Search

Search bills, members, committees and pages...

“Defense through Offense: Examining U.S. Cyber Capabilities to Deter and Disrupt Malign Foreign Activity Targeting the Homeland”

HearingHomeland Security Subcommittee on Cybersecurity and Infrastructure ProtectionJan 13, 2026 · 10:00 AM

Summary

Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection held a hearing on Jan 13, 2026 at 10:00 AM in Cannon House Office Building, Room 310. 4 witnesses appeared.


Record

The meeting has its video, its transcript, witnesses and documents on the record.

Video

The proceedings, as the committee streamed them.

Transcript

The transcript runs to 3,052 lines and 176,147 characters, as the Government Publishing Office printed it.

house-hearing-63558.txt
1[House Hearing, 119 Congress]2[From the U.S. Government Publishing Office]34              DEFENSE THROUGH OFFENSE: EXAMINING U.S.5               CYBER CAPABILITIES TO DETER AND DISRUPT6               MALIGN FOREIGN ACTIVITY TARGETING THE7               HOMELAND8=======================================================================910                                HEARING1112                               BEFORE THE1314                            SUBCOMMITTEE ON15                    CYBERSECURITY AND INFRASTRUCTURE16                               PROTECTION1718                                 OF THE1920                     COMMITTEE ON HOMELAND SECURITY21                        HOUSE OF REPRESENTATIVES2223                    ONE HUNDRED NINETEENTH CONGRESS2425                             SECOND SESSION2627                               __________2829                            JANUARY 13, 20263031                               __________3233                           Serial No. 119-343435                               __________3637       Printed for the use of the Committee on Homeland Security3839[GRAPHIC NOT AVAILABLE IN TIFF FORMAT]4041        Available via the World Wide Web: http://www.govinfo.gov4243                               __________4445                     U.S. GOVERNMENT PUBLISHING OFFICE4663-558 PDF                 WASHINGTON : 202647=======================================================================4849                     COMMITTEE ON HOMELAND SECURITY5051                Andrew R. Garbarino, New York, Chairman52Michael T. McCaul, Texas, Vice       Bennie G. Thompson, Mississippi,53    Chair                                Ranking Member54Michael Guest, Mississippi           Eric Swalwell, California55Carlos A. Gimenez, Florida           J. Luis Correa, California56August Pfluger, Texas                Shri Thanedar, Michigan57Tony Gonzales, Texas                 Seth Magaziner, Rhode Island58Morgan Luttrell, Texas               Daniel S. Goldman, New York59Dale W. Strong, Alabama              Delia C. Ramirez, Illinois60Josh Brecheen, Oklahoma              Timothy M. Kennedy, New York61Elijah Crane, Arizona                LaMonica McIver, New Jersey62Andrew Ogles, Tennessee              Julie Johnson, Texas, Vice Ranking63Sheri Biggs, South Carolina              Member64Gabe Evans, Colorado                 Pablo Jose Hernandez, Puerto Rico65Ryan Mackenzie, Pennsylvania         Nellie Pou, New Jersey66Brad Knott, North Carolina           James R. Walkinshaw, Virginia67Vince Fong, California               Troy A. Carter, Louisiana68Matt Van Epps, Tennessee             Al Green, Texas69Vacant70                     Keighle Joyce, Staff Director71                  Hope Goins, Minority Staff Director72                       Sean Corcoran, Chief Clerk73                                 ------7475      SUBCOMMITTEE ON CYBERSECURITY AND INFRASTRUCTURE PROTECTION7677                   Andrew Ogles, Tennessee, Chairman78Carlos A. Gimenez, Florida           Eric Swalwell, California, Ranking79Morgan Luttrell, Texas                   Member80Ryan Mackenzie, Pennsylvania         Seth Magaziner, Rhode Island81Vince Fong, California               LaMonica McIver, New Jersey82Andrew R. Garbarino, New York (ex    James R. Walkinshaw, Virginia83    officio)                         Bennie G. Thompson, Mississippi84                                         (ex officio)85             Roland Hernandez, Subcommittee Staff Director86           Moira Bergin, Minority Subcommittee Staff Director8788                           C O N T E N T S8990                              ----------91                                                                   Page9293                               Statements9495The Honorable Andrew Ogles, a Representative in Congress From the96  State of Tennessee, and Chairman, Subcommittee on Cybersecurity97  and Infrastructure Protection:98  Oral Statement.................................................     199  Prepared Statement.............................................     3100The Honorable Bennie G. Thompson, a Representative in Congress101  From the State of Mississippi, and Ranking Member, Committee on102  Homeland Security:103  Oral Statement.................................................     4104  Prepared Statement.............................................     5105106                               Witnesses107108Mr. Joe Lin, Co-Founder and Chief Executive Officer, Twenty109  Technologies, Inc.:110  Oral Statement.................................................     7111  Prepared Statement.............................................     8112Ms. Emily Harding, Vice President, Defense and Security113  Department, Center for Strategic and International Studies:114  Oral Statement.................................................    10115  Prepared Statement.............................................    12116Mr. Frank Cilluffo, Director, McCrary Institute for Cyber and117  Critical Infrastructure Security, Auburn University:118  Oral Statement.................................................    15119  Prepared Statement.............................................    17120Mr. Drew Bagley, Chief Privacy Officer, CrowdStrike:121  Oral Statement.................................................    19122  Prepared Statement.............................................    21123124DEFENSE THROUGH OFFENSE: EXAMINING U.S. CYBER CAPABILITIES TO DETER AND125         DISRUPT MALIGN FOREIGN ACTIVITY TARGETING THE HOMELAND126127                              ----------128129                       Tuesday, January 13, 2026130131             U.S. House of Representatives,132                    Committee on Homeland Security,133                         Subcommittee on Cybersecurity and134                                 Infrastructure Protection,135                                                    Washington, DC.136    The subcommittee met, pursuant to notice, at 10:02 a.m., in137room 310, Cannon House Office Building, Hon. Andy Ogles138[Chairman of the subcommittee] presiding.139    Present: Representatives Ogles, Gimenez, Luttrell, Fong,140Swalwell, Magaziner, McIver, and Walkinshaw.141    Also present: Representatives Thompson, and Garbarino.142    Mr. Ogles. The Committee on Homeland Security Subcommittee143on Cybersecurity and Infrastructure Protection will come to144order. Without objection, the Chair may declare the committee145in recess at any point.146    The purpose of today's hearing is to examine the current147state of U.S. capabilities or how those capabilities are used148to deter, disrupt, and impose real cost on foreign adversaries149that target the homeland and our Nation's critical150infrastructure. The hearing will also assess the legal151authorities that govern offensive cyber operations across the152Federal Government and examine the evolving role of the private153sector as the U.S. Government considers whether and under what154circumstances private entities may be authorized to support or155conduct offensive and disruptive cyber activity.156    I now recognize myself for an opening statement.157    Today, the subcommittee is meeting to examine a reality158that the United States can no longer afford to avoid, namely159that deterrence in cyber space does not exist without credible,160lawful, and operational offensive cyber capabilities. Defense161alone is not sufficient. Resilience alone is not sufficient.162Public attribution alone is not sufficient.163    For more than a decade, the United States has invested164heavily in cyber defense and information sharing and165resilience. Those investments are necessary and they have166improved our ability to withstand attacks, but they have not167altered adversarial behavior. Malign cyber actors continue to168penetrate American networks, steal sensitive data, surveil169communications, and position themselves inside critical170infrastructure with little fear of meaningful consequence.171    That reality was reinforced again just days ago, when172public reporting revealed that a Chinese state-sponsored cyber173actor known as Salt Typhoon compromised email systems used by174staff supporting several Congressional committees. This175incident was the latest operation in a sustained campaign176conducted by a broader group of Chinese cyber actors commonly177referred to as the Typhoon Cluster. These actors are not178criminals acting for profit. They are instruments of state179power, and that needs to be underscored.180    Their operations are deliberate, persistent, and strategic181in nature. They are designed to extract intelligence, pre-182position access, and shape the battlefield long before a crisis183or conflict emerges. I am going to say that again. Pre-position184access and shape the battlefield long before a crisis or185conflict emerges. They target not only the Executive branch and186private industry, but now, once again, the Legislative branch187itself.188    The question before this subcommittee is not whether these189threats exist. That is no longer in dispute. The question is190why they continue and what it will take to change the cost-191benefit calculation for adversaries who believe they can192operate against the United States with impunity.193    Currently, authorities for offensive cyber operations are194dispersed across the Department of War, the intelligence195community, law enforcement, while civilian agencies like CISA196play critical roles in defense, response, and resilience.197Existing policy frameworks were developed for an earlier phase198of the cyber threat environment, one that did not fully199anticipate today's scale, speed, and persistence of state-200sponsored activity. Again, the speed and the scale of the201battlefield has changed. They are also not designed for a world202in which the vast majority of digital infrastructure targeted203by adversaries is owned and operated by the private sector.204    The reality is forcing a broader reassessment across the205Federal Government. The Trump administration has signaled its206intent to pursue a more proactive and assertive cyber posture,207one that emphasizes disrupting adversary capabilities before208harm occurs, resetting adversarial risk calculations, and209exploring new ways to integrate private-sector expertise into210national cyber efforts. This reflects an important recognition.211The private sector is not merely a victim in cyber space.212American cybersecurity companies, cloud providers,213telecommunications firms, and emerging technology start-ups are214often the first to detect malicious activity, the first to215analyze adversarial tradecraft, and the first to develop tools216capable of disrupting hostile infrastructure. In many cases,217they already possess visibility and technical insights that218rivals or exceeds that of the Federal Government.219    The challenge is that much of this activity exists in legal220and policy gray space. Companies face uncertainty about221liability, retaliation, and regulatory risk. Government222agencies face constraints on how they can partner, share223information, and act with speed. Adversaries exploit these224seams, operating continuously below the threshold of armed225conflict while benefiting from ambiguity and restraint.226    Today, our witnesses will help us assess how offensive227cyber capabilities can be responsibly integrated into a modern228homeland security framework. I appreciate our witnesses for229being here and I look forward to their testimony and the230discussion ahead. Again, thank you all for being here.231    [The statement of Chairman Ogles follows:]232                   Statement of Chairman Andrew Ogles233                            January 13, 2026234    Today, the subcommittee is meeting to examine a reality that the235United States can no longer afford to avoid, namely that deterrence in236cyber space does not exist without credible, lawful, and operational237offensive cyber capabilities. Defense alone is not sufficient.238Resilience alone is not sufficient. Public attribution alone is not239sufficient.240    For more than a decade, the United States has invested heavily in241cyber defense, information sharing, and resilience. Those investments242are necessary and they have improved our ability to withstand attacks.243But they have not altered adversary behavior. Malign cyber actors244continue to penetrate American networks, steal sensitive data, surveil245communications, and position themselves inside critical infrastructure246with little fear of meaningful consequence.247    That reality was reinforced again just days ago, when public248reporting revealed that a Chinese state-sponsored cyber actor known as249Salt Typhoon compromised email systems used by staff supporting several250Congressional committees. This incident was the latest operation in a251sustained campaign conducted by a broader group of Chinese cyber actors252commonly referred to as the Typhoon cluster.253    These actors are not criminals acting for profit. They are254instruments of state power. Their operations are deliberate,255persistent, and strategic in nature. They are designed to extract256intelligence, pre-position access, and shape the battlefield long257before a crisis or conflict emerges. They target not only the Executive258branch and private industry, but now once again the Legislative branch259itself.260    The question before this subcommittee is not whether these threats261exist. That is no longer in dispute. The question is why they continue,262and what it will take to change the cost-benefit calculation for263adversaries who believe they can operate against the United States with264impunity.265    Currently, authorities for offensive cyber operations are dispersed266across the Department of War, the intelligence community, and law267enforcement, while civilian agencies like CISA play critical roles in268defense, response, and resilience. Existing policy frameworks were269developed for an earlier phase of the cyber threat environment, one270that did not fully anticipate today's scale, speed, and persistence of271state-sponsored cyber activity.272    They were also not designed for a world in which the vast majority273of digital infrastructure targeted by adversaries is owned and operated274by the private sector.275    That reality is forcing a broader reassessment across the Federal276Government. The Trump administration has signaled its intent to pursue277a more proactive and assertive cyber posture, one that emphasizes278disrupting adversary capabilities before harm occurs, resetting279adversary risk calculations, and exploring new ways to integrate280private-sector expertise into national cyber efforts.281    This reflects an important recognition. The private sector is not282merely a victim in cyber space. American cybersecurity companies, cloud283providers, telecommunications firms, and emerging technology start-ups284are often the first to detect malicious activity, the first to analyze285adversary tradecraft, and the first to develop tools capable of286disrupting hostile infrastructure. In many cases, they already possess287visibility and technical insight that rivals or exceeds that of the288Federal Government.289    The challenge is that much of this activity exists in legal and290policy gray space. Companies face uncertainty about liability,291retaliation, and regulatory risk. Government agencies face constraints292on how they can partner, share information, and act with speed.293Adversaries exploit these seams, operating continuously below the294threshold of armed conflict while benefiting from ambiguity and295restraint.296    Today, our witnesses will help us assess how offensive cyber297capabilities can be responsibly integrated into a modern homeland298security framework.299    I appreciate our witnesses for being here, and I look forward to300their testimony and the discussion ahead.301    Thank you.302303    Mr. Ogles. I now recognize the Ranking Member, the304gentleman from Mississippi, Mr. Thompson, for his opening305statement.306    Mr. Thompson. Thank you, Mr. Chairman. Good morning. I307appreciate the opportunity to discuss opportunities to disrupt308and deter malicious cyber activities on domestic networks and309impose cost on our adversaries. I thank the witnesses for310participating.311    Before I begin, however, I would like to send my deepest312condolences to the family of Renee Good, particularly her313partner and 6-year-old child, who is now without a mother. From314everything I have seen, Ms. Good was attempting to de-escalate315and leave the situation and there was no reason to take her316life. I support a full investigation of this shooting and317justice on her behalf.318    Turning to the issue at hand, over the course of the past319year, there have been increased discussions about whether the320United States is using its formidable offensive cyber321capabilities as effectively as it could be to deter and disrupt322cyber attacks. United States' offensive cyber capability is323second to none, but with that awesome power comes awesome324responsibility. As we consider whether and how to deploy325offensive cyber tools differently, we must bear three points in326mind.327    First, cyber offense is no substitute for defense and328resilience. We will have to continue investing in those key329capabilities.330    Second, cyber offense is one tool among many, including331sanctions and other diplomatic levers, that the United States332can use to shape adversary behavior. The tool of--combination333of tools we should align with our mission objectives.334    Finally, any significant change to our approach to the use335of offensive cyber operations could shift global norms, and we336must consult our allies.337    As a committee responsible for overseeing the Cybersecurity338and Infrastructure Security Agency, referred to as CISA, I am339concerned that we are putting the cart before the horse with a340hearing on offensive cyber activity when we have not had a341hearing on why the agency has lost one-third of its work force342over the last year. CISA is an agency responsible for helping343utilities, water treatment facilities, pipelines, and other344critical infrastructure entities keeping Volt Typhoon and other345adversaries off our network. But ever since last January, the346Trump administration harassed key CISA personnel into leaving347their jobs, including the individuals responsible for the348Secure-by-Design Program, the Pre-Ransomware Notification349Initiative, and individuals who work directly with critical350infrastructure operators on security issues. We ought to be351cautious about pursuing an approach involving the use of352offensive cyber tools that could result in retaliation or353escalation if we are not in a position to help defend U.S.354networks.355    Moreover, we must bear in mind that offensive tools are one356of many tools at our disposal to shape behavior in cyber space,357and we need to use them all more effectively and more358deliberately. I understand that plans to impose sanctions on359China's Ministry of State Security for its Salt Typhoon360campaign was put on hold last year as the President negotiated361a trade truce with the country. Our use of sanctions and other362diplomatic tools to deter and impose cost on our adversaries363would be more effective if the President did not start364unnecessary trade wars. Relatedly, we should be clear-eyed365about what our objectives are and how the use of offensive366cyber tools align with our objectives.367    Finally, any change in our approach to the use of offensive368cyber tools that would shift current norms must be done in369consultation with our allies. We cannot afford to distance370ourselves from our security partners more than this371administration already has.372    Having said that, I agree there are opportunities to373increase pressure and impose higher costs on adversaries for374unacceptable behavior in cyber space. We should consider375whether there are many--where there are ways to more376aggressively disrupt adversary infrastructure and deny them the377benefits of success. Additionally, while offensive cyber378activities by and large is a Government function, there may be379new ways for the private sector to support Government efforts380in this space in a manner consistent with the law.381    I look forward to discussing these issues, and I yield back382the balance of my time.383    [The statement of Ranking Member Thompson follows:]384             Statement of Ranking Member Bennie G. Thompson385                            January 13, 2026386    I appreciate the opportunity to discuss opportunities to disrupt387and deter malicious cyber activities on domestic networks and impose388costs on our adversaries, and I thank the witnesses for participating.389    Before I begin, however, I would like to send my deepest390condolences to the family of Renee Good, particularly her partner and3916-year-old child, who is now without a mother. From everything I've392seen, Ms. Good was attempting to de-escalate and leave the situation,393and there was no reason to take her life. I support a full394investigation of this shooting and justice on her behalf.395    Turning to the issue at hand, over the course of the past year,396there has been increased discussion about whether the United States is397using its formidable offensive cyber capabilities as effectively as it398could be to deter and disrupt cyber attacks. The United States'399offensive cyber capability is second-to-none--but with that awesome400power comes awesome responsibility. As we consider whether and how to401deploy offensive cyber tools differently, we must bear three points in402mind:403    First, cyber offense is no substitute for defense and resilience.404We will have to continue investing in those key capabilities. Second,405cyber offense is one tool among many--including sanctions and other406diplomatic levers--that the United States can use to shape adversary407behavior. The tool--or combinations of tools--we use should align with408our mission objectives. Finally, any significant change to our approach409to the use of offensive cyber operations could shift global norms, and410we must consult our allies.411    As the committee responsible