ZCyberNews
中文
Industry News••4 min read•Salt Typhoon

Warner, Cruz Bill Sets Voluntary Cyber Rules After Salt Typhoon

Sens. Warner and Cruz introduced the Telecommunications Cybersecurity and Resilience Act, a voluntary NTIA working group response to Salt Typhoon's breach of at least nine US...

Sen. Mark Warner speaking at a Senate Intelligence Committee hearing in March 2025.

Executive Summary

Sens. Mark Warner (D-VA) and Ted Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act on Thursday, a bipartisan bill that would establish voluntary cybersecurity best practices for US telecom carriers and an optional third-party certification program. The legislation is framed as a direct response to Salt Typhoon, the Chinese state-linked campaign that gave intruders years-long access to at least nine major US telecommunications providers, including Verizon, AT&T, and Lumen.

The bill does not impose mandates or penalties. Instead, it would create a Telecommunications Cybersecurity Working Group inside the National Telecommunications and Information Administration (NTIA) to draft sector-specific practices, review them every two years, and update them after major cyber incidents. Companies could voluntarily submit to independent assessment to certify adoption. The proposal arrives nearly a year after Republican officials scrapped binding telecom rules originally drafted in the wake of the Salt Typhoon intrusions — a rollback that Warner and other Democrats warned would leave voluntary codes toothless against continued Chinese hacking.

Technical Analysis

The Salt Typhoon campaign, attributed by US officials to Chinese government-backed actors, compromised at least nine US carriers over a span of several years. According to the bill's sponsors and prior investigative reporting, the intruders accessed Call Detail Records — granular metadata covering whom a target spoke to, when, for how long, and where they were when the call occurred. In some cases, the hackers intercepted audio and text content directly.

The targeting was not indiscriminate. Reporting cited in the bill's rationale indicates the intruders focused on roughly 150 high-profile individuals, including President Donald Trump, Vice President JD Vance, staff members of then-Vice President Kamala Harris, and Sen. Chuck Schumer (D-NY).

Biden administration investigations into the intrusions concluded the campaign would have been "far riskier, harder and costlier for the Chinese" had carriers implemented minimum practices: secure configurations, up-to-date patching, architecture designed to surface anomalous behavior, and multi-factor authentication on administrator accounts. Those findings underpinned the original binding rules, which would have required carriers to secure networks and submit annual certifications attesting to a cybersecurity risk management plan. That framework was removed by Republican officials roughly a year ago.

The new bill takes a different structural approach. The NTIA working group would convene telecoms, suppliers, cybersecurity experts, and federal officials to produce best practices that "build on existing federal frameworks and threat information while focusing specifically on the telecommunications sector." The group would deliver an annual report to Congress. A separate voluntary certification track would let carriers hire an independent third party to assess and certify that they have implemented and maintained the practices.

Cruz framed the voluntary structure as a deliberate design choice, saying the bill brings government and industry together "rather than adopting rigid federal mandates that quickly become outdated." Warner's statement was more pointed: "The Salt Typhoon intrusion was the worst telecom hack in our nation's history and showed us just how vulnerable our critical infrastructure is, but it does not have to be that way." He added that if carriers adopt best practices, "our networks can be more resilient."

The bill was introduced alongside a separate batch of partisan cybersecurity proposals covering artificial intelligence, according to The Record.

Mitigations & Recommendations

Because the bill is voluntary and not yet law, its practical effect on carrier security posture is prospective. Defenders at telecommunications providers should treat the working group's output, once published, as a baseline for configuration hardening, patch cadence, administrative MFA, and anomaly-detection architecture — the four areas prior investigations identified as decisive in the Salt Typhoon intrusions. Enterprise security teams that rely on carrier infrastructure should also note that no mandatory reporting or certification obligation currently applies to their providers, meaning visibility into carrier-side compromise remains dependent on voluntary disclosure and federal threat-sharing.

Stay Updated

Get the latest cybersecurity news delivered to your inbox.

Tags:#salt-typhoon#telecom-security#cyber-policy#critical-infrastructure#china-apt

Related Articles