U:\2021\Weathering the Storm
Total Page:16
File Type:pdf, Size:1020Kb
WEATHERING THE STORM: THE ROLE OF PRIVATE TECH IN THE SOLARWINDS BREACH AND ONGOING CAMPAIGN JOINT HEARING BEFORE THE COMMITTEE ON OVERSIGHT AND REFORM U.S. HOUSE OF REPRESENTATIVES [Serial No. 117–5] AND THE COMMITTEE ON HOMELAND SECURITY U.S. HOUSE OF REPRESENTATIVES [Serial No. 117–4] ONE HUNDRED SEVENTEENTH CONGRESS FIRST SESSION FEBRUARY 26, 2021 Printed for the use of the Committee on Oversight and Reform ( Available on: govinfo.gov oversight.house.gov docs.house.gov U.S. GOVERNMENT PUBLISHING OFFICE 43–755 PDF WASHINGTON : 2021 COMMITTEE ON OVERSIGHT AND REFORM CAROLYN B. MALONEY, New York, Chairwoman ELEANOR HOLMES NORTON, District of JAMES COMER, Kentucky, Ranking Minority Columbia Member STEPHEN F. LYNCH, Massachusetts JIM JORDAN, Ohio JIM COOPER, Tennessee PAUL A. GOSAR, Arizona GERALD E. CONNOLLY, Virginia VIRGINIA FOXX, North Carolina RAJA KRISHNAMOORTHI, Illinois JODY B. HICE, Georgia JAMIE RASKIN, Maryland GLENN GROTHMAN, Wisconsin RO KHANNA, California MICHAEL CLOUD, Texas KWEISI MFUME, Maryland BOB GIBBS, Ohio ALEXANDRIA OCASIO-CORTEZ, New York CLAY HIGGINS, Louisiana RASHIDA TLAIB, Michigan RALPH NORMAN, South Carolina KATIE PORTER, California PETE SESSIONS, Texas CORI BUSH, Missouri FRED KELLER, Pennsylvania DANNY K. DAVIS, Illinois ANDY BIGGS, Arizona DEBBIE WASSERMAN SCHULTZ, Florida ANDREW CLYDE, Georgia PETER WELCH, Vermont NANCY MACE, South Carolina HENRY C. ‘‘HANK’’ JOHNSON, JR., Georgia SCOTT FRANKLIN, Florida JOHN P. SARBANES, Maryland JAKE LATURNER, Kansas JACKIE SPEIER, California PAT FALLON, Texas ROBIN L. KELLY, Illinois YVETTE HERRELL, New Mexico BRENDA L. LAWRENCE, Michigan BYRON DONALDS, Florida MARK DESAULNIER, California JIMMY GOMEZ, California AYANNA PRESSLEY, Massachusetts VACANCY DAVID RAPALLO, Staff Director PETER KENNY, Chief Investigative Counsel ELISA LANIER, Chief Clerk MARK MARIN, Minority Staff Director CONTACT NUMBER: 202-225-5051 (II) COMMITTEE ON HOMELAND SECURITY BENNIE G. THOMPSON, Mississippi, Chairman SHEILA JACKSON LEE, Texas JOHN KATKO, New York Ranking Minority JAMES R. LANGEVIN, Rhode Island Member DONALD M. PAYNE, JR., New Jersey MICHAEL T. MCCAUL, Texas J. LUIS CORREA, California CLAY HIGGINS, Louisiana ELISSA SLOTKIN, Michigan MICHAEL GUEST, Mississippi EMANUEL CLEAVER, Missouri DAN BISHOP, North Carolina AL GREEN, Texas JEFFERSON VAN DREW, New Jersey YVETTE D. CLARKE, New York RALPH NORMAN, South Carolina ERIC SWALWELL, California MARIANNETTE MILLER-MEEKS, Iowa DINA TITUS, Nevada DIANA HARSHBARGER, Tennessee BONNIE WATSON COLEMAN, New Jersey ANDREW S. CLYDE, Georgia KATHLEEN M. RICE, New York CARLOS A. GIMENEZ, Florida VAL BUTLER DEMINGS, Florida JAKE LATURNER, Kansas NANETTE DIAZ BARRAGA´ N, California PETER MEIJER, Michigan JOSH GOTTHEIMER, New Jersey KAT CAMMACK, Florida ELAINE G. LURIA, Virginia AUGUST PFLUGER, Texas TOM MALINOWSKI, New Jersey ANDREW R. GARBARINO, New York RITCHIE TORRES, New York HOPE GOINS, Staff Director DANIEL KROESE, Minority Staff Director NATALIE NIXON, Clerk (III) CONTENTS Page Hearing held on February 26, 2021 ....................................................................... 1 WITNESSES Sudhakar Ramakrishna, President and Chief Executive Officer, SolarWinds Corporation; accompanied by Kevin B. Thompson, Former Chief Executive Officer, SolarWinds Corporation Oral Statement ........................................................................................................ 8 Kevin Mandia, Chief Executive Officer, FireEye, Inc. Oral Statement ........................................................................................................ 9 Brad Smith, President and Chief Legal Officer, Microsoft Corporation Oral Statement ........................................................................................................ 11 Written opening statements and statements for the witnesses are available in the U.S. House of Representatives Document Repository at: docs.house.gov. INDEX OF DOCUMENTS * Statement for the Record; submitted by Rep. Connolly. * Questions for the Record to: Ramakrishna; submitted by Chairwoman Maloney. * Questions for the Record to: Thompson; submitted by Chairwoman Malo- ney. * Questions for the Record to: Mandia; submitted by Chairwoman Maloney. * Questions for the Record to: Smith; submitted by Chairwoman Maloney. * Questions for the Record to: Ramakrishna; submitted by Committee Chairman Thompson (Homeland), Rep. Titus, and Rep. Guest. * Questions for the Record to: Thompson; submitted by Committee Chair- man Thompson (Homeland), Rep. Titus, and Rep. Guest. * Questions for the Record to: Smith; submitted by Committee Chairman Thompson (Homeland), Rep. Titus, and Rep. Guest. Documents entered into the record during this hearing, and Questions for