CIO Applications Europe
About UsConferencePartner With Us
Close
  • Applications
      • Business Intelligence & Analytics
      • Call Center Solutions
      • CRM & Customer Experience
      • Data Center
      • Digital Transformation
      • E-Invoicing
      • Intelligent ERP & Automation
      • Risk Management & Compliance
      • Unified Communications (UCaaS)
  • Industries
      • Automotive & Mobility
      • Construction & Infrastructure
      • Financial Services
      • Healthcare
      • Retail & E-commerce
      • Telecom & Media
      • Travel and Hospitality Tech
  • Technologies
      • Cloud
      • Cybersecurity & Resilience
      • Data Engineering & Analytics
      • Generative and Agentic AI
      • IoT & Edge Computing
      • Robotics
  • Platforms
      • AWS
      • IBM
      • Microsoft
      • Salesforce
      • SAP
      • ServiceNow
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • CXO Awards
    • Europe
      • US
  • Topics

  • Menu
      • Business Intelligence & Analytics
      • Cloud
      • Digital Transformation
      • Generative and Agentic AI
      • Microsoft
      • Risk Management & Compliance
      • Travel and Hospitality Tech
      • Unified Communications (UCaaS)
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Generative and Agentic AI
  • Digital Transformation
  • Business Intelligence & Analytics
  • Cloud
Topics
  • Topics

  • Business Intelligence & Analytics
  • Cloud
  • Digital Transformation
  • Generative and Agentic AI
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Unified Communications (UCaaS)
  • Home
  • Telecom & Media

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

Huawei

Nuno Teodoro, Cyber Security Officer

Addressing the 5G threat landscape with standardization and equality

While 5G brings a whole new set of capabilities, opportunities and business cases for enhancing the way society communicates and operates, it is also commonly accepted that it brings additional sources of new potential threats that have the capability to disrupt an entire ecosystem, industry or Nation.

Moreover, as a future digital enabler, 5G will have a massive impact and active role in industries such as medicine, agriculture, energy grids and connected devices (to name a few), thus affecting almost every citizen in the World. This, along with the 5G architecture relying on a bigger decentralization and more software based components, adds several new attack entry points and threat vectors, resulting in an obvious need of added efforts and collaboration from cybersecurity entities such as ENISA, and industry associations such as GSMA and 3GPP, in standardizing an enhanced frameworks for securing 5G networks.

Additionally, taking into consideration that operators will be mostly responsible for the 5G secure rollout, each country will embrace the individual responsibility for national security, thus taking advantage of this a strategic coordinated effort from the European Union (EU) in order to achieve an unified and standardized approach in the cyber security measures around this ecosystem.

With the release of ENISA’s report on the threat landscape for 5G networks, it is clear the need for additional requirements and cybersecurity controls on all the key stakeholders that compose the 5G ecosystem: Service customers, Service Providers and Mobile Network Operators (MNOs) (to name a few), along with new and additional responsibilities and competences for ensuring a trustworthy and safe 5G ecosystem assigned to Network Infrastructure Providers, National Regulators, National Cybersecurity Centers and National Certification Authorities

It is only by combining these new cybersecurity controls and responsibilities and competences, using coordinated actions and following standardized frameworks and guidelines, that the overall objective of safeguarding the 5G networks will be achieved, measured and managed.

As a result, to tackle those requirements, the 5G Toolbox was created, aiming to establish the goal of steering a cohesive and pragmatic framework for cybersecurity, ensuring an adequate level of protection on 5G networks across the EU.

These coordinated efforts among member states are to be implemented across three main groups of measures such as “Strategic measures”, “Technical measures” and “Supporting actions”, where the adequacy of each one of them is a direct result of anin-depth risk management process where key assets defined as critical and sensitive (e.g. core network functions and access network functions) along with supplier risk management, are two of the main impacted areas, where a complex balance should be achieved regarding the implementation of appropriate multi-vendor strategy vs technical security on equipment and products from those vendors.

The thematic, although not simple nor consensual, aims to develop a standardized approach based on audits and risk management, where equality among suppliers should be the baseline, while effectively implementing the toolbox measures for suppliers and equipment, and if necessary, apply restrictions or exclusions (to both) if deemed not secure nor trustworthy when assessed towards a recognized and accepted cybersecurity standard.

As a result, and in order to properly implement the technical measure of using EU certification for 5G network components, customer equipment and/or suppliers’ processes, one of the critical steps will be moving towards a direction of 5G security assessments becoming standardized across the industry, placing NESAS as a cornerstone.

The Network Equipment Security Assurance Scheme (NESAS) is jointly defined by GSMA and 3GPP for security evaluation of mobile network equipment. Developed according to security standard guidelines pertaining to vendors' product development and lifecycle processes, the scheme provides a security baseline to evidence that network equipment satisfies a series of security requirements.

With this into consideration, NESAS brings the following benefits to equipment vendors:

• Provides accreditation from the world's leading mobile industry representative body

• Delivers a world-class security review of security related processes

• Offers a uniform approach to security audits

• Avoids fragmentation and potentially conflicting security assurance requirements in different markets

Additionally, NESAS also brings the following benefits to mobile operators:

• Sets a rigorous security standard requiring a high level of vendor commitment

• Offers peace of mind that vendors have implemented appropriate security measures and practices

• Avoid financial and time waste in conducting individual vendor audits.

We are entering an era where 5G cyber-attack vectors will rule nation states security and may have a high impact in the social, political and economic vectors, thus making this a perfect time for empowering government and regulators to audit telecom operators on their unbiased and transparent selection of suppliers, while suppliers will also have to up their game and provide assurance on their due diligence with regards to the cybersecurity and equipment security.

It is only by using a standardized model, demonstrating and providing the tools and mechanisms totest, in a transparent and independent way, the end-to-end cyber security controls, ranging from source code verification, penetration testing, vulnerability management and compliance with local cybersecurity and privacy laws and regulations, that we will have the ability to truly emerge in the 5G world with security, and take advantage of all its capabilities.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
The Leadership Perspectives forum brings together voices shaping construction technology and innovation. Participation is by invitation only. It features leaders who are not merely observing technological change, but actively contributing to it through digital transformation and execution-driven insights.
EDITOR'S CHOICE
  • Willis Towers Watson

    Legal & General

    Building Technology Foundations That Last

    Mark Hall, Group Chief Technology Officer

  • Willis Towers Watson

    Adp Uk

    "Shift left" Defect Discovery using Agile and DevOps

    Keith Watson, Director Of Devops

  • Willis Towers Watson

    Motor Oil

    Trust, Security Strategy and the AI-Driven Threat Landscape

    Syngelakis J. Christos, Group Data Protection Officer

  • Willis Towers Watson

    Swiss Re [SWX: SREN]

    A Future of Enhanced Human Work

    Sergio Chelli, IT Procurement Manager at Swiss Re [SWX: SREN]

Weekly Brief

loading

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

×
#

CIO Applications Europe Weekly Brief

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from CIO Applications Europe

Subscribe

loading

THANK YOU FOR SUBSCRIBING

CIO Applications Europe
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@cioapplicationseurope.com
  • sales@cioapplicationseurope.com
  • marketing@cioapplicationseurope.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 CIO Applications Europe. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://telecom-and-media.cioapplicationseurope.com/leadership-perspective/addressing-the-5g-threat-landscape-with-standardization-and-equality-nid-2621.html