Search

Search bills, members, committees and pages...

Hearings to examine America's communications networks.

MeetingSenate Commerce, Science, and Transportation Subcommittee on Telecommunications and MediaDec 2, 2025 · 10:00 AM

Summary

Senate Commerce, Science, and Transportation Subcommittee on Telecommunications and Media held a meeting on Dec 2, 2025 at 10:00 AM in Russell Senate Office Building, Room 253.


Record

The meeting has its transcript on the record.

Transcript

The transcript runs to 4,868 lines and 284,722 characters, as the Government Publishing Office printed it.

senate-hearing-62989.txt
1[Senate Hearing 119-319]2[From the U.S. Government Publishing Office]34                                                        S. Hrg. 119-31956                 SIGNAL UNDER SIEGE: DEFENDING AMERICA'S7                        COMMUNICATIONS NETWORKS89=======================================================================1011                                HEARING1213                               before the1415                  SUBCOMMITTEE ON TELECOMMUNICATIONS16                               AND MEDIA1718                                 of the1920                         COMMITTEE ON COMMERCE,21                      SCIENCE, AND TRANSPORTATION22                          UNITED STATES SENATE2324                    ONE HUNDRED NINETEENTH CONGRESS2526                             FIRST SESSION2728                               __________2930                            DECEMBER 2, 20253132                               __________3334    Printed for the use of the Committee on Commerce, Science, and Transportation3536               [GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]3738                Available online: http://www.govinfo.gov3940                               ______4142                 U.S. GOVERNMENT PUBLISHING OFFICE434462-989 PDF                WASHINGTON : 20264546       SENATE COMMITTEE ON COMMERCE, SCIENCE, AND TRANSPORTATION4748                    ONE HUNDRED NINETEENTH CONGRESS4950                             FIRST SESSION5152                       TED CRUZ, Texas, Chairman5354JOHN THUNE, South Dakota             MARIA CANTWELL, Washington,55ROGER WICKER, Mississippi                Ranking56DEB FISCHER, Nebraska                AMY KLOBUCHAR, Minnesota57JERRY MORAN, Kansas                  BRIAN SCHATZ, Hawaii58DAN SULLIVAN, Alaska                 EDWARD MARKEY, Massachusetts59MARSHA BLACKBURN, Tennessee          GARY PETERS, Michigan60TODD YOUNG, Indiana                  TAMMY BALDWIN, Wisconsin61TED BUDD, North Carolina             TAMMY DUCKWORTH, Illinois62ERIC SCHMITT, Missouri               JACKY ROSEN, Nevada63JOHN CURTIS, Utah                    BEN RAY LUJAN, New Mexico64BERNIE MORENO, Ohio                  JOHN HICKENLOOPER, Colorado65TIM SHEEHY, Montana                  JOHN FETTERMAN, Pennsylvania66SHELLEY MOORE CAPITO, West Virginia  ANDY KIM, New Jersey67CYNTHIA LUMMIS, Wyoming              LISA BLUNT ROCHESTER, Delaware68                 Brad Grantz, Republican Staff Director69           Nicole Christus, Republican Deputy Staff Director70                   Lila Harper Helms, Staff Director71                 Melissa Porter, Deputy Staff Director7273                                 ------7475              SUBCOMMITTEE ON TELECOMMUNICATIONS AND MEDIA7677DEB FISCHER, Nebraska, Chair         BEN RAY LUJAN, New Mexico, Ranking78JOHN THUNE, South Dakota             AMY KLOBUCHAR, Minnesota79ROGER WICKER, Mississippi            BRIAN SCHATZ, Hawaii80JERRY MORAN, Kansas                  EDWARD MARKEY, Massachusetts81DAN SULLIVAN, Alaska                 GARY PETERS, Michigan82MARSHA BLACKBURN, Tennessee          TAMMY BALDWIN, Wisconsin83TODD YOUNG, Indiana                  TAMMY DUCKWORTH, Illinois84TED BUDD, North Carolina             JACKY ROSEN, Nevada85ERIC SCHMITT, Missouri               JOHN HICKENLOOPER, Colorado86JOHN CURTIS, Utah                    JOHN FETTERMAN, Pennsylvania87BERNIE MORENO, Ohio                  ANDY KIM, New Jersey88TIM SHEEHY, Montana                  LISA BLUNT ROCHESTER, Delaware89SHELLEY MOORE CAPITO, West Virginia90CYNTHIA LUMMIS, Wyoming9192                            C O N T E N T S9394                              ----------95                                                                   Page96Hearing held on December 2, 2025.................................     197Statement of Senator Fischer.....................................     198Statement of Senator Lujan.......................................     299Statement of Senator Cruz........................................    33100Statement of Senator Blackburn...................................    39101Statement of Senator Rosen.......................................    41102Statement of Senator Schmitt.....................................    43103Statement of Senator Hickenlooper................................    45104Statement of Senator Capito......................................    47105Statement of Senator Cantwell....................................    49106Statement of Senator Peters......................................    51107Statement of Senator Young.......................................    53108109                               Witnesses110111Robert Mayer, Senior Vice President of Cybersecurity and112  Innovation, USTelecom--The Broadband Association...............     4113    Prepared statement...........................................     5114Daniel Gizinski, President of Satellite and Space Communications115  Segment, Comtech...............................................     8116    Prepared statement...........................................     9117Jamil N. Jaffer, Founder and Executive Director, National118  Security Institute, Antonin Scalia Law School, George Mason119  University.....................................................    12120    Prepared statement...........................................    14121Debra Jordan, Former Chief of Public Safety and Homeland Security122  Bureau, Federal Communications Commission......................    29123    Prepared statement...........................................    31124125                                Appendix126127Response to written questions submitted to Robert Mayer by:128    Hon. Ted Cruz................................................    59129    Hon. Todd Young..............................................    60130    Hon. Maria Cantwell..........................................    61131    Hon. Amy Klobuchar...........................................    62132Response to written questions submitted to Daniel Gizinski by:133    Hon. Ted Cruz................................................    62134Response to written questions submitted to Jamil N. Jaffer by:135    Hon. Ted Cruz................................................    63136Response to written questions submitted to Debra Jordan by:137    Hon. Amy Klobuchar...........................................    67138139    SIGNAL UNDER SIEGE: DEFENDING AMERICA'S COMMUNICATIONS NETWORKS140141                              ----------142143                       TUESDAY, DECEMBER 2, 2025144145                               U.S. Senate,146      Subcommittee on Telecommunications and Media,147        Committee on Commerce, Science, and Transportation,148                                                    Washington, DC.149    The Subcommittee met, pursuant to notice, at 10 a.m., in150room SR-253, Russell Senate Office Building, Hon. Ted Cruz,151Chairman of the Committee, presiding.152    Present: Senators Fischer, Cruz, Sullivan, Blackburn,153Young, Schmitt, Moore Capito, Lujan, Cantwell, Peters, Rosen,154Hickenlooper, and Blunt Rochester.155156            OPENING STATEMENT OF HON. DEB FISCHER,157                   U.S. SENATOR FROM NEBRASKA158159    Senator Fischer. Good morning. The hearing will come to160order. I want to thank our witnesses for being here with us161today.162    Today's hearing comes at an important moment. Our nation's163communication networks are facing rapidly evolving threats,164ranging from fraud and espionage to sabotage. In a few minutes165we will examine and consider how government and industry can166work together to strengthen our network's security.167    The United States intelligence community assesses that the168People's Republic of China is the most active and persistent169cyber threat to United States institutions. Last year, the170hacking group, Salt Typhoon, backed by the PRC, infiltrated171U.S. telecom providers. We need a unified cyber defense172strategy now more than ever. Threat actors are deploying173advanced technology at scale to try to undermine our networks174at every juncture. These attacks are increasingly supercharged175by artificial intelligence, as well.176    While private industry continues to innovate, collaborate,177and defend against these threats, the risk environment is178growing more complex. Congress must coordinate with industry179and ensure robust Federal response. Supply chain security180remains a critical part of this conversation. The PRC-linked181companies such as Huawei continue to pose significant risks to182allied communication infrastructure. Congress created the Rip &183Replace program to remove this vulnerable equipment from184portions of American networks, and the FCC continues to185identify high-risk vendors.186    This Committee has also advanced my bill to increase187transparency around foreign-owned communication licensees.188Earlier this Congress, I introduced the FACT Act, which189requires the Federal Communications Commission to publicly190identify companies that hold FCC licenses that are owned by191adversarial governments. I am proud it passed the Senate in192October, and I look forward to seeing it become law.193    As we grow more connected, we feel the impacts of network194insecurity, globally, nationally, and locally. Just last month,195Kearney Public Schools in Kearney, Nebraska, experienced a196major cyberattack that disrupted phone and computer systems. We197also witnessed a series of 911 system outages across Nebraska,198with multiple failures caused by a lack of network diversity199and redundancy.200    As global conflict increases, networks that span201international borders are also prime geopolitical targets for202bad actors, seeking to create economic and political203instability. Undersea cables carry more than 95 percent of204international Internet traffic, including sensitive financial205and governmental data. Recent physical cuts to those cables,206both accidental and intentional, have caused disruptions207worldwide, knocking millions of people and businesses offline,208including major cloud services.209    And as we look to space, satellite constellations are210rapidly expanding. With over 10,000 active satellites in orbit,211most operated by United States companies, these systems support212at-home connectivity, national security functions, and critical213infrastructure. We must ensure foreign adversaries do not214infiltrate these systems for espionage or other nefarious215purposes.216    Across all these domains, threat actors are growing more217aggressive and persistent. Today's hearing allows us to deepen218our understanding of these threats and ensure our networks219remain secure. There is no single solution to the network220security challenges ahead. However, I hope today that we will221shed light on different approaches that this Committee can222champion. I look forward to the discussion.223    Senator Lujan, you are recognized for your opening remarks.224225               STATEMENT OF HON. BEN RAY LUJAN,226                  U.S. SENATOR FROM NEW MEXICO227228    Senator Lujan. Thank you, and first off I want to recognize229and thank Chair Fischer for her leadership in calling this230hearing today on a critical issue facing us all across America.231I want to thank our witnesses, as well, for being here.232    I think every member on this Committee can agree that there233is nothing more important than keeping our communities and our234country safe. That is why the security of our communications235networks is vital. The networks are the foundation of our daily236lives. They carry our phone calls, texts, Internet traffic,237health information, emergency services, and so much more. It is238also our responsibility to ensure that foreign actors like239China cannot infiltrate our infrastructure or steal Americans'240data.241    There is clear evidence that foreign adversaries, including242nation-state actors, are escalating their efforts to infiltrate243and compromise our networks. The Salt Typhoon hacks from last244year exposed fundamental weaknesses in our telecom245infrastructure. That attack breached major carriers, such as246Verizon, AT&T, and T-Mobile, and compromised millions of247individuals' information. This attack also likely represents248the largest telecommunications hack in our Nation's history.249    About a year ago, we examined this very topic, in this very250committee room. Yet a year later, our communications networks251are no more secure. And we can see that it is not just the252major carriers. I am also concerned that our schools,253hospitals, libraries, police departments, and emergency254responders are all exposed and do not have the resources to255defend themselves against foreign adversaries.256    I am also extremely concerned that the Federal257Communications Commission rushed to dismantle efforts taken258under the last administration to verify the security of259America's networks. The FCC stripped these protections away,260replacing them with voluntary pledges and handshakes with261companies whose networks have already proven themselves to be262vulnerable to data breaches. To put it plainly, these companies263are basically leaving their front doors unlocked after a data264break-in, and the FCC has decided to take their word when they265promise they have installed deadbolts and security cameras. It266is all deeply troubling.267    By removing enforceable standards, the FCC is weakening our268national security at a time when our communications and digital269landscapes are growing like never before.270    There is still a lot we do not know about the damage done271by the Salt Typhoon hacks. In fact, President Trump fired the272Board that was investigating the attack. But what we do know is273that rolling back protections and requirements to harden our274networks is putting us on a dangerous path, and it will not275prevent or mitigate attacks like this in the future. There will276be more attacks. That is certain.277    This should not be a partisan issue. This is a matter of278national security. We are fortunate to have an expert panel279with us today who will speak to the vulnerabilities in our280communications system and how we can address them to protect281our constituents. I look forward to productive conversation282today, and again, thank you all for being here.283    Thank you, Madam Chair.284    Senator Fischer. Thank you, Senator Lujan. I am very285fortunate to have my friend as the Ranking Member on this286Committee, and I thank you for your comments and look forward287to important work that we can do together.288    I would like to introduce our witnesses now today. Our289first witness is Robert Mayer, Senior Vice President of290Cybersecurity and Innovation at USTelecom. In this role, Mr.291Mayer leads the association's efforts on cyber and national292security.293    Our second witness is Daniel Gizinski, President of294Comtech's Satellite and Space Communications Segment. In his295capacity, Mr. Gizinski leads efforts to advance Comtech's296strategy and growth as the company focuses on next-generation297satellite solutions.298    Our third witness is Jamil Jaffer, Founder and Executive299Director of the National Security Institute. He also serves as300an Assistant Professor of Law and Director of the National301Security Law and Policy Program at the Antonin Scalia Law302School at George Mason University.303    And our final witness is Debra Jordan, former Chief of the304Public Safety and Homeland Security Bureau at the Federal305Communications Commission.306    Mr. Mayer, you are recognized to give your opening307statement.308309      STATEMENT OF ROBERT MAYER, SENIOR VICE PRESIDENT OF310    CYBERSECURITY AND INNOVATION, USTELECOM--THE BROADBAND311                          ASSOCIATION312313    Mr. Mayer. Thank you. Chair Fischer, Ranking Member Lujan,314and members of the Subcommittee, thank you for the opportunity315to appear before you today. I am Robert Mayer, Senior Vice316President of Cybersecurity and Innovation at USTelecom--The317Broadband Association. I also serve as the Chair of the318Communications Sector Coordinating Council at the Department of319Homeland Security.320    This Subcommittee knows the economic, national security,321and social value of our Nation's communications infrastructure322and what we bring to communities around the Nation. And while323we invest billions in protecting our networks and our324customers, nations including China, Russia, and Iran leverage325their capabilities to infiltrate our infrastructure in pursuit326of geopolitical and economic gains.327    Defending against such attacks requires a whole-of-328government coordination and deep and enduring trust between the329private sector and the government when sharing information. It330also requires, when appropriate, our government to push back on331our adversaries by imposing costs through diplomatic, economic,332cyber, and military means, that mirror the scale and333sophistication of our adversaries. Congress can help to advance334this mission by pursuing several core principles and action335steps.336    First, the public-private partnership model should be337preserved and strengthened. It is flexible, evolves with the338threat, supports actionable remediation, and it encourage early339and candid reporting.340    Second, cybersecurity frameworks must be flexible and341adaptive. While there may be a natural impulse to mandate a342detailed cybersecurity checklist, such requirements lag behind343adversaries who change their techniques faster than any rules344can be written. And furthermore, they shift attention away from345managing real risks to managing paperwork, while our346adversaries have already moved on.347    The goal is not less oversight. It is oversight and348measures whether our Nation's defenses are managing risks,349adapting to new intelligence, or shoring up our collective350defense. Those are the outcomes that strengthen national351security, cybersecurity the most.352    Third, under national Cyber Director Sean Cairncross's353leadership, the forthcoming National Cybersecurity Strategy is354expected to strengthen consequence-based responses and deepen355public-private coordination, an approach we strongly support.356Congress must reinforce that direction by restoring durable357information sharing authorities and pass a long-term358reauthorization of the CISA 2015 framework.359    At the same time, Congress and Federal agencies should360prioritize maximizing existing funding mechanisms. For example,361BEAD non-deployment funds and related Federal or State362initiatives should be strategically leveraged to strengthen the363capabilities of local and regional providers, including the364retirement of vulnerable end-of-life equipment and support for365cyber workforce development, ensuring that smaller providers366have sustained access to trained personnel who can effectively367manage the evolving threat environment.368    Congress and the Administration must also accelerate369efforts to speed up deployment of more secure and resilient370fiber broadband networks through much-needed broadband371permitting reform legislation as well as supporting efforts to372retire and reform network modernization rules.373    Finally, cybersecurity requires a whole-of-society approach374with shared responsibility that must be borne at all levels375across the private and public sectors. USTelecom and our376members and the sector writ large remain committed to working377shoulder-to-shoulder with our government partners and Congress378to outpace our adversaries and to protect the infrastructure379that Americans rely upon every day.380    Thank you for the opportunity to testify, and I look381forward to your questions.382    [The prepared statement of Mr. Mayer follows:]383384      Prepared Statement of Robert Mayer, Senior Vice President,385   Cybersecurity and Innovation, USTelecom--The Broadband Association386The Threat Landscape387    Chair Fischer, Ranking Member Lujan, and Members of the388Subcommittee:389390    Thank you for the opportunity to testify. I am Robert Mayer, Senior391Vice President of Cybersecurity and Innovation at USTelecom--The392Broadband Association whose members include the full scope of our393Nation's communications providers--including national, regional and394local companies and cooperatives. I also serve as Chair of the395Communications Sector Coordinating Council which represents broadcast,396cable, satellite wireless, and wireline industries. The mission of said397council is to ensure that communications networks and systems are398secure, resilient, and rapidly restored after a natural or man-made399disaster.400    Cybersecurity has become one of the most persistent and complex401national security challenges our country faces. That challenge spans402the Nation's entire critical infrastructure landscape. Energy systems,403financial networks, transportation systems, cloud environments, public404sector networks, and communications providers all contend with405sophisticated, state-backed and state-funded adversaries--such as406China, Russia, and Iran. These actors have positioned themselves to407conduct long-running campaigns designed not just to disrupt, but to408stealthily infiltrate multiple sectors of U.S. infrastructure.409    These threats are not hypothetical. In recent years, state-410sponsored actors have attempted to infiltrate or actually infiltrated:411U.S. energy grids, water utilities, ports, and telecommunications412infrastructure. Not only are these attacks more overt, more sustained,413and more aggressive than we have seen before, but the attack surface414has also gotten a lot broader. Instead of just denying service to a415single website or releasing ransomware at a single location, these416actors are looking to preposition deep into network infrastructure, and417they are looking at the entire ecosystem of cybersecurity, sometimes418using third-party vendors and other more distant access points to get419at critical infrastructure.420    Beyond incidents visible to the public lies the quiet, steady421probing by these state-sponsored adversaries who use automation,422machine learning, and tailored tradecraft to identify and exploit423vulnerabilities, test defensive reactions, and constantly adapt their424tactics, techniques and procedures. They do this across critical425infrastructure as a whole.426    In a landscape like this, cybersecurity cannot be treated as a427static checklist or a one-time investment. It has to be a continuous428mission: understanding how adversaries are changing, how technologies429are evolving, and where the most serious risks are emerging. It430requires close and continuous coordination between those who operate431critical systems and those in government who see the broader pattern of432foreign activity. Private industry is a critical stakeholder in this433environment, but we cannot do it alone.434    Our national response must remain anchored in a clear understanding435of responsibility: the culpability for these attacks lies with the436nation-states that conduct them, not the industries and organizations437that are aggressively working to defend against them. Importantly,438under the leadership of National Cyber Director Sean Cairncross, we439expect the updated U.S. National Cybersecurity Strategy will underscore440this point--emphasizing a more proactive, consequence-based approach441tied to real-world threats. As an industry, we stand ready to work442closely with the White House and Congress, aligning our capabilities443with the strategy's expected call for strengthened public-private444partnerships and shared defense efforts.445What We Are Doing446    Over the past two decades, the communications sector and the447Federal government have built a partnership model that has grown more448mature and more operational over time. In our sector, that449collaboration is organized through the Communications Sector450Coordinating Council (CSCC), which includes 57 companies of different451sizes, technologies, and regional footprints. The CSCC works closely452with the Government Coordinating Council, which brings together DHS,453CISA, the FCC, DOJ, the Department of War, NSA, and other agencies.454Together, these bodies provide the basic architecture for joint455planning, risk assessment, and information sharing. Providers456participate in regular operational briefings, including classified457briefings on a biweekly cadence, with CISA, law enforcement, as well as458military and intelligence agencies. In these settings, industry and459government experts discuss constantly evolving threats and mitigation460strategies.461    In addition to these recurring engagements, communications462providers participate in a broader ecosystem of public-private463collaboration. That includes the Joint Cyber Defense Collaborative,464which brings industry and government together on joint planning and465response; the Communications Information Sharing and Analysis Center,466which supports operational information sharing among providers; the467Network Security Information Exchange and the National Security468Telecommunications Advisory Committee, which provides technical and469strategic perspectives; and the Enduring Security Framework led by NSA470and CISA, which focuses on the intersection of national security and471commercial technology. Each of these forums plays a different role, but472together they create a fabric of collaboration that has proven its473value repeatedly.474    Cybersecurity programs are continuously evolving. Our members475meet--and very often exceed--cybersecurity requirements as conditions476for authorization to provide services, bid on government contracts, and477participate in government programs, as well as to ensure customer trust478in the competitive global marketplace.479    Not every network is the same. A large nationwide carrier, a480regional operator, and a local rural provider have unique network481architectures. But across the sector, you see the same themes: more482rigorous identity and access management; stronger protections around483administrative interfaces; increased segmentation of networks so that484an issue in one area does not automatically spread to others; more485systematic logging and analysis of activity; implementation of zero486trust architecture; and a steady push to close known vulnerabilities487faster.488    Recent campaigns attributed to sophisticated state-sponsored actors489have pushed these efforts further. Providers have shortened patching490timelines, reexamined remote-access configurations, expanded threat-491hunting programs that look for subtle indicators of compromise,492tightened vendor-security requirements, and invested in new analytic493capabilities that help distinguish normal from abnormal behavior in494large volumes of data. Many are also planning ahead for future classes495of risk, including the eventual need for quantum-resistant cryptography496to protect the most sensitive communications.497    Industry collaboration has deepened as well. Providers, through498CISO-level coordination among major North American carriers, are499standing up the Communications Cybersecurity Information Sharing and500Analysis Center (C2 ISAC), a next-generation platform for real-time501threat sharing and joint analysis. At USTelecom, we also have created502various coordinating and information-sharing platforms such as the503International Communications CISO Council (ICCC), and the Council to504Secure the Digital Economy (CSDE), bringing together high-level U.S.505and international executives to foster sharing best practices,506information, and insights. These initiatives reflect a simple reality:507no single company sees everything, and timely peer-to-peer sharing of508high-quality information makes every participant more resilient.509    All of this work takes place while communications providers510continue to deliver reliable service at national scale, all while511expanding both the infrastructure that will enable AI to promote512American economic competitiveness, scientific and engineering513discovery, and cyber defenses themselves, as well as the broadband514access that brings education, healthcare, and economic opportunity to515more Americans.516Call to Action517    Congress can help advance our sector's mission. The goal should be518to reinforce what is working in our national cybersecurity posture and519to avoid unintentionally weakening it.520    Foremost, our existing public-private partnership model should be521preserved and strengthened. The existing ecosystem--Sector Coordinating522Councils, Government Coordinating Councils, information-sharing523organizations, and joint planning bodies--gives us a way to bring524together operational experience and national-level intelligence. It has525the flexibility to evolve as threats evolve. It encourages frank526discussion and early reporting. Those are not easy things to recreate527once lost.528    From the perspective of communications providers, several529additional principles stand out. First, Congress can make a tangible530difference by strengthening information-sharing authorities. The CISA5312015 framework establishes clear guidance and protections that enable532companies to report threats quickly and safely. The current short-term533extension is helpful, but Congress must pass a long-term534reauthorization to maintain trust, improve early voluntary reporting,535and better align industry capabilities with Federal intelligence and536response efforts. Restoring those authorities would reinforce trust and537encourage the early voluntary reporting that is so important to538effective defense.539    As part of this information sharing, interagency collaboration540needs to be enhanced. We continue to see challenges in collaboration541between Federal agencies, which at times has placed the industry in the542position of helping coordinate between multiple agencies. Congress can543play an important role in driving more effective and sustained544interagency collaboration.545    Any, cybersecurity frameworks need to be flexible and adaptive.546While there may be a natural impulse to impose a detailed cybersecurity547checklist, when requirements are fixed in place they create two primary548problems; they lag behind adversaries who change their techniques549faster than any rule can be written, and they shift attention from550managing real risk to managing paperwork, which means a provider can be551fully compliant yet still exposed. Cybersecurity regulations end up552hardwiring yesterday's best practices into law while the adversary553moves on.554    In a sector as diverse as communications, technical prescriptions555are especially problematic for regional and smaller carriers that556differ widely in resources, size, topology, and technology. Forcing all557of them into a single mold will redirect limited resources away from558high value security investments.559    Most importantly, overly prescriptive mandates can have a chilling560effect on the very collaboration that has proven essential. When every561deviation from a mandated standard carries potential regulatory562consequences, organizations become more cautious about what they share563and who they share it with. Early and validated reporting of threats is564what allows a pattern to be recognized and properly addressed. We565should be encouraging companies to share information quickly and avoid566liabilities that make them hesitant to do so.567    Second, we must future-proof our Nation's cybersecurity investments568by ensuring American leadership in AI, quantum, and other emerging569technologies. The boundaries between cybersecurity and AI innovation570are becoming increasingly indistinguishable as AI becomes both a571critical tool for defending networks and a powerful capability in the572hands of adversaries. Strengthening our position in AI is therefore573inseparable from strengthening our cyber posture, which makes it all574the more essential to accelerate the infrastructure that AI depends on.575    In parallel with these efforts, Congress can help providers deploy576more modern and secure networks by retiring outdated copper577infrastructure regulation and streamlining AI infrastructure and578broadband permitting processes. Our members stand ready to deploy579modern networks, but permitting obstacles at the federal, state, and580local level result in costly delays. Congress should speed up National581Environmental Policy Act (NEPA) and National Historic Preservation Act582(NHPA) approvals for AI infrastructure and broadband permits.583    Third, policy should ensure that local and regional providers are584not left behind. While large carriers may have extensive internal585cybersecurity resources dedicated to engagement with federal partners,586smaller providers do not always have that opportunity. Existing funding587mechanisms--such as BEAD non-deployment funds and related Federal or588state initiatives--should therefore be strategically leveraged to589strengthen local and regional providers' capabilities, including the590retirement of vulnerable end-of-life equipment. These programs can also591play a critical role in supporting cyber workforce development,592ensuring that smaller providers have sustained access to trained593personnel who can effectively manage evolving threats.594    Communications providers are committed to doing their part. We are595investing significantly in our own defenses, engaging actively in596public-private partnerships, and recognizing that the threat597environment is only growing more complex. Cybersecurity is a shared598responsibility, and the most effective path forward is one that599combines operational expertise, national-level intelligence, and policy600frameworks that support collaboration rather than rigidity.601602    Senator Fischer. Thank you, Mr. Mayer. Mr. Gizinski, you603are now recognized for your opening statement.604605STATEMENT OF DANIEL GIZINSKI, PRESIDENT OF SATELLITE AND SPACE606                COMMUNICATIONS SEGMENT, COMTECH607608    Mr. Gizinski. Chair Fischer, Ranking Member Lujan, members609of the Subcommittee, I appreciate the opportunity to speak610before you today.611    America's communications infrastructure is under increasing612pressure from foreign adversaries who are using advanced613techniques to infiltrate, disrupt, and exploit our networks.614Satellite communications are a critical part of that615infrastructure. Satellites have long served a quiet but616critical role in supporting global communications, and over the617past few years we have seen a tremendous pace of innovation,618including the emergence of build-out of large-scale, non-619geostationary orbit constellations, such as SpaceX's Starlink,620Amazon's Leo constellation, and many others.621    We have also seen the emergence of the directed device622market, connecting smartphones and other small devices directly623to satellites, with companies like Apple, AST SpaceMobile, and624Lynk Global.625    One of the unique benefits of satellites is the global626reach, which also increases the attack surface of those627systems. Many of the satellites providing coverage to the628United States expose network traffic far outside of our629borders.630    Yet we have seen that cybersecurity practices in the sector631have not kept pace. A recent study by researchers at the632University of California, San Diego, and the University of633Maryland showed the ability to intercept sensitive traffic634across a number of satellites. Other published studies explore635some of the risks satellites are exposed to across their space636segment, user segment, and ground segment, each with unique637considerations and complexities.638    In the case of the space segment, components are typically639not accessible following launch, which limits the ability to640field certain updates. While there are certain fixes available641for certain use cases, what I refer to as commonsense cyber642hygiene, things like enabling encryption either on the643satellite modem or inline, serve as a low-cost and simple step644and something that we recommend to our customers. We note that645many of the existing satellite security compliance frameworks646that are in place today also recommend this, but despite that647we still see many networks operated without this key protection648step in place.649    Strong cyber posture can be built effectively with a650framework that brings together both government and