" U.S. Federal Communications Commission Chairwoman Jessica Rosenworcel is proposing, opens new tab that communications service providers be required to submit an annual certification attesting that they have a plan in place to protect against cyberattacks"
The plan is “no plan”. They are NOT RESPONSIBLE.
How so? Taking steps to make telecommunications more reliable and more resistant to cyber attacks is in the national interest.
Are the telecoms exempt from liability? If so that is a bad law.
Not sure how this will be implemented, but I recall requirements that executives make certifications of compliance with some requirements in their annual reports. Adding cybersecurity to the requirement would not be difficult.
If they are unwilling to certify, the annual report is delayed. And Wall Street goes crazy.
If they certify and are then attacked, company executives are personally liable for false certification. Might be in court for years deciding if the cybersecurity provisions were appropriate or insufficient resulting in the cyber attack.
Because they say so. Their fundamental policies are very simple: You have to pay them. They have ZERO responsibility for anything (ever). Sound familiar?
The core telecommunications network, (it ceased to be a system some years ago) is so poorly engineered and is so poorly maintained that a prolonged strike can crater it. Or an earthquake. Or the loss of a dam on the Missouri river. Or internal sabotage.
Next time you are driving and you see the 25 year old car with faded paint no hub cap, a bent fender and riding on may pops, know that this is the metaphor for the core telecommunications system.
Cheers
Rest easy now.
Qazulight