FCC to Reverse Network Security Mandates in Shift Towards Industry Voluntarism
The Federal Communications Commission (FCC) is poised to reverse a network security mandate that was established during the Biden administration, instead opting for a voluntary approach championed by industry leaders.
In January 2025, the FCC issued a declaratory ruling requiring telecom providers to secure their networks from unauthorized access or interception of communications, citing the Communications Assistance for Law Enforcement Act (CALEA). However, under the leadership of Chairman Brendan Carr, the agency is now planning to rescind this rule in November, based on feedback from major lobby groups representing internet service providers.
Industry leaders argue that CALEA only obligates carriers to facilitate lawful intercepts from law enforcement and that the FCC lacks authority to promulgate technical standards. In contrast, industry giants such as Verizon and AT&T have taken significant steps to strengthen their cybersecurity defenses.
The FCC will instead rely on these voluntary commitments, which include accelerated patching of outdated equipment, updated access controls, and improved threat-hunting efforts. These measures, according to the agency, represent a "significant change in cybersecurity practices" compared to what existed before.
Critics have argued that this approach is insufficient, as it fails to provide clear guidelines for carriers and leaves them vulnerable to cyber threats. Former FCC Chairwoman Jessica Rosenworcel defended the original rule, stating that it was "common sense" and necessary to secure networks against unlawful access.
The Federal Communications Commission (FCC) is poised to reverse a network security mandate that was established during the Biden administration, instead opting for a voluntary approach championed by industry leaders.
In January 2025, the FCC issued a declaratory ruling requiring telecom providers to secure their networks from unauthorized access or interception of communications, citing the Communications Assistance for Law Enforcement Act (CALEA). However, under the leadership of Chairman Brendan Carr, the agency is now planning to rescind this rule in November, based on feedback from major lobby groups representing internet service providers.
Industry leaders argue that CALEA only obligates carriers to facilitate lawful intercepts from law enforcement and that the FCC lacks authority to promulgate technical standards. In contrast, industry giants such as Verizon and AT&T have taken significant steps to strengthen their cybersecurity defenses.
The FCC will instead rely on these voluntary commitments, which include accelerated patching of outdated equipment, updated access controls, and improved threat-hunting efforts. These measures, according to the agency, represent a "significant change in cybersecurity practices" compared to what existed before.
Critics have argued that this approach is insufficient, as it fails to provide clear guidelines for carriers and leaves them vulnerable to cyber threats. Former FCC Chairwoman Jessica Rosenworcel defended the original rule, stating that it was "common sense" and necessary to secure networks against unlawful access.