Search

Search bills, members, committees and pages...

“Fully Operational: Stuxnet 15 Years Later and the Evolution of Cyber Threats to Critical Infrastructure.”

HearingHomeland Security Subcommittee on Cybersecurity and Infrastructure ProtectionJul 22, 2025 · 10:00 AM

Summary

Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection held a hearing on Jul 22, 2025 at 10:00 AM in Cannon House Office Building, Room 310. 4 witnesses appeared.


Record

The meeting has its video, its transcript, witnesses and documents on the record.

Video

The proceedings, as the committee streamed them.

Transcript

The transcript runs to 4,721 lines and 284,030 characters, as the Government Publishing Office printed it.

house-hearing-62627.txt
1[House Hearing, 119 Congress]2[From the U.S. Government Publishing Office]34               FULLY OPERATIONAL: STUXNET 15 YEARS LATER5                 AND THE EVOLUTION OF CYBER THREATS TO6                 CRITICAL INFRASTRUCTURE7=======================================================================89                                HEARING1011                               BEFORE THE1213                            SUBCOMMITTEE ON14                    CYBERSECURITY AND INFRASTRUCTURE15                               PROTECTION1617                                 OF THE1819                     COMMITTEE ON HOMELAND SECURITY20                        HOUSE OF REPRESENTATIVES2122                    ONE HUNDRED NINETEENTH CONGRESS2324                             FIRST SESSION2526                               __________2728                             JULY 22, 20252930                               __________3132                           Serial No. 119-243334                               __________3536       Printed for the use of the Committee on Homeland Security3738[GRAPHIC NOT AVAILABLE IN TIFF FORMAT]3940        Available via the World Wide Web: http://www.govinfo.gov4142                               __________4344                    U.S. GOVERNMENT PUBLISHING OFFICE4562-627 PDF                  WASHINGTON : 20264647--------------------------------------------------------------------------------------4849                     COMMITTEE ON HOMELAND SECURITY5051                Andrew R. Garbarino, New York, Chairman52Michael T. McCaul, Texas, Vice       Bennie G. Thompson, Mississippi,53    Chair                                Ranking Member54Clay Higgins, Louisiana              Eric Swalwell, California55Michael Guest, Mississippi           J. Luis Correa, California56Carlos A. Gimenez, Florida           Shri Thanedar, Michigan57August Pfluger, Texas                Seth Magaziner, Rhode Island58Marjorie Taylor Greene, Georgia      Daniel S. Goldman, New York59Tony Gonzales, Texas                 Delia C. Ramirez, Illinois60Morgan Luttrell, Texas               Timothy M. Kennedy, New York61Dale W. Strong, Alabama              LaMonica McIver, New Jersey62Josh Brecheen, Oklahoma              Julie Johnson, Texas, Vice Ranking63Elijah Crane, Arizona                    Member64Andrew Ogles, Tennessee              Pablo Jose Hernandez, Puerto Rico65Sheri Biggs, South Carolina          Nellie Pou, New Jersey66Gabe Evans, Colorado                 Troy A. Carter, Louisiana67Ryan Mackenzie, Pennsylvania         Al Green, Texas68Brad Knott, North Carolina           Vacant69Vacant70                    Eric Heighberger, Staff Director71                  Hope Goins, Minority Staff Director72                       Sean Corcoran, Chief Clerk73                                 ------7475      SUBCOMMITTEE ON CYBERSECURITY AND INFRASTRUCTURE PROTECTION7677                            Vacant, Chairman78Clay Higgins, Louisiana              Eric Swalwell, California, Ranking79Carlos A. Gimenez, Florida               Member80Morgan Luttrell, Texas               Seth Magaziner, Rhode Island81Andrew Ogles, Tennessee              LaMonica McIver, New Jersey82Andrew R. Garbarino, New York (ex    Vacant83    officio)                         Bennie G. Thompson, Mississippi84                                         (ex officio)85             Alexandra Seymour, Subcommittee Staff Director86           Moira Bergin, Minority Subcommittee Staff Director87                            C O N T E N T S8889                              ----------90                                                                   Page9192                               Statements9394The Honorable Andrew R. Garbarino, a Representative in Congress95  From the State of New York, Ex Officio, Subcommittee on96  Cybersecurity and Infrastructure Protection, and Chairman,97  Committee on Homeland Security:98  Oral Statement.................................................     199  Prepared Statement.............................................     2100The Honorable Eric Swalwell, a Representative in Congress From101  the State of California, and Ranking Member, Subcommittee on102  Cybersecurity and Infrastructure Protection....................     3103The Honorable Bennie G. Thompson, a Representative in Congress104  From the State of Mississippi, and Ranking Member, Committee on105  Homeland Security:106  Prepared Statement.............................................     5107108                               Witnesses109110Ms. Kim Zetter, Author and Journalist, ``Countdown to Zero Day:111  Stuxnet and The Launch of the World's First Digital Weapon'':112  Oral Statement.................................................     6113  Prepared Statement.............................................     8114Mr. Robert M. Lee, Chief Executive Officer and Co-Founder, Dragos115  Inc.:116  Oral Statement.................................................    15117  Prepared Statement.............................................    17118Ms. Tatyana Bolton, Executive Director, The Operational119  Technology Cyber Coalition:120  Oral Statement.................................................    21121  Prepared Statement.............................................    23122Mr. Nathaniel Gleason, Ph.D., Program Leader, Lawrence Livermore123  National Laboratory:124  Oral Statement.................................................    28125  Prepared Statement.............................................    29126127                               Appendix I128129The Honorable Andrew R. Garbarino, a Representative in Congress130  From the State of New York, Ex Officio, Subcommittee on131  Cybersecurity and Infrastructure Protection, and Chairman,132  Committee on Homeland Security:133  Statement of Ian Jefferies, President and Chief Executive134    Officer, Association of American Railroads...................    53135136                              Appendix II137138Questions From Chairman Andrew R. Garbarino for Kim Zetter.......    57139Questions From Chairman Andrew R. Garbarino for Robert M. Lee....    60140Questions From Chairman Andrew R. Garbarino for Tatyana Bolton...    61141Questions From Chairman Andrew R. Garbarino for Nate Gleason.....    66142143 FULLY OPERATIONAL: STUXNET 15 YEARS LATER AND THE EVOLUTION OF CYBER144                   THREATS TO CRITICAL INFRASTRUCTURE145146                              ----------147148                         Tuesday, July 22, 2025149150             U.S. House of Representatives,151                    Committee on Homeland Security,152                         Subcommittee on Cybersecurity and153                                 Infrastructure Protection,154                                                    Washington, DC.155    The subcommittee met, pursuant to notice, at 10:12 a.m., at156Room 310, Cannon House Office Building, Hon. Andrew R.157Garbarino [Chairman of the committee] presiding.158    Present: Representatives Garbarino, Gimenez, Luttrell,159Ogles, Swalwell, and McIver.160    Mr. Garbarino. The Committee on Homeland Security,161Subcommittee on Cybersecurity Infrastructure Protection will162come to order. Without objection, the Chair may declare the163committee in recess at any point.164    The purpose of this hearing is to examine the evolution of165cybersecurity threats to U.S. critical infrastructure following166discovery of the Stuxnet malware 15 years ago. We will167highlight the importance of securing operational technology, or168OT, to bolster critical infrastructure resilience.169    I now recognize myself for an opening statement.170    Fifteen years ago, the world learned of Stuxnet, a computer171worm that forever altered the cyber threat landscape. Regarded172as the world's first digital weapon, it was designed to target173industrial control systems. It was used against Iran's nuclear174program, reportedly destroying a thousand centrifuges at the175Natanz enrichment plant. Malware or malicious software has176existed since at least 1970's. However, Stuxnet was different177from its predecessor. The discovery of it demonstrated both the178physical impact of malware and raised important questions about179cybersecurity defense and offense. These are issues we continue180to face today.181    It revealed the significant impact that offensive cyber182tools can have on critical infrastructure. It also demonstrated183the importance of securing operational technology. By184exploiting key vulnerabilities in industrial control systems,185it proved that that cybersecurity is not only an IT issue.186Cybersecurity threats can affect critical infrastructure we187depend on daily, from water treatment to energy facilities. The188cybersecurity threat landscape continues to expand and we need189to make sure our cyber professionals are prepared to defend190both IT and OT. Doing so will strengthen the public and private191sector's ability to rapidly respond to threats.192    Since discovering Stuxnet 15 years ago, cybersecurity193threats to critical infrastructure have drastically evolved and194spread beyond just malware. We now see various cyber195capabilities being used to hack critical infrastructure,196including phishing, social engineering, denial-of-service197attacks, and more.198    While cyber attack vectors have grown and matured, malware199is still of great concern. Malware comes in many forms, such as200keyloggers, spyware, viruses, and ransomware, with ransomware201comprising one-third of all cyber attacks in 2024. The202interconnected nature of our networks, devices, and203infrastructure means that critical infrastructure owners and204operators now experience far more attacks than when Stuxnet was205unleashed. Zero-day vulnerabilities are far from being206eliminated.207    Strengthening domestic cybersecurity resilience remains a208key priority for this committee. Considering the sophisticated209cybersecurity threats we now face, we are once again reminded210of the importance of reauthorizing two key authorities ahead of211their expiration this year: the Cybersecurity Information212Sharing Act and the State and Local Cybersecurity Grant213Program.214    Reauthorizing CISA 2015 will ensure we keep encouraging215rapid and trusted information sharing among public and private-216sector entities and extending the State and Local Cybersecurity217Grant Program will make sure that States and localities have218reliable funding to strengthen their cybersecurity posture.219    It is also worth examining the state of the Iranian cyber220threat and potential impact Stuxnet had on Iran's cybersecurity221posture. According to Nozomi Networks Labs, cyber attacks from222Iranian threat actors surged by 133 percent in May and June2232025. An active Department of Homeland Security National224Terrorism Advisory System notice also emphasizes the need to225remain on high alert to Iranian cybersecurity threats to U.S.226critical infrastructure.227    Iran has embraced the targeting of critical infrastructure.228The Islamic Revolutionary Guards Corps' affiliated actors have229recently targeted OT such as U.S. industrial control systems in230key sectors such as water and health care.231    I look forward to examining the current threats facing U.S.232critical infrastructure and enduring significance of Stuxnet233with our panel of expert witnesses today. Today's witnesses234represent a range of perspectives and I thank you all for235contributing to our discussion about this pivotal moment in the236history of cybersecurity. I am confident that your testimony237will help us form a better understanding of today's digital238weapons and the state of U.S. critical infrastructure239resilience.240    [The statement of Chairman Garbarino follows:]241                 Statement of Chairman Andrew Garbarino242                             July 22, 2025243    Fifteen years ago, the world learned of Stuxnet--a computer worm244that forever altered the cyber threat landscape. Regarded as ``the245world's first digital weapon,'' Stuxnet was designed to target246industrial control systems. It was used against Iran's nuclear program,247reportedly destroying 1,000 centrifuges at the Natanz enrichment plant.248    Malware, or malicious software, has existed since at least the2491970's. However, Stuxnet was different from its predecessors. The250discovery of Stuxnet demonstrated both the physical impact of malware251and raised important questions about cybersecurity defense and offense.252These are issues we continue to face today.253    Stuxnet revealed the significant impact that offensive cyber tools254can have on critical infrastructure. Stuxnet also demonstrated the255importance of securing operational technology (OT). By exploiting key256vulnerabilities in industrial control systems, Stuxnet proved that257cybersecurity is not only an IT issue. Cybersecurity threats can affect258critical infrastructure we depend on daily, from water treatment to259energy facilities. The cybersecurity threat landscape continues to260expand, and we need to make sure our cyber professionals are prepared261to defend both IT and OT. Doing so will strengthen the public and262private sectors' ability to rapidly respond to threats.263    Since discovering Stuxnet 15 years ago, cybersecurity threats to264critical infrastructure have drastically evolved and spread beyond just265malware. We now see various cyber capabilities being used to hack266critical infrastructure, including phishing, social engineering,267denial-of-service attacks, and more. While cyber attack vectors have268grown and matured, malware is still of great concern. Malware comes in269many forms, such as keyloggers, spyware, viruses, and ransomware, with270ransomware comprising one-third of all cyber attacks in 2024.271    The interconnected nature of our networks, devices, and272infrastructure means that critical infrastructure owners and operators273now experience far more attacks than when Stuxnet was unleashed. And274zero-day vulnerabilities are far from being eliminated.275    Strengthening domestic cybersecurity resilience remains a key276priority for this committee. Considering the sophisticated277cybersecurity threats we now face, we are once again reminded of the278importance of reauthorizing two key authorities ahead of their279expiration this year: the Cybersecurity Information Sharing Act (CISA2802015) and the State and Local Cybersecurity Grant Program.281    Reauthorizing CISA 2015 will ensure we keep encouraging rapid and282trusted information sharing among public and private-sector entities;283and Extending the State and Local Cybersecurity Grant Program will make284sure that States and localities have reliable funding to strengthen285their cybersecurity posture.286    It is also worth examining the state of the Iranian cyber threat287and the potential impact Stuxnet had on Iran's cybersecurity posture.288According to Nozomi Networks Labs, cyber attacks from Iranian threat289actors surged by 133 percent in May and June 2025. An active Department290of Homeland Security National Terrorism Advisory System notice also291emphasizes the need to remain on high alert to Iranian cybersecurity292threats to U.S. critical infrastructure.293    Iran has embraced the targeting of critical infrastructure. Islamic294Revolutionary Guard Corps-affiliated actors have recently targeted OT,295such as U.S. industrial control systems, in key sectors such as water296and health care.297    I look forward to examining the current threats facing U.S.298critical infrastructure and the enduring significance of Stuxnet with299our panel of expert witnesses. Today's witnesses represent a range of300perspectives, and I thank you all for contributing to our discussion301about this pivotal moment in the history of cybersecurity. I am302confident that your testimony will help us form a better understanding303of today's ``digital weapons'' and the state of U.S. critical304infrastructure resilience.305306    Mr. Garbarino. I now recognize the Ranking Member, the307gentleman from California, Mr. Swalwell, for his opening308statement.309    Mr. Swalwell. Thank you, Chairman.310    Chairman, that was an elegant, impactful, artful statement,311but you buried the lede. Our Chairman of the subcommittee has312been selected by his colleagues to be the Chairman of the full313committee with the resignation of Chairman Green effective314earlier this week. So congratulations. I am excited for what315that means for the full committee. You and I have worked quite316well over the last 3 years on this committee, especially to317take on our cyber challenges. To have somebody at the full318committee with your cyber knowledge and expertise as our cyber319threats are only escalating and AI has made that even more320challenging and the threat of quantum computing and what that321means for cryptology, you are the right person to help lead the322committee to do that. So looking forward to working with you323and I think I speak on behalf of my colleagues that we324congratulate you on that win.325    Earlier this summer, Chairman Mark Green and I went out to326my Congressional district and visited Lawrence Livermore327National Laboratory and committee staff from both sides were328there as well. As you know, Lawrence Livermore National Lab is329the Nation's premier research and development facility. It330attracts the best and brightest minds from around the world and331helps keep the United States on the cutting edge of innovation,332particularly related to national security technologies.333Lawrence Livermore and our national labs are indispensable334partners in our national effort to defend cyber space, keeping335their finger on the pulse of our adversaries' tactics and336motivations while helping to develop novel technologies to337detect and disrupt malicious cyber campaigns. We saw Lawrence338Livermore works first-hand and it is critical to national339efforts to secure critical infrastructure our constituents rely340on every day and the operational technology that underpins it.341    The Lab's work is paying off dividends, especially related342to the Chinese threat actors like Volt Typhoon, and I am343pleased that the Lab today, through Dr. Gleason's testimony,344will talk about its important work. Notably, the Lab is a key345partner in CISA's CyberSentry program, which places sensors on346private-sector networks on a voluntary basis to monitor for and347detect cyber threats. The Lab contextualizes data from the348CyberSentry program with other intelligence feeds, generates349unique insights into malicious cyber activity, and provides350network defenders the know-how to kick out the adversaries. The351knowledge derived through the Lab's work benefits programs and352activities across CISA. I am eager to learn how Lawrence353Livermore and the national lab community can continue to354support Federal efforts to better secure operational355technology.356    Additionally, I am interested to learn how other programs357at sector risk management agencies and CISA, like the Joint358Cyber Defense Collaborative, JCDC, support efforts to mature359our collective approach to security. It is incumbent on the360Federal Government to collaborate with its private-sector361partners to bring security resources to bear to these under362resourced sectors.363    Also at this point I want to just remind the committee and364the public that CISA can only function when it is fully365staffed. It should not be free from reforms, but currently it366has lost approximately 1,000 employees since the DOGE cuts367began to take place. That affects its ability to work with the368private sector and be responsive. Fewer brains and reduced369funding means less capability, less capacity, and less370collaboration, which is detrimental to on-going efforts to371mature operational technology security programs.372    Also I would like to reiterate my strong support for the373reauthorization of the other CISA, CISA 2015. Stakeholders have374referred to CISA 2015 as the most successful cyber law ever375passed and I was a part of writing it and passing it in 2015 as376a Member of both this committee and the House Intelligence377Committee. We cannot allow this critical authority to lapse.378    Toward that end, I was pleased to see a clean 10-year379extension included in the Senate Intelligence Authorization Act380for Fiscal Year 2026. It sends a clear message to our partners381and our adversaries that cybersecurity continues to be a382bipartisan priority in Congress. I look forward to working with383my House colleagues to provide non-Federal stakeholders the384certainty they need to continue their strategic collaboration385with the Government by passing a clean authorization before it386lapses later this fall.387    With that, I yield back.388    Mr. Garbarino. The gentleman yields back.389    Other Members of the committee are reminded that opening390statements may be submitted for the record.391    [The statement of Ranking Member Thompson follows:]392             Statement of Ranking Member Bennie G. Thompson393                             July 22, 2025394    The threat landscape facing our Nation is clear--critical395infrastructure operational technology is a target for our adversaries,396and our cyber defenses are not sufficient for current threats. Under397the Biden administration, Congress and the Executive branch took398important steps to strengthen OT security.399    We invested $1 billion in State and local cybersecurity, and we400have seen States use that money to better defend vulnerable water401utilities and other high-risk sectors. We enacted the Cyber Incident402Reporting for Critical Infrastructure Act so that the Federal403Government would have better visibility into the threats facing our404Nation.405    CISA established the Joint Cyber Defense Collaborative, including a406focus on industrial control system security, and improved its407partnerships with sector-risk management agencies, hiring sector-408specific experts to coordinate with their partner agencies. CISA409further developed cyber performance goals to help critical410infrastructure better understand how to improve their security. And the411Biden administration initiated a series of sprints to strengthen the412security of specific, under-resourced sectors.413    Unfortunately, under the Trump administration, we have seen the414Executive branch step back from prioritizing cybersecurity. Secretary415Noem has overseen the loss of hundreds of cybersecurity experts from416CISA, devastating the agency's capacity for responding to cyber417threats. The President's budget request included a proposed 25 percent418cut to CISA's programs, including eliminating its efforts to train the419OT workforce. Secretary Noem eliminated the Critical Infrastructure420Partnership Advisory Council, devastating the private sector's ability421to collaborate on cybersecurity threats. And CISA has stalled efforts422to carry out its statutorily-mandated obligations under CIRCIA.423    With a Department of Homeland Security focused exclusively on mass424deportations, our Nation is more at risk to cyber attacks from China,425Russia, Iran, and other adversaries. Unfortunately, Republican426leadership in Congress has not been much better. Former Chairman Green427failed to move forward legislation to reauthorize the Cybersecurity428Information Sharing Act of 2015, leaving us just 17 legislative days429away from this vital authority expiring. And House Republicans are430proposing to cut CISA's budget by $135 million.431    I know this subcommittee recognizes the serious cyber threats432facing our Nation, and I hope that this hearing will build greater433awareness in Congress of the threats facing operational technology and434the need for sustained investment in improved security.435436    Mr. Garbarino. I am pleased to have a distinguished panel437of witnesses before us today. I ask that our witnesses please438rise and raise their right hand.439    [Witnesses sworn.]440    Mr. Garbarino. Let the record reflect that the witnesses441have answered in the affirmative. Thank you and please be442seated.443    I would now like to formally introduce our witnesses.444    Ms. Kim Zetter is the author of ``Countdown to Zero Day:445Stuxnet and the Launch of the World's First Digital Weapon,''446and an adjunct professor at Georgetown University. She is also447an award-winning investigative journalist who has written on448cybersecurity and national security for more than 20 years. Ms.449Zetter began her career covering security and privacy issues450for Wired, where she wrote for 13 years.451    Mr. Robert Lee is the chief executive officer and co-452founder of Dragos, a global technology leader in cybersecurity453for OT and ICS environments. Mr. Lee also serves as a454lieutenant colonel in the Army National Guard, where he designs455and leads OT cybersecurity response efforts. He is a member of456the World Economics Forum Subcommittees for the oil, gas, and457electricity communities, and he serves on the advisory boards458of the International Society of Automation and National459Cryptologic Foundation.460    Tatyana Bolton currently serves as executive director of461the Operational Technology Cybersecurity Coalition, where she462advocates for effective OT cybersecurity and critical463infrastructure resilience. Prior to her current role, Ms.464Bolten served as a senior security policy manager at Google's465Security Center of Excellence. Before joining Google, Ms.466Bolton directed the Cybersecurity Emerging Threats Program at467the R Street Institute and served as policy director of the468Cyberspace Solarium Commission.469    Dr. Nate Gleason is the program leader for cybersecurity470infrastructure resilience within the Energy and Homeland471Security Program at Lawrence Livermore National Laboratory.472Prior to joining Lawrence Livermore, Dr. Gleason spent 12 years473at Sandia National Laboratories in a variety of technical and474management positions, including deputy to the vice president475for the California Laboratory and deputy program director for476Sandia's Homeland Security Program.477    I thank the witnesses for being here today.478    I now recognize Ms. Zetter for 5 minutes to summarize your479opening statement.480481STATEMENT OF KIM ZETTER, AUTHOR AND JOURNALIST, ``COUNTDOWN TO482 ZERO DAY: STUXNET AND THE LAUNCH OF THE WORLD'S FIRST DIGITAL483                            WEAPON''484485    Ms. Zetter. Thank you. Chairman Garbarino, Ranking Member486Swalwell, and Members of the subcommittee, thank you for this487opportunity to testify about Stuxnet and threats to critical488infrastructure. My name is Kim Zetter, and I'm a cybersecurity489national security journalist, as well as an adjunct professor490at Georgetown University and the author of the book on Stuxnet,491``Countdown to Zero Day.''492    It was 15 years ago that Stuxnet was discovered on systems493in Iran, but despite the passage of time, its impact is still494felt today. Stuxnet was a digital weapon designed to sabotage495Iran's nuclear program by targeting industrial control systems496at its uranium enrichment plant at Natanz. But these are the497same kinds of systems used in U.S. critical infrastructure.498I've been asked to describe how Stuxnet operated and the499implications for U.S. critical infrastructure and whether these500systems are any more secure today than when Stuxnet was501discovered.502    Stuxnet was a first-of-its-kind attack, the first known503case of malicious code designed to leap from the digital world504to the physical realm to cause disruption and destruction not505of the computers it infected, but of equipment and processes506these computers controlled, in this case the centrifuges at507Natanz. The same techniques Stuxnet use can be used against508critical infrastructure in the United States to disrupt509services the public, Government, and military rely on, or to510damage equipment that can also cause death, either directly by511causing passenger trains to collide or indirectly by preventing512patients from being treated at hospitals because the513electricity is out. I provided in my written testimony details514about how Stuxnet operated, so I won't go into them here, but I515want to point out two things that are relevant.516    First, Stuxnet spread to millions of computers, but it only517unleashed its destructive payload on the specific systems its518creators were targeting. It didn't sabotage other systems519because Stuxnet was a highly sophisticated, carefully crafted520and tested, precision weapon designed to avoid collateral521damage. Other attacks, however, don't need to be precise or522sophisticated to cause disruption or damage. This is worth523noting given the recent warnings about the potential for Iran524to launch cyber attacks against the United States. Iranian525hackers don't have the skills to pull off a Stuxnet-like526attack, but they don't need them to disrupt or damage systems.527    Second, when Stuxnet was first discovered, researchers528believed it was an espionage tool. This is because every time529it infected a new system, it searched for the presence of530Siemens' industrial control system software. Siemens software531is used to control manufacturing assembly lines and other532industrial processes, so researchers believed whoever was533behind the malware was trying to steal blueprints or designs to534for industrial plants. After reverse engineering the code,535however, they realized it was designed for sabotage.536    This is significant because disruptive or damaging attacks537can be indistinguishable from espionage in the initial stages538of infection. Both can use the same tools and techniques to539gain access and move within networks to find data or the540systems they want to disrupt. What's more, intrusions done541initially for intelligence purposes can morph into disruptive542or destructive operations.543    I say this because a lot has been written recently about544the SALT and Volt Typhoon intrusions of telecoms and critical545infrastructure that are attributed to China. These compromises546don't appear now to be aimed at disruption or damage, but could547morph into such operations in the future.548    One of the most significant impacts of Stuxnet was--Stuxnet549had was to raise awareness about vulnerabilities in critical550infrastructure. Prior to Stuxnet, the security community was551focused on IT networks, the business networks that you use to552send email. But Stuxnet put OT networks in the spotlight, and553once researchers began to examine them, they discovered serious554software flaws as well as architectural problems that couldn't555be fixed with a software patch. They also found many systems556connected to the internet.557    The following is a small sample of processes that558industrial control systems control: opening and closing cell559doors at high security prisons, operating traffic lights and560HVAC systems, routing computers--routing commuter and freight561trains to prevent collisions, controlling temperature at which562food is pasteurized and steel is forged, operating chemical and563pharmaceutical plants, and control of the flow of electricity.564    A lot has been done since Stuxnet to secure critical565infrastructure in the United States, but many issues persist.566I'll just give one example before I close. In 2009, in567Washington, DC, a Metro train plowed into the back of another568train stopped at a station during the afternoon commute.569Sensors on the track should have indicated to the incoming570train that a train was stopped ahead of it, but the sensors571failed and the collision killed 9 people and injured 80 others.572This wasn't caused by a cyber attack, but this month CISA573issued a security alert about a decade-old flaw in train574braking systems that hackers could exploit to cause a collision575like the one in 2009. That flaw exists in the protocol that576devices located in the front and back of trains use to577communicate with each other to engage the brakes. The protocol578uses weak authentication, which means an attacker can579impersonate one of these devices to cause a train to suddenly580halt or the brakes to fail. The flaw can't be exploited over581the internet. An attacker needs proximity to send a command.582But this doesn't make it any less dangerous.583    The researcher who discovered the flaw discovered it in5842012 and reported it to the Association of American Railroads.585But the AAR reportedly dismissed it, believing no one could586exploit it. It was only this year, after the research in CISA587threatened to go public, that the AAR announced it would588replace the protocol. A new protocol won't be ready until 2027589at the earliest.590    Thank you.591    [The prepared statement of Ms. Zetter follows:]592                    Prepared Statement of Kim Zetter593                              22 July 2025594    Chairman Garbarino, Ranking Member Swalwell, and distinguished595Members of the subcommittee, thank you for giving me an opportunity to596testify before you today on the subject of Stuxnet and threats to597critical infrastructure. My name is Kim Zetter, and I'm a journalist,598author, and adjunct professor at Georgetown University. I've been599writing about cybersecurity and national security for two decades as a600staff writer for Wired magazine and as a freelancer for the New York601Times, Politico, the Washington Post, and others. I wrote what is602considered to be the seminal work on Stuxnet--Countdown to Zero Day:603Stuxnet and the Launch of the World's First Digital Weapon. Recently, I604have also begun to teach graduate students about nation-state cyber605operations--the threat actors behind them, the technical capabilities606they use to pull off these often very sophisticated operations, and the607vulnerabilities in critical infrastructure and other systems that make608the operations possible. Many of my students currently hold positions609in the Federal Government or military, and others plan to work in610Government when they complete their degrees. My goal is to provide them611with a solid foundation of knowledge--both technical and contextual--612that will serve them in the policy and decisionmaking positions they613currently hold or may hold one day.614    Today, I've been asked to talk about the digital weapon known as615Stuxnet, which was designed to sabotage Iran's nuclear program and was616discovered in 2010, 3 years after it was unleashed. I've been asked617specifically to describe how Stuxnet conducted its sabotage, the impact618it had on Iran's nuclear systems, the implications for other critical619infrastructure here in the United States and whether these systems are620any more secure against similar attacks today than they were at the621time Stuxnet was unleashed.622    Fifteen years ago this month, Stuxnet was discovered on systems in623Iran but its impact has not diminished and is still felt in the624security community today.625    Stuxnet was discovered after it spread out of control and far626beyond the facility at which it was aimed. Although Stuxnet spread to627millions of machines--the exact number is unknown--it only unleashed628its destructive payload on the specific systems it was designed to629target: systems at Iran's underground uranium enrichment plant at630Natanz. It didn't sabotage other systems because Stuxnet was a highly631sophisticated, carefully crafted, precision weapon that was designed to632avoid collateral damage. Attacks against critical infrastructure,633however, don't need to be precision-targeted or sophisticated to cause634disruption or damage. They just need systems that are vulnerable. This635is worth noting given the recent warnings from Government about the636potential for Iran to launch retaliatory cyber attacks against U.S.637critical infrastructure, following the recent U.S. bombing of Iranian638targets, including the Natanz facility that Stuxnet hit more than a639decade ago. Iran doesn't have the skills to pull off a Stuxnet-like640attack, but it doesn't need them to cause disruption and damage to U.S.641critical infrastructure.642    Although a lot has been done since the discovery of Stuxnet to try643to secure critical infrastructure in the United States, many of the644issues that made these systems vulnerable