House seal

House · Hearing transcript

Modernizing DHS SRMA Role: Data Centers, Telecom Networks, Space Systems

Wednesday, April 29, 2026

Summary

  • Mark Montgomery (Senior Director and Senior Fellow, Center on Cyber and Technology Innovation, Foundation for Defense of Democracies) urged designating data centers and space as separate critical infrastructure sectors.
  • Robert Mayer (Senior Vice President, Cybersecurity & Innovation, USTelecom — The Broadband Association) called for coherent federal supply-chain policy and sustained CISA programs like JCDC and Anchor.
  • LaMonica McIver pressed Montgomery on securing AI data centers in communities, and Montgomery recommended standoff distances, drone defenses and NIST cyber standards.
  • Bennie Thompson and Seth Magaziner condemned CISA workforce cuts as dangerous, while Andrew Ogles focused questioning on supply chains, data centers and subsea cables.
  • Scott Algeier (Executive Director, Information Technology-Information Sharing and Analysis Center) urged Congress to reauthorize information-sharing protections and restore CISA staffing and industry partnerships.

Morning digest

Get hearings like this in your inbox

Free weekday email. Unsubscribe anytime.

Hearing Details

Witnesses

Members Who Spoke

View on Congress.gov

Transcript

Rep. Ogles (TN-5)11:24 – 12:31

The Committee on Homeland Security, Subcommittee on Cybersecurity and Infrastructure Protection will come to order. Without objection, the Chair may declare the committee in recess at any point. The purpose of this hearing is to assess the Department of Homeland Security's role as a Sector Risk Management Agency or SRMA for the communications and information technology sectors and to assess whether that role is keeping pace with the evolving thr- threat environment facing America's digital infrastructure. This hearing will examine how infrastructure such as hyperscale data centers, telecommunications networks, sub-C cable systems, and space-based communication platforms fit within the existing critical infrastructure sector, construct, and whether the department's resources and authorities sufficiently support its SRMA role for these sectors. Now we will be having a vote series called here shortly, so I will reserve my opening statement until after that series so that we can get to the witnesses' statements. That said, I now r- recognize I now recognize you, sir.

Robert Mayer (Witness)12:32 – 12:32

Sure.

Rep. Ogles (TN-5)12:32 – 12:38

Yeah. I now recognize the ranking member of the full committee, the gentleman from Mississippi, Mister Thompson, for his opening statement.

Rep. Thompson (MS-2)12:39 – 18:17

Thank you very much, Mister Chairman, and uh I understand the sequencing of votes this morning is interrupting uh part of the activities of the committee. Uh, I wanna welcome a newly minted ranking member, Miss Ramirez, to the committee and uh this is her main board. We appreciate her uh leadership on the full committee and as a former uh uh very interested person in a lot of things, we we're glad to have you. So I'd like to thank the witnesses also for participating in today's hearing. In October, twenty twenty four, we all learned about salt typhoon's successful breach of US telecommunications network. Chinese state-backed hackers had successfully gained access to the sensitive communications of some of the most high profile individuals in our country and accessed data on a vast number of Americans. Undetected for months or even years, this wide-ranging incident demonstrated the sophistication of PRC hackers and the vulnerabilities in our own critical infrastructure. At the time, many thought salt typhoon would be a wake-up call about the needs to prioritize cyber security and invest in improving our cyber defenses. The Biden administration immediately took steps to better understand the incident and strengthen our defenses by launching a cyber safety review board investigation into the incident and the FCC proposed cyber security requirements for telecommunications providers. Unfortunately, starting on January twentieth of last year, President Trump's vendetta against CICER, coupled with Doge's slash-and-burn approach to dismantling the federal government has taken priority over our national security. Under President Trump's CICER has forced roughly one thousand employees, uh almost a third of its staff, out. The Cyber Safety Review Board has been disbanded, leaving Congress and the public largely in the dark about how Salt Typhoon's telecommunications breach occurred. Key public-private collaboration forums, like the Critical Infrastructure Partnership Advisory Committee, or CPAC, has And a Republican-controlled Congress has repeatedly failed to pass a long-term reauthorization of the Cyber Information Sharing Act of twenty fifteen, despite broad bipartisan support for doing so, leaving the private sector in limbo as we as to whether the laws via liability protections will remain in place going forward. Now as we face new threats like rapidly advancing frontier AI models and the war with Iran, CISL's capacity to partner with critical infrastructure and fulfill its sector risk management agency's responsibility is significantly diminished. We must work to right this ship before it's too late. I appreciate the witnesses for being here today to share their perspectives from the private sector on what more is needed from CISL. and Congress to better defend the communications and information technology sectors. We all rely on these sectors every day, and breaches of communications and IT networks put Americans' privacy and our national security at risk. We must act quickly to rebuild CICER's capacity to serve as the sector risk management agency that these sectors need. And CICER must re-establish the public private partnerships that are necessary for the government and critical infrastructure to productively collaborate to secure the homeland. I hope we can have a candid conversation today about the current status of CICER's SRMA work and how CICER can better support critical infrastructure. For CICER to serve the communications and information technology sectors properly, it will need to have sufficient and resources to respond to the evolving threat landscape. I'm glad that CICER is looking to hire over three hundred individuals in the near future, but I worry if qualified applicants will be interested in serving at an agency that has seen its morale destroyed by hostile administration. Additionally, CICER must develop the capacity and leadership to not just manage day-to-day activities, but to carry out meaningful planning and operations that address new threats in technology. That will require restored partnerships with critical infrastructure. I know the witnesses here today have devoted their careers to improving our national security and have long histories of working with CISA and other federal agencies to better secure our critical infrastructure. I look forward to their testimony on what more CISA, and its subcommittee,

Rep. Ogles (TN-5)18:31 – 18:47

Thank you, Ranking Member Thompson. Uh, before we proceed, I would like to also uh take a moment to formally welcome Ranking Member Ramirez as the Ranking Member of the Cybersecurity and Infrastructure Protection Subcommittee. The subcommittee has often been a setting for bipartisanship and collaboration. I look forward to

Rep. Thompson (MS-2)18:59 – 18:59

Right.

