Telecom security in Europe

Independent telecom security audits across Europe

We provide independent, technically deep security assessments for mobile and telecom operators across Europe. We have audited major mobile networks in Spain, Italy, the United Kingdom, Norway, Sweden and Poland across signalling, 5G Core, RAN, IMS, OSS and SIM/eSIM environments.

No vendor ties. No security product catalogue to defend. Just independent findings your engineering team can act on.

6 European countries 20+ networks audited 40+ years of combined experience ISO 27001 Responsible disclosure to GSMA & 3GPP

Telecom security is not a checklist

Modern telecom networks combine decades of legacy technology with increasingly complex 5G infrastructure.

SS7 and Diameter still coexist with 5G Standalone service-based architectures. IMS connects mobile networks to voice services. Virtualised network functions run across cloud and container platforms. SIM and eSIM provisioning introduces another layer of trust and identity.

A security assessment therefore needs to look across the network, not just at individual products. That is where we focus.

Where we have operated
Countries where Ethon Shield has audited major mobile operatorsNorway5G core · NFV/CaaSSwedenOSS · IMSUnited KingdomSignalling · roamingSpainRAN · 5G core · OSSItaly2G–5G RANPolandRAN

Remote and on-site. Signalling and core assessments are often performed remotely; RAN, SIM/OTA and TETRA assessments may require on-site testing depending on the scope. We adapt to each operator's access restrictions and change windows — including out-of-hours testing when production risk requires it.

01 / ScopeWhat we audit

01

Signalling security

SS7/MAP and Diameter remain critical attack surfaces wherever roaming and interconnection dependencies persist. We assess signalling exposure including:

  • subscriber location and tracking
  • authentication and signalling abuse
  • roaming interfaces
  • interception-related attack paths
  • fraud scenarios
  • signalling filtering and security controls

We test the controls that protect the network against realistic signalling attacks rather than simply checking whether a security feature exists.

02

5G Standalone Core

5G Standalone introduces a fundamentally different architecture based on service-to-service communication and APIs. We assess the security of the Service-Based Architecture, including:

  • service discovery and NRF interactions
  • API exposure
  • authentication and authorization between network functions
  • TLS and certificate configuration
  • trust relationships between services
  • exposed management and control interfaces

Our testing covers both architectural weaknesses and implementation or configuration issues that can create exploitable attack paths.

03

RAN security

The radio access network remains one of the most exposed parts of a mobile network. We assess multivendor RAN environments from legacy technologies through 4G and 5G, including:

  • authentication and ciphering configuration
  • downgrade paths
  • radio-layer attack surfaces
  • rogue and false base stations
  • network exposure to unauthorised devices
  • security controls affecting subscriber privacy

Where required, testing is performed on-site using dedicated radio and SDR equipment.

04

IMS, VoLTE and VoNR

Voice services introduce their own signalling, authentication and trust relationships. We assess:

  • SIP signalling
  • authentication and authorization
  • exposed IMS interfaces
  • CPE configuration
  • interconnection security
  • VoLTE and VoNR attack paths
  • voice-fraud scenarios

The objective is to determine what an attacker can actually reach and exploit, rather than simply verifying configuration against a reference document.

05

OSS, NFV and cloud infrastructure

The systems managing and orchestrating telecom networks are part of the attack surface too. We assess:

  • OSS and management interfaces
  • virtualised network functions
  • container isolation
  • orchestration platforms
  • APIs
  • CI/CD integrity
  • cloud and infrastructure security controls

A secure 5G Core is of limited value if the systems used to deploy and operate it provide an easier route into the network.

06

SIM, eSIM and OTA security

Subscriber identity remains one of the foundations of mobile network security. We assess:

  • SIM and eSIM provisioning
  • OTA mechanisms
  • key management
  • authentication flows
  • provisioning infrastructure
  • subscriber identity protection
  • attack paths involving SIM-based trust relationships

Our research into the Ghost SIM class of attacks has directly informed the techniques we use when assessing SIM and subscriber-security architectures.

02 / MethodHow we test

Our assessments combine telecom security research with practical offensive testing. A typical engagement moves through:

Reconnaissance→ Attack surface mapping→ Security testing→ Exploitation→ Impact validation→ Risk assessment→ Remediation

The exact methodology depends on the network and scope. Some assessments can be performed remotely. Signalling and core testing often can. RAN, SIM/OTA, TETRA and other specialised environments may require on-site testing.

We also distinguish carefully between passive and active testing and agree production, laboratory and change-window constraints before testing begins.

Every engagement ends with technically detailed findings, risk prioritisation and a remediation plan your engineering team can act on — not a generic compliance checklist.

03 / IndependenceIndependent by design

Telecom operators can receive security assessments from vendors, integrators, large consultancies and specialist security companies. Our model is different.

Ethon Shield has no telecom security product catalogue to sell. That means our assessment does not need to lead towards a particular product, platform or vendor solution.

The practical difference

An independent assessment can look across the network — including at exposures for which there is no product to sell. The result is a technical view of the network based on what an attacker can reach, exploit and impact.

04 / ResearchResearch becomes methodology

Our security methodology is built on practical telecom security research. We research new attack techniques, analyse real-world implementations and turn those findings into repeatable assessment techniques.