to attack in 2010 make them645still vulnerable today.646    In 2009 here in Washington DC, a metro train plowed into the back647of another metro train that was stopped at a station during the648afternoon rush hour. Sensors on the track should have indicated to any649incoming train that another train was stopped at the station. Sensors650on the front of the incoming train should also have detected the651presence of the train at the station and alerted the driver or652automatically slowed the incoming train. But the sensors failed to work653and the driver noticed the stopped train too late and had trouble654stopping the train manually. The collision killed 9 people and injured65580 others. This incident, as far as anyone knows, wasn't the result of656a cyber attack.657    But this month CISA issued a critical security alert about a658decade-old high-severity flaw in the braking system used by trains that659hackers could exploit to cause a train to abruptly stop or derail. An660attack like this could potentially result in the kind of outcome that661occurred in 2009 or worse. The flaw exists in the protocol that devices662located in the head and end of trains use to communicate with each663other over radio to, among other things, engage the brakes and stop the664train. The protocol employs a weak authentication, however, which means665an attacker can also communicate with one of these devices as if they666were a legitimate train device. They could send brake commands directly667to a device, causing a train to halt or the brakes to fail.668    The Association of American Railroads said it's developing more669secure protocols and systems to replace the current devices and670communication protocols. But the flaw was discovered by researcher Neil671Smith back in 2012 and the AAR has ignored it since then, saying it was672theoretical and without a real-world example to prove the flaw could be673exploited in this way, it left the flawed system in place. Neil674notified ICS-CERT years ago about the problem and together they tried675unsuccessfully to convince the AAR to address it. But it was only after676Smith and CISA recently threatened to go public with information about677the flaw that the AAR announced it would be replacing the bad protocol.678This won't happen, however, before 2027 at the earliest. The flaw can't679be exploited over the internet--an attacker would need proximity to a680train to communicate with it over radio frequency. But here's how Smith681recently described it: ``You could remotely take control over a train's682brake controller from a very long distance away, using hardware that683costs sub-$500. You could induce brake failure leading to derailments684or you could shut down the entire national railway system.''685    In my testimony today I'll focus first on explaining how Stuxnet686operated so you can understand the level of expertise and687sophistication that went into its unique design. Then I'll talk about688the implications--how some of the tactics Stuxnet employed have been689used by other threat actors since 2010, but also how the full690capabilities demonstrated and hinted at by Stuxnet have not been691realized yet in subsequent attacks. What I mean is that Stuxnet opened692the door to a vast array of possibilities when it comes to attacking693critical infrastructure, but threat actors have so far refrained from694deploying the most impactful and dangerous of these, though they no695doubt possess the capability to use them.696                    the world's first digital weapon697    Stuxnet was a first-of-its-kind attack in that it was the first698known example of malicious code designed to leap from the digital realm699to the physical realm to cause physical impact not on the computers it700infected, but on the equipment and processes controlled by those701computers. Unlike other malicious programs in the past that undermined702the computer systems they infected, Stuxnet was targeting the703industrial equipment those computers controlled--centrifuges--in order704to have a kinetic impact on them and sabotage the enrichment of Iran's705uranium. The same tactic and techniques can be used in other critical706infrastructure environments to temporarily disrupt services that the707public, Government, and military rely on daily; to permanently damage708equipment; and, in some cases, to even cause loss of life--either709directly by creating conditions that, for example, cause trains to710collide, or indirectly by preventing patients from being treated at a711hospital that doesn't have electricity.712    Stuxnet was discovered the same year Operation Aurora was713uncovered. Aurora was an espionage campaign, attributed to China,714conducted against Google and dozens of other targets for intelligence-715gathering purposes. Until Stuxnet was discovered, the only attacks we'd716seen in the wild were either cases of cyber crime or espionage. When717Stuxnet was first discovered, researchers believed it, too, was an718espionage operation. This is because embedded in Stuxnet's code were719instructions for it to search for the presence of Siemens Step 7720control software any time it infected a new system. The Siemens721software is used to control and monitor all kinds of manufacturing and722industrial processes, so researchers believed the attack was likely723coming from China and was aimed at stealing the blueprints or724configuration data for industrial plants so that China could emulate725their designs. After reverse-engineering the code, however, researchers726discovered that it was actually designed for sabotage.727    This is significant, because attacks against critical728infrastructure can be almost indistinguishable from espionage729operations in their initial stages of infection. Both kinds of730operations can use the same types of tools, or even identical tools, to731gain initial access to a system, conduct reconnaissance to study the732system or network, and move laterally within the network to find the733systems that contain the data an attacker seeks or that control the734processes they want to affect. What's more, intrusions done initially735for intelligence-collection purposes can morph into a disruptive or736destructive operation simply by introducing malicious code or commands737aimed at that purpose--meaning that an attacker may initially intend738only to steal data from a system but then change course to damage or739disrupt it as well, or to hand off access to the system to another740actor who has the intention to disrupt or destroy. It can be difficult741to discern the end goal of an intrusion until it's too late to stop it.742I say this because a lot has been written recently about the Salt743Typhoon and Volt Typhoon on-going breaches of telecoms and critical744infrastructure and attributed to China. These compromises don't appear745now to be aimed at disruption or damage but could morph into such746operations if China were to decide to use their presence in these747systems for that purpose.748    Returning now to Stuxnet and the Siemens software it sought, if749Stuxnet found the presence of the Siemens Step 7 software on a system750it infected, as well as evidence that the system was connected to a751Siemens programmable logic controller--PLCs are essentially stand-alone752computing devices that are used to control and monitor industrial753equipment and processes--Stuxnet would then deposit its destructive754payload on the PLC. But it did this only if it found a specific model755and number of Siemens PLCs connected to the infected system as well as756a specific model and number of other equipment Stuxnet was targeting.757This was the precision part of Stuxnet that was aimed at ensuring that758Stuxnet would not unleash its payload on any system except the intended759target.760                              the payload761    Two known versions of Stuxnet were unleashed at separate times. The762payloads in both of them operated similarly, though they impacted763different parts of the centrifuges at Natanz. The first version of764Stuxnet targeted the valves on the centrifuges, and the second version765targeted the speed at which the centrifuges would spin.766    With the first version of Stuxnet, once its payload was deposited767on a Siemens PLC, Stuxnet would first sit on the device silently for 30768days and record the normal operation of the centrifuges as the PLC769collected that data and sent it to engineers at monitoring stations.770The PLCs collected data about the temperature of the centrifuges the771speed at which they were spinning; the pressure inside the centrifuges;772and the state of the valves that managed the flow of gas into and out773of the centrifuges, noting if they were open or closed.774    At the end of the 30 days, the sabotage began. Stuxnet began to775close the exit valves on some of the centrifuges to prevent gas from776exiting the devices. Gas would continue to pour into the centrifuges,777but could not get out. In some cases the valves it closed had already778been chosen by the attackers and were hardcoded into Stuxnet. But779Stuxnet also randomly chose some valves on the fly to avoid780consistency. Natanz engineers might notice some of the valves781malfunctioning and closing, but not be able to isolate the cause or see782a pattern.783    Stuxnet would close the valves for a period of 2 hours or until the784pressure inside the affected centrifuges rose 5 times what was normal.785During this time the valves were closed, Stuxnet took the data that it786had recorded during the first 30 days, and fed it to monitoring787stations so that engineers would not see what was occurring. To the788engineers, the valves would have appeared to be open, and the pressure789inside the centrifuges would have appeared to be normal. During this790time, Stuxnet also disabled the safety system on the cascade--a cascade791is a configuration of multiple centrifuges connected by a series of792pipes. Safety systems on industrial control systems are designed to793detect when a system or process is entering into an unsafe or abnormal794condition. When the safety system senses this is occurring, it795initiates an automatic shutdown of the affected components to alert796operators and control the problem. Because Stuxnet disabled this system797during its sabotage, however, the affected centrifuges did not shut798down. At the end of the 2-hour sabotage period, the centrifuges799returned to their normal operation for another 30 days, when the same800sabotage sequence would occur again.801    There are two potential impacts from closing exit valves. By802increasing the pressure of the gas inside the spinning centrifuges, the803uranium gas would have begun to solidify and either slow down the804spinning rotors or cause them to malfunction, potentially damaging the805centrifuges and spoiling the gas.806    The second version of Stuxnet operated in a similar manner. But807this version was designed to alter the speed at which the centrifuges808were spinning. When this version infected a PLC, it would sit on the809device for 26 days recording the normal operation of the centrifuges810and store that information. Then when the sabotage began, Stuxnet would811increase the frequency controlling the centrifuges from 1,064 Hz to8121,400 Hz for 15 minutes, then restore the centrifuges to the normal813frequency. Stuxnet would then wait 13 days and cause the centrifuges to814slow to 2 Hz for 50 minutes then restore the original frequency. During815the sabotage, Stuxnet fed the recorded data to the monitoring stations816so engineers would not see the change in frequency.817    By increasing the frequency to 1,400 Hz, the attackers were pushing818the centrifuges to the highest frequency they could withstand. The819centrifuges Iran used were first-generation devices that had material820defects, and the increased frequency would have caused them to821deteriorate over time or spin out of control. By also slowing down the822centrifuges to 2 Hz for 50 minutes, the attackers would have undermined823the enrichment process itself. For enrichment, centrifuges have to spin824at a high and uniform speed for uninterrupted lengths of time to825separate the isotopes needed for nuclear fission from the rest of the826material in the gas. By slowing down the centrifuges, any separated827isotopes would have come back together with other particles in the gas,828effectively undoing the enrichment. At the end of each enrichment829cycle, Iran would have had less enriched gas than it expected to830produce, and that gas would have been enriched to a lower level than831Iran expected.832    The engineers understood they were having problems with the833centrifuges, but couldn't determine the cause. This is because Stuxnet834thwarted attempts to investigate. If the engineers tried to examine the835code blocks on the PLCs to see if they had been corrupted in some way,836Stuxnet intercepted the code blocks before they were displayed on the837engineering station and scrubbed any malicious code from them so the838engineers would see no change to them. If the engineers decided to wipe839the existing code blocks from the PLC and load new ones, Stuxnet840intercepted the fresh code blocks and injected its malicious code into841them as well. In this way, Stuxnet remained undetected for 3 years.842    The cyclical pattern to the sabotage, and the fact that only some843centrifuges were impacted during each round of sabotage, tells us that844the attackers were not looking to cause one-time catastrophic damage to845the centrifuges and the enrichment process--this would clearly have846been suspicious--but instead intended to cause only incremental impact847over time that could not be easily detected. The aim was to slow the848enrichment process in order to buy time for diplomacy to work and get849Iran to the negotiating table over its nuclear program.850    Stuxnet is believed to have first infected systems at Natanz in851late 2007, and it remained undetected until 2010 when the attackers got852reckless and added too many spreading capabilities to the second853version of Stuxnet. These caused it to proliferate wildly out of854control--which led to its discovery. But, again, because Stuxnet was a855precision weapon, it didn't cause damage to other systems it infected.856    I've provided all of these details about Stuxnet to demonstrate the857high level of sophistication and expertise that went into this858operation. Stuxnet required the attackers to have knowledge not only of859the Siemens software and computer systems controlling the centrifuges,860but also knowledge about the material and parts that formed the861centrifuges and about the uranium gas and enrichment process in order862to understand how their manipulation of the centrifuges would impact863both. The attackers used model centrifuges and cascades made from the864same material and design as the centrifuges in Iran, and built a865makeshift cascade to test the impact the Stuxnet attack would have on866the centrifuges and the enrichment process.867    But as previously noted, other attacks on critical infrastructure868would not need to have the same level of sophistication to cause869considerable disruption or damage. The systems at Natanz were also air-870gapped from the internet--meaning they were not directly connected to871the internet. This made it difficult for the attackers to reach them.872They needed an insider to physically and surreptitiously deliver the873code for them. But many critical infrastructure systems are directly874connected to the internet and have insufficient protections to prevent875attackers from accessing them remotely.876    In 2013 I wrote about a researcher who used an automated scanner to877find systems connected to the internet that were using port 5900 (the878port on a computer that is used for VNC and TeamViewer remote-879management software). He found 30,000 connected systems that required880no authentication to access them. This included two hydroelectric881plants in New York, a generator at a Los Angeles foundry, a system for882monitoring and controlling ventilation for underground miners in883Romania, and the refrigeration system for a food service company in884Pennsylvania that provided lunches to schools and other facilities.885That was 2013. Surely, you'd think, this wouldn't still be the case886years later. But in 2021, a water treatment facility in Oldsmar,887Florida was hacked through its TeamViewer remote-management software888over the internet. All of the computers at Oldsmar were connected to889the internet without a firewall to protect them and limit who could890access them, and all of them apparently shared the same password for891the remote-management software.892                        implications and impact893    One of the most significant impacts of Stuxnet was the awareness it894brought to vulnerabilities in critical infrastructure that few had895noticed before. The security community, largely focused before Stuxnet896on IT networks--the systems used to run the business side of a company897or industrial operation--had its eyes opened to a vast sector it had898previously ignored: industrial control systems and the OT (operational899technology) networks where they are deployed. Control systems consist900not only of programmable logic controllers, but also SCADA systems and901remote terminal units--devices that often sit in the field to operate902and monitor equipment and processes that are distributed across large903geographical distances, like electric substations. Stuxnet provided904stark evidence that physical destruction of critical infrastructure--905using nothing other than code--was not only possible but also likely.906And once security researchers turned their sights on these systems,907they found not only software security holes but also whole architecture908problems that couldn't be fixed with a patch. With so many of the909systems directly connected to the internet, cybersecurity suddenly910became inextricably linked to national security.911    The following is a small sample of the kinds of systems that PLCs912and other industrial control systems operate. They control the opening913and closing of cell doors and gates at high-security prisons; they914manage the timing and sequencing of traffic lights; they are used to915manage HVAC systems in schools, hospitals, and office buildings; they916raise and lower bridges on waterways; they help route commuter and917freight trains and prevent crashes; they control the temperature of918food pasteurization processes to make food safe; they are used to919control the temperature of furnaces in the manufacturing of steel and920fiberglass; they control the flow and distribution of gas through921pipelines; they control the operation of dams and water and sewage922treatment plants; they operate and monitor the processes in chemical923and pharmaceutical plants; and they help manage and control the924distribution of electricity across the Nation's grids--the critical925infrastructure that undergirds all other critical infrastructure.926    Years ago, industrial control systems were manually operated and927were not connected to the internet, keeping them safe from remote928attacks. But for efficiency purposes, these systems were digitalized.929And then for varying reasons, ranging from regulatory requirements to930ease-of-use, many of them were connected to the internet--without931proper attention to securing them. Additionally, systems that once were932highly complex and used proprietary software and protocols that were933hard for attackers to access and study, have been simplified and934standardized, making it easier for hackers to design attacks that can935have wide-spread impact at scale. This is not news.936    In 1997, after Timothy McVeigh blew up a Federal building in937Oklahoma, the Marsh Commission launched an investigation into the938vulnerability of critical infrastructure to both physical and digital939attacks. In their report, the commissioners warned against connecting940critical systems for oil, gas, and electricity to the internet. ``The941capability to do harm . . . is growing at an alarming rate; and we have942little defense against it,'' they wrote. Commands sent to the control943computer at a power plant ``could be just as devastating as a backpack944full of explosives,'' they wrote at the time. ``We should attend to our945critical foundations before we are confronted with a crisis, not after.946Waiting for disaster would prove as expensive as it would be947irresponsible.''948    A second report also released in 1997 by the White House National949Security Telecommunications Advisory Committee warned that the Nation's950power grid and utilities were vulnerable to digital attack. ``An951electronic intruder . . . could dial into an unprotected port and reset952the breaker to a higher level of tolerance than the device being953protected by the breaker can withstand,'' investigators wrote. ``By954doing this, it would be possible to physically destroy a given piece of955equipment within a substation.''956    But instead of heeding the warnings, critical infrastructure became957more connected and more insecure.958    After Stuxnet was discovered, experts expected to see a lot of959copycat attacks against critical infrastructure. This surprisingly960didn't occur. It wasn't until 2015 and 2016 that we saw the first961Stuxnet-level attacks against critical infrastructure. These targeted962Ukraine's electric grid to cause blackouts for a few hours at the963height of winter. The attackers were able to take 60 substations off-964line in 2015, leaving about a quarter of a million customers without965electricity. The attack was limited in scope--presumably it was simply966done to send a message to Ukraine about who was in control of its grid967not cause permanent disruption--but could have been much broader if the968attackers had intended this. The subsequent attack next year showed the969potential for this. The malware used in that attack, known as970Industroyer and Crash Override, caused only a brief outage in parts of971Kyiv. But the code was more advanced than the code used in 2015 because972it had the potential to be automated so that once on a system, it could973execute commands on its own such as opening circuit breakers,974overwriting software, or adapting to whatever environment it found975itself on, without the need for direct control by the attackers.976Whereas the 2015 outage required the attackers to be at the keyboards977issuing a series of commands in real-time, the 2016 version could have978unfolded automatically once the attackers unleashed the code.979    Then in 2017, we saw an attack that went beyond disruption and980destruction to target the safety system on critical infrastructure, as981Stuxnet had done at Natanz. The so-called Triton attack was designed to982disable the safety system at a petrochemical plant in Saudi Arabia.983Presumably, the attackers intended to use it in conjunction with an984attack that would have caused a chemical spill or some other dangerous985condition at the plant and they wanted to prevent the equipment from986automatically shutting down to contain the danger. But fortunately987there was no accompanying attack in this case, and the code targeting988the safety system contained a flaw that caused the safety system to989trigger automatic shutdowns of the plant, alerting engineers to its990presence. It's an attack that could have had a potentially deadly991impact if the attackers had intended this and if they had not made a992mistake.993    Triton wasn't a fully developed and tested attack tool yet. But the994expansive Pipedream attack platform discovered in 2022 was. Researchers995at the security firm Dragos say it had the potential to cause996disruption or destruction and appeared to be focused on electric and997oil and gas facilities--liquified natural gas systems in particular. It998could be modified, however, for use against any industrial environment999and had the ability to disable or brick control systems or undermine1000safety systems in ways that could potentially endanger lives if an1001attacker can cause chemicals to spill or cause equipment to catch fire1002or explode. This impact can be multiplied if disabled safety systems1003prevent engineers from being alerted to a dangerous condition when it1004first starts to unfold or prevent the systems from going into automatic1005shutdown to contain the damage and impact.1006    Since 2017, hackers have increasingly been targeting critical1007infrastructure and industrial control systems--whether cyber criminals1008infecting them with ransomware to extort the infected organizations,1009nation-state actors targeting them to cause disruption or hacktivists1010impacting them to send a message. In 2022, the state-owned Khuzestan1011Steel Company in Iran had to halt operations after being hit with a1012cyber attack. The company claimed it thwarted the attack and no damage1013or disruption occurred. But a hacktivist group believed to be tied to1014Israel claimed credit for the attack and published CCTV footage as1015proof that it did have an impact. The video, purportedly taken from1016inside the plant, showed a fire breaking out from malfunctioning1017equipment that spilled molten steel, evidently a result of the cyber1018attack. Regardless of whether the hacktivist claim is true, it is1019possible that such an attack could result in spillage and a fire.1020    Small critical infrastructure organizations are more vulnerable to1021attack due to the fact that they tend to have insufficient funding to1022hire security staff and replace outdated insecure systems. By contrast,1023large well-resourced facilities tend to have redundant systems that1024make them more resilient to attack so they can prevent disruption and1025downtime or limit their impact. But this is not always the case. The1026ransomware attack against Colonial Pipeline in 2021 revealed that this1027company did not have a CISO in place at the time of the attack, had1028seemingly failed to properly segment its IT and OT networks (requiring1029the company to shut down the pipeline to prevent the malicious code1030from spreading to its OT systems) and prior to the attack ignored1031warnings about lax security as well as Government alerts about1032attackers targeting pipelines.1033    The ransomware struck around 5am on May 7, and by 6am the company1034had shut down its 5,500-mile pipeline. By late afternoon CEO Joseph1035Blount had decided to pay the ransom, which was sent to the hackers the1036next day. He later said they shut down the pipeline out of fear that1037the ransomware might spread from the IT to the OT network, taking1038control of the pipeline out of their hands. The pipeline was down for1039nearly a week and resulted in a cascade of effects the company had no1040direct control over--panic buys and hoarding triggered by consumer1041reaction to the outage. The hack didn't inflate prices and create a1042fuel shortage, but consumers responding to it did.1043    When Colonial Pipeline was hit, many were surprised at how quickly1044the company paid the $4.4 million ransom. Surely a business as big and1045critical to the U.S. economy--Colonial Pipeline supplies 45 percent of1046fuel to the East Coast, which amounts to about 2.5 million barrels1047daily--had sufficient back-ups and a response plan in place to recover1048from the attack without needing to pay the ransom. The company did have1049an emergency-response plan, the CEO told lawmakers on Capitol Hill1050after the attack, but it didn't include a game plan for ransomware--1051even though ransomware actors had been targeting critical1052infrastructure since 2015.1053    Colonial Pipeline was caught off-guard. But the warnings were there1054if the company had been paying attention.1055    There had been some 400 ransomware attacks against critical1056infrastructure the previous year; and between November 2013 and June10572022, there were nearly 1,300. These included attacks on oil and gas1058facilities. The ransomware operators weren't just targeting IT systems1059in critical infrastructure--they were going after OT systems to disrupt1060critical processes.1061    In 2020, the year before Colonial Pipeline was hit, the security1062firm Mandiant reported that 7 different ransomware families had struck1063industrial organizations since 2017, resulting in significant1064disruptions and delays in production as well as the delivery of goods1065and services. Ransomware actors were also becoming increasingly1066sophisticated, Mandiant reported, conducting internal reconnaissance of1067their victims to determine which systems were the most vital to1068production, in order to increase the odds that a victim would pay. The1069ransomware operators actually put together a ``kill list'' of more than10701,000 processes that ransomware operators could choose to halt to1071increase the odds of being paid.1072    If this wasn't enough warning, that same year, DHS's Cybersecurity1073Infrastructure and Security Agency published an alert warning1074specifically about ransomware attacks targeting pipelines. It described1075an attack against a natural-gas compression facility that began with a1076phishing campaign that infected the IT network, then spread to the1077facility's improperly segmented OT network, preventing staff from1078obtaining real-time data from control and communication systems and1079forcing the company to shut down operations for 2 days. The plant1080didn't have a response-plan for cyber attacks in place, and in its1081alert, CISA advised pipeline and other critical infrastructure owners1082to create a response plan, conduct red team exercises to simulate1083attacks and test internal responses, put back-ups off-line or on fully1084segregated networks to keep them from being encrypted along with the1085rest of their systems, and build redundant workflows to maintain1086critical operations in the event of an attack. A year later, ransomware1087struck Colonial Pipeline.1088    The attackers got in through an employee password for the company1089VPN that the employee had apparently re-used for other systems.1090Mandiant later discovered it in a batch of passwords leaked on-line1091from a different data breach, though it's not clear if the Colonial1092Pipeline hackers obtained it this way. The VPN account was a legacy1093system the company no longer used but had failed to disable. And1094because Colonial Pipeline didn't have multi-factor authentication1095enabled on the account, the attackers were able to get in using just1096the employee's username and password.1097    The company told the Associated Press that its IT and OT networks1098were segmented, but if Blount made the decision to shut down the1099pipeline because the company was afraid the ransomware would spread to1100the OT network, this suggests the company wasn't as confident in the1101segmentation as he indicated. He also said his company had the ability1102to operate the pipeline manually, but only, unfortunately, on a small1103scale if a portion of the pipeline went down--not in a scenario in1104which the entire 5,500 miles of pipeline were shut off.1105    In 2018, 3 years before the ransomware attack, an audit of Colonial1106Pipeline systems found that it was deficient in security best1107practices. Robert Smallwood, whose consulting company conducted the1108audit, called Colonial Pipeline's information management practices1109``atrocious'' and said the company had a patchwork of poorly connected1110and secured systems and lacked security awareness.1111    In 2022, CISA released a lengthy list of basic security guidelines1112for pipelines: use strong perimeter controls to isolate ICS/SCADA1113systems and networks from corporate networks and the internet; limit1114communication leaving/entering these perimeters; use multi-factor1115authentication; have a cyber incident response plan in place; and1116maintain good off-line backups.1117    When these came out, many wondered why CISA would distribute a list1118full of basic guidelines--especially after years of red flags about1119threats to critical infrastructure. But Colonial Pipeline--which,1120remember, had no CISO at the time of the hack--showed that companies1121were still not doing some of the basics to secure their systems and1122ensure they would be resilient in an attack.1123    Several years ago, CISA launched a ``More Than a Password''1124campaign to increase adoption of multi-factor authentication and called1125the absence of MFA ``exceptionally risky,'' particularly for critical1126infrastructure. A study by Google and 2 universities found that MFA can1127block up to 99 percent of bulk phishing attacks and about 66 percent of1128targeted attacks. Yet a survey published by Trellix found that 751129percent of respondents in the U.S. oil and gas sector had not fully1130deployed MFA. Over half of them blamed a lack of in-house cyber skills1131for failing to implement it.1132    So although there has been a lot of focus from the Government in1133establishing new security guidelines and mandates and reporting1134requirements for railways and pipelines and other critical1135infrastructure, it's not clear how these industries will reach basic1136levels of security without budgets and skills--and even with those,1137it's not clear how long it will take to get them up to speed. The fact1138that there aren't more attacks against critical infrastructure isn't1139because the systems are secure.1140    Testimony like this often ends with some sort of call to action. I1141don't have any specific prescriptions to suggest because I believe my1142fellow panelists will do that. My goal here has been to bring attention1143to some issues around critical infrastructure that have been simmering1144for 2 decades but are far from being resolved, even though we've had1145decades to address them and events like Stuxnet, the Ukraine power grid1146hack and the Triton assault against the petrochemical plant in Saudi1147Arabia to illustrate the direction the United States is headed if the1148problems aren't addressed.1149    Thank you again for this opportunity to speak with you about this1150issue.11511152    Mr. Garbarino. Thank you, Ms. Zetter.1153    I now recognize Mr. Lee for 5 minutes to summarize his1154opening statement.11551156  STATEMENT OF ROBERT M. LEE, CHIEF EXECUTIVE OFFICER AND CO-1157                      FOUNDER, DRAGOS INC.11581159    Mr. Lee. Chairman Garbarino, Ranking Member Swalwell,1160Members of the subcommittee, 15 years ago, Stuxnet proved cyber1161attacks could cause physical destructions. Attacks on OT1162networks are under sustained and sophisticated assault from our1163adversaries today. I'm Robert Lee, CEO of Dragos, a former Air1164Force officer in NSA, and now serving since the last time we1165all met in this committee in my role as lieutenant colonel in1166the Army Guard designing out OT defense strategies. I spent my1167career protecting these industrial systems that power our1168society.1169    Let me be blunt. We are not prepared for a major attack on1170our critical infrastructure. We know that such an attack would1171be part of any major conflict with an adversary, but we are not1172doing enough to prepare and the results of continued failure1173could be catastrophic, including the loss of life. At Dragos,1174we track over 25 state and non-state actors that target1175operational technology directly. Nine different malware1176families have been built specifically for industrial systems.1177The most versatile is very opposite to Stuxnet. Where Stuxnet1178was very, very targeted, Pipedream can be used against1179everything from unmanned aerial vehicles to water systems to1180power systems.1181    Increasingly, homogenous machinery and technical systems1182have increased the OT attack surface and raised the potential1183consequences of a large-scale attack, but defense is doable.1184One example, Littleton Electric in Massachusetts used a Federal1185grant to install our technology on the network after FBI intel1186indicated to them that they were being targeted by Volt1187Typhoon. We detected, isolated, and mitigated the attack with1188their partnership. They were able to do this because they had1189visibility in their OT networks and they were proactive in1190their security. Most companies don't do this. We know what1191works. Here are a few things that I recommend that we can do.1192    First, we must stop treating OT like IT. These systems have1193different risks and require different defense strategies.1194Hearings like this one are critical to raise awareness of this1195distinction. A significant portion of the funding and1196resourcing in the community goes to IT, whereas the critical1197part of critical infrastructure is OT.1198    Second, make public-private partnerships count. At Dragos,1199we uncovered Pipedream in coordination with the NSA and an1200undisclosed third party. We ended up coordinating with CISA and1201the electric ISAC and that allowed us to warn operators before1202the adversary was even allowed to deploy it against targets1203across the United States. Broad, unfocused information-sharing1204efforts, though, do not work. Targeted, focused coordination1205does.1206    Third, we must streamline Federal guidance. Right now, too1207many agencies are sending too many messages, many of which are1208overlapping and often contradictory to our industry. We have to1209tell the industry, here's the threat, here's what success looks1210like. We have to let them handle the how. Right now it is1211extremely confusing for asset owners and operators on turning1212to who is going to be the one to help them and, most1213importantly, what the actual guidance is that they should1214follow beyond regulatory.1215    Fourth, we have to let the private sector lead on1216technology. We already have the tools to detect advanced1217threats. Federal efforts to replicate them just waste money and1218slow adoption. Fund deployment, not reinvention. Government1219should focus on over-the-horizon threats. The private sector1220has already created the tools and techniques needed to deal1221with the threats in the here to now, it's just about execution.1222Government tools have consistently underperformed in comparison1223to private-sector tools and at a higher cost to taxpayers.1224    Fifth, secure the supply chain. Critical infrastructure1225vendors must meet real security standards. Right now, all of1226the focus is placed on asset owners and operators and not the1227vendors. Asset operators and their vendor community should1228share responsibility for meeting basic security requirements1229for all the components that are installed into our critical1230infrastructure, even the security vendors. As the CEO of1231Dragos, I'm surprised that I have the amount of flexibility I1232do to make willfully poor security choices to increase my1233margins. Though we have not done that and would not do that,1234I'm surprised by the ability of CEOs to make that decision. I1235believe we need higher standards and more selectivity into who1236can sell into critical infrastructure and how.1237    Finally, we need to fix Federal response coordination. Most1238operators simply don't know who to turn to or to call after an1239incident or what they'll get in response. Responses differ1240across State lines and there's no basic credentialing for who1241shows up and what they can do. I'm helping write a national OT1242response plan in my role at the 91st Cyber Brigade, but we need1243legislative support to cut through the bureaucracy. I found1244great partnership in this effort with CISA, particularly strong1245support with Shawn Plankey, and I look forward to his1246confirmation. We simply know what needs to be done and it's1247time to stop standing in our own way. Our kids' lives depend on1248it.1249    To close, our adversaries are gaining ground, but we have1250the tools, the knowledge, and the people to win. Now we need1251large-scale execution in the public and private sectors. We1252know what needs to be done, we just need to do it.1253    I'm grateful to all of you for holding this hearing and1254look forward to the rest of our conversation.1255    I yield back my time.1256    [The prepared statement of Mr. Lee follows:]1257                  Prepared Statement of Robert M. Lee1258                              22 July 20251259    Chairman Garbarino, Ranking Member Swalwell, and distinguished1260Members of the subcommittee, thank you for providing me the opportunity1261to testify before you today. I am Robert M. Lee, the CEO and co-founder1262of Dragos, Inc., a leading industrial cybersecurity technology and1263services provider. I am also a Fellow and course author at the SANS1264Institute which is the leading cybersecurity training provider globally1265where my classes have trained thousands of the world's critical1266infrastructure security practitioners. Additionally, I am a veteran of1267the United States Air Force and National Security Agency and currently1268serve as a Lt. Colonel in the United States Army National Guard where I1269have been tasked to design operational technology (OT) and industrial1270control systems (ICS) defense and response strategies for the country1271in preparation for conflict. It has been my privilege to be on the1272front lines of this problem in both Government and the private sector.1273    This committee's hearing is very timely: an examination of what we1274have learned in the OT/ICS community across the last 15 years since the1275emergence of the malicious software capability STUXNET. I will focus my1276testimony on both the global infrastructure community and specifically1277the national security of the United States. Those two topics are1278intricately connected but there are U.S.