Bipartisan Bill Aims to Bolster Telecom Cybersecurity After 'Salt Typhoon' Attacks
A new bipartisan bill, the **Telecommunications Cybersecurity and Resilience Act**, has been introduced in the U.S. Senate, seeking to establish voluntary cybersecurity best practices and an optional certification process for the telecommunications industry. This initiative comes in the wake of the extensive 'Salt Typhoon' attacks, which saw Chinese state-sponsored hackers compromise major U.S. telecom providers.
U.S. Senators **Mark Warner** (D-VA) and **Ted Cruz** (R-TX) have introduced legislation designed to fortify the cybersecurity posture of America's critical telecommunications infrastructure. The **Telecommunications Cybersecurity and Resilience Act** proposes a framework of voluntary best practices and a certification program, a direct response to the sophisticated 'Salt Typhoon' intrusions.
### The Shadow of Salt Typhoon
Senator Warner emphasized the urgency, stating, "The **Salt Typhoon** intrusion was the worst telecom hack in our nationβs history and showed us just how vulnerable our critical infrastructure is, but it does not have to be that way." The 'Salt Typhoon' campaign involved Chinese government-backed hackers gaining years-long, broad access to at least nine major U.S. telecommunications giants, including **Verizon**, **AT&T**, and **Lumen**.
The attackers reportedly focused on collecting Call Detail Records, which reveal extensive metadata about communications, and in some instances, intercepted audio and text. High-profile targets included former President **Donald Trump**, Vice President **JD Vance**, and staff members of then-Vice President **Kamala Harris**, alongside other senior government leaders like Senator **Chuck Schumer** (D-NY).
Investigations following the incidents highlighted that the 'Salt Typhoon' campaign would have been "far riskier, harder and costlier for the Chinese" had telecoms implemented basic cybersecurity measures such as secure configurations, timely patching, robust monitoring for anomalous behavior, and multi-factor authentication for administrator accounts.
### A New Approach to Resilience
The proposed bill seeks to establish a **Telecommunications Cybersecurity Working Group** within the **National Telecommunications and Information Administration (NTIA)**. This group will convene telecoms, suppliers, cybersecurity experts, and federal officials to develop a set of voluntary cybersecurity best practices tailored for the sector.
These best practices will be reviewed biennially and updated in response to significant cyber incidents. The working group will also submit annual reports to Congress, detailing its progress and findings.
### Voluntary Certification and Industry Collaboration
Crucially, the bill introduces a voluntary certification process. This mechanism would allow telecommunications companies to engage an independent third party to assess and certify their adherence to the established best practices. Senator Cruz underscored the importance of this collaborative, adaptable approach: "Foreign adversaries are increasingly targeting Americaβs communications networks. Securing them requires an approach that keeps pace with evolving threats... This sensible bill brings government and industry together to develop voluntary, telecom-specific cybersecurity best practices rather than adopting rigid federal mandates that quickly become outdated."
This legislative effort follows the scrapping of previous telecom regulations nearly a year ago, which had mandated network security improvements and annual cybersecurity risk management plan certifications. Critics of the earlier repeal had warned that a purely voluntary framework might not sufficiently deter state-sponsored hacking campaigns.
### Broader Legislative Context
The **Telecommunications Cybersecurity and Resilience Act** is part of a broader legislative push, introduced alongside other cybersecurity regulations addressing emerging threats, including those related to **artificial intelligence**.