for overseeing the Cybersecurity and412Infrastructure Security Agency (CISA), I am concerned that we are413putting the cart before the horse with a hearing on offensive cyber414activity when we have not yet had a hearing on why the agency has lost415one-third of its workforce over the past year. CISA is the agency416responsible for helping utilities, water treatment facilities,417pipelines, and other critical infrastructure entities keep Volt Typhoon418and other adversaries off their networks.419    But ever since last January, the Trump administration harassed key420CISA personnel into leaving their jobs, including the individuals421responsible for the Secure-by-Design program, the Pre-Ransomware422Notification Initiative, and individuals who worked directly with423critical infrastructure operators on security issues.424    We ought to be cautious about pursuing an approach involving the425use of offensive cyber tools that could result in retaliation or426escalation if we are not in a position to help defend U.S. networks.427    Moreover, we must bear in mind that offensive tools are one of many428tools at our disposal to shape behavior in cyber space--and we need to429use them all more effectively and more deliberately. I understand that430plans to impose sanctions on China's Ministry of State Security for its431Salt Typhoon campaign were put on hold last year as the President432negotiated a trade ``truce'' with the country.433    Our use of sanctions and other diplomatic tools to deter and impose434costs on our adversaries would be more effective if our President did435not start unnecessary trade wars. Relatedly, we should be clear-eyed436about what our objectives are and how the use of offensive cyber tools437aligns with those objectives.438    Finally, any change in our approach to the use of offensive cyber439tools that would shift current norms must be done in consultation with440our allies. We cannot afford to distance ourselves from our security441partners more than this administration already has. Having said all442that, I agree there are opportunities to increase pressure and impose443higher costs on adversaries for unacceptable behavior in cyber space.444    We should consider whether there are ways to more aggressively445disrupt adversary infrastructure and deny them the benefits of success.446Additionally, while offensive cyber activity is a Government function,447there may be new ways for the private sector to support Government448efforts in this space, in a manner consistent with the law.449450    Mr. Ogles. Thank you, Ranking Member Thompson. Other451Members of the committee are reminded that opening statements452may be submitted for the record.453    I am pleased to have a distinguished panel of witnesses454before us today on this important topic. Pursuant to committee455rule VIII(C), I ask that our witnesses please rise and raise456their right hands.457    [Witnesses sworn.]458    Mr. Ogles. Let the record reflect that the witnesses have459answered in the affirmative. Thank you and please be seated.460    I would like to formally introduce our witnesses. Mr. Joe461Lin currently serves as co-founder and CEO of Twenty462Technologies, a cybersecurity company that develops AI-enabled463capabilities to help Government and national security partners464detect, disrupt, and counter sophisticated cyber threats. In465addition to his current role, he is a commissioner on the466Center for Strategic and International Studies Commission on467Cyber Force Generation. Prior to his roles at Twenty, Mr. Lin468served as the vice president of product management at Palo Alto469Networks, where he founded and led the National Security470Division. A former U.S. Navy Reserve officer, Mr. Lin has spent471over a decade defending U.S. military, Government, and critical472infrastructure networks. Thank you, Mr. Lin.473    Ms. Emily Harding currently serves as vice president of the474Defense and Security Department and director of the475Intelligence, National Security, and Technology Program at the476Center for Strategic and International Studies. That is a477mouthful. In these roles, she provides expert knowledge and478intellectual leadership on issues shaping the future of479intelligence work and national security. Prior to CSIS, Ms.480Harding served as the deputy staff director on the Senate481Select Committee on Intelligence, led analytic programs at the482CIA, and contributed to the first Office of the Director of483National Intelligence-led Presidential transition.484    Mr. Frank Cilluffo serves as the director of Critical485Infrastructure Security at Auburn University. He was a member486of the U.S. Cyber Solarium Commission and served as special487assistant to the President in George W. Bush's administration488in the newly-created White House Office of Homeland Security.489Following this role, he joined George Washington University490where he established the Center for Cyber and Homeland491Security. His previous experience also includes senior policy492positions at the Center for Strategic and International493Studies. Thank you, Ms. Harding--Mr. Cilluffo.494    Mr. Drew Bagley currently serves as the chief privacy495officer at CrowdStrike, where he is responsible for leading the496company's global data protection initiatives, privacy strategy,497and policy engagement. Mr. Bagley previously worked in the498Federal Bureau of Investigation's Office of the General499Counsel. Has served as an advisor to Government and nonprofit500groups, including the Cybersecurity Infrastructure Security501Agency's Joint Cyber Defensive Collaborative at the U.S.502Department of State and Europol. In addition to his corporate503leadership, Mr. Bagley serves on the faculty of American504University where he teaches cyber law and privacy.505    I want to thank each of our distinguished witnesses for506being here today. I now recognize Mr. Lin for 5 minutes to507summarize his opening.508509 STATEMENT OF JOE LIN, CO-FOUNDER AND CHIEF EXECUTIVE OFFICER,510                   TWENTY TECHNOLOGIES, INC.511512    Mr. Lin. Chairman, Ranking Member, Members of the513subcommittee, thank you for the opportunity to testify today.514My name is Joe Lin. I'm the co-founder and CEO of Twenty515Technologies, where we build industrial-scale cyber warfare516capabilities for the United States.517    I want to be direct. The United States is not postured to518deter or defeat its adversaries in cyber space. Our519adversaries, most notably the People's Republic of China, are520running persistent, large-scale cyber campaigns against U.S.521critical infrastructure, telecommunications, the defense522industrial base, and Government networks. These are not523episodic breaches. These are not just thefts of intellectual524property. They are continuous, increasingly automated shaping525operations designed to hold our society at risk at peacetime526and to pre-position for conflict. These campaigns have been527effective. They have imposed real and growing costs on the528United States.529    By contrast, our response is unnecessarily constrained,530particularly in the use of offensive cyber. This restraint has531not prevented escalation, it has encouraged it. When532adversaries escalate and face little or no cost, they learn533that it works. Over time, that becomes an incentive to push534further. In effect, we have created a one-way dynamic. They535escalate and we absorb. Because we absorb, they keep536escalating. Yet the U.S. Government continues to treat537offensive cyber as a bespoke capability, slow to generate,538difficult to scale, and constrained by processes built for a539different era. We rely on small numbers of elite teams540executing one-off operations while our adversaries operate at541machine speed across hundreds or thousands of targets. That542mismatch is the core problem.543    Deterrence in cyber space does not come from symbolic544gestures or isolated tactical wins. It comes from the545demonstrated ability to impose sustained asymmetric cost at546scale to make adversary campaigns fail repeatedly and faster547than they can adapt. This is not just a talent problem, this is548a structural one. Our cyber forces are asked to confront an549industrial scale threat with bespoke tools and processes. We550have not built cyber capabilities for sustained campaigns,551operational tempo, or mass effects. Cyber space is now a552primary domain of conflict where speed, scale, and persistence553determine real-world outcomes. Offensive cyber must therefore554be treated as a core instrument of national power, and that555requires three shifts.556    First, we must industrialize offensive cyber capabilities.557Elite operator tradecraft must be turned into software,558codified, testable, repeatable systems that execute under human559authorization at machine speed. This is not about removing560humans from the loop. It is about leverage. One operator should561be able to direct efforts across hundreds of targets, not one.562    Second, we must align authorities, acquisition, and563operational concepts to sustained campaigns, not single564operations. Our adversaries are persistent. We need565capabilities that are continuously operating, adapting, and566imposing friction, built as operational software, not legacy567Government programs designed for peacetime procurement.568    Third, we must be honest about the role of offense in569defense. Critical infrastructure security will not be solved570through patching alone. Against persistent state-directed571actors, defensive measures are insufficient. Deterrence572requires credible offensive cyber operations that disrupt and573impose costs upstream. This may be uncomfortable culturally,574but unavoidable strategically.575    Effective offensive cyber is not reckless. It is576disciplined, tested, authorized, and aligned with Government577policy. In fact, the absence of scalable, well-engineered578offensive capability increases risk by ceding initiative to our579adversaries and forcing reactive, crisis-driven responses.580    The United States has faced industrial-scale threats581before. Each time we built industrial-scale responses. Cyber is582no different except that time is not on our side. The campaigns583under way today are shaping the battle space for tomorrow.584Every delay compounds the problem. This subcommittee has a585critical role to play. Clarifying mission ownership, enabling586acquisition pathways for commercial offensive cyber587capabilities, and treating offensive cyber operations as a588decisive element of homeland security, not a niche activity. If589we want deterrence, we must build the capabilities that make590deterrence real.591    Thank you and I look forward to your questions.592    [The prepared statement of Mr. Lin follows:]593                     Prepared Statement of Joe Lin594                       Tuesday, January 13, 2026595    Chairman, Ranking Member, and Members of the committee, thank you596for the opportunity to speak before you today. My name is Joseph Lin. I597am the CEO of Twenty, the first U.S. venture-backed cyber warfare598start-up, building industrial-scale offensive cyber capabilities for599the United States and its allies. I've spent my career working600alongside the intelligence community, the Department of War, and601civilian agencies defending American networks.602    My co-founders and I founded this company for a simple reason:603America is under sustained cyber attack, and our adversaries have604learned--correctly--that those attacks rarely produce consequences. We605decided to change that--by making our adversaries think twice before606they attack us.607    For too long, Washington has treated offensive cyber operations as608inherently escalatory--as if responding to a cyber intrusion carried609the same risk as nuclear war. The result is a dangerous pattern: we610absorb attack after attack, issue warnings about ``norms,'' and add a611modest sanction or two. Meanwhile, the People's Republic of China612(PRC), Russia, Iran, and North Korea continue to infiltrate our613critical infrastructure, steal our intellectual property, and pre-614position malware inside our civilian systems--all with increasing615confidence that there will be no real cost.616    That restraint was meant to prevent escalation. In practice, it has617invited it.618    The following is a small fraction of the persistent and escalating619campaign of cyber aggression directed against the United States.620    We have watched as PRC-linked actors conducted the Salt Typhoon621campaign, making deep, strategic infiltrations into multiple major622American telecommunications providers, including AT&T, Verizon, and T-623Mobile.624    We have witnessed the systematic theft of our citizens' most625private data:626   The compromise of Anthem impacted 79 million records--627        including Social Security numbers and medical IDs.628   We have seen the mass exfiltration of personal data from629        Marriott affect 383 million guests, including passport numbers.630   We have seen 145 million Americans--nearly half the631        country--have their financial identities stolen in the Equifax632        breach, an act for which members of the Chinese military were633        directly indicted.634   We have seen 22 million records exfiltrated from the Office635        of Personnel Management, including the highly-sensitive SF-86636        security clearance files of our Federal workforce. It included637        the Social Security numbers, fingerprints, and the most638        intimate background details of current, former, and prospective639        Federal employees, contractors, and their families. By640        harvesting this data, the PRC has gained a permanent641        counterintelligence road map to the people who operate,642        protect, and lead this country.643    Additionally, PRC actors have moved beyond espionage and begun644embedding themselves within our critical infrastructure.645    Through the campaign known as Volt Typhoon, PRC-linked actors have646burrowed into the networks of U.S. water, power, and transit systems.647According to public government reporting, this activity reflects648deliberate pre-positioning to hold hostage our American cities and649communities, and enable disruption during a future crisis or conflict.650    The PRC is not alone. The 2014 Sony Pictures hack--conducted by651North Korean actors--was not about theft alone. It was designed to652destroy systems, disrupt operations, and impose real economic damage on653a U.S. company.654    These are no longer potential risks.655    Our adversaries have learned that the marginal cost of doing more656is low. Every time we respond to aggression with speeches instead of657real consequences, we send a clear signal: keep climbing. Over time,658that becomes a perverse incentive--one that rewards exactly the659behavior we want to stop.660    The cyber domain doesn't behave like the Cold War's nuclear world.661Escalation is not automatic--which means policy makers have more room662to act than their instincts suggest. We don't have to choose between663doing nothing and doing something reckless. We can act proportionally,664preemptively, and persistently.665    Last year, National Cyber Director Sean Cairncross was correct in666saying that the United States needs to ``shift the burden of risk in667cyber space from Americans to them.'' Director Cairncross recognizes668that deterrence in cyber space requires the credible, routine use of669offensive power--not as a last resort, but as a standing expectation.670Our adversaries are not deterred by words; they are deterred by671disruption.672    And the most effective time to disrupt an adversary is before their673campaign becomes a headline. Preemptive operations--when executed674responsibly--can deny access, degrade infrastructure, and raise the675attacker's cost curve. They force our enemies to rebuild, defend, and676think twice.677    In the physical world, we would never allow a terrorist to walk678across our borders, establish a terrorist cell in plain sight, and wait679to stop them only at the moment they reach for the detonator. We don't680wait for the trigger to be pulled or the button to be pressed on a681bomb. We stop them well before they ever reach their target.682Afterwards, our military, intelligence community, and law enforcement683are praised for their ability to identify hostile infrastructure being684built for the purpose of attacking America.685    Cyber space should be no different. We currently possess the686technical ability to see the digital infrastructure of our enemies687being constructed in the shadows of our networks. We can see the688networking established with the intention to paralyze us. Yet, under689our current passive doctrine, we are forced to watch and wait.690    We need a policy of deterrence where we disrupt the threat at its691origin, not at our doorstep. We can leverage the innovation of the692private sector to dismantle these threats before they can be activated.693If we can foresee an attack aimed at an American city or town, a694Fortune 500 company or a Federal agency, a State or local municipality,695our duty is clear: we have the moral and national security obligation696to neutralize the threat.697    At Twenty, we partner closely with the U.S. Government to develop698and deploy these capabilities at scale. We're helping to deliver699exactly what deterrence now requires: speed, agility, and credible700offensive power.701    But this is not just about technology--it's about mindset. For702years, we substituted process for power. We talked about responsible703behavior, issued indictments that foreign operatives will never face,704and redrew red lines every time they were crossed. That approach has705failed not because America lacks cyber talent, but because we have been706paralyzed by outdated theories of escalation.707    To compete, we must build a new habit--responding. Every serious708campaign against the United States must produce real, visible709consequences.710    Congress has a critical role to play by demanding measurable711accountability. On a Classified basis, Congress should require answers712to the following questions: How quickly and how often were preemptive713or proactive offensive cyber actions authorized to disrupt, deny, or714degrade adversary operations? Did those actions reduce adversary715persistence? And were hostile campaigns forced to degrade or rebuild?716    These are the questions that should define cyber deterrence in the71721st Century. Technology will play a decisive role in this718transformation--especially artificial intelligence.719    AI-enabled systems are already reshaping cyber operations, from720accelerating target analysis to automating detection of721vulnerabilities. At Twenty, we are developing AI-driven cyber tools722that can operate securely within Classified environments, multiply723human capability by orders of magnitude, and do so responsibly, with724human oversight.725    Last year, Congress authorized $1 billion for offensive cyber726programs in H.R. 1. This was an important step, but only a down727payment. We cannot treat it as a box checked. These funds must go728toward future-focused technology--not legacy systems--and AI must be a729central part of that investment. And, Congress should condition future730offensive cyber funding on demonstrable improvements in speed, scale,731and mission impact--favoring systems built for rapid, persistent cyber732operations, not legacy platforms designed for episodic, one-off733missions.734    Ultimately, no single entity--not Government, not industry--can735meet this challenge alone. Our adversaries coordinate across Government736and private lines. We must do the same. The White House is right to737emphasize public-private collaboration as a cornerstone of cyber738deterrence. The United States has the talent, the innovation, and the739moral clarity to lead in this new era--but leadership requires urgency,740and it requires partnership.741    At Twenty, we are proud to help make that possible--ensuring that742America's cyber capabilities remain powerful, disciplined, and aligned743with democratic values.744    Thank you for the opportunity to testify. I look forward to your745questions.746747    Mr. Ogles. Thank you, Mr. Lin. I agree, the best defense is748an aggressive offense.749    I now recognize Ms. Harding for 5 minutes to summarize her750opening statement.751752    STATEMENT OF EMILY HARDING, VICE PRESIDENT, DEFENSE AND753  SECURITY DEPARTMENT, CENTER FOR STRATEGIC AND INTERNATIONAL754                            STUDIES755756    Ms. Harding. Thank you for this opportunity. I suspect I'm757going to find myself in fierce agreement with most of my758panelists here, but I'll try to add a little bit. First I want759to walk a bit through the problem and then talk about the war760games that we ran to fully diagnose that problem, and then a761minute on how to fix it.762    So the problem. Washington has failed to establish763deterrence in the cyber domain and our adversaries right now764control the escalation ladder. Historically, U.S. foreign765policy has rested on deterrence with implied escalation766dominance in any domain, but that foundation has failed in the767context of cyber. U.S. responses to cyber attacks have been768muted. Escalation dominance does not exist.769    To actually achieve this deterrence, we need a mindset770shift. We need to stop thinking about cyber attacks as771inevitable nuisances and start seeing them for what they really772are: hostile actions against the United States. China, Russia,773Iran, and North Korea do not see a bright line between war and774peace. Instead, they view cyber attacks as fitting on a775spectrum of warfare. For them, competition with the United776States is on-going. Low-level elements of cyber warfare are not777only acceptable, they're effective.778    In 2023, both Iran and China pushed the boundaries with779attacks on critical infrastructure. In November 2023, the780Islamic Revolutionary Guard Corps of Iran attacked U.S. water781plants. While the intent was to embarrass Israel, the facts are782undeniable: a terrorist group attempted to impair water783delivery to civilians in the United States.784    Also, in late 2023, NSA and cybersecurity researchers785raised renewed alarm about China's Volt Typhoon group. The786attackers burrowed into U.S. water, power, port systems in the787mainland and on Guam. These accesses could give Beijing the788capability to disrupt daily life. This was the pre-positioning789you were talking about in your opening statement, Mr. Chairman,790particularly around U.S. military bases that would serve as791launching pads for U.S. troops in a Pacific fight.792    So let's talk a little bit about the war games we use to793diagnose this problem fully. This is a dangerous new phase in794cyber warfare. We suspected that U.S. policy makers had not795fully wrapped their heads around what it means. So we pulled796together some senior folks who had served in many