-centric lessons learned and1279examples to explore that can provide insights.1280    It has been well-covered over the years that what made STUXNET1281unique was its ability to target and cause destruction to physical1282assets and production processes through cyber methods. It did this by1283targeting OT/ICS--specialized computers and networks that interact with1284the physical world. Sometimes these systems are typical-looking Windows1285Operating Systems on personal computers that have specialized software1286to interact with physical components such as valves and circuit breaks.1287Sometimes they are unique computers, networks, and physical components1288that may only be found in specific production processes such as a1289purpose-built controller interacting with a P-1 gas centrifuge and its1290vibration monitoring sensors.1291    STUXNET was unique at its time in the demonstration that targeting1292ICS/OT with the expertise not just of software developers and cyber1293operators but also engineers and operators could lead to physical1294disruption and destruction of critical infrastructure. There were1295people around the world who already knew this was possible and other1296adversarial countries already developing their expertise in these1297areas. But it is fair to say that many who did not know it before now1298understood that the critical part of critical infrastructure is OT.1299Unfortunately, STUXNET did not remain unique for long in its1300destructive capabilities.1301    Over the last 15 years we have seen a significant rise in the1302number of state and non-state actors that target ICS/OT. At Dragos,1303Inc. we currently track over 25 such groups who have focused their1304cyber operations on the targeting of OT. Some of those groups continue1305to focus their efforts on learning about the structure of, and1306vulnerabilities in, our critical infrastructure. Those groups pose no1307significant immediate threat but may be developing the capacity and the1308knowledge needed to threaten critical infrastructure in the future.1309Other threat groups have caused multiple real-world electric power grid1310outages, disruptions to water systems, and the theft of intellectual1311property in our defense industrial base and manufacturing communities.1312To date, we know of 9 unique families of ICS malware that have been1313developed with espionage or disruption in mind.\1\ The worst of these1314is PIPEDREAM which was the first-ever capability to be re-usable1315against a wide variety of industries ranging from the servo-motors on1316unmanned aerial vehicles to water pumps to combined cycle gas turbine1317control systems.\2\ STUXNET was extremely tailored and capable against1318only one specific target whereas PIPEDREAM was built to impact any1319environment the adversarial country who built it wanted to disrupt.1320---------------------------------------------------------------------------1321    \1\ https://www.dragos.com/wp-content/uploads/2025/06/dragos-1322understanding-ics-malware-whitepaper-june-2025.pdf.1323    \2\ https://hub.dragos.com/hubfs/116-Whitepapers/1324Dragos_ChernoviteWP_v2b.pdf.1325---------------------------------------------------------------------------1326    Criminals are already responsible for thousands of attacks on1327industrial organizations a year with around 75 percent of those1328resulting in some disruption to operations and around 25 percent of1329those attacks resulting in full operations shutdown.\3\ Alarmingly, we1330have recently seen the state actors who once alone possessed the1331capability to cause such disruption sharing their insights and1332resources with non-state actors including criminals. Even with that1333backdrop, the world right now enjoys a relative level of calm that1334comes from having a low frequency of high consequence attacks in1335comparison to what it may become. Unfortunately, non-state actors and1336lesser-restrained states gaining such capabilities will continue to1337increase the frequency of these attacks and many in the cybersecurity1338community are sadly awaiting the days we see the direct loss of human1339life as a result of such attacks. I sincerely hope that we do not learn1340to normalize and accept this as we have sadly collectively normalized1341and accepted increasing attacks on civilian OT infrastructure.1342---------------------------------------------------------------------------1343    \3\ https://hub.dragos.com/hubfs/312-Year-in-Review/2025/Dragos-13442025-OT-Cybersecurity-Report-A-Year-in-Review.pdf.1345---------------------------------------------------------------------------1346    I could spend the entire time of this testimony giving scary1347examples of what has transpired over the last 15 years and why we need1348to take this threat seriously. The unclassified briefings alone of what1349China has done in its VOLT TYPHOON/VOLTZITE campaigns targeting U.S.1350and allied critical infrastructure over the past few years would leave1351no doubt to people about the seriousness of this conversation. Let's be1352clear: the timeline to take action against this growing threat is1353short, and the consequences of failure could, and likely would be1354people dying. Thankfully this is not the first time Congress has taken1355up this discussion. Personally, this marks the fifth me I've testified1356to the House and Senate on such matters. Therefore, I want to focus on1357what problems we must solve for now and how we can solve them. I know1358this is a Congress that listens, and we have a critical infrastructure1359community that acts.1360    There are many areas of investment that can be made but I assess1361the following to be the most practical, right-sized actions against the1362threat, and the most effective moves to counter the risks that our1363communities need protection from most.1364   Recognize and Account for the Differences Between1365        Information Technology and Operational Technology Systems.--IT1366        and OT systems differ fundamentally in both purpose and1367        operation. IT supports how a business is managed, focusing on1368        data security and system integrity, while OT enables the1369        physical functions that are the core reason an organization1370        exists, such as controlling pumps or chemical levels at a water1371        facility. These differing missions shape how risks are assessed1372        and managed. While an adversary might exploit similar1373        vulnerabilities in IT and OT systems, the consequences and1374        adversary behavior differ. A breach in an IT system might1375        result in data theft, but in OT it could lead to physical1376        disruption, equipment damage, or even loss of life. OT1377        environments also have distinct operational demands: systems1378        often run continuously for years, require availability-focused1379        redundancy, and depend on precise millisecond-level1380        responsiveness. While some traditional IT controls have been1381        adapted for OT, the security mindset must differ; tailored to1382        the unique physical environments, long hardware life cycles,1383        and evolving threats targeting operational infrastructure. All1384        these differences dictate some different security practices,1385        technologies, and policy responses. Regulators and policy1386        makers must recognize these critical distinctions when setting1387        policy to avoid costly and counterproductive rules. Asset1388        operators must be mindful of these differences and avoid1389        underinvestment in OT security--currently based on my anecdotal1390        experience about 95 percent of cyber spend is focused on IT1391        systems, with just 5 percent for OT--where the revenue of1392        companies is focused and their impact to society and national1393        security. Hearings like this one draw important attention to1394        these distinctions.1395   Focus on the Fundamentals--Defense is Doable.--As the scale,1396        frequency, and sophistication of threats to critical1397        infrastructure increase it can be easy to fall into a spiral of1398        admiring the problem and failing to defend against it. But1399        fortunately, defense is doable. The vast majority of threats1400        can be prevented from achieving their objectives by simply1401        taking fundamental steps. To provide one example, the Littleton1402        Electric Light and Water Departments in Massachusetts won a1403        Federally-funded grant from the American Public Power1404        Association and used it to install our threat visibility and1405        mitigation technology. At the same time, the U.S. Government1406        including the Federal Bureau of Investigations (FBI) provided1407        critical intelligence to Littleton that they were likely being1408        targeted by VOLT TYPHOON. Upon receiving this intelligence and1409        the deployment of our platform they quickly identified a1410        sophisticated and persistent compromise from the Chinese1411        government. Our team moved swiftly to contain and eliminate1412        this adversarial presence and the utility was able to change1413        its network architecture to remove any advantages for the1414        adversary. This is a common phenomenon: when we gain visibility1415        into an OT network for the first time, we often find evidence1416        of compromise that was previously unknown. Visibility into OT1417        networks is critical to know that you have a compromise, to1418        know the nature of the compromise, and to detect its cause.1419        Only with that information can political and business leaders1420        choose the appropriate response plans and actions. Recognizing1421        this fact, the North American Electric Reliability Corporation1422        (NERC) and the Federal Energy Regulatory Commission (FERC)1423        jointly created Reliability Standard CIP 015-1 Internal Network1424        Security Monitoring. This landmark regulation will vastly1425        improve the security of America's larger electric utilities by1426        requiring network visibility, but it will take time to1427        implement and smaller sites and other industries are not taking1428        the same journey. While I highlight visibility here it is only1429        one of a couple core security controls required. The SANS1430        Institute analyzed all the known OT cyber incidents and1431        determined that 5 security controls were the most effective and1432        could significantly decrease the risk of cyber threats.\4\ Not1433        tens or hundreds but simply 5 security controls. Raising1434        awareness of the threat is a critical part of this effort, but1435        public and private resourcing is also vital for efforts that1436        have been proven to work. We aren't where we need to be right1437        now, but we know what needs to be done, and we know it can be1438        done.1439---------------------------------------------------------------------------1440    \4\ https://www.sans.org/white-papers/five-ics-cybersecurity-1441critical-controls/.1442---------------------------------------------------------------------------1443   Create Public-Private Partnerships That Work.--The necessity1444        of public-private partnerships and information sharing is1445        universally recognized, but the effectiveness of these1446        arrangements is inconsistent. Constant effort must be made to1447        improve and properly resource information-sharing partnerships1448        and learn from what is working and what isn't. As an example of1449        successful partnership, my company, Dragos, collaborated with1450        the NSA Cybersecurity Collaboration Center and a third party to1451        identify and analyze the PIPEDREAM malware before it was1452        employed against its targets. In partnership with the1453        Cybersecurity and Information Security Agency (CISA) and the1454        Electricity Information Sharing and Analysis Center (E-ISAC),1455        we informed industry widely about the threat we had identified,1456        providing operators time to prepare and monitor. The mission1457        succeeded in this instance because everyone involved was1458        focused and understood the nature of the threat. Dragos had the1459        technology and experts to detect the threat and analyze it in1460        collaboration with our Federal partners. E-ISAC and CISA knew1461        who the operators were, and how to communicate the threat to1462        them. The operators, in turn, knew how to defend against the1463        threat once they were aware of it. E-ISAC, and its financial1464        services counterpart FS-ISAC are examples of well-resourced1465        industry partners with proven effectiveness that can and should1466        be emulated. Some other public-private information-sharing1467        efforts have become too broadly based, limiting their1468        effectiveness by making participants hesitant to be candid.1469        Some level of Federal selectivity based on ability to produce1470        unique insights and capabilities makes sense and helps1471        participants stay focused and effective.1472   Keep Federal Guidance Focused and Federal Actions1473        Streamlined.--Federal authorities have promulgated an array of1474        requirements and guidance documents that are often well-1475        meaning, but ultimately ineffective, or even damaging.1476        Different Federal authorities will come to operators advising1477        or requiring them to take different sets of actions. Sometimes1478        these actions are duplicative or even contradictory; even when1479        they're not, their sheer number muddles the mission and makes1480        it difficult for operators to focus on what matters most. The1481        Federal Government should speak with one voice, and they should1482        keep their advice and requirements to industry streamlined and1483        focused. Operators should be informed of the threat scenarios1484        they should prepare for, and the specific outcomes they should1485        be able to achieve, not how they should achieve them. Vague1486        generalities and obscure goals can cause confusion and analysis1487        paralysis. Empowered, focused, and threat-informed Federal1488        authorities should be allowed to have a point of view on the1489        threat scenarios faced by critical infrastructure operators,1490        and they should communicate the threat and desired outcomes1491        clearly and in a unified manner while leaving the details to1492        the industry operators who know their systems best.1493   Let the Private Sector Lead on Security Technology.--Just as1494        some Federal efforts to offer guidance and regulation to the1495        private sector are well-meaning but ultimately ineffectual,1496        there are some Federal technology initiatives that are meant to1497        help but may simply crowd out better solutions. Federally-led1498        and funded cyber technology development efforts aimed at1499        critical infrastructure sectors have not achieved large-scale1500        adoption and serve as a disincentive for infrastructure1501        operators to acquire state-of-the-art cybersecurity solutions;1502        indeed, they discourage private-sector businesses from creating1503        them in the first place. There is no market failure to address.1504        Companies like Dragos, but not limited to Dragos, have produced1505        the tools needed to effectively detect and mitigate even the1506        most advanced operational technology threats. Federal funding1507        can be better spent facilitating the acquisition of advanced1508        cyber technologies than it can by attempting to create them.1509        The alarming fact is, at this moment, most critical1510        infrastructure operators would not be able to detect STUXNET or1511        its techniques on their systems, nor would they be able to1512        recognize the known and highly-publicized tactics and1513        techniques of our advanced adversaries. Again, this is in spite1514        of the fact that the technology and knowledge exist to do so.1515        We have the ability; we know what works. We just need to do it.1516        While innovation is always welcome, we are sorely lacking in1517        execution of what works today. Federal attempts to build1518        duplicative tools will only distort the market and serve as a1519        distraction for operators whereas resourcing the asset owners1520        and operators directly can have a direct and immediate impact.1521   Don't Disregard Supply Chain Security.--Much of my testimony1522        is focused on what we need to do to keep external threats out1523        of operational technology networks, but we also need to focus1524        on making sure that the component parts of these networks and1525        their vendors aren't degrading their security. This committee,1526        and Congress writ large have done important work in raising the1527        alarm about the threat that insufficiently-vetted foreign1528        technology may pose to American telecommunications networks,1529        ports, and other critical infrastructure. This should also1530        extend to domestic technology providers who choose to not make1531        good security choices. Asset operators often feel enormous1532        pressure to go with the most economical choice when buying1533        equipment and other vital operational technology, even if the1534        security of these components is in doubt. This creates a large1535        and looming cybersecurity threat that may be more expensive and1536        complex to address than if properly vetted technology had been1537        installed to begin with. Federal policy makers must have a1538        clear notion of what assets count as critical infrastructure1539        that is continuously updated, and that accounts for the1540        upstream assets that make the operation of critical1541        infrastructure possible. This should also include the security1542        vendors like Dragos. Today, as the CEO of Dragos I can make1543        choices that benefit my company financially but lower the1544        security of our part of the supply chain. Yet I am allowed to1545        make those changes and sell into critical infrastructure where1546        the cost of my choices is not just passed on to the asset1547        owners and operators but the people they serve. I have strived1548        hard not to make such careless choices, but I am surprised with1549        the level of freedom I have in making them and still being1550        allowed to sell into critical infrastructure. Other companies I1551        know of are not being so focused on these choices as market1552        demands and pressures make it challenging for them. Policy1553        makers should not hesitate to set basic security standards for1554        the supply chains of our critical infrastructure or even1555        creating selectivity based on these standards on what companies1556        are allowed to sell into critical infrastructure. These1557        standards should be clear, enforceable, and readily1558        justifiable. The vendor community serving critical1559        infrastructure sectors should know these standards and share1560        accountability for adhering to them. You can only be confident1561        about the security of a critical infrastructure network if1562        you're confident about the security of its components.1563   Have a National OT/ICS Incident Response Plan and Align1564        Authorities.--Just as it's important to align Federal messaging1565        and guidance to industry, it is also critical that we work to1566        align Federal authorities to respond to incidents.1567        Unfortunately, incidents will happen, but their severity can be1568        mitigated by swift and effective response. Although I am here1569        speaking in my capacity as CEO of Dragos, I have recently taken1570        up duties in the 91st Cyber Brigade's Information Operations1571        Support Center of the Army National Guard to aid in this1572        effort. I was tasked with creating a national response plan1573        focused on OT incidents and coordinate across Federal agencies.1574        It has long been clear to me that asset owners and operators1575        often don't know whom to call after an incident, what help they1576        are going to be able to get when they do, and experience1577        consistency across State lines in terms of the expertise and1578        credentialing of the people responding. What I have found is1579        the actual tactical and technical nature of the work is1580        obvious. The plan itself was actually fairly easy to write in a1581        way that would significantly enhance national security. But it1582        is the mismatch of authorities, selecting which budgets efforts1583        are allowed to be coordinated out of, and being able to have a1584        point of view on what right looks like without ``the concern of1585        perception'' that are hindering the roll-out of the plan. I1586        find it morally questionable that we have broad-based support1587        and a knowledge of what to do to protect our kids against1588        foreign threats and it is only ourselves standing in the way.1589        This is not a criticism of the many talented public servants1590        who selflessly carry out tough and important work; it's simply1591        a recognition that existing Federal funding structures and1592        authorities aren't always aligned in a way that is easily1593        accessible to industry, or maximally effective in executing a1594        response. Fixing these issues will likely require legislative1595        action to untangle funding lines, provide indemnification to1596        operators who choose to trust the U.S. Government, and1597        facilitate cooperation with Federal agencies and between1598        agencies. I look forward to working through some of these tough1599        issues and I know there is a broad cross-section of Federal1600        cyber leaders who share a common perception of what the1601        problems are, and broadly how they can be fixed. It is critical1602        that the Federal Government have a single response plan that1603        provides asset owners and operators a unified means of1604        interacting with and receiving help from Federal responders in1605        cooperation with the private sector before and after an1606        incident.1607    In the 15 years that have passed since STUXNET shined a light on1608the threat facing OT/ICS, the threat has grown but so has our ability1609to respond to it. We have better technologies and trained personnel. We1610have an improved sense of what works, and what doesn't work, in public-1611private threat information sharing, incident response, regulation,1612resourcing, and general cyber threat defense. We have a body of case1613studies to draw lessons from. We have real-world examples of the simple1614fact that defense is doable, even for smaller utilities and asset1615operators. That's the good news. The bad news is that major gaps remain1616in the implementation of OT/ICS cyber defenses, and despite1617improvements, Federal guidance and regulations continue to be1618confusing, duplicative, or contradictory in many cases. Federal OT/ICS1619incident response plans remain tangled. The determination and1620sophistication of our adversaries continues to grow, and the scale of1621adversary infiltration into critical infrastructure networks may be far1622greater than we realize. Stated plainly: at this moment, we are not1623prepared for a large-scale attack on critical operational technology.1624    The threat remains, but past progress shows clearly that we can1625solve our current and future challenges. I'm deeply grateful for the1626work that this subcommittee is doing, and the needed attention it is1627drawing to OT/ICS cyber threats. I look forward to the rest of today's1628conversation.16291630    Mr. Garbarino. Thank you, Mr. Lee.1631    I now recognize Ms. Bolton for 5 minutes to summarize her1632opening statement.16331634     STATEMENT OF TATYANA BOLTON, EXECUTIVE DIRECTOR, THE1635             OPERATIONAL TECHNOLOGY CYBER COALITION16361637    Ms. Bolton. Thank you, Chairman. Chairman Garbarino,1638Ranking Member Swalwell, and Members of the subcommittee, thank1639you so much for the opportunity to testify today. I commend the1640subcommittee for prioritizing critical infrastructure security1641and holding this hearing to discuss the heightened threat1642landscape. My name is Tatyana Bolton and I'm the executive1643director of the Operational Technology Cybersecurity Coalition.1644The OTCC is a coalition of OT cybersecurity organizations1645created critical infrastructure operators and thought leaders1646representing the entire OT life cycle and protecting our1647Nation's critical infrastructure assets. We provide vendor-1648neutral perspectives on securing our collective defense and1649advocate for improved OT security policy.1650    Stuxnet marked a pivotal moment in cyber warfare by1651demonstrating that digital tools could indeed cause real-world1652physical destruction to systems known as operational1653technology, or OT. OT is the technology that makes machines1654run, like pumps and valves on the manufacturing room floor or1655machines that control compressors and filters in a water1656treatment facility. It's crucial to recognize, as Rob said,1657that operational technology, OT, is distinct from information1658technology, IT. Their respective security requirements differ1659considerably. OT cybersecurity must prioritize safety,1660reliability, and physical process continuity, and these systems1661can be older, having been built to last decades, and many never1662designed to be connected to the internet in the first place.1663    Despite the elevated risks associated with attacks on OT1664systems, this area of cybersecurity remains significantly under1665prioritized and underfunded. The OTCC is working on a number of1666efforts and has provided multiple recommendations to the1667committee and I'd like to highlight a few of them here from my1668written testimony.1669    First, we need to focus on awareness. The United States1670must prioritize OT cybersecurity to prepare critical1671infrastructure against the growing threats. Our Government has1672acknowledged that U.S. infrastructure is at risk. However, it1673has not taken sufficient steps to address the growing1674vulnerabilities in the wake of attacks like Cyber Avengers or1675Volt and Salt Typhoon. While securing IT is important, the OT1676systems that, if attacked, turn off our lights, bring hospitals1677to a standstill, and disrupt essential services. Congress must1678urgently answer the question of who holds responsibility for1679these risks, as a debilitating cyber attack on our critical1680infrastructure would demand clear accountability.1681    Second, Congress must reauthorize CISA 2015. In May, our1682Coalition submitted a letter to this committee urging the1683reauthorization of the Cybersecurity and Information Sharing1684Act of 2015, which will expire in September of this year. As1685you well know, this legislation is crucial to information1686sharing and strengthening U.S. collective defense. Both public1687and private-sector security teams rely on information sharing1688from other organizations to strengthen their defenses. If the1689legal protections established by this act were to lapse, this1690flow of information would be disrupted up to 80 to 90 percent1691and national security put in jeopardy.1692    Third, we must better resource OT security. From addressing1693the growing tech debt, hiring cybersecurity experts, to1694procuring and building updated and secure systems, OT owners1695and operators don't have the necessary funding to defend their1696networks and often 99 cents of every dollar is spent on1697physical security. We need to address critical infrastructure1698security through a whole-of-nation approach. Just as we1699wouldn't expect an individual county, such as Polk County in1700Texas, to defend themselves against missile strikes from a1701nation-state actor, we shouldn't expect them to respond to1702cyber attacks on their own.1703    This is a national security priority. This is why the State1704and Local Cybersecurity Grant Program must be reauthorized.1705These resources allow underfunded critical entities to remove1706Chinese routers, hire cybersecurity staff and replace outdated1707servers. Congress should also explore whether there are other1708opportunities to provide economic incentives to critical1709infrastructure owners and operators to invest in OT security.1710The biggest vulnerability in any of your States and all of the1711States is your lowest common denominator, so we must increase1712the security baseline of across the board.1713    The threat to critical infrastructure and operational1714technology from our adversaries, including Iran, is real and1715growing. OTCC aims to work with this committee and our1716stakeholders to achieve our common objective. With the right1717policies, resources, and partnerships, we can build a more1718resilient and secure Nation.1719    Thank you again for the opportunity to testify and I look1720forward to your questions.1721    [The prepared statement of Ms. Bolton follows:]1722                  Prepared Statement of Tatyana Bolton1723                             July 22, 20251724    Chairman Garbarino, Ranking Member Swalwell, and Members of the1725subcommittee; on behalf of the Operational Technology Cybersecurity1726Coalition, thank you for the opportunity to share our perspective on1727the threat Iran poses to operational technology and critical1728infrastructure, as well as the broader state of critical infrastructure1729security in the United States. I commend the subcommittee for1730prioritizing critical infrastructure security and holding this hearing1731to discuss the heightened threat landscape.1732    My name is Tatyana Bolton, and I am the executive director of the1733OTCC, where I lead a group of cybersecurity organizations, critical1734infrastructure owners and operators, and thought leaders. Representing1735the entire OT life cycle and with decades of experience protecting our1736Nation's critical infrastructure assets, we believe that the strongest,1737most effective approach to securing our collective defense is one that1738is open, vendor-neutral, and allows for diverse solutions. I look1739forward to discussing our perspective on Iranian cyber threats and the1740state of critical infrastructure resilience in the United States.1741                            what has changed1742    Stuxnet, discovered in 2010, marked a pivotal moment in cyber1743operations by demonstrating that digital tools could indeed cause real-1744world physical destruction. This sophisticated cyber attack targeted1745Iran's nuclear enrichment program, manipulating industrial control1746systems (ICS) to subtly alter centrifuge rotation speeds while feeding1747back normal data, ultimately destroying nearly 1,000 centrifuges and1748setting back Iran's nuclear program by years.1749    Since Stuxnet, the cyber landscape has undergone significant1750transformation. The nature of the threats we face has evolved. While1751Stuxnet utilized physical USB drives, today's cyber actors increasingly1752employ phishing, social engineering, and credential theft as primary1753vectors of attack. Furthermore, they are progressively striking more1754significant entities, as evidenced by the Volt Typhoon attack, which1755should prompt serious reflection on the priority given to and methods1756used for securing critical infrastructure. They stay on networks1757longer, sometimes going unnoticed for several years, putting our most1758sensitive networks at risk.1759    Adversaries have expanded their cyber operations. Iranian actors1760specifically have targeted critical infrastructure entities, focused on1761water and energy sectors, performed defacements, data exfiltration, and1762ransomware attacks. They have also developed strong relationships with1763cyber criminal groups and increased their use of information1764operations. Other actors are targeting critical infrastructure to1765establish persistent access and pre-positioning capabilities for use1766during future geopolitical contingencies.1767    Concurrently, the spectrum of threat actors has become increasingly1768sophisticated, now encompassing organized criminal enterprises, cyber1769mercenary groups, ransom-for-hire organizations, terrorist1770organizations, and state-sponsored proxies. Regrettably, the U.S.1771Government has encountered considerable challenges in effectively1772keeping pace with this accelerating evolution of the cyber threat1773landscape.1774    These attacks are happening on OT networks--the hardware and1775software that monitors and controls physical devices--machines like1776vents, pumps, and SCADA systems. And critically, Operational Technology1777(OT) is distinct from Information Technology (IT), and their respective1778security requirements differ. While IT security protects networks that1779run business systems, OT security protects physical systems and must1780prioritize safety, reliability, and physical process continuity. These1781systems can be older, built to last decades, and many were never1782designed to be connected to the internet. Most importantly, when policy1783makers craft rules and requirements about cybersecurity, they must1784address both IT and OT use cases.1785    Despite the elevated risks associated with attacks on OT systems,1786this area of cybersecurity remains significantly underfunded and1787underprioritized. Even the Department of Defense (DoD) has yet to1788complete the fundamental step of identifying and inventorying its OT1789assets. Congress must urgently answer the question of who has accepted1790these critical risks, as a debilitating cyber attack on our critical1791infrastructure would demand clear accountability.1792    As you examine these issues, there are 3 considerations that I urge1793you to take into account:1794Critical Infrastructure Security is a Matter of National Security1795    Critical infrastructure security is not merely an economic or1796operational concern; it is a foundational element of U.S. national1797security. An attack against critical infrastructure can lead to severe1798consequences, potentially impacting national and economic security,1799public health and safety, and societal trust. Recent incidents vividly1800illustrate this escalating danger:1801   In May 2021, the Colonial Pipeline Company suffered a1802        ransomware attack that halted pipeline operations, disrupting1803        fuel supplies across the East Coast. While this attack did not1804        touch OT systems, OT systems were shut down to prevent the risk1805        of further damage. It is the first time that the public woke up1806        to the danger a cyber attack could pose.1807   In February of the same year, a hacker gained remote access1808        to the Oldsmar, Florida water treatment plant and attempted to1809        dangerously increase sodium hydroxide levels, an attack1810        prevented only by an alert operator.1811   In 2013, an Iranian national employed by a company1812        contracted by Iran's Revolutionary Guard Corps accessed the1813        SCADA systems of the Bowman Dam in Rye, New York, gaining1814        insight into its operational status and water controls.