Telecom cybersecurity is changing fast: What operators need to know
Author
The double edge sword of Artificial Intelligence, expanding attack surface and stricter regulations
We live in an era where rapid advances in emerging technologies, policies, IT and communications are reshaping telecom networks faster than ever, while also creating new challenges.
AI is already changing telecom networks, helping operators boost efficiency, automate processes and strengthen their defences. But it is also giving attackers new tools. Cyber-attacks can now happen faster, at greater scale and with more sophistication than before. At the same time, telecom networks are becoming more exposed.
Similarly, Cloud-native functions, APIs, containers, open RAN and the convergence between IT and network domains all create more potential for new services, network flexibility and scalability but they also introduce new entry points for attackers and more opportunities for lateral movements. For example, a breach in enterprise IT, support systems or cloud platforms can expose CT environments, undermining service availability and resilience.
Regulations also act as a double-edge sword in telecom cybersecurity. While regulators and policy makers establish essential baselines for data protection, they can also restrain innovation and create rigid compliance traps. Today (and likely in the days to come) cybersecurity is no longer a nice-to-have, but a core business requirement for operators. There is an increasing need for compliance with overlapping requirements across cybersecurity, telecoms regulation, data protection, AI governance, critical infrastructure protection and cross-border data management. Regulators are focusing on more perspective obligations, including audit requirements, mandatory reporting timelines, security by design and stronger oversight of third-party vendors.
An idea for the future of cybersecurity governance and architecture
So, what does all this mean for operators?
The old approach of protecting different parts of the network with perimeter defences and a patchwork of security tools is no longer enough. Operators need to shift from simply reacting to cyber risks to building real cyber resilience.
That means having a governance model that makes it clear who is accountable, who owns each risk, who makes key decisions and how senior leaders stay involved.
Asset-centric security governance: A good place to start is with the implementation of asset-centric security governance, by identifying the assets that matter most to keep services running and making sure they get the strongest protection.
It also means rethinking telecom cybersecurity architecture around the principles of Native Security, In-Depth Defense, Network and Collaboration, Differentiated Detection & Response and Dual SOC.
Native Security: Security can no longer be an add-on. It must be seamlessly embedded into network elements from the initial design and production phases through to deployment and daily operation.
In-Depth Defense: Operators must transition to layered, domain-based protection, because a single-point defense system can easily be breached by persistent, intelligent attacks.
Network Control and Collaboration: Defense systems must be unified across network control and security intelligence. Telemetry data generated by network infrastructure must be rapidly analysed by security systems and seamlessly converted into actionable policy.
Differentiated Detection & Response: Generic Endpoint Detection and Response (EDR) systems deployed blindly across the whole telecom network are insufficient. Endpoint protection must adapt dynamically to the specific asset type and network domain.
Dual SOC: Operators should establish separate, yet highly coordinated, security operations centers-an IT-SOC and a CT-SOC to ensure specialised attention without sacrificing holistic visibility.
This translates to an end-to-end, multi-layer, and multi-domain security architecture. It requires deep network-security integration across the application layer, the device layer, the operations layer, the IP transport layer, and the core network itself.
An example of practical implementation of this architectural shift is shown by China Mobile. In 2025, following extensive testing and standardisation, China Mobile commercially launched a new security approach across its network. By bringing security natively across both cloud and network domains, they established a multi-layered defense spanning device-level, connection-level, operations-level, and application-level security. The core concept driving their success was using 5G network elements to gain a true full-stack view of device-level security.
The broader implication and the B2B opportunity
Cybersecurity is quickly becoming a key part of critical infrastructures resilience. Operators are not just protecting their own networks anymore; they are also helping safeguard the digital infrastructure that public services, enterprises and financial systemsrely on. This opens up a big B2B opportunity, that can let operators gain part of the cybersecurity market that GSMA Intelligence estimated to be worth $289 bn by 2030. By turning internal security capabilities into security-as-a-service offerings, operators can support governments, enterprises, industry partners and private 5G customers with services built on their own security expertise and architecture.
Want to know more about it? Download the free GSMA Intelligence white paper: A target architecture for telecoms cybersecurity
How can we support you?
Get in touch
Contact the GSMA Intelligence support team for help with your account, subscriptions, or access to reports and insights.
Newsletter
Subscribe to the GSMA Intelligence newsletter for the latest industry news and insights, delivered to your inbox.
- 200 reports a year
- 50 million data points
- Over 350 metrics
How can we support you?
Get in touch
Contact the GSMA Intelligence support team for help with your account, subscriptions, or access to reports and insights.
Newsletter
Subscribe to the GSMA Intelligence newsletter for the latest industry news and insights, delivered to your inbox.