previous797administrations to walk them through these scenarios. One798scenario, an adversary conducted an attack on critical799infrastructure in the homeland where a dam malfunctioned and800hundreds died. Other scenarios were more complex. We had801attacks on water systems leading to sickness. We had attacks on802power plants leading to deaths at hospitals and from exposure803to cold.804    These games revealed a stark conclusion. Our participants805were confused, spinning their wheels. They had comments like,806well, we should use a proportional response as soon as we807figure out what a proportional response is. These are very808smart people who have served at high levels of Government. This809is just a hard problem they were trying to grapple with. They810lack a shared framework and a coherent viewpoint on what811constitutes an act of war and a proportional response in the812cyber domain. In other words, while our adversaries have fully813incorporated cyber into their foreign policy playbook, we are814still struggling to understand what cyber is and what it should815do.816    So how do we fix it? The U.S. Government needs to establish817a new framework for conceptualizing and responding to cyber818attacks. To address this need, we wrote a recent tome of a819project called ``A Playbook for Winning the Cyber War.'' It's820available on CSIS's website, but here are five key points and821recommendations.822    No. 1, cyber attacks are attacks. If they imperil life,823health, safety, and particularly if they threaten critical824infrastructure in a way that could create a mass casualty825event, the U.S. Government will treat them as they would any826other attack on civilians.827    No. 2, we need to adjust our risk tolerance. Ten years ago,828it made sense to require high-level approval for offensive829cyber action. The tool was new, we didn't really understand it.830But now we have talented, brilliant cyber operators and we need831to let them have their heads. It's really important to flip the832risk calculus. The default answer to a proposed operation833should be yes, and a naysayer should have to prove it is too834risky instead of asking the operators to prove the operation is835safe.836    No. 3, we need to collaborate early. Cyber tools can be837very effective in disrupting an adversary. We saw some of this838in Venezuela just recently. But operators need time to plan.839This is not a tool that just sits on the shelf and you reach840out and grab it when you need it. They need to be incorporated841from the very early stages of planning.842    No. 4, run the playbook. The report lays out these steps in843detail, but here's the key point: be bold. We can retaliate844cyber for cyber, but we don't need to stop there. We need to845match creative policy responses to the pain points of the846particular attacker.847    Then, No. 5, Congress should create and fully fund a cyber848force. I know my colleagues are going to have other things to849say about that, but this is something that I believe will850actually close the gap faster than pretty much anything.851    In conclusion, a dramatic change is needed in the cyber852domain. The Trump administration's recently-released National853Security Strategy did mention offensive cyber operations. I854think that's a positive development. I would suggest a new855policy, cyber first, cyber optional. We are redefining856proportionality in the cyber domain.857    Thank you.858    [The prepared statement of Ms. Harding follows:]859                  Prepared Statement of Emily Harding860                              introduction861    Chairman Ogles, Ranking Member Swalwell, distinguished Members of862the subcommittee, thank you for the opportunity today to testify on863this important topic. The Center for Strategic and International864Studies (CSIS) does not take policy positions, so the views represented865in this testimony are my own and not those of my employer.866    Washington has failed to establish deterrence in the cyber domain,867and our adversaries control the escalation ladder. Historically, U.S.868foreign policy has rested on deterrence, with implied escalation869dominance in any domain. But that foundation has failed in the context870of cyber. U.S. responses to cyber attacks have been muted, and871escalation dominance does not exist.872    The United States' offensive cyber capabilities are strong, perhaps873unmatched. U.S. Cyber Command (CYBERCOM) has repeatedly proven its874capability to disrupt adversary activity, when given the chance. This875demonstrated skill, coupled with overall U.S. strength, makes876deterrence in the cyber domain possible.877    But to actually achieve deterrence, we need a mindset shift. We878need to stop thinking about cyber attacks as inevitable nuisances and879start seeing them for what they are: hostile action against the United880States. Attacks are not always conducted by foreign states--we still881need to draw a distinction between crime and hostile activity--but when882they are, they should be treated as a type of warfare. China, Russia,883Iran, and North Korea do not see a bright line between war and peace.884Instead, they view cyber attacks as fitting on a spectrum of warfare.885For them, competition with the United States is on-going, and low-level886elements of cyber warfare are not only acceptable, they are effective.887            the problem: weak defense and absent deterrence888    U.S. defenses are unacceptably weak, for a set of logical reasons.889The U.S. Government and industry need to put considerable effort and890resources toward making critical infrastructure and Government systems891resilient and ready for this new form of warfare. Systems must be able892to fail, reset, and recover in minutes, not days, with minimal893disruption to essential services.894    We have a long way to go. A series of attacks in 2023 showed the895severity of the gaps in stark relief. In November 2023, a designated896terrorist group that is also the covert action arm of the Iranian897government, the Islamic Revolutionary Guard Corps (IRGC), attacked U.S.898water plants. The stated target was an Israeli company that makes899software for control systems, and the attack was meant to be900retaliation for the war in Gaza. While the intent was to embarrass901Israel, the facts are undeniable: A terrorist group attempted to impair902water delivery to civilians in the United States. Also in late 2023,903the National Security Agency (NSA) and cybersecurity researchers raised904renewed alarm about China's Volt Typhoon group. The attackers burrowed905into U.S. water, power, and port systems across the mainland and in906Guam. These accesses could give Beijing the capability to severely907disrupt daily life, particularly around the U.S. military bases that908would serve as the launching pads for U.S. troops in a Pacific fight.909    These two egregious violations received little attention because910they were cyber attacks, and ``cyber'' has been shunted into a silo of911what tech people do behind the scenes. It's separate, ``technical,''912and an afterthought, not an integrated tool of modern foreign policy.913This mindset is a strategic mistake. While U.S. policy makers allow914these de facto silos, our adversaries are aggressively pursuing an915integrated strategy. While the United States seeks to protect civilians916and carefully selects offensive cyber actions, adversaries are pushing917the envelope.918    Attacks like Iran's and China's should be viewed as part of a919dangerous new phase in cyber warfare, one for which U.S. systems and920policy are ill-prepared. To test how policy makers might respond in a921massive cyber attack on U.S. territory, CSIS ran a series of war games.922The results revealed the likely disastrous confusion that would occur923in a cyber-first conflict, as policy makers lack shared frameworks and924a coherent view on what constitutes an act of war or a proportional925response in the cyber domain. Participants shared comments like ``we926should use a proportional response, as soon as we figure out what a927proportional response is.'' These exercises revealed that decision928makers do not fully understand how cyber attacks fit into traditional929conceptions of the tools of foreign policy. The U.S. Government has no930hope of deterring, defending, and responding unless it begins to931integrate cyber offense and defense into its own national security932strategy. In the Trump administration's recently-released National933Security Strategy, its explicit mention of ``offensive cyber934operations'' as part of a comprehensive U.S. Government response935capability is a positive development.936                     how to fix it: recommendations937    The U.S. Government needs to establish a new framework for938conceptualizing and responding to these kinds of attacks. To address939this urgent need, CSIS created a Playbook for Winning the Cyber War,940which lays out how to shift the mindset, plus actionable steps for941building the larger capacity to fight this modern form of warfare. The942steps are summarized below: creating a new declaratory policy,943rethinking U.S. internal policies, building an international response,944and operationalizing the shift.945Announce the Shift: A New Declaratory Policy on Cyber Warfare946    The first part of a mindset shift is for the U.S. Government to947establish a new declaratory policy with the following key points:948   Cyber attacks are attacks.--If they imperil life, health, or949        safety, and particularly if they threaten critical950        infrastructure in a way that could create a mass casualty951        event, the U.S. Government will treat them as they would any952        other attack on civilians.953   The United States can and will use all elements of state954        power to effectively defend the homeland against any threat, in955        any domain.--Further, the United States prides itself on956        protecting innocent civilians, not targeting them, so it957        refuses to target civilian critical infrastructure. Therefore,958        a proportional response to a cyber attack on our critical959        infrastructure would be severe and likely include economic or960        military measures.961   The United States will assume any cyber attack on critical962        infrastructure has a destructive intent and respond963        accordingly.964Internalize the Shift for U.S. Decision Makers965    Redefine proportionality and escalation to include the big picture.966Policy makers' view of proportionality must expand beyond the most967recent incident and consider the aggregate costs of a pattern of968attacks, the long-term economic and security consequences of those969attacks, and the message sent by inaction. A new policy, which could be970called ``cyber first--cyber optional,'' must begin with explicit971principles that the United States is redefining proportionality in the972cyber domain, bolstering defense, and putting adversaries on notice973that in the future the United States will retaliate for the overall974pattern of behavior, not any one attack in isolation, and will use all975tools at its disposal. A cyber response to a cyber attack is an option,976but far from the only option.977Take the Shift International978    Define international norms of behavior to establish a clear979baseline for future action. This is a worthwhile exercise, even if many980states are likely to ignore those norms. Defining the norms lays the981groundwork for deterrence, because it reduces uncertainty around action982when those norms are violated. Not just the statement, but the983demonstration of will is critical to deterrence. A strong U.S. and984allied response to the first cyber attack after the declaratory policy985goes into place will help set a new tone.986Operationalize the Shift987    Evolve offensive operations to operate as a strategic whole. Cyber988policy plays a late, minor supporting role to the main characters in989foreign policy. The needed evolution, then, depends on two actions: (1)990sliding risk tolerance far higher, freeing operators to do more as the991opportunity arises, and (2) shifting planning far to the left on the992time line, incorporating cyber tools in the early stage policy planning993process. Then, policy makers will be ready to run a new, more robust994playbook to win the cyber war.995    First, adjust risk tolerance. A shift toward a higher risk996tolerance for rapid action is essential for a more flexible, aggressive997approach. Cyber offense must combine long-term planned campaigns and998instant opportunism. A large campaign is essential to create a coherent999long-term approach, but within that campaign, operators must be1000prepared to seize upon a vulnerability in the rare moment it appears.1001Ideally policy makers would flip the risk calculus: The default answer1002to a proposed operation should be ``yes,'' and a naysayer must prove it1003is too risky instead of asking the operators to prove the operation is1004safe.1005    Second, collaborate early. Cyber, in its relative newness, often1006gets relegated to a last-minute add-on to an operational plan instead1007of playing an integrated role in a larger campaign. This approach can1008allow cyber activity to contribute somewhat, but only on the margins.1009Instead, planners should incorporate cyber operators into early stage1010planning, particularly for contingency planning against a peer1011competitor. If developed early enough, cyber tools can distract and1012weaken an adversary, serving as a force multiplier for military and1013diplomatic action. Being ready to capitalize on lucky opportunities1014takes months of research, planning, and prepositioning. If cyber tools1015are to be available in moments of acute need, operators need lead time1016to plan.1017    This evolved model could be imagined as an octopus. Offensive cyber1018tools, at their best, are flexible, inventive, and opportunistic, akin1019to how an octopus hunts in the wild. Cyber offense must combine long-1020term planned campaigns and instant opportunism--like an octopus's1021central brain and tentacles. An octopus camouflages itself perfectly,1022uses its tentacles to explore nooks and crannies, and squeezes into1023impossibly small corners to wait for its prey. Further, each tentacle1024acts independently but also as part of a whole. The central nervous1025system guides the effort, but a brain in each tentacle manages the1026search. An octopus model for offensive cyber operations might include1027strategic guidance from the NSC; interagency campaign planning; a1028forward-leaning approach to exploration and opportunism; and additional1029delegated responsibility to NSA, CIA, and CYBERCOM for execution of1030low-and moderate-risk missions.1031    With these pieces in place, run the playbook. CSIS's report lays1032out these steps in detail, but the main point is this: Be bold. Match1033creative policy responses to the pain points of the particular1034attacker. Demonstrate that the United States will view a cyber attack1035that causes damage as just as serious as a kinetic attack.1036Recommendations for Congress1037    The following Congressional actions can bolster cyber offensive1038capability, bolster domestic defense, and help create much-needed1039deterrence:1040   Create and fund a new Cyber Force.--The cyber domain needs1041        its own service, heavily weighted toward reserve forces, to1042        recruit and retain the best cyber talent from the private1043        sector.1044   Fund cybersecurity.--Congress should consider funding much-1045        needed capital upgrades in Government networks, allow more1046        flexible spending for cybersecurity improvements, and require1047        improved reporting and greater accountability for weak cyber1048        defense inside Government. They should also consider creating a1049        combination of funding streams (carrots) and consequences1050        (sticks) for critical infrastructure providers to significantly1051        improve their resilience against attacks.1052   Protect industry cyber fighters.--Treat the private sector1053        as real partners. Put in place protections for cyber operators1054        who act in conjunction with the U.S. Government, as so many1055        from the private sector did in Ukraine.1056                               conclusion1057    A dramatic change is needed in the cyber domain. Washington1058urgently needs to integrate cyber into its broader foreign policy tool1059kit and determine how cyber activity aligns with larger foreign policy1060actions, including deterrence, proportional response, and international1061norms. In other words, the United States needs a new playbook to1062respond to increasingly disruptive and aggressive cyber attacks. For1063more, see CSIS's A Playbook for Winning the Cyber War.10641065    Mr. Ogles. Thank you, Ms. Harding.1066    I now recognize Mr. Cilluffo.1067    Mr. Cilluffo. It's a mouthful.1068    Mr. Ogles. Cilluffo, my apologies, for 5 minutes.10691070 STATEMENT OF FRANK CILLUFFO, DIRECTOR, MC CRARY INSTITUTE FOR1071 CYBER AND CRITICAL INFRASTRUCTURE SECURITY, AUBURN UNIVERSITY10721073    Mr. Cilluffo. I am in violent agreement with my fellow1074panelists here and really happy to see that you are proposing1075such an important topic and one that I think is going to1076generate a lot more attention in the days ahead.1077    In addition to this question, the fundamental one, we1078really do have to start answering what that requires of our1079authorities, institutions, capabilities, and partnerships. Just1080last month, my institute released a significant report on many1081of these topics on offense, deterrence, and strategic1082competition. I co-chaired that, had the privilege of co-1083chairing that alongside Chris Inglis and General Frank McKenzie1084as well as at Tom Bossert. I suggest everyone take a look at1085that when you get a chance.1086    The summary, the conclusion was pretty straightforward. The1087status quo ain't cutting it and our adversaries are not1088operating episodically. They are operating persistently. Cyber1089space is an always on, always contested domain. China in1090particular, as my panelists have mentioned and you, Mr.1091Chairman, teed up in the very beginning, demonstrated this1092long-term strategic intent. Campaigns such as Flax, Volt, and1093Salt Typhoon are all really serious on their own. Taken1094together, however, they form a perfect storm. It's the pre-1095positioning at a time of their choosing that I think in U.S.1096critical infrastructure that is a line that has been crossed.1097Russia's experience in Ukraine reinforces the point,1098underscoring a hard truth. Our adversaries already view cyber1099space as a domain of continuous engagement.1100    Some of our approaches to tackle this, I'm a big proponent1101of National Security Presidential Memorandum 13, NSPM 13, and1102the adoption of the defend forward approach was an important1103shift, enabling greater agility and allowing U.S. Cyber Command1104to disrupt adversary campaigns before they reach our shores.1105It's generated some genuine real operational benefits, but in1106itself it's not enough.1107    We've also seen more recently how cyber capabilities can be1108integrated with other instruments of national power for1109strategic effect and signaling. The Chairman of the Joint1110Chiefs, publicly discussing the role cyber played in Absolute1111Resolve, by all accounts an exquisite operation targeting the1112Maduro regime in Venezuela, makes this clear.1113    While public acknowledgment is relatively new, it is1114consequential. It underscores that cyber is no longer1115peripheral, but integrated, operational, and central to modern1116deterrence, and can shape the behavior not only of those1117targeted, but all those watching. At the same time, these1118advances surface unresolved questions about oversight,1119interagency coordination, escalation risk, and I'm very much1120with Dr. Lin is in terms of escalation, as well as the1121interaction between cyber operations abroad and defensive1122responsibilities at home. These are not academic debates. They1123go to the heart of democratic accountability and strategic1124stability.1125    One point bears emphasis. Offensive cyber operations alone1126are not sufficient to protect the homeland. When cyber action1127is taken abroad, it must be paired with strong domestic1128defense, led by DHS and CISA working with SLTT and private-1129sector partners to improve resilience across our critical1130infrastructure. But a purely defensive posture is equally1131insufficient, if not more so. Simply put, we cannot firewall1132our way out of this problem.1133    Deterrence in cyber depends on the interaction between1134offense, defense, resilience, and credibility over time, not1135reactive episodic responses built for a different era. In1136essence, we've let the adversaries define our strategy. We1137react and that becomes our strategy. That's unacceptable.1138    This brings me to the private sector. The vast majority, as1139we know, of critical infrastructure is owned and operated by1140the private sector. These entities are already on the front1141lines, yet are too often treated as passive victims rather than1142essential partners. Many of the most relevant capabilities from1143threat intelligence, rapid response, large-scale mitigation,1144reside in technology companies, cloud providers, and1145infrastructure owner-operators. In practice, the private sector1146already conducts elements of active defense. What remains1147unresolved is how far they should be permitted to go, under1148what legal authorities, and with what safeguards. Clarifying1149the legal and policy boundaries around lawful, proportionate,1150and well-governed active cyber defense would strengthen1151collective defense, raise adversary costs, and reduce ambiguity1152while preserving oversight and civil liberties.1153    There are a number of promising steps under way, from1154CISA's JCDC to NSA's CCC. But these efforts have to be1155reinforced by clear doctrine, modernized authorities, and1156governance structures. Net stakes are high as adversaries1157deepen their access into American networks. The United States1158must decide whether to remain constrained by outdated1159frameworks or adapt the realities of 21st Century conflict.1160Congress has a critical role to play in that recalibration by1161modernizing authorities, strengthening oversight, and ensuring1162our institutions can operate with both agility and1163accountability.1164    Mr. Chairman, thank you for the opportunity to join you1165today.1166    [The prepared statement of Mr. Cilluffo follows:]1167                  Prepared Statement of Frank Cilluffo1168                       Tuesday, January 13, 20261169    Good morning, Chairman Ogles, Ranking Member Swalwell, and1170distinguished Members of the subcommittee. Thank you for the1171opportunity to testify today on behalf of the McCrary Institute