\1\1815---------------------------------------------------------------------------1816    \1\ ``Manhattan U.S. Attorney Announces Charges Against Seven1817Iranians for Conducting Coordinated Campaign of Cyber Attacks Against1818U.S. Financial Sector on Behalf of Islamic Revolutionary Guard Corps-1819Sponsored Entities,'' March 24, 2016, https://www.justice.gov/usao-1820sdny/pr/manhattan-us-attorney-announces-charges-against-seven-iranians-1821conducting-coordinated.1822---------------------------------------------------------------------------1823   Most concerning were the Chinese state-sponsored Volt1824        Typhoon attacks, discovered last year, targeting U.S. critical1825        infrastructure sectors, pre-positioning a major adversary for1826        long-term disruption during potential geopolitical conflicts.1827    Indeed, Iranian state-sponsored groups like MuddyWater, APT33,1828OilRig, CyberAv3ngers, FoxKitten, and Homeland Justice have also1829actively targeted U.S. critical infrastructure, particularly in the1830transportation and manufacturing sectors, with Nozomi Networks Labs1831observing a 133 percent increase in their activity in May and June1832alone.\2\1833---------------------------------------------------------------------------1834    \2\ Nozomi Networks, ``Threat Actor Activity Related to the Iran1835Conflict,'' July 9, 2025, https://www.nozominetworks.com/blog/threat-1836actor-activity-related-to-the-iran-conflict.1837---------------------------------------------------------------------------1838    Despite these breaches, the United States does not sufficiently1839prioritize OT and critical infrastructure security. This problem is1840both a cultural and structural issue, and we need to address both in1841order to ensure the security of U.S. critical infrastructure.1842Whole-of-Nation Effort1843    We need to begin addressing critical infrastructure security1844through a whole-of-Nation approach. Just as we would not expect an1845individual district, such as Cameron Parish, Louisiana to defend1846themselves against missile strikes from a nation-state actor, we should1847not expect them to respond to cyber attacks on their own. Of America's18483,144 counties, about 1,500 of them can be classified as rural.\3\1849These counties and municipalities do not have the resources or capacity1850to ensure resilience themselves, yet are often targets of cyber actors1851because they are the weakest link in our chain.1852---------------------------------------------------------------------------1853    \3\ ``Rural and Underserved Counties List/Consumer Financial1854Protection Bureau,'' Consumer Financial Protection Bureau, January 23,18552025, https://www.consumerfinance.gov/compliance/compliance-resources/1856mortgage-resources/rural-and-underserved-counties-list/.1857---------------------------------------------------------------------------1858    As we've seen play out again and again, cyber actors practice on1859smaller entities and then move to bigger targets. And, not only do we1860see our adversaries moving from small entities to larger targets like1861hospitals and casinos, but also globally as our adversaries practice1862their techniques on our allies and partners before they attack U.S.1863entities. And these attacks on small, unprotected entities can have1864significant costs to the entire Nation. A 2023 report by the U.S. Water1865Alliance concluded that a 1-day disruption in water service at a1866national level would amount to a daily loss of $43.5 billion in sales1867and $22.5 billion in GDP. An 8-day national disruption would total a 11868percent loss in annual GDP.\4\1869---------------------------------------------------------------------------1870    \4\ Value of Water Campaign, ``The Economic Benefits of Investing1871in Water Infrastructure,'' n.d., https://uswateralliance.org/wp-1872content/uploads/2023/09/Economic-Impact-of-Investing-in-Water-1873Infrastructure_VOW_FINAL_pages_0.pdf.1874---------------------------------------------------------------------------1875Public-Private Partnerships are Essential1876    Addressing the pervasive and existential threat of modern1877cybersecurity demands robust public and private-sector partnerships.1878This threat impacts the foundational OT underpinning critical1879infrastructure across all sectors, from energy, water, and1880transportation to manufacturing, health care, and financial services.1881The intricate interconnectedness of these systems means a successful1882cyber attack in one area can trigger devastating cascading effects.1883    Since a significant majority of this vital critical infrastructure1884is privately owned and operated, bridging the inherent divide between1885private entities (with their specialized expertise and operational1886control) and the Government (with its responsibility for national1887security and policy) is paramount. True resilience requires deep,1888trust-based collaboration where information, best practices, and threat1889intelligence flow seamlessly.1890    To foster this essential synergy, it is critical to re-establish1891and strengthen effective public-private coordination mechanisms. We1892must bring back mechanisms like the Critical Infrastructure Partnership1893Advisory Council (CIPAC), which provided a vital forum for government1894and industry collaboration on security issues. Organizations like the1895Operational Technology Cybersecurity Coalition (OTCC) also play a1896crucial role in bringing together stakeholders to provide broad1897perspectives and engage with policy makers.1898    By prioritizing and investing in these collaborative frameworks, we1899can ensure our Nation is optimally prepared for today's rapidly1900evolving and increasingly sophisticated cyber threats across all1901critical infrastructure domains.1902                            recommendations1903    These issues are not insurmountable. To prevent adversaries from1904infiltrating our critical infrastructure and protect our national1905defense, the OTCC has the following recommendations1906    Raise Awareness.--The U.S. Government must prioritize operational1907technology cybersecurity to prepare critical infrastructure against1908growing threats. Congress must work with industry to ensure critical1909infrastructure entities are aware of the threats they face, to ensure1910cyber policy always takes OT into account. Our Government has1911acknowledged that U.S. infrastructure is at risk; however, it has not1912taken sufficient steps to address the growing vulnerabilities or1913prioritized response and resilience in the wake of attacks like Volt1914and Salt Typhoon. While securing IT is important, it is the OT systems1915that, if attacked: turn off our lights; bring hospitals to a1916standstill; and disrupt essential services. Congress must be a partner1917in bringing light to this unresolved issue.1918    Reauthorize CISA 2015.--On May 19, 2025, our coalition submitted a1919letter to Congress urging the reauthorization of the Cybersecurity and1920Information Sharing Act of 2015 (CISA 2015), which will expire on1921September 30, 2025.\5\ This legislation is crucial to information1922sharing and strengthening U.S. collective defense.1923---------------------------------------------------------------------------1924    \5\ Operational Technology Cybersecurity Coalition, ``Letter to1925Congress Re: CISA 2015 Reauthorization,'' May 19, 2025, https://1926www.otcybercoalition.org/post/letter-to-congress-re-cisa-2015-1927reauthorization. Letter to Congress re:CISA 2015 Reauthorization.1928---------------------------------------------------------------------------1929    Private-sector cybersecurity teams, particularly those protecting1930critical infrastructure often targeted by foreign adversaries, rely on1931information sharing from other organizations to strengthen their1932defenses. If the legal protections established by the Act were to1933lapse, this flow of information would be disrupted. These communication1934channels are crucial for enhancing national threat awareness and1935enabling rapid responses to cyber incidents, protecting national1936security.1937    Improve Resourcing.--Ultimately, a significant barrier to our1938national security is a lack of resources for OT cybersecurity. From1939addressing the growing tech debt, hiring cybersecurity experts, to1940procuring and building updated and secure systems, OT owners and1941operators do not have the funding necessary to fund the necessary1942security transformation.1943    Funding such as the State and Local Cybersecurity Grant Program1944(SLCGP) allows entities without the resources to utilize grant funding1945to move away from Chinese routers, hire cybersecurity staff, or replace1946outdated servers from the 2000's. Our coalition supports the1947reauthorization of this program and believes that it can help1948organizations take steps like creating an asset inventory; implementing1949multifactor authentication; introducing continuous monitoring and1950detection; ensuring secure remote access processes; and implementing1951network segmentation. OT environments are the heart of our physical1952infrastructure, and increasingly, the battlefield of modern conflict.1953    Asset Investories.--Agencies should prioritize creating OT asset1954inventories, which provide visibility into their OT network. Before an1955organization can protect their systems, it is essential to know what1956technologies are being used. The OTCC is working with the Department of1957Defense and CISA to encourage agencies to complete an OT asset1958inventory.1959    Supply Chain Security.--Entities should also be aware of their1960supply chain risk. Today, critical infrastructure operators and private1961companies face significant vulnerabilities as they expose OT systems to1962the internet and bring on new contractors and vendors.\6\ This risk1963increases when purchasers do not have the capability to identify1964vulnerabilities of third-party software. Like IT security, OT security1965requires expert technical assessments to ensure that the right1966solutions are implemented to mitigate weaknesses.1967---------------------------------------------------------------------------1968    \6\ ``Defending Against Software Supply Chain Attacks,''1969Cybersecurity & Infrastructure Security Agency (CISA), n.d., https://1970www.cisa.gov/resources-tools/resources/defending-against-software-1971supply-chain-attacks.1972---------------------------------------------------------------------------1973    SRMA Maturity.--OTCC is also in the process of publishing a Sector1974Risk Management Agency (SRMA) Maturity Model, which will allow the1975Office of the National Cybersecurity Director to annually grade the1976maturity of each sector. These assessments will give SRMA's direction1977depending on their current maturity and provide a clear road map to1978resilience.1979    We also advocate for measures like multifactor authentication,1980segmentation, and security by design, seeking to increase the1981cybersecurity baseline. Together, these recommendations are a road map1982to ensure the United States retains its OT, and national, security.1983                               conclusion1984    The threat posed by Iran and other adversaries to our operational1985technology and critical infrastructure is indeed real and growing. With1986the implementation of the right policies, allocation of sufficient1987resources, and cultivation of robust partnerships, we can collectively1988build a more resilient and secure Nation. Thank you again for the1989opportunity to testify. I look forward to your questions.1990                                 ______19911992                                    March 21, 2025.1993The Honorable John Thune,1994Majority Leader, U.S. Senate, Washington, DC 20510.1995The Honorable Charles Schumer,1996Minority Leader, U.S. Senate, Washington, DC 20510.1997The Honorable Mike Johnson,1998Speaker, U.S. House of Representatives, Washington, DC 201515.1999The Honorable Hakeem Jeffries,2000Minority Leader, U.S. House of Representatives, Washington, DC 20515.20012002Via Electronic Mail20032004    Dear Majority Leader Thune, Minority Leader Schumer, Speaker2005Johnson, and Minority Leader Jeffries: As the 119th Congress begins, we2006urge Congress to extend the September 30, 2025 expiration date for the2007Cybersecurity Information Sharing Act. This bipartisan legislation2008passed in the wake of the 2015 OPM breach and sought to ``encourage2009public and private sector entities to share cyber threat information,2010removing legal barriers and the threat of unnecessary litigation.''\1\2011This voluntary information sharing framework has been instrumental in2012strengthening our collective defense against cybersecurity threats that2013continue to grow in sophistication and severity.2014---------------------------------------------------------------------------2015    \1\ Consolidated Appropriations Act, Pub. L. No. 114-113, Div. N,2016Title I--Cybersecurity Information Sharing Act, 129 Stat. 2935 (2015),20176 U.S.C.  1501; S. REP. NO. 114-32, at 2 (2015).2018---------------------------------------------------------------------------2019    Recent events underscore the imperative of continuing to support2020both private-public information sharing and collaboration as well as2021providing the legal clarity that companies currently count on to share2022cyber threat information with other companies and across sectors.2023Nation-state hackers have launched numerous attacks on U.S. critical2024infrastructure \2\ signaling they are positioning for bigger, more2025disruptive attacks. Federal agencies have similarly been targeted--most2026recently the Treasury Department in the BeyondTrust breach,\3\ but also2027during the SolarWinds incident where 9 agencies were compromised.\4\2028---------------------------------------------------------------------------2029    \2\ Dustin Volz et al., How Chinese Hackers Graduated From Clumsy2030Corporate Thieves to Military Weapons, WALL ST.J. (Jan. 4, 2025),2031https://www.wsj.com/tech/cybersecurity/typhoon-china-hackers-military-2032weapons-97d4ef95; Office of the Dir. of Nat. Intelligence, SolarWinds2033Orion Software Supply Chain Attack (Aug. 19, 2021), including our2034communications systems--https://www.dni.gov/files/NCSC/documents/2035SafeguardingOurFuture/SolarWinds%20Orion%-203620Software%20Supply%20Chain%20Attack.pdf.2037    \3\ Arielle Waldman, CISA: BeyondTrust breach affected Treasury2038Department only, TECHTARGET (Jan. 7, 2025), https://www.techtarget.com/2039searchsecurity/news/366617777/CISA-BeyondTrust-breach-impacted-2040Treasury-Department-only.2041    \4\ Office of the Dir. Of Nat. Intelligence, SolarWinds Orion2042Software Supply Chain Attack (Aug. 19, 2021), https://www.dni.gov/2043files/NCSC/documents/SafeguardingOurFuture/SolarWinds-2044%20Orion%20Software%20Supply%20Chain%20Attack.pdf.2045---------------------------------------------------------------------------2046    In the decade since its enactment, the law has meaningfully2047improved the capacity and speed with which we can respond to large-2048scale cyber incidents while establishing clear expectations for privacy2049and confidentiality. This includes building the structures used by2050private-sector cyber defenders to inform Government partners of ongoing2051cyber threats from malicious actors. Equally as important, the law's2052antitrust exemption and associated protections have also facilitated2053broader cyber information sharing between private companies. Private-2054sector cyber defenders, including those from critical infrastructure2055entities regularly targeted by foreign threat actors, depend on threat2056indicator sharing from other companies to strengthen their defenses and2057protect their customers' data. A lapse in the legal framework provided2058in the Act could limit this sharing. These communication channels are2059essential for enhancing overall awareness of national security threats2060and quickly responding to incidents. Given that value, these statutory2061provisions have been incorporated by reference to other significant2062cyber laws like the Cyber Incident Reporting for Critical2063Infrastructure Act--making their reauthorization all the more2064critical.\5\2065---------------------------------------------------------------------------2066    \5\ See 6 U.S.C.  681e.2067---------------------------------------------------------------------------2068    The aforementioned attacks demonstrate the urgent need for2069increased collaboration and information sharing. The expiration of2070these protections risks creating a chilling effect on this critical2071information exchange--leaving us all more vulnerable to nation-state2072attacks and cyber criminals moving forward. Thank you for your2073leadership on this important issue and we are committed to working with2074you to preserve these key national security authorities.2075            Sincerely,2076                            Alliance for Digital Innovation2077                               American Bankers Association2078                          American Public Power Association2079                                      Bank Policy Institute2080                                 Business Software Alliance2081                                  Edison Electric Institute2082                   Independent Community Bankers of America2083                    Information Technology Industry Council2084                         Institute of International Bankers2085            National Rural Electric Cooperative Association2086             Operational Technology Cybersecurity Coalition2087     Securities Industry and Financial Markets Association.20882089    Mr. Garbarino. Thank you very much.2090    I now recognize Dr. Gleason for 5 minutes to summarize his2091opening statement.20922093STATEMENT OF NATHANIEL GLEASON, PH.D., PROGRAM LEADER, LAWRENCE2094                 LIVERMORE NATIONAL LABORATORY20952096    Mr. Gleason. Chairman Garbarino, Ranking Member Swalwell,2097and Members of the subcommittee, thank you for the opportunity2098to testify today. My name is Dr. Nate Gleason. I'm the program2099leader for the Cyber and Infrastructure Resilience Program at2100Lawrence Livermore National Laboratory in Livermore,2101California. I lead a multidisciplinary team that works to2102develop technologies to develop--to address nation-state2103threats in the domain of gray zone conflict. Our primary2104emphasis is on the role of critical infrastructure and national2105security. I appreciate the committee's interest in our work,2106particularly your visit to the Lab earlier this summer, which2107reflects your commitment to bolstering the Nation's2108cybersecurity. I'm honored to be here on behalf of Lawrence2109Livermore and National Nuclear Security Administration2110Laboratory and a proud member of DOE's Network of National2111laboratories.2112    Nearly everything we do as a Nation, from energy2113transmission to projecting force around the globe depends on2114critical infrastructure. This makes these systems prime2115targets. Our adversaries are highly capable and invest heavily2116to hold our infrastructure systems and the functions that2117depend on them at risk. To defend against this threat,2118Government and the private sector must partner to out-innovate2119the competition and bring our best technology into operations.2120    One way CISA helps address this need is through the2121CyberSentry program. Since 2020, it has looked to Lawrence2122Livermore for core support for CyberSentry, with our role being2123to develop and deploy advanced analytics to monitor and hunt2124for threats. Through CyberSentry, cyber researchers gain real-2125time access to operational networks and can leverage2126significant investments in national laboratory computational2127and analytical capability, combined with information from the2128intelligence community, to develop and deploy tools to detect2129the latest attack techniques.2130    As one example of program success, in 2022, we detected2131high-risk Chinese surveillance cameras, just like these on the2132table in front of me, that were stealthily built into U.S.2133infrastructure systems. We leveraged our Skyfall laboratory to2134develop an advanced beacon detection analytic that increased2135sensitivity to detect these threats while improving selectivity2136to dramatically reduce false positives. When we deployed the2137analytic to CyberSentry partners, almost immediately our2138analysts detected anomalous beacons on the OT network of a2139participating company. Our team identified the beaconing device2140as a camera manufactured by the Chinese company Dahua.2141Livermore developed a machine learning model to detect these2142devices at scale and deployed it. We found cameras on most of2143the participating CyberSentry entities, in some cases hundreds2144of them.2145    Network traffic showed that these devices were beaconing to2146suspected hostile overseas servers. Some appeared to be2147transmitting encrypted video. Reverse engineering of the2148devices revealed they were also capable of providing a backdoor2149to any connected network. Notably, these devices were mostly2150sitting on OT networks, providing direct access to the physical2151processes.2152    We worked with CISA to create and publish a set of2153playbooks that went out broadly to help asset owners who are2154not part of CyberSentry detect these devices on their own2155systems. This illustrates how the CyberSentry partnership2156between just a few dozen critical infrastructure asset owners,2157national labs, and CISA enhances cybersecurity across U.S.2158critical infrastructure.2159    It's important to recognize detection represents just one2160aspect of defense against cyber threats to our infrastructure.2161The current threat picture demands a multilayer approach. At2162Livermore, we use what we call the Immune Infrastructure2163Framework. This 4-layer approach recognizes that we can't stop2164all attacks and instead, seeks to make it as difficult as2165possible for adversaries to achieve their goals.2166    Layer 1 focuses on understanding critical infrastructure2167systems through modeling, simulation, and analysis. This2168essentially allows us to look at U.S. infrastructure through2169the eyes of our adversaries. Layer 2 attempts to keep the2170adversary out of our systems through supply chain assurance.2171Layer 3 focuses on detecting and responding to intrusions. We2172put significant focus on addressing the previously unseen over2173the horizon threats that China, Russia, and Iran are developing2174that could hold our systems at risk. In layer 4, we engineer2175our systems to operate through compromise by using techniques2176like collaborative autonomy, which are designed to provide2177redundant decentralized control of systems.2178    While all 16 critical infrastructure sectors are important,2179we pay particular attention to energy, water, transportation,2180and communication because of their close connection to national2181security. The energy sector is among the most forward-leaning2182in cybersecurity. Its Sector Risk Management Agency, DOE CESER,2183invests resources in creating capabilities for the energy2184sector that, in coordination with CISA, help set the pace for2185other sectors. CESER is currently working to ensure that AI can2186be securely integrated into energy sector operations. Livermore2187is leading its analysis of potential risks and benefits of AI2188in the energy sector. We are also developing testbeds to assess2189the security and efficacy of various AI capabilities for the2190sector.2191    Another way CESER is working to enhance cybersecurity is2192through its Energy Cyber Sense Program, which focuses on supply2193chain security. We also work closely with the Defense2194Department on defense-critical infrastructure. Through this2195work we have identified how adversaries with advanced knowledge2196of our infrastructure and interdependencies that exist between2197components could exploit multiple assets simultaneously to2198create cascading damage far worse than any single point attack.2199    Thank you again for the opportunity to testify. I would be2200happy to answer any questions.2201    [The prepared statement of Dr. Gleason follows:]2202                   Prepared Statement of Nate Gleason2203                             July 22, 20252204    Chairman Garbarino, Ranking Member Swalwell, Chairman Green,2205Ranking Member Thompson and Members of the subcommittee, thank you for2206the opportunity to testify today.2207    My name is Dr. Nate Gleason, and I am the program leader for the2208Cyber and Infrastructure Resilience Program at Lawrence Livermore2209National Laboratory (LLNL) in Livermore, California. I am honored to be2210here today on behalf of LLNL, a National Nuclear Security2211Administration (NNSA) laboratory and proud member of the Department of2212Energy's network of national laboratories.2213    At the Lab, I have the privilege of leading a multidisciplinary2214team that includes operational technology (OT) cyber experts, threat2215hunters, reverse engineers, data scientists, electrical/chemical/civil/2216mechanical engineers, computer scientists, systems analysts and2217intelligence analysts in a program focused on providing the United2218States with technologies to effectively compete with nation-state2219adversaries like Russia and China in the domain of gray-zone conflict.2220Our primary emphasis is on the role of critical infrastructure in2221national security. I sincerely appreciate the committee's interest in2222the work we do in support of the Cybersecurity and Infrastructure2223Security Agency (CISA), the Department of Energy (DOE), the Department2224of Defense (DOD), and U.S. critical infrastructure writ large, as2225evidenced by your visit to the lab earlier this summer.2226    Nearly everything we do as a Nation, whether it be critical2227national functions like energy transmission or our ability to defend2228our homeland and project force around the globe, depends on critical2229infrastructure. As reflected in reports on Volt Typhoon and other2230threat actors, our adversaries see our critical infrastructure as an2231attractive target. As CISA and the intelligence community (IC) have2232acknowledged, these adversaries seek to pre-position themselves on U.S.2233critical infrastructure networks for disruptive or destructive cyber2234attacks. These adversaries are highly capable and invest significant2235resources in developing capabilities to hold our infrastructure2236systems, and the functions that depend on them, at risk. To defend2237against this threat, the United States must out-innovate the2238competition, work across Federal, State, and local authorities, and2239link with the public and private sectors to bring our best technology2240into operations.2241                              cybersentry2242    CISA plays a key role in bolstering critical infrastructure2243cybersecurity. The CyberSentry program is an excellent example of how2244CISA leverages government capabilities to identify and mitigate highly2245consequential cyber threats targeting critical infrastructure, and I2246would like to thank the committee for its leadership on this program.2247    Through CyberSentry, CISA works with private-sector partners who2248volunteer to have their systems monitored for malicious activity.2249Participants are from a wide range of critical infrastructure sectors2250including energy; water and wastewater; transportation; chemical;2251nuclear reactors, materials and waste; food and agriculture; dams; and2252critical manufacturing. Since 2020, LLNL has provided core support to2253the program by developing advanced analytic capabilities and leveraging2254artificial intelligence (AI) to detect novel adversary techniques and2255then deploying those analytics to operationally monitor and hunt for2256threats in the partner networks.2257    CyberSentry is valuable because it provides cyber researchers real-2258time access to real-world systems and network data so that we can take2259information on adversary intent, capability, and activity from the IC,2260combine it with the technological and computational resources of the2261DOE national laboratories, and develop and deploy new tools to detect2262and mitigate the latest techniques of our adversaries. CISA uses the2263data generated from our work to then create alerts for the broader U.S.2264critical infrastructure operator and owner community.2265    2022 discovery of chinese surveillance cameras on u.s. critical2266                        infrastructure networks2267    One of LLNL's most notable contributions to the CyberSentry program2268was when, in 2022, we detected high-risk Chinese surveillance cameras2269that were stealthily built into U.S. critical infrastructure systems.2270CISA had asked LLNL to develop a capability to detect subtle malicious2271beaconing behavior that available tools could not detect. Using our2272hardware-in-the-loop laboratory (dubbed the ``Skyfall'' lab), LLNL set2273up an operational technology (OT) environment where we deployed various2274samples of beaconing malware and tested existing commercial and open-2275source tools. We then developed a more advanced beacon detection2276analytic that built on the performance of the existing tools, both2277increasing the sensitivity so that it could detect more subtle threats2278and improving the selectivity to dramatically reduce false positives,2279and deployed it in the CyberSentry environment.2280    Almost immediately after deploying the new analytic, our threat2281analysts detected anomalous beacons on the OT network of a2282participating company. Working with that critical infrastructure2283partner, we identified the beaconing device as a security camera2284manufactured by the Chinese company Dahua, which is listed on the2285Federal Communications Commission (FCC) Covered List.2286    With this detection, we were able to create a machine learning2287model to automate detection of these cameras and deploy it widely2288across participating CyberSentry partners. Working with CISA, we2289discovered that the majority of entities in the program had these2290cameras on their networks. In some cases, we found hundreds of these2291devices on individual networks.2292    Notably, not all of the devices detected were branded as Dahua2293devices; many other manufacturers, both foreign and domestic, sold2294devices that used the same components as the Dahua camera and were2295behaving identically. From the network traffic, we were able to observe2296the devices beaconing back to suspected hostile overseas servers. Some2297of the devices were observed sending what appeared to be encrypted2298video to those servers. After acquiring and analyzing some of these2299devices, our reverse engineers were able to identify additional2300functionality that could enable back-door access to any network to2301which the device was connected. For purposes of today's discussion, it2302is worth noting that many of these cameras were sitting on OT networks,2303potentially granting access to control the physical processes in our2304infrastructure.2305    CISA partnered with the Department of Energy's Office of2306Cybersecurity, Energy Security and Emergency Response (CESER) and the2307DOE Office of Intelligence and Counterintelligence (DOE IN) to2308communicate our findings, first throughout the IC and then broadly out2309to the energy sector. Among the products of this collaboration was a2310set of playbooks we created that were published by CISA that allowed2311asset owners to detect these devices in their own systems. In this way,2312the security gains derived from this partnership between a few dozen2313critical infrastructure asset owners and CISA reverberated widely2314across U.S. critical infrastructure.2315                    immune infrastructure framework2316    Detection and mitigation represent just one aspect of defense2317against nation-state cyber threats to our critical infrastructure.2318Today, we are dealing with highly-capable adversaries who bring a wide2319spectrum of capabilities to bear, including network operations, supply2320chain compromise, insider access, and close-access operations. The2321current threat picture demands that we take a multi-layer approach to2322ensure the resilience of the functions that depend on our2323infrastructure.2324    At LLNL, we approach the challenge of securing U.S. critical2325infrastructure through a structure called the ``Immune Infrastructure2326Framework.'' We developed this framework to help define the parameters2327of critical infrastructure resilience and identify strengths and gaps2328in our Nation's capabilities. It is largely reflected in the approach2329taken within DOE to help protect the energy sector, including the DOE2330Cyber Resilience R&D Capabilities Catalog issued by the DOE Chief2331Information Officer (CIO). The Immune Infrastructure Framework accepts2332that it is not practical to prevent all compromises, and structures2333defense in 4 layers to make it as difficult as possible for adversaries2334to achieve their goals and enable our critical infrastructure to2335operate through compromise.2336   Layer 1 focuses on understanding