Salt Typhoon prompts bill for voluntary telecom cyber rules
Two US senators from opposite parties want the telecommunications industry to follow a common set of cybersecurity best practices. Adoption would be voluntary, and there would be an optional certification for companies that can show they follow them.
Sens. Mark Warner (D-VA) and Ted Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act on Thursday. They pointed to the Salt Typhoon campaign, in which Chinese hackers broke into nearly all of the major US telecom providers over several years.
“The Salt Typhoon intrusion was the worst telecom hack in our nation’s history and showed us just how vulnerable our critical infrastructure is, but it does not have to be that way,” Warner said. “If telecommunications companies adopt cybersecurity best practices, our networks can be more resilient.”
A working group inside NTIA
The bill sets up a Telecommunications Cybersecurity Working Group within the National Telecommunications and Information Administration (NTIA), the US federal agency that deals with telecom and information policy. Telecom operators, their suppliers, cybersecurity experts and federal officials would sit on the group.
Its main job is to write voluntary best practices that carriers can use to harden their systems. According to the bill, these should “build on existing federal frameworks and threat information while focusing specifically on the telecommunications sector.”
The practices would be reviewed every two years and updated after any major cyber incident. The group would also report to Congress once a year.
A second part of the bill covers certification. Companies could have an independent third party assess whether they have put the best practices in place and kept them up, and certify them if so. This step is also optional.
“Foreign adversaries are increasingly targeting America’s communications networks. Securing them requires an approach that keeps pace with evolving threats,” Cruz said. He described the bill as a way to bring government and industry together “rather than adopting rigid federal mandates that quickly become outdated.”
What Salt Typhoon took
The Chinese government-backed hackers behind Salt Typhoon had broad, long-term access to at least nine US telecom companies, including Verizon, AT&T and Lumen.
They reached Call Detail Records. These show who a person talked to, when, for how long, and where they were during the call. In some cases the attackers could also intercept audio and text messages.
The operation reportedly focused on about 150 high-profile targets. Among them were President Donald Trump, Vice President JD Vance, staff of then-Vice President Kamala Harris, and senior officials such as Sen. Chuck Schumer (D-NY).
Biden administration officials investigated the breaches after anger from both parties. They concluded that the campaign would have been “far riskier, harder and costlier for the Chinese” if carriers had followed basic practices. The measures they listed included secure configurations, current patching, network designs that watch for anomalous behavior, and multi-factor authentication on administrator accounts.
From mandates to voluntary rules
The new bill arrives almost a year after Republican officials scrapped telecom regulations that had been adopted in response to Salt Typhoon. Those rules would have required carriers to better secure their networks and to certify every year that they had a cybersecurity risk management plan.
Warner and other Democrats criticized the repeal. They warned that voluntary codes without penalties would let Chinese hacking campaigns continue unchecked. Warner is now co-sponsoring a voluntary approach himself.
The bill was introduced alongside a number of partisan cybersecurity proposals on artificial intelligence.
Our Take
The bill shows that there is still bipartisan interest in telecom security, but the question of enforcement is still open. Warner warned last year that codes without penalties would not stop Chinese intrusions. His support for a voluntary framework now suggests the aim is to get something passed instead of nothing.
For defenders, the controls named after Salt Typhoon are not new: patching, secure configuration, monitoring and MFA for admin accounts. Unpatched network equipment remains a common entry point, as the actively exploited Check Point VPN flaw shows. It is worth watching whether carriers actually seek the third-party certification, whether customers or government buyers start asking for it, and whether the bill makes it through Congress at all. Telecom networks are also under physical pressure elsewhere. That is a reminder that resilience covers more than intrusion prevention.
Sponsored Recommended for you – discover more →
