S. HRG. 118–113 CYBERSECURITY: CHALLENGES AND OPPORTUNITIES FOR SMALL BUSINESSES HEARING BEFORE THE COMMITTEE ON SMALL BUSINESS AND ENTREPRENEURSHIP OF THE UNITED STATES SENATE ONE HUNDRED EIGHTEENTH CONGRESS FIRST SESSION AUGUST 15, 2023 Printed for the use of the Committee on Small Business and Entrepreneurship ( Available via the World Wide Web: http://www.govinfo.gov U.S. GOVERNMENT PUBLISHING OFFICE 53–540 WASHINGTON : 2024 son on DSKJM0X7X2PROD with HEARINGS COMMITTEE ON SMALL BUSINESS AND ENTREPRENEURSHIP ONE HUNDRED EIGHTEENTH CONGRESS BENJAMIN L. CARDIN, Maryland, Chairman JONI ERNST, Iowa, Ranking Member MARIA CANTWELL, Washington MARCO RUBIO, Florida JEANNE SHAHEEN, New Hampshire JAMES E. RISCH, Idaho EDWARD J. MARKEY, Massachusetts RAND PAUL, Kentucky CORY A. BOOKER, New Jersey TIM SCOTT, South Carolina CHRISTOPHER A. COONS, Delaware TODD YOUNG, Indiana MAZIE HIRONO, Hawaii JOHN KENNEDY, Louisiana TAMMY DUCKWORTH, Illinois JOSH HAWLEY, Missouri JACKY ROSEN, Nevada TED BUDD, North Carolina JOHN HICKENLOOPER, Colorado SEAN MOORE, Democratic Staff Director MEREDITH WEST, Republican Staff Director dmwilson on DSKJM0X7X2PROD with HEARINGS (II) VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00002 Fmt 5904 Sfmt 5904 E:\HR\OC\B540A.XXX PFRM68 CONTENTS AUGUST 15, 2023 OPENING STATEMENTS Page WITNESSES John Hickenlooper, U.S. Senator from Colorado ................................................... 00 Mr. Kevin Stine, Chief of the Applied Cybersecurity Division, National Insti- tute of Standards and Technology, U.S. Department of Commerce, Gaithers- burg, MD ............................................................................................................... 00 Prepared Statement ......................................................................................... 00 Ms. Gretchen Bliss, Director of Cybersecurity Programs, Cybersecurity Pro- grams Office, University of Colorado, Colorado Springs, Colorado Springs, CO .......................................................................................................................... 00 Prepared Statement ......................................................................................... 00 Mr. Alfred Ortiz, CEO, CSD Cyber, Colorado Springs, CO ................................. 00 Prepared Statement ......................................................................................... 00 Dr. Shawn P. Murray, President-Elect, International Board of Directors, In- formation Systems Security Association, Colorado Springs, CO ...................... 00 Prepared Statement ......................................................................................... 00 dmwilson on DSKJM0X7X2PROD with HEARINGS (III) VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00003 Fmt 5904 Sfmt 5904 E:\HR\OC\B540A.XXX PFRM68 dmwilson on DSKJM0X7X2PROD with HEARINGS VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00004 Fmt 5904 Sfmt 5904 E:\HR\OC\B540A.XXX PFRM68 CYBERSECURITY: CHALLENGES AND OPPORTUNITIES FOR SMALL BUSINESSES TUESDAY, AUGUST 15, 2023 UNITED STATES SENATE, COMMITTEE ON SMALL BUSINESS AND ENTREPRENEURSHIP, Washington, DC. The committee met, pursuant to notice, at 2:30 p.m. MDT, at UCCS Cybersecurity Center, 3650 N. Nevada Avenue, Colorado Springs, Colorado, Hon. John Hickenlooper presiding. Present: Senator Hickenlooper [presiding]. OPENING STATEMENT OF SENATOR HICKENLOOPER Senator HICKENLOOPER. I call this meeting of the Committee on Small Business and Entrepreneurship to order. Today we are going to have a Senate Small Business Committee field hearing on the importance of cybersecurity, especially for small businesses. We want to give special thanks to the University of Colorado at Colorado Springs, the Space Information Sharing and Analysis Center, the ISAC, and the National Cybersecurity Center for their hard work on these critical issues and for providing such a wonder- ful space for us to talk about space. Also thanks to Chair Cardin and Ranking Member Ernst for the opportunity to chair this hear- ing, for their partnership on working on these critical issues. And although they are not here personally they are here in spirit. And especially important in light of the Air Force’s decision to permanently locate Space Command here. Colorado Springs has both the small business base and local expertise to support the work of Space Command, and we look forward to a long, continued alliance with Space Command. We are here today to focus on how to help these small businesses to thrive in an ever-changing economy, especially one where cyber- security becomes a larger and larger risk. The changing nature of commerce means small businesses have the opportunity to inte- grate technology to help them grow and innovate. Internet trans- actions contribute roughly $10 trillion annual to the global econ- omy. But as technology becomes more critical to business oper- ations, cybercrime becomes increasingly threatening. Bad actors target small businesses, large businesses indiscriminately. Some- times they just attack anything that moves. Sixty-six percent of all small businesses have experienced a cyberattack of some sort in the past year. These cyberattacks in- clude software designed to harm computer systems, phishing dmwilson on DSKJM0X7X2PROD with HEARINGS emails, Trojan Horses that contain malware, holding data and ap- (1) VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00005 Fmt 6633 Sfmt 6633 E:\HR\OC\B540A.XXX PFRM68 2 plications for ransom. That includes weaknesses such as weak passwords that can be easily guessed or construed by bad actors. Small businesses often, on account of their size, so often lack the resources and expertise to prevent the cyberattacks before they happen, and in many cases struggle to respond after the attack oc- curs. In so many cases they cannot afford to have a department or even a dedicated engineer to help them be prepared and to help guide them when they have been attacked. Small contractors may struggle to comply with complex Federal contracting requirements. We need to make sure that with the complex systems that the Federal Government requires that we prioritize security without leaving small contractors behind. Cer- tainly when small businesses turn to the insurance market for cyber insurance it can be challenging to understand how the poli- cies work, how insurance can help them recover after a cyberattack, and what the value proposition is, what they are pay- ing for, whether they are getting a fair value for their insurance. Our bipartisan Insure Cybersecurity Act, with Senator Capito from West Virginia, is going to help provide both clarity and guid- ance for small businesses looking to get insured. This is an issue across industries. Even former brewpub owners are sensitive to the need to protect websites, payments, business accounts. The Federal Government has a broad variety of programs to con- nect small businesses with the support they need to do business, and especially do business in this digital economy. The SBA Small Business Development Centers support small firms in a variety of ways, including cyber. One new law requires SBDCs to have em- ployees certified cyber strategy counseling for small businesses. That means that there are answers at hand at almost all times. A few of our witnesses today have done extensive work with the Colorado SBDC to support training small firms in this room. The National Institute of Standards and Technology, more fondly known as NIST to most of us, is a global leader—and I mean that sincerely, a global leader—in setting standards and issuing de- tailed guidance on privacy, connected devices, cybersecurity. We are lucky to have these deep technical experts working to protect public and private institutions, not just nationwide but globally. They establish a common language, and such a commonality of lan- guage is essential to be successful in our defense from intruders. We are excited to hear today from NIST about their work on these issues. This is, without question, a bipartisan issue. There should be no politics involved in this in any way. I think everyone agrees that we need to expand our cyber workforce. Right now we are filling up less than 70 percent of the jobs that need to be filled, the avail- able cyber jobs. We need to provide support, and not just support but genuine technical assistance to small businesses. At the same time, we have to raise awareness of the information that is avail- able for cyber defense, where they can turn. And we have to, at least to some minimum level, establish these cyber standards around creating safeguards. As our economy continues to grow and continues to digitize, we dmwilson on DSKJM0X7X2PROD with HEARINGS need to ensure businesses have the ability to protect themselves in cyberspace. Most important for my job here right now is to thank VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00006 Fmt 6633 Sfmt 6633 E:\HR\OC\B540A.XXX PFRM68 3 all of you for being here, our witnesses. I will introduce Kevin Stine here in a moment. Having a standard Senate hearing proceeding, or not being able to have a standard Senate hearing in the old traditional sense means we will not be taking—let’s get that right. Using the stand- ard Senate hearing proceedings means we cannot take questions from the audience, but if someone wants to sign them out to me I will do the best I can. But certainly if call, send us an email, write us a letter, we will respond and answer any questions that are asked. We have some excellent witnesses today, and I am going to read a description of all four witnesses, although we are going to start with Kevin Stine here, who is Chief of the Applied Cybersecurity Division at the National Institute of Standards and Technology, NIST, the Information Technology Laboratory, or should I say NIST’s Information Technology Laboratory. Do not get me started on the acronyms in the Federal Government. In this role, Kevin leads NIST’s collaborations with industry, with academia, and, of course, with government to improve cyber- security and privacy risk management. We are going to hear in a moment from Gretchen Bliss, who is the Director of Cybersecurity Programs at the University of Colo- rado, Colorado Springs. Gretchen has over 30 years of experience in cybersecurity and leads UCCS’s academic and research efforts in cybersecurity. Alfred Ortiz is the CEO of CSD Cyber. Alfred established his small business after over 20 years of working in cyber systems and is capable of translating even this indecipherable technology into Spanish. Also we have Dr. Shawn Murray, President-Elect of the Informa- tion Systems Security Association. Dr. Murray is a small business owner, the incoming President of an association of IT security pro- fessionals. So again, we are grateful to have all of you here, especially to those of you who are going to have to step up to the witness stand and bear witness. Anyway, we will start with our first panelist, Kevin Stine, and now I will turn it over to you for your opening remarks, and then we will begin the heated questioning, well, lukewarm questioning. STATEMENT OF KEVIN STINE, CHIEF OF THE APPLIED CYBER- SECURITY DIVISION, NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY, U.S. DEPARTMENT OF COMMERCE, GAI- THERSBURG, MD Mr. STINE. I look forward to it. Perfect. Well, thank you Senator Hickenlooper for including NIST in to- day’s field hearing on such an important topic and here in beautiful Colorado Springs. As you mentioned, I am Kevin Stine. I am the Chief of the Applied Cybersecurity Division within the Information Technology Lab at the Department of Commerce’s National Insti- dmwilson on DSKJM0X7X2PROD with HEARINGS tute of Standards and Technology. Keeping track of acronyms, that is DOC NIST ITL ACD, but we will not go there. VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00007 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 4 Thank you again for the opportunity to be here today to discuss NIST’s role in helping small businesses to improve their cybersecu- rity. NIST has worked in the cybersecurity space since about 1972, and really prides itself on our strong partnerships with government agencies, with companies of all sizes, with academic, nonprofit enti- ties, to really develop and improve our