Skip to main content
CybersecurityInfrastructure

Senate Leaders Unveil Bill to Bolster Telecom Cybersecurity

US Senate chamber with officials and subtle network equipment in background.
“The Salt Typhoon intrusion was the worst telecom hack in our nation’s history and showed us just how vulnerable our critical infrastructure is, but it does not have to be that way,” Virginia Sen. Mark Warner said as he and Texas Sen. Ted Cruz introduced new legislation aimed at raising cybersecurity standards for telecommunications nearly two years after the Salt Typhoon campaign became public.

Warner and Cruz introduce the Telecommunications Cybersecurity and Resilience Act

Sen. Warner, the top Democrat on the Senate Intelligence Committee, and Sen. Cruz, the GOP chairman of the Commerce, Science and Technology panel, unveiled the Telecommunications Cybersecurity and Resilience Act. The pair framed the bill as a bipartisan effort to bring government and industry together on voluntary measures rather than imposing rigid federal mandates.

“If telecommunications companies adopt cybersecurity best practices, our networks can be more resilient,” Warner said. Cruz argued for a flexible, collaborative approach: “This sensible bill brings government and industry together to develop voluntary, telecom-specific cybersecurity best practices rather than adopting rigid federal mandates that quickly become outdated.”

Salt Typhoon: the intrusion that prompted action

The bill is explicitly a response to Salt Typhoon, described in the legislation’s backstory as a massive and “indiscriminate” espionage campaign blamed on a Chinese group that hit major telecom carriers and siphoned data from presidential campaigns and candidates. Federal officials, the report says, have repeatedly warned that Salt Typhoon “remains a threat to this day.”

At the same time, the report records concerns inside the cybersecurity community that momentum for stronger telecom rules has waned: “Some cyber officials have worried that public apathy over the attacks has stifled momentum for telecom security rules.” The report also notes, in one instance, “the Trump administration has rolled them back.”

Structure and timeline: an NTIA working group to build the standards

The core mechanism created by the bill is a telecom cybersecurity working group housed within the National Telecommunications and Information Administration (NTIA). The working group would bring together carriers, suppliers, experts and relevant government agencies to develop sector-wide guidance.

Under the legislation, the working group would have 18 months from the bill’s passage to produce voluntary, industry-wide best practices. Those practices would be subject to review for updates every two years or after “major incidents.” The bill directs that the best practices focus “solely on identifying, responding to, mitigating, preventing, and remediating cybersecurity incidents and vulnerabilities,” and that they align with existing federal cybersecurity risk management frameworks.

Voluntary certification and third-party assessors

Beyond setting best practices, the bill would establish a voluntary certification process. That process is intended to be administered through independent third‑party assessors that companies could choose to use. The draft frames this as an effort to create a common, telecom-specific set of practices that can evolve as threats and technology change.

A summary included with the bill argues that what is missing today “is a common, telecom sector-specific set of best practices that brings that expertise together and can evolve as threats and technology change.” The bill seeks to “build on industry’s familiarity with security development and threat information sharing” to “develop and maintain effective techniques and practices to secure networks.”

How carriers, policymakers, and suppliers are affected

  • Carriers and suppliers: The working group’s best practices and voluntary certification would give carriers and equipment suppliers a common yardstick for incident handling and vulnerability remediation, while leaving adoption optional rather than mandatory.
  • Policymakers and regulators: The legislation creates a government convening role at NTIA and prescribes a formal cadence for updates—18 months to initial guidance, then reviews every two years or after major incidents—placing a timeline on the development of telecom-specific cyber guidance.
  • Security experts and third-party assessors: The bill formalizes a role for independent assessors in a voluntary certification process, creating potential demand for third-party evaluation services aligned to the working group’s outputs.

The bill’s immediate, concrete deliverable is procedural: establish the NTIA working group and produce voluntary best practices within 18 months of passage, reviewed biennially or after major incidents. Whether the voluntary approach will alter the risk calculus inside carriers or blunt an attack group that federal officials warn “remains a threat to this day” will be seen in the uptake of those voluntary standards and any future incidents that trigger the review cycle.

Original CyberScoop story