[House Hearing, 119 Congress]
[From the U.S. Government Publishing Office]
OVERSIGHT OF THE DEPARTMENT OF HOMELAND
SECURITY: CISA, TSA, S&T
=======================================================================
HEARING
before the
COMMITTEE ON HOMELAND SECURITY
HOUSE OF REPRESENTATIVES
ONE HUNDRED NINETEENTH CONGRESS
SECOND SESSION
__________
JANUARY 21, 2026
__________
Serial No. 119-35
__________
Printed for the use of the Committee on Homeland Security
[GRAPHIC NOT AVAILABLE IN TIFF FORMAT]
Available via the World Wide Web: http://www.govinfo.gov
______
U.S. GOVERNMENT PUBLISHING OFFICE
63-557 WASHINGTON : 2026
COMMITTEE ON HOMELAND SECURITY
Andrew R. Garbarino, New York, Chairman
Michael T. McCaul, Texas, Vice Bennie G. Thompson, Mississippi,
Chair Ranking Member
Michael Guest, Mississippi Eric Swalwell, California
Carlos A. Gimenez, Florida J. Luis Correa, California
August Pfluger, Texas Shri Thanedar, Michigan
Tony Gonzales, Texas Seth Magaziner, Rhode Island
Morgan Luttrell, Texas Daniel S. Goldman, New York
Dale W. Strong, Alabama Delia C. Ramirez, Illinois
Josh Brecheen, Oklahoma Timothy M. Kennedy, New York
Elijah Crane, Arizona LaMonica McIver, New Jersey
Andrew Ogles, Tennessee Julie Johnson, Texas, Vice Ranking
Sheri Biggs, South Carolina Member
Gabe Evans, Colorado Pablo Jose Hernandez, Puerto Rico
Ryan Mackenzie, Pennsylvania Nellie Pou, New Jersey
Brad Knott, North Carolina James R. Walkinshaw, Virginia
Vince Fong, California Troy A. Carter, Louisiana
Matt Van Epps, Tennessee Al Green, Texas
Vacant
Keighle Joyce, Staff Director
Hope Goins, Minority Staff Director
Sean Corcoran, Chief Clerk
C O N T E N T S
----------
Page
Statements
Honorable Andrew R. Garbarino, a Representative in Congress From
the State of New York, and Chairman, Committee on Homeland
Security:
Oral Statement................................................. 1
Prepared Statement............................................. 3
Honorable Bennie G. Thompson, a Representative in Congress From
the State of Mississippi, and Ranking Member, Committee on
Homeland Security:
Oral Statement................................................. 4
Prepared Statement............................................. 10
Witnesses
Hon. Pedro M. Allende, Under Secretary, Science & Technology
Directorate (S&T):
Oral Statement................................................. 12
Prepared Statement............................................. 13
Mr. Madhu Gottumukkala, Ph.D., Acting Director, Cybersecurity and
Infrastructure Security Agency (CISA):
Oral Statement................................................. 14
Prepared Statement............................................. 16
Ms. Ha Nguyen McNeill, Senior Official Performing the Duties of
the Administrator, Transportation Security Administration
(TSA):
Oral Statement................................................. 18
Prepared Statement............................................. 19
For the Record
Honorable Bennie G. Thompson, a Representative in Congress From
the State of Mississippi, and Ranking Member, Committee on
Homeland Security:
Letter, January 14, 2026....................................... 6
Letter, January 21, 2026....................................... 8
Chart.......................................................... 62
Article, Mother Jones.......................................... 63
Article, Bloomberg............................................. 67
Appendix I
Questions From Chairman Andrew R. Garbarino For Pedro M. Allende. 71
Questions From Honorable Timothy M. Kennedy for Pedro M. Allende. 72
Questions From Chairman Andrew R. Garbarino for Madhu
Gottumukkala................................................... 74
Questions From Honorable August Pfluger For Madhu Gottumukkala... 80
Question From Honorable Matt Van Epps For Madhu Gottumukkala..... 82
Questions From Chairman Andrew R. Garbarino For Ha Nguyen McNeill 82
Questions From Honorable Ryan Mackenzie For Ha Nguyen McNeill.... 88
Questions From Honorable Dale Strong For Ha Nguyen McNeill....... 89
Questions From Honorable Vince Fong For Ha Nguyen McNeill........ 90
Questions From Honorable Matt Van Epps For Ha Nguyen McNeill..... 91
Questions From Honorable Timothy M. Kennedy for Ha Nguyen McNeill 93
Questions From Honorable Troy Carter for Ha Nguyen McNeill....... 94
OVERSIGHT OF THE DEPARTMENT OF HOMELAND
SECURITY: CISA, TSA, S&T
----------
Wednesday, January 21, 2026
U.S. House of Representatives,
Committee on Homeland Security,
Washington, DC.
The committee met, pursuant to notice, at 10:06 a.m., in
room 320, Cannon House Office Building, Hon. Andrew Garbarino
(Chairman of the committee) presiding.
Present: Representatives Garbarino, McCaul, Guest, Gimenez,
Gonzales, Luttrell, Strong, Brecheen, Crane, Ogles, Biggs,
Mackenzie, Fong, Epps, Thompson, Correa, Thanedar, Magaziner,
Goldman, Ramirez, Kennedy, McIver, Pou, Walkinshaw, and Green.
Chairman Garbarino. The Committee on Homeland Security will
come to order. Without objection, the Chair may declare a
committee in recess at any point. The purpose of today's
hearing is to conduct oversight of the Department of Homeland
Security and assess priorities for calendar year 2026 for the
Cybersecurity and Infrastructure Security, Transportation
Security Administration, and Science and Technology
Directorate.
The Chair reminds all Members that the Chair will enforce
the rules of decorum at all times and urges all Members to be
mindful of their remarks. I now recognize myself for an opening
statement.
Good morning, and thank you to our witnesses for being
here. Today, we are conducting oversight of the Department of
Homeland Security focusing on TSA, CISA, and the Science and
Technology Directorate, otherwise known as S&T.
Nearly 25 years ago, 19 hijackers exploited significant
vulnerabilities in our commercial aviation system. The al-Qaeda
terrorist attack on September 11, 2001, killed nearly 3,000
Americans and changed our Nation forever. Our transportation
system, among other critical systems, demanded accountability
and hardened security to ensure a horrific event would never
happen again. In response, Congress enacted the Aviation and
Transportation Security Act to establish TSA and grant DHS
flexible operational authority, allowing it to prepare for and
respond to an ever-evolving threat landscape.
Over the past two decades, threats facing our Nation's
aviation, transportation, and critical infrastructure have only
risen. Today's risks are for more diverse, complex, and
technologically advanced, and the motivations and methods of
our adversaries have shifted rapidly with emerging
technologies. Threats posed by lone-wolf actors, radicalized
individuals, and home-grown extremists have only increased.
Transnational criminal organizations pose a significant threat
by exploiting the transportation system to traffick humans,
drugs, weapons, and illicit goods.
Traditional terror tactics have given way to more
sophisticated methods of attack. Cybersecurity is now at the
forefront of these conversations with adversaries attempting to
take down our transportational systems through digital means.
Similarly, the potential for coordinated tax using drones to
disrupt flights or deliver explosives, represent the new and
growing frontier of security threats.
Sophisticated foreign adversaries, including the People's
Republic of China, Russia, Iran, and North Korea are actively
targeting our digital system, systems that underpin essential
services, economic activity, and national security. These
state-directed campaigns are designed to position hostile
actors with strategic disruption and coercion. Rapid advances
in emerging technologies, including AI, are further
accelerating the scale, speed, and sophistication of these
cybersecurity operations.
In cyber space, the United States is operating in a highly-
contested environment. Congress created CISA to serve as the
Nation's lead civilian cyber defense agency to meet this
reality. CISA's responsibilities included securing Federal
civilian networks, supporting owners and operators of critical
infrastructure, and coordinating with the private sector to
reduce systemic cyber risk. That mission has grown more
consequential as adversaries become more capable, patient, and
willing to operate inside U.S. networks for extended periods of
time.
CISA's authorities extend across a variety of sectors,
including energy, water, communications, health care,
transportation, and financial services. This committee has been
clear about CISA, CISA's expectations. It is not a policy,
think tank, nor a messaging agency. Its mandate is operational.
When that mandate is carried out with discipline and focus, the
agency earns bipartisan support in Congress and confidence from
the industry. When it does not, that confidence erodes.
Over the past year, CISA has faced real operational
challenges. Those challenges include rapidly-evolving threat
landscape, the scope of the agency's responsibility in an
increasingly digital world, and organizational adjustments. As
with any agency responsible for our national security, it is
critical these changes do not degrade readiness,
responsiveness, or mission delivery.
This committee supports the administration's global
aligning of Department resources toward urgent Homeland
Security priorities. At the same time, work force continuity,
clear leadership, and mission readiness are essential to
effective cyber defenses. Professionals at CISA are some of the
most experienced cybersecurity experts in the Federal
Government. Preserving that expertise must remain a priority.
We are encouraged by the President's decision to renominate
Mr. Sean Plankey as director of CISA. Mr. Plankey is a
respected national security professional with decades of
experience. His confirmation provides long-needed stability and
strategic direction at CISA, which has operated without it for
far too long. This committee's oversight of CISA is granted in
respect for its mission and confidence in its work force.
Last, several major high-profile events are set to unfold
across the United States, including the 2026 FIFA World Cup,
America 250, and the 2028 L.A. Olympics. These events will only
increase the volume and complexity of threats facing the
homeland, and DHS must be prepared to respond.
The Trump administration, to its credit, has taken strong
steps to prioritize, strengthen our Nation's security systems.
However, modernization of TSA, CISA, and S&T will require
sustained Congressional support. As Chairman of the Homeland
Security Committee, it's my priority to ensure we support and
invest in the next generation of technologies, and adopt highly
innovative and effective security approaches given the
challenges facing the Department and our country.
This hearing provides an important opportunity to assess
how TSA, CISA, and S&T are carrying out their missions. We look
forward to hearing from our witnesses and engaging in
constructive dialog about how Congress can effectively support
security, operational excellence, and accountability across the
Department.
I also want to take this opportunity to thank our DHS
personnel who keep us safe every day, including our dedicated
cybersecurity professionals, our innovative researchers and
scientists, and our brave TSA security officers who work on the
front lines to protect the traveling public, and who continue
to do so even without pay during the Nation's longest shutdown
last year.
I'm confident that by working together, we can break
through the challenges of today and prepare for threats of
tomorrow. The stakes for the American people cannot be higher.
[The statement of Chairman Garbarino follows:]
Statement of Chairman Andrew Garbarino
January 21, 2026
Good morning and thank you to our witnesses for being here today.
We are conducting oversight of the Department of Homeland Security
focusing on TSA, CISA, and the Science and Technology Directorate,
otherwise known as S&T.
Nearly 25 years ago, 19 hijackers exploited significant
vulnerabilities in our commercial aviation system. The al-Qaeda
terrorist attack on September 11, 2001 killed nearly 3,000 Americans
and changed our Nation forever. Our transportation system, among other
critical systems, demanded accountability and hardened security to
ensure a horrific event would never happen again. In response, Congress
enacted the Aviation and Transportation Security Act to establish TSA
and grant DHS flexible operational authority, allowing it to prepare
for and respond to an ever-evolving threat landscape.
Over the past 2 decades, threats facing our Nation's aviation,
transportation, and critical infrastructure have only risen. Today's
risks are far more diverse, complex, and technologically advanced. And
the motivations and methods of our adversaries have shifted rapidly
with emerging technologies. Threats posed by lone-wolf actors,
radicalized individuals, and home-grown extremists have only increased.
Transnational criminal organizations pose a significant threat by
exploiting the transportation system to traffic humans, drugs, weapons,
and illicit goods.
Traditional terror tactics have given way to more sophisticated
methods of attack. Cybersecurity is now at the forefront of these
conversations with adversaries attempting to take down our
transportational systems through digital means. Similarly, the
potential for coordinated attacks using drones to disrupt flights or
deliver explosives represents a new and growing frontier of security
threats.
Sophisticated foreign adversaries, including the People's Republic
of China, Russia, Iran, and North Korea, are actively targeting our
digital system. Systems that underpin essential services, economic
activity, and national security.
These state-directed campaigns are designed to position hostile
actors for strategic disruption and coercion. Rapid advances in
emerging technologies, including AI, are further accelerating the
scale, speed, and sophistication of these cyber operations. In cyber
space, the United States is operating in a highly contestant
environment. Congress created CISA to serve as the Nation's lead
civilian cyber defense agency to meet this reality. CISA's
responsibilities included securing Federal civilian networks,
supporting owners and operators of critical infrastructure, and
coordinating with the private sector to reduce cyber systemic cyber
risk. That mission has grown more consequential as adversaries become
more capable, patient, and willing to operate inside U.S. networks for
extended periods of time. CISA's authorities extend across a variety of
sectors including energy, water, communications, health care,
transportation, and financial services.
This committee has been clear about CISA's expectations. It is not
a policy think tank nor messaging agency. Its mandate is operational.
When that mandate is carried out with discipline and focus, the agency
earns bipartisan support in Congress and confidence from the industry.
When it does not, that confidence erodes. Over the past year, CISA has
faced real operational challenges. Those challenges include a rapidly-
evolving threat landscape, the scope of the agency's responsibility in
an increasingly digital world, and organizational adjustments.
As with any agency responsible for our national security, it is
critical these changes do not degrade readiness, responsiveness, or
mission delivery.
This committee supports the administration's goal of aligning
Department resources toward urgent homeland security priorities. At the
same time, workforce community continuity, clear leadership, and
mission readiness are essential to effective cyber defenses.
Professionals at CISA are some of the most experienced cybersecurity
experts in the Federal Government and preserving that expertise must
remain a priority. We are encouraged by the President's decision to
renominate Mr. Sean Plankey as director of CISA. Mr. Plankey is a
respected national security professional with decades of experience.
His confirmation will provide long-needed stability and strategic
direction at CISA, which has operated without it for far too long. This
committee's oversight of CISA is grounded in respect for its mission
and confidence in its workforce.
Last, several major high-profile events are set to unfold across
the United States, including the 2026 FIFA World Cup, America 250, and
the 2028 LA Olympics.
These events will only increase the volume and complexity of
threats facing the homeland and DHS must be prepared to respond. The
Trump administration, to its credit, has taken strong steps to
strengthen our Nation's security systems. However, modernization of
TSA, CISA, and S&T will require sustained Congressional support. As
Chairman of the Homeland Security Committee, it is my priority to
ensure we support and invest in the next generation of technologies and
adopt highly innovative and effective security approaches given the
challenges facing the Department and our country. This hearing provides
an important opportunity to assess how TSA, CISA, and S&T are carrying
out their missions. We look forward to hearing from our witnesses and
engaging in constructive dialog about how Congress can effectively
support security, operational excellence, and accountability across the
Department.
I also want to take this opportunity to thank our DHS personnel who
keep us safe every day, including our dedicated cybersecurity
professionals, our innovative researchers and scientists, and our brave
TSA security officers who work on the front lines to protect the
traveling public and who continue to do so even without pay during the
Nation's longest shutdown last year.
I'm confident that by working together, we can break through the
challenges of today and prepare for threats of tomorrow. The stakes for
the American people could not be higher. Thank you.
Chairman Garbarino. Thank you. I now recognize the Ranking
Member, the gentleman from Mississippi, Mr. Thompson, for 5
minutes for his opening statement.
Mr. Thompson. Thank you very much, Mr. Chairman. I want to
thank you for holding today's hearing on Oversight of the
Department of Homeland Security. Congressional Republicans'
oversight of the Trump administration has been dismal this
Congress. Republicans have had administration witnesses before
this committee the fewest times in any recent administration's
first year. Most of that was on the watch of the prior
Chairman, who was, to my favorite phrase of his, derelict in
his duty to bring Trump administration officials before the
committee.
This hearing is a step in the right director. The Trump
administration has created serious issues at TSA, CISA, and DHS
S&T that need to be addressed. Committee Democrats are
committed to taking a hard look at those issues. From President
Trump's slashing the CISA work force, to Secretary Kristi
Noem's unlawful rescinding union rights for front-line
transportation security officers, to the administration cutting
programs that leveraged university-based research to address
critical Homeland Security challenges.
But none of those things can be the sole focus of our
oversight right now, because President Trump and Secretary Noem
have weaponized DHS against the American people and are
wreaking havoc in Minneapolis and other communities across this
country. It's an absolute disgrace that ICE isn't here today in
wake of the shooting death of Renee Good at the hands of an ICE
agent.
Mr. Chairman, as you know, I have asked for ICE Acting
Director Lyons to appear at today's hearing. I ask unanimous
consent to insert in the record my letter to you dated January
14, 2026, requesting Acting Director Lyons appear before the
committee without delay. I want to thank you for issuing that
invitation, but Committee Democrats and I are outraged that ICE
refused to appear today.
Ms. Good was a wife, mother of three young children, a
devout Christian, and a U.S. citizen. We all seen the shooting
video with our own eyes. Ms. Good certainly did not deserve to
be killed by her own government. She should be alive today. Mr.
Chairman, at this time, I ask for a moment of silence in memory
of Renee Good.
[Moment of silence.]
Mr. Thompson. Thank you. Mr. Chairman, in the wake of Ms.
Good's killing, ICE has an obligation to appear and answer
Members' questions. Her tragic killing needs to be thoroughly
investigated, and everyone involved from the ICE officer who
pulled the trigger, to the President and Secretary who sent
them to Minneapolis must be held accountable. DHS also needs to
be held accountable for its out-of-control immigration
operation, creating chaos in communities like Los Angeles,
Chicago, New Orleans, and Minneapolis, terrorizing people from
all walks of life and hurting U.S. citizens and immigrants
alike.
Mr. Chairman, in order to ensure that ICE appears before
the committee, pursuant to clause 2(J)(1) of House Rule 11, I'm
providing you with a letter signed by every Democratic Member
of the committee requesting testimony from Acting Director
Lyons. I ask unanimous consent that this Minority Day letter be
submitted for the record.
Chairman Garbarino. Without objection.
[The information follows:]
[GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
------
[GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
Mr. Thompson. Thank you.
Mr. Chairman, I understand that you intend to hold a series
of oversight hearings with DHS officials. I look forward to ICE
being before the committee at our next hearings; Democrats
insist on that. Never has oversight and accountability been
more necessary than it is now.
President Trump and Secretary Noem are doing real damage to
this country and to the Department that was stood up in the
wake of 9/11 to protect Americans from future attacks.
Unfortunately, President Trump and Secretary Noem have
established a corrupt, above-the-law culture at DHS, and Noem
has enriched herself and her allies at taxpayers' expense. She
has awarded multiple, no-bid contracts to close associates and
siphon $240 million of taxpayers' money to companies connected
to her top adviser and close confidant, Corey Lewandowski, as
well as to her spokesperson husband. She fast-tracked a
contract worth almost $1 billion to a company led by a Trump
donor. She is living rent-free in a U.S. Coast Guard housing
designated for military members.
She has also abused her power as Secretary. She has
acknowledged cherry-picking, which court orders departments
will comply with contrary to the rule of law.
She has used access to disaster funds to punish political
foes, illegally withholding Congressionally-authorized disaster
funds. She has obstructed Congressional oversight, barring
Members from visiting ICE detention facilities, and refusing to
respond to oversight letters and requests.
In short, she has enriched herself, abused the power of her
office, obstructed Congressional oversight, and violated her
oath of office to the Constitution. Never has oversight of the
Department of Homeland Security been more important, and never
has holding an administration accountable been more necessary.
Be assured that accountability is coming. Accountability is
coming, Mr. Chairman, and I yield back.
[The statement of Ranking Member Thompson follows:]
Statement of Ranking Member Bennie G. Thompson
January 21, 2026
Congressional Republicans' oversight of the Trump administration
has been dismal this Congress. Republicans have had administration
witnesses before the committee the fewest times in any recent
administration's first year. Most of that was on the watch of the prior
Chairman, who was--to use a favorite phrase of his--derelict in his
duty to bring Trump administration officials before the committee.
This hearing is a step in the right direction. The Trump
administration has created serious issues at TSA, CISA, and DHS S&T
that need to be addressed. Committee Democrats are committed to taking
a hard look at those issues--from President Trump slashing the CISA
workforce, to Secretary Kristi Noem unlawfully rescinding union rights
for front-line Transportation Security Officers, to the administration
cutting programs that leverage university-based research to address
critical homeland security challenges. But none of those things can be
the sole focus of our oversight right now, because President Trump and
Secretary Noem have weaponized DHS against the American people and are
wreaking havoc in Minneapolis and other communities across this
country.
It's an absolute disgrace that ICE isn't here today, in the wake of
the shooting death of Renee Good at the hands of an ICE agent. As you
know, I asked for ICE Acting Director Lyons to appear at today's
hearing. I want to thank you for issuing that invitation, but committee
Democrats and I are outraged that ICE refused to appear today.
Ms. Good was a wife, mother of 3 young children, a devout
Christian, and a U.S. citizen. We've all seen the shooting video with
our own eyes. Ms. Good certainly did not deserve to be killed by her
own Government. She should be alive today. In the wake of Ms. Good's
killing, ICE has an obligation to appear and answer Members' questions.
Her tragic killing needs to be thoroughly investigated and everyone
involved--from the ICE officer who pulled the trigger to the President
and Secretary who sent him to Minneapolis--must be held accountable.
DHS also needs to be held accountable for its out-of-control
immigration operations creating chaos in communities like Los Angeles,
Chicago, New Orleans, and Minneapolis, terrorizing people from all
walks of life, and hurting U.S. citizens and immigrants alike. In order
to ensure that ICE appears before the committee, pursuant to clause
2(J)(1) of House Rule XI, I am providing you with a letter signed by
every Democratic Member of the committee requesting testimony from
Acting Director Lyons.
I understand that you intend to hold a series of oversight hearings
with DHS officials. I look forward to ICE being before the committee at
our next hearing. Democrats insist on that. Never has oversight and
accountability been more necessary than it is now. President Trump and
Secretary Noem are doing real damage to this country and to the
Department that was stood up in the wake of 9/11 to protect Americans
from future attacks. Unfortunately, President Trump and Secretary Noem
have established a corrupt, ``above the law'' culture at DHS, and Noem
has enriched herself and her allies at tax-payer expense.
She has awarded multiple, no-bid contracts to close associates and
siphoned $240 million of taxpayer money to companies connected to her
top advisor and close confidant, Corey Lewandowski, as well as to her
spokesperson's husband. She fast-tracked a contract worth almost $1
billion dollars to a company led by a Trump donor. And she is living,
rent-free, in U.S. Coast Guard housing designated for military members.
She has also abused her power as Secretary. She has acknowledged
cherry-picking which court orders the Department will comply with,
contrary to the rule of law. She has used access to disaster funds to
punish political foes, illegally withholding Congressionally-authorized
disaster funds. She has obstructed Congressional oversight, barring
Members from visiting ICE detention facilities and refusing to respond
to oversight letters and requests.
In short, she has enriched herself, abused the power of her office,
obstructed Congressional oversight, and violated her oath of office to
the Constitution. Never has oversight of the Department of Homeland
Security been more important and never has holding an administration
accountable been more necessary.
Be assured that accountability is coming.
Chairman Garbarino. The gentleman yields back. Other
Members of the committee are reminded that opening statements
may be submitted for the record.
I am pleased to have a highly distinguished panel of
witnesses before us today. As the Ranking Member knows, we have
talked about doing other oversight hearings, and that is the
intent of this committee to do what Congress is meant to do and
conduct oversight. I'm pleased today that we have our first
panel of DHS officials here. DHS is a big department, and there
should be several of these, and we will have several of these.
Pursuant to committee Rule VII(C), I ask that the witnesses
please rise and raise their right hand.
[Witnesses sworn.]
Chairman Garbarino. Let the record reflect that the
witnesses have answered in the affirmative. Thank you all.
Please be seated.
I would now like to formally introduce our witnesses. Mr.
Pedro Allende is under secretary for science and technology,
leading the Department's research and development efforts and
serving as science advisor to the Secretary. Previously, he
served as Florida's secretary of management services and has
held roles at DHS and the Department of Emergency and Labor.
Mr. Madhu Gottumukkala serves as the acting director and
deputy director for the Cybersecurity Infrastructure Security
Agency; a role in which he helps to lead CISA's mission to
understand, manage, and reduce risks to cyber and physical
infrastructure. Prior to his appointment, he served as
commissioner and chief information officer for South Dakota's
Bureau of Information and Technology.
Ms. Ha Nguyen McNeill is deputy administrator of the
Transportation and Security Agency, a role in which she is
performing the duties of administrator to advance TSA's mission
to secure the Nation's transportation system and improve
operational effectiveness. Previously, she served as acting
president, commercial, and vice president of digital identity
growth at Big Bear AI. Ms. McNeill also served as TSA chief of
staff from 2017 to 2019.
I thank all of the witnesses for being here today. I now
recognize Mr. Allende for 5 minutes to summarize his opening
statement.
STATEMENT OF HON. PEDRO M. ALLENDE, UNDER SECRETARY, SCIENCE &
TECHNOLOGY DIRECTORATE (S&T)
Mr. Allende. Thank you, Mr. Chairman. Chairman Garbarino,
Ranking Member Thompson, and distinguished Members of the
committee. Thank you for the opportunity to appear before you
today. I am honored to serve as under secretary for science and
technology at the Department of Homeland Security. I appreciate
the committee's continued oversight and engagement with their
work.
The Science and Technology Directorate plays a unique role
within DHS. We are the Department's research, development,
test, and evaluation organization responsible for anticipating
emerging threats, identifying technology opportunities, and
ensuring that DHS components have access to solutions that are
timely, effective, and responsible. Our work is grounded in the
simplest measure of success: Whether technology transitions
into the real-world use are effectuated, and whether they
measurably improve mission outcomes.
In my short tenure as under secretary, I have focused on
listening to the operators, across the Department, to
understand where technology is helping today, where it can help
fill up certain gaps. Those conversations reinforce a
consistent message. Technology must be operationally relevant.
It must be rigorously tested and delivered with discipline.
Research alone is not enough.
Capability must reach the operators in the field. To meet
that standard, S&T works closely with the components. From the
earliest stages of development--and we assess emerging threats,
evaluate existing commercial solutions, and apply systems
engineering in tests and evaluation to reduce risks before
acquisition decisions are made.
When a private-sector solution can meet mission needs, that
is our preference. We prioritize adopting those solutions and
adapting them in order to accelerate delivery to the field;
and, frankly, to steward taxpayer dollars effectively and
responsibly.
At the same time, the threat environment facing our
homeland is increasingly dynamic and technology-driven. From
unmanned aircraft systems to cyber-enabled threats, to risks,
to critical infrastructure, S&T's role is to look ahead while
supporting today's operations. That means engaging with
industry, with academia, national laboratories, and FFRDCs, and
interagency partners to ensure that DHS remains prepared for
the future, without losing focus of today's challenges.
Ultimately, my goal as under secretary to ensure that S&T
remains a trusted partner to DHS components; one that delivers
capabilities that work in the field, supports informed decision
making, and strengthens the security of the American homeland.
I look forward to discussing our work with the committee this
morning and to answering your questions. Thank you.
[The prepared statement of Mr. Allende follows:]
Prepared Statement of Pedro M. Allende
January 21, 2026
introduction
Chairman Garbarino, Ranking Member Thompson, and distinguished
Members of the committee, thank you for the opportunity to testify
before you today. I am honored to have the confidence of President
Trump and Secretary Noem to serve as the under secretary for science
and technology (S&T) at the Department of Homeland Security (DHS). I
look forward to executing the Trump administration priorities to make
the Nation safer through advancement and application of science and
technology.
I appreciate the committee's continued engagement with the DHS S&T
Directorate, and I look forward to our work together during my tenure
as under secretary.
The S&T Directorate plays a unique role within DHS. We are
responsible for understanding emerging threats and opportunities, and
for ensuring the Department has access to timely, effective, and
responsible technology solutions to meet its evolving mission needs. As
threats to the homeland become more complex, adaptive, and technology-
enabled, S&T's mission is to help DHS stay ahead of those challenges.
S&T works closely with DHS operational components, the private
sector, academia, international and interagency partners to deliver
solutions that enhance security, improve efficiency, and strengthen
operational effectiveness. Our success is measured not by research
alone, but by outcomes delivered to operators and the American people.
In my short time in this role, I have been energized by seeing S&T
in action and witnessing first-hand the critical role technology plays
in keeping our Nation safe.
Just last week, I had the opportunity to meet with our partners at
operational sites on the West Coast, including our DHS colleagues in
the Transportation Security Administration (TSA), the U.S. Customs and
Border Protection (CBP), and the U.S. Coast Guard, as well as our local
law enforcement partners. At Los Angeles International Airport (LAX), I
observed TSA security operations and gained valuable insight into how
emerging technologies can create new opportunities for enhanced safety
and security. At SoFi Stadium, I engaged with security teams to discuss
how innovative solutions can strengthen our defenses as we prepare to
host the FIFA World Cup in the summer of 2026.
I toured the complex operations and technology required for cargo
operations and screening by CBP as they ensure the safety of two of the
largest U.S. seaports in Los Angeles and Long Beach, California, to
cargo operations and screening. At the Air and Marine Operations
Center, I met with partners to discuss collaborative activities, such
as the Kestrel system which enhances their ability to determine
highest-priority threats and make real-time operational decisions and
explore enhancements to achieve full domain awareness across our
borders and air space.
My experiences this past week have crystalized for me the
importance of advancing the administration's priorities and my
commitment to ensuring S&T remains focused on the needs of our
operational components while staying ahead of our adversaries. Our
organization is also taking on broader challenges, including leading
efforts in areas such as Counter-Unmanned Aircraft Systems. Secretary
Noem recently announced the establishment of the Program Executive
Office for Unmanned Aircraft Systems and Counter-Unmanned Aircraft
Systems, investing to rapidly procure and deploy advanced counter-drone
technologies. As Secretary Noem noted, these are critical investments
to protect our borders and to keep Americans safe and secure during
America 250 celebrations and at 2026 FIFA World Cup venues.
My recent trip also enabled me to engage with private-sector
partners, which will be a key theme of my service as Under Secretary.
Not only does the private sector operate much of the critical
infrastructure upon which our Nation relies, but they are a major
source of technological innovation necessary to protect the homeland.
One of my guiding principles will be to seek out and adopt private-
sector solutions whenever possible. Leveraging existing or adaptable
technologies will allow DHS to accelerate delivery to the field.
I look forward to working with Congress on key legislative
priorities including the restoration of Other Transaction Authority
(OTA). OTA is a critical tool used to partner with nontraditional
small- and medium-sized businesses and organizations on innovations
that enhance our national security. The expiration of the authority on
September 30, 2024, brought to a halt various efforts at S&T to develop
solutions across several mission areas.
Chairman Garbarino, Ranking Member Thompson, and Members of the
committee, S&T is committed to delivering innovative, responsible, and
operationally relevant solutions that strengthen the security of the
homeland.
We look forward to continuing our close collaboration with
Congress, across DHS components and partner agencies, and our external
partners as we work to execute administration priorities, understand
emerging threats, and leverage private-sector innovation to make the
Nation safer.
Thank you for the opportunity to testify. I look forward to your
questions.
Chairman Garbarino. Thank you very much. The gentleman
yields back. I now recognize Mr. Gottumukkala for 5 minutes to
summarize his opening statement.