industry to651share threat intelligence, align incentives, and respond652quickly to emerging risks. Protection requirements should be653aligned with risk, understanding that not all data requires the654same treatment. Our adversaries are looking forward in their655approach to developing attacks, and our defense posture should656reflect that.657    First, we most promote information sharing, both amongst658government and within industry. Establishing a broad forum that659allows for free and open information sharing has strong660industry support including from the Satellite Industry661Association, who represents a number of domestic satellite662industry members.663    Second, we should consider how to move beyond rigid,664compliance-only frameworks toward incentive-based models.665Static checklists and controls are inherently rearward-facing,666whereas a balanced model would allow for industry to be667rewarded for a forward-looking security posture, offering668incentive for those that invest in proactive security measures669or contribute meaningfully toward collaborative threat670mitigations that benefit the sector at large. This cultural671shift will be key to promoting innovation and security that672keeps pace with the rate of commercial innovation.673    Third, cybersecurity must be designed in from the674foundation. This means building subcomponents to be secure by675design, and including the supply chain and threat sharing and676mitigation planning. It also means ensuring that security677frameworks extend to hardware and software vendors with close678attention paid to the source of these critical subcomponents.679    Satellite connectivity supports a wide range of critical680daily services, and is playing a central role in helping expand681connectivity access to underserved communities. It is also a682key enabler of defense and emergency response operations and683continuing to drive innovation across many other industries.684The cyber threats that this sector faces are real, and they are685evolving quickly. If we want to ensure the long-term resilience686and security of this sector, we need to give it the attention687it deserves.688    [The prepared statement of Mr. Gizinski follows:]689690 Prepared Statement of Daniel Gizinski, President, Satellite and Space691                  Segment, Comtech Telecommunications692    Chairman Fischer, Ranking Member Lujan, and Members of the693Subcommittee,694695    Thank you for the opportunity to speak with you today. My name is696Daniel Gizinski, and I serve as President of the Satellite and Space697Communications (S&S) Segment at Comtech. Today, Comtech delivers698resilient, high-performance satellite ground systems and secure699communications technologies that enable real-time connectivity for700government, defense, and commercial missions--most of which are701designed, manufactured, and supported in the US. I appreciate the702opportunity to contribute to this important discussion.703    As this Subcommittee has recognized, America's communications704infrastructure is under increasing pressure from foreign adversaries705who are using advanced technologies to infiltrate, disrupt, and exploit706our networks. Satellite communications are a critical part of that707infrastructure. They enable everything from global military operations708to emergency response and commercial connectivity. And yet, they have709historically received less attention than terrestrial networks when710considering cybersecurity and our national defense posture.711    Since their inception, satellites have played a foundational role712in global communications. Geostationary satellites (GEO) have long713provided backhaul for remote cellular towers, broadcast services, and714critical infrastructure links. For areas underserved by fiber or715terrestrial wireless networks--remote, rural, mountainous regions, or716even maritime environments--satellite links have often been the only717feasible way to transport traffic.718    The industry has seen tremendous innovation over the past five719years, including the emergence and build-out of large-scale non-720geostationary orbit (NGSO) constellations, including SpaceX's Starlink,721Amazon's Leo constellation (formerly Project Kuiper), SES's O3b mPOWER722network, and Eutelsat OneWeb, among many others. These systems deliver723high-speed, low-latency connectivity to users around the world,724including in rural and underserved areas where traditional725infrastructure doesn't reach and enable new capabilities in maritime,726aviation, defense, and enterprise markets.727    At the same time, we're seeing the emergence of the direct-to-728device market--connecting smartphones and other small devices directly729to satellite with companies like Apple, AST SpaceMobile, and Lynk730Global. This has the potential to transform emergency response, expand731mobile coverage globally, and provide critical connectivity services in732underserved locations or areas impacted by natural disasters.733    What makes this moment especially important is the pace of change.734Unlike traditional geostationary satellites, which typically have an735operational lifecycle of 15 to 20 years, low-earth orbit (or LEO)736constellations are built on much shorter technology cycles, typically 5737to 7 years. That means the industry is evolving quickly, with new738capabilities and risks emerging constantly. Our regulatory and security739frameworks need to keep up.740    At the same time, the threat landscape is becoming more complex.741Satellite networks naturally present a broader attack surface than742terrestrial systems--many of the satellites providing coverage to the743United States expose network traffic outside of our borders.744    Yet many of the cybersecurity practices in the sector haven't kept745pace. A recent study by researchers at the University of California,746San Diego, and the University of Maryland\1\, showed that a significant747number of geostationary satellite signals are still being transmitted748without encryption. Using an $800 off-the-shelf receiver and a rooftop749dish, the researchers were able to intercept sensitive data from750commercial airlines, cellular networks, critical infrastructure, and751even military and law enforcement communications.752---------------------------------------------------------------------------753    \1\ Don't Look Up: There Are Sensitive Internal Links in the Clear754on GEO Satellites755---------------------------------------------------------------------------756    This wasn't a sophisticated cyberattack. It was a clear example of757how basic security practices like encryption are still not universally758applied, even when called for by existing security frameworks.759    Additional research has revealed vulnerabilities in commercial760satellite modems, including insecure firmware update paths, exposed web761interfaces, and outdated protocols. In a number of instances,762encryption was disabled by default.\2\ A number of other attack methods763have been demonstrated against a variety of satellite systems.\3\ One764of the potential reasons this has not been more readily explored is765there is little reward to attract low-level cyber criminals to766satellite systems--in contrast, there is substantial interest to767nation-state actors. Our security posture must recognize the level of768sophisticated threat actors these systems face.769---------------------------------------------------------------------------770    \2\ A Comprehensive Analysis of Security Vulnerabilities and771Attacks in Satellite Modems772    \3\ PowerPoint Presentation773---------------------------------------------------------------------------774    Five main threat actors and advanced persistent threat (APT) groups775have targeted satellite communications technology, with others having776conducted attacks as well (Flashpoint, 2024). These attacks include777exploiting legacy protocols, insecure firmware, and unpatched systems778to gain access to sensitive data and disrupt operations.779    We strongly encourage a thoughtful approach to securing these780critical systems. Satellite communications provide a lifeline for both781defense and commercial users. Today, satellites enable global command782and control, real-time intelligence sharing, logistics coordination,783and resilient communications in denied or degraded environments.784Enterprises rely on satellite networks for everything from maritime and785aviation connectivity to oil and gas operations, disaster response, and786financial transactions. A successful cyberattack on a commercial787satellite link or gateway could disrupt services across continents,788compromise customer data, or even impact national economies. At the789same time, many of these systems are highly complex, expensive, and790take a significant amount of time to deploy, which may limit the pace791at which new defensive capabilities can be reasonably fielded.792Satellite systems are exposed to risks across their space segment, user793segment, link segment, and ground segment--each with unique794considerations and complexities.\4\795---------------------------------------------------------------------------796    \4\ Recommendations to Space System Operators for Improving797Cybersecurity798---------------------------------------------------------------------------799    In the case of the space segment--components are typically not800accessible following launch, which limits the ability to field certain801updates. There are simple fixes available for certain use cases--what I802refer to as common-sense cyber hygiene. Enabling encryption, either on803the satellite modem or in-line, is a low cost and simple step, and one804we recommend to our customers--as do many of the existing satellite805security compliance frameworks.\5\ Despite many frameworks calling for806encryption on satellite links, we still see networks operated without807this protection step in place.808---------------------------------------------------------------------------809    \5\ Security and Privacy Controls for Information Systems and810Organizations Introduction to Cybersecurity for Commercial Satellite811Operations812---------------------------------------------------------------------------813    Rigid, rules-based frameworks often rely on static checklists and814controls that have been written and developed in response to past815incidents, rather than in anticipation of future threats. Flexible816frameworks that promote collaboration between industry and Government,817encourage thoughtful risk-based decision-making, and enable flexibility818will be key to developing a culture of innovation around cybersecurity.819This cultural shift will be key to promoting innovation in security820that keeps pace with commercial innovation.821    Strong cyber posture can be built effectively with a framework that822brings together government and industry to share threat intelligence,823aligns incentives, and responds quickly to emerging risks. Protection824requirements should be aligned with risk, understanding that not all825data requires the same treatment. Our adversaries are looking forward826in their approach to developing attacks, and our defense posture should827reflect that.828    First, information sharing at the speed of relevance is critical,829and a point that has broad support across the industry. The Satellite830Industry Association (SIA) is a US-based trade association that831provides representation of leading domestic satellite operators,832service providers, manufacturers, and more.\6\ SIA has long emphasized833that cybersecurity is central to the satellite industry's mission of834providing secure, reliable, and resilient connectivity. SIA also835highlights the importance of voluntary information sharing. Sector836participants often face common threats, and they must be free to837collaborate among themselves and with government to identify and838respond to attacks, share mitigations, and learn from past experiences.839Information sharing benefits should be secure, confidential, and free840from fear of liability or regulatory consequences. This principle is841essential to building trust and strengthening the entire ecosystem.842Ensuring that this collaboration includes both industry and government843perspectives is critical in an era where sophisticated attacks are844common.845---------------------------------------------------------------------------846    \6\ About Satellite Industry Association (SIA)--Washington, DC847---------------------------------------------------------------------------848    Second, I believe we should consider how to move beyond compliance-849only frameworks and begin incorporating incentive-based models into our850cybersecurity posture. Today, much of the focus is on penalties for851breaches or non-compliance. But there's also an opportunity to reward852forward-looking behavior and encourage industry to bring innovative853approaches forward. Organizations that invest in proactive security854measures, adopt modern encryption standards, or participate in855collaborative threat-sharing initiatives could benefit from things like856tax credits, grants, or streamlined certification processes.857Cybersecurity tends to operate as a cost-center in most organizations,858and an incentive program would help industry thoughtfully allocate both859effort and talent. These are ideas worth exploring as part of a860balanced and practical approach to security.861    Third, we need to recognize that cybersecurity can't be an862afterthought. It has to be built in from the start, across all layers863of a system. That means designing subcomponents with security in mind:864secure boot, memory-safe programming languages, authenticated firmware865updates, and architectural decisions that prioritize security alongside866performance and cost\7\. This means extending threat sharing beyond867service providers to many levels of the supply chain, ensuring that all868layers of the tech stack are designed with security in mind. Supply869chain security remains a critical component, and ensuring that870appropriate attention is paid to both the origin of hardware and871software is key\8\.872---------------------------------------------------------------------------873    \7\ Cybersecurity in the Space Domain: Why It's Time to Stop874Leaving the Front Door Unlocked--Comtech Telecommunications Corp.875    \8\ Comtech-WP-Ground-Station-Cyber-Threats-and-Product-Design-876Techniques-for-Defense.pdf877---------------------------------------------------------------------------878    There's also a growing gap between the people writing cybersecurity879policy and the people building the systems. We're seeing more880professionals enter the field who understand the security rules but may881not fully understand the full architecture, product technology,882ecosystem, and/or the potential threat landscape. We need to make sure883cybersecurity expertise is integrated into system design from the884beginning, not added on later.885    With the exponential growth and technology trajectories of this886sector and satellite connectivity becoming increasingly interwoven into887the daily fabric of our lives and our Nation's security, it's clear888that satellite communications must be treated as a priority within our889national communications infrastructure. Satellite connectivity890currently supports a wide range of critical daily services, it is891playing a central role in helping expand connectivity access to892underserved communities, it is a key enabler of defense and emergency893response operations, and satellite connectivity is continuing to drive894innovation across industries. The cyber threats this sector faces are895real, and they are evolving quickly. If we want to ensure the long-term896resilience and security of this sector, we need to give it the897attention it deserves and be willing to rethink how we approach898oversight, collaboration, and innovation.899    I appreciate the opportunity to appear before you today on behalf900of the satellite industry and I am happy to answer any questions.901902    Senator Fischer. Thank you, Mr. Gizinski. Mr. Jaffer, you903are recognized for your opening statement.904905           STATEMENT OF JAMIL N. JAFFER, FOUNDER AND906907EXECUTIVE DIRECTOR, NATIONAL SECURITY INSTITUTE, ANTONIN SCALIA908              LAW SCHOOL, GEORGE MASON UNIVERSITY909910    Mr. Jaffer. Chairman Fischer, Ranking Member Lujan, and911members of the Subcommittee, thank you for taking the time and912for having me here to testify today.913    The unfortunate fact is that we are at war in the cyber914domain today. It is low-level war. Our adversaries are coming915after us day in and day out. The attacks on our system and our916communications infrastructure are constant. China, for one, has917engaged in a wide-scale effort to penetrate every aspect of918America's telecommunications infrastructure, from wire line to919wireless, from undersea cables to our satellite infrastructure.920They are in a constant effort to come after us.921    Russia is similar. Since 2019, Russia has had the922capability to conduct disruptive and destructive attacks,923according to the Director of National Intelligence. China has924now begun deploying that capability, as well, primarily925overseas, but also here in the United States.926    This is an important point. It is important because at this927time in our Nation's history we must remember that President Xi928has told his armed forces to be prepared to invade Taiwan by9292027. If, in fact, President Xi makes good on that effort, and930if the United States decides to push back, we may very well be931in a shooting war with China in the very near future. That932shooting war will not only be in that domain, it will typically933be in the cyber domain, as well. China will engage in efforts934to not only surveil American systems but to go after them935aggressively. And if they have put in place these disruptive936and destructive capabilities that we have seen since Volt937Typhoon was in place, they will use those capabilities to our938detriment.939    It is not just China and Russia, though. Iran and North940Korea, as well, have begun building up their cyber capabilities941and are becoming serious and capable actors. And unlike China942and Russia, it is much harder to deter nations like Iran and943North Korea.944    Of course, in the cyber domain, there are a lot of people945who believe that deterrence is not successful or not possible.946But the reality is that we do not practice deterrence in the947cyber domain to defend our communications infrastructure. The948reality is that our adversaries do not know where our red lines949are. They do not know what we would do if those red lines were950crossed. And to the extent that we do enforce our red lines on951occasion in the cyber or telecommunications domain, we do not952do it in a way that other adversaries can see. As a result, the953deterrent effect is limited.954    If we are going to successfully prevent China and Russia955and Iran and North Korea from taking action against our956telecommunications infrastructure, we must make it clear to957them, at a governmental level, that we will view an attack on958our communications infrastructure as an attack on our Nation959and respond accordingly.960    Beyond that there are big debates about what we should do961about hacks like Salt Typhoon, where the Chinese government was962successfully able to infiltrate and deeply penetrate our963telecommunications infrastructure. On one hand you have the964prior FCC action seeking to effectively and aggressively965regulate our telecommunications infrastructure. On the other966hand, you have a voluntary approach adopted by the current FCC967Chairman. And in the middle you have a question about what the968government should have done about Salt Typhoon.969    We have now learned that the government actually identified970the Salt Typhoon attackers before they came after our971telecommunications infrastructure. We also knew that for years972China had been targeting our telecommunications infrastructure973and have not successfully gotten as deep as they expected. In974many ways, this is like what happened before 9/11. We knew the975attack was coming. We knew it was being planned. We did not976know where. We even identified operatives in Kuala Lumpur. We977just did not know they were coming to the United States. The978same was true of the Salt Typhoon. We knew they were coming979after our infrastructure. They were in our networks. We had980seen them. We did not realize what they were doing to our981telecommunications industry. And the question is, why didn't982the government take more aggressive efforts to protect its own983information, its own infrastructure and our Nation's984infrastructure, and why today is the government's position that985we should aggressively regulate rather than partnering to986effectively achieve success?987    These are difficult questions, but the truth is if we do988not answer those questions today, in the relative peace of the989current moment, even in the low-level war that we are in, we990will face significant and effective attacks on our991infrastructure by our adversaries, if and when that day comes992to pass.993    We cannot allow that day to come to pass, and that is why,994in this moment, it makes sense to find ways to partner, going995forward. The first and most effective thing Congress can do is996to reauthorize the Cyber Information Sharing Act that was997passed in 2015, and was recently reauthorized for a brief998period as part of the government reopening effort.999    But that law can be strengthened. There are those in the1000Senate who actually reduce the effectiveness of those laws and1001would limit their scope. The right thing to do here actually is1002to expand their scope, provide more liability and regulatory1003protection, and provide incentives to our industry to do better1004and be more effective. If we can partner more effectively and1005really build truly on a public and private partnership, that is1006how to be most successful in defending our communications and1007our technology infrastructure at this important time in our1008Nation's history.1009    Thank you for your time, and I appreciate the opportunity,1010and I look forward to your questions.1011    [The prepared statement of Mr. Jaffer follows:]10121013    Prepared Statement of Jamil N. Jaffer\1\ on Signal Under Siege:1014             Defending America's Communications Networks\2\1015---------------------------------------------------------------------------1016    \1\ Jamil N. Jaffer currently serves as Founder & Executive1017Director of the National Security Institute and the NSI Cyber & Tech1018Center and as an Assistant Professor of Law and Director of the1019National Security Law & Policy Program and the Cyber, Intelligence, and1020National Security LL.M. Program at the Antonin Scalia Law School at1021George Mason University. Mr. Jaffer is also a Venture Partner at1022Paladin Capital Group, a leading global multi-stage investor that1023identifies, supports and invests in innovative companies that develop1024promising, early-stage technologies to address the critical cyber and1025advanced technological needs of both commercial and government1026customers. Mr. Jaffer serves on a variety of public and private boards1027of directors and advisory boards, including as a member of the Virginia1028Governor's Task Force on Artificial Intelligence. Among other things,1029Mr. Jaffer previously served as Chief Counsel & Senior Advisor to the1030Senate Foreign Relations Committee, Senior Counsel to the House1031Intelligence Committee, Associate Counsel to President George W. Bush1032in the White House, and Counsel to the Assistant Attorney General for1033National Security in the U.S. Department of Justice, as well as a1034member of the Cyber Safety Review Board at the Department of Homeland1035Security. Mr. Jaffer is testifying before this Subcommittee in his1036personal and individual capacity and is not testifying on behalf of any1037organization or entity, including but not limited to any current or1038former employer or public or private entity.1039    \2\ Significant portions of this testimony have been drawn in whole1040or in part from prior testimony provided to the House and Senate by Mr.1041Jaffer, including, in particular, from Mr. Jaffer's testimony provided1042to the United States House of Representatives Committee on Energy &1043Commerce's Subcommittee on Communications & Technology in April 2025.1044Citations to and quotations marks from such testimony have been1045omitted, including the significant portions of Mr. Jaffer's prior1046testimony which have been excerpted verbatim herein.1047---------------------------------------------------------------------------1048I. Introduction1049    Chairman Fischer, Ranking Member Lujan, and Members of the1050Subcommittee: thank you for inviting me here today to discuss the1051threats facing America's communication networks and how we might best1052defend this critical part of our Nation's infrastructure.1053    This hearing comes at a particularly important time in our Nation's1054history, as we see a series of major technological revolutions1055underway, with artificial intelligence capabilities being brought to1056bear across a broad range of industries and within our government and1057that our allies as well, the near-dawn of the quantum computing era,1058the potential availability of photonics for computing, and expanding1059access to extremely fast and reliable communications capabilities that1060permit the transmission of increasingly massive amounts of data around1061the globe at the speed of light.1062    At the same time, we also see the very core infrastructure that1063these new and novel capabilities depend upon being held at risk, under1064significant threat, by our adversaries, in particular, by nations like1065China, Russia, Iran, and North Korea and their proxies. The threats1066posed by these nation-states and those that they support and allow to1067operate, include efforts to steal our technology at huge scale, to1068limit our ability to design, manufacture, and deploy the massive1069computing infrastructure necessary to sustain and grow these1070revolutionary capabilities, to prevent us from accessing and using data1071necessary to train and employ the mathematical models and algorithms1072that undergird AI and other cutting-edge technologies, to threaten our1073ability to consistently supply the power needed to drive these1074technologies, and, perhaps most importantly for today's hearing, to1075hold at risk the very telecommunications network infrastructure and1076systems that our people, our companies, and our government rely upon to1077provide access to these capabilities and to transmit the data around1078the globe.1079    Indeed, in recent months and years, we've seen the threat landscape1080created by nation-state actors and their proxies, expand significantly.1081Just in the last month, we've learned that Chinese nation-state actors1082utilized Anthropic's Claude Code capabilities and infrastructure1083earlier this fall to launch semi-autonomous hacks against nearly three1084dozen global governments and private sector organizations.\3\ And long1085prior this effort, we've learned about other major threats targeting1086the both America's cyber and telecommunications infrastructure as well1087as that of our allies, including actual hacks and capabilities being1088put in place for destructive attacks--particularly but not exclusively,1089coming from China and its ruling cabal of the Chinese Communist Party1090(CCP).1091---------------------------------------------------------------------------1092    \3\ See Anthropic, Disrupting the First Reported AI-Orchestrated1093Cyber Espionage Campaign (Nov. 2025), available online at .1094---------------------------------------------------------------------------1095    Moreover, while credible reports from last year indicate that the1096Chinese government has successfully penetrated deep into American1097telecommunications networks, and has also sought to put in place1098destructive capabilities at the heart of American and allied critical1099infrastructure--these efforts, known as Salt Typhoon and Volt Typhoon,1100respectively, are part of a much larger and more troubling story. As it1101turns out, there is a significant effort afoot in the cyber domain,1102architected not just by China, but also by Russia, Iran, and North1103Korea, and a wide range of proxy actors operating on their behalf, to1104target America's communications infrastructure, and that of our allies1105and partners as well.1106    These efforts are aimed not only at collecting information and1107intelligence on American government officials and our Federal policies1108and priorities, but also at stealing our intellectual property,1109collecting massive amounts of data and intelligence on our citizens1110and, perhaps most troubling, putting in place capabilities that can be1111used to destructive effect when they choose to do so.1112    These efforts also stretch across significant parts of our Nation's1113critical infrastructure and are aimed--in various forms--at both the1114government and key industries, including our financial services,1115energy, telecommunications, and technology sectors, just to name a few.1116    While today's hearing is focused on threats to America's1117communications networks (and the technology that rides on top of it)1118and assessing what we can do to better defend those networks and1119systems, it is important that we understand these threats--and our1120response--in the context of two key issues: (1) the larger national1121security threat and competition from China, including its key economic1122and technological elements; and (2) the ongoing and increasingly robust1123collaboration between our adversaries in China, Russia, Iran, and North1124Korea.1125II. The Threat Environment Facing America and Our Communications1126        Networks1127A. China1128    Starting with China, the current Director of National Intelligence,1129in her first-ever Annual Threat Assessment of the Intelligence1130Community provided earlier this year, has made clear that the People1131Republic of China (PRC) ``presents the most comprehensive and robust1132military threat to U.S. national security . . . [with] a joint force1133that is capable of full-spectrum warfare'' and active efforts ongoing1134that are ``aimed at making the PLA a world-class military by 2049.''1135\4\ As a result, the DNI expects that China will seek to remain ``in a1136position of advantage in a potential conflict with the United1137States . . . [while also] . . . conducting wide-ranging cyber operations against1138U.S. targets for both espionage and strategic advantage.'' \5\1139---------------------------------------------------------------------------1140    \4\ See Office of the Director of National Intelligence, Annual1141Threat Assessment of the U.S. Intelligence Community (Mar. 2025), at 9,1142available online at .1143    \5\ Id. at 10, available online at .1144---------------------------------------------------------------------------1145    At the same time, the DNI expects that ``Beijing will continue to1146strengthen its conventional military capabilities and strategic forces,1147intensify competition in space, and sustain its industrial-and1148technology-intensive economic strategy to compete with U.S. economic1149power and global leadership.'' \6\ Moreover, as we think about the most1150likely flashpoint with China--over Taiwan (which CCP leader Xi Jinping1151has told his military to be prepared to invade in 2027,\7\ just over a1152year from now)--it is worth noting that the DNI is of the view that1153``[a] conflict between China and Taiwan would disrupt U.S. access to1154trade and semiconductor technology critical to the global economy . . .1155[and] [e]ven without U.S. involvement in such a conflict, there would1156likely be significant and costly consequences to U.S. and global1157economic and security interests.'' \8\1158---------------------------------------------------------------------------1159    \6\ Id. at 9.1160    \7\ See William J. Burns, Transcript: Trainor Award Ceremony1161Honoring CIA Director William J. Burns (Feb. 9, 2023), available online1162at  (``[O]ur assessment at CIA is1163that I wouldn't underestimate President Xi's ambitions with regard to1164Taiwan. . . . We know, as a matter of intelligence, that he's1165instructed the People's Liberation Army to be ready by 2027 to conduct1166a successful invasion.'')1167    \8\ See 2025 Annual Threat Assessment, supra n. 4 at 11.1168---------------------------------------------------------------------------1169    Speaking specifically about threats to American networks writ1170large, the DNI has stated unambiguously that China ``remains the most1171active and persistent cyber threat to U.S. government, private-sector,1172and critical infrastructure networks[,]'' \9\ further noting that that1173``China has demonstrated the ability to compromise U.S. infrastructure1174through formidable cyber capabilities that it could employ during a1175conflict with the United States.'' \10\ Indeed, the DNI's view is that,1176if China believes ``a major conflict with Washington [is] imminent, it1177could consider aggressive cyber operations against U.S. critical1178infrastructure and military assets,'' with the specific aim of1179``deter[ring] U.S. military action by impeding U.S. decision-making,1180inducing societal panic, and interfering with the deployment of U.S.1181forces.'' \11\1182---------------------------------------------------------------------------1183    \9\ Id. at 11.1184    \10\ Id. at 9.1185    \11\ Id. at 12.1186---------------------------------------------------------------------------1187    And this is where the Volt Typhoon and Salt Typhoon efforts by1188China come into play. The DNI has stated that the Volt Typhoon1189``campaign [by China] to preposition access on critical infrastructure1190for attacks during crisis or conflict,'' and the ``more recently1191identified compromise of U.S. telecommunications infrastructure [by1192China], also referred to as Salt Typhoon, demonstrates the growing1193breadth and depth of the PRC's capabilities to compromise U.S.1194infrastructure.'' \12\1195---------------------------------------------------------------------------1196    \12\ Id. at 11.1197---------------------------------------------------------------------------1198    Truth be told, none of this new when it comes to China. Since at1199least 2019, over half a decade ago, the U.S. Intelligence Community has1200been flagging that ``China presents a persistent cyber espionage threat1201and a growing attack threat to our core military and critical1202infrastructure systems,'' and specifically warning that China ``is1203improving its cyber attack capabilities,'' and noting specifically that1204``China has the ability to launch cyber attacks that cause localized,1205temporary disruptive effects on critical infrastructure--such as1206disruption of a natural gas pipeline for days to weeks--in the United1207States.'' \13\1208---------------------------------------------------------------------------1209    \13\ See Daniel R. Coats, Statement for the Record: Worldwide1210Threat Assessment of the U.S. Intelligence Community (Jan. 29, 2019),1211at 5, Senate Select Committee on Intelligence, available online at1212.1213---------------------------------------------------------------------------1214    This drumbeat continued into 2021, with the then-new Administration1215warning that ``China presents a prolific and effective cyber-espionage1216threat, possesses substantial cyber-attack capabilities, and presents a1217growing influence threat[,]'' and specifically noting that China both1218``can launch cyber attacks that, at a minimum, can cause localized,1219temporary disruptions to critical infrastructure within the United1220States[,]'' and noting specifically--for the first time--that China's1221``cyber-espionage operations have included compromising1222telecommunications firms, providers of managed services and broadly1223used software, and other targets potentially rich in follow-on1224opportunities for intelligence collection, attack, or influence1225operations.'' \14\1226---------------------------------------------------------------------------1227    \14\ See Office of the Director of National Intelligence, Annual1228Threat Assessment of the U.S. Intelligence Community (Apr. 9, 2021), at12298, available online at  (emphasis added).1230---------------------------------------------------------------------------1231    This was followed, in 2022, with continued warnings of China's1232``almost certain[]'' capability ``to launch[] cyber attacks that would1233disrupt critical infrastructure services within the United States,1234including against oil and gas pipelines and rail systems,'' and noting1235once again the threat to telecommunications, software and other target1236rich environments.