Senate seal

Senate · Hearing transcript

Enterprise Security and IT Operations of DoD Networks and Systems

Tuesday, March 24, 2026

Summary

  • Kirsten A. Davies (Chief Information Officer, Department of Defense) confirmed Anthropic's supply-chain-risk designation requires removal from defense systems within 180 days.
  • Paul T. Stanton (Director, Defense Information Systems Agency) said resilient multi-path networks and expanding ThunderDome zero trust defend decision advantage for combatant commanders.
  • Jack Reed pressed Davies on Anthropic's risk basis, costs, and continued wartime use, and Davies cited collaborative process and exception time.
  • Mike Rounds stressed warfighting speed and technical debt while Jacky Rosen demanded budget transparency and responsiveness, but both backed modernization.
  • The subcommittee recessed to a classified briefing in Room 217 and required questions for the record within two business days.

Morning digest

Get hearings like this in your inbox

Free weekday email. Unsubscribe anytime.

Hearing Details

Witnesses

Members Who Spoke

View on Congress.gov

Transcript

Sen. Rounds (SD)14:33 – 18:50

Good afternoon and welcome to this afternoon's Cyber Security Subcommittee hearing on Enterprise Security and Information Technology Operations of Department of Defense Networks and Systems. I wanna begin by thanking our witnesses for appearing today before this subcommittee. Your testimony arrives at an inflection point for how the Department of Defense fights, decides and wins. This hearing is fundamentally about war fighting. The digital backbone of the Department of Defense is no longer a support function, it is a weapon system. Our tanks, ships, aircraft and ground forces depend on connected, resilient and secure networks to operate at the speed and precision across vast distances. Sensors all over the world will connect to shooters across the theater, in a vast kill web that must operate faster and more efficiently than our enemy's systems. This is especially true for future conflicts as we continue fielding software intensive systems designed for decision advantage and speed of action. While quantity may have a quality all of its own, the ability to optimize our targeting and orient, decide, and act more quickly then the enemy will likely decide the outcome of the next major war. The department's cultural shifts towards recognizing networks and and information technology infrastructure as a war-fighting platform is one I agree with, yet I realize there is still a long way to go. Software can be developed and deployed in minutes, hours or days. The bureaucratic processes governing how we acquire, certify and field it does not match that timeline, at least not yet. This reality is no longer merely an inconvenience, it is a strategic liability. We have talked long enough about solving these problems, this subcommittee wants to see them resolved. Compounding the urgency is the condition of the infrastructure itself. Defense to information technology budgets have long served as the bill payer, absorbing cuts to fund near-term priorities. The result is a technical debt problem of historic proportions in both hardware and software. Our adversaries are not blind to this. Not surprisingly, they are taking advantage of this blunder. Every day we delay modernizing is a day we strengthen their hand in the cyber domain. As we modernize, speed without security is not an improvement. We must be disciplined about not punting today's problems. That means patching what we have while building with foundational security baked in. This cannot be a government-only endeavor. The private sector can move with speed and provide capabilities the department cannot match but partnership only works when our processes and requirements are transparent and consistent. We owe our industry partners' clarity and we owe our war fighters results. We must ask what kind of compute capacity, network resiliency and data infrastructure our war fighters require, not just today, but as artificial intelligence is deployed at a scale across the force. If we cannot answer that question with specificity, we cannot build toward it. Today, this subcommittee looks forward to hearing from both of you on where the department stands in addressing these efforts. We want to understand how bureaucratic barriers are being dismantled and how our processes are being made more welcoming to industry partners. It is especially important for us to hear whether our networks have the capacity, resilience and performance our military requires for modern warfare against a capable adversary. Thank you again, and now I would like to recognize the ranking member for her remarks. Senator Rosen.

Sen. Rosen (NV)18:51 – 21:44

Well, thank you, Chairman Rounds. Uh, Miss Davies, General Stanton, appreciate you being here. I wanna welcome you. And Miss Davies, congratulations on your recent confirmation and assumption of duties. And so, Miss Davies, as you get settled into this position, we'd like to hear more about your priorities, uh, get some of the ideas of where you're gonna be placing emphasis on funding from FY twenty-six appropriations on any reconciliation funding you may have received as well. And so without discussing specifics, it would also be helpful to know where we might see significant budget swings for programs so we're not surprised when the FY twenty-seven presence budget request is released. That request is already nearly two months late, it's not expected for a few more weeks, and that leaves little time in our NDA process to delve in to the details, and it's critical for us to be able to do that. General Stanton, I want to welcome you back. Thank you for your years of service. I hope you will also share your thoughts on all of these topics as they relate to your role as Director for the Defense Information Systems Agency and Commander for the Department of Defense Cyber Defense Command. As the organization charged with running DOD networks, you have a unique operational perspective on how policy decisions from the department's CIO are translated well into action. But that also means that you have a slightly different view as to the resourcing and workforce needs. The implementation of technology for the war fighters different maybe than the development, right? And the impact of technical debt on the ability of our department to modernize, you can speak to that in practical sense. So we also have a long list of long-term issues we wanna make sure the department is addressing so they don't get lost in the immediate priorities of the day or the specific priorities of this administration. For example, implementation of the cyber security maturity model certification process, improving the authority to operate process for software to be placed on the DOD networks, and addressing the backlog of technical debt in our IT programs to make sure our networks are more modern, more resilient, and of course, more secure. These are just a few of the areas where I think we have common cause and desire to work together to improve the department for the long term. We wanna work collaboratively. collaboratively, excuse me, with you on these issues. However, the department has not been particularly timely or forthcoming on information. So for us to conduct our statuary a statutory obligation to oversee the Department of Defense requires us to have open and honest conversations. Um, there's definitely a trust deficit right now, but I think it's fixable if the department can be more responsive to the requests of this committee and to our members. So I hope we can use this hearing, both open and close to help us get started on the right foot and with that I'm gonna turn it um back over to Chairman Rounds. Thank you.

