[House Hearing, 119 Congress]
[From the U.S. Government Publishing Office]




                OVERSIGHT OF THE DEPARTMENT OF HOMELAND 
                         SECURITY: CISA, TSA, S&T

=======================================================================




                                HEARING

                               before the

                     COMMITTEE ON HOMELAND SECURITY
                        HOUSE OF REPRESENTATIVES

                    ONE HUNDRED NINETEENTH CONGRESS

                             SECOND SESSION
                               __________

                            JANUARY 21, 2026
                               __________

                           Serial No. 119-35
                               __________

       Printed for the use of the Committee on Homeland Security                                     








                [GRAPHIC NOT AVAILABLE IN TIFF FORMAT]
                

               
       

        Available via the World Wide Web: http://www.govinfo.gov        
                               ______                                 

                 U.S. GOVERNMENT PUBLISHING OFFICE

63-557                    WASHINGTON : 2026        








                     COMMITTEE ON HOMELAND SECURITY

                Andrew R. Garbarino, New York, Chairman
                
Michael T. McCaul, Texas, Vice       Bennie G. Thompson, Mississippi, 
    Chair                                Ranking Member
Michael Guest, Mississippi           Eric Swalwell, California
Carlos A. Gimenez, Florida           J. Luis Correa, California
August Pfluger, Texas                Shri Thanedar, Michigan
Tony Gonzales, Texas                 Seth Magaziner, Rhode Island
Morgan Luttrell, Texas               Daniel S. Goldman, New York
Dale W. Strong, Alabama              Delia C. Ramirez, Illinois
Josh Brecheen, Oklahoma              Timothy M. Kennedy, New York
Elijah Crane, Arizona                LaMonica McIver, New Jersey
Andrew Ogles, Tennessee              Julie Johnson, Texas, Vice Ranking 
Sheri Biggs, South Carolina              Member
Gabe Evans, Colorado                 Pablo Jose Hernandez, Puerto Rico
Ryan Mackenzie, Pennsylvania         Nellie Pou, New Jersey
Brad Knott, North Carolina           James R. Walkinshaw, Virginia
Vince Fong, California               Troy A. Carter, Louisiana
Matt Van Epps, Tennessee             Al Green, Texas
Vacant

                     Keighle Joyce, Staff Director
                  Hope Goins, Minority Staff Director
                       Sean Corcoran, Chief Clerk
                       
                       
                       
                       
                       
                       
                       
                       
                            C O N T E N T S

                              ----------                              
                                                                   Page

                               Statements

Honorable Andrew R. Garbarino, a Representative in Congress From 
  the State of New York, and Chairman, Committee on Homeland 
  Security:
  Oral Statement.................................................     1
  Prepared Statement.............................................     3
Honorable Bennie G. Thompson, a Representative in Congress From 
  the State of Mississippi, and Ranking Member, Committee on 
  Homeland Security:
  Oral Statement.................................................     4
  Prepared Statement.............................................    10

                               Witnesses

Hon. Pedro M. Allende, Under Secretary, Science & Technology 
  Directorate (S&T):
  Oral Statement.................................................    12
  Prepared Statement.............................................    13
Mr. Madhu Gottumukkala, Ph.D., Acting Director, Cybersecurity and 
  Infrastructure Security Agency (CISA):
  Oral Statement.................................................    14
  Prepared Statement.............................................    16
Ms. Ha Nguyen McNeill, Senior Official Performing the Duties of 
  the Administrator, Transportation Security Administration 
  (TSA):
  Oral Statement.................................................    18
  Prepared Statement.............................................    19

                             For the Record

Honorable Bennie G. Thompson, a Representative in Congress From 
  the State of Mississippi, and Ranking Member, Committee on 
  Homeland Security:
  Letter, January 14, 2026.......................................     6
  Letter, January 21, 2026.......................................     8
  Chart..........................................................    62
  Article, Mother Jones..........................................    63
  Article, Bloomberg.............................................    67

                               Appendix I

Questions From Chairman Andrew R. Garbarino For Pedro M. Allende.    71
Questions From Honorable Timothy M. Kennedy for Pedro M. Allende.    72
Questions From Chairman Andrew R. Garbarino for Madhu 
  Gottumukkala...................................................    74
Questions From Honorable August Pfluger For Madhu Gottumukkala...    80
Question From Honorable Matt Van Epps For Madhu Gottumukkala.....    82
Questions From Chairman Andrew R. Garbarino For Ha Nguyen McNeill    82
Questions From Honorable Ryan Mackenzie For Ha Nguyen McNeill....    88
Questions From Honorable Dale Strong For Ha Nguyen McNeill.......    89
Questions From Honorable Vince Fong For Ha Nguyen McNeill........    90
Questions From Honorable Matt Van Epps For Ha Nguyen McNeill.....    91
Questions From Honorable Timothy M. Kennedy for Ha Nguyen McNeill    93
Questions From Honorable Troy Carter for Ha Nguyen McNeill.......    94







 
                OVERSIGHT OF THE DEPARTMENT OF HOMELAND 
                         SECURITY: CISA, TSA, S&T

                              ----------                              


                      Wednesday, January 21, 2026

             U.S. House of Representatives,
                    Committee on Homeland Security,
                                            Washington, DC.
    The committee met, pursuant to notice, at 10:06 a.m., in 
room 320, Cannon House Office Building, Hon. Andrew Garbarino 
(Chairman of the committee) presiding.
    Present: Representatives Garbarino, McCaul, Guest, Gimenez, 
Gonzales, Luttrell, Strong, Brecheen, Crane, Ogles, Biggs, 
Mackenzie, Fong, Epps, Thompson, Correa, Thanedar, Magaziner, 
Goldman, Ramirez, Kennedy, McIver, Pou, Walkinshaw, and Green.
    Chairman Garbarino. The Committee on Homeland Security will 
come to order. Without objection, the Chair may declare a 
committee in recess at any point. The purpose of today's 
hearing is to conduct oversight of the Department of Homeland 
Security and assess priorities for calendar year 2026 for the 
Cybersecurity and Infrastructure Security, Transportation 
Security Administration, and Science and Technology 
Directorate.
    The Chair reminds all Members that the Chair will enforce 
the rules of decorum at all times and urges all Members to be 
mindful of their remarks. I now recognize myself for an opening 
statement.
    Good morning, and thank you to our witnesses for being 
here. Today, we are conducting oversight of the Department of 
Homeland Security focusing on TSA, CISA, and the Science and 
Technology Directorate, otherwise known as S&T.
    Nearly 25 years ago, 19 hijackers exploited significant 
vulnerabilities in our commercial aviation system. The al-Qaeda 
terrorist attack on September 11, 2001, killed nearly 3,000 
Americans and changed our Nation forever. Our transportation 
system, among other critical systems, demanded accountability 
and hardened security to ensure a horrific event would never 
happen again. In response, Congress enacted the Aviation and 
Transportation Security Act to establish TSA and grant DHS 
flexible operational authority, allowing it to prepare for and 
respond to an ever-evolving threat landscape.
    Over the past two decades, threats facing our Nation's 
aviation, transportation, and critical infrastructure have only 
risen. Today's risks are for more diverse, complex, and 
technologically advanced, and the motivations and methods of 
our adversaries have shifted rapidly with emerging 
technologies. Threats posed by lone-wolf actors, radicalized 
individuals, and home-grown extremists have only increased. 
Transnational criminal organizations pose a significant threat 
by exploiting the transportation system to traffick humans, 
drugs, weapons, and illicit goods.
    Traditional terror tactics have given way to more 
sophisticated methods of attack. Cybersecurity is now at the 
forefront of these conversations with adversaries attempting to 
take down our transportational systems through digital means. 
Similarly, the potential for coordinated tax using drones to 
disrupt flights or deliver explosives, represent the new and 
growing frontier of security threats.
    Sophisticated foreign adversaries, including the People's 
Republic of China, Russia, Iran, and North Korea are actively 
targeting our digital system, systems that underpin essential 
services, economic activity, and national security. These 
state-directed campaigns are designed to position hostile 
actors with strategic disruption and coercion. Rapid advances 
in emerging technologies, including AI, are further 
accelerating the scale, speed, and sophistication of these 
cybersecurity operations.
    In cyber space, the United States is operating in a highly-
contested environment. Congress created CISA to serve as the 
Nation's lead civilian cyber defense agency to meet this 
reality. CISA's responsibilities included securing Federal 
civilian networks, supporting owners and operators of critical 
infrastructure, and coordinating with the private sector to 
reduce systemic cyber risk. That mission has grown more 
consequential as adversaries become more capable, patient, and 
willing to operate inside U.S. networks for extended periods of 
time.
    CISA's authorities extend across a variety of sectors, 
including energy, water, communications, health care, 
transportation, and financial services. This committee has been 
clear about CISA, CISA's expectations. It is not a policy, 
think tank, nor a messaging agency. Its mandate is operational. 
When that mandate is carried out with discipline and focus, the 
agency earns bipartisan support in Congress and confidence from 
the industry. When it does not, that confidence erodes.
    Over the past year, CISA has faced real operational 
challenges. Those challenges include rapidly-evolving threat 
landscape, the scope of the agency's responsibility in an 
increasingly digital world, and organizational adjustments. As 
with any agency responsible for our national security, it is 
critical these changes do not degrade readiness, 
responsiveness, or mission delivery.
    This committee supports the administration's global 
aligning of Department resources toward urgent Homeland 
Security priorities. At the same time, work force continuity, 
clear leadership, and mission readiness are essential to 
effective cyber defenses. Professionals at CISA are some of the 
most experienced cybersecurity experts in the Federal 
Government. Preserving that expertise must remain a priority.
    We are encouraged by the President's decision to renominate 
Mr. Sean Plankey as director of CISA. Mr. Plankey is a 
respected national security professional with decades of 
experience. His confirmation provides long-needed stability and 
strategic direction at CISA, which has operated without it for 
far too long. This committee's oversight of CISA is granted in 
respect for its mission and confidence in its work force.
    Last, several major high-profile events are set to unfold 
across the United States, including the 2026 FIFA World Cup, 
America 250, and the 2028 L.A. Olympics. These events will only 
increase the volume and complexity of threats facing the 
homeland, and DHS must be prepared to respond.
    The Trump administration, to its credit, has taken strong 
steps to prioritize, strengthen our Nation's security systems. 
However, modernization of TSA, CISA, and S&T will require 
sustained Congressional support. As Chairman of the Homeland 
Security Committee, it's my priority to ensure we support and 
invest in the next generation of technologies, and adopt highly 
innovative and effective security approaches given the 
challenges facing the Department and our country.
    This hearing provides an important opportunity to assess 
how TSA, CISA, and S&T are carrying out their missions. We look 
forward to hearing from our witnesses and engaging in 
constructive dialog about how Congress can effectively support 
security, operational excellence, and accountability across the 
Department.
    I also want to take this opportunity to thank our DHS 
personnel who keep us safe every day, including our dedicated 
cybersecurity professionals, our innovative researchers and 
scientists, and our brave TSA security officers who work on the 
front lines to protect the traveling public, and who continue 
to do so even without pay during the Nation's longest shutdown 
last year.
    I'm confident that by working together, we can break 
through the challenges of today and prepare for threats of 
tomorrow. The stakes for the American people cannot be higher.
    [The statement of Chairman Garbarino follows:]
                 Statement of Chairman Andrew Garbarino
                            January 21, 2026
    Good morning and thank you to our witnesses for being here today. 
We are conducting oversight of the Department of Homeland Security 
focusing on TSA, CISA, and the Science and Technology Directorate, 
otherwise known as S&T.
    Nearly 25 years ago, 19 hijackers exploited significant 
vulnerabilities in our commercial aviation system. The al-Qaeda 
terrorist attack on September 11, 2001 killed nearly 3,000 Americans 
and changed our Nation forever. Our transportation system, among other 
critical systems, demanded accountability and hardened security to 
ensure a horrific event would never happen again. In response, Congress 
enacted the Aviation and Transportation Security Act to establish TSA 
and grant DHS flexible operational authority, allowing it to prepare 
for and respond to an ever-evolving threat landscape.
    Over the past 2 decades, threats facing our Nation's aviation, 
transportation, and critical infrastructure have only risen. Today's 
risks are far more diverse, complex, and technologically advanced. And 
the motivations and methods of our adversaries have shifted rapidly 
with emerging technologies. Threats posed by lone-wolf actors, 
radicalized individuals, and home-grown extremists have only increased.
    Transnational criminal organizations pose a significant threat by 
exploiting the transportation system to traffic humans, drugs, weapons, 
and illicit goods.
    Traditional terror tactics have given way to more sophisticated 
methods of attack. Cybersecurity is now at the forefront of these 
conversations with adversaries attempting to take down our 
transportational systems through digital means. Similarly, the 
potential for coordinated attacks using drones to disrupt flights or 
deliver explosives represents a new and growing frontier of security 
threats.
    Sophisticated foreign adversaries, including the People's Republic 
of China, Russia, Iran, and North Korea, are actively targeting our 
digital system. Systems that underpin essential services, economic 
activity, and national security.
    These state-directed campaigns are designed to position hostile 
actors for strategic disruption and coercion. Rapid advances in 
emerging technologies, including AI, are further accelerating the 
scale, speed, and sophistication of these cyber operations. In cyber 
space, the United States is operating in a highly contestant 
environment. Congress created CISA to serve as the Nation's lead 
civilian cyber defense agency to meet this reality. CISA's 
responsibilities included securing Federal civilian networks, 
supporting owners and operators of critical infrastructure, and 
coordinating with the private sector to reduce cyber systemic cyber 
risk. That mission has grown more consequential as adversaries become 
more capable, patient, and willing to operate inside U.S. networks for 
extended periods of time. CISA's authorities extend across a variety of 
sectors including energy, water, communications, health care, 
transportation, and financial services.
    This committee has been clear about CISA's expectations. It is not 
a policy think tank nor messaging agency. Its mandate is operational. 
When that mandate is carried out with discipline and focus, the agency 
earns bipartisan support in Congress and confidence from the industry. 
When it does not, that confidence erodes. Over the past year, CISA has 
faced real operational challenges. Those challenges include a rapidly-
evolving threat landscape, the scope of the agency's responsibility in 
an increasingly digital world, and organizational adjustments.
    As with any agency responsible for our national security, it is 
critical these changes do not degrade readiness, responsiveness, or 
mission delivery.
    This committee supports the administration's goal of aligning 
Department resources toward urgent homeland security priorities. At the 
same time, workforce community continuity, clear leadership, and 
mission readiness are essential to effective cyber defenses. 
Professionals at CISA are some of the most experienced cybersecurity 
experts in the Federal Government and preserving that expertise must 
remain a priority. We are encouraged by the President's decision to 
renominate Mr. Sean Plankey as director of CISA. Mr. Plankey is a 
respected national security professional with decades of experience. 
His confirmation will provide long-needed stability and strategic 
direction at CISA, which has operated without it for far too long. This 
committee's oversight of CISA is grounded in respect for its mission 
and confidence in its workforce.
    Last, several major high-profile events are set to unfold across 
the United States, including the 2026 FIFA World Cup, America 250, and 
the 2028 LA Olympics.
    These events will only increase the volume and complexity of 
threats facing the homeland and DHS must be prepared to respond. The 
Trump administration, to its credit, has taken strong steps to 
strengthen our Nation's security systems. However, modernization of 
TSA, CISA, and S&T will require sustained Congressional support. As 
Chairman of the Homeland Security Committee, it is my priority to 
ensure we support and invest in the next generation of technologies and 
adopt highly innovative and effective security approaches given the 
challenges facing the Department and our country. This hearing provides 
an important opportunity to assess how TSA, CISA, and S&T are carrying 
out their missions. We look forward to hearing from our witnesses and 
engaging in constructive dialog about how Congress can effectively 
support security, operational excellence, and accountability across the 
Department.
    I also want to take this opportunity to thank our DHS personnel who 
keep us safe every day, including our dedicated cybersecurity 
professionals, our innovative researchers and scientists, and our brave 
TSA security officers who work on the front lines to protect the 
traveling public and who continue to do so even without pay during the 
Nation's longest shutdown last year.
    I'm confident that by working together, we can break through the 
challenges of today and prepare for threats of tomorrow. The stakes for 
the American people could not be higher. Thank you.

    Chairman Garbarino. Thank you. I now recognize the Ranking 
Member, the gentleman from Mississippi, Mr. Thompson, for 5 
minutes for his opening statement.
    Mr. Thompson. Thank you very much, Mr. Chairman. I want to 
thank you for holding today's hearing on Oversight of the 
Department of Homeland Security. Congressional Republicans' 
oversight of the Trump administration has been dismal this 
Congress. Republicans have had administration witnesses before 
this committee the fewest times in any recent administration's 
first year. Most of that was on the watch of the prior 
Chairman, who was, to my favorite phrase of his, derelict in 
his duty to bring Trump administration officials before the 
committee.
    This hearing is a step in the right director. The Trump 
administration has created serious issues at TSA, CISA, and DHS 
S&T that need to be addressed. Committee Democrats are 
committed to taking a hard look at those issues. From President 
Trump's slashing the CISA work force, to Secretary Kristi 
Noem's unlawful rescinding union rights for front-line 
transportation security officers, to the administration cutting 
programs that leveraged university-based research to address 
critical Homeland Security challenges.
    But none of those things can be the sole focus of our 
oversight right now, because President Trump and Secretary Noem 
have weaponized DHS against the American people and are 
wreaking havoc in Minneapolis and other communities across this 
country. It's an absolute disgrace that ICE isn't here today in 
wake of the shooting death of Renee Good at the hands of an ICE 
agent.
    Mr. Chairman, as you know, I have asked for ICE Acting 
Director Lyons to appear at today's hearing. I ask unanimous 
consent to insert in the record my letter to you dated January 
14, 2026, requesting Acting Director Lyons appear before the 
committee without delay. I want to thank you for issuing that 
invitation, but Committee Democrats and I are outraged that ICE 
refused to appear today.
    Ms. Good was a wife, mother of three young children, a 
devout Christian, and a U.S. citizen. We all seen the shooting 
video with our own eyes. Ms. Good certainly did not deserve to 
be killed by her own government. She should be alive today. Mr. 
Chairman, at this time, I ask for a moment of silence in memory 
of Renee Good.
    [Moment of silence.]
    Mr. Thompson. Thank you. Mr. Chairman, in the wake of Ms. 
Good's killing, ICE has an obligation to appear and answer 
Members' questions. Her tragic killing needs to be thoroughly 
investigated, and everyone involved from the ICE officer who 
pulled the trigger, to the President and Secretary who sent 
them to Minneapolis must be held accountable. DHS also needs to 
be held accountable for its out-of-control immigration 
operation, creating chaos in communities like Los Angeles, 
Chicago, New Orleans, and Minneapolis, terrorizing people from 
all walks of life and hurting U.S. citizens and immigrants 
alike.
    Mr. Chairman, in order to ensure that ICE appears before 
the committee, pursuant to clause 2(J)(1) of House Rule 11, I'm 
providing you with a letter signed by every Democratic Member 
of the committee requesting testimony from Acting Director 
Lyons. I ask unanimous consent that this Minority Day letter be 
submitted for the record.
    Chairman Garbarino. Without objection.
    [The information follows:]
    
[GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
    
                                ------                                

[GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]


    Mr. Thompson. Thank you.
    Mr. Chairman, I understand that you intend to hold a series 
of oversight hearings with DHS officials. I look forward to ICE 
being before the committee at our next hearings; Democrats 
insist on that. Never has oversight and accountability been 
more necessary than it is now.
    President Trump and Secretary Noem are doing real damage to 
this country and to the Department that was stood up in the 
wake of 9/11 to protect Americans from future attacks. 
Unfortunately, President Trump and Secretary Noem have 
established a corrupt, above-the-law culture at DHS, and Noem 
has enriched herself and her allies at taxpayers' expense. She 
has awarded multiple, no-bid contracts to close associates and 
siphon $240 million of taxpayers' money to companies connected 
to her top adviser and close confidant, Corey Lewandowski, as 
well as to her spokesperson husband. She fast-tracked a 
contract worth almost $1 billion to a company led by a Trump 
donor. She is living rent-free in a U.S. Coast Guard housing 
designated for military members.
    She has also abused her power as Secretary. She has 
acknowledged cherry-picking, which court orders departments 
will comply with contrary to the rule of law.
    She has used access to disaster funds to punish political 
foes, illegally withholding Congressionally-authorized disaster 
funds. She has obstructed Congressional oversight, barring 
Members from visiting ICE detention facilities, and refusing to 
respond to oversight letters and requests.
    In short, she has enriched herself, abused the power of her 
office, obstructed Congressional oversight, and violated her 
oath of office to the Constitution. Never has oversight of the 
Department of Homeland Security been more important, and never 
has holding an administration accountable been more necessary. 
Be assured that accountability is coming. Accountability is 
coming, Mr. Chairman, and I yield back.
    [The statement of Ranking Member Thompson follows:]
             Statement of Ranking Member Bennie G. Thompson
                            January 21, 2026
    Congressional Republicans' oversight of the Trump administration 
has been dismal this Congress. Republicans have had administration 
witnesses before the committee the fewest times in any recent 
administration's first year. Most of that was on the watch of the prior 
Chairman, who was--to use a favorite phrase of his--derelict in his 
duty to bring Trump administration officials before the committee.
    This hearing is a step in the right direction. The Trump 
administration has created serious issues at TSA, CISA, and DHS S&T 
that need to be addressed. Committee Democrats are committed to taking 
a hard look at those issues--from President Trump slashing the CISA 
workforce, to Secretary Kristi Noem unlawfully rescinding union rights 
for front-line Transportation Security Officers, to the administration 
cutting programs that leverage university-based research to address 
critical homeland security challenges. But none of those things can be 
the sole focus of our oversight right now, because President Trump and 
Secretary Noem have weaponized DHS against the American people and are 
wreaking havoc in Minneapolis and other communities across this 
country.
    It's an absolute disgrace that ICE isn't here today, in the wake of 
the shooting death of Renee Good at the hands of an ICE agent. As you 
know, I asked for ICE Acting Director Lyons to appear at today's 
hearing. I want to thank you for issuing that invitation, but committee 
Democrats and I are outraged that ICE refused to appear today.
    Ms. Good was a wife, mother of 3 young children, a devout 
Christian, and a U.S. citizen. We've all seen the shooting video with 
our own eyes. Ms. Good certainly did not deserve to be killed by her 
own Government. She should be alive today. In the wake of Ms. Good's 
killing, ICE has an obligation to appear and answer Members' questions. 
Her tragic killing needs to be thoroughly investigated and everyone 
involved--from the ICE officer who pulled the trigger to the President 
and Secretary who sent him to Minneapolis--must be held accountable.
    DHS also needs to be held accountable for its out-of-control 
immigration operations creating chaos in communities like Los Angeles, 
Chicago, New Orleans, and Minneapolis, terrorizing people from all 
walks of life, and hurting U.S. citizens and immigrants alike. In order 
to ensure that ICE appears before the committee, pursuant to clause 
2(J)(1) of House Rule XI, I am providing you with a letter signed by 
every Democratic Member of the committee requesting testimony from 
Acting Director Lyons.
    I understand that you intend to hold a series of oversight hearings 
with DHS officials. I look forward to ICE being before the committee at 
our next hearing. Democrats insist on that. Never has oversight and 
accountability been more necessary than it is now. President Trump and 
Secretary Noem are doing real damage to this country and to the 
Department that was stood up in the wake of 9/11 to protect Americans 
from future attacks. Unfortunately, President Trump and Secretary Noem 
have established a corrupt, ``above the law'' culture at DHS, and Noem 
has enriched herself and her allies at tax-payer expense.
    She has awarded multiple, no-bid contracts to close associates and 
siphoned $240 million of taxpayer money to companies connected to her 
top advisor and close confidant, Corey Lewandowski, as well as to her 
spokesperson's husband. She fast-tracked a contract worth almost $1 
billion dollars to a company led by a Trump donor. And she is living, 
rent-free, in U.S. Coast Guard housing designated for military members.
    She has also abused her power as Secretary. She has acknowledged 
cherry-picking which court orders the Department will comply with, 
contrary to the rule of law. She has used access to disaster funds to 
punish political foes, illegally withholding Congressionally-authorized 
disaster funds. She has obstructed Congressional oversight, barring 
Members from visiting ICE detention facilities and refusing to respond 
to oversight letters and requests.
    In short, she has enriched herself, abused the power of her office, 
obstructed Congressional oversight, and violated her oath of office to 
the Constitution. Never has oversight of the Department of Homeland 
Security been more important and never has holding an administration 
accountable been more necessary.
    Be assured that accountability is coming.

    Chairman Garbarino. The gentleman yields back. Other 
Members of the committee are reminded that opening statements 
may be submitted for the record.
    I am pleased to have a highly distinguished panel of 
witnesses before us today. As the Ranking Member knows, we have 
talked about doing other oversight hearings, and that is the 
intent of this committee to do what Congress is meant to do and 
conduct oversight. I'm pleased today that we have our first 
panel of DHS officials here. DHS is a big department, and there 
should be several of these, and we will have several of these.
    Pursuant to committee Rule VII(C), I ask that the witnesses 
please rise and raise their right hand.
    [Witnesses sworn.]
    Chairman Garbarino. Let the record reflect that the 
witnesses have answered in the affirmative. Thank you all. 
Please be seated.
    I would now like to formally introduce our witnesses. Mr. 
Pedro Allende is under secretary for science and technology, 
leading the Department's research and development efforts and 
serving as science advisor to the Secretary. Previously, he 
served as Florida's secretary of management services and has 
held roles at DHS and the Department of Emergency and Labor.
    Mr. Madhu Gottumukkala serves as the acting director and 
deputy director for the Cybersecurity Infrastructure Security 
Agency; a role in which he helps to lead CISA's mission to 
understand, manage, and reduce risks to cyber and physical 
infrastructure. Prior to his appointment, he served as 
commissioner and chief information officer for South Dakota's 
Bureau of Information and Technology.
    Ms. Ha Nguyen McNeill is deputy administrator of the 
Transportation and Security Agency, a role in which she is 
performing the duties of administrator to advance TSA's mission 
to secure the Nation's transportation system and improve 
operational effectiveness. Previously, she served as acting 
president, commercial, and vice president of digital identity 
growth at Big Bear AI. Ms. McNeill also served as TSA chief of 
staff from 2017 to 2019.
    I thank all of the witnesses for being here today. I now 
recognize Mr. Allende for 5 minutes to summarize his opening 
statement.

STATEMENT OF HON. PEDRO M. ALLENDE, UNDER SECRETARY, SCIENCE & 
                  TECHNOLOGY DIRECTORATE (S&T)

    Mr. Allende. Thank you, Mr. Chairman. Chairman Garbarino, 
Ranking Member Thompson, and distinguished Members of the 
committee. Thank you for the opportunity to appear before you 
today. I am honored to serve as under secretary for science and 
technology at the Department of Homeland Security. I appreciate 
the committee's continued oversight and engagement with their 
work.
    The Science and Technology Directorate plays a unique role 
within DHS. We are the Department's research, development, 
test, and evaluation organization responsible for anticipating 
emerging threats, identifying technology opportunities, and 
ensuring that DHS components have access to solutions that are 
timely, effective, and responsible. Our work is grounded in the 
simplest measure of success: Whether technology transitions 
into the real-world use are effectuated, and whether they 
measurably improve mission outcomes.
    In my short tenure as under secretary, I have focused on 
listening to the operators, across the Department, to 
understand where technology is helping today, where it can help 
fill up certain gaps. Those conversations reinforce a 
consistent message. Technology must be operationally relevant. 
It must be rigorously tested and delivered with discipline. 
Research alone is not enough.
    Capability must reach the operators in the field. To meet 
that standard, S&T works closely with the components. From the 
earliest stages of development--and we assess emerging threats, 
evaluate existing commercial solutions, and apply systems 
engineering in tests and evaluation to reduce risks before 
acquisition decisions are made.
    When a private-sector solution can meet mission needs, that 
is our preference. We prioritize adopting those solutions and 
adapting them in order to accelerate delivery to the field; 
and, frankly, to steward taxpayer dollars effectively and 
responsibly.
    At the same time, the threat environment facing our 
homeland is increasingly dynamic and technology-driven. From 
unmanned aircraft systems to cyber-enabled threats, to risks, 
to critical infrastructure, S&T's role is to look ahead while 
supporting today's operations. That means engaging with 
industry, with academia, national laboratories, and FFRDCs, and 
interagency partners to ensure that DHS remains prepared for 
the future, without losing focus of today's challenges.
    Ultimately, my goal as under secretary to ensure that S&T 
remains a trusted partner to DHS components; one that delivers 
capabilities that work in the field, supports informed decision 
making, and strengthens the security of the American homeland. 
I look forward to discussing our work with the committee this 
morning and to answering your questions. Thank you.
    [The prepared statement of Mr. Allende follows:]
                 Prepared Statement of Pedro M. Allende
                            January 21, 2026
                              introduction
    Chairman Garbarino, Ranking Member Thompson, and distinguished 
Members of the committee, thank you for the opportunity to testify 
before you today. I am honored to have the confidence of President 
Trump and Secretary Noem to serve as the under secretary for science 
and technology (S&T) at the Department of Homeland Security (DHS). I 
look forward to executing the Trump administration priorities to make 
the Nation safer through advancement and application of science and 
technology.
    I appreciate the committee's continued engagement with the DHS S&T 
Directorate, and I look forward to our work together during my tenure 
as under secretary.
    The S&T Directorate plays a unique role within DHS. We are 
responsible for understanding emerging threats and opportunities, and 
for ensuring the Department has access to timely, effective, and 
responsible technology solutions to meet its evolving mission needs. As 
threats to the homeland become more complex, adaptive, and technology-
enabled, S&T's mission is to help DHS stay ahead of those challenges.
    S&T works closely with DHS operational components, the private 
sector, academia, international and interagency partners to deliver 
solutions that enhance security, improve efficiency, and strengthen 
operational effectiveness. Our success is measured not by research 
alone, but by outcomes delivered to operators and the American people.
    In my short time in this role, I have been energized by seeing S&T 
in action and witnessing first-hand the critical role technology plays 
in keeping our Nation safe.
    Just last week, I had the opportunity to meet with our partners at 
operational sites on the West Coast, including our DHS colleagues in 
the Transportation Security Administration (TSA), the U.S. Customs and 
Border Protection (CBP), and the U.S. Coast Guard, as well as our local 
law enforcement partners. At Los Angeles International Airport (LAX), I 
observed TSA security operations and gained valuable insight into how 
emerging technologies can create new opportunities for enhanced safety 
and security. At SoFi Stadium, I engaged with security teams to discuss 
how innovative solutions can strengthen our defenses as we prepare to 
host the FIFA World Cup in the summer of 2026.
    I toured the complex operations and technology required for cargo 
operations and screening by CBP as they ensure the safety of two of the 
largest U.S. seaports in Los Angeles and Long Beach, California, to 
cargo operations and screening. At the Air and Marine Operations 
Center, I met with partners to discuss collaborative activities, such 
as the Kestrel system which enhances their ability to determine 
highest-priority threats and make real-time operational decisions and 
explore enhancements to achieve full domain awareness across our 
borders and air space.
    My experiences this past week have crystalized for me the 
importance of advancing the administration's priorities and my 
commitment to ensuring S&T remains focused on the needs of our 
operational components while staying ahead of our adversaries. Our 
organization is also taking on broader challenges, including leading 
efforts in areas such as Counter-Unmanned Aircraft Systems. Secretary 
Noem recently announced the establishment of the Program Executive 
Office for Unmanned Aircraft Systems and Counter-Unmanned Aircraft 
Systems, investing to rapidly procure and deploy advanced counter-drone 
technologies. As Secretary Noem noted, these are critical investments 
to protect our borders and to keep Americans safe and secure during 
America 250 celebrations and at 2026 FIFA World Cup venues.
    My recent trip also enabled me to engage with private-sector 
partners, which will be a key theme of my service as Under Secretary. 
Not only does the private sector operate much of the critical 
infrastructure upon which our Nation relies, but they are a major 
source of technological innovation necessary to protect the homeland. 
One of my guiding principles will be to seek out and adopt private-
sector solutions whenever possible. Leveraging existing or adaptable 
technologies will allow DHS to accelerate delivery to the field.
    I look forward to working with Congress on key legislative 
priorities including the restoration of Other Transaction Authority 
(OTA). OTA is a critical tool used to partner with nontraditional 
small- and medium-sized businesses and organizations on innovations 
that enhance our national security. The expiration of the authority on 
September 30, 2024, brought to a halt various efforts at S&T to develop 
solutions across several mission areas.
    Chairman Garbarino, Ranking Member Thompson, and Members of the 
committee, S&T is committed to delivering innovative, responsible, and 
operationally relevant solutions that strengthen the security of the 
homeland.
    We look forward to continuing our close collaboration with 
Congress, across DHS components and partner agencies, and our external 
partners as we work to execute administration priorities, understand 
emerging threats, and leverage private-sector innovation to make the 
Nation safer.
    Thank you for the opportunity to testify. I look forward to your 
questions.

    Chairman Garbarino. Thank you very much. The gentleman 
yields back. I now recognize Mr. Gottumukkala for 5 minutes to 
summarize his opening statement.

