Cybersecurity Policy Report, Cyber Espionage Threat Looms Over 2027 Global Spectrum Conference in Shanghai, (Mar 17, 2026)
Organizations Mentioned:Ciena Corp.
By Paul Kirby
Senators and witnesses at a hearing before the Senate telecommunications and media subcommittee today stressed the anticipated security threats from the Chinese hosts that the U.S. and other delegations to the 2027 World Radiocommunication Conference (WRC-27) would have to manage.
The sensitive situation makes it all the more important for the head of the U.S. delegation to the conference to be named early, enabling the U.S. to develop unified positions well ahead of the conference and sell them to regional and international allies, according to participants at today’s hearing.
“Next year’s conference will be hosted in Shanghai, and the Chinese Communist Party will certainly be prepared to advance positions meant to undermine the United States’ leadership,” said subcommittee Chair Deb Fischer (R., Neb.). “The United States must enter these negotiations with a strong position.”
“The United States must engage in the lead-up to the conference with clarity and purpose,” added Sen. Ben Ray Luján (D., N.M.), the subcommittee’s ranking member. “If we fail to act, we will arrive in Shanghai divided and unprepared, handing our competitors a strategic advantage.”
“For WRC-27, the takeaway is simple: start early. Consensus takes sustained work with U.S. stakeholders and with other delegations. We cannot afford to delay,” said Grace Koh, who headed the U.S. delegation to the WRC-19 and is vice president-government relations for Ciena Corp.
“Shanghai adds real operational and political risk—including a host government whose interests may diverge sharply from ours. We should assume devices and communications may be monitored. That raises cybersecurity risks for a delegation that depends on laptops, phones, and shared technical documents. We should also plan for constrained connectivity: common U.S. collaboration tools may not work reliably,” she added. “Delegations may have limited access to remote technical support, so key experts must be on site to respond to late-breaking proposals. Export controls can further limit discussions, and state media may try to shape the narrative.”
“The response is preparation and discipline. Resolve sensitive policy issues earlier—not in Shanghai,” Ms. Koh advised. “Train the delegation early. Name the head of delegation early, staff the delegation to cover parallel sessions, and train the team throughout the cycle. Issue clear guidance on cybersecurity, communications, and export compliance. At the conference, enforce tight information-handling practices. The State Department will also need to intensify engagement with ITU leadership to protect a transparent, rules-based conference—and plan now with like-minded partners for contingencies, including unexpected political disruptions.”
She and other witnesses stressed the importance of the head of delegation being “a seasoned leader” and “a great negotiator.” While the official term of that person typically lasts about six months, the witnesses said the official should start work much earlier than that, such as 12 to 18 months. Next year’s WRC is scheduled for Oct. 18-Nov. 12, 2027.
“Negotiating in China poses unique security challenges,” acknowledged James Lewis, distinguished fellow at the Center for European Policy Analysis. “China owns the networks upon which delegates will communicate both with other delegations and with their home countries. China has an immense and powerful cyber intelligence effort that will circumvent most defensive efforts, and any unencrypted communication will likely be subject to interception. China has put a huge effort into managing surveillance data, so the volume of traffic will not be a challenge. This espionage program poses unique problems for all delegations in that the negotiations could easily be compromised to China’s advantage.
“Shanghai will not be a secure environment, and the Chinese have developed very sophisticated techniques to monitor communications within China, largely because of their paranoia about their own population,” Mr. Lewis added. “It will be very difficult to communicate without some degree of Chinese surveillance. Technologies similar to those developed by NSO group and others for implanting surveillance software without the device [owners’] cooperation or knowledge suggest that even physically securing a phone, laptop, or tablet, will not be sufficient to safeguard a device.”
He added that the U.S. “can reduce this risk by first ensuring that all delegations are aware, and by suggesting ways to counter it. There are a few commercially available encryption technologies, such as Signal, that might improve security. Others’ encryption technologies are likely compromised. An awareness of a heightened security challenge in the Shanghai environment will be useful for all delegations to bear in mind. This is a problem, but it can be managed.”
Steve Lang, a senior adviser to Crest Hill Advisors LLC who took over as head of the U.S. delegation at the WRC-23 delegation late in the process after Anna Gomez was confirmed as an FCC Commissioner, outlined steps necessary for a successful U.S. effort next year.
He advised keeping “the pressure on China,” saying that the country “won the vote to host by a narrow margin with only 25 votes of the 48 ITU Council members, and its legitimacy as host is already in question. We must continue to hold China accountable and urge likeminded partners to do the same. … This should include demanding mitigating measures to address information security concerns as well as securing commitments to impartial management of the conference. We must then work with partners to make sure China fulfills those commitments before and during the conference.”
News: FederalLegislation DataSecurity