Telecom security is not a checklist
Modern telecom networks combine decades of legacy technology with increasingly complex 5G infrastructure.
SS7 and Diameter still coexist with 5G Standalone service-based architectures. IMS connects mobile networks to voice services. Virtualised network functions run across cloud and container platforms. SIM and eSIM provisioning introduces another layer of trust and identity.
A security assessment therefore needs to look across the network, not just at individual products. That is where we focus.
Remote and on-site. Signalling and core assessments are often performed remotely; RAN, SIM/OTA and TETRA assessments may require on-site testing depending on the scope. We adapt to each operator's access restrictions and change windows — including out-of-hours testing when production risk requires it.
01 / ScopeWhat we audit
Signalling security
SS7/MAP and Diameter remain critical attack surfaces wherever roaming and interconnection dependencies persist. We assess signalling exposure including:
- subscriber location and tracking
- authentication and signalling abuse
- roaming interfaces
- interception-related attack paths
- fraud scenarios
- signalling filtering and security controls
We test the controls that protect the network against realistic signalling attacks rather than simply checking whether a security feature exists.
5G Standalone Core
5G Standalone introduces a fundamentally different architecture based on service-to-service communication and APIs. We assess the security of the Service-Based Architecture, including:
- service discovery and NRF interactions
- API exposure
- authentication and authorization between network functions
- TLS and certificate configuration
- trust relationships between services
- exposed management and control interfaces
Our testing covers both architectural weaknesses and implementation or configuration issues that can create exploitable attack paths.
RAN security
The radio access network remains one of the most exposed parts of a mobile network. We assess multivendor RAN environments from legacy technologies through 4G and 5G, including:
- authentication and ciphering configuration
- downgrade paths
- radio-layer attack surfaces
- rogue and false base stations
- network exposure to unauthorised devices
- security controls affecting subscriber privacy
Where required, testing is performed on-site using dedicated radio and SDR equipment.
IMS, VoLTE and VoNR
Voice services introduce their own signalling, authentication and trust relationships. We assess:
- SIP signalling
- authentication and authorization
- exposed IMS interfaces
- CPE configuration
- interconnection security
- VoLTE and VoNR attack paths
- voice-fraud scenarios
The objective is to determine what an attacker can actually reach and exploit, rather than simply verifying configuration against a reference document.
OSS, NFV and cloud infrastructure
The systems managing and orchestrating telecom networks are part of the attack surface too. We assess:
- OSS and management interfaces
- virtualised network functions
- container isolation
- orchestration platforms
- APIs
- CI/CD integrity
- cloud and infrastructure security controls
A secure 5G Core is of limited value if the systems used to deploy and operate it provide an easier route into the network.
SIM, eSIM and OTA security
Subscriber identity remains one of the foundations of mobile network security. We assess:
- SIM and eSIM provisioning
- OTA mechanisms
- key management
- authentication flows
- provisioning infrastructure
- subscriber identity protection
- attack paths involving SIM-based trust relationships
Our research into the Ghost SIM class of attacks has directly informed the techniques we use when assessing SIM and subscriber-security architectures.
02 / MethodHow we test
Our assessments combine telecom security research with practical offensive testing. A typical engagement moves through:
The exact methodology depends on the network and scope. Some assessments can be performed remotely. Signalling and core testing often can. RAN, SIM/OTA, TETRA and other specialised environments may require on-site testing.
We also distinguish carefully between passive and active testing and agree production, laboratory and change-window constraints before testing begins.
Every engagement ends with technically detailed findings, risk prioritisation and a remediation plan your engineering team can act on — not a generic compliance checklist.
03 / IndependenceIndependent by design
Telecom operators can receive security assessments from vendors, integrators, large consultancies and specialist security companies. Our model is different.
Ethon Shield has no telecom security product catalogue to sell. That means our assessment does not need to lead towards a particular product, platform or vendor solution.
An independent assessment can look across the network — including at exposures for which there is no product to sell. The result is a technical view of the network based on what an attacker can reach, exploit and impact.
04 / ResearchResearch becomes methodology
Our security methodology is built on practical telecom security research. We research new attack techniques, analyse real-world implementations and turn those findings into repeatable assessment techniques.
Cloning a SIM without the operator's secret key
Our research investigated a class of SIM attacks capable of producing a working SIM clone without requiring the operator's secret authentication key. The work examined the implications across the mobile technologies and operators included in our testing.
Read the research →Security inside the Service-Based Architecture
Our research into 5G Standalone deployments has examined the security of service-to-service communication, encryption, authorization and exposed interfaces within the Service-Based Architecture. These findings directly inform how we approach 5G Core assessments.
Read the research →Probing 5G subscriber-identity privacy
We have researched techniques for probing 5G subscriber-identity privacy and identifying conditions in which network behaviour can reveal information about subscriber identities.
Read the research →Attacks against telecom transport protocols
Our research has also explored attacks against telecom transport and signalling protocols, including SCTP-based attack scenarios.
Read the research →This research-driven approach matters because telecom networks change faster than traditional assessment checklists. When a new attack technique appears in our research, it can become part of our assessment methodology.
Research and the wider security community
Our work has been shared through security research and industry conferences, including Black Hat, DEF CON, RootedCON, EKOparty and other specialist security events. We also contribute research to the wider telecom and security community — see the full research index.
Our objective is not simply to identify vulnerabilities. It is to understand how telecom systems behave under attack and translate that knowledge into practical security testing.
05 / RegulationTelecom security in the European regulatory landscape
Security requirements for European telecom operators are evolving. NIS2, the European Electronic Communications Code, the EU 5G Toolbox and national 5G security frameworks all contribute to an environment in which operators increasingly need demonstrable technical security controls and evidence.
| Framework | What it means for an operator |
|---|---|
| NIS2 | Establishes cybersecurity risk-management and incident-reporting requirements for entities within its scope, including relevant providers of public electronic communications networks and services. The precise obligations and supervisory mechanisms depend on the applicable national implementation. An independent technical assessment can provide useful evidence for risk management and supervisory processes. |
| EU 5G Toolbox | A common European framework for mitigating 5G security risks, including strategic, technical and supporting measures. |
| ENISA guidance | ENISA's 5G Security Controls Matrix provides a useful reference for mapping technical controls, evidence and assessment scope. We use relevant European security frameworks as references when defining assessment scope — while maintaining our own technically driven methodology. |
| National requirements | National frameworks can introduce additional security requirements for operators. In Spain, for example, Royal Decree 443/2024 establishes periodic security audits for operators within the scope of the national 5G security scheme. |
We provide the technical assessment, findings and remediation guidance. We do not provide legal compliance advice or certification.
To test the technology and provide evidence of what is actually exposed.
06 / DeliverablesWhat you receive
Every assessment produces actionable technical output. Depending on scope, this includes:
- detailed technical findings
- attack paths and exploitation evidence
- affected systems and interfaces
- risk prioritisation
- technical impact assessment
- remediation recommendations
- executive-level summary
- technical report for engineering and security teams
We do not stop at identifying that a control is missing. Where practical, we demonstrate what that missing control means in terms of actual attackability and impact.