for1172Cyber and Critical Infrastructure Security at Auburn University. I1173appreciate the subcommittee's leadership in examining how the United1174States can more effectively deter and disrupt malign cyber activity1175targeting the homeland.1176    Last month, the McCrary Institute released a task force report1177directly relevant to today's hearing, U.S. Cyber Policy: Offense,1178Deterrence, and Strategic Competition. I had the privilege of co-1179chairing this effort alongside Chris Inglis, our Nation's first1180National Cyber Director; General Frank McKenzie, former commander of1181U.S. Central Command; and Tom Bossert, former assistant to the1182President for homeland security. This report draws on extensive1183operational, policy, and intelligence experience of our national1184security and law enforcement task force to examine how U.S. cyber1185policy must adapt to persistent strategic competition.1186    At a time when our geopolitical adversaries and transnational1187criminal organizations across the world are creating digital havoc, the1188committee is rightly asking a fundamental question: how can the United1189States more credibly deter adversaries in cyber space and what does1190that require for homeland security and domestic preparedness? The1191question is especially urgent in the age of AI--a topic I know you are1192examining carefully--which is accelerating both adversary tradecraft1193and the speed at which cyber operations can translate into real-world1194effects. I appreciate your understanding that offensive cyber1195capabilities have inherently defensive implications for cybersecurity1196in the homeland.1197    This challenge has grown more acute as adversaries expand their1198capabilities, embed disruptive access within U.S. critical1199infrastructure, and exploit gaps between military, intelligence, law1200enforcement, and civilian authorities. What began in the early 2000's1201as an intelligence-driven model centered on clandestine collection has1202evolved into a contested operational environment where cyber effects1203are now entwined with traditional military planning, economic coercion,1204and crisis escalation dynamics. We saw this dynamic recently in the1205U.S. operation in Venezuela, where reporting indicates cyber activity1206was layered with space, military aircraft, unmanned systems, and1207intelligence assets.1208    The United States must now navigate this environment using1209frameworks that were not designed for the scale, persistence, or tempo1210of today's threats, while relying on an organizational structure that1211reflects both institutional strengths and enduring policy and1212operational friction. The result is a posture that too often emphasizes1213episodic responses rather than sustained advantage in an environment1214defined by continuous contact.1215    Over the last decade, U.S. adversaries--including Russia, China,1216Iran, and North Korea--have steadily expanded the scope,1217sophistication, and ambition of their offensive cyber operations. Among1218them, China has demonstrated the clearest long-term strategic intent.1219Beijing's campaigns targeting U.S. Government networks, defense1220industrial base entities, and privately-owned critical infrastructure1221underscore a preference for persistent access rather than short-term1222disruption. These operations are designed less for immediate disruption1223than for strategic leverage--pre-positioning capabilities that could be1224exercised to coerce, deter, or delay U.S. decision making during a1225crisis.1226    Recent campaigns such as Volt Typhoon and Salt Typhoon represent a1227significant evolution in this approach. Rather than focusing solely on1228data theft, these operations target operational technology and1229infrastructure networks, blurring the line between espionage and1230preparation of the battlefield. This activity should be understood not1231as isolated incidents, but as part of a broader strategy of continuous1232engagement aimed at shaping the strategic environment well in advance1233of conflict.1234    Russia, for its part, has demonstrated how cyber operations can be1235integrated directly into military campaigns. In Ukraine, destructive1236malware, information operations, and cyber-enabled disruption of1237critical services accompanied conventional military assaults. These1238actions reinforce the reality that adversaries increasingly view cyber1239space as a domain that is always ``on''--one in which access,1240influence, and coercive leverage are cultivated over time rather than1241activated only at the moment of crisis.1242    Against this backdrop, U.S. cyber operational policy has undergone1243an important shift. For many years, offensive cyber activity was1244tightly centralized, often requiring extensive interagency deliberation1245and senior-level approval. This changed with the issuance of National1246Security Presidential Memorandum 13 in 2018, which allowed the1247President to delegate greater operational decision-making authority to1248designated organizations, most notably U.S. Cyber Command. At the same1249time, the Department of Defense formally adopted the concept of1250``defend forward,'' recognizing that the United States must operate1251persistently in foreign networks to disrupt adversary campaigns before1252they reach U.S. targets.1253    This shift has yielded meaningful operational benefits. However, it1254has also reignited unresolved questions regarding oversight,1255intelligence equities, and the strategic risks associated with1256persistent engagement. These are not theoretical concerns. They go to1257the heart of how the United States balances operational agility with1258democratic accountability and strategic stability. Moreover, these1259evolutions in how offensive cyber is conducted has created implications1260for our defensive posture and how the Federal Government works with1261stakeholders like the private sector to prepare for and defense against1262threats.1263    Importantly, offensive cyber operations alone are not sufficient to1264protect the homeland. When cyber action is taken abroad, it is1265incumbent upon the Department of Homeland Security--particularly1266through the Cybersecurity and Infrastructure Security Agency--to defend1267domestic networks and work with critical infrastructure owners and1268operators to improve resilience across sectors. This mission is1269essential to homeland security, economic stability, and public1270confidence. Our adversaries increasingly seek to impose domestic costs1271as a means of deterring the United States from advancing its interests1272abroad or honoring its commitments to allies.1273    To meet these challenges, the United States must strengthen the1274doctrinal, legal, and organizational foundations of its cyber strategy.1275This includes clarifying interagency roles and responsibilities,1276improving mechanisms for information sharing with trusted private-1277sector partners, and ensuring that resilience and security are treated1278as core elements of deterrence--not afterthoughts. It also requires1279refining deterrence frameworks to account for adversaries who1280deliberately blend espionage, coercion, influence operations, and pre-1281positioning activity below the threshold of armed conflict.1282    But just as offense alone is insufficient, so too, would be a1283purely defensive posture. Simply put: We cannot firewall our way out of1284this problem. U.S. cyber policy must move beyond reactive, episodic1285responses and toward a durable posture capable of operating effectively1286in an era of continuous foreign intrusion. We should not rely on1287authorities and assumptions built for a different era. Strategic1288competition in cyber space demands sustained engagement, clearer1289governance, and a realistic appreciation of how offensive and defensive1290actions interact to shape adversary behavior.1291    The vast majority of critical infrastructure is owned and operated1292by private entities, placing them on the front lines of strategic1293competition in cyber space. Yet current policy too often treats these1294actors as passive victims rather than as potential partners in defense.1295As our report notes, effective deterrence in cyber space depends not1296only on Government action, but on enabling trusted private-sector1297operators to take timely, proportionate, and lawful steps to detect,1298disrupt, and eject malicious activity from their networks. Clarifying1299the legal and policy boundaries around active cyber defense--while1300preserving strong oversight and safeguards--would strengthen collective1301defense, raise adversary costs, and reduce the burden on Federal1302authorities alone to secure the homeland.1303    Many of the capabilities relevant to modern cyber conflict, such as1304threat intelligence collection, rapid incident response, and the1305ability to deploy deception or interdiction tools at scale, reside not1306within Government networks but inside major technology firms, cloud1307providers, and critical infrastructure operators. Private entities1308already perform elements of active defense by hunting adversaries1309within their systems, deploying beacons, mitigating malicious traffic,1310and collaborating with Federal agencies during botnet takedowns.\1\1311---------------------------------------------------------------------------1312    \1\ ``Into the Gray Zone: The Private Sector and Active Defense1313Against Cyber Threats,'' October 2016, Active Defense Task Force,1314Center for Cyber and Homeland Security, The George Washington1315University, accessed December 6, 2025, (https://cpb-us-e2.wpmucdn.com/1316wordpress.auburn.edu/dist/8/7/files/2021/01/into-the-gray-zone.pdf).1317---------------------------------------------------------------------------1318    Although these actions fall short of offensive operations in the1319traditional sense, they demonstrate how the private sector can seek to1320shape adversary behavior and deny operational freedom through forward-1321leaning measures that are lawful, risk-calibrated, and technically1322sophisticated. What remains unresolved is how far private actors should1323be permitted to go when defending their networks from state-sponsored1324threats, and how the Government should structure oversight, liability1325protections, and coordination frameworks to ensure that such activity1326enhances national security without triggering escalation or infringing1327on civil liberties. As adversaries increasingly target U.S. companies1328to gain strategic leverage, the question is not whether the private1329sector will play a role in active cyber defense, but whether that role1330will be integrated into a coherent national strategy or continue to1331evolve in an ad hoc and legally ambiguous ``gray zone.''1332    Initiatives such as CISA's Joint Cyber Defense Collaborative and1333the NSA's Cybersecurity Collaboration Center are positive steps toward1334operationalizing collaboration between Government and the private1335sector. It is vital that critical infrastructure owners and operators1336have the right relationships and partners in Government to understand1337the threat and improve resiliency. This is the sort of active cyber1338defense we need to build on, in conjunction with a more assertive1339offensive stance.1340    It is a national security imperative that Federal, State, local,1341Tribal, territorial, and private-sector partners cooperate in new and1342robust ways to minimize potential future operational disruptions and1343sensitive data compromises. Last, the threat posed by the adversaries1344like the Typhoon actors is not merely a cybersecurity challenge but1345should be looked at as a broader threat to the United States and its1346allies. As the PRC develops new ways to undermine U.S. national1347security, it is critical to adopt a whole-of-Government approach to1348countering such threats.1349    The stakes are significant. As adversaries deepen their access into1350American networks, the United States must decide whether its cyber1351strategy will remain constrained by outdated frameworks or evolve to1352reflect the realities of twenty-first-century conflict. Congress has a1353critical role to play in that recalibration--by modernizing1354authorities, strengthening oversight, and ensuring that our1355institutions are equipped to operate with both agility and1356accountability.1357    Mr. Chairman, this concludes my prepared remarks. I look forward to1358your questions and to working with the subcommittee to strengthen the1359security and resilience of the United States in cyber space.13601361    Mr. Ogles. Thank you, Mr. Cilluffo.1362    I recognize Mr. Bagley to summarize his opening statement,13635 minutes.13641365  STATEMENT OF DREW BAGLEY, CHIEF PRIVACY OFFICER, CROWDSTRIKE13661367    Mr. Bagley. Chairman Ogles, Ranking Member Thompson,1368Members of the subcommittee, thank you for the opportunity to1369testify before you once again.1370    Throughout my career, I've seen first-hand the challenges1371and opportunities of improving American cybersecurity from my1372work in the private sector, Government, and academia. For more1373than a decade at CrowdStrike, I've had a front row seat to our1374defense of critical entities. This includes many components of1375the U.S. Federal Government, major technology companies,1376financial services firms, 43 of 50 U.S. States, critical1377infrastructure, and thousands of small- and medium-sized1378businesses. We defend America.1379    Today, unfortunately, many organizations remain undefended,1380vulnerable to cyber attacks, the scope and severity of which1381continues to increase. Simply put, threat actors are still1382operating at scale, still operating with limited consequences,1383and still all too often achieving their objectives. They are1384seeing a clear return on investment. Their risk calculus still1385shows favorable outcomes. To make durable progress, we must1386work in a concerted fashion to change each of these conditions.1387    The role for offense in confronting cyber threats is1388textured. I've outlined several elements in my written1389testimony, including the Enterprise Defender's threat hunt1390across their own systems, resources, and data. This is a1391proactive approach, sometimes called active defense, rather1392than offense per se, but it's one of the most effective1393techniques to confront targeted attacks.1394    Some suggest victims or their representatives should hack1395back. I've shared the history of this debate in my written1396testimony. But in short, hack-back operations risk1397revictimization and collateral damage. On-going investigations1398could be disrupted and retaliation could lead to waves of1399geopolitical escalation. For these reasons, offense is best1400left to professionals with relevant authorities, deconfliction1401processes, and clear oversight. A federated regime for hacking1402back that lacks these attributes probably creates more problems1403than it solves.1404    Let me state plainly that defense remains foundational.1405Even those who wish to increase offense must recognize the1406value of robust defenses. New threat actors emerge routinely1407with different capabilities and motivations. Economic and1408geopolitical conditions change, often for the worse. Having1409defenses in place amid this changing terrain is essential and1410effective.1411    A core prescription for better confronting cyber threats is1412more focused, more persistent, and more tightly orchestrated1413campaigns disrupting threat actors and those who support them.1414JCDC, in concert with industry, should establish a most wanted1415style list. As a community, we should work our way down that1416list rapidly, performing disruptions and takedowns to frustrate1417adversaries' objectives and prevent them from reaching scale.1418    For criminal activities, we should apply laser focus on1419preventing monetization. Terrific work is done today, just not1420at a high enough tempo. Still, there remains a role for1421deterrence. Cyber attacks are caused by adversaries. Threats1422themselves are not deterrable. The people, institutions, and1423nations behind them often are. Given that their motivations1424vary so widely. There is no singular approach to deterrence1425that could succeed, but we should still use all available1426tools, including noncyber tools.1427    Policy makers face challenges in considering how to1428resource defense versus offense. Ultimately, it's probably1429reasonable to conceive of security investments as a portion of1430overall IT spending and reasonable to align offensive1431investments as a portion of overall military spending. AI1432impacts these considerations. AI provides threat actors with a1433new class of systems to target and acts as an accelerant to1434automate their TTPs.1435    AI itself is under threat from adversaries, meaningfully1436increasing the attack surface when left unprotected.1437Fortunately, AI detection and response solutions can prevent1438prompt injection, jailbreaks and model manipulation attempts.1439Agentic AI is already revolutionizing security operations to1440assist defenders.1441    To confront these challenges, I recommend the following.1442First, public and private organizations must take reasonable1443actions to defend themselves, with a focus on threat hunting1444and identity security.1445    Second, the cybersecurity community should radically1446increase the operational tempo of malicious infrastructure1447disruptions and takedowns. Given its stakeholder engagement1448functions, CISA should be central to coordinating public and1449private actors to this end.1450    Third, Federal law enforcement, along with Title 10 and1451Title 50 entities, should work to increase deterrence.1452    Finally, we must defend AI systems and leverage AI to1453defend enterprises.1454    Thank you again for the opportunity to testify today and I1455look forward to your questions.1456    [The prepared statement of Mr. Bagley follows:]1457                   Prepared Statement of Drew Bagley1458                            January 13, 20261459    Chairman Ogles, Ranking Member Swalwell, Members of the1460subcommittee, thank you for the opportunity to testify today.1461Throughout my career, I have seen first-hand the challenges and1462opportunities of improving American cybersecurity from my work in the1463private sector, Government, and academia. For more than a decade at1464CrowdStrike, a leading cybersecurity company, I have had a front-row1465seat to cybersecurity innovation while building our privacy and public1466policy programs and advising customers around the globe. Prior to that1467I worked at the intersection of law and technology in the FBI's Office1468of the General Counsel. I previously taught at universities in the1469United States and Europe, and currently serve as an adjunct professor1470in American University's cybersecurity policy program.1471    As a leading U.S. cybersecurity company, CrowdStrike has a useful1472and often quite textured vantage point on malicious activities in cyber1473space. Protecting organizations with our cybersecurity technology,1474threat intelligence, professional services offerings, and incident1475response work, we confront a full range of cyber threats. We defend1476many components of the U.S. Federal Government and serve as a1477commercial cybersecurity provider for major technology companies, 8 of1478the top 10 financial services firms, and 43 of 50 U.S. States;\1\ as1479well as all manner of critical infrastructure entities and small and1480medium-sized businesses. We defend America.1481---------------------------------------------------------------------------1482    \1\ State and Local Governments, CrowdStrike. https://1483www.crowdstrike.com/en-us/solutions/state-local-government/1484---------------------------------------------------------------------------1485    Nation-states are relentless. In parallel, there is a1486democratization of destruction whereby those perpetrating cyber attacks1487no longer need the knowledge, resources, or time once required to1488execute high-impact attacks--indeed, adversaries can ``vibehack'' their1489way to success. Moreover, because legitimate credentials may be1490purchased in on-line criminal forums, along with the tools to deploy1491ransomware and malware, the means to attack are available for those who1492merely have the intent. As adversaries evolve, defenders are most1493successful when they adapt. This holds true for our digital ecosystem1494in general. As we adopt new technologies, features and abilities, we1495must adapt how we secure them. Today, this means we must think about1496how we detect, prevent, and defend an attack surface that now includes1497AI.1498          to what extent is america secure from cyber threats?1499    America remains vulnerable to cyber attacks, and the scope and1500severity of which continues to increase.\2\ To be clear, some1501organizations are effectively defending themselves. Bright spots1502include broader adoption of modern endpoint and managed security1503solutions in public and private enterprises. Still, organizations face1504an array of attacks targeting cloud environments, Software as a Service1505(SaaS) applications, and identities.1506---------------------------------------------------------------------------1507    \2\ America's technology infrastructure consists of an array of IT,1508OT, telecommunications, cloud and digital services, cyber-physical1509systems, and the data and identity layers that connect them all. These1510systems are managed by organizations large and small, well-resourced1511and under-resourced.1512---------------------------------------------------------------------------1513    Under-resourced public institutions and small and medium-sized1514businesses are particularly vulnerable. But high-profile attacks over1515the past few years from China, notably the VANGUARD PANDA/Volt Typhoon1516attacks targeting critical infrastructure and the OPERATOR PANDA/Salt1517Typhoon attacks targeting telecommunications entities have raised the1518most acute concerns from a national security perspective. Despite1519significant investment in cybersecurity measures, the status quo isn't1520working.1521                           what's gone wrong?1522    Simply put: threat actors are still operating at scale, still1523operating with limited consequences, and still all-too-often achieving1524their objectives. They are still seeing a clear return on investment.1525They are still assessing a risk calculus that shows favorable outcomes.1526To make durable progress, we must work in a concerted fashion to change1527each of these conditions. (I describe how below.)1528     what's the role for ``offense'' in confronting cyber threats?1529    In the cyber context, offense can mean a number of different1530things. At a high level, from a law enforcement or industry lens,1531threat actor infrastructure disruptions might include seizing malicious1532domains, servers, or relay infrastructure; asserting control over1533hosted malware kits or botnets; or off-lining darkweb forums or sites1534used to anonymously host pilfered information. Importantly, denying an1535adversary the ability to monetize their efforts is also achievable. At1536a minimum, these sorts of operations require careful planning, pose1537coordination challenges, and may raise questions about burden sharing.1538    Offense from a military or intelligence lens might imply breaching1539foreign organizations or otherwise attacking them, such as through1540denial-of-service or destructive attacks. The latter can focus on1541deleting data, destroying IT systems, or causing ``effects'' in the1542real world, such as by manipulating operational technology (OT) systems1543and thus associated infrastructure.1544    At the level of the enterprise, we advocate that defenders threat1545hunt or work with a partner who can do it on their behalf. This1546essential practice can be performed on each organizations' own systems,1547resources, and data.