Publication

Can You Hear Me Now? Recent Enforcement Activity Against Telecom Demonstrates Importance of Robust Cybersecurity and Data Governance

October 8, 2024
Abstract image of cybersecurity with binary code and graphs

Coming just weeks after the Federal Communications Commission (“FCC” or the “Commission”) announced a Consent Decree with AT&T, 1 the Commission is back with another broad sweeping settlement with T-Mobile. 2 Last year, Verizon also reached a $4 million settlement with the Department of Justice to settle allegations that Verizon fraudulently failed to fully implement cybersecurity controls. 3 These investigations, among others, underscore the FCC and other executive agencies’ efforts during the Biden Administration to leverage enforcement actions to set the bar for cybersecurity and data protection.

The AT&T Consent Decree largely focuses on cybersecurity oversight as well as data retention and deletion policies for third party vendors. In particular, the FCC found that AT&T failed to ensure that its vendor adequately protected customer information, thereby leaving the information in a cloud environment for many years after it was no longer needed, which was ultimately exposed in a 2023 data breach affecting millions of customers. To settle the case, AT&T agreed to pay a $13 million civil penalty and committed to strengthening the company’s data governance and business practices to protect against future breaches. These terms required AT&T to appoint a compliance officer for privacy and information security, develop a compliance plan and information security plan, and increase vendor controls and oversight, among other things.

Following data breaches in 2021, 2022, and 2023 affecting millions of T-Mobile customers in the aggregate and exposing names, addresses, social security numbers and other data elements, the FCC was even more prescriptive with T-Mobile. In addition to providing for a $15,750,000 settlement, the T-Mobile Consent Decree identifies a laundry list of what the FCC believes organizations should do to maintain a reasonable 4 data security and privacy program. The notable cybersecurity practices highlighted in the settlement – and thus, the model the FCC expects from organizations under its jurisdiction – include:

  • Establishing corporate governance structures around cybersecurity, including designating a Chief Information Officer who must report regularly to the Board on cybersecurity matters.
  • Maintaining a comprehensive, written information security program that applies both to an organization and its vendors.
  • Providing annual cybersecurity training to employees, some of which should include role-based training.
  • Maintaining a zero-trust and segmented network.
  • Regularly conducting vulnerability scans.
  • Implementing phishing-resistant multifactor authentication.
  • Maintaining and ensuring regular compliance with policies and procedures for access controls.
  • Implementing secure password encryption and storage procedures.
  • Implementing data retention, minimization, and deletion policies that limit both the collection and retention of data.
  • Maintaining intrusion prevention/detection, endpoint, and threat monitoring systems, which include real-time log monitoring and a process for security alert maintenance.
  • Heightening third-party oversight, including establishing required contractual provisions and developing a risk scoring system for third-party vendors.
  • Maintaining a critical asset inventory and removing or otherwise disabling assets that are no longer necessary.
  • Conducting regular risk assessments.

Notably, the FCC Consent Decree requires T-Mobile to make cybersecurity governance a key part of its overall corporate governance. Based on the language of the Consent Decree, it appears that T-Mobile does not currently have a Chief Information Security Officer. The FCC has required that to change. The new Chief Information Security Officer will also have direct access to the T-Mobile Chief Executive Officer (or designee) as well as at least some members of the Board of Directors. The Consent Decree further provides that T-Mobile must adequately resource the Chief Information Security Officer and T-Mobile’s information security program. Via these detailed steps, the FCC seems to be trying to emphasize and elevate the importance of data protection among the entities regulated by the FCC to make it a more significant corporate priority.

Beyond the minimum requirements of the Consent Decree, which of course was negotiated and not unilaterally imposed, it would be prudent for all companies to also make sure they have individuals with cybersecurity expertise on the Board of Directors. This is not currently a requirement imposed by the Securities and Exchange Commission, but is a best practice. A cyber-savvy Board would be more apt to ensure that the appropriate investments are made in cybersecurity and tough questions are asked to make sure that management is fully tracking, reviewing, and mitigating all significant cyber, data, and technology risks. The FCC has set a minimum baseline in its Consent Decrees but leading companies can and should do much more to try to keep pace with emerging risks and threats and reduce potential liabilities.

Connect with Ice Miller Cybersecurity Attorneys

Ice Miller has extensive experience assisting companies to navigate and comply with federal cybersecurity laws and regulations, as well as develop a cyber incident response playbook. Our team includes Sandeep Kathuria a Senior Counsel in our Business Practice Group; Dakota Coates, an associate in Ice Miller’s Litigation and Data, Security, and Privacy Groups; and Esther Sandlin an associate in Ice Miller’s IP and Data, Security, and Privacy Groups. 

[1] In the Matter AT&T Services, Inc., FCC DA24-892 (Sept. 17, 2024).
[2] In the Matter of T-Mobile US, Inc., FCC DA24-860 (Sept. 30, 2024).
[3] Office for Public Affairs, Cooperating Federal Contractor Resolves Liability for Alleged False Claims Caused by Failure to Fully Implement Cybersecurity Controls, DEPT. OF JUSTICE (Sept. 5, 2023), available at https://www.justice.gov/opa/pr/cooperating-federal-contractor-resolves-liability-alleged-false-claims-caused-failure-fully
[4] In the T-Mobile consent decree, the Commission defined reasonable with regard to cybersecurity to mean “a level of care or effort that is commensurate with industry norms or, as applicable, a Risk Assessment, both in terms of quality and scope of effort, as well as the timing of performance.”

This publication is intended for general information purposes only and does not and is not intended to constitute legal advice. The reader should consult with legal counsel to determine how laws or decisions discussed herein apply to the reader's specific circumstances.

Related People

Related Services & Industries

Related Categories

<p>Sign up now to receive periodic updates from Ice Miller&rsquo;s legal professionals.</p>

Sign up now to receive periodic updates from Ice Miller’s legal professionals.

Subscribe

Firm Highlights