As chief information security officers (CISOs) consider the leap from legacy systems to private 5G networks, they need to understand that this new data-swift environment comes with its own unique set of security challenges and risks.

"5G is architected quite differently than 4G and older mobile technologies," says Zeus Kerravala, principal analyst of ZK Research. "It's cloud-native in design, and the software is built using technologies such as microservices and containers. This provides an enhanced level of security, since if one service or part of the code is breached, it can be isolated and patched quickly versus a monolithic software stack."

While public and private 5G networks use the same software-defined IT, CISOs need to be aware of the unique security challenges that private networks might bring.

Key security differentiators between private and public 5G networks

The main difference in security between public and private 5G networks is the level of control that the organization has over the network. Public 5G networks are owned and operated by mobile network operators (MNOs), while private 5G networks are owned and operated by the organization that needs them.

This difference in ownership and operation leads to several differences in security:

  • Control over access: In a public 5G network, anyone with a compatible device can connect to the network. This means that there is a greater risk of unauthorized access and cyberattacks. In a private 5G network, the organization has control over who can connect to the network. This can be done by using authentication methods such as SIM cards, certificates or passwords.
  • Use of encryption: Public 5G networks use encryption to protect data transmissions. However, the encryption keys are controlled by the MNOs. This means that the organization does not have full control over the security of its data. In a private 5G network, the organization can choose the encryption keys and protocols that they use. This gives them greater control over the security of their data.
  • Deployment: Public 5G networks are typically deployed in large areas, such as cities or countries. This can make it difficult to secure the entire network. Private 5G networks can be deployed in smaller areas, such as a factory or warehouse. This makes it easier to secure the entire network.

Kerravala said that "there are a lot of similarities because they use similar tech, but there are some notable differences in public vs. private networks. The most important is access control. Public 5G networks are designed to provide connectivity to a wide range of users, whereas private 5G is for specific use cases within the boundaries of a company. Access control in a private 5G environment is more centralized and tightly managed," Kerravala said.

"Encryption is critical to both types of networks to protect user data, but companies have more control over key management with private 5G," Kerravala said.

Lisa Pierce, managing VP at Gartner, said a private 5G network offers higher-level security than a public 5G network because it offers restricted access to certain sites, search platforms and other online assets, such as storage. "This benefit helps the user create a tightly controlled and secure network," Pierce said.

Restricted networks, including private 5G networks, are commonly used in schools and corporate offices to control what users can access. However, these are not impenetrable, Pierce said.

How private 5G networks differ in administration of security processes

What are the specific differences in administering security ops for private 5G networks as opposed to other networks?

"The main difference in administering security for private cellular is required SIM authentication," says Matt Addicks, private cellular marketing and strategy expert at Ericsson Cradlepoint. "This means a device would require a provisioned SIM (digital or physical) in order to connect to the network. As opposed to a Wi-Fi network that may or may not have security considerations designed into the network, users may be able to just join with a password."

Another difference is the separation and encryption of data, Addicks said. "SIM configurations can enable data processing and data storage to be separated and protected from the network. Also, unique device identifiers can be encrypted to mitigate risk from any potential rogue base stations or devices," he said.

Finally, private 5G networks have custom security policies; private cellular enables end users to have complete control over their security policies for devices on the network, Addicks said.

"5G is intended to be more pervasive than LTE, and so there are more potential points of entry for bad actors. But the standard itself carries more security capabilities/features than LTE. To this, regulators and select industries are adding additional protection," Pierce said.

Pierce pointed out that 5G networks, private and public, have five properties that, according to Ericsson, contribute to the trustworthiness of the 5G system: resilience, communication security, identity management, privacy and security assurance. No LTE network has all five of these attributes. Each one of these can be bolstered individually as needed, she said.

Kerravala said that network slicing makes a 5G network more secure because traffic can be isolated on each segment, keeping the network in totality much safer.

"With that being said, if the network slicing is not properly secured, a vulnerability in one slice could lead to breaches in others," Kerravala said. "Also, 5G is expected to grow IoT deployments. Many IoT devices have historically been known to have poor security measures, and their increased integration into 5G networks could create more opportunities for threat actors to compromise devices and access the broader network."

CISOs should adopt a layered approach to security

To address emerging security challenges, Cisco Systems says CISOs should adopt a layered 5G security approach that includes the following general security hygiene practices:

  • Perimeter security: This is the first line of defense and should protect the network from unauthorized access. This can be done through firewalls, intrusion detection systems (IDS) and intrusion prevention systems (IPS).
  • Network security: This layer protects the network from attacks that have already bypassed the perimeter security. This can be done through traffic filtering, segmentation and encryption.
  • Endpoint security: This layer protects the devices that are connected to the network, such as smartphones, laptops, and tablets. This can be done through antivirus software, anti-malware software and device hardening.
  • Application security: This layer protects the applications that run on the network. This can be done through application firewalls, code scanning and penetration testing.
  • Data security: This layer protects the data that is stored on the network. This can be done through encryption, access control and data loss prevention (DLP) solutions.

This is Part 3 of a three-part SDxCentral series on 5G security. Part 1 is about 5G and the IoT, and Part 2 examines network slicing.