Rep. Ogles (TN-5)18:59 – 22:42

Uh, the ranking member is gonna reserve her opening statement as well, and then we'll proceed uh forward. Other members of the committee are reminded that opening statements may be submitted for the record. I am pleased to have a distinguished panel of witnesses before us today on this important topic pursuant to commit committee. Committee Rule eight C. I ask that our witnesses please rise and raise their right hands. Do you solemnly swear that the testimony you will give before the Committee on Homeland Security of the United States House of Representatives will be the truth, the whole truth, and nothing but the truth, so help you God. Let the record reflect that the witnesses have answered in the affirmative. Thank you and please be seated. I would like to formally introduce our witnesses. And again, thank you for being here in my Humble apologies for the disruption and flow. Make sure that's not me. Okay. Um, uh, of the proceedings, we'll get to vote, so we'll come back as quickly as possible. Mister Robert Mayer is Senior Vice President of the Cybersecurity and Innovation at US Telecom, the broadband association with responsibility for leading cyber, and national security policy and strategic initiatives. He's the current Chair of the Communications Sector Coordinating Council, and serves as Co-Chair of the Department of Homeland Security's IC T supply chain, Risk Management Task Force. Mister Mayor has previously served as the top Telecommunications Official for New York State, held various regulatory consulting and analyst roles, and served in the US Air Force supervising intelligence and communications operations. Mister Sam Visner is the Chair of the Board of Directors for the Space Information Sharing and Analysis Center. He also serves as Security Director of Netcracker Technology, which he represents as a member of the Executive Committee of the Communications Sector Coordinating Mister Visner is the former Director of MITR's National Cybersecurity FFRDC or NCF, and served as Chief of Signals Intelligence Programs at the National Security Agency. Re-Admiral Mark Montgomery is Senior Director of the Center on Cyber and Technology uh Innovation, CCTI, and a Senior Fellow at the Foundation for Defense of Democracies. At CCTI, he leads efforts to advance U. S. national and economic counter cyber threats and combat adversary cyber-enabled economic warfare campaigns. RADM Montgomery also serves also leads rather CSC two point O, an initiative focused on implementing the recommendations of the Cyberspace Solarium Commission. Prior to these roles, he was the Policy Director for the Senate Armed Service Committee and served for thirty-two years in the US Navy. Mister Scott Algier is the founder, president, and CEO of cyber security consulting firm Conrad, Inc., executive director for of the information technology information sharing and analysis center, ITISAC, and executive director of the food and agriculture information sharing and analysis center. He has spent the past twenty years at the intersection of cyber security policy and operations. Previously, Scott was ma- manager of homeland security at the U. S. Chamber of Commerce, where he coordinated the U. S. Chamber's critical infrastructure protection. cyber security and disaster management public policy initiatives. I wanna thank each of our distinguished witnesses. The the amount of experience you have uh on this panel is uh represents a couple hundred years, and for that we thank you uh for your your time here. So with that, I now recognize Mister Mayor for five minutes to summ summarize his opening statement.

Robert Mayer (Witness)22:43 – 26:17

Uh, Chairman Garbarino, Ranking Member Thompson, Chairman Ogles, Ramirez and members of the subcommittee, thank you for the opportunity to testify today. I'm Robert Mayer, Senior Vice President of Cybersecurity and Innovation at US Telecom and chair of the Communication Sector Coordinating Council. I also serve as co-chair of the Department of Homeland Security's ICT supply chain risk management task force. Today I will focus my remarks on three areas, our partnership with the Cybersecurity and Information Security Agency, CISA, the importance of sustaining and monitoring authorities for public-private coordination and the need for greater visibility and coherence in the ICT supply chain. For over six decades, the communication sector has worked hand-in-hand with the federal government to help protect the systems Americans rely on every day and that partnership has become even more critical, as cyber threats have grown more persistent, sophisticated and far-reaching. Some of the most meaningful advances in communication security have come from sustained operations engagement between government and industry through efforts like the President's National Security Telecommunications Advisory Committee, NSTAC, the Joint Cyber Defense Collaborative, JCDC, and the Enduring Security Framework, ESF. We look forward to supporting the critical infrastructure Fortify program, which will deepen structured engagement between CISR, allied partners and industry to help critical infrastructure organizations rapidly respond during periods of degradation. We should also build on proven mechanisms for collaboration while advancing durable programs such as the proposed alliance of national councils for homeland operational resilience or anchor initiative to support continuous engagement between government and industry on cyber security and resilience. This commitment must also extend beyond federal coordination. Strengthening resilience requires investment across the broader ecosystem. That critical infrastructure depends including support for state and local cyber security preparedness. That is why it is essential that Chairman Ogle's bipartisan Pillar Act moves swiftly through Congress to help strengthen cyber security capabilities at the state and local level. Congress can also help by delivering robust communications infrastructure through streamlined permitting processes and accelerated broadband deployment. Equally important is modernizing broadband networks, continued investment in next-generation infrastructure, such as fiber deployment and data center connectivity enhances both performance and security of the communications networks. Congress and multiple administrations have taken important steps to address legitimate national security concerns tied to the supply chain ecosystem particularly as geopolitical threats have intensified. But too often these efforts develop across multiple agencies and authorities in parallel rather than in coordination. Greater alignment across agencies, clearer lines of authority and more transparency in how supply chain related risks are identified and managed would help industry respond more effectively to emerging threats while strengthening broader national security objectives. As the President's cyber strategy for America strongly emphasized, strengthening the strengthening the partnership between government and industry and modernizing the frameworks that support coordination will bring greater coherence to cyber security policy and operations. We look forward to working with

Rep. Ogles (TN-5)26:27 – 26:32

Thank you, Mister Mayor, I now recognize Mister Bissner for five minutes to summarize his opening statement.