Sen. Rounds (SD)21:45 – 22:19

Thank you, Senator Rosen. Um, today we're pleased to have uh uh our two panelists with us, Kirsten Davies, who is the Chief Information Officer of the Department of Defense, and Lieutenant General Paul Stanton, um, United States Army Director of Defense Information Systems Agency, Commander of the Department of Defense Cyber Defense Command. We welcome both of you here, uh and uh we would look forward to your opening statements. Uh your written statements will be a part of the record, but you we would welcome your opening statements. And with this, uh Miss Davies, would you like to begin?

Kirsten A. Davies (Witness)22:20 – 26:53

Uh thank you. Uh good afternoon, Chairman, Ranking Member, Senator Reid. Uh thank you for the opportunity to speak with you today about the department's strategy to transform technology and cyber security into a decisive war-fighting advantage. Our focus is to enable data supremacy and decision dominance on the contested battlefields of today and tomorrow at the speed and scale our warfighters deserve. In the latest initiative in Secretary Hegset's drive for efficiency and effectiveness, we are undertaking a bold transformation of enterprise IT and the cyber security program, unifying these capabilities under the department's Chief Information Officer. Through this effort, we will eliminate inefficient spending, reduce technical debt, accelerate modernization, drive consistent and up-leveled cyber security, and unleash data and innovation from the core to the edge across our joint forces. Leveraging my oversight of DISA, the NSA Cyber Security Directorate, and the Department's Cyber Crime Center, we are working with the military services, joint staff, combatant commands, and defense agencies across four transformation pillars. I'll provide a few highlights here. Under pillar one, the enduring digital foundation, we're transforming our network infrastructure and communications transport, which extend from undersea cables to terrestrial fiber to advanced satellite capabilities, connecting everything from the home front to the tactical edge. This foundation supports every war-fighting system and our global installations. We're driving continual modernization, expansion and hardening, as well as broad five G usage and data center modernization. We're evolving our crowd, our cloud strategy in JWCC next, and we're also leading a proactive approach to spectrum management and advancing PNT efforts, ensuring ready and resilient capabilities that enable American war-fighting dominance. Under pillar two, agile digital capabilities, reflecting some of your comments, Senator Rand. We are expanding our m- our and maturing digital offerings. We're accelerating delivery of software and SAS services. and standardizing data architectures, streamlining our data flows. We're shifting from slow legacy software development to modern agile delivery, driving interoperability by design and delivering applications and analytics at the speed of relevance. We're driving extensive defense business systems work, whether modernizing or sunsetting those systems, to enable clean audits and reduce wasteful spend. We're also deploying mission partner environment as persistent secure environments where trusted partners can be rapidly integrated. Under pillar three, cyber security for the war-fighting ecosystem, in alignment with President Trump's national security strategy and the na- the national defense strategy, we're moving from checklist driven compliance towards unified holistic risk-based approach. We will emphasize automation and dynamic and continuous monitoring. We will drive risk reduction rather than burdensome paperwork. focusing on anti-fragility and resilience through a holistic blend of streamlined processes, advanced technologies, and skilled people. We're refining the authority to operate process and accelerating our deployment of zero trust principles. We're also refining our risk management process and reigniting the dib to align with the secretary's arsenal of freedom initiatives. Finally, through pillar four, skills and partnerships, we recognize that people are our decisive edge. As part of our transformation, we're reviewing IT and cyber security roles to ensure clear responsibilities, accountability for outcomes, and a bias for action. We're leveraging your provisions in the fiscal year twenty twenty-six NDA A to enhance recruitment and retention of cyber professionals and expand competitive compensation. We will be launching an expanded top-tier certification program in partnership with industry and academia. which will offer upskilling and cross-skilling to our warfighters, from new recruits to season service members. And because we do not fight alone, we're doubling down to influence the digital transformation efforts of our allies and partners, which will better enable all of coalition force readiness. As we advance this bold strategy, thank you for your continued interest in and support of IT and cyber security and for the resources

Sen. Rounds (SD)27:18 – 27:20

Thank you, Miss Davies. Lieutenant General Stanton.

