WASHINGTON, D.C. – During today’s House Appropriations Committee Subcommittee on Homeland Security hearing, Congressman Tony Gonzales (TX-23) asked Cybersecurity and Infrastructure Security Agency (CISA) Acting Director Bridget Bean about the agency’s plans to protect America’s energy industry.

 

Transcript lightly edited for clarity

 

Congressman Gonzales: The oil and gas industry is very important, not only in my district, not only to Texas, but to the United States. The Colonial Pipeline is very much on our minds. Can you briefly talk about what you're doing to make sure that our energy industry is ready for that next attack that's coming?

 

CISA Acting Director Bean: We're working with the Department of Energy and all of the sector risk management agencies…we're working with the oil and gas companies specifically to make sure that they're understanding of what is the threat to them, who is targeting them, and what can they do to help better secure themselves. What we're finding is that our nation-state actors are not using any novel techniques. They're exploiting known vulnerabilities. They are searching the internet looking for misconfiguration. They're getting in, and they're going undetected, because these living off the land kind of techniques don't leave a footprint.

 

We're trying to work with the oil and gas companies, as well as all the rest, to understand…we need to make the adversary work harder to get in…there are things that they can do to significantly, and, I mean, drastically reduce their risk. We're also providing intelligence briefings so that they better understand what exactly are we seeing…so that if we're able to give them a bit more information, we're doing that. And again, our folks on the ground who are working with those companies to understand the interconnectivity, and lastly, making sure that those who rely on the oil and natural gas understand that if something should happen, what are their contingency plans? What are those cascading impacts? We're trying to take a holistic approach to make sure that they are hardened and have a really good resiliency plan so that they can restart operations as soon as possible.

###