Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Cisa Programs And Partnerships topic

No spam. Unsubscribe anytime.

CISA director details programs, partnerships and defenses in committee testimony

3241266 · May 8, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

CISA's senior official testified to the Appropriations subcommittee about the agency's operational work — including the known exploited vulnerability catalog, attack surface management, JCDC partnerships, regional advisers, and support for state, local and small-business cybersecurity — citing metrics on courses, assessments, and mitigations.

Bridget Bean, senior official performing the duties of the director of the Cybersecurity and Infrastructure Security Agency, told the House Appropriations subcommittee that CISA continues to expand operational support and partnerships to defend federal and critical infrastructure networks.

Bean said the agency has delivered operational products with partners including the FBI and NSA, provided more than 269 terrorism-mitigation courses to over 5,000 participants, conducted 68 exercises, completed 9,400 cyber and physical assessments and trainings for state, local and critical infrastructure owners, and issued more than 4,000 early-stage ransomware notifications. "We've expanded CISA's known exploited vulnerability catalog to over 1,300 vulnerabilities," she said, and described measurable reductions in risk for partners who use agency services.

Members questioned how programs such as attack surface management fit into CISA's core capabilities. Bean called attack surface management "one of our core capabilities" and said it is a scalable program that looks "from the outside in" to identify and help partners remediate exposed vulnerabilities before adversaries can exploit them.

Committee members and Bean discussed public-private partnership efforts, including the Joint Cyber Defense Collaborative (JCDC), and the agency's regional delivery model in which security advisers are embedded across states and territories to provide in-person assistance. Bean said that trusted relationships are critical to sharing threat information across sectors and with international partners. "Everything we do is through trusted, established relationships," she said of CISA's partnership model.

Members also asked about sector-specific work: Bean said CISA coordinates with the Department of Energy, sector risk management agencies and private-sector oil and gas firms to identify threats, share intelligence, and encourage contingency planning to limit cascading impacts. On universities and workforce development, Bean said CISA works with higher-education institutions to strengthen cyber curricula, recruit future defenders and exchange defensive research and practices.

Bean and members emphasized practical steps for smaller organizations and businesses: sign up for CISA services such as cyber hygiene scanning, connect with regional security advisers, patch known vulnerabilities, and prioritize secure-by-design procurement. She said CISA's field staff and partnerships enable scalable delivery of those services to states, localities and small businesses.

No formal policy changes were adopted during the hearing; members asked for follow-up materials on program metrics and for the agency to provide requested budget and reprogramming details.