in as little as 2 days, the bureau382can airdrop expertise into partner countries.383    The Department bolsters allied law enforcement capability384to investigate cyber crime and prosecute the offenders and385convinces those same allies and partners to join us when we386call out bad behavior.387    The first step to getting our allies and partners to impose388costs on China is for them to agree that a cyber attack has389occurred and that Beijing is to blame. The bureau helps allies390and partners proactively build cyber resilience. On this, our391strategic priorities are clear: We need the countries that we392fight with and through to have resilient infrastructure.393Resilience buys America time to deploy a range of policy394responses. Had Ukraine succumbed to Russian cyber attacks,395Washington could not have provided the lethal aid that has396helped Kyiv substantially degrade the military capabilities of397a leading U.S. adversary.398    Last summer, FDD led a tabletop exercise in Taiwan,399exploring Chinese cyber enabled economic warfare against the400island. In the game, the thing that gave Beijing the greatest401pause was not U.S. countermeasures, but an assessment that402Taiwan could withstand the attack. If China believed that403Taiwan could survive, it would refrain from attacking in the404first place, lest Taiwan's strengths reveal the CCP's limits.405Resilience has a deterrent power all its own. But building the406resilience of allies and partners will be a Sisyphean task if407the telecommunications infrastructure underpinning all of it is408built by China.409    The U.S. military does not have operational security if410Beijing is listening on the line. In the CHIPS Act, Congress411tasked and funded efforts at State to secure information412communications technology. The cyber bureau is wisely using its413portion on undersea cables in the Indo-Pacific.414    When Congress created the bureau, lawmakers rightfully415articulated that its head must be a principal cybersecurity416policy official in the Department. It also needs permanent417staff billets so that the funding Congress appropriate is spent418wisely and efficiently. There is a battle underway in419cyberspace. Without a robust cyber bureau, we will not win.420    Thank you for inviting me to testify today. I look forward421to your questions.422    [The prepared statement of Ms. Fixler follows:]423424    [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]425426    Mr. Self. Thank you, Ms. Fixler.427    I now recognize Ms. Love-Grayer for your opening statement.428Welcome.429430                STATEMENT OF LATESHA LOVE-GRAYER431432    Ms. Love-Grayer. Chairman Self, Ranking Member Keating, and433members of the subcommittee, thank you for the opportunity to434discuss our work on the Bureau of Cyberspace and Digital Policy435known as CDP. As international trade communication and critical436infrastructure grow more dependent on cyberspace and digital437technology, there is an opportunity to advance U.S. interests438in this digital ecosystem. But also an increase in foreign439cyber threats. Foreign governments and nonState actors are440increasingly using cyberspace as a platform to target critical441infrastructure and our citizens, undermine democracies and442international institutions and uncut global competition by443stealing ideas when they cannot create them. These are among444the reasons that GAO has identified information security as a445high-risk issue.446    In April 2022, State established CDP to lead U.S.447Government international efforts to advance our interest in448cyberspace, which State defines as cyber diplomacy. Its449overarching objectives included building coalitions,450strengthening capacity and reinforcing alarms in cyberspace.451    State uses two main tools to implement the cyber diplomacy452mission, diplomatic engagement and leadership and multilateral453and bilateral fora and foreign assistance that provide training454and technical assistance to our international partners.455    Examples of the diplomatic efforts include engaging with456the European Union to develop shared principles in the 6G457wireless network. And supporting the negotiation process of the458U.N. cybercrime convention, which appropriately, if459appropriately ratified, would facilitate international460cooperation to combat cyber crime.461    As Congress considers State's reauthorization, my statement462today is intended to help inform the discussion about the cyber463diplomacy efforts and was based primarily on the reports that464we have issued between September 2020 and January 2024 related465to those efforts.466    State's cyber diplomacy efforts have evolved between 2011467and the present. Between 2011 and 2018, State established the468Office of the Coordinator of Cyber Issues to lead global469diplomatic engagement and developed an international cyberspace470policy strategy document among other efforts. In January 2019,471Members of Congress introduced the Cyber Diplomacy Act of 2019,472which would have established a new office to lead State's473international cyberspace efforts and consolidate a range of474crosscutting cyber issues.475    Later that year, State notified Congress of its intent to476establish a bureau that was more narrowly focused on477cybersecurity. In September 2020 and January 2021, we assessed478these efforts to establish the cyber bureau. We found that it479had not involved other Federal agencies that contributed to480international cyber diplomacy and the development of its plan481and recommended that it do so.482    We also found that State had not demonstrated that it had483used data and evidence to develop its proposal for establishing484the bureau, and therefore, lacked assurance that its proposal485would effectively set priorities and allocate resources to486achieve those goals. We recommended that it do so.487    In response, State consulted other key Federal agencies and488its plaining and collected data and evidence to inform its489approach, which resulted in changes to the final plan for the490bureau.491    Once the bureau was established, we examined how it was492structured to accomplish its goals. CDP contains four units,493including the office of the coordinator for digital freedom,494international information and communications policy,495international cyberspace security, and a strategies program in496communications unit. The new consolidated bureau and the497appointment of a Senate-confirmed Ambassador at large to lead498it elevated cyber issues in State's diplomatic engagement, that499Ambassador engaged with various other country senior leaders on500advancing cyber goals.501    As an example, in August 2023 the Ambassador headed the502U.S. delegation to the G-20 digital economy ministerial meeting503he highlighted U.S. views and priorities on digital economy504topics.505    In addition, we reported that CDP status as a bureau506provided senior-level support, resources, and involvement, that507did