Responding to Ransomware: Exploring Policy Solutions to a Cybersecurity Crisis
Total Page:16
File Type:pdf, Size:1020Kb
RESPONDING TO RANSOMWARE: EXPLORING POLICY SOLUTIONS TO A CYBERSECURITY CRISIS HEARING BEFORE THE SUBCOMMITTEE ON CYBERSECURITY, INFRASTRUCTURE PROTECTION, AND INNOVATION OF THE COMMITTEE ON HOMELAND SECURITY HOUSE OF REPRESENTATIVES ONE HUNDRED SEVENTEENTH CONGRESS FIRST SESSION MAY 5, 2021 Serial No. 117–12 Printed for the use of the Committee on Homeland Security Available via the World Wide Web: http://www.govinfo.gov U.S. GOVERNMENT PUBLISHING OFFICE 44–930 PDF WASHINGTON : 2021 VerDate Mar 15 2010 11:32 Jun 30, 2021 Jkt 000000 PO 00000 Frm 00001 Fmt 5011 Sfmt 5011 H:\117TH\21CI0505\21CI0505 HEATH Congress.#13 COMMITTEE ON HOMELAND SECURITY BENNIE G. THOMPSON, Mississippi, Chairman SHEILA JACKSON LEE, Texas JOHN KATKO, New York JAMES R. LANGEVIN, Rhode Island MICHAEL T. MCCAUL, Texas DONALD M. PAYNE, JR., New Jersey CLAY HIGGINS, Louisiana J. LUIS CORREA, California MICHAEL GUEST, Mississippi ELISSA SLOTKIN, Michigan DAN BISHOP, North Carolina EMANUEL CLEAVER, Missouri JEFFERSON VAN DREW, New Jersey AL GREEN, Texas RALPH NORMAN, South Carolina YVETTE D. CLARKE, New York MARIANNETTE MILLER-MEEKS, Iowa ERIC SWALWELL, California DIANA HARSHBARGER, Tennessee DINA TITUS, Nevada ANDREW S. CLYDE, Georgia BONNIE WATSON COLEMAN, New Jersey CARLOS A. GIMENEZ, Florida KATHLEEN M. RICE, New York JAKE LATURNER, Kansas VAL BUTLER DEMINGS, Florida PETER MEIJER, Michigan NANETTE DIAZ BARRAGA´ N, California KAT CAMMACK, Florida JOSH GOTTHEIMER, New Jersey AUGUST PFLUGER, Texas ELAINE G. LURIA, Virginia ANDREW R. GARBARINO, New York TOM MALINOWSKI, New Jersey RITCHIE TORRES, New York HOPE GOINS, Staff Director DANIEL KROESE, Minority Staff Director NATALIE NIXON, Clerk SUBCOMMITTEE ON CYBERSECURITY, INFRASTRUCTURE PROTECTION, AND INNOVATION YVETTE D. CLARKE, New York, Chairwoman SHEILA JACKSON LEE, Texas ANDREW R. GARBARINO, New York, Ranking JAMES R. LANGEVIN, Rhode Island Member ELISSA SLOTKIN, Michigan RALPH NORMAN, South Carolina KATHLEEN M. RICE, New York DIANA HARSHBARGER, Tennessee RITCHIE TORRES, New York ANDREW CLYDE, Georgia BENNIE G. THOMPSON, Mississippi (ex officio) JAKE LATURNER, Kansas JOHN KATKO, New York (ex officio) MOIRA BERGIN, Subcommittee Staff Director AUSTIN AGRELLA, Minority Subcommittee Staff Director MARIAH HARDING, Subcommittee Clerk (II) VerDate Mar 15 2010 11:32 Jun 30, 2021 Jkt 000000 PO 00000 Frm 00002 Fmt 5904 Sfmt 5904 H:\117TH\21CI0505\21CI0505 HEATH C O N T E N T S Page STATEMENTS The Honorable Yvette D. Clarke, a Representative in Congress From the State of New York, and Chairwoman, Subcommittee on Cybersecurity, In- frastructure Protection, and Innovation: Oral Statement ..................................................................................................... 1 Prepared Statement ............................................................................................. 2 The Honorable Andrew R. Garbarino, a Representative in Congress From the State of New York, and Ranking Member, Subcommittee on Cybersecu- rity, Infrastructure Protection, and Innovation: Oral Statement ..................................................................................................... 3 Prepared Statement ............................................................................................. 4 The Honorable Bennie G. Thompson, a Representative in Congress From the State of Mississippi, and Chairman, Committee on Homeland Security: Prepared Statement ............................................................................................. 7 The Honorable John Katko, a Representative in Congress From the State of New York, and Ranking Member, Committee on Homeland Security: Oral Statement ..................................................................................................... 5 Prepared Statement ............................................................................................. 6 The Honorable Sheila Jackson Lee, a Representative in Congress From the State of Texas: Prepared Statement ............................................................................................. 8 WITNESSES Major General John A. Davis, U.S. Army (Retired), Vice President, Public Sector, Palo Alto Networks: Oral Statement ..................................................................................................... 12 Prepared Statement ............................................................................................. 13 Ms. Megan H. Stifel, Executive Director, Americas, Global Cyber Alliance: Oral Statement ..................................................................................................... 16 Prepared Statement ............................................................................................. 