Summary
- Kirsten Davies (Chief Information Officer, Department of Defense) announced a major reorganization to unify enterprise IT and cybersecurity under the CIO to eliminate wasteful spending and accelerate modernization.
- Davies testified that the department is shifting toward a risk-based cybersecurity model, prioritizing zero trust implementation, supply chain security initiatives, and the retirement of legacy technical debt.
- Rep. Brad Finstad (R, MN-1) compared DOD's archaic IT to "Oregon Trail" software, prompting Davies to admit the department's legacy systems were a "tremendous surprise" requiring cultural change.
- Rep. Jeff Crank (R, CO-5) and Rep. George Whitesides (D, CA-27) both raised concerns that the high costs of CMMC compliance are driving small businesses out of the industrial base.
- Davies is conducting a review of the CMMC ecosystem to reduce regulatory burdens, while the subcommittee prepares to examine classified quantum computing threats and offensive cyber performance.
Topics Discussed
Transcript
Opening Statements
Good afternoon everyone and welcome to this hearing on information technology posture of the Department of Defense. To add a quote from Don Rumsfeld, you fight with the network you've got. We conduct command and control with the networks that we have. We pair our warfighters with the business applications we have. We plan and conduct operations on the desktops and laptops that we have. We fight at the speed of data and the underlying IT has never been more important. What I want to hear today is simply what is the state of these critical IT networks? I'm interested in hearing more about the department's plans to modernize our networks, process, provide access to secure cloud environments at all security levels and ensure the cybersecurity of our DOD and industrial base assets. While we'll be addressing DOD's major artificial intelligence developments at an upcoming research and engineering posture hearing, it is critical to note that none of that technology works without the foundation provided by IT. If the networks don't work well, nothing else will. So with that, we're joined today by the Department of Defense Chief of Information Officer, Ms. Kirsten Davies. I want to thank you for being so accessible. We've seen you a lot and we're grateful that you are accessible and open to interacting with us so freely. You joined the department from the industry in December. She brings two decades of experience leading large-scale cybersecurity and enterprise technology efforts for major global companies. Ms. Davies, thank you for being here and for your willingness to serve. And with that, I turn to Ms. Houlahan, the ranking member, before hearing our witness.
Thank you, Chairman Bacon. And I would also like to join you in welcoming Ms. Kirsten Davies as CIO at her very first public appearance before this subcommittee. You have a really challenging job, I know, and I'm looking forward very much to working with you. In the interest of time, I'm going to make keep my remarks very brief as well. Gone are the days when the department could focus simply on buying the latest weapon systems, blithely assuming that they will work without having to focus just as much on the vital networks and the data that enable them as well. It is that network and the information infrastructure that forms the backbone of the capabilities that our men and women of the Department of Defense depend on every single day. As CIO, the key initiatives under your purview are essential to the ability of the department to stay ahead of pacing threats. Zero trust implementation, network modernization, enterprise cloud adoption, protection of operational technology, securing our supply chain and retirement of technical debt, including cryptographic modernization, are all critical to reducing our vulnerabilities and to increasing increasingly advanced adversaries. Establishing a clear framework for data interoperability, for modernizing defense business systems, for continuing to deploy the mission partner environment, managing the department's spectrum assets and overhauling the authority to operate process are also just as critical to bringing our own operations up to speed. And most importantly, we must hire and retain the skilled workforce that these challenges demand. This has not been a straightforward matter in recent months, so I hope that we have this discussion aiming towards current and future initiatives that we can likewise dig into the effects of the deferred resignation program and hiring freezes for the future of the current and future workforce. Each of these matters I mentioned have been the subject of significant attention in recent National Defense Authorization Acts, but I know our work just like yours isn't done. You live these critical issues every single day. We look forward to hearing your perspectives on the department's progress and challenges and what we here in Congress should consider for further action. There is absolutely no alternative other than to get this right. And with that, I want to thank again our witness for appearing today. Thank you, Mr. Chair, and I yield back.
Before I recognize Ms. Davies, I just want to thank Ms. Houlahan. We've worked together on this committee, but we also co-chaired the quality of life panel, which had a tremendous success, 29 different issues passed into law. So that was good teamwork. Ms. Davies, you are now recognized.