U.S. critical2337        infrastructure systems. This involves developing tools to2338        characterize, model, and analyze our critical infrastructure so2339        that we can understand our vulnerabilities and also identify2340        where the most attractive targets for an adversary might be.2341        This essentially allows us to look at U.S. infrastructure2342        through the eyes of our adversaries.2343   Layer 2 attempts to keep the adversary out of our systems.2344        This largely involves assuring our supply chain to minimize2345        both vulnerabilities and malicious functionality on the devices2346        and software we put into our infrastructure systems. A key2347        emphasis is on creating scalable capabilities to allow us to2348        exponentially increase the number of devices that can be2349        examined that are present within U.S. critical infrastructure.2350   Layer 3 focuses on detecting and responding to intrusions in2351        our systems. The majority of cyber attacks on critical2352        infrastructure come from lower-tier adversaries--individual2353        hackers, criminal organizations, hacktivist groups--and use2354        known malware and established tactics. The commercial security2355        industry is quite capable of detecting these threat signatures2356        and known adversary behaviors, so as a national laboratory we2357        focus on ``zero-day'' threats. We use advanced analytics and AI2358        in conjunction with information from the IC to detect novel2359        adversary tactics, capabilities, and activities that do not2360        necessarily involve malware. More specifically, as a national2361        security lab, we put significant energy toward assessing the2362        unique capabilities that China, Russia, and Iran are developing2363        that could hold our systems at risk that may never have been2364        seen before.2365   Layer 4 is about engineering our systems to operate through2366        compromise. Despite our best efforts, the most determined and2367        capable adversaries will compromise our systems; we must build2368        in resilience by leveraging the distributed nature of our2369        infrastructure and using techniques like collaborative2370        autonomy, a set of algorithms designed to provide redundant,2371        decentralized control of the system.2372              support for sector risk management agencies2373    As defined in Presidential Policy Directive 21, CISA coordinates2374the national effort to secure and protect against critical2375infrastructure risks, but securing our Nation's critical infrastructure2376is a distributed responsibility. There are 16 critical infrastructure2377sectors, with responsibilities distributed across Federal agencies,2378State and local governments, and asset owners and operators.2379    While all of the sectors are important, at LLNL, we pay particular2380attention to 4 sectors because of their close connection to national2381security concerns--energy, water, transportation, and communications.2382Sector Risk Management Agencies, such as DOE and DOD, have significant2383responsibilities to provide sector-specific expertise and coordinate2384activities within their sectors. We and our partners at other DOE2385national laboratories serve a vital connective tissue between Sector2386Risk Management Agencies, States, and local utilities and work directly2387with private-sector entities to help ensure efforts are coordinated.2388    Among the sectors, the energy sector tends to be one of the most2389forward-leaning about cybersecurity because of the interdependencies2390between energy and every other sector. For its part, DOE CESER invests2391resources in creating capabilities for the energy sector that, in2392coordination with CISA, help set the pace for other sectors. For2393example, DOE is leaning forward to support industry in integrating AI2394securely. LLNL is leading CESER's analysis of the potential risks and2395benefits of AI to the energy sector. We are also developing testbeds2396for CESER to assess both the security and efficacy of various AI2397capabilities for the energy sector and researching new AI capabilities2398to improve the security and resilience of U.S. energy infrastructure.2399    Another way CESER is working to enhance the cybersecurity of the2400energy sector is through its Energy Cyber Sense Program which2401illuminates and reduces vulnerabilities to supply chains. LLNL leads2402national security-focused efforts as part of this work. LLNL also2403develops advanced tools and methodologies to understand and automate2404supply chain assurance with some of the critical partners in industry2405involved in these efforts.2406    In addition to our work on behalf of CISA and CESER efforts, our2407program has worked closely with the DOD, DOE, and CISA on efforts to2408enhance the security and resilience of Defense Critical Infrastructure2409(DCI). These assets are those portions of our Nation's infrastructure2410that directly contribute to the mobilization and sustainment of2411military forces. We lead DOE's Defense Critical Energy Infrastructure2412analysis efforts and support multiple offices in DOD for broader DCI2413efforts. Our work has been critical in identifying potential risks2414posed by adversaries who, with advanced knowledge of our infrastructure2415and the interdependencies that exist between different components,2416could target assets in combination to cause damage that could not be2417realized in a single attack against one asset. LLNL's high-performance2418computing modeling and simulation capabilities and advanced2419optimization tools, codified in the Octopus and Teragrine toolsets,2420move beyond traditional natural hazard-focused planning processes which2421often only consider failures of single system elements and are not2422designed to identify cascading consequences from multiple simultaneous2423disruptions.2424                               conclusion2425    Thank you again for giving me the opportunity to share with you how2426LLNL, as a DOE national laboratory, deploys its multidisciplinary teams2427in partnership with CISA, CESER, DOD and other Federal partners to2428bolster the cybersecurity of the Nation's critical infrastructure2429systems and advance U.S. national security. I would be happy to answer2430any questions.24312432    Mr. Garbarino. Thank you, Dr. Gleason.2433    Members will be recognized by order of seniority for their24345 minutes of questioning. An additional round of questioning2435may be called after all Members have been recognized.2436    I recognize the gentleman from Florida, Mr. Gimenez, for 52437minutes.2438    Mr. Gimenez. Thank you, Mr. Chairman. Let me congratulate2439you on winning the Chairmanship of the entire committee. It Is2440well done and I look forward to working with you.2441    I also share the concerns of the Ranking Member about the2442reauthorization of CISA 2015. Now that the Chairman of the2443subcommittee, now the Chair of the entire committee, I am sure2444that we're going to be accelerating that process. It is a clean2445reauthorization, but then eventually we are going to have to2446look and see how we can tweak that. But first, we need a clean2447reauthorization.2448    Ms. Zetter, I am curious about the viruses and the malware,2449and I am wondering if they are starting to act like real2450viruses. A real virus, when they enter the body and the body2451starts to attack it, can react, it evolves to defend itself.2452Have you seen that progress with computer viruses, with cyber2453viruses? Ability of a virus to evolve so that it can protect2454itself from any kind of defense mechanism?2455    Ms. Zetter. We've seen the early stages of that. I don't2456think that we've seen something that's fully, I would say,2457mature and operational. Rob has a better idea of that because2458he deals with the malware that comes in. But we've seen sort-2459of--even sort-of hints of that, even years ago, just not fully2460developed. Obviously, now with AI, that opportunity exists to2461make something even more autonomous, and also the ability to2462morph very rapidly to the environment.2463    Mr. Gimenez. Interesting that is a scary thought, right?2464That whatever we do, the virus will protect itself somehow and2465find a new way to do what it needs to do.2466    I also, you know, I agree that OT is actually the more2467important aspect of cyber attack. That is really the stuff that2468is really going to hurt us, cause accidents, kill people,2469disrupt everything that we do. You know, I mean, if I can2470foresee a day where, you know, somebody presses a button and2471the next, all the lights go out in North America, right? That2472would be a little bit disruptive, I believe.2473    Ms. Bolton, you talked about the lack of coordination here2474in the United States. I would think that if you kind-of map out2475who has got what, who is responsible for what, it would look2476like a bowl of spaghetti. Am I too far off?2477    Ms. Bolton. I'd say you're not very far off at all. I think2478there are a wide range of frameworks that are in place, a wide2479range of coordination mechanisms, as Rob mentioned in his2480testimony. Also difficulty for the industry to come into the2481Federal Government. There's not one specific door. There's not2482one agency that's responsible for cyber incident response. So2483they all work together.2484    So--but we've got local and State agencies responding to2485incidents. You've got vendors and industry. You've also got2486Federal Government involvement. So I absolutely believe that we2487need to streamline that process. I know the committee is2488working on harmonization, cyber harmonization. We very much2489support that effort because we need to have one easy way, one2490door for the industry to come into the Federal Government for2491support, and then also for the response and collaboration to be2492more clear.2493    Mr. Gimenez. Now, you said that they work with each other,2494but do they really? Don't they--do you see turf guarding a lot?2495    Ms. Bolton. I can't say that we don't see turf guarding. I2496will say that there are experts, national security, you know,2497professionals who are absolutely intent on securing the2498networks for which they're responsible.2499    Mr. Gimenez. But a lot of people will say, well, that's, is2500really, my realm. Well, no, it is my realm and all. I mean,2501look, that is just the norm in any bureaucracy, OK? So we have2502so many agencies doing the same things, that is a natural2503tendency of bureaucracy to try to protect themselves, OK, and2504turf guard.2505    Mr. Gleason, in terms of China, I serve on the Select2506Committee on China, and I have been calling for--we cannot2507decouple fast enough from China. Things that may be innocuous,2508cameras, all right, there is nothing innocuous about them. They2509are malicious. They are relentless in their attacks on us. I2510mean, I was thinking, yes, cameras is one way. Then they report2511back to China. Right? They can also integrate themselves into2512the IT system. That becomes an OT problem, maybe. All right.2513    We had issues where I used to be the mayor of Miami-Dade2514County with cameras at our port system that was reporting back2515to China. We don't know what it was reporting, probably what2516kind of commerce we were doing at that port. We also found that2517they had infected our systems. They were just lying around. OK?2518We don't know what they were lying around for, but I am sure2519that it wasn't for a good purpose.2520    So what can we do to stop this, you know, this relentless2521attacks that we are getting from these systems?2522    I am sorry, my time is up and I yield back.2523    Mr. Garbarino. OK. I was going to say they can answer the2524question, if you want.2525    Mr. Luttrell. I will ask it for you.2526    Mr. Garbarino. I now recognize the gentleman from Texas,2527Mr. Luttrell, for 5 minutes.2528    Mr. Luttrell. If you are reading my notes, sir.2529    Mr. Gimenez. I stole it.2530    Mr. Luttrell. Yes. What can we do to--I don't even know how2531you scale something to this size. What can we do looking2532forward or looking downstream? I cast that out to Mr. Gleason,2533you can start.2534    Mr. Gleason. Yes, I think everything you are mentioning I2535would agree with. I think what this phenomena that we're seeing2536is, is China has recognized that critical infrastructure is a2537new domain of conflict. I think we are catching up to that2538still. They put a lot of energy into this. They are very good.2539We are not going to stop them.2540    One of the goals that we have with the approach we've2541taken, as I mentioned, the immune infrastructure framework, our2542goal is to make it as hard as possible for them to achieve2543their objective at each layer. That includes understanding what2544they're trying to do. It includes securing our supply chains,2545includes detecting, responding, and, most importantly, it2546includes building our systems so that we can live even if they2547compromise them. That doesn't make our mission fail.2548    Mr. Luttrell. The cyber defense is very reactionary. We2549have no idea what's coming at us. The challenging part, I think2550personally, is, you know, and I am not speaking for--look, I2551mean there is only 4 of us. It is hard to dork out on2552cybersecurity, cyber risk, and cyber threat. You really got to2553be passionate about this. The number of subject-matter experts2554that walk into our offices every single day that say they are2555the absolute best at what they do is mind-numbing.2556    The committee is very open-minded to the collective, your2557group, of saying the best way forward to defensively and2558offensively, this is what we need. This is most likely the best2559way forward OT, IT. OK. How do we get that done? Because it2560changes every single second of every minute of every hour of2561every day. The cyber profile, the cyber technology, the cyber2562understanding, everybody is trying to be--to outdo somebody2563else. Again, very reactionary. How do you defend against2564something like that?2565    Ms. Bolton. So I would say we need to start even at the2566very beginning. Most agency--most sectors have not done an OT2567asset inventory. So they don't even know what they have.2568    Mr. Luttrell. Scale that to the Continental United States.2569    Ms. Bolton. Absolutely, absolutely. So I'll give you an2570example. There was an incident response team that went out to a2571pipeline, this was several years ago. They asked them how many2572open ports or ports they have. They said, well, just these that2573you see in this room here, and that was all their IT systems.2574By doing investigations through the internet billing that that2575pipeline had, they found they had over 10,000 open unprotected2576ports. So that's--you know, you need to be able to at least on2577some kind of spreadsheet be able to tell what you have in order2578to be able to start fixing it. That includes things like2579putting in multifactor authentication where it's possible,2580doing supply chain security, as you said, building defense in-2581depth, and building resilience.2582    Mr. Luttrell. Is that even a probability to do?2583    Mr. Lee. Yes, if I could add to that, we very much know2584what to do. But again, if you think about it from a Government2585perspective with private sector, if I'm in the water sector and2586I'm trying to look to CISA, EPA, and all the other components2587and players on what should I focus on, there's a lot of go be2588cyber safe, go be cyber secure, go do cyber, cyber, cyber2589something. Not actual guidance, not, well, we want to prepare2590for Volt Typhoon. This is what we're looking at. Here is what2591we think success looks like. However you want to figure it out,2592go, and then resourcing it. Like, we have the technologies that2593exist, we have the people trained, but there is a lot of2594overlapping guidance and it's paralyzing the private sector.2595    Mr. Luttrell. We weren't ready for Volt Typhoon and2596Stuxnet. Ms. Zetter, I am going to shift over to you. I don't2597know how long whomever created that and handed that football2598off to where it landed. I mean, but the technology in the early25992000's is not the same as it is in 2025 with the use of AI,2600AGI. I am assuming that you can take the baseline algorithm2601from Stuxnet because it had a few bugs in it. That is how we2602found it, if I am speaking correctly. When they started digging2603in and found Stuxnet, there were just a small bit of glitches2604in there. Like, all right, here it is. Now we are tracking.2605Then we unpacked it and, OK, here it is.2606    Ms. Zetter. The core--I'm sorry.2607    Mr. Luttrell. Yes, ma'am, go ahead.2608    Ms. Zetter. The core of Stuxnet did not have glitches, but2609the spreading mechanisms were reckless and it caused Stuxnet to2610spread around the world, and this is why it got caught?2611    Mr. Luttrell. OK. Are we doing--OK. Well, I am going to2612make the assumption that since that thing has been handed back2613to us and globally, that technology and AI, AGI will advance2614Stuxnet, SolarWinds in some way, and we won't be able to not2615only keep up, catch up, but I am assuming there is a2616probability that it is just going to outrun everything. Is that2617a fair statement?2618    Ms. Zetter. Yes. I mean, the details that I provided in the2619written testimony goes in depth into how Stuxnet operated and2620how sophisticated it was. That was state-of-the-art in 2010,2621and it was really genius the way that it was designed. If you2622can imagine now, 15 years later, how much more advanced that2623that should be at this point.2624    Mr. Luttrell. Yes.2625    Ms. Zetter. Then also with AI, then, yes, it's going to2626really fast forward.2627    Mr. Luttrell. I yield back.2628    Mr. Garbarino. The gentleman yields back. Thank you very2629much.2630    I now recognize Ranking Member Mr. Swalwell for 5 minutes2631of questioning.2632    Mr. Swalwell. Thank you. As part of the fiscal year 20222633NDAA, the National Defense Authorization Act, Congress2634authorized the CyberSentry program, which deploys sensors on a2635voluntary basis on critical infrastructure partners in order to2636detect malicious activity, as I noted in my opening statement.2637A critical part of that program is the role that Lawrence2638Livermore National Laboratory plays in analyzing CyberSentry2639data.2640    Dr. Gleason, what is the current status of Lawrence2641Livermore's partnership with CISA on CyberSentry?2642    Mr. Gleason. We've supported CISA in various aspects of2643critical infrastructure security for about a decade. Currently,2644we have agreements that are making, our funding agreements, are2645making their way through DHS processes. Unfortunately, those2646are still making their way through DHS processes. Our work with2647CISA expired last Sunday.2648    Mr. Swalwell. What does it mean that it expired? Is it2649turned off? Are you able to operate without authorities or2650funding? What is the posture right now for this important work?2651    Mr. Gleason. National laboratories are not legally able to2652operate without being funded by a Government agency. So our2653threat-hunters stopped monitoring networks on Sunday.2654    Mr. Swalwell. Who needs to turn it back on?2655    Mr. Gleason. We need the interagency agreement between DHS2656and DOE to be completed.2657    Mr. Swalwell. Would this be a sign-off from the Secretaries2658of both Energy and Homeland Security?2659    Mr. Gleason. Somewhere in that chain, yes. I'm not2660completely familiar with the funding processes that exist in2661those agencies right now, but yes, it needs to be signed off by2662both organizations.2663    Mr. Swalwell. Earlier in your testimony, you alluded to2664some cameras and malicious activity that you had found that2665have been Chinese-placed. Is that the type of work that the2666Sentry program does?2667    Mr. Gleason. Absolutely. We're looking for threats that2668haven't been seen before. We're looking for threats that exist2669right now in our infrastructure. One of the great things about2670the CyberSentry program is it takes the research and marries it2671with what is actually happening on the real networks. So we're2672not just doing science projects. We're deploying that2673technology out in the real world, detecting real threats.2674    Mr. Swalwell. Just so I understand you have--so you now2675with the program that has at least lapsed, or hopefully2676temporarily lapsed, the sensors are still deployed, is that2677right?2678    Mr. Gleason. That's correct. The sensors are still2679deployed. They're still gathering data. We just aren't2680analyzing the data that's coming in.2681    Mr. Swalwell. So I guess you are telling me because you2682don't have the funding, you are not allowed to look at the data2683legally. That is the problem.2684    Mr. Gleason. That's correct.2685    Mr. Swalwell. So, theoretically, we have deployed sensors2686on critical infrastructure, and there could be a malicious2687attack occurring right now that you are not legally able to see2688until the program is refunded.2689    Mr. Gleason. That is correct. Lawrence Livermore analysts2690are not able to monitor that data right now.2691    Mr. Swalwell. What is the risk of you being blind to what2692these sensors are detecting?2693    Mr. Gleason. I think everything that we've talked about in2694this hearing, we've seen how important critical infrastructure2695is to everything we do as a country. I think I'll echo a2696talking point I frequently hear from Dragos. One of the most2697important things is getting visibility into what's happening on2698our OT networks. We don't have enough of that. So losing this2699visibility through this program is a significant loss.2700    Mr. Swalwell. A major priority of mine has been to improve2701operational collaboration between the Federal Government and2702the private sector. To do so, CISA must have the appropriate2703forms for such collaboration, including the JCDC and CPAC.2704    Ms. Bolton, how can JCDC be strengthened so that it can2705better facilitate OT security collaboration? Why is it2706important that CPAC be restored?2707    Ms. Bolton. Thank you for the question. I think CPAC is an2708organization that allows industry to talk to the Government.2709Right now, industry is not able to convene with the liability2710protections that come or the information-sharing protections2711that come with CPAC authorities. So that becomes a bit of a--2712that becomes a problem. It's a national security concern when2713operational collaboration can't happen between those two2714entities.2715    I believe it's very important for CPAC authorities to come2716back. I think as much as possible, industry is continuing to2717try to work with--through other mechanisms. But there was2718nothing specifically like CPAC. We also are--we're continuing2719to work with JCDC and other areas within CISA on OT security2720issues. I think what we'd like to see from JCDC, if we're2721talking about additional work, is more concrete OT efforts that2722industry can get involved with from the ground up.2723    Mr. Swalwell. Great. Thank you.2724    Yield back.2725    Mr. Garbarino. The gentleman yields back.2726    I now recognize the gentleman from Tennessee, Mr. Ogles,2727for 5 minutes of questions.2728    Mr. Ogles. Thank you, Mr. Chairman, and thank you to the2729witnesses for being here.2730    Obviously, this is a high-stakes issue. I mean, it is the2731next battlefront, if not the battlefront, as we move forward.2732When you look at the China threat that Ms. Zetter, I think, you2733know, you have touched on, or all of you have touched on. But2734specifically I want to start with Ms. Bolton.2735    So formerly I was county executive in my community. What I2736can say is that, you know, although we were one of the fastest-2737growing counties in the State of Tennessee, No. 1 producer for2738manufacturing jobs in the State of Tennessee while I was county2739executive, I can tell you that from a cyber and IT/OT2740perspective, we were arguably vulnerable. Please expand on that2741vulnerability. When you look at bad actors as it relates to2742kind of, you know, just our infrastructure security and what2743the consequences might be if there was a coordinated systematic2744attack against those local communities.2745    Ms. Bolton. So a lot of what we see, and you're completely2746right, a lot of what we see is that the threat actors are2747targeting the most vulnerable organizations, right? Many times2748those are smaller organizations without cybersecurity2749expertise. They're at the county level, they're at the local2750level. You see actors either targeting those for, you know, for2751target practice, learning, and then moving to bigger systems,2752or they're doing it in a coordinated manner across a number of2753different States and localities. Particularly we see that in2754the energy sector, and they're using that as a means to prepare2755the battlefield, if you will, for if they're--in a contingency.2756    If it's China, for example, if they're sitting on our2757networks, that is extremely dangerous. Even if they're not2758conducting any particular operations right now, No. 1, we can't2759guarantee that they're off the networks. Even when we find2760them, we find them too late. We find them 3 years after the2761fact. What we don't want to have happen, if, for example, we're2762planning for a 2027 contingency, then we need to start doing2763the work now to build resiliency, defense-in-depth, the ability2764for those smaller local and county entities to be able to2765secure their--to secure all of those ports, right? Secure the2766remote access, put in stronger multifactor authentication,2767modernize their legacy IT. That's why I think it's so important2768to reauthorize the State and Local Cyber Grant Program, because2769without those resources, like I said, most of those localities2770are using the funding for physical security and not OT.2771    Mr. Ogles. Mr. Chairman, you know, again, coming from that2772local governance background, county executive, and I will speak2773for Tennessee, obviously everybody knows Nashville and knows2774Memphis, larger cities with more arguably or hopefully more2775robust systems. But a lot of Tennessee is rural, just like a2776lot of States across the country. What you see are electric2777cooperatives. So just like the county may be vulnerable to that2778infrastructure attack, my guess is in most cases, so are those2779local cooperatives, so is some of the water cooperatives as2780well.2781    So as we look forward to, again, the next battlefield and2782what keeps me up at night, and, quite frankly, Mr. Chairman,2783what I would argue, the most important, some of the most2784important work that we'll do on this committee, this whole2785committee, is what we are doing in cyber as we prepare this2786country for that next battle. It is going to be on our2787computers, it is going to be across our networks, and I would2788argue it is going to be in our local rural communities that2789they are going to hit first because then they can Swiss cheese2790our electrical grids and our water systems and our water2791treatment plants, et cetera. That is what keeps me up at night.2792    So with that, I would love to stay on this topic and just2793kind-of go down the line. We will start with you, Ms. Zetter,2794to see what you might want to add to this subject matter,2795please.2796    Ms. Zetter. I think you're absolutely right in terms of the2797small utilities and cooperatives like that. They don't have the2798money, they don't have the resources, they don't have the2799expertise on staff. They don't even hire security people. But I2800want to also say that, you know, we sort-of anticipate that the2801large organizations would be more secure. If you look at what2802happened to Colonial Pipeline in 2021, we see that this was2803really a major organization, critical infrastructure, supplying2804a lot of gasoline to the East Coast. Yet Colonial Pipeline, at2805the time that it was attacked, did not have a CISO on staff.2806They also had a legacy system that the attackers got in an old2807VPN account they were no longer using, but hadn't bothered to2808disable. They came in through a password that potentially was--2809well, it was leaked on the internet. So the employee who had2810the password had used it for other accounts, and then it was2811leaked on the internet and other breaches.2812    One other point about that was the attackers, we think,2813only got to the IT network, didn't actually make it to the OT2814network. But Colonial Pipeline shut down the pipeline because2815they feared that the attackers would get to the OT network and2816then encrypt it and lock it. But when the CEO of Colonial2817Pipeline testified to Congress, he testified that they had very2818secure, highly segmented OT and IT networks. But if they were2819that confident that the networks were segmented, then they2820wouldn't have had to shut down the pipeline as a precaution.2821    So I just want to say that, yes, those smaller entities are2822a big issue and a prime concern, but also the larger entities2823are having the same problems and not keeping up.2824    Mr. Ogles. Yes. Thank you, ma'am.2825    I apologize, Mr. Chairman, I am over time, but I yield2826back.2827    Mr. Garbarino. Not a problem. The gentleman yields back.2828    I now recognize myself for 5 minutes of questions.2829    We all know CISA plays an important role, sector risk2830management agency for 8 of the 16 critical infrastructure2831sectors, as well as the national coordinator of the sector risk2832management agencies. They do a lot of work. I would like to2833hear from you all. What do you think--how would you assess2834CISA's effectiveness is as a partner when it comes to OT2835cybersecurity? We can start with Ms. Zetter if you want.2836    Ms. Zetter. I don't have direct, because I'm not a2837practitioner, so I don't have that assessment to know first-2838hand. But what I do know is that CISA in the past had, I would2839say in the last decade, really, a lot of expertise that they2840were able to give to critical infrastructure, either to go out2841into the field and do critical assessments of the networks,2842give them risk assessments about what they needed to do, and2843then also they had flyaway teams that when a system was2844compromised, that they would be able to go out and assist2845directly in doing some kind of remediation. So I think that the2846impact of CISA has been really great. But, of course, they're2847limited in their resources and who they can operate--who they2848can give assistance to.2849    Mr. Lee. I would say that my commentary about CISA probably2850is reflective of a number of Government agencies that deal in2851this space, which is really good Americans trying really hard2852to do good work that have very talented people, but are hardly2853being effective for the amount of money we're spending on it in2854comparison to what's happening elsewhere. As an example,2855flyaway teams, the incident response teams, et cetera, there's2856absolutely nothing unique happening there in comparison already2857in the private sector. I think there's a very important role2858and responsibility for Government to play, and I think a2859focused CISA would be extremely impactful. You know, in2860passing, talked to Shawn Plankey, I'm really excited about the2861way they're looking at it now, but I think a lot of times we2862overstate the effectiveness.2863    I'm sure that this is not going to earn me any friends at2864CISA, and many of my friends are there, but I will say that2865we've got a couple of years before we have significant issues2866and I'm very concerned about the next couple of years going to2867war with China and it being focused on our OT. I would really2868like to move past pleasantries, so we should focus them a heck2869of a lot more.2870    Mr. Garbarino. Thank you.2871    Ms. Bolton. I would say that I think CISA, you know, can2872certainly grow in its effectiveness and I think we will see2873that under Sean Plankey. I think things like automated2874information sharing, the Einstein program, CyberSentry, I think2875there's a number of places there where we can modernize some of2876that legacy infrastructure. They're operating not necessarily2877with the most updated sensors. I understand that it is2878expensive to upgrade the systems. But if we want CISA to be2879acting as the, you know, the front-line defense for2880cybersecurity and as an expert, they need to have, you know,2881up-to-date systems. They need to have sensors on the networks2882that are what is modern right now. But I think that'll--that's2883about it.2884    Mr. Garbarino. Dr. Gleason.2885    Mr. Gleason. I would say some of our best and most2886effective work with CISA has been when they've worked in2887partnership with some of the other Federal departments with2888stake in the space, in particular with the Department of Energy2889looking at threats to the energy sector and the Department of2890Defense looking at defense critical infrastructure.2891    Just to echo on some earlier comments, I think CISA also2892works best when they do work that is appropriate to the2893Government to do and not trying to do what the private sector2894is already taking care of. The Government has specific2895advantages in our access to the intelligence community and the2896ability to do things that the private sector is not or2897shouldn't be doing. I think the more that the Government sticks2898to that space, the more effective that that those programs will2899be.2900    I also want to echo, I definitely look forward to Sean2901Plankey coming in and very excited about Nick Anderson coming2902in. We've had great experiences working with him previously and2903think their leadership will be very effective.2904    Mr. Garbarino. I think we can all agree that we are very2905excited to see Sean Plankey get confirmed as soon as possible.2906It will be a good day for, I think, for CISA to have him in2907there.2908    Mr. Lee, I want to go back to this. Because you were very2909passionate in your answer to that and you really want to get2910them focused. Can you go a little more in depth? Because this2911is, like, this is the stuff we are going to have to work on.2912    Mr. Lee. SANS Institute, which is the leading cybersecurity2913provider, analyzed every single industrial cyber attack that's2914happening ever taken place and just asked the basic question of2915what security controls actually worked. It was 5, and we know2916exactly what those 5 are, we know exactly how to do it. If you2917look at regulations, standards and everything else, it's not 5.2918    Further, when you look at our rural communities, as2919mentioned, about 98 percent of this country is in that sort-of2920below the cyber poverty line discussion. They're not doing2921pretty much anything unless it's really passionate members2922there trying to help. But going back to what Kim said as well,2923you've got a large number of companies that will stand up and2924say how robust their security programs are, and I'm in a lot of2925those environments and they're terrifying.2926    So I have 3 kids. I did not really want to go back in the2927Army for, you know, extra time. It was I really want to get2928this right. I think if we're going to be serious about the2929conversation, it's focus on what we can actually do across the2930next couple of years. Pick a point of view. You're going to2931upset some people in doing so, but we need to do it. At the2932same time, I would say you can roll out quickly.2933    I think about 95 percent, anecdotally, about 95 percent of2934all cyber spend goes to enterprise IT, about 5 percent to OT.2935That is where your national security is, your environments,2936your local communities, and all of your ability to generate2937revenue. You look at sort-of the visibility in this country. If2938you actually want to monitor your OT infrastructure, figure out2939is China already there, I would say probably about 10 percent2940of the infrastructure around the country is being monitored. So2941when we're having big discussions about what comes next, I2942would just highlight that we're not even really being serious2943about what we know today.2944    Mr. Garbarino. I appreciate that. Thank you very much.2945    We are going to start our second round of questions.2946    So I recognize, second round, the gentleman from Florida,2947Mr. Gimenez, for 5 minutes.2948    Mr. Gimenez. Thank you, Mr. Chairman. I am going to pivot a2949little bit. So do you all know what MAD is? Mutually assured2950destruction. MAD is not really all that MAD. MAD kept us safe2951for about, you know, 50 years, 60 years. Right. Where, yes, the2952Soviet Union had