cybersecurity resources to best meet their needs. Our direct connections with companies and other users of our guidance helps those organizations but it also advances our efforts to inform government and private sector cy- bersecurity-related policy decisions. I think as you said very clearly, cybersecurity is a challenge for all organizations, and the risks and technologies are constantly changing, and it can be difficult for any organization to keep pace. Small businesses, though, are more innovative, agile, and produc- tive than ever thanks to the capabilities delivered by technology, but the cybersecurity challenges for small businesses certainly loom larger than ever. Not every small business is the same. Their risks will vary. So whether you are a small coffee shop or a brewpub, your risks could be very different compared to a small company that maintains mil- lions of health records, for example. At NIST we believe in risk-based approaches to ensure organiza- tions have the tools to address their specific needs. We have a long- standing effort to help small companies meet their cybersecurity needs. In response to the NIST Small Business Cybersecurity Act several years ago we launched the NIST Small Business Cyberse- curity Corner to help put key resources in one place. The Small Business Administration, the Department of Homeland Security, the Federal Trade Commission, and others have contributed re- sources to that NIST site, and they are also providing small busi- ness-focused resources to be shared through our site, and they pro- mote its awareness and use. In March of this year, NIST launched a Small Business Cyberse- curity Community of Interest to convene companies, trade associa- tions, and others who can share business insights, expertise, chal- lenges, and perspective to guide our work and assist NIST to better meet the cybersecurity needs of small businesses. Members of this community are learning about NIST’s current and planned re- sources intended for smaller organizations, and they also provide us with on-the-ground feedback about the usefulness of those re- sources and how to approve them. Beginning in 2013, NIST created the Framework for Improving Critical Infrastructure Cybersecurity, which is commonly referred to as the Cybersecurity Framework or the CSF, which many orga- nizations, including many small businesses, use to better under- stand, communicate, and reduce cybersecurity risk. Just last week, on August 8th, we issued a complete redraft of the Framework for public comment, and we have based our pro- posed update on lessons learned from the use of the Framework over the last several years. CSF 2.0, as we call it, is explicitly in- tended to be used by organizations of any size and in any sector. dmwilson on DSKJM0X7X2PROD with HEARINGS We have been hosting workshops and collecting comments to in- form improvements to the framework, and that includes reaching VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00008 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 5 out to small businesses for their perspectives, which has been very valuable. Small manufacturers also represent a critically important part of the community. The mission of NIST Manufacturing Extension Partnership, or the MEP, is to assist small and medium-sized man- ufacturers. MEP operates a nationwide network, with centers in every state and in Puerto Rico, and through this program NIST partners with others to provide awareness, training, and hands-on cybersecurity assistance to smaller manufacturers to help them se- cure their business information and assets. You mentioned cybersecurity workforce in your opening remarks. A skilled and diverse cybersecurity workforce in organizations, in- cluding, and sometimes especially in smaller companies, is critical to improving the nation’s cybersecurity capabilities. Another pro- gram led by NIST is NICE—I do not always pick the acronyms, but it is a nice one—which enhances cybersecurity education, training, and workforce development capabilities of the United States. Through NICE we have produced tools and provide resources to help large and small organizations alike to understand and address their cybersecurity workforce needs. We are also home to the National Cybersecurity Center of Excel- lence, which is a collaborative hub where industry, government agencies, and academic institutions and others work together to ad- dress cybersecurity challenges facing U.S. businesses of all sizes. And while we have developed cybersecurity guidance and other resources for small businesses, we are also focused on increasing the security of the technology that we all leverage each and every day, including, for example, our work on next-generation encryption and our efforts to secure software platforms, networks, and connected devices. So again, thank you for the opportunity to explain NIST’s cyber- security portfolio and how it applies to a wide variety of users, from small and medium-sized enterprises to large, private and pub- lic organizations. We know how real and difficult the challenges are, and it is part of our job to help organizations of any size, in any sector, to successfully tackle those challenges so they can do their jobs better. So thank you again for including us, and I look forward to any questions you might have. [The prepared statement of Mr. Stine follows:] dmwilson on DSKJM0X7X2PROD with HEARINGS VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00009 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 6 dmwilson on DSKJM0X7X2PROD with HEARINGS Insert offset folio 16 here 53540.001 VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00010 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 7 dmwilson on DSKJM0X7X2PROD with HEARINGS Insert offset folio 17 here 53540.002 VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00011 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 8 dmwilson on DSKJM0X7X2PROD with HEARINGS Insert offset folio 18 here 53540.003 VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00012 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 9 dmwilson on DSKJM0X7X2PROD with HEARINGS Insert offset folio 19 here 53540.004 VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00013 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 10 dmwilson on DSKJM0X7X2PROD with HEARINGS Insert offset folio 20 here 53540.005 VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00014 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 11 dmwilson on DSKJM0X7X2PROD with HEARINGS Insert offset folio 21 here 53540.006 VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00015 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 12 dmwilson on DSKJM0X7X2PROD with HEARINGS Insert offset folio 22 here 53540.007 VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00016 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 13 dmwilson on DSKJM0X7X2PROD with HEARINGS Insert offset folio 23 here 53540.008 VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00017 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 14 dmwilson on DSKJM0X7X2PROD with HEARINGS Insert offset folio 24 here 53540.009 VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00018 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 15 Senator HICKENLOOPER. You bet. Thank you, Kevin, and I appre- ciate you taking the time out of your busy schedule to get over here for this hearing. Obviously, you are concerned with cyber in all dimensions. How do you think about cyber within small businesses, specifically, and in what ways do you try to think of that, you know, communicate to that community in a specific way? Mr. STINE. Yeah. Cybersecurity, at times, has its own language that we speak, so it is important to be able to talk about cybersecu- rity in a way that will be more consumable and digestible to orga- nizations of all shapes and sizes across all different sectors, and that certainly is inclusive of small businesses. Tools like the Cybersecurity Framework provide, in our view, a common language or a common taxonomy that is intended to help break down some of those communications divides both within com- panies but also across companies and across sectors, and even across nations as well. We think there is a lot of value in having a common language that is provided by the Cybersecurity Frame- work. Senator HICKENLOOPER. What are some of the key pieces of feed- back that you have received from NIST’s new Small Business Cy- bersecurity Community of Interest? Mr. STINE. The Small Business Cybersecurity Community of In- terest. We take small business cybersecurity very seriously, and it is certainly woven into all parts of our cybersecurity and our pri- vacy portfolio at NIST. We stood up the Community of Interest just a few months ago to really help drive more involvement, and I would say that is bidirectional involvement with the small business community, both the businesses themselves but also their advo- cates. It could be associations. It could be service provides to small businesses, for example. And we think having that open line of communication, that bidirectional communication is tremendously valuable for us to help share updates with the small business com- munity on things we are working on but also receive feedback di- rectly from them. And I think over the last few months there are a few themes that I think we have heard in these formative months. The first, I think there has been overwhelming appreciation for having a venue like the Small Business Cybersecurity Community of Interest, where different players in the community can get together, share their ex- periences, and certainly communicate directly with NIST. We frequently hear that one of the big challenges for small busi- nesses, because cybersecurity can be overwhelming, and certainly the standards and guidelines can be overwhelming as well, just the sheer volume of those resources alone can be overwhelming. So being able to discuss just simply where to start—Where do I start? What are some resources that I should start with as a small busi- ness to really get a better sense of where I am today from a cyber- security perspective and where I might need to be, and what are some potentially quick steps I can take on my journey? So hearing that has been very helpful. And I think the final piece that we have heard, and the final dmwilson on DSKJM0X7X2PROD with HEARINGS theme, would be the need and the importance for tailored re- sources. Again, we produce a lot of standards and guidelines and VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00019 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 16 other agencies and other organizations, public and private, produce resources for small businesses. And not all of those resources are written in a way that are tailored or customizable for the unique needs of small businesses. So the learnings that we are kind of observing early on is just the validation that as we are producing standards and guidelines, as we are producing other resources to be able to reflect those to the small business community and get their feedback early and often so that the things that we produce are going to be the most useful and digestible for them. Senator HICKENLOOPER. Integrate it. Take that feedback into the policy. Last week, NIST released a new draft of their highly regarded Cybersecurity Framework, as you were describing, after beginning the 2.0. I know that the NIST Cybersecurity Framework was well received by many large companies. What has the response been— I am sure you have a broader range of responses, but what has the overall response been from the small business community? Mr. STINE. We have been thrilled with the uptake of the Frame- work since we first issued it in 2014, and certainly we have seen tremendous growth and increased uptake across all sectors and all sizes of organizations since we issued that first version back in 2014. And that includes small businesses, and we have had many small businesses that have been on the Cybersecurity Framework journey with us since the early days and have become great advo- cates and amplifying voices for the use of the Framework for small businesses. But I think this 2.0 update process provides us a great oppor- tunity to kind of reevaluate the