home / press / releases

Menu
  • Search all tables

releases: https://www.portman.senate.gov/newsroom/press-releases/hearing-portman-questions-witnesses-election-security-cybersecurity-threats

One row per release. Full-text search runs over title + body text.

Data license: MIT · Data source: dwillis/congress-press

This data as json

url title date year month party chamber state member_name bioguide_id domain scraper source date_source text has_text collected_at updated_at
https://www.portman.senate.gov/newsroom/press-releases/hearing-portman-questions-witnesses-election-security-cybersecurity-threats At Hearing, Portman Questions Witnesses on Election Security & Cybersecurity Threats Facing United States 2020-12-16 2020 2020-12 Republican Senate OH Rob Portman P000449 www.portman.senate.gov     legacy At Hearing, Portman Questions Witnesses on Election Security & Cybersecurity Threats Facing United States December 16, 2020 | Press Releases WASHINGTON, DC Today, at a Homeland Security and Governmental Affairs Committee hearing, U.S. Senator Rob Portman (R-OH) questioned witnesses about election security and the cybersecurity threats facing the country. Portman has led efforts to address state and local cybersecurity threats and has worked to combat cyberattacks and ensure elections are free, fair, and secure from foreign interference. Last week, Portman announced that the Senate-passed FY 2021 National Defense Authorization Act (NDAA) conference report included his bipartisan provision to require the Department of Homeland Security to establish a Cybersecurity State Coordinator position in every state. In 2018, Senator Portman's bipartisan Hack Department of Homeland Security (DHS) ActandPublic-Private Cybersecurity Cooperation Actwere included in a package of billsthat were signed into law. In addition, earlier this year, Senators Portman and Gary Peters (D-MI) introduced the bipartisan Risk-Informed Spending for Cybersecurity (RISC) Act to require the federal government to make better investments in cybersecurity protections to keep Americans' data safe. The legislation would require federal agencies to efficiently allocate limited cybersecurity resources to acquire capabilities that address the most pressing cyber threats. In addition, earlier this month, the senators introduced a bipartisan bill that would increase transparency and modernize how the government responds to cybersecurity incidents on federal information systems. Federal System Incident Response Act will update and add critical new sections to FISMA, increasing transparency by clarifying how and when agencies must notify impacted individuals and Congress when data breaches occur. The bill would also require agencies to share information about cybersecurity incidents with the Office of Management and Budget (OMB) and the Cybersecurity and Infrastructure Security Agency (CISA) to ensure that attacks against one agency can be compared to other agency incidents. In June 2019, Senator Portman, as Chairman of the Permanent Subcommittee on Investigations, released a bipartisan report that found that the vast majority of federal agencies reviewed by the Subcommittee failed to implement effective and comprehensive cybersecurity frameworks. This included the failure to protect sensitive personally identifiable information and an overreliance on outdated legacy systems. Excerpts of the hearing can be found below and a video can be found here. Portman: I have been moving around the Capitol as we have had to vote, but I was at the hearing earlier, and I appreciate the witnesses and all of the information that we have received and you know, as I look at this issue and even watch some of the back and forth today between our colleagues, it seems to me that pulling this out of politics a little bit and having a bipartisan group that is a more independent look at the issue is a good idea. In part because most of us don't believe that this ought to be something that the federal government usurps from the states. In fact, we believe that the Constitution got it right and that, generally speaking, it is better to have these states handle this, but there are obviously many disparities between how the states do it. So there was discussion earlier, I think it was the Carter-Baker Commission, I would ask you, Mr. Starr, is this time for us to establish a commission -- I have been involved in some of these commissions, I have been a commissioner and co-chaired some that have worked, some that haven't worked, but often they can be quite effective at sort of taking the partisan poison out of an issue and addressing it in a very straightforward way. If you had a distinguished Democrat and a distinguished Republican and commissioners who are dedicated to increasing the confidence in our elections, do you think now is the time for us to establish such a commission that could report with plenty of time before the next midterm election and help to give the states a sense of direction and perhaps even a template of best practices? Former Justice Department Independent Counsel Kenneth W. Starr: The short answer is yes. In light of the acrimony and the division with respect to the 2000 election bringing together Jimmy Carter and former Secretary of State Baker was, I think, very efficacious. They made thoughtful recommendations, but they bring attention and shed light on what the issues are, and so yes, I think taking it out of what is clearly continuing to be a highly bitter and acrimonious discussion and to say to the American people, We are going to take a look at this and we are going to try to in fact improve in the great spirit of reform.' We want honest elections. Abraham Lincoln, the subject of the fraudulent mail-in campaign, let's not lose sight -- even though I am thankful that foreign interference and so forth, I very much admire Mr. Krebs and all of that -- but we are really talking about down in the boiler room', so to speak, of American elections, and that is where I think these reforms need to be and safeguards need to be put in place. Portman: Well, thank you for that, and I am looking forward to working with one of my Democratic colleagues to try to promote this idea. We have had some discussions of it already, and I think it again today what we have heard is indicative of the degree of intensity on this issue and the need for free and fair elections. I think everybody agrees with secure elections absolutely, and you mentioned Mr. Krebs; Chris, thank you for your service at CISA. I agree with what was said earlier about the fact that during your time there, you were instrumental in building up our defenses on the cybersecurity side. Particularly thank you for working with Ohio Secretary of State Frank LaRose so well. Frank LaRose and you, I think, were able to provide some examples for other states, as I understand it. You can speak to that. But we have in every county in Ohio the so-called Albert Intrusion Detection Monitoring Hardware, which is designed to detect suspicious cyber activity. Can you comment briefly on the benefits of using this kind of detection and monitoring hardware and how it worked? Cybersecurity and Infrastructure Security Agency