Paul T. Stanton (Witness)27:23 – 32:28

Chairman Rounds, Ranking Member Rosen, Senator Reid, thank you for the privilege of appearing before you today to explain the fundamental shift we are making to ensure that our weapons system, the Department of War Information Network, provides our warfighters with decision advantage. I'm honored to represent the highly skilled and dedicated professionals of the Department of War Cyber Defense Command, and the Defense Information Systems Agency, that design, build, secure, operate, and defend our environment. We must deliver a secure, standardized, resilient and efficient architecture that supports combatant commands. Combatant commands execute war fighting. Nested within the Department of War CIO's vision, the Defense Information System agency has a responsibility to provide functionally relevant capability that aligns with the time and tempo of the warfighter's mission. As the Department of War Cyber Defense command, we have an added responsibility to ensure that our systems and data are properly defended against continuous and sophisticated attacks. Combining these two responsibilities and said simply, we must get the right data to the right place at the right time, such that our commanders make better and faster decisions than our enemies. We are a sub-unified command and a department of war combat support agency. Our mission, and therefore our culture, is to support war fighting. We are fully engaged to move and maneuver the network and our data according to the changing conditions of the operating environment. We design, build, secure, operate, and defend in lockstep with commanders at echelon. We campaign to execute our missions and defeat our adversaries. We present and defend the architecture so that commanders can fight. We are doing so right now in Operation Epic Fury. But we cannot rest. We must transform ourselves and the means by which we support to leverage the most modern and effective technology. We are in a perpetual state of continuous modernization. New solutions, artificial intelligence, commercial SATCOM, mobile data centers, they emerge at industry's pace and we must integrate them into our architecture and missions at speed. Further, we must be prepared to fight alongside our partners, sharing data across war-fighting functions within decision cycles. The coalition information environment, as recently prototyped, during an exercise in the Indo-Pacific theater is a cornerstone of our approach. We know that our adversaries, our enemies, are watching us and will certainly attempt to delay or degrade our decisions. And we will defeat them. We are developing solutions that are secure by design, incorporating perimeter defenses that defeat known attack vectors, and employing zero trust to detect, bound, and defeat new and novel trade craft. Our internet access point and our cloud-based internet isolation war-fighting systems continuously adapt to new threats at our boundary. Our ThunderDome implementation of zero trust is proven, expanding rapidly as we transition defense agencies and field activities into DOD net. We will use these tools and the associated data in an informed, productive, efficient, and speedy manner, automating our defenses and employing human tradecraft for advanced analysis. We prioritize our defenses on what matters. In order to preserve decision space for commanders, we must defend the critical systems upon which they are dependent. Our approach employs a mission-thread defense that we nest and plan amongst commanders and their staffs for synchronization. We align our cyber defenses to how their systems employ and move data, ensuring that they have confidence in the data upon which they make their decisions. Our defenses and our strategic goals require optimization. We have to see ourselves holistically. We have made and continue to make significant progress in sensing, logging, aggregating, and analyzing our data accordingly. Our data analytics support cell is employing our common data analytics platform to continuously run queries in analytics that optimize performance and support defensive operations. CDAP feeds into US Cybercom's joint cyber-warfighting architecture for enrichment with classified intelligence, in coordination with offensive cyber-forces, for speed and lethality. Key to our success is the innovation, talent, and motivation of our workforce. Readiness is a requirement. A trained and ready force has confidence to act with disciplined initiative. Demonstrated confidence leads to trust to make decisions at speed. When we combine our transformational architecture with a talented and trained workforce, we are postured to meet our requirements. This is an imperative. The effectiveness of the Doin is inextricably linked to our missions and our nation's defense. With the continued support of the committee, we will preserve the decisive advantage. We look forward to your questions. Thank you.

Sen. Rounds (SD)32:30 – 32:48

Thank you, General Stanton. Um, normally we would begin with five minute rounds and I would uh start senator rosen the the ranking member would be second and then we'd move back and forth but we also have the ranking member here and if you would like to no no no ok regular order it is

Paul T. Stanton (Witness)32:46 – 32:46

no

Sen. Rounds (SD)32:46 – 33:19

regular order regular order from the ranking member very very very good well then i i i i will begin um miss davies and general stanton the ability of our war fighters to operate in a contested or a degraded environment is directly tied to how resilient and modern those networks are Where does the department stand on network modernization, and are our war fighters confident they can operate if those networks are attacked or denied? Miss Davies?

Kirsten A. Davies (Witness)33:20 – 33:35

Thank you, uh, Senator Rand for that great question. Um, I'll uh allow uh General Stanton to get into a few of the details, but as I reflected on pillar one of our transformation strategy, this is active work that we are doing right now, that DISA has been conducting.

Sen. Rounds (SD)34:02 – 34:03

General Stanton.