Samuel S. Visner (Witness)26:33 – 32:09

Thank you. Mister uh Chairman Ogles, Ranking Member uh Jimenez, Mister Thompson and members of the subcommittee on Cybersecurity and Infrastructure Security Protection, thank you for the opportunity to speak before your subcommittee and share with you my thoughts on the protection of the swiftly evolving telecommunications, information technology and space ecosystems, all of which are vital to our national and economic security. H having failed retirement, I have the honor to serve as the chair of the board of directors of the Space Information Sharing Analysis Center or ISAC. We were founded in two thousand nineteen and our principal uh we are the principal uh information sharing platform for industry and between industry and government regarding threats to our space system. And while our initial focus was on threat cyber threats to these systems, we look at a wide range of threats, including cyber, jamming, spoofing, supply chain challenges, space weather, and more. The Space ISAC and other ISACs, as you know, are led by and funded principally by our industry and academic members. The ISAC partners, however, uh with the public sector. We have in place MOUs with several US government agencies as well as space and cyber security government authorities in Australia, France, Greece, Germany, Israel, Taiwan, and the United Kingdom. And more partnerships are in progress, including a recent MOU we signed with NATO. We set up in two thousand twenty-three an operational watch center in Colorado Springs, one that monitors threats to space systems using a wide range of data from our members, partners, and open sources. And we used the DHS traffic light protocol to control the dissemination of that reporting. We've also announced global hubs in Australia, Canada, Japan and the UK. As these global global hubs become operational and as we build watch center components in these countries the ISAC will gain twenty four seven follow the sun coverage of space syst of space systems environment threats to that environment and incidents that affect the security and resilience of that environment information about these and other space ISAC developments can be found at the link that I've been that's been placed into my written testimony we also convene task forces and working groups to examine and propose challenges and uh uh uh approaches to SICCI space system security challenges, including space system governance analysis, quantum security, and now the security of CISLUNAR operations and other uh and and other domains. Um, the ISAC has grown rapidly. We have over a hundred twenty members. We're a member of the National Council of ISACs, and the US and the EU Council of ISACs as well. From this foregoing, I hope to make clear a few key points, first, the speed and scope with which we have operated and will continue to operate uh, reflect our view that all critical infrastructures depend on space. While in two thousand nineteen there were about two thousand act active satellites today we count over fourteen thousand five hundred with estimates ranging from thirty thousand to as many as sixty thousand by uh twenty thirteen. Surface and air transportation systems depend on space-based navigation. Maritime fleets use space systems for navigation as well as communications. Space systems provide timing data Space-based remote sensing is vital to farming, including what we call precision agriculture, which uh allows which uses space-based systems to pinpoint areas for cultivation and fertilization. Financial systems depend on space infrastructure with satellite commu technology providing precision timing for transaction time stance, GPS for global synchronization and secure data connectivity, even for remote ATMs and high-frequency trading. Space-based communications leak remote locations and commercial space systems are being used by our government for national security and civil government. Industry now leads government in the number of space-based imagery platforms, global five G networks using thousands of satellites are providing worldwide five G IT back planes so space ISAC's members and partners regard space systems absolutely as critical second much of the space systems domain is comprised of unique infrastructure including manufacturing launch ground segment, user segment, and now These are infrastructures are growing rapidly and our members and partners believe we can brook no delay in the protection security and resilience of these supply chains CISLUNAR operations are gonna have their own unique infrastructures including their own navigation satellites and planning for the security of these new infrastructures should start now uh next space system missions are evolving we're likely to see CISLUNAR and asteroid mining uh new commercial space uh stations um energy production, orbital cloud, and data centers. And all of these, securing all of these, will pose their own challenges. Um, and I'm gonna abbreviate my comments because we are running out of time. Um, from the uh, we we leave that that these, the security of these systems must be a global endeavor. To that end, the Space ISAC has been from its inception a global effort, that includes our allies and partners. We should remind each other that prior to Russia's attack on Ukraine, the first thing they did the day before they crossed that border was in fact an attack on a commercial space, uh, space-based satellite communication system. And we have continued to track and report to our members and partners attacks by our adversaries on the space systems on which uh on which we depend. Let me at this point abbreviate my comments and thank you very much. I look forward to your questions. Thank you.

Rep. Ogles (TN-5)32:11 – 32:17

Thank you, Mr. Bissner. I now recognize Rear Admiral Montgomery for five minutes to summarize his opening statement.

Mark Montgomery (Witness)32:17 – 37:28

Uh, thank you, Chairman, all those ranking members, Thompson and Ramirez, and distinguished members of the subcommittee. On behalf of the Foundation for Defense of Democracies, thank you for the opportunity to testify today. The subject of this hearing is timely. You know, our nation is under attack in cyberspace. Our adversaries are increasingly seeing our communications networks as a US vulnerability. And China particularly is conducting operational preparation of the battlefield. Activities that uh attack and put uh malware into our systems. They also do espionage. and intellectual property theft against companies and critical infrastructure. At the same time, we appear to be reducing our investments in cyber defense. I think America's national cyber resilience rests on three legs. The first is a capable federal government, able to mitigate, thwart, deter, and punish attackers. The second is an informed private sector, properly resourced to defend itself from these attacks. And third is a robust public-private collaboration together that facilitates the collective defense of the US economy and national security. Surprisingly, over the past year, the administration's reduced funding for key offices and decommissioned collaboration mechanisms such as CPAC, which I think are critical to our cyber defense. But honestly, Congress hasn't done much better. While this committee has shown important leadership on cyber security issues, unrelated partisan fights and interchamber disagreements have blocked the passage of important legislation. And while we fumble this ball, our adversaries are advancing. As I said, China continues to pre-position destructive capabilities our critical infrastructure. They use covert compromised networks, strategically and at scale, to conduct their malicious campaigns. Countering these threats is going to require reinforcing the three legs of that national cyber resilience table. A critical component of that reinforcement is what this committee is looking at today, how the federal government fulfills its commitments to the private sector. Most specifically, how does DHS support the resilience of the rapidly expanding and evolving components of the communications and information technology? data centers, telecommunication networks, and space-based systems. If our nation does not properly secure these assets, our adversaries will steal, corrupt, and disrupt the data and communications that allow our economy to to function. You know, data centers and cloud infrastructure are becoming more vital to the American economic prosperity in our society due to their important role in enabling on-line services and telecommunication networks. The explosion of AI innovation has catapulted debates about the construction of data centers. in the national spotlight. But I believe the cyber and physical resilience of those data centers merits, an equal level of attention. The proliferation of these data centers is also increasing the demand for electricity. And it's also leading to digitization of the grid. We gotta make sure that in the pursuit of cost savings, we don't embed Chinese-made components in critical control layers of the grid. You know, understanding these sorts of risks and prioritizing mitigations requires a collaboration between the the energy providers and the federal government and and within the gov- government between the Department of Energy and CISA. You know, over the past year there have been some bright spots. The FCC has supercharged its efforts to ban Chinese state-owned emerging technology from critical infrastructures and specifically the FCC leveraged its regulatory authority to prohibit the sale of Chinese-made connected devices in United States. This is vital national security work, but it should not diminish what CISA needs to do as the sector management agency for the communication sector. You know, and in fact, banning Chinese telecommunications equipment is important, but in the case of salt typhoon that uh ranking member Thompson mentioned, the access vector was American Cisco routers. So really critical infrastructure is not just about who manufactures the hardware, but also about whether the manufacturers and the operators properly maintain it. In this regard, the administration's recent dissolving of CPAC and disbanding of the Cyber Safety Review Board were unhelpful actions. And I'm concerned that these failures are symptomatic of a greater problem in CISA's ability to carry out its SRA duties for the communication sector sector writ large. And within that sector, it's the security of the satellite communications and other space-based assets, it gives me the greatest heartburn. As Sam mentioned, uh, one of the first volleys in the Ukraine war was a s- Russian cyber attack against an American satellite communications company. You know, the consequences of failing to protect U. space systems and ceding space superiority to adversaries would be detrimental to national security. That's why I continue to endorse designating space systems as a US critical infrastructure sector, so that space-based assets receive the policy attention and risk management support they deserve. And I also support making NASA the sector's management agency. You know, we need to act now as our adversaries pursue these deliberate efforts to erode US space support priority. In my written testimony, I provided six good recommendations I'll just say the one that I really want to emphasize is fully funding CISA and ensuring that physic CISA conducts an effective force structure assessment. Thank you for the invitation to testify and I look forward to your questions.

