Skip to main content

Industries

Cyber security for telecom & media.

Carrier infrastructure, subscriber data and content delivery at national scale.

Regulators and frameworks

  • DoT
  • TRAI
  • ISO 27001
Talk to a telecom specialist

What is actually going on here

A telecom operator is critical national infrastructure that also happens to be a consumer business. An outage is a news event and a national security matter at the same time, and the subscriber database is one of the most sensitive datasets in the country because it maps identity to location and communication.

The estate is unusually broad: signalling networks running protocols older than the internet, an IT estate like any large enterprise, a retail channel, and increasingly virtualised core network functions that behave like cloud infrastructure and need testing as such.

We work across the network, IT and channel sides, and reconcile what DoT, TRAI and CERT-In each want into a single set of controls rather than three parallel programmes.

Who regulates you, and what they want

Tick the ones that bind you and we will pull together the evidence each of them actually asks for. Nothing is sent anywhere.

Pick one or more above to see what they expect of you.

What goes wrong in this sector

  • Signalling network abuse

    SS7 and Diameter were built for a small set of trusted operators. Interconnect access now enables location tracking and SMS interception, which matters most because SMS still carries one time passwords for banking.

  • SIM swap and subscriber takeover

    Usually a retail channel problem rather than a network one. Weak identity checks or a complicit employee, and an attacker owns the phone number that every account recovery depends on.

  • Subscriber data and CDR exposure

    Call detail records reveal who spoke to whom, when and from where. Exposure is typically through an internal analytics or lawful interception adjacent system with access controls that were never reviewed.

  • Core network function compromise

    Virtualised core functions are software, with the same orchestration and container weaknesses as any cloud platform, but with far higher consequence if compromised.

How we work in this sector

  1. 01

    Assess the signalling perimeter

    We test what an interconnect partner could actually do to your subscribers, which is usually more than expected.

  2. 02

    Test the retail channel

    SIM swap and identity verification are tested as a process, including a social engineering component against the channel, because that is how it is actually attacked.

  3. 03

    Treat the virtualised core as cloud

    Orchestration, container and API testing applied to core network functions, since that is what they now are.

  4. 04

    Reconcile the regulators

    One control set mapped to DoT, TRAI, CERT-In and DPDP, so the same evidence serves all four instead of being produced four times.

What we actually keep finding here

Not a threat list copied from a report. These are the patterns that recur across our own engagements in this sector, with an honest note on how often. Where we do not have a precise number we say so rather than inventing one.

  • Often

    Interconnect access enabling more than expected

    Signalling built for a small set of trusted operators, now reachable by many. Location tracking and SMS interception matter most because SMS still carries banking one time passwords.

  • Most engagements

    SIM swap defeated at the retail counter

    Weak identity verification or a complicit employee. It is a process and channel problem far more than a network one.

  • Often

    CDR access far wider than business need

    Analytics and reporting systems adjacent to lawful interception, with access controls that were set once and never reviewed.

  • Often

    Virtualised core treated as network, not as cloud

    Orchestration and container weaknesses in core network functions, assessed with network tooling that was never designed to find them.

Questions worth asking any provider in this sector

Including us. If a provider cannot answer these clearly, that tells you more than any capability slide will. We would rather you asked them than took our word for it.

  1. 1

    Will you test signalling from an interconnect perspective, using test subscribers only?

  2. 2

    Will SIM swap be tested as a process, including the retail channel?

  3. 3

    Do you treat virtualised core functions as cloud infrastructure and test them as such?

  4. 4

    Can you reconcile DoT, TRAI, CERT-In and DPDP into one control set?

  5. 5

    How will you handle log retention volume within Indian jurisdiction?

What we deliver in this sector

  • Telecom core & signalling security review
  • Subscriber data protection assessment
  • OSS/BSS platform testing
  • Data centre & edge infrastructure security
  • Content platform and DRM review
  • DDoS resilience testing
  • Managed detection and response
  • Regulatory audit support

Work in this sector

Named engagements where the client has agreed to be named, and anonymised ones where they have not, which is most of them. Named references are available under NDA.

  • Client withheld

    Operator, subscriber data access review

    Scope
    Analytics and reporting systems holding call detail records, assessed for access appropriateness.
    What we found
    CDR access far wider than business need, with controls set at deployment and never reviewed.
    Outcome
    Access reduced to a named group with periodic review, and query auditing enabled.
  • Client withheld

    Operator, interconnect exposure

    Scope
    Signalling tested from an interconnect perspective against a controlled set of test subscribers only.
    What we found
    More was reachable from an interconnect partner position than the operator expected, including location queries.
    Outcome
    Filtering tightened at the signalling perimeter and monitoring added for anomalous interconnect queries.
  • Client withheld

    Operator, SIM swap process

    Scope
    SIM swap assessed as a process, including a social engineering component against the retail channel.
    What we found
    Identity verification could be satisfied with information available from a data breach.
    Outcome
    Verification strengthened for high risk swaps, a cooling period added before account recovery use, and staff processing anomalies monitored.
All case studies

Questions we get asked in this sector

Can signalling be tested without affecting subscribers?

Yes. We test from an interconnect perspective against a controlled set of test subscribers you provide. No live subscriber is touched at any point.

How do we reduce SIM swap fraud?

It is mostly a process and channel problem rather than a technical one. Stronger identity verification for high risk swaps, a cooling period before the number can be used for account recovery, and monitoring for staff who process an unusual number of them. The last one finds the insider cases.

Do the CERT-In log retention rules apply to network logs?

Yes, and the volume is the practical problem rather than the principle. Retention has to be planned as infrastructure, and it has to stay within Indian jurisdiction.

Can you support us across multiple countries?

Yes. We deliver across fifteen or more countries and are used to reconciling a group security standard with local licence conditions that do not always agree with it.

Not sure where to start?

Book a 30-minute call with a senior engineer. We will walk through your current posture, the frameworks that bind you, and what a realistic programme looks like.