Paul T. Stanton (Witness)34:05 – 35:01

Senator, thank you for the question, and with great support from Congress, uh, we have an initiative that we reference as DISSIN security, um, and resiliency, so the Defense Information System network, where we focus on undersea cables, um, increased bandwidth for terrestrial fiber, uh, multimodal satellite communications capabilities, what we refer to as an agnostic peering gateway that allows us to communicate over military SATCOM waveforms, but also via commercial satcom capabilities. Uh, as our forces move into theater, as they currently reside in theater, we have a primary alternate contingency in emergency plans put into place. We're never single-threaded on any capability as we enter into the fight, such that if we suffer degradation, we have fall-back capabilities. We're seeing that in spades currently, operating across uh terrestrial, space-based, um and undersea capabilities.

Sen. Rounds (SD)35:02 – 35:31

so recognizing that we're in an unclassed environment we'll go into a classified environment when this when this meeting is done specifically i i think what you're indicating is there's a couple of different areas where we may have um some challenging uh communications problems you mentioned uh undersea cables you mentioned space based assets and so forth are those perhaps the the most challenging that we're gonna face that we can talk about in this in this environment today?

Paul T. Stanton (Witness)35:32 – 36:14

Well, Senator, I think that it's the combination and in the fact that as our war fighting formations are outfitted with capability, uh, we're we we never isolate down to a single mode of transport. Uh, we ensure that we have the ability to to to route terrestrially. Um, we hit to peering points, um, so that such that we can leverage undersea cables. We're never bounded by a single undersea cable. We always have a plan to route around. or have an alternate path. Um, and then the proliferation of space-based assets, specifically in the, in the commercial world, is really game-changing technology, uh, to give us leap-over capability if and when we do suffer a degradation.

Sen. Rounds (SD)36:15 – 36:41

It's an interesting lead in on it then for us to talk a little bit about the reason why we no longer talk about a kill chain. We talk about a kill web. And that is because we have multiple avenues to move from a spotting system uh um back into where you actually have the ability to trigger a weapon. So multiple ways to get the communications from point A to point B, not simply one one line. Fair way of looking at it?

Paul T. Stanton (Witness)36:41 – 36:42

Precisely, yes sir.

Sen. Rounds (SD)36:43 – 37:02

Miss Davies, many smaller defense industrial based companies lack the internal security capability to defend themselves against a sophisticated state actor. What is the department doing to reach that tier of the industrial base, And is voluntary participation in government support programs getting us there?

Kirsten A. Davies (Witness)37:04 – 37:55

Senator Allen, this is a key focus area for me as well. I think we have focused um largely on uh confidentiality of data in the past. Um I know that there has been some burdensome requirements that have been placed on uh large and small businesses alike. Uh in the new transformation uh one of our key pillars is going to be working directly with the defense industrial base. Their resiliency is our resiliency. But it needs to make sense. We've heard Secretary Hegseth talk about reducing the burdens to entrance, um, allowing entrance, new entrance for, uh, smaller companies as well. This is a key focus area for us, whether it's providing guidance, providing principles for them to follow, it's coming alongside them and partnering them, but it's also tailoring these requirements so that they are effective for the arsenal of freedom that we are driving.

Sen. Rounds (SD)37:56 – 37:59

Thank you. My time has expired. Ranking member Rosen.

Sen. Rosen (NV)38:00 – 39:07

Oh, thank you. Um, Chairman Rounds, I'm going to uh just say something and I'll ask for more details in the classified briefing. I just building on what Senator Rounds said, um I wanna hear a little bit about the lessons you learned from the recent military operations in Venezuela and Iran that relate to the DOD networks, um in terms of showing us a little bit of stress testing in the real world, right? We we're we're in um, conflicts in both places and, uh, what we've learned about what we might be changing, um, for future protract protracted conflicts, excuse me. So we're gonna we'll save that one, just put that, uh, out there. So, General Stanton, I wanna, um, talk a little bit about IT support during a war. So the Defense Information Systems Agency, you're a combat support agency for the Department of Defense. So I'm hoping that you can explain for all of us what that means practically, given our current posture in the Middle East. What does your agency do during wartime that could be different than what it does during peacetime, if you would elaborate on that.

Paul T. Stanton (Witness)39:08 – 39:41

Y- yes, ma'am, absolutely. Th- thank you for the question. Uh, so, we, we are at war and we're executing, uh, operation epic period currently, um, which means that, uh, every day, uh, inside of our operations center the defense information systems agency and cyber defense command uh get together um to ascertain what has transpired in in the context of the network what what assets are still up and running what assets need to be resolved how do we route around problems how do we dynamically solve uh

Sen. Rosen (NV)39:39 – 39:39

mmm

Paul T. Stanton (Witness)39:41 – 39:50

uh problems with emergent technology and do so rapidly um from a from a perspective a lot has to do with network transport

Sen. Rosen (NV)39:50 – 39:50

Mm-hmm.

Paul T. Stanton (Witness)39:50 – 40:03

Um, and, and so it, where are the terminals located, how do we get them to the right spot, do we need to lease a new circuit on the fly, um, in order to ensure that critical data gets from point A to point B?

