SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
US telecoms providers face elevated cyber risk, report finds

US telecoms providers face elevated cyber risk, report finds

Thu, 30th Jul 2026 (Today)
Mark Tarre
MARK TARRE News Chief

SureShield and BorderHawk have released a joint cyber risk report on the US telecommunications sector. The study found that 65.5% of analysed providers fall into an elevated cyber risk band.

Using publicly available external data, the report examined thousands of domestic telecommunications providers. It reviewed 3,106 operators and produced in-depth risk profiles for 2,132, without identifying individual companies.

The findings suggest a sector-wide problem rather than isolated weaknesses at a small number of operators. According to the analysis, common and well-documented technical issues account for much of the elevated risk across the industry.

The main issues identified included unpatched software flaws listed in the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalogue, weak email authentication controls, dangling DNS records, exposed public-facing services, and outdated web components.

Dangling DNS configurations were described as particularly widespread among the providers assessed. These records can leave inactive resources linked to active domains, creating an opening for subdomain takeovers.

The study described this as significant because telecommunications underpins a wide range of other essential services. Disruption or compromise at telecoms operators can affect emergency response systems, government services, healthcare networks, finance, and energy infrastructure.

Jay Harmon expanded on that point in comments accompanying the findings.

"Telecommunications is the layer everything else runs on. Emergency services, government operations, healthcare delivery, financial networks, energy grids, and public safety systems all depend fundamentally on the continuous uptime and security of telecom operators. This report gives the industry an essential sector-level view of risk-not as an abstract compliance checklist, but as a practical, actionable resilience benchmark designed to safeguard shared infrastructure," said Jay Harmon, Chief Executive Officer, BorderHawk.

Common weaknesses

The leading risk indicators were not rare or novel attack methods. Instead, the analysis pointed to routine security gaps that many organisations can address through standard maintenance, configuration reviews, and patching practices.

Weak deployment of DMARC and SPF was one example highlighted in the report. Such gaps can make it easier for attackers to spoof domains and run phishing campaigns against customers, partners, or staff.

Exposed public-facing services and outdated web software were also cited as recurring concerns. Internet-facing assets that are not carefully configured can expand the number of routes available to attackers, while unsupported or older components may contain known flaws.

The authors said the exercise was intended to support awareness across the sector, including at board level, and to inform operational planning and policy discussions. By aggregating the data at industry level, the study sought to show broad patterns without naming providers.

Remediation focus

Sanjaya Kumar said the findings also point to direct steps operators can take to reduce their exposure.

"This external, industry-wide cyber risk report developed from publicly available data is a first of its kind. It not only highlights the exact areas that desperately need to be addressed across the sector, but it also underscores the relatively easy, straightforward remediation steps that can be taken right now to mitigate risk exposure for an industry that serves as a cornerstone of our critical national infrastructure," said Sanjaya Kumar, Chief Executive Officer, SureShield.

The report was based entirely on external, non-intrusive data collection. That means the findings reflect what can be observed from outside provider networks, rather than information gathered from internal systems or breach investigations.

For telecoms companies, the results add to pressure to address basic cyber hygiene as scrutiny of critical infrastructure security increases. The emphasis on exposed services, patching, email controls, and DNS management suggests that many of the risks identified lie in areas long regarded as foundational rather than advanced.

The report does not publicly rank or score named operators, but it offers a benchmark for how widespread those weaknesses are across the sector. Its core finding remains that nearly two-thirds of analysed US telecommunications providers sit in an elevated cyber risk band.