Warner, Cruz propose voluntary telecom security bill
The bill creates a working group and voluntary assessments nearly two years after Salt Typhoon, but Cruz's framing rejects the binding rules Wyden proposed in 2024.
TL;DR
Sens. Mark Warner and Ted Cruz introduced the Telecommunications Cybersecurity and Resilience Act on Thursday, establishing an NTIA-chaired working group to develop voluntary telecom cybersecurity best practices within 18 months, plus a process for independent assessment of carrier adoption. The bill lands nearly two years after Salt Typhoon compromised systems handling lawful surveillance requests across multiple U.S. carriers. It follows the FCC's reversal last November of a Biden-era security measure, a rollback Warner criticized as leaving scant detail on how voluntary efforts would prevent another breach.
The bill's structure reflects a split that's been hardening since Salt Typhoon was disclosed: mandate versus volunteer. Wyden's December 2024 Secure American Communications Act would have required the FCC to issue binding rules, annual vulnerability testing, CEO-signed compliance certifications, and independent audits. That bill did not advance. Warner-Cruz takes the opposite approach, best practices, voluntary adoption, no new regulatory authority.
The working group's 18-month timeline means guidance wouldn't arrive until roughly 2028, more than three years after the intrusions became public. The group's membership (providers, suppliers, cybersecurity experts, and government agencies) is broad enough to produce consensus, which is also broad enough to produce lowest-common-denominator output.
Cruz's statement that voluntary protections are preferable to "rigid federal mandates that quickly become outdated" echoes the argument carriers have made since the intrusions. But the problem Salt Typhoon exposed wasn't outdated mandates. It was that carriers were running critical infrastructure (CALEA wiretap systems) without adequate security controls, and in some cases actively limiting incident response. Nextgov/FCW previously reported that incident response personnel at two major U.S. telecom operators were instructed by outside counsel not to look for evidence of Salt Typhoon.
That's not a rigidity problem. It's an accountability problem. Voluntary best practices don't address counsel telling responders to stop looking.
FBI cyber intelligence official Michael Machtinger warned in February that Beijing could retain stolen information indefinitely and combine it with other collected data for surveillance and future exploitation. The intelligence damage is compounding while the working group deliberates.
Published ·Deep Fathom