Sen. Rosen (NV)40:03 – 40:03

Mm-hmm.

Paul T. Stanton (Witness)40:03 – 40:07

Um, these problems present themselves in real time.

Sen. Rosen (NV)40:07 – 40:07

Mm-hmm.

Paul T. Stanton (Witness)40:07 – 40:13

Um, in, in, inside of our op center we are dynamically solving and developing resolution.

Sen. Rosen (NV)40:14 – 40:49

Thank you. Um, I'm gonna move on to you, Miss Davies, cuz we wanna talk a little bit about the joint warfarin. fighting cloud contract and the joint war fight, it's a mouthful, the joint war fighting cloud contract, do not try to say that quickly, we'll just say the JWCC is a little bit easier, is reaching a point soon where it's gonna be need need to be re-competed and there'll be a need to uh be a replacement contract. And so what lessons has DOD learned from the JWCC that we might see next in an updated JWCC? And um how do you see AI um, impacting your decisions.

Kirsten A. Davies (Witness)40:50 – 40:53

Uh, thank you for the question. It is a mouthful, isn't it, Zendaya?

Sen. Rosen (NV)40:52 – 40:54

It is, it is, yes.

Kirsten A. Davies (Witness)40:54 – 41:16

Um, we are, uh, expanding JWCC into a unified cloud marketplace, integrating additional providers, embedding, um, financial operations, automation, and multi-cloud management to enable enterprise-wide cost control and interoperability. I can speak from being new in the role and seeing that there are contracts

Sen. Rosen (NV)41:14 – 41:14

Yeah.

Kirsten A. Davies (Witness)41:16 – 41:21

everywhere and uh different points of authorization with different cloud

Sen. Rosen (NV)41:17 – 41:17

Mm-hmm.

Kirsten A. Davies (Witness)41:21 – 41:59

that's happening one of the the key areas that we need to be looking at from a multi-prong approach is is this the most efficient way to be driving cloud compute it's not we need we need to be continuing on in the JWCC next um is it the most is it the best way to see the spend it is not so JWCC next is going to provide us that financial transparency that's there. And it's also gonna provide General Stanton and his team the ability to do better defense across all this because we're going to know where all of the cloud compute is, and that's key for us in asset identification and asset security.

Sen. Rosen (NV)42:00 – 42:50

Thank you. Um, and then I'm gonna continue with you, Miss Davies, because I want to talk about the Enterprise Chief Information Officer collaboration, right? So DOD, you're, like you're saying, you're just a vast conglomeration of networks, clouds, operating cultures, systems, you name it, it's difficult to craft a one size fit all policy, although you can set standards and you can at least lay out the templates for it. You can you can map out where everything is, um essentially, but in my view there are benefits to having each of the military departments and defense agencies having their own CIO so that they can tailor technology and policies to the needs of the various organizations so could you describe for us your relationship with your CIO counterparts in the military services agencies and are there any lessons um uh helpful or otherwise you might have picked up in your time so far.

Kirsten A. Davies (Witness)42:51 – 42:58

Some some great lessons indeed. I'm holding regular meetings with the my military department counterparts as well as the Dafa counterparts.

Sen. Rosen (NV)42:58 – 42:58

Mm-hmm.

Kirsten A. Davies (Witness)42:58 – 43:26

I'm learning where the operational uh efficiencies are, where the centers of excellence and expertise are, also where the gaps are. So I think there's varying levels of competencies, varying levels of of operational cadence that are there. And, uh, one of the things that we will be getting after with this new strategy is to take a hold of that rising tides, raise all ships, to make sure that we're all pointing in the same direction and focused on operational excellence in cyber defense.

Sen. Rosen (NV)43:28 – 43:29

I yield.

Sen. Rounds (SD)43:30 – 43:31

Senator Reid.

Sen. Reed (RI)43:32 – 44:45

Well, thank you, Mr. Chairman, Madam Ranking Member. I'll thank the witnesses not only for being here today, but for your dedication to all war fighters. Thank you. Uh, Miss Davis, I'm sure you're aware of the recent decision by the secretary to designate Anthropic as a supply chain risk. Uh, indeed you yourself signed out a memo on March sixth directing removal of Anthropic from DOD systems within a hundred and eighty days however the committee still has not heard the rationale from the department about why the designation was made, nor received a full notification which is required under law by section thirty-two fifty-two of title ten. And this notification requires a summary of the risk assessment and a summary of the basis of the determination, uh, including what less intrusive measures, uh, were considered and why they were not reasonably available to reduce supply chain risk. Uh, we have not received that information yet. It is required under the law. Uh, so first, are you aware of the actual reason in designating anthropic a supply chain risk?

Kirsten A. Davies (Witness)44:47 – 44:55

Senator, thank you for the question. I was involved, as many of my counterparts were, in this collaborative decision-making process that followed the regulatory requirements.

Sen. Reed (RI)44:58 – 45:01

Well, why why was it done?

Kirsten A. Davies (Witness)45:02 – 45:04

Um, sir, we're we're in, uh,

Sen. Reed (RI)45:28 – 45:33

Uh, it's just interesting that, uh, you would file required documentations.

