Security obligations for networks, and for the enterprises that have started operating their own. Private 5G moved this domain out of the carrier world and into manufacturing, ports, mining and hospitals.
What we track
UK Telecommunications Security Act
UK. The security duties and the code of practice, and how the regulator is enforcing both.
EU 5G toolbox
EU. Risk mitigation measures, and the national implementations that give them legal force.
High-risk vendor restrictions
EU, UK and US. Which suppliers are restricted, in which parts of the network, and by when.
NIS2 digital infrastructure
EU. Where network and service providers sit in scope, with ENISA implementation guidance behind it.
Private network deployments
All jurisdictions. Obligations attaching to enterprises that operate their own spectrum and core.
Interconnect and signalling
International. Security work on the protocols between networks rather than inside them.
Who is in scope
Public network operators and service providers, through telecoms-specific regimes that predate NIS2 and are stricter than it. In the UK the Telecommunications Security Act applies to providers by size tier, with the largest facing the shortest timescales.
Enterprises with private networks are the new and unprepared group. Deploying your own 5G core for a factory, port, mine or hospital campus means operating telecommunications infrastructure, and the obligations differ by jurisdiction and by how you obtained spectrum.
Where the deadlines fall
Vendor removal deadlines are the hard ones, set in years and tied to network layers, with the core usually first and the access network later. Code of practice timescales are tiered, so a tier one provider and a tier three provider face different dates for the same measure.
Equipment refresh cycles run longer than compliance deadlines, which is the recurring problem in this domain: the compliance date lands before the capital plan does.
Where organisations get caught
Running a private network can make you a regulated entity. An enterprise that deploys its own core has taken on a piece of telecommunications infrastructure. Those duties are different from the ones it already meets as a manufacturer. Procurement usually buys it as an IT project.
Vendor restriction timing. Removal deadlines assume a refresh you may not have budgeted, and derogations are narrower than vendors suggest during a sales cycle.
The boundary. Enterprise security teams are used to owning everything inside the perimeter, and a private network introduces components, a spectrum licence and an operator relationship that sit outside the usual model. Nobody is quite sure who patches the core.
Questions worth asking now
- Do we operate any private cellular network, or plan to?
- If so, in which jurisdiction, on what spectrum, and does that make us a regulated provider?
- Who patches and monitors the core, and is that in a contract?
- Which restricted vendors are present anywhere in our network estate?
- What is the removal deadline, and does our refresh cycle meet it?
- If we buy connectivity rather than operating it, what security commitments did we actually get?
Related domains
Cybersecurity regulation covers the NIS2 duties for digital infrastructure. Cyber-kinetic and OT security covers the plant these networks usually serve. Third-party and supply chain risk covers vendor restrictions.