DOD IT Modernization Strategy
Is my microphone working? Am I good? There we go. Thank you. Good afternoon, Chairman, Congresswoman Houlahan, distinguished members. Thank you for the opportunity to speak with you today about the department's strategy to transform technology and cybersecurity into a decisive warfighting advantage. Our focus is to enable data supremacy and decision superiority in the contested battlefields of today and tomorrow at the speed and scale our warfighters deserve. In the latest initiative of Secretary Hegseth's drive to efficiency and effectiveness, we are undertaking a bold transformation of enterprise IT and cybersecurity program, unifying these capabilities under the department's Chief Information Officer, myself. Through this effort, we will we will eliminate inefficient spending, reduce technical debt, accelerate modernization, drive consistent and up-leveled cybersecurity and unleash data and innovation from the core to the edge for our joint forces. Leveraging my oversight of DISA, the NSA's cybersecurity directorate and the department's Cyber Crime Center, we are working with military services, joint staff, combatant commands and defense agencies across four transformative pillars. I'll provide a few highlights here. Under pillar one, the enduring digital foundation, we're transforming our network infrastructure and communications transport, which extend from undersea cables to terrestrial fiber to advanced satellite capabilities, connecting everything from the home front to the tactical edge. This foundation supports every warfighting system and our global installations. We're driving continual modernization, expansion and hardening as well as broad 5G usage and data center modernization. We're evolving our cloud strategy in JWCC next. We're also leading a proactive approach to spectrum management and advancing PNT, position navigation and timing, ensuring ready and resilient capabilities that enable American warfighter dominance. Under pillar two, agile digital capabilities, we're expanding and maturing digital offerings. We are accelerating delivery of software and SaaS services and streamlining data architectures for streamlined data flows. We are shifting from slow legacy software development to modern agile delivery driving interoperability by design and delivering applications and analytics at the speed of relevance. We are driving extensive defense business systems work, whether modernizing or sunsetting old systems to enable clean audits and reduce wasteful spend. We are deploying mission partner environment, a persistent secure environment where trusted partners can be rapidly integrated. Under pillar three, cybersecurity for the warfighting ecosystem, in alignment with President Trump's national security strategy and the national defense strategy, we're moving from checklist-driven compliance toward a unified holistic risk-based approach. We will emphasize automation and dynamic and continuous monitoring. We will drive risk reduction rather than burdensome paperwork, focusing on anti-fragility and resilience through a holistic blend of streamlined processes, advanced technologies and skilled workers. We are refining the authority to operate process and accelerating our deployment of zero trust principles. We're also refining our risk management process and reigniting the DIB to align with the Secretary's Arsenal of Freedom initiatives. Finally, through pillar four, skills and partnerships, something that you mentioned in your opening comments, we recognize that people are our strategic edge. As part of our transformation, we're reviewing IT and cybersecurity roles to ensure clear responsibilities, accountability for outcomes and a bias for action. We're leveraging your provisions in the fiscal year 2026 NDAA to enhance recruitment and retention of cyber professionals and expand competitive compensation. We will be launching an extended top-tier certification program in partnership with industry and academia, which will offer upskilling and cross-skilling for our warfighters from new recruits to seasoned service members. And because we do not fight alone, we're doubling down to influence the digital transformation efforts of our allies and partners, which will better ensure all of coalition force readiness. As we advance this bold strategy, thank you for your continued interest and support in IT and cybersecurity topics and for the resources you provide to protect national security. The race for data superiority and decision dominance is won or lost every day and this strategy this strategy is a key part of how we together ensure the technology race is won by America. Together we will ensure the resilience, readiness and lethality of America's warfighters across every domain. I look forward to your questions.
Cybersecurity and Industrial Base Protection
Well thank you Ms. Davies. I appreciate your testimony. I've got three questions and I'm going to recognize myself for five minutes. We're working hard to strengthen the defense of our industrial base to include Secretary Hegseth's Arsenal of Freedom Arsenal of Freedom initiative. But none of that works if the companies building our ships, missiles and software are constantly getting hacked and losing intellectual property. Can you talk about how the department is thinking about cybersecurity not for its own IT but as something that directly affects our supply chains and military readiness? What more does the department need to do to help improve cybersecurity across the industrial base, not just in the DOD networks?