Kirsten A. Davies (Witness)45:52 – 46:08

Um, Senator, Senator, I'm I'm aware that the our colleagues in legislative affairs have followed the regulation of what they were in that what they were supposed to provide. Um, I do know that we followed all of the steps of the regulatory requirement of the title ten thirty two fifty two.

Sen. Reed (RI)46:09 – 46:14

Well, um, I don't think we've received it. Uh, we have not received it.

Sen. Rounds (SD)46:14 – 46:18

Just in checking with staff, I do not believe that we have received it at this time.

Sen. Reed (RI)46:18 – 46:43

Thank you, Mr. Chairman, uh, but as you pointed out, a California court has received it because of the litigation. Let me just, uh, one additional question is are you aware of any estimates that were made as to the potential cost impact on DOD uses for removing and replacing anthropic from DOD systems or the cost to replace anthropic with another large language model.

Kirsten A. Davies (Witness)46:45 – 47:08

Um, Senator, I'm aware of the risk analysis that was conducted as a part of that, um, and and I'm aware that we have also constructed our data architectures to be able to be interoperable with a variety of different AI capabilities. And so the the deep assessment of of replacement of that, um, I'm unfamiliar with right here. I can take that away as a as an action for you.

Sen. Reed (RI)47:08 – 47:26

It would be appreciated, because the idea of the scale and the magnitude of the disruption, uh, would be helpful. Um, further, um, it's my understanding that, uh, the anthropics clawed system is being used today in Iran, in our military operations. Is that true?

Kirsten A. Davies (Witness)47:27 – 47:47

Uh, without going into the details in in this forum, uh, uh, Senator, the, uh, the use of the system is is active right now. This is also why we provided for, um, a measure of time we felt was reasonable, um, as well as an exception process for removal of the anthropic systems.

Sen. Reed (RI)47:47 – 47:57

I- it just seems odd that you would continue to use a system which you determined to be a supply chain risk. Does that strike you as odd?

Kirsten A. Davies (Witness)47:58 – 48:24

Senator, at at no time in any way will we interfere with the success, the lethality and the resilience of our war fighters. And for that reason, we've provided what we feel is a reasonable amount of time for those systems to be replaced. We can I can also say um that according to, you know, with President Trump's great leadership, we have a number of technology companies that have come to the table, wanting to do business with us.

Sen. Reed (RI)48:32 – 48:34

Thank you very much, Miss Davis. General, thank you.

Kirsten A. Davies (Witness)48:35 – 48:35

Sure.

Sen. Rounds (SD)48:38 – 49:12

Thank you, Senator Reid. Um, let me just follow up on that for just just briefly here. My understanding is, is that there has been a one hundred and eighty day notification with regard to anthropic. Um, I presume, and you can correct me if I'm wrong, but I presume that there is additional time frame here in which there is the possibility of additional negotiations that can occur during that time period recognising just what a significant change this would be to the department uh with the with the reliance right now on the anthropic product at this time. Fair enough to say?

Kirsten A. Davies (Witness)49:14 – 49:19

I'm I'm not sure what part of the question to answer first, Senator Rounds, let me let me try to unpack that for you.

Sen. Rounds (SD)49:19 – 49:19

Sure.

Kirsten A. Davies (Witness)49:19 – 49:49

Um, we have architected our data insomuch as we can deploy multiple types of AI across our data. That's something that the uh General Stanton and the DISA colleagues have been very careful about, uh number one. Number two, we have provided what we feel is an appropriate amount of time um to remove the anthropic systems in accordance with the designation by the secretary of the supply chain risk designation in and of itself. Does that does that answer your question?

Sen. Rounds (SD)49:49 – 49:49

Yeah,

Sen. Reed (RI)49:49 – 49:49

Sir.

Sen. Rounds (SD)49:49 – 50:12

except that I I I think the other entities that we are looking at, many of them have also indicated that they have anthropic within their systems as well. And and what I what I'm looking for is is the possibility that as this discussion goes on in a business-like manner, I'm assuming it will be done in a business-like manner, that there are opportunities for additional negotiations to continue to occur.

Kirsten A. Davies (Witness)50:13 – 50:17

Senator, I will defer that to my uh colleagues in the legal

Sen. Rounds (SD)50:23 – 50:45

That's fair. And I I do think it'd be fair to say that I think that the the the committee as a whole, and I can't speak for the chairman, but at least with regard to the subcommittee, this is something that we have a real interest in. And we we will want to get in a classified setting probably deeper into the details at some point when you're prepared to to share that with us, uh, well, with the appropriate personnel.

Kirsten A. Davies (Witness)50:46 – 50:48

Senator, we'll take that for action, absolutely. Thank you.