\3\ Therefore, it's mainly a proactive approach--1548sometimes called active defense--rather than offense per se. But threat1549hunting is one of the most effective techniques we have as an industry1550to confront targeted attacks.1551---------------------------------------------------------------------------1552    \3\ As a vendor, we facilitate sharing of visibility in threat1553hunting operations at the sector level, national level, and1554international level through our threat intelligence reporting.1555---------------------------------------------------------------------------1556  should cyber-attack victims or their representatives ``hack back''?1557    When the ``hack back'' policy discourse started in earnest about 151558years ago, it was in response to multiple reports of egregious1559campaigns where adversaries had, for example, breached a series of1560organizations like National Labs or defense contractors, exfiltrated1561gigabytes of sensitive data, left that data on a fairly exposed staging1562server, and collected it later at their convenience. In that type of1563scenario, particularly where the victim(s) possessed relevant forensic1564artifacts and telemetry, the inability to legally ``do something,''1565often meaning to delete the only copy of the stolen data, caused a1566great deal of consternation.1567    Today, attacks are generally far more sophisticated, leveraging1568compromised accounts of legitimate (e.g., SaaS) applications;1569transient, ephemeral, or shared cloud environments; and other1570obfuscation techniques. In this environment, a policy framework that's1571more conducive to ``hack back'' operations carried out by a broad array1572of actors could yield revictimization, collateral damage, and impacts1573to innocent victims. On-going investigations could be disrupted.1574Retaliation could lead to waves of escalation, potentially along1575geopolitically salient lines. For these reasons, we share the view that1576offense is best left to professionals with relevant authorities,1577deconfliction processes, and clear oversight. A democratized regime for1578hacking back that lacks these attributes probably creates more problems1579than it solves.1580                        is defense discredited?1581    No. Defense is foundational. Even those who wish to increase1582offense must recognize the value of robust defenses. Even if a city1583announced an enormous and well-resourced crackdown on crime, homeowners1584should still, rationally, take the basic steps of shutting and locking1585their doors at night. New threat actors emerge routinely with different1586capabilities and motivations. Economic and geopolitical conditions1587change, often for the worse. Having defenses in place amid this1588changing terrain is essential. Further, to the extent policy dictates1589that offensive actions will increase, that should lead to a heightened,1590rather than reduced, focus on defense.1591    In the kinetic world, it is not uncommon to categorize ``soft''1592targets versus ``hard'' targets. Simply put, organizations that have1593hardened themselves with modern approaches are more secure and have1594drastically reduced the likelihood of suffering a high-impact event.1595Those that haven't remain vulnerable not only to infiltration but to1596existential impacts in the face of an incident.1597    It's often said that ``mom-and-pop'' operations can't be expected1598to singlehandedly defeat the People's Liberation Army. That's true.1599National-level policies and capabilities are needed to create1600conditions of reduced threats. But, as with other threats, hazards, and1601risks, all organizations should take reasonable steps to defend1602themselves.1603          what's the role of deterrence in defeating threats?1604    Mechanically, deterrence is achieved either through denial (i.e.,1605an adversary realizes an attack won't be effective, so they apply their1606energies elsewhere) or through a credible threat of retaliation.1607Retaliation can be intra-domain (i.e., also a cyber attack) or cross-1608domain (e.g., leveraging a law enforcement or conventional military1609capability).\4\1610---------------------------------------------------------------------------1611    \4\ For our part, the core technologies we produce--namely the1612Falcon platform and associated capabilities--essentially seek to1613support denial. Our threat intelligence products, among other things,1614can support threat actor identification, which can strengthen targeting1615for organizations with enforcement and defense missions.1616---------------------------------------------------------------------------1617    Cyber attacks are caused by adversaries. Threats themselves aren't1618deterrable; the people, institutions, and nations behind them often1619are. The people in question are military or political figures. Or1620anonymous criminals. They might be rich or poor; empowered or1621desperate; or seeking fame or seeking to effectuate a radical political1622or social cause. They might be, in the political science sense,1623rational or irrational actors. Given that their conditions and1624motivations vary so widely, there is no singular approach to deterrence1625that could succeed.1626    Deterrence is difficult to measure. Clearly, a significant number1627of adversaries are not presently deterred. As a community, we must1628strengthen deterrence as part of a holistic approach to cyber defense.1629  how should policy makers think about resourcing defense vs. offense?1630    Unfortunately, a simple 50-50 (or 80-20, or 20-80)-style answer1631here is elusive. But several considerations should guide investments:1632   With respect to defense, organizations should develop1633        realistic, informed threat models and plan to confront those1634        threats.1635   Some amount of investment in security is reasonable. Against1636        today's adversaries, unfortunately, basic hygiene and best1637        practices alone fail. The ability to achieve real-time1638        visibility, detection, and response across federated IT systems1639        is required for protection and threat hunting. For1640        organizations with resource constraints, clear illustrations1641        depicting how investments map to reduced risks are typically1642        most persuasive to planners, be they management, boards, or1643        appropriators.1644   Efficacy is often more important than resourcing overall.1645        Unfortunately, in today's public policy debates, there are many1646        false proxies for assessing whether cyber defenses are1647        effective. Simply because the Federal Government, a particular1648        sector, or an individual organization spends a certain dollar1649        amount on security does not mean it is buying the best1650        technology, deploying it on the most critical assets, or1651        operating it correctly. Similarly, and especially in1652        government, technology with the lowest price tag--or that is1653        included as part of an add-on bundle--is unlikely to deliver1654        the same security outcomes.1655   Ultimately, it's probably reasonable to conceive of security1656        investments as a portion of overall IT spending (best practices1657        for which may vary, but are sometimes assessed by reputable1658        technology research advisory firms).1659    Similarly, at a national level, it's appropriate and realistic for1660institutions operating under Title 10 and Title 50 authorities to1661resource offensive missions. But rather than defining resourcing levels1662for those activities relative to cyber defense investments, it's1663probably more reasonable for planners to consider cyber offense1664relative to other offensive capabilities (e.g., kinetic options) that1665might achieve a similar outcome.\5\1666---------------------------------------------------------------------------1667    \5\ Whether other means to attain intelligence or other means to1668achieve effects.1669---------------------------------------------------------------------------1670 what roles, missions, and authorities must change to better confront1671                             cyber threats?1672    Our core prescription is bringing to bear more focused, more1673persistent, and more tightly-orchestrated campaigns disrupting threat1674actors and those who support them. This means leveraging more technical1675operations, erecting more barriers to success, and leveraging all1676available tools of statecraft (i.e., cross-domain responses) to1677pressure adversaries, dampen their success, and prevent them from1678operating at scale.1679    Consider first financially-motivated attacks, such as ransomware.1680CISA, probably acting through JCDC, should consult with industry to1681determine which groups are most problematic (either because of scale,1682targeting practices, or some other criteria) and establish a ``Most1683Wanted''-style list. CISA should ascertain targeting information about1684those responsible from stakeholders.\6\ They should orchestrate actions1685with relevant law enforcement partners (or, where appropriate,1686intelligence community partners) to use disruption authorities and,1687where possible, simultaneous enforcement actions to target those1688responsible. They should orchestrate actions with partners at Treasury1689and the private-sector financial ecosystems to complicate or prevent1690cash-outs or monetization of hacking. They should leverage industry1691partners who can contribute along the way by sharing visibility and1692better enforcing their own terms of service, given that most firms1693already contractually prevent criminality and abuse.1694---------------------------------------------------------------------------1695    \6\ Our sense is that CISA possesses all relevant authorities to1696perform these actions. National Defense Authorization Act for Fiscal1697Year 2021, Pub. L. No. 116-283,  1715 (Joint Cyber Planning Office),1698134 Stat. 3388 (2021).1699---------------------------------------------------------------------------1700    Similar coordination must take place focused on nation-state1701actors. In those cases, there might be less focus on disrupting1702monetization and law enforcement actions,\7\ and more on Title 10 and1703Title 50 actions. Still, particular actions should be prioritized in1704consultation with relevant stakeholders and executed with great1705frequency.1706---------------------------------------------------------------------------1707    \7\ Although not in the case of national state actors engaged in1708cyber crime to fund the regime, such as the DPRK, and/or operating from17093rd-party countries where U.S. and allied nations have law enforcement1710reach.1711---------------------------------------------------------------------------1712    Everything I've described here does take place--just not nearly1713enough. It's really a matter of will for decision makers to demand that1714this sort of thing, which happens periodically, takes place1715routinely,\8\ and on the highest-impact targets.1716---------------------------------------------------------------------------1717    \8\ In July 2017, we called on the cybersecurity community to1718``bring more energy to this fight. A serious commitment from law1719enforcement and the security community to attempt to take down one1720botnet every week would be a `game changer.' . . . These goals are1721ambitious relative to the status quo, but not impossible. Ultimately,1722focusing on such initiatives would provide a powerful organizing1723principle for decision makers across Government and industry, going1724well beyond botnets and automated threats to catalyze a seismic shift1725in cybersecurity.'' https://www.ntia.gov/files/ntia/publications/1726crowdstrike-20170713.pdf. Sadly, as a community we've never approached1727this scale.1728---------------------------------------------------------------------------1729      how does the advancement of ai impact these considerations?1730    The advancement of AI does not materially impact threat actor1731motivations. It does, however, provide threat actors with a new class1732of systems to target, new infrastructure to leverage, and a new1733accelerant to automate their own TTPs. We expect this trend to continue1734as adversaries exploit new tools and adapt to changing conditions.1735    AI itself is under threat from adversaries, whether its the1736systems, data, or human and non-human identities or the end-user1737platform. This will only increase as AI becomes more ubiquitous and1738disappears into the traditional IT stack, becoming a commonplace part1739of America's digital infrastructure. Much like the need for detection1740and response for the endpoint, network, cloud and identity, AI1741Detection and Response (AIDR) detects and prevents direct and indirect1742prompt injection, jailbreaks, and model manipulation attempts.1743    At its core, cybersecurity is fundamentally a data problem.1744Fortunately, AI--and specifically Agentic AI--which takes bounded1745actions on users' behalf--radically empowers defenders. One of the most1746immediate areas Agentic AI can improve cybersecurity practices is1747leveraging agents to eliminate bottlenecks in the Security Operations1748Center (SOC). By deploying specialized agents to tackle time-intensive1749tasks, security teams can reclaim a speed advantage, close persistent1750labor and response gaps, and shift from reactive to proactive defense.1751Agents can analyze malware, perform certain hunt actions, prioritize1752exposure remediation, and more.\9\1753---------------------------------------------------------------------------1754    \9\ Such agents are central to a profound change that's under way1755now to modernize traditional SOCs for the emerging era of the Agentic1756SOC. A NextGen SIEM capability will enable organizations to leverage1757these agents by exposing them to all relevant security data and1758positioning them to perform workflows like threat hunting and1759remediation.1760---------------------------------------------------------------------------1761                            recommendations1762   Public and private organizations must take reasonable1763        actions to defend themselves. Denying cyber threat actors the1764        ability to achieve their objectives is an important ordering1765        principle for investments in cybersecurity capabilities. How to1766        achieve this will continue to evolve over time in line with1767        technological adoption and adversary techniques. Right now,1768        enterprises should view endpoint detection and response (EDR),1769        threat hunting, identity threat detection and response, SaaS1770        security, and cloud security as high-leverage areas of1771        investment to this end.1772   The cybersecurity community should radically increase the1773        operational tempo of malicious infrastructure disruptions and1774        takedowns that are carried out by government organizations and1775        aided by private-sector support where appropriate (e.g.,1776        information sharing and operational collaboration). In some1777        instances, private actors like IT providers or1778        telecommunications companies can leverage legal processes or1779        their own terms of service to disrupt operations themselves.1780   Given its stakeholder engagement functions, CISA should be1781        central to coordinating public and private actors to this end.1782        This committee can ensure that CISA \10\ is properly focused1783        and resourced to perform this mission. From an oversight1784        perspective, you can ensure it has authorities, talent, and1785        capabilities to maximize its impact.1786---------------------------------------------------------------------------1787    \10\ Organizations operating under Title 10 and Title 501788authorities have a somewhat more complicated resource allocation1789question, [sic].1790---------------------------------------------------------------------------1791   Federal law enforcement, along with Title 10 and Title 501792        entities, should work to increase deterrence. The USG should1793        lead holistic responses to significant adversary actions,1794        leveraging existing authorities in parallel and with speed to1795        deter adversaries and reduce the ROI for their attacks,1796    Thank you again for the opportunity to testify today, and I look1797forward to your questions.17981799    Mr. Ogles. Thank you, Mr. Bagley.1800    Members will be recognized by order of seniority for their18015 minutes of questioning. I now recognize myself for 5 minutes.1802    Again, I want to thank the panelists for being here. This1803is an important topic for us to be really bringing to the1804forefront of kind-of today's conversations and, quite frankly,1805the onslaught of media that we see every single day. When you1806look at the Monroe Doctrine, you know, our dominance in the1807Western Hemisphere, that is seen in the context of borders and1808boundaries. But now with the cyber and the AI landscapes, that1809would also include those boundaries and those borders.1810    So as we look to our capabilities, clearly Mr. Bagley, we1811need a great defense, threat hunting, and all the such. But1812when you look at the Typhoon clusters, we now are going to have1813to go on offense. We have to make the pain points significant1814for our adversaries to understand that if you breach the Monroe1815Doctrine, that if you break our hemisphere, our borders, our1816boundaries, there will be a price.1817    Mr. Lin, I want to start with the current state of play1818today. Offensive cyber capabilities exist across multiple parts1819of the U.S. Government under different authorities like Title182010 and 50 with varying degrees of integration with the private1821sector. As we look ahead, as the U.S. Government considers a1822more forward-leaning posture in cyber space, what actually1823exists today in terms of offensive cyber capability, who1824currently has the authority to employ it, and what are the most1825important questions Congress should be proud of prioritizing1826right now if we are to consider whether and how the private1827sector could be empowered to play a more direct role in1828offensive or cost-imposing cyber operations?1829    Mr. Lin. Thank you, Chairman. You know, I'll answer your1830question in two ways. No. 1 is around authorities. I think it's1831important and critical that, (A), as my, some of my co-1832panelists have said that we are cooperating hand-in-hand with1833the authority holders of Title 10 and Title 50. But it's1834important to remember that DHS, CISA have authorities of their1835own that ought to be used as well and used aggressively here.1836We're talking about Title 18, we're talking about Title 14.1837Right? So the ability to use law enforcement authorities in1838combination in concert with Title 18--Title 10 and Title 50 is1839absolutely critical.1840    But No. 2, I think what needs to shift here is a mindset1841not just around doing episodic one-off operations of1842disruption, which are important and critical and can be1843successful, have been proven to be successful, much like the KB1844botnet takedown that the FBI led recently. But what does it1845take to match the speed and scale of our adversaries? To match1846the scope of what it is that they are conducting against us?1847One-off episodic operations, while important for deterrence,1848will never be enough to change the cost calculus of our1849adversaries.1850    Mr. Ogles. Exactly. Well said.1851    Ms. Harding, recent reporting indicates that a PRC-linked1852cyber actor, commonly referred to as Salt Typhoon, targeted1853systems supporting Congressional committees. This was not a1854private company or an Executive agency. It was the Legislative1855branch of the U.S. Government. From a strategic standpoint,1856what message does it send when a nation-state is willing to1857target Congress directly? Should this committee view that as a1858clear evidence that current approach to deterrence in cyber1859space is insufficient?1860    Ms. Harding. In a word, yes. I would want to draw a1861distinction, however, between an intelligence operation and a1862disruptive operation. As a former intelligence officer myself,1863I have to sort-of tip my hat to Salt Typhoon. They have been1864very clever, very talented. They have proven just how good1865China is at its current cyber activities. Going after1866Congressional staff from a intelligence perspective is a1867logical target. In my last role on the Senate Intelligence1868Committee, we frequently gave defensive briefings to our fellow1869staff and to Members of Congress to explain just how much they1870would be targeted and how sophisticated the adversaries were1871who were coming after them.1872    Ideally, yes, you'd be able to establish deterrence in an1873intelligent sense and you'd be able to say, OK, if you1874penetrate our networks, then you will feel consequences for1875that. It also is sort-of a normal spy versus spy, tit for tat.1876    A very clear distinction, however, is between the Salt1877Typhoon kind of activity and the Volt Typhoon kind of activity.1878There is zero intelligence value in penetrating water networks,1879power networks, especially around military bases. That is there1880for one reason and one reason only: to disrupt the United1881States military in the case that we had to deploy suddenly. If1882there were to be a Pacific contingency, a 6-hour delay, an 8-1883hour delay, a 12-hour delay could be definitive. If sailors1884can't get to their ships, if you can't load the ships full of1885equipment, then that is a 6-hour delay, an 8-hour delay, a 12-1886hour delay. It's a smart act for, I think, a potential1887adversary to take, but it is one we may not allow. We have to1888be able to deter that kind of activity and strike