\15\1237---------------------------------------------------------------------------1238    \15\ See Office of the Director of National Intelligence, Annual1239Threat Assessment of the U.S. Intelligence Community (Feb. 7, 2022), at12408, available online at .1241---------------------------------------------------------------------------1242    It is also worth noting that these threats in the cyber domain,1243including to American communications networks--both historic and1244ongoing--are undergirded by China's efforts to ``dominat[e] global1245markets and strategic supply chains . . . making other nations1246dependent on China[,]'' particularly in areas that are critical to1247United States technology leadership, such as critical minerals,1248semiconductors, and artificial intelligence.\16\ For example, the1249current DNI has made clear that ``China's dominance in the mining and1250processing of several critical materials is a particular threat,1251providing it with the ability to restrict quantities and affect global1252prices.'' \17\ We also know that China seeks to ``become a global1253[science and technology] superpower, surpass the United States, promote1254self-reliance, and achieve further economic, political, and military1255gain . . . [by] prioritiz[ing] technology sectors such as advanced1256power and energy, AI, biotechnology, quantum information science, and1257semiconductors.'' \18\1258---------------------------------------------------------------------------1259    \16\ See 2025 Annual Threat Assessment, supra n. 4 at 12.1260    \17\ See id.1261    \18\ Id. at 13.1262---------------------------------------------------------------------------1263    And the tie-in between these efforts and the threats to our1264telecommunications and cyber infrastructure is that the Chinese are1265actively exploiting our communications networks to juice their efforts1266to become a technology superpower. They are doing so in a range of1267ways, including engaging in intellectual property theft at industrial1268scale, with the DNI noting that China is directly stealing ``hundreds1269of gigabytes of intellectual property from companies in Asia, Europe,1270and North America in an effort to leapfrog over technological hurdles,1271with as much as 80 percent of U.S. economic espionage cases as of 20211272involving PRC entities.'' \19\ China also use its intelligence1273collection capabilities on U.S. networks to identify investments,1274recruit talent, evade sanctions, and conduct cyber operations, all of1275which are key parts of their effort to ``accelerat[e] [China's] S&T1276progress through a range of licit and illicit means.'' \20\1277---------------------------------------------------------------------------1278    \19\ Id.1279    \20\ Id.1280---------------------------------------------------------------------------1281    And it is worth noting that China's ongoing ``multifaceted,1282national-level strategy designed to displace the United States as the1283world's most influential AI power by 2030,'' \21\ is not simply aimed1284at economic gain but is also designed to support China's intelligence1285collection efforts and its larger plan to undermine American national1286security.1287---------------------------------------------------------------------------1288    \21\ Id.1289---------------------------------------------------------------------------1290    Indeed, the current DNI has made clear that ``Chinese AI firms are1291already world leaders in voice and image recognition, video analytics,1292and mass surveillance technologies,'' and that the ``[t]he PLA probably1293plans to use large language models (LLMs) to generate information1294deception attacks, create fake news, imitate personas, and enable1295attack networks.'' \22\1296---------------------------------------------------------------------------1297    \22\ Id.1298---------------------------------------------------------------------------1299    It goes without saying that these Chinese intelligence collection1300efforts and covert and overt messaging operations take place over the1301entirety of America's communications networks. One obvious example is1302very real threat posed by TikTok to America's national security.\23\1303While many Americans--and perhaps some key leaders and policymakers--1304view TikTok primarily as a way to watch a bunch of kid and dog videos,1305the fact is that TikTok's extensive collection of data on Americans and1306our allies, its ties to the Chinese Communist Party, and the Chinese1307government's influence over TikTok's algorithm, makes it a unique and1308serious national security threat. \24\1309---------------------------------------------------------------------------1310    \23\ See, e.g., Protecting Americans from Foreign Adversary1311Controlled Applications Act, Pub. L. No. 118-50, div. H, 138 Stat. 9551312(2024); The White House, Protecting Americans' Sensitive Data from1313Foreign Adversaries, 86 Fed. Reg. 31423 (June 9, 2021); The White1314House, Addressing the Threat Posed by TikTok, 85 Fed. Reg. 48637-381315(Aug. 6, 2020).1316    \24\ See Brief of Amicus Curiae Former National Security Officials,1317TikTok Inc., et al., v. Merrick B. Garland, No. 24-1113 (S. Ct.) (filed1318Dec. 27, 2024), available online at .1319---------------------------------------------------------------------------1320    Indeed, when one combines the massive amount of data that TikTok1321collects on its users with other data stolen by Chinese government1322hackers, including security clearance files and the sensitive1323financial, health, and travel data of millions of Americans, it is1324clear that the Chinese government can use this data--powered by AI--to1325drive future sophisticated intelligence collection and disinformation1326campaigns targeting Americans and our allies.\25\1327---------------------------------------------------------------------------1328    \25\ Id. at 4-13.1329---------------------------------------------------------------------------1330    As if this weren't enough, it is worth noting that China also seeks1331to increase its already central role in the semiconductor supply chain1332to undermine U.S. communications networks, including our ability to1333build them and to secure them. The DNI has identified that the China1334has ``made progress in producing advanced 7-nanometer (nm)1335semiconductor chips for . . . cellular devices using previously1336acquired deep ultraviolet (DUV) lithography equipment,'' and has noted1337that while they may face volume production challenges, China is also1338continuing to ``explore applying advanced patterning techniques to DUV1339machines to produce semiconductor chips as small as 3nm,'' \26\ a claim1340that appears to be supported by reporting earlier this year that1341Chinese semiconductor company SMIC has managed to manufacture 5 nm1342chips using such techniques with DUV machines.\27\ And, of course, the1343DNI rightly notes that ``China [already] leads the world in legacy1344logic semiconductor (28nm and up) production, accounting for 39.31345percent of global capacity, and is expected to add more capacity than1346the rest of the world combined through 2028[,]'' for chips that are1347``vital to producing automobiles, consumer electronics, home1348appliances, factory automation, broadband, and many military and1349medical systems,'' \28\ including critical parts of our1350telecommunications networks and systems.1351---------------------------------------------------------------------------1352    \26\ See 2025 Annual Threat Assessment, supra n. 4 at 14.1353    \27\ See Ananya Gairola, China's Chip Breakthrough Without ASML1354Makes Chamath Palihapitiya Take Stock Of Beijing's `Formidable' Nature:1355`America Can Win If . . .', Benzinga (Apr. 23, 2025), available online1356at .1357    \28\ See 2025 Annual Threat Assessment, supra n. 4 at 13.1358---------------------------------------------------------------------------1359    Indeed, China has long sought to infiltrate U.S., allied, and other1360global communications networks with their own equipment, both by1361building it on the cheap using stolen U.S. technology and then1362innovating on top of it, as well as by heavily subsidizing the sale of1363such equipment. The stories of how companies like Huawei and ZTE built1364their core networking capabilities and got them deployed globally are1365well known,\29\ and multiple Congressional committees and U.S.1366administrations have sought to highlight the threat to our own1367infrastructure and that of our allies,\30\ and the relative success of1368the U.S. domestic rip-and-replace program can serve as a model for1369other nations as well.\31\ But the challenges continue. A recent report1370from the U.S.-China Economic and Security Review Commission (USCC)1371notes Chinese critical infrastructure investments in various strategic1372locations around globe, including in the Middle East, Southeast Asia,1373and Africa, noting, for example, that China's investment into Southeast1374Asia's information and communications technology sector exceeds $121375billion and is focused on areas like cloud computing, data center1376capacity, and core network equipment provision for national1377telecommunications infrastructure.\32\ Taking a page from the U.S.1378book, the USCC notes that while today Huawei supplies 70 percent of1379Indonesia's network equipment, it ``has offered to take over the1380remaining percentage with a free rip-and-replace program.'' \33\ This1381approach is almost certainly being mirrored in strategic locations1382around the globe.1383---------------------------------------------------------------------------1384    \29\ See, e.g., Jill C. Gallagher, U.S. Restrictions on Huawei1385Technologies: National Security, Foreign Policy, and Economic1386Interests, Congressional Research Service (Jan. 5, 2022), at 6-12,1387available online at .1388    \30\ Id. at 12-39.1389    \31\ Id. at 22-25.1390    \32\ See U.S.-China Economic and Security Review Commission, 20251391Report to Congress (Nov. 2025), at 233-34, available online at .1392    \33\ Id. at 234.1393---------------------------------------------------------------------------1394    China has also targeted the undersea cables that serve as the1395backbone of the international communications system, which carries 951396percent of global Internet traffic and around 99 percent of1397transoceanic digital communications.\34\ The USCC report notes that1398China is ``increasingly engaged in undersea cable-cutting activities as1399a gray zone pressure tactic, and there is mounting evidence that1400Beijing is developing new cable-cutting technologies for potential1401wartime use.'' \35\ The USCC goes on to note that ``[f]or over a1402decade, Chinese scientists at research institutions affiliated with the1403PLA have actively researched strategies for severing undersea cables,1404acquiring numerous patents for technologies designed to cut deep-sea1405cables more cheaply and efficiently'' and that earlier this year, the1406China Ship Scientific Research Center (a U.S. sanctioned entity)1407``unveiled a new design for an `electric cutting device for deep-sea1408cables' reportedly capable of severing armored cables at depths of more1409than 13,000 feet.'' \36\ Indeed, the USCC reports that ``Chinese1410vessels have sabotaged critical undersea cables near Taiwan and in the1411Baltic Sea'' and notes two incidents in 2025 alone, where ``Chinese-1412owned `shadow fleet' vessels cut cables near Taiwan while engaging in1413highly irregular movement patterns and disguising their identities and1414locations as well as a November 2024 incident where a ``Chinese vessel1415severed two undersea cables in the Baltic Sea--one connecting Sweden1416and Lithuania, the other connecting Germany and Finland--after dragging1417its anchor for more than 100 miles,'' which European investigators1418believe was a joint Russia-China operation.\37\ And this doesn't even1419cover the potential tapping threat posed by Chinese cable repair1420vessels nor the relative lack of allied repair capacity in the1421IndoPacific (as well as globally) noted by the USCC.\38\1422---------------------------------------------------------------------------1423    \34\ See Jill C. Gallagher, Undersea Telecommunication Cables:1424Technology Overview and Issues for Congress, Congressional Research1425Service (Sept. 13, 2022), available online at .1426    \35\ See USCC 2025 Report, supra n. 32 at 98.1427    \36\ Id.1428    \37\ Id.1429    \38\ Id. at 99.1430---------------------------------------------------------------------------1431    Finally, when it comes to the threats posed by China to American1432communication networks, we cannot forget about China's efforts to1433compete with the United States in the space domain and, in particular,1434its ability to potentially take action against the United States in1435that arena. While it is true that in recent decades, the long-haul1436telecommunications infrastructure has pivoted from satellite-based1437communications to undersea cables as noted above, the reality is that1438we are increasingly relying on space-based assets for a range of1439services and capabilities that are critical to our communications1440capabilities, including position, navigation, and timing, as well as1441broadband access across the globe, both for government and industry use1442cases. As such, China's rapidly developing capabilities in1443intelligence, surveillance, and reconnaissance (ISR), where the DNI1444finds that it has ``achieved global coverage . . . in some of its . . .1445constellations and world-class status in all but a few space1446technologies[,]'' as well as its Beidou constellation which competes1447with our GPS system, and its recent launch of a low Earth orbit (LEO)1448constellation for satellite Internet services,\39\ are all concerning1449trends.1450---------------------------------------------------------------------------1451    \39\ See 2025 Annual Threat Assessment, supra n. 4 at 15.1452---------------------------------------------------------------------------1453    These trends, of course, are also particularly concerning when1454viewed in light of China's counterspace capabilities, which the DNI has1455made clear ``will be integral to PLA military campaigns,'' particularly1456given that ``China has counterspace-weapons capabilities intended to1457target U.S. and allied satellites.'' \40\ Chinese capabilities to go1458after America's space-based communications infrastructure don't just1459include ``ground-based counterspace capabilities, including EW systems,1460directed energy weapons (DEWs), and antisatellite (ASAT) missiles1461intended to disrupt, damage, and destroy target satellites,'' but also1462includes ``orbital technology demonstrations . . . [and] on-orbit1463satellite inspections of other satellites,'' capabilities that ``while1464not counterspace weapons tests, prove [China's] ability to operate1465future space-based counterspace weapons . . . [and] which probably1466would be representative of the tactics required for some counterspace1467attacks.'' \41\1468---------------------------------------------------------------------------1469    \40\ Id.1470    \41\ Id.1471---------------------------------------------------------------------------1472    For its part, the Federal Communication's Commission under its new1473chairman has sought to take action to address the threats posed by1474China and other threat actors. For example, the FCC recently1475established a Council on National Security aimed at leveraging the1476FCC's authorities to counter foreign adversaries, like China, with the1477goals of reducing the American technology and communications sectors'1478supply chain dependencies on such adversaries; mitigating America's1479vulnerabilities to cyberattacks, espionage, and surveillance; and1480ensuring U.S. victory in our strategic competition with China in1481critical technology domains like AI, space, next gen communications,1482and quantum computing.\42\ The FCC has also taken action in a range of1483areas including foreign ownership, control, and influence over FCC1484licensees,\43\ foreign controlled labs,\44\ and the security of1485submarine cables,\45\ to name just a few.1486---------------------------------------------------------------------------1487    \42\ See Federal Communications Commission, FCC Council on National1488Security, available online at .1489    \43\ See Federal Communications Commission, Protecting our1490Communications Networks by Promoting Transparency Regarding Foreign1491Adversary Control, Notice of Proposed Rulemaking (May 22, 2025),1492available online at .1493    \44\ See Federal Communications Commission, FCC Takes Action on1494``Bad Labs'' Apparently Controlled By China (Sept. 25, 2025), available1495online at .1496    \45\ See Federal Communications Commission, Review of Submarine1497Cable Landing License Rules and Procedures to Assess Evolving National1498Security, Law Enforcement, Foreign Policy, and Trade Policy Risks,1499Report and Order and Further Notice of Proposed Rulemaking (Aug. 7,15002025), available online at .1501---------------------------------------------------------------------------1502B. Russia1503    Turning to Russia, it is clear--and the current DNI agrees--that1504``Russia's current geopolitical, economic, military, and domestic1505political trends underscore its resilience and enduring potential1506threat to U.S. power, presence, and global interests[,]'' and that1507Russian President Vladimir Putin is ``prepared to pay a very high price1508to prevail in what he sees as a defining time in Russia's strategic1509competition with the United States, world history, and his personal1510legacy.'' \46\ Indeed, the DNI believes that ``Moscow's massive1511investments in its defense sector will render the Russian military a1512continued threat to U.S. national security,'' noting that Russia has1513``increased its defense budget to its heaviest burden level during1514Putin's more than two decades in power,'' while also ``import[ing]1515munitions such as UAVs from Iran and artillery shells from North1516Korea . . . enhancing the threat its military poses.'' \47\1517---------------------------------------------------------------------------1518    \46\ See 2025 Annual Threat Assessment, supra n. 4 at 16.1519    \47\ Id. at 18.1520---------------------------------------------------------------------------1521    Like China, Russia's ``disinformation, espionage, influence1522operations, military intimidation, cyberattacks, and gray zone1523tools . . . [are also part of an effort] to try to compete below the level of1524armed conflict and fashion opportunities to advance Russian1525interests.'' \48\ Indeed, the current DNI has made clear that Russia's1526cyber-enabled ``influence activities . . . including [] stoking1527political discord in the West, sowing doubt in democratic processes and1528U.S. global leadership, degrading Western support for Ukraine, and1529amplifying preferred Russian narratives. . .will continue for the1530foreseeable future and will almost certainly increase in sophistication1531and volume.'' \49\ And current DNI's view is that Russian ``information1532operations efforts to influence U.S. elections are advantageous,1533regardless of whether they affect election outcomes, because1534reinforcing doubt in the integrity of the U.S. electoral system1535achieves one of [Russia's] core objectives.'' \50\1536---------------------------------------------------------------------------1537    \48\ Id.1538    \49\ Id. at 20.1539    \50\ Id.1540---------------------------------------------------------------------------1541    The fact, of course, is that much of these efforts, take place1542through Russia's cyber exploitation of American communications and1543technology networks and systems. Specifically, the DNI has determined1544that ``Russia's advanced cyber capabilities, its repeated success1545compromising sensitive targets for intelligence collection, and its1546past attempts to pre-position access on U.S. critical infrastructure1547make it a persistent counterintelligence and cyber attack threat.''1548\51\1549---------------------------------------------------------------------------1550    \51\ Id. at 19.1551---------------------------------------------------------------------------1552    Such capabilities should be a major concern for the United States1553because the ``practical experience [Russia] has gained integrating1554cyber attacks and operations with wartime military action . . . [will]1555almost certainly amplify[] its potential to focus combined impact on1556U.S. targets in [a] time of conflict.'' \52\ Indeed, the DNI assesses1557that Russia's ``demonstrat[ion] [of] real-world disruptive capabilities1558during the past decade, including gaining experience in attack1559execution by relentlessly targeting Ukraine's networks with disruptive1560and destructive malware[,]'' \53\ provides Moscow with a ``unique1561strength'' in the cyber domain.\54\1562---------------------------------------------------------------------------1563    \52\ Id.1564    \53\ Id. at 20.1565    \54\ Id. at 19.1566---------------------------------------------------------------------------1567    As with China, however, these facts should not be surprising,1568particularly given that since at least 2019, the United States has been1569raising concerns about Russia's efforts to ``map[] our critical1570infrastructure with the long-term goal of being able to cause1571substantial damage,'' and given that the then-DNI, Senator Dan Coats,1572specifically disclosed that Russia was actively ``staging cyber attack1573assets to allow it to disrupt or damage U.S. civilian and military1574infrastructure during a crisis.'' \55\1575---------------------------------------------------------------------------1576    \55\ See 2019 Worldwide Threat Assessment, supra n. 13 at 6.1577---------------------------------------------------------------------------1578    This is the exact same kind of deployment of cyber capabilities1579that we saw Volt Typhoon put in place more recently on behalf of the1580Chinese government. Indeed, as one thinks about the capabilities that a1581nation like Russia has available to target American telecommunications1582systems and networks today, it is worth noting that back in 2019, the1583then-DNI stated that ``Russia has the ability to execute cyber attacks1584in the United States that generate localized, temporary disruptive1585effects on critical infrastructure--such as disrupting an electrical1586distribution network for at least a few hours[.]'' \56\1587---------------------------------------------------------------------------1588    \56\ Id.1589---------------------------------------------------------------------------1590    And these concerns only grew more troubling, particularly for our1591telecommunication's infrastructure, in 2021 and 2022, when the DNI1592specifically noted that ``Russia continues to target critical1593infrastructure, including underwater cables and industrial control1594systems, in the United States and in allied and partner countries, as1595compromising such infrastructure improves--and in some cases can1596demonstrate--its ability to damage infrastructure during a crisis.''1597\57\1598---------------------------------------------------------------------------1599    \57\ See 2021 Annual Threat Assessment, supra n. 14 at 9; 20221600Annual Threat Assessment, supra n. 15 at 12.1601---------------------------------------------------------------------------1602    Russia, like China, is also focused on American undersea cables.1603For at least a decade, news reports have flagged the threat that1604Russian ships pose to American undersea cable networks systems, both1605from a damage perspective as well as from an intelligence collection1606capability.\58\ And in 2023, the Congressional Research Service noted1607that as far back in 2018, the Associated Press cited a Russian1608publication for the proposition that ``Russia has the capability to cut1609cables, connect to top-secret cables, and jam underwater sensors that1610detect intrusions'' raising significant concern for the NATO allies,1611among others.\59\1612---------------------------------------------------------------------------1613    \58\ See, e.g., David E. Sanger & Eric Schmitt, Russian Ships Near1614Data Cables Are Too Close for U.S. Comfort, New York Times (Oct. 26,16152015), available online at ; see also, e.g., Morgan Chalfant & Olivia1616Beavers, Spotlight Falls on Russian Threat to Undersea Cables, The Hill1617(June 17, 2018), available online at ; CBS News, Concern over Russian Ships Lurking Around Vital1618Undersea Cables (Mar. 30, 2018), available online at ; Michael Birnbaum, Russian Submarines Are Prowling1619Around Vital Undersea Cables. It's Making NATO Nervous, Washington Post1620(Dec. 22, 2017), available online at .1621    \59\ See Jill C. Campbell, Protection of Undersea Telecommunication1622Cables: Issues for Congress, Congressional Research Service (Aug. 7,16232023), at 7, available online at .1624---------------------------------------------------------------------------1625    Like China, as well, it is worth noting Russia also has advanced1626``space programs threaten the Homeland, U.S. forces, and key1627warfighting advantages,'' \60\ and that ``Russia continues to train its1628military space elements and field new antisatellite weapons to disrupt1629and degrade U.S. and allied space capabilities[, including by] . . .1630expanding its arsenal of jamming systems, DEWs, on-orbit counterspace1631capabilities, and ASAT missiles designed to target U.S. and allied1632satellites.'' \61\1633---------------------------------------------------------------------------1634    \60\ See 2025 Annual Threat Assessment, supra n. 4 at 19.1635    \61\ Id. at 20.1636---------------------------------------------------------------------------1637    It is also clear that ``Russia has proven adaptable and resilient,1638in part because of the expanded backing of China, Iran, and North1639Korea[,]'' \62\ that ``Russia's relationship with China has helped1640Moscow circumvent sanctions and export controls to continue the war1641effort, maintain a strong market for energy products, and promote a1642global counterweight to the United States, even if at the cost of1643greater vulnerability to Chinese influence[,]'' and that Russia's1644``increase[ed] military cooperation with Iran and North Korea . . .1645continue[s] to help its war effort[.]'' \63\1646---------------------------------------------------------------------------1647    \62\ Id. at 16.1648    \63\ Id. at 17.1649---------------------------------------------------------------------------1650C. Iran1651    Members of this Committee are also well aware of the significant1652threat that Iran poses to American national security and our interests,1653allies, and partners globally, including our longstanding allies in the1654Middle East, including Israel, Jordan, Saudi Arabia, the United Arab1655Emirates, and Bahrain, to name a few. This threat is perhaps most clear1656in the Iranian regime's support of all manner of terrorist groups1657around the world from Hizballah to Hamas and Palestinian Islamic Jihad1658to the Yemeni Houthis and groups in Iraq and Syria that have directly1659attacked--and kidnapped and killed--Americans citizens and soldiers for1660years. The DNI recently made clear that Iran ``will continue to1661directly threaten U.S. persons globally and remains committed to its1662decade-long effort to develop surrogate networks inside the United1663States . . . [including] seek[ing] to target former and current U.S.1664officials it believes were involved in the killing of . . . IRGC[]-Qods1665Force Commander Qasem Soleimani in January 2020[, having] previously []1666tried to conduct lethal operations in the United States.'' \64\1667---------------------------------------------------------------------------1668    \64\ Id. at 22.1669---------------------------------------------------------------------------1670    And we well know of Iran's longstanding efforts to pursue nuclear1671weapons capabilities, against the interests of the United States and1672our allies. But it is also worth noting that Iran is also building up--1673and sharing with other U.S. adversaries--its conventional weapons1674capabilities as well. Indeed, according to the DNI, ``Iranian1675investment in its military has been a key plank of its efforts to1676confront diverse threats and try to deter and defend against an attack1677by the United States or Israel[,]'' including through its efforts to1678``bolster the lethality and precision of its domestically produced1679missile and UAV systems,'' \65\ and to share them with countries like1680Russia, which has long been using Iranian Shaheed drones in Ukraine.1681---------------------------------------------------------------------------1682    \65\ Id.1683---------------------------------------------------------------------------1684    But the one of the most important--and undercounted--threats posed1685by Iran are its efforts in the cyber domain, including its efforts to1686target our telecommunications networks and systems. Specifically,1687according to the DNI, ``Iran's growing expertise and willingness to1688conduct aggressive cyber operations also make it a major threat to the1689security of U.S. and allied and partner networks and data.'' \66\1690---------------------------------------------------------------------------1691    \66\ Id.1692---------------------------------------------------------------------------1693    Indeed, the current DNI has noted that ``[g]uidance from Iranian1694leaders has incentivized cyber actors to become more aggressive in1695developing capabilities to conduct cyber attacks.'' \67\ This is1696particularly concerning because in 2019, the-DNI Coats told Congress1697that Iran was ``attempting to deploy cyber attack capabilities that1698would enable attacks against critical infrastructure in the United1699States and allied countries,'' and that it was then ``capable of1700causing localized, temporary disruptive effects--such as disrupting a1701large company's corporate networks for days to weeks--similar to its1702data deletion attacks against dozens of Saudi governmental and private-1703sector networks in late 2016 and early 2017.'' \68\1704---------------------------------------------------------------------------1705    \67\ Id.1706    \68\ See 2019 Worldwide Threat Assessment, supra n. 13 at 6.1707---------------------------------------------------------------------------1708    And we also know that ``Iran often amplifies its influence1709operations with offensive cyber activities[,]'' including efforts1710during the last election cycle to acquire information from the1711President's campaign and to ``manipulate U.S. journalists into leaking1712[the] information illicitly acquired from the campaign.'' \69\1713---------------------------------------------------------------------------1714    \69\ See 2025 Annual Threat Assessment, supra n. 4 at 26.1715---------------------------------------------------------------------------1716    These capabilities and efforts demonstrate Iran's interest in and1717ability to target and use American communications systems to undermine1718our national security. When combined with the challenges of effectively1719deterring an actor like Iran, as well as the limited efforts the United1720States has historically taken to establish real deterrence in the cyber1721domain by being relatively unwilling to impose significant1722consequences, the potential for a strategic miscalculation increases1723significantly as does the threat to American communications networks.1724D. North Korea1725    The DNI also assesses that North Korea will ``continue to pursue1726strategic and conventional military capabilities that target the1727[United States], threaten U.S. and allied armed forces and citizens,1728and . . . undermine U.S. power and reshape the regional security1729environment in [North Korea's] favor.'' \70\1730---------------------------------------------------------------------------1731    \70\ Id.1732---------------------------------------------------------------------------1733    North Korea's focus, in the cyber domain, is targeting American1734telecommunications networks and the financial institutions that ride1735upon them to ``fund[] its military development--allowing it to pose1736greater risks to the United States--and economic initiatives by1737stealing hundreds of millions of dollars per year in cryptocurrency.''1738\71\ However, the DNI also assesses that North Korea ``may also expand1739its ongoing cyber espionage to fill gaps in the regime's weapons1740programs, potentially targeting defense industrial base companies1741involved in aerospace, submarine, or hypersonic glide technologies.''1742\72\1743---------------------------------------------------------------------------1744    \71\ Id. at 28.1745    \72\ Id.1746---------------------------------------------------------------------------1747    Like with China, Russia, and Iran, much of this unsurprising1748because we knew back in 2019 that ``North Korea poses a significant1749cyber threat to financial institutions [and] remains a cyber espionage1750threat . . . us[ing] cyber capabilities to steal from financial1751institutions to generate revenue[,] . . . includ[ing] attempts to steal1752more than $1.1 billion from financial institutions across the world1753[and] . . . a successful cyber heist of an estimated $81 million from1754the New York Federal Reserve account of Bangladesh's central bank.''1755\73\1756---------------------------------------------------------------------------1757    \73\ See 2019 Worldwide Threat Assessment, supra n. 13 at 6.1758---------------------------------------------------------------------------1759    We also learned, interestingly, in 2019 that North Korea ``retains1760the ability to conduct disruptive cyber attacks,'' \74\ a capability1761that we more recently learned was focused on American cyber networks.1762Specifically, in 2021, the DNI told Congress that that ``Pyongyang1763probably possesses the expertise to cause temporary, limited1764disruptions of some critical infrastructure networks and disrupt1765business networks in the United States, judging from its operations1766during the past decade, and [further that] it may be able to conduct1767operations that compromise software supply chains.'' \75\ We also1768learned, in 2022, that ``Pyongyang is well positioned to conduct1769surprise cyber attacks given its stealth and history of bold action.''1770\76\1771---------------------------------------------------------------------------1772    \74\ Id.1773    \75\ See 2021 Annual Threat Assessment, supra n. 14 at 14; 20221774Annual Threat Assessment, supra n. 15 at 17.1775    \76\ See 2022 Annual Threat Assessment, supra n. 15 at 17.1776---------------------------------------------------------------------------1777    As with Iran, given North Korea's burgeoning capacity and1778willingness to conduct operations in the cyber domain, and the relative1779challenges of using deterrence against a nation like North Korea poses,1780as well as the limited willingness of the United States to engage in1781more generally deterrence in the cyber domain, the potential for a1782tactical miscalculation--and the concomitant threat to American1783communications networks--is more significant than one might initially1784assume.1785III. Assessing the Threats to America's Communications Infrastructure1786    When we look across the totality of the threats to America's1787communications infrastructure posed these four major nation-state1788threat actors--China, Russia, Iran, and North Korea--what becomes1789increasingly clear is that it is virtually impossible for any one1790private sector actor, or even any single industry in the United States1791alone, writ-large, to effectively combat these the scale, scope and1792nature of these threats.1793    We are faced today with a nonstop, day-in, day-out, military-grade1794assault on our Nation's critical infrastructure and that of our allies.1795This effort is being undertaken by multiple military and intelligence1796organizations across multiple adversary countries and is focused on the1797core networks, systems, and technologies that support our governments,1798telecommunications systems, banking networks, energy grids, and1799healthcare institutions, just to name a few important ones.1800    While this assault is not always aimed the destruction or1801disruption of these networks, systems, or technologies, even the1802intelligence collection and information operations that our adversaries1803are running can have massive implications for our economic and national1804security. They can enable mass-scale intellectual property theft--much1805of which is already taking place--and thereby undermine America's1806innovation-driven economy while bootstrapping nations like China. They1807can also undermine government institutions and cut out basic support1808for the rule of law across the globe. And they can enable future1809military and intelligence operations against our nations and its1810allies. Even more troublingly, we are seeing nation-state adversaries1811put in place the very capabilities that would enable them to engage in1812large-scale, sustained disruptions of American and allied critical1813infrastructure, including key telecommunications networks and systems.1814    The question then is what is to be done about these threats posed1815to our core networks, systems, and technologies. As a nation, the stark1816reality is we are not currently positioned to provide for a1817comprehensive defense of our nation--nor the very communications1818systems or networks that American companies help operate--and we do not1819appear prepared to undertake the actions needed to do so.1820    One need only look at the Salt Typhoon hacks aimed at our1821communications infrastructure--primarily for intelligence collection--1822to understand just how vulnerable (and underprepared) we are to deal1823with these adversaries. In that case, we learned--after years and years1824of knowing that the Chinese government and its military and1825intelligence institutions were focused on this effort--that China had1826obtained widescale access to our telecommunications networks.