HSDF THE PODCAST

Congressional Cybersecurity Priorities Part 1

Kevin Long

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 21:42

Welcome to our “TUESDAY EDITION of HSDF THE PODCAST,” a collection of policy discussions on government technology and homeland security brought to you by the Homeland Security and Defense Forum

 In this two part episode, examine why vulnerability management is buckling under the scale of modern discovery and what it takes to modernize the CVE and NIST NVD pipeline without slowing down response. We also connect the dots between AI governance, public-private partnership, and quantum readiness so we can build trust and security before the next leap in capability.

Featuring: 

  • Moira Bergin, Subcommittee Director/Counsel, Subcommittee on Cybersecurity and Infrastructure Protection, Committee on Homeland Security 
  • Casey Dolen, Professional Staff Member, Subcommittee on Cybersecurity and Infrastructure Protection, Committee on Homeland Security
  • Alan McQuinn, Professional Staff Member, Subcommittee on Research and Technology, House Committee on Science, Space and Technology
  • Emily Park, Professional Staff Member, Senate Homeland Security and Governmental Affairs Committee 
  • Frank Cilluffo, Director, McCrary Institute (moderator)

 This discussion took place June 10th, 2026, at HSDF’s Cyber Symposium

Follow  HSDF THE PODCAST and never miss latest insider talk on government technology, innovation, and security.  Visit the HSDF YouTube channel to view hours of insightful policy discussion.  For more information about the Homeland Security & Defense Forum (HSDF), visit hsdf.org.

Why Tech Outruns Policy

SPEAKER_04

Awesome. Thank you, Megan, and congrats on a great day today. Really excited about this conversation. I'm sure it's a little difficult for some of those following the chairs and their bosses on Capitol Hill, but but I know we couldn't ask for a better panel than the one we have today. I think one consistent theme, at least as long as I've been here today, that we're seeing is technology is moving faster than policy, than institutions, and sometimes the governance structures that are the wrapper around all of that. And one of the things that I'd like to zero in on today are the congressional priorities for the remainder of 2026, what we think actually has uh likelihood. I'm not asking for, I know there are all these gambling sites now. I'm not asking anyone to try to guess what the what the actual number of passage of different bills are, but generally speaking, what we think can get over the goal line. A little discussion on emerging technology, not only artificial intelligence and some of the executive orders we're seeing pop out there, but I also want to touch on quantum and other priorities Congress may have in the tech space. Then take a little look at strategic competition, take a look at critical infrastructure, where we stand in some of those areas, and then finally, time permitting, what the future looks like. And I love to quote Yogi Berra, which works in a US context, not always overseas, but the future ain't what it used to be. And all these people here are shaping it, though, what it can be and what it ought to be. So I want to start with, and we can start with Moira and then go down the line, and then we'll flip it in other directions for pre-next questions. But where are we in 2026? What do we hope to get over the goal line? And what are you excited about? And what are you concerned about?

SPEAKER_01

I'm a little bit excited for recess next week, but I don't think that's what you're interested

CISA Extension And Cyber Grants

SPEAKER_01

in. So at a high point, I think we would put it in two buckets. So we have some what I would consider housekeeping matters, and then we have some more future proofing matters. So in the housekeeping matters, we have the extension of CISI 2015 winway. I don't know what that means, but some of the I'm sure there's a story that we will learn soon. But congratulations on getting that into NDAA. That's incredibly important as a top priority for all of our members. I think it's a bipartisan priority. Looking forward to getting that across the finish line so that we aren't doing this again next year. Same thing goes with state and local cyber grants, was encouraged to see funding in the appropes bill. That's something that our members championed on a bipartisan basis in 2021. And we're very glad to see the progress that the grant investments have made in driving down risk across state and local governments, but there's still a lot of work to do. That initial billion dollars was just level setting about understanding where we are in cybersecurity in state and local governments and what where we need to plus up. And with the advent of mythos and other frontier models, it just accelerates the need to really roll out the tools that can keep state and local governments secure and keep the services that they provide our constituents every day functioning. So that would be another level setting housekeeping matter that we want to maintain. Related to that, is last year when I was here, we talked about the staffing changes at CISA. We're still concerned about the staffing changes. I will say that over the past year, especially over the past four months with the new leadership, we have gotten a lot more information from CISA. There's been, they've been a lot more responsive to us about what their staffing look like, looks like, what needs they have. Obviously, they're being very proactive about onboarding staffing. The acting director has set good goals for onboarding people in short timelines, which we're happy to see. We want to support that. We want to understand where we're staffing people though. What we're still looking for is more discrete information about what programs took the biggest hits when people left and took the fork last year. Relatively, we're still looking for information about where the contracts that were ended last year affected operations. So those are just the housekeeping matters because it's hard to build on an agency when you don't know what you're working with. So we got to know what cards we're holding. And so that's a very big priority for us over the next six months as we gear up for the next Congress. Whatever that looks like, we want to make sure that we're ready out of the gate.

