enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Global Head- Advanced Consulting Services at Nokia

Stay Ahead in the 5G Era: 6 Best Practices for Next Generation Security Operations for CSPs

Srinivas Bhattiprolu, Global Head- Advanced Consulting Services at Nokia

Maintaining the security of communication service providers’ (CSP) environment is a constant struggle for CSPs and governments. Cyberattacks are frequent and increasing in complexity andstate sponsored attacks are a significant risk.

Cloudification, virtualization, multiplying application programming interfaces (APIs) and open 5G architectures are dramatically increasing the network attack surface, giving malicious actors more points of entry and more opportunities to break through. Communications service provider (CSP) security teams have to scramble to fend off attacks amid nonstop alerts and floods of log data that make it hard to tell real incidents from false alarms. All this while the costs and consequences of breaches continue to climb.

There is a sense of urgency amongst CSPs to build and grow their 5G businessas its adoption gains momentum. Critical Infrastructure Security is of paramount importance to the sustainability of CSPs. 5G securitybecomes a very important focus area for CSPs as they provide advanced 5G services to their esteemed customers.

Security operations teams are under pressure to defend against cyber threats and contain the cost of breaches — protecting network environments that have never been more open or more challenging to secure.

The function of the security operations center (SOC) is to monitor, prevent, detect, investigate, and respond to cyber threats around the clock. SOC teams are charged with monitoring and protecting the CSP's assets including intellectual property, personnel data, business systems, and brand integrity.Constantlyexposed to various threats, CSPs are starting to place the security of their network infrastructure as a top priority. Security Operations Center (SOC) is now an essential part of the protection plan and data protection system that reduces the level of exposure of information systems to both external and internal risks for CSPs. 

Key technology trends that impact 5G security

Over the past decade, according to the World Economic Forum (WEF) Global Risks Report, cybercrime has moved from being a specialist crime to one of the most significant strategic risks facing the world today. The 2022 report warns that a growing dependency on digital systems, intensified by COVID-19, has transformed societies. CSPs play a pivotal role in accelerating digital transformation by providing the most important element – resilient connectivity through its 5G services– hence they become the primary target for attacks. 

Lower barriers to entry for cyberthreat actors are more aggressive attack methods, a dearth of cybersecurity professionals, and patchwork governance mechanisms.These issuesaggravate the risk to critical infrastructure. This will be especially true in the years ahead as we go further into the 5G era. As new 5G services targeted at consumers and enterprises continue to proliferate, security will be one of the most important factors for driving the success of digital transformation in society. While CSPs continue to build their 5G business, they should be aware of these two important security trends:

Macroeconomic trends- geopolitical environments and COVID-19 are known trends but we now see country specific regulations being drafted to protect critical infrastructure. A new EU draft law, NIS2, sets out tighter cybersecurity obligations regarding risk management, reporting obligations, and information sharing. The punitive measures for not conforming to the regulatory standards are growing enormously. CSPs will bear the brunt of these regulatory changes and so will the critical infrastructure suppliers. Also, there is a looming shortage of skilled professionals in security. By 2023, it’s expected that the industry will fall short of 2 million workersThis will cause current security professionals to be overworked which will affect their effectiveness and productivity.

Technology trends-New vulnerabilities are always coming to light, and they can be difficult to fix. A prime example of this emerged in December 2021 with an obscure but frequently used piece of software called Log4j.The use of AI in building new threat vectors is becoming a reality. AI can be a double-edged knife; it can preclude attacks,but it can also generate new types of attacks exploiting new vulnerabilities. More efficient ransomware is the biggest threat for critical infrastructure. Insider threats still pose a challenge as the job market shifts in the wake of the pandemic. Further, the number of tools that are emerging to protect critical infrastructure is growing exponentially. It is impossible for CSPs to procure all these tools due to budget constraints. There is an increasing focus to evolve and make best use of existing tools to protect the critical infrastructure.

How is  5G different from 3/4G from a security operations perspective?

The main difference between 5G and 3/4G is that  5G security operations requires end-to-end optimization without any compromise, from devices and access sites to the cloud edge and network core.

There is a myriad of threat vectors, and attacks can ensue with or without any human involvement in the 5G realm. Additionally, the scale of infection spread is very high and rapid in the case of 5G making the negative ramification more pronounced. We’ve identified industry best practices to combat the evolving threat vectors across levels of 5G.

Security operations best practices

There are a multitude of cyber threats and vulnerabilities  so there is no silver bullet for ensuring resilient 5G security operations.However,  there are a few best practices that will aid in effective 5G security:

To sum up the importance of 5G security operations

5G is at an inflection point and expanding rapidly into mission critical areas especially with the imminence Industry 4.0.Security and privacy concerns will hinder5Gadoption and growth if CSPsdon’t implement robust security operations to alleviate these apprehensions. Governments must focus on driving unified standards/regulations for 5G security an improve awareness of the same among the key stakeholders. It goes without saying that building a strong security operations team and capabilities is the biggest long-term sustainable advantage for CSPs.  However, this needs to be supplemented with the development of some intellectual property around key outcomes / propositions to protect their critical infrastructure. Failure to do this will result in obsolescence.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.