thousands of nuclear weapons, but so did we.2953If they ever used it, then we would use it on them. That kept2954us safe in a frightening kind of way, but it did. It kept us2955safe. All right.2956    So my question to you is, there is the Department of2957Defense, but part of the Department of Defense is the2958Department of Offense. So if we were just a--well, we are here2959to defend the homeland and we are going to play defense, well,2960you are inviting attacks because there is no counterpunch. What2961is our offensive capability? Where is your assessment of our2962offensive capability in this realm?2963    Mr. Lee. I'll take first pass that we are very, very good2964at our offensive capability. I think some concerns I have, you2965have to be able to get to root cause analysis on determining if2966we were attacked for us to go back and do something. I'm aware2967of numerous cases the Government is currently tracking as2968maintenance issues for explosions otherwise, that were actually2969cyber attacks. If we're not detecting what's happening, then2970we're just going to say, oh, it must have been something2971random, and we're never going to get offensive. But putting my2972military hat on now, even just down the 91st Brigade alone,2973we've got a lot of offensive capability and I would not want to2974be on the other side of us. But we also have to make it2975extremely hard for our competition to come back at us and at2976least know when they do it so that we can unleash our warriors.2977    Mr. Gimenez. Do we do that often enough? Do we flex our2978muscle often enough?2979    Mr. Lee. I think just looking back to testimony and2980commentary from Joe Nakasone, General Haugh, and others, I2981would say that we do not. I do not want to see an offensive2982world. I do not want to see targeting civilian infrastructure.2983But when our adversaries make it very clear that they want to2984hurt us and hurt our families, I think we have to be very2985serious about showing them that we can do the same.2986    Mr. Gimenez. I agree. So, I mean, if we actually flexed our2987muscle every once in a while, I mean, the DOD flexes its muscle2988every once in a while, right? So I guess you are saying we2989don't flex our muscle often.2990    Mr. Lee. I'm saying we don't flex it enough. But I would2991also advise that we had to be very serious on defense because2992we will see things back. Even if one agency in a Government2993authorizes something at us and we are doing something that we2994view to be retaliatory, other agencies in that same Government2995may not be aware of it unless we're able to call it out. Then2996all of a sudden you have a very escalatory situation.2997    Mr. Gimenez. You know, we have a new realm of warfare. I2998guess defense and offense is space. So we created the Space2999Force. Right? Should we create a Cyber Force?3000    Mr. Lee. I'll stick with it and then open up to the3001panelists. I think it's time. I was very against it when I was3002in the Air Force. I was very against it for the years after3003looking at how it was going to be orchestrated. I think it's3004time to do it, sticking to its OT&E mission of organizing,3005training, and equipping. Let Cyber Command and the Combatant3006Commands be the actual Title 10 authorities that we have. But3007we definitely need a dedicated service.3008    But I think if you're going to do it right, you have to do3009it extremely big and right because the problem that you'll have3010is all that infighting and the stuff that people say, oh, we3011politely work together in interagency. No, we don't. People are3012very territorial and people will keep their best cyber warriors3013to themselves.3014    Mr. Gimenez. So you are going back to my first round of3015questioning, right?3016    Mr. Lee. Yes.3017    Mr. Gimenez. That there is turf guarding.3018    Mr. Lee. There's a lot of turf guarding.3019    Mr. Gimenez. Or there is a lot of turf guarding. So I would3020figure that now with Space Force and the Air Force, there is3021probably a lot of turf guarding there. Right?3022    Mr. Lee. I don't see it as much myself, but I did leave the3023Air Force a while ago. I will say the Army would be very happy3024to have a Cyber Force under it from a department level, but I'm3025not so sure that it shouldn't just be made a department-level3026service.3027    Mr. Gimenez. OK, fair enough.3028    OK. That is all the questions I have, and I yield back the3029rest of my time. Thank you.3030    Mr. Garbarino. The gentlemen yields back.3031    I now recognize the gentleman from Texas, Mr. Luttrell, for30325 minutes of questions.3033    Mr. Luttrell. Good to hear you say--I have been working on3034that Cyber Force idea for a while, and General Haugh and I had3035some pretty interesting conversations behind closed doors.3036Absolutely a brilliant guy in his stance, but I think he was3037trying to protect the nest. But I think we are far enough along3038where a cyber force should be--absolutely, the conversation3039should be had.3040    To the conversations that you were having with the Chairman3041and you listed 5 things. I come from a very rural district and3042I have had CISA out to the district to talk to our business3043owners, but where is the piece of paper at? What can I hand off3044to everybody that is in my district and to my State and say,3045here, implementation of these 5 things will get you to a better3046place?3047    Of course, as you said, everybody is going to beat it up,3048because they are not going to be the ones that are involved in3049it or whatever. But, I mean, from our nursing homes to our3050banks to our school districts, they have all been hit. We have3051those--again, you heard me say it in my last line of question.3052Very reactionary because we don't know what we don't know.3053Where does that live? Hand it to me. I mean, help me out here.3054    Mr. Lee. Yes, sir. Yes. The SANS Institute published the 53055critical controls. It's been backed by other governments as3056well.3057    Mr. Luttrell. The what did?3058    Mr. Lee. The SANS, S-A-N-S, Institute.3059    Mr. Luttrell. Where does that live? Because if I walked3060into Conroe, Texas, and said, hey, go visit this place, they're3061going to look, I mean, they are looking at me like I am crazy.3062    Mr. Lee. Yes.3063    Mr. Luttrell. The legislation all the way up needs to be3064talking about it. I mean, I like to say we need to Facebook3065this thing so everybody and their cousin knows about it.3066    Mr. Lee. Yes, sir. Yes, I would love to see again3067Government have a single voice to say, here's actually what's3068working. As a rural guy from Alabama who joined the military,3069if I can figure it out, I promise everyone in your district can3070as well. But we need to speak again with one voice of3071Government. If CISA had a single page of here's the resources3072available to you, this is what you can do, and every agency3073around supported it instead of their own thing, I think you'd3074see a lot more outcomes.3075    Mr. Luttrell. If we do do that, will the bad actors3076globally pinpoint those specific IT, OT, and go after it, and3077then we are just dead in the water?3078    Mr. Lee. No, I don't think it would work in that such way.3079Even if you advertise broadly what your strategy for security3080is, it's the fact that your actually doing and implementing it3081that makes you defended. The fact that your adversary knows you3082want to invest in secure monitoring or secure mode access or3083monitoring, that doesn't make you any less secure.3084    Mr. Luttrell. Well, they will most likely look somewhere3085else.3086    Mr. Lee. I hope so. Right now it is way too easy to target3087our systems, and right now we are doing very little. I would3088love to raise the bar where they actually have to come up with3089something creative.3090    Mr. Luttrell. Raise it. I mean, you are sitting in front of3091the group that is sitting here, hey, we are asking you. I won't3092speak for my colleagues, but, hey, I am asking you right now,3093on record, do it. Bring it to us right now.3094    Mr. Lee. Yes, sir. Provide some written testimony, I'm3095happy to brief you at any time. I am trying my best.3096    Mr. Luttrell. I will absolutely see you after class, sir.3097    With that, Mr. Chairman, I yield back.3098    Mr. Garbarino. The gentleman yields back.3099    I now recognize the gentlelady from New Jersey, Mrs.3100McIver, for 5 minutes of questions.3101    Mrs. McIver. Thank you so much, Chairman. Thank you to our3102Ranking Member.3103    My district sits at the heart of our Nation's largest3104metropolitan area and is home to a major airport, one of our3105Nation's busiest ports, numerous railroads, and pipelines, and3106key industrial facilities, among other critical infrastructure.3107Securing these facilities requires resources and for publicly-3108owned critical infrastructure those resources have often been3109lacking. As part of the Infrastructure Investment and Jobs Act,3110Congress provided 1 billion to establish the State and local3111cybersecurity grant program. State and local governments can3112use this funding to strengthen the OT security of publicly-3113owned critical infrastructure. Unfortunately, under current3114law, the program is set to inspire to expire in just over 23115months.3116    Ms. Bolton, I have a question for you. How important is it3117to continue funding for the State and Local Cybersecurity Grant3118Program?3119    Ms. Bolton. I think it's critical to continue that funding.3120I mentioned in my testimony that most--a third of districts3121around the country are rural districts. Obviously that's not3122the case for your district, but I think it's still incredibly3123important. There are not only large ports and airports in your3124district, but also smaller entities, and those are the ones3125that really desperately need help.3126    I will add to your question earlier as well that CISA has3127released a top 5 OT cybersecurity guide. So I think that also3128can help to provide guidance to those entities as to what they3129can use their cybersecurity spend on. At OTCC we're also3130working on guidance as well.3131    Mrs. McIver. Thank you. Can you just elaborate a little bit3132more on how should State and local governments prioritize their3133resources to strengthen their OT security?3134    Ms. Bolton. So I think it's very important to start at the3135very beginning. We do know some of the controls that work and3136so we should put those in place. Multifactor authentication,3137segmenting, even micro-segmentation of networks, making sure3138that we are securing remote access.3139    Also I'd add that, you know, most of the attacks that are3140happening on our critical infrastructure aren't zero days.3141They're not the most sophisticated vulnerability or the most3142sophisticated attacks. They are using things that we've seen3143before, sometimes not changed at all, sometimes mildly changed.3144We continue to be hit by these attacks.3145    I think, for example, CISA releases a top 12 cyber3146vulnerabilities--top 12 routinely exploited vulnerabilities3147list. Why would the Government or any State entity still be3148able to buy those products off of that list? If one side of the3149Government is saying these are commonly and routinely3150exploited, we should never be allowed to buy those. So things3151like that I think are extremely important.3152    Mrs. McIver. Thank you so much. I want to thank the3153witnesses for being here today for providing testimony, and I3154really do appreciate the Chairman and the Ranking Member's, you3155know, steadfast focus on this issue and also being supporters3156of the reauthorizing of the State and Local Cybersecurity Grant3157Program. So I look forward to continuing to work with both of3158you in this committee to provide State and local governments3159the resources they so desperately need to secure their critical3160infrastructure.3161    With that, I yield back.3162    Mr. Luttrell. Will the gentlewoman yield? Can I borrow your3163minute?3164    Mrs. McIver. Sure.3165    Mr. Luttrell. This is piggybacking off one of the questions3166you asked. You said CISA listed 5 things as well. Is it the3167exact same list as what you are saying?3168    Ms. Bolton. No, it is not. This is another issue that we3169have.3170    Mr. Luttrell. OK. So there's a problem. I have now taking 23171lists----3172    Ms. Bolton. Yep.3173    Mr. Luttrell [continuing]. And saying here you go. Then3174that is an issue.3175    Ms. Bolton. Absolutely.3176    Mr. Luttrell. On top of those 2 and the 10,000, 100 million3177that everybody else brings to you. For a poor district like3178ours, like, I mean, yes, here we go.3179    Ms. Bolton. Yes.3180    Mr. Luttrell. Thank you very much.3181    Ms. Bolton. Well, and I will say this. The cybersecurity3182industry as a whole is, is aligned on things like implementing3183multifactor authentication, network segmentation, continuous3184monitoring and detection. But there are sort-of these3185conflicting guidances that do exist. Same with frameworks,3186conflicting frameworks for OT. So the people in your district3187or the operators in your district that are trying to just do3188the right thing, they don't know where to start.3189    Mr. Luttrell. Correct.3190    Ms. Bolton. Especially when it's like NIST Cybersecurity3191Framework 2.0, there's like 80 pages. Right? People who are3192running these OT networks don't have the knowledge to read3193through an 80-page document and know where to start. So one of3194the things is like NIST is creating some quick start guides. I3195think that would be very important to do for OT security.3196    Mr. Luttrell. Thank you. I yield back. Thank you, ma'am.3197    Mr. Garbarino. The gentlelady yields.3198    Thank you very much for your enthusiasm about State and3199local, the grant program. I hope it is something that we can3200get reauthorized right away. I think it could be a very big3201bipartisan issue.3202    I now recognize the gentleman from Tennessee, Mr. Ogles,3203for his second 5 minutes of questions.3204    Mr. Ogles. Thank you, Mr. Chairman.3205    Mr. Lee, I think you said 98 percent of communities were3206below the cyber poverty line?3207    Mr. Lee. Yes, Congressman, about--if you look at companies3208under about 100 million in revenue across all of our electric3209and water utilities, that's about 95 to 98 percent of them.3210    Mr. Ogles. Goodness gracious. So I want to go back and just3211double down on this issue. Again, coming from the county3212executive level and, you know, to my good friend to my left3213here, you know, his district as well, I am sure he is seeing3214the same thing, is that, you know, your IT director is also the3215guy that is setting up emails and plugging in keyboards and3216probably spends 60, 80 percent of his time not in his office,3217not at his desk, not being offensive because a good defense is3218a good offense, you know, looking for those weaknesses, looking3219for those back doors, looking for those left-around passwords,3220and such. So, and I will use the word ``framework'' in the3221context of more like a toolbox.3222    You know, I want to be careful here because, you know,3223borrowing from Reagan, you know, he said the scariest phrase in3224the English language is ``I'm from the Government and I'm here3225to help.'' What we don't want to do is create a monster that3226suddenly is nothing more than a big bureaucracy that is3227designed to grow and gobble up resources. But what I do see3228here, again, coming from that local background, is there is a3229vacuum here, there is a void. Quite frankly, our communities3230don't have the expertise. Even if they do have the expertise, I3231am not sure they have the bandwidth, bandwidth in the context3232of man or woman hours.3233    So we have got to figure out how we move forward and how3234we, quite frankly, equip some of our local communities.3235Because, again, if I am on the other side of the pond and I am3236seeing the opportunity that most moment to seize, I am going3237after the locals, I am going after those water systems and, you3238know, talk about creating pandemonium. Suddenly your small3239rural cooperative electric or water system goes down and it is3240not working and it is not coming back on-line for a few weeks.3241That has been Swiss cheese across the country. That is what,3242again, I go back having been the county executive, that is what3243keeps me up at night.3244    Mr. Chairman, I think my challenge to the committee is that3245is something that we need to work on, being careful not to3246create, again, a monster that grows and grows and feeds at the3247trough, that Government trough.3248    Then back to the whole idea of creating a department-level3249service with cyber force, I think that is incredibly,3250incredibly important. Because cyber is not just across the3251networks, it touches into the drones and the capability of3252jamming and all sorts of things. So those capabilities have to3253become--we have to lead on that frontier and, quite frankly,3254become untouchable in the same way we are untouchable in air3255space and communications.3256    With that, Mr. Chairman, I yield back.3257    Mr. Garbarino. The gentleman yields back.3258    I now recognize the Ranking Member, the gentleman from3259California, Mr. Swalwell, for his second 5 minutes of3260questions.3261    Mr. Swalwell. Dr. Gleason, what is the status of Lawrence3262Livermore's other partnerships, including its support for the3263National Infrastructure Simulation and Analysis Center?3264    Mr. Gleason. Those are in a similar status to our support3265for CyberSentry. Our work for National Risk Management Center,3266again, looking at infrastructure interdependencies and3267cascading consequences of disruption to infrastructure, has3268been going on for a decade. Our interagency agreement expired3269in March for that work.3270    Mr. Swalwell. What is the risk to what you are able to see3271or what you were able to see and what you don't see now as far3272as cyber vulnerabilities that are out there?3273    Mr. Gleason. I think one of the big things that we miss,3274and I want to emphasize the idea of cascading consequences. A3275lot of times when we're thinking about cyber attacks on3276critical infrastructure, the target may not be that3277infrastructure system itself. It may be what is supported by3278that infrastructure system. When we fail to understand those3279interdependencies, we are opening up avenues for our3280adversaries to disrupt key national security capabilities.3281    A great example of this is some of the capabilities on the3282territory of Guam. This is a small, very hard-working, very3283dedicated power company, but very under-resourced. Some of our3284most important capabilities for defending against a potential3285China invasion scenario are based in Guam. There are ways to3286defeat those capabilities that go through, for lack of a better3287word, the back door, by exploiting kind-of the weak underbelly,3288the under-defended part of our critical infrastructure because3289those are very small systems. By not understanding those3290interdependencies, it's not that they don't exist. Our3291adversaries know them. If we don't, we're not looking in the3292right place for our defense.3293    Mr. Swalwell. In just over 2 months, the--I am sorry, did3294someone else--you are good. In just over 2 months, the3295Cybersecurity Information Sharing Act of 2015, the other CISA,3296is set to expire and Mr. Gimenez alluded to this. It is3297essential that we act promptly to reauthorize it in a clean3298way. I am open to any reforms that we could discuss down the3299road under the Chairman's leadership of the full committee. But3300I think there is a wide consensus that we don't have time to do3301that now. Congress will be in recess, effective this week until3302after Labor Day, and then we will be right up against CISA's3303expiration.3304    Ms. Bolton, your testimony discusses the importance of3305reauthorizing CISA 2015. What would be the national security3306impact if the law lapses?3307    Ms. Bolton. The estimates are that about 80 to 90 percent3308of information sharing would be cut off from the Federal3309Government. When I was at the Cyberspace Solarium Commission,3310one of the main things that we tried to do was to make sure3311that the Federal Government at least had a full threat picture.3312This authority is part of that work, a significant part of that3313work. We must reauthorize it.3314    If we are about 2 years away from a contingency with China3315in 2027, as ODNI has said, then we have to be fully prepared.3316We have to be taking steps now and not just addressing, you3317know, the information-sharing piece. That should be a baseline,3318it should be a given, and we should be focused on the3319additional steps that we need to take.3320    So I hope that that gets reauthorized quickly and that we3321can move on to some of these other topics that we've been3322discussing and addressing some of the other extremely serious3323issues, because China is not waiting. China is preparing now3324and so are all our other adversaries.3325    Mr. Swalwell. Mr. Lee, your experience in the private3326sector, is there any world where CISA 2015 lapses and a3327private-sector company that has been hit would still be willing3328to come forward and share information with the Department of3329Homeland Security?3330    Mr. Lee. No, I think it's incredibly important to3331reauthorize it. The bidirectional communication from Government3332to private sector, especially on the threat picture overall, is3333exactly one of the roles and responsibilities that makes a lot3334of sense.3335    Mr. Swalwell. Then that's because no CISO would be able to3336go to the DHS without liability protection and their fiduciary3337duty to the shareholders. I mean, they would be exposing3338themselves to a lot of risk. Is that right?3339    Mr. Lee. Absolutely. That's actually a broader issue. Even3340looking from a National Guard perspective of could we go in and3341respond if a utility gets hit, we have no indemnification to3342give utilities. So they're not going to let us touch anything3343and do any action on it. There are very simple bureaucratic3344things that could be fixed to increase national security3345tomorrow.3346    Mr. Swalwell. Thank you. Yield back.3347    Mr. Garbarino. The gentleman yields back.3348    I can't agree with him and the witnesses more and my other3349colleagues that we have to reauthorize. We do have to change3350the name, though.3351    Mr. Swalwell. Yes.3352    Mr. Garbarino. OK. That has got to be at least one change3353we have to do. You know, I understand people want to do clean3354and we have to get it done, but I do want to hear from you all3355because I think there should be changes. There should be--it is3356a 10-year-old law and, you know, clean reauth it doesn't3357include things that we have learned over the last 10 years.3358    So I would like to hear from you all, is there language or3359are there changes or focuses that we should implement into the3360law that we should consider to ensure OT is better protected or3361covered?3362    Ms. Bolton. Well, I would just add that, and I think you3363all are already considering this, but including OT much more3364directly within the language. It's currently not in the bill or3365not in the legislation.3366    I would also say that identifying DHS and CISA as the main3367sort-of gateway for sharing would be ideal because, as we've3368spoken before, the confusion for industry of coming into and3369talking with the Federal Government, sharing information with3370the Federal Government, that remains a problem. We hear that3371all the time from our member companies and from other companies3372that I work with that they don't know where to go. They say,3373well I need to talk to--maybe I should talk to TSA, maybe I3374need to talk to FBI, and then maybe FBI will tell CISA. That3375can't be assumed. So we need to make sure that that language is3376clear within the legislation.3377    Mr. Lee. Yes, I would completely agree with that. Also3378there needs to be, here's what you get in return. Here is what3379we can do to help you because you gave us this information. A3380lot of times a lot of asset owners and operators feel that it's3381a one-way communication in the Government with no expectation3382of what comes out of it. You want somebody to go through the3383risk of sharing information? There's got to be a very clear and3384here's the rules of the road of what we can provide for you as3385a result, cross agency, without any drama.3386    We talked about turf wars. I led the OT portion of the3387incident response for Colonial Pipeline. I witnessed a lot of3388turf wars between FBI and CISA. It needs to be very clean or no3389asset owner-operator will want to work with them. They view3390them as children.3391    Mr. Garbarino. Yes, I've heard from a bunch of--it is very3392important this was a major part of my, by the way, my3393presentation to become Chair of the full committee was making3394sure that this does not lapse. So it is a top priority for me3395and as I know, for the other Members on the committee. I have3396spoken to many people in the private sector that said it would3397be devastating and they would not be able to talk to the3398Government if this expires, and it would be devastating for us.3399    I do want to get back to the Stuxnet, and, you know, we are3400very privileged to have Ms. Zetter here to talk about it. So I3401want to get it back into what is the significance of Stuxnet3402today and what lessons did we learn? What lessons should we3403have learned that we have not learned yet from it?3404    Ms. Zetter. I mean, the primary lesson is the focus on OT3405systems that Stuxnet showed the danger that weapons like this3406can have against critical infrastructure and, of course, not3407just doing what a normal virus does, but causing destruction. I3408think, also, the--basically the small utilities and the small3409organizations, I just want to emphasize that because it's been3410brought up a lot.3411    I talked about when you asked me how effective CISA has3412been, and I said that they've been effective in terms of3413providing these small organizations with a service that they3414can't otherwise get. The panelists had said that the CISA3415shouldn't be doing what local--or what private industry can be3416doing. The problem is that those small utilities and small3417organizations don't have the funds, or haven't had the funds,3418in many cases to actually get it privately. So they have relied3419on CISA for that kind of service. I think that when we have3420legislation, of course, that has that ability to provide the3421funds, that's really significant for those organizations, and3422that shouldn't go away.3423    So I think that the overall lesson from Stuxnet is that the3424capabilities out there are really sophisticated, really3425advanced, and we haven't seen the full use of the capabilities3426that Stuxnet showed, for various reasons. Probably deterrence3427is one of the good ones, at least from the U.S. perspective,3428that adversaries are, you know, having second thoughts about3429targeting U.S. infrastructure. But, also, I sort-of make a3430distinction between those who have the will and those who have3431the ability. Those who have the ability haven't until now3432really had the will to go after U.S. critical infrastructure.3433Those who have had the will, perhaps maybe terrorist groups,3434others, haven't necessarily had the ability. It doesn't take3435much to marry those two together. Even someone that has will3436and doesn't have ability can purchase that ability, can3437purchase that capability.3438    Now we're entering into a phase where even we've relied on3439the large nation-states, China and Russia, we've relied on them3440not having the will to target U.S. infrastructure. I think what3441we're talking about and going into potential conflict with3442China, we've reduced--we've eliminated that gate now, and they3443do have the will potentially to go after U.S. infrastructure.3444So I think that that's the lesson learned from Stuxnet.3445    Mr. Garbarino. That is a scary way to end this committee3446hearing, but I appreciate it, and that is a big concern for me,3447is when the people with the will and the ability are the same3448person. Because that is a scary thought, and that is what we3449have to be prepared for.3450    I want to thank all the witnesses and all the Members. I3451mean, the fact that so many people stuck around for second3452round of questions just shows you how important this topic is.3453So I want to thank you all for your valuable testimony, the3454Members for their questions.3455    The Members of the committee may have additional questions3456for the witnesses, and we ask that you all respond to those in3457writing. Pursuant to committee rule VII(E), the hearing record3458will be held open for 10 days.3459    Without objection, this committee stands adjourned.3460    [Whereupon, at 11:23 a.m., the subcommittee was adjourned.]34613462                           A P P E N D I X  I34633464                              ----------34653466  Statement of Ian Jefferies, President and Chief Executive Officer,3467                   Association of American Railroads3468                             July 22, 20253469                              introduction3470    On behalf of the members of the Association of American Railroads3471(AAR), thank you for the opportunity to submit this statement for the3472record regarding the rail industry's work to address cybersecurity3473threats, including our on-going collaboration with the Government.3474AAR's freight railroad members include the 6 Class I railroads, as well3475as scores of U.S. short line and regional railroads. Together, they3476account for the vast majority of freight railroad mileage, employees,3477and traffic in the United States.3478    Freight railroads integrate skilled personnel and ingenuity with3479technology to keep the network infrastructure safe and the supply chain3480moving every day. Advanced information and communications technologies3481are helping our employees across all aspects of operations, including3482train control, track and equipment inspections, emergency response,3483dispatching, railcar tracking, locomotive fuel management, predictive3484performance analysis, employee training, and more. Cybersecurity is an3485on-going arms race between attackers and defenders, which is why our3486highly-skilled, highly-trained employees work diligently to continually3487strengthen their capabilities and guard against cyber attacks that3488threaten the safety and integrity of rail operations. Railroads3489continually evaluate and enhance cybersecurity through recurring3490exercises and frequent consultations with Government and private-sector3491security experts. These efforts ensure maximum sustained effectiveness,3492supported by a strong working relationship with the Federal Government.3493    For more than 25 years, railroads have maintained a dedicated3494coordinating committee focused on cyber threats, effective risk3495mitigation practices, and engagement with appropriate Government3496entities. Railroads leverage a strong mix of public and private3497capabilities to help effectively prevent and respond to malicious cyber3498activity. As threats continue to evolve, our industry strives to remain3499agile and innovative to address the dynamic cyber threat landscape.3500         a unified commitment to overall security preparedness3501    The rail industry addresses cybersecurity head-on through a long-3502standing, industry-wide, risk-based, and intelligence-driven plan.3503Railroads' specialized and highly-skilled cybersecurity teams carry out3504comprehensive, multifaceted cybersecurity plans focused on the factors3505experts have identified as the most effective in preventing cyber3506attacks.3507    Two AAR committees lead the industry's cybersecurity preparedness.3508First, the Rail Information Security Committee (RISC) is comprised of3509the chief information security officers and cybersecurity leads from3510major North American railroads. These committee members coordinate3511cybersecurity efforts, share information on threats, and discuss3512effective protective measures and risk-mitigating actions. Initially,3513the RISC included only Class I railroads and Amtrak, but membership has3514since expanded to include representatives from short-line and commuter3515railroads, as well as Railinc--a wholly-owned subsidiary of AAR that3516provides essential information technology support to enhance safety,3517efficiency, and smarter operations across the rail network. Second, the3518Rail Security Working Committee includes senior law enforcement and3519security officials focused on countering domestic and international3520terrorism. Together, these committees form the Rail Sector Coordinating3521Council (RSCC), the rail industry's primary channel for communication3522and coordination with Government agencies on cybersecurity initiatives.3523    The importance of the industry's cybersecurity posture and its3524collaboration with Government agencies can be highlighted through the3525recent publication of an advisory last week regarding a vulnerability3526in end-of-train devices from the Department of Homeland Security's3527(DHS) Cybersecurity and Infrastructure Security Agency (CISA).3528            railroad response to end of device vulnerability3529    The Federal Railroad Administration requires that all freight3530trains operating in excess of 30 miles per hour be equipped with End-3531of-Train (EoT) and Head-of-Train devices, while AAR updates and3532maintains the device standards. EoT devices collect brake line pressure3533data and send the information via radio signal to a head-end device3534aboard the locomotive, allowing the engineer to monitor the braking3535system. EoT devices also relay data about whether the rear end of a3536train is stopped or moving forward or backward and allow simultaneous3537brake application from both ends of the train in emergencies.3538    Recently, two independent researchers shared with CISA a3539vulnerability in EoT devices that could potentially allow an attacker3540to disrupt communications between the EoT and the head-end device and3541thereby stop the train. CISA's acting executive assistant director for3542cybersecurity, Chris Butera, stated:35433544``The End-of-Train (EOT) and Head-of-Train (HOT) vulnerability has been3545understood and monitored by rail sector stakeholders for over a decade.3546To exploit this issue, a threat actor would require physical access to3547rail lines, deep protocol knowledge, and specialized equipment, which3548limits the feasibility of widespread exploitation--particularly without3549a large, distributed presence in the U.S.3550``While the vulnerability remains technically significant, CISA has3551been working with industry partners to drive mitigation strategies.3552Fixing this issue requires changes to a standards-enforced protocol,3553and that work is currently under way. CISA continues to encourage3554manufacturers to adopt Secure by Design principles to reduce the attack3555surface and ensure resilient communications systems for operators.''35563557    While there is no evidence that the vulnerability has ever been3558exploited, the rail industry takes all cybersecurity threats very3559seriously and is working with the original equipment manufacturers to3560develop solutions compatible with all current-generation systems.3561Moreover, the industry has also been working on updates to develop the3562next generation of EoT technology for several years. These next3563generation EoT devices have the potential to significantly improve3564communication between lead locomotives and the end of the train,3565enhance reliability and security, and streamline operations.3566    The rail industry recognizes and remains supportive of the good3567work that CISA provides. The industry will continue to build and3568maintain our partnerships with DHS, the Transportation Security3569Administration, and the Federal Railroad Administration through joint3570efforts such as Project CHARIOT--an initiative focused on identifying3571vulnerabilities and developing robust mitigation strategies to reduce3572cyber risks. This collaboration will lead to the evaluation of a wide3573array of technologies and equipment and the ultimate hardening of3574critical infrastructure, ensuring the safe delivery of freight for3575customers across the network.3576    reauthorizing the cybersecurity information sharing act of 20153577    In addition to the rail industry's on-going efforts in3578cybersecurity preparedness, the Cybersecurity Information Sharing Act3579of 2015 (CISA 2015) provides legal safeguards that have