A great question. Thank you for that. You know, there's a lot that we can do. Historically speaking, we've been focusing quite a bit in IT security across the confidentiality of data. From my perspective, that's bread and butter. We should be doing that across the board, across government, across industry as well. I think where we can really look to refine our focus is also in the integrity and the availability side. So from a defense industrial base perspective, the Arsenal of Freedom is focused on munitions and advancement of of propagating more and more access for the DIB into our supply chain. We need to be looking much more holistically across the cybersecurity of our defense industrial base and their third parties as well. We do a lot of this work through DC3, which this body has supported in the past and I hope you will continue to support in the future. We have a great outreach there to the DIB on cybersecurity matters. Also through the NSA we have a great outreach there.
Thank you. My second question is on operational technology or OT cybersecurity, things like industrial control systems, shipyard systems and energy systems. These systems were or often weren't designed to be connected to networks, now they are, which creates vulnerabilities. Can you talk about how this problem is across the department and what your priorities are for improving this security for the OT and critical infrastructure for our installations and facilities?
Ranking member, a topic near and dear to my heart having come from the manufacturing industry. You're absolutely right to say that these systems were never intended to be connected directly to the internet. They're also legacy systems, largely speaking. They have a lot of hard coding in them which means they're not readily updated. Part of our focus area is going to be to establishing a center of excellence with regards to OT security. It's a very bespoke specific set of skills that are needed there, security controls that are needed to be wrapped around those. It's also an interaction again to my previous comments around the defense industrial base. So manufacturing has a lot of this operational technology and we need to be working more with them so that they are upgrading their security and their security standards therein.
Thank you. My third question deals with quantum computing. Obviously if we have it, that's a huge, you know, benefit for our side, it gives us an advantage. But if our adversaries got it, our encryption systems become vulnerable. The higher math issues that underlie our security or our encryption can be broken. So I understand the department and the federal government's moving towards a post-quantum cryptography or new encryption methods that are resistance to quantum computing. Can you talk about what you're working on this or where you're at?
Chairman, this is a huge field for us. Cryptography is a critical cornerstone of the Department of War systems. It's also a critical cornerstone across all government systems in and of itself. We have significant efforts in this, some of which I will defer to a closed session rather than speaking about here. But we look at this really quite holistically. We have targets from the federal government across government for us to achieve in the post-quantum compute world. It impacts everything from high to medium to low assurance devices, PKI, SSL. There's a significant piece of work that needs to be done not only for Department of War but across government as well. And I'll defer to the closed session for for greater details.
Thank you. I yield to the acting ranking member, Ms. Houlahan.
Electromagnetic Spectrum and Drone Warfare
The acting ranking member, thanks, the Chairman. So I have a lot of questions, but I think maybe I'll start first of all welcoming you again. I know you haven't been in this position very long and so I'm actually very interested in kind of understanding your thoughts on electromagnetic spectrum as you head into this position from your outside experience. It's something that since I've been here, which has been seven years, we've talked a lot about and done little about. Deconflicting the use for commerce versus DOD or official use or government use versus commercial use. We know that both have a valid claim or use for the spectrum. In your opinion or assessment these early days, how do you feel as though the DOD is doing in terms of using the spectrum efficiently?
Thank you for that question. Also passionate on this topic as well. We do understand that prior to my arriving there has been some great negotiations and laying flat in the one big beautiful bill with regards to certain bands being protected, which is wonderful. We know that the US military uses spectrum for every mission across all of our domains. It is critical. As the CIO for the department, it rests in my office to be navigating this for the Department of War with regards to broader interagency discussions. And I'm certainly involved and my team is involved in great detail across these discussions. We know economic security is national security and our warfighting is national security as well. So you have my commitment that I'll be balancing. But do you currently believe it to be being used efficiently and cooperatively with industry? The spectrum. It is, in my estimation.
But do you currently believe it to be being used efficiently and cooperatively with industry? The spectrum.
It is, in my estimation, it is right now. Of course there are ongoing, there's a balancing to be had ongoing. The President has been very clear about his direction with regards to protecting national security. And so what we're doing in the midst of all of this is ensuring that the warfighter needs are appropriately represented. The other thing that we're doing is we're looking at new technologies to see how the spectrum sharing can be much more dynamic and be more enhanced, it can be more secure. We are definitely on top of those things.
No, I think that's definitely the key. Another thing that's happened recently is the increased use of drones and of course there is a spectrum management issue there and strategy there. What have we learned from Ukraine if anything on this issue? What should we be doing better to accommodate what we can only expect to be increased drone usage with spectrum issues?
