Telecommunications as Essential Entities
Under NIS2, telecommunications providers are classified as essential entities — the highest regulatory tier. This means stricter supervision, higher penalties (up to 2% of global turnover or €10M), and proactive regulatory oversight rather than reactive enforcement.
5G infrastructure introduces new security challenges that traditional telecom security frameworks don't fully address: software-defined networking, cloud-native core networks, multi-vendor RAN, and edge computing.
NIS2 Requirements for Telecom
Article 21 — Security Measures
NIS2's 10 minimum security measures applied to telecom infrastructure:
- Risk analysis (Art. 21(2)(a)): Comprehensive risk assessment of 5G core, RAN, transport, and edge infrastructure — including geopolitical vendor risk
- Incident handling (Art. 21(2)(b)): 24-hour early warning, 72-hour full notification. Telecom incidents often affect millions — classification must account for subscriber impact.
- Business continuity (Art. 21(2)(c)): Network resilience planning — what happens when a core network function fails? When a RAN site goes down?
- Supply chain security (Art. 21(2)(d)): 5G supply chain is geopolitically sensitive. EU Toolbox on 5G Security requires assessment of "high-risk vendors."
- Network security (Art. 21(2)(j)): Network segmentation between 5G network slices, user plane separation, signalling security (Diameter/GTP)
5G-Specific Security Challenges
- Cloud-native core: 5G Standalone core runs on Kubernetes — all K8s security challenges apply (container security, RBAC, network policies, supply chain)
- Network slicing: Each slice must be isolated — a compromised IoT slice must not affect the enhanced mobile broadband slice
- Multi-vendor RAN (Open RAN): O-RAN architecture introduces interfaces between vendors — each interface is an attack surface
- Edge computing (MEC): Processing at the network edge — physically distributed, harder to secure, higher attack surface
- API exposure: 5G Network Exposure Function (NEF) exposes network capabilities via APIs — requires OAuth 2.0, rate limiting, and input validation
Supply Chain & Vendor Risk
The EU 5G Security Toolbox and national implementations (Netherlands: Telecomwet amendments) require:
- Vendor risk assessment: Evaluate vendors against criteria including country of origin, corporate governance, and susceptibility to government interference
- High-risk vendor restrictions: Limit or exclude high-risk vendors from core network functions and sensitive locations
- Multi-vendor strategy: Avoid single-vendor dependency for critical network functions
- Software supply chain: SBOM requirements for network functions running on cloud-native infrastructure
This intersects directly with NIS2 Article 21(2)(d) on supply chain security and the broader EU approach to strategic autonomy in critical infrastructure.
Kubernetes Recipes
A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).
Watch on Skillshare →Implementation Priorities
- Kubernetes security for 5G core — Apply the same controls as any regulated K8s environment: RBAC, network policies, pod security, image signing, runtime monitoring
- Network slice isolation testing — Verify that compromising one slice cannot impact others (penetration testing + chaos engineering)
- Signalling security — Protect Diameter, GTP, and HTTP/2 signalling interfaces against interception and injection
- Incident response for mass-impact events — Telecom incidents affect millions. Response procedures must scale accordingly.
- Vendor diversification roadmap — Document current vendor dependencies and plan for strategic diversification where concentration risk exists
Related Solution
Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 3-4 weeks.
Explore AI Readiness for Regulated Enterprises →
Luca Berton