The Federal Communications Commission (FCC) proposed new rules for telecom network data breaches less than six months after T-Mobile US suffered the largest carrier breach on record.

The proposed rules do little to improve customer privacy, but instead address how quickly a carrier must notify customers and regulators of a data breach. 

The FCC proposes an elimination of the current seven-business-day mandatory waiting period for customer notification. It also intends to require carriers to notify the FCC, FBI, and U.S. Secret Service of all reportable breaches.

“These rules need updating to fully reflect the evolving nature of data breaches and the real-time threat they pose to affected customers,” FCC Chair Jessica Rosenworcel said in a statement. “Customers deserve to be protected against the increase in frequency, sophistication, and scale of these data leaks, and the consequences that can last years after an exposure of personal information.”

The rule changes would also better align with recent developments in federal and state data breach laws covering other industries, according to the FCC. 

Analysts Applaud Rule Changes, Push for More

Analyst reactions to the proposed rule changes are mixed. While the removal of a waiting period is widely seen as a positive, analysts also say more needs to be done to confront the increasing sophistication and occurrence of attacks on networks. 

“This doesn’t really offer much better protection for customers as it addresses how breaches are reported,” said Zeus Kerravala, principal analyst at ZK Research. “More and faster reporting is obviously better. Customers have the right to know immediately when a service provider they are using has been breached as it allows them to change passwords, move data, or take other corrective actions.”

Eric Hanselman, principal research analyst at S&P Global Market Intelligence’s 451 Research, suggests the rule changes should increase the FCC’s visibility into operator security behaviors. “Protecting customer proprietary network information involves a more comprehensive set of controls that will affect operating processes as well as the technology involved,” he wrote in response to questions. 

“The longer-term potential is for the FCC to assess operator security performance and impose requirements or standards,” Hanselman added.

The elimination of the waiting period for notification presents the most significant change, but the new rules will have “very little” impact on network security overall, according to Will Townsend, VP and principal analyst at Moor Insights & Strategy.

“Much of the recent government regulation around cybersecurity has been broad and at times vague pointing to their potential misunderstanding of what is truly needed,” he added. 

Townsend claims operators are addressing security gaps irrespective of regulatory oversight because breaches can result in lost revenue. 

Telecom Networks Face Growing Threat

Nonetheless, telecom networks — some more than others — face increased difficulty in preventing cyberattacks that put their customers’ information in the hands of criminals. 

“Security breaches seem to be a growing asymmetric problem where the number of threat vectors, the attack surfaces, and type of breaches is growing exponentially, outpacing ways to protect networks and systems,” Kerravala said.

Last summer’s data breach at T-Mobile, its fifth publicly acknowledged incident in three years, exposed personal data on at least 54 million people. 

“Operators struggle with the same security challenges as any large enterprise. They are balancing simplified customer experience with more restrictive data protection controls,” Hanselman explained. “The hitch is that they hold what is potentially much more sensitive information than many consumer relationships. Revealing shopping histories has much less potential impact than spilling where someone is, the applications they use, and all the people they’ve interacted with.”

As such, Kerravala encourages the FCC and network operators to be more aggressive in using artificial intelligence (AI)-based security technologies. 

“Threats are so advanced today that manual methods are no longer effective,” he said. “I believe AI to be the only path forward for securing critical infrastructure. I know many telcos are trialing and using systems but lessons learned and the results should be pooled and shared so everyone benefits.”