The European Commission (EC) and most of its European Union (EU) member states published a coordinated risk assessment report on 5G network security. The release is part of an ongoing process that began earlier this year tied to identifying main threats and “actors” that could impact 5G network security.

The report notes that 5G networks could pose a greater cybersecurity risk than past technologies due to the greater use of software to control functions and edge networking components to serve more use cases.

“With 5G networks increasingly based on software, risks related to major security flaws, such as those deriving from poor software development processes within suppliers are gaining in importance,” the report states. “They could also make it easier for threat actors to maliciously insert backdoors into products and make them harder to detect.”

That supplier angle also tied into increased security risks due to the growing number and reach of suppliers of key infrastructure.

“A major dependency on a single supplier increases the exposure to a potential supply interruption, resulting for instance from a commercial failure, and its consequences,” the report explains. “It also aggravates the potential impact of weaknesses or vulnerabilities, and of their possible exploitation by threat actors, in particular where the dependency concerns a supplier presenting a high degree of risk.”

5G Geo-Political Security Concerns

The latest report also identifies the 5G market’s largest vendors. This includes Huawei, Ericsson, and Nokia as being “main suppliers,” and ZTE, Samsung, and Cisco as “other suppliers.” It also points to possible geo-political issues tied to the headquarters of those suppliers.

“Some of these suppliers are headquartered in the EU (Ericsson and Nokia) while the others are headquartered outside the EU,” the report states. “Their corporate governance presents notable differences, for example in terms of level of transparency and type of corporate ownership structure.”

It also noted that some European Union (EU) members have “identified that certain non-EU countries represent a particular cyber threat to their national interests, based on previous modus operandi of attacks by certain entities or on the existence of an offensive cyber program of a given third state against them.”

The report includes a spider chart that graphically shows member concerns.

The geo-political topic is tangentially tied to ongoing U.S.-led efforts to bar equipment from China-based vendors – like Huawei and ZTE – from 5G deployments in Western countries.

While the U.S. has threatened to limit the sharing of intelligence information to countries that allow those vendors to supply equipment to 5G networks, some countries have moved forward on allowing their country’s telecom operators to use that equipment.

German operators Vodafone Germany and Deutsche Telekom, for instance, have recently launched 5G networks in that country using Huawei equipment. Those operators have stated that the Huawei equipment is superior to that of equipment offered by rival vendors Nokia and Ericsson, which in turn those vendors have categorically denied.

Ongoing 5G Cybersecurity Process

The report release is part of an ongoing EC process that was initially proposed in late March. That proposal called for EU member states to identify main threats and “actors” impacting 5G networks; how sensitive 5G network components and functions are to possible security threats; and the different types of vulnerabilities that can arise from the 5G supply chain.

The EC also recommended that member states work with suppliers and operators toward ensuring network security. Those member states have the right to “exclude companies from their markets for national security reasons, if they do not comply with the country’s standards and legal framework.”

Two dozen EU member states in July completed the first step in setting up national risk assessments tied to securing their 5G networks.

The next step is the release of a complementary report from the European Agency for Cybersecurity that will include a specific threat landscape “mapping related to 5G networks, which considers in more detail certain technical aspects covered in the report.”

The EC also noted that it’s expecting its NIC Cooperation Group to provide an agreed upon “toolbox of mitigating measures to address the identified cybersecurity risks at national and union level” by the end of the year.