Skip to main content

Security, complexity and Huawei; protecting the UK's telecoms networks

With 5G set to transform mobile services, Ian Levy explains how the UK has approached telecoms security, and what that means for the future.

An image of a busy London at night

We all rely on our telecoms services more than we realise. We expect fast connectivity everywhere we go, something that would have looked like magic only 50 years ago. Ubiquitous connectivity has enabled new ways for people to interact, the apps we use every day, and new ways of building systems. However, very few people know how these telecoms services work, or how they’re built. So as we start talking about 5G and the next generation of fixed and mobile connectivity, I thought it’d be useful to explain how UK operators, regulators and government works to protect these critical services.

This blog is supposed to be accessible, but it inevitably contains some scary-sounding terminology. However, as is often the case with cyber security, the concepts behind them are quite straightforward. For example, there's some really clever technologies involved in sending as much data as possible down fibre, one of which is ‘dense wave division multiplex’. This is a techy way of saying that we can use different colours of light for different streams of data down the same fibre. We can guarantee they won’t interfere with each other in the fibre and then we can split them out at the other end using (effectively) a prism like you did in physics lessons at school. So, you can use one physical glass fibre for lots of different data streams, and keep them separate.

Most people should be able to understand most of the concepts involved in this blog, even if not the deep detail. Where the technical details are unavoidable, I'll explain what they mean, so please keep reading. It's also worth remembering that this blog deals almost exclusively with data, because in modern networks, voice is really transported as data.

Firstly, it’s worth talking about security. There are no absolutes in cyber security, and there’s no such thing as a 100% secure system. In the end, cyber security is all about risk management, judgement, and trying to make your adversaries’ lives harder.

For telecom services, think of it like this. Nationally, we set a bar at a particular height, and if the adversary can jump over the bar undetected, they get to do what they want - whether that’s 'disrupt a service' or 'snoop on calls'. The NCSC looks for attackers successfully jumping over the bar to help manage risk in the UK. It’s for ministers to set the height of the bar, and then for operators overseen by Ofcom and DCMS (and helped by NCSC) to try to make the networks meet that expectation. We know that the bar isn’t currently met in some places in the UK, and there’s a long-term piece of work already running to try to fix that. You can’t just patch a national telecoms network like you can your home PC; when you’re talking about national scale systems, changes take time.






Written by

Ian Levy

Published

Part of blog