back.1889    Mr. Ogles. Thank you.1890    I now recognize the Ranking Member, the gentleman from1891Mississippi, for 5 minutes.1892    Mr. Thompson. Thank you very much, Mr. Chairman. Very1893rarely do I find witnesses with very little difference in1894testimony, so I compliment you on that.1895    But if our national cybersecurity strategy is going to1896shift toward a more aggressive offensive cyber strategy, we1897will need to ensure that the agencies responsible for such1898efforts, such as U.S. Cyber Command and the National Security1899Agency, have the staffing and resources necessary to carry out1900offensive cyber operations. Yet both Cyber Command and NSA have1901had personnel reductions over the last year.1902    All of you have talked about capabilities. I mean, if you1903are going to fight an enemy, you need the ability to do that.1904So in your analysis, are we in a position, given the current1905staffing, to say that we are at a point where we are good or1906the cuts have vulnerabilities that we should address at this1907point?1908    I will start with you, Mr. Lin, and we will go down the1909line.1910    Mr. Lin. Thank you, sir. I can't comment on the specific1911force structure or even the numbers that we necessarily need in1912each of these organizations, but what I can say is this: we1913will never have enough people if we're simply trying to throw1914more people at the problem against our adversaries. Our1915adversaries outnumber us 50 to 1 or, in some cases, 100 to 1.1916So when we think about what is the future of staffing1917structures, force structures, whether we're talking about for1918Cyber Command, for NSA, for DHS, we have to approach this1919problem from the perspective, of course, of thinking about1920what's the level of human expertise and oversight and control1921that's needed, but also what are the technologies that are1922needed that enable our people, our war fighters, our officers,1923to operate at scale against an adversary that has a1924quantitative advantage against this, and that exceeds orders of1925magnitude.1926    Mr. Thompson. Ms. Harding.1927    Ms. Harding. Thank you, sir. You're absolutely right that a1928lot of very talented people have left the Government, and there1929is concern there. I think the question is right-sizing and1930having the right talent in place to be able to fight back1931against these particularly talented and committed adversaries.1932    Cyber force, so I think at least three of us up here are in1933favor of the creation of a cyber force. That is because we need1934to think about this talent differently. We need to think about1935this force structure differently. This is not necessarily, you1936know, picking up a heavy rucksack and a hundred pounds of1937batteries and running through a field. Instead, this is a very1938specific set of skills, and we do want to lean heavily into a1939reserve cadre for cyber force. We have lots of talented people1940in the private sector, two of whom are sitting right here at1941the table with me, who can contribute both to the U.S.1942Government in a military sense and also in their private day1943jobs. Israel is perhaps an example to look at for this. They do1944this exceptionally well, where they blend together their1945private sector and their military activity so that both1946benefit, frankly.1947    I would also encourage, especially given this committee's1948jurisdiction, to take a hard look at the Coast Guard. They have1949a spectacular set of authorities and a really interesting cadre1950of cyber operators that can do all kinds of things that you1951wouldn't necessarily expect. That's kind-of a latent cyber1952power that I don't think we give enough credit to right now.1953Also, the National Guard. There are quite a few National Guard1954units, especially in places that are obvious, like Maryland,1955that have real talent in this space. They have clearances, they1956have capabilities, and they could play a much bigger role,1957especially in homeland defense, than we're currently allowing1958them.1959    Mr. Cilluffo. Mr. Thompson, just very briefly, I would1960support Emily's comments there. Yes, we've lost some people.1961We're never going to have enough people. But I think there's1962some issues we need to get our arms around quickly. Some of1963them may not be sexy, but they're actually important.1964    Cyber is not--it is its own domain, but it transcends all1965other domains: air, land, sea, space. Until we integrate1966computer network attack and cyber into our war-fighting1967strategy and doctrine, we're going to be hamstrung. So part of1968that is making sure we have the structural capabilities, that1969we have the women and men that can help make that happen. Part1970of that is ensuring we have the political will, because1971deterrence only works if it's consistent and if it's credible.1972    Here's the truth. If you look at how we've responded thus1973far, we've, in essence, been blaming the victim. An incident1974occurs, who do you blame? You blame the company, you blame the1975critical infrastructure, owner, operator? Yes, they need to do1976more. But how many of these companies went into business1977thinking they had to defend themselves against foreign1978militaries and foreign intelligence services? It's an unlevel1979playing field. So I think consistency, credibility, and1980signaling that there will be consequences for bad behavior is1981essential.1982    Mr. Thompson. Thank you. I appreciate the Chair allowing1983Mr. Bagley to answer the question.1984    Mr. Bagley. Thank you, Mr. Chair. Thank you, Ranking Member1985Thompson. I think fundamentally we should think about what we1986all discussed today as being a call for cross-domain responses1987at times. Sometimes we'll confront cyber with cyber, sometimes1988there'll be cross-domain responses.1989    So in terms of resourcing, I can't speak to the appropriate1990number of personnel. I think those in charge of agencies are1991best able to speak to that. But I can say we should want CISA1992to succeed, for example, and to have the processes and the1993technology they need. Then to make sure this subcommittee,1994through its oversight powers, is ensuring they have the1995personnel they need to succeed in that mission. But we should1996also be thinking expansively, as my colleagues have suggested,1997about other capabilities and other agencies throughout the1998Government. Because when we are trying to change adversary1999behavior, sometimes it's going to take authorities that are2000outside of the realm of what we think about with CISA or DHS in2001general, and instead we're going to be thinking about2002diplomatic tools, economic tools, law enforcement tools, or2003even military tools. So I think we should think expansively2004about that and work backward from that problem set.2005    Mr. Thompson. Thank you. I yield back, Mr. Chair.2006    Mr. Ogles. Thank you, Ranking Member.2007    I now recognize Mr. Fong for his 5 minutes of questioning.2008    Mr. Fong. Thank you, Mr. Chairman. I want to thank the2009panelists. This certainly builds upon the previous committee2010hearing that we had, when we talk about how we are seeing our2011foreign adversaries weaponizing AI and quantum tools to2012automate cyber espionage campaigns against the United States2013and soft targets, as mentioned before.2014    I do want to delve into this cyber force, cyber talent2015conversation. You know, certainly we are seeing universities2016and we are seeing community colleges try to develop a pipeline2017when it comes to teaching students cybersecurity tools and the2018technology.2019    I kind-of want to get your thought, Ms. Harding, in terms2020of, you know, as Mr. Lin had talked about, we don't have enough2021people compared to our adversaries. But how do you--what is2022your perspective on how we need to invest in our universities2023and community colleges in terms of developing that cyber2024talent?2025    Ms. Harding. So universities and community colleges are2026very important. I think we have focused a lot on certifications2027for cybersecurity, and that's important. But what we really2028want to push forward in the future is capabilities in AI,2029understanding how that's going to really change the landscape,2030and then also just sort-of a creative thinking. Some of the2031best cyber operators are not the ones who are the best coders.2032They're the ones who have the best ideas and the guys who think2033like the adversary, the guys who can come up with creative ways2034to get around obstacles, if they find them. These are the2035people who do the biggest, baddest cyber operations, and it is2036a thing of beauty to watch.2037    I think that, you know, we can think about the talent2038pipeline in the kids who are coming up now. We also really need2039to think hard, especially in this moment where we do have this2040meeting of the minds between Silicon Valley and Austin, Texas,2041and Washington, DC, where this is an important skill set to2042welcome people into the Government in a part-time capacity. You2043were a Navy Reservist. This is a great model. If you have2044people who can serve in the military reserves, serve in a cyber2045capacity, take the skills they've learned in their private-2046sector positions, and then pull them into the Government, like2047that is ideal.2048    Mr. Fong. I think that is an important point, which is if2049we need to be training and teaching students differently in2050terms of not just on just a cybersecurity defensive posture,2051but to look at how do we make our technologies more robust,2052this is something that as universities and community colleges2053start developing their curriculum, we might need to have a2054conversation about how we get--if universities and community2055colleges are going to develop these programs, actually have2056them train students to actually meet the demand and the needs2057that our country needs. So I would love to continue that2058conversation.2059    I would like to ask Mr. Lin, when it comes to information2060sharing, certainly with your expertise, private-sector2061cybersecurity firms often possess earlier and deeper visibility2062into our adversaries' infrastructure, attack paths, operational2063patterns than the Government systems alone. Based on your2064experience, how is information sharing now and what barriers2065exist currently that we need to address to ensure that we have2066more robust coordination?2067    Mr. Lin. Thank you, sir. Let me answer your last question2068first, which is how is it now? It's certainly improved2069considerably from 10 years ago or even 15 years ago. What you2070alluded to is spot-on, which is that these days private-sector2071companies, especially those in the cybersecurity domain, have2072extraordinary global sensor networks that rival those of even2073other intelligence--signals intelligence agencies. So it makes2074enormous sense for there to be very robust information-sharing2075bidirectionally and it has to be bidirectionally. We have to2076have--we have to make it possible, easy, and we have to2077encourage private-sector companies to share what their sensors2078are seeing as holistically as possible with our intelligence2079agencies, and it has to go--and vice versa. When we are able to2080downgrade intelligence that we're seeing through our robust2081signals intelligence apparatus, we have to be willing to share2082that with our private-sector companies as well. Go ahead.2083    Mr. Fong. Yes.2084    Mr. Cilluffo. Mr. Fong, just because I think the committee2085itself should be applauded for the PILLAR Act pivot, I mean,2086these are essential to be able to move forward. But I think to2087your point earlier, it's not just the traditional rote learning2088in a classroom. You need to give students opportunities to be2089in applied environments where they're actually engaged. Because2090I'm telling you, most of the best in the cyber community are2091not learning it in the classroom, they're learning it in the2092real world. I think looking to ways where we can build co-ops,2093we can build new opportunities with both industry and2094Government will be absolutely essential for success.2095    I would just add on the information-sharing question, we've2096been around this issue for 25 years. Here's the truth. We've2097got to move beyond information sharing to operational2098collaboration. Until we get to that stage, we're always going2099to be marching into the future backward. That is always by2100definition reactive. We need to get to the point where it's2101combined. You're in the same foxhole and you're fighting the2102same fight and you build the trust, which is everything. It2103takes years to build, nanoseconds to lose.2104    So I just needed to jump on that. I'm sorry for jumping in2105here.2106    Mr. Fong. Oh, I appreciate that. This is a very----2107    Mr. Cilluffo. Random unspoken thought, sorry.2108    Mr. Fong. This is a very important topic and we need to2109continue the conversation.2110    Thank you, Mr. Chairman, for your leadership in putting2111this panel together. Thank you. I yield back.2112    Mr. Ogles. The gentleman yields back.2113    I now recognize the Member from New Jersey, Mrs. McIver.2114    Mrs. McIver. Thank you, Mr. Chair and Ranking Member, and2115thank you to our witnesses for being here today.2116    I just want to quickly express my condolences to the family2117of Renee Good as well. What happened in Minneapolis, where she2118was fatally shot by an ICE agent, is horrific and deeply2119troubling. My thoughts are with her loved ones, especially her2120children, and with those affected by this tragedy as many in2121this country continue to mourn and seek answers.2122    As we discuss Trump's reliance on offensive cybersecurity2123tools, we must ask whether we are prepared to use these tools2124responsibly. Cyber offense depends on a strong, well-trained2125work force, not only to conduct operations, but to manage2126consequences and defend against a counter attack. Today we face2127a serious cybersecurity work force gap, which has been2128discussed in deep by many of our witnesses. We lack enough2129individuals to protect our infrastructure, economy, and2130national security. Expanding offensive tools without the people2131to sustain and defend ourselves is not deterrence, it is a2132risk. We must ensure that our home is secure. We must have the2133personnel and resources to fight any cyber threat before we2134dedicate time and resources to provoking malicious actors and2135cyber offense.2136    With that, many of our witnesses, especially Ms. Harding2137and Mr. Bagley, talked a lot about what we need to do in order2138to increase work force. Would love to give you guys a few2139moments just to talk about some of the barriers. How do we2140remove some of the barriers that we see right now with folks2141trying to join the cybersecurity work force?2142    I can start with Ms. Harding. Ladies first.2143    Ms. Harding. Why, thank you, ma'am.2144    So some of the barriers that we see, No. 1, is a barrier of2145imagination. I think there are people who think, you know, oh,2146that's going to be technical, that's going to be hard. I can't2147do it. There are some great programs to reach out to2148communities that maybe don't see themselves in this world, and2149those should definitely continue. There's some women in STEM2150programs, for example, that are really tremendous.2151    I think also, you know, when people think about the2152intelligence community, they think about that as a certain type2153of person that you've got to be really straightlaced. You've2154got to be, you know, the kind of person that has a buzz cut as2155opposed to the kind of person who has purple hair. It's just2156not true. I think welcoming a wide variety of talent into the2157Government is really important. You know, I say to people all2158the time, are you interested in doing really, really sneaky and2159sometimes illegal things in the cyber world? Join NSA. This is2160what they do and they do it very well. I think there's some2161real opportunity out there that maybe it just doesn't occur to2162people.2163    Another one of the barriers that we should really think2164through, I think, is going to be this coders to the AI space.2165So it's going to be a sea change. I know that you'll have more2166to say about this, but, you know, we've trained people to do2167really excellent jobs coding. In this strange new world we're2168going to have AI doing a lot of this work for us, and we're2169going to have a dearth of talent that really understands the2170way that AI works both for offense and defense.2171    One of the things that I would really love to see the2172Government put in place as well on the defensive front that you2173were talking about, that we really need to secure and be more2174resilient at home, is to create kind-of a Teach for America,2175but in the cyber realm. So the Government perhaps funds some2176training for people and in return you give 2 years back where2177you work in a school system, you work in a rural area, you're2178responsible for cybersecurity in a whole raft of rural water2179treatment facilities. You then repay what--the loan you got2180basically to go to school and you give to communities that are2181desperately in need of strong cyber talent to build a better2182defense.2183    Mrs. McIver. Yes, thank you for mentioning that. I am a big2184supporter of Teach for America coming from a school district2185and working. It is a great program and offers great incentives2186that brings many talents from across the world to work in these2187school districts. So thank you for that.2188    Mr. Bagley.2189    Mr. Bagley. Thank you. I think with my limited time, two2190primary ways we should think about this are, No. 1, with2191pathways, but we shouldn't think about pathways only being at2192the beginning of the career cycle. Instead, there should be2193more return to work programs where those who have taken time2194out of the work force, such as to be a caretaker or those who2195have taken a different career path, still have a path back into2196cybersecurity.2197    The second, and I think that enables the first, is really2198this upskilling we're seeing with AI. Now that we have this2199notion where a lot of automation can occur and we're really2200relying upon talent to have wisdom and do good decision making,2201we're no longer relying upon the same set of skills that would2202have taken years and years to learn when we were talking about2203coding from scratch. So I think that's something we should2204really leverage as an opportunity to bring more into the work2205work force.2206    Mrs. McIver. Thank you so much.2207    With that, Mr. Chairman, with that, I yield back.2208    Mr. Ogles. The gentlewoman yields back.2209    I now recognize the gentleman from Florida, Mr. Gimenez,2210for his 5 minutes.2211    Mr. Gimenez. Thank you very much, Mr. Chairman. I am sorry2212I wasn't here for the testimony, so maybe some of these things2213have been answered.2214    You know, if I were a CEO of a large corporation constantly2215being attacked and constantly being attacked, you know, from2216what I am reading is I have limited capability of hitting back,2217correct? Yes. That would be an itch that I really want to2218scratch. OK. So has there been any thought of creating--I mean,2219some of our corporations have billions and billions of dollars,2220you know, probably way more capable than we are, OK, in terms2221of resources, of creating some kind of a private-government,2222you know, offensive team that would allow me to satisfy my2223itch, OK, and hit back at some of these people that are hitting2224me all the time? Has there been a thought to do that? Do we2225have something like that? Anybody can answer.2226    Mr. Bagley. Sure. Thank you for the question, Congressman,2227and good to see you again. I think, importantly, JCDC does2228possess the ability to nominate campaigns and to nominate2229campaigns to those with Title 10 and Title 50 capabilities to2230be able to engage in appropriate activities such as taking down2231adversary infrastructure, such as doing some sort of activity2232that would, hopefully, deter and change that behavior. So I2233think that's the appropriate mechanism.2234    So I think, if anything, this is something where there2235should be, as I noted in my written testimony, there should be2236something akin to a top 10, a most wanted list, perhaps it's2237more than 10, but a most wanted list. That's the mechanism by2238which companies, organizations, nonprofits, academia, those2239affected, those impacted, can work through JCDC, get those that2240have a high impact nominated, and then using existing2241capabilities can, at a high tempo, go after these sorts of2242adversaries.2243    Mr. Gimenez. So that we can kind-of control who it is that2244we are going after, the Government controls who control who we2245are going after. It is like a bounty. You are a bounty hunter.2246    Mr. Bagley. It's a public-private collaboration.2247    Mr. Gimenez. OK. All right.2248    Mr. Cilluffo. Mr. Gimenez, if I could just expand on that.2249I think this is a significant issue and an important issue and2250I think time to really address this particular matter. In2251addition to JCDC, the National Security Agency has its2252Cybersecurity Collaboration Center, which coordinates with the2253defense industrial base. I think there is an opportunity to get2254to genuine operational collaboration. I don't want Yosemite Sam2255shooting all over the place. But at the end of the day, think2256about it as suppressive fire. Think about it in a football2257context. You have offense, you have defense, you have2258linebackers who blitz the adversary, the other team's2259quarterback.2260    So all things said and done, I think we need to get to that2261point and I think there are some authorities questions that2262need to be answered. But your itch is my itch and it's been2263there for a long time.2264    Mr. Gimenez. I like your football analogy since I am a big2265Kane fan. OK? We're in the National.2266    Mr. Cilluffo. I have two daughters who went to Miami, so I2267know they've got their NIL money.2268    Mr. Gimenez. The question that I have is that, you know, we2269have the criminal element, that a lot of it is based overseas,2270a lot of it based in some adversarial countries. Do we have2271evidence that those adversarial countries are actually working2272with those criminal elements inside to hit us? Do we have any2273evidence that they actually get a cut of whatever it is that2274those criminal elements do get? Open-ended question to anybody2275wish to answer.2276    Ms. Harding. I'll start on that one briefly. It's a2277complicated answer to what seems like a very straightforward2278question.2279    In the sense of China, we are seeing more sort-of popping2280up of criminal networks that seem to be government people who2281are moonlighting on