Modernizing CVE And NVD Programs

SPEAKER_01

In terms of future proofing, and this sort of straddles both buckets is our committee is working with Alan over here on legislation to authorize the CVE program. We all remember last year, the fire drill that we had when we thought that the program wasn't going to be funded anymore. We're happy to see that it is funded. But as we work together to figure out how to stabilize funding for the program, we learned through very passionate feedback about a program I didn't realize there was so much passion about. It's not exactly a kitchen table issue, but a lot of passion about how the CVE program is operated, a lot of concerns that came up about how it was on autopilot for quite a period of time and the need to modernize the program, particularly once again, in the advent of these frontier models that are discovering vulnerabilities at a very rapid pace. We really need to make sure that we are well prepared to understand what the vulnerabilities mean for the systems that we rely on every day, how they can be chained together to have vulnerabilities that we didn't expect to be so sophisticated or so severe, and then prioritize patching effectively. NVD's prioritization, I think, is a step in the right direction, but we really need to be ready so that we can be secure as technology evolves. So that's where we are now. We're hopeful that Don. I'm sorry, it took so much time.

SPEAKER_04

No, that was great. Thank you, Mau. Casey, anything you want to do.

SPEAKER_00

Yes, Maura really covered it great with WimWeg being one of our primary priorities, obviously. And I think the chairman spoke to that as well. Happy to see that in NDAA. Um, and then also state and local cybersecurity grant program, our subcommittee chairman, Andy Ogles, put forth his Pillar Act, which passed the House in November of last year. We were happy to see the 50 million allocated to the states. I think we still have a ways to go, but hosting a hearing just a couple of weeks ago, bringing in state and local cyber officials to be able to illuminate how they've been spending the money, what's been successful, how the threat landscape has changed, and really make it clear to our members and others that states should not be going toe-to-toe against nation-state adversaries. And the federal government certainly has a role to play there. Eager to see how that moves in the Senate and what additional support we can get there. We've really been focused on AI, as is no surprise. If you look at our website, Mora knows, we've been super busy with hearings and roundtables. So we've been holding a series of closed-door roundtables with Frontier AI labs, startups, cybersecurity companies to talk about the topic of the day. We've been having these about monthly closed door sessions with the full committee. They've been super well attended. And each iteration of these roundtables comes with a new issue. Mythos obviously has been top of mind and what that looks like for federal government access and where we need to go once we have access. What does that mean for patching timelines and things like that? So that's been a really great series. And we're looking forward to building on that, putting pen to paper based off of a lot of the groundwork we've laid in terms of those roundtable series and the hearings we've held on a number of topics.

SPEAKER_04

Thank you, Alan.

SPEAKER_03

Hey, folks, thank you for having me. I might seem like a little bit of an odd duck on this panel with this distinguished panel with operational cybersecurity experts, right? What does the science committee do in cybersecurity? We do a lot, actually. We're more on the standards and guidelines and workforce side of the equation. But our committee oversees the National Institute of Standards and Technology, whom you all know. We oversee the National Science Foundation, OSTP, and we're really focused on a lot of the critical and emerging technologies. While AI is a very big topic over the last few years, our committee actually passed the first AI bill back in 2020, the National AI Initiative Act of 2020, that created a lot of the intergovernmental structures that are still around today for how we think about AI, how we do RD development and testing for these programs. It created the NIST RMF for AI, for example. We've been focused on a lot of these challenges. I think our three main priorities related to cybersecurity, this Congress, are thusly. First, we recently reauthorized the National Quantum Initiative Act. It passed through our committee. There are a lot of components in this related to cybersecurity. I'm sure you all are quite aware of the post-quantum cryptography PQC standards that NIST put together a couple years ago. We're trying to think about how to move the ball on getting those, getting the transition ready for people to adopt those standards broadly. Right now, especially in the federal government, implementation has been, you know, not that great. And but I'm happy to talk more about quantum later. Another major priority of our committee has been on the AI side of the equation. We haven't passed any AI bills in the last couple of years since the Chat GPT moment, despite passing 13 AI bills out of our committee last Congress. We're hopeful that in the next six weeks or so, we're gonna have another markup with a lot of AI bills that are top-of-mind big priorities. Some that relate directly to cybersecurity, some that relate to workforce development, some that relate to other things that are related. For example, we will likely consider an authorization of Casey, the Center for AI Standards and Innovation at NIST. Sorry, they changed the name recently. I'm trying to get the acronym down, that does a lot of the evaluations for capabilities of what, including cyber capabilities of frontier model systems. Another one that we're looking at is related to vulnerability management. So a lot of the programs that exist currently that Maura talked about, the CVE program and the NVD program, they're not optimized for AI-related vulnerabilities for AI systems specifically, data poisoning, for example. And we're looking at legislation that can help figure out where there are missing opportunities, how to square that circle and make sure that our existing cybersecurity processes are ready for the AI moment. And then, yeah, I'll just foot stomp on everything Maura said around the CVE program and the NVD program. How can we modernize and make sure that these programs are sustainable going forward? Because they're incredibly critical to everyone's cybersecurity, and we want to make sure that lapses like what happened last year for the CVE program and kind of the breakdown of the NVD program over the last few years due to the exponential rise in discovered vulnerabilities don't happen again.