   STATEMENT OF MADHU GOTTUMUKKALA, PH.D., ACTING DIRECTOR, 
    CYBERSECURITY AND INFRASTRUCTURE SECURITY AGENCY (CISA)

    Mr. Gottumukkala. Chairman Garbarino, Ranking Member 
Thompson, and Members of the committee, thank you for the 
opportunity to appear before you today. My name is Madhu 
Gottumukkala, and I serve as the acting director of the 
Cybersecurity and Infrastructure Security Agency or, CISA.
    Before joining the Federal Government, I oversaw State-wide 
technology and cybersecurity operations for the State of South 
Dakota. Earlier in my career, I worked across a wide list of 
telecom and health technology sectors. Those experiences shape 
how I approach the role with a practical understanding of how 
State and local governments and critical infrastructure 
operators experienced this on the ground. I'm honored that the 
President and Secretary Noem asked me to lead this agency.
    Since arriving last May, I have been proud to see the 
professionalism, talent, and deep mission commitment of the 
CISA work force each and every day. I'm also grateful for this 
country's continued bipartisan support and for the authorities 
Congress has provided to enable CISA's mission.
    Over the past year and under President Trump's leadership 
and Secretary Noem's guidance, CISA has remained squarely 
focused on the mission Congress intended when the agency was 
established; that is, supporting, strengthening, and securing a 
Nation's critical infrastructure from cyber and physical 
threats. That mission is operational and outcome-driven.
    Every day, CISA's people work to protect the financial 
systems, safeguard pipelines, and ensure the digital and 
physical infrastructure Americans rely on can withstand 
disruption.
    In 2025, CISA made meaningful progress in an increasingly 
aggressive threat environment. We strengthen our ability to 
detect and respond to cybersecurity threats, deepen 
collaboration across Government and industry, and shared threat 
information and mitigation guidance faster and in more 
integrated ways.
    As it is, CISA supported more than 4,000 victims of cyber 
incidents, published over 1,600 cybersecurity products, shared 
more than 2,500 threat and incident reports, and triaged over 
30,000 incidents through our 24/7 operations center. These 
efforts produced real-world impact and helped ensure Americans 
could continue to rely on the S&T resources.
    As the operational lead for Federal civilian cybersecurity, 
CISA worked really closely with departments and agencies to 
promote risk-based policies and best practices to respond to 
the evolving threats. In 2025, we issued three emergency 
directors to address critical vulnerabilities and cyber 
threats. We also scaled the endpoint detection and response 
technology to over 60 agencies and more than 500,000 endpoints, 
giving analysts near real-time visibility to detect and stop 
those advanced threats.
    In early 2025 alone, CISA blocked more than 1.7 billion 
malicious connections on Federal networks, including 142 
million targeting the critical infrastructure. CISA also 
continued delivering security directly to the State, local, 
Tribal, and territorial governments; a mission that is very 
personal to me given my time serving in the State level.
    With a nationwide presence across the 10 regions, we 
provided tailored training, technical assistance, and planning 
support, recognizing that many of our partners operate with 
limited budgets and staffing. To help address this, in August 
2025, the Department of Homeland Security released funding 
opportunities under the State and local cybersecurity grant 
program, and the Tribal Cybersecurity Grant program making 
available over $100 million to help reduce the cybersecurity 
risk nationwide.
    Physical security remains a no-fail mission for the agency. 
In fiscal year 2025, CISA delivered more than 1,000 counter-IED 
and risk mitigation training courses to over 26,000 
participants; strengthen preparedness, awareness, and also the 
response capabilities.
    We are also actively preparing for the major national and 
international neighbors, including the FIFA World Cup, America 
250, and the 2028 Olympic Games. In April, CISA convened more 
than 730 partners from over 40 agencies at the Lincoln 
Financial Field for the first scale exercise of the workup. 
That exercise produced influence in coordination, 
communication, and public safety.
    As we enter 2026, CISA is executing a mission-first 
approach. We are launching targeted initiatives to close the 
most pressing risk gaps facing the critical infrastructure, but 
clearly, where cyber threats intersect with real-world 
consequences. We are proud as in what works, eliminating 
duplication and ensuring that every product and service 
directly advances CISA's regulatory mission and alliance with 
the administration's goals of efficiency, accountability, and 
impact. This includes incorporating the industry and 
Congressional feedback into the final rule for the Cyber 
Incident Reporting for Critical Infrastructure Act. It also 
includes modernizing how we engage with critical infrastructure 
partners by replacing CPAC, the most streamlined and effective 
engagement framework.
    Finally, we recognize that a disciplined mission requires 
the right work force--not the larger one, but a more capable 
and a skilled one. In 2026, CISA will continue prioritizing in 
mission-critical roles while remaining aligned with the broader 
efforts to convert costs and maximize return.
    Under President Trump's leadership and Secretary Noem's 
guidance, CISA remains committed to being a focused, efficient, 
and accountable agency--one that executes the mission Congress 
assigned and diversity and security for the American people.
    Thank you, again, for your support, and I look forward to 
your questions.
    [The prepared statement of Mr. Gottumukkala follows:]
                Prepared Statement of Madhu Gottumukkala
                            January 21, 2026
                              introduction
    Chairman Garbarino, Ranking Member Thompson, and Members of the 
committee, thank you for the opportunity to appear before you today, 
and for the opportunity to discuss the Cybersecurity and Infrastructure 
Security Agency's priorities to protect the Nation's critical 
infrastructure from cyber and physical threats.
    I appreciate the committee's continued support for the critical 
mission that CISA carries out on behalf of the American people. Since 
President Trump took office last year, and with strong support and 
guidance from Secretary Noem, CISA has been laser-focused on fulfilling 
the mission Congress gave us when the agency was first established by 
President Trump in 2018: to support, strengthen, and secure our 
Nation's critical infrastructure. Our work today is squarely aligned 
with the agency's original statutory purpose. That means working with 
Government and private-sector partners to protect our financial 
systems, safeguard our pipelines, and ensure the digital and physical 
systems our Nation depends on to remain resilient against disruption 
from possible cyber attacks.
    To do this, over the past year, CISA has focused its work on 
efforts aligned to the agency's statutory priorities, including:
   Reinforcing Federal civilian network defense.
   Supporting critical infrastructure nationwide in defending 
        against physical and cyber threats.
   Delivering security directly to State and local governments 
        by offering an array of no-cost resources and tools, such as 
        technical assistance, exercises, and cybersecurity assessments.
   Continuing to share threat information and mitigation 
        guidance in a faster, more integrated way.
    Through these efforts, we remain deeply committed to working side-
by-side with organizations of every size, across every critical sector. 
Because no single entity--not even the Federal Government--can manage 
these risks alone.
    Thanks to the leadership of President Trump and Secretary Noem, 
CISA is leading the fight against malign actors. We strengthened our 
operational capabilities to detect and to respond to cyber threats, 
deepened collaboration across Government and industry, and continued to 
provide guidance to the critical infrastructure community to reduce 
vulnerabilities and systemic risk across our Nation's most critical 
systems and functions as malign actors seek to exploit our Nation's 
vulnerabilities.
    CISA has continued to provide practical services and guidance to 
critical infrastructure owners and operators, helping them to improve 
their resilience, limit disruptions, and recover more quickly when 
incidents do occur.
    Under the Trump administration, CISA is focused on our No. 1 
priority: protecting and defending the American people. CISA's work has 
reduced the impact of cyber incidents and helped to ensure that 
Americans could continue to use the critical infrastructure functions 
they rely on. The agency also continues to share threat and incident 
reports, coordinate intelligence across the Federal Government, and 
partner through structured meetings and threat briefings to strengthen 
resilience nationwide.
    As the operational lead for Federal cybersecurity, and as part of 
our mission to protect and defend Federal civilian networks, CISA 
strengthened its work with each department and agency to promote the 
adoption of risk-based common policies and best practices to 
effectively respond to the ever-evolving threat landscape.
    Secretary Noem recognizes that cybersecurity is national security 
and in 2025, under her leadership, CISA issued 3 emergency directives 
to protect Federal networks from critical vulnerabilities and cyber 
threats. CISA also scaled its Endpoint Detection and Response (EDR) 
Technology, giving analysts near-real-time visibility to detect and 
stop advanced threats.
    The Trump administration recognizes that the Federal Government 
cannot fight our Nation's adversaries alone--we must empower our local 
partners. That is why CISA has worked alongside our State, local, 
Tribal, and territorial (SLTT) governments to deliver security to our 
local partners. With a nationwide presence in 10 regions across the 
country, CISA delivered tailored resources, training, and technical 
assistance to help our partners anticipate, withstand, and recover from 
threats. We also recognize that many SLTT governments across the 
country are constrained by smaller, more limited operating budgets, and 
fewer IT staff than a similarly-sized business. Secretary Noem and I 
recognize this challenge, and so to help support our SLTT partners last 
year, the Department of Homeland Security released Notice of Funding 
Opportunities for the State and Local Cybersecurity Grant Program 
(SLCGP) and the Tribal Cybersecurity Grant Program (TCGP)--$91.7 
million to States and territories and $12.1 million to Tribal 
Governments to address cybersecurity risks.
    CISA remains dedicated to supporting critical infrastructure owners 
and operators. Physical security, defending against physical threats, 
remains a no-fail mission for the agency. In fiscal year 2025, CISA 
continued to train public and private-sector stakeholders on counter-
improvised explosive device (C-IED) and risk mitigation practices, 
enhancing threat awareness, preparedness, and capabilities across the 
critical infrastructure community.
    We also continue to look ahead to preparing for major events in 
2026 and beyond, including the FIFA World Cup, America 250, and the 
2028 Olympics in Los Angeles. To give you just one example of this 
work, in April, CISA convened participants from more than 40 agencies 
at Lincoln Financial Field in Philadelphia, one of the 11 American Host 
cities, for a full-scale exercise ahead of the FIFA World Cup. The 
exercise produced areas for improvement and action recommendations to 
enhance coordination, communication, and public safety.
    Continuing to look ahead as we begin 2026, CISA will reinvigorate 
its mission-first approach. We will be launching targeted initiatives 
designed to close the most pressing risk gaps facing critical 
infrastructure--particularly where cyber threats intersect with real-
world consequences. These efforts are intentionally-scoped, 
operationally-focused, and aligned with the Trump administration's 
broader goals and priorities of efficiency, accountability, and impact. 
We are prioritizing what works from previous lessons learned, 
eliminating duplication, and ensuring every new service or product we 
release directly advances CISA's statutory mission and 
responsibilities.
    For example, CISA is currently reviewing public comments on the 
proposed rule for the Cyber Incident Reporting and Critical 
Infrastructure Act of 2022, or CIRCIA. CISA appreciates the input it 
received from Congress and the public about aligning with Congressional 
intent and streamlining the CIRCIA requirements. CISA is also cognizant 
of the concerns raised regarding the scope and burden of the rule and 
improving harmonization of CIRCIA with other Federal cyber incident 
reporting requirements. CISA is considering this feedback as it works 
to issue a final rule. I look forward to continuing to engage with 
Congress on these efforts and providing updates as the final rule 
process nears its completion.
    Mr. Chairman, I would like to take a moment to thank Congress, and 
particularly this committee under your leadership, for their work on 
reauthorizing CISA 2015, which is mission-critical for CISA's work and 
information sharing with the private sector. The Secretary and I have 
been very clear that we fully support the reauthorization of this vital 
piece of legislation.
    CISA remains steadfast on the agency's statutory intent, we also 
recognize that a disciplined mission requires the right workforce--not 
a larger one, but a more capable and technically-skilled one. In 2026, 
CISA will continue to right-size and rebalance its workforce by 
prioritizing highly technical professionals in mission-critical roles, 
including cybersecurity operators and infrastructure security experts. 
These targeted positions will support front-line critical 
infrastructure owners and operators across every region in the United 
States in reducing their long-term risks. We will execute our hiring 
authorities while remaining consistent with the administration's 
efforts to streamline the Government workforce, control cost, and 
maximize return.
    Under President Trump's leadership and Secretary Noem's guidance, 
CISA remains committed to being a focused, efficient, and accountable 
agency--one that executes the mission Congress assigned, supports the 
administration's priorities, and delivers real security outcomes for 
the American people. We look forward to continuing to work with this 
committee to ensure that CISA has the tools and capabilities necessary 
to protect the Nation's critical infrastructure.
    Thank you again for your support and I look forward to your 
questions.

    Chairman Garbarino. Thank you, Mr. Gottumukkala. I now 
recognize Ms. McNeill for 5 minutes to summarize her opening 
statement.

STATEMENT OF HA NGUYEN MC NEILL, SENIOR OFFICIAL PERFORMING THE 
     DUTIES OF THE ADMINISTRATOR, TRANSPORTATION SECURITY 
                      ADMINISTRATION (TSA)

    Ms. McNeill. Good morning, Chairman Garbarino, Ranking 
Member Thompson, and distinguished Members of the committee. 
Thank you for the invitation to testify before you today on 
behalf of the Transportation Security Administration. I'm 
honored to be here, and grateful for the long-standing and 
productive partnerships TSA shares with this committee and 
Congress.
    I would like to start by thanking TSA employees for their 
unrelenting efforts day in and day out to secure the Nation's 
transportation systems. TSA is an agile security agency 
embodied by a dedicated and professional work force that work 
around the clock to outmatch an increasingly sophisticated and 
dynamic threat.
    TSA's greatest assets is its people, and I want to 
sincerely thank them. From our transportation security officers 
and K-9 handlers to our Federal air marshals, these men and 
women embody the agency's core values. They worked through the 
longest Government shutdown in American history, many without 
pay, and experience personal financial hardships. Their 
commitment to the TSA mission and to the traveling public is 
unparalleled.
    Under the leadership of President Trump and Department of 
Homeland Security, Secretary Kristi Noem, TSA is laser-focused 
on delivering for the American people. The upcoming World Cup, 
America 250, and 2028 Olympics present an enormous opportunity 
to boldly transform transportation security in the United 
States and usher in President Trump's vision for a new golden 
age of travel. Achieving these priorities starts with deploying 
upgraded state-of-the-art technology to our over 430 commercial 
airports nationwide, focusing on our core mission of 
transportation security and harnessing our collective 
investment power and innovation through robust, public, private 
partnerships.
    Last year, passenger volumes at airports reached record 
highs, recording 8 out of the top 10 busiest days in TSA's 
history. In 2025, TSA screened 907 million passengers, 480 
million checked bags, and 2.1 billion carry-on bags.
    With the transportation sector remaining a top target for 
bad actors and continued year-over-year passenger volume 
growth, it is more critical than ever to have a 
technologically-advanced, seamless, and secure aviation system.
    I would like to thank the committee for its strong support 
of the agency's critical aviation security programs, including 
two I would like to highlight: First, the Screening Partnership 
Program through which TSA is working closely with airports and 
industry to incentivize investment in more tailored and 
innovative solutions to strengthen security; and second, the 
One Stop Security Pilot Program which significantly improves 
international aviation security and streamlines the transfer 
process for passengers inbound from the United States with a 
connecting flight.
    In addition to strong partnerships, we must invest in 
modernizing our security technology. One avenue to achieving 
this is for Congress to expand the amount and scope of the 
Aviation Security Capital Fund. Starting in 2004, Congress 
authorized the first $250 million in revenue collected each 
year from the passenger security fee to go to TSA's capital 
fund to be used for checked baggage technology. That amount has 
not been adjusted or raised in 21 years with the next $1.6 
billion in the fee revenue going to annual national deficit 
reduction.
    If Congress were to return the funds collected to be used 
for its intended purpose, passenger security, and expanded to 
include checkpoint technology, TSA can significantly shorten 
its technology deployment time frames, improving both security 
and the passenger experience.
    TSA is committed to making the airport experience smooth 
and stress free for the traveling public, including military 
personnel and American families traveling with children.
    Last year we established the Serve With Honor, Travel With 
Ease Program which provides screening lanes for Active-Duty 
military personnel and their families, as well as the Families 
on the Fly Program, which dedicated lanes for families.
    With the strong leadership of President Trump and Secretary 
Noem, coupled with continued support from Congress and industry 
partners, we can transform aviation security and return America 
to being the world's No. 1 travel destination.
    Chairman Garbarino, Ranking Member Thompson, and 
distinguished Members of the committee, it is a privilege to 
testify before you today. I thank you for your support of TSA 
and look forward to your questions.
    [The prepared statement of Ms. McNeill follows:]
                Prepared Statement of Ha Nguyen McNeill
                            January 21, 2026
                              introduction
    Good morning, Chairman Garbarino, Ranking Member Thompson, and 
distinguished Members of the committee. Thank you for the invitation to 
testify before you today on behalf of the Transportation Security 
Administration (TSA). I am honored to be here and grateful for the 
long-standing and productive partnership TSA shares with this 
committee.
    I would like to start by thanking TSA's employees for their 
unrelenting efforts day in and day out to secure the Nation's 
transportation systems. TSA is an agile security agency, embodied by a 
dedicated and professional workforce that works tirelessly to outmatch 
an increasingly sophisticated and dynamic threat.
    Under the Trump administration and Department of Homeland Security 
(DHS) Secretary Kristi Noem, TSA is laser-focused on delivering for the 
American people, fortifying travel security, renewing its commitment to 
the traveler experience, and serving as a responsible steward of the 
American tax dollar. This starts with deploying upgraded, state-of-the-
art technology to airports nationwide, renewing our commitment to the 
American taxpayer, returning to our core mission, leveraging public-
private partnerships, and enhancing hospitality and the passenger 
experience.
                             tsa priorities
    With the transportation sector remaining a top target for malign 
actors, and passenger volumes at airports reaching record highs in 
2025--including 8 out of the top 10 busiest travel days on record--it 
is more critical than ever to have a technologically advanced, 
seamless, and secure aviation security system. In 2025 alone, TSA 
screened 906.7 million passengers, 480 million checked bags, and 2.1 
billion carry-on bags.
    The upcoming 2026 World Cup, America250 events, and 2028 Summer 
Olympics present an enormous opportunity to boldly transform 
transportation security in the United States. Through new policies, 
legislation, and private-sector partnerships that support technological 
innovation and modernizing the screening process, we can usher in 
President Trump's vision for a new Golden Age of American travel.
Leveraging Public-Private Partnerships to Advance the Mission
    TSA's mission is supported by critical public-private partnerships, 
and the Trump administration, DHS, and TSA are strongly committed to 
working more collaboratively with industry stakeholders than ever 
before, utilizing their expertise and efficiency, to strengthen 
aviation security and improve the passenger experience. On that note, I 
would like to thank this committee for ensuring TSA and our critical 
interagency, State, local, and private-sector partners have the 
resources needed to mitigate the evolving threat landscape, which 
includes the proliferating cybersecurity and Counter-Unmanned Aircraft 
Systems (C-UAS) threats.
            Screening Partnership Program
    Under the Screening Partnership Program (SPP), TSA contracts with 
qualified private companies to provide personnel to perform security 
screening operations at commercial airports. TSA is working closely 
with Congressional and industry partners to modernize SPP to 
incentivize airports and industry to invest in more tailored and 
innovative solutions faster, to optimize security operations, while 
maintaining the Agency's rigorous regulatory oversight and outcome-
based security standards.
            One-Stop Security
    In close partnership with the Department of State, industry, and 
international partners, TSA is advancing the One-Stop Security (OSS) 
pilot program. OSS improves international aviation security, 
streamlines the transfer process for passengers inbound to the United 
States with connecting flights, and eliminates the need for passengers 
and their bags to go through screening again. Last summer, TSA launched 
its first OSS pilot location at London-Heathrow Airport (LHR), 
demonstrating an immediate success for all stakeholders. Currently, 
there are 7 OSS flights per day from LHR into Hartsfield-Jackson 
International Airport (ATL) and Dallas-Fort Worth International Airport 
(DFW), saving each OSS passenger up to 2 hours that he or she can now 
use to relax, shop, and dine at the airport.
            Reimbursable Screening Services Program
    Another critical pilot program that Congress has afforded us to 
explore with industry partners is the Reimbursable Screening Services 
Program (RSSP). RSSP enables TSA to work with industry to screen 
passengers in a location separate from the checkpoint, such as an off-
airport cruise or VIP terminal. RSSP is an innovative public-private 
partnership to alleviate congestion at the checkpoint and offset TSA 
costs. Permanently authorizing RSSP, which is set to expire on January 
30 of this year, will provide certainty and unlock innovation, further 
increasing industry interest and participation.
Investing in Modernizing Security Technology
    Starting in 2004, Congress authorized the first $250 million in 
revenue collected each year from the Passenger Security Fee to go to 
the Aviation Security Capital Fund (ASCF), to be used for checked 
baggage technology. Along with amounts provided in annual 
appropriations, amounts in the ASCF were meant to recapitalize and 
modernize TSA screening technology, but unfortunately this level of 
investment has not kept pace with changing technology and the evolution 
of the threat landscape.
    Over the past several years, Congress has diverted approximately 
$1.6 billion in TSA Passenger Security Fee revenue each year for 
deficit reduction purposes. The President's fiscal year 2026 budget 
proposes to eliminate the deficit reduction contributions and instead 
direct Passenger Security Fee amounts to their intended purpose of 
bolstering TSA aviation screening operations. The fiscal year 2026 
budget also includes proposed additional investments in aviation 
screening technology, such as Computed Tomography (CT) technology, that 
can supplement ASCF amounts to make improvements to both security and 
the passenger experience at the checkpoints. TSA encourages Congress to 
act on the President's fiscal year 2026 budget request so that the ASCF 
is not the only source of funding for modernizing TSA security 
technology.
Renewing Focus on Core Mission and Serving the American Taxpayer
            REAL ID
    Under the leadership of Secretary Noem, since May 2025, TSA is 
fully enforcing its statutory requirements under the REAL ID Act of 
2005. The legislation was enacted in response to the 9/11 Commission 
Report recommendations aimed at combatting fraudulent identity 
documents (IDs) and ensuring passengers are who they say they are. As 
the 9/11 Commission Report stated, ``For terrorists, travel documents 
are as important as weapons.'' This administration acted swiftly to 
enforce the law to ensure TSA maintains the highest standards of 
aviation security for the American taxpayer and traveler.
    Currently, most travelers (about 94 percent) present either a REAL 
ID-compliant or another acceptable form of ID. However, we must ensure 
that everyone who flies is who they say they are. TSA ConfirmID is a 
new modernized alternative identity verification system to enhance and 
streamline identity verification for travelers that do not have an 
acceptable form of ID.
    Starting February 1, 2026, travelers who do not present an 
acceptable form of ID at TSA checkpoints and still want to fly, have 
the option of paying a $45 fee and undergoing the TSA ConfirmID 
process. The fee ensures that the cost to cover verification of an 
unacceptable ID will be borne by the non-compliant traveler, not the 
American taxpayer, and prevents malign actors from getting on a plane. 
TSA will continue working closely with all States to increase adoption 
of REAL IDs and urges all travelers to obtain a REAL ID, or other 
acceptable form of ID, as soon as possible to avoid delays and 
potentially missing flights.
            Improving the Travel Experience for Our Military and 
                    American Families
    TSA is committed to making the airport experience as smooth and 
stress-free for active-duty military personnel and their families, and 
American families traveling with children. To honor those who protect 
our Nation and to recognize their service and sacrifices, TSA has 
established the ``Serve with Honor, Travel with Ease'' program, which 
provides dedicated screening lanes for active-duty military personnel 
and their families at airports near the Nation's largest military 
bases. Similarly, the agency is actively working to create a welcoming 
environment for families with children. TSA's new ``Families on the 
Fly'' program provides dedicated lanes for families at select airports 
to create a welcoming environment and ease stress for families 
traveling with children.
                               conclusion
    Today, TSA is at a strategic crossroads. With continued support 
from Congress and industry partners, a screening process that is more 
efficient, technologically integrated, secure, and affordable to the 
American taxpayer, is within our grasp. Chairman Garbarino, Ranking 
Member Thompson, and distinguished Members of the committee, it is a 
privilege to testify before you today.
    I thank you for your support of TSA and look forward to your 
questions.

    Chairman Garbarino. Thank you, Ms. McNeill. The committee 
will now--I will now recognize myself for 5 minutes of 
questions. But I want to--because it's an oversight hearing, 
and we do have--I want to make sure everybody can ask their 
questions--I will entertain unanimous consent at the end like 
we did last time. So we will accept them all. Just we want to 
do it at the end so there's enough time for everyone to ask 
questions. Because we do have a 2 o'clock--a very important 2 
o'clock hearing that Chairman Guest is running. So, I want to 
make sure that that starts on time as well. So I will start.
    Dr. Gottumukkala, it's been a year now in the Trump 
administration, and there's been some major shakeups at CISA, 
specifically, with some RIFs, and there's been a lot of 
changes. But the agency still remains responsible for defending 
the Federal civilian networks, supporting State and local 
partners, and coordinating with critical infrastructure sectors 
under sustained targeting by foreign adversaries. I have said 
it publicly, I know a number of Members on this committee have 
said it publicly, that any organizational restructuring must 
reinforce CISA's ability to execute its core mission and should 
be done so in coordination with Congress.
    There have been reports that there are planned 
reorganization efforts for CISA. Can you please describe what, 
if any, organizational changes you, as acting director, are 
planning to make in the months ahead, and if there are any that 
you have already done?
    Mr. Gottumukkala. Chairman Garbarino, thank you for the 
question. I want to start by saying that CISA is trying to get 
back on its mission, which is protecting the critical 
infrastructure security from physical and cyber threats. CISA 
is a young agency, and we have grown. As we continue to make 
sure, and as we are rescoping, as you have suggested, sir, we 
do have a lot of changes in the last year. But we do not have 
or planned any organizational changes. But we are continuing to 
look at how we will scope our existing work that we have, so 
that we can get back on our mission of protecting the critical 
infrastructure. If there's any organizational changes, I will 
assure that we will communicate with you.
    Chairman Garbarino. So as of now, you don't have any 
planned reorganizational changes that will be coming to CISA?
    Mr. Gottumukkala. That's correct, sir.
    Chairman Garbarino. OK. I just wanted to reiterate, you 
just said you will--anything--you will be sure to notify 
Congress of any intent to reorganize CISA?
    Mr. Gottumukkala. Absolutely, sir. We want to make sure 
that our resources are aligned with the statutory authorities 
that you have given us and we'll make sure that we'll work with 
you.
    Chairman Garbarino. Wonderful. Do you have the proper 
staffing right now to fulfill CISA's critical mission?
    Mr. Gottumukkala. Chairman Garbarino, thank you for the 
question. We have the staff that we need for the mission that 
we want to protect. So, yes, we have--and like any other 
situation, we do have attrition, we use other hiring 
authorities to make sure that we go back and get back to our 
mission. We are protecting the Nation now every single day.
    Chairman Garbarino. You are in the process of hiring 4 
specific positions right now?
    Mr. Gottumukkala. We have. We obviously use other hiring 
authorities that we have, sir. We are making sure that we have 
the right skills and the right talent that we need across our 
mission areas.
    Chairman Garbarino. Thank you very much. I want to follow 
up also. The Cyber Incident Reporting for Critical 
Infrastructure Act, or CIRCIA, was signed into law nearly 4 
years ago. I was one of the co-leads on it. The final 
regulations, which were supposed to be in October 2025, the 
deadline has now slipped to May 2026. I am happy with that, 
actually, because a lot of us did not like what was coming out 
of the rule making.
    There was supposed to be a--I remember the Secretary last 
year said that there was going to be possible ex parte process 
to update the world. I just want to know where is CISA right 
now in the rule making? Has there been an ex parte process? Are 
they getting close to the Congressional intent that we had when 
we passed the bill originally?
    Mr. Gottumukkala. Chairman Garbarino, thank you for the 
question. The CIRCIA that you are referring to, the Cyber 
Incident Reporting for the Critical Infrastructure Act of 2022, 
what it does, sir, is it requires the covered critical 
infrastructure entities to report any significant cyber 
incidents, ransomware payments to CISA, so the Government can 
highly detect threats faster and assist the systems more 
effectively, and be able to warn others before the attacks are 
spread.
    Chairman Garbarino. I'm going to interrupt you because I'm 
running out of time, but I want to make sure--are you on 
schedule to come out, and have you been working with the 
private sector to address the concerns that came out in the 
original rule-making process?
    Mr. Gottumukkala. Chairman Garbarino, absolutely. We are 
working really hard to make sure that we are getting toward the 
closure line. We did not miss the deadline due to inaction. It 
was a deliberate decision driven by a substance. Some of the 
key drivers that we have worked out, 280-plus detailed public 
comments. We have the stakeholder engagement that is on-going 
and extensive. We want to make sure that the protection for 
companies is there. We are making sure that there is not a 
burden on the people that are making those requirements.
    Chairman Garbarino. I appreciate it. I have run out of 
time. I now recognize the Ranking Member for 5 minutes of 
questions.
    Mr. Thompson. Thank you very much, Mr. Chairman. I'm kind-
of taking off on where you started off with respect to CISA's 
staffing. Congressman McCaul and myself supported CISA becoming 
a part of DHS for all the right reasons. You said that no 
organizational changes; that you're able to accomplish the 
mission. How many vacancies do you have right now in CISA?
    Mr. Gottumukkala. Sir, our head count as of--Ranking 
Member, thank you for your question. We have about 2,400-plus 
employees at CISA. We have the required work force that does 
the mission support every day.
    Mr. Thompson. I need the numbers. How many are you short?
    Mr. Gottumukkala. We have the normal attrition like any 
other Federal agency, sir, which is at 7.5 percent 
approximately this past year. That is significantly less than 
the previous prior years, and as compared to the other Federal 
agencies as well. But, in general, we have the required 
authorities to make sure that we go back to hiring authority to 
be able to hire the required talent.
    Mr. Thompson. I appreciate it. But your staff has been cut 
by one-third. Is that not true?
    Mr. Gottumukkala. Ranking Member Thompson, what we had is a 
work force transition program, and people who left the 
organization, they participated voluntarily. We have the 
required staff that is supporting the mission like we do.
    Mr. Thompson. I'm sure you're going to say that. But I'm 
just trying to get to a number that you started with and what 
the President cut. I mean, it should be easy for you to just 
come up and say, I lost a third of my people, but I'm able to 
accomplish the mission.
    Mr. Gottumukkala. Understood, sir. Ranking Member Thompson, 
the way--let me clarify this. As of January 20, 2025, our CISA 
work force was 3,389-plus. At the end of December, we were at 
2,389. We have the work force transition, like I said, and we 
have the normal attrition. But like I said, the way we are 
supporting background mission is to make sure that we are 
protecting our critical infrastructure from physical and cyber 
threats; and our divisions are properly equipped; and we are 
making sure that we are aligning all existing resources----
    Mr. Thompson. Thank you very much. But you provided a 
November memo that said, contrary to what you're telling the 
committee; we will send a letter to you asking for the specific 
numbers that you're short, and just tell us. That's the only 
thing.
    But this leads me to another issue, since you wouldn't give 
me the number that I ask. Are you aware that you reportedly 
failed the counterintelligence polygraph test?
    Mr. Gottumukkala. Ranking Member Thompson, I do not accept 
the premise of the characterization, and I'm not going to 
discuss the testing outcomes or clearance matters in an open 
session. Those issues are handled through the DHS adjudication 
process which are currently under way.
    Mr. Thompson. Did you fail the test; yes or no?
    Mr. Gottumukkala. Sir, like I said, I do not accept the 
premise of the characterization. I understand why people ask 
the question. I'm mindful that situations like this affect 
people, which is why I'm respecting the process and keeping the 
mission steady, sir.
    Mr. Thompson. You're in a very sensitive area, and CISA is 
important to us. I think we need to have people who are in that 
space that pass the standard test. So, I mean, we will pursue 
that a little later, but I was just looking for a yes-or-no 
answer. If you took the test and passed it, fine. If you 
didn't, that's a problem. But I can't get an answer one way or 
the other out of you, and we'll go forward with that.
    Are you aware of the chief information officers at CISA 
that you are, at present, trying to get rid of or have gotten 
rid of?
    Mr. Gottumukkala. Ranking Member Thompson, thank you for 
the question. Individual, personal matters are not made. The 
decisions are not made in vacuum. It is a leadership level at 
the highest levels. We work according to how we see the roles 
fit. But I am not here to comment on them.
    Mr. Thompson. I understand. The last question, Mr. 
Chairman, are you aware of a SCIF being planned and paid for by 
DHS to be built in South Dakota?
    Mr. Gottumukkala. Ranking Member Thompson, thank you for 
the question. I don't know the full specifics of who is 
building, what is building, but I think it is not Federally 
funded by us, which means we will probably be supporting in 
terms of like any other SCIF that we have, irrespective of 
where the location is.
    Mr. Thompson. So you don't know anything about it?
    Mr. Gottumukkala. Yes, sir, of course I know that there is 
propositions for a SCIF like any other location.
    Mr. Thompson. Mr. Chair, I'll follow up with some more 
questions for the witness. I yield back.
    Mr. McCaul [presiding]. The Chair recognizes myself for 5 
minutes. I need to say, first, when I was Chairman of this 
committee, 2015, we passed the Cyber Information Sharing Act--
the Ranking Member and I did together. It's been a very 
bipartisan issue. In 2018, we passed the Cyber Security and 
Information Security Agency permanent authorization. The reason 
why I'm going through this legislative history, it's very 
important to know what is still authorized today and what is 
not.
    One of the most critical pieces of CISA, as we imagined in 
Congress, was to share information with the private sector, not 
only to the private sector, but from the private sector, which 
holds about 80 percent of the cyber threat information. Would 
you agree with that, sir?
    Mr. Gottumukkala. Yes, sir.
    Mr. McCaul. Yes. So, that was vitally important as the 
authors of this agency--and we had quite a battle with, I would 
say, with House Intelligence over whether this should be 
warehoused under the National Security Agency which is not a 
civilian agency to interact with the private sector. We thought 
a civilian agency would be the better fit. I would like to 
think that we were right about that. But then the goal was to 
expand the capabilities so that you could meet those 
requirements. Do you feel that you have those capabilities 
today?
    Mr. Gottumukkala. Sir, the CISA 2015, the Cybersecurity 
Information Sharing Act of 2015 that you're referring to, it 
provides the leader foundation for cyber threat information 
sharing between the Federal Government and the private sector. 
It remains one of the most important authorities for defending 
the U.S. critical infrastructure against increasingly 
sophisticated cyber threats.
    Mr. McCaul. OK. So now, let me get back to the 
authorizations, because this is really important for the 
committee Members to know. That now, CISA, the agency was 
permanently authorized. So there's no expiration. However, 
there is one on the Cyber Information Sharing Act was just 
brought about by a compromise with various Members who would 
not vote for it unless we put that expiration term in there.
    So, as of now, it is no longer authorized. It was 
temporarily reauthorized in the CR, which will expire January 
30. So if I can correct myself, it will expire on January 30 of 
this year.
    Mr. Garbarino and Mr. Thompson introduced a reauthorization 
that passed in the Homeland approps bill that did not go to the 
Senate. It is not in the Homeland approps we are voting on this 
week.
    My question to you is: While you still have appropriations 
to the majority, I think, of your agency, I think, if not all, 
to not be authorized, to have a lapse in authorization, at this 
point in time where the cyber threat is far greater today than 
when Mr. Thompson and I first created the agency in the 
Information Sharing Act, in addition, coupled with the World 
Cup FIFA events coming up, the Olympics, and the anniversary or 
250th anniversary of the Republic, how does that harm your 
efforts to protect the Nation?
    Mr. Gottumukkala. Congressman, thank you, again. Like I 
said, I personally support, and DHS also supports the long-term 
reauthorization of the CISA 2015. I understand that the Act 
expires January 30. One of the strengths of CISA is the 
partnership and collaboration with the private sector. The 
private sector understands that this will be extended through 
the continuing resolution.
    Like we have worked with Chairman Garbarino and the 
committee and the wide-spread information----
    Mr. McCaul. Again, if I could--my time is going to expire, 
but this is not your fault, this is Congress' fault. You know, 
it is incumbent, I think the House has done its job, but the 
Senate has not done their job on this.
    So, it is vitally important--and this is a message to the 
Senate--that when we do pass this, again, that the Senate 
reauthorize your mission, otherwise your ability to collect 80 
percent of the threat information from the private sector is 
gone. You're no longer authorized to do that by law. So that is 
why that is so important, sir. This is always--as Mr. Thompson 
knows--it's always been a bipartisan issue. I really hope--and 
I don't have any doubt on my colleagues on the other side of 
the aisle or in the House when you get this done, but the 
Senate, for the sake of the Nation and our security, needs to 
act on this, is highly irresponsible, and quite frankly, just 
downright dangerous what they're doing. They're playing games 
with something that's very serious. With that, I now 
recognize--who is next--Mr. Correa.
    Mr. Correa. Thank you, Mr. Chairman. I want to thank the 
witnesses for being here today. Dr. Madhu, if I may, I wanted 
to follow up with some of the questions and thoughts, 
directions, of the Chairman and the Ranking Member.
    You said--correct me if I'm wrong--a third of your people 
have left voluntarily?
    Mr. Gottumukkala. About 806 people, sir, yes.
    Mr. Correa. A third. It was just stated from both sides of 
the aisle that the threat, cyber threat, is ever-increasing. 
It's even worse now. When I go home, I get stories from local 
vendors that they've been hacked. I get stories that they're 
essentially being held ransom because somebody from outside the 
country has got to them.
    From that level up to Colonial Pipeline, cyber threats 
everywhere, your agency lost a third of their staff. We're 
about to vote on a bill that cuts your funding by about $270 
million. Is that correct, sir? Yes, no, maybe? You're under 
oath, by the way.
    Mr. Gottumukkala. Congressman, thank you. I appreciate 
the----
    Mr. Correa. Yes or no?
    Mr. Gottumukkala. I have to look, sir. We have----
    Mr. Correa. You haven't looked at it, yet----
    Mr. Gottumukkala. We had a Defense budget of $2.5 billion.
    Mr. Correa. Are we about to cut your budget by $270 
million--vote to do that? Are we, yes or no?
    Mr. Gottumukkala. I----
    Mr. Correa. Yes or no?
    Mr. Gottumukkala. I don't have the exact number----
    Mr. Correa. We are. We are. Just watch the votes in the 
next couple of days. Yet you've said that you can still do your 
mission, your assignment to defend this country, 
satisfactorily. Is that what you're saying? Yes or no?
    Mr. Gottumukkala. Congressman----
    Mr. Correa. Yes or no? Do you need more resources?
    Mr. Gottumukkala. Congressman, we are----
    Mr. Correa. Yes or no? Do you need more resources, sir? 
You're under oath.
    Mr. Gottumukkala. Congressman----
    Mr. Correa. Can you assure the public of this country that 
based on all these cuts you've lost a third of your personnel; 
we are about to your cut your budget that you can still do your 
job? Yes or no?
    Mr. Gottumukkala. Congressman, thank you for the question. 
Like----
    Mr. Correa. Yes or no?
    Mr. Gottumukkala. Sir, I did----
    Mr. Correa. Thank you very much. I have got 2\1/2\ minutes 
left. If you could answer that to me in writing later on, I 
would appreciate it.
    Ms. McNeill, thank you for being here today. Quick history. 
TSA, Homeland Security, Department of Homeland Security was 
created as a result of 9/11. That cowardly attack on our 
country that cost us thousands of lives. We don't want to see 
that repeated again. If I remember correctly, hijackers, 
terrorists broke into the cabin of a number of airline flights 
on that day, took command, control of airplanes, and used them 
as weapons against the United States. Is that correct? More or 
less?
    Ms. McNeill. That's correct.
    Mr. Correa. Do you have the resources today to defend 
against something like that?
    Ms. McNeill. We do, sir. Since the establishment of TSA, 
we've taken a concerted layer of approach to aviation security.
    Mr. Correa. Recently--if I may?
    Ms. McNeill. Yes, sir.
    Mr. Correa. Reassignment of some of your personnel to ICE 
and CBP over the last year. So, is that correct? You've lost 
about 250 air marshals; air marshals who are randomly on 
airplanes, on commercial flights, to prevent another 9/11 from 
happening. Those folks are now assisting in ICE removals. Does 
that not concern you? Do you think you are still OK doing your 
job of defending this great country against another hijacking 
attack?
    Ms. McNeill. Yes, we do, Congressman. The Federal air 
marshals today are more agile than at any time before they----
    Mr. Correa. Well, they're agile, but do you have the 
personnel to actually carry out your mission?
    Ms. McNeill. Yes, and they are deployed based on risk on 
our flights. They also offer ground-based security. Yes, they 
do support our colleagues across DHS to advance the National 
Security and Transportation Security Mission, that includes our 
colleagues at ICE, as you mentioned, also the Secret Service.
    Mr. Correa. If I may, I have less than half a minute left. 
If you can answer this question for me in writing: You're 
focused more on investment and technology. I like the focus on 
trained personnel. It sounds like we're cutting back in 
personnel and trying to focus more on technology. I think it's 
a combination of both. But if you can explain to me how we can 
assure this country, our citizens that they are safer today 
than they were back in 9/11. Thank you very much, Mr. Chair. My 
time is up, and I yield.
    [The information follows:]

