Overview of the Cyber Risk Report
SureShield and BorderHawk Cybersecurity have recently published an exhaustive report titled
The State of U.S. Telecommunications: Cyber Risk in a Critical-Infrastructure Sector. This important study delves into the cyber risk indicators affecting the telecommunications sector, crucial to national infrastructure.
Key Findings
The analysis covered over 3,100 U.S. telecommunications operators, with in-depth profiles for 2,132 of them. Alarmingly, the findings revealed that approximately
65.5% of these providers are categorized in an elevated cyber risk band, suggesting a pressing industry-wide issue rather than isolated instances of vulnerability. This insight underscores the critical need for enhanced resilience across the telecommunications landscape.
The report is structured to facilitate industry awareness, engagement with policy discussions, and operational planning without targeting specific providers. It heavily relies on publicly available, non-intrusive data to illustrate systemic risks impacting the broader sector.
Implications for Critical Infrastructure
Jay Harmon, CEO of BorderHawk, emphasized the significance of telecommunications, stating, "Telecommunications is the layer everything else runs on. Emergency services, government functions, healthcare, financial systems, and public safety all depend on telecom." This report provides a sector-wide view of risks, serving as a practical benchmark for resilience rather than mere compliance requirements.
Identified Vulnerabilities
The report highlights several critical indicators contributing to increased risk within the telecommunications sector, including but not limited to:
- - CISA Known Exploited Vulnerabilities: Acknowledged security weaknesses that are frequently abused by cybercriminals.
- - Weak Email Authentication: Inadequate DMARC and SPF configurations that compromise email security.
- - Dangling DNS Configuration: Vulnerabilities associated with domain name systems, which can lead to exploitation.
- - Outdated Web Components: The presence of outdated technologies increases susceptibility to cyber attacks.
One alarming trend observed among the analyzed providers was numerous dangling DNS configurations, which could open the door for potential security breaches.
Industry's First External Cyber Risk Report
This groundbreaking report is the first of its kind to be developed from publicly available data. Sanjaya Kumar, the CEO of SureShield, commented, "This external, industry-wide cyber risk report not only emphasizes what needs to be addressed but also identifies relatively simple remediation steps that can substantially reduce risk exposure for an industry that constitutes our critical national infrastructure."
Conclusion and Next Steps
Organizations concerned about their cyber risk exposure in the telecommunications sector are encouraged to access the complete
Telecommunications Cybersecurity Benchmarking Report [here]. Moreover, they can request a confidential benchmarking review for insights tailored specifically to their operational context.
About SureShield
SureShield specializes in bolstering cybersecurity resilience while integrating governance, risk management, compliance, and cyber maturity solutions. Their approach combines advanced technology with advisory expertise to support organizations in developing sustainable programs that align with their business objectives.
About BorderHawk
BorderHawk provides consulting services concerning CMMC, HIPAA, SOC2, and NIST CSF Compliance Readiness, along with supply chain risk management for highly regulated organizations in critical infrastructure sectors. For further inquiries, reporters can reach out to Jay Harmon, CEO at BorderHawk, via email or phone.
By turning attention to these critical risks and initiating discussions on remediation actions, the telecommunications industry can take significant strides toward safeguarding its systems and the essential services they support.