SPEAKER_04

So I just wanted to recognize that and obviously the amazing work you've done to make that happen. So please go ahead.

SPEAKER_02

Yeah,

Senate Priorities Satellites And CIRCIA

SPEAKER_02

I a lot of the priorities for Senator Peters as former chair, now ranking member of Senate Committee on Homeland Security and Governmental Affairs, His GAC, we share a lot of the jurisdiction that some of the other folks have here. So we get to share a lot of these priorities and prioritization of efforts. So quickly running down on what we're expecting, what we're excited about for 2026, which yes, unfortunately will be Senator Peters last year in the Senate. He has decided to not run for re-election. And he will go on to do much more amazing, better, fantastic things that he is also very excited about. So first and foremost, for Senator Peters, getting a long-term extension of CISA 2015, I think just about everybody up here is we're all rowing that canoe as best we can. It's really critical for industry, really critical for our cyber defenders across the nation. We want to make sure that the folks who are doing the defending from some of these significant cyber attacks have the legal assurances necessary to do their job on a daily basis without necessarily the involvement of a bunch of lawyers. So that's far and away number one. Number two, making sure that there is appropriate funding for our agencies such as CISA and MIST, making sure there's personnel in place to do the job that they need to do to meet congressional intent for the agencies as established. And that also goes towards making sure that some of the programs, like state and local cybersecurity grant program, have the appropriate level of funding to make sure that states and locals can continue to do that hard work to defend themselves from some of the emerging cyber threats that we're seeing. And the third bucket would be some new fun work that we've started to do over the last two years. And that would be mostly on the commerce side. So that's moving a satellite cybersecurity bill, which got marked up a couple months ago in Senate Commerce. And that would authorize a voluntary information sharing platform between commercial satellites, cyber commercial satellite owners and operators and connect them with cybersecurity resources so that there's fewer vulnerabilities in those some of those critical satellite systems that we rely on every single day. And FORS would just be continuing to get some of the legacy items across the finish lines. That would be looking forward to that final rule for critical infrastructure incident reporting for Circia, which some other folks over here are looking forward to as well, making sure that final rule meets the congressional intent when the bill was signed into law to create this authority, and ensuring that critical infrastructure owners and operators understand these requirements that may come down from the Circia final rule and helping them making sure they have the opportunity to give the appropriate feedback. So that's the four big things for this year.

SPEAKER_04

Awesome. Thank you, Emily.

AI Executive Order Praise And Pushback

SPEAKER_04

And I want to jump to the emerging technology discussion. We'll start with you and go down the line this time. And the president recently promulgated an executive order around AI that had a tough balance between innovation and security. Firstly, I'd be curious what your overall take is on the executive order. Did they find that Goldilocks happy medium, or should it shift in one direction or another from your perspective? And then secondly, what do you think the biggest implementation challenges will be? So, as with any major directive, whether an executive order, a presidential decision directive, or the like, one thing to get it on paper and get people to agree, not always the same to implement and execute. So I'd be curious what your thoughts are, and we'll go down the line.

SPEAKER_02

It was clear that there was some interesting choices made. So just looking for how this AI executive order actually will be implemented, I think is key. Top level, there were some good things that made it clear that the team in this administration is taking somebody's threats very seriously, which we like to see. But just making sure that long term this doesn't just become like John Rackler, by the way.

SPEAKER_04

CIA's in the room. I had plenty of money. Sorry.

