Industries
Cyber security for telecom & media.
Carrier infrastructure, subscriber data and content delivery at national scale.
What is actually going on here
A telecom operator is critical national infrastructure that also happens to be a consumer business. An outage is a news event and a national security matter at the same time, and the subscriber database is one of the most sensitive datasets in the country because it maps identity to location and communication.
The estate is unusually broad: signalling networks running protocols older than the internet, an IT estate like any large enterprise, a retail channel, and increasingly virtualised core network functions that behave like cloud infrastructure and need testing as such.
We work across the network, IT and channel sides, and reconcile what DoT, TRAI and CERT-In each want into a single set of controls rather than three parallel programmes.
Who regulates you, and what they want
Tick the ones that bind you and we will pull together the evidence each of them actually asks for. Nothing is sent anywhere.
Pick one or more above to see what they expect of you.
What goes wrong in this sector
Signalling network abuse
SS7 and Diameter were built for a small set of trusted operators. Interconnect access now enables location tracking and SMS interception, which matters most because SMS still carries one time passwords for banking.
SIM swap and subscriber takeover
Usually a retail channel problem rather than a network one. Weak identity checks or a complicit employee, and an attacker owns the phone number that every account recovery depends on.
Subscriber data and CDR exposure
Call detail records reveal who spoke to whom, when and from where. Exposure is typically through an internal analytics or lawful interception adjacent system with access controls that were never reviewed.
Core network function compromise
Virtualised core functions are software, with the same orchestration and container weaknesses as any cloud platform, but with far higher consequence if compromised.
How we work in this sector
- 01
Assess the signalling perimeter
We test what an interconnect partner could actually do to your subscribers, which is usually more than expected.
- 02
Test the retail channel
SIM swap and identity verification are tested as a process, including a social engineering component against the channel, because that is how it is actually attacked.
- 03
Treat the virtualised core as cloud
Orchestration, container and API testing applied to core network functions, since that is what they now are.
- 04
Reconcile the regulators
One control set mapped to DoT, TRAI, CERT-In and DPDP, so the same evidence serves all four instead of being produced four times.
What we actually keep finding here
Not a threat list copied from a report. These are the patterns that recur across our own engagements in this sector, with an honest note on how often. Where we do not have a precise number we say so rather than inventing one.
- Often
Interconnect access enabling more than expected
Signalling built for a small set of trusted operators, now reachable by many. Location tracking and SMS interception matter most because SMS still carries banking one time passwords.
- Most engagements
SIM swap defeated at the retail counter
Weak identity verification or a complicit employee. It is a process and channel problem far more than a network one.
- Often
CDR access far wider than business need
Analytics and reporting systems adjacent to lawful interception, with access controls that were set once and never reviewed.
- Often
Virtualised core treated as network, not as cloud
Orchestration and container weaknesses in core network functions, assessed with network tooling that was never designed to find them.
Questions worth asking any provider in this sector
Including us. If a provider cannot answer these clearly, that tells you more than any capability slide will. We would rather you asked them than took our word for it.
- 1
Will you test signalling from an interconnect perspective, using test subscribers only?
- 2
Will SIM swap be tested as a process, including the retail channel?
- 3
Do you treat virtualised core functions as cloud infrastructure and test them as such?
- 4
Can you reconcile DoT, TRAI, CERT-In and DPDP into one control set?
- 5
How will you handle log retention volume within Indian jurisdiction?
What we deliver in this sector
- Telecom core & signalling security review
- Subscriber data protection assessment
- OSS/BSS platform testing
- Data centre & edge infrastructure security
- Content platform and DRM review
- DDoS resilience testing
- Managed detection and response
- Regulatory audit support
Work in this sector
Named engagements where the client has agreed to be named, and anonymised ones where they have not, which is most of them. Named references are available under NDA.
- Client withheld
Operator, subscriber data access review
- Scope
- Analytics and reporting systems holding call detail records, assessed for access appropriateness.
- What we found
- CDR access far wider than business need, with controls set at deployment and never reviewed.
- Outcome
- Access reduced to a named group with periodic review, and query auditing enabled.
- Client withheld
Operator, interconnect exposure
- Scope
- Signalling tested from an interconnect perspective against a controlled set of test subscribers only.
- What we found
- More was reachable from an interconnect partner position than the operator expected, including location queries.
- Outcome
- Filtering tightened at the signalling perimeter and monitoring added for anomalous interconnect queries.
- Client withheld
Operator, SIM swap process
- Scope
- SIM swap assessed as a process, including a social engineering component against the retail channel.
- What we found
- Identity verification could be satisfied with information available from a data breach.
- Outcome
- Verification strengthened for high risk swaps, a cooling period added before account recovery use, and staff processing anomalies monitored.
Questions we get asked in this sector
Can signalling be tested without affecting subscribers?
Yes. We test from an interconnect perspective against a controlled set of test subscribers you provide. No live subscriber is touched at any point.
How do we reduce SIM swap fraud?
It is mostly a process and channel problem rather than a technical one. Stronger identity verification for high risk swaps, a cooling period before the number can be used for account recovery, and monitoring for staff who process an unusual number of them. The last one finds the insider cases.
Do the CERT-In log retention rules apply to network logs?
Yes, and the volume is the practical problem rather than the principle. Retention has to be planned as infrastructure, and it has to stay within Indian jurisdiction.
Can you support us across multiple countries?
Yes. We deliver across fifteen or more countries and are used to reconciling a group security standard with local licence conditions that do not always agree with it.
Not sure where to start?
Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.












