HardenStance’s MWC 2025 review says telco cybersecurity is improving, but only incrementally, with regulators, vendors, and operators increasingly focused on scam protection, network hardening, and AI-driven security. The report highlights major gaps in telco preparedness alongside rising threats from AI fakes, China-nexus intrusion activity, and continued pressure to deploy practical protections such as DNS filtering, fraud registries, and Open Gateway APIs. #SaltTyphoon #LiminalPanda #LocksmithPanda #OperatorPanda #LightBasin #STC #Singtel #Telefonica #Whalebone #Aeris #Nokia #Ericsson #Allot #Bitdefender #Enea #F-Secure #GenDigital #Mobileum #Netnumber #PowerDNS #Ribbon
Keypoints
- This annual report follows a typical conference-review structure: an opening executive takeaway, followed by thematic sections, vendor-by-vendor observations, key threat-intelligence highlights, and a concluding view on market direction and regulation.
- The main sections are telco network protection, enterprise network protection, and user protection, with each section focusing on products, operational challenges, vendor announcements, and the practical security problems those tools are meant to address.
- The report emphasizes that telco security remains fragmented and slow-moving, with most vendors offering incremental improvements rather than breakthrough innovation in telco-specific security operations.
- A major headline finding is the UK NCSC CTO’s “C+ at best” assessment of telecom cybersecurity, which the report uses to frame the sector’s persistent weaknesses in posture, awareness, and execution.
- The report highlights a mismatch between confidence and reality: operators are still being compromised through default passwords, poor configurations, and limited visibility into software and infrastructure.
- A recurring theme is the growing importance of AI in both defense and attack, including AI assistants for incident handling, AI-based scam detection, and the new challenge of AI-generated fakes that undermine trust in what users see and hear.
- Threat intelligence cited from CrowdStrike shows China-nexus activity increased 50% in 2024 versus 2023, underscoring continued strategic targeting of government, technology, and telecommunications sectors.
- CrowdStrike identified seven new China-based targeted intrusion adversaries in 2024, including high-capability groups such as LIMINAL PANDA, LOCKSMITH PANDA, and OPERATOR PANDA, each with specialized telecom targeting tradecraft.
- The report repeatedly notes that telco security operations remain difficult to commercialize, with legal, privacy, data protection, and scalability issues slowing adoption of AI-driven SOC platforms and telco log/traffic inspection solutions.
- In telco network protection, Ericsson, Nokia, and Netscout present more mature operational tooling, including security automation, signaling protection, DDoS mitigation, PCF-based mitigation, and threat hunting tied to mobile network telemetry.
- Ericsson’s updates include a Gen AI Assistant for Ericsson Security Manager, integration with Post Luxembourg’s TIDS for roaming signaling detection, and customized Integrated EDR for the radio baseband environment.
- Netscout’s roadmap focuses on more granular visibility and mitigation, including traffic classification, packet-level analysis, retrospective review, and enabling mitigations through the Policy Control Function.
- Nokia’s Cyberdome demo centers on proactive detection and hunting, using threat intelligence, telemetry mapping, and OpenAI LLMs in Microsoft Azure to generate attack playbooks and update SOC rules quickly.
- In enterprise network protection, the market is shifting toward telcos as distribution channels for security services, especially SASE, NGFW, and IoT security, rather than telcos buying only for their own infrastructure.
- Aeris stands out with IoT WatchTower, described as the first fully integrated cellular IoT security solution, built into the connectivity layer and requiring no agent or custom SIM card.
- F5’s AI Gateway, Fortinet’s Sovereign SASE, Juniper’s SRX 4700 NGFW, and Palo Alto Networks’ Prisma SASE 5G all show vendors trying to converge security and connectivity for enterprise 5G and AI traffic.
- Palo Alto Networks’ Singtel deployment is notable for protecting more than 20,000 customers, filtering over 600,000 malicious URLs, and blocking more than 5,000 threats daily through 5G slice-based security.
- In user protection, regulators play a much larger role than before, pushing telcos toward scam blocking, identity verification, call authentication, and consumer-facing security services.
- Allot’s turnaround is supported by renewed revenue growth and a 49% year-over-year increase in Security as a Service, alongside products like OffnetSecure that extend protection beyond the home network.
- Bitdefender, F-Secure, and Gen Digital all focus on multi-stage scam protection, combining endpoint, router, DNS, identity, and phishing defenses rather than single-point detection.
- Gen Digital’s LifeLock and Genie illustrate the move toward identity restoration and AI-assisted authenticity checks, while F-Secure’s TOTAL suite added seven AI-driven scam protection features.
- Mobileum’s recovery after Chapter 11 and its RAID 9 release reflect renewed emphasis on fraud controls, SMS content inspection, AI call analysis, and stronger integration with regulators and DNS infrastructure.
- Mobileum and Enea both note that demand for SEPP solutions remains weak because 5G SA roaming adoption is still slow, while demand for GTP firewalls is rising for reasons that may include attacker adaptation and defenses shifting pressure elsewhere.
- Netnumber’s Fraud Prevention Registry and Dynamic DNO service show how number intelligence, fraud data sharing, and spoofed-call blocking are becoming core anti-fraud capabilities.
- PowerDNS, Ribbon, and Whalebone demonstrate the growing importance of DNS and caller-authentication controls, including DNS filtering, STIR/SHAKEN, and number-based fraud prevention.
- Whalebone’s growth is especially strong, with 17 new telco account wins in a year and significant traction in markets where regulators mandate universally accessible DNS or network-based user protection.
- GSMA Open Gateway APIs are emerging as a major commercial and security platform, enabling use cases such as SIM swap detection, phone verification, age verification, KYC support, and fraud-resistant onboarding.
- Telefonica’s ecosystem examples show tangible business value: Cabify expects a 7.7% improvement in sign-up completion, Itau Unibanco reports about 2 million monthly SIM swap API hits and a 30% call center efficiency gain, and BBVA uses SIM swap signals to adjust authentication.
- Overall, the report’s main takeaway is that telco security is becoming more strategic and more monetizable, but progress is uneven and depends heavily on regulation, telco willingness to invest, and the ability of vendors to move beyond incremental feature upgrades.
Source: Awesome Annual Security Reports - The reports in this collection are limited to content which does not require a paid subscription, membership, or service contract. (https://github.com/jacobdjwilson/awesome-annual-security-reports/)