    TSA has recognized that there is a need for innovative approaches, 
including technology and process improvements, to enhance security 
effectiveness and operational efficiency. As passenger volume continues 
to grow, technology improvements will be key to maintaining passenger 
throughput, hospitality, and customer service that the American public 
expects at our Nation's airports.
    TSA is looking at new checkpoint technology to improve efficiencies 
and reducing staffing requirements. Examples of this include e-Gates 
and Image on Alarm Only, where new technology will allow us to screen 
more passengers with fewer officers, while continuing to maintain our 
security standards.
    Additionally, the fiscal year 2026 (FY26) President's budget 
request (PBR) included a request to end the requirement for 
Transportation Security Officers (TSOs) to staff airport exit lanes. 
Currently 80 percent of all airports maintain the sole responsibility 
for securing exit lanes from unlawful entry into sterile areas, while 
TSA provides staffing coverage at 89 of the over 430 Federalized 
airports. TSA continues to partner with airport authorities to 
transition from exit lanes that require TSO oversight, to those that 
utilize technological solutions to maintain access control as 
opportunities arise. This has allowed TSA to reallocate resources away 
from exit lane staffing to higher-priority security functions.
    This shift recognizes that not all aviation security challenges 
can, or should be, addressed solely through human staffing solutions.

    Chairman Garbarino. The gentleman yields back. I now 
recognize the gentleman from Mississippi, Mr. Guest, for 5 
minutes of questions.
    Mr. Guest. Thank you, Mr. Chairman.
    Ms. McNeill, thank you for being here. Thank you for the 
dedicated men and women who serve under your command. I 
particularly want to thank you in light that those men and 
women worked for a period of 6 weeks, without being paid, as my 
colleagues on the other side of the aisle chose to shut down 
the Federal Government. But they continued to come to work. 
They continued to protect the traveling people. So, thank you 
for their professionalism, for their dedication, for their hard 
work, particularly in a time where you talk about, in the 
statistics that you gave, that last year, passenger volume 
reached record high. You say in your opening statement that 8 
of the 10 busiest traveling days were last year, and that the 
men and women who serve under TSA, that they screened over 906 
million passengers, 480 million checked bags, and 2.1 billion 
carry-on bags, all for 6 weeks without getting paid, continuing 
to do their duty to the traveling public.
    You also mentioned in your opening statements some 
challenges, opportunities that lie ahead. Those include the 
2026 World Cup, where we know that people will be coming from 
across the globe to America to enjoy soccer in the World Cup 
being hosted here. America 250, also next year. Then 2028, we 
know that the Olympics will be held in California. Once again, 
we will have individuals coming across the globe here, coming 
to America to enjoy those events.
    So I want to talk a little bit about--and you mentioned 
this in your statement--I know this is something that near and 
dear to the Chairman, the passenger security fee diversion. For 
now, some 20 years, we've seen a diversion of those funds, 
funds that were originally set up $5.60 for a one-way ticket; 
$11.20 for a round-trip ticket for reinvestment back into 
aviation security. We know that some 20 years ago, before most 
of us were here in Congress, that a decision was made to divert 
some of those fees. That diversion now totals roughly $1.6 
billion a year. Also, in your statement, not only we talked 
about the diversion of those fees, but we talk about the 
Aviation Security Capital Fund which also was established some 
20-some-odd years ago. Originally, $250 million was set aside 
in revenue to screen luggage that is checked by passengers. 
We've seen that that number has not increased now for 20 years. 
You talk about the fact that we are in need of and, one, 
returning those diverted fees back to TSA, putting that money 
back into aviation security, which is what it was created for. 
You also talk in your opening statement about the need to 
increase the Aviation Security Capital Fund. So I want to give 
you just a minute, if you could, to expound on both of those.
    Ms. McNeill. Absolutely. Congressman, I thank you for 
recognizing the work force, because seeing them turn up day in 
and day out throughout that Government shutdown was nothing 
short of inspiring. They kept our skies safe for the traveling 
public and did so with absolute commitment to the TSA mission. 
It is our responsibility to ensure that they have the best 
tools at their disposal to do the job that we are asking them 
to do, and that is why investment in technology is so critical. 
We are facing, year over year, volume growth at our checkpoints 
in infrastructure-constrained environments. The only way that 
we're going to be able to maintain our security posture and 
improve our security posture and deliver an increasingly 
improved passenger experience is through that combination of 
our human talent and technology. That is what we are looking to 
work with as Congress to do to ensure that the Passenger 
Security Fund is used for those purposes.
    I would say that there are several different buckets of 
technology advancement that we would want to ensure that we are 
investing in. One is that cutting-edge screening technology at 
the checkpoint that we all experience when we fly through the 
airports, making sure that that is detecting threats adequately 
as we face an evolving adversary and threat environment.
    Second is around identity verification, right. One of the 
cornerstones of our aviation computer security system is 
knowing who is coming through our checkpoints and doing that 
adequate vetting so we know who they are before they even show 
up. Then, third, is really bringing our checkpoint into the 
21st Century and providing that IT infrastructure so that we 
can really drive improvement on a continual basis to our 
checkpoints.
    Mr. Guest. Ms. McNeill, thank you. My time has expired. I 
yield back.
    Chairman Garbarino. The gentleman yields back. I now 
recognize the gentleman from Michigan, Mr. Thanedar, for 5 
minutes of questions.
    Mr. Thanedar. Thank you, Chairman, and thank you Ranking 
Member for this hearing.
    Ms. McNeill, I have the honor of representing Detroit Metro 
Airport, Michigan's busiest airport, and one of the largest 
airline hubs in the world. Given that I represent Detroit, 
which prides itself on its long history of blue-collar 
contributions to our great Nation, you must also know that I am 
a strong supporter of unions, organized labor, and collective 
bargaining rights.
    In March, TSA announced it will be stripping the collective 
bargaining rights through the American Federation of Government 
Employees, or TSA personnel, but it was blocked by the courts.
    In December, TSA tried, again, to strip collective 
bargaining rights and were again blocked by the courts. Earlier 
last year, you were questioned regarding the role of TSA and if 
you believed that TSA should be privatized. You said that 
nothing is off the table.
    In July, TSA announced it would be seeking private-sector 
assistance for the development and deployment of turn-key 
solutions for use at the airport security checkpoints. Many 
speculate that this announcement means that the TSA is seeking 
to replace its personnel with private-sector security, a common 
union-busting tactic.
    Ms. McNeill, I have very little time, so just a yes-or-no 
question, do you value the work of our hardworking TSA 
personnel?
    Ms. McNeill. Thank you, Congressman, for that question. 
Yes, absolutely. In my opening statement, I stated that TSA's 
greatest assets are its people.
    Mr. Thanedar. Now, if you believe that their work is so 
valuable, why are you seeking to make their jobs harder by 
getting rid of collective bargaining rights, which will help 
them with job security, safe working conditions, and ensuring 
accountability in the workplace?
    Ms. McNeill. The existence of a collective bargaining 
agreement is inconsistent with the mission that TSA has to 
perform and the agility with which we need to run this agency, 
and our employees know that. Actually, the accountability of 
ensuring that we don't have 200 personnel that are doing 
nonscreening work is in place, and returning them to the 
checkpoint is actually better for our employees and the morale. 
Time and again----
    Mr. Thanedar. This is hardworking men and women taking----
    Ms. McNeill. Yes, they are.
    Mr. Thanedar. It's a very stressful environment. They do 
their best to work as hard as--to keep America safe.
    Look, it is a fact that work force morale and retention 
increased significantly since the Biden administration expanded 
bargaining rights. The move to end collective bargaining rights 
is wrong, and I look forward to the courts to continue to block 
these attempts to harm the workplace rights of our Nation's 
workers.
    Now, while I appreciate the TSA workers working so hard, I 
kept hearing a video that was--kept showing every time I'm 
crossing the TSA line.
    Ms. McNeill, in October a video of Secretary Noem blaming 
the Government shutdown on Democrats aired at TSA checkpoints 
across the country.
    As I am sure you know, this was a blatant violation of the 
Hatch Act, which bars partisan activity using Government 
resources. It also violates the Antideficiency Act, which 
prohibits Federal agencies from spending funds beyond what 
Congress has appropriated since the TSA was operating without 
funds at the time.
    Ms. McNeill, why did you allow these blatantly political-
charged videos to play at TSA checkpoints across our country?
    Ms. McNeill. Our responsibility at TSA is, in part, to 
inform the traveling public of what they can expect when they 
arrive at our checkpoints. During the longest Government 
shutdown, that was absolutely necessary to ensure that they 
understood the environment that they were coming into and the 
facts behind that environment.
    The Secretary is very supportive of the TSA work force and 
our mission----
    Mr. Thanedar. I have just a little bit of time.
    Chairman Garbarino. You have no time. The gentleman's time 
has expired.
    Mr. Thanedar. Thank you.
    Chairman Garbarino. I now recognize the gentleman from 
Florida, Mr. Gimenez, for his 5 minutes of questions.
    Mr. Gimenez. Thank you very much, and I'll try to keep this 
brief.
    Ms. O'Neill, have we ever had the capacity to put an air 
marshal on every single domestic flight in the United States?
    Ms. McNeill. The deployment of Federal air marshals----
    Mr. Gimenez. Yes or no, have we ever had the capacity to 
put an air marshal on every single flight in the United States?
    Ms. McNeill. No. That is not----
    Mr. Gimenez. No. OK. That would be--same as me as a fire 
chief closing down a fire station every once in a while and 
hoping a fire didn't happen in that area. So that's what I feel 
about the air marshal program. We're going to have to have a 
lot more conversation about the air marshal program in the 
future. I don't have time right now.
    Second thing, Mr. Gottumukkala--I'm sorry if I butchered 
your name, sorry--where does the Secretary of Homeland Security 
reside?
    Mr. Gottumukkala. In the NCR region.
    Mr. Gimenez. I think she's from South Dakota. OK? Don't you 
think that as the Secretary of Homeland Security, every once in 
a while she's going to need access to a SCIF? Yes. Thank you.
    All right. Now back to Ms. O'Neill. I don't represent an 
airport. I actually ran one, OK? As a mayor of Miami-Dade 
County, I ran Miami International Airport. So airport security 
is really important to me.
    We talk about passenger fees and all that, and if we--if we 
use the schedule you have right now, by what year are we going 
to have the things that you think are vital to our Nation's 
security installed in all our airports?
    Ms. McNeill. At the current pace of funding, Congressman, 
for our computer tomography technology, we're looking at 2042 
and our credential authentication by 2049.
    Mr. Gimenez. Two thousand forty-nine. I hope I'm alive. I 
don't know. It's kind-of getting close. OK.
    So how do they fund these security measures in Europe?
    Ms. McNeill. In Europe, it's a vastly different construct 
than--than here in the United States. The regulatory body set 
the standards and put the requirements on the airports to----
    Mr. Gimenez. That's right. They put it on the airports. You 
know why they put it on the airports? Because they can get it 
done. All right? We're not going to get it done because we have 
fiscal constraints.
    So let me tell you how an airport works. An airport 
decides--in the beginning, the budget, what happens is what is 
it that we need in order to operate this airport? There's a 
number. Then after that, they go, OK, how do we attain that 
number? Well, they attain that number through passenger fees, 
landing fees, concessions, et cetera, because there's revenue 
that comes into the airport and then they balance.
    So if we were to set the standards for what we believe we 
need to secure the American public, I think it would make a 
heck of a lot more sense for us to say the airports, because 
we're actually doing this for you, and the airport--and the 
traveling public, et cetera, to make it safe--which, by the 
way, if we make it unsafe and people don't travel by air 
anymore, it's an unbelievable economic impact on the United 
States.
    The No. 1 economic generator of Miami-Dade County is Miami 
International Airport, and I'm sure that in other communities 
around this country, the No. 1 economic generator is probably 
their airports. I bet you, you know, bottom dollar that in 
Atlanta, for sure, OK, the No. 1 economic generator is the 
airports; Chicago probably, too; New York, the 3 airports, too.
    So why don't we use the European model? Why don't we tell 
the airports what they need to purchase. They will figure that 
into their--into their budgets, finance it, and then give those 
assets over to--to us, which some airports do when they want to 
actually be a little ahead of the game. Isn't that correct?
    Ms. McNeill. We--yes. We have great partnerships with 
airports across the country, and we have put in place several 
different ways for which airports can drive investment to their 
checkpoints, and we have a capability acceptance program where 
airports can essentially donate qualified equipment to TSA so 
that we can upgrade the equipment at the checkpoint.
    That, combined with appropriated funds and looking to 
improve programs like the Screening Partnership Program, allow 
us to provide options to airports on how to drive that 
investment. I'm a big believer in public-private partnerships.
    Like you said, airports are major economic engines of the 
community around them, and this should be an all-hands-on-deck 
approach, and we are an important part of that. Our 
partnerships are actually--absolutely critical to advancing 
that.
    Mr. Gimenez. By the way, we divert a lot of what's supposed 
to be used for security to other purposes. The passenger 
security fee, which is supposed to be----
    Ms. McNeill. Annually, about $1.6 billion.
    Mr. Gimenez. Right, which is supposed--which, when I pay a 
passenger security fee, I expect it to be used for passenger 
security and not to help balance the Federal budget, which is 
what we do here. All right. So I don't think we're going to be 
able to solve that.
    So, Mr. Chairman, I'm going to be introducing legislation 
to change the way that we fund security at the airports, more 
like the--more like the European model, and so, finally, we 
can--we can get the security that we need at our airports 
before the year 2049.
    Thank you. I yield back.
    Chairman Garbarino. Gentleman yields back. I now recognize 
the gentleman from Rhode Island, Mr. Magaziner, for 5 minutes 
of questions.
    Mr. Magaziner. Thank you, Chairman.
    On a Saturday morning in Cicero, Illinois, a young couple 
got in the car with their 1-year-old child and drove to a Sam's 
Club to go grocery shopping. When they arrived, they saw a 
large law enforcement presence, some sort of an operation going 
on in the parking lot, and so they turned their car around to 
leave.
    As they were leaving the Sam's Club parking lot, this 
happened. Please show the first video.
    [Video shown.]
    Mr. Magaziner. Do you know how dangerous it is to spray 
pepper spray into a moving vehicle? Not only could that kill 
the people inside the car, it could kill other drivers and 
bystanders who might be hit by the vehicle.
    There is not a law enforcement agency in this country that 
teaches its officers to do that. In fact, in most law 
enforcement agencies, those officers will be fired, but not in 
Donald Trump's Department of Homeland Security.
    We don't know who these officers were or if they were 
disciplined in any way. All we know is that the White House 
keeps telling them that they have ``absolute immunity.'' 
Absolute immunity, pepper spraying a young family in a moving 
vehicle.
    Whenever we call attention to these kinds of abuses, the 
first thing the administration does is try to blame the 
victims, but this is a family of United States citizens. They 
weren't even protesting. They were just out to get groceries.
    This keeps happening again and again and again. Show the 
second video, please.
    [Video shown.]
    Mr. Magaziner. What was the response of the Homeland 
Security Department leadership after this? Did they express 
remorse? Did they suspend the agents or launch an 
investigation? No. They put up a false tweet blaming that 
family, the victims, calling the Jackson family ``radical 
agitators.''
    Now, unlike a lot of the victim-blaming tweets that the 
administration posts, they actually took that one down because 
it was so indefensible.
    But why was it put up in the first place? What does it say 
about the rotten culture at the Trump Department of Homeland 
Security that, when American citizens are hurt by Federal 
agents, the response is to immediately blame the victims before 
you even know the facts?
    Now, we can keep going and going. These are just a couple 
of examples. I know that this hearing is supposed to be about 
TSA and cyber, which is important, but when the Federal 
Government is sending poorly-trained masked agents into the 
streets beating and gassing peaceful people, including American 
citizens, we cannot pretend that this is normal and act like it 
should be business as usual.
    We need real standards in place, just like every other law 
enforcement agency in the country has, to make sure that 
Federal agents are well-trained, do not use excessive force 
when not warranted, and are held accountable when they do 
things like tear gas a family inside a moving vehicle. This has 
to stop.
    I yield back.
    Chairman Garbarino. Gentleman yields back.
    I now recognize the gentleman from Texas, Mr. Gonzales, for 
5 minutes of questions.
    Mr. Gonzales. Thank you, Chairman. Thank you, panelists.
    Director, Dr. Gottumukkala, this--you know, CISA isn't a 
small little agency that you just go to retire at. It's 
arguably one of the most important agencies in our Government 
that most people don't realize what's happening.
    This year, I would argue one of the biggest things that's 
going to be in your purview is going to be the selection. It's 
going to determine the future not only of our country, but also 
the future of the world in general.
    So midterms elections, my question to you is, what is CISA 
doing to ensure our midterm elections are safe, secure, and 
fair?
    Mr. Gottumukkala. Congressman, thank you. We--election 
security is very important for national security and somehow 
the claim that DHS CISA has rolled back election security 
protections is not accurate.
    We treat election security like any other critical 
infrastructure sector and our election security services remain 
fully in place, including cybersecurity support that we 
provide, the physical security guidance provided. There is the 
incident response that we provide, and also the threat 
briefings for the State and local election officials.
    The election infrastructure owners and operators continue 
to receive the same level of support as other critical 
infrastructure entities. So the--what changed was the scope, 
not the security, sir.
    We ended activities that were outside its core mission but 
not election protections itself, and the election security is 
focused on the infrastructure by all means.
    What it means is we are exclusively focused on defending 
the election infrastructure from any cyber threats, any 
physical threats, and also any foreign adversaries that are out 
there.
    As you may know, sir, foreign threats remain a core 
priority for us. The nation-state adversaries continue to pose 
risks to our election infrastructure. CISA, we are providing 
that threat intelligence, we are conducting the vulnerability 
scanning to all our State and local infrastructure owners, and 
we are making sure that we are coordinating that incident 
response across the board.
    Election security remains integrated into CISA's broader 
cyber and physical security mission, sir.
    Mr. Gonzales. I ask that you make that a top priority, 
because it's a top priority for many Americans. You know, you 
can win an election, you can lose an election, but it has to be 
fair and has to be secure, and our adversaries don't want that.
    My question to you is, how many cyber intrusions do we 
expect this midterm election?
    Mr. Gottumukkala. Sir, we--we look at it as incident by 
incident, and we look at what the risks are. I don't have a 
specific number in mind.
    Mr. Gonzales. Well, we should have that number. We should--
it should first start by how many intrusions did we have last 
midterm and the midterm before that and the midterm before 
that. I don't want us waiting until after the fact to be able 
to go, Yes, we got it wrong, and it turns out our adversaries 
influenced our election.
    To that point, what actions is CISA doing to work with 
other partners, like CYBERCOM, to ensure that these--these 
adversaries are not intruding on our election?
    Mr. Gottumukkala. We have a very good working relationship. 
Our strength is collaboration. We want to make sure that we're 
working with our law enforcement and cluster intelligence 
partners across the country and international partners to make 
sure that we are safe.
    Mr. Gonzales. CYBERCOM in particular, is CISA working with 
CYBERCOM on any cyber offensive actions to prevent our 
adversaries from interfering in our elections?
    Mr. Gottumukkala. Congressman, thank you. We work with 
CYBERCOM on threat intelligence sharing and making sure that we 
have the incident response and we are working with the private 
and stakeholder communities to make sure that threat 
information is shared.
    Mr. Gonzales. OK. We need that to be a priority. That needs 
to be a priority.
    Between CYBERCOM and CISA, you two are the two 
organizations that are going to keep this Nation and our world 
safe to ensure that these elections are fair and secure.
    To that point, what actors--what actors--what state or non-
state actors are the most aggressive in interfering with our 
elections?
    Mr. Gottumukkala. Congressman, thank you. I think the 
threat actors continue--the foreign state adversaries, 
especially the People's Republic of China and Russia, seems to 
be the most adversive nation-state actors. The strategic 
adversary is China. They are long-term, and they have patient 
campaigns focused on prepositioning in our critical 
infrastructure for a strategic advantage.
    As you might have seen with Volt Typhoon and Salt Typhoon, 
they are both PRC state-sponsored campaign focused on 
repositioning themselves inside the U.S. critical 
infrastructure for potential disruption for a future crisis. 
Unlike the traditional espionage, these actors use living-off-
the-land techniques.
    Mr. Gonzales. Director, I have 10 seconds left.
    What I'd say is, you just said everything that everyone has 
ever come before this committee and said. The same actors over 
and over and over again. So it's no surprise that these actors 
are going to be involved. They were involved in the last 
election, they'll be involved in this election, they'll be 
involved in every election going forward.
    What I ask is, instead of the United States playing 
defense, it's long time we play offense and prevent these bad 
actors from influencing our elections.
    With that, Chairman, I yield back.
    Chairman Garbarino. Gentleman yields back.
    I now recognize the gentlelady from Illinois, Mrs. Ramirez, 
for 5 minutes of questions.
    Mrs. Ramirez. Thank you, Chairman. I do have a number of 
articles I want to enter into the record at the end.
    So as a Chicagoan, I know the terror that DHS can inflict 
with unlimited resources and unchecked power. You just saw some 
of that with what Congressman Magaziner just showed.
    Our constituents are being surveilled, they're being 
threatened, they're being tear-gassed, and subjected to 
warrantless arrests, rammed with vehicles. They're being 
kidnapped, and you've seen it, they're also being disappeared. 
Yet, those--there are those in Congress who would still expand 
DHS's budget and ICE capacity to enact Trump's mass deportation 
agenda.
    So, I often get asked back in my district, how is this 
possible? How is it that they can behave this way? How can they 
tear gas a 6-month-old baby? Isn't Congress supposed to be a 
check on DHS?
    Well, first, I say to them, that would require my 
Republican colleagues to agree that bringing senior ICE 
officials to testify before this committee is critical. I do 
hear, Chairman, that that may happen in 6 weeks or so. I think 
it's far too late; they should be here right now.
    Second, that would also suggest that DHS is behaving in 
ways outside its design. Now, let me be clear. DHS and ICE, 
it's not rogue. Let me tell you why.
    Because from its establishment, Congress empowered DHS to 
violate our rights under the pretense of securing our safety. 
Who feels safe right now under DHS? DHS was intentionally 
established with an overbroad mission, an unchecked power, 
which has been expanded by Republicans with a blank check, 
unlimited personnel, and no guardrails whatsoever.
    Trump, with his authoritarian tendencies, is only making 
visible what so many communities have already known to be true. 
DHS is a threat to our collective safety and funding it only 
fuels our destruction and our human suffering.
    It's why 32 people have died in detention in ICE's 
deadliest year yet. U.S. citizens are being shot and killed, 
and the agency doesn't even know who they're hiring and doesn't 
seem to even care who they're hiring. Yet, Trump's campaign 
donors are profiting off the pain of our neighbors, including 
children.
    So today, I say enough. I am introducing today the Melt ICE 
Act that would prohibit DHS from using funds to detain or 
monitor immigrants, effectively limiting ICE's authority and 
ability to continue to cause pain and terror, while redirecting 
the funding that they have, taxpayer dollars that they're using 
to kill U.S. citizens, back into the communities impacted by 
ICE's terror through wraparound services, because we know that 
DHS is being used as a weapon to be pointed toward anyone the 
Government considers a public enemy. Fascism always requires a 
public enemy.
    So we must take the weapon away and hold those who have 
allowed our communities to be terrorized accountable.
    So let me get to the witnesses here. My understanding is 
that your agencies are working with ICE in some capacity under 
the Trump administration. Ms. McNeill, is your agency sharing 
data with ICE, yes or no?
    Ms. McNeill. Absolutely. We are part of the----
    Mrs. Ramirez. Got it.
    Ms. McNeill [continuing]. Department of Homeland Security, 
and that's what we do.
    Mrs. Ramirez. Yes or no, that's it. Thank you.
    Ms. McNeill, I have a follow-up question for you. Why is 
TSA making life miserable for people that have every right to 
travel domestically and who pose no threat to aviation instead 
of focusing on your security mission?
    Ms. McNeill. I don't agree with your statement, ma'am. As 
we have seen, the men and women of TSA are absolutely dedicated 
to the transportation and national security mission, and that 
was very apparent during the 43-day shutdown where they 
continued to show up to work while we waited for funding to 
come----
    Mrs. Ramirez. Thank you, Ms. McNeill. It is clear that 
people are living in fear, and TSA is working with ICE to 
terrorize our communities.
    Dr. Gottumukkala, has your agency taken personnel off 
mission to work for ICE? Let me add to that, that includes 
details and reassignments from your agency to ICE or CBP, as 
well as to the Federal Protective Service and U.S. Marshals in 
communities with ICE enforcement operations. That's a yes-or-no 
question.
    Mr. Gottumukkala. Congressman, not in my times at----
    Mrs. Ramirez. So in the last year, your agency has not 
taken personnel off mission to work for ICE? Yes or no?
    Mr. Gottumukkala. Not in my time, ma'am.
    Mrs. Ramirez. OK. I'll have something into the record that 
indicates the opposite.
    So let me ask you another question. Does it concern you 
that your personnel might already have staffing shortages, as 
we just heard a moment ago, over a third in staff shortages, 
yet the administration is asking for your staff to be used for 
ICE enforcement?
    Mr. Gottumukkala. Congressman--Congresswoman, I think the--
--
    Mrs. Ramirez. Does it concern you, yes or no?
    Mr. Gottumukkala. We are on mission. We are doing all the 
cyber from----
    Mrs. Ramirez. Let me ask you a follow-up question to that.
    Has your agency transferred funding to ICE, yes or no? Has 
any of your funding gone to ICE, yes or no?
    Mr. Gottumukkala. Congresswoman, I--we--not in my time.
    Mrs. Ramirez. The answer is yes, my time is up.
    Chairman Garbarino. Gentlelady's time has expired.
    I now recognize the gentleman from Alabama, Mr. Strong, for 
5 minutes of questions.
    Mr. Strong. Thank you, Chairman Garbarino, Ranking Member 
Thompson.
    As my colleagues have noted, the United States is entering 
a period marked by high-profile special events that increase 
global travel, underscoring the importance of readiness across 
the homeland security enterprise. Thank you to our witnesses 
and their teams for their work to meet these challenges.
    Mr. Allende, within the Science and Technology Directorate 
R&D portfolio, where does the threat posed by unmanned aerial 
systems and Counter-UAS capabilities rank as a priority?
    Mr. Allende. Thank you, Congressman, for your question.
    I think it's very high on our high-priority list. That's 
exhibited by Secretary Noem's creating a program executive 
office within S&T that brings together both the policy and the 
R&D aspects, acquisition support aspects to handle the Counter-
UAS mission, particularly in a speedy manner as we approach the 
FIFA World Cup, L.A. 2028 Olympics, and America 250.
    Mr. Strong. Given the rapid evolution of drone technology, 
how is S&T keeping its Counter-UAS research ahead of its 
threats?
    Mr. Allende. Thank you, Congressman, for the question.
    At present, our focus is getting to speedy delivery of 
systems in the field in preparation for these events. So we're 
providing technical review and assistance to our partners to 
ensure that the right systems that work well get out into the 
field to prevent the threats.
    We are also doing a number of testing, development, and 
evaluation efforts to look at new technologies that may help 
change the game for us. But at present, given the short time 
frames, the thrust of our effort is getting delivery out into 
the fields.
    Mr. Strong. OK. My district is home to the joint S&T, FBI, 
and TSA TIDE Center, as well as the FBI's Terrorist Explosive 
Device Analytical Center. These centers work closely together 
to protect our homeland and stay ahead of potential threats.
    How does the FBI's expertise inform S&T's efforts at TIDE, 
and how does the collaboration enhance TSA's implementation of 
effective screening technologies?
    Ms. McNeill. Thank you for that question.
    We--as an agency, focused on delivering transportation 
security, the traveling public are always focused on looking at 
cutting-edge technologies and how to advance those in 
collaboration with our partners at S&T and across the U.S. 
Government.
    The evolving threat requires us to always evolve our 
posture, and that includes technology. So, you know, we look 
forward to our continued partnership across DHS to ensure that 
we're meeting that mission, but also to work with this 
committee and Congress to ensure that we've got the funding to 
be able to deploy that technology into the hands of our 
operators.
    Mr. Strong. Thank you. Dr. Gottumukkala--how do you say it? 
I won't ask again.
    Mr. Gottumukkala. You're good, sir. You can call me with my 
first name.
    Mr. Strong. Dr. G, there we go.
    CISA was created by Congress with bipartisan support to 
protect national security. Unfortunately, the Biden 
administration transformed an agency once focused on cyber and 
foreign threats to critical infrastructure into an 
unaccountable censorship agency that pressured social media 
companies to take down speech protected by the First Amendment.
    Can you confirm that CISA has stopped those policies of 
policing American speech and returned to its authorized mission 
scope?
    Mr. Gottumukkala. Congressman, thank you for the question.
    I mentioned earlier what changed was the scope, not 
security. CISA ended all the activities that were outside its 
core mission, not election protections. The activities that 
ended involved monitoring any American's lawful speech, any 
narrative management, or any coordination with those social 
media companies on election-related posts.
    Those activities are not operational election security 
services, so we ended abuses, not any protections that we do 
with elections.
    Mr. Strong. You said earlier--and I quote--``CISA is trying 
to get back on mission.''
    For the record, during the Biden administration, what got 
CISA so off its core mission?
    Mr. Gottumukkala. Congressman, thank you for the question.
    As part of this administration and under the guidance of 
Secretary Noem, we are reviewing, line by line, on all the 
items that we do, and we are eliminating any redundancy. We 
have eliminated duplicative oversight roles, and we have 
consolidated fragmented IT support structures.
    We unified a lot of fragmented IT functions under one 
office. We eliminated overlapping IT operations. We removed 
over 300-plus duplicative contractor roles. We modernized some 
of the enterprise IT environment.
    Mr. Strong. Thank you. My time has expired. I thank you.
    Mr. Chairman, I yield back.
    Chairman Garbarino. Gentleman yields back.
    I now recognize the gentleman from New York, Mr. Kennedy, 
for 5 minutes of questions. Sorry about those Bills, buddy.
    Mr. Kennedy. Yes, we are in pain with Bills Mafia. Thank 
you.
    We're here to talk about some very important issues here, 
Mr. Chairman. I want to thank you for bringing this committee 
together today.
    But I am terribly disappointed both by the answers that I'm 
hearing, or the lack thereof answers, as well as the lack of 
ICE being here with us to answer some very serious questions. 
They should be here testifying under oath, answering pressing 
questions that all of us have.
    This committee needs answers from ICE. The people of this 
country need answers of what is happening across this Nation. 
Like what happens to families like Renee Nicole Good's who are 
left with a massive hole in their hearts because of this 
administration's lawlessness?
    What credibility can investigation into this tragedy 
possibly have if it ends as quickly as it begins and 
scrutinizes everyone in Minneapolis except for the agent who 
shot her?
    How many U.S. citizens and lawful residents have been swept 
up in the Trump administration's immigration raids? How many of 
them have seen their due process rights, those enshrined in the 
U.S. Constitution, willfully ignored?
    Why is Secretary Noem taking no responsibility for the 
violence she has brought to our communities? How much farther 
is she willing to go to destroy the American dream as we know 
it?
    What critical DHS missions are being neglected at the 
expense of Secretary Noem's extreme immigration agenda?
    That last question, I'd like to ask the witnesses in detail 
about reassignments away from your respective agencies and 
immigration enforcement missions.
    We know that Secretary Noem has taken thousands of Federal 
personnel from their assigned duties, and it's felt acutely in 
my community in Western New York. My district has four bridges 
that connect New York and Canada, and yet, many of these travel 
processing booths are empty because Secretary Noem is diverting 
resources from Northern Border communities. This drives up 
costs, takes away good-paying jobs, deters travel with our 
closest ally to the north, and makes things less safe.
    So I understand both CISA and TSA have had employees 
reassigned to oversee the Trump administration's immigration 
and deportation operations, along with its Draconian crackdown 
on Americans exercising First Amendment rights.
    So, Acting Director Gottumukkala and Deputy Administrator 
McNeill, how many people from CISA and TSA have been 
reassigned?
    Mr. Gottumukkala. Congressman, not to the knowledge of--I 
don't have the knowledge of any people from CISA.
    Mr. Kennedy. But your agency has been cut by over a third?
    Mr. Gottumukkala. The team participated in a voluntary--the 
work force transition program, and we are working toward our 
own mission of making sure that we are protecting the critical 
infrastructure from cyber and critical threats.
    Mr. Kennedy. Ms. McNeill, how many of your employees have 
been reassigned?
    Ms. McNeill. I'm not aware of any of our employees being 
moved over to ICE.
    Mr. Kennedy. Two hundred fifty air marshals, you've 
testified today, are--have been reassigned. Is that accurate?
    Ms. McNeill. That is not a reassignment. The Federal air 
marshals are providing in-flight security for deportation 
flights, which is actually--falls within their mission space.
    Mr. Kennedy. So outside of commercial flights----
    Ms. McNeill. That's what they do is provide flight 
security.
    Mr. Kennedy. Outside of commercial flights, they have been 
resigned to other flights--250 air marshals have been 
reassigned.
    How can we assure the American people that flying in this 
country is safe post-9/11 if the air marshals that have been 
provided to do the work to keep them safe in the skies have 
been reassigned off of those commercial flights?
    Ms. McNeill. Providing in-flight security for deportation 
flight keeps our skies safe. I don't think that your number is 
accurate, Congressman, but we're happy to make sure that we get 
you that number.
    [The information follows:]