Framework, reevaluate its utility for small businesses, and I would say more importantly, or just as importantly, the types of derivative resources we can produce to really help make it more consumable and digestible for small orga- nizations. I think that common language that it provides is probably the greatest value provision, if you will, for the framework, because it can speak to and be understood by non-cybersecurity, non-technical folks, maybe the folks that understand mission and risk, maybe not cybersecurity risk, but they understand risk, and being able to talk about cybersecurity risk in that bigger enterprise risk discussion, whether your enterprise is 10 people in a coffee shop or a brewpub, or a much larger multinational organization. We think there is a lot of value in that, and we are excited to continue to get feedback during this draft comment period to help further inform the frame- work. Senator HICKENLOOPER. And I have not seen this in previous dis- cussions. That common language, I agree with you, is crucial. In a funny way it almost allows you to be able to measure and begin to define increments of measure, which allows one to create not only defenses but solutions when you have been hacked. How does that integrate? In other words, are you trying to figure out the increments of measure by which you could classify attacks as part of this overall language that is being created? dmwilson on DSKJM0X7X2PROD with HEARINGS Mr. STINE. Measurement is a challenging area in the cybersecu- rity space, especially for a precision measurement organization like VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00020 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 17 NIST. I do not know that you are going to get down to the next- best—— Senator HICKENLOOPER. Atomic clocks. Mr. STINE. Yeah. We do have that, and that is a very precise measurement and a lot of value there. Cybersecurity is a different beast at times. But certainly there are things that you can measure today. But I think the value, again, of the Cybersecurity Framework, again, that common language and taxonomy is bringing in a whole different set of users to the cybersecurity discussion, which is tre- mendously valuable. It is not just the technologists and the cyber- security professionals. It is the educators. It is the lawyers. It is the human resources professionals. And I think as more folks, kind of that ‘‘big tent’’ approach, as more folks become part of that tent and that community there are going to be new and innovative ways to not only use the Framework but also the technologies and the services and the approaches to help achieve those outcomes that are expressed in the framework. We are going to learn a lot about that and help improve future versions as well. Senator HICKENLOOPER. I think that is one of the amazing things about NIST. Again, the United States is home to a center. I mean, most of us in business learned early on that what gets measured is what is gets done. If you cannot measure things you are going to have a hard time achieving results. And yet in something like this it is growing at a rate that makes it almost impossible to have a common language, let alone to measure the different things. That framework of language you are creating is actually going to allow— it is a little bit the same thing with fighting climate change, that we do not have the capability to measure accurately climate-chang- ing emissions at the level at the level it needs to be done to really address it. But NIST will figure that out as well. Mr. STINE. We are on it. Senator HICKENLOOPER. I am not trying to alarm anybody. I just want to make sure that they feel secure in NIST’s mission. What other guidance do you think small businesses need in order to deal with some of these cybersecurity risks? Mr. STINE. There are a lot of standards and guidelines that exist today in the cybersecurity and increasingly the privacy space. Cer- tainly we produce a lot of those. Others produce them as well. But I think, again, what we have heard very clearly from the small business community and those that provide services to support them are taking the voluminous guidance that might exist today and really distilling it down into much more practical, actionable, and consumable resources, things like Quick Start guides, tem- plates, fact sheets, those types of things that can distill the some- times very complex and potentially technical information into something that is going to be a little bit more immediately action- able. And again, I used the phrase earlier, organizations are on the journey. And as small businesses start on that journey and they begin to improve there are certainly more robust resources that can help them advance their cybersecurity capabilities. dmwilson on DSKJM0X7X2PROD with HEARINGS Senator HICKENLOOPER. And think that journey, there is a micro- cosm going on 100 times or 1,000 times in any company. Each indi- VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00021 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 18 vidual is going on that journey, and I think you are exactly right to be able to find those increments of information so that they can get on board and get engaged and grow into the complexity of the subject and hopefully help create those increments of measure as we go down the road. Obviously, just extending that train of thought, small businesses are part of a larger food chain, as it were. Maybe that is an inap- propriate word, but let’s call it a supply chain, to stay with a more acceptable business nomenclature. Obviously, the smaller firms are vital parts of the supply chains that bigger companies count on, and we have seen this frequently since the pandemic, that when these supply chains get interrupted it disrupts our entire economy. What is NIST doing to help secure or make more secure these complex supply chains that integrate small, medium, and large businesses? Mr. STINE. Yeah, you are absolutely right, and this is such a crit- ical topic for so many organizations. We have a longstanding pro- gram, an area of focus on cybersecurity supply chain risk manage- ment, so helping organizations better understand and manage the cybersecurity risks in the context of their supply chain activities. We certainly have produced guidance and different types of best practices that we have kind of gleaned from the best practices of other organizations over the years to really help organizations, again, of all shapes and sizes across all different sectors, but par- ticular small business, to better understand and then manage their cybersecurity risks in the context of supply chains. You know, every organization, large or small, is either a producer of technologies or services but also a consumer of those same serv- ices. So I think one of the frequent pieces of feedback we provide to small businesses, and certainly even large businesses as well, as they are interacting with smalls, is understanding and having more visibility into your supply chains, understanding what you are pro- viding, what the expectations are from you, and then being able to clearly express what those capabilities are from a cybersecurity perspective. I think increasingly we are also trying to take the standards and guidance and other technologies and practices that exist today and begin to demonstrate very practical example implementations of those, in the supply chain space in particular, through our National Cybersecurity Center of Excellence to provide, in some cases, some blueprints and some worked examples that can give really any or- ganization, but I think increasingly small businesses a better start- ing place on this journey as well. Senator HICKENLOOPER. Right. Michael, are we out of time? What is your sense of this, for the first panel. We are good? So I can ask another question. Good. Check with John Conrad because I do not really trust you, Michael. No, I am just kidding. I am just kidding. [Laughter.] Senator HICKENLOOPER. It is all about security. It is all about se- curity. You were saying this, that so many small businesses lack the time and the money and the personnel to really address cybersecu- dmwilson on DSKJM0X7X2PROD with HEARINGS rity and to assess what is necessary and the resources to create se- curity. But if they could be provided the essential information, in VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00022 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 19 a compact way, as you say, I think you used the word ‘‘digestible,’’ easily digestible, small businesses, I think, would make consist- ently better decisions. Is NIST able to coordinate, or are you already coordinating and partnering with other agencies in the Federal Government, such as the SBA here today, to ensure that small businesses are getting ac- curate, the right information, to be prepared for threats and to be able to respond? Mr. STINE. We do work very closely with our interagency part- ners and increasingly other organizations outside the Federal Gov- ernment as well, and I think through programs like the Small Business Cybersecurity Corner as well as the Community of Inter- est that we just established, we think those are going to be very helpful mechanisms as well to share resources from different parts of the interagency, whether it is SBA, or the Federal Trade Com- mission, our colleagues at the Department of Homeland Security, and CISA in particular, and many others. So there are a lot of opportunities for us to coordinate and col- laborate across the interagency to bring those resources to bear. And we do the same with many of our public sector or non-govern- ment entities. For example, the National Cybersecurity Alliance is another great resource that we work very closely with to help am- plify their message, and vice versa. We think there are plenty of resources. There are a lot of re- sources. There are a lot of coordination opportunities, and we are happy to coordinate and engage and play our part. Senator HICKENLOOPER. And are you able to focus on some of the networks that are smaller but make up the constituency that the SBA services, say women-owned or minority-owned businesses? Mr. STINE. We are, and I think that is where some of the oppor- tunities working with even other commerce bureaus. Like the Mi- nority Business Development Agency, for example, within the De- partment of Commerce, or within NIST’s Manufacturing Extension Partnership are two great mechanisms that have nationwide net- works and tentacles out there, if you will, to help reach diverse communities, including minority- and women-owned businesses. So tremendous value there. And I think part of the opportunity we have with the Cybersecu- rity Framework 2.0 update process is we really need to double down in our engagement with more diverse parts of the community to get their unique feedback to help inform the framework so that it can be the most useful for all involved. Senator HICKENLOOPER. Right. Last question, and I appreciate that. Obviously, companies large and small have to worry about cy- bersecurity, as you have been explaining, but also concerns about privacy, and different but similar, protecting the information of their customers. These three issues kind of intersect in small firms especially. So how do you help them address all three of these con- cerns as efficiently as possible? Mr. STINE. One of the most exciting parts and areas of most sig- nificant growth in our broader program in NIST is our Privacy Pro- dmwilson on DSKJM0X7X2PROD with HEARINGS gram. We think there is just tremendous opportunity there, both from the privacy risk management perspective but also the privacy- VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00023 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 20 enhancing technologies perspective. There are a lot of very exciting and innovative approaches that are out there. We try to ensure that for all the potential points of integration between cybersecurity and privacy, and there are many, many cy- bersecurity standards and controls and capabilities help to improve privacy protections as well, and that goes in both directions. So we try to take every advantage of the relationships and the expertise we have and the relationships we have in the community to