Lightspeed Networks, Inc. — Letter of Agreement (Team Telecom)
The Letter of Agreement requires Lightspeed Networks and PocketiNet Communications to implement mitigation measures addressing national-security and law-enforcement risks associated with Lightspeed’s proposed increase in foreign ownership and voting interests in PocketiNet.
What it does This Team Telecom agreement governs access to PocketiNet’s U.S. communications, infrastructure, lawful-process information, and customer records. It requires a U.S. law-enforcement point of contact, a U.S.-based security officer eligible for a Secret clearance, personnel screening, compliance with lawful interception requirements and CALEA, U.S.-located responsive records, and restrictions on disclosure to foreign governments or persons. PocketiNet must submit and maintain cybersecurity and system-security plans, identify foreign access, countries of access, principal equipment, service providers, network operations centers, and storage locations, and report security incidents within 48 hours. The Compliance Monitoring Agencies may require audits, site visits, annual reports, and plan or operational changes.
Who it affects The obligations bind PocketiNet, LightSpeed, and their successors, assigns, subsidiaries, and affiliates. They also flow to service providers, equipment providers, personnel, foreign persons with access, and network operations providers. DOJ, including the FBI, and DoD serve as the compliance monitoring agencies, while the FCC is the licensing authority whose authorization may be conditioned or acted upon for noncompliance.
Why it matters The LOA illustrates how FCC review of foreign ownership in telecommunications can be conditioned on continuing Team Telecom oversight. It combines control of lawful-access responses and sensitive U.S. records with cybersecurity, supply-chain, equipment, vendor, foreign-access, and ownership-change controls, including reporting concerning Covered List and Commerce Entity List providers.
Key dates and numbers
- Signed and dated September 7, 2023.
- Associated with TT 23-010 and FCC No. ISP-PDR-20221013-00009.
- Initial LEPOC information, foreign-access information, equipment, and service-provider lists are generally due within 15 or 30 days after FCC approval; security plans and network maps are generally due within 60 days.
- Known or suspected security incidents and material breaches must be reported within 48 hours; CPNI incidents must be reported within seven business days under the cited FCC rule.
- Annual reports are due one year after FCC approval and each year thereafter.