Ghost SIM

Cloning a SIM without the operator's secret key

Our research investigated a class of SIM attacks capable of producing a working SIM clone without requiring the operator's secret authentication key. The work examined the implications across the mobile technologies and operators included in our testing.

Read the research →
5G Standalone

Security inside the Service-Based Architecture

Our research into 5G Standalone deployments has examined the security of service-to-service communication, encryption, authorization and exposed interfaces within the Service-Based Architecture. These findings directly inform how we approach 5G Core assessments.

Read the research →
SUCI privacy

Probing 5G subscriber-identity privacy

We have researched techniques for probing 5G subscriber-identity privacy and identifying conditions in which network behaviour can reveal information about subscriber identities.

Read the research →
SCTP & signalling

Attacks against telecom transport protocols

Our research has also explored attacks against telecom transport and signalling protocols, including SCTP-based attack scenarios.

Read the research →

This research-driven approach matters because telecom networks change faster than traditional assessment checklists. When a new attack technique appears in our research, it can become part of our assessment methodology.

Research and the wider security community

Our work has been shared through security research and industry conferences, including Black Hat, DEF CON, RootedCON, EKOparty and other specialist security events. We also contribute research to the wider telecom and security community — see the full research index.

Our objective is not simply to identify vulnerabilities. It is to understand how telecom systems behave under attack and translate that knowledge into practical security testing.

05 / RegulationTelecom security in the European regulatory landscape

Security requirements for European telecom operators are evolving. NIS2, the European Electronic Communications Code, the EU 5G Toolbox and national 5G security frameworks all contribute to an environment in which operators increasingly need demonstrable technical security controls and evidence.

FrameworkWhat it means for an operator
NIS2Establishes cybersecurity risk-management and incident-reporting requirements for entities within its scope, including relevant providers of public electronic communications networks and services. The precise obligations and supervisory mechanisms depend on the applicable national implementation. An independent technical assessment can provide useful evidence for risk management and supervisory processes.
EU 5G ToolboxA common European framework for mitigating 5G security risks, including strategic, technical and supporting measures.
ENISA guidanceENISA's 5G Security Controls Matrix provides a useful reference for mapping technical controls, evidence and assessment scope. We use relevant European security frameworks as references when defining assessment scope — while maintaining our own technically driven methodology.
National requirementsNational frameworks can introduce additional security requirements for operators. In Spain, for example, Royal Decree 443/2024 establishes periodic security audits for operators within the scope of the national 5G security scheme.

We provide the technical assessment, findings and remediation guidance. We do not provide legal compliance advice or certification.

Our role is straightforward

To test the technology and provide evidence of what is actually exposed.

06 / DeliverablesWhat you receive

Every assessment produces actionable technical output. Depending on scope, this includes:

  • detailed technical findings
  • attack paths and exploitation evidence
  • affected systems and interfaces
  • risk prioritisation
  • technical impact assessment
  • remediation recommendations
  • executive-level summary
  • technical report for engineering and security teams

We do not stop at identifying that a control is missing. Where practical, we demonstrate what that missing control means in terms of actual attackability and impact.

07 / FAQFrequently asked questions

Which European countries do you work in?
We work across Europe. Our previous assessments include major mobile networks in Spain, Italy, the United Kingdom, Norway, Sweden and Poland. The exact delivery model depends on the assessment scope: signalling and core assessments can often be performed remotely, while RAN, SIM/OTA and specialised telecom environments may require on-site testing.
How disruptive is a telecom security assessment?
We design the assessment around the operator's operational constraints. Testing can combine passive analysis, controlled active testing, laboratory validation and agreed production test windows. The objective is to demonstrate real security exposure without creating unnecessary operational risk.
Do you perform active attacks against production networks?
Active testing can be performed when agreed as part of the scope and change-management process. Before testing begins, we define the permitted attack techniques, systems, test windows and safeguards required to protect production services.
Can you test a 5G Standalone Core?
Yes. We assess 5G Standalone environments including Service-Based Architecture interfaces, service discovery, authentication and authorization, TLS and certificate configuration, exposed APIs and interactions between network functions.
Do you test RAN as well as Core?
Yes. Our telecom security assessments can cover the RAN, Core, signalling, IMS, OSS and subscriber-security layers. RAN testing may require on-site access depending on the scope and test objectives.
Can you assess SIM and eSIM security?
Yes. We assess SIM/eSIM provisioning, OTA mechanisms, authentication flows and related infrastructure. Our research into SIM security directly informs this work.
Does an independent audit help with NIS2?
An independent technical assessment can provide useful evidence for cybersecurity risk management and supervisory processes under NIS2. The exact evidence required depends on the applicable national implementation and supervisory framework. We provide technical findings and remediation guidance rather than legal compliance advice.
Do you provide a sample report?
Yes. We can provide an anonymised sample report so that prospective clients can understand the level of technical detail, risk assessment and remediation guidance included in our assessments.
Can you assess private 5G networks?
Yes. We can assess private and specialised telecom environments, including private 5G deployments and other dedicated mobile networks.
Do you assess legacy technologies such as 2G and 3G?
Yes. Legacy technology remains relevant wherever it is still deployed or where interworking, roaming or fallback mechanisms create dependencies. Auditing legacy is protecting the present, not looking at the past.
Operating a network in Europe? Let's look at what is actually exposed.
Independent telecom security assessment · remote or on-site
Talk to Ethon Shield →