In a pair of congressional hearings held Sept. 29 examining the current state of U.S. cybersecurity, top Defense Department and intelligence officials, as well as industry experts, all acknowledged what the Office of Personnel Management breach exposed: America is behind on cybersecurity.
The pessimistic views shared particularly by the government officials came just days after the U.S. and China announced a “common understanding” not to hack each other’s economic interests.
“I think we will have to watch what their behavior is, and it’ll be incumbent on the intelligence community, I think, to depict [and] portray to policymakers what behavioral changes — if any — result from this agreement,” Director of National Intelligence James Clapper told the Senate Armed Services Committee.
When asked by committee chair Sen. John McCain (R-Ariz.) if he was optimistic about a cyber deal with China, Clapper gave an emphatic “no.”
Adm. Michael Rogers, commander of U.S. Cyber Command and director of the National Security Agency, told the committee he believes China to be the biggest perpetrator of the volumes of attacks barraging U.S. networks, and the military is struggling to keep up, even as the services train up their forces to fight in cyberspace.
“The demand for our cyber forces far outstrip the supply,” Rogers said.
On the other side of the Hill, in a House Armed Services Committee hearing, a panel of industry experts weighed in with their perspectives on how the Defense Department is doing in cyberspace. In general, they agreed with Clapper and Rogers, particularly when it comes to the pervasive theft of intellectual property.
With cyberattacks being an inevitability, DoD leaders need to determine first how much risk they can tolerate, according to Richard Bejtlich, chief security strategist at FireEye.
“What is acceptable level of loss for this country? [For example], every store accepts a certain amount of theft…we accept in geopolitics a certain level of instability,” Bejtlich said, noting the U.S. currently tolerates a lot now, including intellectual property theft. “Do we want to push back on that? That to me is the central question — what is the acceptable level of loss and what’s the definition of that loss?”
In his written testimony, Clapper agreed, but noted that the government has to approach risk tolerance differently from the private sector.
“The cyber threat cannot be eliminated; rather, cyber risk must be managed,” he said. “Moreover, the risk calculus employed by some private-sector entities does not adequately account for foreign cyber threats or the systemic interdependencies between different critical infrastructure sectors.”
The New America Foundation’s Ian Wallace noted that the U.S. may need to look at its other core strengths if it’s losing the battle in cyberspace — and the technological edge.
Those other strengths could be “the ability to build alliances, the quality of our people,” Wallace said. “But that doesn’t happen by accident…that requires investment.”
Back on the Senate side, McCain underscored what turned out to be a theme for both hearings, and likely those to follow on Sept. 30.
“Make no mistake, we are not winning the fight in cyberspace,” McCain said.
RELATED: Homeland Security Secretary Jeh Johnson and DISA Director LTG Alan Lynn will appear as keynote speakers at C4ISR & Networks and Federal Times’ CyberCon 2015, held Nov. 18 at the Ritz Carlton-Pentagon City in Arlington, Virginia.




