
Federal regulators are not requiring phone and internet carriers to follow new cybersecurity standards. On November 20, 2025, the Federal Communications Commission voted 2-1 to rescind a January 2025 ruling that treated network security as a legal duty for carriers, and it withdrew a related proposal for new rules.
A separate FCC rule on how carriers report data breaches is also in doubt after a federal appeals court agreed in July 2026 to rehear a challenge to it.
What the FCC undid
The January 16, 2025 ruling followed the Salt Typhoon hacking campaign. The FCC's own order says it was disclosed in September 2024 that this China-sponsored group had infiltrated at least eight U.S. communications companies, mostly by exploiting publicly known vulnerabilities rather than previously unknown ones.
The ruling and its companion proposal would have required carriers to create and carry out cybersecurity risk management plans and to certify them to the FCC every year, BleepingComputer reported.
Chairman Brendan Carr and Commissioner Olivia Trusty voted to reverse it. "The Declaratory Ruling that we reconsider today was neither lawful nor effective," Carr said, as quoted by Cybersecurity Dive. Commissioner Anna Gomez dissented: "If voluntary cooperation were enough, we would not be sitting here today in the wake of Salt Typhoon."
Instead of mandates, the FCC pointed to voluntary commitments. According to the order, carriers agreed to speed up patching of outdated or vulnerable equipment, review access controls, disable unnecessary outbound connections, improve threat hunting and share more information with the government and with each other.
The breach notification rule is back in court
In 2023 the FCC expanded its breach reporting rules for carriers, including interconnected VoIP providers. Under the FCC's summary of that order, a breach affecting 500 or more customers, or one that risks customer harm, must be reported to the FCC, FBI and Secret Service no later than seven business days after the carrier determines it happened. Affected customers must be told without unreasonable delay and no later than 30 days after that determination, unless law enforcement asks for a delay.
A panel of the Sixth Circuit Court of Appeals upheld the rule 2-1 on August 13, 2025. On July 31, 2026, the full court granted rehearing and vacated that decision, according to Davis Wright Tremaine, which leaves the rule's future uncertain. Arguments before the full court are set for October 21, 2026.
What this means for your business
The security of your carrier's network now rests mostly on the carrier and its voluntary commitments. You cannot audit that, so the practical move is to protect the accounts and devices you control.
After Salt Typhoon, CISA published mobile security guidance. It was written for "highly targeted" officials, but CISA says it is "applicable to all audiences." Its advice includes using end-to-end encrypted messaging, switching to phishing-resistant sign-ins, dropping text message codes for multifactor authentication and adding a PIN to mobile carrier accounts.
What to do
- Stop using text message codes as a second factor for email, banking and Microsoft 365 or Google Workspace. Use an authenticator app, passkeys or security keys instead.
- Add a PIN or passcode to every company mobile account to make SIM swapping harder.
- Use an end-to-end encrypted app for sensitive conversations instead of plain text messages.
- Ask your phone and internet carriers how they notify business customers about breaches and whom to contact.
- Keep passwords, account numbers and wire instructions out of text messages.
WITTCO can help secure the accounts and devices your team relies on every day, from phishing-resistant sign-ins in Microsoft 365 or Google Workspace to endpoint protection and patching.
Sources
- Federal Communications Commission, "Order on Reconsideration: Protecting the Nation's Communications Systems from Cybersecurity Threats, FCC 25-81" (November 21, 2025): https://docs.fcc.gov/public/attachments/FCC-25-81A1.pdf
- Cybersecurity Dive, "FCC eliminates cybersecurity requirements for telecom companies" (November 20, 2025): https://www.cybersecuritydive.com/news/fcc-eliminates-telecom-cybersecurity-requirements/806052/
- BleepingComputer, "FCC rolls back cybersecurity rules for telcos, despite state-hacking risks" (November 21, 2025): https://www.bleepingcomputer.com/news/security/fcc-rolls-back-cybersecurity-rules-for-telcos-despite-state-hacking-risks/
- Federal Communications Commission, "FCC Fact Sheet: Data Breach Reporting Requirements" (November 22, 2023): https://docs.fcc.gov/public/attachments/DOC-398669A1.pdf
- Davis Wright Tremaine, "UPDATE: Sixth Circuit Upholds FCC Data Breach Order: Analyzing the Implications for Telecom Carriers and the FCC" (updated August 5, 2026): https://www.dwt.com/blogs/privacy--security-law-blog/2025/08/fcc-telecom-carrier-data-breach-order-upheld
- Broadband Breakfast, "Sixth Circuit to Rehear Case on FCC Data Breach Rules Case" (July 31, 2026): https://broadbandbreakfast.com/sixth-circuit-to-rehear-case-on-fcc-data-breach-rules-case/
- CISA, "Mobile Communications Best Practice Guidance" (December 18, 2024): https://www.cisa.gov/sites/default/files/2024-12/guidance-mobile-communications-best-practices.pdf