high- light those points of intersection and really work with the innovators in the community to be able to produce the technologies and the resources that can be most useful. Senator HICKENLOOPER. Right. Absolutely. Well, I hate to inter- rupt this but I look forward to continuing the conversations over a cold beer at some point, to talk about something we do know how to measure properly. Mr. STINE. Yes, we do. We do that as well. Senator HICKENLOOPER. Anyway, thank you so much for your public service and investing so much of your life into something that is clearly tremendously important to the country, but I think underappreciated by most of the public. So that is always when public service is at its most public that you have to go on the line day in and day out and provide answers to difficult questions, and the public not really appreciating what you do. I think over the next few years the public will more and more appreciate people like yourself that are really working so hard to keep us safe. So thank you very much. Mr. STINE. Thank you, sir. I appreciate it. [Applause.] [Break.] Senator HICKENLOOPER. The only places you see such a rapid change of sets is in Hollywood or Washington, D.C., but here we are matching them in time. I want to welcome back, although you really have not gone any- where, but welcome back from the front row Gretchen Bliss, Alfred Ortiz, and Dr. Shawn Murphy—Murray. One of my oldest friends is named Shawn Murphy, and I am probably going to do that three or four times over the course of the next hour. Anyway, Gretchen is the Director of Cybersecurity Programs at the University of Colorado, Colorado Springs, which we mentioned earlier, Alfred Ortiz is the CEO of CSD Cyber, and Dr. Murray is the President-Elect of the Information Systems Security Associa- tion. [Applause.] Senator HICKENLOOPER. That was a better plug than I thought. All right. First a question that you can each do in turn. Gretch- en, we will start with you and just work down the line. Obviously, cybersecurity is a bipartisan issue. It requires a whole-of-govern- ment approach both to assessing the risk and trying to be able to preempt the cyber threats that we know are out there. And I ap- preciate all of you being here. What is the number one issue each of you would recommend we dmwilson on DSKJM0X7X2PROD with HEARINGS highlight as we work with the executive branch on ways to help small businesses safeguard their data? You are all experts. VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00024 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 21 Oh, what am I saying? You are supposed to do introductory statements and I went right to the questions. I get excited. What can I say? I apologize. We will go and let each of you do your open- ing statements, please. STATEMENT OF GRETCHEN BLISS, DIRECTOR OF CYBERSECU- RITY PROGRAMS, CYBERSECURITY PROGRAMS OFFICE, UNI- VERSITY OF COLORADO, COLORADO SPRINGS, CO Ms. BLISS. Thank you so much. As the Senator mentioned, I am Gretchen Bliss. I am the Director of Cybersecurity Programs at the University of Colorado, Colorado Springs. I am very honored to be here, to be invited to discuss my thoughts and background in bring- ing cybersecurity, small business, education, and students together to raise the bar on cybersecurity for all. The Colorado Springs ecosystem has been developing for at least the last 9 years into a coalition of the willing that connects edu- cation, industry, government, and community. The workforce de- mand for cybersecurity professionals is huge. Over 663,000 jobs are available today across the nation, 22,641 of those in Colorado alone. Cybersecurity is needed across all industry sectors, not just for military or government contractors, agencies, and departments. The National Cybersecurity Workforce and Education Strategy that was recently released, stated that, ‘‘Responsibility for defending cyberspace should be shifted from individuals and small businesses to the most capable actors in cyberspace, and vigorous collaboration among education, labor, and commercial stakeholders is essential to success.’’ Small Businesses face mounting and expanding challenges re- garding cybersecurity protection and threats. To underscore the need, Forbes reports that in 2021 alone, 70 percent of ransomware attacks were directed at small and mid-sized businesses. We are currently leveraging several federally funded initiatives to support collaboration among education and small business. Years back, our Pikes Peak State College team received a Regional Alliances and Multistakeholder Partnerships to Stimulate— RAMPS, another great acronym—grant from NIST’s NICE, since Kevin already covered that. We built the Cyber Prep program, where 17 high school students in the summer were paired with 14 small businesses, some of them sitting at this table, and they had a paid internship and got cybersecurity training sessions. The busi- nesses were shocked at the depth of talent that high school stu- dents possessed in cybersecurity. Two of the students have contin- ued with their companies through college and beyond. Of the over 400 U.S. institutions that the National Security Agency has designated as Centers of Academic Excellence in Cyber- security, 15 are in the state of Colorado. UCCS was the first CU system school designated as a Center of Academic Excellence in 2012. The CAE program helps to standardize academic cybersecu- rity programs. It provides grants to support the expansion and col- laboration between these educational programs across the country. Government and industry demand three things from a commu- dmwilson on DSKJM0X7X2PROD with HEARINGS nity student: a degree, industry-recognized certification, and hands- on experience. The grants that the CAE has provided provide stu- VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00025 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 22 dents with that experience and knowledge they need to be later hired to support cybersecurity needs across industry. Regionally, education and small business collaborate through the Small Business Development Center programs. One called Cyber Cover Your Assets, CYA, and the annual Colorado SBDC Network Cybersecurity conference. This program was the first of its kind and is leading programs nationwide. Small businesses work with the SBDC under an 8-week cyber implementation program where they receive risk assessment and education and budget-friendly so- lutions to secure their business assets. In addition, community ex- perts, small businesses—represented by my co-panelist Shawn Murray—and high school and community college students conduct cybersecurity hygiene checkups for small businesses. We actually just found out late last night that the collaboration between the SBDC, who is represented here, UCCS, NCC, and Murray Security Services were awarded a $1 million grant from SBA to bring cyber clinics, not unlike legal and medical clinics, to students and small businesses to build resilience and collaboration to solve those cybersecurity challenges. [Applause.] Ms. BLISS. Research is also fundamental to bringing businesses, government, and students together to solve those wicked-hard problems in cybersecurity. UCCS has a robust cybersecurity faculty that was awarded over $19 million in government funds over the past 3 years to conduct in-depth research for the Department of Defense, Department of Energy, the National Science Foundation, Cyber Command, Space Command, and industry partners. Re- search not only solves complex problems but also prepares students for industries’ workforce needs. Continued research funding across government agencies remains critical to solving these problems. The Space Information Sharing and Analysis Center, ISAC, is an embedded partner with UCCS, over in our other building here, and they have over 70 small, medium- and large-sized companies as members. The Space ISAC facilitates collaboration against cyber and space threats across the global space industry, enhancing in- dustry preparation for, and in response to, vulnerabilities, inci- dents, and threats. It also hosts a fellowship program for industry and educational fellows. Cross-disciplinary organizations, such as the Space ISAC, develop cyberspace resiliency throughout industry, government, and education. UCCS is leading the University of Colorado system and the state in finding new and unique ways to create cybersecurity partner- ships with small businesses. UCCS has developed a workforce pipe- line that begins in K–12 and crosses into community colleges and the CU system to ensure cyber capabilities are available to Colo- rado at many levels. Over the past four years, UCCS has expanded cybersecurity degrees and programs to 20 pathways across five col- leges, beyond the longstanding cornerstone programs in our engi- neering department at the bachelor’s, master’s and doctorate levels. Programs can now be found in the College of Public Service with a cyber law, policy, and forensics concentration; our Letters Arts and Sciences with a Technical Communication and Information De- dmwilson on DSKJM0X7X2PROD with HEARINGS sign bachelor’s degree; our College of Business with Cybersecurity Management degree at the bachelor’s, MBA, and DBA levels; and VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00026 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 23 finally, the College of Education, where we do teacher prep work- shops to bring cybersecurity into the classroom to make teachers comfortable and share it with their students down to the middle school level. Needless to say, UCCS believes strongly in cybersecu- rity as an interdisciplinary necessity. The nation benefits greatly from community programs such as those at UCCS, NIST, NICE, CAE, Space ISAC, Colorado Springs Community and SBDC. These programs develop a workforce so direly needed to protect our national security and solve those hard technical problems for the country. They bring small businesses to- gether with education to create the future workforce that will solve complex problems and raise the bar for cybersecurity nationwide. [The prepared statement of Ms. Bliss follows:] dmwilson on DSKJM0X7X2PROD with HEARINGS VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00027 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 24 dmwilson on DSKJM0X7X2PROD with HEARINGS Insert offset folio 46 here 53540.010 VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00028 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 25 dmwilson on DSKJM0X7X2PROD with HEARINGS Insert offset folio 47 here 53540.011 VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00029 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 26 dmwilson on DSKJM0X7X2PROD with HEARINGS Insert offset folio 48 here 53540.012 VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00030 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 27 Senator HICKENLOOPER. Thank you very much. Mr. Ortiz. STATEMENT OF ALFRED ORTIZ, CEO, CSD CYBER, COLORADO SPRINGS, CO Mr. ORTIZ. Good afternoon, Senator Hickenlooper, staff, and attendees. My name is Alfred Ortiz and I am the CEO of CSD Cyber, with 20 years of cyber and IT experience, moving from cor- porate America and starting my business over 5 years ago. As a small Colorado-based enterprise, I understand what it takes to grow a small business. In addition to CSD Cyber, I volunteer with the local Pikes Peak SBDC as a cyber expert and serve as a mem- ber of the board of directors for the local ISSA chapter. I have taught undergraduate and graduate students with a focus on cyber- security at the University of Colorado, Denver. I have dedicated my working career to helping individuals and firms keep their data safe from threats. My father and grandfather were entrepreneurs, so owning a small business and understanding its demands are embedded in my daily life as I work with people from all facets of our society. Cybersecurity is an all-partisan issue that affects Americans from every strand of our society as they may be affected personally and professionally. Approximately two-thirds of American business comes from small and medium entrepreneurs, like me and many attending today, and those whose small businesses are affected by Federal legislation. Of these small enterprises, those