Rep. Ogles (TN-5)37:28 – 37:34

Thank you, Admiral. I now recognize Mister Al- Algier for five minutes to summarize his opening statement.

Scott Algeier (Witness)37:36 – 42:17

Thank you, Mr. Chairman. Um, thank um, thank you, Ranking Member Thompson. Thank you, Ranking Member Ramirez, uh, members of the committee, uh, thank you for the opportunity to be here today. Uh, as mentioned, my name is Scott Algier. For nearly twenty-one years I have served as the Executive Director of the i- Information Technology, Information Sharing and Analysis Center. The ITI SAC is a not-for-profit, non-profit, partisan industry association formed in two thousand with a simple premise, that we're all stronger together. At a time when we're all resource and highly skilled nation state actors are targeting industry, the ITI SAC helps companies make and form the risk management decisions through voluntary threat intelligence. Our members span almost every segment of the IT sector that propels today's global economy. The ITI stack has long considered CISA to be a key partner. We value the relationships we have built with CISA. Uh, we are have always engaged in an honest and unpartisan way and will continue to do so. The threats facing critical infrastructure have never been more serious, and the ability to defend against them are strained. Capabilities, partnerships, and programs that industry depend on have been reduced or eliminated. Engagement with industry on operational threat intelligence matters is also reduced. The good news is that there is a path to renew and strengthen CISA. Uh, this could be achieved through the following actions. Implement a replacement for the, for CPAC. When CPAC, uh, when DHS disbanded CPAC, it removed the legal framework that enabled and protected strategic engagement between CISA and industry. As a result, most of the work with CISA is out of standstill. Our adversaries have not paused, they have not stopped. They are continuing to attack with impunity. Provide for a long-term extension of the Cyber Security Information Sharing Act of twenty fifteen. Uh, SYSTA twenty fifteen is a critical tool that provides liability, antitrust, and euphoria protections for sharing cyber threat intelligence. It is important to maintain a trust of the legal framework that incentivizes and protects companies who voluntarily share threat intelligence. confirm a assistant director. While this is not the purview of the house, uh the absence of a senate confirmed director creates a leadership gap and makes it harder for Sissa to advocate for resources and priorities. While Nick Anderson is doing an admirable job as acting director, the agency will benefit from having a senate confirmed director. Prioritize resources through collaboration. Resources, time, money and people are limited and must be leveraged to maximum effect. Collaborative collaboratively developing priorities can help industry and government allocate resources more effectively. Analyze the impacts of CISA staff funding reductions. Changing um staffing levels based on organization priorities is a common management practice, but to ensure CISA can maintain its vital core functions, it should engage with industry partners to understand the impact reductions we're having and evaluate whether any adjustments are warranted. Enhance analytical engagement with industry. CISA should designate cyber security analysts to support specific sectors. The analysts would uh build relationships with sector ISACs and their members uh to know and understand the specific industries and threats to them. This will create trusted relationships, better analysis, and improve threat intelligence. Um uh r- create common situational awareness. CISA currently sends alerts on specific incidents, but this is a whack-a-mole approach that is not suitable for a sustained capability that provides near real-time, strategic, and tactical threat intelligence. Uh, it it doesn't create shared situational awareness to inform decision making. Vulnerability management modernization. Are vulnerability, disclosure, and patch management processes already struggling with today's pace of disclosures? AI threatens to further stress this. CISA can convene a relevant communities to address this. Um, refining, SOSIA, the ITI sec and the IT sector coordinating council have expressed that the proposed SOSIA regulations were too broad and would result in it receiving more information than it could process. Limiting SOSIA's scope and scale to more closely align with legislative intent will not only reduce the reporting burden on industry but helps us to develop and distribute more meaningful threat intelligence. We applaud CISA for planning a series of town halls to receive additional input. Implement effective partnership principles. In in twenty twelve, the IT sector coordinating a council identified twelve

Rep. Ogles (TN-5)42:38 – 42:47

Thank you, Mr. Algier. As they have called votes, we will take a brief recess and reconvene promptly thereafter. Again, thank you to the witnesses

Scott Algeier (Witness)42:46 – 42:46

Thank you.

Rep. Ogles (TN-5)42:49 – 1:57:59

Uh pursuant to committee rules, the committee stands in recess. we're gonna reconvene uh this committee hearing um i know the votes are still uh ongoing so we're gonna jump right into questions uh and so i'll recognize uh myself for five minutes of questioning and then i'll

Robert Mayer (Witness)1:58:23 – 1:58:59

Sure. Sure. So I would say that over the last two years we've seen a marked um increase So I would say that over the last two year we've seen a marked um increase the quality and the frequency of intelligence briefings, classified briefings. Um, uh, information on all of the major, ma- major attacks were discussed in those environments. Uh, we sh- we shared with, sort of what we were seeing on our networks, they were sharing with us what the im- intelligence community was seeing. Um, and I think we've made a lot of progress in this, that area. I think one area that, uh, deserves greater attention is the ability

Rep. Ogles (TN-5)1:59:24 – 1:59:29

Oh thank you. Um, I'll go to Admiral Montgomery, uh, it with rapid

Robert Mayer (Witness)1:59:28 – 1:59:29

With rapid

Mark Montgomery (Witness)1:59:43 – 2:00:59

Yeah, thanks for asking that. It's exa exactly my greatest concern is that in our in our rush to build them or to have the environmental discussions about them we're missing the really important physical and cyber security discussions we have to make sure that they're both physically secure, but then we um and there I think about drone attacks as you probably have been briefed in uh in the uh Iran the recent conflict with Iran, the Iranians directly attacked uh US owned data centers in the uh uh uh you know within our our partners. But the second part is cyber security, and this has to do with both the supply chain of the parts you have in the data center, making sure that they're uh not from countries of concern like China, but secondly, that you're doing the proper level of, you've up the proper standards for security on them and that you have the proper operational environment one thing i'd recommend is we there should be a strong consideration of whether data centers and cloud need to be a separate critical and national critical infrastructure there's been a push for that in the past um it fell short with the cloud but now that you have the data centers as well and we can all see the dynamic the the the the large role they're gonna play in the united states possibly an independent national critical infrastructure that handles data center and clouds separate

Rep. Ogles (TN-5)2:01:01 – 2:01:13

So you you may have answered my my next question, but the UK has designated data centers as critical national infrastructure. Uh, do you believe that the United States should follow suit? And and that I'll open that question up to the rest of the panel, but uh Admiral.

