The Breach Nobody Should Have Been Surprised About
Late 2024 hit different. The FBI and CISA confirmed what security researchers had been muttering about in Slack channels for months: Chinese state-sponsored actors had spent over a year living rent-free inside at least nine major US telecom carriers. AT&T, Verizon, and others. The big names. The ones we’re supposed to trust with our infrastructure. And they got in through doors that should have been locked years ago.

Here’s the thing that gets me as an engineer: this wasn’t sophisticated. It wasn’t some zero-day weaponized at a nation-state facility. The attackers exploited legacy SNMP configurations, unpatched edge devices from Cisco and Fortinet, and networks that had no meaningful segmentation. According to the CISA Salt Typhoon advisory, these were known, fixable problems. The kind of things you write down in your architecture review and then… don’t do because it’s expensive and nobody’s screaming about it yet.
Except someone was screaming. We just weren’t listening hard enough.

The $47 Million Reality Check
Mandiant’s February 2025 report landed like a punch. Seventy-three percent of affected organizations needed full re-architecture of their carrier-grade network management interfaces. Not patches. Not configuration tweaks. Full. Re-architecture. And the bill? North of $47 million per carrier on average. That’s not a typo. That’s the cost of fixing what should never have broken in the first place.
Think about that number for a moment. That’s not just remediation spend. That’s the cost of retraining teams on new architectures, the downtime coordinating with regulatory agencies, the forensic work to understand what was accessed and when, and the infrastructure rebuild that should have happened incrementally but now has to happen all at once. It’s the cost of delay, compressed into a brutal present.
For individual engineers reading this, here’s the career signal: organizations that can articulate why architectural debt becomes operational debt are about to become very, very valuable. You know that tech lead who keeps pushing for network segmentation when everyone else wants to ship faster? They’re about to get vindicated in a way that comes with promotion conversations and better offers.
Cisco’s CVE-20198 and the One-Year Patch Gap
Let’s talk about CVE-2023-20198. Cisco disclosed this vulnerability in their IOS XE platform with a perfect CVSS score of 10.0. Perfect. Worst possible. And here’s the engineer’s nightmare: a patch had been available for over a year before anyone confirmed Salt Typhoon actors were actively exploiting it. One year. In that year, how many security meetings happened? How many “we’ll patch next quarter” conversations? How many people decided it wasn’t critical enough?
This is the part that should terrify you if you work anywhere near network operations. You can do everything right on your side. You can write pristine code, you can design elegant systems, but if your dependencies aren’t patched and you don’t have visibility into whether they are, you’re basically relying on luck. And luck, as we’ve now learned at the nation-state scale, is not a security strategy.
For engineers building systems that touch carrier infrastructure or anything adjacent to it, this is your canary in the coal mine. Your architecture needs to assume that dependencies will be exploited before patches are applied. Not after. Before.
January 2025: The FCC Finally Blinks
The FCC issued new cybersecurity rules under Section 105 of the Communications Act in January 2025. First annual cybersecurity risk management plans mandated by federal regulation for carriers. This isn’t guidance. This isn’t a suggestion. This is law, and it’s going to ripple through every organization that touches telecom infrastructure in ways we’re just starting to understand.
What this actually means for you as an engineer: the era of “security is nice to have” is over. Dead. Not in five years. Now. Organizations are already staffing up for compliance. They’re hiring architects who understand regulatory frameworks. They’re promoting engineers who can explain why a system design either helps or hurts their compliance posture. The FCC cybersecurity rulemaking proceeding is where the jobs are going to be.
More importantly, this is where your credibility gets built. If you’ve been saying “we need to implement proper network segmentation” and leadership kept saying “too expensive,” you now have federal regulators who agree with you. Use that. Respectfully. But use it.
What You Actually Build Differently Starting Now
Here’s what changes in your actual day-to-day: you stop accepting “we’ll patch in Q3” as an answer. You start treating network segmentation like it’s not optional infrastructure anymore. You build observability into systems that are adjacent to critical infrastructure like your job depends on it. Because now it actually might.
If you’re an architect, you’re re-evaluating every legacy protocol and every edge device in your design. SNMP without authentication? That’s not a known issue anymore. That’s a liability. Unpatched Cisco or Fortinet boxes? Same thing. Flat networks with no segmentation? This is the year you draw a line and say no.
If you’re a junior engineer, pay attention to whoever in your organization is leading the Salt Typhoon remediation efforts. That person is about to become extremely valuable. Learn from them. Understand their reasoning. This is the most practical cybersecurity education you can get, and it’s happening right now at your company.
The Salt Typhoon breach wasn’t interesting because it was sophisticated. It was interesting because it was a perfectly documented case study in why architectural decisions made years ago suddenly cost tens of millions to fix. The lesson isn’t new, but the price tag is impossible to ignore.
What’s your experience been so far with rebuilding systems in response to Salt Typhoon? What architectural decisions in your systems feel suddenly urgent? Drop a comment or reach out. I’m genuinely curious what the front lines look like in different organizations right now.