STATEMENT OF MADHU GOTTUMUKKALA, PH.D., ACTING DIRECTOR,
CYBERSECURITY AND INFRASTRUCTURE SECURITY AGENCY (CISA)
Mr. Gottumukkala. Chairman Garbarino, Ranking Member
Thompson, and Members of the committee, thank you for the
opportunity to appear before you today. My name is Madhu
Gottumukkala, and I serve as the acting director of the
Cybersecurity and Infrastructure Security Agency or, CISA.
Before joining the Federal Government, I oversaw State-wide
technology and cybersecurity operations for the State of South
Dakota. Earlier in my career, I worked across a wide list of
telecom and health technology sectors. Those experiences shape
how I approach the role with a practical understanding of how
State and local governments and critical infrastructure
operators experienced this on the ground. I'm honored that the
President and Secretary Noem asked me to lead this agency.
Since arriving last May, I have been proud to see the
professionalism, talent, and deep mission commitment of the
CISA work force each and every day. I'm also grateful for this
country's continued bipartisan support and for the authorities
Congress has provided to enable CISA's mission.
Over the past year and under President Trump's leadership
and Secretary Noem's guidance, CISA has remained squarely
focused on the mission Congress intended when the agency was
established; that is, supporting, strengthening, and securing a
Nation's critical infrastructure from cyber and physical
threats. That mission is operational and outcome-driven.
Every day, CISA's people work to protect the financial
systems, safeguard pipelines, and ensure the digital and
physical infrastructure Americans rely on can withstand
disruption.
In 2025, CISA made meaningful progress in an increasingly
aggressive threat environment. We strengthen our ability to
detect and respond to cybersecurity threats, deepen
collaboration across Government and industry, and shared threat
information and mitigation guidance faster and in more
integrated ways.
As it is, CISA supported more than 4,000 victims of cyber
incidents, published over 1,600 cybersecurity products, shared
more than 2,500 threat and incident reports, and triaged over
30,000 incidents through our 24/7 operations center. These
efforts produced real-world impact and helped ensure Americans
could continue to rely on the S&T resources.
As the operational lead for Federal civilian cybersecurity,
CISA worked really closely with departments and agencies to
promote risk-based policies and best practices to respond to
the evolving threats. In 2025, we issued three emergency
directors to address critical vulnerabilities and cyber
threats. We also scaled the endpoint detection and response
technology to over 60 agencies and more than 500,000 endpoints,
giving analysts near real-time visibility to detect and stop
those advanced threats.
In early 2025 alone, CISA blocked more than 1.7 billion
malicious connections on Federal networks, including 142
million targeting the critical infrastructure. CISA also
continued delivering security directly to the State, local,
Tribal, and territorial governments; a mission that is very
personal to me given my time serving in the State level.
With a nationwide presence across the 10 regions, we
provided tailored training, technical assistance, and planning
support, recognizing that many of our partners operate with
limited budgets and staffing. To help address this, in August
2025, the Department of Homeland Security released funding
opportunities under the State and local cybersecurity grant
program, and the Tribal Cybersecurity Grant program making
available over $100 million to help reduce the cybersecurity
risk nationwide.
Physical security remains a no-fail mission for the agency.
In fiscal year 2025, CISA delivered more than 1,000 counter-IED
and risk mitigation training courses to over 26,000
participants; strengthen preparedness, awareness, and also the
response capabilities.
We are also actively preparing for the major national and
international neighbors, including the FIFA World Cup, America
250, and the 2028 Olympic Games. In April, CISA convened more
than 730 partners from over 40 agencies at the Lincoln
Financial Field for the first scale exercise of the workup.
That exercise produced influence in coordination,
communication, and public safety.
As we enter 2026, CISA is executing a mission-first
approach. We are launching targeted initiatives to close the
most pressing risk gaps facing the critical infrastructure, but
clearly, where cyber threats intersect with real-world
consequences. We are proud as in what works, eliminating
duplication and ensuring that every product and service
directly advances CISA's regulatory mission and alliance with
the administration's goals of efficiency, accountability, and
impact. This includes incorporating the industry and
Congressional feedback into the final rule for the Cyber
Incident Reporting for Critical Infrastructure Act. It also
includes modernizing how we engage with critical infrastructure
partners by replacing CPAC, the most streamlined and effective
engagement framework.
Finally, we recognize that a disciplined mission requires
the right work force--not the larger one, but a more capable
and a skilled one. In 2026, CISA will continue prioritizing in
mission-critical roles while remaining aligned with the broader
efforts to convert costs and maximize return.
Under President Trump's leadership and Secretary Noem's
guidance, CISA remains committed to being a focused, efficient,
and accountable agency--one that executes the mission Congress
assigned and diversity and security for the American people.
Thank you, again, for your support, and I look forward to
your questions.
[The prepared statement of Mr. Gottumukkala follows:]
Prepared Statement of Madhu Gottumukkala
January 21, 2026
introduction
Chairman Garbarino, Ranking Member Thompson, and Members of the
committee, thank you for the opportunity to appear before you today,
and for the opportunity to discuss the Cybersecurity and Infrastructure
Security Agency's priorities to protect the Nation's critical
infrastructure from cyber and physical threats.
I appreciate the committee's continued support for the critical
mission that CISA carries out on behalf of the American people. Since
President Trump took office last year, and with strong support and
guidance from Secretary Noem, CISA has been laser-focused on fulfilling
the mission Congress gave us when the agency was first established by
President Trump in 2018: to support, strengthen, and secure our
Nation's critical infrastructure. Our work today is squarely aligned
with the agency's original statutory purpose. That means working with
Government and private-sector partners to protect our financial
systems, safeguard our pipelines, and ensure the digital and physical
systems our Nation depends on to remain resilient against disruption
from possible cyber attacks.
To do this, over the past year, CISA has focused its work on
efforts aligned to the agency's statutory priorities, including:
Reinforcing Federal civilian network defense.
Supporting critical infrastructure nationwide in defending
against physical and cyber threats.
Delivering security directly to State and local governments
by offering an array of no-cost resources and tools, such as
technical assistance, exercises, and cybersecurity assessments.
Continuing to share threat information and mitigation
guidance in a faster, more integrated way.
Through these efforts, we remain deeply committed to working side-
by-side with organizations of every size, across every critical sector.
Because no single entity--not even the Federal Government--can manage
these risks alone.
Thanks to the leadership of President Trump and Secretary Noem,
CISA is leading the fight against malign actors. We strengthened our
operational capabilities to detect and to respond to cyber threats,
deepened collaboration across Government and industry, and continued to
provide guidance to the critical infrastructure community to reduce
vulnerabilities and systemic risk across our Nation's most critical
systems and functions as malign actors seek to exploit our Nation's
vulnerabilities.
CISA has continued to provide practical services and guidance to
critical infrastructure owners and operators, helping them to improve
their resilience, limit disruptions, and recover more quickly when
incidents do occur.
Under the Trump administration, CISA is focused on our No. 1
priority: protecting and defending the American people. CISA's work has
reduced the impact of cyber incidents and helped to ensure that
Americans could continue to use the critical infrastructure functions
they rely on. The agency also continues to share threat and incident
reports, coordinate intelligence across the Federal Government, and
partner through structured meetings and threat briefings to strengthen
resilience nationwide.
As the operational lead for Federal cybersecurity, and as part of
our mission to protect and defend Federal civilian networks, CISA
strengthened its work with each department and agency to promote the
adoption of risk-based common policies and best practices to
effectively respond to the ever-evolving threat landscape.
Secretary Noem recognizes that cybersecurity is national security
and in 2025, under her leadership, CISA issued 3 emergency directives
to protect Federal networks from critical vulnerabilities and cyber
threats. CISA also scaled its Endpoint Detection and Response (EDR)
Technology, giving analysts near-real-time visibility to detect and
stop advanced threats.
The Trump administration recognizes that the Federal Government
cannot fight our Nation's adversaries alone--we must empower our local
partners. That is why CISA has worked alongside our State, local,
Tribal, and territorial (SLTT) governments to deliver security to our
local partners. With a nationwide presence in 10 regions across the
country, CISA delivered tailored resources, training, and technical
assistance to help our partners anticipate, withstand, and recover from
threats. We also recognize that many SLTT governments across the
country are constrained by smaller, more limited operating budgets, and
fewer IT staff than a similarly-sized business. Secretary Noem and I
recognize this challenge, and so to help support our SLTT partners last
year, the Department of Homeland Security released Notice of Funding
Opportunities for the State and Local Cybersecurity Grant Program
(SLCGP) and the Tribal Cybersecurity Grant Program (TCGP)--$91.7
million to States and territories and $12.1 million to Tribal
Governments to address cybersecurity risks.
CISA remains dedicated to supporting critical infrastructure owners
and operators. Physical security, defending against physical threats,
remains a no-fail mission for the agency. In fiscal year 2025, CISA
continued to train public and private-sector stakeholders on counter-
improvised explosive device (C-IED) and risk mitigation practices,
enhancing threat awareness, preparedness, and capabilities across the
critical infrastructure community.
We also continue to look ahead to preparing for major events in
2026 and beyond, including the FIFA World Cup, America 250, and the
2028 Olympics in Los Angeles. To give you just one example of this
work, in April, CISA convened participants from more than 40 agencies
at Lincoln Financial Field in Philadelphia, one of the 11 American Host
cities, for a full-scale exercise ahead of the FIFA World Cup. The
exercise produced areas for improvement and action recommendations to
enhance coordination, communication, and public safety.
Continuing to look ahead as we begin 2026, CISA will reinvigorate
its mission-first approach. We will be launching targeted initiatives
designed to close the most pressing risk gaps facing critical
infrastructure--particularly where cyber threats intersect with real-
world consequences. These efforts are intentionally-scoped,
operationally-focused, and aligned with the Trump administration's
broader goals and priorities of efficiency, accountability, and impact.
We are prioritizing what works from previous lessons learned,
eliminating duplication, and ensuring every new service or product we
release directly advances CISA's statutory mission and
responsibilities.
For example, CISA is currently reviewing public comments on the
proposed rule for the Cyber Incident Reporting and Critical
Infrastructure Act of 2022, or CIRCIA. CISA appreciates the input it
received from Congress and the public about aligning with Congressional
intent and streamlining the CIRCIA requirements. CISA is also cognizant
of the concerns raised regarding the scope and burden of the rule and
improving harmonization of CIRCIA with other Federal cyber incident
reporting requirements. CISA is considering this feedback as it works
to issue a final rule. I look forward to continuing to engage with
Congress on these efforts and providing updates as the final rule
process nears its completion.
Mr. Chairman, I would like to take a moment to thank Congress, and
particularly this committee under your leadership, for their work on
reauthorizing CISA 2015, which is mission-critical for CISA's work and
information sharing with the private sector. The Secretary and I have
been very clear that we fully support the reauthorization of this vital
piece of legislation.
CISA remains steadfast on the agency's statutory intent, we also
recognize that a disciplined mission requires the right workforce--not
a larger one, but a more capable and technically-skilled one. In 2026,
CISA will continue to right-size and rebalance its workforce by
prioritizing highly technical professionals in mission-critical roles,
including cybersecurity operators and infrastructure security experts.
These targeted positions will support front-line critical
infrastructure owners and operators across every region in the United
States in reducing their long-term risks. We will execute our hiring
authorities while remaining consistent with the administration's
efforts to streamline the Government workforce, control cost, and
maximize return.
Under President Trump's leadership and Secretary Noem's guidance,
CISA remains committed to being a focused, efficient, and accountable
agency--one that executes the mission Congress assigned, supports the
administration's priorities, and delivers real security outcomes for
the American people. We look forward to continuing to work with this
committee to ensure that CISA has the tools and capabilities necessary
to protect the Nation's critical infrastructure.
Thank you again for your support and I look forward to your
questions.
Chairman Garbarino. Thank you, Mr. Gottumukkala. I now
recognize Ms. McNeill for 5 minutes to summarize her opening
statement.
STATEMENT OF HA NGUYEN MC NEILL, SENIOR OFFICIAL PERFORMING THE
DUTIES OF THE ADMINISTRATOR, TRANSPORTATION SECURITY
ADMINISTRATION (TSA)
Ms. McNeill. Good morning, Chairman Garbarino, Ranking
Member Thompson, and distinguished Members of the committee.
Thank you for the invitation to testify before you today on
behalf of the Transportation Security Administration. I'm
honored to be here, and grateful for the long-standing and
productive partnerships TSA shares with this committee and
Congress.
I would like to start by thanking TSA employees for their
unrelenting efforts day in and day out to secure the Nation's
transportation systems. TSA is an agile security agency
embodied by a dedicated and professional work force that work
around the clock to outmatch an increasingly sophisticated and
dynamic threat.
TSA's greatest assets is its people, and I want to
sincerely thank them. From our transportation security officers
and K-9 handlers to our Federal air marshals, these men and
women embody the agency's core values. They worked through the
longest Government shutdown in American history, many without
pay, and experience personal financial hardships. Their
commitment to the TSA mission and to the traveling public is
unparalleled.
Under the leadership of President Trump and Department of
Homeland Security, Secretary Kristi Noem, TSA is laser-focused
on delivering for the American people. The upcoming World Cup,
America 250, and 2028 Olympics present an enormous opportunity
to boldly transform transportation security in the United
States and usher in President Trump's vision for a new golden
age of travel. Achieving these priorities starts with deploying
upgraded state-of-the-art technology to our over 430 commercial
airports nationwide, focusing on our core mission of
transportation security and harnessing our collective
investment power and innovation through robust, public, private
partnerships.
Last year, passenger volumes at airports reached record
highs, recording 8 out of the top 10 busiest days in TSA's
history. In 2025, TSA screened 907 million passengers, 480
million checked bags, and 2.1 billion carry-on bags.
With the transportation sector remaining a top target for
bad actors and continued year-over-year passenger volume
growth, it is more critical than ever to have a
technologically-advanced, seamless, and secure aviation system.
I would like to thank the committee for its strong support
of the agency's critical aviation security programs, including
two I would like to highlight: First, the Screening Partnership
Program through which TSA is working closely with airports and
industry to incentivize investment in more tailored and
innovative solutions to strengthen security; and second, the
One Stop Security Pilot Program which significantly improves
international aviation security and streamlines the transfer
process for passengers inbound from the United States with a
connecting flight.
In addition to strong partnerships, we must invest in
modernizing our security technology. One avenue to achieving
this is for Congress to expand the amount and scope of the
Aviation Security Capital Fund. Starting in 2004, Congress
authorized the first $250 million in revenue collected each
year from the passenger security fee to go to TSA's capital
fund to be used for checked baggage technology. That amount has
not been adjusted or raised in 21 years with the next $1.6
billion in the fee revenue going to annual national deficit
reduction.
If Congress were to return the funds collected to be used
for its intended purpose, passenger security, and expanded to
include checkpoint technology, TSA can significantly shorten
its technology deployment time frames, improving both security
and the passenger experience.
TSA is committed to making the airport experience smooth
and stress free for the traveling public, including military
personnel and American families traveling with children.
Last year we established the Serve With Honor, Travel With
Ease Program which provides screening lanes for Active-Duty
military personnel and their families, as well as the Families
on the Fly Program, which dedicated lanes for families.
With the strong leadership of President Trump and Secretary
Noem, coupled with continued support from Congress and industry
partners, we can transform aviation security and return America
to being the world's No. 1 travel destination.
Chairman Garbarino, Ranking Member Thompson, and
distinguished Members of the committee, it is a privilege to
testify before you today. I thank you for your support of TSA
and look forward to your questions.
[The prepared statement of Ms. McNeill follows:]
Prepared Statement of Ha Nguyen McNeill
January 21, 2026
introduction
Good morning, Chairman Garbarino, Ranking Member Thompson, and
distinguished Members of the committee. Thank you for the invitation to
testify before you today on behalf of the Transportation Security
Administration (TSA). I am honored to be here and grateful for the
long-standing and productive partnership TSA shares with this
committee.
I would like to start by thanking TSA's employees for their
unrelenting efforts day in and day out to secure the Nation's
transportation systems. TSA is an agile security agency, embodied by a
dedicated and professional workforce that works tirelessly to outmatch
an increasingly sophisticated and dynamic threat.
Under the Trump administration and Department of Homeland Security
(DHS) Secretary Kristi Noem, TSA is laser-focused on delivering for the
American people, fortifying travel security, renewing its commitment to
the traveler experience, and serving as a responsible steward of the
American tax dollar. This starts with deploying upgraded, state-of-the-
art technology to airports nationwide, renewing our commitment to the
American taxpayer, returning to our core mission, leveraging public-
private partnerships, and enhancing hospitality and the passenger
experience.
tsa priorities
With the transportation sector remaining a top target for malign
actors, and passenger volumes at airports reaching record highs in
2025--including 8 out of the top 10 busiest travel days on record--it
is more critical than ever to have a technologically advanced,
seamless, and secure aviation security system. In 2025 alone, TSA
screened 906.7 million passengers, 480 million checked bags, and 2.1
billion carry-on bags.
The upcoming 2026 World Cup, America250 events, and 2028 Summer
Olympics present an enormous opportunity to boldly transform
transportation security in the United States. Through new policies,
legislation, and private-sector partnerships that support technological
innovation and modernizing the screening process, we can usher in
President Trump's vision for a new Golden Age of American travel.
Leveraging Public-Private Partnerships to Advance the Mission
TSA's mission is supported by critical public-private partnerships,
and the Trump administration, DHS, and TSA are strongly committed to
working more collaboratively with industry stakeholders than ever
before, utilizing their expertise and efficiency, to strengthen
aviation security and improve the passenger experience. On that note, I
would like to thank this committee for ensuring TSA and our critical
interagency, State, local, and private-sector partners have the
resources needed to mitigate the evolving threat landscape, which
includes the proliferating cybersecurity and Counter-Unmanned Aircraft
Systems (C-UAS) threats.
Screening Partnership Program
Under the Screening Partnership Program (SPP), TSA contracts with
qualified private companies to provide personnel to perform security
screening operations at commercial airports. TSA is working closely
with Congressional and industry partners to modernize SPP to
incentivize airports and industry to invest in more tailored and
innovative solutions faster, to optimize security operations, while
maintaining the Agency's rigorous regulatory oversight and outcome-
based security standards.
One-Stop Security
In close partnership with the Department of State, industry, and
international partners, TSA is advancing the One-Stop Security (OSS)
pilot program. OSS improves international aviation security,
streamlines the transfer process for passengers inbound to the United
States with connecting flights, and eliminates the need for passengers
and their bags to go through screening again. Last summer, TSA launched
its first OSS pilot location at London-Heathrow Airport (LHR),
demonstrating an immediate success for all stakeholders. Currently,
there are 7 OSS flights per day from LHR into Hartsfield-Jackson
International Airport (ATL) and Dallas-Fort Worth International Airport
(DFW), saving each OSS passenger up to 2 hours that he or she can now
use to relax, shop, and dine at the airport.
Reimbursable Screening Services Program
Another critical pilot program that Congress has afforded us to
explore with industry partners is the Reimbursable Screening Services
Program (RSSP). RSSP enables TSA to work with industry to screen
passengers in a location separate from the checkpoint, such as an off-
airport cruise or VIP terminal. RSSP is an innovative public-private
partnership to alleviate congestion at the checkpoint and offset TSA
costs. Permanently authorizing RSSP, which is set to expire on January
30 of this year, will provide certainty and unlock innovation, further
increasing industry interest and participation.
Investing in Modernizing Security Technology
Starting in 2004, Congress authorized the first $250 million in
revenue collected each year from the Passenger Security Fee to go to
the Aviation Security Capital Fund (ASCF), to be used for checked
baggage technology. Along with amounts provided in annual
appropriations, amounts in the ASCF were meant to recapitalize and
modernize TSA screening technology, but unfortunately this level of
investment has not kept pace with changing technology and the evolution
of the threat landscape.
Over the past several years, Congress has diverted approximately
$1.6 billion in TSA Passenger Security Fee revenue each year for
deficit reduction purposes. The President's fiscal year 2026 budget
proposes to eliminate the deficit reduction contributions and instead
direct Passenger Security Fee amounts to their intended purpose of
bolstering TSA aviation screening operations. The fiscal year 2026
budget also includes proposed additional investments in aviation
screening technology, such as Computed Tomography (CT) technology, that
can supplement ASCF amounts to make improvements to both security and
the passenger experience at the checkpoints. TSA encourages Congress to
act on the President's fiscal year 2026 budget request so that the ASCF
is not the only source of funding for modernizing TSA security
technology.
Renewing Focus on Core Mission and Serving the American Taxpayer
REAL ID
Under the leadership of Secretary Noem, since May 2025, TSA is
fully enforcing its statutory requirements under the REAL ID Act of
2005. The legislation was enacted in response to the 9/11 Commission
Report recommendations aimed at combatting fraudulent identity
documents (IDs) and ensuring passengers are who they say they are. As
the 9/11 Commission Report stated, ``For terrorists, travel documents
are as important as weapons.'' This administration acted swiftly to
enforce the law to ensure TSA maintains the highest standards of
aviation security for the American taxpayer and traveler.
Currently, most travelers (about 94 percent) present either a REAL
ID-compliant or another acceptable form of ID. However, we must ensure
that everyone who flies is who they say they are. TSA ConfirmID is a
new modernized alternative identity verification system to enhance and
streamline identity verification for travelers that do not have an
acceptable form of ID.
Starting February 1, 2026, travelers who do not present an
acceptable form of ID at TSA checkpoints and still want to fly, have
the option of paying a $45 fee and undergoing the TSA ConfirmID
process. The fee ensures that the cost to cover verification of an
unacceptable ID will be borne by the non-compliant traveler, not the
American taxpayer, and prevents malign actors from getting on a plane.
TSA will continue working closely with all States to increase adoption
of REAL IDs and urges all travelers to obtain a REAL ID, or other
acceptable form of ID, as soon as possible to avoid delays and
potentially missing flights.
Improving the Travel Experience for Our Military and
American Families
TSA is committed to making the airport experience as smooth and
stress-free for active-duty military personnel and their families, and
American families traveling with children. To honor those who protect
our Nation and to recognize their service and sacrifices, TSA has
established the ``Serve with Honor, Travel with Ease'' program, which
provides dedicated screening lanes for active-duty military personnel
and their families at airports near the Nation's largest military
bases. Similarly, the agency is actively working to create a welcoming
environment for families with children. TSA's new ``Families on the
Fly'' program provides dedicated lanes for families at select airports
to create a welcoming environment and ease stress for families
traveling with children.
conclusion
Today, TSA is at a strategic crossroads. With continued support
from Congress and industry partners, a screening process that is more
efficient, technologically integrated, secure, and affordable to the
American taxpayer, is within our grasp. Chairman Garbarino, Ranking
Member Thompson, and distinguished Members of the committee, it is a
privilege to testify before you today.
I thank you for your support of TSA and look forward to your
questions.
Chairman Garbarino. Thank you, Ms. McNeill. The committee
will now--I will now recognize myself for 5 minutes of
questions. But I want to--because it's an oversight hearing,
and we do have--I want to make sure everybody can ask their
questions--I will entertain unanimous consent at the end like
we did last time. So we will accept them all. Just we want to
do it at the end so there's enough time for everyone to ask
questions. Because we do have a 2 o'clock--a very important 2
o'clock hearing that Chairman Guest is running. So, I want to
make sure that that starts on time as well. So I will start.
Dr. Gottumukkala, it's been a year now in the Trump
administration, and there's been some major shakeups at CISA,
specifically, with some RIFs, and there's been a lot of
changes. But the agency still remains responsible for defending
the Federal civilian networks, supporting State and local
partners, and coordinating with critical infrastructure sectors
under sustained targeting by foreign adversaries. I have said
it publicly, I know a number of Members on this committee have
said it publicly, that any organizational restructuring must
reinforce CISA's ability to execute its core mission and should
be done so in coordination with Congress.
There have been reports that there are planned
reorganization efforts for CISA. Can you please describe what,
if any, organizational changes you, as acting director, are
planning to make in the months ahead, and if there are any that
you have already done?
Mr. Gottumukkala. Chairman Garbarino, thank you for the
question. I want to start by saying that CISA is trying to get
back on its mission, which is protecting the critical
infrastructure security from physical and cyber threats. CISA
is a young agency, and we have grown. As we continue to make
sure, and as we are rescoping, as you have suggested, sir, we
do have a lot of changes in the last year. But we do not have
or planned any organizational changes. But we are continuing to
look at how we will scope our existing work that we have, so
that we can get back on our mission of protecting the critical
infrastructure. If there's any organizational changes, I will
assure that we will communicate with you.
Chairman Garbarino. So as of now, you don't have any
planned reorganizational changes that will be coming to CISA?
Mr. Gottumukkala. That's correct, sir.
Chairman Garbarino. OK. I just wanted to reiterate, you
just said you will--anything--you will be sure to notify
Congress of any intent to reorganize CISA?
Mr. Gottumukkala. Absolutely, sir. We want to make sure
that our resources are aligned with the statutory authorities
that you have given us and we'll make sure that we'll work with
you.
Chairman Garbarino. Wonderful. Do you have the proper
staffing right now to fulfill CISA's critical mission?
Mr. Gottumukkala. Chairman Garbarino, thank you for the
question. We have the staff that we need for the mission that
we want to protect. So, yes, we have--and like any other
situation, we do have attrition, we use other hiring
authorities to make sure that we go back and get back to our
mission. We are protecting the Nation now every single day.
Chairman Garbarino. You are in the process of hiring 4
specific positions right now?
Mr. Gottumukkala. We have. We obviously use other hiring
authorities that we have, sir. We are making sure that we have
the right skills and the right talent that we need across our
mission areas.
Chairman Garbarino. Thank you very much. I want to follow
up also. The Cyber Incident Reporting for Critical
Infrastructure Act, or CIRCIA, was signed into law nearly 4
years ago. I was one of the co-leads on it. The final
regulations, which were supposed to be in October 2025, the
deadline has now slipped to May 2026. I am happy with that,
actually, because a lot of us did not like what was coming out
of the rule making.
There was supposed to be a--I remember the Secretary last
year said that there was going to be possible ex parte process
to update the world. I just want to know where is CISA right
now in the rule making? Has there been an ex parte process? Are
they getting close to the Congressional intent that we had when
we passed the bill originally?
Mr. Gottumukkala. Chairman Garbarino, thank you for the
question. The CIRCIA that you are referring to, the Cyber
Incident Reporting for the Critical Infrastructure Act of 2022,
what it does, sir, is it requires the covered critical
infrastructure entities to report any significant cyber
incidents, ransomware payments to CISA, so the Government can
highly detect threats faster and assist the systems more
effectively, and be able to warn others before the attacks are
spread.
Chairman Garbarino. I'm going to interrupt you because I'm
running out of time, but I want to make sure--are you on
schedule to come out, and have you been working with the
private sector to address the concerns that came out in the
original rule-making process?
Mr. Gottumukkala. Chairman Garbarino, absolutely. We are
working really hard to make sure that we are getting toward the
closure line. We did not miss the deadline due to inaction. It
was a deliberate decision driven by a substance. Some of the
key drivers that we have worked out, 280-plus detailed public
comments. We have the stakeholder engagement that is on-going
and extensive. We want to make sure that the protection for
companies is there. We are making sure that there is not a
burden on the people that are making those requirements.
Chairman Garbarino. I appreciate it. I have run out of
time. I now recognize the Ranking Member for 5 minutes of
questions.
Mr. Thompson. Thank you very much, Mr. Chairman. I'm kind-
of taking off on where you started off with respect to CISA's
staffing. Congressman McCaul and myself supported CISA becoming
a part of DHS for all the right reasons. You said that no
organizational changes; that you're able to accomplish the
mission. How many vacancies do you have right now in CISA?
Mr. Gottumukkala. Sir, our head count as of--Ranking
Member, thank you for your question. We have about 2,400-plus
employees at CISA. We have the required work force that does
the mission support every day.
Mr. Thompson. I need the numbers. How many are you short?
Mr. Gottumukkala. We have the normal attrition like any
other Federal agency, sir, which is at 7.5 percent
approximately this past year. That is significantly less than
the previous prior years, and as compared to the other Federal
agencies as well. But, in general, we have the required
authorities to make sure that we go back to hiring authority to
be able to hire the required talent.
Mr. Thompson. I appreciate it. But your staff has been cut
by one-third. Is that not true?
Mr. Gottumukkala. Ranking Member Thompson, what we had is a
work force transition program, and people who left the
organization, they participated voluntarily. We have the
required staff that is supporting the mission like we do.
Mr. Thompson. I'm sure you're going to say that. But I'm
just trying to get to a number that you started with and what
the President cut. I mean, it should be easy for you to just
come up and say, I lost a third of my people, but I'm able to
accomplish the mission.
Mr. Gottumukkala. Understood, sir. Ranking Member Thompson,
the way--let me clarify this. As of January 20, 2025, our CISA
work force was 3,389-plus. At the end of December, we were at
2,389. We have the work force transition, like I said, and we
have the normal attrition. But like I said, the way we are
supporting background mission is to make sure that we are
protecting our critical infrastructure from physical and cyber
threats; and our divisions are properly equipped; and we are
making sure that we are aligning all existing resources----
Mr. Thompson. Thank you very much. But you provided a
November memo that said, contrary to what you're telling the
committee; we will send a letter to you asking for the specific
numbers that you're short, and just tell us. That's the only
thing.
But this leads me to another issue, since you wouldn't give
me the number that I ask. Are you aware that you reportedly
failed the counterintelligence polygraph test?
Mr. Gottumukkala. Ranking Member Thompson, I do not accept
the premise of the characterization, and I'm not going to
discuss the testing outcomes or clearance matters in an open
session. Those issues are handled through the DHS adjudication
process which are currently under way.
Mr. Thompson. Did you fail the test; yes or no?
Mr. Gottumukkala. Sir, like I said, I do not accept the
premise of the characterization. I understand why people ask
the question. I'm mindful that situations like this affect
people, which is why I'm respecting the process and keeping the
mission steady, sir.
Mr. Thompson. You're in a very sensitive area, and CISA is
important to us. I think we need to have people who are in that
space that pass the standard test. So, I mean, we will pursue
that a little later, but I was just looking for a yes-or-no
answer. If you took the test and passed it, fine. If you
didn't, that's a problem. But I can't get an answer one way or
the other out of you, and we'll go forward with that.
Are you aware of the chief information officers at CISA
that you are, at present, trying to get rid of or have gotten
rid of?
Mr. Gottumukkala. Ranking Member Thompson, thank you for
the question. Individual, personal matters are not made. The
decisions are not made in vacuum. It is a leadership level at
the highest levels. We work according to how we see the roles
fit. But I am not here to comment on them.
Mr. Thompson. I understand. The last question, Mr.
Chairman, are you aware of a SCIF being planned and paid for by
DHS to be built in South Dakota?
Mr. Gottumukkala. Ranking Member Thompson, thank you for
the question. I don't know the full specifics of who is
building, what is building, but I think it is not Federally
funded by us, which means we will probably be supporting in
terms of like any other SCIF that we have, irrespective of
where the location is.
Mr. Thompson. So you don't know anything about it?
Mr. Gottumukkala. Yes, sir, of course I know that there is
propositions for a SCIF like any other location.
Mr. Thompson. Mr. Chair, I'll follow up with some more
questions for the witness. I yield back.
Mr. McCaul [presiding]. The Chair recognizes myself for 5
minutes. I need to say, first, when I was Chairman of this
committee, 2015, we passed the Cyber Information Sharing Act--
the Ranking Member and I did together. It's been a very
bipartisan issue. In 2018, we passed the Cyber Security and
Information Security Agency permanent authorization. The reason
why I'm going through this legislative history, it's very
important to know what is still authorized today and what is
not.