Mark Montgomery (Witness)2:01:13 – 2:01:25

I do. In fact, of the things we're talking about today, data centers, space and telecommunications, I think they're three separate critical infrastructure. So I don't I don't know if Sam joins me with this, but I think space is a critical infrastructure, and I think data centers are a critical infrastructure.

Rep. Ogles (TN-5)2:01:26 – 2:01:29

Mr. Ma- Mr. Mayor, I will start with you and we'll run down the now.

Robert Mayer (Witness)2:01:29 – 2:01:52

Look, given the e exponential growth in data centers, we're gonna see more of that. Um, connectivity is gonna be a major aspect to that, so there are links to the communication sector. Um, but I think given the um, scrutiny that is required to make sure that those data centers are secure, uh, there would be a benefit, I think, in uh having them work together as a unique coordinating council.

Mark Montgomery (Witness)2:01:54 – 2:01:54

Mr. Mayor.

Samuel S. Visner (Witness)2:01:55 – 2:02:58

I'd thank you. Uh, thank you for the question, Congressman. I'd have to agree. if you take a look at what's happening with data centers, the infrastructure that data centers are are building, and that they're going to be driving with energy, you're gonna have massive data centers, hyper-scalers, data centers that are gonna be powered independently by small and modular nuclear reactors, that infrastructure is going to become an important part of the national landscape. It's gonna employ thousands of people, it's going to contrib contribute hundreds of billions and eventually trillions of dollars to the, Mr. Rajiv. Uh,

Scott Algeier (Witness)2:02:59 – 2:03:40

mr. chairman thank you for the question um i would like to just note that the data center community is currently represented within the information technology ISAC we have a number of data center uh providers who are members uh we've formed a what we call a special interest group for the data center providers so that they can communicate with other data center providers and share threat intelligence uh share mitigation practices share um policies on on both cyber and physical so right the the the data centers are integrated already into uh the critical infrastructure discussions and we they they we serve them through the information technology ISAC.

Rep. Ogles (TN-5)2:03:40 – 2:03:46

uh thank you thank you very much i now recognize ranking member the gentlewoman from illinois and mr. ramirez for five for five minutes of questions.

Rep. Ramirez (IL-3)2:03:47 – 2:07:21

uh thank you chair i wanna thank the four witnesses for being here i know that it's been a little untraditional uh having the votes in between our committee session, i wanna also thank uh chairman ogles uh for for his warm welcome today. I look forward to the work that we do in this subcommittee, particularly as we improve the cyber security posture of federal networks and critical infrastructure. Since today is my first hearing after being appointed to the ranking member of the cyber security infrastructure protection subcommittee I do think it's important for me to share my perspective on this work. Under this administration it's clear that the security of our communities, information, federal networks, and critical infrastructure have not been prioritized. Between the security failures of Doge, the abuses of immigrant families' data, and the decimation of CISA's workforce and resources, my colleagues here have demonstrated a lack of interest in safeguarding our nation's cyber security and our residents' civil rights and privacy. In neglecting necessary oversight, Republicans have deregulated emerging technologies, allowed bad actors to profit from violations of our civil rights, and consented to the weaponization of government systems. It's more critical than whenever that we assert our congressional authority and that we disrupt the the dere the the dereliction of duty and blatant corruption making us all less safe. So I'm clear, there's a lot of work that we have to do, especially in the subcommittee, and I'm ready to roll up my sleeves and get to work to protect the data, the rights and privacy, to defend CIC's mission, and to do so, I I wanna talk a little bit about where we are. You see, it's ironic to talk about modernizing the HSS sector risk management, when Trump has been in a vindictive campaign to dismantle CISA, the very agency he established, but started attacking the minute it became an obstruction to his interest. CISA serving as a sector risk management agency requires adequately resourcing and staffing the agency's critical infrastructure. That includes checks and balances and policy solutions that make us all more secure. So I wanna establish some facts. Since January, twenty twenty five, CISA has lost nearly one third of its workforce through terminations, involuntary reassignments, or deferred resignations that workers were harassed into accepting. The stakeholder engagement division, which conducts CISA's sector risk management work, was cut nearly in half. Between January twenty twenty five and December thirteen twenty twenty five, CISA's stakeholder engagement division said it lost ninety-six of its one hundred and eighty-nine employees when you look at that math that's half of the workforce. And during the Republican shutdown last CICER attempted to illegally fire additional staff at CET. Under the President's proposed budget of twenty twenty seven, funding for CET's international affairs, council management and strategic relations units would be eliminated, eliminated, only leaving CET's sector risk management agency unit still funded. These facts make it clear we're not just talking about a personnel loss, we're actually talking about a loss in institutional knowledge, sector-specific expertise, and trusted relationships. that we've built over time. So my question is for Mister Montgomery. How has the loss of key CSA personnel affected the agency's ability to execute its sector risk management agency responsibilities? In particular, Mister Gummer Montgomery, can you talk to me about how the loss of individuals with institutional knowledge undermines CSA's ability to carry out its mission?

Mark Montgomery (Witness)2:07:24 – 2:08:03

First, congratulations on your selection as ranking member and uh, I share your concerns about the loss of personnel. You know, I served thirty six years in the military and I never once had a subordinate say to me, sir, the the right way forward is to cut thirty five percent of my people, uh, and I'll get the mission done. I'm sorry, I love I do like Nick Anderson, the acting director, but I believe we're doing him a great disservice with these personnel cuts. Now, having said that, how it specifically impacts is the without the stakeholder engagement division you don't have the ability to set up the information sharing agreements to do the engagement with the sector. You know, when I said three legs to the to the uh national cyber resilience. It's how the government does,

Rep. Ramirez (IL-3)2:08:02 – 2:08:02

Mm.

Mark Montgomery (Witness)2:08:03 – 2:08:05

how the private sector does, and how we collaborate together.

Rep. Ramirez (IL-3)2:08:05 – 2:08:05

Mm-hmm.

Mark Montgomery (Witness)2:08:05 – 2:08:10

It's that collaboration together that gets lost. And I'd emphasize the removal of the CPAC,

Rep. Ramirez (IL-3)2:08:11 – 2:08:11

Mm-hmm.

Mark Montgomery (Witness)2:08:11 – 2:08:44

the Cook Overshuksher uh Partnership uh Advisory Council, and most importantly the removal of the multi-state ISAC and the um and the loss of its funding that's how we get funding down to our public utilities and our, and our um our uh local hospitals because it uh, I'm very concerned that the lack of that, these are two, these organizations in rural hospitals and in um and in underserved communities where the medical centers don't have the money to pay for the uh basic IT services themselves.

