US Regulator to Drop Network Security Mandate for Telecom Providers, Relying on Voluntary Commitments Instead.
The Federal Communications Commission (FCC) will vote in November to repeal a ruling that requires telecom providers to secure their networks, following pressure from the biggest lobby groups representing internet service providers. The move marks a significant shift in the agency's stance on network security, and it comes as some lawmakers and experts have questioned the effectiveness of the previous mandate.
The FCC's decision is seen as a victory for the telecom industry, which had opposed the original rule. In January 2025, the agency adopted a declaratory ruling that found telecommunications carriers have a legal obligation to secure their networks against unlawful access and interception under the Communications Assistance for Law Enforcement Act (CALEA). However, some lawmakers and industry groups argued that the law only requires carriers to facilitate lawful intercepts from law enforcement.
The new draft order, which will be voted on in November, argues that the previous interpretation of CALEA was "unlawful because the FCC purported to read a statute that required telecommunications carriers to allow lawful wiretaps within a certain portion of their network as a provision that required carriers to adopt specific network management practices in every portion of their network." Instead, the order suggests that the FCC can achieve cybersecurity through a "collaborative" approach via "federal-private partnerships" and more targeted, legally sound rulemaking.
The decision has been welcomed by industry groups, which have argued that voluntary commitments from carriers are sufficient to address security concerns. The CTIA-The Wireless Association, NCTA-The Internet & Television Association, and USTelecom-The Broadband Association filed a petition asking the FCC to reverse the original ruling in February, citing concerns about the law's scope and the agency's authority.
However, some experts have questioned the effectiveness of the new approach. "The problem is not just that carriers don't take cybersecurity seriously enough," said one expert, who wished to remain anonymous. "It's that the FCC doesn't understand how security works in the network." Others have warned that relying solely on voluntary commitments from carriers could leave consumers vulnerable to cyber threats.
As the debate over network security continues, lawmakers are grappling with the implications of the FCC's decision. Some have called for more stringent regulations, while others argue that the current approach is a step in the right direction. One thing is clear: the telecom industry's shift towards voluntary commitments has significant implications for consumers and the broader cybersecurity landscape.
The Federal Communications Commission (FCC) will vote in November to repeal a ruling that requires telecom providers to secure their networks, following pressure from the biggest lobby groups representing internet service providers. The move marks a significant shift in the agency's stance on network security, and it comes as some lawmakers and experts have questioned the effectiveness of the previous mandate.
The FCC's decision is seen as a victory for the telecom industry, which had opposed the original rule. In January 2025, the agency adopted a declaratory ruling that found telecommunications carriers have a legal obligation to secure their networks against unlawful access and interception under the Communications Assistance for Law Enforcement Act (CALEA). However, some lawmakers and industry groups argued that the law only requires carriers to facilitate lawful intercepts from law enforcement.
The new draft order, which will be voted on in November, argues that the previous interpretation of CALEA was "unlawful because the FCC purported to read a statute that required telecommunications carriers to allow lawful wiretaps within a certain portion of their network as a provision that required carriers to adopt specific network management practices in every portion of their network." Instead, the order suggests that the FCC can achieve cybersecurity through a "collaborative" approach via "federal-private partnerships" and more targeted, legally sound rulemaking.
The decision has been welcomed by industry groups, which have argued that voluntary commitments from carriers are sufficient to address security concerns. The CTIA-The Wireless Association, NCTA-The Internet & Television Association, and USTelecom-The Broadband Association filed a petition asking the FCC to reverse the original ruling in February, citing concerns about the law's scope and the agency's authority.
However, some experts have questioned the effectiveness of the new approach. "The problem is not just that carriers don't take cybersecurity seriously enough," said one expert, who wished to remain anonymous. "It's that the FCC doesn't understand how security works in the network." Others have warned that relying solely on voluntary commitments from carriers could leave consumers vulnerable to cyber threats.
As the debate over network security continues, lawmakers are grappling with the implications of the FCC's decision. Some have called for more stringent regulations, while others argue that the current approach is a step in the right direction. One thing is clear: the telecom industry's shift towards voluntary commitments has significant implications for consumers and the broader cybersecurity landscape.