no fear
– Getty Images

The Federal Communications Commission (FCC) decision late last week to rescind a telecom cybersecurity ruling enacted during the last days of the previous government administration of course rang of politics –but it was also the most audacious act so far by current FCC Chairman Brendan Carr.

And I say that being a big fan of Carr’s audaciousness to date, including the facilitation of Charlie Ergen’s multibillion-dollar exit from the mobile telecommunications space. I am still in awe of that one.

Dan Meyer
“Fool me once … shame on … you … can’t get fooled again.”

Carr’s latest move revoked what had been one of the last acts by previous FCC Chairwoman Jessica Rosenworcel, who just prior to the administration change in January enacted rules that attempted to put more responsibility on telecom operators to protect their networks from increasingly insidious cyberattacks. Rosenworcel specifically linked the move to the Salt Typhoon attack that has been tied to the Chinese government and was what one U.S. senator called the “worst telecom hack in our nation’s history."

Carr in a statement tied to the reversal claimed his predecessor’s action was “unlawful” due to an incorrect interpretation of a law tied to “lawful wiretaps,” and “ineffective because it neither responded to the nature of the relevant cybersecurity threats nor was it consistent with the agile and collaborative approach to cybersecurity that has proven successful.”

That first argument is a bit ambiguous as Carr obviously has a different interpretation of that initial action, but I do applaud the word play. The second point is moot now since the actions never went into effect, and I always looks for ways to use the word “moot.”

Instead, Carr said the FCC under his direction has worked directly with telecom operators “who have agreed to make extensive, coordinated efforts to harden their networks against a range of cyber intrusions. These have included accelerated patching of outdated or vulnerable equipment, updating and reviewing access controls, disabling unnecessary outbound connections, improving their threat-hunting efforts, and increasing cybersecurity information sharing.”

Cool. If the folks that were unknowingly hacked and allowed said hackers to rifle around inside of those networks for months said they have fixed the problem, then I think we are all good. Case closed. Well done everyone. Be safe getting home.

Unless, of course, those operators only think they have actions and processes in place to stop what will undoubtedly be the next cyberattack that will be built on the learnings from Salt Typhoon.

I don’t doubt that those operators did indeed tell Carr that they made those “extensive, coordinated efforts” to bolster their network security, but if we assume (hope?) that they already had extensive and coordinated efforts in place prior to the Salt Typhoon attack – and many others – are we foolish to think those operators have now leapt ahead of future attackers?

Historically, operators have received a slap on the wrist for such infractions, punishment that clearly did not fit the bill nor provide that significant of a deterrence.

I know in the big picture of cyberlife that nothing is ever secure and that I have digital doppelgangers all over the world living high on my distinctly “mid” credit score. If anything, I get angry at times because I think my digital twins are doing a better job of living that life than I am.

Don't get fooled again!

Telecom operators have a chequered history when it comes to protecting their networks. Sure, they might not be suffering a new breach every day/hour/minute/second so that could be considered a win – but they have been breached, and sometimes repeatedly.

What’s that saying: “Fool me once … shame on … you … can’t get fooled again.”

I think that’s appropriate here.

Would Rosenworcel’s actions have solved all telecom cybersecurity concerns? No. Would it have solved some? Maybe.

Will Carr’s action solve all telecom cybersecurity concerns? No. Will it solve some? Maybe.

With what we have seen from Carr so far, I doubt this will be his most audacious endeavor. But a poor outcome from this move could have the most devastating and far-reaching blast radius.

This leaves me perplexed as to why Carr would put what might be his long-term reputation, which is only of importance to him, but more importantly the potential cybersecurity of basically all Americans and other wide-ranging national security operations in the hands of entities that have shown they can’t handle the task?

Look, I am all for audacious, especially when it involves high stakes. Now, in this case, those stakes are both high and wide, which does add a layer of uncomfortableness to my joy.

I have no insight or even want to guess Carr’s mindset going into this, but putting my reputation on the cybersecurity success of telecom operators is one audacious step too far for me.