enabled the3580private sector and the Federal Government in combating cybersecurity3581threats. Private entities need the antitrust exemptions and civil3582liability protections, disclosure law exemptions, and regulatory use3583exemptions in CISA 2015 to enable and sustain the unencumbered flow of3584cybersecurity information between reporting entities and the Federal3585Government. However, CISA 2015 is set to expire this year--unless3586Congress acts quickly to extend its protections.3587    Including the protections of CISA 2015 in all future cybersecurity3588legislation will build upon the successful legacy and partnerships that3589CISA 2015 helped to establish. Under CISA 2015, when a private3590organization shares information about a cybersecurity threat with DHS,3591that information is analyzed to identify possible threat actors and the3592threat actor's tactics, techniques, and procedures. Currently, the3593Government is obligated to protect the private organization's sensitive3594information. Losing these privacy protections would greatly3595disincentivize companies from coming forward. If private organizations3596stop sharing information on the details of cyber attacks with the3597Government, those private entities fighting cybersecurity threats would3598lose visibility on shifting tactics of malicious actors, thereby3599increasing the threats of bad actors for companies across the United3600States.3601    However, the law has been underutilized because the information3602permitted to be shared is too narrow. Under CISA 2015, a private3603company receives liability protections only if it shares through DHS's3604Automated Indicator Sharing system. These protections must expressly3605extend to sharing with other U.S. departments and agencies, such as the3606FBI and Secret Service, which are positioned to help private3607organizations improve their cybersecurity. Additionally, CISA 20153608permits information sharing where there is a ``cybersecurity purpose,''3609which is narrowly defined as ``the purpose of protecting an information3610system or information that is stored on, processed by, or transiting an3611information system from a cybersecurity threat or security3612vulnerability.'' This definition should be expanded to encompass other3613systems beyond an ``information system.'' Expanding the scope of CISA36142015 will allow the private sector to share more information, leading3615to an even greater ability for collaboration than what is currently3616realistic under current law. More collaboration between the Government3617and the private sector will allow for both to be better prepared3618against cybersecurity threats.3619                               conclusion3620    Railroad operations are resilient thanks to years of proactive and3621extensive efforts by highly-skilled railroad employees to develop,3622implement, and continuously improve plans, practices, and measures for3623cybersecurity as threats and security concerns emerge. However, risks3624are constantly evolving, and real-time adaptation is essential to3625reduce risk. Fortunately, the railroad industry and the Government3626share a common purpose: ensuring that effective and sustainable3627measures are in place and regularly reviewed for continuous3628improvement, in order to mitigate risk in the face of ever-evolving3629cyber threats. Railroads and their employees will continue to work3630cooperatively with private and public entities to ensure that our3631Nation's rail network--and the people, firms, and communities we serve3632remain safe, efficient, and secure.36333634                          A P P E N D I X  I I36353636                              ----------36373638       Questions From Chairman Andrew R. Garbarino for Kim Zetter3639    Question 1. Since Stuxnet's creation, how have you seen cyber3640attacks against critical infrastructure evolve, especially during3641heightened conflicts?3642    Answer. Following the discovery of Stuxnet, everyone expected that3643we would see similar copycat attacks against critical infrastructure,3644but we've seen surprisingly few operations that target critical3645infrastructure at this level. There have been ransomware operations3646against critical infrastructure, of course--the 2021 attacks against3647Colonial Pipeline and JBS Foods being 2 of the most famous ones. But in3648terms of cyber physical attacks that had a destructive or damaging3649intent that rise to the level of Stuxnet, we've had very few examples.3650The most significant are the 2015 and 2016 Russian attacks on Ukraine's3651energy infrastructure, and the 2017 attack against a petro-chemical3652plant in Saudi Arabia, both of which I discuss in my written witness3653testimony. For quick reference, here is what I wrote previously:36543655``It wasn't until 2015 and 2016 that we saw the first Stuxnet-level3656attacks against critical infrastructure. These targeted Ukraine's3657electric grid to cause blackouts for a few hours at the height of3658winter. The attackers were able to take 60 substations offline in 2015,3659leaving about a quarter of a million customers without electricity. The3660attack was limited in scope--presumably it was simply done to send a3661message to Ukraine about who was in control of its grid not cause3662permanent disruption--but could have been much broader if the attackers3663had intended this. The subsequent attack next year showed the potential3664for this. The malware used in that attack, known as Industroyer and3665Crash Override, caused only a brief outage in parts of Kyiv. But the3666code was more advanced than the code used in 2015 because it had the3667potential to be automated so that once on a system, it could execute3668commands on its own such as opening circuit breakers, overwriting3669software or adapting to whatever environment it found itself on,3670without the need for direct control by the attackers. Whereas the 20153671outage required the attackers to be at the keyboards issuing a series3672of commands in real-time, the 2016 version could have unfolded3673automatically once the attackers unleashed the code.3674``Then in 2017, we saw an attack that went beyond disruption and3675destruction to target the safety system on critical infrastructure, as3676Stuxnet had done at Natanz. The so-called Triton attack was designed to3677disable the safety system at a petrochemical plant in Saudi Arabia.3678Presumably, the attackers intended to use it in conjunction with an3679attack that would have caused a chemical spill or some other dangerous3680condition at the plant and they wanted to prevent the equipment from3681automatically shutting down to contain the danger. But fortunately3682there was no accompanying attack in this case, and the code targeting3683the safety system contained a flaw that caused the safety system to3684trigger automatic shutdowns of the plant, alerting engineers to its3685presence. It's an attack that could have had a potentially deadly3686impact if the attackers had intended this and if they had not made a3687mistake.''36883689    These three attacks are noteworthy for the way they showed an3690advancement in techniques and skill from Russia. The 2015 attack on3691Ukraine's power grid was a time-and-resource-heavy manual attack that3692was customized to target 3 different energy distribution companies,3693each of which used different models of control systems and had3694different configurations that the attackers had to study. It also3695required the operators to conduct the attack in real time with their3696hands on keyboards. The 2016 attack, however, had automation3697capabilities, which made it more dangerous. And the Triton attack3698showed that attackers were upping their game in terms of potential3699consequences.3700    The subsequent Pipedream attack platform discovered in 2022 went3701even further. It appeared to be focused on electric and oil and gas3702facilities--liquified natural gas systems in particular. But it could3703be modified for use against any industrial environment and had the3704ability to disable or brick control systems and undermine safety3705systems in ways that could potentially endanger lives--for example, if3706it was used to cause a chemical spill or cause equipment to catch fire3707or explode. This impact can be multiplied if safety systems are3708simultaneously disabled as Stuxnet did and as Triton was designed to3709do.3710    So in summary, we've seen threat actors testing and toying with3711increasingly destructive capabilities, though we haven't yet seen them3712deployed to their full ability.3713    With regard to attacks during heightened conflict, we so far only3714have a limited view of attacks that have occurred during conflict. Your3715committee no doubt has access to more extensive information about what3716has occurred that may not be publicly known.3717    In the case of Ukraine, we expected Russia to engage in more3718destructive attacks against Ukrainian critical infrastructure, but3719Russia's actions in cyber space have been fairly mild in comparison to3720what they could have done. In the early days of the invasion these3721operations were mostly limited to denial-of-service attacks and wipers3722that erased data and system files on government and military networks.3723But there have been a couple of examples that went beyond this--3724Russia's attack against Viasat modems used for satellite communications3725and internet connectivity. The attack was time to occur at the start of3726the invasion and succeeded to wipe thousands of modems to render them3727inoperable. Users were unable to get internet access and wind turbine3728operators were unable to monitor their systems over the internet. The3729attack also likely had some impact on the ability of Ukraine's military3730to use satellite communications during a critical time at the start of3731the invasion, but there are conflicting reports about the extent of the3732impact and we likely won't have a complete picture of what occurred3733until after the war.3734    A second consequential--and potentially destructive attack--was3735discovered before it could work. I'm referring to the discovery of3736malware in the early days of the war that could have taken out power in3737part of Ukraine had it not been discovered first. Since then there have3738been attacks designed to subvert drones and drone operators. But the3739war in Ukraine has mostly been dominated by kinetic operations rather3740than cyber ones--with the caveat that we don't know what we don't know.3741No doubt more information about cyber operations conducted during this3742conflict will come out after the conflict ends.3743    The reasons for Russia's limited showing in cyber space during the3744conflict are varied. Russia intended Kyiv to fall within 3 days after3745the invasion and therefore may have decided not to damage grid and3746other critical systems because it would have needed these systems to be3747active for when it took control of Ukraine. There are also suggestions3748that assistance from US Cyber Command and private security firms in the3749days leading up to the invasion helped Ukraine root out Russian hackers3750who were lying in wait inside critical infrastructure systems. Booting3751them out before the invasion left them with no access to these networks3752when the invasion occurred.3753    The other recent conflict that has been included digital attacks is3754the conflict between Israel and Iran--but many of these operations have3755been conducted under a guise of hacktivism, so it's unclear which3756operations can be directly attributed to either of these nations or to3757hacktivists working on their behalf or direction. In the case of Iran,3758we have seen attempts to target critical infrastructure in Israel, but3759these have not been very successful. Against Iran, we have seen more3760successful operations, such as one that led to a fire at a steel plant.3761But again, we have a limited view of what's occurred. Israel has3762extensive capabilities in cyber space and it will take time to discern3763how it used them during this conflict.3764    All of this is to say that attacks against critical infrastructure3765have, in practice, been less damaging than they could be--certainly3766less damaging than the adversaries conducting them are capable of3767doing.3768    Question 2. Why is it significant that Stuxnet exploited 4 zero3769days?3770    Answer. It's only significant for what it told us about the attack3771and the attackers behind it. At the time Stuxnet was discovered in37722010, zero-day exploits were rarely discovered in the wild. Out of 123773million pieces of malware that security firms captured and examined3774each year, only about 12 of these were zero-day exploits. The rest were3775exploits targeting known, and patched, vulnerabilities.3776    Zero-day exploits were rare in part because they were resource-3777heavy to discover and use, and they were expensive to purchase for3778anyone who didn't have the ability to discover them on their own. A3779researcher could take days picking through software code to discover a3780zero-day vulnerability, then someone would have to write exploit code3781to attack the vulnerability, and test that attack code to make sure it3782worked as intended. All of this took time and money, which is why most3783attacks involved non-zero-day exploits that targeted already-known and3784patched vulnerabilities.3785    So when researchers discovered that Stuxnet was using 4 zero-day3786exploits (it actually used 5 zero days, but Microsoft patched the fifth3787vulnerability the exploit was designed to target, before the attackers3788could use their exploit). The number of zero days in one attack made it3789immediately clear to the researchers who studied it that Stuxnet was3790the product of a nation-state. Only a state agency or military would3791possess a stockpile of zero days so large that it could afford to waste37924 zero days in a single attack. I say ``waste'' because once Stuxnet3793was discovered, those exploits became mostly obsolete, due to software3794vendors patching the vulnerabilities they attacked and antivirus firms3795adding detection capabilities to their products to catch any exploits3796targeting those vulnerabilities.3797    But the use of 4 (5) zero days also revealed something else. It3798revealed that the attackers were so determined--or desperate--to get3799their weapon onto the targeted systems that they were willing to burn 53800zero days to accomplish this.3801    Question 3. How did Stuxnet transform the interest of nation-3802states, such as China and Russia, in developing cyber capabilities to3803disrupt critical infrastructure?3804    Answer. Stuxnet put critical infrastructure on the map. It put this3805infrastructure on the map for defenders--in terms of raising awareness3806that these systems were highly vulnerable to attack--but it also put3807infrastructure on the map for attackers. Stuxnet was proof of concept3808for attackers that causing physically damaging critical infrastructure3809was possible using nothing other than malicious code. It also provided3810a detailed blueprint for how they could do this.3811    Post-Stuxnet, countries that until then had only conducted cyber3812espionage, invested heavily in building teams capable of conducting3813cyber offensive operations against critical infrastructure. Iran is3814among the countries that only began to develop these capabilities after3815the discovery of Stuxnet, and directly in response to Stuxnet. It's a3816cliche to say that Stuxnet opened a Pandora's box, but it really did.3817    Question 4. Did the development and execution of Stuxnet drive3818improvements around the security of sensitive and/or critical programs3819and operations in the United States? Please explain.3820    Answer. It did and it didn't. Certainly Stuxnet created awareness3821that critical infrastructure systems were poorly designed and3822vulnerable to attack, and as a result of this there were increased3823efforts to address this. An entire industry of people and companies3824emerged to focus on securing critical infrastructure. Researchers3825interested in uncovering vulnerabilities in the systems in order to fix3826them also emerged. And vendors who had poorly designed the systems in3827the first place began to develop new ones that were more secure.3828    But securely-built systems aren't the only problem with critical3829infrastructure. A larger problem is resources and policies and a3830willingness to do what needs to be done.3831    For example, the intrusion into the Oldsmar water plant in 20213832highlighted the vulnerability of water treatment systems in particular,3833which are often managed by poorly resourced municipalities that lack3834people and money to secure and manage these systems. Oldsmar was using3835wildly outdated software and had poor password practices that left it3836vulnerable, and many small critical infrastructure facilities don't3837have the knowledge or staff to ensure that their systems and networks3838are secure.3839    But as I pointed out in my written testimony, even large critical3840infrastructure facilities like Colonial Pipeline are not up to speed.3841Colonial Pipeline failed to heed warnings about attacks that had been3842hitting pipelines for more than a year and also failed to follow a3843number of best practices that might have prevented the attack or3844mitigated its impact. Colonial Pipeline, despite its critical role in3845distributing fuel, had no chief information security officer and3846instead had left its deputy IT director to manage security duties on3847top of his regular ones.3848    For many of these operations it comes down to priorities and cost.3849Security isn't cheap or easy to implement and it also isn't static. You3850can't simply install a firewall and antivirus software and implement3851multi-factor authentication and call it a day. Threats evolve and3852networks constantly change each time you install new software or swap3853out a server with a different one. Security requires constant3854attention, re-evaluation and upkeep, and this is expensive.3855    I want to mention one last thing before I end, because this often3856doesn't get addressed in discussions about critical infrastructure.3857Election systems are critical infrastructure as well, and they are no3858more secure than any other critical infrastructure though every bit as3859important. Many State, county, and municipal departments that run3860elections don't have the resources to secure their voting machines and3861back-end infrastructure and now have even less assistance to help them3862do this following recent cuts to Federal funding and staff. I've been3863writing about election security since 2004, and although awareness of3864election security has grown immensely in the last decade, the systems3865themselves are far from secure given the current nature of threats3866against them.3867    I'd be happy to elaborate further on anything I've written here.3868     Questions From Chairman Andrew R. Garbarino for Robert M. Lee3869    Question 1. While the cyber threat landscape has changed3870significantly since the discovery of Stuxnet, the use of malware to3871disrupt critical infrastructure continues to occur. How has malware3872evolved since Stuxnet?3873    Answer. Malware has become more sophisticated in the 15 years since3874Stuxnet, and its use has scaled up dramatically. Stuxnet was a bespoke,3875targeted weapon and existed in a context of fewer, and less3876sophisticated cyber threats. The threat landscape today is a sprawling3877interplay of criminal groups and state actors working to rapidly3878identify and exploit vulnerabilities for a range of economic,3879ideological, and espionage purposes. Attacker tactics and techniques3880have evolved to a degree that perimeter-based cyber defenses are3881obsolete, and sophisticated actors can, and do, enter advanced3882enterprise networks and remain undetected for months or years.3883Ransomware has developed into a full-fledged industry. In an3884operational technology context, malware, like PIPEDREAM has evolved to3885target a range of industrial control systems. Criminal and state actors3886are increasingly turning their attention to OT environments, because3887they know how critical they are to the basic functions of civilization.3888That prioritization means more numerous, and more sophisticated types3889of malware targeting these systems. All of this means that operational3890technology networks are under unprecedented threat, and the potential3891damage from an attack has grown in tandem.3892    Question 2. How often are zero days exploited now, and what steps3893can operational technology (OT) providers take to reduce the presence3894of zero days in OT environments?3895    Answer. Zero-day vulnerabilities are a real problem, and operators3896need to be diligent about patching vulnerabilities as quickly as3897possible and monitoring their networks for threats and anomalies. That3898said, the vast majority of attacks continue to exploit known3899vulnerabilities, and human error. By implementing the 5 critical3900controls that I, and Tim Conway, laid out in our SANS Institute paper3901on the topic, operators can protect themselves from most attacks. Most3902critically, operators need to know what's in their network. Network3903visibility is key to mitigating all vulnerabilities, including zero3904days. Visibility is what enables you to find vulnerabilities and find3905out if you've had any vulnerabilities exploited. Most of our3906adversaries don't rely on vulnerabilities--they rely on the inability3907of operators to see them when they breach a network. This enables them3908to live off the land and sustain breaches for long periods of time. OT3909network visibility is what enables you to detect, stop, and mitigate3910attacks. Of course, we should be diligent about finding and patching3911vulnerabilities, but for operators, the use of key security controls,3912and maintaining strong network visibility is where the focus should be.3913We have the tools and practices to protect utilities from these3914threats. As I said in my testimony, defense is doable and should focus3915on the fundamentals.3916    Question 3. Given our scarcity of cyber professionals, many State3917and local critical infrastructure owners and operators may not have3918someone on staff who focuses on cybersecurity. For those owners and3919operators who lack skilled cyber talent and have scarce resources, what3920cybersecurity measures would you recommend they prioritize to secure3921their systems?3922    Answer. Under-resourced utilities face a tough set of challenges3923stemming from a lack of skilled cyber professionals, and from the cost3924of implementing strong cybersecurity protections. Dragos has worked to3925address these challenges through our Community Defense Program, which3926provides our full security platform to American utilities with $1003927million or less in annual revenue. We also have the free OT CERT3928program, which provides a number of free training, threat intelligence,3929and best-practices resources to under-resourced utilities. I'd urge3930eligible utilities to take advantage of the resources we offer. Beyond3931that, I again must emphasize the importance of fundamentals.3932Implementing the basic controls I outlined during the hearing, and in3933these responses, will eliminate most threats. It's also critical that3934governments don't overload small operators with contradictory and3935confusing rules that distract from basic security work.3936    Question 4. What new risks do artificial intelligence (AI)-enabled3937cyber tools introduce to critical infrastructure that we did not face3938during the Stuxnet era?3939    Answer. The full effect that AI will have for both attackers and3940defenders remains to be seen, but AI will very likely increase the3941scale and sophistication of threats against OT systems. Stuxnet was3942carefully produced with a distinct target in mind. Since that attack,3943we've seen malware like PIPEDREAM developed that can target multiple3944types of systems. AI may enable adaptive malware that can morph and3945evolve in response to the defenses it encounters, with the goal of3946overcoming them. So AI will likely continue the evolution of malware to3947become more capable and more ubiquitous. But that's not the only3948consideration when it comes to AI in an OT environment. AI is already3949being connected to OT networks to harvest data. This is done for3950operational purposes: to improve automation, make systems more3951efficient, and the like. This increases the attack surface for OT3952systems and introduces a new attack vector that hasn't been fully3953considered by many operators.3954    Question 5. Can you describe the trends you have seen regarding how3955hacktivists target Western critical infrastructure? What are their3956motivations, capabilities, and primary targets?3957    Answer. Dragos has observed a large increase in the number of3958attacks being carried out by, or under the guise of, hacktivist groups.3959State-aligned hackers are using cyber operations to hit critical3960infrastructure in conflict hotspots like Ukraine, Russia, and the3961Middle East, while hacktivist groups are stepping up their own attacks3962on energy and water systems worldwide. These actors have managed to3963penetrate further into OT networks than was ever the case previously.3964In some cases, they are teaming up with government-backed actors,3965giving nations a deniable way to cause disruption. It is reasonable to3966expect that we will see a hacktivism component to any major conflict in3967the future, and the already blurred line between the goals and3968motivations of hacktivist groups and the states they are aligned with3969could get yet more confusing. This is part of the reason that network3970monitoring is critical. Network monitoring increases the chances that3971an attack will be detected, and properly attributed, and that the3972effects of an attack won't be passed off as an unrelated technical3973issue. This gives operators, and policy makers a more stable3974environment to make decisions about how best to defend networks, and3975how to identify and stop bad actors.3976    Question 6a. What unique cyber threats does the defense industrial3977base face from other sectors, particularly from Iranian-affiliated3978actors?3979    Answer. The defense industrial base is one of, if not the most3980targeted sectors of our economy for obvious reasons. While Iranian-3981affiliated actors aren't as advanced as other adversaries, they are3982highly motivated at this time. As with all critical infrastructure3983sectors, when thinking about the defense industrial base, we can't only3984consider production facilities, company headquarters, and the like. We3985also need to consider the upstream utilities that make the operations3986of those facilities possible. Iran has targeted American utilities in3987the past and could do so again as a way of disrupting the DIB.3988    Question 6b. Although the Cybersecurity and Infrastructure Security3989Agency (CISA) is not the Sector Risk Management Agency for the DIB, how3990can CISA be a helpful partner to the DIB in its role as National3991Coordinator of Sector Risk Management Agencies?3992    Answer. CISA is well placed to serve as the lead coordinator, and3993main policy-setting authority for different industries. As I made clear3994in my testimony, I believe that CISA can be most effective in this role3995by being selective in whom it involves in threat sharing and policy3996setting efforts. Involving too many individuals or entities makes these3997programs unwieldy and unfocused. CISA can help the DIB by coordinating3998threat information sharing in a sensible and focused way and helping to3999set outcome-based rules and standards. As I advocated in the hearing4000and elsewhere, I believe the National Guard can best serve as a4001nationwide incident response force for OT attacks, including those4002targeting the DIB, but this should occur in conjunction with CISA as4003the primary Federal policy coordinator.4004     Questions From Chairman Andrew R. Garbarino for Tatyana Bolton4005    Question 1. Has the intrusion of Volt Typhoon, a People's Republic4006of China (PRC) state-sponsored cyber actor, spurred more awareness in4007the cybersecurity community about risks facing operational technology4008(OT) environments? Why or why not?4009    Answer. The intrusion of Volt Typhoon has undeniably amplified4010awareness within the cybersecurity community regarding the specific4011risks facing operational technology (OT) environments. The public4012nature and scale of this and other similar breaches, such as the4013National Guard breach, have served as a stark reminder of the4014persistent and sophisticated threats posed by state-sponsored actors.4015    While there is heightened awareness, the OTCC members have observed4016that this has not consistently translated into widespread, measurable4017behavioral changes across all critical infrastructure sectors. The4018initial alarm generated by these events often fades, and organizations4019may return to pre-incident operational norms without implementing the4020robust, long-term security measures necessary to mitigate future risks.4021    A critical vulnerability highlighted by these intrusions is the4022interconnectedness of information technology (IT) and OT networks. Many4023attacks on critical infrastructure have originated in the IT4024environment before penetrating the more sensitive OT systems. This4025underscores the urgent need for a ``survivability'' mindset, where OT4026systems are designed and protected to remain operational even if the IT4027network is compromised. This can only be achieved through rigorous4028network segmentation, physically and logically separating OT from IT to4029create a resilient defense.4030    A significant gap remains between awareness and action, as I4031mentioned in my opening statement. The prioritization and allocation of4032resources to defend our Nation's critical infrastructure must increase4033to a level commensurate with the severity of the threat.4034    Question 2. Which sectors of U.S. critical infrastructure are most4035dependent on OT systems for daily operations? How do you assess the4036current state of OT resilience for those sectors?4037    Answer. The short answer is: all 16 critical infrastructure sectors4038rely on OT systems for daily operations, from water and health care to4039chemical facilities and the Defense Industrial Base. However, some are4040so fundamentally reliant that any disruption to their OT would have an4041immediate and catastrophic impact. These include:4042   The Energy Sector.--The electric grid, oil and gas4043        pipelines, and power generation facilities are controlled4044        almost entirely by OT systems.4045   Water and Wastewater Systems.--OT systems manage everything4046        from water purification and pumping to distribution and4047        wastewater treatment.4048   The Manufacturing Sector.--OT is essential for continuous4049        and automated processes in areas like chemicals, food and4050        agriculture, and critical defense manufacturing.4051    The current state of OT resilience across these sectors is4052inconsistent. While awareness of cyber threats to OT has grown4053significantly, major gaps and vulnerabilities remain.4054    1. Legacy Systems and Convergence.--Many critical infrastructure4055        facilities still run on legacy OT systems that were never4056        designed with modern cybersecurity in mind. The increasing4057        convergence of IT and OT networks--while efficient--has created4058        new pathways for attackers to move from an enterprise network4059        to a core industrial control system.4060    2. Fragmented Regulations.--The regulatory landscape is a4061        patchwork. Some sectors, like the electric grid, have well-4062        established mandatory standards (e.g., NERC CIP), while others4063        have minimal or voluntary frameworks. This leads to4064        inconsistent levels of security and makes the entire ecosystem4065        more vulnerable.4066    3. Resource Disparity.--Smaller entities within these sectors, such4067        as small water utilities and regional manufacturers, often lack4068        the financial resources and technical expertise to implement4069        robust cybersecurity measures, as was discussed during the4070        hearing.4071    Addressing these challenges requires a comprehensive and4072collaborative approach.4073    The Operational Technology Cybersecurity Coalition (OTCC) is4074currently working on publishing a Maturity Model for Sector Risk4075Management Agencies (SRMAs). This model is designed to provide a4076standardized, risk-based framework for organizations that lead critical4077infrastructure engagement. It's a vital step toward creating a4078consistent and repeatable process for assessing and improving OT4079security.4080    However, more must be done, especially to support the most4081critically under-resourced sectors. Providing financial aid, technical4082assistance, and clear, actionable guidance is essential. The Government4083must work hand-in-hand with the private sector to build a more4084resilient and secure critical infrastructure for our Nation.4085    Question 3. How do organizations safely integrate information4086technology (IT) systems with OT? Please provide some best practices.4087    Answer. Safely integrating information technology (IT) and4088operational technology (OT) systems is a complex but necessary process4089that requires a strategic approach. The goal is to leverage the4090benefits of IT/OT convergence--such as enhanced data analytics,4091efficiency, and predictive maintenance--without compromising the4092safety, reliability, and security of critical OT environments. The4093fundamental principle is to establish a secure boundary between the two4094systems while allowing for controlled and monitored communication.4095    Here are some best practices for safely integrating IT and OT4096systems:4097    1. Network Segmentation and Zero Trust Architecture4098   Implement Network Segmentation.--This is the most crucial4099        step. Physically and logically separate the OT network from the4100        IT network using firewalls and demilitarized zones (DMZs). This4101        creates a buffer zone where data can be exchanged, but direct4102        connections between the two environments are prohibited. This4103        prevents threats that compromise the IT network from easily4104        propagating to the OT network.4105   Micro-segmentation.--Further segment the OT network into4106        smaller zones to limit the lateral movement of a threat if a4107        breach occurs within the OT environment itself.4108   Adopt a Zero Trust Model.--The principle of ``never trust,4109        always verify'' is essential. Assume that any user, device, or4110        connection, whether inside or outside the network, is a4111        potential threat. All access requests must be authenticated and4112        authorized, even for traffic moving between IT and OT systems.4113        While Zero Trust for OT is not the same as Zero Trust in IT,4114        these main principles remain.4115    2. Comprehensive Asset Inventory and Monitoring4116   Establish a Complete Asset Inventory.--Maintain a detailed4117        and continuously updated inventory of all OT assets, including4118        hardware, software, firmware, and their vulnerabilities. This4119        provides a clear understanding of the attack surface and helps4120        in prioritizing security efforts.4121   Continuous Monitoring.--Use specialized monitoring tools4122        that understand OT protocols to track network traffic and asset4123        behavior. This helps in detecting unusual activity and4124        identifying potential threats in real time, enabling a faster4125        response.4126    3. Strict Access Control and Authentication4127   Principle of Least Privilege.--Grant users and devices only4128        the minimum level of access required to perform their4129        functions. This limits the potential damage if an account is4130        compromised.4131   Role-Based Access Control (RBAC).--Assign access based on4132        job roles to streamline management and ensure that permissions4133        are appropriate for each user's responsibilities.4134   Multi-Factor Authentication (MFA).--Require multiple4135        verification methods for access to critical systems, especially4136        for remote access. This adds a crucial layer of security,4137        making it much harder for an attacker to gain unauthorized4138        access even if they have a password.4139    4. Holistic Risk Management and Governance4140   Develop a Joint IT/OT Security Policy.