\77\1827Specifically, the FBI stated that China's ``targeting of commercial1828telecommunications infrastructure has revealed a broad and significant1829cyber espionage campaign,'' and that Chinese-affiliated actors ``have1830compromised networks at multiple telecommunications companies to enable1831the theft of customer call records data, the compromise of private1832communications of a limited number of individuals who are primarily1833involved in government or political activity, and the copying of1834certain information that was subject to U.S. law enforcement requests1835pursuant to court orders.'' \78\1836---------------------------------------------------------------------------1837    \77\ See Chris Jaikaran, Salt Typhoon Hacks of Telecommunications1838Companies and Federal Response Implications, Congressional Research1839Service (Jan. 23, 2025), available online at  (``In early1840October 2024, media outlets reported that People's Republic of China1841(PRC) state-sponsored hackers infiltrated United States1842telecommunications companies (including Internet service1843providers). . . . [P]ublic reporting suggests that the hackers may have1844targeted the systems used to provide court-approved access to communication1845systems used for investigations by law enforcement and intelligence agencies.1846PRC actors may have sought access to these systems and companies to1847gain access to presidential candidate communications. With that access,1848they could potentially retrieve unencrypted communication (e.g., voice1849calls and text messages).'')1850    \78\ See Federal Bureau of Investigations, Joint Statement from FBI1851and CISA on the People's Republic of China Targeting of Commercial1852Telecommunications Infrastructure (Nov. 14, 2024), available online at1853.1854---------------------------------------------------------------------------1855    This was an astounding event; according to the then-Chairman of the1856Senate Intelligence Committee, Senator Mark Warner (D-VA), it was the1857``worst telecom hack in our Nation's history--by far,'' \79\ and1858according the then-Vice Chair of the Committee (and now current1859Secretary of State and National Security Advisor) Senator Marco Rubio1860(R-FL) referred to the hack as ``an egregious, outrageous and dangerous1861breach of our telecommunications systems across multiple companies[.]''1862\80\1863---------------------------------------------------------------------------1864    \79\ Ellen Nakashima, Top Senator Calls Salt Typhoon ``Worst1865Telecom Hack in our Nation's History,'' Washington Post (Nov. 21,18662024), available online at .1867    \80\ Patrick Maguire, Sen. Marco Rubio Says Chinese Hacking of U.S.1868Telecom Companies is a ``Very Serious Situation that we Face,'' CBS1869News (Nov. 3, 2024), available online at .1870---------------------------------------------------------------------------1871    And yet, after the reported convening of a White House Unified1872Coordination Group (UCG),\81\ a lengthy (and apparently still ongoing)1873law enforcement investigation,\82\ and a nascent (and incomplete)1874investigation by the Cyber Safety Review Board (of which I was once a1875member),\83\ not to mention a rushed regulatory effort by the Federal1876Communications Commission\84\ (which has since been reversed by the1877current FCC in favor of a number of more focused actions directed at1878the Chinese threat as noted above and in line with a more ``agile and1879collaborative approach to cybersecurity that has proven1880successful''),\85\ the release of two security guidance documents1881jointly released by a significant number of law enforcement and1882intelligence agencies from multiple allied countries,\86\ and1883legislation introduced,\87\ we have precious little substantive action1884to show for this hack.1885---------------------------------------------------------------------------1886    \81\ See, e.g., Ellen Nakashima, White House Forms Emergency Team1887to Deal with China Espionage Hack, Washington Post (Nov. 11, 2024)1888(``The White House on Tuesday convened a meeting of deputy secretaries1889of key agencies to stand up what's known as a `unified coordination1890group.' The group's role is to ensure there is consistent interagency1891visibility into the response by the FBI, the Office of the Director of1892National Intelligence, and the Department of Homeland Security's1893Cybersecurity and Information Security Agency (CISA).''); see also Salt1894Typhoon Hacks, supra n. 61 at 2 (discussing Salt Typhoon and noting1895that ``[b]y publicly available counts, this is the fourth time that the1896U.S. government has established a Cyber UCG--which were previously1897established for China's compromise of Microsoft Exchange services in18982021, Russia's compromise of SolarWinds in 2021.'')1899    \82\ See, e.g., Federal Bureau of Investigation, FBI Seeking Tips1900about PRC-Targeting of U.S. Telecommunications (Apr. 24, 2025),1901available online at .1902    \83\ Martin Matishak, Cyber Incident Board's Salt Typhoon Review to1903Begin Within Days, CISA Leader Says, The Record (Dec. 3. 2024),1904available online at .1905    \84\ See Federal Communications Commission, Protecting the Nation's1906Communications Systems from Cybersecurity Threats, Declaratory Ruling1907and Notice of Proposed Rulemaking (Jan. 15, 2025), available online at1908; see also1909Federal Communications Commission, Chairwoman Rosenworcel Announces1910Agency Action to Require Telecom Carriers to Secure their Networks1911(Dec. 5, 2024), available online at .1912    \85\ See Federal Communications Commission, Protecting the Nation's1913Communications Systems from Cybersecurity Threats, Order on1914Reconsideration (Nov. 20, 2025), available online at .1915    \86\ See National Security Agency, et al., Countering Chinese1916State-Sponsored Actors Compromise of Networks Worldwide to Feed Global1917Espionage System (Aug/Sept. 2025), available online at ; Cybersecurity and1918Infrastructure Security Agency, et al., Enhanced Visibility and1919Hardening Guidance for Communications Infrastructure (Dec. 3, 2024),1920available online at .1921    \87\ See Senator Ron Wyden, Wyden Releases Draft Legislation to1922Secure U.S. Phone Networks Following Salt Typhoon Hack (Dec. 10, 2024),1923available online at .1924---------------------------------------------------------------------------1925    According to press reports, at least some of the telecommunications1926companies involved have managed to remove the attackers (or at least1927those they could identify),\88\ and the breadth of the hack appears to1928have been global, affecting at least nine telecommunications1929companies,\89\ at least a dozen nations,\90\ and targeting senior U.S.1930government officials,\91\ with significant amounts of metadata and the1931content of certain individuals' communications obtained.\92\ And the1932FCC, while reversing its earlier rush to regulation, has obtained1933series of commitments from American communications companies to upgrade1934their cybersecurity practices by taking coordinated actions to harden1935their networks against a range of cyber intrusions.\93\ These actions1936include accelerating the patching of outdated or vulnerable equipment,1937updating and reviewing system access controls, disabling unnecessary1938outbound connections, improving threat-hunting efforts, and1939cybersecurity information sharing.\94\ In addition, the FCC has1940recently been working more closely with regulators from the U.K.,1941Canada, Australia, and New Zealand to strengthen cooperation amongst1942these partners to respond to threats against our communications1943networks.\95\1944---------------------------------------------------------------------------1945    \88\ See Matt Kapko, AT&T, Verizon say they evicted Salt Typhoon1946from their networks, Cybersecurity Dive (Jan. 7. 2025), available1947online at .1948    \89\ See The White House, On-the-Record Press Gaggle by White House1949National Security Communications Advisor John Kirby (Dec. 27. 2024),1950available online at  (``[A]s we look at China's compromise of now nine1951telecom companies, the first step is creating a defensible1952infrastructure.'') (statement of Deputy National Security Advisor Anne1953Neuberger).1954    \90\ See Aamer Madhani, White House Says at Least 8 U.S. Telecom1955Firms, Dozens of Nations Impacted by China Hacking Campaign, Associated1956Press (Dec. 4, 2024), available online at  (``A top White House official on Wednesday said at least eight1957U.S. telecom firms and dozens of nations have been impacted by a1958Chinese hacking campaign . . .'').1959    \91\ Id. (``The U.S. believes that the hackers were able to gain1960access to communications of senior U.S. government officials and1961prominent political figures through the hack, Neuberger said.'')1962    \92\ See On-The-Record Press Gaggle, supra n. 89 (``Our1963understanding is that a large number of individuals were geolocated in1964the Washington, D.C./Virginia area. We believe it was the goal of1965identifying who those phones belong to and if they were government1966targets of interest for follow-on espionage and intelligence collection1967of communications, of texts, and phone calls on those particular1968phones. So, we believe a large number of individuals were affected by1969geolocation and metadata of phones; a smaller number around actual1970collection of phone calls and texts. And I think the scale we're1971talking about is far larger on the geolocation; probably less than 1001972on the actual individuals.'') (statement of A. Neuberger).1973    \93\ See Order on Reconsideration, supra n. 85 at 2, 9-10, 13-14 &197417.1975    \94\ Id.1976    \95\ Id. at 17.1977---------------------------------------------------------------------------1978    Yet the impact of these hacks, particularly when combined with1979other hacks, remains quite serious. The most recent security guidance1980document released by the U.S. and multiple allied intelligence and law1981enforcement agencies noted that the Salt Typhoon actors has been1982operating ``globally since at least 2021'' and indicated that ``[t]he1983data stolen through this activity against foreign telecommunications1984and Internet service providers (ISPs), as well as intrusions in the1985lodging and transportation sectors, ultimately can provide Chinese1986intelligence services with the capability to identify and track their1987targets' communications and movements around the world.'' \96\ And1988while that guidance document specifically offered recommendations to1989close known vulnerabilities in systems built at least three allied1990providers, the government agencies also noted that they suspected that1991at least six other vendors may also have been compromised.\97\1992---------------------------------------------------------------------------1993    \96\ See Countering Chinese State-Sponsored Actors, supra n. 86 at19945.1995    \97\ Id. at 6-7.1996---------------------------------------------------------------------------1997    At the same time, earlier this year, more than six months after the1998hack was identified, the FBI sought the public's help in ``report[ing]1999information about PRC-affiliated activity publicly tracked as `Salt2000Typhoon' and the compromise of multiple U.S. telecommunications2001companies, especially information about specific individuals behind the2002campaign[,]'' and specifically noting that if members of the public,2003``have any information about the individuals who comprise Salt Typhoon2004or other Salt Typhoon activity, we would particularly like to hear from2005you.'' \98\ And the U.S. government--apparently having identified at2006least three Chinese entities involved in the incident\99\--has issued2007sanctions against one of them.\100\2008---------------------------------------------------------------------------2009    \98\ See FBI Seeking Tips, supra n. 82.2010    \99\ See Countering Chinese State-Sponsored Actors, supra n. 86 at20115 (naming Sichuan Juxinhe Network Technology Co. Ltd., Beijing Huanyu2012Tianqiong Information Technology Co., Ltd., and Sichuan Zhixin Ruijie2013Network Technology Co., Ltd. as being linked to Salt Typhoon operations2014and ``provid[ing] cyber-related products and services to China's2015intelligence services, including multiple units in the People's2016Liberation Army and Ministry of State Security.'').2017    \100\ See, e.g., U.S. Department of the Treasury, Treasury2018Sanctions Company Associated with Salt Typhoon and Hacker Associated2019with Treasury Compromise (Jan. 17, 2025) (``Additionally, OFAC is2020sanctioning Sichuan Juxinhe Network Technology Co., LTD., a Sichuan-2021based cybersecurity company with direct involvement in the Salt Typhoon2022cyber group, which recently compromised the network infrastructure of2023multiple major U.S. telecommunication and Internet service provider2024companies. People's Republic of China-linked (PRC) malicious cyber2025actors continue to target U.S. government systems, including the recent2026targeting of Treasury's information technology (IT) systems, as well as2027sensitive U.S. critical infrastructure.'')2028---------------------------------------------------------------------------2029    And yet, in perhaps one of the most stunning revelations to come2030out of this incident, even as the FCC and White House were calling for2031significant regulation of American telecommunications companies,\101\2032the outgoing head of the Department of Homeland Security's2033Cybersecurity and Infrastructure Security Agency (CISA), published a2034blog post stating that ``CISA threat hunters previously detected the2035same actors in U.S. government networks.'' \102\ The next day, at an2036on-the-record event at the Foundation for the Defense of Democracies,2037the CISA Director stated that while the government had previously2038detected the Salt Typhoon actors on other Federal networks at the time2039``[w]e saw it as a separate campaign called another goofy2040name[.]''\103\ According to newspaper reports, ``CISA's observations2041didn't prevent Salt Typhoon from attacking the telecom networks en2042masse, but [the CISA Director] presented the agency's threat hunting2043and intelligence gathering capabilities as an example of intra-2044government and public-private collaboration improvements made under her2045stewardship of the agency.'' \104\2046---------------------------------------------------------------------------2047    \101\ See Chairwoman Rosenworcel Announces Agency Action, supra n.204884; see also On-The-Record Press Gaggle, supra n. 89 (``[W]e need to2049see every member of the--all the FCC commissioners vote to implement2050the required minimum cybersecurity practices across telecom, because2051once those are in place, once companies are taking those steps to make2052their networks defensible, we would feel more confident to say that the2053Chinese actors have been evicted and can continue to not be able to2054come in.'') (statement of A. Neuberger).2055    \102\ See Jen Easterly, Strengthening America's Resilience Against2056the PRC Cyber Threats, CISA (Jan. 15, 2025), available online at2057.2058    \103\ See Matt Kapko, CISA clocked Salt Typhoon in Federal networks2059before telecom intrusions, Cybersecurity Dive (Jan. 16, 2025),2060available online at .2061    \104\ Id.2062---------------------------------------------------------------------------2063    While all this may make one recall the findings of the 9/112064Commission report, which noted that the U.S. government had both2065successfully the potential of a major terrorist attack and knew of2066specific terrorists with visas to enter the United States, but2067critically failed to share actionable information in a timely fashion2068with those able to identify and stop those individuals,\105\ it also2069raises important questions about where the responsibility for defending2070the Nation against these types of attacks ought properly lie.2071---------------------------------------------------------------------------2072    \105\ See National Commission on Terrorist Attacks Upon the United2073States, The 9/11 Commission Report (July 22, 2004), at 155-59, 181-82,2074266-72, available online at .2075---------------------------------------------------------------------------2076    As I previously noted in testimony before another House committee2077back in 2020, while we've established an entity with the theoretical2078responsibility for defending the Nation in the cyber domain in U.S.2079Cyber Command, we've never provided it with anywhere near the kind of2080authorities or resources it would take to actually do that job.\106\2081And while there may not be a consensus in our Nation today on what the2082government's role in defending our Nation's overall cyber2083infrastructure ought exactly be, the idea that we ought leave our2084critical infrastructure provider alone to defend themselves against2085foreign nation-state threat actors--or even worse penalize them when2086they find themselves unable to stop such actors who come to the fight2087with virtually unlimited resources--is not only unrealistic, it is2088setting up ourselves to fail every time.\107\ Just as we don't expect2089Target or Walmart to have surface-to-air missiles on the roofs of their2090warehouses to defend against Russian Bear aircraft dropping bombs in2091the United States, we ought not expect the same from our2092telecommunications and infrastructure companies in the cyber2093domain.\108\2094---------------------------------------------------------------------------2095    \106\ See CISA Clocked Salt Typhoon, supra n. 103.2096    \107\ See GEN. Keith B. Alexander, Jamil N. Jaffer, and Jennifer S.2097Brunet, Clear Thinking about Protecting the Nation in the Cyber Domain,2098Cyber Defense Review 2, no. 1 at 29, 33 (2017), available online at2099 (``The2100fact is that commercial and private entities cannot be expected to2101defend themselves against nation-state attacks in cyberspace. Such2102organizations simply do not have the capacity, the capability, nor the2103authority to respond in a way that would be fully effective against a2104nation-state attacker in cyberspace. Indeed, in most other contexts, we2105do not (and should not) expect corporate America to bear the burden of2106nation-state attacks.'').2107    \108\ See id.; see also, e.g., GEN (Ret) Keith B. Alexander & Jamil2108N. Jaffer, Iranian Cyberattacks Are Coming, Security Experts Warn,2109Barron's (Jan. 10, 2020) (``Expecting individual companies to defend2110themselves against a nation state with virtually unlimited financial2111resources and human capital does not make sense. Yet today that is our2112national policy in cyberspace. This is so even though, in every other2113context, defense against nation-state attacks is the province of the2114government. We don't expect Target or Walmart to have surface-to-air2115missiles to defend against Russian Bear bombers. Yet when it comes to2116cyberspace, we expect exactly that of every American company, large or2117small.'').2118---------------------------------------------------------------------------2119IV. Considering Effective Responses to Defend America's Communications2120        Infrastructure2121    This, of course, puts front and center the question of what might2122be done to address this clear and present threat to the America's2123communications infrastructure and that of our allies and partners.2124    First and foremost, we must remember that private sector companies,2125including those in the telecommunications and infrastructure sectors,2126are not primarily in the business of defending themselves against2127cyberattacks; rather, they operate in order to provide products and2128services to customers and to generate economic returns from such2129business. And this is a net positive for our Nation and its allies.2130After all, without these companies, the vast majority of our AI tools2131and large language models, which rely often rely on connections to2132cloud infrastructure and access to massive amounts of data and compute,2133wouldn't be able to operate or service customers large and small across2134the globe. Without a strong American communications sector, we wouldn't2135have built, expanded, or maintained the freedom of access to the global2136information networks that form the Internet. And without American and2137allied telecommunications and infrastructure companies, we would likely2138not have seen the massive gains from innovation that have driven the2139U.S. and world economy for at least the last five decades.2140    To preserve the value these organizations--and many other private2141sector entities--provide us, the Federal government must partner2142tightly with industry to enable better cyber defense. This means2143sharing massive amounts of data (classified and otherwise), providing2144incentives to obtain and deploy better defensive cyber systems and2145capabilities, and aggressively imposing costs on adversaries, in2146appropriate circumstances, to deter the deployment or use of2147potentially disruptive or destructive capabilities. The fact of the2148matter is that we cannot cede this critical ground to our adversaries2149by leaving companies in the telecommunications, infrastructure, and2150technology sectors alone to defend themselves against nation-state2151attacks.2152    One example of providing the right incentives would be to2153consider--in reauthorizing (and ideally making permanent) the Cyber2154Information Sharing Act of 2015 (which having expired earlier this year2155was the subject of a short reauthorization in the recent government2156reopening deal)--providing the type of liability and regulatory2157protections that were contained when the original version of that2158legislation as passed by the House back in 2011.\109\ Those2159protections, which fell out of the legislation negotiated by the House2160and Senate four years later when it was enacted,\110\ are a key example2161of lining up the incentives between industry and the government and2162using carrots, instead of the proverbial regulatory stick.\111\2163Likewise, providing clear authority and direction to provide security2164clearances and share classified intelligence with the private sector in2165a manner that allows them to operationalize it, as well as ensuring2166that private sector entities can go anywhere in the government to share2167information, as the original legislation did, are also key elements to2168better collaborating with the private sector on cyber defense. The2169government cannot expect the private sector to do strong work sharing2170information within and across sectors, while also maintaining massive2171silos within the government. We can and should expect better of our2172Federal agencies.2173---------------------------------------------------------------------------2174    \109\ See Cyber Intelligence Sharing and Protection Act, H.R. 3523,2175112th Cong. (engrossed in the House), available online at .2176    \110\ See Consolidated Appropriations Act of 2015, P.L. 114-113,2177129 Stat. 2242 (``CISA''); see also Cybersecurity Information Sharing2178Act of 2015, S. 754, 114th Cong. (as passed by the Senate on Oct. 27,21792015).2180    \111\ See Jamil N. Jaffer, Carrots and Sticks in Cyberspace:2181Addressing Key Issues in the Cybersecurity Information Sharing Act of21822015, 67 S. Car. L. Rev. 585, 589-98 (2016), available online at2183.2184---------------------------------------------------------------------------2185    Another key effort that the government ought take up is2186affirmatively harmonizing existing compliance requirements and2187regulations across various agencies, and to adopt the collaborative,2188voluntary approach taken by the FCC, in the first instance. At a2189minimum, the government ought permit compliance with one set of2190regulations--ideally those developed in the collaborative manner like2191that used by the FCC--that the serve as effective compliance with2192others where the subject matter of the regulation is similar. Likewise,2193getting unhelpful regulations out of the way and avoiding undermining2194our own national security policies for political gain by going after2195our best players--large and small--in the technology industry is2196critical to avoid. Efforts in recent years to amend longstanding and2197highly effective antitrust laws that have served our economy well for2198decades,\112\ are a key example of the kind of new policies that would2199be highly detrimental in the context of the ongoing economic and2200national security competition with China. These efforts, which target a2201handful of technology companies based on the nature and scale of their2202business, are largely driven by policy issues unrelated to innovation2203or competition.\113\ It also sends the wrong message to startup2204innovators, namely, that if they thrive and become highly successful,2205the government might seek to target them for special attention,2206creating laws just to cut them down to size.\114\ The White House has2207made clear it is on a strong deregulatory path, and action across all2208of these domains, could help significantly ensure that we are2209empowering the American private sector to innovate and create and2210implement better cyber defenses in partnership with the government.2211---------------------------------------------------------------------------2212    \112\ See, e.g., American Innovation and Choice Online Act, S.2992,2213117th Cong. (2021); Open App Markets Act, S.2710, 117th Cong. (2021).2214    \113\ See Bill Evanina & Jamil N. Jaffer, Kneecapping U.S. Tech2215Companies Is a Recipe for Economic Disaster, Barron's (June 17, 2022),2216available online at2217(``Conservatives are often worried--sometimes for good reason--that2218certain social or mainstream media companies might actively seek to2219suppress or quiet conservative voices. On the liberal side, there are a2220range of legitimate concerns with technology companies, including the2221displacement of traditional labor in the new gig economy. . . Yet2222rather than tackling these concerns directly by going after the2223specific behaviors or actions that trouble ordinary Americans,2224politicians in Washington have chosen instead to vilify some of our2225most successful companies and to go after them economically.''); see2226also David R. Henderson, A Populist Attack On Big Tech, The Hoover2227Institution (Mar. 3, 2022), available online at .2228    \114\ See Klon Kitchen & Jamil Jaffer, The American Innovation &2229Choice Online Act is a Mistake, The Kitchen Sync (Jan. 19, 2022),2230available online at  (``Going after our technology companies,2231particularly a targeted shot at certain big ones, sends the wrong2232message to startups and investors alike; it tells them that if you are2233innovative enough to be successful and grow significantly larger, you2234may be targeted for different treatment. This undermines not only the2235companies that are likely to be investing in R&D over the next decade2236and generating some of the key innovations that will contribute to our2237national security, it also undermines a central proposition that has2238created a robust tech ecosystem in this country: take risk, innovate,2239fail fast and often, and when you succeed, reap the rewards so long as2240you don't exploit your position to gain unfair advantage.''); Evanina &2241Jaffer, Kneecapping U.S. Tech Companies, supra n. 86 (``Picking and2242choosing individual companies to be treated differently than others2243under our antitrust laws is inconsistent with the heart of our economic2244system, which Seeks to reward innovation and success, not penalize2245them.'').2246---------------------------------------------------------------------------2247    Likewise, we ought work with our allies and partners across the2248globe--as well as investors and innovators who share our views--to2249advance American and allied interests, both by deploying capital2250effectively and ensuring that we don't undermine one another's2251strongest capabilities in the larger fight against our common2252adversaries. This also means that we must help our allies across the2253globe to better protect their own telecommunications infrastructure,2254which includes sharing information and intelligence ahead of potential2255threats and coming together to do what we did so effectively here in2256the United States--removing adversary capabilities, like Huawei and2257ZTE--from the global telecommunications infrastructure.2258    It likewise also means that we must lean aggressively forward--both2259globally and at home--as we look to put in place new technologies like22605G Advanced and 6G, including working collaboratively with across2261allied governments and industry to get the right international2262standards in place, including prioritizing allied collaboration on2263spectrum and on efforts like ORAN, while also protecting historical2264capabilities, like WHOIS, that have gone--or are going--dark.2265    The government also ought provide the right incentivizes for2266industry to build out both domestic and allied communications2267infrastructure and to invest in the capacity and innovation to deliver2268advanced technology capabilities globally. To that end, the government2269should provide tax and other economic incentives for increased private2270investment in the development of such technologies, the broader2271deployment of large-scale computing and communications infrastructure2272to support cloud and edge computing, and the expansion of AI2273capabilities being made available to U.S. and allied innovators across2274the globe.2275    These incentives are particularly important because the security2276of--and trust in--America's communications infrastructure (and that of2277our allies) is so central to our success in the larger competition with2278China. After all, no matter how secure our core technology capabilities2279themselves are, if we connect them to a weakly defended network, they2280will no longer be secure.2281    If we are to win this competition, therefore, we must ensure that2282we are properly incentivizing the buildout of these trusted2283communication capabilities in both the hardwired (including fiber) and2284wireless domains. Moreover, the government should also work with2285innovators and investors across the who share our interests to2286understand key government needs and priorities to develop the2287innovations and capabilities to address those needs.2288    Likewise, ensuring that the United States and our allies are able2289to access the manufacturing capacity and workforce necessary to support2290a modern technology and communications infrastructure--including2291consistent access to semiconductors, critical minerals, and other core2292materials necessary to support major technological innovation--will2293also be of critical strategic importance to the United States in the2294coming years, particularly as our competition with China heats up. It2295is critical that government and industry work together to create the2296right tax and regulatory incentives to ensure that American and allied2297companies invest their money here and in allied nations to create much-2298needed capacity, including in the communications, technology, and2299infrastructure industries, and to ensure that we have the skilled2300workers necessary to build and maintain this trusted capacity and2301capability.2302    When it comes to addressing lessons learned from the Salt Typhoon2303hacks and the Volt Typhoon capability deployments, Congress ought2304consider collaborating with the Executive Branch to appoint an2305independent third-party commission, taking a page from the successful23069/11, Intelligence Reform, and Cyberspace Solarium Commissions, putting2307legislators on the panel alongside distinguished private sector and2308policy leaders to identify key challenges and draft actionable2309proposals that can actually be enacted by Congress and implemented by2310the Executive Branch in the near-term.2311    As noted above, another key element of any effort to push back on2312adversary operations on our communications networks or to control those2313networks communications network is to effectively deter those threat2314actors from taking action in the first instance. While there are those2315who argue that deterrence doesn't work in the technology domain, the2316reality is we simply don't practice real, effective deterrence2317today.\115\ We don't talk about the redlines that, if crossed, would2318provoke a response from the United States, we don't talk about our2319capacity to respond, we don't talk what a response might look like, and2320when our communications systems are threatened (or hit), we often2321simply fail to respond.\116\ Even worse, in the rare circumstances when2322we do respond, we often do so in a fairly limited fashion and without2323any public acknowledgement or attribution.\117\ The problem with this2324approach is that it undermines any deterrence benefit we might2325otherwise enjoy.2326---------------------------------------------------------------------------2327    \115\ See Jamil N. Jaffer, Statement for the Record, Safeguarding2328the Federal Software Supply Chain, Committee on Oversight and2329Accountability, Subcommittee on Cybersecurity, Information Technology,2330and Government Innovation (Nov. 29, 2023), at 10, available online at2331 (``[T]he reality is that the United States does2332not effectively practice deterrence in the cyber domain for a variety2333of reasons.'')2334    \116\ Id.2335    \117\ Id.2336---------------------------------------------------------------------------2337    The fact is that if an attacked party is willing to deliver real2338consequences, and is seen to actually do so, deterrence can in fact2339work to protect our communications and technology infrastructure.