Zero Day Room
Live
Regulation & compliance

Bipartisan Bill Proposes Voluntary Telecom Security Rules

Senators Mark Warner and Ted Cruz introduced the Telecommunications Cybersecurity and Resilience Act, creating a voluntary framework for telecom

Senators Mark Warner and Ted Cruz introduced the Telecommunications Cybersecurity and Resilience Act, creating a...

U.S. Sens. Mark Warner (D-VA) and Ted Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act on Thursday. The bipartisan bill aims to establish voluntary cybersecurity best practices and a certification process for the telecom sector through a new federal working group.

The legislation would create a telecom cybersecurity working group within the National Telecommunications and Information Administration. This group will bring together carriers, suppliers, cybersecurity experts, and federal officials. Its primary task is to develop a common, sector-specific set of voluntary best practices within 18 months of the bill's passage.

These practices would focus on identifying, responding to, mitigating, preventing, and remediating cybersecurity incidents and vulnerabilities. They must align with existing federal cybersecurity risk management frameworks. The working group is also tasked with creating a voluntary certification process where independent third-party assessors can verify a company's implementation.

A summary of the bill states that what is missing now is a common set of best practices that can evolve as threats and technology change. The best practices would be reviewed for updates every two years or after major cyber incidents. The working group will send an annual report to Congress about its progress.

Ted Cruz said: "Foreign adversaries are increasingly targeting America’s communications networks. Securing them requires an approach that keeps pace with evolving threats."

Response to Salt Typhoon and Scrapped Rules

The bill comes nearly one year after Republican officials scrapped mandatory telecom security rules. Those rules, originally passed following the Salt Typhoon incidents, would have required telecoms to better secure their networks and submit annual certifications of a cybersecurity risk management plan.

Salt Typhoon is a Chinese government-backed hacking group blamed for a massive espionage campaign. Over several years, the hackers breached nearly all major telecommunications giants in the U.S., including Verizon, AT&T, and Lumen. The intruders gained access to Call Detail Records, which provide granular data on calls, and in some cases intercepted audio and text.

The campaign reportedly focused on gathering information about 150 high-profile targets. These included President Donald Trump, Vice President JD Vance, staff members of then-Vice President Kamala Harris, and Sen. Chuck Schumer (D-NY). Biden administration officials stated that the Salt Typhoon campaign would have been far riskier and harder for the Chinese if telecoms had implemented minimum security practices.

Voluntary Approach Amid Criticism

The Warner-Cruz legislation takes the approach of improving telecom security with voluntary measures jointly developed by government and industry. Warner and other Democratic officials had previously criticized the removal of the mandatory rules, warning that voluntary codes with no penalties would allow Chinese hacking campaigns to continue unabated.

Federal officials have repeatedly warned that Salt Typhoon remains a threat. Some cyber officials have worried that public apathy over the attacks has stifled momentum for telecom security rules. The new working group will develop its voluntary industry-wide best practices within 18 months of the bill's passage and send annual reports to Congress on its progress.

Topics

#telecom

Related coverage

More from Regulation & compliance