not exist before. Although State's efforts to promote cyber508diplomacy have evolved, challenges remained. Among them clearly509defining CDP's roles and responsibilities across overlapping510issuers with other inter, intra and inter agencies that conduct511work in cyber diplomacy, especially given the breadth of cyber512issues, as well as ensuring that the bureau has sufficient513expertise to carry out its goals.514    These are among the challenges that the bureau will still515need to effectively navigate to lead cyber diplomacy in the516future, especially a State considers streamlining its functions517and addressing any new priorities of the administration.518    Chairman Self, Ranking Member Keating and members of the519subcommittee, this concludes my oral statement. I would be520happy to take questions at this time.521    [The prepared statement of Ms. Love-Grayer follows:]522523    [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]524525    Mr. Self. Thank you, Ms. Love-Grayer.526    I now recognize Mr. Nemeroff for his opening statement,527welcome.528529                 STATEMENT OF THEODORE NEMEROFF530531    Mr. Nemeroff. Chairman Self, Ranking Member Keating,532distinguished members of the subcommittee, thank you for the533opportunity to testify today. My remarks are drawn from my534written testimony and offered in my personal capacity.535    This subcommittee is reviewing the Cyber Diplomacy Act at a536critical time. American leadership and key technologies,537especially AI, positions us to shape the global technological538ecosystem in ways that align with our values and benefit U.S.539national and economic security. But our vision is contested, as540my colleagues here has really effectively outlined. China poses541the greatest and most comprehensive challenge to U.S.542leadership, leveraging both economic and security tools to543advance its goals. Russia, Iran and North Korea also pose544significant threats and ransomware actors operating with545impunity from Russian territory routinely disrupt our546businesses, our hospitals and our schools.547    Through the Cyber Diplomacy Act. This committee has helped548ensure the State Department is better prepared to meet these549challenges. A key strength of Congress' vision was to integrate550national security, economic and human rights equities in CDP.551This has increased efficiency and reduced redundancy within the552Department, and unlocked opportunities to face the challenge553posed by China in particular in more comprehensive and554strategic ways. But we can always do better. I recommend going555forward focusing on four areas: First, CDP should take further556steps to organize itself around a full-stack approach to cyber557and digital diplomacy. Whether our adversaries gain access to558critical systems through hacking or by selling untrusted559undersea cables data centers or 5G, it all harms our national560security, and the Department needs to think about this all561together.562    A full stack approach enables us to see the full picture563and leverage engagements at one layer to have influence at564others. For example, the way that our cyber support to Costa565Rica, which has been cited several times already, has, since5662022, opened the door to deeper cooperation with the country on567telecom issues.568    Second, CDP should continue to lead efforts to deter569adversaries that behave irresponsibly. Cyber deterrence is not570like nuclear deterrence. It requires a dynamic and constant571effort, warning adversaries about activities we won't accept572and then swiftly, preferably with allies, responding to573activities that cross our lines by imposing meaningful574consequences.575    This effort started in the first Trump administration with576coordinated international responses to incidents like Russia's5772017 NotPetya cyber attack, and it continued in the Biden578administration with actions like our response to Iran's brazen5792022 cyber attack against Albania, attempting to coerce a NATO580ally.581    Third, CDP should continue to take on a more operational582role, especially in incident response, and by using diplomatic583channels to support whole-of-government adversary disruption584campaigns. These activities show clear gaps in interagency585capabilities that I saw when I was at NSC working on issues586around Ukraine and others.587    I want to particularly highlight the potential for CDP's588recently piloted falcon capability which allows State to589rapidly deploy private sector incident responders to countries590in need.591    Finally, I want to emphasize the importance of foreign592assistance and development finance. We are in a global tech593competition with China. We need every tool possible to level594the playing field for our companies against China's subsidies595and hardball tactics. And a well-placed cyber assistance596project, or a well-timed loan can make all the difference. CDP597needs funding to provide specialized foreign assistance where598it is most needed, and it should be empowered to build a599coordinated, full-stack investment strategy across the600interagency, including with institutions like development601finance corporation.602    This subcommittee has been--we will be reauthorized in the603Cyber Diplomacy Act, alongside the administration's recently604announced plans to reorganize the Department.605    I offer four key questions to consider as you decide on the606way ahead: First, does the proposed restructuring enable the607type of integrated approach I have discussed today? Second,608does it maintain the requisite attention authority and609responsibility of the Department's most senior leaders, the610ones who can make this a priority in States regionally oriented611work?612    Third, does it sustain and ideally accelerate efforts to613bill a technology savvy workforce? And fourth, does the614proposed budget provide the resources required for this615critical mission set?616    I want to thank this subcommittee for its continuing617leadership and I look forward to your questions.618    [The prepared statement of Mr. Nemeroff follows:]619620    [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]621622    Mr. Self. Thank you, Mr. Nemeroff.623    I now recognize myself for 5 minutes of questioning. A624series of questions, Ms. Fixler. You say Taiwan survived the625attack. What did you mean when you say, survived the attack? Is626that physical or is that cyber? What are you referring to?627    Ms. Fixler. Sure so in the tabletop exercise we did, it was628a series of economic and cyber attacks that were testing the629societal resilience of Taiwan to withstand Chinese aggression630and withstand efforts to coerce its policy to agree to a631reunification with the mainland, so it was a societal and cyber632resilience. And if the CPP judged that Taiwan could survive the633pressure campaign, it might actually----634    Mr. Self. By not go kinetic.635    Ms. Fixler. Yes.636    Mr. Self. Okay. I