Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Government

FCC Taking Action in Response to China’s Telecoms Hacking

The FCC adopts declaratory ruling requiring telecommunications providers to secure their networks against nation-states and other threats.

The Federal Communications Commission has adopted a declaratory ruling requiring telecommunications providers to secure their networks against cybersecurity threats.

The ruling, for which the FCC currently seeks public comment, will also require wireless carriers to submit annual certification to the commission, proving that they have a cybersecurity risk management plan in place.

“There is a pressing national security and public safety need to take additional measures to safeguard our nation’s communications systems from real and present cybersecurity threats. The federal government must be able to maintain communication capabilities to fulfill its most critical and time-sensitive missions under any circumstances,” the FCC says.

The declaratory ruling was adopted in response to the recent Chinese hacking of at least nine wireless carriers in the US. The attacks have been attributed to a Chinese-state sponsored threat actor named Salt Typhoon.

According to the commission, successful cyberattacks on telecom providers could have damaging effects on other critical infrastructure, as each sector depends on communications to support its operations.

The ruling finds that section 105 of the Communications Assistance for Law Enforcement Act (CALEA), which was enacted in 1994, affirmatively requires telecommunications carriers, which include broadband internet providers and VoIP providers, “to secure their networks from unlawful access to or interception of communication”, the FCC announced.

Advertisement. Scroll to continue reading.

Previously, the FCC ruled that, under section 105 of CALEA, telecom carriers were required to prevent suppliers of untrusted equipment from illegally activating interceptions without the carriers’ knowledge, and the new ruling extends those duties to how carriers manage their networks.

“We reiterate the Commission’s previous conclusion that section 105 of CALEA affirmatively obligates carriers to take action to prevent all unauthorized interception and access to call-identifying information within their networks, whether by law enforcement or by other parties,” the FCC notes in a notice of rulemaking (PDF).

The notice also proposes cybersecurity and supply chain risk management requirements that will be applied to several types of service providers, including radio broadcasting stations, television stations, cable systems, satellite and wireline communications providers, MVNOs, VoIP providers, covered 911 and 988 service providers, and other entities.

All covered entities will be required to establish and implement cybersecurity and supply chain risk management plans tailored to their needs and aligned to NIST standards, and to ensure the confidentiality, integrity, and availability of their systems and services, while their executive leaders will be required to endorse those plans, the FCC says.

The commission is seeking comment on these and other requirements, on whether the covered entities should routinely assess their implementation of the plans, on whether they should submit an annual certification attesting the adoption and implementation of these plans, and on whether they should make these plans available to the commission upon request.

The FCC says that the declaratory ruling takes effect immediately, while the comment period will end 30 days after the ruling and notice are published in the Federal Register.

Related: Treasury Levels Sanctions Tied to a Massive Hack of Telecom Companies and Breach of Its Own Network

Related: Cambodia Delays Controversial Internet Gateway

Related: UK Telecom Companies Face Big Fines Under New Security Law

Related: Senators: CIA Has Secret Program That Collects American Data

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks.

Register

People on the Move

Opal Security has appointed CPO, CTO, VP of Field Engineering, VP of Marketing, and Head of Product and Solutions Marketing.

The Department of the Air Force has appointed Ashley Devoto as Chief Information Officer.

Bartley Richardson has been named Chief AI and Autonomous Systems Officer at CrowdStrike.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.