Cybersecurity Policy Report, FCC Workshop Aims to Give Smaller Carriers Cybersecurity Guidance, (May 15, 2026)
All telecom carriers, including the smaller ones, should develop plans for how to handle a cyber attack before one occurs so that everyone involved understands their role, according to speakers at a cybersecurity workshop hosted today by the FCC.
“You've got to be able to use that plan when something happens, and you know exactly who's going to do what when, because you can't be figuring it out when you're in the middle of the incident,” said John Marinho, vice president–cybersecurity & technology at CTIA.
“You don't expect the firefighter to figure out how to hook up the hose when they pull up to the incident,” Mr. Marinho added.
The workshop was largely geared toward advising smaller carriers that might lack the cyber resources of larger companies but that nevertheless are an indispensable part of U.S. communications networks.
“The small and medium-sized carriers are mission critical,” noted Charles Clancy, chief technology officer at Mitre Labs. “Particularly as you look at our 911 response infrastructure, ... all of this is dependent not only on the larger carriers, but also many of the medium and smalls as well.”
Ransomware operators are behind most of today’s “disruptive” attacks, Mr. Clancy said, while adversarial nations, such as China are more likely to target carriers for their espionage value. But that could change quickly, he warned.
“If you play the tape forward—say three to five years—there is significant risk of nation-state adversaries pivoting to disruptive attacks. We're already seeing Russia and China begin to experiment with disruptive attacks against critical infrastructure and telecommunications in particular,” he said.
The Chinese government’s “Typhoon” cyber campaigns against critical infrastructure, including the targeting of telecom networks by Salt Typhoon, aim to preposition malware on critical infrastructure networks in advance of conflict with the U.S., Mr. Clancy said.
“If we're looking at a 2027-2028 timeline, which is what a lot of people are talking about for Chinese readiness to invade Taiwan, ... we could be facing some of these larger destructive attacks against our critical infrastructure,” he added.
He and other speakers advised carriers that need help to avail themselves of cybersecurity resources provided by federal agencies, including the Cybersecurity Framework developed by the National Institute of Standards and Technology and the guidance published by the Cybersecurity and Infrastructure Security Agency.
“When cyber attacks against telecommunications carriers are successful, they result in real-world consequences that can disrupt critical communication services,” said Austin Randazzo, deputy chief of the FCC’s Public Safety and Homeland Security Bureau.
“In the face of these growing threats, service providers must be able to effectively prevent, detect, respond to, and recover from cybersecurity incidents. This might seem like a tall order for small providers that aren't sure how to get started. But don't worry: The FCC is here to help,” Mr. Randazzo said.
“Our goal today,” he added, “is to demystify cybersecurity for you so that service providers of all sizes can take immediate action to reduce the risk to their networks.”
News: FederalLegislation DataSecurity