want to read something to you. Yesterday,637probably everyone in this room was aware of the three-nation638outage in Europe. I got back from Europe a week ago Saturday,639so this is from the Siemens Security Advisory, just to show you640how important this issue is, the point of origin for the641blackout possibly originated--when they say possibly, they are642not definitively saying something, but I believe that they643believe this, possibly originated in a high-voltage substation644in the Basque region of northern Spain specifically near Balboa645at the substation that they named. The potential method of646sabotage was a sophisticated cyber attack targeting the647substation SCADA system, injecting malware that overloaded648transformers and triggered a cascading failure across the649European grid. The malware exploited a known vulnerability in650the Siemens system and they listed that.651    So Ms. Fixler, you, in your testimony you mentioned the652need for partners and allies to be cyber resilient. When I was653in Europe, I talked to both politicals in Europe and to our654U.S. military, and they made the U.S. military from the SAC655(ph) on down said that we need to be aware that their656infrastructure to include cyber needs to support our war plans.657Can you elaborate on what you said about their vulnerable658infrastructure impacts our national security?659    Ms. Fixler. Sure, thank you so much for the question. So we660recently at FDD issued a report looking at military mobility,661specifically the way that U.S. military forces rely on civilian662critical infrastructure to move men and material in the United663States. That is true as well overseas, and we intend to look664more closely at the infrastructure in our NATO allies and how665it must be secure so that our troops have secure transportation666infrastructure, telecommunications infrastructure, because all667of our forces rely not on infrastructure-owned and operated668exclusively by the Defense Department, but by civilian-owned669infrastructure. So that infrastructure must be resilient to670secure our forces overseas.671    Mr. Self. Thank you. Ms. Love-Grayer, in what way has the672CDP worked with other agencies to advance cyber diplomacy? How673does that impact national interest, defense interest? And where674is the coordination point? And who holds the big stick, I will675call it, in this area, cyber diplomacy?676    Ms. Love-Grayer. Thank you for that question. I actually677have several examples. But I want to use one that connects to678what you just mentioned. So the DOD has an operation called679Hunt Forward, where they assist our partner countries by680assessing their vulnerabilities in their cyber systems. CDP681partners with them by going in afterward and actually providing682the technical assistance and capacity building needed to683address the vulnerability that they have identified. And so684again, if we are partners with those countries and we are685working with them closely, we may even have our own troops in686those countries. It is important to not only identify the687vulnerabilities, but to help them to address it.688    In terms of the coordination, there are various ways that689CDP coordinates that we found in our audit. There is informal690regular meetings between the heads of corporations and the691agencies and with private sector corporations. But also, there692is formal interagency agreements. So CDP at the time that we693conducted our audit had 11 different agreements with different694agencies such as DOD, Department of Commerce, the FCC, DHS,695USAID and others. And these interagency agreements allowed them696to partner with these other agencies who have specific697capabilities and skill sets that could be used to provide,698again, technical assistance and capacity building to other699countries.700    Who has the big stick? At the moment, it depends on--I701would say, depending on what you call the big stick. I think702who has the mandate for cyber diplomacy is CDP. Sometimes it is703the other agencies who might have the technical expertise or704even the funding. CDP does provide foreign-assistance funding,705but in other cases they may just partner. So CDP has the706mandate and there are a number of other players who have707different types of capabilities that they bring to the table.708    Mr. Self. Very good. I now recognize Ranking Member Keating709for 5 minutes.710    Mr. Keating. Thank you, Mr. Chairman.711    I think when we use terms like cyber diplomacy and other712terms like that, it really doesn't give us back to the real713threat that we have. It sounds something that wouldn't be like714a direct kinetic attack or something that we had.715    But cyber, unlike other kinds of warfare, or other kinds of716threats, there is no barriers there, there is no wall that can717be built, there is no ocean that stands between these threats.718They are global and they have to be approached globally. And719so, we really rely had on our allies in this area even more in720some respects than we would through conventional kinds of721threats that we deal with. So how important is it to have us722make sure we are working in these areas, making sure we are723funding the cuts to USAID and the other things that could have724an effect on our ability to work with our allies? Because if we725are working America alone will just not work when it comes to726cyber. So how great a threat is that and what should we be727looking for? Mr. Nemeroff.728    Mr. Nemeroff. Thank you. I think it is a long old saying729that cybersecurity is a team sport, both within the interagency730and with our allies and partners. The key thing is to be able731to work with allies and partners at different levels of cyber732capacity and cyber capability. So in NATO, for example, we work733across the board to try to raise the level of cyber hygiene and734cyber capability. And then with particular countries,735particularly those that are foreign-assistance eligible,736foreign assistance is a fantastic lever to be able to help them737help themselves. I think that is the key piece of this. Albania738is a NATO ally. Albania was targeted by Iran by a major cyber739attack that I think really implicated alliance-wide issues, and740having foreign assistance as a way to get them to raise their741capability was an important way of achieving our policy goals742and to make the alliance safer.743    Mr. Keating. I think readiness is a really clear744comparative here too, because timing is so important. Ms.745Fixler, you mentioned how quickly the response has to be, and746that is critical to being able to deal with this. And it has to747be in place ahead of time.748    So another question I have, in our own internal domestic749workforces there to support this, I am concerned with a lot of750these cuts that are going on and the effects on the workforce751and the expertise that could be walking out the door here, how752important is it to have a workforce that is