https://www.theregister.com/2024/02/12/fcc_gets_tough_on_telcos/ # # Sign in / up The Register(r) -- Biting the hand that feeds IT # # # Topics Security Security All SecurityCyber-crimePatchesResearchCSO (X) Off-Prem Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem On-Prem All On-PremSystemsStorageNetworksHPCPersonal TechCxOPublic Sector (X) Software Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Special Features Special Features All Special Features Cloud Infrastructure Week Cybersecurity Month Blackhat and DEF CON Sysadmin Month The Reg in Space Emerging Clean Energy Tech Week Spotlight on RSA Energy Efficient Datacenters Vendor Voice Vendor Voice Vendor Voice All Vendor Voice Amazon Web Services (AWS) Business Transformation Google Cloud Infrastructure Hewlett Packard Enterprise: AI & ML solutions Hewlett Packard Enterprise: Edge-to-Cloud Platform Intel vPro VMware (X) Resources Resources Whitepapers Webinars & Events Newsletters [front] Security 3 comment bubble on white FCC gets tough: Telcos must now tell you when your personal info is stolen 3 comment bubble on white Yep, cell carriers didn't have to do this before icon Brandon Vigliarolo Mon 12 Feb 2024 // 18:45 UTC # The FCC's updated reporting requirements mean telcos in America will have just seven days to officially disclose that a criminal has broken into their systems. After releasing a proposed rule in early January and giving the industry 30 days to respond, the FCC's final rule was published today. It solidifies what the agency proposed a little more than a month ago, and what was teased in early 2022 when FCC chairwoman Jessica Rosenworcel drafted initial changes to the commission's 16-year old security "breach" reporting duties. Along with requiring that attacks are reported to the FCC within seven days of a telco discovering them, the same deadline now exists to report any data leaks to the FBI and US Secret Service as well. As the FCC planned, the new rule also eliminates the mandatory seven-day waiting period for reporting break-ins to consumers. [front] The FCC now "requires carriers to notify customers of breaches of covered data without unreasonable delay ... and in no case more than 30 days following reasonable determination of a breach." [front] [front] "Reasonable determination" of a data blurt is further defined as "when the carrier has information indicating that it is more likely than not that there was a breach" and "does not mean reaching a conclusion regarding every fact surrounding a data security incident that may constitute a breach." In other words, if customers are affected then they had better be notified post-haste. [front] The FCC has additionally extended the scope of data exposure types that telecom customers must be notified of. Prior to the passage of the new rule customers only had to be told if Customer proprietary network information (CPNI) was exposed to the world. CPNI, for those unfamiliar, is all the data a cellular carrier retains about phone calls and service agreements - i.e., the data that appears on a bill. Personal identifiable information (PII) wasn't included in previous reporting requirements, meaning carriers whose customer records were exposed, didn't have to tell customers if CPNI wasn't accessed. "Without an FCC rule requiring breach notifications for the above categories of PII, there would be no requirement in Federal law that telecommunications carriers report non-CPNI breaches to their customers," the FCC said of the new rule. [front] Starting now, names, government ID numbers, data used for authentication purposes, email addresses/passwords and biometric data is all included in the FCC's reporting requirements. Dissociated data, if linkable to an individual using other data criminals accessed during a break-in, has to be reported as well. The new rules add an exception for customer notifications as well. If a carrier can "determine that no harm to customers is reasonably likely to occur," then it doesn't have to inform subscribers of the incident. Along with increased reporting rules for the content of data leaks, the new rule also expands the FCC's definition of "breach" to include "inadvertent access, use or disclosure of customer information." Inadvertent, much like the exposure of 63k employee records Verizon reported last week. Luckily for Verizon it won't have to worry about falling foul of the new rules, which don't go into effect until March 13. Telecom relay service providers, which provide assistance for hearing-impaired phone users, will be covered under the new rule as well. Here a breach, there a breach, everywhere a breach report The FCC's updated directive is the latest in a string of federal agency breach reporting requirements, with rules passed by the FTC and SEC set to go into effect later this year, and federal contractors getting their own set of newly-proposed IT security breach reporting rules too. As has been the case with those other rules, the FCC's requirements, when formally proposed last month, ran up against opposition. * Future of America's Cyber Safety Review