Lawmakers introduce bill for voluntary telecom cyber rules after Salt Typhoon hacks
Sens. Warner and Cruz introduced a bill for voluntary telecom cybersecurity practices after Salt Typhoon.
U.S. Sens. Mark Warner and Ted Cruz introduced the Telecommunications Cybersecurity and Resilience Act to create voluntary cybersecurity best practices and an optional third-party certification for telecom companies. The bill would form a working group inside the NTIA to draft sector-specific practices, review them every two years, and report annually to Congress. It follows Salt Typhoon, in which China-backed hackers held years-long access to at least nine U.S. carriers, including Verizon, AT&T, and Lumen, collecting call detail records and sometimes intercepting audio and text tied to about 150 high-profile targets. The proposal comes nearly a year after earlier mandatory telecom cybersecurity rules adopted after those intrusions were scrapped.
- Warner and Cruz introduced the Telecommunications Cybersecurity and Resilience Act.
- An NTIA working group would draft voluntary telecom cybersecurity best practices.
- Optional third-party certification would confirm companies follow those practices.
- Salt Typhoon accessed at least nine U.S. carriers, including Verizon, AT&T, and Lumen.
- Earlier mandatory post-Salt Typhoon telecom cyber rules were later scrapped.
Full article653 words · extracted from therecord.media · click to collapse
A new bill has been introduced by a bipartisan team of senators that would create a set of voluntary cybersecurity best practices for the telecommunications industry and build out an optional certification companies could obtain. U.S. Sens. Mark Warner (D-VA) and Ted Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act on Thursday, arguing that the new effort was necessary in light of the Salt Typhoon attacks which saw Chinese hackers breach nearly all of the major telecommunications giants in the U.S. over the span of several years. “The Salt Typhoon intrusion was the worst telecom hack in our nation’s history and showed us just how vulnerable our critical infrastructure is, but it does not have to be that way,” Warner said in a statement. “If telecommunications companies adopt cybersecurity best practices, our networks can be more resilient.” The bill creates a Telecommunications Cybersecurity Working Group within the National Telecommunications and Information Administration (NTIA) that would bring together telecoms, suppliers, cybersecurity experts and federal officials. The group will eventually create a set of voluntary cybersecurity best practices telecom companies can adopt to better protect their systems. The proposed bill comes nearly one year after Republican officials successfully scrapped telecom regulations originally passed in the wake of the Salt Typhoon incidents — which saw Chinese government-backed hackers gain broad, years-long access to at least nine telecommunications giants in the U.S., including Verizon, AT&T and Lumen. The intruders gained access to Call Detail Records, which provide granular data on whom a person spoke to, when, for how long, and where they were when they took the call. In some cases, the hackers were able to intercept audio and text. The hackers reportedly focused on gathering information about 150 high-profile targets including President Donald Trump, Vice President JD Vance and staff members of then-Vice President Kamala Harris, as well as other senior government leaders like Sen. Chuck Schumer (D-NY). Investigations into the incidents, prompted by bipartisan outrage, led to reports from Biden administration officials that said the Salt Typhoon campaign would have been “far riskier, harder and costlier for the Chinese” if telecoms had minimum practices, such as secure configurations, up-to-date patching, architecting to monitor for anomalous behavior that would have detected this earlier, and managing administrator accounts with multi-factor authentication. The now-scrapped rules would have mandated telecoms to better secure their networks and submit annual certifications attesting to the creation of a cybersecurity risk management plan. Warner and other Democratic officials slammed the decision to remove the rules, warning that voluntary codes with no penalties would allow the Chinese government to continue its hacking campaigns unabated. The bill introduced by Warner and Cruz on Thursday tasks the working group with creating new, voluntary rules that would “build on existing federal frameworks and threat information while focusing specifically on the telecommunications sector.” The best practices outlined by the working group would be reviewed every two years and would be updated following any major cyber incidents. The working group would also send an annual report to Congress about its work. It would also create a voluntary certification process that would allow companies to have an independent third party assess and certify that they have implemented and maintained the best practices. “Foreign adversaries are increasingly targeting America’s communications networks. Securing them requires an approach that keeps pace with evolving threats,” Cruz said. “This sensible bill brings government and industry together to develop voluntary, telecom-specific cybersecurity best practices rather than adopting rigid federal mandates that quickly become outdated.” The bill was introduced alongside a flurry of other partisan cybersecurity regulations covering artificial intelligence.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.