18 Mr. Denis Goulet, Commissioner, Department of Information Technology, and Chief Information Officer, State of New Hampshire, and President, Na- tional Association of Chief Information Officers, Testifying on Behalf of the National Association of Chief Information Officers: Oral Statement ..................................................................................................... 21 Prepared Statement ............................................................................................. 23 Mr. Christopher C. Krebs, Private Citizen, Former Director of the Cybersecu- rity and Infrastructure Security Agency, U.S. Department of Homeland Security: Oral Statement ..................................................................................................... 27 Prepared Statement ............................................................................................. 28 (III) VerDate Mar 15 2010 11:32 Jun 30, 2021 Jkt 000000 PO 00000 Frm 00003 Fmt 5904 Sfmt 5904 H:\117TH\21CI0505\21CI0505 HEATH VerDate Mar 15 2010 11:32 Jun 30, 2021 Jkt 000000 PO 00000 Frm 00004 Fmt 5904 Sfmt 5904 H:\117TH\21CI0505\21CI0505 HEATH RESPONDING TO RANSOMWARE: EXPLORING POLICY SOLUTIONS TO A CYBERSECURITY CRISIS Wednesday, May 5, 2021 U.S. HOUSE OF REPRESENTATIVES, COMMITTEE ON HOMELAND SECURITY, SUBCOMMITTEE ON CYBERSECURITY, INFRASTRUCTURE PROTECTION, AND INNOVATION, Washington, DC. The subcommittee met, pursuant to notice, at 2:30 p.m., via Webex, Hon. Yvette Clarke [Chairwoman of the Subcommittee] presiding. Present: Representatives Clarke, Jackson Lee, Langevin, Rice, Torres, Garbarino, Norman, Harshbarger, and Clyde. Also present: Representative Katko. Chairwoman CLARKE. The Subcommittee on Cybersecurity, Infra- structure Protection, and Innovation will come to order. Without objection, the Chair is authorized to declare the subcommittee— oops, excuse me. Let me move forward. Good afternoon and thank you to our witnesses for joining us today to discuss how we can respond to the ransomware crisis. You know, I first chaired this subcommittee over 10 years ago. While ransomware is not a new problem, the number of cases and the financial impact has skyrocketed since then. That is why I wanted to focus on ransomware at our first subcommittee hearing this year. We must understand the problem we are facing, learn more about how the Federal Government should respond, and do something. Estimates show that ransomware victims paid $350 million in ransom payments last year. Among those victims were 2,400 U.S.- based governments, health care facilities, and schools. As the COVID–19 pandemic forced governments and businesses to shift to remote work, thousands found themselves locked out of their net- works as cyber criminals demanded ransom payments. These at- tacks are more than a mere inconvenience. They are a National se- curity threat. It is time for bold action rooted in robust partner- ships between the Federal Government and its State, local, and private-sector partners. In the coming days, I will introduce the State and Local Cyberse- curity Improvement Act, which will authorize $500 million in an- nual grants to State, local, territorial, and Tribal governments to strengthen their cybersecurity. As the ever-increasing number of (1) VerDate Mar 15 2010 11:32 Jun 30, 2021 Jkt 000000 PO 00000 Frm 00005 Fmt 6633 Sfmt 6633 H:\117TH\21CI0505\21CI0505 HEATH 2 ransomware attacks on State and local governments demonstrates, adequate treatment in cybersecurity has been lacking and more re- sources are needed. Just last week we saw some ransomware attacks that released sensitive law enforcement information from police departments in Washington, DC, and Presque Isle, Maine, showing that cities, large and small, are vulnerable to this type of cyber crime. This legislation would ensure funding is available while insisting State and local governments step up to prioritize cybersecurity in their own budgets. I am proud of the bipartisan support this bill has received on this committee and look forward to working with Ranking Member Garbarino along with Chairman Thompson and Ranking Member Katko to get this critical bill enacted. I hope this hearing will give us an opportunity to learn more about the challenges State chief information officers face under current funding constraints and how they would be able to use additional resources to strengthen their defenses to ransomware. While State and local governments are some of the most notable victims of ransomware, this crisis affects many private businesses in the United States and around the world. Combatting this threat will require coordination between the public and private sectors and all levels of government. The Ransomware Task Force report released last week provided 48 recommendations on what Government