Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
    • Wiretap Law Needs Updating to Prevent Future Salt Typhoons, House Panel Told
    • House Financial Services Committee Republicans call on SEC to withdraw 14 rules including cybersecurity rules
    • House Commerce Plans Markup of Bills Addressing Data Security, Privacy
    • House Resolution Seeks Answers About DOGE’s Handling of Americans’ Data
    • Spanish Employer Fined Over Exposure of Harassment Victim’s Data
    • Swiss Cyber Incident Reporting Law Takes Effect
    • Telemarketing Bill Clears Committee Vote in Oregon
    • U.K. Offers Guidance on Law Enforcement Use of Facial Recognition Technology
  • Articles
  • Articles

    Cybersecurity Policy Report, Wiretap Law Needs Updating to Prevent Future Salt Typhoons, House Panel Told, (Apr 2, 2025)

    By Tom Leithauser

    The Salt Typhoon cyber espionage campaign relied on built-in wiretap capabilities in the networks of telecom carriers and should lead to changes in the law dictating how carriers handle government surveillance requests, a House subcommittee was told ...

    By Tom Leithauser

    The Salt Typhoon cyber espionage campaign relied on built-in wiretap capabilities in the networks of telecom carriers and should lead to changes in the law dictating how carriers handle government surveillance requests, a House subcommittee was told today.

    “Ultimately, it is time to re-think CALEA,” the Communications Assistance for Law Enforcement Act, which was enacted in 1994 to require telecom carriers to assist in wiretaps, according to Matt Blaze, a Georgetown University professor of computer science and law.

    “The CALEA wiretap mandates, while well-intentioned, are showing their age and effectively degrade the security of U.S. telecommunications infrastructure,” Mr. Blaze told the House Oversight and Government Reform Committee’s military and foreign affairs subcommittee.

    “The interfaces provided by CALEA, and the services that have evolved around them, were a significant enabler of Salt Typhoon, a major cyber-intelligence operation against the United States. Similar attacks are likely to occur in the future unless significant changes are made,” Mr. Blaze said in his written testimony.

    When carriers engineered their networks to comply with CALEA, they introduced vulnerabilities that have only grown worse over time, he said. Early on, complying with CALEA required some manual processes by carriers, but those processes are almost entirely automated today, he explained.

    Telecom infrastructure has changed “radically” since the 1990s, Mr. Blaze told the subcommittee, and CALEA itself should undergo changes to close security gaps that the Salt Typhoon hackers exploited to conduct what amounted to illegal wiretaps on the phones of U.S. government officials and other high-value targets.

    “Requiring new services to be engineered with wiretapping as a central requirement is dangerous, and requiring wiretap interfaces to be present in every switch serving every customer is effectively an open invitation to foreign adversaries,” he testified.

    “At a minimum, CALEA should be revised to incorporate rigorous security testing, reviewed on an ongoing basis and as new services and equipment are introduced. And the capabilities should be required to be off by default, rather than enabled even in facilities where no wiretaps are active,” he added.

    Another witness at the hearing said the federal government should insist that critical infrastructure operators adopt more robust security practices.

    “Government cannot easily dictate how private industry operates generally. But critical infrastructure is different—justified clearly by national security,” said Josh Steinman, chief executive officer of Galvanick, Inc., a cybersecurity service provider.

    “Our industrial base—pipelines, ports, railroads, and critical defense production—is designed primarily for efficiency and profitability, not resilience under attack,” Mr. Steinman said in his written testimony.

    “Defense-critical manufacturing infrastructure that isn't built to survive past day one of conflict constitutes national negligence, a quiet betrayal hidden behind spreadsheets and quarterly earnings,” he testified.

    “America can no longer afford to fake resilience. Infrastructure not designed to operate during conflict is ultimately a threat to our national security,” he told the panel.

    Edward Amaroso, CEO of TAG Infosphere, Inc., a cybersecurity firm, recommended that the federal government take steps to develop artificial intelligence systems that can protect critical infrastructure from cyber attacks.

    “We will not solve this challenge by playing defense alone. We cannot rely solely on reactive ‘damage control’ strategies that wait for the next breach before moving,” Mr. Amaroso said in his written testimony.

    “Instead, we must fundamentally shift our approach. And I believe this pivot begins with research and development, with a bold, national investment in artificial intelligence-driven cybersecurity,” he said.

    “The United States must lead in building AI-powered cybersecurity systems that can anticipate, detect, and autonomously mitigate emerging threats to critical infrastructure. This means embracing deep learning, behavioral analytics, and real-time adaptive controls that can outpace the stealth and speed of AI-guided adversaries,” Mr. Amaroso told the subcommittee.

    Rep. William Timmons (R., S.C.), the subcommittee’s chairman, called for a more aggressive stance in cyberspace. The U.S. should retaliate against nations, such as China in the case of the Salt Typhoon, that conduct cyber attacks on U.S. critical infrastructure, he said.

    “Instead of merely reacting after breaches occur, we must be forward-thinking and resolute,” Rep. Timmons said.

    “The threat we face is not a result of negligence from our telecom companies, but a deliberate, strategic maneuver by sophisticated and hostile state actors intent on undermining our national sovereignty,” he said.

    “Legislators have begun proposing measures to require annual cybersecurity certifications for telecom companies, ensuring they adhere to strict security protocols,” he noted.

    “Yet, this is only part of the solution,” he added. “We must also invest in a more aggressive offensive capability that deters adversaries from exploiting our vulnerabilities, sending a clear message that cyber espionage against American infrastructure will have severe consequences.”

    MainStory: TopStory DataSecurity FederalLegislation

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use