On the recordMay 19, 2021
As I rise, gasoline is once again flowing through the Colonial Pipeline, and we are getting ready to undertake our routine briefs--those of us who sit on the Intelligence Committee and the Committee on Homeland Security--of this week's cyberattacks. Many of them will have come from Russia, from China, from North Korea, from Iran, or from some shadowy criminal group, which is often sheltered or at least tolerated by one of these countries. Many will have succeeded in stealing critical data or penetrating essential networks. Only a few, like the recent attacks on the Colonial Pipeline, will ever become publicly known. There is a long list of things that we must do to stop these attacks. We should require private companies to tell the public, or at least the government, when these attacks occur. We should make sure that experts in places like the NSA and the FBI are working side-by-side with network operators to address these attacks, and we should have a clear policy on the payment of ransom to ransomware attacks. But at the very top of the list is the need to fundamentally change the game by establishing a sure and swift deterrence. Time and again, we do too little, too late.…