\118\2340---------------------------------------------------------------------------2341    \118\ See Keith B. Alexander & Jamil N. Jaffer, Iran's Coming2342Response: Increased Terrorism and Cyber Attacks?, The Hill (May 15,23432019) (``While some have suggested that deterrence doesn't work in the2344cyber domain, the reality is that if an attacked party is willing to2345deliver real consequences and is seen to do so, deterrence can in fact2346work.'').2347---------------------------------------------------------------------------2348    As such, when it comes to threats to our communications2349infrastructure, we should be clear about our capabilities, put out a2350clear declaratory policy on our redlines, and be willing to take swift,2351decisive, and visible action when those lines are crossed. To do so,2352therefore, we must authorize, fund, and encourage more forward-leaning2353efforts by the government to overtly impose substantive costs on our2354cyber adversaries. It is only through such clear, public, and2355attributable action can we possibly expect to effectuate real2356deterrence in this domain.2357    And finally, the key rubric to apply in this domain, as well as in2358other key areas of technology across the board, is to apply the2359traditional American approach to innovation: first, do no harm. In2360practice, this means allowing innovation to flourish, only having the2361government intervene in the limited and clear cases, circumstances2362which ought be extremely rare. American and allied innovation deserves2363our protection and our support. We ought not, like some of our allies,2364regulate first and innovate latter. To the contrary, we ought do2365exactly the opposite.2366V. Conclusion2367    Such an approach--across all these fronts--is all the more critical2368when, as now, the United States and our allies are in a massive2369competition--economic, military, and political--with a near-peer2370competitor, where technology and innovation is at the heart and soul of2371the competition. This is a fight we can--and should--win; we just have2372to get out of our own way and enable our best, most capable actors2373across the government and industry.23742375    Senator Fischer. Thank you, Mr. Jaffer. Ms. Jordan, you are2376now recognized for your opening statement.23772378            STATEMENT OF DEBRA JORDAN, FORMER CHIEF,23792380          PUBLIC SAFETY AND HOMELAND SECURITY BUREAU,23812382               FEDERAL COMMUNICATIONS COMMISSION23832384    Ms. Jordan. Good morning, Chair Fischer, Ranking Member2385Lujan, Chair Cruz, and members of the Subcommittee. Thank you2386for the opportunity to appear before you today.2387    I am grateful to have served nearly 10 years at the Federal2388Communications Commission as a Deputy and then Bureau Chief for2389the Public Safety and Homeland Security Bureau. My2390responsibilities included national security, cybersecurity, and2391resilience of the communications sector. As a career civil2392servant, I was honored to have served under four Commission2393Chairs, from both parties.2394    Before joining the FCC, I spent three decades as a civilian2395with the U.S. Navy. There I implemented the Navy's first ever2396cybersecurity framework for critical systems such as2397electrical, water, and wastewater.2398    A little over a year ago, while I was at the FCC, the U.S.2399uncovered Salt Typhoon as a sophisticated campaign sponsored by2400the Chinese government. We now know that they infiltrated nine2401of our Nation's largest communications providers, and at least2402200 other U.S. organizations, including government agencies.2403They exfiltrated millions of calls and text messages and2404metadata of targeted individuals, including then candidates2405President Trump, Vice President Vance, then Vice President2406Harris, as well as Members of Congress. Additionally, they2407compromised systems that log U.S. law enforcement requests for2408criminal wiretaps, potentially tipping off Chinese intelligence2409about American investigative targets.2410    And if Salt Typhoon does not make you shudder, let's go2411back a little further in time to Volt Typhoon. Active since at2412least 2021, but not revealed until much later, the attack was2413attributed to Chinese hackers who gained widespread access to2414critical infrastructure like coms, water, and power systems.2415They used a tactic known as ``living off the land,'' where they2416stole credentials, quietly used administrative accounts to2417collect data, and retain high-level access to networks. They2418remain in the networks in preparation for potential armed2419conflict between the U.S. and China over Taiwan.2420    These attacks highlight the vulnerabilities in our2421communications networks, which provide the foundation of2422trillions of dollars of economic captivity. So how do we secure2423our communications networks, which serve as the underpinnings2424of our modern digital society? We can either lean forward,2425leveraging flexible cyber standards, to support our Nation's2426economy and security, or we can sit back and wait for the2427inevitable next attack to happen.2428    After the revelation of Salt Typhoon, the FCC leaned2429forward, in January 2025. The FCC ruled that Section 105 of the2430Communications Assistance for Law Enforcement Act, or CALEA,2431requires telecom providers to secure their networks against2432unlawful access. Also, the FCC proposed rules that would2433require communications providers to certify that they have2434created and implemented an up-to-date cyber risk management2435plan, which would strengthen network defenses from future2436cyberattacks.2437    However, on November 20, 2025, the FCC reversed the ruling,2438withdrew the proposed rules, putting the Nation at risk. The2439FCC cited engagement with providers and, quote, ``their2440agreement to take extensive steps to protect national security2441interests,'' unquote. However, the FCC does not cite any2442process by which the providers will be held accountable to meet2443specific commitments. From my experience as Bureau Chief, I am2444not convinced that providers will take sufficient and sustained2445actions in the wake of Volt and Salt Typhoon without a strong2446verification regime. As things stand now, we can hope that2447providers are taking appropriate steps long-term, and hope is2448not really a strategy to secure our networks.2449    So what can Congress do? I have three recommendations.2450    First, we have tools such as the Cyber Risk Management2451framework developed by NIST. Congress should encourage the FCC2452to require the NIST Cybersecurity Framework, or similar2453guidance, for all telecom providers. The framework is flexible2454and developed in collaboration with industry and the public to2455assist organizations to manage and reduce cyber risks.2456    Second is to upgrade our communications infrastructure.2457Keeping communications infrastructure current is critical, but2458also costly. I encourage Congress to fully fund communications2459infrastructure such as Next Generation 911 and cyber funding2460for state, local, Tribal, and territorial entities. We cannot2461enable modern digital network security when running on old2462analog infrastructure.2463    And last, verification must be a part of trust. We must2464establish a verification regime to ensure the security of our2465Nation's communications infrastructure. We have seen, time and2466again, where providers have not implemented even some of the2467most basic cyber hygiene consistently across their networks,2468such as changing default passwords. Industry says they are2469committed to implementing extensive cyber protections, so let's2470establish a regime in a secure setting for them to share their2471progress and further plans.2472    Thank you, and I look forward to your questions.2473    [The prepared statement of Ms. Jordan follows:]24742475  Testimony of Debra Jordan, Former Chief, Public Safety and Homeland2476           Security Bureau, Federal Communications Commission2477    Good morning, Chair Fischer, Ranking Member Lujan, Chair Cruz,2478Ranking Member Cantwell, and Members of the Subcommittee. Thank you for2479the opportunity to appear before you today.2480    I appreciate the Senate's interest in this critical and urgent2481topic and am honored to share my perspective on Defending America's2482Networks. I'm grateful to have served for nearly 10 years at the2483Federal Communications Commission as the Deputy and then Bureau Chief2484for the Public Safety & Homeland Security Bureau, where my2485responsibilities included national security, cybersecurity, and2486resilience of the communications sector. As a career civil servant, I2487was honored to have served under four Commission Chairs, from both2488parties. My responsibilities included interagency and multi-stakeholder2489engagements regarding the communications sector and its impacts on our2490Nation either directly or through cascading effects on other critical2491infrastructure sectors--such as electric, water, transportation, and2492healthcare.2493    Before joining the FCC, I spent three decades as a civilian with2494the U.S. Navy, serving as Command Information Officer for Naval2495Facilities and Engineering Command. There, I developed and obtained2496funding to implement the Navy's first ever cybersecurity framework for2497critical systems such as electrical, water, and wastewater.2498    A little over a year ago, while I was at the FCC, the U.S.2499uncovered Salt Typhoon, a sophisticated campaign sponsored by the2500Chinese government. We know now they infiltrated nine of our Nation's2501largest communications providers, and at least 200 other U.S.2502organizations, including government agencies. Believed to have been2503carried out by an advance persistent threat actor attributed to the2504Chinese Ministry of State Security (MSS), Salt Typhoon exfiltrated2505millions of metadata records and content associated with calls and text2506messages of targeted individuals to include then-candidates President2507Trump and Vice President Vance, then Vice President Harris, and members2508of Congress. To be specific:25092510   They monitored live phone calls, gaining access to cellphone2511        and data networks, enabling real-time eavesdropping of calls2512        and texts.25132514   They harvested sensitive data by collecting private2515        communications, including those of individuals involved in2516        government or political activities25172518   And they compromised law enforcement systems by accessing2519        systems that log U.S. law enforcement requests for criminal2520        wiretaps, potentially tipping off Chinese intelligence about2521        American investigative targets.25222523    If that doesn't make you shudder--let's go a little further back in2524time. Active since at least 2021 but not revealed until much later--is2525Volt Typhoon. The Volt Typhoon attack was attributed to Chinese hackers2526who gained wide-spread access to critical infrastructure systems using2527a tactic known as ``living-off-the-land.'' These hackers stole2528credentials and quietly used administrative accounts to collect data2529and retain high level access to essential networks, remaining in the2530networks in preparation for a potential armed conflict--such as one2531between the U.S. and China over Taiwan.2532    This was an earlier advance persistent threat attributed to China.2533How did it work? Chinese-attributed hackers gained access to numerous2534critical infrastructure networks and systems with privileged admin-2535level accounts and valid passwords. They didn't use a virus--but rather2536gained access through stolen credentials and therefore look like valid2537users. Basically--living in our networks. They have been quietly using2538these accounts to:25392540  (1)  collect data, including credentials from local and network2541        systems,25422543  (2)  put the data into an archive file to stage it for exfiltration,2544        and then25452546  (3)  use the stolen valid credentials to maintain persistence.25472548    These attacks highlight the vulnerabilities in our communications2549networks, which provide the foundation for 1/6 of our Nation's economy.2550And trillions of dollars of economic activity depend on these networks2551every day. So, how do we secure our communications networks--which2552serve as the underpinnings of our modern digital society? We can either2553sit back or lean forward regarding the security of our networks. We can2554lean forward leveraging flexible cyber standards to support our2555Nation's economy and security, or we can sit back and wait for the2556inevitable next attack to happen.2557    After the revelation of Salt Typhoon, the FCC leaned forward in2558January 2025, by adopting a Declaratory Ruling finding that Section 1052559of the Communications Assistance for Law Enforcement Act (``CALEA'')2560requires telecommunications carriers to secure their networks against2561unlawful access or interception of communications. That action was2562accompanied by a proposal to require communications service providers2563to certify to the FCC that they have created and implemented an up-to-2564date cybersecurity risk management plan, which would strengthen network2565defenses from future cyberattacks. Similar requirements had already2566been adopted or proposed in multiple regulatory actions, such as being2567required of recipients of universal service high-cost support through2568the Enhanced Alternative Connect America Cost Model. The specific2569requirements were carefully designed to provide a risk-based, flexible2570approach while offering the Department of Commerce's National Institute2571for Standards and Technology (NIST) cybersecurity framework as a2572recommended option to meet the requirements. This approach was also2573coordinated with other regulators through the Cybersecurity Forum for2574Independent and Executive Branch Regulators. It provides a non-2575prescriptive, risk-based approach that allows agile flexibility, while2576providing a foundational framework with which to collaborate in a2577multi-stakeholder environment.2578    However, on November 20, 2025, the Commission reversed the ruling2579and putting the Nation at risk. The FCC cited engagement with providers2580and ``their agreement to take extensive steps to protect national2581security interests.'' However, the Commission does not cite any process2582by which providers will be held accountable to meet specific2583commitments. From my experience as Bureau Chief, I am not convinced2584that providers will take sufficient, sustained actions in the wake of2585Salt and Volt Typhoon without a strong verification regime. In my2586experience, the Commission could have incorporated the discussions and2587agreements from providers into the requirement to create, update, and2588implement a cyber risk management plan. That would have merged the2589accountability aspect with the providers' agreements. As things stand2590now, we can only hope that providers are taking appropriate steps and2591that these actions are sustained as the cyber threats evolve. And hope2592is not a strategy to secure our networks.2593    So, what can Congress do? I have three recommendations:25942595    First, we have tools such as the Cybersecurity Framework developed2596by NIST. Congress should encourage the FCC to require the NIST2597Cybersecurity Framework (or similar guidance) for all2598telecommunications providers. The framework is flexible and developed2599in collaboration with industry and the public to assist organizations2600to manage and reduce cyber risks. The FCC already requires small2601subsets of communications providers to develop and implement cyber risk2602management plans, citing the NIST Cybersecurity Framework as a model2603framework; in fact, they just proposed in August to require this of2604subsea cable licensees. Why not make this a requirement across all2605communications providers to ensure a ubiquitous level of cyber risk2606management?2607    Second, is to upgrade our communications infrastructure. Keeping2608communications infrastructure current is critical, but also costly. I2609encourage Congress to fully fund communications infrastructure such as2610Next Generation 911 and cyber funding for state, local, Tribal, and2611territorial entities. We can't enable modern digital network security2612when running on old analog infrastructure.2613    And lastly, verification must be part of trust. I agree that it's2614critical for industry to own the implementation of cyber risk2615management and that collaboration among government and industry2616stakeholders is key. But trust without verify is an incomplete2617solution. We must establish a verification regime to ensure the2618security of our Nation's communications infrastructure from the largest2619to the smallest providers. We've seen time and again through outage and2620enforcement investigations, where providers have not implemented even2621some of the most basic cyber hygiene uniformly across their networks,2622such as changing default passwords. Their networks are large, complex2623and difficult to secure--and yet they are critical to our Nation's2624economy and security. Industry says they're committed to implementing2625extensive cyber protections, so let's establish a regime in a secure2626setting for them to share their progress and further plans.2627    Thank you and I look forward to your questions.26282629    Senator Fischer. Thank you, Ms. Jordan.2630    We have been joined by the Chairman of the Commerce2631Committee, Senator Cruz. Would you like to make some opening2632remarks, sir?26332634                  STATEMENT OF HON. TED CRUZ,2635                    U.S. SENATOR FROM TEXAS26362637    Chairman Cruz. Thank you, Madam Chairman. I appreciate it,2638and thank you for holding this hearing. We have a distinguished2639panel before us and I want to thank each of our witnesses for2640being here to share your expertise.2641    In our digital age, communications networks form the2642cornerstone of our economy and our national security. That2643makes them a top target not only for criminals seeking2644financial gain, but also for our adversaries.2645    America's enemies have learned they do not need to launch2646missiles or deploy troops to harm the United States. Instead,2647they can use teams of skilled and well-resourced cyber hackers2648to steal our intellectual property, to gather intelligence, and2649to hide within critical infrastructure to disrupt essential2650services, all while maintaining plausible deniability.2651    2025 has been a pivotal year in network security, marked by2652the rise of AI-empowered attacks and defenses, alongside2653persistent risks ranging from infrastructure sabotage to2654increased supply chain vulnerabilities. Incidents such as Salt2655Typhoon and the SIM farms recently discovered near the United2656Nations headquarters in New York have served as sobering2657reminders of how relentless and creative our adversaries2658continue to be.2659    Unfortunately, there is no single, silver-bullet solution2660to address cybersecurity. Protecting America's communications2661networks is a complex undertaking that demands continued2662vigilance and cannot be reduced to rote box-ticking.2663    The United States is a primary target for cyber threats2664precisely because we lead the world in technological2665innovation. Our challenge, therefore, is to secure2666communications infrastructure effectively without creating2667excessive and useless regulation that stifles the very2668innovation that gives us our competitive edge.2669    That is why I commend FCC Chairman Brendan Carr for moving2670last month to rescind the Biden administration's misguided2671January 2025 Declaratory Ruling, which tried to shoehorn new2672cybersecurity mandates into a 1994 law about cooperating with2673law enforcement. Chairman Carr's decision to shift away from2674ineffective and burdensome requirements is consistent with both2675the Commission's legal authority and sound policy.2676    Federal agencies cannot regulate their way into creating2677perfect network security, and attempts to do so will backfire.2678Forcing telecom carriers to chase the false security of2679compliance checklists instead of engaging real-world threats2680diverts resources away from the necessary partnerships and2681response capabilities that actually stop intrusions.2682    Worse still, the legal risks these compliance regimes2683impose have a chilling effect, as armies of lawyers focus on2684avoiding lawsuits and regulatory penalties instead of2685information-sharing and collaboration when every moment counts.2686    To meet these evolving threats, the Federal Government must2687incentivize genuine cooperation so that communications networks2688can focus on anticipating the next attack, not just responding2689to the last one.2690    This needed foresight and agility, and it does not come2691from imposing outdated checklists and top-down regulations. It2692arises from a strong partnership between the private sector and2693the government, working together to detect and deter attacks in2694real time.2695    I am proud of this Committee's progress toward2696strengthening network security, but much work remains. Our2697efforts show that success is possible. With full funding now2698secured, the Rip and Replace program is removing the remaining2699Huawei and ZTE equipment from our networks.2700    GPS offers another example. When threats to our positioning2701and timing capabilities were identified, we acted decisively by2702passing the National Timing Resilience and Security Act to2703establish backup systems. Now, alternative and complementary2704positioning, navigation, and timing systems are in development,2705with NTIA recently identifying at least 50 companies attempting2706to increase our resilience and complement this critical system.2707    Today's hearing is an opportunity to assess the current2708threat landscape, identify where our defenses fall short, and2709explore how the Federal Government and the private sector2710together can better protect America's communications2711infrastructure from both foreign and domestic threats. I look2712forward to a productive exchange.2713    Senator Fischer. Thank you, Senator Cruz. We will now begin2714our questions for the panel, and I will start. We will do a2715five-minute round, please.2716    Mr. Jaffer, as you testified, the Salt Typhoon hacks proved2717that China obtained widescale access to our telecommunications2718network, and based on the publicly available information, what2719distinguishes Salt Typhoon from prior nation state operations2720targeting U.S. telecom networks?2721    Mr. Jaffer. Thank you, Chairman Fischer. I think the most2722distinctive thing about Salt Typhoon is the breadth and the2723depth of the access the Chinese government obtained to2724America's telecommunications infrastructure. Now again, only2725based on what we know publicly, it is clear that they were able2726to go after nine telecommunications providers. It appears that2727they actually obtained access to either our law enforcement or2728potentially our foreign intelligence surveillance systems at2729some level. Whether it was the collection or the task targets,2730we do not know the details.2731    But if you think about what that means, that depth of2732access, and that sustained access to that sensitive information2733is massively damaging not just to our communications2734capabilities, but to our national security. And so this is the2735real challenge, is the depth and breadth of the access they2736obtained.2737    Senator Fischer. How difficult is it to be able to detect2738that, and what does that tell us about the current existing2739capabilities that we have to monitor?2740    Mr. Jaffer. Well, we obviously were able to eventually find2741them, but it took us too long. We now have assessed that they2742were in those systems, or were targeting those systems, since2743at least 2021, or at least going after them. And we do not know2744when they got in.2745    The other real problem is that once they got in, they2746burrowed so deep we are not sure whether we can or have gotten2747them all out completely. They may still very well be in our2748systems. At least one provider suggested they have successfully2749removed the actors they know about. The question is, how deep2750are those actors in our systems and how sustained is their2751access.2752    So we were not able to detect them when they came in. Could2753we have? Possible. Certainly we had plenty of warning that they2754were coming after our systems. And this is what is crazy to me.2755The government actually now has admitted that it identified2756them in different systems. It did not realize they were the2757Salt Typhoon hackers. But now having connected them to these2758hackers, they now realize they actually saw them.2759    Senator Fischer. Is it easier now to be able to detect from2760lessons learned?2761    Mr. Jaffer. Well, look. Certainly every day that goes by we2762learn more about the adversary. We learn more about our2763capabilities. We develop new capabilities. The advent of AI,2764while it provided significant benefit to the offense, also2765provides a significant benefit to the defenders, as well. We2766should be deploying that at scale.2767    The real challenge today, though, remains that we remain in2768the situation sort of blaming via victim. In this case we are2769saying, look, if the telecom companies, they did not do their2770part, they did not update their systems--and there may be2771serious problems there and things that need to be addressed--2772but beyond that, the question is what did the government know2773about the attacks, why did it identify the attackers as2774different systems, and not take action to find them everywhere2775else they were, having found them once? And why didn't they2776share that information effectively with the private sector2777rapidly? I mean, this is like the CIA identifying Khalid2778Almidhar and Nawaf Alhazmi in Kuala Lumpur and not telling the2779FBI that they had visas to come to California, to come to the2780United States.2781    Senator Fischer. You know, I mentioned the FACT Act, the2782bill that I passed here in the Senate. How concerned should we2783be about China in our hardware, in core networks? Briefly.2784    Mr. Jaffer. Well, there is no question that we need to go2785after the Chinese in this space. They are absolutely targeting2786those core networks. They have spent a lot of time trying to2787get into our hardware and infiltrate our supply chains. I think2788the FACT Act is a great piece of legislation. We need to get it2789enacted as soon as possible. But we need to go even further. We2790really have got to get aggressive about identifying the fact2791that China has infiltrated our infrastructure not just through2792hardware itself but through the chips, as well. China has a2793huge supply of large-format chips. They are trying to get2794advanced chips, as well. They are on the path to it. They are2795not going to get EUV for a while, but they are going to use2796advanced EUV, and that is a problem.2797    Senator Fischer. You know, Mr. Mayer, as we are looking2798here in Congress to be able to remove a lot of that risky2799telecom gear from our networks currently, what policies do you2800think we need to prioritize with regard to supporting2801manufacturing of our domestic or our trusted ally equipment2802here, so we do not run into a lot of the situations that Mr.2803Jaffer was referring to?2804    Mr. Mayer. So to set the stage for responding, the2805equipment in the telecom ecosystem is massive. It spans many2806continents, overly concentrated, frankly, in an area of the2807world which we know is subject to disruption. The Chinese have2808expressed their interest in terms of what they want to2809accomplish in that region, and there are a lot of countries2810that are now moving their supply chain to countries in that2811region also.2812    So I think from a policy perspective, we have to understand2813that there is significant technology embedded in our systems,2814and I think what Congress did with Rip and Replace was2815admirable, because it recognized two vendors who we knew were2816responsible for malicious surveillance and presented a risk to2817our military establishments in some areas, but more2818importantly, an overall risk to our ability to manage and2819control network security.2820    Senator Fischer. I am out of time so briefly, can you do2821like a one, two, three, what we need to do with our2822manufacturing on this?2823    Mr. Mayer. Right. I think we have to tighten the2824requirements on vendors to improve cybersecurity. I think the2825concept of security dies by design. It is critical. We have to2826build it in, not bolt it on afterwards.2827    Senator Fischer. OK.2828    Mr. Mayer. And I think we need to have a very close2829relationship with our government intelligence community about2830what they discover, what is suspicious, and they have to share2831that with us so we can probe and help them resolve some of the2832insecurities in that realm.2833    Senator Fischer. Thank you very much. Thank you. Senator2834Lujan, you are recognized.2835    Senator Lujan. Thank you, Chair Fischer. Ms. Jordan, you2836were at the FCC as Chief of the Public Safety and Homeland2837Security Bureau when the FCC adopted the declaratory ruling2838that affirmatively required telecommunication carriers to2839secure their networks from unlawful access and interception of2840communication. The FCC also proposed rules to require covered2841communication service providers to submit an annual2842certification attesting that they created updated and2843implemented cybersecurity supply chain risk management plans,2844things of that nature.2845    Can you explain briefly why the FCC moved forward with the2846declaratory ruling and advanced additional proposals earlier2847this year?2848    Ms. Jordan. As I mentioned earlier, part of what Salt2849Typhoon did was gain access into our law enforcement requests2850and records, giving China access to our administrative2851proceedings against adversaries. And so as I mentioned, Section2852105 of CALEA, with its systems security and integrity, requires2853that they secure the systems from unauthorized access. So it2854was basically reemphasizing that.2855    With regard to the Cyber Risk Management Framework, that2856was developed by NIST, I think it is being referred to as a2857checklist, and I kind of take exception to that. It is a risk2858management plan. Yes, there are a number of steps that you go2859through. Do you have governance? Are you changing and not using2860default passwords? Are you assessing your risk against a number2861of things like installing patches in a timely manner? You know,2862the FCC just recently released another warning to the EAS, the2863alerting systems, that they need to patch their systems because2864again they have been hacked.2865    And so that proposal that was pulled back to implement the2866Cybersecurity Framework is already in place, voted unanimously2867in the past several years, for portions of the communications2868sector. In fact, in August it was proposed for subsea cable2869licensees to be required to do similar cyber risk management2870planning.2871    So again, it is not a checklist. It is do your2872cybersecurity in a methodical, planned way, and keep track of2873what you are doing so that you know internally, your leadership2874knows, and you can share it when asked, whether Congress or the2875FCC were to ask.2876    Senator Lujan. Ms. Jordan, with that being said, a couple2877of weeks ago the proposals were off the table after the Trump2878FCC voted along party lines to rescind these rulings. Has the2879FCC proposed any rules in the place of what it just rescinded2880to ensure that our networks are safe and secure against cyber2881threats?2882    Ms. Jordan. I have not seen anything. I have seen and2883heard, both in Robert's testimony as well as in the statements2884released by the FCC and the policies, that industry has2885committed or said that they will take extensive steps. But as I2886mentioned during my comments, there are no assurances. We do2887not know what those extensive steps are.2888    Communications networks are large, complex, and they2889require significant measures to be taken to secure them. So2890without some sort of accountability regime, we do not really2891know what they are doing, how effective it is, how widespread2892those measures will be.2893    So the answer is no, there is nothing that I am aware of2894that they have put in place.2895    Senator Lujan. Mr. Mayer, Mr. Jaffer, you have both2896stressed the importance of American leadership in emerging2897technologies such as AI and quantum in your opening statements.2898In this Committee, in this year alone, we have had multiple2899hearings on AI, and we often hear that we are in a race against2900the Chinese government.2901    The question for both of you, yes or no--and if you want to2902editorialize I would invite you submit that into writing--yes2903or no, please. Is it possible to win a race against the Chinese2904government if America is constantly leaking our IP to them2905through hacks in our telecom networks? Mr. Mayer?2906    Mr. Mayer. Is it possible to beat the Chinese in the AI2907race if there are leaks in our infrastructure?2908    Senator Lujan. That is the question.2909    Mr. Mayer. Yes. So the answer is that----2910    Senator Lujan. Yes or no, sir. You can editorialize all you2911want, volumes and volumes, in writing.2912    Mr. Mayer. Yes, I do not think it lends itself to a yes or2913no.2914    Senator Lujan. I appreciate that. Mr. Jaffer?2915    Mr. Jaffer. No.2916    Senator Lujan. I appreciate that. The correct answer is no.2917If the Chinese government is able to get their hands on2918everything we are doing in the United States with IP, then what2919are we doing? We should just have open protocol everywhere and2920let them do whatever the hell they want. How can we ensure2921equally strong cybersecurity standards across our networks2922without proper Federal regulations? Is it possible, yes or no,2923Mr. Mayer?2924    Mr. Mayer. We can do it without Federal regulation. The2925regulation is a prescriptive, bureaucratic, static approach to2926a problem. It does not solve the environment we are in today.2927    Senator Lujan. So you are suggesting it can be done2928voluntarily?2929    Mr. Mayer. I am suggesting that there is a shared2930responsibility across all aspects of the digital ecosystem.2931    Senator Lujan. So if I heard you correctly earlier, you2932said that there should be tightening on the vendors. So there2933should be regulation on vendors?2934    Mr. Mayer. There should be expectations put on vendors to--2935--2936    Senator Lujan. Should there be expectations put onto2937telecommunications companies?2938    Mr. Mayer. There are expectations put on telecommunications2939companies.2940    Senator Lujan. I appreciate. Mr. Jaffer?2941    Mr. Jaffer. I think you can do it without Federal2942regulation, but I think the better way to do it is with a2943partnership between the public and private sector. If we2944incentivize the kind of behavior we want from our industry, we2945are more likely to get it. Let me give you just one example2946why. The more regulations we put on our providers, the more you2947are saying put the lawyers in the room and have the lawyers2948decide what happens. And you know what lawyers do? I am a2949lawyer, a recovering lawyer. We tell our clients to do the2950minimum necessary, at the latest time possible, do only what2951you are required to do.2952    If, on the other hand, you incentivize people to do the2953right thing, you give them tax benefits, access to government2954programs, and the like, they are more likely to line up, your2955boards, your CEOs. Everyone is going to be in the same room2956because they are going to say, kook, we get a benefit by doing2957these things. Give me liability protection. Give me regulatory2958protection. Now I am going to tell my CFO, go share all the2959information you can. Now everyone is lined up in the same2960direction. To me that is a more effective way to get to the2961goal you want, which is exactly right. We cannot win the AI2962race if we are leaking stuff out to China. The question is how2963do we get there. do we regulate it in place or do we2964incentivize it?2965    Senator Lujan. Thank you, Mr. Jaffer. My time has expired.2966If we have another round of questioning I would like to come2967back. Thank you.2968    Senator Fischer. Thank you, Senator Lujan. Senator2969Blackburn, you are recognized.29702971              STATEMENT OF HON. MARSHA BLACKBURN,2972                  U.S. SENATOR FROM TENNESSEE29732974    Senator Blackburn. Thank you, Madam Chairman, and thank you2975all for being here.2976    I want to return to the subsea cable issue, which I think2977is so vitally important. And I had introduced the Undersea2978Cable Protection Act because of concerns over what was being2979done that would really preserve and make certain that we had2980these cables. Of course, attacks on these--tampering, cutting--2981is something that is there.2982    Mr. Jaffer, let me come to you because I want you to talk2983for a minute about the vulnerability of the landing stations2984and the cable routes to foreign adversaries and foreign2985attacks, and why we should prioritize these protections?2986    Mr. Jaffer. Well, Senator Blackburn, as you know, 902987percent of the world's Internet traffic travels over these2988cables, 99 percent of transoceanic communication goes over2989these cables. And so you are right. It is not just the cables2990themselves that are vulnerable. It is the landing stations, as2991well.2992    Talk about the cables first. You have got cable cuts that2993have happened, and we see them in Taiwan, we see them in the2994Baltics. The Chinese have been dragging their anchors2995intentionally. We think it is intentional, certainly maybe by2996accident. These things can happen at times. We have known for a2997decade the Russians have been targeting our cables for2998surveillance, and they are almost certainly if they are able to2999get devices on the cables to tap them, they can certainly3000disrupt them, as well. So it is a huge problem when you are3001talking about the quantity of communications that are there.3002    The other problem is once the cables are cut, getting3003capability