Thank you. I won't go sideways on updates that are provided by my colleagues with regards to active use in these areas. What I can say, we have learned quite a bit from the Russia-Ukraine war. There's significant use of UASs, drones, across multiple arenas. And we are actively looking at defense measures across that. We're actively looking at those spectrum bands that do impact that. We'd be happy to come back and provide a deeper briefing if that...
Sure, and would love of course to know what Congress can be doing to be more useful in that area. And my final question again regarding spectrum and data. Mobile data traffic is forecasted to grow between 20 and 30 percent just over the next few years alone, especially with the increased use and growing use of 5G. How are you and the administration able to balance or planning to balance this significant growth that we're anticipating in commercial wireless services and spectrum use against the needs for government access to the spectrum, especially as our commercial technology is getting better and starts encroaching on or blurring where the DOD operates?
Congresswoman, that's part of the active discussions around spectrum management. I will say that we are having incredible successes across deployment of 5G across our installations. We are currently at 88 percent of US military installations possessing commercial 5G infrastructure in at least one. We're diversifying that support, that backbone of 5G infrastructure as well. And those are ongoing discussions around the use, the dynamic use of spectrum for those.
Appreciate you. Thank you. I yield.
Mr. Finstad, you're recognized.
Modernizing Legacy Software and Systems
Thank you, Mr. Chair. Thank you for having this hearing today. And thank you, Ms. Davies, for being here. You mentioned a couple things in your opening testimony that kind of struck, I was maybe going to go a different direction, but I think I'm just going to talk a little bit about slow legacy software. So I had the honor of being the state director for USDA Rural Development Minnesota. And I was blown away at the archaic, slow, clumsy legacy software that our federal agencies operate under. And this probably isn't going to speak to maybe some of the staff, but a few of us on this table will associate with this, but I mean this is like Oregon Trail type stuff, right? When we can't use a mouse to click from one screen to the next, we're using the F1 key and it's a black screen with green cursors. I mean I'm thinking Oregon Trail. But yet we're called and you're called and the agency is called to, you know, the highest level of security. And we look at things like some of the failures in audits in the past and how do we kind of get our head around embracing commercial, you know, the commercial sector, what we've seen happen in the private sector. I mean I will tell you right now, Walmart knows where every toothbrush is in that big old company of theirs. But yet I wonder and I worry if we know where our bag of bolts are within the Department of War. And so on that front, you talked about modernizing legacy IT systems, you talked about the slow legacy software. What are the obstacles that you're seeing like right in front of you right now? How do we bring an Oregon Trail type platform, and I'm not, you know, making the assumption that you're all like the USDA, but how do, what are the obstacles that you see in front of you right now that can help us through this?
An area I'm extraordinarily passionate about. It was a tremendous surprise to me coming into the department to witness what you have reflected on as well, Congressman. I think some of the, first of all, the President recognizes these challenges. He's issued executive orders in support of us driving technology modernization, AI strategies moving forward. The Secretary has been very clear in his vision for us to drive through technological advancement. So what we're doing is really to look at where are the opportunities to streamline these efforts. Do we have old legacy systems that very few users are using? We should sunset them. We should migrate to much more consistent, contiguous platforms that are there. I think some of the barriers are simply that we've never done it this way before. When we look to introduce innovation and we look to introduce modernization, there are some wonderful people in the department who really want to embrace innovation. Those are the people that I'm looking to point out and say, hey, come alongside and let's do this together. I think the people inside the building realize that this is a big problem. I think in a lot of ways they've been writing for the right, waiting for the right leadership to come and say, we are now going to tackle this, roll up your sleeves.
I appreciate that. I appreciate your attitude around that. You've spent some time in the private sector, you're now in this role. You know, we sit around and pass an NDAA every year, we do about a trillion dollars of appropriations. I mean this is a big deal. A trillion dollars in the private sector, would we be successful operating under the legacy systems that we have in the private sector at a trillion dollars a year?
We wouldn't be spending that kind of money on legacy systems with a trillion dollar budget.
I appreciate that. So I think that is something again, this isn't an R or D issue, this should just be a USA common sense issue. I think this is something that should bring us together. We owe it to our warfighters to be, you know, as lethal with our external outward-looking systems as we are with our internal. And that helps the discussions that we have around this table when we're talking a trillion dollars. I would like to know with confidence that you all know where the bag of bolts is. Because at the end of the day if we don't, if you don't, our warfighters don't. And that is delay and that is cost and that is just a real inefficiency that we should be able to fix. By the time that you and I have talked here, I probably could have got a car loan on my phone. And so there's technologies out there. And so maybe on that front and last question for you, what are the challenges that you see in regards to that culture of the risk culture that you talked about, but also embracing some of the things that are off-the-shelf commercial products that we could bring in to make us more efficient and to really solve some of these legacy challenges that we have?