Sen. Rounds (SD)50:48 – 51:42

Thank you. Let me go on a little bit here. I I'm just curious, uh, General Stanton. One item that we've talked about is deterrence. And as we be uh as we will use our offensive capabilities Uh, one of the reasons why you use offensive capabilities is to deter future attacks, and to let people know that we know who they are, we know where they are, and and and we do have access to some very exquisite capabilities. to um uh to stop them from actually using kinetic activities or kinetic systems. Can you talk a little bit in this open session, just so that the American public will understand just kind of some of the things that we have the ability to do, now that we've actually utilized some of them, and our the bad guys know that what we can do. Can you talk just briefly about that, just to share with the American public what what their taxpayer dollars are buying?

Paul T. Stanton (Witness)51:42 – 51:48

Y- yes, Senator, and and I I look forward to having a more robust conversation in a classified setting.

Sen. Rounds (SD)51:48 – 51:51

Uh, I understand, but but the public can't see that and like I said,

Paul T. Stanton (Witness)51:49 – 51:51

But Ye-

Sen. Rounds (SD)51:51 – 51:59

I don't wanna do any damage to our ability to do it in the future, but I think it's fair for deterrence sake to maybe talk a little bit about what our capabilities are, if that is acceptable.

Paul T. Stanton (Witness)51:59 – 52:55

Y- y- y- yes, Senator. So I I I think I would uh address it in in two principal ways. The first is, um, there's a deterrent effect associated with cost imposition. Um, if you make it really hard for the enemy to attempt to achieve the effects that the enemy uh intends, uh then it it is a cost imposition. The enemy has to spend more money, more time, develop more resources, and apply it in ways that uh that the enemy may not have been prepared. Um, that that's a cost imposition. Um, in addition, we have offensive cyber capabilities, and we have offensive cyber capabilities that can uh respond at speed to evidence of adversarial activity um beyond the bounds of uh our US networks. So when when we see operations in foreign space um as uh actioned by our cyberspace foreign adversaries we have the capabilities to uh to deny them those resources.

Sen. Rounds (SD)52:55 – 53:01

Fair to say it we can deny them the ability to communicate in some cases.

Paul T. Stanton (Witness)53:02 – 53:02

Yes, Senator.

Sen. Rounds (SD)53:03 – 53:09

Fair to say that we can sometimes make it so they can't see what they wanna see on their systems

Paul T. Stanton (Witness)53:09 – 53:10

Yes, Senator.

Sen. Rounds (SD)53:10 – 53:19

to know what's going on in their in in their part of the world. Fair to say that we can make them see things that maybe aren't even there today.

Paul T. Stanton (Witness)53:19 – 53:35

So the the ability to deny access to systems, the ability to manipulate data, to get inside the decision cycle of the adversary are all the art of the possible, um, in in techniques developed in support of offensive cyber operations.

Sen. Rounds (SD)53:35 – 53:48

All of which means that our young men and women are there's are then safer when they go in harm's way, because we limit the adversary's ability to respond to our young men and women who are on the battlefront.

Paul T. Stanton (Witness)53:49 – 53:51

Unequivocally. Yes, Senator.

Sen. Rounds (SD)53:50 – 53:51

Thank you.

Kirsten A. Davies (Witness)53:51 – 53:51

Sure.

Sen. Rounds (SD)53:51 – 53:53

Thank you. Ranking member Rosen.

Sen. Rosen (NV)53:55 – 55:07

Thank you. I want to, in the classified, I'm gonna ask a little bit more about uh um how you've architect architected, it's a new verb, architected uh your data uh to feed into many different, I would assume, large language models or the like. I think that it's very interesting to me, but uh for this open session I wanna talk about the authority to operate process, because I'm encouraged by the department's continued support for improving security cyber security and supply chain risk management of course, and you've made progress towards reforming and accelerating acquisition testing. authorization of commercial software. But more, of course, can always be done to streamline the authority to operate ATO, a single process into a single department-wide accredica accreditation for secure software providers streamlining the process. So can you talk about um the status of your efforts to streamline that process, what actions you're taking and what plans um your office may have to establish and encourage reciprocities for um ATO's between individual service branches and department components so pulling all that back up to the center

Kirsten A. Davies (Witness)55:07 – 55:17

ranking member great question um the ATO process is part of the broader risk management framework as you are very familiar with um right now we have a

Sen. Rosen (NV)55:13 – 55:16

mmm mmm

Kirsten A. Davies (Witness)55:17 – 55:22

uh a very static snapshot in time with regards to risk management

Sen. Rosen (NV)55:22 – 55:22

mmm

Kirsten A. Davies (Witness)55:23 – 55:45

and that needs to be moved to a much more dynamic framework and process which includes um inheritance of assessments that are conducted somewhere else across the department on a piece of software. That inheritance can then travel to a new department that wants to leverage that piece of software. That inheritance of all the testing and uh the scalability and all of those types of things.

Sen. Rosen (NV)55:42 – 55:42

Mm-hmm.

