news.mlab.sh
Back to the feed
threat-intel

UK weakens proposed telecoms defenses against Chinese hackers after industry pushback

High
Summary

The UK government has weakened proposed cybersecurity protections for its telecoms networks in response to pushback from telecom companies regarding the cost and practicality of implementing measures designed to counter the Salt Typhoon espionage campaign. Despite concerns about Chinese-linked hacking targeting critical sectors, including a cluster of activity observed in the UK, the government rolled back key protections, including requirements for intrusion detection systems and monthly network restarts. This decision highlights a broader tension between the desire for government support and the industry's resistance to access and obligations.

The UK’s decision to weaken cybersecurity protections for its telecoms networks stems from a conflict between government efforts to defend against state-backed hacking and the telecom industry’s concerns about the implementation of those defenses. Initially prompted by the Salt Typhoon campaign, which has impacted over 80 countries, the proposed measures aimed to address vulnerabilities in telecoms signaling infrastructure, a key tactic used by the attackers. Specifically, the proposed regulations included requirements for independent intrusion detection systems and monthly network restarts to mitigate the risk of sophisticated memory-only malware. However, telecom companies, including BT, VMO2, Vodafone, Sky, Ericsson, and Amazon Web Services, argued that these measures were too costly and impractical, leading to significant pushback.

The government’s response to the consultation, released last week, significantly reduced the scope of the proposed protections. Key elements, such as the mandatory deployment of intrusion detection systems and the requirement for monthly network restarts, were dropped or delayed. This rollback reflects a broader challenge in securing critical infrastructure, as highlighted by the reluctance of companies to grant access and comply with obligations demanded by security agencies. The situation underscores the difficulty in balancing national security concerns with the operational realities of the private sector.

Despite the weakened code being technically guidance rather than directly enforceable law, it still provides a ‘yardstick’ for regulated companies to be measured against. Failure to adhere to the guidance could result in fines up to 10% of their turnover, highlighting the potential consequences for telecom providers. The revised rules recommend restarts only where feasible, acknowledging the operational challenges faced by the industry.

Read the full article at The Record