It's part and parcel of my strategy, Congressman. What you've heard me talk about in my opening comments and the comments for the record is we need to get after this. With the Secretary's leadership, we have the right leadership in place to be getting after these big problems. I've found historically things are a little bit less of a technology problem than they are a culture problem. I think we have a little bit of both in the department and what you're going to see with this leadership team, including with Honorable Michaels at R&E, myself, with Honorable Duffy in A&S, we have a whole of team effort at the department.
Thank you. I yield to Mr. Ryan.
Streamlining the ATO and Workforce Gaps
Thank you, Mr. Chair. Thank you, Ms. Davies, for being here. Two questions. The first is one that you rightly talked about in your opening statement and in your submitted testimony, one that a lot of us hear about and that there's strong bipartisan agreement and bicameral agreement on, which is the ATO process. And we all say the right things and put out the memos and give the speeches about speeding commercial capabilities into the department as my colleague just talked about, and then over and over those of us engaging with the best of emerging innovative companies, high growth companies and even our highest performing companies all come back to the ATO process is still frustratingly slow. A lot of us worked in the last NDAA to put in section 1521 that required you and your team to create an expedited review process for ATO. So I know we're not at the 180 day deadline yet, we're getting to it, and I know you have a lot on your plate, but could you just give us an update on how that's going and what more we can do if needed to speed that up?
Thank you for your passion around this issue. I think we would agree that that ATO process is much slower than it needs to be. It speaks to the risk management framework in and of itself, the ATO process being a part of it. There's a lot of managing of this by spreadsheets and emails. There's a lot of brokenness in the midst of inheritance process when you have one area that conducts a risk management on a piece of software or an asset and then that assessment, that analysis doesn't transfer over to the next ATO. These are the things that we're going to get after under my leadership. This fundamentally can be helped through technology. It can be sped up, still staying in alignment with the regulatory requirements around the risk management framework, but speeding things up and making this a much more dynamic and continual process as well rather than a one and done checklist.
Are we on time to get a update per the NDAA from your team?
I will take that back for the record. We're working on it for sure, Congressman.
Thank you. And I know you know this, but I do think a lot of it is just the inconsistency across the authorizing officials and just, you know, you just literally submit it and you don't know sort of if it's a lottery if you're going to get. So you talked about culture and I think I agree and I know you get that, but anything you need from us to reinforce that, I just think obviously given everything happening this is such an urgent priority. Second is on the workforce building on what my colleague Ms. Houlahan talked about. Specifically I wanted to talk about, and you also talked about this in your opening testimony, the our cyber workforce and the the CES program. Can you talk about measurable progress you've made in closing the cyber workforce gaps? We continue to hear from all the leaders that that continues to be a problem.
We are underway in the midst of this. This is a large problem for industry as well as for government. We've been seeing that there are gaps in the cyber workforce globally speaking as well as across America. So this is a passionate area that I draw from my experience to bring into here. To date we have, I believe, over 170 scholarships. We have partnerships with over 450 academic institutions. We're working on, we're announcing very soon, well, I guess I'm announcing right now, that we're going to be doing a rotation internship program that's going to be providing a lot more skills uplift that are there. I'm also looking to see how we can be working much more effectively with K through 12 in order to be uplifting the cyber workforce of the future. I would be remiss...
And just, sorry, in the interest of time I've got to hit one more thing. I would specifically love to follow up with you and your team on the K through 12 component, if you're willing.
Absolutely.
The last thing I just want to bring up, which I think would almost certainly have to be addressed in the closed session, is just your whatever you can share in this forum of, you know, we're in a war despite what different people are calling it. And we're testing all these systems, I know, under your purview. What can you share about how our performance has been? As many know in the room, Iran actually does have a quite sophisticated offensive cyber capability and so how are we holding up there? And of course defer to hearing more in the closed session.
Certainly we'll have to defer the majority of that to a closed session. I will say that across the board, across every theater, we've been working for resilience and diversity in our long-haul transports, our network capability, our communications capability. We've been working at resiliency and anti-fragility plans with regards to data center modernization and all of that as well. There's significant work being done by our colleagues across Cyber Command.
Thank you. Yield back, Mr. Chair.
