Senators propose voluntary telecom security framework after Salt Typhoon hacks

Li Xiang/Xinhua via Getty Images

The bipartisan bill would establish cybersecurity best practices and independent certification, following the FCC’s rollback of safeguards adopted in response to the Chinese hacking campaign.

Two Senate committee leaders introduced legislation Thursday to develop voluntary cybersecurity practices for telecommunications operators, renewing efforts to protect U.S. communications networks nearly two years after the Salt Typhoon espionage campaign became public.

The Telecommunications Cybersecurity and Resilience Act, from Sens. Mark Warner, D-Va., and Ted Cruz, R-Texas, would bring government officials and industry representatives together to develop security guidance and establish a voluntary process for independently assessing companies’ adoption of those practices. Warner is vice chairman of the Senate Intelligence Committee, while Cruz chairs the Senate Commerce Committee.

The Chinese hackers compromised systems handling lawful surveillance requests as part of a broader campaign targeting communications providers and prominent political figures. The campaign has also spread worldwide.

Under the legislation, a working group within the Commerce Department’s National Telecommunications and Information Administration would develop telecom-specific best practices within 18 months of enactment. Its members would include providers, suppliers, cybersecurity experts and government agencies. CyberScoop first reported the legislation.

“The Salt Typhoon intrusion was the worst telecom hack in our nation’s history and showed us just how vulnerable our critical infrastructure is, but it does not have to be that way,” Warner said in a statement.

Cruz described the bill as a way to develop voluntary protections “rather than adopting rigid federal mandates that quickly become outdated.”

The proposal comes after the Federal Communications Commission reversed a Biden-era security measure last November that sought to protect telecom networks against unauthorized access to systems handling lawful surveillance requests. 

In reversing the measure, FCC Chairman Brendan Carr argued that the commission had misinterpreted its legal authority and pointed to carriers’ voluntary work to patch equipment, improve access controls and share threat information.

Warner criticized that decision at the time, saying Carr had provided little detail about how voluntary efforts would prevent another compromise. The new legislation would establish a more defined process for developing and assessing those practices, while leaving participation voluntary.

Congress has also struggled to obtain information about carriers’ security weaknesses following the intrusions.

Sen. Maria Cantwell, D-Wash., the Commerce Committee’s top Democrat, said in February that AT&T and Verizon had prevented cybersecurity firm Mandiant from providing network security assessments she requested. She had also called for the companies’ chief executives to testify. 

Nextgov/FCW previously reported that incident response personnel at two major U.S. telecom operators were instructed by outside counsel not to look for evidence of Salt Typhoon, according to a person familiar with the matter. The person did not identify the companies. 

The intelligence consequences may persist long after carriers secure their networks. FBI cyber intelligence official Michael Machtinger warned in February that Beijing could retain the stolen information indefinitely and combine it with other collected data for surveillance and future exploitation.