One of the most critical pieces of CISA, as we imagined in
Congress, was to share information with the private sector, not
only to the private sector, but from the private sector, which
holds about 80 percent of the cyber threat information. Would
you agree with that, sir?
Mr. Gottumukkala. Yes, sir.
Mr. McCaul. Yes. So, that was vitally important as the
authors of this agency--and we had quite a battle with, I would
say, with House Intelligence over whether this should be
warehoused under the National Security Agency which is not a
civilian agency to interact with the private sector. We thought
a civilian agency would be the better fit. I would like to
think that we were right about that. But then the goal was to
expand the capabilities so that you could meet those
requirements. Do you feel that you have those capabilities
today?
Mr. Gottumukkala. Sir, the CISA 2015, the Cybersecurity
Information Sharing Act of 2015 that you're referring to, it
provides the leader foundation for cyber threat information
sharing between the Federal Government and the private sector.
It remains one of the most important authorities for defending
the U.S. critical infrastructure against increasingly
sophisticated cyber threats.
Mr. McCaul. OK. So now, let me get back to the
authorizations, because this is really important for the
committee Members to know. That now, CISA, the agency was
permanently authorized. So there's no expiration. However,
there is one on the Cyber Information Sharing Act was just
brought about by a compromise with various Members who would
not vote for it unless we put that expiration term in there.
So, as of now, it is no longer authorized. It was
temporarily reauthorized in the CR, which will expire January
30. So if I can correct myself, it will expire on January 30 of
this year.
Mr. Garbarino and Mr. Thompson introduced a reauthorization
that passed in the Homeland approps bill that did not go to the
Senate. It is not in the Homeland approps we are voting on this
week.
My question to you is: While you still have appropriations
to the majority, I think, of your agency, I think, if not all,
to not be authorized, to have a lapse in authorization, at this
point in time where the cyber threat is far greater today than
when Mr. Thompson and I first created the agency in the
Information Sharing Act, in addition, coupled with the World
Cup FIFA events coming up, the Olympics, and the anniversary or
250th anniversary of the Republic, how does that harm your
efforts to protect the Nation?
Mr. Gottumukkala. Congressman, thank you, again. Like I
said, I personally support, and DHS also supports the long-term
reauthorization of the CISA 2015. I understand that the Act
expires January 30. One of the strengths of CISA is the
partnership and collaboration with the private sector. The
private sector understands that this will be extended through
the continuing resolution.
Like we have worked with Chairman Garbarino and the
committee and the wide-spread information----
Mr. McCaul. Again, if I could--my time is going to expire,
but this is not your fault, this is Congress' fault. You know,
it is incumbent, I think the House has done its job, but the
Senate has not done their job on this.
So, it is vitally important--and this is a message to the
Senate--that when we do pass this, again, that the Senate
reauthorize your mission, otherwise your ability to collect 80
percent of the threat information from the private sector is
gone. You're no longer authorized to do that by law. So that is
why that is so important, sir. This is always--as Mr. Thompson
knows--it's always been a bipartisan issue. I really hope--and
I don't have any doubt on my colleagues on the other side of
the aisle or in the House when you get this done, but the
Senate, for the sake of the Nation and our security, needs to
act on this, is highly irresponsible, and quite frankly, just
downright dangerous what they're doing. They're playing games
with something that's very serious. With that, I now
recognize--who is next--Mr. Correa.
Mr. Correa. Thank you, Mr. Chairman. I want to thank the
witnesses for being here today. Dr. Madhu, if I may, I wanted
to follow up with some of the questions and thoughts,
directions, of the Chairman and the Ranking Member.
You said--correct me if I'm wrong--a third of your people
have left voluntarily?
Mr. Gottumukkala. About 806 people, sir, yes.
Mr. Correa. A third. It was just stated from both sides of
the aisle that the threat, cyber threat, is ever-increasing.
It's even worse now. When I go home, I get stories from local
vendors that they've been hacked. I get stories that they're
essentially being held ransom because somebody from outside the
country has got to them.
From that level up to Colonial Pipeline, cyber threats
everywhere, your agency lost a third of their staff. We're
about to vote on a bill that cuts your funding by about $270
million. Is that correct, sir? Yes, no, maybe? You're under
oath, by the way.
Mr. Gottumukkala. Congressman, thank you. I appreciate
the----
Mr. Correa. Yes or no?
Mr. Gottumukkala. I have to look, sir. We have----
Mr. Correa. You haven't looked at it, yet----
Mr. Gottumukkala. We had a Defense budget of $2.5 billion.
Mr. Correa. Are we about to cut your budget by $270
million--vote to do that? Are we, yes or no?
Mr. Gottumukkala. I----
Mr. Correa. Yes or no?
Mr. Gottumukkala. I don't have the exact number----
Mr. Correa. We are. We are. Just watch the votes in the
next couple of days. Yet you've said that you can still do your
mission, your assignment to defend this country,
satisfactorily. Is that what you're saying? Yes or no?
Mr. Gottumukkala. Congressman----
Mr. Correa. Yes or no? Do you need more resources?
Mr. Gottumukkala. Congressman, we are----
Mr. Correa. Yes or no? Do you need more resources, sir?
You're under oath.
Mr. Gottumukkala. Congressman----
Mr. Correa. Can you assure the public of this country that
based on all these cuts you've lost a third of your personnel;
we are about to your cut your budget that you can still do your
job? Yes or no?
Mr. Gottumukkala. Congressman, thank you for the question.
Like----
Mr. Correa. Yes or no?
Mr. Gottumukkala. Sir, I did----
Mr. Correa. Thank you very much. I have got 2\1/2\ minutes
left. If you could answer that to me in writing later on, I
would appreciate it.
Ms. McNeill, thank you for being here today. Quick history.
TSA, Homeland Security, Department of Homeland Security was
created as a result of 9/11. That cowardly attack on our
country that cost us thousands of lives. We don't want to see
that repeated again. If I remember correctly, hijackers,
terrorists broke into the cabin of a number of airline flights
on that day, took command, control of airplanes, and used them
as weapons against the United States. Is that correct? More or
less?
Ms. McNeill. That's correct.
Mr. Correa. Do you have the resources today to defend
against something like that?
Ms. McNeill. We do, sir. Since the establishment of TSA,
we've taken a concerted layer of approach to aviation security.
Mr. Correa. Recently--if I may?
Ms. McNeill. Yes, sir.
Mr. Correa. Reassignment of some of your personnel to ICE
and CBP over the last year. So, is that correct? You've lost
about 250 air marshals; air marshals who are randomly on
airplanes, on commercial flights, to prevent another 9/11 from
happening. Those folks are now assisting in ICE removals. Does
that not concern you? Do you think you are still OK doing your
job of defending this great country against another hijacking
attack?
Ms. McNeill. Yes, we do, Congressman. The Federal air
marshals today are more agile than at any time before they----
Mr. Correa. Well, they're agile, but do you have the
personnel to actually carry out your mission?
Ms. McNeill. Yes, and they are deployed based on risk on
our flights. They also offer ground-based security. Yes, they
do support our colleagues across DHS to advance the National
Security and Transportation Security Mission, that includes our
colleagues at ICE, as you mentioned, also the Secret Service.
Mr. Correa. If I may, I have less than half a minute left.
If you can answer this question for me in writing: You're
focused more on investment and technology. I like the focus on
trained personnel. It sounds like we're cutting back in
personnel and trying to focus more on technology. I think it's
a combination of both. But if you can explain to me how we can
assure this country, our citizens that they are safer today
than they were back in 9/11. Thank you very much, Mr. Chair. My
time is up, and I yield.
[The information follows:]
TSA has recognized that there is a need for innovative approaches,
including technology and process improvements, to enhance security
effectiveness and operational efficiency. As passenger volume continues
to grow, technology improvements will be key to maintaining passenger
throughput, hospitality, and customer service that the American public
expects at our Nation's airports.
TSA is looking at new checkpoint technology to improve efficiencies
and reducing staffing requirements. Examples of this include e-Gates
and Image on Alarm Only, where new technology will allow us to screen
more passengers with fewer officers, while continuing to maintain our
security standards.
Additionally, the fiscal year 2026 (FY26) President's budget
request (PBR) included a request to end the requirement for
Transportation Security Officers (TSOs) to staff airport exit lanes.
Currently 80 percent of all airports maintain the sole responsibility
for securing exit lanes from unlawful entry into sterile areas, while
TSA provides staffing coverage at 89 of the over 430 Federalized
airports. TSA continues to partner with airport authorities to
transition from exit lanes that require TSO oversight, to those that
utilize technological solutions to maintain access control as
opportunities arise. This has allowed TSA to reallocate resources away
from exit lane staffing to higher-priority security functions.
This shift recognizes that not all aviation security challenges
can, or should be, addressed solely through human staffing solutions.
Chairman Garbarino. The gentleman yields back. I now
recognize the gentleman from Mississippi, Mr. Guest, for 5
minutes of questions.
Mr. Guest. Thank you, Mr. Chairman.
Ms. McNeill, thank you for being here. Thank you for the
dedicated men and women who serve under your command. I
particularly want to thank you in light that those men and
women worked for a period of 6 weeks, without being paid, as my
colleagues on the other side of the aisle chose to shut down
the Federal Government. But they continued to come to work.
They continued to protect the traveling people. So, thank you
for their professionalism, for their dedication, for their hard
work, particularly in a time where you talk about, in the
statistics that you gave, that last year, passenger volume
reached record high. You say in your opening statement that 8
of the 10 busiest traveling days were last year, and that the
men and women who serve under TSA, that they screened over 906
million passengers, 480 million checked bags, and 2.1 billion
carry-on bags, all for 6 weeks without getting paid, continuing
to do their duty to the traveling public.
You also mentioned in your opening statements some
challenges, opportunities that lie ahead. Those include the
2026 World Cup, where we know that people will be coming from
across the globe to America to enjoy soccer in the World Cup
being hosted here. America 250, also next year. Then 2028, we
know that the Olympics will be held in California. Once again,
we will have individuals coming across the globe here, coming
to America to enjoy those events.
So I want to talk a little bit about--and you mentioned
this in your statement--I know this is something that near and
dear to the Chairman, the passenger security fee diversion. For
now, some 20 years, we've seen a diversion of those funds,
funds that were originally set up $5.60 for a one-way ticket;
$11.20 for a round-trip ticket for reinvestment back into
aviation security. We know that some 20 years ago, before most
of us were here in Congress, that a decision was made to divert
some of those fees. That diversion now totals roughly $1.6
billion a year. Also, in your statement, not only we talked
about the diversion of those fees, but we talk about the
Aviation Security Capital Fund which also was established some
20-some-odd years ago. Originally, $250 million was set aside
in revenue to screen luggage that is checked by passengers.
We've seen that that number has not increased now for 20 years.
You talk about the fact that we are in need of and, one,
returning those diverted fees back to TSA, putting that money
back into aviation security, which is what it was created for.
You also talk in your opening statement about the need to
increase the Aviation Security Capital Fund. So I want to give
you just a minute, if you could, to expound on both of those.
Ms. McNeill. Absolutely. Congressman, I thank you for
recognizing the work force, because seeing them turn up day in
and day out throughout that Government shutdown was nothing
short of inspiring. They kept our skies safe for the traveling
public and did so with absolute commitment to the TSA mission.
It is our responsibility to ensure that they have the best
tools at their disposal to do the job that we are asking them
to do, and that is why investment in technology is so critical.
We are facing, year over year, volume growth at our checkpoints
in infrastructure-constrained environments. The only way that
we're going to be able to maintain our security posture and
improve our security posture and deliver an increasingly
improved passenger experience is through that combination of
our human talent and technology. That is what we are looking to
work with as Congress to do to ensure that the Passenger
Security Fund is used for those purposes.
I would say that there are several different buckets of
technology advancement that we would want to ensure that we are
investing in. One is that cutting-edge screening technology at
the checkpoint that we all experience when we fly through the
airports, making sure that that is detecting threats adequately
as we face an evolving adversary and threat environment.
Second is around identity verification, right. One of the
cornerstones of our aviation computer security system is
knowing who is coming through our checkpoints and doing that
adequate vetting so we know who they are before they even show
up. Then, third, is really bringing our checkpoint into the
21st Century and providing that IT infrastructure so that we
can really drive improvement on a continual basis to our
checkpoints.
Mr. Guest. Ms. McNeill, thank you. My time has expired. I
yield back.
Chairman Garbarino. The gentleman yields back. I now
recognize the gentleman from Michigan, Mr. Thanedar, for 5
minutes of questions.
Mr. Thanedar. Thank you, Chairman, and thank you Ranking
Member for this hearing.
Ms. McNeill, I have the honor of representing Detroit Metro
Airport, Michigan's busiest airport, and one of the largest
airline hubs in the world. Given that I represent Detroit,
which prides itself on its long history of blue-collar
contributions to our great Nation, you must also know that I am
a strong supporter of unions, organized labor, and collective
bargaining rights.
In March, TSA announced it will be stripping the collective
bargaining rights through the American Federation of Government
Employees, or TSA personnel, but it was blocked by the courts.
In December, TSA tried, again, to strip collective
bargaining rights and were again blocked by the courts. Earlier
last year, you were questioned regarding the role of TSA and if
you believed that TSA should be privatized. You said that
nothing is off the table.
In July, TSA announced it would be seeking private-sector
assistance for the development and deployment of turn-key
solutions for use at the airport security checkpoints. Many
speculate that this announcement means that the TSA is seeking
to replace its personnel with private-sector security, a common
union-busting tactic.
Ms. McNeill, I have very little time, so just a yes-or-no
question, do you value the work of our hardworking TSA
personnel?
Ms. McNeill. Thank you, Congressman, for that question.
Yes, absolutely. In my opening statement, I stated that TSA's
greatest assets are its people.
Mr. Thanedar. Now, if you believe that their work is so
valuable, why are you seeking to make their jobs harder by
getting rid of collective bargaining rights, which will help
them with job security, safe working conditions, and ensuring
accountability in the workplace?
Ms. McNeill. The existence of a collective bargaining
agreement is inconsistent with the mission that TSA has to
perform and the agility with which we need to run this agency,
and our employees know that. Actually, the accountability of
ensuring that we don't have 200 personnel that are doing
nonscreening work is in place, and returning them to the
checkpoint is actually better for our employees and the morale.
Time and again----
Mr. Thanedar. This is hardworking men and women taking----
Ms. McNeill. Yes, they are.
Mr. Thanedar. It's a very stressful environment. They do
their best to work as hard as--to keep America safe.
Look, it is a fact that work force morale and retention
increased significantly since the Biden administration expanded
bargaining rights. The move to end collective bargaining rights
is wrong, and I look forward to the courts to continue to block
these attempts to harm the workplace rights of our Nation's
workers.
Now, while I appreciate the TSA workers working so hard, I
kept hearing a video that was--kept showing every time I'm
crossing the TSA line.
Ms. McNeill, in October a video of Secretary Noem blaming
the Government shutdown on Democrats aired at TSA checkpoints
across the country.
As I am sure you know, this was a blatant violation of the
Hatch Act, which bars partisan activity using Government
resources. It also violates the Antideficiency Act, which
prohibits Federal agencies from spending funds beyond what
Congress has appropriated since the TSA was operating without
funds at the time.
Ms. McNeill, why did you allow these blatantly political-
charged videos to play at TSA checkpoints across our country?
Ms. McNeill. Our responsibility at TSA is, in part, to
inform the traveling public of what they can expect when they
arrive at our checkpoints. During the longest Government
shutdown, that was absolutely necessary to ensure that they
understood the environment that they were coming into and the
facts behind that environment.
The Secretary is very supportive of the TSA work force and
our mission----
Mr. Thanedar. I have just a little bit of time.
Chairman Garbarino. You have no time. The gentleman's time
has expired.
Mr. Thanedar. Thank you.
Chairman Garbarino. I now recognize the gentleman from
Florida, Mr. Gimenez, for his 5 minutes of questions.
Mr. Gimenez. Thank you very much, and I'll try to keep this
brief.
Ms. O'Neill, have we ever had the capacity to put an air
marshal on every single domestic flight in the United States?
Ms. McNeill. The deployment of Federal air marshals----
Mr. Gimenez. Yes or no, have we ever had the capacity to
put an air marshal on every single flight in the United States?
Ms. McNeill. No. That is not----
Mr. Gimenez. No. OK. That would be--same as me as a fire
chief closing down a fire station every once in a while and
hoping a fire didn't happen in that area. So that's what I feel
about the air marshal program. We're going to have to have a
lot more conversation about the air marshal program in the
future. I don't have time right now.
Second thing, Mr. Gottumukkala--I'm sorry if I butchered
your name, sorry--where does the Secretary of Homeland Security
reside?
Mr. Gottumukkala. In the NCR region.
Mr. Gimenez. I think she's from South Dakota. OK? Don't you
think that as the Secretary of Homeland Security, every once in
a while she's going to need access to a SCIF? Yes. Thank you.
All right. Now back to Ms. O'Neill. I don't represent an
airport. I actually ran one, OK? As a mayor of Miami-Dade
County, I ran Miami International Airport. So airport security
is really important to me.
We talk about passenger fees and all that, and if we--if we
use the schedule you have right now, by what year are we going
to have the things that you think are vital to our Nation's
security installed in all our airports?
Ms. McNeill. At the current pace of funding, Congressman,
for our computer tomography technology, we're looking at 2042
and our credential authentication by 2049.
Mr. Gimenez. Two thousand forty-nine. I hope I'm alive. I
don't know. It's kind-of getting close. OK.
So how do they fund these security measures in Europe?
Ms. McNeill. In Europe, it's a vastly different construct
than--than here in the United States. The regulatory body set
the standards and put the requirements on the airports to----
Mr. Gimenez. That's right. They put it on the airports. You
know why they put it on the airports? Because they can get it
done. All right? We're not going to get it done because we have
fiscal constraints.
So let me tell you how an airport works. An airport
decides--in the beginning, the budget, what happens is what is
it that we need in order to operate this airport? There's a
number. Then after that, they go, OK, how do we attain that
number? Well, they attain that number through passenger fees,
landing fees, concessions, et cetera, because there's revenue
that comes into the airport and then they balance.
So if we were to set the standards for what we believe we
need to secure the American public, I think it would make a
heck of a lot more sense for us to say the airports, because
we're actually doing this for you, and the airport--and the
traveling public, et cetera, to make it safe--which, by the
way, if we make it unsafe and people don't travel by air
anymore, it's an unbelievable economic impact on the United
States.
The No. 1 economic generator of Miami-Dade County is Miami
International Airport, and I'm sure that in other communities
around this country, the No. 1 economic generator is probably
their airports. I bet you, you know, bottom dollar that in
Atlanta, for sure, OK, the No. 1 economic generator is the
airports; Chicago probably, too; New York, the 3 airports, too.
So why don't we use the European model? Why don't we tell
the airports what they need to purchase. They will figure that
into their--into their budgets, finance it, and then give those
assets over to--to us, which some airports do when they want to
actually be a little ahead of the game. Isn't that correct?
Ms. McNeill. We--yes. We have great partnerships with
airports across the country, and we have put in place several
different ways for which airports can drive investment to their
checkpoints, and we have a capability acceptance program where
airports can essentially donate qualified equipment to TSA so
that we can upgrade the equipment at the checkpoint.
That, combined with appropriated funds and looking to
improve programs like the Screening Partnership Program, allow
us to provide options to airports on how to drive that
investment. I'm a big believer in public-private partnerships.
Like you said, airports are major economic engines of the
community around them, and this should be an all-hands-on-deck
approach, and we are an important part of that. Our
partnerships are actually--absolutely critical to advancing
that.
Mr. Gimenez. By the way, we divert a lot of what's supposed
to be used for security to other purposes. The passenger
security fee, which is supposed to be----
Ms. McNeill. Annually, about $1.6 billion.
Mr. Gimenez. Right, which is supposed--which, when I pay a
passenger security fee, I expect it to be used for passenger
security and not to help balance the Federal budget, which is
what we do here. All right. So I don't think we're going to be
able to solve that.
So, Mr. Chairman, I'm going to be introducing legislation
to change the way that we fund security at the airports, more
like the--more like the European model, and so, finally, we
can--we can get the security that we need at our airports
before the year 2049.
Thank you. I yield back.
Chairman Garbarino. Gentleman yields back. I now recognize
the gentleman from Rhode Island, Mr. Magaziner, for 5 minutes
of questions.
Mr. Magaziner. Thank you, Chairman.
On a Saturday morning in Cicero, Illinois, a young couple
got in the car with their 1-year-old child and drove to a Sam's
Club to go grocery shopping. When they arrived, they saw a
large law enforcement presence, some sort of an operation going
on in the parking lot, and so they turned their car around to
leave.
As they were leaving the Sam's Club parking lot, this
happened. Please show the first video.
[Video shown.]
Mr. Magaziner. Do you know how dangerous it is to spray
pepper spray into a moving vehicle? Not only could that kill
the people inside the car, it could kill other drivers and
bystanders who might be hit by the vehicle.
There is not a law enforcement agency in this country that
teaches its officers to do that. In fact, in most law
enforcement agencies, those officers will be fired, but not in
Donald Trump's Department of Homeland Security.
We don't know who these officers were or if they were
disciplined in any way. All we know is that the White House
keeps telling them that they have ``absolute immunity.''
Absolute immunity, pepper spraying a young family in a moving
vehicle.
Whenever we call attention to these kinds of abuses, the
first thing the administration does is try to blame the
victims, but this is a family of United States citizens. They
weren't even protesting. They were just out to get groceries.
This keeps happening again and again and again. Show the
second video, please.
[Video shown.]
Mr. Magaziner. What was the response of the Homeland
Security Department leadership after this? Did they express
remorse? Did they suspend the agents or launch an
investigation? No. They put up a false tweet blaming that
family, the victims, calling the Jackson family ``radical
agitators.''
Now, unlike a lot of the victim-blaming tweets that the
administration posts, they actually took that one down because
it was so indefensible.
But why was it put up in the first place? What does it say
about the rotten culture at the Trump Department of Homeland
Security that, when American citizens are hurt by Federal
agents, the response is to immediately blame the victims before
you even know the facts?
Now, we can keep going and going. These are just a couple
of examples. I know that this hearing is supposed to be about
TSA and cyber, which is important, but when the Federal
Government is sending poorly-trained masked agents into the
streets beating and gassing peaceful people, including American
citizens, we cannot pretend that this is normal and act like it
should be business as usual.
We need real standards in place, just like every other law
enforcement agency in the country has, to make sure that
Federal agents are well-trained, do not use excessive force
when not warranted, and are held accountable when they do
things like tear gas a family inside a moving vehicle. This has
to stop.
I yield back.
Chairman Garbarino. Gentleman yields back.
I now recognize the gentleman from Texas, Mr. Gonzales, for
5 minutes of questions.
Mr. Gonzales. Thank you, Chairman. Thank you, panelists.
Director, Dr. Gottumukkala, this--you know, CISA isn't a
small little agency that you just go to retire at. It's
arguably one of the most important agencies in our Government
that most people don't realize what's happening.
This year, I would argue one of the biggest things that's
going to be in your purview is going to be the selection. It's
going to determine the future not only of our country, but also
the future of the world in general.
So midterms elections, my question to you is, what is CISA
doing to ensure our midterm elections are safe, secure, and
fair?
Mr. Gottumukkala. Congressman, thank you. We--election
security is very important for national security and somehow
the claim that DHS CISA has rolled back election security
protections is not accurate.
We treat election security like any other critical
infrastructure sector and our election security services remain
fully in place, including cybersecurity support that we
provide, the physical security guidance provided. There is the
incident response that we provide, and also the threat
briefings for the State and local election officials.
The election infrastructure owners and operators continue
to receive the same level of support as other critical
infrastructure entities. So the--what changed was the scope,
not the security, sir.
We ended activities that were outside its core mission but
not election protections itself, and the election security is
focused on the infrastructure by all means.
What it means is we are exclusively focused on defending
the election infrastructure from any cyber threats, any
physical threats, and also any foreign adversaries that are out
there.
As you may know, sir, foreign threats remain a core
priority for us. The nation-state adversaries continue to pose
risks to our election infrastructure. CISA, we are providing
that threat intelligence, we are conducting the vulnerability
scanning to all our State and local infrastructure owners, and
we are making sure that we are coordinating that incident
response across the board.
Election security remains integrated into CISA's broader
cyber and physical security mission, sir.
Mr. Gonzales. I ask that you make that a top priority,
because it's a top priority for many Americans. You know, you
can win an election, you can lose an election, but it has to be
fair and has to be secure, and our adversaries don't want that.
My question to you is, how many cyber intrusions do we
expect this midterm election?
Mr. Gottumukkala. Sir, we--we look at it as incident by
incident, and we look at what the risks are. I don't have a
specific number in mind.
Mr. Gonzales. Well, we should have that number. We should--
it should first start by how many intrusions did we have last
midterm and the midterm before that and the midterm before
that. I don't want us waiting until after the fact to be able
to go, Yes, we got it wrong, and it turns out our adversaries
influenced our election.
To that point, what actions is CISA doing to work with
other partners, like CYBERCOM, to ensure that these--these
adversaries are not intruding on our election?
Mr. Gottumukkala. We have a very good working relationship.
Our strength is collaboration. We want to make sure that we're
working with our law enforcement and cluster intelligence
partners across the country and international partners to make
sure that we are safe.
Mr. Gonzales. CYBERCOM in particular, is CISA working with
CYBERCOM on any cyber offensive actions to prevent our
adversaries from interfering in our elections?
Mr. Gottumukkala. Congressman, thank you. We work with
CYBERCOM on threat intelligence sharing and making sure that we
have the incident response and we are working with the private
and stakeholder communities to make sure that threat
information is shared.
Mr. Gonzales. OK. We need that to be a priority. That needs
to be a priority.
Between CYBERCOM and CISA, you two are the two
organizations that are going to keep this Nation and our world
safe to ensure that these elections are fair and secure.
To that point, what actors--what actors--what state or non-
state actors are the most aggressive in interfering with our
elections?
Mr. Gottumukkala. Congressman, thank you. I think the
threat actors continue--the foreign state adversaries,
especially the People's Republic of China and Russia, seems to
be the most adversive nation-state actors. The strategic
adversary is China. They are long-term, and they have patient
campaigns focused on prepositioning in our critical
infrastructure for a strategic advantage.
As you might have seen with Volt Typhoon and Salt Typhoon,
they are both PRC state-sponsored campaign focused on
repositioning themselves inside the U.S. critical
infrastructure for potential disruption for a future crisis.
Unlike the traditional espionage, these actors use living-off-
the-land techniques.
Mr. Gonzales. Director, I have 10 seconds left.
What I'd say is, you just said everything that everyone has
ever come before this committee and said. The same actors over
and over and over again. So it's no surprise that these actors
are going to be involved. They were involved in the last
election, they'll be involved in this election, they'll be
involved in every election going forward.
What I ask is, instead of the United States playing
defense, it's long time we play offense and prevent these bad
actors from influencing our elections.
With that, Chairman, I yield back.
Chairman Garbarino. Gentleman yields back.
I now recognize the gentlelady from Illinois, Mrs. Ramirez,
for 5 minutes of questions.
Mrs. Ramirez. Thank you, Chairman. I do have a number of
articles I want to enter into the record at the end.
So as a Chicagoan, I know the terror that DHS can inflict
with unlimited resources and unchecked power. You just saw some
of that with what Congressman Magaziner just showed.
Our constituents are being surveilled, they're being
threatened, they're being tear-gassed, and subjected to
warrantless arrests, rammed with vehicles. They're being
kidnapped, and you've seen it, they're also being disappeared.
Yet, those--there are those in Congress who would still expand
DHS's budget and ICE capacity to enact Trump's mass deportation
agenda.
So, I often get asked back in my district, how is this
possible? How is it that they can behave this way? How can they
tear gas a 6-month-old baby? Isn't Congress supposed to be a
check on DHS?
Well, first, I say to them, that would require my
Republican colleagues to agree that bringing senior ICE
officials to testify before this committee is critical. I do
hear, Chairman, that that may happen in 6 weeks or so. I think
it's far too late; they should be here right now.
Second, that would also suggest that DHS is behaving in
ways outside its design. Now, let me be clear. DHS and ICE,
it's not rogue. Let me tell you why.
Because from its establishment, Congress empowered DHS to
violate our rights under the pretense of securing our safety.
Who feels safe right now under DHS? DHS was intentionally
established with an overbroad mission, an unchecked power,
which has been expanded by Republicans with a blank check,
unlimited personnel, and no guardrails whatsoever.
Trump, with his authoritarian tendencies, is only making
visible what so many communities have already known to be true.
DHS is a threat to our collective safety and funding it only
fuels our destruction and our human suffering.
It's why 32 people have died in detention in ICE's
deadliest year yet. U.S. citizens are being shot and killed,
and the agency doesn't even know who they're hiring and doesn't
seem to even care who they're hiring. Yet, Trump's campaign
donors are profiting off the pain of our neighbors, including
children.
So today, I say enough. I am introducing today the Melt ICE
Act that would prohibit DHS from using funds to detain or
monitor immigrants, effectively limiting ICE's authority and
ability to continue to cause pain and terror, while redirecting
the funding that they have, taxpayer dollars that they're using
to kill U.S. citizens, back into the communities impacted by
ICE's terror through wraparound services, because we know that
DHS is being used as a weapon to be pointed toward anyone the
Government considers a public enemy. Fascism always requires a
public enemy.
So we must take the weapon away and hold those who have
allowed our communities to be terrorized accountable.
So let me get to the witnesses here. My understanding is
that your agencies are working with ICE in some capacity under
the Trump administration. Ms. McNeill, is your agency sharing
data with ICE, yes or no?
Ms. McNeill. Absolutely. We are part of the----
Mrs. Ramirez. Got it.
Ms. McNeill [continuing]. Department of Homeland Security,
and that's what we do.
Mrs. Ramirez. Yes or no, that's it. Thank you.
Ms. McNeill, I have a follow-up question for you. Why is
TSA making life miserable for people that have every right to
travel domestically and who pose no threat to aviation instead
of focusing on your security mission?
Ms. McNeill. I don't agree with your statement, ma'am. As
we have seen, the men and women of TSA are absolutely dedicated
to the transportation and national security mission, and that
was very apparent during the 43-day shutdown where they
continued to show up to work while we waited for funding to
come----
Mrs. Ramirez. Thank you, Ms. McNeill. It is clear that
people are living in fear, and TSA is working with ICE to
terrorize our communities.
Dr. Gottumukkala, has your agency taken personnel off
mission to work for ICE? Let me add to that, that includes
details and reassignments from your agency to ICE or CBP, as
well as to the Federal Protective Service and U.S. Marshals in
communities with ICE enforcement operations. That's a yes-or-no
question.
Mr. Gottumukkala. Congressman, not in my times at----
Mrs. Ramirez. So in the last year, your agency has not
taken personnel off mission to work for ICE? Yes or no?
Mr. Gottumukkala. Not in my time, ma'am.
Mrs. Ramirez. OK. I'll have something into the record that
indicates the opposite.
So let me ask you another question. Does it concern you
that your personnel might already have staffing shortages, as
we just heard a moment ago, over a third in staff shortages,
yet the administration is asking for your staff to be used for
ICE enforcement?
Mr. Gottumukkala. Congressman--Congresswoman, I think the--
--
Mrs. Ramirez. Does it concern you, yes or no?
Mr. Gottumukkala. We are on mission. We are doing all the
cyber from----
Mrs. Ramirez. Let me ask you a follow-up question to that.