--Create unified4141        security policies that address the unique requirements and risk4142        tolerance of both IT and OT environments. This requires close4143        collaboration between IT and OT teams to ensure a shared4144        understanding of security goals and operational priorities.4145   Regular Risk Assessments.--Conduct frequent risk assessments4146        to identify and prioritize vulnerabilities. This process should4147        be specific to the OT environment and consider the potential4148        physical and safety consequences of a cyber attack.4149   Create a Culture of Collaboration.--Bridge the cultural and4150        knowledge gap between IT and OT teams. Provide cross-training4151        to ensure both teams understand each other's priorities,4152        challenges, and security needs.4153    5. Incident Response and Recovery Planning4154   Develop a Specific OT Incident Response Plan.--Create a4155        detailed incident response plan that outlines procedures for4156        detecting, containing, and recovering from security incidents4157        in the OT environment. This plan should account for the unique4158        operational constraints of industrial systems and prioritize4159        safety and continuity.4160   Regular Drills and Exercises.--Regularly test the incident4161        response plan through tabletop exercises and simulated attacks.4162        This ensures that teams are prepared to respond effectively and4163        efficiently in a real-world scenario, minimizing downtime and4164        damage.4165    6. Patch Management and Compensating Controls4166   Careful Patch Management.--Develop a systematic and tested4167        approach to patching OT systems. Patches should be thoroughly4168        tested in a controlled environment before deployment to avoid4169        disrupting critical operations.4170   Compensating Controls.--For legacy OT systems that cannot be4171        patched, implement compensating controls, such as network4172        segmentation, virtual patching, and rigorous monitoring, to4173        mitigate known vulnerabilities.4174    Question 4. How can the United States ensure it has a workforce4175that is sufficiently trained and large enough in size to protect both4176OT and IT systems? Please describe the current level of coordination4177among professionals with these individual skill sets in the United4178States, as well as assess the state of individuals in the U.S. cyber4179workforce that have both skill sets.4180    Answer. The United States faces a growing shortage of cybersecurity4181professionals in both operational technology (OT) and information4182technology (IT), creating a serious risk to national infrastructure. OT4183cybersecurity requires specialized knowledge of physical systems,4184industrial protocols, and real-time operations. Unlike IT, which4185focuses on data protection, OT is tied to the safety and continuity of4186physical processes. Yet most training programs and workforce strategies4187still focus heavily on IT, leaving a gap in OT expertise.4188    Professionals trained in both domains are scarce, and coordination4189between OT and IT teams remains limited. Many organizations lack clear4190pathways for talent development in industrial cybersecurity roles.4191    To address this, the OTCC recommends the following:4192   Create targeted training programs, apprenticeships, and4193        curricula that combine engineering and cybersecurity skills,4194        tailored to OT environments.4195   Expand upskilling efforts to help existing IT and4196        engineering professionals transition into OT cybersecurity4197        roles through hands-on, practical training.4198   Establish clear career pathways within industrial4199        cybersecurity, including:4200     Junior IT and OT roles that lead to OT GRC or Security4201            Analyst positions4202     OT Analysts progressing to Security Architect or Director4203            of OT Security.4204   Encourage integrated OT-IT teams across public and private4205        sectors to improve collaboration and break down operational4206        silos.4207    A resilient cyber workforce must be equipped to secure both digital4208networks and the physical systems that depend on them. The OTCC urges4209Federal leaders to prioritize OT cybersecurity workforce development in4210all national security planning. Congress can directly help by funding4211workforce grants focused on OT training, supporting partnerships with4212industry for hands-on experience, and ensuring Federal cybersecurity4213initiatives include OT-specific talent development goals.4214    Question 5. What resources exist for State and local OT operators4215to best protect themselves from cyber threats, especially from nation-4216state actors?4217    Answer. There are many resources available to help State and local4218governments strengthen the cybersecurity of their operational4219technology and industrial control systems (OT/ICS). Several of the most4220useful are listed below. However, the real gap is not in the4221availability of guidance--it is in the capacity to use it.4222    Most State and local governments do not have full-time staff with4223expertise in OT security. Aside from State departments of4224transportation and the occasional water utility, these governments4225typically lack the dedicated personnel needed to apply technical4226guidance, assess vulnerabilities, or manage secure system design.4227Budget constraints are the main barrier.4228    As a result, many governments rely heavily on outside vendors--4229systems integrators and OT product suppliers--to design and deploy4230secure systems. This approach is expensive, and because internal staff4231often lack the technical knowledge to request or evaluate cybersecurity4232features during procurement, essential protections are frequently left4233out altogether.4234    Even when governments want to improve, they struggle to act on best4235practices outlined in standards such as those from NIST or ISA/IEC423662443. These frameworks are valuable, but without the staffing and4237resources to implement and verify the work, they have limited practical4238impact. It is like giving someone a detailed blueprint without an4239architect--they can see the plan, but not how to build it.4240    In addition to resourcing, our coalition encourages the Federal4241Government to provide the same level of support to State and local4242operators under attack as they would a kinetic act of war. While OT4243systems need better cybersecurity, the reality is that States and small4244or medium-sized OT owners and operators do not have the resources4245necessary to defend against a nation-state actor.4246Expiring Provisions That Congress Must Swiftly Reauthorize4247   State and Local Cybersecurity Grant Program (SLCGP).--4248        Provides dedicated funding to help State and local governments4249        build foundational cybersecurity capabilities. Grants can4250        support hiring staff, developing cybersecurity plans, improving4251        incident response, and securing critical infrastructure4252        systems, particularly where in-house expertise is limited.4253   Cybersecurity Information Sharing Act of 2015 (CISA 2015).--4254        Enables timely, secure sharing of cyber threat information4255        between the Federal Government and non-Federal entities--4256        including State and local governments--by offering liability4257        protections and privacy safeguards. These protections make it4258        easier for governments to participate in information-sharing4259        programs and benefit from real-time threat intelligence.4260Training & Webinars4261   Critical Infrastructure Training Portal.--Offers free4262        independent study, sector-specific trainings (e.g., Chemical,4263        Dams, Nuclear), and instructor-led modules to infrastructure4264        owners and operators. (CISA)4265   Critical Infrastructure Learning Series.--No-cost, hour-long4266        expert-led webinars on infrastructure security best practices.4267        (CISA)4268   Cybersecurity Training & Exercises.--Includes no-cost4269        incident response training, cyber range exercises, tabletop4270        exercise packages, and participation in large-scale drills like4271        Cyber Storm. (CISA)4272   NICCS/FedVTE/CISA Learning.--The NICCS portal provides4273        access to thousands of cybersecurity courses. FedVTE (now4274        evolving into CISA Learning) delivers free on-line training in4275        areas like ethical hacking, risk management, and malware4276        analysis. (CISA)4277Assessment Tools & Services4278   Infrastructure Survey Tool (IST).--Web-based assessment to4279        evaluate facility security and resilience. (CISA)4280   Regional Resiliency Assessment Program (RRAP) and Resilience4281        Planning Framework/Playbook.--Tools for identifying risks and4282        building resilience at the facility or regional level. (CISA)4283Cybersecurity Tools & Services4284   Free Cybersecurity Services & Tools Catalog.--An interactive4285        database of free CISA-provided and external tools, searchable4286        by readiness level, performance goals, or provider. (CISA)4287   Cyber Hygiene Services.--Free vulnerability scanning of4288        internet-facing systems with automated weekly reporting. (CISA)4289   Cybersecurity Evaluation Tool (CSET).--A downloadable tool4290        to assess cybersecurity posture using recognized frameworks;4291        supports both IT/OT systems. (CISA)4292   Ransomware Guides, Alerts & Advisories.--Regularly updated4293        publications, playbooks, and advisories to help organizations4294        detect and respond to threats. (CISA)4295Other Non-CISA resources available:4296            National Institute of Standards and Technology (NIST)4297   NIST Cybersecurity Framework (CSF).--Free, widely-adopted4298        framework for assessing and improving cybersecurity posture.4299   Special Publications (SP 800 series).--Free, detailed4300        guidance on topics like risk management, access control,4301        industrial control systems (ICS), and supply chain risk.4302   Self-assessment tools.--For example, the Baldrige4303        Cybersecurity Excellence Builder (free) helps align4304        cybersecurity activities with business strategy.4305   https://www.nist.gov/cyberframework.4306            Department of Energy (DOE)--Office of Cybersecurity, Energy4307                    Security, and Emergency Response (CESER)4308   Cybersecurity Capability Maturity Model (C2M2).--Free tool4309        for energy and utility companies to evaluate and improve4310        cybersecurity posture.4311   Free Technical Assistance Programs.--Offered through4312        national labs to help electric utilities with risk assessments4313        and vulnerability mitigation.4314   Risk-informed Planning Resources.--Playbooks and templates4315        specific to energy infrastructure resilience.4316   https://www.energy.gov/ceser.4317            Multi-State Information Sharing and Analysis Center (MS-4318                    ISAC)4319    Run by CIS (Center for Internet Security) and funded by DHS/CISA,4320this is free for SLTTs (State, Local, Tribal, and Territorial4321entities):4322   Free endpoint detection (Albert Sensor).4323   Vulnerability assessments and scanning.4324   24/7 SOC and incident response.4325   Security advisories and intelligence feeds.4326   https://www.cisecurity.org/ms-isac.4327            U.S. Cyber Command/Joint Cyber Defense Collaborative (JCDC)4328   Threat intel sharing (via JCDC).--Public-private4329        partnerships to proactively share and address threats to4330        national critical infrastructure.4331   Cyber Hunt & Response Teams (CHRTs).--Deployable Federal4332        experts for incident response (in coordination with CISA/FBI).4333   https://www.cybercom.mil/.4334    Question 6. What steps should the U.S. Government take beyond4335issuing the June 22 DHS National Terrorism Advisory System alert, if4336any, to support OT partners?4337    Answer. In addition to issuing the June 22 DHS National Terrorism4338Advisory System (NTAS) alert, the U.S. Government should take proactive4339steps to materially support operational technology (OT) stakeholders in4340defending critical infrastructure. Alerts are important, but without4341sustained resourcing and implementation support, their impact is4342limited.4343    To move beyond awareness and toward resilience, the Government4344should prioritize the following:4345   Mandate and fund OT asset inventories across Federal4346        agencies, beginning with the Department of Defense and4347        expanding to all departments responsible for critical4348        infrastructure. Without clear visibility into deployed systems,4349        agencies cannot assess or mitigate risk.4350   Explicitly prioritize OT security in national cybersecurity4351        strategies and funding allocations. OT systems are often4352        underrepresented in policy and budget planning, despite being4353        essential to physical infrastructure operations. They require4354        distinct attention apart from traditional IT systems.4355   Expand the State and Local Cybersecurity Grant Program4356        (SLCGP) by creating a dedicated track for OT-related needs.4357        This funding should be directed to small and rural4358        infrastructure operators, such as water utilities and local4359        transportation agencies, which are frequent targets but often4360        lack full-time cybersecurity staff.4361   Invest in technical workforce development focused on OT4362        environments. Many public entities are aware of their risks but4363        lack the personnel with specialized expertise to apply4364        frameworks such as ISA/IEC 62443 or NIST's Cybersecurity4365        Framework in operational settings.4366   Support the use of the OTCC-developed Sector Risk Management4367        Agency (SRMA) Maturity Model, which helps identify gaps in4368        sector preparedness and guides incremental, practical4369        investment. The model allows Federal leaders to tailor guidance4370        based on a sector's current level of maturity and progress4371        toward resilience.4372    Ultimately, NTAS alerts should be matched with sustained public-4373private coordination and the delivery of meaningful resources. The risk4374to OT systems is not hypothetical. Our adversaries are actively4375preparing to exploit these vulnerabilities, and national policy must4376reflect that urgency.4377      Questions From Chairman Andrew R. Garbarino for Nate Gleason4378    Question 1. What resources exist for State and local operational4379technology (OT) operators to best protect themselves from cyber4380threats, especially from nation-state actors?4381    Answer. The vast majority of cyber attacks on critical4382infrastructure systems take advantage of poor cyber hygiene practices4383and known vulnerabilities and exploits. Ensuring basic cyber hygiene is4384an important step that operational technology (OT) operators can take4385to protect themselves. There are existing resources that can help an4386operator improve their preparedness:4387   The NIST Cybersecurity Framework provides high-level4388        structure and can help develop a strategic view of cyber4389        defense.4390   The CIS Critical Security Controls provide more detailed4391        information on how to implement the strategy in the4392        cybersecurity framework.4393   The SANS Top 5 Critical Security Controls emphasize the 54394        most important recommendations out of the CIS Critical Security4395        Controls.4396   CISA's Cross-Sector Cybersecurity Performance Goals provide4397        a checklist to ensure a baseline level of protection.4398    An organization might choose to use the CISA Cross-Sector4399Cybersecurity Performance Goals to achieve a minimum level of4400capability, then expand that capability over time using the CIS4401Critical Security Controls. Federal funding opportunities like the4402Department of Homeland Security's State and Local Cybersecurity Grant4403Program can help provide resources for implementation.4404    Products like the Section 9 Risk Register, developed for the energy4405sector by the Department of Energy's (DOE) Office of Cybersecurity,4406Energy Security and Emergency Response (CESER), can help operators4407understand their level of preparedness against current nation-state4408threats. The Risk Register uses current intelligence information to4409develop a set of unclassified attack scenarios that broadly capture the4410intent and capability of current nation-state adversaries. Operators4411can select characteristics of their system and receive a score that4412indicates how difficult it would be for adversaries to achieve certain4413outcomes. Operators can then explore how various additional hardening4414and mitigation options would affect that score.4415    Participation in Federal public-private partnership programs allows4416operators to both leverage Federal capabilities and threat information4417as well as benefit from the expertise and experience of other critical4418infrastructure operators.4419   DHS CISA invites the country's most critical infrastructure4420        entities to participate in the CyberSentry program. This4421        program brings advanced detection capabilities to program4422        participants and helps enrich Federal Government understanding4423        of current threats being seen on U.S. OT networks.4424   DOE's Cybersecurity Risk Information Sharing Program (CRISP)4425        is a partnership between the electric power industry, DOE and4426        the Electricity Information Sharing and Analysis Center (E-4427        ISAC) that enables utility network traffic to be analyzed4428        against a wide variety of threat indicators from Government and4429        intelligence sources. Participants can share their information4430        anonymously and receive near-real-time alerts and mitigation4431        guidance.4432   DHS CISA offers their Cyber Hygiene Services (CyHy) at no4433        cost to critical infrastructure operators. The CyHy service4434        provides vulnerability scanning for internet-accessible assets4435        and delivers a weekly report to help organizations reduce their4436        attack surface.4437    The Federal Government also offers various tools and training to4438help critical infrastructure operators defend their systems. CISA's4439Malcolm tool, developed in collaboration with Idaho National4440Laboratory, is an open-source network traffic analysis tool suite that4441works with OT protocols. CISA offers both on-line and in-person4442training for OT operators. And DOE CESER, also in collaboration with4443Idaho National Laboratory, leads the Operational Technology Defender4444Fellowship Program, which is a year-long education and development4445program for OT security or operations managers at energy sector4446organizations.4447    For additional help, CISA has more than 100 cybersecurity advisors4448deployed around the country that can be accessed through the CISA4449regional offices. Emerging initiatives outside of the government, like4450DEF CON Franklin, are also seeking to organize community volunteers to4451help improve cybersecurity at critical infrastructure entities.4452    Question 2. In what ways can artificial intelligence (AI) improve4453the detection and response capabilities of defenders protecting OT4454environments from cyber attacks?4455    Answer. AI is rapidly transforming the way defenders detect and4456respond to cyber attacks in OT environments. OT systems--such as those4457controlling power plants, manufacturing lines, or water treatment4458facilities--are increasingly targeted by sophisticated cyber threats.4459Traditional approaches to identifying anomalous network activity and4460vulnerable software rely on exhaustively enumerating potential concerns4461and continuously scanning for them. Examples include rules-based4462security tools (for example, flagging logins at unusual hours or4463blocking known malicious IP addresses) or static software analysis4464tools (which examine code without executing it, looking for potential4465weaknesses that could be exploited by malicious actors). These4466approaches remain important, but they have significant limitations,4467particularly when dealing with nation-state threats. These methods4468often generate large volumes of alerts, most of which turn out to be4469benign. This high rate of false positives can overwhelm security teams,4470making it difficult to identify true threats, especially those that are4471subtle or novel. These approaches can also be computationally4472expensive, which make it infeasible to scan for all vulnerabilities4473exhaustively.4474    AI enhances detection and response in several key ways:4475   Contextual Analysis.--AI can analyze vast amounts of network4476        and device data to understand normal OT operations and4477        relationships.4478   Alert Prioritization.--AI can filter and prioritize alerts,4479        reducing noise and helping defenders focus on the most credible4480        threats.4481   Anomaly Detection.--Machine learning models can identify4482        subtle deviations from normal behavior that are often missed by4483        static rules.4484   Threat Correlation.--AI can correlate events across4485        different systems and time frames, revealing attack patterns4486        that humans might miss.4487   Automated Response.--AI can trigger automated containment or4488        investigation actions, enabling faster, more consistent4489        responses.4490    At Lawrence Livermore National Laboratory (LLNL), we have developed4491several AI-driven tools to address these challenges. Some examples4492include:4493   OTDetect learns the typical communication patterns between4494        devices in an OT network and flags unusual interactions that4495        could indicate a compromise.4496   Greywind is designed to detect sophisticated beaconing or4497        ``phoning home'' behavior by compromised devices.4498   NetWolf integrates data from multiple sources to provide a4499        holistic, AI-driven view of network activity, enabling4500        defenders to see the bigger picture and respond more4501        effectively.4502   OGhidra is an advanced bridge connecting local Large4503        Language Models (LLMs) with the Ghidra reverse engineering4504        platform to provide an AI-driven interface for binary analysis.4505    Detecting and responding to intrusions is critical, but those4506activities alone cannot secure OT environments. LLNL has developed a4507multilayered framework called Immune Infrastructure, which also4508includes focuses on understanding the systems, keeping the adversary4509out, and operating through compromise. For example, adversaries can4510work through hardware and software supply chains as an initial avenue4511to compromise an OT environment or as a mode to create malicious4512effects. AI can be a force multiplier to illuminating supply chains,4513identifying vulnerabilities in hardware and software, and supporting4514the secure implementation of devices in OT environments. To help drive4515this, LLNL is leading efforts to incorporate AI into the Energy Cyber4516Sense program focused on Energy Sector supply chain risk management.4517    These AI-based tools do not replace human defenders but rather4518amplify their effectiveness. By automating the analysis of complex data4519and highlighting the most significant threats, AI allows security teams4520to respond faster and more accurately--critical in environments where4521down time or disruption can have serious safety and operational4522consequences.4523    In summary, AI augments the detection and response capabilities of4524OT defenders by:4525   Reducing alert fatigue through smarter filtering and4526        prioritization4527   Detecting sophisticated and previously unknown attacks4528   Enabling faster, more coordinated responses4529   Providing actionable insights that support both immediate4530        and long-term security improvements.4531    As cyber threats to OT environments continue to evolve, integrating4532AI-driven tools is becoming essential for maintaining robust, resilient4533operations.4534    Question 3. Are you concerned about the risks to OT posed by4535quantum computers that are capable of breaking cryptography? If yes,4536what is the role of the Federal Government in helping critical4537infrastructure owners and operators address the potential threat to4538their OT posed by advancements in quantum computing?4539    Answer. While encryption on OT networks can increase the security4540of the system, there are concerns that it could impact network4541performance, introduce challenges with some legacy devices and reduce4542visibility into the network. As a result, encryption is not widely used4543on OT networks, so once an adversary has access to an OT network,4544breaking cryptography is often unnecessary, rendering risks from4545quantum attacks somewhat limited.4546    However, there are cases where the risk of quantum attacks is of4547concern for OT systems.4548   If access to the OT systems is provided through VPNs or4549        other remote access solutions (RDP, SSH) that rely on weak4550        cryptography for security, then they may be vulnerable to4551        quantum attacks.4552   With more prominent cloud adoption by OT operators, any OT4553        services or data leveraging the cloud, where encryption is4554        heavily used, could be susceptible to quantum attacks.4555   There is potential that adversaries are currently collecting4556        encrypted traffic that could contain credentials or other4557        sensitive information that once decrypted would allow4558        adversaries to access the OT systems even if quantum-safe4559        encryption was adopted.4560   OT services that use encryption will need to be updated with4561        quantum resistant algorithms. However, many OT devices have4562        limited processing power and memory, which could make4563        transition to more complex, quantum-safe encryption algorithms4564        challenging.4565   Many firmware updates are digitally signed. Quantum4566        algorithms could be used to derive underlying private keys,4567        allowing the adversary to make malicious modifications to a4568        device's firmware and forge the digital signature of the4569        vendor, allowing it to be run on the device.4570    In summary, there are use cases that need to be considered for OT4571systems in a post-quantum world and there is a need to identify risks,4572enumerate vulnerable OT applications and design effective mitigations.4573Collaboration between vendors, operators, service providers,4574regulators, and sector risk management agencies is essential to get4575ahead of this threat.4576    Question 4. Can you describe the trends you have seen regarding how4577hacktivists target Western critical infrastructure? What are their4578motivations, capabilities, and primary targets?4579    Answer.4580Rising threats to Western critical infrastructure4581    Over the past 20 years, cyber defenders have witnessed a notable4582rise in the volume, sophistication, and targeting of Western critical4583infrastructure by threat actors. In today's cyber landscape, attackers4584can directly impact the physical systems supported by information or4585operational technology, resulting in cyber-physical effects such as4586power or water outages and degraded services.4587    Traditional social protest cyber attacks continue to grow,4588disrupting fuel stations and web services to draw attention to activist4589causes. The availability of attack tools, safe havens for operations,4590and the expanded attack surface of Western infrastructure contribute to4591a persistent opportunity for hacktivists. Increasingly, such activity4592also serves as a front for hybrid, nation-state-sponsored campaigns4593aimed at advancing geopolitical objectives.4594Motivations and key actors4595    Hacktivists targeting Western critical infrastructure are motivated4596by geopolitical agendas, political objectives, or social protest. The4597majority of current activity comes from pro-Russian, pro-Iranian, and4598vigilante groups, with many receiving direction and funding from state4599sponsors. This blurs the line between independent activism and state-4600backed cyber operations.4601    These hybrid threats often masquerade as hacktivist activity but4602later prove to involve nation-state actors, as seen in the 20154603Ukrainian energy grid attacks.\1\ They merge elements of hacktivism,4604financial crime, and geopolitical strategy, exploiting global events to4605advance their sponsors' interests.\2\4606---------------------------------------------------------------------------4607    \1\ https://www.wired.com/2016/03/inside-cunning-unprecedented-4608hack-ukraines-power-grid/.4609    \2\ https://www.airuniversity.af.edu/Wild-Blue-Yonder/Article-4610Display/Article/4040975/resilient-nations-and-hybrid-threats-what-can-4611the-united-states-learn-from-swed/.4612---------------------------------------------------------------------------4613    Notable examples include:4614   The Cyber Army of Russia Reborn hacktivist group has4615        targeted critical sectors in the United States--specifically4616        water and wastewater and oil and natural gas--with confirmed4617        incidents in California, Florida, and Pennsylvania.\3\ Target4618        selection for this group is designed to support Russian4619        interests, and reports have tied them to Sandworm, a Russian4620        military intelligence unit.\4\ The group has been sanctioned by4621        the U.S. Department of Treasury.4622---------------------------------------------------------------------------4623    \3\ https://hub.dragos.com/hubfs/312-Year-in-Review/2025/Dragos-46242025-OT-Cybersecurity-Report-A-Year-in-Review.pdf?hsLang=en.4625    \4\ https://www.wired.com/story/cyber-army-of-russia-reborn-4626sandworm-us-cyberattacks/.4627---------------------------------------------------------------------------4628   Since 2022, utilities in North America and Europe have4629        reported a surge in attacks from pro-Russian hacktivists4630        against water and wastewater treatment facilities, dams, energy4631        providers, and the food and agriculture sectors.\5\4632---------------------------------------------------------------------------4633    \5\ https://www.cisa.gov/sites/default/files/2024-05/defending-ot-4634operations-against-ongoing-pro-russia-hacktivist-activity-508c.pdf.4635---------------------------------------------------------------------------4636   In 2023, CyberAv3ngers (linked to Iran) attacked water4637        treatment facilities in the United States and Israel where they4638        demonstrated access to Human Machine Interface (HMI) devices by4639        defacing the device by leaving a message threatening Israeli-4640        made equipment.\6\4641---------------------------------------------------------------------------4642    \6\ https://claroty.com/team82/research/from-exploits-to-forensics-4643unraveling-the-unitronics-attack.4644---------------------------------------------------------------------------4645   GhostSec attacked programmable logic controllers (PLCs) of4646        Israeli companies as part of their ``Free Palestine''4647        campaign.\7\4648---------------------------------------------------------------------------4649    \7\ https://www.otorio.com/blog/pro-palestinian-hacking-group-4650compromises-berghof-plcs-in-israel/.4651---------------------------------------------------------------------------4652Advances in AI and availability of tools enable hacktivists4653    Hacktivists have a treasure trove of cyber capabilities to enable4654their operations. Their main techniques are distributed-denial-of-4655service (DDoS), hack and leak, website defacements, publishing4656personally identifiable information, and network intrusions.\8\4657Hacktivists have access to a bevy of tools on the internet and can4658purchase exploits on the Dark Web, often with technical support4659included. Training in hacking is readily accessible through free and4660paid services, enabling hacktivists to upskill quickly to target4661specific technologies or take advantage of well-publicized exploits. In4662addition, services that sell credentials from information stealers can4663be used as part of operations for initial entry, giving hacktivists4664access to critical infrastructure organizations for a fee. Network4665intrusions can lead to the most crippling effects, which could include4666data wiping of critical equipment.\9\ Wiper and ransomware software is4667readily available for sale, and in some cases with technical support4668arranged as part of the purchase.\10\4669---------------------------------------------------------------------------4670    \8\ https://cloud.google.com/blog/topics/threat-intelligence/4671global-revival-of-hacktivism.4672    \9\ https://www.cisa.gov/sites/default/files/2024-05/defending-ot-4673operations-against-ongoing-pro-russia-hacktivist-activity-508c.pdf.4674    \10\ https://www.justice.gov/usao-edny/pr/hacker-and-ransomware-4675designer-charged-use-and-sale-ransomware-and-profit-sharing.4676---------------------------------------------------------------------------4677    In today's cyber space, a motivated and financed hacktivist can4678upskill, find, target, and even leverage AI to exploit poorly-defended4679critical infrastructure assets.4680Hacktivist techniques are regularly observed through the CyberSentry4681        Program4682    Through participation in the CyberSentry program, LLNL threat4683hunters have observed many cyber intrusions to critical infrastructure.4684Attribution of these attacks is difficult to conclusively prove, as the4685emergence of hybrid threats blends criminal with geopolitical4686motivations. LLNL analysts have observed exfiltration of sensitive4687data, attempted extortion, attempted ransomware deployment and4688cryptocurrency mining, some of which could be hacktivist-related.4689    Over the past few years, targeted threat hunts have been conducted4690against ongoing hacktivist campaigns. CyberSentry partners have4691notified CyberSentry of ongoing DDoS attacks, a known tactic of4692hacktivists, which were never attributed to a known threat actor.4693Without further visibility, monitoring and analysis of CyberSentry4694data, it will remain unseen if hacktivists are targeting our4695CyberSentry partners.4696National security implications4697    Although the primary target of hacktivist groups may be a4698privately-owned energy or water facility, the impact could have4699cascading effects on national security. LLNL works closely with DOE to4700identify cyber risks that could impact Defense Critical Electric4701Infrastructure. This work with the DOE is instrumental in modeling the4702second and third order effects of cyber attacks and the consequences to4703national defense. These cyber weaknesses, much like the Goth's4704targeting of Rome's aqueducts, could lead to catastrophic4705consequences.\11\ Western critical infrastructure is the underlying4706backbone for our Nation's and Western allies' ability to conduct4707defense, and without the water, energy, and communications4708infrastructure our military capability could significantly be degraded.4709---------------------------------------------------------------------------4710    \11\ https://historyofthegermans.com/2021/12/17/totila/.4711---------------------------------------------------------------------------4712    The threat of hacktivism to Western critical infrastructure has4713significantly morphed over the past 20 years--from groups motivated by4714inspiring social change with little to no cyber skills to present-day4715state-sponsored hybrid threats with deep experience in hacking and4716network intrusion. The combination of more internet-connected devices4717managing cyber physical systems and the proliferation of attack tools4718and training available to would-be hackers has intensified the risk of4719significant cyber events impacting critical infrastructure.47204721                                 [all]

Witnesses

4 witnesses appeared, with 9 papers on file.

NamePositionPapers
Mr. Robert LeeChief Executive Officer and Co-Founder, Dragos, Inc.Truth in Testimony · Testimony
Dr. Nathaniel GleasonProgram Leader, Lawrence Livermore National LaboratoryTruth in Testimony · Testimony · Biography
Ms. Kim ZetterAuthor and JournalistTruth in Testimony · Testimony
Ms. Tatyana BoltonExecutive Director, The Operational Technology Cyber CoalitionTruth in Testimony · Testimony

Documents

The committee filed 2 documents for the meeting.

DocumentKindFormat
Hearing: Witness ListHearing: Witness ListPDF
Hearing NoticeSupport DocumentPDF