Former Director Christopher C. Krebs: Yes, sir. First off, I want to thank you for actually just the state of Ohio; for some reason, in my senior staff and my front office, two of my top three advisors happen to be from Ohio, so you are doing something right there. The Albert systems are intrusion detection systems that effectively sit on the network, sit on the wire, that capture traffic that we can work with our intelligence community partners and develop what is known as signatures', looking for known malicious activity or known interaction with suspicious IP addresses, just looking for bad interaction. And it gives us a good insight into what sort of behaviors may be happening on those networks and they were actually pretty key after the 2016 election. Once we were able to get a sense of what was happening in Illinois, we could load up some of those signatures and then go do forensics. It is a passive system. It is a forensics system. Where we need to go, though, is building on the trust we have developed through the Albert sensors and through the ISAC and through the coordinating councils to start deploying more advanced technologies, and I am specifically talking about some of the endpoint detection and response capabilities that will actually sit on a computer in a state and local office and be more of a real-time monitoring and mitigation capability. That is how we continue moving forward. We need the same capability in the federal government. We are not there yet, but we have to continue advancing, and I think Congress will. Portman: Chris, and I again, as you know, you and I have talked about this, I appreciate what you did for elections. I also am very concerned that our federal government is not up to the task generally, and that is another topic for another hearing, perhaps one where you will be back to testify. But look what has happened just recently. In the last week, we found out that a very sophisticated group of hackers got into the computers of some of our most sensitive agencies and so we obviously have a lot of work to do, and I am not suggesting that CISA, you know, was that fault there, but on the other hand, I think we have not yet given even CISA the adequate resources and authority to be able to handle all of these issues, not just the election issues, but obviously we have a huge problem right now with cyberattacks, and we don't know all of the details yet, and I won't ask you to get into stuff you don't know about, but it was a massive cyber-attack on federal agencies that undercut our national security, we know that. By the way, Senator Paul earlier talked about the fact that there has been some lack of understanding between what you testified to and what you stated as to the election being secure from cyber-attacks and this notion that there were not instances of irregularity and fraud in this election, which of course there have been in every election in the history of our country and there were in this election, and we have heard about some of those today. Is Senator Paul correct, and I guess I would slightly amend what he said. He said that your focus was just on foreign adversaries. My sense is your focus is not just on foreign adversaries, although you feel fairly confident that that did not happen this time, and obviously based on what happened in 2016 with the Russians, this is good news but also with regard to domestic cyber-attacks is that what your report was about? Is he accurate in saying that? Mr. Krebs: Yes, sir, so you know when you come in a federal office, you pledge the oath to uphold and defend the Constitution from threats foreign and domestic, and that is what we did. The focus of the statement, the joint statement, was security. It was secure, I think terms have been conflated here, you know, alleging that we were speaking to the fraud aspect. We absolutely were not. We were talking about security, hacking, manipulation of these machines. That was the thrust of the statement. Portman: Yeah, I think that is very important to point out, and I think a number of people were confused about that, including perhaps some folks in the administration. Post-election there's been a lot of talk about signature matching and I will end with this Mr. Chairman, I know we are getting overtime here, but in Ohio what we know is -- and we have been doing this for 15 years quite successfully -- we send out an application for an absentee ballot. It's a no-fault absentee. That's how I vote. But you have to send in an application including a signature. Those signatures are checked. Then the signature on the actual ballot -- once you receive the ballot and you send that in, you have another signature -- that's checked, and then of course the two are compared. They also, in Ohio, have access to other signatures if there is some confusion as to whether it might be the right person or not. Could you, Mr. Krebs or others, perhaps comment on that system? Is that a good way to ensure that you have the protection that we all want to have that the person who requested the ballot is an eligible voter and that the returned ballot was completed by that same person? Mr. Krebs: Not an expert on the system. Seems reasonable to me. Portman: Anybody else want to comment on that? Commonwealth of Pennsylvania State Representative Francis X. Ryan: Sir, this is State Representative Frank Ryan. I would tell you that that is a good system, and that would alleviate significant number of the concerns that I had in the election. And based upon some of the comments that were made by many of the senators and the testifiers, I would indicate that we saw a major problem with the dotcom bubble in 2001, which led to the Sarbanes-Oxley bill, much of which is the basis of my testimony today. And in 2008 and 2009 we had the crisis that happened in the banking industry with the no documentation law, and so we saw how that worked, it led to the Dodd-Frank bill. I would hope that what happened in 2000 elections and in the Abraham Lincoln election, and this most recent one in 2016 and 2020, there would be similar legislation that could help us restore the confidence that people have that there is some degree of uniform perspective about the requirements that each of the states needs to be able to comply with. What Ohio is doing would have alleviated a major amount of the concerns I had when we had a Supreme Court that decided to legislate from the bench. Mr. Starr: And Mr. Chairman, if I may say just a word, and that is I think what, Senator Portman, you have identified, is a best practice, and it certainly qualifies as one of the things that perhaps a commission, if one is founded, can say We have canvassed the entire 50 states, and here are the best practices.' The recommendations could be based on experience as opposed to simply theoretical constructs. Let's just see what has worked in the various states with reputations for honesty and integrity. Portman: I think that would be the objective. Thank you, Mr. Starr, and thank you, Mr. Chairman, for your indulgence. ### 1 2026-03-30T12:14:52Z 2026-03-30T12:14:52Z
Powered by Datasette · Queries took 2.115ms · Data license: MIT · Data source: dwillis/congress-press