Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
Senators Warner and Cruz introduced a bill for voluntary telecom cybersecurity standards after the Salt Typhoon campaign.
Senate Intelligence Vice Chairman Mark Warner and Commerce Chairman Ted Cruz introduced the Telecommunications Cybersecurity and Resilience Act. It would create an NTIA working group of carriers, suppliers, experts, and agencies to write voluntary telecom cybersecurity best practices within 18 months, with reviews every two years or after major incidents. The bill also proposes an optional third-party certification aligned with existing federal risk frameworks. It follows Salt Typhoon, the Chinese espionage campaign that compromised major U.S. carriers and collected data tied to presidential campaigns.
- Warner and Cruz proposed the Telecommunications Cybersecurity and Resilience Act.
- An NTIA group would draft voluntary telecom best practices within 18 months.
- Companies could seek optional certification from independent third-party assessors.
- The bill responds to Salt Typhoon espionage against U.S. telecom carriers.
Full article698 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The legislation from Senate Intelligence Vice-Chairman. Mark Warner, D-Va., and Senate Commerce Chairman Ted Cruz, R-Tex., would create a government-industry group to write voluntary best practices.
Listen to this article
0:00
Learn more.
Two Senate committee leaders are introducing legislation to foster cybersecurity standards for the telecommunications sector nearly two years after the landmark Salt Typhoon campaign was made public.
First reported by CyberScoop, Virginia Sen. Mark Warner, the top Democrat on the Intelligence Committee, and Texas Sen. Ted Cruz, the GOP chairman of the Commerce, Science and Technology panel, are introducing the Telecommunications Cybersecurity and Resilience Act.
“The Salt Typhoon intrusion was the worst telecom hack in our nation’s history and showed us just how vulnerable our critical infrastructure is, but it does not have to be that way,” Warner said. “If telecommunications companies adopt cybersecurity best practices, our networks can be more resilient. This bipartisan legislation is a good start in protecting our nation and strengthening the communications networks Americans rely on every day.”
Federal officials have repeatedly warned that Salt Typhoon — the Chinese group blamed for the massive and “indiscriminate” espionage campaign that hit major telecom carriers and siphoned data from presidential campaigns and candidates — remains a threat to this day.
Yet some cyber officials have worried that public apathy over the attacks has stifled momentum for telecom security rules. In one case the Trump administration has rolled them back.
The Warner-Cruz legislation takes the approach of trying to improve telecom security with voluntary measures jointly developed by government and industry.
“Foreign adversaries are increasingly targeting America’s communications networks. Securing them requires an approach that keeps pace with evolving threats,” Cruz said. “This sensible bill brings government and industry together to develop voluntary, telecom-specific cybersecurity best practices rather than adopting rigid federal mandates that quickly become outdated.”
Their bill would create a telecom cybersecurity working group within the National Telecommunications and Information Administration to bring together carriers, suppliers, experts and relevant government agencies.
The working group would develop voluntary industry-wide best practices within 18 months of passage of the bill, which would be reviewed for updates every two years or after major incidents.
The best practices would “focus solely on identifying, responding to, mitigating, preventing, and remediating cybersecurity incidents and vulnerabilities,” according to the legislation, and would be in line with existing federal cybersecurity risk management frameworks.
The working group would also create a voluntary certification process through independent third-party assessors that companies could choose to use.
“What is missing” now, according to a summary of the bill, “is a common, telecom sector-specific set of best practices that brings that expertise together and can evolve as threats and technology change. Building on industry’s familiarity with security development and threat information sharing, this bill would bring stakeholders — government and private sector — together to develop and maintain effective techniques and practices to secure networks.”
Latest Podcasts
Government
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems
ShinyHunters claims attack on FBI exposes almost all agents
After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program
Technology
Threats
Ryuk ransomware operator sentenced to 2 years in prison
Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
Early Scattered Spider member pleads guilty to cybercrime spree