
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
Summary
Sens. Mark Warner (D-VA) and Ted Cruz (R-TX) have introduced a bill to create a voluntary framework for addressing cyber threats in the communications sector, building on lessons learned from the Salt Typhoon hacks that impacted major telecom providers in 2024. “The Salt Typhoon intrusion was the worst telecom hack in our nation’s history and showed us just how vulnerable our critical infrastructure is, but it does not have to be that way.
If telecommunications companies adopt cybersecurity best practices, our networks can be more resilient. This bipartisan legislation is a good start in protecting our nation and strengthening the communications networks Americans rely on every day,” Warner said in a Sept. 24 release .
The bill is a bipartisan effort from two major players in the communications space. Warner is ranking member of the Seante Intelligence Committee, while Cruz is chair of the Senate Commerce Committee. The bill would create a Telecommunications Cybersecurity Working Group with the National Telecommunications and Information Administration to develop industry best practices.
The working group would build on “a network of independent third-party assessors to certify implementation of those practices, and provid[e] technical feedback and implementation guidance,” according to a bill summary . The summary says the practices must: Focus on identifying, responding to, mitigating, preventing, and remediating cybersecurity incidents and vulnerabilities; Be risk-based and consistent with existing federal frameworks (e.g., the NIST cybersecurity framework, the NIST risk management framework, and guidance under executive order 14028); Consider allied-nation cybersecurity requirements (NATO members, major non-NATO allies, or Five Eyes partners) for interoperability purposes; Avoid duplicating existing risk-management processes; and Reflect current threat intelligence and technology. The release emphasizes the creation of a “voluntary certification process, that puts real accountability behind the adoption of best practices through independent third-party assessment and certification.” The best practices must be “reviewed and updated at least every two years and following major cyber incidents or significant changes in the threat landscape,” according to the release.
Cruz said in the release, “This sensible bill brings government and industry together to develop voluntary, telecom-specific cybersecurity best practices rather than adopting rigid federal mandates that quickly become outdated.
KazaSec's take
A newly disclosed vulnerability is only a real risk to your organization once it's confirmed present and exploitable in your own environment — not every CVE applies equally to every network. Knowing the difference is exactly what a proper vulnerability assessment is for.
Coverage details
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.