out there to restore them is limited significantly,3004and that is why legislation like yours is so important. But we3005rely on Chinese companies to do a lot of the cable fixes,3006particularly in the Pacific. That is a huge problem. If these3007cable are cut, we are essentially blind. We have got a lot of3008capabilities with satellite, as well, but, of course, the3009Chinese are targeting our satellites, as well. It is a huge3010problem.3011    Senator Blackburn. Yes. Let me jump in there, on the3012satellite. And is it Mr. Gizinski--I want to be sure I am3013saying it right--talk for a little bit about that. Because our3014primary delivery system is the subsea cables, and then you look3015at what we can do with the satellite capacity, and I think that3016what we have, satellites would offer about 50 terabytes. You3017know, we understand how indispensable this subsea3018infrastructure is.3019    So talk with me about how we should look at the3020complementary role of the subsea cables and then also the3021satellite system?3022    Mr. Gizinski. Senator, thanks for the question. I think a3023couple of key points. Certainly the capacity for satellite3024communications is lower than that of subsea cables, but they do3025provide today both core critical infrastructure on an ongoing3026basis as well as key disaster failover capabilities.3027    One of the core areas of focus, though, is the same risks3028that are present to those subsea cables are also present to3029satellites. They are vulnerable to both physical,3030electromagnetic, and cyberattacks. It is a core area of focus,3031something that we have looked at closely. In many cases, those3032deployed and operational satellite systems are either owned and3033operated underneath a foreign flag or they have a number of3034foreign supply components into them. That same level of3035attention and focus that is paid to other aspects of the3036infrastructure is important to pay to that core aspect of3037failover infrastructure, as well.3038    Senator Blackburn. OK. Let me ask you this. Have you, by3039any chance, seen or are you aware of the Naval Capitation3040Project at the Port of Memphis? OK. It would be worth your3041time, because they are looking at the underwater and also the3042above, and it is a wonderful project there at the Port of3043Memphis.3044    Mr. Jaffer, I want to come back to you. SIM farms. I think3045that these SIM farms are powering the large robocall operations3046and the scams, and we are seeing a lot of these. There has been3047a lot of talk about that this week because of Black Friday and3048Cyber Monday. What are the weaknesses in our current3049authentication systems when it comes to isolating or actually3050pinpointing these SIM farms?3051    Mr. Jaffer. Yes. Well, as we have seen, we saw what3052happened. Chairman Cruz referred to it in his opening statement3053about the SIM farm that we saw up in New York during the U.N.3054hearings. You have talked about it, and the fraud that we have3055seen against our seniors and a lot of consumers. It is hugely3056problematic.3057    Obviously, we need to get better on this front. The3058question becomes how do you do it in a way that is effective3059and still deployable in our current infrastructure, and that3060is, I think, the hard part. You know, we have done a lot with3061eSIM, and I think eSIM is significantly more secure and has the3062ability to be leveraged to be more secure. So I think as we3063shift to more eSIMs that will make it more effective.3064    The adversary is always going to make a move. The offense3065is always going to have an edge. The best you can do as a3066defender is hope to keep up, and with the advent of modern3067technology, and AI in particular, people worry that the offense3068is going to get a lot better. But I believe, actually, it will3069allow our defense to get just as good and to keep up more3070effectively.3071    So I think applying those capabilities in the3072authentication domain is really important, not just, by the3073way, for SIMs, but for regular Internet authentication, as3074well, financial transactions, and the like. We have seen the3075pivot to passkeys from passwords. That is a significant move. I3076think that is going to be empowered by our new-found AI3077capabilities.3078    Senator Blackburn. Thank you. Thanks, Madam Chairman.3079    Senator Fischer. Thank you, Senator Blackburn. Senator3080Rosen, you are recognized.30813082                STATEMENT OF HON. JACKY ROSEN,3083                    U.S. SENATOR FROM NEVADA30843085    Senator Rosen. Thank you, Chair Fisher, Ranking Member3086Lujan, for holding such an important hearing. It is really3087critically important because the security of our telecom3088industry is not only essential, I believe, for our national3089security but also for closing the digital divide, because3090connectivity must be secure and resilient, as we have all been3091talking about, for it to be successful. And I appreciate the3092discussion on Salt Typhoon. We need to be sure that we protect3093ourselves in every way possible, and building on our satellites3094and our undersea.3095    But I want to move on to something you just touched on,3096artificial intelligence and our threat environment. Because AI3097tools have made it easier than ever for threat actors to create3098realistic and sophisticated attacks to gain access to sensitive3099systems, to our valuable data. And even without the use of AI,3100we continue to see cyberattacks with increasing frequency.3101    In August, Nevada was hit with a devastating cyberattack,3102crippling its agencies while the state worked with CISA and the3103FBI to track down the cyber criminals and secure Nevada's data.3104Thankfully, the state made a full recovery. It appears that no3105sensitive data was taken.3106    But Ms. Jordan, I am going to start with you. In this3107environment with threats from cyberattacks growing every day,3108what is the risk of having a reactive Federal response rather3109than proactively encouraging, and in some cases requiring,3110certain levels of cybersecurity for our critical sectors?3111    Ms. Jordan. Thank you for the question. The risk is high,3112and the consequences are severe. We saw Salt Typhoon. There3113could be things that happened that are even worse than that, or3114Salt Typhoon could continue. They could be continuing to3115exfiltrate information.3116    Senator Rosen. And so we have cut resources at CISA. We3117have disbanded Cyber Safety Review Board. So how is this3118impacting what we are able to do?3119    Ms. Jordan. It is of great impact. I think to CISA, with3120them putting out guidelines, them putting out known exploited3121vulnerabilities, sharing the patches and the criticality, in3122other words, you should do this one really soon because it is a3123high vulnerability. This one maybe can wait a little longer. So3124without that information, that information sharing that my3125colleagues have been talking about is limited.3126    Senator Rosen. CISA is that bridge between public and3127private, between our grid and all of that. It is important that3128we do not just get rid of CISA.3129    Ms. Jordan. I think so, yes.3130    Senator Rosen. And so, you know, people have talked about3131the incentives for current telecom companies to ensure their3132networks are secure, commonsense cyber hygiene, all the kinds3133of things that you spoke about, encryption, dual-factor3134authentication, passkeys. Ms. Jordan, again I am going to ask3135you. Are there any Federal programs that incentivize smart3136cyber practices, and what do you think about those? Quickly3137because I have another question to ask Mr. Mayer.3138    Ms. Jordan. Yes. I am not aware of any that incentivize3139other than regulations that require. I think if there were3140incentives I would be in favor of them, alongside an3141accountability regime like regulation that looked at3142incentivization, as well.3143    Senator Rosen. Thank you. Mr. Mayer, I am going to move on3144to you. In an AI-enabled threat environment what can Congress3145do to help secure our networks? For example, some have3146suggested additional funding to support carriers and ISPs,3147ensuring that they have adequate cybersecurity protections.3148Quickly--I have one more question for a former Nevadan, I3149believe, worked for Sierra Nevada Corporation--how do you think3150we can provide that support here in Congress?3151    Mr. Mayer. I think you have to encourage innovation, not3152regulation. We had an incident two weeks ago reported by3153Anthropic, that for the first time, using commercial, off-the-3154shelf AI platforms they were able to initiate a cyberattack.3155Eighty percent of that attack did not require human3156intervention. It was fully executed by an AI platform that is3157currently commercially available. Over time, that 80 percent is3158going to move toward 100 percent. That is the environment we3159are in.3160    There is no way that a prescriptive checklist regulation is3161going to allow us to innovate in the way we need to innovate to3162address that threat.3163    Senator Rosen. So investing in public-private partnerships3164and innovation in our universities, our research institutions,3165and with our private companies would be, in your advice,3166reasonable.3167    Mr. Mayer. Reasonable, vastly superior, and should be3168encouraged by Congress.3169    Senator Rosen. Thank you. I have one last question about3170U.S. leadership in the telecom industry. It is essential to3171securing our network. We have to be on that leading edge of3172innovation, maintaining our U.S. leadership in international3173settings standards. So Mr. Gizinski, you worked for defense3174companies like Sierra Nevada Corporation, which is proudly3175headquartered in Sparks, Nevada. Can you speak to the3176importance of ensuring we have secure and resilient3177communication networks, how important is it to national3178security and U.S. jobs if we do not have a strong cyber posture3179across critical infrastructure sectors like telecom?3180    Mr. Gizinski. Senator, thanks for the question. It is3181critically important that we have a secure cyber3182infrastructure. One of the core areas that I have looked at and3183thought about quite a bit in this is promoting that culture3184throughout the defense industrial base of leaning forward and3185adopting strong cyber practices. I think that is something that3186we have seen some adoption driving toward strong incentive3187programs, encouraging the innovation that is being harnessed3188today to deliver next-generation technical innovations. We are3189seeing in the satellite industry the launch of a number,3190thousands of new satellites a year. That same innovation should3191be harnessed and driven to secure our cyber posture, as well.3192    Senator Rosen. Thank you very much.3193    Senator Fischer. Thank you, Senator Rosen. Senator Schmitt,3194you are recognized.31953196                STATEMENT OF HON. ERIC SCHMITT,3197                   U.S. SENATOR FROM MISSOURI31983199    Senator Schmitt. Thank you, Madam Chair. Just to follow up3200on that a little bit, Mr. Jaffer. In December I had called for3201an investigation of the Department of War handling of the post-3202Salt Typhoon risk, in particular, the Department's failure to3203ensure its communications, voice, text, video were protected3204from foreign espionage vulnerabilities. In your view, what are3205the structural problems in Federal procurement that make it3206possible--or I should say, what should Congress consider as far3207as the Federal procurement process to make that better?3208    Mr. Jaffer. Well, Senator, certainly I think that the3209procurement system is one place where Congress and the3210Executive Branch can do a lot more to ensure effective3211cybersecurity. In the procurement process, because you are3212spending our taxpayer dollars and people want these contracts,3213we can impose whatever requirements we want on them. To me that3214is a much more preferable way to address the regulatory burden3215that folks want to put on industry. It is because if you a3216government contract, they should secure the systems to the3217government's standards.3218    At the same time, we are seeing the Department of War today3219pivot to a much more innovative approach to procurement, a much3220more commercial approach to procurement. I think that is the3221right thing to do. It allows us to get newer, better technology3222in faster. There we have to make sure we are not over-imposing3223cybersecurity burdens that will prevent us from getting the3224technology we want. There is a balance there that we can3225achieve, I think one that we can do successfully as we need to,3226going forward.3227    Senator Schmitt. I agree in the sense that we have a lot of3228leverage as it relates to those contracts. In your view, what3229are some of the minimum cybersecurity standards or audit3230compliance that should be included in those contracts?3231    Mr. Jaffer. What I do think we should do is require3232companies that sell to the Federal Government to go through a3233security audit and to demonstrate, to an independent third3234party, that they have successfully met things like the NIST3235Cybersecurity Framework, that they are applying it effectively3236and they are implementing it effectively. That, to me, is a3237good starting point. If they are able to show that to the3238government, the government does not need to do additional work3239on its own to qualify them. They can do that ahead of time.3240They can get the audit paperwork, present it to the government,3241and then become a contractor much faster. To me, that is the3242way to get smaller, faster companies in and not put an3243additional Federal regulatory burden upon them while still3244requiring them to meet good cyber hygiene requirements like the3245NIST framework.3246    Senator Schmitt. Mr. Mayer, I wanted to ask you, in your3247testimony you emphasized that prescriptive regulations cause us3248to lag behind adversaries, for a bunch of different reasons.3249You warned that this shift in attention from managing real risk3250to managing paperwork means a provider can legally and fully be3251compliant but still be very exposed.3252    Can you speak to the impact that we have seen already from3253the previous administration's more prescriptive checklist-3254driven approach what that has kind of left behind and what we3255can learn from that, moving forward?3256    Mr. Mayer. So we know that the checklist, and we have3257evidence of this, have not been successful. There are examples3258where individuals or organizations that was managed by3259checklists, they missed things. And in this environment where3260the adversaries are evolving on a daily basis, using a3261checklist would, in a sense, be looking in a rearview mirror.3262We have heard talk about the flexibility in the NIST framework.3263That was designed to withstand the test of time. It worked over3264a decade.3265    So I think the better approach, and we are doing this, is3266to engage with our government partners, on a regular basis,3267including the intelligence community and the law enforcement3268community, and talk about what we are observing, what the3269government is observing, how to mitigate those activities. And3270we do hold ourselves accountable. I can tell you, the frontline3271practitioners in our companies work every day to defeat these3272attacks. We do not hear about their success rate, but they are3273dedicated and passionate about security, and they are held3274accountable within their organizations, to their customers.3275    And finally I would say in the context of contracts, that3276is a legitimate avenue for negotiations, to talk about the3277security requirements that are needed, and we have been doing3278that for years, through service-level agreements and other ways3279to reach an understanding of what is expected.3280    Senator Schmitt. So with the 43 seconds I have remaining, I3281will just throw two questions out for whoever wants to grab3282onto them, because I do think these are important. What we3283learned, I think, from Salt Typhoon is that there are a lot of3284deficiencies in the hardware that currently exists, that is3285outdated, and I know there are efforts to sort of update that.3286Can you give me an update on where that stands? And why, as it3287relates to satellite security, what are just some simple things3288like enabling encryption, why are we not further along with3289that?3290    So hardware issues and updating that and then encryption3291for satellites.3292    Mr. Gizinski. So I think a couple of aspects, certainly on3293the hardware side, major area of emphasis and ultimately very3294important to pay attention to the supply chain of not just the3295hardware but the software that is going into those systems,3296putting together transparent messaging around the source of all3297of the software aspects that are incorporated in deliverable3298systems.3299    There are a number of explanations that have been provided3300for some of the complexities that are created by enabling3301encryption. I would say it is a little bit of a surprise, and I3302think there is probably further discussion needed, on some of3303the limitations that are preventing encryption from being3304broadly used on satellites. It is something that we have3305strongly advocated for. We have made those tools available to3306many of our customers that are using that equipment over3307satellite links. And we are still seeing, to this day, that3308equipment not being enabled, that feature not being turned on,3309and those links being left out in the clear.3310    We do think a part of the driver for that, the shift toward3311the concept of zero trust architecture, where each system and3312subsystem is assumed to be untrusted, has not been fully3313adopted across the satellite industry, more broadly. Certainly3314it appears to be potentially a misunderstanding of who is3315responsible for that layer of security in the overall system.3316    Senator Schmitt. Thank you. Thank you, Madam Chair.3317    Senator Fischer. Thank you, Senator Schmitt. Senator3318Hickenlooper, you are recognized.33193320             STATEMENT OF HON. JOHN HICKENLOOPER,3321                   U.S. SENATOR FROM COLORADO33223323    Senator Hickenlooper. Thank you, Madam Chair, and I thank3324all of you for being here. I appreciate all the work you are3325doing. As a broad context, when I was finishing my first term3326as Governor of Colorado, we did an economic development trip3327around Asia, and it ended up in Israel. So we just saw a lot of3328the technologies you all are familiar with. We also saw3329Israel's ability to connect military with their academic3330research and their universities, with their entrepreneurs. And3331we have a National Center for Cybersecurity in Colorado Springs3332that tried to pick up on that. But I think that is an art, just3333as we discuss these issues.3334    And just to continue what Senator Schmitt was asking, and3335maybe I will turn to Ms. Jordan on this, Colorado's critical3336infrastructure from energy facilities to military3337installations, top to bottom, depends on secure communication3338links. And we know that adversaries are constantly trying to3339interrupt and disrupt our communications, penetrate our3340national security in every way they can.3341    In your view, what are the largest gaps in Federal-State3342information sharing on security as threats to our3343communications?3344    Ms. Jordan. So I think that information sharing, in3345general, is important, both among industry and the government,3346and it should include state and local, for instance, state3347fusion centers, along with the Federal intelligence3348communities. And where that is not happening, that is a big3349gap.3350    I think that understanding what the threats are,3351implementing even the most basic cybersecurity hygiene,3352updating the patches to software, and those kinds of things,3353are critical.3354    Senator Hickenlooper. Right. So those are the easy parts.3355So we turn the page and we look at, as quantum advances,3356certainly the encryption systems protecting our communications3357networks eventually are going to become vulnerable to rapid--3358can you say decryption? Is that fair? Is that the right word?3359And this is a future threat window that is immense by most3360measure.3361    Now, NIST recently published the world's first Postquantum3362Cryptography Standards that can be adopted by the U.S.3363Government, which you were just describing is a pretty basic3364blocking and tackling. We need to go to that next level. So3365given your experience with the Public Safety and Homeland3366Security Bureau, how should the FCC begin incorporating3367quantum-resisting cryptography and post-quantum transition3368planning into its network security roles?3369    Ms. Jordan. It is definitely an advanced area that needs to3370be looked it. I agree with my colleagues on collaboration. I3371think that having those joint discussions with industry on how3372that is being rolled out, the pace at which it is being rolled3373out, and then looking smartly at what needs regulation, where3374there should be secure by design, in other words, things that3375are built into products before they are deployed, and then3376where is there a need, for instance.3377    The FCC hosts something called the Communities Security3378Reliability Interoperability Council, CSRIC. It is a3379partnership, and they come up with beset practices. So that is3380like ripe for a CISREC committee. But then when those best3381practices are put out, they have to be used.3382    Senator Hickenlooper. Right. Well, that is the next big3383step. I agree.3384    Mr. Mayer, as you know, again, Colorado is home to many3385entrepreneurs and research labs up and down the Front Range,3386and definitely on the front lines of 5G and next-gen wireless3387communications. But we have been working in a bipartisan3388fashion to finally close the shortage of funding for the SEC's3389Rip and Replace, where we found that we had a lot of3390infrastructure that was not as secure as we would like. The3391Salt Typhoon showed how deeply adversaries can burrow into our3392communications networks.3393    How can Colorado's rural broadband providers, which operate3394on thin, very thin, margins, benefit from additional Federal3395guardrails or minimum cybersecurity baselines to make sure we3396do not have similar breaches?3397    Mr. Mayer. Well, I think, sir, that the notion of doing3398basic hygiene is very important, and my experience is that the3399companies understand that and they are basically implementing3400that. The challenge for the rural providers is not having the3401resources that the larger providers have.3402    Senator Hickenlooper. Exactly.3403    Mr. Mayer. So what you are asking basically is a local3404telephone operation be able to compete against a nation state3405that is throwing everything everywhere, all the time, on these3406networks. They view those providers as access points to the3407entire ecosystem, and they exploit that. And we have seen that3408with Salt Typhoon, how that works.3409    So I think the other opportunity for us is there is $203410billion in non-deployed defunding. Cybersecurity would be an3411excellent way to invest that money, both in cybersecurity3412workforce development, training, and also the fact that there3413are legacy technologies. Rip and Replace was a great start. The3414list is getting bigger.3415    Senator Hickenlooper. Right. No, I agree. I am out of time.3416Mr. Gizinski, I have got a couple of questions for you that I3417will put into written questions. But I appreciate all of you3418being here. Thank you for your service. I yield back the floor.3419Sorry.3420    Senator Fischer. Thank you, Senator Hickenlooper. As a3421Senator you do not have to yield back time when you are3422finished.3423    Senator Hickenlooper. Really?3424    Senator Fischer. ``Thank you'' works.3425    Senator Hickenlooper. Well, I was out of time, so thank3426you, Madam Chair.3427    Senator Fischer. I am doing a rules thing now, too. Thank3428you. Senator Capito, welcome. You are recognized.34293430            STATEMENT OF HON. SHELLEY MOORE CAPITO,3431                U.S. SENATOR FROM WEST VIRGINIA34323433    Senator Capito. Thank you. Thank you, Senator Fischer, and3434thank you all for holding this hearing. Nice to see you. I am3435all the way over here.3436    Mr. Mayer, you kind of got into what one of my questions3437was going to be, but let me begin with this. The BEAD program,3438the West Virginia application was just OKed by the NTIA several3439weeks ago, and if you followed it you probably know that the3440original $1.2 billion that was allotted for West Virginia,3441which was quite large for a small state, is now $600 million,3442to deliver the BEAD program in West Virginia, after it had been3443rebid and everything.3444    I guess, in my opinion, where do you think--and I think you3445already mentioned this, but if we could flush it out a little3446bit more--with those extra dollars that are allotted for3447broadband, it seems to me that cybersecurity and other areas--3448you mentioned workforce training--where would you see--I would3449like to keep those dollars captured for the deployment and the3450safety of broadband, particularly the rural broadband. So if3451you could expound on that a little bit more?3452    Mr. Mayer. I think we can do both. It is very important to3453use that money for broadband deployment, especially in the3454rural areas of the country. We need to make sure that these3455citizens are not left out of the revolution that is underway,3456AI and all of that.3457    I think there is a general understanding that the nature of3458the threat environment right now is different. It is becoming3459much more urgent, that we have resources available to support3460that community.3461    So I think what we are talking about is targeted funding,3462with full accountability, in areas that these companies can--3463and they know, you know, we need this system, or we can use3464this mechanism, or we need these professional supports--have3465them being able to access those funds for purposes of3466increasing their cybersecurity, protecting their customers,3467protecting their networks. That is how we view it.3468    Senator Capito. Well, I think for small systems, which we3469have in a small state like ours--some of them are small; some3470of them are major--they just do not have the money to be able3471to do that. So then you look at, well, what are you going to3472do? Are you going to not deploy service in a rural area?3473Because you are going to have to make a choice. And it would be3474nice since, in the case of West Virginia, $600 million is not3475going to be spent where it was initially intended to, would be,3476I think, a source of funds.3477    I would like to see some more of those funds still3478deployed, because there are still going to be people that are3479left out, even after the BEAD program. And those are very3480difficult areas. But it sounds like we are saying the same3481thing in terms of the affordability of a rural broadband3482deployment company to be able to do this. I mean, I think if3483you think of it in terms of 9/11, where did they get in? They3484got in in small airports where there were vulnerabilities. Same3485thing with cybersecurity, to take the whole system down.3486    Which brings me to another issue. There is a lot of talk3487about data centers and the deployment of data centers, and how3488critical they are in the race for AI, and critical for us to be3489able to take advantage of the great technologies that we have.3490But those are new vulnerabilities, I believe, that are going to3491be presented. I was thinking about undersea cables and other3492things. Is this something that you all--should we be3493designating data centers as critical infrastructure, so that it3494can be part of how CISA and others look at our critical3495infrastructure? I do not know if you have any thoughts on that.3496    Mr. Mayer. I will take that. I think, to a large extent,3497data center infrastructure is already reflected in some of the3498critical infrastructure, whether that is critical3499manufacturing, the IT sector, the communications sector. It is3500in there. It is something that we take very seriously, frankly,3501because we are seeing evidence now that the data centers are3502targets. And we also see, we saw this week, or two weeks ago, a3503situation where a cooling device in a data center resulted in a3504massive disruption, one cooling device affecting major e-3505commerce platforms and social media platforms across the globe.3506    So there is an element of systemic risk that is built into3507a highly complicated, distributed network ecosystem. And I3508think that understanding that we are talking about attacks that3509are everywhere, all the time, I like to talk about the fact3510that they are 22,300 feet in the sky, they are 4 miles3511underneath the surface of the sea, and everything in between.3512That is the attack vector. And for us, as network service3513providers, we are very concerned about the ability to3514infiltrate edge devices that do not have the appropriate3515security built in. They want to go to market quickly. They want3516to go with cheap prices. That is why the FCC action, for3517example, around clean cars, which would impose expectations on3518the retailers to not make those faulty edge devices available3519to the public. That is an important step going forward,3520recognizing that issue.3521    Senator Capito. Thank you. Thank you, Madam Chair.3522    Senator Fischer. Thank you, Senator Capito, and thank you3523for bringing up the BEAD program, which you and I worked on in3524that infrastructure bill and the importance of that on making3525sure unserved areas are connected, and hopefully that funding3526that was provided to our states will remain there and be able3527to be used for things, not just connectivity but also the3528security that is needed.3529    Senator Capito. I think that would be a well-placed use of3530the funds, and it is so necessary, certainly in light of the3531testimony we have heard today. Thank you.3532    Senator Fischer. Thank you very much. Senator Peters. Oh, I3533am sorry. Senator Cantwell has joined us, Ranking Member.3534Welcome, Senator Cantwell. Do you have opening comments you3535would like to make, or questions?3536    Senator Cantwell. I will just make a few comments and then3537get to questions.35383539               STATEMENT OF HON. MARIA CANTWELL,3540                  U.S. SENATOR FROM WASHINGTON35413542    Senator Cantwell. Thank you, Madam Chair. Thank you so much3543for holding this hearing, to you and to Ranking Member Lujan.3544    I want to focus on Salt Typhoon. Obviously, the Chinese3545government's espionage operation deeply penetrated networks of3546at least nine U.S. telecom companies, including AT&T and3547Verizon. It has been described as the worst telecom hack in our3548Nation's history, and the Chinese government-sponsored hackers3549broke into our Nation's telecommunications backbone. They3550exploited the wiretapping system that our law enforcement3551agencies rely on under the Communications Assistance for Law3552Enforcement Act, known as CALEA.3553    These systems became an open door for Chinese intelligence.3554Salt Typhoon allowed the Chinese operation to track millions of3555Americans' locations in real time, record phone calls at will,3556and read our text messages. Their targets included then3557candidates President Trump and Vice President Vance, as well as3558senior government officials. And the hackers were also able to3559determine who the U.S. Government was wiretapping, including3560suspected Chinese spies, telling Beijing which of their3561operatives might be compromised.3562    So how did this happen? Senior national security officials3563said the breach occurred in large part because3564telecommunications companies failed to implement rudimentary3565cybersecurity measures. Investigators found legacy equipment3566not updated in years, router vulnerabilities with patches3567available for 7 years--7 years--that were never applied, and3568hackers acquiring credentials through weak passwords.3569    Security professionals across the industry were shocked3570because this kind of basic failure would not be acceptable in3571health care or banking or in technology firms. Yet here we are,3572the telecom system, and basically the most sensitive3573communications. AT&T and Verizon claimed they contained the3574attack, but government officials and cybersecurity experts3575remain deeply skeptical. The FBI said it cannot predict when we3576will have a ``full eviction'' of these bad actors, and even3577Chairman Carr acknowledging, when he was rolling back the rules3578that protected us, quote, ``We are still being exploited,'' end3579quote.3580    Earlier this year, I wrote to the CEOs of AT&T and Verizon,3581demanding that they provide documentation of their remedies.3582Both companies refused--hardly a transparent effort. I believe3583that the American people deserve to know whether China is still3584inside our telecom networks. We deserve to know.3585    Perhaps the most telling response in the breach came from3586the FBI itself. In an unprecedented step, last December, the3587FBI and CISA urged all Americans to use encrypted messaging--3588basically apps like Signal--to protect their communications.3589Hmm, interesting. ``Encryption is your friend,'' they said.3590Think about that. Our Federal law enforcement agencies are3591telling Americans, ``You cannot trust the security of your own3592telephone networks.'' That is what they are saying, and ``you3593should use encrypted communication''.3594    So, Ms. Jordan, what level of requirements should we be3595putting on our wireless providers that make sure that we are3596getting the level of security that Americans deserve? And when3597we are handing them over such valuable resources like spectrum,3598and they are trying to constantly end-run important national3599security and DoD initiatives just to get their hands on the3600spectrum, what requirements should we be putting in place that3601really do make Americans more secure in their communications?3602    Ms. Jordan. There must be structured cybersecurity3603requirements levied. I am not talking about a checklist, which3604has been referred to, but cyber risk management planning and3605executing those plans. That has to be put in place, and it3606should be a requirement. The FCC has already required it of3607certain subsections of the communications sector. In fact, in3608August, this Administration proposed it for subsea cable3609licensees.3610    So continuing along that path, the continued partnership of3611industry, the telecommunications industry, with government, the3612intelligence sector, CISA, others who know of the recent3613threats. And as you mentioned, doing basic cyber hygiene. You3614know, I would never let my iPhone go 7 years without a patch3615update, right? Ordering a pizza sometimes requires two-factor3616authentication. Why are our providers not implementing basic3617hygiene? They should be held accountable, and they should be3618doing a structured plan, and being held to a verification3619regime that would give you the information that you asked for3620and did not receive.3621    Senator Cantwell. Well, what about the FCC, walking back3622requirements additionally? It is like they are supposed to be3623the overall entity that says, look, here is how you have these3624communications licenses to provide communication, yet if you3625are not going to do good hygiene, why should we keep your3626license?3627    Ms. Jordan. Yes, I do not believe that a fallback of3628enforcement action is appropriate, because that is after the3629fact. So again, they should be leveraging this requirement to3630use the cybersecurity framework, or something similar, to do3631structured planning and execution of cyber risk management3632across the entire communications sector. They should not be3633doing it in little pieces like the E-ACAM or the subsea cable3634or this pocket. It should be done pervasively.3635    Senator Cantwell. Well, the grid, NARUC, is a similar3636organization that does this for the grid itself. Do you think3637that that is what we need here, something like that, where, at3638least, there is a dynamic and input? I mean, me personally, I3639think this is--we know this is the information age. We know3640that this is what is going to happen. So, letting these guys3641off the hook when there is so much vulnerability for Americans3642that our FBI and law enforcement are telling us, ``use3643encrypted networks,'' it has gotten to a point where we have3644got to do something to better help the public. Or basically you3645are just setting them up. You are just setting