the side at night doing criminal activity.2282But China's pretty locked down. They like to control their2283people and what they're doing, so it's sort-of a tight ship2284that they run.2285    Russia, on the other hand, is a very different story. We2286see more of an atmosphere where there's a commander's intent.2287You know, Putin wants this particular adversary to have2288problems, go forth and make it happen. There's kind-of a deal2289that happens between a lot of Russian criminal networks and the2290Russian state, where the Russian state says, you're going to2291operate outside of Russia, you're going to make life hard for2292our adversaries. We're going to ignore the criminal activity2293that you're doing and allow you to operate. But if you get2294cross with us, then we will come after you and arrest you on a2295moment's notice.2296    Mr. Gimenez. Do they get a cut?2297    Ms. Harding. I'm sorry?2298    Mr. Gimenez. Does the Government get a cut of the profit of2299the criminal activity?2300    Ms. Harding. There's probably some interesting work to be2301done following the money there. I mean, in Russia in2302particular, there's a lot of corruption. Right? So, yes, you2303know, do you get a kickback for allowing criminal activity to2304go on? I would assume so. But you'd want somebody to really get2305in deep and follow the money there.2306    Mr. Gimenez. My final comment is going to be if we continue2307just to play defense and play defense and play defense, we are2308just inviting attacks. So we need to go on the offensive and2309really whack them. As hard as they whack us, we need to whack2310them twice as hard so that this stuff stops.2311    With that, my time is up and I yield back. Thank you.2312    Mr. Ogles. The gentleman yields back.2313    I now recognize the gentleman from Virginia, Mr.2314Walkinshaw, for his 5 minutes.2315    Mr. Walkinshaw. Thank you, Mr. Chairman. I want to add to2316the condolences for the family and loved ones of Renee Good.2317She had 3 children, including a 6-year-old, who are all without2318their mother today.2319    Mr. Chairman, thank you for convening today's hearing. You2320beat me to the punch on the sports analogies. You are right2321that the best defense is a strong offense. I think it is still2322the case, however, maybe arguable, that defense wins2323championships. The Commanders have no offense and no defense,2324but I think both are still important. Yes.2325    A talented work force combined with a Federal IT2326infrastructure that embraces cutting-edge technologies, I2327think, should be the foundation of our efforts to counter cyber2328threats and to maintain an offensive cyber posture or grow our2329offensive cyber posture. It does trouble me that last year a2330third of the work force, and this has been noted by others2331already at CISA, which is our leading agency to deter threats2332to both our cyber and physical infrastructure, was wiped out by2333DOGE. In the recent shutdown, staff at CISA received RIF2334notices. Turned out those notices were illegal, according to2335courts, and a lot of them were moved to ICE and CBP to engage2336in immigration enforcement efforts. So these staffing cuts have2337left a big hole in our cyber defenses, our ability to combat2338attacks from Iran, Russia, the PRC, has been noted.2339    Mr. Bagley, in your written testimony, you analogized2340cybersecurity to physical security and you made the point that2341in a city, even with a very successful crackdown on crime,2342where law enforcement is going out and arresting the bad guys,2343still prudent to lock your door at night. Unfortunately, in my2344view, the firing of many of our cyber experts unlocks and opens2345some of our doors. So I am hopeful that will be reversed.2346    One of my concerns is the administration's elimination of2347the Multi-State Information Sharing and Analysis Center. It was2348a critical tool for decades for State and local governments,2349especially small, rural local governments, who maybe didn't2350have their own resources, our capacity to have visibility into2351the cyber threats that they face. I think it is the case that2352even if we want to be more aggressive in terms of our offensive2353cyber posture, we have to start from a place of visibility into2354the threats and cyber attacks that we are facing, especially2355State and local governments, which, as a former local2356government official knows, a lot of the personally identifiable2357information of every single American is held by State and local2358government. So the loss of that capacity concerns me.2359    I want to just dig in a little bit, and there has been a2360lot of agreement, but, Mr. Lin, you said in your testimony our2361offensive cyber utilizes bespoke teams, not at an industrial2362level, kind-of limited in your view. Ms. Harding, you said the2363U.S. offensive cyber capabilities are strong, perhaps unmatched2364in the world. A little bit different analysis there. I only2365have 1 minute, so maybe I will give you each 30 seconds to let2366me know whether you all disagree or agree.2367    Mr. Lin. Yes, sir. Not contradictory.2368    Mr. Walkinshaw. OK.2369    Mr. Lin. What I would say is this, which is, yes, we have2370some of the most talented cyber operators in the world, highly2371committed to the mission, very, very creative in terms of what2372they're able to pull off. I think we've seen perhaps a little2373bit of evidence of that in the last couple months. However, to2374what extent can they actually conduct those types of operations2375at scale? That is fundamentally what we're talking about here.2376Can they conduct those operations at speed and scale versus2377episodically? In cases where--in those cases does it take2378months or perhaps even years of planning to be able to pull off2379what they did?2380    Mr. Walkinshaw. OK. Ms. Harding.2381    Ms. Harding. Again, not contradictory, right. I think one2382interesting case study was the SYMPHONY exercise that we did a2383few years ago against ISIS in Syria. You can read through that2384and see just how many layers of approvals had to take place in2385order for that operation to come off. Now, things have changed2386since then, but it's really important to note that it's not2387necessarily--I mean, you could have 100 people or you could2388have 10 people running an operation. If it takes them 4 months2389to get the approvals they need to actually execute on the2390operation, then the opportunity is going to go. They're going2391to miss it. So it's--we are the most talented. We, also, I2392think need a more robust capability.2393    Mr. Walkinshaw. Thank you. Thank you, Mr. Chairman.2394    Mr. Ogles. The gentleman yields back.2395    You know, to continue the sports analogy now, I think we2396are, when you look at cyber capabilities in this rebuilding2397phase where we need that better collaboration, we need quality2398versus quantity, we need those force multipliers, which2399includes the private sector, that is the way forward.2400    With that, I recognize the gentleman from New York, the2401Chairman of the full committee, to use as much time as he2402needs.2403    Mr. Garbarino. I wish that was the case. Thank you very2404much, Chairman. Thank you very much for all witnesses for being2405here. To admit you are a Jets fan is very--I mean, it is a2406difficult thing to do every year and watch them every year. It2407is very difficult. But, yes.2408    Ms. Harding, I have a question with you. If the United2409States adopts a more forward-leaning cyber posture, including2410the use of private-sector capabilities, to disrupt or impose2411costs on foreign adversaries, what should the operational role2412of DHS and CISA be when retaliatory cyber activities targets2413the homeland?2414    Ms. Harding. Right. So what we've heard from the private2415sector, sort-of through the evolution of CISA and DHS, is that2416they see them as the good guys. When FBI shows up and asks a2417lot of questions, you know, they want to be helpful, but2418they're also there to look for criminal activity and to2419prosecute the criminals. That's a very specific skill set. When2420they talk to CISA, when they talk to DHS, what they're really2421feeling like they're getting is more of a partner.2422    I think the, you know, the JCDC had its upsides and its2423downsides, but it was, in fact, doing a lot of good trust-2424building with the private sector and it was a place to2425collaborate. I think that trying to adapt that, to adjust that,2426to moderate it for the future is really important.2427    Then what we were talking about with the two-way2428information sharing is absolutely critical. I think that the--2429one of the criticisms that DHS frequently gets is that, you2430know, you, you have your one person who you get cleared at the2431secret level and they go in and they get a briefing and they're2432like, that's it, that's all you're giving me? I could have read2433that in the New York Times. So we need to be more aggressive in2434sharing some intelligence information that we have. That's hard2435for me to say as a former intelligence officer, but I do think2436it's important.2437    Mr. Garbarino. No, absolutely. That is one of the--you2438know, I have been between Ranking Member and Chairman for the2439last 5 years on this committee. The one thing I have heard2440repeatedly from our partners, private sector and allies2441overseas, is we are very good at taking information. We are2442very not good--it is not a one-way street. We are not good at2443sharing information.2444    Ms. Harding. Exactly.2445    Mr. Garbarino. Just to follow up on that, does DHS and CISA2446currently have the authorities or network access or operational2447agility required to move in that direction if that is where we2448go?2449    Ms. Harding. I'm sorry, you're asking if DHS has the2450capabilities to conduct offensive cyber activities?2451    Mr. Garbarino. Well, I mean, does CISA have the authorities2452necessary to do it or do we have to give them more authorities?2453Do we have to give them more access to--is there action that we2454need to do so the private sector can work with these partners2455in CISA?2456    Ms. Harding. Yes. I mean, I think that there's a sort-of2457patchwork of authorities out there that you can cobble together2458to do some pretty impressive things. But I think looking at it2459from a zero-based standpoint and saying what we want to achieve2460here is really tight collaboration between the Government and2461the private sector, and what we want to do is take the best2462athlete from each team to sort-of continue the analysis. What2463can we do to make that happen and to really let the private2464sector shine in the things that they're very good at? I expect2465my co-panelists might have some other thoughts about the2466specific authorities of DHS, though.2467    Mr. Garbarino. Sure. Jump in if you want.2468    Mr. Lin. If I may, one of the other things that I would2469add, right, is that we have to start thinking about cyber as a2470core element of multi-domain operations. So when HSI is2471conducting investigations, they should have the ability, the2472authority, the resources needed to be able to leverage cyber2473capabilities as part of their work. When Coast Guard is2474conducting missions, given their unique authorities, as my2475panelists have said, they should be able to leverage, they2476should have the capabilities and the tool sets needed to be2477able to leverage cyber, offensive cyber as part of their core2478responsibilities.2479    Mr. Cilluffo. Just to build on that, Mr. Chairman, is--I2480mean, Emily brought up JCDC. I think JCDC, again, pros, cons,2481but in the event of a crisis, they're actually quite good.2482Bombs start dropping in Ukraine, they can get critical2483infrastructure owner-operators together, they can start sharing2484information. But it's episodic. It's only when there is a big2485event. What is that daily battle rhythm?2486    I mean, go with the sports analogies, which I started,2487sorry, but at the end of the day you got to put the reps in.2488You're not going to suddenly become a five-star recruit if you2489haven't been in the gym and on the field for years. So I think2490there needs to be something there that allows it to succeed not2491only in a bad day, but every day, so you're ready for that bad2492day.2493    I think, Mr. Gimenez, I am very much at the point where I2494think there are some authorities and some protections that are2495needed. First, WIMWIG, you got to get that over the goal line.2496That is essential. You can't trust the Government's going to2497lose all confidence of the private sector if we can't even get2498the basics. Imagine kicking us back a decade. That's what we're2499looking at here. That's unacceptable. So thank you for your2500leadership there. But I think just as importantly, you do need2501to also look to what that combined operation could look like2502from a collaboration standpoint, not industry on its own, in2503conjunction with government.2504    Mr. Garbarino. Absolutely. I ran out of time. In fact, I2505would let you add on and I will yield back. But as for WIMWIG2506and PILLAR, those are two things that we are making a hard2507push. I believe the Minority is also making a hard push as well2508as the Senate Minority to get included in our final package2509next--instead of just a blank extender or a short-term2510extender, to get actually the bills done in next week's final2511package. But we will see.2512    With that, Chairman, I yield back.2513    Mr. Ogles. The Chairman yields back.2514    I now recognize the gentleman from Rhode Island, Mr.2515Magaziner, for his 5 minutes.2516    Mr. Magaziner. Thank you, Mr. Chairman. I also want to2517start by offering my condolences to the family of Renee Good,2518especially her children, who are going to have to live the rest2519of their lives without their mother. You know, we have a long2520history in this country of protest and civil disobedience.2521Those who engage in protest know that there can be consequences2522for doing so, but those consequences shouldn't be a death2523sentence.2524    I had an opportunity to attend an event over the weekend2525with all the police chiefs across Rhode Island, several of whom2526came up to me and said that the tactics that they are seeing2527increasingly being employed by Federal agents and immigration2528enforcement are tactics that police departments stopped using2529years ago. One of the things that I think we need to do as a2530committee is exercise our oversight responsibilities to see2531what the leadership level at DHS is instructing its agents and2532officers in the field to do, because if they are not getting2533the proper training and guidance, not only does it do a2534disservice to the civilians who are being put at risk, but also2535to the officers and agents themselves.2536    Now, that being said, I am very glad that we are having a2537hearing today on this topic, and I thank you, Mr. Chairman, on2538the topic of how we deter and disrupt cyber attacks in the2539United States, because it has often occurred to me that these2540attacks are happening at increasing frequency and increasing2541brazenness. When I ask what the consequences are when foreign2542actors and other adversaries conduct these attacks, there don't2543seem to be any. We do need to have, I think, a serious2544retooling of the way that we think about this. If there are2545malign actors out there that continue to attack us in the cyber2546domain, we need to have the ability and the intent to disrupt2547their ability to continue to do so, period.2548    This is a little bit of a difficult conversation to have in2549an open setting. One of the things that I was going to suggest,2550Chairman, is perhaps we could continue this conversation in a2551Classified setting at some point so we can get into the weeds2552of what some of the different offensive deterrents could be in2553a way that we don't want to project publicly. But I just want2554to ask our panelists at a high level, when we think about what2555the parameters should be in terms of our offensive cyber2556actions to disrupt these threats, what are the sort of2557boundaries that we want to give not just to our cyber warriors,2558but that we want to project to the rest of the world? Keeping2559in mind that we are in an open setting here.2560    I notice, for example, Ms. Harding, you wrote in your2561testimony, ``The U.S. prides itself on protecting innocent2562civilians, not targeting them. Therefore, a proportional2563response to a cyber attack on our critical infrastructure would2564be severe and likely include economic or military measures.''2565So, like, I will start with you, and I will give the others a2566chance to weigh in, when you think about what the boundaries2567should be, what should be off-limits, what we want to project2568our boundaries as being, how do we think about that?2569    Ms. Harding. So we have always prided ourselves in trying2570to protect civilian life. You know, if you're an innocent2571bystander, you shouldn't be wrapped into the political fighting2572that's going on and then the actual fighting that's going on.2573So I think that a clear bright line is civilian critical2574infrastructure. You know, if you are shutting off the lights in2575a city, hypothetically, for a military action, that's one2576thing, but the lights came back on. This is not, you know,2577dropping Kyiv into winter without any power and without any2578heat, that should be a very clear bright line.2579    I think that part of what we're all saying here is that we2580need to stop thinking about cyber as the thing that's over here2581in a silo. We need to think about it as fully integrated in the2582full range of policy measures, and we don't necessarily have to2583respond to an attack on critical infrastructure with an attack2584on critical infrastructure. We're the United States of America.2585We have other options.2586    Mr. Magaziner. Would anyone else like to weigh in on this2587question? Yes, Mr. Lin.2588    Mr. Lin. Thank you, sir. If I may, two thoughts.2589    No. 1, I would like for us to get to a place where we're2590not thinking about retaliation because we have done such a good2591job of being proactive in disrupting adversary operations well2592before they're able to conduct attacks against us. That's No.25931.2594    No. 2, what you are alluding to, sir, is the fact that2595there is this very perverse cost calculus for our adversaries.2596They have every incentive to go on the offense against us.2597There is no punishment. There is no cost. So the question that2598we should be asking, the objective is, how do we insert enough2599friction to drive up the cost, to change their cost calculus2600such that they're not thinking about offensive cyber operations2601as something that is easy to do, that they reap all the2602benefits from, and suffer no consequences for?2603    Mr. Magaziner. Yes, that makes sense. My time is running2604out, so I will just say this. I agree and I think this is an2605important conversation for us to be having. We also have to2606anticipate that our actions could provoke reactions and so we2607will need to harden our defensive cyber capabilities as well.2608That is why it is so important that we staff up and fund CISA2609and other agencies tasked with cyber defenses, not defund them,2610not shift resources away from them, as, unfortunately, I think2611has been happening over the last year. So, but directionally, I2612think everything that you all are saying makes a lot of sense.2613    With that, I yield back.2614    Mr. Ogles. The gentleman yields back. Mr. Magaziner, to2615your point, one of the things that I am working on is a2616roundtable approach where we can gather industry experts and2617then we would have that in the SCIF to allow for more both2618frank conversation, educational back and forth, because it is2619critical.2620    You know, as you see the kinetic action that took place2621with Maduro, I think we unveiled technologies that probably2622caught our adversaries off-guard, which means that the cyber2623attacks are going to escalate now. So there has to be that2624cost-benefit analysis of if you move ahead, what is the penalty2625for your country, for, you know, whatever group or organization2626that is attached to Russia or China?2627    But, you know, sticking with that, when you look at our2628current--you know, we have relied on attribution, sanctions,2629indictments, defensive improvements, which is critically2630important to respond to state-sponsored activity. You know, we2631see Chinese and Russian campaigns continue with increasing2632persistence and confidence. In your judgment, what actually2633changes adversarial behavior in the cyber space?2634    So let's go down the line. You know, Mr. Lin, we put you in2635charge of cyber force. Your job in charge is to protect the2636United States of America, to implement the Monroe Doctrine, to2637make it clear that the Western Hemisphere includes the cyber2638realm. What do you do next, sir? Ms. Harding is ready.2639    Mr. Lin. A couple things. Let me start by adding an2640additional observation, which is that what we're seeing from2641our adversaries is wholesale adoption of artificial2642intelligence for the purpose of offensive cyber. You can be--2643the hearing, sir, previously where that was soon after this was2644disclosed by Anthropic, where they discovered that state-2645directed PRC threat actors were abusing their models to be able2646to conduct operations against American targets, both Government2647and commercial, there has to be wholesale adoption on our end.2648Smart, well-regulated, governed, thoughtful, but wholesale2649adoption of artificial intelligence capabilities merged in with2650modern software that we're using to, first, equip our soldiers,2651our warfighters, with the capabilities to be able to operate at2652the speed and skill that's needed in order to compete in this2653domain. If we're single-threading operations, we will be2654losing. That's No. 1.2655    No. 2, we have a lot of authorities in place. Again, I2656think some of my panelists have mentioned this before, which is2657there has to be a will, a political will, to employ these2658capabilities against our adversaries.2659    Mr. Ogles. Ms. Harding.2660    Ms. Harding. So I love thinking like the adversary, and I2661like trying to figure out how we can hold to American values2662and morals, but still really mess with the other guys.2663Disruption, I think, is the No. 1 point. If you unleash our2664cyber operators, where the minute they see some adversary2665activity on a particular node, they can go after that node and2666shut it down. That's key.2667    A critical point in this is actually incorporating our2668allies. As you know, the internet is global. It's not just one2669point. Right? It actually touches on a lot of different things.2670You need to have a bunch of allies in place that can