Cybersecurity threats will raise the bar for future AI-Native Networks
Author
Recently, we had the privilege to attend the GSMA’s 3rd APAC Telecommunications Cybersecurity Summit in Bangkok, Thailand, in partnership with Huawei. The event brought together a unique aggregation of cybersecurity stakeholders from across the Asia-Pacific region to discuss current and emerging security landscapes, threat vectors and new cybersecurity strategies.
Compliance is history, Trust is the future
The event kicked off with a keynote from Air Vice Chief Marshal, Amorn Chomchoey, who heads the Thailand National Cyber Security Agency (NCSA). He highlighted the extensive and downright exhausting work being done by the NCSA to combat cyber-crime in the country, claiming to have brought financial losses from cyber-crime from an average of 150 million Thai Baht (THB) to 30 million THB daily. Nonetheless, a lot of work remains to be done and he highlighted the importance of a shift towards Zero-Trust architectures.
Echoing the comments of the Air Vice Chief Marshal, GSMA’s Julian Gorman, Head of Asia-Pacific, said, “Compliance is history; Trust will be the way we navigate into the future.” In the APAC region, not dissimilar to their global peers, the traditional focus has been to ensure that security procedures are tightly coupled with metrics and measurement, along with perceived successful defense postures, was against compliance, to those procedures. But this approach needs to be updated to zero-trust with multi-layered defense a key pillar of any future defense strategy to be employed by enterprises and service providers. As Sean Yang, Global CSO, Huawei, remarked, “The era of passive defense is over!”
The Growing Attack Surface
As the telecoms industry transitions into the AI-era, increasingly rapid innovation cycles are driving new services, new devices, AI agents and advanced robotics and pushing telecom service providers to adapt quickly to ensure security. With new device form-factors like AI glasses and robots, the attack surface is also expanding exponentially. If we think of the emerging class of AI agents as endpoints on the network, as highlighted by Dr Chunchi Liu of Huawei, then the attack surface is even more complex and greater to contemplate.
The traditional approach to network defense has been similar to an old adage from Western movies - "circle the wagons" — that is, establish a hard perimeter to keep bad actors out. Today, that approach is outdated and obsolete. The 2025 GSMA Intelligence Security Survey revealed a complex threat landscape, highly sophisticated, and increasingly disparate. Beyond established attack types like DDoS, phishing, and malware, operators are now confronting threat vectors where the source and mechanism are largely uncertain. GenAI-driven attacks, deepfakes, and the looming shadow of quantum computing represent significant blind spots for the industry.
The Confidence Gap
Telco confidence about their readiness posture remains robust when securing traditional network domains—the core, the transport layer, and the RAN. However, confidence wanes precipitously when looking at IT systems, cloud environments, and BSS/OSS architectures. Operators perceive high threat levels from GenAI attacks, ransomware, and signaling vulnerabilities, yet they freely admit their readiness to defend against these specific threats is lacking. Dr Varin Khera, the Founder/CEO of SecStrike, made a telling comment that “Telcos are like living museums.” Dr Khera was speaking in the context that over the years, telcos have continued to run great numbers of legacy equipment, platforms and software without cleaning house. This legacy “baggage” can also include vulnerable inventory and systems which are prime targets for hackers. Indeed, Dr Khera cited a live example of an attack on an operator where the original access happened through an internal Exchange server, deployed for employee email.
The AI Paradox: Rescue or Risk?
Artificial Intelligence (AI) has massive potential for boosting network security, but the reality is that AI is a double-edged sword. On one hand, operators see immense promise in AI and machine learning for threat detection and analysis, automated incident response, and comprehensive log analysis. It offers the speed and scale necessary to combat modern threats.
On the other hand, the deployment of AI introduces profound concerns. GSMA Intelligence survey data indicates that operators are deeply worried about data privacy and security when feeding sensitive network data into AI models. Furthermore, the risks of false positives and negatives, combined with a fundamental lack of explainability and trust in AI decision-making processes, are causing significant hesitation. There is also an emerging but major risk from rapid deployment of AI agents, which generates significant East-West traffic, but also captures a lot of credentials for unauthorized access. Dr Liu cited the example of AI agents built on OpenClaw that have been widely deployed but there are
Ultimately, the challenge is not just deploying AI but securing the "whole estate”, managing the widened attack surface of the cloud while preparing for the unprecedented disruption that quantum computing will inevitably bring. To secure the “whole estate”, operators will need to adopt an end-to-end, multi-layer, and multi-domain security architecture, requiring deep network-security integration across the application layer, the device layer, the operations layer, the IP transport layer, and the core network itself. In other words, operators must move towards native security for future AI-native networks.
How can we support you?
Get in touch
Contact the GSMA Intelligence support team for help with your account, subscriptions, or access to reports and insights.
Newletter
Subscribe to the GSMA Intelligence newsletter for the latest industry news and insights, delivered to your inbox
- 200 reports a year
- 50 million data points
- Over 350 metrics
How can we support you?
Get in touch
Contact the GSMA Intelligence support team for help with your account, subscriptions, or access to reports and insights.
Newsletter
Subscribe to the GSMA Intelligence newsletter for the latest industry news and insights, delivered to your inbox.