Rep. Ramirez (IL-3)2:08:40 – 2:08:40

Mm-hmm.

Mark Montgomery (Witness)2:08:44 – 2:08:56

So without those programs running properly, um I think the l- the most likely to be ill-served are our underserved communities or and our rural um public public health utilities.

Rep. Ramirez (IL-3)2:08:56 – 2:08:59

Thank you. I'll ask a follow-up question in the next round. Thank you.

Rep. Ogles (TN-5)2:08:59 – 2:09:33

uh we're gonna do a second round of questions uh so i'll i'll i'll start my my with myself um uh i wanted to follow up with you uh admiral montgomery and um and others can can can jump in as well on you mentioned the the supply chain risk um with components manufactured uh by the prc uh including chips power systems including infrastructure uh how and how would you or is it possible to harden our supply chain and and become um on on um on the PRC for these parts and components.

Mark Montgomery (Witness)2:09:34 – 2:11:07

Uh yeah thanks for asking, you know I did a report and testified to Congress last year to the China select committee about something called illuminations where we illuminated a hundred and eighty US weapon systems the vast vast majority of which had Chinese parts only two or three down s- levels down the supply chain. So even our military does a has a hard time with this. And I c- in my testimony I mentioned the Federal Communications Commission among m- among the many things it's doing. One of the things that I could really uh support is their the national security effort to remove China from our emerging technologies so when you ask, how do we get our supply chain right, we have to decide what are our emerging technologies, you know, five G, drones, um LIDAR, um uh motor cellular modems, you know, we need to get the we need to not have Chinese state-owned enterprises providing products to the US military and to the dot gov and so what I've noticed congress does is they first pass a law to remove these components from the dot mil then the next year we pass a law to remove them from the dot gov and then the next year we'd move them for the critical infrastructure and that's a nice sequence way and if i were to recommend an area to do it right now it's cellular modems which are in all our operational technology communicate back and forth to their point of origin which tends to be china i'm not sure we want our cranes our tractors our planes all communicating back to China each night with different different material, even if it's innocuous at first, it it could become completely sensitive later.

Rep. Ogles (TN-5)2:11:08 – 2:11:10

Is uh is anyone else wanna uh chime in?

Samuel S. Visner (Witness)2:11:11 – 2:13:27

I'd like to, thank you. And I agree with Admiral Montgomery's comments, but I wanna add a point. If you take if one takes a look um at the space at space systems, at the whole ecosystem, it's very much a commoditized industry now. You're going back in time to the early days of NASA, you know, where'd you get this, you know, where'd you get this part, I wanna see the factory. Where'd you get the bolt, I wanna see the people who made the bolt. Where'd you get the the the steel, I wanna see where the steel was made. Where'd you get the iron ore, I wanna see the vein of iron. So you had a great deal of visibility. That's not true anymore, necessarily. And we have a global supply chain, it's not just China, for space systems. And since we're gonna be depending not only on our space systems, but on those produced by allies and partners, better technologically to find vulnerabilities in space systems regardless of where they're manufactured. And I think one of the our uh the other panelists here talked about, well, there were problems with with domestically manufactured routers w in which we found vulnerabilities. So it's not just, yes, we should be worried about Chinese uh uh infiltration of the of the supply chain, but we also need better technology and better understanding of how vulnerabilities can be introduced into any of our systems, particularly given the commoditized nature of this, where you don't necessarily have the same level of visibility. I think we're all aware of what's happening right now with the undetected vulnerabilities in operating systems which are now only being uncovered by the, uh, by, by the, you know, by the mythos tool. We need to understand that we're likely to have vulnerabilities that have existed in some of these systems for many years, and the commoditization of the supply chain is something, is a challenge that, we're not going to we're not going to be able to to to overcome simply by eliminating one country we might that will help but it won't be enough but uh the the means to detect vulnerabilities and to mitigate them on anything that's manufactured wherever it occurs and that's one of the reasons why i've been pushing for a national r and d strategy on cyber security and particularly one for the for uh an r and d strategy on the security of our space systems thank you

Rep. Ogles (TN-5)2:13:27 – 2:13:29

thank you uh mister mayor i'll give you uh thirty

Robert Mayer (Witness)2:13:29 – 2:14:34

Yeah, I'll I'll be real quick real quick, as I mentioned in my testimony, there has to be coherent policy across the government agencies with respect to supply chain risk management. Right now we have Commerce BIS, we have the FCC, we have CISA, we have federal acquisition security uh councils. Um, we wanna see a coherent approach to supply chain. We also wanna see the intelligence community be more forthcoming with us, with respect to supply chain risks that they've identified. And lastly, i would say the dhs ict task force uh that i co-chair has been an excellent venue for working with our it partners the entire comm sector including the vendors as well as government uh participation we did for example work on a hardware bill of materials to identify what the criteria needs to be for evaluating your your supply chain so there's a lot of activity that can be rationalized but it should continue with co- coordination with i t sector the comp sector uh and government uh participants so such as a

Rep. Ogles (TN-5)2:14:33 – 2:14:43

thank you uh i let you go a little bit over but uh let me uh go back to the second round let me uh yield and and recognize uh the ranking member again for the for five minutes of questions

Rep. Ramirez (IL-3)2:14:45 – 2:15:09

thank you i wanna come back to admiral montgomery um in the first round we talked a little bit about the impact that the cut in workforce has had on CISA now i wanna also ask you to comment on how the administration's actions cutting CISA more broadly undermine its ability to support SMAs that are building capacity, building capacity like EPA and the Department of Agriculture. Can you talk a little bit more about that?

Mark Montgomery (Witness)2:15:10 – 2:15:40

Uh, thank you. You know, one of the responsibilities is that a national it says I should be the national coordinator for our resilience effort. Um, in the in the cuts that have occurred, their ability I I would not have given them high grades previously on their ability to work with EPA um health and human services agriculture, you know, the uh, th those are the three, the water, health care, and food, uh, food and agriculture are three of our worst performing um uh critical

Rep. Ramirez (IL-3)2:15:38 – 2:15:38

Mm.