already trained,753experienced, in place? And what would happen through754reorganization or cuts, that that was reduced and we lost that?755How much of a threat would that create?756    Ms. Fixler. I would just say that thank you for the757question. Recruiting and retaining technical talent is a758persistent problem in the Federal Government across the Federal759Government. At least part of it is a pipeline problem. We need760a lot more STEM graduates. We need a lot more folks focused and761pursuing cybersecurity degrees. Not all of them need to be 4-762year degrees, associates degrees are great, on-the-job training763is great, apprenticeships are great. And so I am particularly764heartened by some of the efforts in this Congress to focus on765cyber workforce, including things like the PIVOT Act providing766a faster way for community college graduates to get into the767Federal Government with cyber degrees, because we need a lot of768cyber professionals in our government to focus on cybersecurity769and the intersection between cybersecurity and national770security.771    Ms. Love-Grayer. I will just add a few thoughts to this.772One of the concerns that we had after we conducted our review773on CDP is that they did need to recruit a specific type of774official. They needed someone who had not just technical775capability, but also diplomacy skills. And competing for that,776as we spoke with the former Ambassador of CDP, he noted it is777very hard to compete with the private sector for individuals778who can harness both of those skill sets. And so having the779staff is once you get them on board keeping them and helping780them to grow and understand the issues is important, but also781having staff who can really cover the range. There is a broad782spectrum of issues involved in cyber diplomacy.783    Mr. Keating. Yes, with 30 seconds left too, Mr. Nemeroff784mentioned AI, and this is just going to accentuate and785geometrically affect our ability to respond in any timely786fashion. And one of my concerns is with the reorganization,787there could be siloing of different functions. And the whole788point is to bring it all together and perhaps any kind of789written responses that you might have, since my time is running790out, you could really comment in greater detail on the threat791of that siloing and how--we should be looking at792reorganizations so that there is not greater difficulty in793being able to respond to these really critical threats. I yield794back.795    Mr. Self. I now recognize Mr. Davidson for 5 minutes.796    Mr. Davidson. Thank you, Chairman. Thanks to our witnesses797for your testimony and your preparation for this hearing.798    Ms. Fixler, you argued in a March 17 op-ed that cuts to799USAID harm our cyber assistance to allies and partners. I mean,800by definition, if we don't give them money, we are harming the801assistance, but are they really harmed? And I guess to what802extent do we want to preserve it? I think you make the case803that this could and should be consolidated under CDP. What is804the appropriate amount and kind of cyber assistance that the805United States should be distributing?806    Ms. Fixler. Sure, thank you for the question. So I think807one of the things that CDP has demonstrated it is good at is808using a little bit of U.S. foreign assistance, marrying that809with assistance from U.S. partners and allies and private810sector investment. So I will talk about the undersea cables811area because that I think is where this shines. U.S. technology812companies, communications companies are making major813investments in undersea cables. They are interested in814connecting major population centers because that makes sense815from a market perspective.816    When CDP is able to get involved, it can use a little bit817of foreign assistance, find U.S. partners and allies who are818interested in the issue, and then combine that with the private819sector investment so that we look at it from a strategic820perspective. And we don't just focus on the market, but also on821where it matters for U.S. military capabilities, particularly822in the south--the Indo-Pacific, but that is applicable in other823areas as well.824    Mr. Davidson. Yes, thank you for a very concrete825illustration. And as you talk about blending public sector work826to try to foster some private sector investment, one of the big827things that we are trying to do as a Congress, really as a828country, but we need a law that my other subcommittee might as829chairman of the national security, I went to finance, we are830working on outbound investment. So I wonder, Mr. Nemeroff, as831you think about AI, in particular, one of the most rapidly832changing tech sectors and you think about cyber and other833factors, what kinds of things ought we to consider within834cybersecurity? I think the real tension comes between one835approach that says, we don't want American companies investing836in AI outside of America, or maybe a more concrete example that837uses kind of the financial services' Treasury thing and saying,838Here is specifically who we don't want you investing with. What839are the tradeoffs there and what is your view?840    Mr. Nemeroff. Thank you. So there was a hot AI competition841happening right now among companies and among countries. And we842have to think very strategically about that. Cybersecurity843comes into it in a lot of different places, but critically in844this area in protecting the hard one IP that our companies845produce in developing AI models. And so, I think it is846important to be thoughtful when one is building data centers847anywhere, whether it is here in the United States or elsewhere,848how do we build in the right cybersecurity systems in order to849protect--and protect our assets from others who might try to850steal them for advantage?851    Mr. Davidson. Yes, nation states that might use their852intelligence services to steal American intellectual property.853    Mr. Nemeroff. Absolutely.854    Mr. Davidson. Like China?855    Mr. Nemeroff. Like China.856    Mr. Davidson. All right. So that is exactly what we are857trying to cutoff. And of course they don't say, Hey, we are858with the Chinese intelligence service, they set up companies859and they use it to steal it. That is why we really want to go860with a sanctioned-oriented approach. I think where you go named861individuals and named companies that basically you create a862burn list and which keep it going.863    So we will see where that goes but hopefully, we will get864that done.865    You know, one of the tradeoffs there is always civil866liberties, so we find people that say, You know, we are really867concerned about freedom of speech, Congress, of course, isn't.868According to the First Amendment supposed to make any laws869abridging the freedom of speech. What can our committee do by870working with CDP, because that was the claim that they were871just combating misinformation and disinformation. When