them up to say,3646``You are going to be a target.''3647    Ms. Jordan. I agree, and I think that there are some3648aspects of what China is doing that our Nation state, and3649therefore even the telecom providers, might not be able to3650stave them off. But if the providers are not doing basic3651hygiene across their networks consistently, then yes, they3652should be held accountable. I am not saying if a nation state3653comes in and does something that we could not predict. That is3654a different scenario. But they should be held accountable to3655doing the basic hygiene--patching, not default passwords,3656encryption, those kinds of things.3657    Senator Cantwell. Well, I think that is the most shocking3658thing. And this Committee has had several hearings, and there3659was another big break, and that was exactly the same issue.3660There was a patch. It was available. You know, as we have3661looked at privacy laws and what you need to do if you are3662providing some sort of system, yes. Nothing against 20- or 21-3663year-old administrators, but you have got to have more3664hierarchy to your enforcement and capabilities on security than3665just hiring a bunch of very smart, talented people when you3666have consumers who are going to be vulnerable to these kinds of3667things.3668    So, we look forward to working with the Subcommittee, Madam3669Chair, and figuring out what we can do to better protect3670Americans. Thank you.3671    Senator Fischer. Thank you, Senator Cantwell. Senator3672Peters, you are recognized.36733674                STATEMENT OF HON. GARY PETERS,3675                   U.S. SENATOR FROM MICHIGAN36763677    Senator Peters. Thank you, Madam Chair and Ranking Member.3678Mr. Mayer, as Ranking Member of the Homeland Security and3679Governmental Affairs Committee, one of my biggest concerns and3680focuses has been on long-term extension of authorities that are3681contained in the Cybersecurity Information Sharing Act of 2015,3682which I know you are very familiar with. Over 80 companies now,3683and organizations, support legislation that I am working on3684with Senator Rounds, in a bipartisan way, entitled ``Protecting3685America from Cybersecurity Threats Act'', which would basically3686extend those cybersecurity threat information sharing3687authorities for an additional 10 years. Like we all know, the3688last 10 years have been very successful. We need to continue to3689make sure that they are in place for long term, that industry3690and others can rely on it.3691    And I certainly appreciate how vocal USTelecom has been3692about the importance of extending this authority. Could you3693explain to this Committee how cyber threat information sharing3694is absolutely critical for defending telecommunications3695networks, and what more do you think the Trump administration3696should do to help us extend this essential authority? I am3697going to be hoping all my colleagues on this panel will support3698that. Give them reasons why it is important.3699    Mr. Mayer. It is critical. We are not going to be3700successful in addressing the threats that we currently face. It3701has been invaluable in terms of our ability to share3702information without concerns about liability, without concerns3703about punishment, enforcement.3704    We have an excellent relationship with our government3705partners--the intelligence community, CISA, all of these3706organizations. It is grounded on this Act. It is ability for us3707to have conversations about what we are seeing, what they are3708seeing, what we are doing to mitigate the risk. These3709conversations are happening constantly.3710    And I think it speaks to a broad consensus that this Act3711has worked for 10 years. it is lapsing in the end of January if3712we do not deal with it. I would say it is probably the number3713one issue for us in the short term, to in a sense get an3714improved cybersecurity writ large for this Nation.3715    Senator Peters. So as you mentioned, it is riding along the3716CR, which would expire at the end of January. Tell us, riding3717along CRs is not the way to do it. Why do we need that 10-year3718extension?3719    Mr. Mayer. Well, because we do not want to do this every3720few years.3721    Senator Peters. It is every few months right now.3722    Mr. Mayer. Or every few months. Yes, that is not good3723policy.3724    Senator Peters. Right.3725    Mr. Mayer. So this is a cornerstone of our ability to3726collaborate with government.3727    Senator Peters. Great. I am also extremely concerned, and3728we heard from my colleague, Ranking Member Cantwell, about the3729FCC's decision last month to roll back what are basically, I3730think, commonsense cybersecurity rules to safeguard America's3731data. These rules were announced, as you know, in the wake of3732Salt Typhoon, and I will not go into all of the challenges3733there. It has already been brought up before the Committee. But3734I think, without question, the rollback of these rules leaves3735Americans exposed and erodes our ability to prevent future3736attacks.3737    I think this is even more concerning when you look at that3738rollback as part of a broader trend that is being carried out3739by the Trump administration right now, where officials say--3740they talk a good game--they say cybersecurity is a priority.3741But at the same time they are basically gutting all of our3742cybersecurity institutions, from rolling back the FCC rule to3743ignoring their own guidelines regarding the handling of3744America's most sensitive personal information, as well as3745pushing out cybersecurity experts all across government, firing3746the people who know what needs to be done.3747    So my question for you, Mr. Mayer, is the FCC rule to3748require telecommunications providers to have a cybersecurity3749plan, and then stick to it, I think is pretty common sense and3750a step forward to ensuring cybersecurity. So my question is,3751why did USTelecom push the FCC to roll back these efforts in3752this case? And are you confident the vulnerabilities exposed of3753the Salt Typhoon will not occur again in the future? But why3754push to roll those back?3755    Mr. Mayer. Because they were ineffective. They would not3756have produced the results that we are looking for. We are not3757going to regulate our way out of this issue. We are going to3758have to innovate our way. We are going to have to match an3759adversary who is using the most sophisticated techniques3760possible.3761    It was not a checklist or a compliance thing that was3762bypassed. It was advanced defensive capabilities that are being3763deployed by our member companies that were bypassed. Why?3764Because the Chinese are masters at stealth. They use--when you3765talk about here the Salt Typhoon being identified in 2021,37662020--they used Asia's specific region as a testing ground for3767these types of techniques, these stealth techniques, on3768countries and organizations that were less hardened. And then3769they perfected it, they came to the United States, they came3770into our networks, they used stealth technology that is3771actually anti-forensic, in a sense. The breadcrumbs disappear.3772And once they are in the network, I mean, it does not take3773more--in some cases less than a minute to laterally move3774throughout the networks, operating support systems, business3775support systems.3776    So we have a very sophisticated adversary, and the way to3777deal with this is collaboration with government, partnership3778with government, accountability, absolutely. And I am in the3779conversations. I know how much we are talking to these3780different government entities, classified settings,3781unclassified settings, numerous venues. We are making progress,3782and we should not stifle that or kill that with a compliance3783regime where you have 40 to 70 percent of your practitioners3784doing paperwork.3785    We need to focus on the threat. We need to focus on the3786triage when it happens. And we are supportive of things like3787incident reporting that Congress passed in CIRCIA, if it3788implemented correctly.3789    Senator Peters. Great. Thank you. My time has expired. But3790Ms. Jordan, I am going to ask you a question related to this,3791as to why you may think the FCC's actions were appropriate, and3792why it may have been wrong to have those rolled back? But I3793will ask that in writing.3794    Thank you, Madam Chair.3795    Senator Fischer. Thank you, Senator Peters. Senator Young,3796you are recognized.37973798                 STATEMENT OF HON. TODD YOUNG,3799                   U.S. SENATOR FROM INDIANA38003801    Senator Young. Well, thank you, Madam Chair, for your3802interest in this topic, and I want to thank all of our3803panelists here today. Thank you for your thoughtful3804contribution as it relates to policymaking on this host of3805issues.3806    You mentioned in your testimony, Mr. Jaffer, that China is3807increasingly engaged in undersea cable cutting activities. This3808is something that, for a couple of years running, I have had a3809real interest in, and as a member of the Intelligence Committee3810I am trying to find countermeasures that might help us address3811this growing challenge.3812    Subsea cables, we know, serve as the backbone to today's3813world communication system, so we are going to have to come up3814with some checks. And I believe we must adequately address3815these broader challenges in coming months and years.3816    Earlier this year, relatedly, the FCC put forward rules to3817streamline submarine cable application reviews, protect3818submarine cables against national security risks, and3819incentivize cable buildout. In those rules, one requirement was3820for applicants and licensees to create cybersecurity and3821physical security risk management plans.3822    Can you identify maybe other areas that should be a focus3823for strengthening our resiliency of subsea cable3824infrastructure, especially as our adversaries continue to3825advance tactics to do harm?3826    Mr. Jaffer. Well, Senator Young, it is a great and3827important question. I think the most effective way that we can3828prevent our adversaries from cutting cables and the like is to3829create more cables, to have diversity of them, to have them3830owned by American companies, have more ships to be able to fix3831them, and frankly, make clear to our adversaries that if they3832cut our cables, we will treat it as an attack on our critical3833infrastructure, because that is exactly what it is.3834    Today, adversaries largely get away with it because it is3835an accident, it was a mistake, we did not know it was you. But3836we watched the Russians surveil our cables. We watched them3837look at them and consider cutting. We have seen the Chinese3838actually do it in Taiwan and in the Baltics. One might be an3839accident. Certainly three in a row is a pattern.3840    And so when our adversaries realize that we are actually3841watching them and are going to do something about it, that is3842when they will stop doing it, and if we build enough cables and3843enough access that we can rely on our own system. Then there3844are other things you can do. You can do physical security. You3845can put them in more robust casings and the like. You can have3846surveillance measures down on this undersea floor.3847    But at the end of the day, if you are really going to push3848back against a nation state action, it is going to have to be3849nation state response.3850    Senator Young. And we are going to have to come up with3851protocols, it sounds like you are saying, or expectations that3852we will treat this almost in domestic law like a strict3853liability situation, or if not strict liability, the burden of3854proof or production will be on whomever supposedly accidentally3855cut a cable, right?3856    Mr. Jaffer. That is exactly right.3857    Senator Young. OK. Mr. Mayer, same question to you. Are3858there other areas that should be a focus for strengthening our3859resiliency as it relates to subsea cables?3860    Mr. Mayer. Yes, I think so. We have to make sure, and we3861are doing this, we are an important stakeholder in the3862submarine cable. The transmissions are often transmissions that3863we are generating and moving along, both nationally and3864internationally, especially internationally.3865    So we are aware of what the FCC is doing. We have had3866conversations with the FCC National Security Council about3867cybersecurity practices related to protecting, well, all3868practices--it is physical, as well--to how we can support3869enhancing making these systems less vulnerable. But there is an3870inherent risk when there are so many--I think there are almost3871500 to 700 submarine cables. Many of these are in the Indo-3872Pacific region. This is China's area. The ability for them to3873disrupt transoceanic communications at a time when suits their3874needs is real and serious. And to Mr. Jaffer's point, this3875really requires Federal engagement and activities. And we are3876willing and ready to collaborate with any government partner3877and organizations to make sure that these systems are more3878secure.3879    Senator Young. Well, who should bear the cost of, let's3880say, redundancy, right, building out more cables? These are3881expensive capital investments. Would it be rational, from an3882economic standpoint, for us to say, OK, we have an idea who are3883the greatest users of these cables are, because they send data3884across them, across the ocean. Maybe we should put it on the3885companies. What would you say to that line of economic3886argument?3887    Mr. Mayer. Well, I think the economic argument would be you3888cannot impose costs that are going to make the business3889unprofitable and not attract investors. As you point out, you3890need big investment, huge investment to deploy, to maintain, to3891install these. The economic problem with dealing with3892asymmetrical issues like this is serious. And I think that this3893is a question for national policy in terms of what kind of3894assistance can we do to safeguard our infrastructure against3895what we are experiencing today and what we know is possible3896tomorrow.3897    Senator Young. Well, I think coming up with a doctrine of3898deterrence----3899    Mr. Mayer. Absolutely.3900    Senator Young.--just to be candid, will be as a matter of3901politics, internal congressional politics and with a broader3902public of telecom consumers, that will be an easier sell. So3903maybe we should focus, in the near term, on what is achievable,3904and it seems to me a deterrence approach is eminently3905achievable.3906    So thank you all. Chairman.3907    Senator Fischer. Thank you, Senator Young. As I put out a3908last call for any members who are trying to get to this hearing3909to ask questions, Senator Lujan and I are each going to ask a3910final question.3911    Mr. Gizinski, you stated that many of the satellites3912providing coverage to the United States expose network traffic3913outside of our borders. So how do we meaningfully improve3914encryption and security protocols across our satellite3915infrastructure, an inconsistency that you highlighted?3916    Mr. Gizinski. It is an excellent question. I think a few3917key points that are critical, the first is we seek3918consistently, and I think this is a true point across both3919telecom and the satellite industry, most of the operators are3920not vertically integrated, so they are heavily reliant on a3921supply chain to build those subsystems that go in, things that3922enable those encryption capabilities. It is important that we3923extend the threat-sharing information and the opportunity down3924into the supply chain and ensure that we are building the right3925secure-by-design subsystems, with flexible encryption protocols3926and other appropriate security considerations from the ground3927up.3928    We have seen, very publicly, some of the examples where3929that has gone poorly, where foreign-supplied components had3930security vulnerabilities present in them, from the initial3931delivery. Encouraging that same approach throughout the3932satellite industry I think is incredibly important.3933    The second point is recognizing that in most cases folks3934that are designing and building these systems have the best3935view of what the vulnerabilities are and may be. They can be a3936great partner in closing those. We have seen consistently the3937application of well-intended checklists on defense systems3938often are not designed with the end system architecture in3939mind. Having that in-depth, open conversation has been3940incredibly valuable in securing other systems that we have3941built and delivered over the years. I think that is a great3942model to following out into the future.3943    Senator Fischer. Thank you. Mr. Jaffer, how severe do you3944think the threat is to our space systems that we have?3945    Mr. Jaffer. I mean, I think the threat is quite severe. You3946just look at a capability that China has. They have the SJ-213947satellite. This is a repair satellite. It is designed to remove3948debris, the demonstrated ability to grab another satellite and3949move it to a different orbit. Now, you think about what that3950could do if used in an offensive manner. That is obviously a3951huge problem. China has that capability. Other nations have3952that capability.3953    The threat to our infrastructure is huge, and they do not3954even have to take out a satellite directly. They can destroy3955one satellite and the debris itself, the debris field, can3956cause problems for our satellites. It is a huge issue in outer3957space, it is a real challenge, and we have got to make our3958satellites defensible.3959    And part of it is having a diversity of systems. Like we3960talked about the cables. If you can have more satellites going3961up faster, that is essentially going to create a more resilient3962and more capable system. It is also going to make it more3963technologically efficient, because it will get newer3964capabilities into space faster. So the better we can get at3965launch, the better we can get at building smaller and faster3966and more capable satellites, the better off we will be.3967    Senator Fischer. Thank you. Senator Lujan.3968    Senator Lujan. Thank you, Madam Chair. Mr. Mayer, in your3969testimony you said that any cybersecurity framework needs to be3970flexible and adaptive. I agree. Do you agree with me that the3971FCC has a role to play in ensuring that our communication3972networks are protected against cybersecurity threats?3973    Mr. Mayer. Absolutely, yes.3974    Senator Lujan. I appreciate that. Now, recently Senator3975Peters asked a question around USTelecom, their role, their3976advocacy to reverse the FCC's actions in response to Salt3977Typhoon. A few things that the FCC required was changing3978default passwords, requiring minimum password strength,3979adopting multifactor authentication, and patching known3980vulnerabilities, all simple things.3981    Congress is constantly told that we are behind the curve on3982technology, even if we have these basic protections in place.3983Which of these basic protections was too burdensome for your3984member organizations?3985    Mr. Mayer. Senator, I think what you are describing are not3986burdensome.3987    Senator Lujan. I appreciate that. That is an answer. I3988appreciate that. With that being said, do your member companies3989have cybersecurity risk management plans?3990    Mr. Mayer. Absolutely. They have been working on this for3991many, many years. They are evolving their risk management3992plans.3993    Senator Lujan. Are you willing to share those with the3994Committee?3995    Mr. Mayer. The risk management plans?3996    Senator Lujan. Yes.3997    Mr. Mayer. No. We are in a trade association. I cannot say3998what our members are willing to share.3999    Senator Lujan. So you are telling me to trust you.4000    Mr. Mayer. I am telling you that we are doing a lot, and we4001have been doing a lot, and you can ask our government partners4002whether they think we are doing a lot, because I do believe----4003    Senator Lujan. I have a follow up there, as well. But I4004appreciate it. The reason I am asking you these questions, sir,4005is you, of all the panelists today, my constituents depend on4006your members every day, all day, around the clock, all day4007long. As a matter of fact, most of my small businesses right4008now just rely on the services that your member companies4009provide. So I am picking on you, and I apologize for that. But4010it matters to my constituents.4011    Now, earlier there was a question asked by Senator Schmitt4012about requirements for contracts for the Federal Government to4013be wise around taxpayer dollars. And I heard at least two of4014the panelists suggest, well, that might be a good idea to4015require anyone doing work with the Federal Government to meet,4016is it fair to say, a floor of standards, a floor of4017requirements, in order to safeguard taxpayer dollars? Would4018that be fair? Well, that is my assumption. If I am incorrect I4019would invite you to submit into the record where I got that4020wrong.4021    Now, I asked my staff to let me know how much money the4022Federal Government, over the last few Fiscal Years, has spent4023in a very specific area, namely in telecommunication contracts.4024They told me that what GAO says is from 2014 to 2018, the4025government spent $30 billion--$30 billion--for4026telecommunication contracts, $4 billion for call center4027contracts, $6 billion per year that has likely gone up, $14.34028billion for IT services for Fiscal Year 2024 alone, $3.24029billion in IT and telecom products for Fiscal Year 2024.4030    I look forward to working with you all to have4031requirements. I just look forward to working with you all, that4032there is a floor of cyber requirements. That is a lot of money.4033And we talk about national security vulnerabilities and how we4034outsource all of our work to call centers. The smallest of the4035small in the most rural part of America that allows someone in,4036an actor in, infects the whole system.4037    And so I certainly hope that these are some areas that we4038can get together.4039    The last question I have, Madam Chair, is to Mr. Jaffer.4040You served on the Cyber Safety Review Board, CSRB, which was4041under the Department of Homeland Security. My question is a4042simple one. Was it a mistake to disband this Board?4043    Mr. Jaffer. Well, you know, we were asked to look at the4044Salt Typhoon hack, and because of internal government4045bureaucracy decisions we were unable to even get off the4046ground. We were not able to get our clearances in time. We were4047not able to do any questioning of any of the communications4048companies, of any of the government officials involved. So we4049were tasked with the Cyber Safety Review Board review months in4050advance. We took months, we did not get anything done, and then4051the Board was disbanded.4052    Should it have been disbanded? No. Should it be back?4053Absolutely. But even when it was in place, under the 4 or 54054months I served on that Board, we got nothing effectively done4055because it was not allowed to do its work. There were claims4056because there was a law enforcement investigation going on,4057because industry was partnering with the government they could4058not talk to us. We even asked to talk to providers that said4059they were not affected by Salt Typhoon. We were not allowed to4060do that. So the Board was not being used effectively. It should4061not have been disbanded. It would be better if it was back in.4062But if it is going to back in place it needs to be effective.4063    At the end of the day, I think what Congress ought to think4064about doing is empaneling an outside commission to look at what4065happened in Salt Typhoon and Volt Typhoon and make4066recommendations to you, like the 9/11 Commission did, about4067what we should do most effectively to get the Executive Branch4068and legislative branch and industry back together and working4069on this issue.4070    Senator Lujan. I am glad I asked that question. So if, in4071fact, that body is brought back, it needs to be fixed and it4072needs to be effective, and the tools need to be in place to be4073able to discover all the information, to be able to provide4074information to Congress. In addition to that, your4075recommendation is now of an outside commission, as well. I4076appreciate that. Thank you. Thank you, Madam Chair.4077    Senator Fischer. Thank you, Senator Lujan. I would say the4078problem with any commissions is by the time we get the report4079it is like past due. It is past due, and it is really, really4080difficult to be able to get any movement forward from the4081recommendations that are put into place. So I look forward to4082working with you, Senator Lujan, and trying to figure out, as4083anything with the Federal Government, how do we cut through4084things and try and move quicker so that we can have private4085industry be able to work with the Federal Government to get us4086the information we need.4087    Mr. Jaffer. One thought, Madam Chairwoman, you know, the4088other committees, the Senate Intelligence Committee, for4089example, has a technical advisory group that it empanels, that4090brings industry and government together. It is something that4091the Commerce Committee could consider doing, and bring a panel4092together, and then you could do it on your own time schedules.4093You do not need to worry about getting it authorized by law and4094all that sort of stuff, and we could just advise the Committee4095itself.4096    Senator Fischer. And a lot of the issues we have are4097jurisdictional, as well, you know, whether it is with Intel,4098whether it is with Armed Services Committee intersecting with4099Commerce Committee. And the time it takes is very, very4100frustrating.4101    Thank you, Senator Lujan. Good hearing. Thank you to our4102panel today for the good information that you have provided to4103this Committee. With that we are adjourned.4104    [Whereupon, at 11:46 a.m., the hearing was adjourned.]41054106                            A P P E N D I X41074108      Response to Written Questions Submitted by Hon. Ted Cruz to4109                              Robert Mayer4110    Question 1. The Federal Communications Commission (FCC) does not4111run cyber operations, nor does it investigate intrusions. It is a4112communications regulator, without direct insight into national security4113threats. Agencies like the Cybersecurity and Infrastructure Security4114Agency, the National Security Agency, and the Federal Bureau of4115Investigation handle cybersecurity every day. They track nation-state4116activity, run threat hunting teams, and respond to intrusions in real-4117time. Given the clear delineation in authorities and expertise, should4118the FCC be writing cybersecurity rules for the telecom sector when it4119lacks that operational understanding or legal authority to do so?4120    Answer. Federal agencies should closely adhere to the statutory4121boundaries on cybersecurity policymaking established by Congress. The4122FCC is no exception.4123    While the FCC has a role to play in protecting America's networks4124against foreign adversaries by ensuring equipment is properly4125authorized--a role defined by Congress in the Secure Networks Act,4126other Federal agencies in law enforcement, the intelligence community,4127and industry are the primary drivers of cybersecurity, vulnerability4128management, and critical-infrastructure protection. Introducing another4129layer of oversight that Congress never intended is duplicative and4130unhelpful. Fragmented oversight splinters accountability, complicates4131incident response, and forces operators to satisfy divergent mandates4132rather than focusing on effective risk management.41334134    Question 2. Given the scale and the speed of nation-state threats4135to telecommunications networks, how should the Federal government4136engage on carrier cybersecurity in a way that recognizes its importance4137but avoids mandates that are so rigid they hinder the substantial4138security work industry is already doing?4139    Answer. Collaboration and information sharing are key to thwarting4140future attacks. The Office of the National Cyber Director (ONCD) should4141set a tone on Federal cyber policymaking that is supportive of public-4142private collaboration on cybersecurity--as is expected in the upcoming4143National Cybersecurity Strategy It is imperative that Congress pass a4144long-term reauthorization of the Cybersecurity Information Sharing Act4145of 2015 to ensure robust information sharing among public and private4146sector partners.4147    The Federal Government should also recognize that these are nation-4148state attacks, and use its full capacity to impose costs on state-4149sponsored adversaries to deter future cyberattacks. We cannot allow4150these entities to act with impunity.41514152    a. How do you view the shift away from the prior declaratory ruling4153toward a more collaborative, less prescriptive framework?4154    Answer. The shift will allow cybersecurity practitioners to focus4155their attention squarely where it belongs--on cybersecurity innovation4156and partnerships designed to secure our Nation against state-sponsored4157adversaries.4158    Providers have been participating in biweekly briefings with the4159intelligence community, Federal law enforcement agencies, and the4160Department of War for several years. These briefings are designed to4161facilitate timely bidirectional information sharing, coordinate4162defensive measures, assess ongoing threats and align national response4163strategies following major cyber incidents.4164    Leading industry providers have established a formal forum for4165collaboration, bringing together the Chief Information Security4166Officers (CISOs) from the largest carriers in the United States and4167Canada. As a result, engagement and coordination at both the CISO and4168senior staff levels have significantly increased across the sector.4169    Question 3. Could you briefly discuss concerns about products and4170equipment sourced from foreign vendors--particularly those linked to4171the People's Republic of China--containing exploitable weaknesses or4172that could give adversaries opportunities to pre-position access deep4173inside U.S. networks?4174    Answer. Congress should establish a single point of contact within4175government where industry can obtain the latest intelligence about4176suspect suppliers. As we make decisions about suppliers for our4177networks, sharing information about these suppliers will help industry4178better assess potential risks, even for suppliers that may not be4179formally banned but are under investigation by the U.S. government.4180    USTelecom members are fully committed to taking the necessary steps4181to ensure our national security, and to ensure that the United States'4182supply chains are protected against bad actors. We are currently4183engaged with a wide variety of government partners:41844185   The Department of Commerce Bureau of Industry and Security4186        (BIS) can review transactions and uses of services involving4187        ICTS developed and controlled by a foreign adversary as set4188        forth in the Information and Communications Technology and4189        Services Supply Chain Rule pursuant to EO 13873 on Securing the4190        ICTS Supply Chain and the International Emergency Economic4191        Powers Act. BIS has numerous work streams that address ICTS run4192        by the Office of Information and Communications Technology and4193        Services (OICTS).41944195   The FCC has several workstreams that examine foreign4196        adversary participation in regulated activities. One example is4197        the Covered List implementing the Secure Networks Act, while4198        others look at licensed activities and propose more4199        comprehensive regulatory review of FCC-licensed equipment for4200        sale in the United States.42014202   The Federal Acquisition Regulation Council is tasked with4203        developing rules governing Section 889 of the 2019 NDAA, which4204        imposes restrictions on Federal contractors' use of covered4205        telecommunications equipment and services from specified4206        foreign entities.42074208   The Department of War maintains a list of Chinese Military-4209        Civil Fusion contributors operating directly or indirectly in4210        the United States to implement section 1260H of the National4211        Defense Authorization Act for Fiscal Year 2021.42124213   The Committee for the Assessment of Foreign Participation in4214        the United States Telecommunications Services Sector (Team4215        Telecom) assists the FCC in reviewing license applications for4216        national security concerns and may prohibit the use of certain4217        equipment on a case-by-case basis through deal-specific4218        agreements negotiated with executive-branch agencies.42194220    All of this work is in addition, or sometimes responsive to,4221company or product-specific actions by Congress, like the Select4222Committee on the CCP or specific directives in the National Defense4223Authorization Act. Agency work overlaps and in some areas is not4224consistent. Some work by the government is not transparent or results4225in abrupt changes to the legal status or risk related to products and4226services. Security concerns may not be transparently communicated to4227regulated entities. All of this creates an unpredictable environment.4228Congress and the President should promote coordination and4229deconfliction of supply chain related work across the Federal4230government. Again, a single point of contact within the government4231would assist providers as they seek to make informed decisions4232regarding suppliers.42334234    a.  