Has your agency transferred funding to ICE, yes or no? Has
any of your funding gone to ICE, yes or no?
Mr. Gottumukkala. Congresswoman, I--we--not in my time.
Mrs. Ramirez. The answer is yes, my time is up.
Chairman Garbarino. Gentlelady's time has expired.
I now recognize the gentleman from Alabama, Mr. Strong, for
5 minutes of questions.
Mr. Strong. Thank you, Chairman Garbarino, Ranking Member
Thompson.
As my colleagues have noted, the United States is entering
a period marked by high-profile special events that increase
global travel, underscoring the importance of readiness across
the homeland security enterprise. Thank you to our witnesses
and their teams for their work to meet these challenges.
Mr. Allende, within the Science and Technology Directorate
R&D portfolio, where does the threat posed by unmanned aerial
systems and Counter-UAS capabilities rank as a priority?
Mr. Allende. Thank you, Congressman, for your question.
I think it's very high on our high-priority list. That's
exhibited by Secretary Noem's creating a program executive
office within S&T that brings together both the policy and the
R&D aspects, acquisition support aspects to handle the Counter-
UAS mission, particularly in a speedy manner as we approach the
FIFA World Cup, L.A. 2028 Olympics, and America 250.
Mr. Strong. Given the rapid evolution of drone technology,
how is S&T keeping its Counter-UAS research ahead of its
threats?
Mr. Allende. Thank you, Congressman, for the question.
At present, our focus is getting to speedy delivery of
systems in the field in preparation for these events. So we're
providing technical review and assistance to our partners to
ensure that the right systems that work well get out into the
field to prevent the threats.
We are also doing a number of testing, development, and
evaluation efforts to look at new technologies that may help
change the game for us. But at present, given the short time
frames, the thrust of our effort is getting delivery out into
the fields.
Mr. Strong. OK. My district is home to the joint S&T, FBI,
and TSA TIDE Center, as well as the FBI's Terrorist Explosive
Device Analytical Center. These centers work closely together
to protect our homeland and stay ahead of potential threats.
How does the FBI's expertise inform S&T's efforts at TIDE,
and how does the collaboration enhance TSA's implementation of
effective screening technologies?
Ms. McNeill. Thank you for that question.
We--as an agency, focused on delivering transportation
security, the traveling public are always focused on looking at
cutting-edge technologies and how to advance those in
collaboration with our partners at S&T and across the U.S.
Government.
The evolving threat requires us to always evolve our
posture, and that includes technology. So, you know, we look
forward to our continued partnership across DHS to ensure that
we're meeting that mission, but also to work with this
committee and Congress to ensure that we've got the funding to
be able to deploy that technology into the hands of our
operators.
Mr. Strong. Thank you. Dr. Gottumukkala--how do you say it?
I won't ask again.
Mr. Gottumukkala. You're good, sir. You can call me with my
first name.
Mr. Strong. Dr. G, there we go.
CISA was created by Congress with bipartisan support to
protect national security. Unfortunately, the Biden
administration transformed an agency once focused on cyber and
foreign threats to critical infrastructure into an
unaccountable censorship agency that pressured social media
companies to take down speech protected by the First Amendment.
Can you confirm that CISA has stopped those policies of
policing American speech and returned to its authorized mission
scope?
Mr. Gottumukkala. Congressman, thank you for the question.
I mentioned earlier what changed was the scope, not
security. CISA ended all the activities that were outside its
core mission, not election protections. The activities that
ended involved monitoring any American's lawful speech, any
narrative management, or any coordination with those social
media companies on election-related posts.
Those activities are not operational election security
services, so we ended abuses, not any protections that we do
with elections.
Mr. Strong. You said earlier--and I quote--``CISA is trying
to get back on mission.''
For the record, during the Biden administration, what got
CISA so off its core mission?
Mr. Gottumukkala. Congressman, thank you for the question.
As part of this administration and under the guidance of
Secretary Noem, we are reviewing, line by line, on all the
items that we do, and we are eliminating any redundancy. We
have eliminated duplicative oversight roles, and we have
consolidated fragmented IT support structures.
We unified a lot of fragmented IT functions under one
office. We eliminated overlapping IT operations. We removed
over 300-plus duplicative contractor roles. We modernized some
of the enterprise IT environment.
Mr. Strong. Thank you. My time has expired. I thank you.
Mr. Chairman, I yield back.
Chairman Garbarino. Gentleman yields back.
I now recognize the gentleman from New York, Mr. Kennedy,
for 5 minutes of questions. Sorry about those Bills, buddy.
Mr. Kennedy. Yes, we are in pain with Bills Mafia. Thank
you.
We're here to talk about some very important issues here,
Mr. Chairman. I want to thank you for bringing this committee
together today.
But I am terribly disappointed both by the answers that I'm
hearing, or the lack thereof answers, as well as the lack of
ICE being here with us to answer some very serious questions.
They should be here testifying under oath, answering pressing
questions that all of us have.
This committee needs answers from ICE. The people of this
country need answers of what is happening across this Nation.
Like what happens to families like Renee Nicole Good's who are
left with a massive hole in their hearts because of this
administration's lawlessness?
What credibility can investigation into this tragedy
possibly have if it ends as quickly as it begins and
scrutinizes everyone in Minneapolis except for the agent who
shot her?
How many U.S. citizens and lawful residents have been swept
up in the Trump administration's immigration raids? How many of
them have seen their due process rights, those enshrined in the
U.S. Constitution, willfully ignored?
Why is Secretary Noem taking no responsibility for the
violence she has brought to our communities? How much farther
is she willing to go to destroy the American dream as we know
it?
What critical DHS missions are being neglected at the
expense of Secretary Noem's extreme immigration agenda?
That last question, I'd like to ask the witnesses in detail
about reassignments away from your respective agencies and
immigration enforcement missions.
We know that Secretary Noem has taken thousands of Federal
personnel from their assigned duties, and it's felt acutely in
my community in Western New York. My district has four bridges
that connect New York and Canada, and yet, many of these travel
processing booths are empty because Secretary Noem is diverting
resources from Northern Border communities. This drives up
costs, takes away good-paying jobs, deters travel with our
closest ally to the north, and makes things less safe.
So I understand both CISA and TSA have had employees
reassigned to oversee the Trump administration's immigration
and deportation operations, along with its Draconian crackdown
on Americans exercising First Amendment rights.
So, Acting Director Gottumukkala and Deputy Administrator
McNeill, how many people from CISA and TSA have been
reassigned?
Mr. Gottumukkala. Congressman, not to the knowledge of--I
don't have the knowledge of any people from CISA.
Mr. Kennedy. But your agency has been cut by over a third?
Mr. Gottumukkala. The team participated in a voluntary--the
work force transition program, and we are working toward our
own mission of making sure that we are protecting the critical
infrastructure from cyber and critical threats.
Mr. Kennedy. Ms. McNeill, how many of your employees have
been reassigned?
Ms. McNeill. I'm not aware of any of our employees being
moved over to ICE.
Mr. Kennedy. Two hundred fifty air marshals, you've
testified today, are--have been reassigned. Is that accurate?
Ms. McNeill. That is not a reassignment. The Federal air
marshals are providing in-flight security for deportation
flights, which is actually--falls within their mission space.
Mr. Kennedy. So outside of commercial flights----
Ms. McNeill. That's what they do is provide flight
security.
Mr. Kennedy. Outside of commercial flights, they have been
resigned to other flights--250 air marshals have been
reassigned.
How can we assure the American people that flying in this
country is safe post-9/11 if the air marshals that have been
provided to do the work to keep them safe in the skies have
been reassigned off of those commercial flights?
Ms. McNeill. Providing in-flight security for deportation
flight keeps our skies safe. I don't think that your number is
accurate, Congressman, but we're happy to make sure that we get
you that number.
[The information follows:]
As part of their regular mission scope Law Enforcement/Federal Air
Marshal Service (LE/FAMS) has provided approximately 100 Federal air
marshals (FAMs) on a rotating basis to provide security on select ICE
Enforcement and Removal Operation (ERO) domestic transfer and
deportation flights. These FAMs are not reassigned to ICE but perform
in-flight security and other law enforcement functions that align with
LE/FAMS' existing in-flight security mission.
Mr. Kennedy. I believe that's the number that was mentioned
in this testimony today.
Do you believe the TSA employees have the right to
organize, Ms. McNeill?
Ms. McNeill. As I stated earlier, the administrator has--
has the authority to set the terms and framework of employment
of the TSO work force, and we need to do so in a way that keeps
in mind the mission of TSA which was granted by Congress----
Mr. Kennedy. Is that a yes or a no?
Ms. McNeill [continuing]. That we have a work force to
deliver to the American people.
Mr. Kennedy. Do you believe that the employees that keep
our skies, our communities safe have a right to organize in
this country?
Ms. McNeill. I think that is----
Mr. Kennedy. Yes or no?
Ms. McNeill [continuing]. Determined by--by the
administrator. Actually, what we are focused on is delivering
aviation and transportation security for the American people
and being a good steward of the taxpayer.
Mr. Kennedy. Yes. I will take that as either a nonanswer
or, quite frankly--sounds like a no to me, which is very, very
disappointing, disheartening not just to this panel and to this
committee, but to the rank-and-file working families that are
out there protecting us each and every day.
It is their right in this country to organize if they
choose to do so, and quite frankly, it is an obligation of this
Government to work with them in a collective bargaining
scenario to provide them the rights that they deserve.
I yield back.
Chairman Garbarino. Gentleman yields back.
I now recognize the gentleman from Arizona, Mr. Crane, for
5 minutes of questions.
Mr. Crane. Thank you, Mr. Chairman.
I want to start by pushing back against my colleagues on
the other side. You know, it's interesting to me, I've only
been in Congress for 3 years now, but they clearly created this
catastrophe. We warned about it in the last Congress, why the
Southern Border was wide open, and many of our visa programs
were being completely exploited, and now you have 15 million
people in the country. That's a figure they won't even argue
with.
Now the American people elected President Trump and this
administration to go and solve the problem. Now--so they've
turned on ICE, whose job is to get the criminals and these
people out of the country, and so they've turned on ICE. We
even have a Member on this panel, again, who assaulted an ICE
agent, and we wonder why this stuff continues to happen.
I didn't hear any of them talking about the deportations
that took place under President Obama, who I believe was
deporting even more people than President Trump has in his
first year.
Next I want to turn what this committee is actually about,
and I want to start with CISA. Dr. Gottumukkala, under the
Biden administration, censorship, deplatforming, and flagging
speech of Americans they didn't like was very common and often
reported. They censored American citizens who were posting
about election integrity. They were also deplatforming anybody
who talked about COVID-19 and its origins.
What is--correct me if I'm wrong, Doctor, but I thought
CISA was for, you know, protecting American infrastructure and
cybersecurity. Is that correct? Why do you think CISA started,
you know, going after Americans for exercising free speech?
Mr. Gottumukkala. Congressman, thank you for the question.
You'd have--election security is focused on infrastructure,
and CISA's election security is focused exclusively on
defending the election infrastructure from cyber threats and
physical threats and foreign adversaries. That includes any
voter registration systems, election technology, and supporting
systems, not speech or content moderation.
Precisely why I keep saying is that watching was the scope,
not the security. We ended activities that were outside its
core mission and not election protections. Those activities
that ended involved monitoring any Americans' lawful speech and
narrative management, and like you said, sir, coordination with
social media companies on election-related posts. Those
activities are not operational election security issues.
Mr. Crane. Thank you. Sorry I got to cut you off. I got
more questions.
I want to turn to Ms. McNeill with TSA. On July 8, TSA
ended its shoes-off policy, which was obviously in place
because we had incidents like the shoe bomber that tried to
bring a bomb in his shoe on board an airplane.
Why was that policy ended, Ms. McNeill?
Ms. McNeill. Thank you for the question, Congressman Crane.
At TSA, we're continually looking at the risk environment
that we operate within and improving our standard operating
procedures and operations at the checkpoint to reflect that
risk picture. There had been multiple risk assessments done in
past years that allowed us to make that change and amend our
procedures to maintain the safety of the skies, while
delivering for the American public continual improvement is
something that, you know, TSA embraces and----
Mr. Crane. Ms. McNeill, real quick, do you think with
technology adapting, it's impossible for somebody to make a
bomb out of their shoes?
Ms. McNeill. The way that we approach security is to deploy
multiple different layers of security and pieces of technology
to ensure that nobody can, essentially, game the system. We
have multiple layers from identity and vetting through all of
the physical screening that happens at the checkpoint and then
in-flight security as well.
So through that layered security approach is how we deliver
for the American public, and that's something that, you know,
has been in place since the inception of TSA.
Mr. Crane. Thank you. I want to turn to some of the Somali
cash going through airports.
It's estimated that $700 million in cash in passenger
luggage was leaving the Minnesota airport in the last 2 years.
Has TSA made any changes to its policies to prevent this
activity that is tied to the fraud in Minnesota from continuing
on?
Ms. McNeill. We are extremely proud of the team at TSA for
highlighting this issue, by reporting what they saw in the
normal course of their screening in Minnesota.
Mr. Crane. But reporting is not enough, right? It continued
to go on, and we got $700 million in cash. Has anything been
changed? That's the question I asked you to stop this from
happening.
Ms. McNeill. We are working with our interagency partners
and law enforcement partners to ensure that this issue is being
addressed. We continue being a good partner to them.
The money that was moved through, was moved through through
legal means, and so, this is where I think Congress has a role
to play to think about the authorities around--around this bulk
cash movement.
Mr. Crane. Thank you. I yield back.
Chairman Garbarino. The gentleman yields back.
I now recognize the gentlelady from New Jersey, Ms. McIver,
for 5 minutes of questions.
Mrs. McIver. Mr. Crane, I don't know what your obsession is
with me.
Mr. Crane. I thought you were supposed to address the
Chair?
Mrs. McIver. But I am so tired of you mentioning me.
Mr. Crane. Mr. Chairman, is she supposed to address me or
the Chair?
Mrs. McIver. You can take that obsession and you can put it
to the people of Arizona, not me. My name----
Mr. Crane. Yes. Well, If you quit assaulting ICE agents----
Chairman Garbarino. The committee will come to order.
Mr. Crane [continuing]. Then I wouldn't keep bringing you
up.
Mrs. McIver. I am reclaiming my time. I am reclaiming my
time.
Chairman Garbarino. The committee will come to order.
Mrs. McIver. Watch your mouth when you're talking----
Mr. Crane. Follow the rules of the committee, Mrs. McIver.
Chairman Garbarino. Come to order.
Mrs. McIver. Excuse me. I'm reclaiming my time.
Thank you, Mr. Chairman and Ranking Member. Let me get to
the business that I'm here for, for the people of New Jersey,
not Mr. Crane. Thank you for holding today's hearing.
Here we are 3 weeks into the new year, and finally, we're
having our first full committee hearing in more than a month.
During that time, the lawlessness of DHS under Donald Trump and
Kristi Noem has increased tenfold.
Just last week, a parent in my home State of New Jersey was
detained by ICE after ordering food for his 6-year-old
daughter. When her dad didn't come home, the little girl was
then found crying and wandering around for hours outside
parentless. How inhumane.
Like I told Secretary Noem when she sat in this room last
month, the greatest threat to the homeland right now is the
Department of Homeland Security under her control.
Unfortunately, the Republicans, like Mr. Crane, in control of
Congress are not up to the task.
In the face of the administration's appalling escalation of
violence, the Majority has set up this hearing with a random
assortment of DHS leaders who are not the ones we really need
to hear from in this moment. I join my colleagues in demanding
that we bring ICE's acting director, Todd Lyons, before the
committee as soon as possible, respectfully, Mr. Chairman.
That would be just the start of providing the
accountability and change our constituents are demanding of us
right now in this moment. Now, since having administration
witnesses is a rarity this Congress, I do want to talk a bit
about TSA.
Acting Administrator McNeill, I want to note that I am the
top Democrat on the Transportation and Maritime Security
Subcommittee, but this is the first time we have met. In fact,
this is the first time we have had a single TSA witness before
the full committee or any subcommittee this Congress, even as
the Majority is embarking on an effort to reauthorize the
agency.
Ms. McNeill, as with other DHS components, this
administration has been lawless in its direction for TSA. Last
month, Secretary Noem tried to abolish the work force's
collective bargaining rights in a blatant defiance of a court
order to keep them in place.
My fellow Democrats and I wrote to the Secretary and to you
to demand that you halt those efforts, and I am glad that a
court has since ruled that those efforts are, in fact, illegal.
However, we still did not hear from you.
Ms. McNeill, I recognize you have no control over Kristi
Noem's lawlessness and cannot speak to whether she will
continue to break the law. But speaking for yourself in this
moment, yes or no, will you commit to abiding by the court
order to keep TSA's collective bargaining agreement in place
and fully honor its provisions?
Ms. McNeill. Every step that the Secretary and that we have
taken has been in compliance with the courts.
Mrs. McIver. Is that yes or no? I'm speaking on behalf of
you, not Secretary Noem.
Will you commit to that? Will you commit to the----
Ms. McNeill. The Secretary and I have continued to be in
compliance.
Mrs. McIver [continuing]. Provision? Will you commit to the
provision as the acting administrator, yes or no?
Ms. McNeill. We are--we are both--both the Secretary and
myself are committed----
Mrs. McIver. OK. I'll go to my next question, Ms. McNeill,
because you're going to do this today. I don't have much time.
OK. Ms. McNeill, what has TSA done prior to providing
passenger data to ICE to ensure compliance with the law?
Ms. McNeill. We are acting within our absolute authorities.
We are part of the Department of Homeland Security.
It was a department that was set up by Congress to ensure
that these agencies weren't operating in silos, and that's what
we are doing today to advance the mission--the national
security mission of the Department.
Mrs. McIver. Ms. McNeill, TSA mission is to secure
transportation, not to assist ICE with immigration enforcement.
There is no law that forbids undocumented people from flying
domestically within the United States.
The vast majority of undocumented people have no criminal
record and pose absolutely no threat to aviation. Under what
authority is TSA sharing passenger data with ICE?
Ms. McNeill. We are absolutely within our authorities to
share information within the Department of Homeland Security to
further the national security mission.
Mrs. McIver. What statute are you following, or policy?
Point to the policy or the statute that you are following.
Under what authority is TSA sharing passenger data with
ICE, that you are allowed to do that?
Ms. McNeill. We are allowed to do that. We have authority.
Mrs. McIver. What policy or statute are you following?
Ms. McNeill. I can get you the exact policy.
Ms. McIver. Please do. We will wait on that.
With that, I yield back, Mr. Chairman.
Ms. McNeill. Gladly.
[The information follows:]
TSA is authorized to share information pursuant to the Aviation and
Transportation Security Act (49 U.S.C. 114(f)), which empowers TSA to
``develop policies, strategies, and plans for dealing with threats to
transportation security'' and to ``carry out such duties, and exercise
such other powers, relating to transportation security as the
Administrator considers appropriate.''
The Intelligence Reform and Terrorism Prevention Act (49 U.S.C.
44903(j)) and the Implementing Recommendations of the 9/11 Commission
Act (49 U.S.C. 114(h)) direct TSA to implement watchlist matching and
enhance information sharing for security purposes. The Implementing
Recommendations of the 9/11 Commission Act (49 U.S.C. 114(t)) also
direct TSA to establish a Transportation Security Information Sharing
Plan to promote the sharing of transportation security information
between DHS and public and private stakeholders.
The Privacy Act of 1974 (5 U.S.C. 552a(b)(1)) allows intra-agency
sharing, such as sharing between components of one agency, when there
is a ``need to know.'' DHS's Policy for Internal Information Exchange
and Sharing (Policy Statement 262-18, 2007) clarifies that ``all DHS
components are considered part of one `agency' for purposes of the
Privacy Act 5 U.S.C. 552a(a)(1), (b)(1),'' and that information shall
be shared within DHS ``whenever the requesting officer or employee has
an authorized purpose for accessing the information in the performance
of his or her duties.'' Therefore, information sharing between DHS
components is permissible under the Privacy Act when there is a ``need
to know.''
Consistent with Privacy Act exception (b)(1) and DHS Policy
Statement 262-18, TSA entered into an agreement with ICE to use
information provided by ICE to identify potential matches in TSA's
data, beginning in early June 2025.
The information sharing outlined in the 2025 MOA reaffirmed and
codified a history of coordination between TSA and ICE that has been
used during multiple administrations to address threats within the U.S.
border, including under the Biden administration.
TSA only shares the flight information of potential matches to
individuals that meet ICE mission needs, which is a very small subset
of the traveling public. TSA assigns a confidence level to individual
matches identified and any matches that score a confidence of 100
percent based on full name and date of birth are returned to ICE to
perform any additional adjudication of the matches. TSA does not
perform any vetting or adjudication of matches provided to ICE, nor
does the agency advise on immigration enforcement decisions. ICE
retains final authority for immigration enforcement operations.
TSA complies with the e-Government Act of 2002 ( 208, 44 U.S.C.
3501), Privacy Act of 1974 (5 U.S.C. 552a(e)(4)), and Homeland
Security Act of 2002 ( 892, 6 U.S.C. 482) by publishing Privacy
Impact Assessments (PIAs) and System of Records Notices (SORNs) for the
Secure Flight Program (73 Fed. Reg. 64018), ensuring transparency,
accountability, and on-going oversight by DHS Privacy and Civil Rights
offices.
TSA has provided public notice that this sharing will occur in
Privacy Impact Assessment DHS/TSA/PIA-018--TSA Secure Flight Program,
which states TSA ``will share information within DHS with those offices
and components that have a need for the information in the performance
of their duties under 5 U.S.C. 552a(b)(1). These purposes may include
national security, law enforcement, immigration, intelligence, and
other DHS mission-related functions and to provide associated testing,
training, management reporting, planning and analysis.''
Chairman Garbarino. Gentlelady yields back.
I now recognize the gentleman from Tennessee, Mr. Ogles,
for 5 minutes of questions.
Mr. Ogles. Thank you, Mr. Chairman. Thank you to the
witnesses.
You know, there's been a lot of talk about ICE and,
unfortunately, really outside the scope of this hearing. For
that, to our witnesses, I apologize, because Science and
Technology, TSA, as Chairman of cyber, I'm going to spend a lot
of my time with the good doctor here.
But, S&T, if you would, please, if there's anything that we
can do as Members of this committee and Congress to help you
affect your job more efficiently, please, if you'll reach out
to my office. I'd love to have an off-line conversation with
you.
TSA, same with you as well. I commend you and your office
and your agents for the job you're doing during the shutdown.
It should be noted, Mr. Chairman, that Joe Biden, you know,
reassigned air marshals to assist with the movement of illegals
across the Southern Border. So when we talk about reassignment
of roles, let's look at the large scope of how it's been done
under previous administrations.
So--and then again, collective bargaining, you want to talk
about manufacturing, when you look at Six Sigma, and Lean Six
and efficiencies within operations, the----
Mr. Correa. Will the gentleman yield?
Mr. Ogles [continuing]. Fact that we leave to the--to the
Government is a good thing as we move forward.
So specifically to Mr.--Dr. Gottumukkala, we have the
privilege of talking, when you look at reductions within your
agency, one of the things we've said--or I've said in a
previous hearing of the Cyber Subcommittee, was that it's about
quality, not necessarily quantity.
Can you speak to the numbers and, quite frankly, the trend
lines, your Department is--when you look at attrition, it's
slightly below the Federal average. Take it away, sir.
Mr. Gottumukkala. Thank you, Congressman.
Mr. Correa. Gentleman yield?
Mr. Ogles. I do not. Thank you.
Mr. Gottumukkala. Congressman, thank you for the question.
First of all, I want to say that there is continued
bipartisan support across for CISA. The personnel that we have,
we are making sure that they are on mission. For somehow the
bad press of whatever we see, we miss the point that CISA
personnel are deployed across the 10 regions in support of all
56 States and territories.
Mr. Ogles. Specifically, good Doctor, because we have
limited time. So roughly, 800 agents. What percentage of the
work force is that? Twenty-three semi-percent?
Mr. Gottumukkala. That is correct, sir. There were 23
percent participated in the work force transition program.
Mr. Ogles. Then the national average aside from that,
roughly 9 percent across Federal agencies, you're trending
what, 7 percent attrition?
Mr. Gottumukkala. That is correct, sir. Compared with
previous years, it's about 9.25 approximately across all
Federal agencies, and we are or we were at 6.5 to 7.5 percent
from an actual attrition this year.
Mr. Ogles. So the facts, quite frankly, speak for
themselves. As Chairman of Cyber, you know, I've spent a lot of
time in the SCIF getting updates on the constant attacks that
we face from threat actors like China, like North Korea, like
Iran, like Russia.
Yet, you're doing more with less, and you're doing it more
efficiently. So for that, I say thank you.
Now, one of the things that we've talked about and what's
important, I think, to the American people, when we--again, I
said in the hearing the war has already begun. We know who the
adversary is. Our primary adversary is China.
It's important that we on this committee, and you and your
agency, have better communications, increase communications,
and then were updated really on a much more timely basis. So
with that--and, again, per our conversation, do you agree that
Members of this committee, and in particular, the Subcommittee
on Cybersecurity and Infrastructure--which has direct oversight
of CISA--will be informed in a timely manner and, quite
frankly, when needed, in a SCIF so that we can do our jobs and
help you and assist you in doing yours, sir?
Mr. Gottumukkala. Congressman, I appreciate the support.
Yes, definitely.
Mr. Ogles. Then to change subjects--and I appreciate your
willingness to meet with me. I appreciate all of you for being
here.
When we look at the mission statement and the directive we
have here with the committee, it's important that we keep
things in perspective. We have an obligation to the American
people and to the American taxpayer.
One of the things that we've seen under the previous
administration--administrations, plural--is the absolute suck
on our system, our infrastructure, and our welfare. So, for
example, Bataan, 81.4 percent are on welfare; Yemen, 75.2
percent; Somalia, 71.9 percent; Marshall Islands, 71.4 percent;
Afghani, 68.1; Dominican Republic, 68.1; Bangladesh, 54.8;
Pakistan, 40.2; and I can go on.
But this idea that doctors and lawyers were brought into
this country to help our society is absolute nonsense. Go back
to Hart-Celler, back to the 1960's, let's abolish it and, quite
frankly, deport them all.
This is the United States of America. We get to decide who
comes in, and, Mr. Chairman, we get to decide who leaves. I
yield back.
Chairman Garbarino. Gentleman yields back.
I now recognize the gentlelady from New Jersey, Ms. Pou,
for 5 minutes of questions.
Ms. Pou. Thank you, Mr. Chairman. So as we sit here, DHS is
operating an armed invasion of an American State: Minnesota.
Local law enforcement described DHS tactics as ``profoundly
detrimental to public safety.''
An American citizen was shot in the face and killed by an
ICE agent. Secretary Noem and ICE Director Todd Lyons should be
here testifying under oath what happened to Renee Good, and the
pervasive ICE violence against Americans because we know Noem's
taxpayers-funded media tour continues to spew outright lies
about her Department, including calling Renee Good a domestic
terrorist.
Just this weekend, the Secretary went on TV and said that
70 percent of the people held by ICE have committed violent
crimes. In fact, only 25 percent of individuals of--in ICE
custody have criminal convictions, with many being minor
offenses like traffic violations, and that's a fact.
No one here can speak to the rampant DHS corruption, like
the $200 million in taxpayers' money used for an ad campaign to
the Secretary's aide and family, or her so-called border czar,
who accepted a fast food checkout bag stuffed with $50,000 cash
bribe.
Why is DHS illegally blocking Congress from entering ICE
facilities? Is it to cover up the 32 people who died in ICE
custody last year or the 4 this year, including a reported
homicide at a Texas ICE facility earlier this month?
There are now reports that in my home State of New Jersey,
ICE is looking to convert massive warehouses into detention
centers, including one in Roxbury.
None of these witnesses can speak to any of these abuses,
but there are important questions that we can cover, starting
with election security. I am alarmed by the administration's
termination of funding for State and local elections offices
for election security. We talked earlier, and someone asked
about how safe are our elections? Are they fair? Will they be,
indeed, secured?
This President has attempted to weaponize CISA and spread
disinformation about his election loss in 2020. So I'd like to
ask Dr. Gottumukkala, did Donald Trump win or lose the 2020
election? Yes or no?
Mr. Gottumukkala. Congresswoman, I will be more than happy
to talk about----
Ms. Pou. Yes or no?
Mr. Gottumukkala. I am not here to discuss about----
Ms. Pou. I know. Yes or no?
Mr. Gottumukkala [continuing]. The 2000 election or the
2020 election.
Ms. Pou. Did Donald Trump lose the 2020 election, yes or
no?
Mr. Gottumukkala. Ma'am, I'll be more than happy to discuss
about the legwork that CISA does and how we are back on mission
and----
Ms. Pou. You know what, it's--I can understand----
Mr. Gottumukkala [continuing]. How we are----
Ms. Pou. You know, I will tell you, it's--this is a simple
question that only has the right--only has one right answer.
Yes, he was, in fact, defeated.
Do you believe that Donald Trump defeats--do you believe
that Trump's defeat in 2020 contributed to this
administration's cutting funds to support election security for
State and local officials? Yes or no?
Mr. Gottumukkala. Ma'am, election security is focused on
infrastructure, and as CISA, we are exclusively focused on
defending the election infrastructure.
Ms. Pou. Quite honestly, it's very simple. What kind of
justification could explain this reckless cut? Please explain
that.
Mr. Gottumukkala. Ma'am, once again, I have explained
before, the people that have participated in the work force
transition program, they have done that voluntarily.
Ms. Pou. It's clear that you're not going to be able to do
that. I'm sorry, but it's obviously clear that you're not
looking to answer a simple question with a yes-or-no answer.
I am very concerned, Mr. Chairman, over the fact that one
of my colleagues asked earlier about sharing information. Ms.
McNeill, the passengers, are we--are we, in fact, making TSA--
American citizens aware that TSA is, in fact, diverting
resources and how are they--those personnel information being
shared between agencies?
Do the American people know that their information may very
well be shared?
Chairman Garbarino. The gentlelady can maybe respond in
writing to that question. The time has expired.
Ms. Pou. That's fine.
Chairman Garbarino. I appreciate that.
[The information follows:]
TSA is authorized to share information pursuant to the Aviation and
Transportation Security Act (49 U.S.C. 114(f)), which empowers TSA to
``develop policies, strategies, and plans for dealing with threats to
transportation security'' and to ``carry out such duties, and exercise
such other powers, relating to transportation security as the
Administrator considers appropriate.''
The Intelligence Reform and Terrorism Prevention Act (49 U.S.C.
44903(j)) and the Implementing Recommendations of the 9/11 Commission
Act (49 U.S.C. 114(h)) direct TSA to implement watchlist matching and
enhance information sharing for security purposes. The Implementing
Recommendations of the 9/11 Commission Act (49 U.S.C. 114(t)) also
direct TSA to establish a Transportation Security Information Sharing
Plan to promote the sharing of transportation security information
between DHS and public and private stakeholders.
The Privacy Act of 1974 (5 U.S.C. 552a(b)(1)) allows intra-agency
sharing, such as sharing between components of one agency, when there
is a ``need to know.'' DHS's Policy for Internal Information Exchange
and Sharing (Policy Statement 262-18, 2007) clarifies that ``all DHS
components are considered part of one `agency' for purposes of the
Privacy Act 5 U.S.C. 552a(a)(1), (b)(1),'' and that information shall
be shared within DHS ``whenever the requesting officer or employee has
an authorized purpose for accessing the information in the performance
of his or her duties.'' Therefore, information sharing between DHS
components is permissible under the Privacy Act when there is a ``need
to know.''