with less than 50 employees, 47 percent of them, do not have a budget for cyberse- curity. Adding to this, approximately 76 percent of SMBs, or 25.2 million businesses, have experienced a cyberattack in the last 6 months. Many will not recover. From malware, ransomware, to so- cial engineering and other threats, small firms have more demands with the least number of resources to defend themselves. CSD can cite circumstances where we have helped companies at all tiers. In one instance, we helped a small bank comply with Fed- eral regulations, and a Fortune 50 company to do the same. An- other time, CSD worked with a town to demonstrate the vulnerabilities of their water utility system so the residents can have safe drinking water, and we helped a local gym in securing their wireless network so their members can listen to their music safely as they work out. At times, firms like these do not know where to go for help or are limited on resources and might not know who to trust, they may have to decide on buying that new piece of capital equipment, fly to meet a client, or spend on advertising, not thinking about se- curing their vital data and that of their clients. Advocating for small business, CSD Cyber launched an SMB store on the Fourth of July this year for this very reason, to give SMBs options where they can go to for help with a reasonable price. With larger consulting firms charging over $500 an hour, we hope to change the rules by giving small business a fighting chance. Spending on cybersecurity is a necessity for today’s market, dmwilson on DSKJM0X7X2PROD with HEARINGS yet every firm knows that driving revenues is the lifeblood of their business. VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00031 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 28 The U.S. Federal Government is the largest buyer of goods and services in our country. With that, our small and medium busi- nesses make up over two-thirds of our economy and should have a fair shake at the table for business. When the CHIPS and Science Act was invoked, President Biden stated that it represents ‘‘a once-in-a-generation investment in America itself.’’ With approximately $57.2 billion to be funded, one might ask, were set-asides for SMBs and minority firms placed in the legislation so larger corporations could contract and fulfil their obligations with this Federal funding? More importantly, there needs to be considerations for small business to make it easier to participate in the Federal bidding process. When it takes 3 to 6 months to fill out a bid for an oppor- tunity and another year to 18 months to wait for the award, many small businesses cannot sustain that cycle. If these small enterprises do not sustain themselves with reve- nues and cybersecurity investment the Federal Government may have a three-fold problem: One, vital data on Americans may be lost to the dark web; two, for every SBA loan that fails, a person and their family will fall under that burden and lastly the Federal government will lose tax revenues. In short, cybersecurity is an all- American issue that affects American business. In conclusion, I am here before you with an unwavering commit- ment to the pivotal realms of cybersecurity, small business pros- perity, and legislative foresight. As a CEO, educator, and citizen, I come armed with a wealth of IT experience and the enduring leg- acy of my family’s entrepreneurial spirit. The resonance of our dialogue today reverberates far beyond these walls, underscoring the urgency of safeguarding data in a digital age, touching every facet of American society. Through the lens of CSD Cyber’s transformative collaborations, I have witnessed firsthand the pressing need for accessible solutions that empower entities of all scales to secure their futures. As we forge ahead into an era of legislative possibilities, let us champion the inclusion of small and minority businesses as inte- gral contributors, fueled by equitable opportunities and stream- lined processes. Together, we have the power to reshape the trajec- tory of our economy, bolstering its very foundation with the resil- ience of entrepreneurship and the fortified defense of cybersecurity. Thank you, Senator Hickenlooper, staff, and guests. I will now hand back my time to you, Senator. [The prepared statement of Mr. Ortiz follows:] dmwilson on DSKJM0X7X2PROD with HEARINGS VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00032 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 29 dmwilson on DSKJM0X7X2PROD with HEARINGS Insert offset folio 55 here 53540.013 VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00033 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 30 dmwilson on DSKJM0X7X2PROD with HEARINGS Insert offset folio 56 here 53540.014 VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00034 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 31 Senator HICKENLOOPER. Thank you. Thank you, Alfred. Dr. Murray. STATEMENT OF SHAWN P. MURRAY, Ph.D., PRESIDENT-ELECT, INTERNATIONAL BOARD OF DIRECTORS, INFORMATION SYS- TEMS SECURITY ASSOCIATION, COLORADO SPRINGS, CO Mr. MURRAY. Thank you, Senator. As mentioned, my name is Shawn Murray. I am the President and Chief Academic Officer at Murray Security Services, and I am the new President-Elect for the oldest and largest professional industry-driven cybersecurity infor- mation association in the world. [Applause.] Mr. MURRAY. Senator Hickenlooper, Chairman Cardin and other members of the Committee, thank you for this opportunity to ad- dress an area of national interest addressing cybersecurity con- cerns for small businesses in the United States. As a practitioner and educator, it is my intent to make you aware of some very im- portant information which can be used to influence decisions re- lated to information privacy and cybersecurity. Today, we know that 80 percent of most organizations’ business processes are automated, meaning that we are using some type of technology to process, transmit, or store information related to a job task that are performed by employees. There can be risk associ- ated with these processes if the employees and business managers do not consider security as part of awareness. The following statis- tics associated with cybersecurity trends for small and mid-sized businesses include: According to the National Cybersecurity Alliance, 70 percent of cyberattacks target small to mid-sized businesses. The Ponemon Institute reports that the average cost of a breach for small or midsized business, per incident, is $383,000. According to the Bet- ter Business Bureau, 50 percent will become unprofitable within a month of being breached. Finally, Gartner published in its Top Trends in Cybersecurity 2023 report that 60 percent of small busi- nesses that are victims of a cyberattack go out of business within 6 months, and overall, cybercrime costs small and medium busi- nesses more than $2.2 million a year. In the 2023 Data Breach Investigations Report published by Verizon every year, ‘‘Ransomware continues to be a major threat for organizations of all sizes and industries and is present in 24 percent of breaches. Of those cases, 94 percent fall within system intrusion’’; ‘‘74 percent of all breaches include the human element, with people being involved either via error, privilege misuse, use of stolen credentials or social engineering’’; ‘‘83 percent of breaches involved external actors, and the primary motivation for attacks continues to be overwhelmingly financially driven, at 95 percent.’’ The coronavirus pandemic saw a significant increase of remote workers and an investment of online technology, remote meeting applications, and cloud-based business resource subscriptions. The initial focus of small businesses was to get connected to resources. Unfortunately, security was often not considered until the business began experiencing data breaches, interception of remote meetings dmwilson on DSKJM0X7X2PROD with HEARINGS and unauthorized disclosure of sensitive information on non-com- pany-owned devices. While cloud and remote computing have in- VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00035 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 32 creased productivity and business capabilities, they have increased the cyberattack terrain. In the last 2 years our team at Murray Security Services per- formed assessments on small and medium-sized businesses in mul- tiple industries and in multiple states across the country. Some of the top issues we have seen, personally, include social engineering people to disclose things like user names and passwords, sensitive product information and personal identifiable information; lack of dedicated IT or cybersecurity resources; uncontrolled access to sen- sitive areas of a building—if I can get physical access, the rest is even easier; sensitive information found in trash cans, dumpsters and in unattended workspaces; computer applications or equipment that are vulnerable to cyber-attacks due to missing patches or misconfigurations. Cybersecurity is primarily about protecting information. Some of the most sensitive information that needs to be protected is privacy information. This means that the relationship between cybersecu- rity and privacy data and information is significant. While the United States has many various privacy laws related to highly reg- ulated industries like banking and finance as well as healthcare, we do not yet have an overarching national privacy law such as the General Data Protection Regulation in the EU. A current bill being considered, since 2019, called the ‘‘Safe Data Act’’ would address many of these areas. Instead, businesses have to navigate the complexity of 50 states’ privacy and cybersecurity laws, which can become overwhelming and very time consuming. The United States provides, as Al mentioned, one of the largest procurements of small business resources. To be considered, busi- nesses now have to comply with cybersecurity hygiene require- ments as identified by FedRamp, the Cybersecurity Maturity Model Certification, as mentioned previously by Mr. Stine, the NIST Spe- cial Pub 800–171 Protecting Controlled Unclassified Information, CUL—another acronym—in nonfederal systems and organizations, as well as other requirements identified in the Federal Acquisition regulation. Small businesses need access to free resources for education and training to understand these requirements. Based on recently passed legislation, SBDCs now require a cybersecurity lead center to support their small business clients to help address cyber issues. SBA should require additional dedicated funding to better develop standardized programs across SBDCs and SCOREs for consistent training and education as well as cyber-related resources to help protect small businesses. An example of this is the America’s SBDC North Star program which represents the overarching efforts of the America’s SBDC network to mitigate cyber threats to small busi- nesses. Dedicated funding would allow consistent cyber program- ming instead of having to chase funding through grant proposals each year. For small businesses, an additional resource to consider is the Center for Internet Security which provides CIS critical security controls and benchmarks for a prioritized set of actions to protect organizations and data from cyberattack vectors. dmwilson on DSKJM0X7X2PROD with HEARINGS For small businesses the three primary areas to focus are secu- rity awareness and skills training, data recovery, and access con- VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00036 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 33 trol management. The National Institute of Standards and Tech- nology provides additional guidance and resources as discussed in Mr. Stine’s testimony. In closing, cyber threats pose a significant challenge to our coun- try, our businesses and to our national security. A disruption to commerce due to threat actors attacking businesses should be con- sidered a serious threat to our economic viability. With the onset of new technological advances such as artificial intelligence and the Internet of Things, there needs to be dedicated resources to edu- cate, train, and advise business owners and leaders on achieving appropriate cybersecurity hygiene to protect their