A new bill has been introduced by a bipartisan team of senators that would create a set of voluntary cybersecurity best practices for the telecommunications industry and build out an optional certification companies could obtain. U.S. Sens. Mark Warner (D-VA) and Ted Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act on Thursday, arguing that the new effort was necessary in light of the Salt Typhoon attacks which saw Chinese hackers breach nearly all of the major telecommunications giants in the U.S. over the span of several years. “The Salt Typhoon intrusion was the worst telecom hack in our nation’s history and showed us just how vulnerable our critical infrastructure is, but it does not have to be that way,” Warner said in a statement. “If telecommunications companies adopt cybersecurity best practices, our networks can be more resilient.” The bill creates a Telecommunications Cybersecurity Working Group within the National Telecommunications and Information Administration (NTIA) that would bring together telecoms, suppliers, cybersecurity experts and federal officials. The group will eventually create a set of voluntary cybersecurity best practices telecom companies can adopt to better protect their systems. The proposed bill comes nearly one year after Republican officials successfully scrapped telecom regulations originally passed in the wake of the Salt Typhoon incidents — which saw Chinese government-backed hackers gain broad, years-long access to at least nine telecommunications giants in the U.S., including Verizon, AT&T and Lumen. The intruders gained access to Call Detail Records, which provide granular data on whom a person spoke to, when, for how long, and where they were when they took the call. In some cases, the hackers were able to intercept audio and text. The hackers reportedly focused on gathering information about 150 high-profile targets including President Donald Trump, Vice President JD Vance and staff members of then-Vice President Kamala Harris, as well as other senior government leaders like Sen. Chuck Schumer (D-NY). Investigations into the incidents, prompted by bipartisan outrage, led to reports from Biden administration officials that said the Salt Typhoon campaign would have been “far riskier, harder and costlier for the Chinese” if telecoms had minimum practices, such as secure configurations, up-to-date patching, architecting to monitor for anomalous behavior that would have detected this earlier, and managing administrator accounts with multi-factor authentication. The now-scrapped rules would have mandated telecoms to better secure their networks and submit annual certifications attesting to the creation of a cybersecurity risk management plan. Warner and other Democratic officials slammed the decision to remove the rules, warning that voluntary codes with no penalties would allow the Chinese government to continue its hacking campaigns unabated. The bill introduced by Warner and Cruz on Thursday tasks the working group with creating new, voluntary rules that would “build on existing federal frameworks and threat information while focusing specifically on the telecommunications sector.” The best practices outlined by the working group would be reviewed every two years and would be updated following any major cyber incidents. The working group would also send an annual report to Congress about its work. It would also create a voluntary certification process that would allow companies to have an independent third party assess and certify that they have implemented and maintained the best practices. “Foreign adversaries are increasingly targeting America’s communications networks. Securing them requires an approach that keeps pace with evolving threats,” Cruz said. “This sensible bill brings government and industry together to develop voluntary, telecom-specific cybersecurity best practices rather than adopting rigid federal mandates that quickly become outdated.” The bill was introduced alongside a flurry of other partisan cybersecurity regulations covering artificial intelligence.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.