    As part of their regular mission scope Law Enforcement/Federal Air 
Marshal Service (LE/FAMS) has provided approximately 100 Federal air 
marshals (FAMs) on a rotating basis to provide security on select ICE 
Enforcement and Removal Operation (ERO) domestic transfer and 
deportation flights. These FAMs are not reassigned to ICE but perform 
in-flight security and other law enforcement functions that align with 
LE/FAMS' existing in-flight security mission.

    Mr. Kennedy. I believe that's the number that was mentioned 
in this testimony today.
    Do you believe the TSA employees have the right to 
organize, Ms. McNeill?
    Ms. McNeill. As I stated earlier, the administrator has--
has the authority to set the terms and framework of employment 
of the TSO work force, and we need to do so in a way that keeps 
in mind the mission of TSA which was granted by Congress----
    Mr. Kennedy. Is that a yes or a no?
    Ms. McNeill [continuing]. That we have a work force to 
deliver to the American people.
    Mr. Kennedy. Do you believe that the employees that keep 
our skies, our communities safe have a right to organize in 
this country?
    Ms. McNeill. I think that is----
    Mr. Kennedy. Yes or no?
    Ms. McNeill [continuing]. Determined by--by the 
administrator. Actually, what we are focused on is delivering 
aviation and transportation security for the American people 
and being a good steward of the taxpayer.
    Mr. Kennedy. Yes. I will take that as either a nonanswer 
or, quite frankly--sounds like a no to me, which is very, very 
disappointing, disheartening not just to this panel and to this 
committee, but to the rank-and-file working families that are 
out there protecting us each and every day.
    It is their right in this country to organize if they 
choose to do so, and quite frankly, it is an obligation of this 
Government to work with them in a collective bargaining 
scenario to provide them the rights that they deserve.
    I yield back.
    Chairman Garbarino. Gentleman yields back.
    I now recognize the gentleman from Arizona, Mr. Crane, for 
5 minutes of questions.
    Mr. Crane. Thank you, Mr. Chairman.
    I want to start by pushing back against my colleagues on 
the other side. You know, it's interesting to me, I've only 
been in Congress for 3 years now, but they clearly created this 
catastrophe. We warned about it in the last Congress, why the 
Southern Border was wide open, and many of our visa programs 
were being completely exploited, and now you have 15 million 
people in the country. That's a figure they won't even argue 
with.
    Now the American people elected President Trump and this 
administration to go and solve the problem. Now--so they've 
turned on ICE, whose job is to get the criminals and these 
people out of the country, and so they've turned on ICE. We 
even have a Member on this panel, again, who assaulted an ICE 
agent, and we wonder why this stuff continues to happen.
    I didn't hear any of them talking about the deportations 
that took place under President Obama, who I believe was 
deporting even more people than President Trump has in his 
first year.
    Next I want to turn what this committee is actually about, 
and I want to start with CISA. Dr. Gottumukkala, under the 
Biden administration, censorship, deplatforming, and flagging 
speech of Americans they didn't like was very common and often 
reported. They censored American citizens who were posting 
about election integrity. They were also deplatforming anybody 
who talked about COVID-19 and its origins.
    What is--correct me if I'm wrong, Doctor, but I thought 
CISA was for, you know, protecting American infrastructure and 
cybersecurity. Is that correct? Why do you think CISA started, 
you know, going after Americans for exercising free speech?
    Mr. Gottumukkala. Congressman, thank you for the question.
    You'd have--election security is focused on infrastructure, 
and CISA's election security is focused exclusively on 
defending the election infrastructure from cyber threats and 
physical threats and foreign adversaries. That includes any 
voter registration systems, election technology, and supporting 
systems, not speech or content moderation.
    Precisely why I keep saying is that watching was the scope, 
not the security. We ended activities that were outside its 
core mission and not election protections. Those activities 
that ended involved monitoring any Americans' lawful speech and 
narrative management, and like you said, sir, coordination with 
social media companies on election-related posts. Those 
activities are not operational election security issues.
    Mr. Crane. Thank you. Sorry I got to cut you off. I got 
more questions.
    I want to turn to Ms. McNeill with TSA. On July 8, TSA 
ended its shoes-off policy, which was obviously in place 
because we had incidents like the shoe bomber that tried to 
bring a bomb in his shoe on board an airplane.
    Why was that policy ended, Ms. McNeill?
    Ms. McNeill. Thank you for the question, Congressman Crane.
    At TSA, we're continually looking at the risk environment 
that we operate within and improving our standard operating 
procedures and operations at the checkpoint to reflect that 
risk picture. There had been multiple risk assessments done in 
past years that allowed us to make that change and amend our 
procedures to maintain the safety of the skies, while 
delivering for the American public continual improvement is 
something that, you know, TSA embraces and----
    Mr. Crane. Ms. McNeill, real quick, do you think with 
technology adapting, it's impossible for somebody to make a 
bomb out of their shoes?
    Ms. McNeill. The way that we approach security is to deploy 
multiple different layers of security and pieces of technology 
to ensure that nobody can, essentially, game the system. We 
have multiple layers from identity and vetting through all of 
the physical screening that happens at the checkpoint and then 
in-flight security as well.
    So through that layered security approach is how we deliver 
for the American public, and that's something that, you know, 
has been in place since the inception of TSA.
    Mr. Crane. Thank you. I want to turn to some of the Somali 
cash going through airports.
    It's estimated that $700 million in cash in passenger 
luggage was leaving the Minnesota airport in the last 2 years. 
Has TSA made any changes to its policies to prevent this 
activity that is tied to the fraud in Minnesota from continuing 
on?
    Ms. McNeill. We are extremely proud of the team at TSA for 
highlighting this issue, by reporting what they saw in the 
normal course of their screening in Minnesota.
    Mr. Crane. But reporting is not enough, right? It continued 
to go on, and we got $700 million in cash. Has anything been 
changed? That's the question I asked you to stop this from 
happening.
    Ms. McNeill. We are working with our interagency partners 
and law enforcement partners to ensure that this issue is being 
addressed. We continue being a good partner to them.
    The money that was moved through, was moved through through 
legal means, and so, this is where I think Congress has a role 
to play to think about the authorities around--around this bulk 
cash movement.
    Mr. Crane. Thank you. I yield back.
    Chairman Garbarino. The gentleman yields back.
    I now recognize the gentlelady from New Jersey, Ms. McIver, 
for 5 minutes of questions.
    Mrs. McIver. Mr. Crane, I don't know what your obsession is 
with me.
    Mr. Crane. I thought you were supposed to address the 
Chair?
    Mrs. McIver. But I am so tired of you mentioning me.
    Mr. Crane. Mr. Chairman, is she supposed to address me or 
the Chair?
    Mrs. McIver. You can take that obsession and you can put it 
to the people of Arizona, not me. My name----
    Mr. Crane. Yes. Well, If you quit assaulting ICE agents----
    Chairman Garbarino. The committee will come to order.
    Mr. Crane [continuing]. Then I wouldn't keep bringing you 
up.
    Mrs. McIver. I am reclaiming my time. I am reclaiming my 
time.
    Chairman Garbarino. The committee will come to order.
    Mrs. McIver. Watch your mouth when you're talking----
    Mr. Crane. Follow the rules of the committee, Mrs. McIver.
    Chairman Garbarino. Come to order.
    Mrs. McIver. Excuse me. I'm reclaiming my time.
    Thank you, Mr. Chairman and Ranking Member. Let me get to 
the business that I'm here for, for the people of New Jersey, 
not Mr. Crane. Thank you for holding today's hearing.
    Here we are 3 weeks into the new year, and finally, we're 
having our first full committee hearing in more than a month. 
During that time, the lawlessness of DHS under Donald Trump and 
Kristi Noem has increased tenfold.
    Just last week, a parent in my home State of New Jersey was 
detained by ICE after ordering food for his 6-year-old 
daughter. When her dad didn't come home, the little girl was 
then found crying and wandering around for hours outside 
parentless. How inhumane.
    Like I told Secretary Noem when she sat in this room last 
month, the greatest threat to the homeland right now is the 
Department of Homeland Security under her control. 
Unfortunately, the Republicans, like Mr. Crane, in control of 
Congress are not up to the task.
    In the face of the administration's appalling escalation of 
violence, the Majority has set up this hearing with a random 
assortment of DHS leaders who are not the ones we really need 
to hear from in this moment. I join my colleagues in demanding 
that we bring ICE's acting director, Todd Lyons, before the 
committee as soon as possible, respectfully, Mr. Chairman.
    That would be just the start of providing the 
accountability and change our constituents are demanding of us 
right now in this moment. Now, since having administration 
witnesses is a rarity this Congress, I do want to talk a bit 
about TSA.
    Acting Administrator McNeill, I want to note that I am the 
top Democrat on the Transportation and Maritime Security 
Subcommittee, but this is the first time we have met. In fact, 
this is the first time we have had a single TSA witness before 
the full committee or any subcommittee this Congress, even as 
the Majority is embarking on an effort to reauthorize the 
agency.
    Ms. McNeill, as with other DHS components, this 
administration has been lawless in its direction for TSA. Last 
month, Secretary Noem tried to abolish the work force's 
collective bargaining rights in a blatant defiance of a court 
order to keep them in place.
    My fellow Democrats and I wrote to the Secretary and to you 
to demand that you halt those efforts, and I am glad that a 
court has since ruled that those efforts are, in fact, illegal. 
However, we still did not hear from you.
    Ms. McNeill, I recognize you have no control over Kristi 
Noem's lawlessness and cannot speak to whether she will 
continue to break the law. But speaking for yourself in this 
moment, yes or no, will you commit to abiding by the court 
order to keep TSA's collective bargaining agreement in place 
and fully honor its provisions?
    Ms. McNeill. Every step that the Secretary and that we have 
taken has been in compliance with the courts.
    Mrs. McIver. Is that yes or no? I'm speaking on behalf of 
you, not Secretary Noem.
    Will you commit to that? Will you commit to the----
    Ms. McNeill. The Secretary and I have continued to be in 
compliance.
    Mrs. McIver [continuing]. Provision? Will you commit to the 
provision as the acting administrator, yes or no?
    Ms. McNeill. We are--we are both--both the Secretary and 
myself are committed----
    Mrs. McIver. OK. I'll go to my next question, Ms. McNeill, 
because you're going to do this today. I don't have much time.
    OK. Ms. McNeill, what has TSA done prior to providing 
passenger data to ICE to ensure compliance with the law?
    Ms. McNeill. We are acting within our absolute authorities. 
We are part of the Department of Homeland Security.
    It was a department that was set up by Congress to ensure 
that these agencies weren't operating in silos, and that's what 
we are doing today to advance the mission--the national 
security mission of the Department.
    Mrs. McIver. Ms. McNeill, TSA mission is to secure 
transportation, not to assist ICE with immigration enforcement. 
There is no law that forbids undocumented people from flying 
domestically within the United States.
    The vast majority of undocumented people have no criminal 
record and pose absolutely no threat to aviation. Under what 
authority is TSA sharing passenger data with ICE?
    Ms. McNeill. We are absolutely within our authorities to 
share information within the Department of Homeland Security to 
further the national security mission.
    Mrs. McIver. What statute are you following, or policy? 
Point to the policy or the statute that you are following.
    Under what authority is TSA sharing passenger data with 
ICE, that you are allowed to do that?
    Ms. McNeill. We are allowed to do that. We have authority.
    Mrs. McIver. What policy or statute are you following?
    Ms. McNeill. I can get you the exact policy.
    Ms. McIver. Please do. We will wait on that.
    With that, I yield back, Mr. Chairman.
    Ms. McNeill. Gladly.
    [The information follows:]

    TSA is authorized to share information pursuant to the Aviation and 
Transportation Security Act (49 U.S.C.  114(f)), which empowers TSA to 
``develop policies, strategies, and plans for dealing with threats to 
transportation security'' and to ``carry out such duties, and exercise 
such other powers, relating to transportation security as the 
Administrator considers appropriate.''
    The Intelligence Reform and Terrorism Prevention Act (49 U.S.C.  
44903(j)) and the Implementing Recommendations of the 9/11 Commission 
Act (49 U.S.C.  114(h)) direct TSA to implement watchlist matching and 
enhance information sharing for security purposes. The Implementing 
Recommendations of the 9/11 Commission Act (49 U.S.C.  114(t)) also 
direct TSA to establish a Transportation Security Information Sharing 
Plan to promote the sharing of transportation security information 
between DHS and public and private stakeholders.
    The Privacy Act of 1974 (5 U.S.C.  552a(b)(1)) allows intra-agency 
sharing, such as sharing between components of one agency, when there 
is a ``need to know.'' DHS's Policy for Internal Information Exchange 
and Sharing (Policy Statement 262-18, 2007) clarifies that ``all DHS 
components are considered part of one `agency' for purposes of the 
Privacy Act 5 U.S.C.  552a(a)(1), (b)(1),'' and that information shall 
be shared within DHS ``whenever the requesting officer or employee has 
an authorized purpose for accessing the information in the performance 
of his or her duties.'' Therefore, information sharing between DHS 
components is permissible under the Privacy Act when there is a ``need 
to know.''
    Consistent with Privacy Act exception (b)(1) and DHS Policy 
Statement 262-18, TSA entered into an agreement with ICE to use 
information provided by ICE to identify potential matches in TSA's 
data, beginning in early June 2025.
    The information sharing outlined in the 2025 MOA reaffirmed and 
codified a history of coordination between TSA and ICE that has been 
used during multiple administrations to address threats within the U.S. 
border, including under the Biden administration.
    TSA only shares the flight information of potential matches to 
individuals that meet ICE mission needs, which is a very small subset 
of the traveling public. TSA assigns a confidence level to individual 
matches identified and any matches that score a confidence of 100 
percent based on full name and date of birth are returned to ICE to 
perform any additional adjudication of the matches. TSA does not 
perform any vetting or adjudication of matches provided to ICE, nor 
does the agency advise on immigration enforcement decisions. ICE 
retains final authority for immigration enforcement operations.
    TSA complies with the e-Government Act of 2002 ( 208, 44 U.S.C.  
3501), Privacy Act of 1974 (5 U.S.C.  552a(e)(4)), and Homeland 
Security Act of 2002 ( 892, 6 U.S.C.  482) by publishing Privacy 
Impact Assessments (PIAs) and System of Records Notices (SORNs) for the 
Secure Flight Program (73 Fed. Reg. 64018), ensuring transparency, 
accountability, and on-going oversight by DHS Privacy and Civil Rights 
offices.
    TSA has provided public notice that this sharing will occur in 
Privacy Impact Assessment DHS/TSA/PIA-018--TSA Secure Flight Program, 
which states TSA ``will share information within DHS with those offices 
and components that have a need for the information in the performance 
of their duties under 5 U.S.C.  552a(b)(1). These purposes may include 
national security, law enforcement, immigration, intelligence, and 
other DHS mission-related functions and to provide associated testing, 
training, management reporting, planning and analysis.''

    Chairman Garbarino. Gentlelady yields back.
    I now recognize the gentleman from Tennessee, Mr. Ogles, 
for 5 minutes of questions.
    Mr. Ogles. Thank you, Mr. Chairman. Thank you to the 
witnesses.
    You know, there's been a lot of talk about ICE and, 
unfortunately, really outside the scope of this hearing. For 
that, to our witnesses, I apologize, because Science and 
Technology, TSA, as Chairman of cyber, I'm going to spend a lot 
of my time with the good doctor here.
    But, S&T, if you would, please, if there's anything that we 
can do as Members of this committee and Congress to help you 
affect your job more efficiently, please, if you'll reach out 
to my office. I'd love to have an off-line conversation with 
you.
    TSA, same with you as well. I commend you and your office 
and your agents for the job you're doing during the shutdown.
    It should be noted, Mr. Chairman, that Joe Biden, you know, 
reassigned air marshals to assist with the movement of illegals 
across the Southern Border. So when we talk about reassignment 
of roles, let's look at the large scope of how it's been done 
under previous administrations.
    So--and then again, collective bargaining, you want to talk 
about manufacturing, when you look at Six Sigma, and Lean Six 
and efficiencies within operations, the----
    Mr. Correa. Will the gentleman yield?
    Mr. Ogles [continuing]. Fact that we leave to the--to the 
Government is a good thing as we move forward.
    So specifically to Mr.--Dr. Gottumukkala, we have the 
privilege of talking, when you look at reductions within your 
agency, one of the things we've said--or I've said in a 
previous hearing of the Cyber Subcommittee, was that it's about 
quality, not necessarily quantity.
    Can you speak to the numbers and, quite frankly, the trend 
lines, your Department is--when you look at attrition, it's 
slightly below the Federal average. Take it away, sir.
    Mr. Gottumukkala. Thank you, Congressman.
    Mr. Correa. Gentleman yield?
    Mr. Ogles. I do not. Thank you.
    Mr. Gottumukkala. Congressman, thank you for the question.
    First of all, I want to say that there is continued 
bipartisan support across for CISA. The personnel that we have, 
we are making sure that they are on mission. For somehow the 
bad press of whatever we see, we miss the point that CISA 
personnel are deployed across the 10 regions in support of all 
56 States and territories.
    Mr. Ogles. Specifically, good Doctor, because we have 
limited time. So roughly, 800 agents. What percentage of the 
work force is that? Twenty-three semi-percent?
    Mr. Gottumukkala. That is correct, sir. There were 23 
percent participated in the work force transition program.
    Mr. Ogles. Then the national average aside from that, 
roughly 9 percent across Federal agencies, you're trending 
what, 7 percent attrition?
    Mr. Gottumukkala. That is correct, sir. Compared with 
previous years, it's about 9.25 approximately across all 
Federal agencies, and we are or we were at 6.5 to 7.5 percent 
from an actual attrition this year.
    Mr. Ogles. So the facts, quite frankly, speak for 
themselves. As Chairman of Cyber, you know, I've spent a lot of 
time in the SCIF getting updates on the constant attacks that 
we face from threat actors like China, like North Korea, like 
Iran, like Russia.
    Yet, you're doing more with less, and you're doing it more 
efficiently. So for that, I say thank you.
    Now, one of the things that we've talked about and what's 
important, I think, to the American people, when we--again, I 
said in the hearing the war has already begun. We know who the 
adversary is. Our primary adversary is China.
    It's important that we on this committee, and you and your 
agency, have better communications, increase communications, 
and then were updated really on a much more timely basis. So 
with that--and, again, per our conversation, do you agree that 
Members of this committee, and in particular, the Subcommittee 
on Cybersecurity and Infrastructure--which has direct oversight 
of CISA--will be informed in a timely manner and, quite 
frankly, when needed, in a SCIF so that we can do our jobs and 
help you and assist you in doing yours, sir?
    Mr. Gottumukkala. Congressman, I appreciate the support. 
Yes, definitely.
    Mr. Ogles. Then to change subjects--and I appreciate your 
willingness to meet with me. I appreciate all of you for being 
here.
    When we look at the mission statement and the directive we 
have here with the committee, it's important that we keep 
things in perspective. We have an obligation to the American 
people and to the American taxpayer.
    One of the things that we've seen under the previous 
administration--administrations, plural--is the absolute suck 
on our system, our infrastructure, and our welfare. So, for 
example, Bataan, 81.4 percent are on welfare; Yemen, 75.2 
percent; Somalia, 71.9 percent; Marshall Islands, 71.4 percent; 
Afghani, 68.1; Dominican Republic, 68.1; Bangladesh, 54.8; 
Pakistan, 40.2; and I can go on.
    But this idea that doctors and lawyers were brought into 
this country to help our society is absolute nonsense. Go back 
to Hart-Celler, back to the 1960's, let's abolish it and, quite 
frankly, deport them all.
    This is the United States of America. We get to decide who 
comes in, and, Mr. Chairman, we get to decide who leaves. I 
yield back.
    Chairman Garbarino. Gentleman yields back.
    I now recognize the gentlelady from New Jersey, Ms. Pou, 
for 5 minutes of questions.
    Ms. Pou. Thank you, Mr. Chairman. So as we sit here, DHS is 
operating an armed invasion of an American State: Minnesota. 
Local law enforcement described DHS tactics as ``profoundly 
detrimental to public safety.''
    An American citizen was shot in the face and killed by an 
ICE agent. Secretary Noem and ICE Director Todd Lyons should be 
here testifying under oath what happened to Renee Good, and the 
pervasive ICE violence against Americans because we know Noem's 
taxpayers-funded media tour continues to spew outright lies 
about her Department, including calling Renee Good a domestic 
terrorist.
    Just this weekend, the Secretary went on TV and said that 
70 percent of the people held by ICE have committed violent 
crimes. In fact, only 25 percent of individuals of--in ICE 
custody have criminal convictions, with many being minor 
offenses like traffic violations, and that's a fact.
    No one here can speak to the rampant DHS corruption, like 
the $200 million in taxpayers' money used for an ad campaign to 
the Secretary's aide and family, or her so-called border czar, 
who accepted a fast food checkout bag stuffed with $50,000 cash 
bribe.
    Why is DHS illegally blocking Congress from entering ICE 
facilities? Is it to cover up the 32 people who died in ICE 
custody last year or the 4 this year, including a reported 
homicide at a Texas ICE facility earlier this month?
    There are now reports that in my home State of New Jersey, 
ICE is looking to convert massive warehouses into detention 
centers, including one in Roxbury.
    None of these witnesses can speak to any of these abuses, 
but there are important questions that we can cover, starting 
with election security. I am alarmed by the administration's 
termination of funding for State and local elections offices 
for election security. We talked earlier, and someone asked 
about how safe are our elections? Are they fair? Will they be, 
indeed, secured?
    This President has attempted to weaponize CISA and spread 
disinformation about his election loss in 2020. So I'd like to 
ask Dr. Gottumukkala, did Donald Trump win or lose the 2020 
election? Yes or no?
    Mr. Gottumukkala. Congresswoman, I will be more than happy 
to talk about----
    Ms. Pou. Yes or no?
    Mr. Gottumukkala. I am not here to discuss about----
    Ms. Pou. I know. Yes or no?
    Mr. Gottumukkala [continuing]. The 2000 election or the 
2020 election.
    Ms. Pou. Did Donald Trump lose the 2020 election, yes or 
no?
    Mr. Gottumukkala. Ma'am, I'll be more than happy to discuss 
about the legwork that CISA does and how we are back on mission 
and----
    Ms. Pou. You know what, it's--I can understand----
    Mr. Gottumukkala [continuing]. How we are----
    Ms. Pou. You know, I will tell you, it's--this is a simple 
question that only has the right--only has one right answer. 
Yes, he was, in fact, defeated.
    Do you believe that Donald Trump defeats--do you believe 
that Trump's defeat in 2020 contributed to this 
administration's cutting funds to support election security for 
State and local officials? Yes or no?
    Mr. Gottumukkala. Ma'am, election security is focused on 
infrastructure, and as CISA, we are exclusively focused on 
defending the election infrastructure.
    Ms. Pou. Quite honestly, it's very simple. What kind of 
justification could explain this reckless cut? Please explain 
that.
    Mr. Gottumukkala. Ma'am, once again, I have explained 
before, the people that have participated in the work force 
transition program, they have done that voluntarily.
    Ms. Pou. It's clear that you're not going to be able to do 
that. I'm sorry, but it's obviously clear that you're not 
looking to answer a simple question with a yes-or-no answer.
    I am very concerned, Mr. Chairman, over the fact that one 
of my colleagues asked earlier about sharing information. Ms. 
McNeill, the passengers, are we--are we, in fact, making TSA--
American citizens aware that TSA is, in fact, diverting 
resources and how are they--those personnel information being 
shared between agencies?
    Do the American people know that their information may very 
well be shared?
    Chairman Garbarino. The gentlelady can maybe respond in 
writing to that question. The time has expired.
    Ms. Pou. That's fine.
    Chairman Garbarino. I appreciate that.
    [The information follows:]

    TSA is authorized to share information pursuant to the Aviation and 
Transportation Security Act (49 U.S.C.  114(f)), which empowers TSA to 
``develop policies, strategies, and plans for dealing with threats to 
transportation security'' and to ``carry out such duties, and exercise 
such other powers, relating to transportation security as the 
Administrator considers appropriate.''
    The Intelligence Reform and Terrorism Prevention Act (49 U.S.C.  
44903(j)) and the Implementing Recommendations of the 9/11 Commission 
Act (49 U.S.C.  114(h)) direct TSA to implement watchlist matching and 
enhance information sharing for security purposes. The Implementing 
Recommendations of the 9/11 Commission Act (49 U.S.C.  114(t)) also 
direct TSA to establish a Transportation Security Information Sharing 
Plan to promote the sharing of transportation security information 
between DHS and public and private stakeholders.
    The Privacy Act of 1974 (5 U.S.C.  552a(b)(1)) allows intra-agency 
sharing, such as sharing between components of one agency, when there 
is a ``need to know.'' DHS's Policy for Internal Information Exchange 
and Sharing (Policy Statement 262-18, 2007) clarifies that ``all DHS 
components are considered part of one `agency' for purposes of the 
Privacy Act 5 U.S.C.  552a(a)(1), (b)(1),'' and that information shall 
be shared within DHS ``whenever the requesting officer or employee has 
an authorized purpose for accessing the information in the performance 
of his or her duties.'' Therefore, information sharing between DHS 
components is permissible under the Privacy Act when there is a ``need 
to know.''
    Consistent with Privacy Act exception (b)(1) and DHS Policy 
Statement 262-18, TSA entered into an agreement with ICE to use 
information provided by ICE to identify potential matches in TSA's 
data, beginning in early June 2025.
    The information sharing outlined in the 2025 MOA reaffirmed and 
codified a history of coordination between TSA and ICE that has been 
used during multiple administrations to address threats within the U.S. 
border, including under the Biden administration.
    TSA only shares the flight information of potential matches to 
individuals that meet ICE mission needs, which is a very small subset 
of the traveling public. TSA assigns a confidence level to individual 
matches identified and any matches that score a confidence of 100 
percent based on full name and date of birth are returned to ICE to 
perform any additional adjudication of the matches. TSA does not 
perform any vetting or adjudication of matches provided to ICE, nor 
does the agency advise on immigration enforcement decisions. ICE 
retains final authority for immigration enforcement operations.
    TSA complies with the e-Government Act of 2002 ( 208, 44 U.S.C.  
3501), Privacy Act of 1974 (5 U.S.C.  552a(e)(4)), and Homeland 
Security Act of 2002 ( 892, 6 U.S.C.  482) by publishing Privacy 
Impact Assessments (PIAs) and System of Records Notices (SORNs) for the 
Secure Flight Program (73 Fed. Reg. 64018), ensuring transparency, 
accountability, and on-going oversight by DHS Privacy and Civil Rights 
offices.
    TSA has provided public notice that this sharing will occur in 
Privacy Impact Assessment DHS/TSA/PIA-018--TSA Secure Flight Program, 
which states TSA ``will share information within DHS with those offices 
and components that have a need for the information in the performance 
of their duties under 5 U.S.C.  552a(b)(1). These purposes may include 
national security, law enforcement, immigration, intelligence, and 
other DHS mission-related functions and to provide associated testing, 
training, management reporting, planning and analysis.''