say, yes,2671I'm in favor of this. Let's go do it.2672    No. 2, we've gotten really good at very targeted activity.2673There's no real reason to go after an entire network if you2674know exactly where the bad guys are operating and you can mess2675with them specifically. I think more about that in closed2676session would be good.2677    Then finally, rapid response is really important. Right now2678our cyber operators are frequently asked to do things on a time2679scale that's just impossible because they haven't been given2680the time and the opportunity to actually build a tool kit. I2681think we do need more people and we also need more authorities2682to go and build those things ahead of time so that when2683something happens, there can be a very quick, punishing2684response to create that deterrence.2685    Basically, to sum it up, unleash the cyber operators. Let2686them play.2687    Mr. Ogles. We will pause there and we will come back to2688you, sir, in just a moment. But I would like to recognize the2689gentleman from Texas, Mr. Luttrell, for his 5 minutes.2690    Mr. Luttrell. Thank you, Mr. Chairman. Forgive my2691tardiness.2692    Good morning, everyone. I will throw this one probably Mr.2693Bagley, but Ms. Harding, you can jump in on it as well. I would2694like to talk on undersea cabling. Defensive, offensive2695posturing on our undersea cabling system, which remarkably, as2696most of you probably know, that over 90 percent of all of our2697information flows through these cabling systems, that we have,2698the three different--the varying types that we have. The2699organizations that sit on top that provide us those cabling2700capabilities, who protects the system itself, which department2701that may be, whether it's Homeland Security, DOJ, or Department2702of War? If you guys have an answer for me on that one, that2703would be amazing, because I can't seem to figure that one out.2704    How do we release our front-line operators if necessary?2705How do we defend against the bad actors globally that most2706likely know where our cabling systems lie and how to attack2707them? Then I really don't really care how much redundancy we2708have in anything. One good one, it is kind of a showstopper.2709    So I threw that one to you, Mr. Bagley, but absolutely2710anybody on the panel, if you are educated in this in any way,2711please share that information with me.2712    Mr. Bagley. Thank you, Mr. Congressman, for the question. I2713think fundamentally, as you're noting, one of the risks posed2714to undersea cables comes from the physical realm and the2715ability to actually cut cables, to splice cables, and2716ultimately to redirect traffic. Right? We've seen this time and2717time again where adversaries have been able to do that,2718redirect traffic. Part of that actually goes to the network2719design of the internet itself, of the domain name system, and2720the ways in which, by design, it redirects when it reaches a2721dead end.2722    Mr. Luttrell. Do we have enough redundancy in place to do a2723redirect? Because these cables on average, what, twice a week2724possibly are hit and then it takes months to fix it if we can2725figure out who--which shoreline is going to be responsible for2726it.2727    Mr. Bagley. Yes, it's a great example of a cross-domain2728style attack in many ways that then also needs a cross-domain2729response. So the U.S. Navy naturally is going to own part of2730that, but also network operators and those who own the cables2731themselves, as the majority of infrastructure is owned by the2732private sector. So, fundamentally, a lot of what we've talked2733about today that I think is very important here is how to deter2734adversary behavior, how to make it so that their risk calculus2735changes when they decide that they're going to splice a cable,2736cut a cable. I think that's something that we should see as2737going well beyond just the cyber domain and thinking about all2738of our capabilities, including those, again, with the U.S.2739Navy, as far as undersea cables.2740    Mr. Luttrell. Physical security is one aspect of it. There2741is so many of them. When it is onshore, it is even worse2742considering the threat levels that exist in the metaverse that2743sit above our head. Putting a--I don't think globally we agree2744on what prosecution looks like for those that are cutting these2745cables, whether or not it is an accident, whether or not it is2746by anchor, a fishing vessel that drags there, or it is2747nefarious. I don't know if we can have--where we need to be2748because, oddly enough, what we are receiving from the private2749sector is very different than what we kind-of see here in2750Congress.2751    Now, where do we basically go from here is my question? Ms.2752Harding.2753    Ms. Harding. Thank you. So one of my folks on staff is our2754Coast Guard fellow actually right now, who just wrote a really2755excellent piece on this, Joel Coito, on the undersea cables and2756legal prosecution options for this.2757    Mr. Luttrell. Can I get that from you guys, please?2758    Ms. Harding. Absolutely, sir. I'll be sure to send it to2759you. I would also say, just for really precise recommendations,2760more repair ships so they can get back up and running quickly.2761    Mr. Luttrell. I would like to know how many.2762    Ms. Harding. OK.2763    Mr. Luttrell. And what that looks like. That's information2764that we need to know.2765    Ms. Harding. We will get you that, sir. Then I do have a2766lot of hope here for AI surveillance. So a lot of the ships2767that are accidentally, with air quotes, going after these2768cables are operating in very strange patterns on top of them.2769If you can get eyes on that target and you can identify a2770pattern of behavior that's anomalous, that really doesn't look2771much like fishing, then you can get on scene quickly and then,2772hopefully, deter that activity by interrupting it.2773    Mr. Cilluffo. Mr. Luttrell, if I could just--we recently2774hosted a lengthy podcast specifically on this issue. I think2775you're right to underscore, if you were to compare the2776intelligence, without getting into anything Classified,2777capabilities we'd have for space, for cyber, for land, sea is--2778actually, we have very little visibility.2779    Mr. Luttrell. Very little. Correct.2780    Mr. Cilluffo. The scale and scope and just distance is2781massive and the dependencies are essential. But I think here2782what we're really getting at, and, again, this isn't to punt on2783your question, but it is multi-domain. We need all the2784intelligence disciplines to merge and we need to invest more in2785undersea, there's no question.2786    Mr. Luttrell. It seems like the multi-discipline domains2787that live and breathe don't pay attention to everything in the2788middle.2789    Mr. Cilluffo. Absolutely.2790    Mr. Luttrell. Because it goes under water, nobody sees it.2791    Mr. Cilluffo. Absolutely right.2792    Mr. Luttrell. Mr. Chairman, I yield back. Can----2793    Mr. Ogles. That is fine.2794    Mr. Luttrell. OK, thank you. When we talk about the2795agencies and then we inject the Navy, now, I don't know if you2796can really move through silos very well on your side, but I2797tell you what, getting the Department of War to talk to2798Department of State or whomever, man, I was in the military, it2799was a very challenging thing. But since we have so much of this2800information that lives and breathes, do we need to increase,2801and I don't have a name for it, I am just kind-of making this2802up as I go, do we need to increase kind-of our undersea cabling2803fleet, as you mentioned, Ms. Harding? But I think we have two2804vessels, two companies that kind-of touch this. Then if you--2805and then of course, China and France and whomever else is2806really kind-of--Italy is really getting into this. Is that2807something that we in Congress need to talk to the Department of2808the Navy about? Because, honestly, the Chairman and I are2809really paying attention to this, but I don't think enough folks2810are paying attention to this.2811    Ms. Harding. One hundred percent agree that not enough2812people are paying attention to this. Because it is such a2813complicated set of actors that need to be involved, and, yes, a2814lot of attention, a lot of focus across disciplinary effort is2815important. Talk to the Navy, absolutely. I think it's also2816about creating the incentive structures for some folks in the2817private sector to really invest more in the capability to2818protect the technology and then also to repair it.2819    Mr. Luttrell. Well, I think they would if it was so2820complicated to get that done because now you are dealing with2821the Government. Who do you think is in charge?2822    Ms. Harding. Of undersea cables?2823    Mr. Luttrell. Yes. Who is a subject-matter expert?2824    Ms. Harding. Inside the Government?2825    Mr. Luttrell. Or anybody.2826    Ms. Harding. I know I have some at CSIS, but inside the2827Government, I would say that there's no one good home.2828    Mr. Luttrell. OK, thank you. Thank you, Mr. Chairman.2829    Mr. Ogles. You know, as fate would have it, all three of us2830have had these conversations about undersea cables and the2831vulnerabilities that they create.2832    But so if we will, we are getting near the end, we will2833pick up with you are in charge of the cyber force. What is your2834next step? Then once Mr. Bagley goes, we can simply go down the2835line one after another for kind-of closing remarks, anything2836that you want to emphasize that we missed or, quite frankly,2837that we got wrong. That is what this hearing is for. You are2838the subject-matter experts and we need and want to hear from2839you because part of my job and our job collectively is to bring2840this to the forefront. Because we are literally under attack2841and, quite frankly, I don't think enough agencies and2842departments are working together, that one-way street of2843information, and we are not fully prepared.2844    Mr. Cilluffo.2845    Mr. Cilluffo. Chairman Ogles, thank you. God help us all if2846I were leading a cyber force.2847    But first, I think Mr. Lin captured the end-state well. I2848don't want to be reacting. We're always marching into the2849future. In essence, we've literally ceded the battlefield to2850our enemy. They do something, we respond. We need to be able to2851shape that environment. I think I mentioned suppressive fire is2852sort-of a tactical set of issues, adding friction into the2853system. I don't want to get to that point where it is already2854too late. If that's the time we're demonstrating our2855capability, game over. We've already lost to one extent or2856another.2857    So how do we do this in a proactive environment? I hate to2858say it, I think political will is essential here. Again, to2859have a deterrent, it has to be credible, it has to be2860consistent. If a line is crossed, you have to respond. How many2861more darn lines have to be crossed? I feel like we've had this2862discussion for a while. So I think political will,2863demonstrating capabilities.2864    Differentiating between Salt and Volt Typhoon, I'm very2865much where Emily is here. Salt Typhoon, it's awful, but hats2866off. I mean, I'm shocked there's gambling going on in the2867casino, to take from ``Casablanca.'' I mean, truth is, is2868that's what they're doing. They're doing well. Vault Typhoon,2869on the other hand, is a clear line that has been crossed and2870there were zero consequences.2871    So I think, ultimately, it's bringing all instruments of2872national power, of which cyber is a big one. Quite honestly, I2873think it's unleashing some of the capabilities of not only our2874operators, but also our front-line owner-operator, critical2875infrastructure defenders.2876    Mr. Bagley. Thank you, Mr. Chairman. I think,2877fundamentally, you know, when we think about what's been2878previewed so far with the forthcoming National Cybersecurity2879Strategy from Director Karen Cross, and specifically PILLAR2880One, which focuses on this notion of changing adversary2881behavior, I think some core objectives that should just be2882baseline really are that we need to be changing behavior so2883that we're diminishing the ability of the adversary to scale2884and diminishing the ability of the adversary to repeat. Those2885two basic things alone are fundamentally important when we're2886talking about the rate at which adversaries are adapting, the2887rate at which technology is evolving, and machine speed is now2888the speed at which we're all moving at.2889    So I think that in doing that, you know, as Frank was2890noting, I think there is a distinction, of course, between2891espionage used to collect information and actual cyber attacks2892that are attacks or that are pre-positioning for attacks. I2893think that's what needs to be prioritized, fundamentally2894prioritized, where we are changing behavior so that there are2895costs for attacking the United States, there are costs for2896attacking our allies, and that fundamentally there is a risk2897calculus that the adversary is going to have to take.2898    Mr. Ogles. Mr. Lin, closing thoughts?2899    Mr. Lin. Thank you, sir. Just three.2900    No. 1, again, I think it's absolutely critical, as you2901alluded to, sir, that we understand the escalation dynamics2902that are at play here. The escalation dynamics are such that2903right now, currently, there is little to no cost for our2904adversaries to hold our society, our country at risk, to place2905the digital equivalent of explosives into our critical2906infrastructure networks, right, in order to pre-position for2907war and to hold that sword over our heads. We have to change2908that. Playing defense simply is not enough.2909    No. 2, we really do have to start moving at machine speed.2910So while I appreciate the fact that we certainly need more2911talented people, we need to have the right talent pipeline2912going into Government, going into Cyber Command, going to DHS,2913going to NSA. At the end of the day, we simply cannot be2914throwing more people at the problem.2915    So that brings me to my last point, which is that we have2916to be smart about how we are investing in our offensive cyber2917capabilities. We have to make sure not just that it's2918resourced. So Congress passed, as you well know, sir, Congress2919passed a billion dollars for offensive cyber in the2920reconciliation bill, plus another quarter-billion dollars for2921artificial intelligence to be used in offensive cyber in the2922reconciliation bill. That's an amazing down payment. We need to2923make sure that resourcing is not just spent on more bodies or2924on legacy Government programs, but on the types of capabilities2925that enable our people to operate at 100X of where they are2926today.2927    Ms. Harding. So two points.2928    No. 1, intel collection in the private sector. We need to2929take a hard look at the way we do contracting with the private2930sector. They have an intelligence collection network that does,2931in fact, rival the U.S. Government's and it is tapped, but only2932in a patchwork sense. This is their lifeblood, this is how they2933make money. So the Government does need to work with them to2934actually pay for that information. But there are much more2935efficient ways of bringing it into the system and using it2936across the U.S. Government for better indications and warning.2937    No. 2, I think this is a more strategic point. I've heard a2938lot today that sounds like defense and offense in the cyber2939realm are in opposition to each other. That's not the way to2940look at it. It really is both. It's a both/and. In fact, our2941offensive capability is severely hamstrung by our lack of good2942defense. A lot of times what we see playing out in Government2943discussions is there's a great idea for a cyber operation and2944then the policy decision is, well, if we do that, then they're2945going to hit us back and we're weaker than they are2946defensively. So, in fact, we're deterring ourselves. We have to2947fix that defensive picture so that we can unleash on the2948offensive front.2949    Mr. Cilluffo. Again, the challenge of going after two2950panelists that I agree with a hundred percent. So I'll go back2951with the football analogy. We actually need a head coach where2952both the offensive and defensive coordinators feed the2953playbooks into. That, I think, should be the national cyber2954direction. Because, ultimately, if--and to pivot to another2955sports analogy, if we're going to be punching, we've got to be2956able to absorb the punches. The reality is we have a whole lot2957more to lose than some of our adversaries.2958    The flip side is you hear a lot of people saying, oh, it's2959going to create escalation. I don't know what more escalation2960can happen before we recognize there has to be a consequence2961for inducing change in bad behavior.2962    The public-private partnership, long on nouns, short on2963verbs. Time we finally get to what is operational2964collaboration. Move beyond the information-sharing questions,2965which are essential. If we really want to be creative there why2966doesn't critical infrastructure have the ability to levy2967intelligence requirements? Maybe the National Intelligence2968Priority Framework should be open to some of our most essential2969critical infrastructure owner-operators. There are some2970creative things we can do there, but, ultimately, it can't be--2971if you don't have the trust that we currently do not fully have2972at the scale we need, if you're not in the foxhole fighting the2973same fight on every day, you're always going to plug-and-play2974in the midst of a crisis. That's not the time to be exchanging2975business cards. That's not the time to get to know one another.2976You got to do it in advance.2977    Mr. Ogles. Mr. Bagley.2978    Mr. Bagley. Thank you. Couldn't agree more that defense is2979fundamental for anything we're going to do that would be more2980aggressive in trying to change adversary behavior. Defense is2981foundational and the two should not be viewed as some sort of2982dichotomy that resources allocated for defense are at the2983expense of offense or vice versa. It's two different domains.2984    But defense, fundamentally, is something that should always2985be viewed as something that is ever-evolving. We should never2986think that you can make a one-time investment or choose a2987number that is the same number for years of investment and that2988that will be sufficient in protecting our Federal systems and2989protecting our critical infrastructure or in organizations2990protecting themselves around the country. So it's fundamental2991to note that as adversaries evolve, defenders must adapt. As2992new technologies are deployed, they need to be deployed with2993security so that they can be deployed with confidence, because2994if they're not, then they'll just increase the attack surface.2995This is fundamental as we as a country innovate with AI, adopt2996AI quickly, and also want to leverage the benefits from AI.2997    So I would implore the committee to continue the great2998oversight work it's doing, to think about how the U.S.2999Government is using these technologies, but also how the U.S.3000Government is increasing its own defense as it looks to change3001the risk calculus for adversaries.3002    Mr. Luttrell. Very well-spoken, all four of you. I would3003hate for all of you to walk out that door and then what you3004recommended to Congress never shows up again. The presentation3005outlined, if I was to ask all four of you, do you agree on one3006specific thing that you can push up to this committee, that we3007can help you--that might be challenging. If you are counting on3008Congress to write out what the internal infrastructure looks3009like defensively and offensively, it will fail. That is why we3010are--that is why you are here.3011    But you need to be on send while we are on receive and say,3012hey, through heavy negotiation, a large amount of debate, this3013is what we think is the baseline assessment. As we3014progressively move forward--because we are happy. This3015committee and I would assume the Majority Members of Congress3016understand the threat, the viable threat and risk to cyber3017attacks. We do. Even more so, we are getting there. You would3018be surprised how many people walk into our offices with a great3019idea that needs $20 billion every day.3020    It would be nice if the collective whole of the most3021brilliant operators that this country has would show up, it was3022like, this is what we have come up with, this is the best way3023forward. It will flex left, right, or center. It does not have3024a hardcore left and right flank. You cannot do that in the3025digital space. But what we understand, what we know now and3026where we are going downstream, this is our starting point. OK,3027fair enough?3028    Thank you, Mr. Chairman.3029    Mr. Ogles. I want to thank you all for your testimony3030today. I think when you look at some of the conflict and the3031partisan nature that is Congress, that you see a great deal of3032agreement amongst the panelists, but also the Members. I think3033that underscores the urgency of the topic and the subject, you3034know, nature of the matter.3035    We are under attack. The war has begun and we are fighting3036it from multiple adversaries. We have Russia, we have malign3037actors, we have Iran, we have North Korea, and, of course, we3038have China. Let me be clear. We are the United States of3039America. We have been alerted. We are aware and we are3040watching. If I have my will, we are going on offense. We are3041going to strengthen our defense. There is going to be a price3042to pay when you incur, infringe on our borders, whether that is3043in the Western Hemisphere or in the cyber space.3044    I thank the witnesses. Members of the subcommittee may have3045some additional questions for the witnesses and we would ask3046that the witnesses to respond to these in writing. Pursuant to3047committee rule VII(E), the hearing record will be open for 103048days.3049    Without objection, the subcommittee stands adjourned.3050    [Whereupon, at 11:48 a.m., the subcommittee was adjourned.]30513052                                 [all]

Witnesses

4 witnesses appeared, with 12 papers on file.

NamePositionPapers
Ms. Emily HardingVice President, Defense and Security Department, Center for Strategic and International StudiesTestimony · Truth in Testimony · Biography
Mr. Drew BagleyChief Privacy Officer, CrowdstrikeTruth in Testimony · Biography · Testimony
Mr. Joe LinCo-Founder and Chief Executive Officer, Twenty Technologies, Inc.Truth in Testimony · Biography
Mr. Frank CilluffoDirector, McCrary Institute for Cyber and Critical Infrastructure SecurityBiography

Documents

The committee filed 2 documents for the meeting.

DocumentKindFormat
Hearing NoticeSupport DocumentPDF
Hearing: Witness ListHearing: Witness ListPDF