indonesia telecom sdx crop
– Tropic Creative/Getty Images

Mobile network operators (MNOs) are bogged down by too much red tape to bulletproof their cybersecurity, the GSMA has warned in a new report.

The mobile communications trade body claimed 80% of cybersecurity operations time is devoted to audits and compliance tasks instead of threat detection or incident response. This was put down to “poorly designed, misaligned or overly prescriptive regulation” that in some cases, is helping to increase the risk of cyber attacks instead of remediating the threat.

The report, which surveyed 14 MNOs across Africa, Asia Pacific, Europe, Latin America, the Middle East, and North America, revealed operators are spending $15-19 billion annually on core cybersecurity activities, a figure expected to rise to $40-42 billion by 2030.

Examples of a “fragmented and inconsistent” regulatory environment include that belonging to Europe, which was called out by the GSMA for multiple and overlapping frameworks such as the Network and Information Systems (NIS2) Directive, the Cyber Resilience Act (CRA), the Digital Operational Resilience Act (DORA), and the AI Act.

Worsening the situation are “prescriptive ‘box-ticking’ rules that mandate tools or processes rather than focusing on real-world security outcomes,” according to the researchers.

A similar complexity can be found in cybersecurity budgets, which now sprawl all across segments of the organization, extending beyond traditional IT budgets.

These funds were reported as divesting investment from other areas of the business, such as service improvements, network quality, or new products.

Singled out as possible regulatory role models were cybersecurity frameworks from Australia and Singapore, which the GSMA said both allowed for flexibility for operators while offering a single unified reporting regime to one body instead of multiple organizations. The nations were also praised for recognising the interdependence of key sectors and the demand for consistent underlying protections.

The report comes as cybersecurity grows in threat to all sectors, with telecoms especially smarting from recent intrusions such as the China-affiliated Salt Typhoon assaults from last year.

One country that may be loosening the ropes on regulation is the U.S., with the Federal Communications Commission (FCC) repealing security regulations on operators, with voluntary assurances to replace Democrat-era directives on securing network cybersecurity.