    Ms. Pou. Thank you, Mr. Chairman. I yield back. I would 
like, however, to be able to ask that question.
    Chairman Garbarino. Absolutely. All committee Members will 
have the time to submit questions in writing.
    Ms. Pou. Thank you.
    Chairman Garbarino. I know I have a bunch that I'm going 
to----
    Ms. Pou. Thank you very much.
    Chairman Garbarino. Thank you. Gentlelady yields back.
    I now recognize the gentlelady from South Carolina, Mrs. 
Biggs, for 5 minutes of questions.
    Mrs. Biggs. Thank you, Mr. Chairman, and thank you to our 
panelists for being here today.
    I would like to elaborate on my colleague, Congressman 
Crane, what he was stating. It is concerning to me that for 2 
years, Somali residents were walking through the Minneapolis 
airport with duffel bags filled with cash, on nearly $1 million 
a day totaling nearly $1 billion. I think that's astonishing.
    TSA reportedly flagged this flood of money and raised it to 
DHS and to intel agencies. So, Administrator McNeill, did that 
really happen, and who were these individuals responsible for 
this, and where was the cash going? Because to me, it--if that 
is what was reported, why wasn't it stopped immediately? This 
money could have easily been used for terrorists and tied to 
the same massive Somali fraud networks that we keep seeing 
across Minnesota.
    Ms. McNeill. Thank you, Congresswoman, for that question.
    TSA did, indeed, report these incidents as it came across 
the checkpoint because bulk cash shows up as a mass on the X-
ray, and so our officers have to resolve what they can't 
identify on the X-ray machine. Through the course of their 
normal day-to-day duties, they reported that to our law 
enforcement partners in compliance with their standard 
operating procedures.
    This is why it's really important to take a whole-of-
Government approach on this and levy the authorities of all 
these law enforcement agencies, both across DHS and with the 
Department of Treasury, to ensure that we are taking a 
concerted whole-of-Government approach to this. I think this is 
where the role of Congress is also critical to ensure that we 
have the right framework in place to take action.
    As I mentioned earlier, the movement of this money 
historically had been done through legal channels, and so, you 
know, I think we're going to have to collectively work on this.
    Mrs. Biggs. I still didn't hear what is actually being done 
about it.
    Ms. McNeill. We continue to report it based on our standing 
operating procedures. I know there's a, you know, an on-going 
investigation with our law enforcement partners. We are part of 
that, and we are happy to brief you and the Members of this 
committee on any developments that we see on that front.
    Mrs. Biggs. OK. I guess my next question would be, why is 
Congress finding out about this from journalists and not from 
DHS?
    Ms. McNeill. I can't speak to that. I mean, again, I think 
we, you know, are committed to transparency with this 
committee. As the investigation evolves, we are happy to brief 
out on our part in this and, you know, work with the rest of 
the U.S. Government to make sure that we're taking action.
    Mrs. Biggs. Well, thank you for that. My constituents and 
the American people would love to hear a follow-up on that. 
Thank you.
    So my next question--TSA, the Touchless PreCheck is a 
biometric identity verification capability that enables 
enrolled PreChecked travelers to verify their identity at 
airport checkpoints using facial recognition and eliminating 
the need to present a physical ID. What is TSA's long-term 
vision for this TIS? Is it intended only as a checkpoint 
identity verification tool, or does TSA envision it becoming a 
broader identity platform across the transportation system?
    Ms. McNeill. So, we have launched the Touchless 
Identification System. As you mentioned, TIS in 15 locations 
today for PreCheck. It is a voluntary, facilitative technology 
that we offer to our PreCheck members. We're going to be 
rolling out additional locations, you know, based on the needs, 
experience, and feedback that we're getting from our PreCheck 
populations. It is very well-received. Again, I would just 
state it's voluntary, and it's meant to really provide that 
seamless experience to our trusted populations as they travel 
through our airports because you don't have to take out your 
identity or your boarding pass at the checkpoints. So, it is a 
facilitative tool. That is the intent of that program is to 
offer that benefit to our PreCheck populations.
    Mrs. Biggs. Just one more quick thing. So, is it beyond 
passenger screening? Will it be, like, for cargo or 
international operations? Will it go more in-depth?
    Ms. McNeill. It is intended for passenger screening and for 
our PreCheck population.
    Mrs. Biggs. OK. Thank you. I yield back.
    Chairman Garbarino. The gentlelady yields back. I now 
recognize the gentleman from Texas, Mr. Green, for 5 minutes of 
questions.
    Mr. Green. Thank you, Mr. Chairman. I thank the Ranking 
Member as well. I thank the witnesses for appearing today.
    Ms. McNeill, the Transportation Security Officers' Union is 
under attack. Thankfully, a court injunction has kept TSA's 
union in place. Most recently, the Secretary openly defied the 
court order and tried to disband TSA's union for a second time. 
Last week, the court said those actions plainly defy its 
injunction and ordered the Secretary to keep TSA's collective 
bargaining agreement in place or risk contempt.
    My question to you, acting administrator, is this: Will you 
commit to abiding by the court's order to keep the TSA's 
collective bargaining agreement in place?
    Ms. McNeill. Congressman, every step that we've taken to 
date, and we will continue to abide by court order----
    Mr. Green. Excuse me, if I may. Since I control the time, 
if I may, please. This question can be answered with a yes or a 
no. If there's anything less than a yes or a no, I will assume 
you mean no.
    So, now, back to you again, will you commit to honoring a 
court's order, a court's order, a court's order? When you don't 
honor court's orders and you're the Secretary, you can be 
impeached. So, now, will you commit to honoring the court's 
order?
    Ms. McNeill. Yes.
    Mr. Green. Thank you. I'm pleased that you said yes because 
the Secretary needs to confer with you. She needs your advice. 
The Secretary, quite frankly, is probably being influenced by 
the President. Disobeying court orders is something that is 
antithetical to the Constitution. The courts are there for a 
reason. If we can disobey court orders, we no longer have a 
Constitution that we can count on. You're defacing, demeaning, 
and denigrating the Constitution when this happens--not you 
personally. You've already said yes, and I'm grateful to you 
for saying yes. But that's what's happening. I can assure you 
people are growing tired of seeing what's happening in terms of 
the lawlessness emanating from this Department. They're growing 
tired of it.
    What happened to Ms. Good is something that people are not 
going to forget. For the Secretary and others to contend that 
she was a domestic terrorist is beyond comprehension without 
even having investigated it immediately.
    This was a Christian woman with children, who according to 
her wife, they had whistles, and they indicated that the 
constabulary had pistols as evidenced by the fact that she is 
no longer with us.
    People are getting fed up with this behavior and the 
justifications for lawlessness. We must return to the rule of 
law. One of the ways to return to the rule of law is to enforce 
the law. One of the laws that we can use to make sure the rule 
of law prevails is impeachment.
    This Secretary is putting herself in harm's way as it 
relates to impeachment, not a physicality, but in terms of how 
she is conducting herself in office. My guess is if she is not 
very careful, she may become the first Secretary to be removed 
from office. We have a long runway here. It doesn't end at the 
end of this year. There is a long runway. So, I'm going to beg 
you to counsel with her and help her to better understand that 
the law prevails, and she is not the law, and neither is the 
President. I yield back the balance of my time.
    Chairman Garbarino. The gentleman yields back. I now 
recognize the gentleman from Oklahoma, Mr. Brecheen, for 5 
minutes of questions.
    Mr. Brecheen. Thank you, Mr. Chairman. To our witnesses, 
thank you. As typical in Washington, some of us having to shift 
in and shift out because of scheduling conflicts. I am certain, 
because I heard some of the commentary as I walked in, some of 
what we are going to be discussing, my part, is a little bit 
redundant. Please forgive me, because I did miss some of the 
prior discussion.
    Relative to CISA, and the weaponization that many felt like 
to the social component, social media, I just want to make this 
as a statement--this is kind-of a rhetorical statement, that is 
something of major concern to us that under this administration 
we continue to pay attention to that and make sure that our 
Government is not allowing that to continue that we saw in 
years past.
    That said and moving on for TSA. For the oversight we are 
conducting with the World Cup, with the Olympics, I know 
Director McNeill that you are very much attuned to what's 
ahead, the high volume, the international traffic; look, the 
heightened threat level, the landscape that we had in this 
hearing months ago because of the illegal populations that was 
led in by the prior administration. There is a different threat 
landscape. Whether it be the biometric security screening, REAL 
ID enforcement, the gaps in that, it's been astounding to me to 
find out the number of States that are allowing REAL ID-
compliant driver's license. I've had some State-elected 
officials show me how that is in the past played out to whereby 
the way the prior administration was implementing parole in the 
work permitting process, that REAL ID-compliant driver's 
licenses were being handed to those who were here illegally. So 
to be able to--and I know by your response, I am taking it for 
granted that you may have not heard this before--but it's 
something I would very much like some feedback for our office 
to obtain where we're at on ensuring that with REAL ID coming 
into compliance this year, and all of the objections--and I was 
one of them on the State level--that if we have that type of 
possibility of illegal aliens getting a REAL ID-compliant 
driver's license, what a major security concern that is.
    [The information follows:]

    Under the REAL ID Act and relevant regulations, jurisdictions may 
only issue REAL ID-compliant Drivers Licenses/Identity Documents (IDs) 
to individuals who demonstrate evidence of lawful presence. 
Additionally, jurisdictions must set the credential's expiration date 
to match the end of the individual's lawful presence or a maximum of 8 
years, whichever is sooner. When applying for a REAL ID, individuals 
must present documentation, as outlined in the REAL ID Act, sufficient 
to demonstrate that they are lawfully present in the United States 
which must be verified through the Systematic Alien Verification for 
Entitlements (SAVE) system.
    DHS transferred the REAL ID program to TSA as part of the fiscal 
year 2023 budget, to include recertification requirements. TSA's 
recertification process follows the procedures established in the REAL 
ID regulations, specifically 6 CFR  37.59. As part of TSA's oversight 
of the REAL ID program, TSA recertifies a State's compliance with the 
REAL ID Act and regulations on a regular cycle. States and Territories 
are required to be recertified on a rolling 3-year basis. The recurring 
re-certification process includes a review of the State's procedures 
and practices, as well as on-site inspections, to ensure that all REAL 
ID requirements are satisfied, including the requirement that States 
only issue REAL IDs to individuals who are lawfully present in the 
United States.

    Mr. Brecheen. All right. I want to shift over. I know 
you've talked about the Somalian incident, cash, you've talked 
about, you know, in terms of what you all are doing. My 
question on that is when were you all as an agency made aware 
that this was happening? What was the time line of the millions 
of dollars that, you know, going through the airport security 
system, what timing did you all become aware of this?
    Ms. McNeill. I believe that the reporting started back in 
2017.
    Mr. Brecheen. Two thousand seventeen. OK. With the World 
Cup, with the Olympics, I'm about to say something that I'm 
going to make sure my words are precise and give you a chance 
to kind-of think this thing through because there's an element 
to this just for national security purposes, the DHS Inspector 
General released a report on November 1, 2025 on its 
independent covert testing of the TSA checkpoint screening to 
see how effective it is at preventing threat items from being 
brought onto commercial aircraft. We cannot publicly talk about 
the contents of that report due to the sensitivity of the 
information. But let me ask you, generally, are you aware of 
the report? Have you read it? When did you receive it?
    Ms. McNeill. Yes. Yes to both of your first questions, in 
last November.
    Mr. Brecheen. OK. Do you agree with the findings and 
recommendations of that report?
    Ms. McNeill. I do. It's not anything that actually we 
didn't know already and fully consider in our security 
policies.
    Mr. Brecheen. Would you commit to providing this committee 
with results of any follow-up analysis conducted by TSA related 
to this report?
    Ms. McNeill. We would be glad to have a briefing on this 
topic in the proper Classified environment.
    Mr. Brecheen. Thank you. Transition to another little 
different direction here. New travelers are confused by TSA's 
facial screening practices. Can you please clarify whether this 
is mandatory or optional?
    Ms. McNeill. It is absolutely voluntary. We have signage at 
our checkpoints that notify the passengers of that. If they 
don't opt in, there are alternate procedures that they go 
through. So, it's 100 percent voluntary.
    Mr. Brecheen. With the 25 seconds that I have left, what 
would you say to travelers who are concerned about their 
biometric data being retained as a result of that process?
    Ms. McNeill. I would say that we don't retain the data that 
is captured at the checkpoint. It's solely for the purpose of 
identification at that point in time as we traverse through the 
checkpoint.
    Mr. Brecheen. Thank you very much. Thank you, panel. I 
yield, Mr. Chairman.
    Chairman Garbarino. The gentleman yields back. I now 
recognize the gentleman from New York, Mr. Goldman, for 5 
minutes.
    Mr. Goldman. Thank you, Mr. Chairman. It is good that we're 
having a full committee hearing here. I appreciate you calling 
this hearing. Of course, it relates to nothing that we have an 
urgent need to do oversight on. We do not have Acting Director 
Lyons here when what we're seeing around the country is a mass 
secret agency, dragnet, using violence against American 
citizens and others. It's bewildering to me because I know the 
Chairman is a very good person. We worked together on 
legislation. In fact, I'm optimistic we will pass the Zadroga 
Act together to make sure that 9/11 survivors have certainty 
and security in their health care.
    But I know, I know that you and your colleagues cannot 
possibly be OK watching secret masked ICE agents barging into 
homes without a warrant, pulling American citizens out in their 
underwear, stopping American citizens on the streets and 
demanding their citizenship. That, of course, is not even to 
mention the violence in Renee Good's murder as well as 
everything else we're seeing.
    There is an urgent, urgent need to conduct oversight from 
this committee of the Department of Homeland Security. But it 
is not the Science and Technology Directorate, it is not the 
Cybersecurity and Infrastructure Security Agency, it is not the 
TSA, all of which are very important agencies, and certainly do 
very important work. I am not disparaging the work you all do. 
But the urgency in this country right now is what's going on 
with ICE. Why are we having a hearing with Department of 
Homeland Security officials who know nothing about ICE? We get 
such misinformation from this Department of Homeland Security. 
We're told, oh, it's the worst. It's the murderers. It's the 
rapists.
    In our home State, Mr. Chairman, of the 22 of the 3,212 
people ICE arrested in New York City in 2025 up through October 
15, 70 percent had no pending criminal charges and no criminal 
convictions. Fifteen percent had pending criminal charges, 
which of course with due process would have to play out before 
they are removed. Fifteen percent were convicted criminals, and 
5 percent had serious felonies. That is not the worst of the 
worst. That is what we should be doing oversight of.
    But since we do have the TSA here, Ms. McNeill, I want to 
ask you about this new policy that my understanding is you have 
implemented where you are--the TSA, rather, is providing 
information to ICE to assist them with the deportation effort. 
You're familiar with what I'm referring to?
    Ms. McNeill. I am.
    Mr. Goldman. Just to be clear, this was a new policy 
implemented under this administration, correct?
    Ms. McNeill. It is not new policy to share information 
between the agencies of the Department of Homeland Security. 
Past administrations have shared information.
    Mr. Goldman. No, that's not what I asked. Is it a new 
policy that the TSA sends identification information of all 
passengers to ICE so that they can check for potential 
deportation orders?
    Ms. McNeill. That is not what is occurring. We don't send 
the information to ICE. We help ICE check against information. 
Yes, absolutely, we do that, and we are supporting the mission 
of our colleagues at the Department of Homeland Security, and 
that includes enforcement of immigration laws, and----
    Mr. Goldman. Can I--just because I have a little time--can 
I ask you in--last year, Secretary Noem said that the Biden 
administration allowed immigrants who are in our country 
illegally to jet around the country without identification. Is 
that true; they had no identification, but yet they were able 
to get on an airplane?
    Ms. McNeill. I can't speak to what occurred before, you 
know, this administration took place. But as you know, we 
started enforcing REAL ID last year which was a law that was 
passed by Congress over 20 years ago. Today, people who are----
    Mr. Goldman. Just because I'm running out of time. Is it 
your view that the Biden administration said it's OK for people 
to go on airplanes without identification? I've never been on 
an airplane without identification, but was it OK in the Biden 
administration?
    Ms. McNeill. Apparently, it was allowed.
    Mr. Goldman. Apparently, because Secretary Noem said it? 
You ought to be careful what you testify to, and I yield back.
    Chairman Garbarino. The gentleman's time has expired. I now 
recognize the gentleman from Pennsylvania, Mr. Mackenzie, for 5 
minutes of questions.
    Mr. Mackenzie. Thank you, Mr. Chairman. Thank you to all 
the testifiers for being here today. Obviously, each of you 
cover very important agencies, and having you here is critical 
to the work we do at the Homeland Security Committee.
    I'm going to focus my questions to Ms. McNeill. The TSA is 
an important agency that keeps all Americans safe. First, I'd 
like to commend our local TSA agents at the A-B Lehigh Valley 
International Airport. They just went through the highest 
record and busiest year in history at the Lehigh Valley 
International Airport. Over a million passengers moved through 
successfully and faithfully, and we thank all of them for their 
work, especially during a Democrat-led shutdown where they were 
not being paid for a period of time. We thank them for their 
service and their work.
    Two things that I would like to highlight: First is ways 
that you were actually reforming the administration to move 
passengers through more quickly and improve the passenger 
experience. One of those is the Families on the Fly Initiative. 
Can you speak to that and how that program works, what you're 
doing to help families, typically with children under the age 
of 12, to not only move them through more expeditiously, but 
also speed up lines for everybody else?
    Ms. McNeill. Thank you, Congressman Mackenzie, for that 
question. Families on the Fly is an initiative--but we rolled 
out last year in support of American families traveling through 
our airports. It dedicates a lane, a specific lane for families 
that go through the checkpoint. You know, as many of us know 
when you travel with children, there's a lot of gear and 
equipment that gets brought through. So it provides a wider 
lane, easier access for families to go through and extra 
assistance to screen all of their gear that they bring through. 
It has the added benefit actually to driving down wait times in 
nonfamily lanes as well. So, you know, it's been a win-win for 
everyone. We're really happy to be able to support families 
traveling throughout our airports.
    Mr. Mackenzie. Well, thank you for that. It's an important 
improvement to making the agency--obviously, a lot people 
outside of A-B have difficult experiences with TSA. While it 
should be predominantly and primarily focused on safety and 
security, it is also a customer service-facing organization. We 
want to improve that experience. So, I think there are lots of 
great ways that we can coordinate to make sure that passengers 
have the best experience possible.
    The second thing I would like to focus on relates to the 
last administration. So, I understand you may not be in a 
position to share all the information that I'm looking for 
here. If you don't have the information, I would ask that you 
do follow up with committee with written documentation of the 
information that we do have. What it relates to is during the 
last administration, there was something that was commonly 
referred to as ghost flights where illegal immigrants in this 
country were being moved on planes across the country to 
different locations. Many times it was minors.
    The last administration then proceeded to lose thousands of 
minors that were supposed to be in their custody. When we went 
to our local airports and other airports in the region and 
asked for documentation of who was on those flights, they could 
not provide any manifest or logs of those flyers on the plane. 
We couldn't get any information on these individuals, whether 
they were here legally or in some kind of protected status. We 
couldn't get any information on who paid for those flights. 
Many of those people were in the country illegally, though, we 
know, based on some of the information that was shared publicly 
from the last administration, or they just said that it was 
people, there were minors here in the country illegally, and 
being moved to a different location. So, those individuals do 
not have proper documentation.
    So the last question I am going to ask, if people were 
being moved on flights without report identification? The 
answer is undoubtedly yes. We know that for a fact. So, my 
question to you is what information, what has this Department 
of DHS done under this administration to look into those 
transgressions that occurred in the last administration, those 
ghost flights. What can we now share with the public about what 
was going on, who was paying for them, who was on those 
flights? Again, if you don't have that information, I would ask 
that you look into it and get back to us with as much detailed 
information as possible--even if it has to be anonymized so 
that no individual information is disclosed. But that program 
and that activity is highly egregious and very concerning for 
the American people.
    Ms. McNeill. What I can say is that under no circumstances 
would that happen under this administration and the initiative 
that we have ruled out at our airports, namely, under the 
leadership of the Secretary, we have ruled out REAL ID, a law 
that was passed 20 years ago. That really does enforce identity 
verification standards at our checkpoints. I mentioned early on 
in my statement, identity verification is the cornerstone of 
our aviation security system. Knowing who is accessing our 
aircrafts is critical to our security posture. I'm happy to get 
back to you on the details of the scenario that you raised 
earlier.
    Mr. Mackenzie. Please do look into those ghost flights. 
It's something that, again, should not have been occurring, 
should not occur going forward. I know it wouldn't stand under 
this administration, but any information you can shed on what 
the last administration was doing incorrectly would be helpful 
for us going forward. Thank you, and I yield back.
    [The information follows:]

    TSA defers to DHS/ICE for a response.

    Chairman Garbarino. The gentleman yields back. I now 
recognize the gentleman from Virginia, Mr. Walkinshaw, for 5 
minutes of questions.
    Mr. Walkinshaw. Thank you, Chairman Garbarino, for 
convening today's hearing and for our witnesses for joining us. 
Last week, I visited Minnesota with 27 other Members of the 
House where we heard from community leaders and Members about 
the brutal masked secret police that had been unleashed in 
their streets. They have shackled peaceful protestors, pulled 
guns on children, dragged pregnant mothers, and as we all know 
shot an unarmed mother in the face.
    Just yesterday in Minnesota we heard from local law 
enforcement leaders that their off-duty officers, United States 
citizens, have been targeted by ICE. Had the Department honored 
the committee's request--and I appreciate the Chairman for 
making the request for Acting ICE Director Lyons to testify 
today--I and I think others would have questioned him directly 
about his role in escalating tensions by deploying thousands of 
masked immigration officers. I should say masked and minimally-
trained immigration officers in Minnesota.
    That said, I want to just discuss another one of this 
administration's failures. Last year, President Trump's DOGE 
and its chain-saw wiped out 72,000 Federal jobs just here in 
the national capital region, which includes the district and 
Virginia that I represent, including a lot of cyber 
professionals. These are patriotic Americans who chose a career 
of public service, and instead they were fired, pushed out, or 
moved to support this administration's mass deportation effort. 
That's currently, as I noted, harassing U.S. citizens, 
including law enforcement officers in Minnesota.
    CISA--as we know, is a lead agency to defend and mitigate 
against threats to our cyber and physical infrastructure--lost 
a third of its work force. One year ago at CISA, much of its 
career work force was bullied into quitting. They were 
threatened with RIFs that would not come with any severance. 
So-called probationary employees were fired. In the recent 
Government shutdown, some CISA staff even received the illegal 
RIF notices. Court after court after court has determined that 
those attempted RIFs were illegal. Others were moved to ICE or 
to CBP or told they'd be fired if they didn't accept their 
transfer orders. CISA has cut support to critical partners like 
the multi-State ISAC and the Election Infrastructure ISAC, 
while the Department has dismantled key oversight and 
prevention efforts, including eliminating the Cyber Safety 
Review Board. The leaders behind the pre-ransomware 
notification and Secure-by-Design initiatives have left.
    At a time of persistent and growing cyber threats from 
malign foreign actors, these choices by the President and the 
Secretary have weakened our defenses and left our critical 
systems and infrastructure more exposed and the American people 
more vulnerable.
    Dr. Gottumukkala, has CISA conducted an analysis to prove 
that its current staffing levels enable mission delivery? Have 
you done that analysis?
    Mr. Gottumukkala. Congressman, thank you for the question. 
Please allow me to clarify. I think capability--somehow I think 
the narrative comes across in the media as 800 people just left 
overnight. That's not the case. This is a work force transition 
program. People who participated in the program did so 
voluntarily. And----
    Mr. Walkinshaw. Yes, I don't agree with that. But just 
answer the question, please. Have you conducted an analysis to 
prove that your current staffing levels today enable you to 
accomplish your mission? Where is that analysis?
    Mr. Gottumukkala. Congressman, the work that we do is 
mission-focused, which means capability is measured by 
outcomes, not head count. And CISA remains fully operational 
from what we do from securing the Nation from----
    Mr. Walkinshaw. So you have not conducted an analysis. Is 
there an analysis you can provide to the committee to determine 
you can meet your mission with the work force you have today?
    Mr. Gottumukkala. Congressman, we support every single 
statutory authority given to us, and we support every single 
one of that for the mission.
    Mr. Walkinshaw. OK. Thank you.
    Mr. Gottumukkala. That has not been compromised by anyone.
    Mr. Walkinshaw. OK. So there is no analysis. Funding for 
the multi-State ISAC has been eliminated. I referenced it. I'm 
sure you know a lot about it. The Senate provided no-cost 
services for cash-strapped State and local governments, 
especially small local governments in rural communities who 
don't have the ability to do this on their own. Has the threat 
landscape against State and local governments diminished or 
increased over the past year? Has it gone up or down?
    Mr. Gottumukkala. Congressman, thank you for the question. 
Again, consistent with all ISACs, there is no Federal funding. 
But we do work with all the ISACs and working with the joint 
safety of the products. We deployed automatic communication for 
the joint cyber communication, joint cyber defense 
collaborative, expanding the real-time communication----
    Mr. Walkinshaw. OK.
    Mr. Gottumukkala. And----
    Mr. Walkinshaw. Thank you. You've managed to answer none of 
my questions. You haven't answered a single question, but thank 
you for coming.
    Chairman Garbarino. The gentleman yields back. I now 
recognize the gentleman from California, Mr. Fong, for 5 
minutes of questions.
    Mr. Fong. Thank you, Mr. Chair. Thank you to the panelists 
for the work that you do. I want to start with Under Secretary 
Allende. The threats our Nation faces require us to continue 
developing new technological capabilities.
    Specifically, my district is home to the Naval Air Weapons 
Station Channel 8, which supports the Navy's research, 
development, accusation, and testing, and evaluation of 
advanced weapon systems. Recently, the Department of Homeland 
Security Science and Technology Directorate in coordination 
with the U.S. Coast Guard and the Naval Warfare Center Weapons 
Division, Channel 8, tested a contactless vessel-stopping 
capability prototype that uses high-energy radio frequency to 
safely stop small, noncompliant vessels, which is an exciting 
new development. How do S&T's partnerships with key military 
bases enhance testing and development efforts?
    Mr. Allende. Thank you, Congressman, for the question. At 
S&T, we take a whole-of-component, a whole-of-DHS approach to 
understanding the needs and requirements. We take a whole-of-
Government approach to reduce duplication and create 
efficiencies. Often, some of the systems that are developed for 
other departments, including the Department of War may have a 
civilian application. Or the core technology may be 
transferable. Obviously, they're very different mission sets. 
But the technology you're referring to is very promising. We 
would like to do some continued testing on it to make sure that 
it is suitable for deployment. But it is a concern that I heard 
both in my engagements with the Coast Guard and from CBP and 
others in my trip to California this past week.
    Mr. Fong. Well, you're always welcome in California. So, 
certainly, if you're in the area, please, we would love to roll 
out the red carpet for you.
    I wonder if you describe how S&T is working with private-
sector vendors to ensure technologies being developed, 
procured, and deployed are up-to-date, incorporate the latest 
innovations, and avoid becoming obsolete before they are 
fielded.
    So what does the procurement process look like? Are there 
changes that need to be made? Certainly, as mentioned before, 
we have major special events occurring in the United States 
with the World Cup and the Olympics, and the celebration of 
America's 250th birthday. How can we facilitate the spread of 
these technologies and deploy them ahead of these events for 
any threat that exist?
    Mr. Allende. Sure. Thank you for the question. The private 
sector is able to address a number of problems that Government 
just really could not do on its own in many aspects. It's 
generally wise to look for those technologies and the 
applications that they might be suitable for. We do that soup 
to nuts at the Department. We're always looking for 
opportunities to bring in existing technologies.
    I guess my answer to you is, if there's something that can 
be applied, our preference would be to either adopt it or adapt 
it for our use, rather than going through a long research 
development time line.
    Now, in fairness, there are those areas where there is no 
private-sector market. In those instances, it's suitable for us 
to take lead on that.
    Mr. Fong. Can you expound on that? What type of 
capabilities--I mean, does a demand signal have to be provided 
for the private sector to address some of the Department needs? 
Or is it something that is solely focused within the Department 
that you just prefer to have it in house?
    Mr. Allende. I would say there's two sets of demand 
signals. There is something that private sectors develop with a 
private market in mind that might have a very good Government 
application. There is the alternative which is something that 
is a--almost uniquely Government niche that ultimately has a 
private-sector application. In those instances we'd be looking 
to do tech transfer at the earliest possible moment, and that's 
the private sector. For the components, our--you know operation 
delivery is our goal. So, by either method, we look to get out 
in the field.
    Mr. Fong. Do you have a particular time frame you would 
look at when you're trying to deploy with your processes in 
place?
    Mr. Allende. ASAP is really my preference. There is nuance 
to that, of course. You want to make sure that it is properly 
tested, evaluated, and in a position to be deployed. We have 
very smart people that get after that issue.
    Mr. Fong. Sure. Well, I know that when it comes to the 
threats that our country faces, the technology is going to be 
critically important for us to address that both from the 
private-sector side and on the research and development side. 
So, find a way we can facilitate the deployment of promising 
technologies, but please let us know. With that I yield back.
    Chairman Garbarino. The gentleman yields back. I now 
recognize the gentleman from Tennessee, Mr. Van Epps, for 5 
minutes of questions.
    Mr. Van Epps. Thank you, Mr. Chairman. Thank you to our 
witnesses for sharing with us today. This Department is tasked 
with the most sacred mission: To protect the American homeland. 
Our witnesses today represent vital aspects of that mission, 
and I'm grateful for your time.
    I'm going to build off of my colleagues' questions.
    Mr. Allende, S&T's Office of Safety Act Implementation, 
OSAI, plays an important role in mitigating litigation risks to 
incentivize the private sector to require and deploy 
antiterrorism technologies. Building off of previous questions, 
what additional resources, if any, does OSAI require in order 
to process applications for designated and certified 
antiterrorism technologies at a speed sufficiently appropriate 
to keep pace with emerging threats and technologies?
    Mr. Allende. Thank you, Congressman, for the question. I 
would like to ask for an opportunity to come back and brief you 
on this. I can tell you, we currently have a large number of 
applications pending. We've had a 50 percent increase in 
applications, which we attribute to FIFA, L.A. 2028, and 
America 250. We are working very diligently to get through 
those. I have some time actually scheduled toward the end of 
this week to see how many we can get through. But certainly, it 
is top of mind and not something that we take lightly.
    Mr. Van Epps. Great. Thank you. To what extent does OSAI 
perform evaluations of technologies that have already received 
safety act certifications or other safety act designations to 
ensure that these technologies remain effective at mitigating 
terrorist acts? Is OSAI adequately resourced to complete 
necessary reevaluation processes in a timely fashion?
    Mr. Allende. Thank you, Congressman. There are different 
sets of certifications that are offered by OSAI, and each of 
these is on a renewal review period. So, we periodically 
revisit the applications. There is a whole host of requirements 
that are part of that, including evaluations sites and so on. 
So, yes, we do try to keep with the times and the emerging 
threats if that's--I think that answers your question.
    Mr. Van Epps. Great. Thank you. Pivoting here--and this 
will be for Administrator McNeill--TSA announced at the end of 
last year that passengers who do not present a REAL ID or 
acceptable form of ID at the TSA security checkpoint would have 
to pay a $45 fee for a 10-day travel authorization under new 
program called Confirm ID which we've talked about some today.
    With the new program starting February 1, the committee has 
concerns about whether TSA holds the requisite authority to 
levy this fee and bill by the contract for an alternative 
travel authorization system. Can you please explain to the 
committee why this Confirm ID program is necessary, how this 
program does not go against TSA's goal to enforce REAL ID 
compliance, and a pulled identification security since it would 
allow individuals without proper identification to still travel 
simply by paying the fee?
    Ms. McNeill. Thank you for your question, Congressman. When 
we rolled out enforcement of REAL ID in May 2025, we saw 
approximately 93 percent compliance rate. Today, it's around 94 
percent. The Confirm ID is really meant to address the 
continuing noncompliant populations, about 6 percent of what we 
see through our airports every day. It's been 20 years since 
Congress passed this law, and, you know, for folks to show up 
with a noncompliant ID is a draw on our resources, 
operationally. So, and that cost today is borne by the 
taxpayer. So the fee is really meant to defray the cost of us 
processing people who don't show up with the acceptable form of 
ID, ensure that they do not pose a threat to our skies, and 
have the fee borne by the noncompliant population.
    Mr. Van Epps. Could you just talk a little bit about how 
TSA determined the $45 would cover the cost of the travel 
authorization for a passenger? Without an acceptable ID, I 
believe the original amount considered was $18.
    Ms. McNeill. Absolutely. So you know with any fee that we 
issue, there is a fee study that we conduct. There was a 
realization that we did not include all of the cost in the 
initial assessment. That's part of our fee revision process. 
You know, we will do so on a recurrent basis to ensure that the 
fee reflects the cost of carrying out that program.
    Mr. Van Epps. Great. Thank you. Mr. Chairman, I yield back.
    Chairman Garbarino. Thank you very much. The gentleman 
yields back. I will now entertain--and I appreciate my 
colleagues waiting for the--I will now entertain UC motions.
    Mr. Thompson. Thank you very much, Mr. Chairman. I ask 
unanimous consent to introduce into the record a staffing chart 
provided by CISA that shows 65 employees have been transferred 
out of CISA in management-directed reassignments since January 
20, 2025--and that CISA has lost 998 employees since January 
20, 2025. Nearly one-third of its total personnel.
    Further, I ask unanimous consent to include in the record 2 
articles describing how TSA and CISA are contributing to ICE's 
deportation push on behalf of Mrs. Ramirez.
    [The information follows:]
    
[GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT]
    

    Chairman Garbarino. Without objection. Well, I want to 
thank you all, the witnesses, for being here today. One of the 
main things we do here is oversight, and this was the first of 
many hearings. You all run very important departments under the 
Department of Homeland Security. I appreciate your willingness 
and your time coming here today. The Members of the committee 
may have some additional questions--I know I do--and we would 
ask that all the witnesses respond to these in writing.
    Pursuant to committee Rule VII(E), the hearing record will 
be held open for 10 days. Without objection, this committee 
stands adjourned.
    [Whereupon, at 12:45 p.m., the committee was adjourned.]