the Record (QFR’s) with responses are available at: docs.house.gov. (V) WEATHERING THE STORM: THE ROLE OF PRIVATE TECH IN THE SOLARWINDS BREACH AND ONGOING CAMPAIGN Friday, February 26, 2021 HOUSE OF REPRESENTATIVES, COMMITTEE ON OVERSIGHT AND REFORM COMMITTEE ON HOMELAND SECURITY Washington, D.C. The committees met, pursuant to notice, at 9:06 a.m., via Webex, Hon. Carolyn Maloney [chairwoman of the Committee on Oversight and Reform] presiding. Present from Committee on Oversight and Reform: Representa- tives Present: Representatives Maloney, Norton, Lynch, Cooper, Connolly, Krishnamoorthi, Khanna, Mfume, Porter, Tlaib, Bush, Rice, Wasserman Schultz, Welch, Johnson, Sarbanes, Speier, Kelly, DeSaulnier, Comer, Jordan, Hice, Grothman, Cloud, Keller, Ses- sions, Biggs, Donalds, Fallon, and Franklin. Present from Committee on Homeland Security: Representatives Thompson, Langevin, Payne, Correa, Slotkin, Cleaver, Clarke, Swalwell, Watson Coleman, Rice, Demings, Barraga´n, Gottheimer, Malinowski, Torres, Katko, McCaul, Higgins, Guest, Bishop, Van Drew, Norman, Miller-Meeks, Harshbarger, Clyde, Gimenez, LaTurner, Meijer, Cammack, Pfluger, and Garbarino. Chairwoman MALONEY. The committee will come to order. Without objection, the chair is authorized to declare a recess of the committee at any time. I now recognize myself for an opening statement. Good morning. I want to welcome everyone to this joint hearing of the Committee on Oversight and Reform and the Committee on Homeland Security. Welcome to Chairman Thompson, Ranking Member Katko, Ranking Member Comer, and all of our members. Today’s hearing is the first in the House on the cyberattack uncov- ered last year that initially targeted the software company, SolarWinds, and its Orion product. The details are truly fright- ening. Here is what we know. A sophisticated attacker, reported to be the Russian Government, broke into SolarWinds’ system and in- serted malicious code into its software which customers then downloaded. The numbers tell how dangerous an attack like this can be. Nearly 18,000 customers downloaded updates containing the malicious code. It is not just the number of potential victims, as staggering as that is, or even the number of known victims of (1) 2 secondary attacks, but the nature of this attack and the profiles of victims that should give us all grave concern. Among the victims were major technology companies, some of which have the best cy- bersecurity in the world, as well as critical infrastructure firms, our Nation’s law enforcement and government agencies involved in foreign affairs, and national security. It has affected approximately 100 private sector companies and at least nine Federal agencies, including the Department of Homeland Security, Department of Justice, and state, and Treasury, and that is just what we know. There is much more that we still don’t know. We still don’t know if they are still in the system. In the weeks and months ahead, our committee will continue our joint investigation to examine other as- pects of this massive attack. Today, our focus is on the private sector. The private sector plays a key role in our Nation’s cyber defenses, they own critical infra- structure, and they develop essential information, communications, and technology products. They help the government and other com- panies secure and defend their own networks. It was the private sector that uncovered this attack, not our own government. Specifi- cally, FireEye discovered it, reported its findings, and shared it with the world. Had FireEye not taken that action, the attack could very well be fully up and running today. At the same time, the private sector was targeted as part of a campaign to gain access to government networks and other enti- ties. All of the companies here today are victims of this attack, and all provide products and services to the government that puts the government at risk. Additionally, it is the private sector to whom the government must turn. In particular, the government has turned to Microsoft to learn whether it was exposed and how badly due to the widespread adoption of Office 365 Cloud. The private sector must be held accountable for its role. Our committees recently obtained a presentation made by a former em- ployee at SolarWinds named Ian Thornton-Trump. The 23-page presentation, a portion of which I will put up on the screen now, appears to include a proposal from 2017 that stated, and I quote, ‘‘The survival of the company depends on an internal commitment to security. The survival of our customers depends on a commit- ment to build secure solutions.’’ I look forward to hearing from Mr. Thompson about the steps the company took in response. Cybersecurity demands strong leadership, but, unfortunately, we have suffered under four years of terrible