CISA was872frankly it seemed pretty Orwellian, I mean a lot of my873constituents had a lot of concerns about an American Big874Government agency saying what an American citizen is saying is875somehow foreign misinformation. How do we get that right?876    Mr. Nemeroff. Fundamentally, the First Amendment kind of877has to be at the bedrock of everything that we do. We do have a878challenge that adversaries seek to use the openness of our879system to exploit and disrupt or cause--to advance their880agenda, that has got to be a part of the consideration. CDP's881focus primarily has been on promoting freedom of expression and882digital freedom abroad, and in particular, safeguarding our883networks and other people's networks from cyber threats.884    Mr. Davidson. I that is the proper focus. I think CISA885definitely got it wrong and frankly some of these agencies that886were created to defend America were weaponized against American887citizens. We want to make sure that we prevent that from888happening. Maybe the best way to do that is to hold some of889those former officials accountable.890    Thanks. My time has expired. I yield back.891    Mr. Self. I now recognize Representative Amo, Mr. Amo?892    Mr. Amo. Thank you, Chairman Self. And thank you to our893witnesses for being here. Look, it is no secret that digital894technologies are quickly evolving, brain--greater connectivity895and new and emerging threats. And these threats are not unique896to the United States. They transcend borders and affect their897allies from across the world. They require close collaboration898and global solutions. And starting under the first Trump899administration there was bipartisan consensus that America900needed a crosscutting bureau, reporting directly to senior901State Department leadership that could coordinate the various902elements of cyberspace, digital technologies and global digital903governance.904    The Bureau of Cyberspace and Digital Policy, and I know we905are all associated with the acronym CDP now was born in 2022.906And its mission, I think, is one to come back to, to907underscore, to ensure an open, secure, and reliable internet, a908necessity to promote democratic values like privacy, freedom of909expression, access through information.910    CDP made our foreign cyber policy more efficient and911streamline our cyber diplomacy. But Secretary Rubio's new912reorganization plan for the State Department breaks CDP. And I913think it is important to highlight these changes. It is914separating its economic functions and moving cybersecurity into915the new emerging threats branch. This plan undermines the core916reason CDP was created, again streamlining international cyber917policy.918    It is not efficient to create overlapping and redundant919mandates. It is not efficient to jeopardize how CDP coordinates920cyber policy with the Department of Defense, Homeland Security921and the intelligence community. And it is not efficient to922jeopardize the essential work that CDP does, alongside the923cybersecurity and infrastructure security agency or CISA,924because we know that CDP manages programs for CISA that925provides training and resources to protect targeted countries926from cyber attacks. And given that CISA already faces drastic927cuts to their programs, thanks to the actions of President928Trump and Elon Musk, ending coordination with CDP could cause929tremendous harm in keeping Americans safe.930    So Ms. Love-Grayer, how does CDP coordinate with CISA to931ensure that we have a comprehensive strategy for cyber932diplomacy? And how would the plan on the table from Secretary933Rubio split up--splits up CDP, affect their collaboration with934agencies like CISA?935    Ms. Love-Grayer. In the past we found that CDP, and in936particular, the Ambassador-at-large who led it, coordinated937very closely with CISA, with the Office of the National Cyber938Director to ensure that our domestic policy and our foreign939policy, our foreign facing policy aligned so that our views,940our perspectives, our policy interests, and our values would be941represented in the foreign policy that we had as we faced and942engaged with our multilateral organizations. So there was a lot943of coordination there.944    At the same time, the views and the interests and the945issues that the Ambassador heard out in the world, he would946bring back to our leaders here on the domestic side to ensure947that we could learn from that as well, that we were using that948to inform our strategies and our own protections at home. So949that collaboration we found to be pretty important.950    In terms of where they sat, it was very important that the951Ambassador did report to the deputy secretary because he had952more direct influence and the ability to get leadership support953on major decisions. That coordination sat above all the other954bureaus, and so there was a higher level of gravitas that was955given to CDP in being able to garner resources and support956across the Department is what we found. So breaking that up957could look different in the future.958    Mr. Amo. And no better time to elevate and make sure that959gravitas of that coordination is central while the threats grow960by the day.961    Before I wrap up here, last week back at home in Rhode962Island, I joined Rhode Island College to recognize their963designation as a National Security Agency center of academic964excellence. And during that time we spent together, we965discussed the need for a well-trained and stable cybersecurity966workforce and a pipeline. And one of the things that I967certainly would welcome your responses in writing as my time968wraps up, we have seen this disdain from a President for public969service and Federal workers and firing employees. And so, I970want to ask a different version of what the ranking member971asked previously just to assess the firing and how it has--of972workers and how it has affected our future ability to attract.973And I know that might require you to speculate a little bit,974but clearly, there is an impact, a lasting impact that in the975termination of employees, you know, for no reason will have on976the cybersecurity workforce. It will make us less safe. And I977welcome your thoughts on that in the future. With that, I yield978back.979    Mr. Self. Thank you. Before I introduce our next speaker,980the ranking member has asked for a comment.981    Mr. Keating. Thank you, Mr. Chairman.982    As you are aware, since our last hearing, we had a983discussion, and you expressed that you intend to continue a984manner of introduction of a member that at a minimum, is not985becoming of this committee. I hope you reconsider. I want to986make clear my objection to the harmful, wrong-minded language987of the chairman's introduction. It is the wrong way to treat988duly elected Members of Congress. It is the wrong way to treat989a colleague. The wrong way to treat any individual. The990chairman knows, I suggested to both