                           A P P E N D I X  I

                              ----------                              

    Questions From Chairman Andrew R. Garbarino For Pedro M. Allende
    Question 1. Under Secretary Allende, starting with this year's FIFA 
World Cup, our Nation is entering into an unprecedented period of 
hosting major international sporting events. How is S&T leveraging its 
programs, including the Program Executive Office within S&T you 
mentioned during the hearing, to provide C-UAS support to Federal, 
State, local, Tribal, and territorial (SLTT) law enforcement entities 
ahead of these events, and how is S&T collaborating with other DHS 
components in providing this assistance?
    Answer. The new Program Executive Office (PEO) for Unmanned 
Aircraft Systems (UAS) and Counter-UAS (C-UAS) in U.S. Department of 
Homeland Security's (DHS) Science and Technology Directorate (S&T) 
announced by Secretary Noem on January 12, 2026, consolidates all 
supporting UAS and C-UAS activities across the Department, to include 
systems acquisition, research and development, and air space 
integration. The PEO will help streamline the Department's exercise of 
its 
C-UAS authorities and enhance coordination with interagency partners, 
as well as State, local, Tribal, and territorial (SLTT) law 
enforcement--especially for significant events such as the World Cup 
and America 250 celebrations. S&T C-UAS subject-matter experts helped 
review submissions from SLTT partners related to the Federal Emergency 
Management Agency's C-UAS Grant Program. S&T engineers and research 
specialists are also conducting site surveys at World Cup stadium 
locations in partnership with SLTT entities to ensure each site 
receives adequate 
C-UAS equipment and resources. Broadly, the new PEO will address 
existing gaps and future challenges by centralizing acquisition 
decision making and investment oversight. The Program Executive Office 
will also collaborate with the U.S. Departments of Justice, 
Transportation, and War, including Joint Interagency Task Force 401 and 
other relevant organizations, to synergize acquisition, research and 
development, and testing and evaluation activities and reduce 
duplication of efforts in the homeland. These changes are fully aligned 
with the President's direction to restore air sovereignty over the 
United States (Executive Order 14305: Restoring American Airspace 
Sovereignty) and secure our Nation's borders (Executive Order 14165: 
Securing Our Borders; Presidential Proclamation 10886: Declaring a 
National Emergency at the Southern Border of the United States).
    Question 2a. Under Secretary Allende, a report by the Government 
Accountability Office (GAO) from October 2024 found that DHS S&T could 
amend its policies to prevent potential unnecessary research and 
development overlap among its Federally-funded research and development 
centers (FFRDCs).
    S&T's Program Management Office (PMO) has a role in overseeing the 
performance of DHS's FFRDCs and ensuring that research and development 
activities performed by these FFRDCs do not overlap between each other 
and with the research and development activities of DHS components. How 
effective has S&T's PMO office been in performing this work and what 
challenges remain?
    Answer. DHS remains committed to streamlining task oversight across 
the Department by centralizing review of analytic research activities, 
strengthening documentation requirements, and enhancing enterprise-wide 
visibility to prevent duplication of research and development (R&D). We 
are also improving collaboration across components to ensure our 
investments are aligned, complementary, and directly tied to 
operational mission needs.
    S&T's Program Management Office (PMO) has enhanced its oversight by 
implementing structured portfolio reviews, standardized task order 
approval processes, and cross-component coordination mechanisms. These 
steps have strengthened our ability to detect and prevent potential 
overlap. Establishing a more comprehensive quarterly and annual 
Federally-funded research and development centers (FFRDC) performance 
review will also enhance oversight, support reducing potential overlap, 
and will also support potential reuse of solutions across DHS. The 
integration of planning cycles across components remains an area of on-
going focus, and we are committed to continuous improvement.
    Question 2b. How does the work completed by DHS's FFRDCs align with 
Departmental priorities, and how is S&T and its PMO working to 
integrate research performed by FFRDCs into DHS's current strategic 
focus?
    Answer. FFRDC projects are mapped to DHS strategic priorities, 
including border security, Counter-UAS, biosecurity and protection of 
critical infrastructure. The PMO ensures that work performed supports 
validated mission gaps identified and approved by operational 
components. The PMO supports the components in ensuring that the work 
is efficiently transitioned to support and effectively impact mission 
operations.
    Questions From Honorable Timothy M. Kennedy for Pedro M. Allende
    Question 1. Under Secretary Allende, DHS's fiscal year 2026 funding 
bill, if enacted, would move a significant portion of the Countering 
Weapons of Mass Destruction office's mission into your directorate. 
Specifically, it transfers funding for ``Mission Support for Research 
and Development,'' ``Transformational Research and Development,'' 
``Technical Forensics,'' and ``Detection Capability Development.'' How 
do you plan to integrate these operational and support functions into 
your existing research and development structure without losing the 
specialized expertise required for WMD threat detection?
    Answer. The S&T team has already engaged with the DHS Countering 
Weapons of Mass Destruction (CWMD) team to understand their R&D 
portfolio and activities. This exercise will allow us to better 
collaborate as a single or separate organizations within DHS. S&T will 
accept the transfer of these CWMD programs and specialized staff, 
ensure their continued operations, and then evaluate program 
performance, impact, and outcome to inform the fiscal year 2027 and 
out-year budgeting requirements. S&T will enable the programs to 
continue to meet the mission and the Congressional direction for these 
departmental capabilities.
    Question 2a. As Ranking Member of the Subcommittee on Emergency 
Management and Technology, I was troubled by the reports stating that 
the Trump administration had made the reckless decision to terminate 
funding for S&T's Centers of Excellence. These Centers are unique and 
essential partnerships between academic institutions, the private 
sector, homeland security agencies, and other partners who work 
together to produce groundbreaking research that helps keep our Nation 
safe now and in the future. For example, one of these Centers focused 
on enhancing critical infrastructure security to protect our Nation 
against a variety of threats, from natural disasters to attacks by 
hostile entities. How many of the 9 Centers of Excellence are currently 
operational?
    Answer. Although I disagree with your assertion that assessing and 
deciding to terminate Centers of Excellence (COE's) was reckless, I 
recognize and appreciate the relationships the DHS COE's have forged 
with DHS components and the broader Homeland Security Enterprise. On 
April 24, 2025, DHS reinstated the cooperative agreements for 2 DHS 
COE's:
   National Counterterrorism Innovation, Technology, and 
        Education Center, led by University of Nebraska Omaha.
   Arctic Domain Awareness Center--Addressing Rapid Changes 
        Through Technology Innovation and Collaboration.
    The expertise and capabilities afforded through the other 6 Centers 
that DHS was funding through cooperative agreements remain available 
via utilization of their Basic Ordering Agreement. This task order 
vehicle is a funding mechanism through which Government agencies can 
directly contract with an emeritus COE, providing streamlined access to 
leading researchers. Additionally, projects conducted using a Basic 
Ordering Agreement are directly for the benefit of the Government. The 
Department is considering the future of the Cross-Border Threat 
Screening and Supply Chain Defense COE as it relates to Department and 
administration priorities.
    Question 2b. If Congress provides funding to keep all 9 of S&T's 
Centers of Excellence fully staffed and operational, will you commit to 
respecting the will of this body by using that funding to keep these 
Centers open?
    Answer. I commit to working with you and the committee to align 
Congressional appropriations and intent for COE's with administration 
priorities. DHS recognizes the value of its partnerships between 
academic institutions, the private sector, and homeland security 
agencies across the Homeland Security Enterprise. We will continue to 
assess pathways for establishing these partnerships in alignment with 
administration priorities, including through university-led DHS COE's.
    Question 3a. For years, S&T has partnered with Minority-Serving 
Institutions, such as Historically Black Colleges and Universities, to 
expand the agency's talent pipeline and broaden its research base. 
Among other benefits, these partnerships helped DHS address persistent 
staffing shortages by producing qualified graduates who were familiar 
with DHS mission areas, and who otherwise might not have pursued a 
career in homeland security.
    Last April, S&T reportedly ended all of its partnerships with 
Minority-Serving Institutions. Among other impacts, this pulled the rug 
out from students who thought they could count on Federal funding to 
help attain their degrees.
    What specific deficiencies did S&T identify in its partnerships 
with Minority-Serving Institutions that justified ending all of these 
partnerships rather than addressing individual issues?
    Answer. S&T conducted a comprehensive review of its grants and 
cooperative agreements, with special attention given to alignment with 
new Departmental directives. Consistent with the administration's 
direction to uniformly implement funding restrictions and maintain 
fiscal discipline, continued funding of these cooperative agreements 
risked potential misalignment with current strategic priorities and 
conflicted with newly-issued Departmental guidance.
    Question 3b. Does S&T believe it is appropriate for the Federal 
Government to abruptly withdraw promised support from students who 
relied on these programs to complete their degree programs, and who 
want to support our Nation's homeland security posture?
    Answer. I do not agree with the premise of your question. S&T is 
tasked with a number of competing responsibilities relating to 
research, educational support, and general financial stewardship. In 
this instance, it was not possible to avoid the effect discontinuing 
all grants and cooperative agreements had on individual students. S&T 
Directorate continues to meet its mandate in the Homeland Security Act 
of 2002 for the Under Secretary for Science and Technology to support 
United States leadership in science and technology. Part of this 
includes funding internships and fellowships geared toward building the 
future homeland security science and engineering workforce. In 
addition, we continue to support graduate and undergraduate students 
engaged in homeland security research and development through our 
current DHS COE's.
    Question 3c. If evidence shows that ending these partnerships has 
harmed DHS workforce readiness or its homeland security research base, 
is S&T prepared to reinstate these programs?
    Answer. S&T continually examines the efficiency and effectiveness 
of its investments, including those that contribute to workforce 
readiness and homeland security research capabilities. Future 
investment decisions will be determined by those parameters and 
strategic alignment with the administration's priorities to ensure that 
we remain good stewards of taxpayer dollars.
    Question 4. When DHS was established, S&T played a critical role in 
developing technology to harden our critical infrastructure--making it 
safer for Americans to fly and take public transportation. Back then 
S&T worked closely with Department of Energy labs, as contemplated in 
the Homeland Security Act. Unfortunately, in recent years, with 
reductions to S&T budget, that relationship has eroded.
    As you think about the challenges that you intend to tackle, where 
do you see opportunities to reinvigorate the partnership with DOE labs?
    Answer. DHS maintains a strong and collaborative partnership with 
our colleagues at the U.S. Department of Energy (DOE), specifically 
within S&T. S&T continues to play a critical role in developing 
technology to harden our critical infrastructure in partnership with 
the DOE's National Laboratories as envisioned in the Homeland Security 
Act. This partnership, originally established in the Homeland Security 
Act, recognized the essential role of DOE labs in supporting DHS's 
mission. Over time, this relationship has evolved and been formalized 
through a Memorandum of Understanding between DHS and DOE, ensuring 
streamlined collaboration and access to world-class scientific 
resources. In the face of DOE National Lab realignment and mission re-
focus on energy dominance, our collaboration with the DOE National Labs 
remains strong and continues to be a cornerstone of our efforts to 
advance homeland security research and technology. Through on-going 
coordination facilitated by our Office of National Laboratories, we 
have maintained robust engagement, streamlined access, and aligned 
projects with DHS mission priorities. As we look ahead to new 
challenges, there are numerous opportunities to expand our partnership 
with DOE National Labs--leveraging their world-class expertise, 
infrastructure, and innovative capabilities to deliver transformative 
solutions for homeland security. Our sustained collaboration positions 
us well to address emerging threats and enhance the safety and security 
of the American public. In both fiscal year 2023 and fiscal year 2024, 
DHS funded roughly 240 projects at the DOE National Labs. In fiscal 
year 2024 alone, nearly $390 million was expended by DHS to leverage 
DOE National Lab capabilities and support our mission.
   Questions From Chairman Andrew R. Garbarino for Madhu Gottumukkala
    Question 1. As the Sector Risk Management Agency for the 
communications sector, CISA has responsibility for helping secure 
infrastructure that nearly every other critical infrastructure sector 
depends on, including energy, financial services, emergency response, 
health care, and transportation. Recent nation-state cyber activity has 
made clear that U.S. telecommunications networks are increasingly 
viewed by sophisticated adversaries as high-value strategic targets. 
Campaigns attributed to PRC-linked actors, such as Salt Typhoon, have 
underscored both the scale of the risk and the potential cascading 
consequences of disruption in this sector.
    Please describe in detail how CISA is currently engaging with 
telecommunications providers and other relevant public and private-
sector stakeholders to strengthen the security and resilience of the 
communications sector and to mitigate threats posed by cyber actors 
affiliated with the PRC. In your response, identify specific programs, 
operational activities, and coordination mechanisms CISA is using for 
information sharing, threat detection, incident response, and 
continuity and resilience planning. Please also explain how these 
efforts are designed to reduce the likelihood, severity, and duration 
of service disruptions and to ensure continuity of operations for the 
critical infrastructure sectors that rely on U.S. communications 
networks.
    Answer. The Cybersecurity and Infrastructure Security Agency (CISA) 
engages with telecommunications providers and other stakeholders to 
strengthen the security and resilience of the communications sector and 
mitigate threats posed by People's Republic of China-affiliated (PRC) 
cyber actors. These activities include continuity planning, information 
sharing, guidance, and incident handling.
    One of CISA's joint planning efforts focuses on hardening 
telecommunications infrastructure against nation-state threats. It 
enhances the cybersecurity and resilience of the telecommunications 
sector by improving providers' ability to operate through compromise 
and recover quickly. Activities include routine threat exchanges and 
briefings for telecom executives, tabletop exercises simulating PRC-
linked campaigns, and technical hardening guidance to reduce 
vulnerabilities and improve redundancy. Additional measures involve 
sector-wide risk modeling to assess cascading impacts on critical 
sectors such as energy, health care, and transportation, developing 
incident response playbooks, and creating continuity of operations 
templates to ensure essential services remain available during 
prolonged disruptions.
    CISA also leans into information sharing with Government and 
industry partners, including the Communications Information Sharing and 
Analysis Center. These partnerships help accelerate CISA and the 
sector's response to cyber incidents.
    Question 2. The Cyber Incident Reporting for Critical 
Infrastructure Act (CIRCIA) was signed into law nearly 4 years ago, and 
Congress directed CISA to finalize implementing regulations by October 
2025. That deadline has now slipped to May 2026. The justification 
given by the agency includes a need to better incorporate industry 
feedback and streamline the proposed rule to avoid undue burden.
    Please explain in detail how CISA is using this additional time to 
align the final rule with Congressional intent, including which 
elements of the proposed regulation are being revised to reduce 
overreach, clarify scope, and ensure the final rule reflects a 
practical, risk-based approach for covered entities.
    Answer. CISA received many written comments and requests from 
entities in critical infrastructure sectors and other stakeholders to 
directly engage CISA further on the Cyber Incident Reporting for 
Critical Infrastructure Act (CIRCIA) rulemaking. CISA appreciates 
stakeholders' interest and concern that CISA implement CIRCIA to 
maximize its positive impact on improving the Nation's cybersecurity 
posture while minimizing unnecessary burden.
    Given the broad stakeholder community that CIRCIA may potentially 
impact and significant passage of time (including due to a prolonged 
lapse in DHS funding) since publication of the notice of proposed 
rulemaking in April 2024, CISA will conduct a series of town hall 
meetings to solicit additional input on the notice of proposed 
rulemaking (NPRM). At the conclusion of the town hall meeting process, 
CISA will evaluate the feedback and determine the most appropriate next 
step for the CIRCIA rulemaking.
    Question 3. Much of the public and Congressional attention in 
recent years has understandably focused on cyber activity attributed to 
the People's Republic of China, particularly given the scope, 
persistence, and strategic nature of those operations against U.S. 
critical infrastructure and government systems. At the same time, other 
nation-state actors continue to pose serious, and in some cases, more 
immediate cyber risks to the homeland, even if they receive less 
sustained attention in public reporting or policy debates.
    Please explain how CISA assesses and prioritizes the cyber threats 
posed by Russia, Iran, and North Korea relative to the PRC. In your 
response, describe how differences in these actors' capabilities, 
objectives, and operational patterns are reflected in CISA's analytic, 
operational, and resource allocation decisions.
    Answer. CISA assesses and prioritizes cyber threats by evaluating 
each actor's capabilities, objectives, and operational patterns, 
focusing on potential severity and impact to the homeland. The PRC is 
the highest-priority threat due to the scale, sophistication, and 
persistence of its malicious cyber activity. CISA continues to closely 
monitor activity from Russia, Iran, and North Korea, especially focused 
on their collective potential to cause disruption or harm. CISA views 
Russia as a highly capable and historically aggressive actor, willing 
to conduct disruptive operations; this leads to focused analysis on 
Russian tools and targeting, joint advisories with partners, and 
concentrated support to sectors most vulnerable to disruptive Russian 
activity. Iranian cyber operations are often retaliatory or regionally 
focused but have demonstrated disruptive potential, prompting CISA to 
monitor targeting shifts tied to geopolitical developments and issue 
tailored guidance to likely targets. North Korea activity is primarily 
financially-motivated cryptocurrency theft, financial fraud, and 
ransomware. In response, CISA focuses its analytical and operational 
support towards the financial services sector and organizations at risk 
from ransomware. These differing profiles directly shape CISA's 
analytic priorities, operational planning, and allocation of limited 
resources across the threat landscape.
    Question 4a. Russia has long demonstrated a willingness to use 
cyber operations as a tool of state power, including disruptive attacks 
against energy systems, government services, and civilian 
infrastructure across Europe. Russia's on-going war against Ukraine has 
provided clear examples of how cyber operations are used alongside 
military activity to degrade civilian services, disrupt energy and 
communications systems, and shape the operating environment during 
conflict. These campaigns suggest that Russia treats cyber operations 
not merely as espionage tools, but as instruments of coercion and 
operational disruption.
    Please confirm whether CISA is examining or evaluating Russian 
cyber operations related to the war in Ukraine and, if so, explain in 
detail how CISA collects and analyzes technical and operational data 
from those campaigns and how that information is being used to inform 
risk assessments and defensive measures for U.S. critical 
infrastructure.
    Answer. CISA monitors malicious Russian cyber activity available 
through Classified sources, industry and international partners, 
cybersecurity vendors, and open-source reports, especially as it 
relates to critical infrastructure and government networks. CISA 
actively analyzes this data to identify relevant threats and 
operational patterns, and shares resulting synthesized insights with 
Government and industry partners when applicable to inform risk 
assessments and defensive measures.
    Question 4b. Please explain how those lessons are being translated 
into concrete guidance, preparedness activities, and operational 
support for U.S. infrastructure owners and operators.
    Answer. CISA issues timely advisories, technical alerts, and best 
practices based on threat actor activity. We support readiness by 
executing exercises, conducting cybersecurity assessments, and sharing 
real-time threat intelligence. These actions equip U.S. Government and 
critical infrastructure partners to defend against similar disruptive 
cyber tactics.
    Question 5a. North Korea presents a different but no less serious 
cyber challenge from the PRC and Russia, particularly through 
financially-motivated operations tied directly to regime survival. In 
addition to well-documented cryptocurrency theft, ransomware activity, 
and exploitation of financial systems, there are increasing reports 
that North Korea is placing or attempting to place IT workers inside 
U.S. and European companies under false identities. These individuals 
may gain legitimate access to corporate networks, generate revenue that 
flows back to the regime, and create opportunities for follow-on cyber 
activity, intellectual property theft, or insider-enabled attacks.
    Please describe how CISA is assessing and addressing the threat 
posed by North Korean cyber activity, including the placement of North 
Korean IT workers inside Western companies. In your response, explain 
how CISA works with other Federal agencies and the private sector to 
help organizations identify, prevent, and respond to this activity.
    Answer. CISA assesses and addresses the threat posed by North 
Korean cyber activity by monitoring their tactics and in collaboration 
with Government and industry partners, takes appropriate actions to 
include information sharing, alerts, and guidance. Together, these 
efforts help organizations identify, prevent, and respond to observed 
threat activity.
    Question 5b. From CISA's perspective, how significant is this 
threat to U.S. companies and critical infrastructure, particularly 
given the potential for revenues to flow back to the North Korean 
regime and support its weapons programs?
    Answer. CISA observes that North Korea cyber activity primarily 
focuses on revenue generation, targeting organizations that offer the 
greatest return on investment. North Korea actors often pursue easier 
targets rather than highly secured networks. Implementation of basic 
and foundational cyber defense and hygiene measures is the greatest 
defense to protect U.S. companies and critical infrastructure. We 
actively monitor threat reporting for evolving tactics; however, robust 
cybersecurity fundamentals remain currently effective in mitigating 
this threat.
    Question 6a. In December, CISA released a new report titled Venue 
Guide for Mitigating Dependency Disruptions to help stadiums and arenas 
strengthen resilience ahead of major events such as the 2026 FIFA World 
Cup, America 250, and the 2028 Summer Olympics. The guide focuses on 
lifeline dependencies, including energy, communications, water, and 
transportation, and how disruptions to those systems could affect 
public safety at large gathering venues. At the same time, we are 
seeing growing concern about the use of unmanned aircraft systems, 
including drones, as a means to disrupt venue operations or exploit 
dependencies on critical lifeline services during high-profile events.
    Please describe CISA's current assessment of the evolving drone 
threat to stadiums, arenas, and other public gathering venues.
    Answer. Threats posed by unmanned aircraft systems (UAS) to 
stadiums, arenas, and other public gathering venues are evolving as 
commercial UAS platforms become more widely accessible and technically 
capable, raising the potential for both negligent and intentional 
misuse that could disrupt safety, operations, or critical dependencies 
at high-profile events. The 2025 DHS Homeland Threat Assessment 
underscores that UAS activity over sensitive critical infrastructure 
and large public venues remains a significant risk, with the potential 
to disrupt facility operations, impede emergency response, and enable 
intelligence collection by malign actors.\1\ Further compounding the 
challenge, small UAS platforms are increasingly capable of carrying 
larger, more sophisticated payloads, conducting surveillance, and 
undermining critical lifeline services. Even non-malicious or reckless 
activity can trigger serious safety, security, and operational 
consequences, including flight disruptions, crowd safety hazards, and 
delays in emergency response. High-profile events such as the 2026 FIFA 
World Cup, America 250 celebrations, and the 2028 Summer Olympics 
present attractive targets, as demonstrated by the interception of 53 
unauthorized drones during the 2024 Paris Olympics.\2\
---------------------------------------------------------------------------
    \1\ Department of Homeland Security, 2025 Homeland Threat 
Assessment, 2025, dhs.gov/publication/homeland-threat-assessment.
    \2\ Elaine Cobbe, CBS News. ``2024 Paris Olympics security 
challenges include 53 intercepted drones and 5,000 people barred from 
the Games,'' August 1, 2024, cbsnews.com/news/2024-paris-olympics-
security-drones-intercepted-5000-people-barred-from-games/.
---------------------------------------------------------------------------
    Question 6b. Please explain how CISA is incorporating drone-related 
risks into its guidance, planning, and engagement with venue owners, 
operators, and State and local partners, including how these risks are 
factored into dependency mapping, vulnerability assessments, and event 
preparedness.
    Answer. CISA integrates UAS risk considerations into its efforts to 
strengthen stakeholder capabilities, recognizing these threats as an 
escalating concern that requires proactive planning, coordination, and 
layered security measures to protect public venues and the critical 
services they depend on, and incorporates these considerations across 
our guidance, planning, and engagement activities:
   Guidance.--Includes specialized resources with UAS-focused 
        content to raise awareness and provide risk mitigation 
        recommendations, through our Be Air AwareTM website 
        that equips organizations with information and recommendations 
        to advance UAS risk management and increase security and 
        resilience against UAS threats, including:
     Unmanned Aircraft System Detection Technology Guidance for 
            Critical Infrastructure provides critical infrastructure 
            owners and operators with key considerations for how to 
            select and leverage detection technology to increase 
            awareness of UAS activity over a facility or site.
     Safe Handling Considerations for Downed Unmanned Aircraft 
            Systems provides information on how to prepare for and 
            respond to downed UAS that may pose a safety or security 
            concern.
     Suspicious Unmanned Aircraft System Activity Guidance for 
            Critical Infrastructure Owners and Operators offers 
            criteria for recognizing suspicious UAS activity and 
            recommendations for responding appropriately.
     Suspicious UAS Identification Poster and Postcard are 
            quick-reference visual guides that help security personnel 
            and the public recognize indicators of potentially 
            suspicious drones, outlining warning signs, and 
            recommending safety actions such as treating grounded UAS 
            as potential explosive threats and reporting incidents to 
            law enforcement.
     Interagency Security Committee Best Practices for 
            Protecting Against the Threat of UAS provides Federal 
            facility security professionals and critical infrastructure 
            stakeholders with guidance on UAS threats, offering 
            strategies for vulnerability assessments, protective 
            measures, workforce awareness, and response planning to 
            mitigate malicious drone activity.
   Planning.--Addresses UAS risks through coordinated air space 
        security measures and preparedness exercises. These activities 
        help stakeholders understand the potential impacts of UAS 
        incidents and strengthen operational readiness for major 
        events.
     In fiscal year 2025, 224 temporary flight restrictions 
            were coordinated with the FAA to secure air space for 
            special events, helping minimize risks from unauthorized 
            UAS operations and deter activity that could lead to 
            security incidents.
     CISA Tabletop Exercise Packages regularly include UAS 
            scenarios and outline potential consequences--such as 
            disruptions to nearby infrastructure--providing a self-
            service tool for stakeholders to examine plans and 
            procedures, and CISA complements this by conducting 
            facilitated, full-scale exercises with partners to 
            strengthen preparedness and coordination.
   Engagement.--Focuses on training, dependency and 
        vulnerability analysis, and interagency coordination to 
        strengthen Federal, State, local, Tribal, territorial, and 
        critical infrastructure partner readiness and mitigate UAS 
        risks.
     In fiscal year 2025, more than 370 infrastructure 
            assessments incorporate UAS risk considerations to help 
            venues identify dependencies and reduce potential 
            disruptions.
     Accredited counter-improvised explosive device and risk 
            mitigation training builds stakeholder capabilities to 
            address weaponized UAS tactics and enhance protective 
            measures.
     Information sharing and technical assistance improve 
            situational awareness and support timely, coordinated 
            responses to emerging UAS threats.
     Regional security advisors actively engage with and 
            support local stakeholders by raising awareness and 
            connecting them with available CISA UAS resources that 
            support effective planning and coordination.
    Question 7. CISA plays an important role in defending Federal 
civilian networks, including through capabilities such as Continuous 
Diagnostics and Mitigation (CDM) and broader Federal threat detection 
and response efforts. As nation-state cyber activity becomes more 
persistent and sophisticated, the effectiveness of these programs is 
critical to preventing intrusions from becoming large-scale incidents. 
At the same time, both defenders and adversaries are increasingly using 
AI and automated tools to accelerate detection, analysis, and 
exploitation, raising important questions about how Federal cyber 
defense capabilities are evolving to keep pace.
    Please describe CISA's current assessment of Federal civilian 
network visibility and response capabilities, including how automation 
and AI-enabled tools are being integrated into detection, analysis, and 
mitigation activities.
    Answer. CISA continues to make investments to increase visibility 
throughout Federal agency networks via the Continuous Diagnostics and 
Mitigation (CDM) program, cyber shared services, and on-going 
coordination with agencies. Through CDM, CISA has improved asset 
visibility across newer asset classes, including mobile devices, cloud 
services, and internet of things/operational technology devices. These 
efforts are expanding CISA's operational visibility. Additionally, CISA 
is expanding network-level visibility through new CDM capabilities such 
as advanced network protection and security information and event 
management as a service. For those agencies that are in the process of 
adopting newer capabilities, CISA's operational visibility is 
substantially improved. The Federal Government's investments in 
endpoint detection and response capabilities further improve network 
visibility by complementing CDM asset management and network security 
management capabilities. Specifically, the use of endpoint detection 
and response and enrollment of agencies within CISA's persistent access 
capability result in significantly improved detection by adding near 
real-time and detailed, host-level asset and activity visibility.
    Additionally, the operationalization of endpoint detection and 
response and CISA's persistent access capability has greatly improved 
CISA's response capabilities. For those agencies enrolled, CISA can 
collaborate in real time with agency security operations centers to 
investigate and action against threats that span agency boundaries or 
utilize techniques for which there are no known indicators. When 
conducting advanced investigations and incident response, utilizing 
persistent access capability reduces CISA's time to engage with 
agencies from days to minutes. It eliminates the logistical challenges 
and delays associated with traditional on-premises response, allowing 
analysts in CISA to work directly with agencies virtually.
    All these visibility and response capabilities utilize commercial 
off-the-shelf tools, many of which are incorporating artificial 
intelligence-assisted capabilities into their standard commercial 
platforms. This approach has resulted in better correlation of 
seemingly unrelated data points that assist in detection, more 
effective elimination of false positives, and reduction of manual labor 
required when performing detailed analysis.
    Question 8. For many years, the Critical Infrastructure Partnership 
Advisory Council, or CIPAC, provided a formal, legally-supported 
framework that enabled sustained and structured engagement between the 
Federal Government and private-sector owners and operators of critical 
infrastructure. Since its discontinuation, a number of stakeholders 
have expressed uncertainty about how best to coordinate planning 
efforts, share sensitive but unclassified information, and maintain 
consistent and reliable engagement with the Department on risk 
management and incident preparedness. Recent public reporting indicates 
that the Department is finalizing a new engagement construct referred 
to as ANCHOR that is intended to address these gaps.
    Can you describe in detail where DHS is in the process of 
finalizing and implementing ANCHOR, how the construct is expected to 
operate in practice across sectors, and how this new model will provide 
the clarity, predictability, and collaboration that private-sector 
partners need to manage cyber and infrastructure risk alongside the 
Federal Government?
    Answer. The U.S. Department of Homeland is working to implement a 
new partnership framework, and we look forward to sharing additional 
details as soon as we can. Rapidly-evolving cyber threats demand a new 
level of partnership between Government and industry--one that goes 
beyond exchanging data to true actionable collaboration. Looking ahead, 
we need to continue to shift from transactional sharing to true 
actionable collaboration. In today's environment we know that sharing 
information alone isn't enough; we need joint action and shared 
responsibility.
    Question 9. CISA is often called upon to provide surge support 
during major cyber incidents affecting Federal agencies, State and 
local governments, or critical infrastructure operators. Maintaining 
that response capacity during periods of workforce transition and 
elevated threat is essential to the agency's credibility and 
effectiveness.
    Please explain how CISA is ensuring it retains sufficient incident 
response and surge capacity to respond to major cyber events, including 
what steps are being taken to sustain operations if multiple 
significant incidents occur simultaneously.
    Answer. CISA prioritizes the most critical operations--those that 
protect national security, critical infrastructure, and mission-
essential systems. Prioritizing incident response and threat-hunting 
efforts along those lines enables rapid response to high-risk 
incidents, optimizes limited resources, and aligns efforts with 
strategic objectives. This ensures we aren't only reactive, but also 
take a proactive and prioritized approach, making the most efficient 
use of our resources to safeguard Federal networks and those of 
critical infrastructure operators.
    Currently, CISA's support in protecting and remediating the 
networks of Federal agencies and critical infrastructure owners and 
operators is based around the ability to support multiple on-going 
engagements with compromised entities at one time. In the event of an 
exigent major cyber event, CISA prioritizes finite resources towards 
threats assessed to be more significant to national security. 
Additionally, CISA leverages trusted partnerships with Federal and 
private stakeholders when appropriate to assist entities affected by 
significant cyber events.
    Question 10. CISA has emphasized Secure-by-Design principles as a 
way to encourage stronger security practices by technology 
manufacturers and reduce the burden placed on end-users. This approach 
reflects a longer-term effort to improve the security of products 
before they are widely deployed.
    Please describe the progress CISA has made in advancing Secure-by-
Design principles and explain how the agency is working with industry 
to translate these principles into measurable improvements in product 
security.
    Answer. CISA continues to advance Secure-by-Design principles by 
publishing relevant, actionable guidance on topics such as modernizing 
the common baseline of software bills of materials, a key for supply 
chain risk management;\3\ how to improve authentication practices by 
critical infrastructure providers; working with the open-source 
software community to support secure development of the software that 
underlies the software products that Americans rely on;\4\ how to 
securely develop artificial intelligence software systems;\5\ and how 
organizations can acquire software that is secure by design.\6\ CISA is 
also measuring the effectiveness of the Secure-by-Design Pledge through 
the voluntary progress reports provided by pledge signers. A 
vulnerability management community such that consumers and operators 
know when there are vulnerabilities in their software continues to be a 
focus.\7\ Also, collaborating with international partners towards 
harmonization of Secure-by-Design expectations, as represented by the 
international partner co-seal endorsement on CISA's Secure-by-Design 
publications referenced above.
---------------------------------------------------------------------------
    \3\ Department of Homeland Security. Request for Comment on 2025 
Minimum Elements for a Software Bill of Materials. Aug 22, 2025. 
Federal Register Notice 90 FR 41094.
    \4\ CISA. Open Source Security. https://www.cisa.gov/opensource.
    \5\ CISA and NCSC-UK. Guidelines for secure AI system development. 
Nov 27, 2023.