Thank you. Mr. Crank, you are now recognized.
CMMC Compliance and Small Business Impact
Thank you, Mr. Chairman. Ms. Davies, thank you for your time and your testimony today. And I'm sorry I'm hopping back and forth between committees. Congratulations on your recent confirmation. I want to ask you about the DOD's Cybersecurity Maturity Model Certification, or CMMC, requirements. I think we can all agree on the national security imperative of protecting sensitive government information from our adversaries. But when regulations created to achieve this goal are so overbearing and so restrictive that it causes important small businesses to leave the defense industrial base or to decide against working with the government in the first place, that also harms our national security. And for an example, I had a recent meeting with my defense advisory board. I heard from one small business in my district that they do all of their contracted work on-base and on government computers. However, the owner has to handle federal contract information on a private work laptop which, according to the program, only requires CMMC level one self-attestation. However, the department has informed her that she must meet CMMC level two high requirements. This one requirement, which only applies to one employee who isn't even doing the sensitive work, is going to cost her company over $100,000 just to be able to do business with the department. And this is just one of the many stories I've heard from my district over the last several months while CMMC implementation begins. And while large primes may be able to stomach those costs and employ dozens of employees to track compliance, these regulations and costs can easily cause a small contractor to go bankrupt or leave the industrial base, depriving our warfighters of their exceptional capabilities. In a recent GAO study found that the DOD had, quote, "not systematically assessed and documented the external factors that could affect the department meeting its CMMC goals," unquote. They specifically called out the DOD's reliance on private stakeholders for assessing compliance, such as the Cyber AB, an independent nonprofit tasked with overseeing CMMC implementation and compliance. According to the report, the department does not adequately understand whether there are enough C3PAOs to handle the volume of contractors needing to be deemed CMMC compliant. So I want to commend you first because one of your early actions after being confirmed was to order a dedicated review of the CMMC ecosystem and its effects on our national defense strategy. What's the status of this review and when can we expect to receive the results?
Congressman, the review is still underway, but I'm happy to share with you some early observations. I think my observations are also informed by having been in industry as well and looking at this. Look, the topic of supply chain risk management, and especially cyber risk management across the supply chain, is very important. Of course we want the data to be safe, confidential. Of course we want the integrity of the data to be there. But what we really also want is our defense industrial base to have availability of their systems in order to produce the things that the Department of War and our military warfighters need, right? So part of the observation that I can share with you is what the Secretary has so wisely spoken loud and clear, which is we need to reduce the regulatory burden and offer new entrants a shot at getting in and doing business with us. I can commit to you that this is the lens through which I am looking at CMMC.
Great. Great. And so what kind of oversight does the department have into the millions of dollars received by Cyber AB and C3PAOs from the, frankly, exorbitant fees that they're charging for their services?
A lot of the supply chain risk management, even in industry, Congressman, is conducted by third parties. The volume of it is so enormous, we couldn't possibly hire enough people to do all of those assessments. That said, the oversight does come through my office and we are having a look at that as well to see where we can be streamlining things, looking first at the totality of CMMC and how we can be addressing the Secretary's direction of reducing regulatory burden, but then also looking to see how we can streamline these efforts too.
Okay. And just very, I've got just a couple seconds left, but let's talk about over-classification. What's your office doing to ensure the department's not over-classifying CUI basic information and data?
A topic near to my heart. We are right in the thick of looking at this right now, Congressman.
Great. All right. Thank you. And I yield back.
Thank you. Mr. Vindman, you are now recognized.