Consistent with Privacy Act exception (b)(1) and DHS Policy
Statement 262-18, TSA entered into an agreement with ICE to use
information provided by ICE to identify potential matches in TSA's
data, beginning in early June 2025.
The information sharing outlined in the 2025 MOA reaffirmed and
codified a history of coordination between TSA and ICE that has been
used during multiple administrations to address threats within the U.S.
border, including under the Biden administration.
TSA only shares the flight information of potential matches to
individuals that meet ICE mission needs, which is a very small subset
of the traveling public. TSA assigns a confidence level to individual
matches identified and any matches that score a confidence of 100
percent based on full name and date of birth are returned to ICE to
perform any additional adjudication of the matches. TSA does not
perform any vetting or adjudication of matches provided to ICE, nor
does the agency advise on immigration enforcement decisions. ICE
retains final authority for immigration enforcement operations.
TSA complies with the e-Government Act of 2002 ( 208, 44 U.S.C.
3501), Privacy Act of 1974 (5 U.S.C. 552a(e)(4)), and Homeland
Security Act of 2002 ( 892, 6 U.S.C. 482) by publishing Privacy
Impact Assessments (PIAs) and System of Records Notices (SORNs) for the
Secure Flight Program (73 Fed. Reg. 64018), ensuring transparency,
accountability, and on-going oversight by DHS Privacy and Civil Rights
offices.
TSA has provided public notice that this sharing will occur in
Privacy Impact Assessment DHS/TSA/PIA-018--TSA Secure Flight Program,
which states TSA ``will share information within DHS with those offices
and components that have a need for the information in the performance
of their duties under 5 U.S.C. 552a(b)(1). These purposes may include
national security, law enforcement, immigration, intelligence, and
other DHS mission-related functions and to provide associated testing,
training, management reporting, planning and analysis.''
Ms. Pou. Thank you, Mr. Chairman. I yield back. I would
like, however, to be able to ask that question.
Chairman Garbarino. Absolutely. All committee Members will
have the time to submit questions in writing.
Ms. Pou. Thank you.
Chairman Garbarino. I know I have a bunch that I'm going
to----
Ms. Pou. Thank you very much.
Chairman Garbarino. Thank you. Gentlelady yields back.
I now recognize the gentlelady from South Carolina, Mrs.
Biggs, for 5 minutes of questions.
Mrs. Biggs. Thank you, Mr. Chairman, and thank you to our
panelists for being here today.
I would like to elaborate on my colleague, Congressman
Crane, what he was stating. It is concerning to me that for 2
years, Somali residents were walking through the Minneapolis
airport with duffel bags filled with cash, on nearly $1 million
a day totaling nearly $1 billion. I think that's astonishing.
TSA reportedly flagged this flood of money and raised it to
DHS and to intel agencies. So, Administrator McNeill, did that
really happen, and who were these individuals responsible for
this, and where was the cash going? Because to me, it--if that
is what was reported, why wasn't it stopped immediately? This
money could have easily been used for terrorists and tied to
the same massive Somali fraud networks that we keep seeing
across Minnesota.
Ms. McNeill. Thank you, Congresswoman, for that question.
TSA did, indeed, report these incidents as it came across
the checkpoint because bulk cash shows up as a mass on the X-
ray, and so our officers have to resolve what they can't
identify on the X-ray machine. Through the course of their
normal day-to-day duties, they reported that to our law
enforcement partners in compliance with their standard
operating procedures.
This is why it's really important to take a whole-of-
Government approach on this and levy the authorities of all
these law enforcement agencies, both across DHS and with the
Department of Treasury, to ensure that we are taking a
concerted whole-of-Government approach to this. I think this is
where the role of Congress is also critical to ensure that we
have the right framework in place to take action.
As I mentioned earlier, the movement of this money
historically had been done through legal channels, and so, you
know, I think we're going to have to collectively work on this.
Mrs. Biggs. I still didn't hear what is actually being done
about it.
Ms. McNeill. We continue to report it based on our standing
operating procedures. I know there's a, you know, an on-going
investigation with our law enforcement partners. We are part of
that, and we are happy to brief you and the Members of this
committee on any developments that we see on that front.
Mrs. Biggs. OK. I guess my next question would be, why is
Congress finding out about this from journalists and not from
DHS?
Ms. McNeill. I can't speak to that. I mean, again, I think
we, you know, are committed to transparency with this
committee. As the investigation evolves, we are happy to brief
out on our part in this and, you know, work with the rest of
the U.S. Government to make sure that we're taking action.
Mrs. Biggs. Well, thank you for that. My constituents and
the American people would love to hear a follow-up on that.
Thank you.
So my next question--TSA, the Touchless PreCheck is a
biometric identity verification capability that enables
enrolled PreChecked travelers to verify their identity at
airport checkpoints using facial recognition and eliminating
the need to present a physical ID. What is TSA's long-term
vision for this TIS? Is it intended only as a checkpoint
identity verification tool, or does TSA envision it becoming a
broader identity platform across the transportation system?
Ms. McNeill. So, we have launched the Touchless
Identification System. As you mentioned, TIS in 15 locations
today for PreCheck. It is a voluntary, facilitative technology
that we offer to our PreCheck members. We're going to be
rolling out additional locations, you know, based on the needs,
experience, and feedback that we're getting from our PreCheck
populations. It is very well-received. Again, I would just
state it's voluntary, and it's meant to really provide that
seamless experience to our trusted populations as they travel
through our airports because you don't have to take out your
identity or your boarding pass at the checkpoints. So, it is a
facilitative tool. That is the intent of that program is to
offer that benefit to our PreCheck populations.
Mrs. Biggs. Just one more quick thing. So, is it beyond
passenger screening? Will it be, like, for cargo or
international operations? Will it go more in-depth?
Ms. McNeill. It is intended for passenger screening and for
our PreCheck population.
Mrs. Biggs. OK. Thank you. I yield back.
Chairman Garbarino. The gentlelady yields back. I now
recognize the gentleman from Texas, Mr. Green, for 5 minutes of
questions.
Mr. Green. Thank you, Mr. Chairman. I thank the Ranking
Member as well. I thank the witnesses for appearing today.
Ms. McNeill, the Transportation Security Officers' Union is
under attack. Thankfully, a court injunction has kept TSA's
union in place. Most recently, the Secretary openly defied the
court order and tried to disband TSA's union for a second time.
Last week, the court said those actions plainly defy its
injunction and ordered the Secretary to keep TSA's collective
bargaining agreement in place or risk contempt.
My question to you, acting administrator, is this: Will you
commit to abiding by the court's order to keep the TSA's
collective bargaining agreement in place?
Ms. McNeill. Congressman, every step that we've taken to
date, and we will continue to abide by court order----
Mr. Green. Excuse me, if I may. Since I control the time,
if I may, please. This question can be answered with a yes or a
no. If there's anything less than a yes or a no, I will assume
you mean no.
So, now, back to you again, will you commit to honoring a
court's order, a court's order, a court's order? When you don't
honor court's orders and you're the Secretary, you can be
impeached. So, now, will you commit to honoring the court's
order?
Ms. McNeill. Yes.
Mr. Green. Thank you. I'm pleased that you said yes because
the Secretary needs to confer with you. She needs your advice.
The Secretary, quite frankly, is probably being influenced by
the President. Disobeying court orders is something that is
antithetical to the Constitution. The courts are there for a
reason. If we can disobey court orders, we no longer have a
Constitution that we can count on. You're defacing, demeaning,
and denigrating the Constitution when this happens--not you
personally. You've already said yes, and I'm grateful to you
for saying yes. But that's what's happening. I can assure you
people are growing tired of seeing what's happening in terms of
the lawlessness emanating from this Department. They're growing
tired of it.
What happened to Ms. Good is something that people are not
going to forget. For the Secretary and others to contend that
she was a domestic terrorist is beyond comprehension without
even having investigated it immediately.
This was a Christian woman with children, who according to
her wife, they had whistles, and they indicated that the
constabulary had pistols as evidenced by the fact that she is
no longer with us.
People are getting fed up with this behavior and the
justifications for lawlessness. We must return to the rule of
law. One of the ways to return to the rule of law is to enforce
the law. One of the laws that we can use to make sure the rule
of law prevails is impeachment.
This Secretary is putting herself in harm's way as it
relates to impeachment, not a physicality, but in terms of how
she is conducting herself in office. My guess is if she is not
very careful, she may become the first Secretary to be removed
from office. We have a long runway here. It doesn't end at the
end of this year. There is a long runway. So, I'm going to beg
you to counsel with her and help her to better understand that
the law prevails, and she is not the law, and neither is the
President. I yield back the balance of my time.
Chairman Garbarino. The gentleman yields back. I now
recognize the gentleman from Oklahoma, Mr. Brecheen, for 5
minutes of questions.
Mr. Brecheen. Thank you, Mr. Chairman. To our witnesses,
thank you. As typical in Washington, some of us having to shift
in and shift out because of scheduling conflicts. I am certain,
because I heard some of the commentary as I walked in, some of
what we are going to be discussing, my part, is a little bit
redundant. Please forgive me, because I did miss some of the
prior discussion.
Relative to CISA, and the weaponization that many felt like
to the social component, social media, I just want to make this
as a statement--this is kind-of a rhetorical statement, that is
something of major concern to us that under this administration
we continue to pay attention to that and make sure that our
Government is not allowing that to continue that we saw in
years past.
That said and moving on for TSA. For the oversight we are
conducting with the World Cup, with the Olympics, I know
Director McNeill that you are very much attuned to what's
ahead, the high volume, the international traffic; look, the
heightened threat level, the landscape that we had in this
hearing months ago because of the illegal populations that was
led in by the prior administration. There is a different threat
landscape. Whether it be the biometric security screening, REAL
ID enforcement, the gaps in that, it's been astounding to me to
find out the number of States that are allowing REAL ID-
compliant driver's license. I've had some State-elected
officials show me how that is in the past played out to whereby
the way the prior administration was implementing parole in the
work permitting process, that REAL ID-compliant driver's
licenses were being handed to those who were here illegally. So
to be able to--and I know by your response, I am taking it for
granted that you may have not heard this before--but it's
something I would very much like some feedback for our office
to obtain where we're at on ensuring that with REAL ID coming
into compliance this year, and all of the objections--and I was
one of them on the State level--that if we have that type of
possibility of illegal aliens getting a REAL ID-compliant
driver's license, what a major security concern that is.
[The information follows:]
Under the REAL ID Act and relevant regulations, jurisdictions may
only issue REAL ID-compliant Drivers Licenses/Identity Documents (IDs)
to individuals who demonstrate evidence of lawful presence.
Additionally, jurisdictions must set the credential's expiration date
to match the end of the individual's lawful presence or a maximum of 8
years, whichever is sooner. When applying for a REAL ID, individuals
must present documentation, as outlined in the REAL ID Act, sufficient
to demonstrate that they are lawfully present in the United States
which must be verified through the Systematic Alien Verification for
Entitlements (SAVE) system.
DHS transferred the REAL ID program to TSA as part of the fiscal
year 2023 budget, to include recertification requirements. TSA's
recertification process follows the procedures established in the REAL
ID regulations, specifically 6 CFR 37.59. As part of TSA's oversight
of the REAL ID program, TSA recertifies a State's compliance with the
REAL ID Act and regulations on a regular cycle. States and Territories
are required to be recertified on a rolling 3-year basis. The recurring
re-certification process includes a review of the State's procedures
and practices, as well as on-site inspections, to ensure that all REAL
ID requirements are satisfied, including the requirement that States
only issue REAL IDs to individuals who are lawfully present in the
United States.
Mr. Brecheen. All right. I want to shift over. I know
you've talked about the Somalian incident, cash, you've talked
about, you know, in terms of what you all are doing. My
question on that is when were you all as an agency made aware
that this was happening? What was the time line of the millions
of dollars that, you know, going through the airport security
system, what timing did you all become aware of this?
Ms. McNeill. I believe that the reporting started back in
2017.
Mr. Brecheen. Two thousand seventeen. OK. With the World
Cup, with the Olympics, I'm about to say something that I'm
going to make sure my words are precise and give you a chance
to kind-of think this thing through because there's an element
to this just for national security purposes, the DHS Inspector
General released a report on November 1, 2025 on its
independent covert testing of the TSA checkpoint screening to
see how effective it is at preventing threat items from being
brought onto commercial aircraft. We cannot publicly talk about
the contents of that report due to the sensitivity of the
information. But let me ask you, generally, are you aware of
the report? Have you read it? When did you receive it?
Ms. McNeill. Yes. Yes to both of your first questions, in
last November.
Mr. Brecheen. OK. Do you agree with the findings and
recommendations of that report?
Ms. McNeill. I do. It's not anything that actually we
didn't know already and fully consider in our security
policies.
Mr. Brecheen. Would you commit to providing this committee
with results of any follow-up analysis conducted by TSA related
to this report?
Ms. McNeill. We would be glad to have a briefing on this
topic in the proper Classified environment.
Mr. Brecheen. Thank you. Transition to another little
different direction here. New travelers are confused by TSA's
facial screening practices. Can you please clarify whether this
is mandatory or optional?
Ms. McNeill. It is absolutely voluntary. We have signage at
our checkpoints that notify the passengers of that. If they
don't opt in, there are alternate procedures that they go
through. So, it's 100 percent voluntary.
Mr. Brecheen. With the 25 seconds that I have left, what
would you say to travelers who are concerned about their
biometric data being retained as a result of that process?
Ms. McNeill. I would say that we don't retain the data that
is captured at the checkpoint. It's solely for the purpose of
identification at that point in time as we traverse through the
checkpoint.
Mr. Brecheen. Thank you very much. Thank you, panel. I
yield, Mr. Chairman.
Chairman Garbarino. The gentleman yields back. I now
recognize the gentleman from New York, Mr. Goldman, for 5
minutes.
Mr. Goldman. Thank you, Mr. Chairman. It is good that we're
having a full committee hearing here. I appreciate you calling
this hearing. Of course, it relates to nothing that we have an
urgent need to do oversight on. We do not have Acting Director
Lyons here when what we're seeing around the country is a mass
secret agency, dragnet, using violence against American
citizens and others. It's bewildering to me because I know the
Chairman is a very good person. We worked together on
legislation. In fact, I'm optimistic we will pass the Zadroga
Act together to make sure that 9/11 survivors have certainty
and security in their health care.
But I know, I know that you and your colleagues cannot
possibly be OK watching secret masked ICE agents barging into
homes without a warrant, pulling American citizens out in their
underwear, stopping American citizens on the streets and
demanding their citizenship. That, of course, is not even to
mention the violence in Renee Good's murder as well as
everything else we're seeing.
There is an urgent, urgent need to conduct oversight from
this committee of the Department of Homeland Security. But it
is not the Science and Technology Directorate, it is not the
Cybersecurity and Infrastructure Security Agency, it is not the
TSA, all of which are very important agencies, and certainly do
very important work. I am not disparaging the work you all do.
But the urgency in this country right now is what's going on
with ICE. Why are we having a hearing with Department of
Homeland Security officials who know nothing about ICE? We get
such misinformation from this Department of Homeland Security.
We're told, oh, it's the worst. It's the murderers. It's the
rapists.
In our home State, Mr. Chairman, of the 22 of the 3,212
people ICE arrested in New York City in 2025 up through October
15, 70 percent had no pending criminal charges and no criminal
convictions. Fifteen percent had pending criminal charges,
which of course with due process would have to play out before
they are removed. Fifteen percent were convicted criminals, and
5 percent had serious felonies. That is not the worst of the
worst. That is what we should be doing oversight of.
But since we do have the TSA here, Ms. McNeill, I want to
ask you about this new policy that my understanding is you have
implemented where you are--the TSA, rather, is providing
information to ICE to assist them with the deportation effort.
You're familiar with what I'm referring to?
Ms. McNeill. I am.
Mr. Goldman. Just to be clear, this was a new policy
implemented under this administration, correct?
Ms. McNeill. It is not new policy to share information
between the agencies of the Department of Homeland Security.
Past administrations have shared information.
Mr. Goldman. No, that's not what I asked. Is it a new
policy that the TSA sends identification information of all
passengers to ICE so that they can check for potential
deportation orders?
Ms. McNeill. That is not what is occurring. We don't send
the information to ICE. We help ICE check against information.
Yes, absolutely, we do that, and we are supporting the mission
of our colleagues at the Department of Homeland Security, and
that includes enforcement of immigration laws, and----
Mr. Goldman. Can I--just because I have a little time--can
I ask you in--last year, Secretary Noem said that the Biden
administration allowed immigrants who are in our country
illegally to jet around the country without identification. Is
that true; they had no identification, but yet they were able
to get on an airplane?
Ms. McNeill. I can't speak to what occurred before, you
know, this administration took place. But as you know, we
started enforcing REAL ID last year which was a law that was
passed by Congress over 20 years ago. Today, people who are----
Mr. Goldman. Just because I'm running out of time. Is it
your view that the Biden administration said it's OK for people
to go on airplanes without identification? I've never been on
an airplane without identification, but was it OK in the Biden
administration?
Ms. McNeill. Apparently, it was allowed.
Mr. Goldman. Apparently, because Secretary Noem said it?
You ought to be careful what you testify to, and I yield back.
Chairman Garbarino. The gentleman's time has expired. I now
recognize the gentleman from Pennsylvania, Mr. Mackenzie, for 5
minutes of questions.
Mr. Mackenzie. Thank you, Mr. Chairman. Thank you to all
the testifiers for being here today. Obviously, each of you
cover very important agencies, and having you here is critical
to the work we do at the Homeland Security Committee.
I'm going to focus my questions to Ms. McNeill. The TSA is
an important agency that keeps all Americans safe. First, I'd
like to commend our local TSA agents at the A-B Lehigh Valley
International Airport. They just went through the highest
record and busiest year in history at the Lehigh Valley
International Airport. Over a million passengers moved through
successfully and faithfully, and we thank all of them for their
work, especially during a Democrat-led shutdown where they were
not being paid for a period of time. We thank them for their
service and their work.
Two things that I would like to highlight: First is ways
that you were actually reforming the administration to move
passengers through more quickly and improve the passenger
experience. One of those is the Families on the Fly Initiative.
Can you speak to that and how that program works, what you're
doing to help families, typically with children under the age
of 12, to not only move them through more expeditiously, but
also speed up lines for everybody else?
Ms. McNeill. Thank you, Congressman Mackenzie, for that
question. Families on the Fly is an initiative--but we rolled
out last year in support of American families traveling through
our airports. It dedicates a lane, a specific lane for families
that go through the checkpoint. You know, as many of us know
when you travel with children, there's a lot of gear and
equipment that gets brought through. So it provides a wider
lane, easier access for families to go through and extra
assistance to screen all of their gear that they bring through.
It has the added benefit actually to driving down wait times in
nonfamily lanes as well. So, you know, it's been a win-win for
everyone. We're really happy to be able to support families
traveling throughout our airports.
Mr. Mackenzie. Well, thank you for that. It's an important
improvement to making the agency--obviously, a lot people
outside of A-B have difficult experiences with TSA. While it
should be predominantly and primarily focused on safety and
security, it is also a customer service-facing organization. We
want to improve that experience. So, I think there are lots of
great ways that we can coordinate to make sure that passengers
have the best experience possible.
The second thing I would like to focus on relates to the
last administration. So, I understand you may not be in a
position to share all the information that I'm looking for
here. If you don't have the information, I would ask that you
do follow up with committee with written documentation of the
information that we do have. What it relates to is during the
last administration, there was something that was commonly
referred to as ghost flights where illegal immigrants in this
country were being moved on planes across the country to
different locations. Many times it was minors.
The last administration then proceeded to lose thousands of
minors that were supposed to be in their custody. When we went
to our local airports and other airports in the region and
asked for documentation of who was on those flights, they could
not provide any manifest or logs of those flyers on the plane.
We couldn't get any information on these individuals, whether
they were here legally or in some kind of protected status. We
couldn't get any information on who paid for those flights.
Many of those people were in the country illegally, though, we
know, based on some of the information that was shared publicly
from the last administration, or they just said that it was
people, there were minors here in the country illegally, and
being moved to a different location. So, those individuals do
not have proper documentation.
So the last question I am going to ask, if people were
being moved on flights without report identification? The
answer is undoubtedly yes. We know that for a fact. So, my
question to you is what information, what has this Department
of DHS done under this administration to look into those
transgressions that occurred in the last administration, those
ghost flights. What can we now share with the public about what
was going on, who was paying for them, who was on those
flights? Again, if you don't have that information, I would ask
that you look into it and get back to us with as much detailed
information as possible--even if it has to be anonymized so
that no individual information is disclosed. But that program
and that activity is highly egregious and very concerning for
the American people.
Ms. McNeill. What I can say is that under no circumstances
would that happen under this administration and the initiative
that we have ruled out at our airports, namely, under the
leadership of the Secretary, we have ruled out REAL ID, a law
that was passed 20 years ago. That really does enforce identity
verification standards at our checkpoints. I mentioned early on
in my statement, identity verification is the cornerstone of
our aviation security system. Knowing who is accessing our
aircrafts is critical to our security posture. I'm happy to get
back to you on the details of the scenario that you raised
earlier.
Mr. Mackenzie. Please do look into those ghost flights.
It's something that, again, should not have been occurring,
should not occur going forward. I know it wouldn't stand under
this administration, but any information you can shed on what
the last administration was doing incorrectly would be helpful
for us going forward. Thank you, and I yield back.
[The information follows:]
TSA defers to DHS/ICE for a response.
Chairman Garbarino. The gentleman yields back. I now
recognize the gentleman from Virginia, Mr. Walkinshaw, for 5
minutes of questions.
Mr. Walkinshaw. Thank you, Chairman Garbarino, for
convening today's hearing and for our witnesses for joining us.
Last week, I visited Minnesota with 27 other Members of the
House where we heard from community leaders and Members about
the brutal masked secret police that had been unleashed in
their streets. They have shackled peaceful protestors, pulled
guns on children, dragged pregnant mothers, and as we all know
shot an unarmed mother in the face.
Just yesterday in Minnesota we heard from local law
enforcement leaders that their off-duty officers, United States
citizens, have been targeted by ICE. Had the Department honored
the committee's request--and I appreciate the Chairman for
making the request for Acting ICE Director Lyons to testify
today--I and I think others would have questioned him directly
about his role in escalating tensions by deploying thousands of
masked immigration officers. I should say masked and minimally-
trained immigration officers in Minnesota.
That said, I want to just discuss another one of this
administration's failures. Last year, President Trump's DOGE
and its chain-saw wiped out 72,000 Federal jobs just here in
the national capital region, which includes the district and
Virginia that I represent, including a lot of cyber
professionals. These are patriotic Americans who chose a career
of public service, and instead they were fired, pushed out, or
moved to support this administration's mass deportation effort.
That's currently, as I noted, harassing U.S. citizens,
including law enforcement officers in Minnesota.
CISA--as we know, is a lead agency to defend and mitigate
against threats to our cyber and physical infrastructure--lost
a third of its work force. One year ago at CISA, much of its
career work force was bullied into quitting. They were
threatened with RIFs that would not come with any severance.
So-called probationary employees were fired. In the recent
Government shutdown, some CISA staff even received the illegal
RIF notices. Court after court after court has determined that
those attempted RIFs were illegal. Others were moved to ICE or
to CBP or told they'd be fired if they didn't accept their
transfer orders. CISA has cut support to critical partners like
the multi-State ISAC and the Election Infrastructure ISAC,
while the Department has dismantled key oversight and
prevention efforts, including eliminating the Cyber Safety
Review Board. The leaders behind the pre-ransomware
notification and Secure-by-Design initiatives have left.
At a time of persistent and growing cyber threats from
malign foreign actors, these choices by the President and the
Secretary have weakened our defenses and left our critical
systems and infrastructure more exposed and the American people
more vulnerable.
Dr. Gottumukkala, has CISA conducted an analysis to prove
that its current staffing levels enable mission delivery? Have
you done that analysis?
Mr. Gottumukkala. Congressman, thank you for the question.
Please allow me to clarify. I think capability--somehow I think
the narrative comes across in the media as 800 people just left
overnight. That's not the case. This is a work force transition
program. People who participated in the program did so
voluntarily. And----
Mr. Walkinshaw. Yes, I don't agree with that. But just
answer the question, please. Have you conducted an analysis to
prove that your current staffing levels today enable you to
accomplish your mission? Where is that analysis?
Mr. Gottumukkala. Congressman, the work that we do is
mission-focused, which means capability is measured by
outcomes, not head count. And CISA remains fully operational
from what we do from securing the Nation from----
Mr. Walkinshaw. So you have not conducted an analysis. Is
there an analysis you can provide to the committee to determine
you can meet your mission with the work force you have today?
Mr. Gottumukkala. Congressman, we support every single
statutory authority given to us, and we support every single
one of that for the mission.
Mr. Walkinshaw. OK. Thank you.
Mr. Gottumukkala. That has not been compromised by anyone.
Mr. Walkinshaw. OK. So there is no analysis. Funding for
the multi-State ISAC has been eliminated. I referenced it. I'm
sure you know a lot about it. The Senate provided no-cost
services for cash-strapped State and local governments,
especially small local governments in rural communities who
don't have the ability to do this on their own. Has the threat
landscape against State and local governments diminished or
increased over the past year? Has it gone up or down?
Mr. Gottumukkala. Congressman, thank you for the question.
Again, consistent with all ISACs, there is no Federal funding.
But we do work with all the ISACs and working with the joint
safety of the products. We deployed automatic communication for
the joint cyber communication, joint cyber defense
collaborative, expanding the real-time communication----
Mr. Walkinshaw. OK.
Mr. Gottumukkala. And----
Mr. Walkinshaw. Thank you. You've managed to answer none of
my questions. You haven't answered a single question, but thank
you for coming.
Chairman Garbarino. The gentleman yields back. I now
recognize the gentleman from California, Mr. Fong, for 5
minutes of questions.
Mr. Fong. Thank you, Mr. Chair. Thank you to the panelists
for the work that you do. I want to start with Under Secretary
Allende. The threats our Nation faces require us to continue
developing new technological capabilities.
Specifically, my district is home to the Naval Air Weapons
Station Channel 8, which supports the Navy's research,
development, accusation, and testing, and evaluation of
advanced weapon systems. Recently, the Department of Homeland
Security Science and Technology Directorate in coordination
with the U.S. Coast Guard and the Naval Warfare Center Weapons
Division, Channel 8, tested a contactless vessel-stopping
capability prototype that uses high-energy radio frequency to
safely stop small, noncompliant vessels, which is an exciting
new development. How do S&T's partnerships with key military
bases enhance testing and development efforts?
Mr. Allende. Thank you, Congressman, for the question. At
S&T, we take a whole-of-component, a whole-of-DHS approach to
understanding the needs and requirements. We take a whole-of-
Government approach to reduce duplication and create
efficiencies. Often, some of the systems that are developed for
other departments, including the Department of War may have a
civilian application. Or the core technology may be
transferable. Obviously, they're very different mission sets.
But the technology you're referring to is very promising. We
would like to do some continued testing on it to make sure that
it is suitable for deployment. But it is a concern that I heard
both in my engagements with the Coast Guard and from CBP and
others in my trip to California this past week.
Mr. Fong. Well, you're always welcome in California. So,
certainly, if you're in the area, please, we would love to roll
out the red carpet for you.
I wonder if you describe how S&T is working with private-
sector vendors to ensure technologies being developed,
procured, and deployed are up-to-date, incorporate the latest
innovations, and avoid becoming obsolete before they are
fielded.
So what does the procurement process look like? Are there
changes that need to be made? Certainly, as mentioned before,
we have major special events occurring in the United States
with the World Cup and the Olympics, and the celebration of
America's 250th birthday. How can we facilitate the spread of
these technologies and deploy them ahead of these events for
any threat that exist?
Mr. Allende. Sure. Thank you for the question. The private
sector is able to address a number of problems that Government
just really could not do on its own in many aspects. It's
generally wise to look for those technologies and the
applications that they might be suitable for. We do that soup
to nuts at the Department. We're always looking for
opportunities to bring in existing technologies.
I guess my answer to you is, if there's something that can
be applied, our preference would be to either adopt it or adapt
it for our use, rather than going through a long research
development time line.
Now, in fairness, there are those areas where there is no
private-sector market. In those instances, it's suitable for us
to take lead on that.
Mr. Fong. Can you expound on that? What type of
capabilities--I mean, does a demand signal have to be provided
for the private sector to address some of the Department needs?
Or is it something that is solely focused within the Department
that you just prefer to have it in house?
Mr. Allende. I would say there's two sets of demand
signals. There is something that private sectors develop with a
private market in mind that might have a very good Government
application. There is the alternative which is something that
is a--almost uniquely Government niche that ultimately has a
private-sector application. In those instances we'd be looking
to do tech transfer at the earliest possible moment, and that's
the private sector. For the components, our--you know operation
delivery is our goal. So, by either method, we look to get out
in the field.
Mr. Fong. Do you have a particular time frame you would
look at when you're trying to deploy with your processes in
place?
Mr. Allende. ASAP is really my preference. There is nuance
to that, of course. You want to make sure that it is properly
tested, evaluated, and in a position to be deployed. We have
very smart people that get after that issue.
Mr. Fong. Sure. Well, I know that when it comes to the
threats that our country faces, the technology is going to be
critically important for us to address that both from the
private-sector side and on the research and development side.
So, find a way we can facilitate the deployment of promising
technologies, but please let us know. With that I yield back.
Chairman Garbarino. The gentleman yields back. I now
recognize the gentleman from Tennessee, Mr. Van Epps, for 5
minutes of questions.
Mr. Van Epps. Thank you, Mr. Chairman. Thank you to our
witnesses for sharing with us today. This Department is tasked
with the most sacred mission: To protect the American homeland.
Our witnesses today represent vital aspects of that mission,
and I'm grateful for your time.
I'm going to build off of my colleagues' questions.
Mr. Allende, S&T's Office of Safety Act Implementation,
OSAI, plays an important role in mitigating litigation risks to
incentivize the private sector to require and deploy
antiterrorism technologies. Building off of previous questions,
what additional resources, if any, does OSAI require in order
to process applications for designated and certified
antiterrorism technologies at a speed sufficiently appropriate
to keep pace with emerging threats and technologies?
Mr. Allende. Thank you, Congressman, for the question. I
would like to ask for an opportunity to come back and brief you
on this. I can tell you, we currently have a large number of
applications pending. We've had a 50 percent increase in
applications, which we attribute to FIFA, L.A. 2028, and
America 250. We are working very diligently to get through
those. I have some time actually scheduled toward the end of
this week to see how many we can get through. But certainly, it
is top of mind and not something that we take lightly.
Mr. Van Epps. Great. Thank you. To what extent does OSAI
perform evaluations of technologies that have already received
safety act certifications or other safety act designations to
ensure that these technologies remain effective at mitigating
terrorist acts? Is OSAI adequately resourced to complete
necessary reevaluation processes in a timely fashion?
Mr. Allende. Thank you, Congressman. There are different
sets of certifications that are offered by OSAI, and each of
these is on a renewal review period. So, we periodically
revisit the applications. There is a whole host of requirements
that are part of that, including evaluations sites and so on.
So, yes, we do try to keep with the times and the emerging
threats if that's--I think that answers your question.
Mr. Van Epps. Great. Thank you. Pivoting here--and this
will be for Administrator McNeill--TSA announced at the end of
last year that passengers who do not present a REAL ID or
acceptable form of ID at the TSA security checkpoint would have
to pay a $45 fee for a 10-day travel authorization under new
program called Confirm ID which we've talked about some today.