    \6\ CISA. Secure by Demand Guide: How Software Customers Can Drive 
a Secure Technology Ecosystem. 2025. https://www.cisa.gov/resources-
tools/resources/secure-demand-guide.
    \7\ See for example the continued operational work in support of 
BOD 22-01: Reducing the Significant Risk of Known Exploited 
Vulnerabilities, CISA's coordinated vulnerability disclosure program, 
and the CISA ``Vulnrichment'' project (which supplies information about 
vulnerabilities to Federal agencies and the public to support risk-
informed cybersecurity decision making).
---------------------------------------------------------------------------
    CISA is working with industry to translate principles into 
measurable improvements by holding regular sessions of the Technical 
Exchange Group for industry pledge signers to learn from one another 
through voluntary presentations on pledge goal progress. Additionally, 
CISA directed all devices on Federal information networks to receive 
supported security updates.\8\
---------------------------------------------------------------------------
    \8\ CISA. BOD 26-02: Mitigating Risk From End-of-Support Edge 
Devices. Feb 5, 2026.
---------------------------------------------------------------------------
    Question 11. Artificial intelligence is increasingly shaping both 
offensive and defensive cyber operations. While adversaries are already 
leveraging AI to scale attacks, these tools also offer opportunities to 
improve detection, analysis, and response.
    Please describe how CISA is currently incorporating AI into its 
operations and identify which applications show the greatest promise 
for improving detection, analysis, and response across Federal networks 
and critical infrastructure.
    Answer. CISA regularly evaluates tools for their potential to 
improve automation for CISA's mission. For example, CISA published the 
results of our Pilot for Artificial Intelligence Enabled Vulnerability 
Detection.\9\ Following Departmental guidance, CISA publishes an 
inventory of all the Artificial Intelligence use cases we currently 
deploy or plan to deploy for our mission: https://www.cisa.gov/ai/cisa-
use-cases.
---------------------------------------------------------------------------
    \9\ CISA. Pilot for Artificial Intelligence Enabled Vulnerability 
Detection. July 29, 2024. https://www.cisa.gov/resources-tools/
resources/pilot-artificial-intelligence-enabled-vulnerability-detection
---------------------------------------------------------------------------
    Often, CISA finds that the best defenses against AI-enabled cyber 
incidents address weak or vulnerable points in the information system 
infrastructure through cybersecurity best practices. This includes more 
thorough application of existing guidance such as adhering to Secure-
by-Design principles (described in Question 10), patching known 
exploited vulnerabilities, following CISA's cybersecurity performance 
goals, publishing an organizational vulnerability disclosure policy, 
using phishing-resistant multi-factor authentication, and practicing or 
exercising incident response and recovery.
    Question 12. While large-scale quantum computing threats may still 
be years away, the transition to post-quantum cryptography will require 
early planning and coordination across Government and industry.
    Please describe how CISA is assisting Federal agencies and critical 
infrastructure operators in preparing for this transition, including 
what actions are being taken now to ensure systems can migrate securely 
to post-quantum standards.
    Answer. CISA recognizes the threat that cryptographically-relevant 
quantum computers pose to traditional encryption and is taking 
proactive measures to prepare Federal agencies, State, local, Tribal, 
and territorial governments, and critical infrastructure owners and 
operators for a secure migration to quantum-resistant systems.
    CISA helps raise awareness about the quantum computing threats and 
the actions needed to mitigate them by regularly engaging with partners 
across Government, critical infrastructure, and industry. Feedback from 
these engagements informs actionable recommendations to accelerate 
migration to post-quantum cryptography.
    CISA publishes guidance and best practices on its post-quantum 
cryptography webpage. Topics include considerations for operational 
technology, strategies for automated cryptographic discovery and 
inventory, and product categories that use post-quantum cryptography 
standards. These resources are often developed in collaboration with 
interagency partners. CISA actively collaborates with international, 
interagency, industry, and critical infrastructure stakeholders to 
coordinate efforts, share insights, and harmonize approaches for post-
quantum migration.
    CISA works with the Office of Management and Budget (OMB) and the 
Office of the National Cyber Director (ONCD) to collect annual 
cryptographic inventories to understand the scope of the problem. The 
agency analyzes these inventories, identifies challenges, and shares 
lessons learned with Federal agencies. CISA also partners with the 
National Institute of Standards and Technology (NIST) to demonstrate 
automated cryptographic discovery and inventory tools, which will 
improve visibility into cryptographic vulnerabilities and support 
automation.
     Questions From Honorable August Pfluger For Madhu Gottumukkala
    Question 1a. In recent years, there has been no shortage of high-
profile cyber attacks attributed to our foreign adversaries, including 
SolarWinds, Colonial Pipeline, and, more recently, campaigns like Volt 
Typhoon and Salt Typhoon targeting U.S. critical infrastructure and 
telecommunications networks.
    We have also seen Iran-aligned groups such as Cyber Av3ngers probe 
U.S. industrial control systems and water utilities, underscoring that 
multiple adversaries are targeting our critical infrastructure.
    Last month, it was widely reported that Salt Typhoon struck again, 
compromising email systems used by House staff on select committees 
dealing with China, foreign affairs, intelligence, and armed services.
    How is CISA working with critical infrastructure operators and 
other relevant stakeholders to strengthen resilience in the 
communications sector?
    Answer. CISA engages with telecommunications providers and other 
stakeholders to strengthen the security and resilience of the 
communications sector and mitigate threats posed by PRC cyber actors. 
These activities include continuity planning, information sharing, 
guidance, and incident handling.
    One of CISA's joint planning efforts focuses on hardening 
telecommunications infrastructure against nation-state threats. These 
efforts enhance the cybersecurity and resilience of the 
telecommunications sector by improving providers' ability to operate 
through compromise and recover quickly. Activities include routine 
threat exchanges and briefings for telecom executives, tabletop 
exercises simulating PRC-linked campaigns, and technical hardening 
guidance to reduce vulnerabilities and improve redundancy. Additional 
measures involve sector-wide risk modeling to assess cascading impacts 
on critical sectors such as energy, health care, and transportation, 
developing incident response playbooks, and creating continuity of 
operations templates to ensure essential services remain available 
during prolonged disruptions.
    CISA also leans into information sharing with Government and 
industry partners, including through the Communications Information 
Sharing and Analysis Center. These partnerships help accelerate CISA 
and the sector's response to cyber incidents.
    Question 1b. One issue CISA and the committee have been focused on 
is the threat posed by end-of-life network equipment that is so old it 
cannot be patched. How big of a problem is this issue, and what more 
can be done to secure our critical infrastructure, like Federal agency 
environments, from this risk?
    Answer. End-of-support devices, which no longer receive security 
updates from vendors, present a substantial and constant cybersecurity 
risk. CISA has observed advanced threat actors widely targeting these 
end-of-support edge devices, which when compromised, can provide the 
threat actor with extensive access to the victim's networks. 
Organizations can mitigate this threat by ensuring devices are 
proactively replaced before they become end-of-support.
    CISA issued Binding Operational Directive 26-02 on February 5, 
2026. This Directive requires Federal agencies to phase out unsupported 
edge devices. CISA strongly recommends other organizations, including 
critical infrastructure, to voluntarily take the mitigatory actions in 
the Directive to address the risk beyond the Federal Government.
    Question 2a. I have heard from stakeholders that when a 
sophisticated cyber attack occurs, multiple agencies reach out to them, 
both seeking information on the scale of the attack and offering 
assistance.
    What ends up happening is that the company has to repeatedly 
process and respond to duplicative requests, which takes manpower and 
resources away from responding to the attack.
    Under CIRCIA and the National Cyber Incident Response Plan, is it 
CISA's role to serve as the primary Federal interface for a private 
entity going through a major cyber attack?
    Answer. For cyber incident response, 6 U.S.C.  659 and PPD-41 
dictate that CISA leads the asset response activities, including 
offering technical support to reduce impacts of cyber incidents and 
speed recovery. PPD-41 separately provides that Federal Bureau of 
Investigation (FBI) leads threat response activities, leading 
investigations in pursuit and disruption of threat activity, and the 
Office of the Director of National Intelligence (ODNI) leads 
intelligence response. This complementary relationship ensures that 
each agency's mission is carried out and coordinated in parallel to 
ensure speed in response and recovery. CISA, FBI, and ODNI continuously 
synchronize efforts as appropriate, including to perform notifications 
and provide incident response support.
    For cyber incident reporting, CIRCIA tasks other Federal agencies 
that receive cyber incident reports, following implementation of the 
CIRCIA final rule, to share such reports with CISA for further 
interagency sharing and coordination (6 U.S.C.  681g). This will help 
provide a clearer picture of the threat landscape, enriching CISA and 
Federal partners' ability to carry out their respective cybersecurity 
missions. A goal of CIRCIA is to reduce the burden of entities 
reporting to multiple agencies so they can focus on incident response. 
CISA is committed to these benefits as it works to finalize the rule 
for CIRCIA.
    Question 2b. How are you working with other Federal agencies to 
streamline reporting and coordination, so that from the company's 
perspective they are not answering the same questions over and over 
while they are still trying to contain the incident?
    Answer. CISA continuously deconflicts with the FBI and Sector Risk 
Management Agencies when appropriate to avoid duplicating efforts 
during incident response.
    Question 3a. Congress is actively working toward a long-term 
reauthorization of the Cybersecurity Information Sharing Act of 2015, 
recognizing that it created the legal backbone for cyber threat 
information sharing between Government and the private sector.
    CISA 2015's liability protections, FOIA exemptions, and authorities 
helped address long-standing concerns from ISPs, cloud providers, and 
other critical-infrastructure owners about sharing sensitive threat 
data with the Government and with each other.
    At the same time, the threat environment and technology landscape 
have changed dramatically since 2015, with the rise of cloud, AI-
enabled threats, and persistent campaigns such as Volt Typhoon and Salt 
Typhoon targeting U.S. infrastructure.
    From your perspective, why are the core protections and authorities 
in CISA 2015 still essential to CISA's ability to work effectively with 
industry today?
    Answer. The U.S. Government and our private-sector partners rely on 
the Cybersecurity Information Sharing Act of 2015 (6 U.S.C. 1501 et. 
seq) to keep America safe. It fuels the trust, speed, and collaboration 
that make us stronger together. The law's protections play a vital role 
in the sharing of cyber threat indicators and defensive measures among 
private-sector entities and with Federal agencies, as well as in 
monitoring and defending their networks. Specifically, the law 
authorizes private entities to monitor their networks for cybersecurity 
purposes and to deploy defensive measures to detect or block malicious 
cyber threats on their networks without implicating Federal and State 
laws that may complicate defensive actions. Private entities are 
authorized to share cyber threat indicators or defensive measures with 
Federal and other entities for cybersecurity purposes, with protections 
including liability protection; an anti-trust exemption for private 
entities sharing with each other; exemptions from Federal and State 
disclosure laws and regulatory use; and preserved privilege for shared 
material.
    Question 3b. Are there areas where additional authority from 
Congress would materially improve CISA's ability to defend the U.S. 
Government and support critical-infrastructure operators?
    Answer. CISA is grateful that this committee advanced by a 
unanimous (25-0) vote H.R. 5079, the Widespread Information Management 
for the Welfare of Infrastructure and Government Act. This legislation 
would reauthorize the Cybersecurity Information Sharing Act of 2015 for 
another 10 years. This is an important step in strengthening our 
defenses at a time when our adversaries are constantly testing us. We 
stand ready to assist Congress in any way to ensure that these critical 
protections remain in place.
      Question From Honorable Matt Van Epps For Madhu Gottumukkala
    Question. Dr. Gottumukkala, while large-scale quantum computing 
threats may still be years away, the transition to post-quantum 
cryptography will require early planning and coordination across 
Government and industry. How is CISA helping Federal agencies and 
critical infrastructure operators prepare for this transition, and what 
steps are being taken now to ensure systems can migrate securely to 
post-quantum standards when the time comes?
    Answer. CISA recognizes the threat that cryptographically-relevant 
quantum computers pose to traditional encryption and is taking 
proactive measures to prepare Federal agencies, State, local, Tribal, 
and territorial governments, and critical infrastructure owners and 
operators for a secure migration to quantum-resistant systems.
    CISA helps raise awareness about the quantum computing threats and 
the actions needed to mitigate them by regularly engaging with partners 
across Government, critical infrastructure, and industry. Feedback from 
these engagements informs actionable recommendations to accelerate 
migration to post-quantum cryptography.
    CISA publishes guidance and best practices on its post-quantum 
cryptography webpage. Topics include considerations for operational 
technology, strategies for automated cryptographic discovery and 
inventory, and product categories that use post-quantum cryptography 
standards. These resources are often developed in collaboration with 
interagency partners. CISA actively collaborates with international, 
interagency, industry, and critical infrastructure stakeholders to 
coordinate efforts, share insights, and harmonize approaches for post-
quantum migration.
    CISA works with OMB and the ONCD to collect annual cryptographic 
inventories to understand the scope of the problem. The agency analyzes 
these inventories, identifies challenges, and shares lessons learned 
with Federal agencies. CISA also partners with the NIST to demonstrate 
automated cryptographic discovery and inventory tools, which will 
improve visibility into cryptographic vulnerabilities and support 
automation.
   Questions From Chairman Andrew R. Garbarino For Ha Nguyen McNeill
    Question 1a. As TSA is set to launch the new Confirm.ID program 
February 1, 2026, the committee remains concerned over the scope of the 
program and TSA's requisite authority to implement it. In official 
statements and briefings to the committee, TSA has asserted its 
authority to set a fee under Confirm.ID derives from the Registered 
Traveler program. However, TSA has also separately cited Pub. L. 109-90 
and 49 U.S.C.  114 as legal justification for the start of this new 
program. Specifically, the statutory language cited by TSA only notes 
the existence of the Registered Traveler program, and TSA's ability to 
recover costs associated with such programs.
    Please clarify, how does TSA hold the requisite authority to start 
the Confirm.ID program without explicit Congressional authorization?
    Answer. The Transportation Security Administration (TSA) has broad 
statutory authority to prescribe screening measures and procedures for 
individuals entering the sterile areas of airports.\1\ The Intelligence 
Reform and Terrorism Prevention Act of 2004 (IRTPA) directs TSA to 
perform ``the passenger prescreening function of comparing passenger 
information to the automatic Selectee and No Fly lists and utilize all 
appropriate records in the consolidated and integrated terrorist 
watchlist maintained by the Federal Government in performing that 
function.''\2\ TSA carries out this statutory requirement through the 
Secure Flight program, which relies on information that passengers 
provide to airlines at the time they make a reservation.\3\ Secure 
Flight compares the passenger's reservation information to the 
identifying information of individuals on Federal Government watch 
lists and informs the airline whether or not it may issue a boarding 
pass based on the results of the prescreening process. IRTPA further 
directs TSA to establish ``procedures to ensure that individuals 
selected by [computer assisted passenger pre-screening] and their 
carry-on and checked baggage are adequately screened.''\4\ Identity 
verification procedures at the checkpoint are necessary to ensure that 
each passenger receives the appropriate level of screening, or is 
denied entry to the sterile area, in accordance with Secure Flight 
vetting results and security considerations.
---------------------------------------------------------------------------
    \1\ See, e.g., 49 U.S.C.  44901(a)-(b) (directing TSA to provide 
for and supervise the screening of all passengers and property that 
will be carried aboard a passenger aircraft); 44903(j)(2)(A)(ii) 
(requiring TSA to establish ``procedures to ensure that individuals 
selected by [computer-assisted passenger prescreening] and their carry-
on and checked baggage are adequately screened''); 114(f)(3) (directing 
TSA to ``develop policies, strategies, and plans for dealing with 
threats to transportation security''); 114(f)(11) (directing TSA to 
``oversee the implementation, and ensure the adequacy, of security 
measures at airports''); 114(h)(3) (requiring TSA to establish policies 
and procedures to prevent individuals who may be a threat to civil 
aviation or national security from boarding an aircraft).
    \2\ 49 U.S.C.  44903(j)(2)(C)(ii).
    \3\ Secure Flight Program, 73 Fed. Reg. 64018 (2008) (codified at 
49 CFR parts 1540, 1544, 1560).
    \4\ 49 U.S.C.  44903(j)(2)(A)(ii); see also 49 U.S.C.  44901(a).
---------------------------------------------------------------------------
    Under TSA's current screening procedures, the primary method of 
identity verification at the checkpoint is asking a passenger to 
present an acceptable form of ID that matches the passenger's 
identifying information in Secure Flight. TSA has long sought to 
facilitate passenger travel, consistent with its responsibility to 
ensure the security of aviation. For this reason, using appropriated 
funds, TSA has historically provided a call-center-based option to 
attempt to identify individuals who failed to produce acceptable IDs at 
the checkpoint. The limited number of individuals who used this 
alternative identity verification process received substantially 
heightened screening.
    With full enforcement of REAL ID, the number of individuals 
presenting without acceptable ID at the checkpoint significantly 
increased, exceeding both the capacity of the call center and resources 
for subsequent additional screening. As a result, TSA transformed its 
process for alternative identity verification, replacing a one-size-
fits-all approach with a registered travel identity verification model. 
The new model allows individuals who choose to participate to provide 
additional biographic and/or biometric information that TSA can 
leverage for alternative identity verification, with differing levels 
of reliability. As a result, there is a continuum of risk-based 
screening that reflects both the information available to TSA as part 
of the Secure Flight vetting process, including whether an individual 
has been vetted as a member of TSA PreCheck, and TSA's level of 
identity assurance that the pre-vetting established by Secure Flight 
applies to the individual presenting at the checkpoint. ConfirmID, like 
all TSA registered traveler programs, allows passengers to receive 
facilitated travel while enabling TSA to appropriately assign limited 
screening resources based on the risk associated with the individual 
passenger.
    Question 1b. How did TSA come to the determination to include 
Confirm.ID under the Registered Traveler program?
    Answer. In 2006, Congress directed TSA to collect a non-refundable 
fee to cover the costs of any registered traveler program.\5\ This 
provision requires TSA to ``impose a fee for any registered traveler 
program undertaken by the U.S. Department of Homeland Security (DHS) by 
notice in the Federal Register'' provided that ``such fees shall not 
exceed the aggregate costs associated with the program.'' TSA may also 
modify the fee through notice published in the Federal Register. As 
exemplified by the 2008 Registered Traveler Interoperability Pilot 
Program Fee Notice, programs funded under registered traveler fee 
authority have always consisted of components including Secure Flight 
vetting, additional pre-vetting, and identity verification.\6\ In fact, 
registered traveler programs consisting solely of enhanced identity 
verification and Secure Flight vetting, without additional pre-vetting, 
are active at 60 airports across the Nation through public-private 
partnership. As TSA transformed its former ``back-up call center'' into 
a multi-tiered capability for alternative identity verification, where 
passengers provide additional biographic and/or biometric information 
to enable access to expedited risk-based screening and TSA's 
application of limited screening resources to the highest-risk 
passengers, it was determined the program fit within the ``registered 
traveler'' category alongside those other programs. Therefore, 
consistent with the statutory mandate, TSA imposed a fee to recover the 
costs of providing this service, ensuring that individuals who benefit 
from the program rather than the taxpayer bear those costs.
---------------------------------------------------------------------------
    \5\ Department of Homeland Security Appropriations Act, 2006, 
Public Law 109-90, sec. 540, (119 Stat. 2064, 2088-89 (Oct. 18, 2005)) 
(codified at 49 U.S.C. 114 note).
    \6\ 73 Fed. Reg. 44275 (July 30, 2008).
---------------------------------------------------------------------------
    Question 1c. Given this, why would TSA interpret the Registered 
Traveler program to mean it has free-standing authority to create any 
new program under the guise of ``Registered Traveler,'' even when 
Confirm.ID explicitly deals with travelers outside the Trusted Traveler 
population?
    Answer. Reliable identity verification has long been a fundamental 
component of Registered Traveler programs. There are existing 
registered traveler programs that, like ConfirmID, rely on identity 
verification alongside Secure Flight vetting.\7\ Identity verification 
is the first step of physical screening at a TSA security checkpoint 
and the last step of TSA's intelligence-based prescreening of 
individuals. It ensures individuals receive the appropriate level of 
screening, ranging from expedited screening to enhanced screening 
(i.e., Selectees), including any additional screening associated with 
special circumstances, before entering the sterile area of an airport 
or boarding a flight. It also ensures that individuals designated as 
``No Flys'' are excluded from the screening checkpoint. There is a 
continuum of risk-based screening that reflects both the information 
available to TSA as part of the Secure Flight vetting process, 
including whether an individual has been vetted as a member of TSA 
PreCheck, and TSA's level of identity assurance that the vetting 
status established by Secure Flight applies to the individual 
presenting at the checkpoint. Although ``trusted traveler'' programs 
that involve additional vetting in advance of passenger arrival also 
rely on registered traveler fee authority, it is not additional pre-
vetting of individuals beyond Secure Flight that defines something as a 
registered traveler programs, but rather the provision of additional 
biographical and/or biometric information by passengers that in turn 
enables TSA to appropriately assign screening resources based on the 
risk associated with that individual passenger. As with all registered 
traveler programs, this serves both to expedite low-risk passenger 
travel and maximize the security effectiveness of finite TSA screening 
resources.
---------------------------------------------------------------------------
    \7\ 73 Fed. Reg. 44275 (July 30, 2008).
---------------------------------------------------------------------------
    Question 1d. Last, please explain further how the TSA does not view 
this as a ``mandatory'' fee, but rather as an optional one. Wouldn't a 
passenger going through the Confirm.ID process be required to pay the 
fee in order to receive the 10-day travel authorization?
    Answer. ConfirmID is not mandatory; but like all registered 
traveler programs, it requires a fee to use the service. ConfirmID 
participation is not required for passengers to receive TSA security 
screening and enter the sterile area. Under TSA's current screening 
procedures, the primary method of identity verification at the 
checkpoint occurs through the presentation of an acceptable form of ID 
that matches the passenger's identifying information provided to Secure 
Flight. TSA's list of acceptable forms of ID is prescribed in the 
Checkpoint and Specialized Screening Standard Operating Procedures, and 
TSA has published an abbreviated list (which includes the most common 
and widely-accepted IDs) for the public at TSA.gov.
    ConfirmID represents a risk-based effort by TSA to provide 
alternative identity verification options when an individual arrives at 
the checkpoint without an acceptable form of ID to facilitate passenger 
travel, consistent with TSA's responsibility to ensure the security of 
aviation. Federal Security Directors retain additional authorities 
regarding the screening process to address special circumstances.
    Question 2a. TSA has long emphasized a ``layered approach'' to 
transportation security, from the deployment of canine units to 
advanced technologies, to enhance the screening process and maintain 
the safe flow of travel.
    What does the layered security approach look like today, and can 
you explain how it is currently implemented? Specifically, can you 
address the role explosive detection canine units play within that 
framework?
    Answer. Every day, TSA relies on its intelligence and risk-based, 
layered security approach to aviation security that employs over 20 
layers, seen and unseen, from vetting and checkpoint screening to in-
flight security. TSA is prepared to offer a briefing at the proper 
classification level for layered security approach.
    TSA's layered approach begins before an individual arrives at the 
TSA checkpoint, when he or she is vetted through Secure Flight, TSA's 
automatic pre-screening program. Key to this security layer is identity 
verification, which ensures passengers receive the appropriate level of 
physical screening at the TSA checkpoint. Through automation efforts, 
TSA is able to leverage the Credential Authentication Technology and 
Touchless Identity Systems biometrics to confirm the passenger's 
identity and ensure the passenger does not present a threat to aviation 
security.
    In keeping with TSA's layered security approach, Explosive 
Detection Canine teams can be used to reduce risk and facilitate more 
efficient screening during periods of high passenger throughput or when 
checked baggage screening capacity has been exceeded. TSA continuously 
advances deployment strategies for Explosive Detection Canine teams 
through rigorous research, testing, and analysis. Canines serve as a 
critical complement to TSA's advanced technologies, providing 
capabilities that are additive, not substitutive. Where canine assets 
are deployed, they significantly enhance security operations by 
offering rapid, non-intrusive screening for explosives and explosive 
devices. Canines act as a visible deterrent to malicious activity and 
are uniquely able to adapt quickly to dynamic environments and evolving 
threats. Their exceptional ability to detect concealed threats in 
crowded and complex areas strengthens TSA's security protocols, 
delivering an additional layer of protection that is both flexible and 
highly effective. This synergy between canine teams and advanced 
technology ensures a robust, multi-faceted approach to safeguarding 
transportation systems.
    Question 2b. What risk assessments drive a decision not to deploy 
canine units, and how does TSA ensure that any security gaps are still 
mitigated?
    Answer. The primary constraint on deploying canine units at a 
particular location is the availability of the resource rather than a 
risk assessment. Canine units are unique in their deterrent effect and 
their high-volume screening capability, and they are therefore often 
deployed where those characteristics--in addition to their detection 
capabilities--are most needed. In the absence of canine units, security 
gaps are mitigated with other screening capabilities. TSA is prepared 
to offer a briefing at the proper classification setting to discuss the 
``other screening capabilities.''
    Question 3. Ms. McNeill, you mentioned in your testimony that TSA 
flagged the appropriate law enforcement agencies about the frequent 
large-sum cash-flow through Minneapolis Airport. Please provide a list 
of the agencies TSA notified along with the dates and information 
reported.
    Answer. In calendar years 2024 and 2025, TSA recorded 362 instances 
in which bulk currency was found during security screening at the 
passenger checkpoint at Minneapolis-Saint Paul International Airport 
(MSP), which required law enforcement notification. The Minneapolis-
Saint Paul International Airport follows the TSA standard operating 
procedure for reporting large amounts of currency discovered during 
screening at the checkpoint. Carrying currency in and of itself is not 
prohibited nor illegal. When clearing an alarm during the screening 
process, if a Transportation Security Officer discovers currency that 
appears to exceed $10,000 and is bound for an international 
destination, or appears to be related to potential criminal activity, 
the Transportation Security Officer notifies a supervisor to determine 
whether further notification to Federal or State authorities is 
required. If the Supervisory Transportation Security Officer determines 
that the large amount of currency appears to exceed $10,000, and the 
individual is traveling internationally, the Supervisory Transportation 
Security Officer notifies the TSA Coordination Center at the 
Minneapolis-Saint Paul International Airport, which in turn notifies 
U.S. Customs and Border Protection and U.S. Immigration and Customs 
Enforcement's Homeland Security Investigations (HSI) and provides the 
individual's name, flight information, and airport code. If any amount 
of currency is discovered during the screening process that appears to 
be related to criminal activity, the Supervisory Transportation 
Security Officer must notify a law enforcement officer, which can 
include TSA's Federal partners; and at a local Minneapolis-Saint Paul 
International Airport law enforcement level, the Minneapolis-Saint Paul 
International Airport Police Department. If TSA has cleared all alarms, 
and the law enforcement officers who have been notified are not present 
at the conclusion of the screening process, the individual may be asked 
to wait, but he or she will be free to leave once TSA screening is 
completed. Any further action concerning the individual or his or her 
property will be handled by the appropriate law enforcement agency.
    Question 4. As you know, TSA is the lead on pipeline security 
across the United States. Given the current global terror landscape, 
what are the most pressing threats to U.S. pipeline infrastructure? 
What steps is DHS taking to enhance pipeline security, and how does 
technology factor into that effort?
    Answer. Current threats to U.S. pipeline infrastructure is defined 
by a combination of evolving physical and cyber risks, such as 
sabotage, drone-enabled attacks, theft, vandalism, insider actions 
targeting critical assets and facilities, and persistent state-
sponsored cyber risks. Other risks include theft or stripping of 
pipeline assets for copper, trace amounts of precious metals, and other 
materials for criminal economic gain. Among the most pressing threats 
to U.S. pipeline infrastructure are increasingly sophisticated nation-
state cyber operations and, increasingly, the integration of Artificial 
Intelligence capabilities. Examples include:
   Nation-State Cyber Persistence.--Adversaries are 
        increasingly shifting from short-term disruption to ``living 
        off the land,'' where they embed themselves in systems for 
        months or years to strategically position for future global 
        conflict. China remains the most active of these state 
        actors,\8\ as seen in the Volt Typhoon campaign which 
        compromised, among others, transportation entities.
---------------------------------------------------------------------------
    \8\ Volt Typhoon targets U.S. critical infrastructure with living-
off-the-land techniques/Microsoft Security Blog.
---------------------------------------------------------------------------
   AI-Enhanced Attacks.--Malicious actors are leveraging 
        Artificial Intelligence to plan, scale, and automate physical 
        and cyber attacks on critical infrastructure. This includes 
        more sophisticated phishing techniques and the scaling of cyber 
        compromises.
   Operational Technology Vulnerabilities.--Many pipeline 
        systems use legacy Operational Technology that was not 
        originally built with cybersecurity in mind, making these 
        systems highly vulnerable to remote exploitation and potential 
        physical destruction (e.g., explosions or sabotage).
   Ransomware and Criminal Groups.--High-profile incidents like 
        the ransomware attacks against Colonial Pipeline (2021) and the 
        Port of Seattle (2024) demonstrate that even non-state criminal 
        groups can cause massive national disruption by targeting 
        Information Technology systems and even force the precautionary 
        shutdowns of operational networks across the U.S. 
        Transportation System.
   Physical and Social Unrest.--Pipelines face threats from 
        ``hacktivist'' campaigns and physical vandalism or equipment 
        destruction related to political issues and high-profile 
        development projects. Through robust, mandatory performance-
        based requirements and enhanced incident reporting protocols, 
        TSA has significantly strengthened the cybersecurity posture of 
        critical pipeline owners and operators, ensuring proactive 
        mitigation and rapid response to evolving cyber threats. 
        Notable actions include:
   Mandatory Cybersecurity Directives.--TSA-issued Security 
        Directive Pipeline-2021-02. This directive requires critical 
        pipeline owners and operators to submit and maintain a unique 
        Cybersecurity Implementation Plan, develop a system-specific 
        Cybersecurity Incident Response Plan, and conduct an annual 
        Cybersecurity Architecture Design Review.
   Strengthened Incident Reporting.--TSA-issued Security 
        Directive Pipeline-2021-01. This directive requires critical 
        pipeline owners and operators to also report cyber incidents to 
        the Cybersecurity and Infrastructure Security Agency and 
        designate a Cybersecurity Coordinator. Notably, non-U.S. 
        citizens in this role must now undergo specific vetting via 
        programs like Global Entry or NEXUS.
    While TSA's cybersecurity directives are mandatory, its physical 
security strategy leverages targeted, risk-based guidance and proactive 
engagement with industry partners. Through the Corporate Security 
Review program, TSA conducts comprehensive assessments based on a set 
of jointly agreed-to best practices and encourages operators to 
promptly report significant physical security concerns.
   TSA conducts Critical Facility Security Reviews to assess 
        the physical security measures in place at critical pipeline 
        facilities.
   TSA provides recommendations as appropriate to owners and 
        operators to enhance their physical policies, plans, and 
        practices.
   TSA further enhances protection by delivering timely 
        intelligence on emerging physical threats, such as sabotage, 
        vandalism, or terrorist activity, enabling owners and operators 
        to take swift, informed action to safeguard critical 
        infrastructure.
    Question 5a. Under the Biden administration, TSA increasingly 
relied on rapidly promulgating rules through Security Directives rather 
than the formal rule-making and comment process, leaving stakeholders 
to comply with new security changes often at a higher cost.
    What steps does TSA take to ensure that Security Directives do not 
impose unnecessary costs or operational burdens on airlines, airports, 
and surface transportation operators?
    Answer. When a regulation or security directive must be issued 
immediately to protect transportation security, TSA will issue it 
without providing notice or an opportunity for comment. See 49 U.S.C.  
114(l)(2). In developing mandatory requirements, TSA weighs options and 
courses of action and considers the operational and economic impact to 
ensure the measures are practical and tailored to the specific threat. 
To the extent practicable, TSA shares the proposed security directives 
with the affected regulated entities to ensure the mandatory security 
measures reduce the risk, and that industry--regardless of the size of 
the regulated party--is able to operationally and economically 
implement the requirements. If necessary, TSA revises the security 
measures to ensure the measures reduce risk and industry can implement 
the requirements.
    Question 5b. Please provide examples of how TSA has improved 
coordination with the regulated entities to ensure practical and 
tailored rules fit for specific operating environments.
    Answer. TSA complies with existing standards and practices to 
ensure that unnecessary costs or burdens are not imposed on our 
industry stakeholders. TSA is required, by law, to comprehensively 
review each security directive in consultation with the appropriate 
regulated entities to determine its continued relevance; determine 
whether the directive should be streamlined to most efficiently 
maximize risk reduction; and update, consolidate, or revoke any 
directive as necessary. TSA's Policy, Plans, and Engagement Aviation 
Division Airlines Policy Branch conducts annual reviews of each 
security directive in accordance with:

``FAA Extension and Safety Act of 2016 (P.L. 114-190); Tile III 
Aviation Security, SEC. 3409. SECURITY DIRECTIVES.
``(a) REVIEW.--Not later than 180 days after the date of the enactment 
of this Act and annually thereafter, the Administrator, in consultation 
with the appropriate regulated entities, shall conduct a comprehensive 
review of every current security directive addressed to any regulated 
entity to--(1) determine whether each such security directive continues 
to be relevant; (2) determine whether such security directives should 
be streamlined or consolidated to most efficiently maximize risk 
reduction; and (3) update, consolidate, or revoke any security 
directive as necessary.
``FAA Reauthorization Act of 2018 (P.L. 115-254); Subtitle E--Foreign 
Airport Security, Sec 1953 Last point of departure airports; security 
directives
``(a) NOTICE AND CONSULTATION.--(1) IN GENERAL.--The Administrator 
shall, to the maximum extent practicable, consult and notify the 
following stakeholders prior to making changes to security standards 
via security directives and emergency amendments for last points of 
departure: (A) Trade association representatives, for affected air 
carriers and airports, who hold the appropriate security clearances. 
(B) The head of each relevant Federal department or agency, including 
the Administrator of the Federal Aviation Administration.''

