Enterprises are increasingly adopting private 5G connectivity as either a primary or backup path for their growing networking needs, which is placing increasing pressure on ensuring that an organization’s security posture is being fully ported to the cellular world.

Most 5G operators are tackling the pure transport security needs using either the embedded security standards provided in the 5G specification or by adding their own layers of additional security on top. But enterprises are faced with now dealing with a more mobile and diverse connectivity geography that with the additional bandwidth being provided by 5G can open up new security concerns for traffic being transported from those devices into the enterprise.

Netskope Chief Platform Officer Joe DePalo told SDxCental in an interview that enterprises are indeed increasingly tapping into 5G connectivity to power more advanced use cases, but that many are glossing over the security component when they are deploying those 5G devices into the wild.

“What we have seen is the enterprise using 5G typically is scrambling to consider and/or deploy a security component because they got a little ahead of themselves, which is fairly typical evolution when you think about internet, you think about public cloud, you think about applications,” DePalo said. “Now with 5G, typically the business is ahead of security when it comes to deployment of enabling functionality before securing. It's not a-typical of the market.”

DePalo added that this scrambling results in enterprises looking for security help after the fact.

“The overwhelming majority of the customers that we see that are using 5G for operating business are, I wouldn't say surprised, but they're definitely looking for solutions versus there being a standard,” DePalo said.

Securing the private 5G device One area where the industry is coalescing to help with the issue of device security is the use of eSIM technology. This is basically an electronic subscriber identity chip in a device that can act as a unique identifier for devices connecting to a network and thus allow for connectivity control over that device.

Ericsson, Microsoft, and French multinational Thales recently worked with T-Mobile US, Japan’s SoftBank, and Telia Sweden on a new service that uses secure access service edge (SASE) (SASE)-embedded SIM cards to support secure remote provisioning of enterprise devices. That work tapped into the Ericsson Virtual Cellular Network (EVCN) program, which is a new program designed to automate digital SIM (eSIM) profile management and allows an enterprise to activate and manage eSIM-based device access.

Analyst firms have noted the advantage of using eSIM technology to help bolster a device’s security posture.

IoT Analytics explained that the “technology incorporates embedded secure elements, providing advanced security features compared to traditional SIM cards. The secure element acts as a hardware root of trust for asymmetric encryption, ensuring secure end-to-end communication.”

DePalo noted that this push toward eSIMs also eases device management as the technology can be used across the device and operator ecosystem.

“From a technical perspective, the carriers are standardizing on the eSIM and use it so you don't have to have different clients or a different method for every carrier,” DePalo said.

That level of standardization should help enterprises better manage the growing number of 5G connected devices running across their private 5G deployments.

“Believe me, every security member of an enterprise is aware of the security solutions and every network team is aware of the physical mediums, it's peanut butter and chocolate: do you get them to talk together,” DePalo said, noting that these embedded systems “will solve that problem.”