business as well as their information. Again, thank you for this opportunity to testify in front of you today. [The prepared statement of Mr. Murray follows:] dmwilson on DSKJM0X7X2PROD with HEARINGS VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00037 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 34 dmwilson on DSKJM0X7X2PROD with HEARINGS Insert offset folio 64 here 53540.015 VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00038 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 35 dmwilson on DSKJM0X7X2PROD with HEARINGS Insert offset folio 65 here 53540.016 VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00039 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 36 dmwilson on DSKJM0X7X2PROD with HEARINGS Insert offset folio 66 here 53540.017 VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00040 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 37 dmwilson on DSKJM0X7X2PROD with HEARINGS Insert offset folio 67 here 53540.018 VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00041 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 38 Senator HICKENLOOPER. Thank you, Shawn. I appreciate it. I ap- preciate all of you being here. I am so glad I gave you a chance to make your opening comments. So I will repeat my first question that I so inelegantly began with. This is a bipartisan issue. It is going to require a whole-of- government response to make sure that we are able to allow small businesses to preempt the risk of cyberattacks. I appreciate Kevin’s time with us today and all the work that NIST is doing, moved light years in a very short period of time. Just each of you, just to start, what would be the one issue you would recommend we highlight as we work with the executive branch on the Federal Government on ways that small businesses can safeguard their data. Ms. BLISS. Senator, because I am the educator on this panel, al- though you all are educators, we all do this, I think you need to make it a team sport, and we have to think about it longer term and look for very unique, diverse teams to solve not just the cur- rent problems but come up with a way, in that K-to-gray mindset, that we can then bring those students into this conversation so that we are not having people having the problems that we have today. So if we have that baseline across the education system, then as people build their businesses they will build that resiliency in cy- bersecurity in because they will be aware of how to do that. Obvi- ously, resource is a big part of that, and I know you guys will talk to that. But I think the education and training piece of taking a non-tra- ditional approach than we have had in the past with the silos, and this is how education works, or this is how training works, and blending that together, kind of like we are going to do on our grants—we are going to test it out—I think is the way we can move forward to solve the future problems. Because I feel like we are chasing our tails today, but if we look at it bigger term we can solve longer-term problems. Senator HICKENLOOPER. Alfred. Mr. ORTIZ. Senator, so my late father-in-law used to say edu- cation is the great equalizer, and I think the cyberspace is no dif- ferent. I think if we can get these new businesses, these smaller businesses I mentioned before, and be able to educate those folks before they get an SBA loan, or before they take that next step, the same way that they would go get an attorney and an accountant to do their books, they should go take a couple of classes in cyber- security at SBDC with one of us who is a certified-slash-educator in this space, and I think it would really help. We are really on the next generation of where IT and cyber meets. You know, I am aging myself, but those Commodore 64’s and all of those computers are old school, and we are now in that next generation or age. So I think education and certainly funding behind that to get these small businesses going will certainly take us to that next level. Senator HICKENLOOPER. Great. Mr. MURRAY. Senator, thanks. You know, my colleagues here dmwilson on DSKJM0X7X2PROD with HEARINGS have identified a lot of the training and education so I will take a different approach to it, and that is collaboration, collaboration, col- VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00042 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 39 laboration. Here in our own ecosystem there is so much that is going on here in our community, from IT and cyber perspective. We looked at a capability to build a level of collaboration by cre- ating a program called the Cyber Leadership Roundtable. Aikta Marcoulier, who is our Regional Director for SBA, was our SBDC Director at the time. She and I both co-chair that organization. We actually have a charter. We have various goals and objectives to be able to collaborate and achieve different things. The idea here is we do not compete with cyber resources. So if our local chapter for ISSA is running an event, we will not run a different event to compete with it. We will collaborate with them, and we will share the space, and we will send out the message. You know, the example of winning this grant is an example of that collaboration that came out of the Cyber Leadership Round- table, where we now have multiple organizations that can collabo- rate together to get more opportunity to get grants and funding. So state and local resource, look at your ecosystem, understand who the movers and shakers are, commit to be able to collaborate to solve problems. Senator HICKENLOOPER. All right. Well, that collaboration, I could not agree more. More education, more collaboration, those are the two hallmarks. And in a funny way, when this facility was ac- tually put together that idea of having education, universities col- laborating with small businesses and larger businesses, but also working with government was kind of first and foremost in everybody’s mind. And there is nothing stronger, and something that really does set us aside from most of our rivals in the world. Gretchen, why don’t I start with you in terms of the evolving state of the workforce in cybersecurity. As we move towards deploy- ing more and more 5G networks and beyond and further enabling, let’s call it, the Internet of Things everywhere, how is the demand for cybersecurity professionals going to change? How do you keep up with that? Ms. BLISS. That is the million-dollar question. Senator HICKENLOOPER. Who is going to pay me? Ms. BLISS. You know, the issue with this is that when you think about education systems, a lot of times I use history as an example. My mom is a history professor. You know, the battles happened on a certain day and you get to learn that, and you get to put it in context. But in cybersecurity it changes every single day, and so that demand is that currency. We have to increase not only the numbers, we have to increase the diversity that we have in cyber- security. We have to diversify the experience. You know, as my example of all the programs across all the interdisciplinaries we have, plus the training and education piece that we do, I feel that we really have to be able to respond to the evolution of the threat, and that is something that we do chase our tails on. And if there is a way that we could tweak the education system so that it can be more dynamic and interactive, with indus- try, with government, again, that kind of team sport, if we can ap- proach it that way, I think what is going to happen is that the pro- fessionals need to be that adaptable. They need to be able to move dmwilson on DSKJM0X7X2PROD with HEARINGS into different areas and not get stuck in stovepipes, which edu- cation tends to do. VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00043 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 40 But that hands-on experience piece that we get from our part- ners I think broadens that, so those students, those employees, that workforce can be a little more dynamic and respond in dif- ferent industry sectors and create some sort of commonality be- tween them. Senator HICKENLOOPER. And in that evolving world of education, that assumes, I guess, a constantly changing and improving and more essential group of foundational concepts and applications that people have to learn, just to begin their journey. Ms. BLISS. Absolutely. The thing I always say is it is a purple unicorn. You guys have heard me say this a lot. You have got to get a degree of some sort, you have got to get hands-on experience, and you have to get an industry credential, and educational pro- grams do not necessarily wrap themselves around those three ideas. So I feel like through the CAE program we are embracing that diversity to try and build programs that can be that dynamic and responsive. Senator HICKENLOOPER. I agree. We sometimes lose track in the race for education that there is supposed to be a good job and a career attached to that. Mr. Ortiz—I am going to call you Alfred, first thing. I have known Gretchen now. We are not a Washington—— Mr. ORTIZ. This is Colorado. Senator HICKENLOOPER. Yeah, exactly. Alfred, we are going to take off our ties, you know. Mr. ORTIZ. Where is that beer? Senator HICKENLOOPER. Cyber insurance can help businesses re- spond to and recover from cyber incidents if they do occur. Our In- sure Cybersecurity Act, which is a bill we worked on last year with Senator Capito from West Virginia, offers, or will someday offer clear information to businesses to businesses on how cyber insur- ance works and how it can make their business more cyber resil- ient. How should small businesses evaluate cyber insurance, and is there some benefit to clear and simple information that helps them make better informed decisions? Mr. ORTIZ. I think that it is a little bit tough in some instances with regard to the types of business you get into. So for example, if you have a small medical firm that is worried about HIPAA com- pliance and things of that nature the risk may be higher than if it were to be, let’s say, automotive repair shop, like my father used to have. Where is that data? What type of risk is out there? And how much is that risk going to cost the owner of that company? To the point that I think depending on the industry, whether it be NAIC codes that you could use to be able to say this particular code would say that this business has this level of risk, in general, may help with regard to appropriately getting the right amount of cyber insurance. So that could be a possible way to tie in the risk with the type of business vertical that you are looking at. Obviously, the more, the better, but because of the amount of cyberattacks, that insurance amount may be going up as well. dmwilson on DSKJM0X7X2PROD with HEARINGS Senator HICKENLOOPER. Yeah, and I think we talked about a lit- tle of this with Kevin, you know, having the right language so that VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00044 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 41 people understand these risks and maybe some of the increments as we become better able to understand them ourselves, would have value as well. Mr. MURRAY. Senator, if I may add to that, the complexity of cyber insurance has grown significantly over just the last 5 years. It does not matter what size your business is. You know, initially when cyber insurance came out the underwriters were going like, ‘‘Cyber insurance? Free money,’’ and then all of a sudden we start- ed making claims and breaches, and the costs associated with those highly regulated industries, as Al mentioned. Now, cybersecurity underwriters are putting in amount of rigor in your policy that says you will have antivirus, you will have an assessment, you will protect sensitive information or data, and if you do not, we are not going to pay the breach, to a point where you may have to have an assessment hired by the insurance com- pany after a breach happens, and if they can prove that you did not do what you were supposed to, your due diligence, they are not going to pay anymore. Senator HICKENLOOPER. All right. It is a little bit like the issues we face, different states face around insurance for wildfires. With climate change and deeper droughts all over the country we see greater risk, and the insurance companies