With the new program starting February 1, the committee has
concerns about whether TSA holds the requisite authority to
levy this fee and bill by the contract for an alternative
travel authorization system. Can you please explain to the
committee why this Confirm ID program is necessary, how this
program does not go against TSA's goal to enforce REAL ID
compliance, and a pulled identification security since it would
allow individuals without proper identification to still travel
simply by paying the fee?
Ms. McNeill. Thank you for your question, Congressman. When
we rolled out enforcement of REAL ID in May 2025, we saw
approximately 93 percent compliance rate. Today, it's around 94
percent. The Confirm ID is really meant to address the
continuing noncompliant populations, about 6 percent of what we
see through our airports every day. It's been 20 years since
Congress passed this law, and, you know, for folks to show up
with a noncompliant ID is a draw on our resources,
operationally. So, and that cost today is borne by the
taxpayer. So the fee is really meant to defray the cost of us
processing people who don't show up with the acceptable form of
ID, ensure that they do not pose a threat to our skies, and
have the fee borne by the noncompliant population.
Mr. Van Epps. Could you just talk a little bit about how
TSA determined the $45 would cover the cost of the travel
authorization for a passenger? Without an acceptable ID, I
believe the original amount considered was $18.
Ms. McNeill. Absolutely. So you know with any fee that we
issue, there is a fee study that we conduct. There was a
realization that we did not include all of the cost in the
initial assessment. That's part of our fee revision process.
You know, we will do so on a recurrent basis to ensure that the
fee reflects the cost of carrying out that program.
Mr. Van Epps. Great. Thank you. Mr. Chairman, I yield back.
Chairman Garbarino. Thank you very much. The gentleman
yields back. I will now entertain--and I appreciate my
colleagues waiting for the--I will now entertain UC motions.
Mr. Thompson. Thank you very much, Mr. Chairman. I ask
unanimous consent to introduce into the record a staffing chart
provided by CISA that shows 65 employees have been transferred
out of CISA in management-directed reassignments since January
20, 2025--and that CISA has lost 998 employees since January
20, 2025. Nearly one-third of its total personnel.
Further, I ask unanimous consent to include in the record 2
articles describing how TSA and CISA are contributing to ICE's
deportation push on behalf of Mrs. Ramirez.
[The information follows:]
[GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
Chairman Garbarino. Without objection. Well, I want to
thank you all, the witnesses, for being here today. One of the
main things we do here is oversight, and this was the first of
many hearings. You all run very important departments under the
Department of Homeland Security. I appreciate your willingness
and your time coming here today. The Members of the committee
may have some additional questions--I know I do--and we would
ask that all the witnesses respond to these in writing.
Pursuant to committee Rule VII(E), the hearing record will
be held open for 10 days. Without objection, this committee
stands adjourned.
[Whereupon, at 12:45 p.m., the committee was adjourned.]
A P P E N D I X I
----------
Questions From Chairman Andrew R. Garbarino For Pedro M. Allende
Question 1. Under Secretary Allende, starting with this year's FIFA
World Cup, our Nation is entering into an unprecedented period of
hosting major international sporting events. How is S&T leveraging its
programs, including the Program Executive Office within S&T you
mentioned during the hearing, to provide C-UAS support to Federal,
State, local, Tribal, and territorial (SLTT) law enforcement entities
ahead of these events, and how is S&T collaborating with other DHS
components in providing this assistance?
Answer. The new Program Executive Office (PEO) for Unmanned
Aircraft Systems (UAS) and Counter-UAS (C-UAS) in U.S. Department of
Homeland Security's (DHS) Science and Technology Directorate (S&T)
announced by Secretary Noem on January 12, 2026, consolidates all
supporting UAS and C-UAS activities across the Department, to include
systems acquisition, research and development, and air space
integration. The PEO will help streamline the Department's exercise of
its
C-UAS authorities and enhance coordination with interagency partners,
as well as State, local, Tribal, and territorial (SLTT) law
enforcement--especially for significant events such as the World Cup
and America 250 celebrations. S&T C-UAS subject-matter experts helped
review submissions from SLTT partners related to the Federal Emergency
Management Agency's C-UAS Grant Program. S&T engineers and research
specialists are also conducting site surveys at World Cup stadium
locations in partnership with SLTT entities to ensure each site
receives adequate
C-UAS equipment and resources. Broadly, the new PEO will address
existing gaps and future challenges by centralizing acquisition
decision making and investment oversight. The Program Executive Office
will also collaborate with the U.S. Departments of Justice,
Transportation, and War, including Joint Interagency Task Force 401 and
other relevant organizations, to synergize acquisition, research and
development, and testing and evaluation activities and reduce
duplication of efforts in the homeland. These changes are fully aligned
with the President's direction to restore air sovereignty over the
United States (Executive Order 14305: Restoring American Airspace
Sovereignty) and secure our Nation's borders (Executive Order 14165:
Securing Our Borders; Presidential Proclamation 10886: Declaring a
National Emergency at the Southern Border of the United States).
Question 2a. Under Secretary Allende, a report by the Government
Accountability Office (GAO) from October 2024 found that DHS S&T could
amend its policies to prevent potential unnecessary research and
development overlap among its Federally-funded research and development
centers (FFRDCs).
S&T's Program Management Office (PMO) has a role in overseeing the
performance of DHS's FFRDCs and ensuring that research and development
activities performed by these FFRDCs do not overlap between each other
and with the research and development activities of DHS components. How
effective has S&T's PMO office been in performing this work and what
challenges remain?
Answer. DHS remains committed to streamlining task oversight across
the Department by centralizing review of analytic research activities,
strengthening documentation requirements, and enhancing enterprise-wide
visibility to prevent duplication of research and development (R&D). We
are also improving collaboration across components to ensure our
investments are aligned, complementary, and directly tied to
operational mission needs.
S&T's Program Management Office (PMO) has enhanced its oversight by
implementing structured portfolio reviews, standardized task order
approval processes, and cross-component coordination mechanisms. These
steps have strengthened our ability to detect and prevent potential
overlap. Establishing a more comprehensive quarterly and annual
Federally-funded research and development centers (FFRDC) performance
review will also enhance oversight, support reducing potential overlap,
and will also support potential reuse of solutions across DHS. The
integration of planning cycles across components remains an area of on-
going focus, and we are committed to continuous improvement.
Question 2b. How does the work completed by DHS's FFRDCs align with
Departmental priorities, and how is S&T and its PMO working to
integrate research performed by FFRDCs into DHS's current strategic
focus?
Answer. FFRDC projects are mapped to DHS strategic priorities,
including border security, Counter-UAS, biosecurity and protection of
critical infrastructure. The PMO ensures that work performed supports
validated mission gaps identified and approved by operational
components. The PMO supports the components in ensuring that the work
is efficiently transitioned to support and effectively impact mission
operations.
Questions From Honorable Timothy M. Kennedy for Pedro M. Allende
Question 1. Under Secretary Allende, DHS's fiscal year 2026 funding
bill, if enacted, would move a significant portion of the Countering
Weapons of Mass Destruction office's mission into your directorate.
Specifically, it transfers funding for ``Mission Support for Research
and Development,'' ``Transformational Research and Development,''
``Technical Forensics,'' and ``Detection Capability Development.'' How
do you plan to integrate these operational and support functions into
your existing research and development structure without losing the
specialized expertise required for WMD threat detection?
Answer. The S&T team has already engaged with the DHS Countering
Weapons of Mass Destruction (CWMD) team to understand their R&D
portfolio and activities. This exercise will allow us to better
collaborate as a single or separate organizations within DHS. S&T will
accept the transfer of these CWMD programs and specialized staff,
ensure their continued operations, and then evaluate program
performance, impact, and outcome to inform the fiscal year 2027 and
out-year budgeting requirements. S&T will enable the programs to
continue to meet the mission and the Congressional direction for these
departmental capabilities.
Question 2a. As Ranking Member of the Subcommittee on Emergency
Management and Technology, I was troubled by the reports stating that
the Trump administration had made the reckless decision to terminate
funding for S&T's Centers of Excellence. These Centers are unique and
essential partnerships between academic institutions, the private
sector, homeland security agencies, and other partners who work
together to produce groundbreaking research that helps keep our Nation
safe now and in the future. For example, one of these Centers focused
on enhancing critical infrastructure security to protect our Nation
against a variety of threats, from natural disasters to attacks by
hostile entities. How many of the 9 Centers of Excellence are currently
operational?
Answer. Although I disagree with your assertion that assessing and
deciding to terminate Centers of Excellence (COE's) was reckless, I
recognize and appreciate the relationships the DHS COE's have forged
with DHS components and the broader Homeland Security Enterprise. On
April 24, 2025, DHS reinstated the cooperative agreements for 2 DHS
COE's:
National Counterterrorism Innovation, Technology, and
Education Center, led by University of Nebraska Omaha.
Arctic Domain Awareness Center--Addressing Rapid Changes
Through Technology Innovation and Collaboration.
The expertise and capabilities afforded through the other 6 Centers
that DHS was funding through cooperative agreements remain available
via utilization of their Basic Ordering Agreement. This task order
vehicle is a funding mechanism through which Government agencies can
directly contract with an emeritus COE, providing streamlined access to
leading researchers. Additionally, projects conducted using a Basic
Ordering Agreement are directly for the benefit of the Government. The
Department is considering the future of the Cross-Border Threat
Screening and Supply Chain Defense COE as it relates to Department and
administration priorities.
Question 2b. If Congress provides funding to keep all 9 of S&T's
Centers of Excellence fully staffed and operational, will you commit to
respecting the will of this body by using that funding to keep these
Centers open?
Answer. I commit to working with you and the committee to align
Congressional appropriations and intent for COE's with administration
priorities. DHS recognizes the value of its partnerships between
academic institutions, the private sector, and homeland security
agencies across the Homeland Security Enterprise. We will continue to
assess pathways for establishing these partnerships in alignment with
administration priorities, including through university-led DHS COE's.
Question 3a. For years, S&T has partnered with Minority-Serving
Institutions, such as Historically Black Colleges and Universities, to
expand the agency's talent pipeline and broaden its research base.
Among other benefits, these partnerships helped DHS address persistent
staffing shortages by producing qualified graduates who were familiar
with DHS mission areas, and who otherwise might not have pursued a
career in homeland security.
Last April, S&T reportedly ended all of its partnerships with
Minority-Serving Institutions. Among other impacts, this pulled the rug
out from students who thought they could count on Federal funding to
help attain their degrees.
What specific deficiencies did S&T identify in its partnerships
with Minority-Serving Institutions that justified ending all of these
partnerships rather than addressing individual issues?
Answer. S&T conducted a comprehensive review of its grants and
cooperative agreements, with special attention given to alignment with
new Departmental directives. Consistent with the administration's
direction to uniformly implement funding restrictions and maintain
fiscal discipline, continued funding of these cooperative agreements
risked potential misalignment with current strategic priorities and
conflicted with newly-issued Departmental guidance.
Question 3b. Does S&T believe it is appropriate for the Federal
Government to abruptly withdraw promised support from students who
relied on these programs to complete their degree programs, and who
want to support our Nation's homeland security posture?
Answer. I do not agree with the premise of your question. S&T is
tasked with a number of competing responsibilities relating to
research, educational support, and general financial stewardship. In
this instance, it was not possible to avoid the effect discontinuing
all grants and cooperative agreements had on individual students. S&T
Directorate continues to meet its mandate in the Homeland Security Act
of 2002 for the Under Secretary for Science and Technology to support
United States leadership in science and technology. Part of this
includes funding internships and fellowships geared toward building the
future homeland security science and engineering workforce. In
addition, we continue to support graduate and undergraduate students
engaged in homeland security research and development through our
current DHS COE's.
Question 3c. If evidence shows that ending these partnerships has
harmed DHS workforce readiness or its homeland security research base,
is S&T prepared to reinstate these programs?
Answer. S&T continually examines the efficiency and effectiveness
of its investments, including those that contribute to workforce
readiness and homeland security research capabilities. Future
investment decisions will be determined by those parameters and
strategic alignment with the administration's priorities to ensure that
we remain good stewards of taxpayer dollars.
Question 4. When DHS was established, S&T played a critical role in
developing technology to harden our critical infrastructure--making it
safer for Americans to fly and take public transportation. Back then
S&T worked closely with Department of Energy labs, as contemplated in
the Homeland Security Act. Unfortunately, in recent years, with
reductions to S&T budget, that relationship has eroded.
As you think about the challenges that you intend to tackle, where
do you see opportunities to reinvigorate the partnership with DOE labs?
Answer. DHS maintains a strong and collaborative partnership with
our colleagues at the U.S. Department of Energy (DOE), specifically
within S&T. S&T continues to play a critical role in developing
technology to harden our critical infrastructure in partnership with
the DOE's National Laboratories as envisioned in the Homeland Security
Act. This partnership, originally established in the Homeland Security
Act, recognized the essential role of DOE labs in supporting DHS's
mission. Over time, this relationship has evolved and been formalized
through a Memorandum of Understanding between DHS and DOE, ensuring
streamlined collaboration and access to world-class scientific
resources. In the face of DOE National Lab realignment and mission re-
focus on energy dominance, our collaboration with the DOE National Labs
remains strong and continues to be a cornerstone of our efforts to
advance homeland security research and technology. Through on-going
coordination facilitated by our Office of National Laboratories, we
have maintained robust engagement, streamlined access, and aligned
projects with DHS mission priorities. As we look ahead to new
challenges, there are numerous opportunities to expand our partnership
with DOE National Labs--leveraging their world-class expertise,
infrastructure, and innovative capabilities to deliver transformative
solutions for homeland security. Our sustained collaboration positions
us well to address emerging threats and enhance the safety and security
of the American public. In both fiscal year 2023 and fiscal year 2024,
DHS funded roughly 240 projects at the DOE National Labs. In fiscal
year 2024 alone, nearly $390 million was expended by DHS to leverage
DOE National Lab capabilities and support our mission.
Questions From Chairman Andrew R. Garbarino for Madhu Gottumukkala
Question 1. As the Sector Risk Management Agency for the
communications sector, CISA has responsibility for helping secure
infrastructure that nearly every other critical infrastructure sector
depends on, including energy, financial services, emergency response,
health care, and transportation. Recent nation-state cyber activity has
made clear that U.S. telecommunications networks are increasingly
viewed by sophisticated adversaries as high-value strategic targets.
Campaigns attributed to PRC-linked actors, such as Salt Typhoon, have
underscored both the scale of the risk and the potential cascading
consequences of disruption in this sector.
Please describe in detail how CISA is currently engaging with
telecommunications providers and other relevant public and private-
sector stakeholders to strengthen the security and resilience of the
communications sector and to mitigate threats posed by cyber actors
affiliated with the PRC. In your response, identify specific programs,
operational activities, and coordination mechanisms CISA is using for
information sharing, threat detection, incident response, and
continuity and resilience planning. Please also explain how these
efforts are designed to reduce the likelihood, severity, and duration
of service disruptions and to ensure continuity of operations for the
critical infrastructure sectors that rely on U.S. communications
networks.
Answer. The Cybersecurity and Infrastructure Security Agency (CISA)
engages with telecommunications providers and other stakeholders to
strengthen the security and resilience of the communications sector and
mitigate threats posed by People's Republic of China-affiliated (PRC)
cyber actors. These activities include continuity planning, information
sharing, guidance, and incident handling.
One of CISA's joint planning efforts focuses on hardening
telecommunications infrastructure against nation-state threats. It
enhances the cybersecurity and resilience of the telecommunications
sector by improving providers' ability to operate through compromise
and recover quickly. Activities include routine threat exchanges and
briefings for telecom executives, tabletop exercises simulating PRC-
linked campaigns, and technical hardening guidance to reduce
vulnerabilities and improve redundancy. Additional measures involve
sector-wide risk modeling to assess cascading impacts on critical
sectors such as energy, health care, and transportation, developing
incident response playbooks, and creating continuity of operations
templates to ensure essential services remain available during
prolonged disruptions.
CISA also leans into information sharing with Government and
industry partners, including the Communications Information Sharing and
Analysis Center. These partnerships help accelerate CISA and the
sector's response to cyber incidents.
Question 2. The Cyber Incident Reporting for Critical
Infrastructure Act (CIRCIA) was signed into law nearly 4 years ago, and
Congress directed CISA to finalize implementing regulations by October
2025. That deadline has now slipped to May 2026. The justification
given by the agency includes a need to better incorporate industry
feedback and streamline the proposed rule to avoid undue burden.
Please explain in detail how CISA is using this additional time to
align the final rule with Congressional intent, including which
elements of the proposed regulation are being revised to reduce
overreach, clarify scope, and ensure the final rule reflects a
practical, risk-based approach for covered entities.
Answer. CISA received many written comments and requests from
entities in critical infrastructure sectors and other stakeholders to
directly engage CISA further on the Cyber Incident Reporting for
Critical Infrastructure Act (CIRCIA) rulemaking. CISA appreciates
stakeholders' interest and concern that CISA implement CIRCIA to
maximize its positive impact on improving the Nation's cybersecurity
posture while minimizing unnecessary burden.
Given the broad stakeholder community that CIRCIA may potentially
impact and significant passage of time (including due to a prolonged
lapse in DHS funding) since publication of the notice of proposed
rulemaking in April 2024, CISA will conduct a series of town hall
meetings to solicit additional input on the notice of proposed
rulemaking (NPRM). At the conclusion of the town hall meeting process,
CISA will evaluate the feedback and determine the most appropriate next
step for the CIRCIA rulemaking.
Question 3. Much of the public and Congressional attention in
recent years has understandably focused on cyber activity attributed to
the People's Republic of China, particularly given the scope,
persistence, and strategic nature of those operations against U.S.
critical infrastructure and government systems. At the same time, other
nation-state actors continue to pose serious, and in some cases, more
immediate cyber risks to the homeland, even if they receive less
sustained attention in public reporting or policy debates.
Please explain how CISA assesses and prioritizes the cyber threats
posed by Russia, Iran, and North Korea relative to the PRC. In your
response, describe how differences in these actors' capabilities,
objectives, and operational patterns are reflected in CISA's analytic,
operational, and resource allocation decisions.
Answer. CISA assesses and prioritizes cyber threats by evaluating
each actor's capabilities, objectives, and operational patterns,
focusing on potential severity and impact to the homeland. The PRC is
the highest-priority threat due to the scale, sophistication, and
persistence of its malicious cyber activity. CISA continues to closely
monitor activity from Russia, Iran, and North Korea, especially focused
on their collective potential to cause disruption or harm. CISA views
Russia as a highly capable and historically aggressive actor, willing
to conduct disruptive operations; this leads to focused analysis on
Russian tools and targeting, joint advisories with partners, and
concentrated support to sectors most vulnerable to disruptive Russian
activity. Iranian cyber operations are often retaliatory or regionally
focused but have demonstrated disruptive potential, prompting CISA to
monitor targeting shifts tied to geopolitical developments and issue
tailored guidance to likely targets. North Korea activity is primarily
financially-motivated cryptocurrency theft, financial fraud, and
ransomware. In response, CISA focuses its analytical and operational
support towards the financial services sector and organizations at risk
from ransomware. These differing profiles directly shape CISA's
analytic priorities, operational planning, and allocation of limited
resources across the threat landscape.
Question 4a. Russia has long demonstrated a willingness to use
cyber operations as a tool of state power, including disruptive attacks
against energy systems, government services, and civilian
infrastructure across Europe. Russia's on-going war against Ukraine has
provided clear examples of how cyber operations are used alongside
military activity to degrade civilian services, disrupt energy and
communications systems, and shape the operating environment during
conflict. These campaigns suggest that Russia treats cyber operations
not merely as espionage tools, but as instruments of coercion and
operational disruption.
Please confirm whether CISA is examining or evaluating Russian
cyber operations related to the war in Ukraine and, if so, explain in
detail how CISA collects and analyzes technical and operational data
from those campaigns and how that information is being used to inform
risk assessments and defensive measures for U.S. critical
infrastructure.
Answer. CISA monitors malicious Russian cyber activity available
through Classified sources, industry and international partners,
cybersecurity vendors, and open-source reports, especially as it
relates to critical infrastructure and government networks. CISA
actively analyzes this data to identify relevant threats and
operational patterns, and shares resulting synthesized insights with
Government and industry partners when applicable to inform risk
assessments and defensive measures.
Question 4b. Please explain how those lessons are being translated
into concrete guidance, preparedness activities, and operational
support for U.S. infrastructure owners and operators.
Answer. CISA issues timely advisories, technical alerts, and best
practices based on threat actor activity. We support readiness by
executing exercises, conducting cybersecurity assessments, and sharing
real-time threat intelligence. These actions equip U.S. Government and
critical infrastructure partners to defend against similar disruptive
cyber tactics.
Question 5a. North Korea presents a different but no less serious
cyber challenge from the PRC and Russia, particularly through
financially-motivated operations tied directly to regime survival. In
addition to well-documented cryptocurrency theft, ransomware activity,
and exploitation of financial systems, there are increasing reports
that North Korea is placing or attempting to place IT workers inside
U.S. and European companies under false identities. These individuals
may gain legitimate access to corporate networks, generate revenue that
flows back to the regime, and create opportunities for follow-on cyber
activity, intellectual property theft, or insider-enabled attacks.
Please describe how CISA is assessing and addressing the threat
posed by North Korean cyber activity, including the placement of North
Korean IT workers inside Western companies. In your response, explain
how CISA works with other Federal agencies and the private sector to
help organizations identify, prevent, and respond to this activity.
Answer. CISA assesses and addresses the threat posed by North
Korean cyber activity by monitoring their tactics and in collaboration
with Government and industry partners, takes appropriate actions to
include information sharing, alerts, and guidance. Together, these
efforts help organizations identify, prevent, and respond to observed
threat activity.
Question 5b. From CISA's perspective, how significant is this
threat to U.S. companies and critical infrastructure, particularly
given the potential for revenues to flow back to the North Korean
regime and support its weapons programs?
Answer. CISA observes that North Korea cyber activity primarily
focuses on revenue generation, targeting organizations that offer the
greatest return on investment. North Korea actors often pursue easier
targets rather than highly secured networks. Implementation of basic
and foundational cyber defense and hygiene measures is the greatest
defense to protect U.S. companies and critical infrastructure. We
actively monitor threat reporting for evolving tactics; however, robust
cybersecurity fundamentals remain currently effective in mitigating
this threat.
Question 6a. In December, CISA released a new report titled Venue
Guide for Mitigating Dependency Disruptions to help stadiums and arenas
strengthen resilience ahead of major events such as the 2026 FIFA World
Cup, America 250, and the 2028 Summer Olympics. The guide focuses on
lifeline dependencies, including energy, communications, water, and
transportation, and how disruptions to those systems could affect
public safety at large gathering venues. At the same time, we are
seeing growing concern about the use of unmanned aircraft systems,
including drones, as a means to disrupt venue operations or exploit
dependencies on critical lifeline services during high-profile events.
Please describe CISA's current assessment of the evolving drone
threat to stadiums, arenas, and other public gathering venues.
Answer. Threats posed by unmanned aircraft systems (UAS) to
stadiums, arenas, and other public gathering venues are evolving as
commercial UAS platforms become more widely accessible and technically
capable, raising the potential for both negligent and intentional
misuse that could disrupt safety, operations, or critical dependencies
at high-profile events. The 2025 DHS Homeland Threat Assessment
underscores that UAS activity over sensitive critical infrastructure
and large public venues remains a significant risk, with the potential
to disrupt facility operations, impede emergency response, and enable
intelligence collection by malign actors.\1\ Further compounding the
challenge, small UAS platforms are increasingly capable of carrying
larger, more sophisticated payloads, conducting surveillance, and
undermining critical lifeline services. Even non-malicious or reckless
activity can trigger serious safety, security, and operational
consequences, including flight disruptions, crowd safety hazards, and
delays in emergency response. High-profile events such as the 2026 FIFA
World Cup, America 250 celebrations, and the 2028 Summer Olympics
present attractive targets, as demonstrated by the interception of 53
unauthorized drones during the 2024 Paris Olympics.\2\
---------------------------------------------------------------------------
\1\ Department of Homeland Security, 2025 Homeland Threat
Assessment, 2025, dhs.gov/publication/homeland-threat-assessment.
\2\ Elaine Cobbe, CBS News. ``2024 Paris Olympics security
challenges include 53 intercepted drones and 5,000 people barred from
the Games,'' August 1, 2024, cbsnews.com/news/2024-paris-olympics-
security-drones-intercepted-5000-people-barred-from-games/.
---------------------------------------------------------------------------
Question 6b. Please explain how CISA is incorporating drone-related
risks into its guidance, planning, and engagement with venue owners,
operators, and State and local partners, including how these risks are
factored into dependency mapping, vulnerability assessments, and event
preparedness.
Answer. CISA integrates UAS risk considerations into its efforts to
strengthen stakeholder capabilities, recognizing these threats as an
escalating concern that requires proactive planning, coordination, and
layered security measures to protect public venues and the critical
services they depend on, and incorporates these considerations across
our guidance, planning, and engagement activities:
Guidance.--Includes specialized resources with UAS-focused
content to raise awareness and provide risk mitigation
recommendations, through our Be Air AwareTM website
that equips organizations with information and recommendations
to advance UAS risk management and increase security and
resilience against UAS threats, including:
Unmanned Aircraft System Detection Technology Guidance for
Critical Infrastructure provides critical infrastructure
owners and operators with key considerations for how to
select and leverage detection technology to increase
awareness of UAS activity over a facility or site.
Safe Handling Considerations for Downed Unmanned Aircraft
Systems provides information on how to prepare for and
respond to downed UAS that may pose a safety or security
concern.
Suspicious Unmanned Aircraft System Activity Guidance for
Critical Infrastructure Owners and Operators offers
criteria for recognizing suspicious UAS activity and
recommendations for responding appropriately.
Suspicious UAS Identification Poster and Postcard are
quick-reference visual guides that help security personnel
and the public recognize indicators of potentially
suspicious drones, outlining warning signs, and
recommending safety actions such as treating grounded UAS
as potential explosive threats and reporting incidents to
law enforcement.
Interagency Security Committee Best Practices for
Protecting Against the Threat of UAS provides Federal
facility security professionals and critical infrastructure
stakeholders with guidance on UAS threats, offering
strategies for vulnerability assessments, protective
measures, workforce awareness, and response planning to
mitigate malicious drone activity.
Planning.--Addresses UAS risks through coordinated air space
security measures and preparedness exercises. These activities
help stakeholders understand the potential impacts of UAS
incidents and strengthen operational readiness for major
events.
In fiscal year 2025, 224 temporary flight restrictions
were coordinated with the FAA to secure air space for
special events, helping minimize risks from unauthorized
UAS operations and deter activity that could lead to
security incidents.
CISA Tabletop Exercise Packages regularly include UAS
scenarios and outline potential consequences--such as
disruptions to nearby infrastructure--providing a self-
service tool for stakeholders to examine plans and
procedures, and CISA complements this by conducting
facilitated, full-scale exercises with partners to
strengthen preparedness and coordination.
Engagement.--Focuses on training, dependency and
vulnerability analysis, and interagency coordination to
strengthen Federal, State, local, Tribal, territorial, and
critical infrastructure partner readiness and mitigate UAS
risks.
In fiscal year 2025, more than 370 infrastructure
assessments incorporate UAS risk considerations to help
venues identify dependencies and reduce potential
disruptions.
Accredited counter-improvised explosive device and risk
mitigation training builds stakeholder capabilities to
address weaponized UAS tactics and enhance protective
measures.
Information sharing and technical assistance improve
situational awareness and support timely, coordinated
responses to emerging UAS threats.
Regional security advisors actively engage with and
support local stakeholders by raising awareness and
connecting them with available CISA UAS resources that
support effective planning and coordination.
Question 7. CISA plays an important role in defending Federal
civilian networks, including through capabilities such as Continuous
Diagnostics and Mitigation (CDM) and broader Federal threat detection
and response efforts. As nation-state cyber activity becomes more
persistent and sophisticated, the effectiveness of these programs is
critical to preventing intrusions from becoming large-scale incidents.
At the same time, both defenders and adversaries are increasingly using
AI and automated tools to accelerate detection, analysis, and
exploitation, raising important questions about how Federal cyber
defense capabilities are evolving to keep pace.
Please describe CISA's current assessment of Federal civilian
network visibility and response capabilities, including how automation
and AI-enabled tools are being integrated into detection, analysis, and
mitigation activities.
Answer. CISA continues to make investments to increase visibility
throughout Federal agency networks via the Continuous Diagnostics and
Mitigation (CDM) program, cyber shared services, and on-going
coordination with agencies. Through CDM, CISA has improved asset
visibility across newer asset classes, including mobile devices, cloud
services, and internet of things/operational technology devices. These
efforts are expanding CISA's operational visibility. Additionally, CISA
is expanding network-level visibility through new CDM capabilities such
as advanced network protection and security information and event
management as a service. For those agencies that are in the process of
adopting newer capabilities, CISA's operational visibility is
substantially improved. The Federal Government's investments in
endpoint detection and response capabilities further improve network
visibility by complementing CDM asset management and network security
management capabilities. Specifically, the use of endpoint detection
and response and enrollment of agencies within CISA's persistent access
capability result in significantly improved detection by adding near
real-time and detailed, host-level asset and activity visibility.
Additionally, the operationalization of endpoint detection and
response and CISA's persistent access capability has greatly improved
CISA's response capabilities. For those agencies enrolled, CISA can
collaborate in real time with agency security operations centers to
investigate and action against threats that span agency boundaries or
utilize techniques for which there are no known indicators. When
conducting advanced investigations and incident response, utilizing
persistent access capability reduces CISA's time to engage with
agencies from days to minutes. It eliminates the logistical challenges
and delays associated with traditional on-premises response, allowing
analysts in CISA to work directly with agencies virtually.
All these visibility and response capabilities utilize commercial
off-the-shelf tools, many of which are incorporating artificial
intelligence-assisted capabilities into their standard commercial
platforms. This approach has resulted in better correlation of
seemingly unrelated data points that assist in detection, more
effective elimination of false positives, and reduction of manual labor
required when performing detailed analysis.
Question 8. For many years, the Critical Infrastructure Partnership
Advisory Council, or CIPAC, provided a formal, legally-supported
framework that enabled sustained and structured engagement between the
Federal Government and private-sector owners and operators of critical
infrastructure. Since its discontinuation, a number of stakeholders
have expressed uncertainty about how best to coordinate planning
efforts, share sensitive but unclassified information, and maintain
consistent and reliable engagement with the Department on risk
management and incident preparedness. Recent public reporting indicates
that the Department is finalizing a new engagement construct referred
to as ANCHOR that is intended to address these gaps.
Can you describe in detail where DHS is in the process of
finalizing and implementing ANCHOR, how the construct is expected to
operate in practice across sectors, and how this new model will provide
the clarity, predictability, and collaboration that private-sector
partners need to manage cyber and infrastructure risk alongside the
Federal Government?
Answer. The U.S. Department of Homeland is working to implement a
new partnership framework, and we look forward to sharing additional
details as soon as we can. Rapidly-evolving cyber threats demand a new
level of partnership between Government and industry--one that goes
beyond exchanging data to true actionable collaboration. Looking ahead,
we need to continue to shift from transactional sharing to true
actionable collaboration. In today's environment we know that sharing
information alone isn't enough; we need joint action and shared
responsibility.
