Two Senate committee leaders are introducing legislation to foster cybersecurity standards for the telecommunications sector nearly two years after the landmark Salt Typhoon campaign was made public.
First reported by CyberScoop, Virginia Sen. Mark Warner, the top Democrat on the Intelligence Committee, and Texas Sen. Ted Cruz, the GOP chairman of the Commerce, Science and Technology panel, are introducing the Telecommunications Cybersecurity and Resilience Act.
“The Salt Typhoon intrusion was the worst telecom hack in our nation’s history and showed us just how vulnerable our critical infrastructure is, but it does not have to be that way,” Warner said. “If telecommunications companies adopt cybersecurity best practices, our networks can be more resilient. This bipartisan legislation is a good start in protecting our nation and strengthening the communications networks Americans rely on every day.”
Federal officials have repeatedly warned that Salt Typhoon — the Chinese group blamed for the massive and “indiscriminate” espionage campaign that hit major telecom carriers and siphoned data from presidential campaigns and candidates — remains a threat to this day.
Yet some cyber officials have worried that public apathy over the attacks has stifled momentum for telecom security rules. In one case the Trump administration has rolled them back.
The Warner-Cruz legislation takes the approach of trying to improve telecom security with voluntary measures jointly developed by government and industry.
“Foreign adversaries are increasingly targeting America’s communications networks. Securing them requires an approach that keeps pace with evolving threats,” Cruz said. “This sensible bill brings government and industry together to develop voluntary, telecom-specific cybersecurity best practices rather than adopting rigid federal mandates that quickly become outdated.”
Their bill would create a telecom cybersecurity working group within the National Telecommunications and Information Administration to bring together carriers, suppliers, experts and relevant government agencies.
The working group would develop voluntary industry-wide best practices within 18 months of passage of the bill, which would be reviewed for updates every two years or after major incidents.
The best practices would “focus solely on identifying, responding to, mitigating, preventing, and remediating cybersecurity incidents and vulnerabilities,” according to the legislation, and would be in line with existing federal cybersecurity risk management frameworks.
The working group would also create a voluntary certification process through independent third-party assessors that companies could choose to use.
“What is missing” now, according to a summary of the bill, “is a common, telecom sector-specific set of best practices that brings that expertise together and can evolve as threats and technology change. Building on industry’s familiarity with security development and threat information sharing, this bill would bring stakeholders — government and private sector — together to develop and maintain effective techniques and practices to secure networks.”
The post Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks appeared first on CyberScoop.