Do you see evidence that adversaries view commercial telecom4235equipment as a strategic foothold that gives them long-term options to4236exploit crises?4237    Answer. State-sponsored adversaries continually probe for4238vulnerabilities across a broad array of industries and government,4239seeking opportunities to gain strategic, economic, or technological4240advantage. This dynamic threat landscape extends to commercial4241telecommunications equipment. For this reason, we remain committed to4242close coordination with our government partners--across all relevant4243agencies and collaborative forums--to ensure that risks are identified4244early, mitigated effectively and addressed through sound policy and4245technical safeguards. By working together, we can strengthen the4246resilience of our communications infrastructure and uphold the security4247and trust that our interconnected nation depends on.4248                                 ______42494250     Response to Written Questions Submitted by Hon. Todd Young to4251                              Robert Mayer4252Artificial Intelligence4253    Mr. Meyer [sic]--In your testimony, you discuss how adversaries are4254using automation, machine learning, and tailored tradecraft to identify4255and exploit vulnerabilities and then are constantly updating or4256modifying their technologies to better advance their tactics.4257Technologies, like AI, have been actively discussed as a tool used by4258bad actors and criminals to not only damage our critical4259infrastructures but also conduct scam and fraud. What is not as often4260discussed is the ``good guys'' application of technologies like AI to4261identify, respond to, or effectuate resilient mechanisms to protect4262against these attacks to our communication networks.42634264    Question 1. Why is that the case? Is technology too nascent to4265combat these criminals' tactics? Are companies not deploying it because4266of regulatory barriers? Or is it happening and it's just being4267overshadowed by the negative use cases of the technology?4268    Answer. While the technology is indeed nascent, we are already4269seeing emerging use cases that empower ``good guys'' to improve4270security.4271    AI can be used to identify vulnerabilities and early indicators of4272cyber threats by assessing network operations, system performance and4273technical signals at machine speed, allowing operators to detect and4274address risks before they disrupt service.4275    These capabilities support a more proactive security posture by4276enabling automated risk assessment, faster identification of abnormal4277conditions, and quicker response to potential attacks. AI can also help4278strengthen defenses by learning from prior incidents and shared threat4279intelligence, improving the ability to anticipate and counter4280increasingly sophisticated threats.4281    Ensuring U.S. leadership in AI is therefore closely tied to4282embracing new technological opportunities to protect critical4283infrastructure. Continued investment in advanced network technologies4284and close collaboration between industry and government will help4285reinforce the security, resilience and reliability of the Nation's4286communications networks.42874288    Question 2. We are all aware of efforts to remove barriers to4289deployment of AI, but what else can we be doing that we haven't thought4290of, or worked on, to advance technologies or the capabilities of4291technologies to protect against attacks to our communications networks?4292    Answer. Among ways Congress can strengthen U.S. leadership in AI is4293by streamlining permitting on Federal lands. Simply put, permitting4294processes for AI-ready connectivity and broadband deployment at all4295levels of government are in desperate need of reform. These processes4296are the single most time-consuming aspect of a high-speed network build4297or upgrade. Streamlining NEPA and historical review approvals,4298including eliminating duplicative reviews on previously analyzed lands,4299would accelerate broadband deployment in rural America and allow4300providers to install the newest and most secure technologies more4301quickly.4302    In addition, the Federal government has a critical role in4303increasing the costs and consequences imposed on malicious cyber4304actors--using diplomatic, economic, law-enforcement and national4305security tools--to ensure that nation-state adversaries are deterred4306from targeting U.S. networks with impunity. Meeting this challenge4307requires a unified front between government and industry to confront4308foreign threats to critical infrastructure.4309                                 ______43104311   Response to Written Questions Submitted by Hon. Maria Cantwell to4312                              Robert Mayer4313Cybersecurity and BEAD Non-Deployment Grants4314    The bipartisan Infrastructure Investment and Jobs Act of 20214315appropriated $42 billion for the BEAD program, $1.2 billion of which4316was allocated to the State of Washington to connect households to4317broadband.4318    What's more, the plan was designed to provide states with4319opportunities for programs beyond connecting unserved and underserved4320households, allowing some of the state's funding to go to non-4321deployment initiatives like adoption and network resiliency.4322    Yet while the Trump Administration has delayed states' access to4323funding and tacked on unrelated policy objectives conditioned on the4324deployment money, they've also been holding up other important non-4325deployment resources. Resources that could be used for improving4326cybersecurity in the communications networks we're investing billions4327in.43284329    Question 1. Should NTIA and the Department of Commerce release the4330non-deployment funding for states to use?4331    Answer. We believe non-deployment funds should be made available to4332states, and they should use these funds for:43334334  (1)  Funding for states to upgrade 911 facilities to fiber and NG91143354336  (2)  Expediting broadband permitting at the federal, state and local4337        levels43384339  (3)  Cybersecurity funding for end-of-life equipment and workforce4340        training43414342    Question 2. How can this funding help to strengthen network4343security?4344    Answer. The BEAD NOFO explicitly lists ``cybersecurity training''4345and ``workforce development'' as eligible non-deployment activities.4346Using non-deployment funds to upskill local provider employees and4347replacing known insecure legacy equipment ensures that the people and4348equipment running the network are as modern as the fiber in the ground.4349                                 ______43504351    Response to Written Question Submitted by Hon. Amy Klobuchar to4352                              Robert Mayer4353Critical Infrastructure and Artificial Intelligence4354    Question 1. Recent cyberattacks, such as Volt Typhoon, have4355revealed the fragility of America's critical infrastructure.4356Adversaries including China and Russia continue to attack our critical4357infrastructure, threatening systems including electrical, industrial4358control, and rail. In your testimony you wrote about the need to ensure4359American leadership in AI to defend our networks. How can we use AI to4360identify vulnerabilities to cyber-attacks and protect our critical4361infrastructure?4362    Answer. AI can be used to identify vulnerabilities and early4363indicators of cyber threats by assessing network operations, system4364performance, and technical signals at machine speed, allowing operators4365to detect and address risks before they disrupt service.4366    These capabilities support a more proactive security posture by4367enabling automated risk assessment, faster identification of abnormal4368conditions and quicker response to potential attacks. AI can also help4369strengthen defenses by learning from prior incidents and shared threat4370intelligence, improving the ability to anticipate and counter4371increasingly sophisticated threats.4372    Ensuring U.S. leadership in AI is therefore closely tied to4373protecting critical infrastructure. Continued close collaboration4374between industry and government will help reinforce the security,4375resilience, and reliability of the Nation's communications networks.4376                                 ______43774378      Response to Written Questions Submitted by Hon. Ted Cruz to4379                            Daniel Gizinski4380    Question 1. Given the scale and the speed of nation-state threats4381to telecommunications networks, how should the Federal government4382engage on carrier cybersecurity in a way that recognizes its importance4383but avoids mandates so rigid they hinder the substantial security work4384industry is already doing?4385    Answer. The pace at which nation-state threats continue to advance4386makes it clear that industry and government must work together in a4387highly coordinated manner. We see a few key steps that can help promote4388an effective, consolidated approach:43894390    1: Establish an appropriate forum for information sharing between4391government and telecommunications operators, inclusive of the supply4392chain, will help ensure that threats are communicated at the pace of4393relevance.43944395    2: Frame an end-to-end view of cybersecurity that presents a4396legally sound and durable compliance framework along with thoughtful4397incentive programs that facilitate/a proactive cyber posture and4398collaborative information sharing.43994400    3: Recognize that the advent of 5G Non-Terrestrial Networks (NTN)4401\1\ blur the lines between satellite cybersecurity and telecom4402cybersecurity, any such compliance framework must consider the need to4403protect data across the various different networks that may be4404transited, including systems that may be served by both terrestrial4405networks and Supplemental Coverage from Space (SCS).\2\4406---------------------------------------------------------------------------4407    \1\ Non-Terrestrial Networks (NTN)4408    \2\ FCC Advances Supplemental Coverage from Space Framework |4409Federal Communications Commission44104411    How do you view the shift away from the prior declaratory ruling4412toward a more collaborative, less prescriptive framework?4413    Answer. U.S. communications security is far too important to4414address with anything other than wholehearted commitment from both4415industry and government--establishing a collaborative framework is a4416key first step. We see tremendous value in establishing and4417incentivizing participation in taking an active defense posture.4418Industry suppliers are well-placed to provide recommendations for4419approaches that are less disruptive to operators but effective against4420various threat actors.4421    Cyber warfare is inherently asymmetric. Our telecom operators must4422close every possible ingress point, while adversaries only need to find4423a single entry point. The more secure our systems are, the more4424difficult--and expensive--it becomes to find these entry points. The4425best opportunity to disrupt this is to move quickly and thoughtfully to4426provide baseline security for these systems in the immediate term and4427over the longer term, operate under a framework that makes clear that4428new vulnerabilities can and will be addressed as they are discovered--4429rather than on a predictable schedule.44304431    Question 2. Could you briefly discuss concerns about products and4432equipment sourced from foreign vendors--particularly those linked to4433the People's Republic of China--containing exploitable weaknesses or4434that could give adversaries opportunities to pre-position access deep4435inside U.S. networks?4436    Answer. Hardware and software should be viewed thoughtfully when4437designing and developing critical infrastructure. Education and4438incentives should be established during the design phase to ensure that4439telecommunication operators are leveraging secure-by-design systems,4440ideally those that are designed and manufactured in the USA. ``Rip and4441Replace'' is a critical step from the position we are in today, but it4442is both more efficient and safer to avoid replicating the situation4443that created this risk in the first place. Encouraging the use of4444secure-by-design components with verifiable supply chain integrity will4445help ensure a strong security foundation.\3\4446---------------------------------------------------------------------------4447    \3\ Comtech-WP-Ground-Station-Cyber-Threats-and-Product-Design-4448Techniques-for-Defense.pdf44494450    a. Do you see evidence that adversaries view commercial telecom4451equipment as a strategic foothold that gives them long-term options to4452exploit crises?4453    Answer. There is strong evidence that companies like Huawei are4454leveraging state support to underbid competitors by significant4455margins--in some cases with 70 percent lower prices than competitors4456and extended financing terms.\4\ This practice appears to be enabled by4457state subsidies and favorable financing from Chinese policy banks. This4458has allowed these companies to crowd out competitors and embed their4459equipment in critical national networks. This entrenchment in critical4460infrastructure is a strategic foothold that could allow for possible4461surveillance, data exfiltration, or even disruption in times of4462crisis.\5\4463---------------------------------------------------------------------------4464    \4\ China's Competitiveness: Huawei4465    \5\ Huawei and Its Siblings, the Chinese Tech Giants: National4466Security and Foreign Policy Implications--United States Department of4467State4468---------------------------------------------------------------------------4469                                 ______44704471      Response to Written Questions Submitted by Hon. Ted Cruz to4472                            Jamil N. Jaffer4473    Question 1. The Federal Communications Commission (FCC) does not4474run cyber operations, nor does it investigate intrusions. It is a4475communications regulator, without direct insight into national security4476threats. Agencies like the Cybersecurity and Infrastructure Security4477Agency, the National Security Agency, and the Federal Bureau of4478Investigation handle cybersecurity every day. They track nation-state4479activity, run threat hunting teams, and respond to intrusions in real-4480time. Given the clear delineation in authorities and expertise, should4481the FCC be writing cybersecurity rules for the telecom sector when it4482lacks that operational understanding and legal authority to do so?4483    Answer. As your question highlights, traditional communications4484regulators like the Federal Communications Commission (FCC) have4485limited expertise and authorities relative to cyber threats,4486particularly on the former front and as compared to certain other4487government agencies and certainly as compared to industry leaders and4488cybersecurity innovators. The limited expertise and carefully bounded4489authority of the FCC certainly make it less effective for the FCC to4490try to be the key player writing the ``cyber rules of the road'' for4491the telecommunications industry in what is a very rapidly cyber4492evolving threat environment.4493    Indeed, as I describe more fully in my response to your second4494question below, I'm also quite skeptical of the ability of the FCC or4495other government departments and agencies to do an effective job of4496imposing detailed, specific regulatory measures in this domain. Rather,4497I support a collaborative approach where the government: (1) provides4498frameworks to industry to outline a broad, effective approach to cyber4499defense; (2) shares detailed, actionable information with industry; and4500(3) takes direct action to impose costs on nation-state adversaries in4501order to deter them from targeting America's critical4502infrastructure.\1\4503---------------------------------------------------------------------------4504    \1\ See, e.g., Jamil N. Jaffer, Statement for the Record, Signal4505Under Siege: Defending America's Communications Networks, Subcommittee4506on Telecommunications & Media, U.S. Senate Committee on Commerce (Dec.45072, 2025), at 19, available online at  (``To4508preserve the value these organizations--and many other private sector4509entities--provide us, the Federal government must partner tightly with4510industry to enable better cyber defense. This means sharing massive4511amounts of data (classified and otherwise), providing incentives to4512obtain and deploy better defensive cyber systems and capabilities, and4513aggressively imposing costs on adversaries, in appropriate4514circumstances, to deter the deployment or use of potentially disruptive4515or destructive capabilities.'')4516---------------------------------------------------------------------------4517    For far too long, nation-states like China, Russia, Iran, and North4518Korea and their private sector proxies have largely gotten off scot-4519free when infiltrating U.S. private sector systems and networks,4520including critical infrastructure systems, to steal data,\2\ put in4521place potentially damaging capabilities,\3\ and take destructive4522actions against certain companies.\4\ The failure of the United States4523to effectively imposes costs on our adversaries, particularly in a4524public manner, creates an inherently unstable situation where our4525adversaries are more likely to get increasingly aggressive, increasing4526the risk of a significantly problematic scenario where the U.S.4527government has no choice to respond.\5\ As such, rather than4528regulating, whether through the FCC or otherwise, the U.S. government4529ought do its part to enable private sector defense and take the fight4530to the enemy in the cyber domain.4531---------------------------------------------------------------------------4532    \2\ See, 3e.g., Keith B. Alexander, Prepared Statement of GEN (Ret)4533Keith B. Alexander, A Borderless Battle: Defending Against Cyber4534Threats, House Committee on Homeland Security (Mar. 22, 2017), at 2,4535available online at  (``[T]he4536ongoing theft of intellectual property from American companies . . .4537continues to represent the greatest transfer of wealth in human4538history.'').4539    \3\ See Office of the Director of National Intelligence, Annual4540Threat Assessment of the U.S. Intelligence Community (Mar. 2025), at 9,4541available online at4542    \4\ See Director of National Intelligence James R. Clapper, Opening4543Statement to Worldwide Threat Assessment Hearing, Senate Armed Services4544Committee (Feb. 26, 2015), at 11, available online at4545(``2014 saw, for the first time, destructive cyberattacks carried out4546on U.S. soil by nation-state entities, marked first by the Iranian4547attack against the Las Vegas Sands Casino Corporation, a year ago this4548month, and the North Korean attack against Sony in November.'')4549    \5\ See, e.g., Jamil N. Jaffer, Statement for the Record,4550Safeguarding the Federal Software Supply Chain, Subcommittee on4551Cybersecurity, Information Technology, and Government Innovation, House4552Committee on Oversight and Accountability (Nov. 29, 2023), at 10,4553available online at  (``[W]hen our adversaries don't4554know how we might react--or worse, based on prior practices assume that4555we won't react all--they are more likely to push the envelope and test4556our boundaries. Not only is this bad for the United States because we4557pay the price for such adversary activity, but such a scenario is4558actually inherently unstable and therefore likely to lead to more4559conflict not less. That's because having been tempted by a lack of4560American response into trying the next more aggressive thing, at some4561point our adversary may--whether intentionally or inadvertently--cross4562a line that neither they nor we understood existed but which, once4563crossed, requires us to respond in a significant way.'').45644565    Question 2. Given the scale and the speed of nation-state threats4566to telecommunications networks, how should the Federal government4567engage on carrier cybersecurity in a way that recognizes its importance4568but avoids mandates so rigid they hinder the substantial security work4569industry is already doing?4570    Answer. As you know, cybersecurity threats morph at a rapid rate,4571particularly in the modern age of AI-enabled attacks. One need only4572look at the recently released report by Anthropic about the use of its4573systems by Chinese nation-state attackers to engage in novel forms of4574automated exploitation to get a sense of how rapidly the threat4575landscape is changing.\6\ Given this context, I am highly skeptical of4576the ability of any regulatory agency--whether the Federal4577Communications Commission, the Cybersecurity Infrastructure & Security4578Agency within the Department of Homeland Security, or any other--to4579effectively be able to keep up with this rapidly changing environment.4580---------------------------------------------------------------------------4581    \6\ See Anthropic, Disrupting the First Reported AI-Orchestrated4582Cyber Espionage Campaign (Nov. 2025), available online at .4583---------------------------------------------------------------------------4584    To the contrary, I actually worry that the promulgation of new4585regulations is likely to actually further solidify an already-4586problematic compliance culture, where regulatory lawyers are called in4587to identify the minimum a company might do to follow a given4588regulation. This problem, of course, is worsened when such regulation4589is rapidly outstripped by innovation, meaning that the very standard4590being complied with outdated even before the ink is try, potentially4591creating more vulnerabilities than less.4592    As such, in my view, the better approach is for the Federal4593government to collaborate tightly with innovators and industry players4594who have a real sense of what the threat landscape looks like and how4595it is changing, and to provide defensive frameworks to help industry4596get better at its own defense, rather than specific, detailed4597regulatory proceedings that can't keep up with adversaries. Moreover,4598rather than reaching first for the regulatory stick, as Federal4599agencies are often wont to do, Congress should encourage--and perhaps4600direct--such agencies to utilize carrots, including tax incentives and4601the benefits of Federal procurement, to align their interests with4602those of companies, their boards, and their investors.\7\ Indeed, if4603the government were to do so, it would likely see a much more4604significant uptake in industry efforts to harden network defenses than4605the traditional regulate-first, get-smart later approach.4606---------------------------------------------------------------------------4607    \7\ See, e.g., Jaffer, Statement for the Record, Signal Under4608Siege, supra n.1 at 21-22.4609---------------------------------------------------------------------------4610    In addition, to the extent that Federal agencies or Congress4611believe that government ought be doing more than just incentivizing4612good behavior, I also agree. But rather than imposing high-cost (and4613likely ineffectual) regulation, the government ought instead seek to4614collect intelligence on the cyber threat actors coming after American4615industry and share that information with the private sector at scale,4616in detailed and actionable form (including in classified form if4617necessary), and assist industry with the right techniques and tools to4618effectively defend themselves against sophisticated nation-state4619actors.4620    The recent Salt Typhoon activity by Chinese actors against American4621telecommunications companies is instructive in this regard. In that4622case, not only did the government fail to provide detailed, actionable4623warnings of the type that could have actually help industry protect4624itself (or protect the government information their systems contained),4625the government also failed to effectively identify information it4626already had in its possession about those same threat actors in Federal4627networks and, as a result, didn't share that information with industry4628either.\8\ Worse still, even after the government realized its own4629failure, rather than taking swift action to ensure that such errors4630don't happen again, the FCC instead sought to impose short-sighted4631regulations on industry without any accounting for the government's own4632failures.\9\4633---------------------------------------------------------------------------4634    \8\ See id. at 18 (``And yet, in perhaps one of the most stunning4635revelations to come out of this incident, even as the FCC and White4636House were calling for significant regulation of American4637telecommunications companies, the outgoing head of the Department of4638Homeland Security's Cybersecurity and Infrastructure Security Agency4639(CISA), published a blog post stating that `CISA threat hunters4640previously detected the same actors in U.S. government networks.' . . .4641[A]ll this may make one recall the findings of the 9/11 Commission4642report, which noted that the U.S. government had both successfully the4643potential of a major terrorist attack and knew of specific terrorists4644with visas to enter the United States, but critically failed to share4645actionable information in a timely fashion with those able to identify4646and stop those individuals[.]''); see also, e.g., Tim Starks, `Whatever4647We Did Was Not Enough': How Salt Typhoon Slipped Through the4648Government's Blind Spots, CyberScoop (May 20, 2025), available online4649at4650    \9\ Id.4651---------------------------------------------------------------------------4652    Finally, in addition to helping industry defend itself more4653effectively, given the stark reality that private sector companies4654operating in a constrained environment cannot possibly be expected to4655defend themselves against nation-state actors with access to virtually4656unlimited resources and manpower, it is critical that the Federal4657government engage in a much more robust set of responsive actions to4658deter nation-state actors.\10\ The current Administration has4659demonstrated a willingness to push back against our adversaries in4660range of contexts over the last year and I am hopeful that the4661President's soon-to-be-released National Cybersecurity Strategy will4662take a forward-leaning approach in the cyber domain as well.\11\4663---------------------------------------------------------------------------4664    \10\ See, e.g., GEN (Ret) Keith B. Alexander & Jamil N. Jaffer,4665Iranian Cyberattacks Are Coming, Security Experts Warn, Barron's (Jan.466610, 2020) (``Expecting individual companies to defend themselves4667against a nation state with virtually unlimited financial resources and4668human capital does not make sense. Yet today that is our national4669policy in cyberspace. This is so even though, in every other context,4670defense against nation-state attacks is the province of the government.4671We don't expect Target or Walmart to have surface-to-air missiles to4672defend against Russian Bear bombers. Yet when it comes to cyberspace,4673we expect exactly that of every American company, large or small.'');4674see also, e.g., Jaffer, Statement for the Record, Signal Under Siege,4675supra n.1 at 19 (``[W]e must remember that private sector companies,4676including those in the [] telecommunications and infrastructure4677sectors, are not primarily in the business of defending themselves4678against cyberattacks; rather, they operate in order to provide products4679and services to customers and to generate economic returns from such4680business.'').4681    \11\ See Tim Starks, Five-Page Draft Trump Administration Cyber4682Strategy Targeted for January Release, CyberScoop (Dec. 4, 2025),4683available online at  (``National Cyber Director Sean4684Cairncross recently offered a preview of some of those themes and4685plans. `As a top line matter, it's going to be focused on shaping4686adversary behavior, introducing costs and consequences into this mix,'4687Cairncross said last month at the 2025 Aspen Cyber Summit.'').46884689    a. How do you view the shift away from the prior declaratory ruling4690toward a more collaborative, less prescriptive framework?4691    Answer. I am strongly supportive of the government, including the4692Federal Communications Commission, shifting away from aggressive4693declaratory rulings that seek to blame and penalize the victims of4694nation-state architected cyber operations and instead moving towards a4695more collaborative, less-prescriptive framework that enables and4696supports the efforts of private sector actors to defend themselves.46974698    Question 3. As adversaries adopt AI to scale cyber operations,4699industry is also leveraging AI-driven defenses to identify threats4700earlier and respond more effectively. Our adversaries are wasting no4701time leveraging AI to enhance their attack operations, but carriers are4702also using AI to strengthen defenses. From your perspective, what role4703do emerging AI tools play in helping telecom providers secure their4704networks?4705    Answer. In my view, the advent of AI-enabled capabilities is likely4706to effectively enable both offensive and defensive actors in the cyber4707domain. As such, I think that there are significant benefits to our4708telecommunications industry working with innovative technology4709companies, from venture-backed startups to large companies building4710scaled capabilities, to obtain, deploy, and utilize AI-enabled4711defensive capabilities.4712    While there are many who fear that the widespread deployment of AI4713capabilities will benefit attackers more than defenders, my view is4714that the outcome is likely to be significantly more nuanced. While it4715is true that in the cyber domain--as in the physical world--the offense4716often has a slight edge, in part because of its first-mover advantage,4717and that AI-enabled capabilities may very well enhance that edge, it is4718also the case that AI-enabled cyber defenses will allow rapid and4719evolving responses to cyber threats and will help defenders not only4720keep up, but on occasion, even get ahead of potential threats.\12\ As4721such, while I am not blind to the very real challenges that AI will4722bring to the cyber defense domain, I also believe there are terrific4723opportunities for innovation and advantage here and that the American4724systems of capital allocation and innovation is best positioned to take4725advantage of these opportunities.4726---------------------------------------------------------------------------4727    \12\ See House Committee on Energy & Commerce, Subcommittee on4728Communications & Technology, Global Networks at Risk: Securing the4729Future of Communications Infrastructure (Apr. 30, 2025), Serial No.4730119-17, Government Printing Office, at 73, available online at4731(``[T]here is a big debate about will AI improve the attacker more or4732improve the defender more, and I actually [think] it is a mixed bag [].4733In some ways, it will definitely, as Ms. Galante pointed out, enable4734attackers who don't have capabilities today to have more capabilities.4735At the same time, the defender will have an edge as well because they4736will be able to get ahead of the threats, identify vulnerabilities, cut4737them off at the pass and go after the attackers. So[,] while the4738offense, like in football, always has a little bit of an edge, [] and4739AI will enhance that, AI is going to enhance defenders as well.'')47404741    a. What role should the Federal government play in this space?4742    Answer. Helping enable the creation and development of AI-enabled4743cyber defenses not only for industry but for government is an area4744where Congress can play a major role by providing incentives to4745industry players to create, obtain, and deploy such capabilities.4746Specifically, Congress might consider the development of tax incentives4747to encourage investors and innovators--particularly those who agree to4748not provide capabilities to American adversaries, not take adversary4749capital, nor invest alongside adversaries--to build such capabilities.4750Likewise, Congress might provide similar incentives to industry,4751particularly American critical infrastructure organizations, to acquire4752and deploy such capabilities across their networks, including4753telecommunications systems and backbone networks.4754    Moreover, Congress might helpfully to encourage Federal agencies to4755avoid imposing unhelpful regulations that encourage the adoption of4756legacy capabilities or the creation of new defenses against legacy4757threats.4758    Finally, Congress can also help in a major way by taking action to4759``occupy the field'' with pro-innovation policies--like those that you4760have championed\13\--to stave off unhelpful state-based and Federal4761regulation that would actually limit the ability of forward-leaning,4762innovative AI companies to develop the very advanced capabilities that4763can help the government and industry better protect ourselves from4764America's adversaries.4765---------------------------------------------------------------------------4766    \13\ See, e.g., Senator Ted Cruz, Sen. Cruz: Adopting Europe's4767Approach on Regulation Will Cause China to Win the AI Race (May 8.47682025), available online at  (``[Senator] Cruz announced he4769will soon release a new bill that creates a regulatory sandbox for AI--4770modeled on the approach taken by Congress and President Clinton with4771respect to the internet--to remove barriers to AI adoption, and prevent4772needless state over-regulation.''); see also, e.g., Senator Ted Cruz,4773Sen. Cruz Unveils AI Policy Framework to Strengthen American AI4774Leadership (Sept. 10, 2025) available online at  (``Today, U.S. Senate Commerce4775Committee Chairman Ted Cruz (R-Texas) released a legislative framework4776designed to promote American leadership in artificial intelligence. . .4777. The bill creates a regulatory `sandbox,' a policy endorsed by4778President Trump's AI Action Plan, that gives AI developers space to4779test and launch new AI technologies without being held back by outdated4780or inflexible Federal rules.'').4781---------------------------------------------------------------------------4782                                 ______47834784   Response to Written Questions Submitted by Hon. Amy Klobuchar to4785                              Debra Jordan4786Next Generation 911:4787    Question 1. As co-chair of the Next Generation 911 caucus with4788Senator Budd, I was pleased to see your recommendation to fully fund4789Next Generation 911 as one of your recommendations to secure our4790networks. I also lead the Enhancing First Response Act with Senator4791Blackburn, which would reclassify 911 operators as emergency4792responders. Can you speak to the importance of this reclassification?4793    Answer. Reclassification of 911 operators is a long overdue action4794that would recognize these critical first responders. They are the4795first person in the 911 emergency process, the voice of calm4796reassurance to individuals in a crisis--whether a mass casualty event,4797domestic violence, or any other emergency. Continuing to classify them4798as administrative personnel simply ratifies the injustice. Their duties4799typically involve triaging of emergency calls, providing emergency4800medical assistance and dispatch, and handling other life-or death4801situations until field units arrive.4802    In my career as Chief and Deputy Chief of the Public Safety and4803Homeland Security Bureau at the Federal Communications Commission, I4804was privileged to visit many Public Safety Answering Points. There I4805spoke with 911 operators and witnessed them in the midst of their work.4806These visits solidified for me that they are indeed first responders4807and not administrative personnel. Whether talking a caller through an4808active labor/delivery situation, domestic violence, or a child through4809an unresponsive parent situation, these 911 operators handled the4810situation with the professionalism of their field counterparts.4811    Reclassification as first responders would recognize their critical4812role as first point of contact and grant them much needed access to4813benefits such as mental health support, training, and the appropriate4814recognition. It would likely also improve recruitment to this career4815field that is too often understaffed. It is simply the right thing to4816do.4817Public Safety:4818    Question 2. Recently the Federal Communications Commission rolled4819back a ruling that affirmatively requires telecommunications carriers4820to secure their networks from unlawful access or interception of4821communications, despite, according to one report, more than 60 percent4822of telecommunications operators experiencing a cyber-attack in the last4823year. How does this action threaten the work of emergency responders4824relying on telecommunications networks to reach people who need their4825help?4826    Answer. Our digital society is highly dependent on4827telecommunications networks in nearly every aspect of our lives from4828finance to education to healthcare and more. Emergency responders4829specifically, must be able to assume that critical communications4830services will be consistently and securely available at all times. This4831includes citizens' ability to dial 911 and reach first responder4832services, for 911 Operators to be able to dispatch field agents, and4833for the wide range of public safety personnel to communicate and4834collaborate. They must be able to rely on their communications being4835reliable and secure from compromise. If a law enforcement agency serves4836legal process for a wiretap, they must have the legally required4837assurance that those requests will be confidential and secure from4838adversaries' access. Emergency alerting systems that support4839presidential and every day alerts must be confident that when an alert4840is issued to the public, that it is done so by authorized alert4841originators. These are just a few examples of how emergency responders4842must be able to rely on the confidentiality, integrity, and4843availability of telecommunications networks.4844    The declaratory ruling and notice of proposed rule making that the4845FCC recently overturned would have made clear to telecommunications4846providers that they are responsibility for the security of their4847networks. The declaratory ruling specifically clarified that Section4848105 of the Communications Assistance for Law Enforcement Act (CALEA)4849requires only lawful intercepts of telecom networks. And the Notice of4850Proposed Rulemaking would have leveraged basic cyber risk management4851requirements across all of our Nation's telecom providers. Those common4852sense requirements basically required providers to develop, update, and4853implement cyber risk management plans, leveraging the Cyber Security4854Framework developed by the National Institute of Standards and4855Technology through extensive public and private sector collaboration.4856The Commission already has similar rules in place for a small subset of4857telecom providers, and in fact in August 2025, proposed similar4858requirements for undersea cable licensees.4859    Instead, the FCC Chairman says the Commission is talking with4860providers about securing their networks. As we all know, there are4861thousands of telecom providers, large and small. They should all have4862clear common sense guidelines to assess risk and implement at least4863basic hygiene to reduce and manage cyber risk. The ongoing public-4864private dialog between government regulators, intel agencies, and4865telecom providers would then provide an excellent addition to adapt to4866emerging threats.48674868                                  [all]