maintain dignity and991respect the committee, while continuing our committee's focus992on policy issues, that the chairman simply address members by993their title if he wants, Representative. But the chairman has994said to me that he can't do that because it is just not him.995    Representative McBride, on the other hand, has publicly996indicated this had he wants to focus on committee policy at997hand. Representative McBride has identified who she is, the998chairman has identified who he is. And I think it is something999to reflect on each time her introduction is disrespectfully1000invoked.1001    I yield back.1002    Mr. Self. With that, in order--I find myself in the1003position in order to maintain the parliamentary integrity of1004this hearing with being the lone majority member here, I would1005like to recognize Representative McBride.1006    Ms. McBride. Thank you, Mr. Chairman. I appreciate that,1007thank you. That means a lot. And thank you, Ranking Member1008Keating, for your friendship and your support. Thank you so1009much to our witnesses for joining us today for your1010perseverance through a hearing.1011    Cyber diplomacy has never been more important to American1012national security interests, and it will continue to grow in1013its significance in the years to come. This is why the1014administration's proposal to reorganize the Bureau of1015Cyberspace and Digital Policy deserves serious consideration1016and security. And today, we should be asking ourselves does the1017proposal by the administration make America safer, stronger and1018more prosperous?1019    Unfortunately, in just 100 days, the Trump administration1020has attempted to undertake massive and disruptive changes in1021how our Nation conducts our diplomacy, throwing our entire1022national diplomatic ecosystem into upheaval. While serious and1023thoughtful reforms on how the U.S. can best defend our1024interests abroad should always be welcome, far too many of this1025administration's actions have been rushed, misinformed and1026often downright incoherent.1027    America's diplomatic and soft power is one of our most1028valuable assets. And Congress' role is to ensure our foreign1029policy continues to align with our national interests. I1030promised I would work with anyone who is willing to work with1031me to deliver for Delawareans so I am looking forward to1032learning more about this administration's plans.1033    My first question is for you, Mr. Nemeroff. As emerging1034technologies transform global digital infrastructure, how can1035CDP stay ahead of the curve? And what resources or capabilities1036do you think CDP needs to stay competitive?1037    Mr. Nemeroff. Thank you for the question. I am going to1038come back to the idea of looking at this from a full-stack1039approach. This isn't a matter of us competing with one1040technology, but thinking about how we are working to promote a1041trusted technology ecosystem around the world. Undersea cables,1042older technology like undersea cables and data centers, and1043then 5G networks, that is going to shape a lot of what then1044gets rolled out in terms of AI in different countries as well.1045    We have stiff competition from models like DeepSeek that1046are open source and low cost. And so a key piece, in my view of1047what our strategy needs to be, is thinking about how are we1048building that entire stack to enable our technology to get out1049there. And then how were we using cybersecurity? In our1050remarkable capabilities as a government and a society and our1051private sector to secure all of those pieces so that we can1052trust that our information and our ideas can be used safely and1053without causing harm to our national security.1054    Ms. McBride. Thank you. Ms. Love-Grayer, how does the Trump1055administration shuttering of U.S. foreign assistance writ large1056impact the ability of the CDP bureau to effectively conduct1057outreach to allies and partners? What impact do you think the1058cessation of cyber-related foreign assistance has on CDP's1059ability to carry out its mission?1060    Ms.Love-Grayer. We haven't yet assessed the effects of1061these changes, especially since they are not formalized. But I1062will say we do have a request, a congressional request to look1063at the impact of foreign assistance changes, including to the1064workforce and so we plan to do that soon.1065    Ms. McBride. Thank you very much.1066    I want to reiterate the comments of my colleague,1067Representative Amo and the ranking member made earlier about1068the importance for us to provide a respectful, predictable,1069sustainable career option for public servants across the1070Federal Government. And this is an area that obviously requires1071specific training, specific skills, which makes it that much1072more difficult to recruit for and retain in, especially when1073competing with the private sector. And I think it is important1074as we have these conversations to recognize the importance of1075protecting our Federal workforce and treating them with respect1076as we seek to fill these positions and have the best and1077brightest working in this critical capacity so thank you very1078much.1079    Mr. Chairman, I yield back.1080    Mr. Self. Thank you, I recognize myself for 5 minutes.1081    We are leading on this CDP reauthorization. I have several1082questions, for everyone's information here, we have1083nongovernmental witnesses here because we don't have a lot of1084people confirmed yet. So that is why we have you. And I1085appreciate you all filling in the gaps while we can.1086    So a couple of--first of all, for you, Ms. Fixler, undersea1087cable routing, because we have seen undersea cables being torn1088up in several different theaters of the world. Is this an area1089that we ought to be engaging with our allies? Because--is there1090any way to protect the undersea cables or route them which1091would help national security?1092    Ms. Fixler. Sure. Thank you for the question. Undersea1093cables are a critical issue. And it is both the physical1094resilience and the cyber resilience of that infrastructure. And1095the ownership and operation of that infrastructure.1096    China and Russia have demonstrated they are interested in1097disrupting that infrastructure. And China has also demonstrated1098that it is interested in owning operating that infrastructure1099so that it can route and control the flow of communications.1100And so, it is concerning when our adversaries are trying to1101disrupt the infrastructure, and when they are trying to control1102the infrastructure.1103    Mr. Self. Okay, thank you.1104    I just want to get to the specifics here. We are talking1105about cybersecurity professionals. Give me a range of--first of1106all, what level to we need in the CDP and what would be a range1107of salaries? Who wants to tackle that? Ms. Love-Grayer?1108    Ms. Love-Grayer. Well, I think I will tackle part of this1109question. We are