Question 9. CISA is often called upon to provide surge support
during major cyber incidents affecting Federal agencies, State and
local governments, or critical infrastructure operators. Maintaining
that response capacity during periods of workforce transition and
elevated threat is essential to the agency's credibility and
effectiveness.
Please explain how CISA is ensuring it retains sufficient incident
response and surge capacity to respond to major cyber events, including
what steps are being taken to sustain operations if multiple
significant incidents occur simultaneously.
Answer. CISA prioritizes the most critical operations--those that
protect national security, critical infrastructure, and mission-
essential systems. Prioritizing incident response and threat-hunting
efforts along those lines enables rapid response to high-risk
incidents, optimizes limited resources, and aligns efforts with
strategic objectives. This ensures we aren't only reactive, but also
take a proactive and prioritized approach, making the most efficient
use of our resources to safeguard Federal networks and those of
critical infrastructure operators.
Currently, CISA's support in protecting and remediating the
networks of Federal agencies and critical infrastructure owners and
operators is based around the ability to support multiple on-going
engagements with compromised entities at one time. In the event of an
exigent major cyber event, CISA prioritizes finite resources towards
threats assessed to be more significant to national security.
Additionally, CISA leverages trusted partnerships with Federal and
private stakeholders when appropriate to assist entities affected by
significant cyber events.
Question 10. CISA has emphasized Secure-by-Design principles as a
way to encourage stronger security practices by technology
manufacturers and reduce the burden placed on end-users. This approach
reflects a longer-term effort to improve the security of products
before they are widely deployed.
Please describe the progress CISA has made in advancing Secure-by-
Design principles and explain how the agency is working with industry
to translate these principles into measurable improvements in product
security.
Answer. CISA continues to advance Secure-by-Design principles by
publishing relevant, actionable guidance on topics such as modernizing
the common baseline of software bills of materials, a key for supply
chain risk management;\3\ how to improve authentication practices by
critical infrastructure providers; working with the open-source
software community to support secure development of the software that
underlies the software products that Americans rely on;\4\ how to
securely develop artificial intelligence software systems;\5\ and how
organizations can acquire software that is secure by design.\6\ CISA is
also measuring the effectiveness of the Secure-by-Design Pledge through
the voluntary progress reports provided by pledge signers. A
vulnerability management community such that consumers and operators
know when there are vulnerabilities in their software continues to be a
focus.\7\ Also, collaborating with international partners towards
harmonization of Secure-by-Design expectations, as represented by the
international partner co-seal endorsement on CISA's Secure-by-Design
publications referenced above.
---------------------------------------------------------------------------
\3\ Department of Homeland Security. Request for Comment on 2025
Minimum Elements for a Software Bill of Materials. Aug 22, 2025.
Federal Register Notice 90 FR 41094.
\4\ CISA. Open Source Security. https://www.cisa.gov/opensource.
\5\ CISA and NCSC-UK. Guidelines for secure AI system development.
Nov 27, 2023.
\6\ CISA. Secure by Demand Guide: How Software Customers Can Drive
a Secure Technology Ecosystem. 2025. https://www.cisa.gov/resources-
tools/resources/secure-demand-guide.
\7\ See for example the continued operational work in support of
BOD 22-01: Reducing the Significant Risk of Known Exploited
Vulnerabilities, CISA's coordinated vulnerability disclosure program,
and the CISA ``Vulnrichment'' project (which supplies information about
vulnerabilities to Federal agencies and the public to support risk-
informed cybersecurity decision making).
---------------------------------------------------------------------------
CISA is working with industry to translate principles into
measurable improvements by holding regular sessions of the Technical
Exchange Group for industry pledge signers to learn from one another
through voluntary presentations on pledge goal progress. Additionally,
CISA directed all devices on Federal information networks to receive
supported security updates.\8\
---------------------------------------------------------------------------
\8\ CISA. BOD 26-02: Mitigating Risk From End-of-Support Edge
Devices. Feb 5, 2026.
---------------------------------------------------------------------------
Question 11. Artificial intelligence is increasingly shaping both
offensive and defensive cyber operations. While adversaries are already
leveraging AI to scale attacks, these tools also offer opportunities to
improve detection, analysis, and response.
Please describe how CISA is currently incorporating AI into its
operations and identify which applications show the greatest promise
for improving detection, analysis, and response across Federal networks
and critical infrastructure.
Answer. CISA regularly evaluates tools for their potential to
improve automation for CISA's mission. For example, CISA published the
results of our Pilot for Artificial Intelligence Enabled Vulnerability
Detection.\9\ Following Departmental guidance, CISA publishes an
inventory of all the Artificial Intelligence use cases we currently
deploy or plan to deploy for our mission: https://www.cisa.gov/ai/cisa-
use-cases.
---------------------------------------------------------------------------
\9\ CISA. Pilot for Artificial Intelligence Enabled Vulnerability
Detection. July 29, 2024. https://www.cisa.gov/resources-tools/
resources/pilot-artificial-intelligence-enabled-vulnerability-detection
---------------------------------------------------------------------------
Often, CISA finds that the best defenses against AI-enabled cyber
incidents address weak or vulnerable points in the information system
infrastructure through cybersecurity best practices. This includes more
thorough application of existing guidance such as adhering to Secure-
by-Design principles (described in Question 10), patching known
exploited vulnerabilities, following CISA's cybersecurity performance
goals, publishing an organizational vulnerability disclosure policy,
using phishing-resistant multi-factor authentication, and practicing or
exercising incident response and recovery.
Question 12. While large-scale quantum computing threats may still
be years away, the transition to post-quantum cryptography will require
early planning and coordination across Government and industry.
Please describe how CISA is assisting Federal agencies and critical
infrastructure operators in preparing for this transition, including
what actions are being taken now to ensure systems can migrate securely
to post-quantum standards.
Answer. CISA recognizes the threat that cryptographically-relevant
quantum computers pose to traditional encryption and is taking
proactive measures to prepare Federal agencies, State, local, Tribal,
and territorial governments, and critical infrastructure owners and
operators for a secure migration to quantum-resistant systems.
CISA helps raise awareness about the quantum computing threats and
the actions needed to mitigate them by regularly engaging with partners
across Government, critical infrastructure, and industry. Feedback from
these engagements informs actionable recommendations to accelerate
migration to post-quantum cryptography.
CISA publishes guidance and best practices on its post-quantum
cryptography webpage. Topics include considerations for operational
technology, strategies for automated cryptographic discovery and
inventory, and product categories that use post-quantum cryptography
standards. These resources are often developed in collaboration with
interagency partners. CISA actively collaborates with international,
interagency, industry, and critical infrastructure stakeholders to
coordinate efforts, share insights, and harmonize approaches for post-
quantum migration.
CISA works with the Office of Management and Budget (OMB) and the
Office of the National Cyber Director (ONCD) to collect annual
cryptographic inventories to understand the scope of the problem. The
agency analyzes these inventories, identifies challenges, and shares
lessons learned with Federal agencies. CISA also partners with the
National Institute of Standards and Technology (NIST) to demonstrate
automated cryptographic discovery and inventory tools, which will
improve visibility into cryptographic vulnerabilities and support
automation.
Questions From Honorable August Pfluger For Madhu Gottumukkala
Question 1a. In recent years, there has been no shortage of high-
profile cyber attacks attributed to our foreign adversaries, including
SolarWinds, Colonial Pipeline, and, more recently, campaigns like Volt
Typhoon and Salt Typhoon targeting U.S. critical infrastructure and
telecommunications networks.
We have also seen Iran-aligned groups such as Cyber Av3ngers probe
U.S. industrial control systems and water utilities, underscoring that
multiple adversaries are targeting our critical infrastructure.
Last month, it was widely reported that Salt Typhoon struck again,
compromising email systems used by House staff on select committees
dealing with China, foreign affairs, intelligence, and armed services.
How is CISA working with critical infrastructure operators and
other relevant stakeholders to strengthen resilience in the
communications sector?
Answer. CISA engages with telecommunications providers and other
stakeholders to strengthen the security and resilience of the
communications sector and mitigate threats posed by PRC cyber actors.
These activities include continuity planning, information sharing,
guidance, and incident handling.
One of CISA's joint planning efforts focuses on hardening
telecommunications infrastructure against nation-state threats. These
efforts enhance the cybersecurity and resilience of the
telecommunications sector by improving providers' ability to operate
through compromise and recover quickly. Activities include routine
threat exchanges and briefings for telecom executives, tabletop
exercises simulating PRC-linked campaigns, and technical hardening
guidance to reduce vulnerabilities and improve redundancy. Additional
measures involve sector-wide risk modeling to assess cascading impacts
on critical sectors such as energy, health care, and transportation,
developing incident response playbooks, and creating continuity of
operations templates to ensure essential services remain available
during prolonged disruptions.
CISA also leans into information sharing with Government and
industry partners, including through the Communications Information
Sharing and Analysis Center. These partnerships help accelerate CISA
and the sector's response to cyber incidents.
Question 1b. One issue CISA and the committee have been focused on
is the threat posed by end-of-life network equipment that is so old it
cannot be patched. How big of a problem is this issue, and what more
can be done to secure our critical infrastructure, like Federal agency
environments, from this risk?
Answer. End-of-support devices, which no longer receive security
updates from vendors, present a substantial and constant cybersecurity
risk. CISA has observed advanced threat actors widely targeting these
end-of-support edge devices, which when compromised, can provide the
threat actor with extensive access to the victim's networks.
Organizations can mitigate this threat by ensuring devices are
proactively replaced before they become end-of-support.
CISA issued Binding Operational Directive 26-02 on February 5,
2026. This Directive requires Federal agencies to phase out unsupported
edge devices. CISA strongly recommends other organizations, including
critical infrastructure, to voluntarily take the mitigatory actions in
the Directive to address the risk beyond the Federal Government.
Question 2a. I have heard from stakeholders that when a
sophisticated cyber attack occurs, multiple agencies reach out to them,
both seeking information on the scale of the attack and offering
assistance.
What ends up happening is that the company has to repeatedly
process and respond to duplicative requests, which takes manpower and
resources away from responding to the attack.
Under CIRCIA and the National Cyber Incident Response Plan, is it
CISA's role to serve as the primary Federal interface for a private
entity going through a major cyber attack?
Answer. For cyber incident response, 6 U.S.C. 659 and PPD-41
dictate that CISA leads the asset response activities, including
offering technical support to reduce impacts of cyber incidents and
speed recovery. PPD-41 separately provides that Federal Bureau of
Investigation (FBI) leads threat response activities, leading
investigations in pursuit and disruption of threat activity, and the
Office of the Director of National Intelligence (ODNI) leads
intelligence response. This complementary relationship ensures that
each agency's mission is carried out and coordinated in parallel to
ensure speed in response and recovery. CISA, FBI, and ODNI continuously
synchronize efforts as appropriate, including to perform notifications
and provide incident response support.
For cyber incident reporting, CIRCIA tasks other Federal agencies
that receive cyber incident reports, following implementation of the
CIRCIA final rule, to share such reports with CISA for further
interagency sharing and coordination (6 U.S.C. 681g). This will help
provide a clearer picture of the threat landscape, enriching CISA and
Federal partners' ability to carry out their respective cybersecurity
missions. A goal of CIRCIA is to reduce the burden of entities
reporting to multiple agencies so they can focus on incident response.
CISA is committed to these benefits as it works to finalize the rule
for CIRCIA.
Question 2b. How are you working with other Federal agencies to
streamline reporting and coordination, so that from the company's
perspective they are not answering the same questions over and over
while they are still trying to contain the incident?
Answer. CISA continuously deconflicts with the FBI and Sector Risk
Management Agencies when appropriate to avoid duplicating efforts
during incident response.
Question 3a. Congress is actively working toward a long-term
reauthorization of the Cybersecurity Information Sharing Act of 2015,
recognizing that it created the legal backbone for cyber threat
information sharing between Government and the private sector.
CISA 2015's liability protections, FOIA exemptions, and authorities
helped address long-standing concerns from ISPs, cloud providers, and
other critical-infrastructure owners about sharing sensitive threat
data with the Government and with each other.
At the same time, the threat environment and technology landscape
have changed dramatically since 2015, with the rise of cloud, AI-
enabled threats, and persistent campaigns such as Volt Typhoon and Salt
Typhoon targeting U.S. infrastructure.
From your perspective, why are the core protections and authorities
in CISA 2015 still essential to CISA's ability to work effectively with
industry today?
Answer. The U.S. Government and our private-sector partners rely on
the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501 et.
seq) to keep America safe. It fuels the trust, speed, and collaboration
that make us stronger together. The law's protections play a vital role
in the sharing of cyber threat indicators and defensive measures among
private-sector entities and with Federal agencies, as well as in
monitoring and defending their networks. Specifically, the law
authorizes private entities to monitor their networks for cybersecurity
purposes and to deploy defensive measures to detect or block malicious
cyber threats on their networks without implicating Federal and State
laws that may complicate defensive actions. Private entities are
authorized to share cyber threat indicators or defensive measures with
Federal and other entities for cybersecurity purposes, with protections
including liability protection; an anti-trust exemption for private
entities sharing with each other; exemptions from Federal and State
disclosure laws and regulatory use; and preserved privilege for shared
material.
Question 3b. Are there areas where additional authority from
Congress would materially improve CISA's ability to defend the U.S.
Government and support critical-infrastructure operators?
Answer. CISA is grateful that this committee advanced by a
unanimous (25-0) vote H.R. 5079, the Widespread Information Management
for the Welfare of Infrastructure and Government Act. This legislation
would reauthorize the Cybersecurity Information Sharing Act of 2015 for
another 10 years. This is an important step in strengthening our
defenses at a time when our adversaries are constantly testing us. We
stand ready to assist Congress in any way to ensure that these critical
protections remain in place.
Question From Honorable Matt Van Epps For Madhu Gottumukkala
Question. Dr. Gottumukkala, while large-scale quantum computing
threats may still be years away, the transition to post-quantum
cryptography will require early planning and coordination across
Government and industry. How is CISA helping Federal agencies and
critical infrastructure operators prepare for this transition, and what
steps are being taken now to ensure systems can migrate securely to
post-quantum standards when the time comes?
Answer. CISA recognizes the threat that cryptographically-relevant
quantum computers pose to traditional encryption and is taking
proactive measures to prepare Federal agencies, State, local, Tribal,
and territorial governments, and critical infrastructure owners and
operators for a secure migration to quantum-resistant systems.
CISA helps raise awareness about the quantum computing threats and
the actions needed to mitigate them by regularly engaging with partners
across Government, critical infrastructure, and industry. Feedback from
these engagements informs actionable recommendations to accelerate
migration to post-quantum cryptography.
CISA publishes guidance and best practices on its post-quantum
cryptography webpage. Topics include considerations for operational
technology, strategies for automated cryptographic discovery and
inventory, and product categories that use post-quantum cryptography
standards. These resources are often developed in collaboration with
interagency partners. CISA actively collaborates with international,
interagency, industry, and critical infrastructure stakeholders to
coordinate efforts, share insights, and harmonize approaches for post-
quantum migration.
CISA works with OMB and the ONCD to collect annual cryptographic
inventories to understand the scope of the problem. The agency analyzes
these inventories, identifies challenges, and shares lessons learned
with Federal agencies. CISA also partners with the NIST to demonstrate
automated cryptographic discovery and inventory tools, which will
improve visibility into cryptographic vulnerabilities and support
automation.
Questions From Chairman Andrew R. Garbarino For Ha Nguyen McNeill
Question 1a. As TSA is set to launch the new Confirm.ID program
February 1, 2026, the committee remains concerned over the scope of the
program and TSA's requisite authority to implement it. In official
statements and briefings to the committee, TSA has asserted its
authority to set a fee under Confirm.ID derives from the Registered
Traveler program. However, TSA has also separately cited Pub. L. 109-90
and 49 U.S.C. 114 as legal justification for the start of this new
program. Specifically, the statutory language cited by TSA only notes
the existence of the Registered Traveler program, and TSA's ability to
recover costs associated with such programs.
Please clarify, how does TSA hold the requisite authority to start
the Confirm.ID program without explicit Congressional authorization?
Answer. The Transportation Security Administration (TSA) has broad
statutory authority to prescribe screening measures and procedures for
individuals entering the sterile areas of airports.\1\ The Intelligence
Reform and Terrorism Prevention Act of 2004 (IRTPA) directs TSA to
perform ``the passenger prescreening function of comparing passenger
information to the automatic Selectee and No Fly lists and utilize all
appropriate records in the consolidated and integrated terrorist
watchlist maintained by the Federal Government in performing that
function.''\2\ TSA carries out this statutory requirement through the
Secure Flight program, which relies on information that passengers
provide to airlines at the time they make a reservation.\3\ Secure
Flight compares the passenger's reservation information to the
identifying information of individuals on Federal Government watch
lists and informs the airline whether or not it may issue a boarding
pass based on the results of the prescreening process. IRTPA further
directs TSA to establish ``procedures to ensure that individuals
selected by [computer assisted passenger pre-screening] and their
carry-on and checked baggage are adequately screened.''\4\ Identity
verification procedures at the checkpoint are necessary to ensure that
each passenger receives the appropriate level of screening, or is
denied entry to the sterile area, in accordance with Secure Flight
vetting results and security considerations.
---------------------------------------------------------------------------
\1\ See, e.g., 49 U.S.C. 44901(a)-(b) (directing TSA to provide
for and supervise the screening of all passengers and property that
will be carried aboard a passenger aircraft); 44903(j)(2)(A)(ii)
(requiring TSA to establish ``procedures to ensure that individuals
selected by [computer-assisted passenger prescreening] and their carry-
on and checked baggage are adequately screened''); 114(f)(3) (directing
TSA to ``develop policies, strategies, and plans for dealing with
threats to transportation security''); 114(f)(11) (directing TSA to
``oversee the implementation, and ensure the adequacy, of security
measures at airports''); 114(h)(3) (requiring TSA to establish policies
and procedures to prevent individuals who may be a threat to civil
aviation or national security from boarding an aircraft).
\2\ 49 U.S.C. 44903(j)(2)(C)(ii).
\3\ Secure Flight Program, 73 Fed. Reg. 64018 (2008) (codified at
49 CFR parts 1540, 1544, 1560).
\4\ 49 U.S.C. 44903(j)(2)(A)(ii); see also 49 U.S.C. 44901(a).
---------------------------------------------------------------------------
Under TSA's current screening procedures, the primary method of
identity verification at the checkpoint is asking a passenger to
present an acceptable form of ID that matches the passenger's
identifying information in Secure Flight. TSA has long sought to
facilitate passenger travel, consistent with its responsibility to
ensure the security of aviation. For this reason, using appropriated
funds, TSA has historically provided a call-center-based option to
attempt to identify individuals who failed to produce acceptable IDs at
the checkpoint. The limited number of individuals who used this
alternative identity verification process received substantially
heightened screening.
With full enforcement of REAL ID, the number of individuals
presenting without acceptable ID at the checkpoint significantly
increased, exceeding both the capacity of the call center and resources
for subsequent additional screening. As a result, TSA transformed its
process for alternative identity verification, replacing a one-size-
fits-all approach with a registered travel identity verification model.
The new model allows individuals who choose to participate to provide
additional biographic and/or biometric information that TSA can
leverage for alternative identity verification, with differing levels
of reliability. As a result, there is a continuum of risk-based
screening that reflects both the information available to TSA as part
of the Secure Flight vetting process, including whether an individual
has been vetted as a member of TSA PreCheck, and TSA's level of
identity assurance that the pre-vetting established by Secure Flight
applies to the individual presenting at the checkpoint. ConfirmID, like
all TSA registered traveler programs, allows passengers to receive
facilitated travel while enabling TSA to appropriately assign limited
screening resources based on the risk associated with the individual
passenger.
Question 1b. How did TSA come to the determination to include
Confirm.ID under the Registered Traveler program?
Answer. In 2006, Congress directed TSA to collect a non-refundable
fee to cover the costs of any registered traveler program.\5\ This
provision requires TSA to ``impose a fee for any registered traveler
program undertaken by the U.S. Department of Homeland Security (DHS) by
notice in the Federal Register'' provided that ``such fees shall not
exceed the aggregate costs associated with the program.'' TSA may also
modify the fee through notice published in the Federal Register. As
exemplified by the 2008 Registered Traveler Interoperability Pilot
Program Fee Notice, programs funded under registered traveler fee
authority have always consisted of components including Secure Flight
vetting, additional pre-vetting, and identity verification.\6\ In fact,
registered traveler programs consisting solely of enhanced identity
verification and Secure Flight vetting, without additional pre-vetting,
are active at 60 airports across the Nation through public-private
partnership. As TSA transformed its former ``back-up call center'' into
a multi-tiered capability for alternative identity verification, where
passengers provide additional biographic and/or biometric information
to enable access to expedited risk-based screening and TSA's
application of limited screening resources to the highest-risk
passengers, it was determined the program fit within the ``registered
traveler'' category alongside those other programs. Therefore,
consistent with the statutory mandate, TSA imposed a fee to recover the
costs of providing this service, ensuring that individuals who benefit
from the program rather than the taxpayer bear those costs.
---------------------------------------------------------------------------
\5\ Department of Homeland Security Appropriations Act, 2006,
Public Law 109-90, sec. 540, (119 Stat. 2064, 2088-89 (Oct. 18, 2005))
(codified at 49 U.S.C. 114 note).
\6\ 73 Fed. Reg. 44275 (July 30, 2008).
---------------------------------------------------------------------------
Question 1c. Given this, why would TSA interpret the Registered
Traveler program to mean it has free-standing authority to create any
new program under the guise of ``Registered Traveler,'' even when
Confirm.ID explicitly deals with travelers outside the Trusted Traveler
population?
Answer. Reliable identity verification has long been a fundamental
component of Registered Traveler programs. There are existing
registered traveler programs that, like ConfirmID, rely on identity
verification alongside Secure Flight vetting.\7\ Identity verification
is the first step of physical screening at a TSA security checkpoint
and the last step of TSA's intelligence-based prescreening of
individuals. It ensures individuals receive the appropriate level of
screening, ranging from expedited screening to enhanced screening
(i.e., Selectees), including any additional screening associated with
special circumstances, before entering the sterile area of an airport
or boarding a flight. It also ensures that individuals designated as
``No Flys'' are excluded from the screening checkpoint. There is a
continuum of risk-based screening that reflects both the information
available to TSA as part of the Secure Flight vetting process,
including whether an individual has been vetted as a member of TSA
PreCheck, and TSA's level of identity assurance that the vetting
status established by Secure Flight applies to the individual
presenting at the checkpoint. Although ``trusted traveler'' programs
that involve additional vetting in advance of passenger arrival also
rely on registered traveler fee authority, it is not additional pre-
vetting of individuals beyond Secure Flight that defines something as a
registered traveler programs, but rather the provision of additional
biographical and/or biometric information by passengers that in turn
enables TSA to appropriately assign screening resources based on the
risk associated with that individual passenger. As with all registered
traveler programs, this serves both to expedite low-risk passenger
travel and maximize the security effectiveness of finite TSA screening
resources.
---------------------------------------------------------------------------
\7\ 73 Fed. Reg. 44275 (July 30, 2008).
---------------------------------------------------------------------------
Question 1d. Last, please explain further how the TSA does not view
this as a ``mandatory'' fee, but rather as an optional one. Wouldn't a
passenger going through the Confirm.ID process be required to pay the
fee in order to receive the 10-day travel authorization?
Answer. ConfirmID is not mandatory; but like all registered
traveler programs, it requires a fee to use the service. ConfirmID
participation is not required for passengers to receive TSA security
screening and enter the sterile area. Under TSA's current screening
procedures, the primary method of identity verification at the
checkpoint occurs through the presentation of an acceptable form of ID
that matches the passenger's identifying information provided to Secure
Flight. TSA's list of acceptable forms of ID is prescribed in the
Checkpoint and Specialized Screening Standard Operating Procedures, and
TSA has published an abbreviated list (which includes the most common
and widely-accepted IDs) for the public at TSA.gov.
ConfirmID represents a risk-based effort by TSA to provide
alternative identity verification options when an individual arrives at
the checkpoint without an acceptable form of ID to facilitate passenger
travel, consistent with TSA's responsibility to ensure the security of
aviation. Federal Security Directors retain additional authorities
regarding the screening process to address special circumstances.
Question 2a. TSA has long emphasized a ``layered approach'' to
transportation security, from the deployment of canine units to
advanced technologies, to enhance the screening process and maintain
the safe flow of travel.
What does the layered security approach look like today, and can
you explain how it is currently implemented? Specifically, can you
address the role explosive detection canine units play within that
framework?
Answer. Every day, TSA relies on its intelligence and risk-based,
layered security approach to aviation security that employs over 20
layers, seen and unseen, from vetting and checkpoint screening to in-
flight security. TSA is prepared to offer a briefing at the proper
classification level for layered security approach.
TSA's layered approach begins before an individual arrives at the
TSA checkpoint, when he or she is vetted through Secure Flight, TSA's
automatic pre-screening program. Key to this security layer is identity
verification, which ensures passengers receive the appropriate level of
physical screening at the TSA checkpoint. Through automation efforts,
TSA is able to leverage the Credential Authentication Technology and
Touchless Identity Systems biometrics to confirm the passenger's
identity and ensure the passenger does not present a threat to aviation
security.
In keeping with TSA's layered security approach, Explosive
Detection Canine teams can be used to reduce risk and facilitate more
efficient screening during periods of high passenger throughput or when
checked baggage screening capacity has been exceeded. TSA continuously
advances deployment strategies for Explosive Detection Canine teams
through rigorous research, testing, and analysis. Canines serve as a
critical complement to TSA's advanced technologies, providing
capabilities that are additive, not substitutive. Where canine assets
are deployed, they significantly enhance security operations by
offering rapid, non-intrusive screening for explosives and explosive
devices. Canines act as a visible deterrent to malicious activity and
are uniquely able to adapt quickly to dynamic environments and evolving
threats. Their exceptional ability to detect concealed threats in
crowded and complex areas strengthens TSA's security protocols,
delivering an additional layer of protection that is both flexible and
highly effective. This synergy between canine teams and advanced
technology ensures a robust, multi-faceted approach to safeguarding
transportation systems.
Question 2b. What risk assessments drive a decision not to deploy
canine units, and how does TSA ensure that any security gaps are still
mitigated?
Answer. The primary constraint on deploying canine units at a
particular location is the availability of the resource rather than a
risk assessment. Canine units are unique in their deterrent effect and
their high-volume screening capability, and they are therefore often
deployed where those characteristics--in addition to their detection
capabilities--are most needed. In the absence of canine units, security
gaps are mitigated with other screening capabilities. TSA is prepared
to offer a briefing at the proper classification setting to discuss the
``other screening capabilities.''
Question 3. Ms. McNeill, you mentioned in your testimony that TSA
flagged the appropriate law enforcement agencies about the frequent
large-sum cash-flow through Minneapolis Airport. Please provide a list
of the agencies TSA notified along with the dates and information
reported.
Answer. In calendar years 2024 and 2025, TSA recorded 362 instances
in which bulk currency was found during security screening at the
passenger checkpoint at Minneapolis-Saint Paul International Airport
(MSP), which required law enforcement notification. The Minneapolis-
Saint Paul International Airport follows the TSA standard operating
procedure for reporting large amounts of currency discovered during
screening at the checkpoint. Carrying currency in and of itself is not
prohibited nor illegal. When clearing an alarm during the screening
process, if a Transportation Security Officer discovers currency that
appears to exceed $10,000 and is bound for an international
destination, or appears to be related to potential criminal activity,
the Transportation Security Officer notifies a supervisor to determine
whether further notification to Federal or State authorities is
required. If the Supervisory Transportation Security Officer determines
that the large amount of currency appears to exceed $10,000, and the
individual is traveling internationally, the Supervisory Transportation
Security Officer notifies the TSA Coordination Center at the
Minneapolis-Saint Paul International Airport, which in turn notifies
U.S. Customs and Border Protection and U.S. Immigration and Customs
Enforcement's Homeland Security Investigations (HSI) and provides the
individual's name, flight information, and airport code. If any amount
of currency is discovered during the screening process that appears to
be related to criminal activity, the Supervisory Transportation
Security Officer must notify a law enforcement officer, which can
include TSA's Federal partners; and at a local Minneapolis-Saint Paul
International Airport law enforcement level, the Minneapolis-Saint Paul
International Airport Police Department. If TSA has cleared all alarms,
and the law enforcement officers who have been notified are not present
at the conclusion of the screening process, the individual may be asked
to wait, but he or she will be free to leave once TSA screening is
completed. Any further action concerning the individual or his or her
property will be handled by the appropriate law enforcement agency.
Question 4. As you know, TSA is the lead on pipeline security
across the United States. Given the current global terror landscape,
what are the most pressing threats to U.S. pipeline infrastructure?
What steps is DHS taking to enhance pipeline security, and how does
technology factor into that effort?
Answer. Current threats to U.S. pipeline infrastructure is defined
by a combination of evolving physical and cyber risks, such as
sabotage, drone-enabled attacks, theft, vandalism, insider actions
targeting critical assets and facilities, and persistent state-
sponsored cyber risks. Other risks include theft or stripping of
pipeline assets for copper, trace amounts of precious metals, and other
materials for criminal economic gain. Among the most pressing threats
to U.S. pipeline infrastructure are increasingly sophisticated nation-
state cyber operations and, increasingly, the integration of Artificial
Intelligence capabilities. Examples include:
Nation-State Cyber Persistence.--Adversaries are
increasingly shifting from short-term disruption to ``living
off the land,'' where they embed themselves in systems for
months or years to strategically position for future global
conflict. China remains the most active of these state
actors,\8\ as seen in the Volt Typhoon campaign which
compromised, among others, transportation entities.
---------------------------------------------------------------------------
\8\ Volt Typhoon targets U.S. critical infrastructure with living-
off-the-land techniques/Microsoft Security Blog.
---------------------------------------------------------------------------
AI-Enhanced Attacks.--Malicious actors are leveraging
Artificial Intelligence to plan, scale, and automate physical
and cyber attacks on critical infrastructure. This includes
more sophisticated phishing techniques and the scaling of cyber
compromises.
Operational Technology Vulnerabilities.--Many pipeline
systems use legacy Operational Technology that was not
originally built with cybersecurity in mind, making these
systems highly vulnerable to remote exploitation and potential
physical destruction (e.g., explosions or sabotage).
Ransomware and Criminal Groups.--High-profile incidents like
the ransomware attacks against Colonial Pipeline (2021) and the
Port of Seattle (2024) demonstrate that even non-state criminal
groups can cause massive national disruption by targeting
Information Technology systems and even force the precautionary
shutdowns of operational networks across the U.S.
Transportation System.
Physical and Social Unrest.--Pipelines face threats from
``hacktivist'' campaigns and physical vandalism or equipment
destruction related to political issues and high-profile
development projects. Through robust, mandatory performance-
based requirements and enhanced incident reporting protocols,
TSA has significantly strengthened the cybersecurity posture of
critical pipeline owners and operators, ensuring proactive
mitigation and rapid response to evolving cyber threats.
Notable actions include:
Mandatory Cybersecurity Directives.--TSA-issued Security
Directive Pipeline-2021-02. This directive requires critical
pipeline owners and operators to submit and maintain a unique
Cybersecurity Implementation Plan, develop a system-specific
Cybersecurity Incident Response Plan, and conduct an annual
Cybersecurity Architecture Design Review.
Strengthened Incident Reporting.--TSA-issued Security
Directive Pipeline-2021-01. This directive requires critical
pipeline owners and operators to also report cyber incidents to
the Cybersecurity and Infrastructure Security Agency and
designate a Cybersecurity Coordinator. Notably, non-U.S.
citizens in this role must now undergo specific vetting via
programs like Global Entry or NEXUS.