Mark Montgomery (Witness)2:15:40 – 2:16:29

infrastructures and yet three of the most important to public health and safety. So they were poor before. It has only gotten worse under this. And as I said, it's a combination of cutting the people and then cutting the programs. And and in Congress you all have the s the state and local cyber security grant program which you've been unable to reauthorize for an extended When you combine those three efforts together, the cutting of the multi-state ISAC, the cutting of the personnel, and the cutting of the cyber security s the state and local cyber security grant programs, there's no way that these small public utilities, who don't have two wood nickels to rub together, normally in their budget for cyber security, are able to make the proper investments to protect those utilities against ransomware and against nation state actors. And so our our public health and safety at the very core, at our at our most vulnerable level, is

Rep. Ramirez (IL-3)2:16:29 – 2:16:59

Yeah. Well, thank you, Admiral. Uh, look, I I hear you loud and clear, and this this has been a concern for us here in the committee for for a while now. Cutting people, cutting programs in a time where we should be investing in the infrastructure of CISA, uh, is really detrimental to the security and safety of every single person in this country. So, I am committed as ranking member, as this new ranking member, to make sure that CISA is resourced, and it's capable of working with the critical infrastructure owners and operators,

Rep. Ogles (TN-5)2:17:10 – 2:17:17

Uh, I now wanna recognize um, the my colleague uh from Rhode Island, Mister Magi- uh Mister Magisner for his five minutes of questions.

Rep. Magaziner (RI-2)2:17:18 – 2:19:38

Thank you to the chair and to the uh new ranking member, congratulations. Um, I have to say cyber security is one of the issues here in Congress where I think there's the biggest disconnect between the rhetoric and the reality. The rhetoric is always very positive, that this is a bipartisan issue, that everyone agrees that we need to do more to protect our country against cyber threats from state actors, from international criminal organizations and the like. But the reality is that uh the administration with the complicity of the majority party in Congress continues to cut our cyber defense capabilities at the worst possible time and in fact even does things that undercut our defenses. And so, I just want to make sure everybody who's watching at home understands that the Trump administration has already eliminated a third of the entire CISL workforce, one thousand employees. These are the people whose job is to keep our country safe from cyber and has proposed an additional eight hundred cuts uh at CISA f- in their fiscal twenty-seven budget. The leadership at CISA has been a mess under the administration. The last acting director was a disaster. He failed a counter-intelligence polygraph test. He was caught uploading sensitive um, before he ultimately was removed from his position. Now the next guy, the appointee, just withdrew himself from consideration because he couldn't get confirmed by the Senate. And so the administration is not acting like they are taking cyber security seriously. And frankly, our colleagues in the majority are not doing anything about it either. The rhetoric is there. The rhetoric is always very positive, but the reality has been woefully lacking. So I'll ask all four expert witnesses here do any of you think that the huge staffing cuts at CISA are making our country safer

Mark Montgomery (Witness)2:19:40 – 2:19:59

I'll go ahead and start already cuz I already said no first I wanted to say your predecessor representative Jim Langevin absolutely did uh with representative Mike Gallagher from Wisconsin a significant amount of bipartisan work both in this committee and in the house armed services committee so it is absolutely achievable whether it can get done

Rep. Magaziner (RI-2)2:20:19 – 2:20:19

Yeah.

Mark Montgomery (Witness)2:20:19 – 2:20:36

So no, they're not gonna do better with a thirty five percent cut. They've got a that three hundred percent addition that uh ranking member Thompson mentioned in his opening remarks. It's just a down payment on what we need to do to recover CISA, to get it to get it to a place uh where it's useful.

Rep. Magaziner (RI-2)2:20:33 – 2:20:33

Yeah.

Mark Montgomery (Witness)2:20:36 – 2:20:52

I wanna say one other thing, you know, in my I graded the Biden I'm a lax grader at Georgetown, but I wou I still would give the Biden administration a D and I'd give this administration an F on their performance. It says uh it's completely unacceptable that our civilian cyber defense agencies treated like this.

Rep. Magaziner (RI-2)2:20:50 – 2:20:50

Great.

Mark Montgomery (Witness)2:20:52 – 2:20:56

We would never treat the National Security Agency or US Cyber Command the same way.

Rep. Magaziner (RI-2)2:20:56 – 2:21:51

Yeah, I agree. And just because I have limited time, I have to move to a different topic. So, I still have not had anyone give me a good reason why we should allow the administration to sell uh the H two hundred AI chips, the Nvidia chips, to China. Like to a country that is actively engaging in cyber warfare against us, and we are apparently now selling them the tools to do it. So, I'll ask you all. Would anyone like to take a crack at explaining why we should allow There's there's no good no one has been able to give me a good answer. There is no good answer. Congress is not powerless here. We could pass a bill to stop it today. As a matter of fact, a bill already passed out of committee over in foreign affairs, but it's been sitting on Speaker Johnson's desk for months. We we ought to do something about this. Um, and

Mark Montgomery (Witness)2:21:50 – 2:21:50

Mm.

Rep. Magaziner (RI-2)2:21:52 – 2:22:33

with that I I'm just about out of time, but I I do wanna elevate the point I think it was Mister Visner made. Um, um technology from from Anthropic we're still learning about it, but I think it does speak to the need to have some sort of a consumer safety test for AI products before they are released to the market because Anthropic is doing the right thing by voluntarily holding back on releasing it until the big players can be warned about about what their vulnerabilities are but they didn't have to do that there was no law that required them to. And so there is a I think a desperate need for Congress to step up and ensure that their uh in these products before they go to market with that i'll yield back

Rep. Ogles (TN-5)2:22:33 – 2:22:59

uh thank you uh we'll do one last round of questions and then um we'll conclude this um at this hearing uh let me go to mister visitor um you know clearly there is uh an intense threat environment when it comes to our um our um our our space systems what specifically is missing uh from the current us approach to space infrastructure security and what changes to law policy or federal organization would meaningfully improve our ability

Samuel S. Visner (Witness)2:23:00 – 2:25:08

Thank you, uh, Mister Chairman, for the question. Um, I don't know that I'm gonna be in a position to propose any legislative remedies, but there are some things that I think we ought to do. First, we need to recognize that space systems are in fact critical to every aspect of our national security, every aspect of our economic security, and every aspect of the security of our critical infrastructure. And we need to say so. We need to say so to ourselves, we need to say so to our people. We need to say so to our partners and our allies. and we need to say so to our adversaries as well, that this is a line you may not cross. That's a f a first thing. Um, I would refer you as well to a report done last year by the Council on Foreign Relations, and I was a um a member of the task force that produced that report. It's called " Securing Space". And it said that the White House should in fact um uh declare that that um that uh that space is a top priority for this country. Um, it recommended that the White House a space summit in the first year of the administration or as soon as possible. Um, and it also said that we ought to launch an assessment of the vulnerability of space vulnerability remediation deterrence. That included the participation of the Department of War, the intelligence community, the private sector, represented as a civil space organization's academia. And I would add, by the way, that it certainly should include DHS, which despite its its decrement in its in its staffing, there have been people at DHS who have worked very closely um with with the space ISAC and with the space systems domain um and have shown a a great deal of interest so i do think that before we do anything else we ought to get our act together and one of the things that i would ask that we look at is um the national security council could play a role in coordinating the various stakeholders in the federal government to coordinate space system security and that would include the the uh this national space council which i think um could and and hopefully will be reconstituted um that's something i think that could be done thank you

Mark Montgomery (Witness)2:25:09 – 2:25:13

sir can i add one thing to that you actually congressman lioux has twice

Rep. Ogles (TN-5)2:25:10 – 2:25:11

uh it's really liberal

Mark Montgomery (Witness)2:25:13 – 2:25:29

tabled a bill to make space a critical infrastructure and a bipartisan bill you should you should retake that bill up and pass it that if congress wants to impact things you force the government to make it a national critical infrastructure treat it that way

Rep. Ogles (TN-5)2:25:46 – 2:25:59

Oh, thank you for that. Um, I'll uh I'll stay with you, Admiral. Um, you you also mentioned um the the threat to subsea cable infrastructure. We did have a hearing on that uh previously um on this on

Samuel S. Visner (Witness)2:25:59 – 2:25:59

Oh.