Board hangs in balance amid calls for rethink * Blackbaud settles with FTC after that IT breach exposed millions of people's info * Mon Dieu! Nearly half the French population have data nabbed in massive breach * 40% of IT security pros say they've been told not to report a data leak Per the FCC, the Cellular Telecommunications Industry Association raised an objection on several grounds, including that the FCC rule would create a system of dual jurisdiction between the FCC and FTC once the latter's rule goes into effect. As has been the case with objections raised to the wide and varying data leak reporting requirements now enacted by the US federal government, the FCC said it finds industry objections "unpersuasive." Congress has even raised objections to some of the new reporting rules, with bills introduced in the House and Senate to overturn the SEC's four-day reporting deadline for data break-ins that could have a "material" effect on a company's finances and, by extension, its investors. The feds were generally dismissive of the complaints, with the Biden administration saying it would veto any attempts to undo the SEC's reporting rules. Industry figures, and congressional representatives, have pointed to the Cybersecurity and Infrastructure Security Agency's forthcoming rules for security breach requirements as a potential inter-agency standard. It's not clear whether CISA's rules, a draft of which is expected to be published next month, will harmonize standards or otherwise eliminate the need for companies covered under multiple rules to make multiple reports. (r) Get our Tech Resources # Share More about * Cybersecurity * Data Breach * FCC More like these x More about * Cybersecurity * Data Breach * FCC * Telecommunications Narrower topics * 5G * AT&T * British Telecom * Comcast * EE * Emergency Services Network * Ericsson * Mobile Network * National Broadband Network * NTT * Orange * RSA Conference * Telecommunications Act of 1996 * TETRA * Verizon * Vodafone * Voice over IP Broader topics * Sector * Security More about # Share 3 comment bubble on white COMMENTS More about * Cybersecurity * Data Breach * FCC More like these x More about * Cybersecurity * Data Breach * FCC * Telecommunications Narrower topics * 5G * AT&T * British Telecom * Comcast * EE * Emergency Services Network * Ericsson * Mobile Network * National Broadband Network * NTT * Orange * RSA Conference * Telecommunications Act of 1996 * TETRA * Verizon * Vodafone * Voice over IP Broader topics * Sector * Security TIP US OFF Send us news --------------------------------------------------------------------- Other stories you might like LockBit shows no remorse for ransomware attack on children's hospital It even had the gall to set the ransom demand at $800K ... for a nonprofit Cyber-crime1 Feb 2024 | 41 Jet engine dealer to major airlines discloses 'unauthorized activity' Pulls part of system offline as Black Basta docs suggest the worst Cyber-crime12 Feb 2024 | 2 Biden will veto attempts to kill off SEC's security breach reporting rules Senate, House can try but won't make it past the Prez, says White House Security1 Feb 2024 | 17 Redefining datacenter connectivity with open source networking Why meeting escalating traffic demands requires flexible, resilient, modern network architectures built on open standards Sponsored Feature [front] Mon Dieu! Nearly half the French population have data nabbed in massive breach Infosec In Brief PLUS: Juniper's support portal leaks customer info; Canada moves to ban Flipper Zero; Critical vulns Security12 Feb 2024 | 18 Sorry, scammers: The FCC says AI robocalls are definitely illegal Existing telemarketing abuse laws apply to AI voices, too, says Commission AI + ML8 Feb 2024 | 16 The FCC wants to criminalize AI robocall spam The only thing worse than a telemarketer is a robo-telemarketer Public Sector2 Feb 2024 | 38 Europe's largest caravan club admits wide array of personal data potentially accessed Experts also put an end to social media security updates Cyber-crime12 Feb 2024 | 9 America's broadband bill subsidy runs out of money and halts enrollments Program that gets the hard-up online needs money by May Public Sector6 Feb 2024 | 11 Lurie Children's Hospital back to pen and paper after cyberattack It's the second Chicago hospital to disclose a major incident in the same week Cyber-crime5 Feb 2024 | 8 Akira ransomware gang says it stole passport scans from Lush in 110 GB data heist Updated Cosmetics brand goes from Jackson Pollocking your bathwater to cleaning up serious a digital mess Cyber-crime26 Jan 2024 | 35 Chinese Coathanger malware hung out to dry by Dutch defense department Attack happened in 2023 using a bespoke backdoor, confirming year-old suspicions CSO6 Feb 2024 | 11 The Register icon Biting the hand that feeds IT About Us* * Contact us * Advertise with us * Who we are Our Websites* * The Next Platform * DevClass * Blocks and Files Your Privacy* * Cookies Policy * Privacy Policy * T's & C's * Do not sell my personal information Situation Publishing Copyright. All rights reserved (c) 1998-2024 no-js