IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
Two-thirds of US telecoms in elevated cyber risk band

Two-thirds of US telecoms in elevated cyber risk band

Tue, 22nd Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

SureShield and BorderHawk have published a report on cyber risk in the US telecommunications sector, finding that 66% of assessed operators fall into an elevated risk band.

The report examines 3,106 telecom operators across all 50 states using open-source data. It presents its findings against rising concern over attacks on critical infrastructure, arguing that telecommunications deserves special attention because outages or compromises in communications networks can disrupt emergency services, banking, defence communications and other infrastructure sectors at the same time.

That case has gained force after a cyberattack shut a British power plant for four days, with media reports attributing the incident to Iranian-linked hackers. The report also points to separate US concern over attacks on water systems and to the Salt Typhoon operation, which exposed the scale of state-backed access inside major telecom networks.

Sector exposure

The study identified 7,320 US telecom operators through the FCC registry, with 3,106 included in detailed scoring and 2,732 matched with fuller business profiles such as revenue, headcount and founding year. It assessed five categories: external-facing attack surface, email security hygiene, dark web exposure, known exploited vulnerabilities, and DNS and certificate hygiene.

The analysis relied on non-intrusive, publicly available information rather than authenticated scans or any form of privileged access. In practice, that means the weaknesses identified are visible from the public internet and could also be seen by attackers conducting reconnaissance.

A central finding is that smaller telecom operators appear to carry greater average risk than larger peers. The report notes that 69% of US telecom operators employ fewer than 50 people, a scale that often leaves little room for dedicated security staff or round-the-clock monitoring.

It also cautions against relying on sector averages alone. Larger carriers with more resources can raise the mean, while the median offers a less flattering picture of typical cyber health across the operator base.

Why telecom matters

Telecom risk matters because the sector serves as a shared dependency across critical infrastructure. Communications networks support 911 systems, first-responder radio links, payment systems, ATM connectivity, trading infrastructure, and a wide range of government and military communications that transit commercial carriers.

In sectors such as healthcare, transport, energy and water, loss of communications can quickly become a coordination failure. In that sense, the report argues, telecom does not sit alongside other critical sectors so much as beneath them.

BorderHawk Chief Executive Officer Jay Harmon echoed that view. "When Critical National Infrastructure, like telecommunication services, is at risk of compromise or unable to support its operations securely, everything downstream that depends on its functioning is at risk and can experience significant disruption," Harmon said.

Common gaps

The study highlights several recurring weaknesses across operators, including gaps in DMARC deployment that can make it easier to spoof company domains in phishing campaigns, exposure of credentials on dark web markets and forums, and vulnerabilities already listed in the CISA Known Exploited Vulnerabilities catalogue.

These conditions are especially significant because state-backed and criminal attackers often begin with peripheral weaknesses rather than direct attacks on their final objective. Mapping internet-facing systems, collecting leaked credentials and moving through less well-defended nodes remains a common route into more sensitive environments.

The report also sets out what it calls a 0-to-90-day roadmap for operators. Early steps include auditing DMARC settings, checking internet-facing assets against known exploited vulnerabilities, monitoring for exposed credentials, and identifying public management interfaces such as RDP, SSH and Telnet.

Later actions include patching or mitigating listed vulnerabilities, tightening email authentication policies, segmenting operational technology from corporate networks, and carrying out tabletop exercises based on ransomware or state-backed lateral movement. The final phase focuses on governance, including audit evidence, dashboard reporting, and alignment with FCC and NIST expectations.

Software pitch

SureShield links the findings to its own compliance and monitoring software, designed to automate evidence collection, control monitoring and reporting for operators that lack large in-house teams. It argues that manual compliance work is increasingly difficult for smaller providers trying to keep up with technical fixes and regulatory scrutiny at the same time.

SureShield Chief Executive Officer Sanjaya Kumar put that position plainly. "Our country is at risk without secure networks. Our mission is to secure America's future, one company at a time," Kumar said.

BorderHawk also tied the issue to the audit and compliance demands facing operators in regulated sectors. "BorderHawk empowers organizations with a clear, structured, and sustainable path to cybersecurity compliance, enabling them to meet and exceed audit standards with confidence and clarity," Harmon said.