Kirsten A. Davies (Witness)55:45 – 56:38

The ATO process as a as a piece of that also needs a reform. Um we're finding that it's very difficult for people to actually grab that inheritance over Um, it's very difficult to, um, to understand the work of that risk management framework because it's broken, it's fragmented, and it's static. So what we're doing is we're looking to do a lot more automation across this, um, having dynamic repositories of this information and the testing in and of itself. This work of the of the RMS fri uh, RMF framework as well as the ATO processes will be sitting underneath the department's Chief Information Security Officer. who um was uh presidentially appointed just a few weeks ago but he's uh right on top of it and and going to be uh working very actively with me to um make sure that we're reforming that appropriate to the risk of of the uh actual work that needs to be done.

Sen. Rosen (NV)56:38 – 57:13

Well I I understand what you're saying, how important it is to be more dynamic dynamic and sometimes less static, but I'm also well aware of the vulnerabilities it places when you are um quickly dynamic without the proper um audits and controls over that as well, because you'd never wanna sacrifice speed and uh, I'm not saying static is always the way to go, but you have to be very careful about that dynamic architecture as well, because it can create vulnerabilities because moving at the speed of light, uh or sound or nano second, whatever you want is uh

Kirsten A. Davies (Witness)57:14 – 57:14

Mm-hmm.

Sen. Rosen (NV)57:14 – 57:28

um has risks risks in there as well, so I hope that you're building in a good audit process, review of of of how that's working so in that speed we don't get uh

Kirsten A. Davies (Witness)57:27 – 57:51

Yes, Senator, and we're it's it's a great point. We're going to be bringing in a lot of indus industry good practices across this as well, where we've learned to do a lot of the automation of processes, less paperwork, more dynamic checking across the software design life cycle. We can do a lot of code scanning, code reviews. Those are the types of automation that will help us speed these things up while we're compiling appropriate data repositories

Sen. Rosen (NV)57:47 – 57:48

Mm-hmm.

Kirsten A. Davies (Witness)57:52 – 57:54

for that constant risk checking.

Sen. Rosen (NV)57:54 – 58:06

Right, cuz if you do it too fast, once a piece of bad code gets in, it's already replicated quickly across your system before you may have caught the um the bug, if you will.

Kirsten A. Davies (Witness)58:05 – 58:06

That's right.

Sen. Rosen (NV)58:06 – 58:06

So

Kirsten A. Davies (Witness)58:06 – 58:09

You you understand the risk process very much, yes.

Sen. Rosen (NV)58:08 – 58:10

I I think I do, but thank you.

Kirsten A. Davies (Witness)58:09 – 58:09

Yes, ma'am.

Sen. Rosen (NV)58:10 – 59:16

I'm gonna talk a little bit in my uh just asked you a question about artificial intelligence. Um, the validity, we've talked about anthropic. I know we're gonna go talk some more about this. Um, the validity of their output, critical to the effectiveness of what we do, um, as we acquire and deploy more systems, artificial intelligence systems, look more fighting. You said we're in a war. But it's gonna help our situational awareness, our decision making, and we must secure these systems and the data that powers them. The data, that's why I wanna talk about how you architect your data, Data is power. If you're smart enough to analyze it and use it, it's all about how you use it. The data is key. And so, um, it's important and critical to maintain the, uh, trust trustworthiness, the integrity of all of that, avoid any corruption, man mali malicious manipulation. And so, um, uh, how are you kind of a As much as you can say here, what are you doing to, uh, ensure that you're leveraging existing commercial solutions, um, without making us vulnerable.

Kirsten A. Davies (Witness)59:16 – 1:00:12

Mm-hmm. Uh, yeah. Thank uh, thank you, ranking member. In July of twenty twenty five, my office published um the DOW AI Cybersecurity Risk Management uh tailoring handbook. So we provided some great guidance across that. This is an ever-evolving framework or or competency, I would say. We've been tackling this in the industry across the last, I'd say, five to seven years, providing appropriate garter rails, um ethics, uh security across this, looking at the weights of models as well as hallucinations to try to reduce all of these factors that are there. We're going to be continually evaluating this as we go through. Um we have provided uh strong garter rails, uh we're doing risk management assessing on a regular basis across this. And so this you we we will continue to have conversations around this because it is an evolving category of software if we want to.

Sen. Rosen (NV)1:00:13 – 1:00:14

Thank you.

Sen. Rounds (SD)1:00:16 – 1:01:02

I think at this time we will conclude the open portion of today's cyber security subcommittee hearing. As all of you know, we'll be reconvening here in a few minutes. We've got a a vote at three fifteen that's scheduled. Matter of fact, three of them, but it'll give us an opportunity to go make our first vote. We'd like to reconvene at three thirty down in two seventeen in the skiff for a classified portion of this. And then for the information of members who will not be joining us for the closed briefing questions for the record will be due to the committee within two business days of the conclusion of the hearing and with that i wanna thank you for this open session we look forward to visiting with you again very shortly beginning at three thirty in the closed session in the skiff and with that the subcommittee meeting is adjourned

Morning digest

Start every morning briefed on yesterday’s hearings

A free weekday email covering yesterday’s hearings and transcripts newly unlocked in the archive.

Free weekday email. Unsubscribe anytime.