are still trying to catch up. You cannot have wooden roofs. You cannot have scrub grass coming up to the side of your house, wooden decks, all those things that invite a fire. I think the same thing is true in cyber, right? Mr. MURRAY. Right. It is evolving. Senator HICKENLOOPER. Yeah. And the rate of change, and we were talking about this earlier when we were—our green room was not really green, but when we were talking beforehand—the rate of change is only accelerating, and I think that is going to really require the universities, the private sector, and government to real- ly step and make sure that we can keep up so that small busi- nesses do not get wiped away. I thought some of the statistics, Shawn, that you gave of once you are breached what the possibility is that you end up out of business in a year was truly startling, and something certainly the SBA should be pushing out there. Gretchen, small businesses—Shawn, you helped with the pre- vious question so you almost lost your own question—small busi- nesses owners are in industries often with comparatively less expo- sure to cyber threats. I am not aware of a brewpub that has been hacked yet. They are often focused on other priorities—building your sales, creating the team, running your business. In your experience of cybersecurity training how aware would you say, on the broad arc of small business owners, how aware of they in various industries of digital threats and of the cost-effective strategies to be ready? Mr. MURRAY. So it is a great question. I think all small busi- nesses, whether it is Al’s dad’s automotive mechanic shop or it is the food truck or a hospitality organization, or a highly regulated industry, a small clinic, insurance company, my accountant, every- one is aware of the cyber threats these days. Certain world events dmwilson on DSKJM0X7X2PROD with HEARINGS like the invasion of Ukraine with Russia and all of a sudden there is a significance in how is Russia going to fund what it needs to VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00045 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 42 do. Well, ransomware, we still know, is one of the most significant areas where we have a lot of attacks, so we need to be aware of that. Small businesses were afraid of what was going to happen during that time frame. So literally, a partnership with our SBDC, we came up with a white paper to pass out to all of our small business clients to edu- cate them on what they could be doing and should be doing, and that is focusing on understanding what your critical assets are within your organization, understand what critical processes that you have. We had an electric company that they had one person that did payroll for a 54-person company. That person got in a car accident and was in a coma for 3 or 4 days. Nobody else knew how to do payroll. So because that critical process was not understood, and they did not have that backup person, they hired us to come in, try and hack into the payroll system—well, you have an IT person, we can get it there, but where is it documented how they do payroll? So luckily she came out in a few days and they were able to fig- ure that out. In the meantime, we advised the client, go ahead and run the same payroll that you did, contact your bank, run the same payroll as you did last time. You will have to figure out who has got overtime, on vacation. But again, understanding the critical as- sets, those critical processes, understanding how to back those areas up. And then the threat of that cyberattack, when we talk about the cyber threat itself, in educating, this is where the SBDCs come in. So that Cyber CYA program, Cover Your Assets, that program and its initial pilot allowed us to educate a select of about eight dif- ferent businesses, where they got to participate in understanding their own business. We helped them identify their critical proc- esses, their critical assets, and they had to develop a plan at the end. We actually did an assessment with them. At the end they had to come up with a plan. And a partnership that we had with the Better Business Bureau stated if you actually execute your plan and you are a BBB mem- ber, we will give you a Cyber Badge of Honor on your BBB profile that says, ‘‘Hey, I am a business that is dedicated to protecting your information as well as mine.’’ So those innovative programs to educate and train, outside of regular academia, I think are important. Senator HICKENLOOPER. And so you guys chime in. Since we are not in Washington we can have a free-form discussion. Just do not tell anyone. Where would people find out about these kinds of programs? Ob- viously you must have outreach through the SBA, SBDCs, and what have you, but also through your organization. How would the normal small business come across this if they were not connected to the SBA? Mr. MURRAY. So it just comes about communities and resources. I think a lot of businesses during the pandemic came out because they were struggling. Where can I get resources, resources for training, you know, the Pikes Peak Workforce Center here in our dmwilson on DSKJM0X7X2PROD with HEARINGS community. I was advising my clients, there is all kinds of funding coming out of the current Administration providing upskilling for VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00046 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 43 just about any type of positions. But then I volunteered at my local Workforce Center board, and I learned so much about workforce and the things that help your community interact, and used those resources to educate the businesses that I was doing business with. So one of the challenges—Tracy Marquez is the CEO of our Workforce Center. She is only allowed 10 percent for marketing for all of the programs that she puts out there. We have got to be able to release some of the restrictions on allowing us to educate the community about what resources are available. The same restrictions apply to the SBDCs and some of the other programs. So the ability to allow us to market and get that word out would be a lot more advantageous. Senator HICKENLOOPER. And again, when Kevin was talking about creating a language, that marketing, in a way, educates ev- erybody and helps universalize that language. Let me move on. Gretchen, small businesses, just the nature that they are small they already face stiff competition, whatever indus- try they are in, but this is especially true in those companies that do Federal contracting, and they are always against larger busi- nesses. Usually the deck is stacked against them. The larger busi- nesses have far more resources. What can the SBA do to support small businesses so they have a strong cybersecurity posture and are positioned to secure con- tracts with the Federal Government? Ms. BLISS. Well, I think a lot of it, I was particularly impressed with the way that the President’s training and education strategy came out and talked about how you do not need to be alone and unafraid in this process. We need to build a coalition. We need to build those public-private partnerships. We need to build those con- versations on education and training. And I feel like in an eco- system where you have got all of those elements actively engaged you can create some wraparound and support for those small busi- nesses to do those things. Because I believe the way the process is, too, between primes and subs, I think there is a really good con- versation to have there where the primes can educate the subs and have it be part of their responsibility to protect—you go back to supply chain, you talked about supply chain. And I also think the stuff that NIST is doing with the working group is a big part of getting that conversation and having them understand better the common vocabulary, the common language, and to create an understand. In education it is all about under- standing, and I feel like all those efforts to educate in different ways, because not every student learns the same way, we create ten pathways for people to get to the same information just so they can get there and be able to use it in an active way to help support their company, to help be an active workforce member, or to help build the economy or a government entity. So I feel like if we could do those things I think that is where the small businesses would then be able to compete on par with companies and partnered with companies to be able to win those government contracts. dmwilson on DSKJM0X7X2PROD with HEARINGS Senator HICKENLOOPER. All right. And I think streamlining those requirements obviously is a big part of this in every way. VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00047 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 44 Alfred, NIST, SBA, all these agencies are working hard to try and help small businesses secure their data, but obviously the gov- ernment cannot do this on its own. We have limited resources and the great American public wants to have this happen on a more universal scale. How can we expand public-private partnerships in such a way that allows small businesses to get better cybersecurity protection? Mr. ORTIZ. Well, I think there are a number of different ways, and something that Mr. Stine and I were talking about earlier was with respect to seeing how different states are handling it. If we look at some of the privacy requirements there is one for Colorado, there is one for California, Virginia, and other states. So if we were to move our business or to start up a business somewhere else, how would it be different with regard to some of those data require- ments in different states? How do we make it so that it is some- what universal, that there is some baseline, if you will, with regard to some of these frameworks that we are looking for, and in various areas? So I think from a legislative standpoint, the European Union, for example, handles those GDPR privacy requirements, whereas in the United States we may enjoy our state independence from the Federal Government, but from a cyber perspective it may look a lit- tle bit different. So looking at that, being able to get the word out. One of the things that I saw was something very important was last year, I believe it was March 22, where I was invited by the White House to speak at Denver Community College to entrepreneurs for the White House Economic Initiative. Some of those businesses that they saw did not realize PCR requirements with regard to pay- ments, how important that data was. So we educated them a little bit on that. Their eyes did open quite big when they heard some of those. And just the basics to be able to go out there and say, hey, this is the effort. It is affecting everybody, from the smallest player that maybe has a sub with a contract, we have already seen that it af- fects all of the bigger players as well, going back to Gretchen’s point. And I will say it because it is a public case study, is the F– 35 fighter jet. All the way from the bold step, the small tier three supply chain manufacturer got hacked because they did not have cybersecurity, went up to tier two, and then the main supplier. And now our adversaries have a copy of that in their back yard. So it affects everybody. Senator HICKENLOOPER. Yeah, no, absolutely, and I think that vulnerability up and down the supply chain is something that peo- ple are just coming to grips with. I hear all the time from small businesses that just of the simple protections, like dual authentication, you know, to make sure that people, when they sign on, log in, that they are taking some mini- mal, slightly inconvenient, but people are so used to their cellphones, their handheld devices, that they do not think they need that security, and obviously, you could not be further mis- taken. dmwilson on DSKJM0X7X2PROD with HEARINGS Shawn, many small businesses lack resources as the largest busi- nesses to invest in these protections. Do you think there are incen- VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00048 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 45 tives that Congress should be considering, and what kind of incen- tives should we be considering to help small businesses make these early investments, within the recognition that obviously this has got to be something that is sustainable. In other words, this budget is going to be tighter than last year. I think next year’s budget is going to be tighter than this year. We have to find ways of achiev- ing this with minimal cost impact. Mr. MURRAY. So great question. You know, we could go a thou- sand different directions on this, but I have got an example. Here is one that is near and dear, especially in this community, being a big government contractor, defense industrial base community. The CMMC is a great example, the Community Maturity Model Certification. The initial release of CMMC was so rigorous and so significant that I heard complaints from small businesses that were already doing business with the government, stating, ‘‘Wow, I have got to invest in all of this cybersecurity and these programs, and I have got to get a certification, and I have got to understand all these controls, and I just build bolts that go on an aircraft that part of that supply chain, and there is risk associated with that. And now I have to do this to get the contract back again. So how do I justify the expense of all of this money, because all of the vendors, they jump onto whatever the latest and greatest technology is, they scare everybody, charge boatloads of money for it, and small busi- nesses cannot sustain.’’ I helped two congressional members with an update to the Na- tional Defense Authorization Act, and we got an amendment passed that required a complete review of the CMMC, which then released CMMC 2.0, which addressed a lot of the small business concerns. There is now a platform that takes the NIST 800–171, Controlled Unclassified Information, and there are three tiers that focus just on one NIST artifact as opposed to ten different sources that are complex. There is a free website now where you can log into and start filling out everything that you need. There are vid- eos educating you why you need to be doing what you are doing. And instead of five complex tiers you only have three now. And the program now is looked at so well that we are not looking at it just for DoD anymore. We are looking at it for the entire Federal Gov- ernment, consistency. So that is an example that I would suggest you take back to your team and consider other legislation that makes things like the SBDs, the SCOREs, or the other resources that are being funneled into programs that allow consistency across the Federal acquisition regulation, because the FAR is just so complex and it takes too long to get approved. Senator HICKENLOOPER. All right. So the idea is that you would get through that initial investment and that would carry you every- where. Mr. MURRAY. Correct. Now you still have to do your due diligence and keep that up. But the initial expense up front, with no guar- antee that you are going to get something in the end, that is where small businesses are concerned. dmwilson on DSKJM0X7X2PROD with HEARINGS Senator HICKENLOOPER. Yeah, and I cannot blame them. No guarantee that they are going to get back that contract. There is VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00049 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 46 no guarantee that the investment will hold up. And from a number of people I have heard that they worry that they make those in- vestments, and within 2 years there is a whole new set that they have got to come back with, and they have barely gotten their man- ufacturing line in place. We are about out of time here. I am amazed I have not gotten the boot yet. But I am going to keep talking until they tell me to stop. One of the things I was interested in, a couple of talked about whether there should be some sort of a boot camp for cybersecurity, that the Federal Government should help put together. How do you all think about that? I mean, it is obviously very difficult, for all the reasons you just described, to do something that was suffi- ciently meaningful to make it worth the investment of a small busi- ness owner’s time and resources. But there is something also ap- pealing about having something like that, that once you had cre- ated it, would allow people to feel confident that what they are in- vesting in, it would have some sort of stamp of approval. Mr. MURRAY. So I want to make sure I clarify before I respond. Are we talking about a boot camp for Congress? [Laughter.] Senator HICKENLOOPER. There already is. It is called elections. Mr. MURRAY. Right. Constituents and how we are getting that funding. It is twofold. I would love to be able to share some of the stories that are absolutely real, and when you tell the story it really brings it home as to, wow, we have that same vulnerability, or we have that same issue, and that could be me, whereas, you know, going to academia and reading stuff, and this is an IP address, and this is how things communicate. But going out and understanding what that terrain looks like, and listening to other people’s stories and how relevant it is, I think that is where it is going to bring it home. I think that is more meaningful—tell a story. Mr. ORTIZ. I think from that standpoint there are a number of ways. I always look at maybe some of the smaller towns that have small businesses but do not have access to the NCCs of the world or UCCSs of the world and making it a point where even students could go, instead of taking a biology class they can say, ‘‘I can take a cyber class for my science class, and I can learn about this stuff and get exposed to it.’’ So that is one way to be able to get it out to some of the smaller areas. And being able to have a road show, if you will, of these kinds of things, where small businesses can come into their local SBDC or Chamber of Commerce and listen to somebody talk, at least on those first things, as you mentioned, Senator, multifactor authentication, VPN, and the basics of pass- words and so forth. Senator HICKENLOOPER. All right. Gretchen. Ms. BLISS. Yeah. The boot camp concept is very effective because it is time effective, it is depth and content effective, and it estab- lishes that common understanding of vocabulary. And that goes back to Shawn’s comments about consistency. I did a research project once and looked at the 47 definitions that the government uses for cybersecurity. It is confusing. So if we can dmwilson on DSKJM0X7X2PROD with HEARINGS use something like that to create that common understanding and baseline I think it will help everyone to be successful and be able VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00050 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 47 to have that conversation. Because once you establish that baseline then you can respond in kind, into whatever industry, and things can be industry-unique. We have constantly talked about having a level of certification, like a bar for a lawyer, right. Do we have something like that in cybersecurity? Are we getting there? What does that look like? You know, IEEE has the stuff that they do with their standards, and they have put cybersecurity in it as well. So I feel like there are efforts out there, but they are not nec- essarily consolidated and consistent so that they can be accessible by everyone. Senator HICKENLOOPER. That is a little bit like the Field of Dreams as well—if you build it, will they really come? I always worry that as effective as the Small Business Administration has been and the SBDCs, there are so many small businesses that are working so hard that they are not in the Chamber of Commerce. My small business, I never joined the Chamber of Commerce. I was in business for 15 years before I decided I was going to run for mayor of Denver. But if you are really immersed in your small business, sometimes you are not in a place where you can see that, and I think a boot camp is the kind of thing that might actually bring people to the table that are not members anywhere, and I think that is a real issue. Anyway, closing thoughts, any of you? I think we have probably taken a lot of your time, too much of your time. Ms. BLISS. Not at all, sir. I just want to say thank you for your interest in this topic. As you know, cybersecurity is very broad, it is very deep, and sometimes we are all in a room talking about it and it is like touching the elephant. So I feel like efforts like this, and hearings like this help to broaden that context of conversation and understanding, and I appreciate you bringing it to Colorado Springs, because I feel like we have a very unique ecosystem here that we have been developing to have exactly the conversations that you are talking about. And we have kind of piloted some things, and we are going to keep doing that until we feel like we are getting it right. So I really appreciate that, and just understand that the partner- ship here is going to continue to expand and build on the baseline that you have basically gotten in place with this effort over the last 10 years. So I really appreciate that. Mr. ORTIZ. Senator, thank you for having us. I echo Gretchen’s sentiments wholeheartedly. I think what we have got to do is col- laborate with what Shawn was saying, come together, be able to put this first and foremost, as Americans, an all-partisan issue, as I had mentioned before, and put it out there so that we can all learn a little bit about cyber, so we can just keep our data safe, ei- ther as a business or personally, so we can be out there. And I think there are a number of folks that understand that, and we can all be neophytes to the message around cyber. Mr. MURRAY. Thank you again, Senator and the Committee, for allowing us to come up and provide some testimony to be consid- dmwilson on DSKJM0X7X2PROD with HEARINGS ered as you move back and make decisions. Remember that cyber- security is about protecting information. It is a national security VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00051 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68 48 issue, it is an economic issue, and both of them are tied together. We need to be able to protect the viability of our small businesses. I cannot say any more. This has been a great venue. I appreciate you hosting us and allowing us to testify in front of you today. Senator HICKENLOOPER. Thank you all, and I think a lot of the foundations that you led and that we heard from NIST and Kevin describing the importance of education and collaboration and cre- ating this new language and getting the word out there. It does need to be just—several of you, or almost all of you, I think, at one time or another mentioned it, the analogy between accountants and your doctor or your attorney. You know, I am from the school that actually believes you should not have to have your attorney on speed dial. I would like to get back to the time when you do not have so many rules and regula- tions. But I think within cybersecurity I think that is something that we are going to need. I probably just offended 200 lawyers. But the ability of our culture, our country, to really address this and make sure that everybody understands it somewhat in the way that everyone drives—if you go out on the roads, most people know ‘‘somewhat’’ how to drive a car. Sometimes we wonder. But that awareness and that understanding of the basic prin- ciples has to expand. It has to get out there a lot faster. And you all being here and the work that you are doing every day is helping lead this country in that effort. As a Senator I get to say on behalf of our country thank you for your help today and all your public service. Now to conclude our hearing for today I would like to again, one last time, thank each of our witnesses for their testimony. I do hate calling you ‘‘witnesses’’ because it does imply a crime, which in this particular case I am not aware. There are many crimes around cy- bersecurity. I am not sure which one we are addressing. We will keep the hearing record open for questions for 2 weeks, until August 28, 2023. We ask that witnesses submit their re- sponses to those questions. As they come in we will get them to you and get us your responses by September 11, 2023. With that this hearing is adjourned. [Whereupon, at 4:02 p.m., the hearing was adjourned.] dmwilson on DSKJM0X7X2PROD with HEARINGS VerDate Sep 11 2014 02:11 Mar 18, 2024 Jkt 053540 PO 00000 Frm 00052 Fmt 6633 Sfmt 6602 E:\HR\OC\B540A.XXX PFRM68