SPEAKER_02

So just making sure that, you know, that actual implementation guidance is something that's reasonable and doable. And I will say that is one of the big sticklers for Senator Peters, is he has repeatedly said that you can have the loftiest goals possible in some of these executive orders, but if you don't have the personnel at the agencies with the expertise and know-how to carry out these actions, then what are you actually doing there? You have an agency that's tasked with a purpose, with a mission that is unimplementable because you don't have the right people in the room. And unfortunately, we've seen a lot of departures at federal agencies like SISA at NIST. And so that's been one of the big focuses is yes, and AI exhort AI executive order and making sure you have the right people in the room.

SPEAKER_04

Thanks, Emily. Alan? Is that Brad Pitt?

SPEAKER_03

Um so uh I haven't talked to my boss about the executive order yet. So these opinions are my own. And I would definitely lean on my colleagues who have more operational experience in this area than I do. I'll say a couple of comments up top. Uh, first, the executive order and the following NSM seem to downplay the role of the Department of Commerce, where a lot of this expertise exists, especially at Casey, in the evaluations of these systems. And it they seem to empower agencies I wouldn't normally associate with having expertise over ones that do, like the Department of Treasury over CISA or MIST. They seem concerning to me for two reasons. First, we have spent a lot of resources to create that nexus of intelligence at Casey to be able to do some of this analysis and and to not utilize that seems uh misappropriate. It seems not appropriate. I would also just say that uh we want to continue to get more resources into Casey to be able to do this type of work, and I think that aligns with what the president is trying to do with the executive order. I also say that it takes some of this work that should be done in the limelight out and makes it more on the secret side. And I'm not saying that it's not appropriate to have secret or top secret research to understand and assess capabilities, but there's less of a ability for Congress and the and public to understand what those capabilities are if we're focused primarily on the IC.

SPEAKER_00

Yeah, so a couple thoughts from my perspective. So I think whenever cybersecurity is elevated to a West Wing kind of priority, we see an executive order sign. That's really encouraging. And so I think the AI executive order lays out that public-private partnership is foundational to a lot of these efforts. And I think, again, we're seeing the stuff that we have been saying for years, the models that we know work continuing to shine through, and especially bringing in that clearinghouse framework. I think we're going to be really interested to see how that plays out in effect. I think, yeah, we share some questions about Treasury's role versus CISA's. And we have members who have expressed an interest in seeing that CISA maintain a coordination role. They bring expertise, they have teams that are equipped to do this. They, in our view, are the ones that we really want to see them empowered in this role. So again, I think a step in the right direction. I'm still hopeful to see additional actions come out of that in other forms. Not everything has to be in executive order for things to get done in the F subs. That's certainly, I think, the perspective that we're bringing to this.

SPEAKER_01

I would say that much like my colleagues have said, some direction is better than no direction, which is where we were two weeks ago. Having said that, very early in the administration, the president rescinded President Biden's AI executive order, which dictated policy not only on cybersecurity, but impacts on workforce, privacy and civil liberties, innovation, et cetera. This was a very narrow executive order that leaves a lot of other really important issues related to AI still on the table. So I think that's a concern for many of our members, number one. Number two, as my colleagues have also said, the delegation of certain authorities to Department of Treasury is bizarre. It's clearly personality driven, in my view. And I'm not an expert on this administration, so take it with a grain of salt. But I think the logic that the financial services industry is advanced on this, so we should just give it to Treasury denies like decades worth of doctrine about which agencies carry out different roles and responsibilities. And that's not how we make policy that endures over time. So putting an AI cybersecurity clearinghouse at Treasury instead of CISA to me makes no sense when CISA already is responsible for cataloging vulnerabilities however they're found, whether they're found through AI or found some other way. Similarly, as Alan mentioned, NIST has expertise in evaluating AI models. So why you would have Treasury leading on the framework to evaluate whether or not something is a frontier model, NSA dictating that it is a frontier model, and then a host of people led by Treasury deciding who gets access to these models on a voluntary basis doesn't to me make a ton of sense. And it ignores the expertise that exists across government. I think, but it also ignores as we rush to deploy these models across the federal government, is that we are missing talent in CIO offices that would be responsible for deploying these tools. And so we don't know how we're deploying them securely and who's writing the governance models for AI deployment at these agencies. And that's really important. Otherwise, we're going to have people using shadow AI. So I think, I think it's a step in the right direction. And I'm glad they got something out. I think it from our perspective, it would be an interesting opportunity to collaborate and engage more with the executive branch on the direction they continue to take this in and see if we can't course correct a little bit on some of the roles and responsibilities in the

Transparency And The Intelligence Community

SPEAKER_01

executive order. I also agree with Alan on the NSM from or NPSM. I can't remember the acronym now, but we all know what I'm talking about released last Friday about the focus on the IC role in AI and wanting to make sure that there's transparency in how the government is evaluating these.