talking about cybersecurity, but also beyond1110cybersecurity, there are a range of cyber issues and technical1111capacities that are needed, and you need diplomacy skills as1112well. One of the things we heard from CDP after our review is1113that they had trained about 250 diplomats on cyber issues. So1114there is internal training you can do, as well as hiring, and I1115think we need to use both capabilities.1116    Mr. Self. So what about salary range? Who wants to tackle1117that? Because we are competing with a growth industry here.1118    Mr. Nemeroff. I can start. The one piece I would emphasize,1119I am a lawyer by training----1120    Mr. Self. I am sorry.1121    Mr. Nemeroff. Yes. And I think what I learned in legal1122cyber practice has also been true in diplomatic cyber practice,1123which is that you take the old skills and you apply it to a new1124technology. And so that is a lot of what CDP does really well,1125it brings in diplomatic whizzes who can learn the technology1126and apply it. And it brings in tech whizzes who can learn the1127diplomacy and do that too.1128    Salary is a problem, we operate on the normal GS-15 scale1129so there is no special cyber pay at the State Department, and I1130do think that is an issue that you have colleagues who can----1131    Mr. Self. No, I am asking, what are we competing against?1132    Mr. Nemeroff. In the private sector?1133    Mr. Self. Right.1134    Mr. Nemeroff. Hundreds of thousands of dollars.1135    Mr. Self. Okay. I do want to get to because several1136mentions have been made of the new org chart. I want to just1137hear briefly--I have less than 2 minutes here. Let's go down1138the line, what do you recommend? I think part of it was in your1139written testimoneys, part of it was in your verbal testimoneys,1140but I want to hear specifically what do you recommend for CDP1141in the reauthorization, quickly.1142    Ms. Fixler. I will jump in. I think Congress had it right1143on a bipartisan basis, you created the cyber bureau and you1144understood the importance of the integration between the1145different components of the cyber mission, the cybersecurity1146mission, the digital economy mission, the emerging threats1147mission. All of those work hand in hand. And so, seeing that1148integration remain I think is a wise decision Congress1149previously made. I look forward to Congress continuing to weigh1150in on that.1151    Mr. Self. But now, it is directly underneath the deputy1152secretary. It is probably not going to stay under the deputy1153secretary.1154    Ms. Fixler. Yes, or maybe. I mean, you are going to1155reauthorize right it. Thank you for the question, though. I1156think the integration of the bureau is where I would focus.1157Whether--the head of the bureau needs to have the authority in1158crosscutting authorities, but whether exactly where you1159position the bureau I think may be less important than the1160integration of the different capabilities within the bureau.1161    Mr. Self. Thank you.1162    Ms. Love-Grayer. Actually I really agree with this point. I1163think integration is really critical even as we interface with1164other governments who are structured differently. However, I do1165think that where it sits plays an important role as well,1166because depending on where it sits it may have to compete with1167others for resources. And it also needs the ability to have the1168leader communicate with the most senior leaders at State in1169order make some pretty important decisions.1170    I would consider where it is placed. It also says something1171about what where the focus is. If it is in the E bureau versus1172the T bureau, it sends a signal about what the focus of the1173bureau will be, or the E family versus the T family.1174    Mr. Self. Out of time. But quickly, Mr. Nemeroff, I very1175much agree with the point about maintaining integration. There1176is no perfect answer, if you are going to try to put it under E1177or T, I think you need to make sure that whoever it is1178reporting to cares about the whole mission and that senior1179leaders at the top of the department the deputy secretary are1180still going to be representing all the equities that deputies1181committee meetings and diplomatic engagement.1182    Mr. Self. Thank you, I recognize our ranking member.1183    Mr. Keating. Ms. Fixer mentioned the tabletop exercise that1184occurred. I am just curious as part of that, since I am also in1185the Armed Services Committee, we are boosting our undersea1186autonomous vehicles, and we have been doing it every year1187because of threats like this.1188    Did you--is any of that considered, I know it is not1189strictly cyber, but we have been talking about the integrity of1190undersea cables?1191    Ms. Fixler. Yes. Thank you for the question. I am happy to1192provide more information about the exercise that we conducted.1193We have an after-action report, I am happy to share that with1194the committee.1195    The exercise looked at a number of different attacks that1196China could conduct. Some of them were cyber-related. Some of1197them were sort of more in the economic realm. And they looked1198also at undersea cables, mostly the disruption and the need to1199be able to quickly repair that infrastructure.1200    Mr. Keating. The other thing is, I remember my time in1201homeland security, how we were trying to deal with cyber1202threats and the importance of dealing with the private sector,1203because many of the countries that are represented, as well as1204our own, that is done on the private side and has an enormous1205impact to our safety and economy.1206    The same is true for the other countries that we are trying1207to make more resilient and make sure we are not affected by1208things that affect them.1209    So when you are looking at that situation and you are1210dealing with a private side, can you explain advantages there1211might be with the fact that we can deal with other countries to1212deal with their own private sector instances in terms of1213getting that kind of cooperation, particularly in revealing a1214cyber attack, you know, just minutes, hours make a difference1215in the ability to contain that. Perhaps anyone might want to1216address that.1217    Mr. Nemeroff. It was particularly breathtaking, I thought,1218to see the scale and speed and agility of the private sector in1219the days after the Russian invasion of Ukraine. They were able1220to move at a speed I wish governments could move at, and so,1221they are a critical partner wherever you are operating.1222    I found that foreign assistance is a part of it, but1223another part of it is maintaining a shared situational1224awareness.1225    The reporting that you referred to that they often issue is1226really an early warning often of incidents that we need to1227respond to quickly, and so they are a critical partner.1228    Mr. Keating. Great. Thank you. I notice we have another1229member who has come for a first