While TSA's cybersecurity directives are mandatory, its physical
security strategy leverages targeted, risk-based guidance and proactive
engagement with industry partners. Through the Corporate Security
Review program, TSA conducts comprehensive assessments based on a set
of jointly agreed-to best practices and encourages operators to
promptly report significant physical security concerns.
TSA conducts Critical Facility Security Reviews to assess
the physical security measures in place at critical pipeline
facilities.
TSA provides recommendations as appropriate to owners and
operators to enhance their physical policies, plans, and
practices.
TSA further enhances protection by delivering timely
intelligence on emerging physical threats, such as sabotage,
vandalism, or terrorist activity, enabling owners and operators
to take swift, informed action to safeguard critical
infrastructure.
Question 5a. Under the Biden administration, TSA increasingly
relied on rapidly promulgating rules through Security Directives rather
than the formal rule-making and comment process, leaving stakeholders
to comply with new security changes often at a higher cost.
What steps does TSA take to ensure that Security Directives do not
impose unnecessary costs or operational burdens on airlines, airports,
and surface transportation operators?
Answer. When a regulation or security directive must be issued
immediately to protect transportation security, TSA will issue it
without providing notice or an opportunity for comment. See 49 U.S.C.
114(l)(2). In developing mandatory requirements, TSA weighs options and
courses of action and considers the operational and economic impact to
ensure the measures are practical and tailored to the specific threat.
To the extent practicable, TSA shares the proposed security directives
with the affected regulated entities to ensure the mandatory security
measures reduce the risk, and that industry--regardless of the size of
the regulated party--is able to operationally and economically
implement the requirements. If necessary, TSA revises the security
measures to ensure the measures reduce risk and industry can implement
the requirements.
Question 5b. Please provide examples of how TSA has improved
coordination with the regulated entities to ensure practical and
tailored rules fit for specific operating environments.
Answer. TSA complies with existing standards and practices to
ensure that unnecessary costs or burdens are not imposed on our
industry stakeholders. TSA is required, by law, to comprehensively
review each security directive in consultation with the appropriate
regulated entities to determine its continued relevance; determine
whether the directive should be streamlined to most efficiently
maximize risk reduction; and update, consolidate, or revoke any
directive as necessary. TSA's Policy, Plans, and Engagement Aviation
Division Airlines Policy Branch conducts annual reviews of each
security directive in accordance with:
``FAA Extension and Safety Act of 2016 (P.L. 114-190); Tile III
Aviation Security, SEC. 3409. SECURITY DIRECTIVES.
``(a) REVIEW.--Not later than 180 days after the date of the enactment
of this Act and annually thereafter, the Administrator, in consultation
with the appropriate regulated entities, shall conduct a comprehensive
review of every current security directive addressed to any regulated
entity to--(1) determine whether each such security directive continues
to be relevant; (2) determine whether such security directives should
be streamlined or consolidated to most efficiently maximize risk
reduction; and (3) update, consolidate, or revoke any security
directive as necessary.
``FAA Reauthorization Act of 2018 (P.L. 115-254); Subtitle E--Foreign
Airport Security, Sec 1953 Last point of departure airports; security
directives
``(a) NOTICE AND CONSULTATION.--(1) IN GENERAL.--The Administrator
shall, to the maximum extent practicable, consult and notify the
following stakeholders prior to making changes to security standards
via security directives and emergency amendments for last points of
departure: (A) Trade association representatives, for affected air
carriers and airports, who hold the appropriate security clearances.
(B) The head of each relevant Federal department or agency, including
the Administrator of the Federal Aviation Administration.''
When conducting comprehensive reviews and considering revisions to
these directives, TSA holds roundtable discussions with industry
stakeholders. These meetings garner an understanding of operational
realities and the potential impact of new requirements. TSA uses a
risk-based approach to decide which owners and operators are covered by
the directives, focusing compliance obligations on entities that
present the highest risks to national and economic security.
Any time TSA issues a revised security directive, TSA consults with
the affected industry to determine if the measures continue to be
relevant. Once it is determined that the measures are necessary, TSA
shares the proposed changes to the security directive with the affected
regulated entities to ensure the mandatory security measures reduce the
risk, and that industry is able to implement the requirements.
Question 6a. DHS OIG recently completed a review of Covert Testing
of TSA's Checkpoint Security Screening Effectiveness that raises
serious issues in its final report.
What role did TSA have in reviewing and providing comments on that
final report?
Answer. TSA was not afforded the opportunity to review and comment
on the draft report prior to the issuance of the final report. A
technical meeting between TSA and the DHS Office of the Inspector
General is occurring on April 23, 2026.
Question 6b. How confident are you that TSA's technology can catch
rapidly-evolving threats rather than reacting after vulnerabilities are
exposed?
Answer. TSA employs a risk-based, layered security approach and
remains confident in our security posture in the face of evolving
threats. The agency performs continuous risk analyses and tests to
inform its procedures and address the changing risk landscape.
Question 7a. TSA recently announced a $1 billion nationwide upgrade
to TSA's security screening equipment, specifying the funds will be
used to update screening equipment across multiple airports and expand
training programs to better detect potential threats.
How would the $1 billion be allocated to support modernization of
TSA's screening technology?
Answer. TSA assessed the capital investment requirements that are
needed to provide the Nation's highest-passenger-volume airports with
advanced screening technologies. This includes requirements for
Computed Tomography, Credential Authentication Technology, Advanced
Imaging Technology, and Next-Generation Liquid and Powder Explosives
detection systems. However, TSA's current capital resources are
insufficient to meet these needs at the necessary scale and pace,
resulting in a significant multi-year funding shortfall that constrains
TSA's ability to stay ahead of the evolving threat environment.
Restoring to TSA the portion of aviation security fee collections that
is currently diverted outside the agency is critical to closing this
gap, enabling timely deployment and recapitalization of these essential
screening technologies, and ensuring TSA can proactively address
current and emerging threats.
Question 7b. Has DHS determined which airports or kinds of
equipment would be prioritized for investment, such as passenger,
baggage, or cargo screening technology?
Answer. If funding is available, TSA would deploy the equipment to
the Nation's highest-passenger-volume airports.
Question 7c. How would this address the backlog of airports that
have requested support to update or procure new screening technology?
Answer. If these funds become available, they would significantly
reduce the current backlog of airports seeking support to update or
procure new screening technology by accelerating deployment time lines
and expanding coverage across the system.
Questions From Honorable Ryan Mackenzie For Ha Nguyen McNeill
Question 1a. The Transportation Security Administration (TSA) is
the Sector Risk Management Agency (SRMA) responsible for security
across all transportation modes, including pipelines. The agency
provides security oversight, risk assessments, and guidance, working
with the Pipelines and Hazardous Materials Safety Administration
(PHMSA) and operators to secure these critical energy infrastructure
assets.
As the SRMA for pipelines, how does TSA support this critical
infrastructure sector in mitigating risk?
Answer. As the Sector Risk Management Agency (SRMA) for pipelines,
TSA supports this critical infrastructure sector through a layered,
risk-based approach that integrates mandatory regulatory oversight with
collaborative public-private partnerships. Since 2021, TSA has
transitioned from a primarily non-regulatory security model to one with
enforceable security standards relating to cybersecurity for the most
critical U.S. pipelines, significantly enhancing sector resilience. TSA
deploys cybersecurity professionals who work closely with industry
partners to ensure compliance with technical requirements across both
Information Technology and Operational Technology environments.
In addition to regulatory oversight, TSA offers non-regulatory
services to strengthen cyber resilience and posture. For physical
security, TSA relies on non-regulatory activities and risk-based
guidance, primarily utilizing the Corporate Security Review and
Critical Facility Security Reviews programs. In addition to the
required cyber incident reporting, facility owners and operators are
encouraged to report significant physical security concerns, and TSA
provides timely intelligence on emerging threats, including sabotage,
vandalism, and terrorist plots, which enable rapid and informed
responses.
Question 1b. How does TSA interact with the pipeline sector? And
similarly, how does the agency coordinate with the Department of Energy
(DOE) as the SRMA for the energy sector?
Answer. TSA maintains robust working relationships with pipeline
industry owners and operators, fostering open, on-going dialogue to
collaboratively address security challenges and develop effective ways
to mitigate risks. TSA holds regular conference calls with industry
about security issues, particularly when TSA has revised its
cybersecurity requirements. This partnership-driven approach ensures
that industry feedback is taken into consideration for TSA's regulatory
development; and industry engagement ensures practical, informed, and
effective implementation, which enhances sector resilience. TSA also
coordinates closely with the U.S. Department of Energy through the
Critical Infrastructure Partnership Model and the National
Infrastructure Protection Plan Partnership Framework that aligns TSA's
regulatory authority over pipeline security with the Department of
Energy's broader responsibilities as the SRMA for the energy sector,
ensuring unified risk mitigation and information sharing across both
agencies.
Question 2. The Known Crewmember (KCM) program is a critical risk-
based aviation security capability that enables expedited screening for
trusted flight and cabin crew while supporting operational reliability
across the airline system. As TSA moves to assume governance of KCM
through the Crewmember Access Point, the transition represents a
significant shift in program oversight with direct implications for
system performance, labor trust, identity assurance, and insider threat
mitigation. Congressional oversight is necessary to ensure the
transition strengthens security and governance without degrading timely
crewmember access or airline operations.
What is TSA's plan and time line to assume governance of the Known
Crewmember program, and how will you preserve expedited, risk-based
crew access while strengthening identity assurance and insider threat
protections?
Answer. TSA is committed to providing crewmembers an expedited
method for accessing the sterile area of airports, as is statutorily
required, and mitigating transportation security risk. Transition from
the Known Crewmember program to the Crewmember Access Point program is
planned to begin in the summer of 2026 and will take approximately 6
months to fully incorporate across all impacted airports. TSA's
approach aligns with TSA Modernization efforts and incorporates
technology to strengthen identity verification of crewmembers at
designated Crewmember Access Point program locations and expedite
screening. It also incorporates Unpredictable Screening Procedures, in
which the Crewmember Access Point technology randomly selects
participating crewmembers for additional screening, to directly address
potential insider threats. TSA will continue to work with its industry
partners and stakeholders to facilitate a smooth transition.
Question 3a. TSA Touchless PreCheck is a biometric identity
verification capability that enables enrolled PreCheck travelers to
verify their identity at airport checkpoints using facial recognition,
eliminating the need to present a physical ID. The capability is
currently operational at 20 airport locations, including major hubs
such as DFW, JFK, ORD, DCA, LGA, LAX, CLT, PHL, and BOS. Expansion is
under way to an additional 2 hubs and 35 spoke locations, with full
deployment targeted for completion by Q1 2026. As of mid-January,
traveler adoption continues to grow, with approximately 955,000 options
and more than 209,000 successful Touchless ID transactions completed.
What is TSA's long-term vision for Touchless ID? Is Touchless ID
intended solely as a checkpoint identity verification tool, or does TSA
envision it becoming a broader identity platform across the
transportation system?
Answer. TSA PreCheck Touchless ID is an identity verification tool
that delivers a seamless, curb-to-gate experience for trusted travelers
who opt-in to participate. As of February 11, 2026, the capability is
operational at 40 airport locations, and by April 2026 it will be
operational at 65 airports and 112 aviation security checkpoints.
As adoption grows, TSA's long-term goal is to accelerate the
deployment of touchless technologies across the TSA enterprise and to
enhance automation throughout the transportation system. To date, 5
airlines are currently participating in TSA PreCheck Touchless ID at
the security checkpoint, and all participating carriers have indicated
interest in extending its use to baggage check-in. Two of the
participating carriers have already begun rollout of TSA PreCheck
Touchless ID for baggage check-in at select locations.
Question 3b. Are there future use cases TSA is evaluating for
Touchless ID beyond passenger screening such as employee access, cargo,
or international operations?
Answer. At this time, additional use cases for TSA PreCheck
Touchless ID, beyond passenger screening, have not been identified. TSA
continues to leverage the infrastructure developed for TSA PreCheck
Touchless ID to identify opportunities to improve security and improve
the passenger experience.
Question 3c. As TSA considers scaling Touchless ID nationwide, what
challenges do you see related to infrastructure, funding, and system
reliability, and how is TSA planning to sustain the system over time?
Answer. The current TSA PreCheck Touchless ID edge device may
evolve to enable the expansion of TSA PreCheck Touchless ID and allow
additional trusted travelers to experience the capability throughout
their travel journey. As we continue to scale nationwide, TSA will work
to align Touchless ID with other DHS initiatives to minimize impact to
infrastructure and system reliability.
Questions From Honorable Dale Strong For Ha Nguyen McNeill
Question 1a. Ms. McNeill, TSA plays a critical role in protecting
the traveling public by both proactively identifying emerging threats
and ensuring that aviation security protocols keep pace with changes in
the industry.
With charter operators increasingly functioning like scheduled
commercial airlines, how does TSA view the security implications of
this shift, and what risks, if any, does it present for passenger
screening and vetting?
Answer. TSA has substantially enhanced security requirements for
scheduled commercial airlines over more than 2 decades. As some charter
operators are now functioning and increasing charter passenger volume
in ways that are more similar to other scheduled, commercial
operations, TSA has updated its security programs for charter
operations to ensure comprehensive vetting and screening of passengers
and their accessible property to mitigate potential threats to
aviation. In addition, through regular engagements with the aviation
community, TSA actively shares threat information, best practices, and
lessons learned, reinforcing the shared responsibility of securing the
national air space among pilots, air carriers, airport operators,
fixed-base operators, and Government agencies. Despite these efforts,
TSA has concerns about how foreign governments approve charter
operations, stemming from well-documented cases in 2023 and 2024 of
Legend Airlines, a Romanian charter airline, which engaged in human
smuggling and trafficking.
Question 1b. As charter operations grow and more passengers are
flying through fixed-based operators rather than traditional commercial
terminals, are you confident these facilities are properly equipped to
screen the increasing number of travelers, or do you see potential
security gaps if charter flights continue operating outside the same
screening framework as commercial aviation?
Answer. TSA's role in conducting passenger and property screening
is generally focused on passengers that will enplane or deplane within
sterile areas of airports. Outside of this context, the responsibility
for passenger screening generally rests with the aircraft operator. TSA
regulates both Private Charter and Public Charter operators through
established security programs, such as the Private Charter Standard
Security program and the Twelve-Five Standard Security program, which
mandate comprehensive vetting and screening procedures. While their
operations may be conducted through fixed-base operators, the fixed-
base operators are not responsible for the screening.
Question 2a. Ms. McNeill, it has been nearly 3 years since TSA
first issued emergency cyber requirements for the aviation sector, and
since then, the agency has made a number of updates and adjustments to
the program.
How is TSA evaluating how well the program has worked over this
period, and what steps are you taking to ensure these requirements are
strengthening aviation cybersecurity while being implemented
effectively across the aviation industry?
Answer. TSA is working closely with all entities that fall under
TSA's aviation cybersecurity requirements. TSA's initial outreaches and
inspections show that cybersecurity maturity varies widely across the
aviation sector.
We are focusing our efforts on helping each organization meet these
cybersecurity requirements and strengthen their cybersecurity
practices. Through these partnerships, we are seeing strong
cooperation, and overall cybersecurity is improving across the sector.
TSA built into its cybersecurity program a proactive evaluation of
the cybersecurity measures that entities are implementing. TSA requires
certain entities to develop and submit annually to TSA a Cybersecurity
Assessment Program, which proactively assesses the effectiveness of the
cybersecurity measures they are required to implement. The
Cybersecurity Assessment Program is designed to ensure that the
policies, procedures, capabilities, and measures being implemented by
entities are effective and strengthen aviation cybersecurity.
Additionally, TSA actively gathers input from airports and industry
partners, recognizing the real-world challenges of funding and
prioritizing cybersecurity. The feedback from inspections and
engagements is used to refine TSA's cybersecurity requirements, as well
to clarify guidance and provide necessary support to entities. By the
end of fiscal year 2027, cyber compliance inspectors will have
completed the initial baseline inspections for each airport/aircraft
operator/fuel farm consortium covered by the Joint Emergency Amendment,
Fuel Order, and National Amendments. During fiscal year 2026, our
cybersecurity inspectors and architects completed the first 87
inspections; we are on schedule to complete the remaining 84 initial
inspections during fiscal year 2027. Through feedback from our
regulated partners and the inspection process, the cyber inspectors
share these results with the TSA enterprise, so timely adjustments can
be made to the Joint Emergency Amendment and National Amendments.
To ensure TSA's cybersecurity requirements are being effectively
implemented across the aviation industry, TSA conducts inspections of
covered entities to assess compliance. These inspections are an
important tool and serve as a catalyst for improving cybersecurity
maturity, helping covered entities identify gaps and prioritize
cybersecurity measures. TSA provides guidance and assistance prior to
the on-site inspection, fostering a supportive environment that helps
airports prepare and understand requirements. During the inspections,
TSA ensures that entities are implementing TSA's cybersecurity
requirements and provides entities with recommended areas of
improvement to enhance their cybersecurity posture beyond what is
merely required. TSA tracks compliance, incident reporting, and
progress on security upgrades to ensure requirements are not only met
but are also improving the overall cybersecurity posture.
Questions From Honorable Vince Fong For Ha Nguyen McNeill
Question 1. The Screening Partnership Program (SPP) allows airports
to opt in to private screening solutions, which can generate savings of
up to 20 percent on personnel costs for TSA without jeopardizing safety
standards. How does TSA plan to leverage public-private partnerships,
including SPP, to increase efficiencies and free up savings that can be
reinvested in needed technology upgrades?
Answer. TSA is working to enable innovative public-private
partnerships through the Screening Partnership Program (SPP). In July
2025, TSA released the ``Turnkey Request for Information (RFI)'' to
solicit industry input on potential fully integrated, turnkey solutions
that could drive new innovations at checkpoint and in checked baggage
screening. TSA sought comment from both traditional and non-traditional
industry partners.
Using input from the Turnkey RFI, TSA is developing a framework to
modernize the SPP to drive public-private partnerships. This new
framework will give airports a choice in how they engage with TSA and
will drive greater capital to the checkpoints, to airports, and the
communities they serve.
By enabling public-private partnerships, TSA can drive greater
efficiencies and create a more competitive market for innovative
aviation security technologies. This market will drive savings for TSA
by incentivizing private investment at the checkpoint, in checked
baggage screening technologies, and at airports more broadly.
Question 2. Cutting-edge, current-day baggage screening
technologies are not expected to be deployed at all U.S. airports until
2040, at which point they will be obsolete. How can TSA accelerate the
modernization of aviation safety infrastructure, including by
leveraging public-private partnerships and the Screening Partnership
Program (SPP)?
Answer. TSA will leverage the SPP to develop security solutions
that include technology and maintenance in addition to personnel, which
will incentivize industry to accelerate deployment of checkpoint and
checked-baggage screening technologies that provide better security,
passenger experience, and throughput.
Additionally, TSA is enhancing its existing Capability Acceptance
Process and Third-Party Testing programs to increase the speed of
testing, certifying, and deploying new security technology innovations.
This will expedite the delivery of innovative checkpoint and checked
baggage solutions to the marketplace and further support innovation in
future public-private partnerships.
Question 3. What airports has TSA determined are most in need of
screening technology upgrades, and how may public-private partnerships,
including participation in the Screening Partnership Program (SPP),
help to accelerate the process of purchasing and deploying upgraded
equipment?
Answer. TSA considers many factors when identifying airports in
need of screening technology upgrades, including airport volume,
airport capacity constraints, age of currently deployed technology,
potential risk reduction provided by upgrades, and future growth or
infrastructure investments.
Leveraging the SPP could attract the additional private investment
necessary to accelerate the deployment of next-generation checkpoint
and checked-baggage screening technologies. TSA is exploring a number
of areas including equipment, maintenance, and future technology
upgrades in the scope of the SPP. While the SPP currently focuses on
privatized screening personnel, allowing participating airports to
incorporate both privatized screeners and technology into the SPP may
incentivize private partners to innovate and automate screening
operations.
Questions From Honorable Matt Van Epps For Ha Nguyen McNeill
Question 1a. Ms. McNeill, as we consider new threats to air
transportation, what would TSA's response to a drone attack on an
airport look like?
How is TSA addressing UAS threats?
Answer. TSA employs a variety of tactics, techniques, and
procedures to address the threat of careless/clueless, reckless/
negligent operators, or even potentially nefarious actors utilizing
Unmanned Aircraft Systems (UAS) in the national air space. These
tactics, techniques, and procedures can be grouped into 3 broad
categories:
Left-of-Launch.--Pre-incident activities that help to reduce
risk from potential UAS threats before they occur;
Incident response.--Actions taken to address or mitigate
threats in real-time; and
Post-incident response.--Actions taken to improve future
left-of-launch or incident response activities.
Left-of-launch activities consist of several steady-state functions
that Federal Air Marshals (FAMs) from headquarters and the field
perform on a routine basis. These activities include:
Deployment of drone detection equipment to improve domain
awareness around airports and transportation infrastructure.
Developing an understanding of what's flying in the air space
allows FAM's to share these data (while complying with the
privacy requirements of section 124n of title 6, and with the
First and Fourth Amendment) with local stakeholders, so that
everyone has a better idea of what is occurring in their areas
of responsibility.
Conducting airport vulnerability assessments to improve an
airport's preparedness and response posture in the event of a
potential disruption.
Outreach and education among public and private-sector
stakeholders to help reduce the risk of careless/clueless
violators operating in controlled air space.
Pilot engagement to document interactions and potential
regulatory violations for referrals to the Federal Aviation
Administration (FAA).
Proactive utilization of FAMs' access to the FAA's
registration and drone authorization database so that FAMs can
reach out to pilots ahead of time to inform them of pending
Temporary Flight Restrictions to ensure pilots are aware of
these changes.
Incident Response occurs in real-time, with FAMs addressing a drone
incident that has the potential to impact an airport, transportation
sector, or a special event. These activities will be guided by the Core
30 CONOPS, an interagency command and control document for Counter-
Unmanned Aircraft System (C-UAS) emergency response at the Core 30
airports that designates TSA as the Lead Federal Agency for C-UAS
response at airports. The response will include:
Real-time utilization of TSA's access to the FAA's
registration and drone authorization database so that FAMs can
attempt to identify air space violators in real time.
Conduct ground response-based on technical or visual
sightings, whereby FAM's identify and make contact with
operators, instructing drone violators to safely land aircraft
that may pose a potential danger.
Conducting field interviews that document misdemeanor
violations that could result in the issuance of a District
Court Violations Notice or ticket.
In the event of a persistent disruption, FAMs are prepared
to respond to an on-going shutdown of a Core 30 airport in
accordance with the Unified National Level Response to a
Persistent Disruption of Operations at Core 30 Airports,
utilizing all its field-based capabilities, up to and including
conducting mitigation operations.
Post-incident response activities include conducting data analysis
and information sharing (as permitted under section 124n of Title 6,
and the First and Fourth Amendment) in response to inter-agency
requests for support; and engaging in routine cooperation among law
enforcement and transportation stakeholders to identify trends or gaps
to better prepare for future incidents.
Question 1b. How is TSA implementing the Safer Skies Act of last
year's NDAA?
Answer. In response to the passage of the Safer Skies Act, TSA
started or increased several initiatives to better prepare itself to
utilize the broader DHS authorities ``to enforce the law'' and
``protect the public.'' TSA no longer must rely on the emergency
provisions under 124n and can now proactively prepare and develop its
own C-UAS capabilities and operational framework to be executed when
authorized by the Secretary. These current efforts can be divided into
3 main pillars: procurement, training, and operational planning.
Question 2. Ms. McNeill, what operational, policy, and interagency
coordination reforms could TSA implement with law enforcement and CBP
to strengthen oversight and reduce risk of suspicious cash-flow through
travel hubs?
Answer. TSA relies on administrative search authority for its
operations at travel hubs. An administrative search is an exception to
the 4th Amendment and is conducted without a warrant as part of a
regulatory plan in furtherance of a specified non-law enforcement
government purpose, such as to determine compliance with TSA
regulations or to prevent the carrying of threat items or entry of an
unauthorized person into the sterile area, or to screen passengers
entering any public conveyance. Consistent with the parameters of the
4th amendment exception, TSA conducts all administrative searches in a
manner designed to be minimally intrusive, in light of current
technology, to detect the presence of threat items. TSA recognizes that
individuals being searched have an expectation of privacy in their
persons and property and requires that all TSA personnel conduct
searches in such a way as to respect those privacy interests, while
advancing TSA's transportation security mission.
Administrative searches may not be conducted to detect evidence of
crimes unrelated to transportation security. However, if such evidence
is discovered during the normal course of a screening, TSA personnel
refer it to a supervisor and/or a law enforcement official for
appropriate action. TSA has specific procedures for these referrals,
including when certain currency is discovered at checkpoints.
TSA is looking into ways to simplify the reporting requirements
built into screening procedures. In addition, any information reported
to TSA's Coordination Centers may also be included in a Field
Intelligence Officer's Field Information Report. A Field Information
Report is a mechanism TSA uses to provide raw data to deliver valuable,
relevant, and timely information to the DHS Intelligence Enterprise on
transportation security operations. The raw data are not actionable in
and of themselves; rather, it is information that may be analyzed and
assessed for relevant patterns and trends and evaluated, in context, to
determine the existence of actionable information.
Law Enforcement/Federal Air Marshal Service Assistant Federal
Security Directors--Law Enforcement, HSI Border Enforcement Security
Team Task Force Officers, and Homeland Security Task Force Officers are
aware of the current bulk cash issues and remain in contact with both
TSA Security Operations personnel and law enforcement entities with a
vested interest in the movement of the suspicious cash. Law
Enforcement/Federal Air Marshal Service personnel will continue to
support efforts to reduce the risk of suspicious cash flow through
travel hubs, as permitted based on legal authorities, policy, and
standard operating procedures.
Question 3. Ms. McNeill, while Confirm.ID is designed to alleviate
the burden of accommodating travelers without an acceptable form of
identification, under what authority did TSA increase the fee and under
which authority does TSA collect and appropriate such a fee?
Answer. In 2006, Congress directed TSA to collect a non-refundable
fee to cover the costs of any registered traveler program.\9\ This
provision requires TSA to ``impose a fee for any registered traveler
program undertaken by the Department of Homeland Security by notice in
the Federal Register,'' provided that ``such fees shall not exceed the
aggregate costs associated with the program.'' TSA may also modify the
fee through notice published in the Federal Register. As exemplified by
the 2008 Registered Traveler Interoperability Pilot Program Fee Notice,
programs funded under registered traveler fee authority have always
consisted of components including Secure Flight vetting, additional
pre-vetting, and identity verification.\10\ Registered traveler
programs consisting solely of enhanced identity verification and Secure
Flight vetting, without additional pre-vetting, are active at 60
airports across the Nation through public-private partnerships. As TSA
transformed its former back-up call center into a multi-tiered
capability for alternative identity verification, where passengers
provide additional biographic and/or biometric information to enable
access to expedited risk-based screening and TSA's application of
limited screening resources to the highest-risk passengers, it was
determined the program fit within the ``registered traveler'' category
alongside those other programs. Therefore, consistent with the statute,
TSA imposed a fee to recover the costs of providing this service,
ensuring that individuals who benefit from the program rather than the
taxpayer bear those costs.
---------------------------------------------------------------------------
\9\ Department of Homeland Security Appropriations Act, 2006,
Public Law 109-90, sec. 540, (119 Stat. 2064, 2088-89 (Oct. 18, 2005))
(codified at 49 U.S.C. 114 note).
\10\ 73 Fed. Reg. 44275 (July 30, 2008).
---------------------------------------------------------------------------
Questions From Honorable Timothy M. Kennedy for Ha Nguyen McNeill
Question 1. TSA, through AbilityOne, has created employment
opportunities for certain individuals who are blind or severely
disabled in Upstate New York and nationwide. For example, Upstate New
York-based non-profit organizations working under AbilityOne supply TSA
with 1.3 million nitrile exam gloves annually.
Please describe TSA's plans to continue use of the AbilityOne law
to procure products. Is TSA considering expanding its use of the
AbilityOne program?
Answer. TSA remains committed to fulfilling its obligations under
the AbilityOne program and continues to utilize AbilityOne to procure
products and services, including personal protective equipment such as
nitrile exam gloves. TSA is required to use the DHS Safety Stock
Personal Protective Equipment Strategic Sourcing Vehicle. The
contractor, LC Industries, partners with the Central Association for
the Blind and Visually Impaired to support TSA's nitrile glove needs.
Currently, TSA does not have any service contracts with AbilityOne;
however, TSA regularly evaluates procurement strategies to ensure
compliance with Federal requirements and to maximize opportunities for
AbilityOne participation. Any expansion of AbilityOne use would be
considered in accordance with DHS and Federal procurement guidelines.
Question 2. Based on TSA's data, please outline the number of jobs
created nationally for the blind and severely disabled who rely on TSA
AbilityOne contracts.
Answer. TSA does not possess data regarding this matter. For
information regarding job creation, TSA recommends contacting the
AbilityOne program or its affiliated non-profit agencies, as they are
best-positioned to provide detailed employment statistics.
Questions From Honorable Troy Carter for Ha Nguyen McNeill
Question 1. With the rise of charter operators operating more like
scheduled commercial airlines, are you concerned that they are skirting
appropriate safety protocols, such as TSA screening, and creating a
potential threat to the flying public? Can you explain what is being
done to address this threat?
Answer. In response to some charter operators now functioning
similarly to scheduled commercial operations and increasing charter
passenger volumes, TSA updated its security programs for charter
operations to ensure comprehensive vetting and screening of passengers
and their accessible property to mitigate potential threats to
aviation. In addition, through regular engagements with the aviation
community, TSA actively shares threat information, best practices, and
lessons learned, to reinforce the shared responsibility of securing the
national air space among pilots, air carriers, airport operators,
fixed-base operators, and Government agencies.
Question 2. Charter operators who act like commercial airlines
don't have to follow the same safety protocols as commercial airlines.
What are you doing to ensure that their growth doesn't create a safety
risk for the traveling public?
Answer. While the FAA is responsible for establishing safety
protocols, TSA is committed to securing the aviation system for the
traveling public by implementing and updating security measures for
aircraft operators. TSA actively collaborates with charter operators
and industry partners to enhance security within general aviation.
TSA provides comprehensive guidance and screening frameworks and
has updated security programs for charter operations to ensure that
passengers are properly vetted, and their persons and accessible
property are screened. These measures effectively mitigate potential
threats and support the safe and secure growth of charter services.
Question 3. Are fixed-based operators equipped to properly screen
the growing number of passengers flying on scheduled charter
operations? Are you concerned about their ability if this loophole
continues to be exploited?
Answer. There is no security loophole for scheduled charter
operations. While Fixed-Base Operators are not required under TSA
regulations to conduct passenger and accessible property screening, for
private and public charter passenger operations, aircraft operators are
required by regulation to provide for the safety of persons and
property traveling on flights provided by the aircraft operator against
acts of criminal violence; air piracy; and the introduction of
explosives, incendiaries, or weapons aboard aircraft. TSA security
programs mandate that aircraft operators implement appropriate
screening measures at Fixed-Base Operators locations. These required
screening measures are to prevent unauthorized access to aircraft and
facilities, address insider threats, and mitigate misuse of aircraft.
TSA maintains on-going oversight and enforcement of these security
requirements, and we ensure any issues identified during compliance
inspections are addressed in a timely manner.
[all]