The open architecture that enables strong and scalable 5G connectivity will also make for complex security challenges in 2023, according to telecom security company SecurityGen.

The company has been pushing operators to upgrade network defenses, and recently opened its testing lab. Telcos can test and validate 5G network security solutions in the lab as well as engage with a training platform on 5G’s specific threat vectors.

Last week, SecurityGen released its top five priorities for telecom operators in 2023. Its council boiled down to a memorandum for telcos: Because operators are such high-target entities for ransomware, they must take a more hands-on and collaborative approach in addressing the security threats of openly integrated – and moreover non-standalone (NSA) – 5G technology.

“Operators are large, high-profile companies that serve millions of customers and earn millions in revenue. It’s this that makes them high-value targets. Any company, whether digital or not, must today have a well-defined level of cyberresilience in place as part of its business strategy,” SecurityGen co-founder and CTO Dmitry Kurbatov told SDxCentral.

5G’s Double-Edged Security Sword   

As Kurbatov said in an earlier interview, what makes 5G robust and flexible also makes it vulnerable to hidden threats. This means as 5G adoption continues to proliferate, telcos must be ready to address its unique challenges.

“It’s clear that non-standalone 5G networks will be the dominant version of 5G for a while," he said. "Securing these networks means protecting legacy systems like evolved packet cores [EPCs] and IMS [IP multimedia subsystems].

While “basic security measures” have been implemented in recent years, Kurbatov claims the next steps are learning how to integrate “comprehensive proactive controls and continuous monitoring,” as the virtualization of 5G has brought in a slew of new features, services, and applications that need to now be accounted for by operator security teams.

Part of this will be industry collaboration, as “there is no single silver bullet solution for effective cybersecurity,” he explained. Enterprises will need to share actionable practices with the industry to help resolve the emerging risks and threats as open architecture demand expands.

This type of telecom coopetition (i.e., cooperation between competitors) is epitomized by groups forming to protect telcos and their user bases from the projected dangers of quantum computing, and Verizon’s recent trials sharing the challenges around its quantum-safe technology deployments.

“Effective 5G security requires more than just installed software solutions and automated monitoring and testing,” SecurityGen noted in its press release. “Extensive and ongoing training is also essential so that operator security teams can explore and stay up to date with the latest cyberthreats – and also identify new vulnerabilities as they emerge.”

Kurbatov also emphasized focused communication up to the C-suite.

“If I have to point to one detail above all else, it is for telco security teams to brief your senior leadership on the operational importance of cyberresilience. Earn their support by keeping them well-informed about the latest risks and threats and how to mitigate them,” he advised.

The company's position is that this mitigation will require the adoption of ongoing end-to-end network assessments and monitoring because "5G networks are a step-change in complexity that are more like IT systems than legacy mobile networks." Those incessant security checks and analyses will be key in constructing defense measures "fine-tuned for the telecom environment."