This morning, U.S. Senator Deb Fischer (R-Neb.), a member of the Senate Armed Services Committee and Chairman of the Subcommittee on Emerging Threats and Capabilities, questioned Secretary of Defense Ash Carter and Chairman of the Joint Chiefs of Staff General Joseph Dunford about recent cyber-attacks attributed to Russia and other state actors.
A few short hours after this morning's hearing, Yahoo Inc. announced it had been the victim of an attack by a "state-sponsored actor" in 2014. The breaking news, reported by The New York Times, revealed that the personal account information of at least 500 million users was compromised.
This information included names, email addresses, telephone numbers, birth dates, passwords, and in some cases. security questions.
Below is the full transcript of their exchange this morning:
Senator Fischer: Thank you Mr. Chairman and thank you gentlemen for your service, it is appreciated by all of us. Secretary Carter, you stated that the United States will not ignore attempts to interfere with our democratic processes, which I believe is in reference to the recent cyber-attacks on political parties, candidates, and election systems. By that do you mean that costs will be imposed on those responsible for these attacks?
Secretary Carter: Sadly, the reference is a very broad one. I made it in Europe and it was speaking to that audience very broadly to include the issue you stated which is a concern they all have, that we have at NATO. The broader category is called "hybrid warfare," it ranges from little green men to people interfering in the democratic process, that's a concern that I was discussing with allies when I was over there and it is part of the way NATO is going to have to adapt to the world as it really is. And yes, we are going to have defend ourselves against that kind of thing.
Senator Fischer: So costs would be imposed for cyber-attacks?
Secretary Carter: That is -- like any other attack.
Senator Fischer: Do you think that with regards to cyber that this should be done in a public way so that the penalties are clearly visible to other potential attackers in the future?
Secretary Carter: I certainly think that we need to defend ourselves and then take action against perpetrators when we identify them and that is an appropriate way -- I simply meant that because the perpetrators are, of cyber-attacks, and cyber intrusions, range from and cyber intrusions range from nation states to cut outs to hackers to criminal gangs and it's quite a variety and it's why our highest priority in cyber, including in our Cyber Command, is defense of our own networks.
Senator Fischer: Right. It has been widely reported that Russian hackers are responsible for the penetration that we've seen at the Democratic National Committee, those computer systems, when we look at leaks of the DNC emails and documents, I guess the questions continue to persist regarding the strength of that connection between the hackers and Russian officials, and it is generally accepted that the affiliation exists. If this is true, that there is this connection out there, what is clear is that it's, to me, another very public instance, this time using cyber where Russia continues their aggression towards this country and towards our interests, and when we have an adversary who so brazenly strikes at the heart of our democratic process, I think that indicates how low they believe the cost of that behavior is going to be. So, in other words, I think we have possibly lost the deterrence factor when it comes to cyber-attacks. Would you agree with that?
Secretary Carter: Uh, we can't lose deterrence effect ever, and with respect to Russia, one of the reasons, one of the emphases stresses we made in our budget (by the way this is one of the reasons why we would appreciate having our budget passed as is, to get back to an earlier question) is because it prioritizes something we haven't had to do, Senator, as you're stressing, for a quarter of a century. Which is, it used to be, we haven't had, as a major component of our defense strategy countering the possibility of Russian aggression, now we do. That's why we're making investments, and it ranges from cyber to the European reassurance initiative, which is one of the things that we hope doesn't get affected in budget review.
Senator Fischer: I apologize for interrupting you, the Chairman is strict on time. But dealing with, dealing with cyber, when we look at cyber, do you have plans that you have given to this administration or plans available to provide the administration with flexibility in dealing with cyber? Specifically, how do we address such attacks, whether they are from a nation-state, whether they are from organized crime, or whether they are from individuals? Are there plans out there on how these attacks are going to be addressed, whether through deterrence or actual actions? And, are those plans updated as we continue to see the expansion of cyber-attacks on this country?
Secretary Carter: That is a very good question and we're just discussing here, because there are many, many aspects to the answer to this, but yes. We have a lot of cyber capabilities that we are building, developing in all the services, and at cyber command, and we're generally for the Russians, let me ask the chairman to add something.
General Dunford: Senator, for exactly the reason you're raising, we're in the process of rewriting, at the secretary's direction, a more broad framework for dealing with Russia and contingencies associated with Russia. It's also the reason why our national military strategy now will be a classified document, because what we are trying to do is provide a strategic framework to deal with the full range of behavior that we may see from a state like Russia, China, North Korea, and Iran. And in some cases, a cyber-attack may not beget a cyber response. We want to make sure our national command authority has a full range options to deal with something that has been determined in fact a violation of our sovereignty and an attack in cyberspace. So there's really two things; 1) the strategic framework we're working on, and 2) we're also working on a full range of tools -- cyber tools -- so that we have both the ability to protect our own network and to take the fight to the enemy in cyberspace as required, our offensive cyber capability, so I would tell you that the issue you are outlining really is being addressed in both a strategic framework as well as physical tools that we are developing. But again, it's not just focused on cyber -- it's focused on providing the Secretary and the president a full range of options with which to respond in the event of an attack, again whether it be cyber or anything else.
Senator Fischer: I thank you for that and I think the deterrence aspect of cyber response is very, very important that we keep that. And also that public responses make an impression as well. Thank you, sir.