Digital Twin Technology and Infrastructure Resilience
Thank you, Chairman. So the Department of Defense, first of all, welcome Ms. Davies. Good to see you. The Department of Defense Inspector General recently found that the Department of the Navy has made minimal progress in mitigating known cyber vulnerabilities across defense critical infrastructure. In many cases, there was no clear ownership of systems, no defined responsibility for risk management, in some cases no visibility into whether vulnerabilities had even been addressed. That's not just a process failure, it is mission risk. These systems underpin our ability to deploy, support, and sustain military operations worldwide. At the same time, the threat environment is becoming more severe. The intelligence community assesses that cyber actors from China, Russia, Iran, North Korea, and criminal ransomware groups pose persistent and growing threats to U.S. networks and critical infrastructure, with the capacity to preposition for or execute disruptive and destructive attacks. China in particular is identified as the most active and persistent cyber threat, while Russia continues to field advanced cyber capabilities and non-state actors are increasing the speed and scale of attacks against critical infrastructure. This means we're facing a reality where adversaries are not just probing our systems, they're actively preparing the battlefield in cyberspace. Concurrently, advances in digital twin technology, which creates virtual and data-driven representation of real-world systems, allows operators to model infrastructure, simulate disruptions, and test mitigation strategies in real time. These systems integrate sensor data from physical assets and run simulations that generate actionable insights back to the real world. This matters for cybersecurity. Instead of reacting to vulnerabilities after they are discovered, digital twins allows us to anticipate failure points, model cyber attacks on infrastructure systems, and identify cascading effects before they occur. In particular, digital twins would prove especially helpful in identifying cyber risks for critical infrastructure attached to military bases, especially bases that rely on local energy and water infrastructure. For the NDAA, I'm considering language to help implement this technology. Given the IG's findings and the IC threat assessment, do you support implementing a digital twin model pilot program at military installations to provide real-time visibility and improve risk management?
Absolutely, Congressman. I think this is fabulous. I've been working with digital twin technology across my commercial career. And I think that the availability, the potential of that usage for simulating attacks, simulating patching across these brittle systems is actually quite profound.
Do you have any current plans to implement digital twin systems or programs?
We're working on a design around this right now. Of course we've been working through and we've published out of my office OT playbook guidance around OT security, industrial control systems, a lot of those areas. We've also had a very strong target for zero trust principles across OT. In my background, bringing this with me into the department, I have established a very clear focus that we want to get after this, so we're looking at piloting that.
Wonderful. And then I have a little bit more time, so let me ask you from the Ukraine conflict, what are there lessons that have been learned? I mean, Russia has persistently been attacking Ukrainian systems for years. Obviously this is their number one priority. What have we learned that we could adapt, adopt in the United States?
I won't speak specific to the Ukraine conflict, I'll defer to my colleagues who are much more vocal and fluent in those topics. What I will speak about though is much more broadly what we've learned across time is we need much more resilience and modernization across our systems. In the network refreshes and modernization that we're doing across DISA and the DISN, the Defense Information Systems Network itself, we're looking at how we can develop and deploy alternate routing, SATCOM usage, and things like that that will promote resiliency and anti-fragility across not only our network and our COMMS transports, but also our systems themselves.
I'll just say in the remaining seconds that we have, obviously we have friends and allies all around the world and that we should be able to leverage their experience into our own systems and our own resilience. Thank you. I yield back.
Thank you. Mr. Whitesides, you are now recognized.
Thank you, Mr. Chairman. I just have I think just one question, actually following up on what my colleague Mr. Crank had said. I too have met with small businesses, some of them working in the defense space, and they have brought to me concerns about the cost of complying with the CMMC. And, you know, how do you intend to balance the need for really exquisite security given our adversaries who are trying every way they can to break into systems, often through vendors outside of the government to get at critical information, with the concerns that we should have and we do have about our defense industrial complex? How do you intend to balance the interest of security and making sure that we have a strong defense industrial base?
This is the balance to be had, Congressman. Thank you for this question. We already provide quite a few things across the department that I believe are great benefit for the defense industrial base through NSA's C3. They, for members who sign up for this, they provide threat intelligence, they provide indicators of compromise so that the DIB can uplift their own security. Through our DC3, we're also working with them on forensic investigations when there is an issue that they are then of course required to report back to us through their contract terms themselves. So we provide a lot of this information for them right now. We also have quite a few provisions that you as Congress have authorized for us between the supply chain risk management or the cyber supply chain risk management. We look to those all the time. I have direct engagement back with the defense industrial base as well as the CIO, and we are looking to create greater partnerships there in order for them to uplift their security.
Do you think we ought to be providing grants or low-interest loans to small businesses such as in my district and that my colleague Mr. Crank mentioned so that they can upgrade their systems? They're critical that they're involved in providing a service to the government, and the costs are not really questioned so much as certainly expensive for a small business, can put them out of business, can discourage them from engaging with the government. Shouldn't we be granting financial assistance to these businesses so that they can comply and provide us all the information we need in the most secured, protected way as possible?
I think, Congressman, that is an idea of many, perhaps. I know with the defense industrial base companies that work with NSA's C3, they have the ability to work on several of their systems. There's 11 different capabilities that are offered for the small businesses themselves. So I think it's probably a combination of several efforts where we can support them and help them and guide them.