    When conducting comprehensive reviews and considering revisions to 
these directives, TSA holds roundtable discussions with industry 
stakeholders. These meetings garner an understanding of operational 
realities and the potential impact of new requirements. TSA uses a 
risk-based approach to decide which owners and operators are covered by 
the directives, focusing compliance obligations on entities that 
present the highest risks to national and economic security.
    Any time TSA issues a revised security directive, TSA consults with 
the affected industry to determine if the measures continue to be 
relevant. Once it is determined that the measures are necessary, TSA 
shares the proposed changes to the security directive with the affected 
regulated entities to ensure the mandatory security measures reduce the 
risk, and that industry is able to implement the requirements.
    Question 6a. DHS OIG recently completed a review of Covert Testing 
of TSA's Checkpoint Security Screening Effectiveness that raises 
serious issues in its final report.
    What role did TSA have in reviewing and providing comments on that 
final report?
    Answer. TSA was not afforded the opportunity to review and comment 
on the draft report prior to the issuance of the final report. A 
technical meeting between TSA and the DHS Office of the Inspector 
General is occurring on April 23, 2026.
    Question 6b. How confident are you that TSA's technology can catch 
rapidly-evolving threats rather than reacting after vulnerabilities are 
exposed?
    Answer. TSA employs a risk-based, layered security approach and 
remains confident in our security posture in the face of evolving 
threats. The agency performs continuous risk analyses and tests to 
inform its procedures and address the changing risk landscape.
    Question 7a. TSA recently announced a $1 billion nationwide upgrade 
to TSA's security screening equipment, specifying the funds will be 
used to update screening equipment across multiple airports and expand 
training programs to better detect potential threats.
    How would the $1 billion be allocated to support modernization of 
TSA's screening technology?
    Answer. TSA assessed the capital investment requirements that are 
needed to provide the Nation's highest-passenger-volume airports with 
advanced screening technologies. This includes requirements for 
Computed Tomography, Credential Authentication Technology, Advanced 
Imaging Technology, and Next-Generation Liquid and Powder Explosives 
detection systems. However, TSA's current capital resources are 
insufficient to meet these needs at the necessary scale and pace, 
resulting in a significant multi-year funding shortfall that constrains 
TSA's ability to stay ahead of the evolving threat environment. 
Restoring to TSA the portion of aviation security fee collections that 
is currently diverted outside the agency is critical to closing this 
gap, enabling timely deployment and recapitalization of these essential 
screening technologies, and ensuring TSA can proactively address 
current and emerging threats.
    Question 7b. Has DHS determined which airports or kinds of 
equipment would be prioritized for investment, such as passenger, 
baggage, or cargo screening technology?
    Answer. If funding is available, TSA would deploy the equipment to 
the Nation's highest-passenger-volume airports.
    Question 7c. How would this address the backlog of airports that 
have requested support to update or procure new screening technology?
    Answer. If these funds become available, they would significantly 
reduce the current backlog of airports seeking support to update or 
procure new screening technology by accelerating deployment time lines 
and expanding coverage across the system.
     Questions From Honorable Ryan Mackenzie For Ha Nguyen McNeill
    Question 1a. The Transportation Security Administration (TSA) is 
the Sector Risk Management Agency (SRMA) responsible for security 
across all transportation modes, including pipelines. The agency 
provides security oversight, risk assessments, and guidance, working 
with the Pipelines and Hazardous Materials Safety Administration 
(PHMSA) and operators to secure these critical energy infrastructure 
assets.
    As the SRMA for pipelines, how does TSA support this critical 
infrastructure sector in mitigating risk?
    Answer. As the Sector Risk Management Agency (SRMA) for pipelines, 
TSA supports this critical infrastructure sector through a layered, 
risk-based approach that integrates mandatory regulatory oversight with 
collaborative public-private partnerships. Since 2021, TSA has 
transitioned from a primarily non-regulatory security model to one with 
enforceable security standards relating to cybersecurity for the most 
critical U.S. pipelines, significantly enhancing sector resilience. TSA 
deploys cybersecurity professionals who work closely with industry 
partners to ensure compliance with technical requirements across both 
Information Technology and Operational Technology environments.
    In addition to regulatory oversight, TSA offers non-regulatory 
services to strengthen cyber resilience and posture. For physical 
security, TSA relies on non-regulatory activities and risk-based 
guidance, primarily utilizing the Corporate Security Review and 
Critical Facility Security Reviews programs. In addition to the 
required cyber incident reporting, facility owners and operators are 
encouraged to report significant physical security concerns, and TSA 
provides timely intelligence on emerging threats, including sabotage, 
vandalism, and terrorist plots, which enable rapid and informed 
responses.
    Question 1b. How does TSA interact with the pipeline sector? And 
similarly, how does the agency coordinate with the Department of Energy 
(DOE) as the SRMA for the energy sector?
    Answer. TSA maintains robust working relationships with pipeline 
industry owners and operators, fostering open, on-going dialogue to 
collaboratively address security challenges and develop effective ways 
to mitigate risks. TSA holds regular conference calls with industry 
about security issues, particularly when TSA has revised its 
cybersecurity requirements. This partnership-driven approach ensures 
that industry feedback is taken into consideration for TSA's regulatory 
development; and industry engagement ensures practical, informed, and 
effective implementation, which enhances sector resilience. TSA also 
coordinates closely with the U.S. Department of Energy through the 
Critical Infrastructure Partnership Model and the National 
Infrastructure Protection Plan Partnership Framework that aligns TSA's 
regulatory authority over pipeline security with the Department of 
Energy's broader responsibilities as the SRMA for the energy sector, 
ensuring unified risk mitigation and information sharing across both 
agencies.
    Question 2. The Known Crewmember (KCM) program is a critical risk-
based aviation security capability that enables expedited screening for 
trusted flight and cabin crew while supporting operational reliability 
across the airline system. As TSA moves to assume governance of KCM 
through the Crewmember Access Point, the transition represents a 
significant shift in program oversight with direct implications for 
system performance, labor trust, identity assurance, and insider threat 
mitigation. Congressional oversight is necessary to ensure the 
transition strengthens security and governance without degrading timely 
crewmember access or airline operations.
    What is TSA's plan and time line to assume governance of the Known 
Crewmember program, and how will you preserve expedited, risk-based 
crew access while strengthening identity assurance and insider threat 
protections?
    Answer. TSA is committed to providing crewmembers an expedited 
method for accessing the sterile area of airports, as is statutorily 
required, and mitigating transportation security risk. Transition from 
the Known Crewmember program to the Crewmember Access Point program is 
planned to begin in the summer of 2026 and will take approximately 6 
months to fully incorporate across all impacted airports. TSA's 
approach aligns with TSA Modernization efforts and incorporates 
technology to strengthen identity verification of crewmembers at 
designated Crewmember Access Point program locations and expedite 
screening. It also incorporates Unpredictable Screening Procedures, in 
which the Crewmember Access Point technology randomly selects 
participating crewmembers for additional screening, to directly address 
potential insider threats. TSA will continue to work with its industry 
partners and stakeholders to facilitate a smooth transition.
    Question 3a. TSA Touchless PreCheck is a biometric identity 
verification capability that enables enrolled PreCheck travelers to 
verify their identity at airport checkpoints using facial recognition, 
eliminating the need to present a physical ID. The capability is 
currently operational at 20 airport locations, including major hubs 
such as DFW, JFK, ORD, DCA, LGA, LAX, CLT, PHL, and BOS. Expansion is 
under way to an additional 2 hubs and 35 spoke locations, with full 
deployment targeted for completion by Q1 2026. As of mid-January, 
traveler adoption continues to grow, with approximately 955,000 options 
and more than 209,000 successful Touchless ID transactions completed.
    What is TSA's long-term vision for Touchless ID? Is Touchless ID 
intended solely as a checkpoint identity verification tool, or does TSA 
envision it becoming a broader identity platform across the 
transportation system?
    Answer. TSA PreCheck Touchless ID is an identity verification tool 
that delivers a seamless, curb-to-gate experience for trusted travelers 
who opt-in to participate. As of February 11, 2026, the capability is 
operational at 40 airport locations, and by April 2026 it will be 
operational at 65 airports and 112 aviation security checkpoints.
    As adoption grows, TSA's long-term goal is to accelerate the 
deployment of touchless technologies across the TSA enterprise and to 
enhance automation throughout the transportation system. To date, 5 
airlines are currently participating in TSA PreCheck Touchless ID at 
the security checkpoint, and all participating carriers have indicated 
interest in extending its use to baggage check-in. Two of the 
participating carriers have already begun rollout of TSA PreCheck 
Touchless ID for baggage check-in at select locations.
    Question 3b. Are there future use cases TSA is evaluating for 
Touchless ID beyond passenger screening such as employee access, cargo, 
or international operations?
    Answer. At this time, additional use cases for TSA PreCheck 
Touchless ID, beyond passenger screening, have not been identified. TSA 
continues to leverage the infrastructure developed for TSA PreCheck 
Touchless ID to identify opportunities to improve security and improve 
the passenger experience.
    Question 3c. As TSA considers scaling Touchless ID nationwide, what 
challenges do you see related to infrastructure, funding, and system 
reliability, and how is TSA planning to sustain the system over time?
    Answer. The current TSA PreCheck Touchless ID edge device may 
evolve to enable the expansion of TSA PreCheck Touchless ID and allow 
additional trusted travelers to experience the capability throughout 
their travel journey. As we continue to scale nationwide, TSA will work 
to align Touchless ID with other DHS initiatives to minimize impact to 
infrastructure and system reliability.
       Questions From Honorable Dale Strong For Ha Nguyen McNeill
    Question 1a. Ms. McNeill, TSA plays a critical role in protecting 
the traveling public by both proactively identifying emerging threats 
and ensuring that aviation security protocols keep pace with changes in 
the industry.
    With charter operators increasingly functioning like scheduled 
commercial airlines, how does TSA view the security implications of 
this shift, and what risks, if any, does it present for passenger 
screening and vetting?
    Answer. TSA has substantially enhanced security requirements for 
scheduled commercial airlines over more than 2 decades. As some charter 
operators are now functioning and increasing charter passenger volume 
in ways that are more similar to other scheduled, commercial 
operations, TSA has updated its security programs for charter 
operations to ensure comprehensive vetting and screening of passengers 
and their accessible property to mitigate potential threats to 
aviation. In addition, through regular engagements with the aviation 
community, TSA actively shares threat information, best practices, and 
lessons learned, reinforcing the shared responsibility of securing the 
national air space among pilots, air carriers, airport operators, 
fixed-base operators, and Government agencies. Despite these efforts, 
TSA has concerns about how foreign governments approve charter 
operations, stemming from well-documented cases in 2023 and 2024 of 
Legend Airlines, a Romanian charter airline, which engaged in human 
smuggling and trafficking.
    Question 1b. As charter operations grow and more passengers are 
flying through fixed-based operators rather than traditional commercial 
terminals, are you confident these facilities are properly equipped to 
screen the increasing number of travelers, or do you see potential 
security gaps if charter flights continue operating outside the same 
screening framework as commercial aviation?
    Answer. TSA's role in conducting passenger and property screening 
is generally focused on passengers that will enplane or deplane within 
sterile areas of airports. Outside of this context, the responsibility 
for passenger screening generally rests with the aircraft operator. TSA 
regulates both Private Charter and Public Charter operators through 
established security programs, such as the Private Charter Standard 
Security program and the Twelve-Five Standard Security program, which 
mandate comprehensive vetting and screening procedures. While their 
operations may be conducted through fixed-base operators, the fixed-
base operators are not responsible for the screening.
    Question 2a. Ms. McNeill, it has been nearly 3 years since TSA 
first issued emergency cyber requirements for the aviation sector, and 
since then, the agency has made a number of updates and adjustments to 
the program.
    How is TSA evaluating how well the program has worked over this 
period, and what steps are you taking to ensure these requirements are 
strengthening aviation cybersecurity while being implemented 
effectively across the aviation industry?
    Answer. TSA is working closely with all entities that fall under 
TSA's aviation cybersecurity requirements. TSA's initial outreaches and 
inspections show that cybersecurity maturity varies widely across the 
aviation sector.
    We are focusing our efforts on helping each organization meet these 
cybersecurity requirements and strengthen their cybersecurity 
practices. Through these partnerships, we are seeing strong 
cooperation, and overall cybersecurity is improving across the sector.
    TSA built into its cybersecurity program a proactive evaluation of 
the cybersecurity measures that entities are implementing. TSA requires 
certain entities to develop and submit annually to TSA a Cybersecurity 
Assessment Program, which proactively assesses the effectiveness of the 
cybersecurity measures they are required to implement. The 
Cybersecurity Assessment Program is designed to ensure that the 
policies, procedures, capabilities, and measures being implemented by 
entities are effective and strengthen aviation cybersecurity.
    Additionally, TSA actively gathers input from airports and industry 
partners, recognizing the real-world challenges of funding and 
prioritizing cybersecurity. The feedback from inspections and 
engagements is used to refine TSA's cybersecurity requirements, as well 
to clarify guidance and provide necessary support to entities. By the 
end of fiscal year 2027, cyber compliance inspectors will have 
completed the initial baseline inspections for each airport/aircraft 
operator/fuel farm consortium covered by the Joint Emergency Amendment, 
Fuel Order, and National Amendments. During fiscal year 2026, our 
cybersecurity inspectors and architects completed the first 87 
inspections; we are on schedule to complete the remaining 84 initial 
inspections during fiscal year 2027. Through feedback from our 
regulated partners and the inspection process, the cyber inspectors 
share these results with the TSA enterprise, so timely adjustments can 
be made to the Joint Emergency Amendment and National Amendments.
    To ensure TSA's cybersecurity requirements are being effectively 
implemented across the aviation industry, TSA conducts inspections of 
covered entities to assess compliance. These inspections are an 
important tool and serve as a catalyst for improving cybersecurity 
maturity, helping covered entities identify gaps and prioritize 
cybersecurity measures. TSA provides guidance and assistance prior to 
the on-site inspection, fostering a supportive environment that helps 
airports prepare and understand requirements. During the inspections, 
TSA ensures that entities are implementing TSA's cybersecurity 
requirements and provides entities with recommended areas of 
improvement to enhance their cybersecurity posture beyond what is 
merely required. TSA tracks compliance, incident reporting, and 
progress on security upgrades to ensure requirements are not only met 
but are also improving the overall cybersecurity posture.
       Questions From Honorable Vince Fong For Ha Nguyen McNeill
    Question 1. The Screening Partnership Program (SPP) allows airports 
to opt in to private screening solutions, which can generate savings of 
up to 20 percent on personnel costs for TSA without jeopardizing safety 
standards. How does TSA plan to leverage public-private partnerships, 
including SPP, to increase efficiencies and free up savings that can be 
reinvested in needed technology upgrades?
    Answer. TSA is working to enable innovative public-private 
partnerships through the Screening Partnership Program (SPP). In July 
2025, TSA released the ``Turnkey Request for Information (RFI)'' to 
solicit industry input on potential fully integrated, turnkey solutions 
that could drive new innovations at checkpoint and in checked baggage 
screening. TSA sought comment from both traditional and non-traditional 
industry partners.
    Using input from the Turnkey RFI, TSA is developing a framework to 
modernize the SPP to drive public-private partnerships. This new 
framework will give airports a choice in how they engage with TSA and 
will drive greater capital to the checkpoints, to airports, and the 
communities they serve.
    By enabling public-private partnerships, TSA can drive greater 
efficiencies and create a more competitive market for innovative 
aviation security technologies. This market will drive savings for TSA 
by incentivizing private investment at the checkpoint, in checked 
baggage screening technologies, and at airports more broadly.
    Question 2. Cutting-edge, current-day baggage screening 
technologies are not expected to be deployed at all U.S. airports until 
2040, at which point they will be obsolete. How can TSA accelerate the 
modernization of aviation safety infrastructure, including by 
leveraging public-private partnerships and the Screening Partnership 
Program (SPP)?
    Answer. TSA will leverage the SPP to develop security solutions 
that include technology and maintenance in addition to personnel, which 
will incentivize industry to accelerate deployment of checkpoint and 
checked-baggage screening technologies that provide better security, 
passenger experience, and throughput.
    Additionally, TSA is enhancing its existing Capability Acceptance 
Process and Third-Party Testing programs to increase the speed of 
testing, certifying, and deploying new security technology innovations. 
This will expedite the delivery of innovative checkpoint and checked 
baggage solutions to the marketplace and further support innovation in 
future public-private partnerships.
    Question 3. What airports has TSA determined are most in need of 
screening technology upgrades, and how may public-private partnerships, 
including participation in the Screening Partnership Program (SPP), 
help to accelerate the process of purchasing and deploying upgraded 
equipment?
    Answer. TSA considers many factors when identifying airports in 
need of screening technology upgrades, including airport volume, 
airport capacity constraints, age of currently deployed technology, 
potential risk reduction provided by upgrades, and future growth or 
infrastructure investments.
    Leveraging the SPP could attract the additional private investment 
necessary to accelerate the deployment of next-generation checkpoint 
and checked-baggage screening technologies. TSA is exploring a number 
of areas including equipment, maintenance, and future technology 
upgrades in the scope of the SPP. While the SPP currently focuses on 
privatized screening personnel, allowing participating airports to 
incorporate both privatized screeners and technology into the SPP may 
incentivize private partners to innovate and automate screening 
operations.
      Questions From Honorable Matt Van Epps For Ha Nguyen McNeill
    Question 1a. Ms. McNeill, as we consider new threats to air 
transportation, what would TSA's response to a drone attack on an 
airport look like?
    How is TSA addressing UAS threats?
    Answer. TSA employs a variety of tactics, techniques, and 
procedures to address the threat of careless/clueless, reckless/
negligent operators, or even potentially nefarious actors utilizing 
Unmanned Aircraft Systems (UAS) in the national air space. These 
tactics, techniques, and procedures can be grouped into 3 broad 
categories:
   Left-of-Launch.--Pre-incident activities that help to reduce 
        risk from potential UAS threats before they occur;
   Incident response.--Actions taken to address or mitigate 
        threats in real-time; and
   Post-incident response.--Actions taken to improve future 
        left-of-launch or incident response activities.
    Left-of-launch activities consist of several steady-state functions 
that Federal Air Marshals (FAMs) from headquarters and the field 
perform on a routine basis. These activities include:
   Deployment of drone detection equipment to improve domain 
        awareness around airports and transportation infrastructure. 
        Developing an understanding of what's flying in the air space 
        allows FAM's to share these data (while complying with the 
        privacy requirements of section 124n of title 6, and with the 
        First and Fourth Amendment) with local stakeholders, so that 
        everyone has a better idea of what is occurring in their areas 
        of responsibility.
   Conducting airport vulnerability assessments to improve an 
        airport's preparedness and response posture in the event of a 
        potential disruption.
   Outreach and education among public and private-sector 
        stakeholders to help reduce the risk of careless/clueless 
        violators operating in controlled air space.
   Pilot engagement to document interactions and potential 
        regulatory violations for referrals to the Federal Aviation 
        Administration (FAA).
   Proactive utilization of FAMs' access to the FAA's 
        registration and drone authorization database so that FAMs can 
        reach out to pilots ahead of time to inform them of pending 
        Temporary Flight Restrictions to ensure pilots are aware of 
        these changes.
    Incident Response occurs in real-time, with FAMs addressing a drone 
incident that has the potential to impact an airport, transportation 
sector, or a special event. These activities will be guided by the Core 
30 CONOPS, an interagency command and control document for Counter-
Unmanned Aircraft System (C-UAS) emergency response at the Core 30 
airports that designates TSA as the Lead Federal Agency for C-UAS 
response at airports. The response will include:
   Real-time utilization of TSA's access to the FAA's 
        registration and drone authorization database so that FAMs can 
        attempt to identify air space violators in real time.
   Conduct ground response-based on technical or visual 
        sightings, whereby FAM's identify and make contact with 
        operators, instructing drone violators to safely land aircraft 
        that may pose a potential danger.
   Conducting field interviews that document misdemeanor 
        violations that could result in the issuance of a District 
        Court Violations Notice or ticket.
   In the event of a persistent disruption, FAMs are prepared 
        to respond to an on-going shutdown of a Core 30 airport in 
        accordance with the Unified National Level Response to a 
        Persistent Disruption of Operations at Core 30 Airports, 
        utilizing all its field-based capabilities, up to and including 
        conducting mitigation operations.
    Post-incident response activities include conducting data analysis 
and information sharing (as permitted under section 124n of Title 6, 
and the First and Fourth Amendment) in response to inter-agency 
requests for support; and engaging in routine cooperation among law 
enforcement and transportation stakeholders to identify trends or gaps 
to better prepare for future incidents.
    Question 1b. How is TSA implementing the Safer Skies Act of last 
year's NDAA?
    Answer. In response to the passage of the Safer Skies Act, TSA 
started or increased several initiatives to better prepare itself to 
utilize the broader DHS authorities ``to enforce the law'' and 
``protect the public.'' TSA no longer must rely on the emergency 
provisions under 124n and can now proactively prepare and develop its 
own C-UAS capabilities and operational framework to be executed when 
authorized by the Secretary. These current efforts can be divided into 
3 main pillars: procurement, training, and operational planning.
    Question 2. Ms. McNeill, what operational, policy, and interagency 
coordination reforms could TSA implement with law enforcement and CBP 
to strengthen oversight and reduce risk of suspicious cash-flow through 
travel hubs?
    Answer. TSA relies on administrative search authority for its 
operations at travel hubs. An administrative search is an exception to 
the 4th Amendment and is conducted without a warrant as part of a 
regulatory plan in furtherance of a specified non-law enforcement 
government purpose, such as to determine compliance with TSA 
regulations or to prevent the carrying of threat items or entry of an 
unauthorized person into the sterile area, or to screen passengers 
entering any public conveyance. Consistent with the parameters of the 
4th amendment exception, TSA conducts all administrative searches in a 
manner designed to be minimally intrusive, in light of current 
technology, to detect the presence of threat items. TSA recognizes that 
individuals being searched have an expectation of privacy in their 
persons and property and requires that all TSA personnel conduct 
searches in such a way as to respect those privacy interests, while 
advancing TSA's transportation security mission.
    Administrative searches may not be conducted to detect evidence of 
crimes unrelated to transportation security. However, if such evidence 
is discovered during the normal course of a screening, TSA personnel 
refer it to a supervisor and/or a law enforcement official for 
appropriate action. TSA has specific procedures for these referrals, 
including when certain currency is discovered at checkpoints.
    TSA is looking into ways to simplify the reporting requirements 
built into screening procedures. In addition, any information reported 
to TSA's Coordination Centers may also be included in a Field 
Intelligence Officer's Field Information Report. A Field Information 
Report is a mechanism TSA uses to provide raw data to deliver valuable, 
relevant, and timely information to the DHS Intelligence Enterprise on 
transportation security operations. The raw data are not actionable in 
and of themselves; rather, it is information that may be analyzed and 
assessed for relevant patterns and trends and evaluated, in context, to 
determine the existence of actionable information.
    Law Enforcement/Federal Air Marshal Service Assistant Federal 
Security Directors--Law Enforcement, HSI Border Enforcement Security 
Team Task Force Officers, and Homeland Security Task Force Officers are 
aware of the current bulk cash issues and remain in contact with both 
TSA Security Operations personnel and law enforcement entities with a 
vested interest in the movement of the suspicious cash. Law 
Enforcement/Federal Air Marshal Service personnel will continue to 
support efforts to reduce the risk of suspicious cash flow through 
travel hubs, as permitted based on legal authorities, policy, and 
standard operating procedures.
    Question 3. Ms. McNeill, while Confirm.ID is designed to alleviate 
the burden of accommodating travelers without an acceptable form of 
identification, under what authority did TSA increase the fee and under 
which authority does TSA collect and appropriate such a fee?
    Answer. In 2006, Congress directed TSA to collect a non-refundable 
fee to cover the costs of any registered traveler program.\9\ This 
provision requires TSA to ``impose a fee for any registered traveler 
program undertaken by the Department of Homeland Security by notice in 
the Federal Register,'' provided that ``such fees shall not exceed the 
aggregate costs associated with the program.'' TSA may also modify the 
fee through notice published in the Federal Register. As exemplified by 
the 2008 Registered Traveler Interoperability Pilot Program Fee Notice, 
programs funded under registered traveler fee authority have always 
consisted of components including Secure Flight vetting, additional 
pre-vetting, and identity verification.\10\ Registered traveler 
programs consisting solely of enhanced identity verification and Secure 
Flight vetting, without additional pre-vetting, are active at 60 
airports across the Nation through public-private partnerships. As TSA 
transformed its former back-up call center into a multi-tiered 
capability for alternative identity verification, where passengers 
provide additional biographic and/or biometric information to enable 
access to expedited risk-based screening and TSA's application of 
limited screening resources to the highest-risk passengers, it was 
determined the program fit within the ``registered traveler'' category 
alongside those other programs. Therefore, consistent with the statute, 
TSA imposed a fee to recover the costs of providing this service, 
ensuring that individuals who benefit from the program rather than the 
taxpayer bear those costs.
---------------------------------------------------------------------------
    \9\ Department of Homeland Security Appropriations Act, 2006, 
Public Law 109-90, sec. 540, (119 Stat. 2064, 2088-89 (Oct. 18, 2005)) 
(codified at 49 U.S.C. 114 note).
    \10\ 73 Fed. Reg. 44275 (July 30, 2008).
---------------------------------------------------------------------------
   Questions From Honorable Timothy M. Kennedy for Ha Nguyen McNeill
    Question 1. TSA, through AbilityOne, has created employment 
opportunities for certain individuals who are blind or severely 
disabled in Upstate New York and nationwide. For example, Upstate New 
York-based non-profit organizations working under AbilityOne supply TSA 
with 1.3 million nitrile exam gloves annually.
    Please describe TSA's plans to continue use of the AbilityOne law 
to procure products. Is TSA considering expanding its use of the 
AbilityOne program?
    Answer. TSA remains committed to fulfilling its obligations under 
the AbilityOne program and continues to utilize AbilityOne to procure 
products and services, including personal protective equipment such as 
nitrile exam gloves. TSA is required to use the DHS Safety Stock 
Personal Protective Equipment Strategic Sourcing Vehicle. The 
contractor, LC Industries, partners with the Central Association for 
the Blind and Visually Impaired to support TSA's nitrile glove needs. 
Currently, TSA does not have any service contracts with AbilityOne; 
however, TSA regularly evaluates procurement strategies to ensure 
compliance with Federal requirements and to maximize opportunities for 
AbilityOne participation. Any expansion of AbilityOne use would be 
considered in accordance with DHS and Federal procurement guidelines.
    Question 2. Based on TSA's data, please outline the number of jobs 
created nationally for the blind and severely disabled who rely on TSA 
AbilityOne contracts.
    Answer. TSA does not possess data regarding this matter. For 
information regarding job creation, TSA recommends contacting the 
AbilityOne program or its affiliated non-profit agencies, as they are 
best-positioned to provide detailed employment statistics.
       Questions From Honorable Troy Carter for Ha Nguyen McNeill
    Question 1. With the rise of charter operators operating more like 
scheduled commercial airlines, are you concerned that they are skirting 
appropriate safety protocols, such as TSA screening, and creating a 
potential threat to the flying public? Can you explain what is being 
done to address this threat?
    Answer. In response to some charter operators now functioning 
similarly to scheduled commercial operations and increasing charter 
passenger volumes, TSA updated its security programs for charter 
operations to ensure comprehensive vetting and screening of passengers 
and their accessible property to mitigate potential threats to 
aviation. In addition, through regular engagements with the aviation 
community, TSA actively shares threat information, best practices, and 
lessons learned, to reinforce the shared responsibility of securing the 
national air space among pilots, air carriers, airport operators, 
fixed-base operators, and Government agencies.
    Question 2. Charter operators who act like commercial airlines 
don't have to follow the same safety protocols as commercial airlines. 
What are you doing to ensure that their growth doesn't create a safety 
risk for the traveling public?
    Answer. While the FAA is responsible for establishing safety 
protocols, TSA is committed to securing the aviation system for the 
traveling public by implementing and updating security measures for 
aircraft operators. TSA actively collaborates with charter operators 
and industry partners to enhance security within general aviation.
    TSA provides comprehensive guidance and screening frameworks and 
has updated security programs for charter operations to ensure that 
passengers are properly vetted, and their persons and accessible 
property are screened. These measures effectively mitigate potential 
threats and support the safe and secure growth of charter services.
    Question 3. Are fixed-based operators equipped to properly screen 
the growing number of passengers flying on scheduled charter 
operations? Are you concerned about their ability if this loophole 
continues to be exploited?
    Answer. There is no security loophole for scheduled charter 
operations. While Fixed-Base Operators are not required under TSA 
regulations to conduct passenger and accessible property screening, for 
private and public charter passenger operations, aircraft operators are 
required by regulation to provide for the safety of persons and 
property traveling on flights provided by the aircraft operator against 
acts of criminal violence; air piracy; and the introduction of 
explosives, incendiaries, or weapons aboard aircraft. TSA security 
programs mandate that aircraft operators implement appropriate 
screening measures at Fixed-Base Operators locations. These required 
screening measures are to prevent unauthorized access to aircraft and 
facilities, address insider threats, and mitigate misuse of aircraft.
    TSA maintains on-going oversight and enforcement of these security 
requirements, and we ensure any issues identified during compliance 
inspections are addressed in a timely manner.

                                 [all]