Rep. Ogles (TN-5)2:26:00 – 2:26:13

by the full committee uh how serious is this threat and uh how would a successful attack on a major cable route affect um connectivity how would it impact national security the financial system um and the government's ability to operate and I would like to just like to hear your perspective on this.

Mark Montgomery (Witness)2:26:13 – 2:27:14

But I'm glad you mentioned that. It's absolutely a uh the the most significant uh kinetic threat to the communications network. In other words, if I went after the satellites I could attack ground stations, I could take out five percent of data flow. If I went after the submarines, and cut the cables, I could cut ninety five percent of data flow. So it's uh it's obviously critical that we defend these. They are generally undefended assets. We know both Russia and China are aggressively dev designing weapon systems to attack them. Um, less sophisticated countries like Iran or North Korea can drop anchors on those cables that does less damage but can still have an effect. So my my recommendation, sir, is that we take a we take a look at how we defend those cables, how we empower the coast guard to do it and then i would step even one farther back what is the supply chain for those cables to ensure that there isn't a a pre-existing flaw inserted in them so i'm glad you brought that up it's well worth the congress's attention

Rep. Ogles (TN-5)2:27:15 – 2:27:23

uh thank you very much um i'll conclude my questioning i'll uh i'll recognize uh the gentleman from new jersey uh miss mcgrib

Rep. McIver (NJ-10)2:27:23 – 2:29:15

thank you so much chairman and ranking member uh look ai data centers are shaping American cities, and they may be doing more harm than good. For many, an AI data center in your area means a decline in quality of life. It can mean higher utility costs, sometimes up to three hundred percent more a month. It means air pollution already causing up to one hundred million a year in health damages, and a strain on water supply, with numerous reports of contaminated well water. This reality is especially true for lower income communities and communities of color. My neighbors back home know this very well. A plant data center in Kenilworth, New Jersey in my district has received major pushback just in a few in the last couple of days from the community. These constituents deserve to be heard. That is why I introduced the AI Data Center Site Selection Transparency Act of twenty twenty six. This bill would ensure communities are informed at least one hundred and eighty days in advance before any major step toward developing an AI So communities have a real chance to organize, raise concern and demand accountability. It will be impossible to regulate AI data centers if they are forced onto people with no community input which makes things a lot worse. We know that the that the future is coming quickly and we need to make sure people are prepared to thrive not ignored or harmed. With that, Mister Montgomery, first of all, I wanna thank each of the witnesses for your testimony today and for coming here to be with us. even in our tricky schedules here in this uh place. Um, Mister Montgomery, as AI data centers rapidly expand across the country, how should we be thinking about ensuring both the cyber and physical security of these facilities as they are built within our communities?

Mark Montgomery (Witness)2:29:16 – 2:29:30

Uh, thank you for that question, and of course, I'm never gonna be opposed to transparency, so uh that's always a good thing. Um, what we've what I've argued for here uh is that we need to make data centers and cloud a, independent critical infrastructure,

Rep. McIver (NJ-10)2:29:30 – 2:29:31

Mm.

Mark Montgomery (Witness)2:29:31 – 2:30:16

one with which a federal agency is charged with coordinating across the other agencies to make sure that sort of transparency is clear, that the whoever the agency in charge is understands what the Department of Energy is setting for standards what the Homeland Security is setting for standards when they're on military basis what the Department of Defense is setting for standards and we have consistency across those and then most importantly it sets what are the physical standards in terms and it might be in terms of pollution but it also could be in terms of physical and what the cyber standards are for the security that whether it's the actual cyber security or the supply chain. So if we do that and make it a independent uh critical infrastructure sector, I think we'll begin to get the kind of transparency, consistency, and security that you're demanding.

Rep. McIver (NJ-10)2:30:16 – 2:30:40

Got it. Thank you so much for that. You've also noted that the cyber and physical resilience of these facilities merits the same level of attention and we've already seen real world risks, including reported attacks on data centers abroad that disrupted essential services for millions. Given those vulnerabilities, what baseline security standards or planning considerations should be in place before a data center is approved or constructed?

Mark Montgomery (Witness)2:30:41 – 2:30:59

Well, I think the physical security ones would begin with stand-off distances, uh, so, uh, that you traditionally have for military facilities against explosive devices. Uh, we're going to start thinking about drone security for these, uh, as we look at what's happened, not just in, uh, uh, Iran, but in your own state of New Jersey.

Rep. McIver (NJ-10)2:30:57 – 2:30:58

In New Jersey, yeah.

Mark Montgomery (Witness)2:30:59 – 2:31:28

Um and then uh we're gonna as I mentioned earlier we're gonna need cyber standards um both in terms of the supply chain and the actual operational technology running on the systems look and look I would hope that NIST which has also, we've talked about funding challenges, I think NIST's cyber security division has been cut too far, but it needs to become more involved in in this and start setting the NIST a NIST eight hundred series uh for data centers to establish the proper level of cyber security on those centers.

Rep. McIver (NJ-10)2:31:28 – 2:31:29

Thank you so much.

Rep. Ogles (TN-5)2:31:32 – 2:31:55

uh thank you very much uh i wanna congratulate uh the uh new ranking member uh look forward to working with you uh i wanna thank the witnesses for their testimony and the members for their questions members of of the subcommittee may have uh some additional questions for the witnesses and we would ask the witnesses to respond to these in writing pursuant to committee rule seven e the hearing record will be held open for ten days and without objection the sub subcommittee stands adjourned

Mark Montgomery (Witness)2:31:55 – 2:31:56

thank you

Morning digest

Start every morning briefed on yesterday’s hearings

A free weekday email covering yesterday’s hearings and transcripts newly unlocked in the archive.

Free weekday email. Unsubscribe anytime.