Thank you, Mr. Chairman. I yield back.
Thank you. I have one more question here and then I'll see if Ms. Houlahan has any follow-ups. One thing we hear frequently is that the department is still operating a large number of legacy systems and networks, and they're very difficult to secure and expensive to maintain. Can you talk about how much of the department's cybersecurity challenge is really a legacy IT problem and whether modernization of networks enterprise services is keeping pace with the cyber threat?
Zero Trust Implementation and Closing Remarks
A question dear to my heart. There's always a challenge with legacy IT. It is usually quite sprawling, just generic comments from me, sprawling technology that is not kept up to date or is out of service by the main providers themselves, which in and of itself means it's not being patched, it doesn't have updated software on it. So legacy IT does pose quite a significant problem. One ends up designing security controls around allowing those systems to exist and remain rather than investing the time, the resources, the budget that are necessary to not just replace the systems but also train people on how to use new and modernized techniques. I'd say there's a direct correlation with the cybersecurity posture with regards to those legacy IT systems. It's something, Chairman, we are getting after with quite fervor under my leadership.
Thank you. Ms. Houlahan, do you have a closing question or comments?
I have a real quick one. You mentioned a little bit about zero trust and specifically about OT or operational technology zero trust initiatives. My understanding is that the zero trust strategy prior to you coming has a deadline of September 30, 2027, to be implemented across DOD. With this OT addition, do you anticipate an extension of that deadline, an additional deadline, or is this integrated into the existing strategy?
The existing strategy includes an IT deadline, which is the one that you refer to, and then there's a secondary OT deadline that is there. I've been taking the time to assess that and look to see where we can pull that in. I think that this is the OT side is direct impacting to our supply chain, it's direct impacting to our warfighters, the distribution of all of the materials that they need, it's direct impacting to weapon systems as well. And so we're looking to see where we can pull that deadline in.
So right now there isn't one and you're hoping to have established one?
There is one right now. I can take that one back for you. I don't have the date in my notebook, probably because I've determined to pull the date in.
And will that could that be affected by workforce reductions that may be happening either in the past or in the future?
I wouldn't say that that's that there's a correlation there, Congresswoman. I think it's a matter of prioritization that is needed. So the work needs to be prioritized in order to get after it. And with the leadership that we have now from the Secretary on down, we're seeing that there's a priority of an action bias for action and results oriented. So we'll start to see a lot more progress in that area.
And finally, is there anything that you need from Congress for this?
Your continued attention to these matters, without sounding sycophantic, is actually really quite important. And I appreciate the attention on these matters. I think sometimes IT is thought of as a back-office function when indeed we power a lot of what's happening for our warfighters. And that is our primary mission is to empower them, embolden them, and give them all the resources that they need. So thank you for your continued attention.
You're welcome. I yield. Thanks.
Thank you. Mr. Vindman says he has one more question.
I do. Thank you. And this is a little bit of a follow-up on what Representative Houlahan was just getting at and your comment that under this administration and your interest is a bias for action. What's the most radical idea or plan you have to address, you know, the issues that you see as most problematic? So from your own perspective, like what's the most radical idea or plan that you have and then how can we help you execute that?
I have not fully formulated the intricacies of the strategy, but I will tell you the office of the CIO has not been reorged since it was established back in 2012, 2014. We have looked at things through lenses that I think are outdated. And so what you will see from my office, Congressman, is you're going to see an operational mindset, which is radical for some people to think that a CIO's office would be much more operational. That's not radical in industry, by the way. It is that's one of the areas that we're looking at. I think in some of these places where we're looking to set up sandbox ideas, not unlike yours, I feel like, Congressman, you might have read my notes on leveraging digital twin technologies. These are some of the things that we're looking after. Some of the radical plans will be in using commercial technology to support the work and leapfrog in the modernization effort. So more to come on that one, Congressman. leapfrog in the modernization effort. So more to come on that one, Congressman.
Thank you. At this time, we will conclude the open portion of today's subcommittee hearing. For members who will not be joining us, questions for the record will be due to the committee within a week after the conclusion of this hearing. With that, I want to thank you for this open session. We appreciate you being here and sharing your expertise and thoughts. We will now reconvene in the SCIF in Rayburn 2337 for the classified portion. The subcommittee hearing is adjourned.
Same-day access
Read every hearing transcript the day it happens
Paid seats unlock fresh transcripts immediately, including synced video and clear summaries.