line of questioning, so I yield1230back.1231    Mr. Self. I now recognize Mrs. Kim.1232    Mrs. Kim. Thank you, Chairman Self. Thank you. I want to1233thank our witnesses for being here today. You know, let me go1234right into questions like, how can private sectors'1235technological expertise such as that from organizations like1236very fake AI be leveraged to enhance the resilience of ally1237infrastructure against the response of a cyber attack?1238    Mr. Nemeroff. Thank you. I think it is a critical thing1239that every country in government needs to recognize that this1240has to be a public-private partnership, and that governments1241need to rely and use private sector capabilities to secure1242their networks.1243    We have made important strides within the U.S. Government,1244for example, moving to cloud as a place to store our data in1245order to help take cybersecurity out of the hands of individual1246offices and place it higher up.1247    We have also found that when incidents happen, private1248sectors are often the most agile in investigating and1249remediating, and so, it is very important as we talk to our1250allies and partners to make sure that they are thinking about1251this as a team sport as, well working with their own companies,1252or working with capable U.S. cybersecurity providers in order1253to provide these kinds of services and support.1254    Ms. Fixler. I would just add as well, CDP maintains some of1255those relationships, and its incident response capability, the1256foreign assistance funding that you all authorized to focus on1257rapid response and rapid deployment of resources, that is a1258partnership with private sector companies. It is not deploying1259U.S. Government personnel, but it is the relationship with1260private sector cybersecurity incident response professionals.1261    Ms. Love-Grayer. I will add just one note, which is, CDP's1262foreign assistance also sometimes makes it capable--or makes1263the environment possible for private sector companies to come1264in. And we saw that with Costa Rica, because they changed their1265environment based on CDP assistance, Intel felt more secure in1266being able to go in and make a $1.2 billion investment that1267they probably would not have made if Costa Rica had not changed1268many of its cyber norms and policies as a result of its1269interactions and engagement with CDP.1270    Ms. Kim. Thank you. You know, Ms. Fixler, from your1271perspective, how should the CDP bureau foster such partnerships1272to enhance cybersecurity in ally infrastructure, and what1273challenges must be addressed to ensure effective cooperation1274across the borders?1275    Ms. Fixler. Thank you for the question. I will focus1276specifically on the challenge. I think there is a challenge to1277think about things strategically. When it comes to critical1278infrastructure, everything is critical, but, frankly, there are1279things that are more critical, and we need to focus on that1280systemically important infrastructure in our own country and1281abroad to think about what do we most need to protect against.1282So if we can think about that strategically, I think that is a1283challenge, but a real opportunity for us to do better.1284    Mrs. Kim. Ms. Love-Grayer, can you provide which offices1285GAO found to have overlapped with CDP, and how the bureau works1286to ensure clear delineation between responsibilities with other1287offices that have cyber equities?1288    Ms. Love-Grayer. Within State, we found that the Bureau of1289Democracy and Human Rights and Labor, DRL, as well as INL,1290which focuses on international law enforcement, both of those1291bureaus also have equities in cyber diplomacy.1292    DRL, in particular, works on freedom, internet freedom1293issues, and they engage in multilateral foreign--they provide1294foreign assistance.1295    INL works on combating cyber crime. And they also lead a1296lot of the foreign assistance initiatives with other foreign1297governments, as well as multilateral diplomacy efforts.1298    So the coordination between all three of them are1299important. We found that they do have regular meetings and1300conversations, but they were still facing challenges defining1301who should take the lead on certain initiatives given the1302expertise that already exists in these other bureaus.1303    Mrs. Kim. Let's talk about that, so can you talk about the1304steps that CDP can take to mitigate risk of the overlap or1305redundancy that you are talking about in existing cybersecurity1306efforts across the Federal agencies, and how has CDP improved1307collaboration with key partners like DHS, DOJ, DOD and1308Treasury?1309    Ms. Love-Grayer. Within the Department, one of the things1310they--I believe they have started to do and they can continue1311to do is ensure that there is constant communication between1312all of the bureaus and they are well aware of which partners1313they are working with and where the focus ought to be for each1314one of them.1315    There is still some overlap in the missions, and I think1316there could be greater delineation between who is taking the1317lead on certain issues if they are not going to be consolidated1318in any kind of way.1319    In terms of the interagency, currently they have formal1320interagency agreements with several agencies, DHS, DOD, FTC,1321Department of Commerce, those do seem to be working well1322because they outline the parameters of those relationships and1323who is taking the lead.1324    Mrs. Kim. Thank you. Chairman, I yield back.1325    Mr. Self. I thank the witnesses for their testimony, and1326the members for their questions. The members of the1327subcommittee may have some additional questions for you, and we1328would ask you to respond to those in writing.1329    Pursuant to committee rules, all members may have 5 days to1330submit statements, questions and extraneous materials for the1331record subject to the length of limitations. Without objection,1332the committee stands adjourned. Thank you very much.1333    [Whereupon, at 3:27 p.m., the subcommittee was adjourned.]13341335                                APPENDIX13361337                              ----------13381339               Material Submitted for the Hearing Record13401341    [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]13421343                                 [all]

Witnesses

3 witnesses appeared, with 9 papers on file.

NamePositionPapers
Ms. Latesha Love-GrayerDirector, International Affairs and Trade, U.S. Government Accountability Office
Ms. Annie FixlerDirector, Center on Cyber and Technology, Foundation for Defense of DemocraciesBiography · Testimony · Truth in Testimony
Mr. Theodore NemeroffCo-Founder and Vice President for Data and Compliance, Verific AITruth in Testimony · Biography · Testimony

Documents

The committee filed 2 documents for the meeting.

DocumentKindFormat
Member AttendanceHearing: Member RosterPDF
Hearing NoticeSupport DocumentPDF