Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Network Security - Major US telecom providers debut C2 ISAC to counter AI-driven threats
Network Security Artificial Intelligence Internet of Things Security Latest News News & Analysis Security

Major US telecom providers debut C2 ISAC to counter AI-driven threats

Kirsten DoyleBy Kirsten DoyleMay 26, 2026Updated:May 26, 20264 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Major US telecom providers
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Eight of the leading communications companies in the United States have created a new cybersecurity alliance that aims to improve threat intelligence sharing within the telecommunications industry, amid growing concerns about AI cyberattacks, state-sponsored espionage, and infrastructure attacks. 

The new cybersecurity partnership, the Communications Cybersecurity Information Sharing and Analysis Center (C2 ISAC), has been launched by eight leading US communications firms, including AT&T, Verizon, T-Mobile, Comcast, Charter Communications, Cox Communications, Lumen Technologies, and Zayo. 

The telecommunications industry fears that none of the companies have sufficient presence to effectively monitor and respond to increasingly coordinated cyberattacks. According to the founding companies, the increasing involvement of AI is contributing to both the sophistication and the magnitude of cyberattacks. 

Rich Baich, the Chief Information Security Officer of AT&T and the first chairperson of the C2 ISAC board, believes the communications sector is experiencing “more sophisticated and persistent” cyberattacks. 

This group is a reflection of a broader movement towards cooperation driven by the private industry rather than relying on the Communications Information Sharing and Analysis Center (COMM-ISAC), a cooperative effort between the private industry and the federal government.  

The new cooperation effort will take place within the business community, independent of the federal government. 

The timing is not accidental 

Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, at Suzu Labs, says: “The companies that Salt Typhoon compromised are now building the sharing infrastructure they needed before the compromise happened. Telecom was the only major critical infrastructure sector whose information sharing body sat inside the federal government rather than being industry run.” 

Krell says that arrangement discouraged candid exchange at exactly the moments it mattered most. “T-Mobile’s own CSO acknowledged publicly that carriers withheld threat data that turned out to be connected to larger campaigns. Financial services and energy solved this problem years ago. The telecom sector is arriving late to a model the rest of critical infrastructure already depends on.” 
 
He says the timing is not incidental. “CISA has lost nearly a third of its workforce and faces a $495 million budget cut. The CIPAC coordination framework has been shuttered. C2 ISAC joins the Alliance for Critical Infrastructure as another case of industry organising its own defence because federal capacity is no longer guaranteed. Sharing intelligence is the easy part. Acting on it faster than the threat evolves is the part that matters.” 

Jacob Warner, Director of IT at Xcape Inc, adds: “This massive telecom consolidation effectively signals that the private sector is seizing control of its own operational defence grid to bypass slow, risk-averse federal bureaucracy. By establishing a private-sector-only consortium away from the legacy, government-managed COMM-ISAC, these hyper-competitive carriers are creating a safe harbour to share highly sensitive, early-stage telemetry without the chill of immediate regulatory scrutiny or Freedom of Information Act exposure. 

The primary gatekeepers can no longer defend in silos 

Warner says for enterprise risk leaders, the creation of C2 ISAC serves as a stark warning that core communication foundations, specifically 5G orchestration, signalling protocols, and transit backbones, are under such aggressive nation-state and AI-driven bombardment that the primary gatekeepers can no longer defend them in silos.  

“Security executives must exploit this shift by auditing their external edge exposure, updating their disaster recovery playbooks for multi-carrier cross-operator dependencies, and demanding that their managed service and telecom providers provide direct visibility into the technical indicators validated by this new alliance.” 

Warner offers several critical takeaways

  • Sovereign-level threats require industry scale: When carriers like AT&T, Verizon, and Lumen band together, it is a direct response to highly advanced threat actors, such as Salt Typhoon, moving laterally through transit links that no single carrier fully controls. 
  • Bypassing the bureaucratic bottleneck: Moving threat intelligence operations outside of CISA’s direct house allows carriers to share actionable telemetry and operational vulnerabilities at the speed of an incident, unencumbered by federal administrative latency. 
  • Supply chain visibility mandate: Enterprises must weaponise this development during procurement, demanding that their telecommunications providers actively consume and prove compliance with C2 ISAC’s shared defensive playbooks. 

“When eight bitter telecom rivals suddenly agree to share their internal security playbooks, it is not an act of corporate charity, it is a clear sign that the house is on fire and the fire department is out of water,” he ends. 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories
  • Kirsten Doyle
    Dutch police, NCSC take down major botnet
  • Kirsten Doyle
    Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

FCC Blocks Foreign-Made Routers, Citing National Security Risks

March 26, 20268 Mins Read

Cutting Into Overtime, Not Corners: How Network Automation Drives Business Value

March 13, 20266 Mins Read

Major Sites Stumble After Cloudflare Misfire

November 19, 20257 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}