Skip to main content

The future of telecoms in the UK

NCSC Technical Director Dr Ian Levy explains how the security analysis behind the DCMS supply chain review will ensure the UK’s telecoms networks are secure – regardless of the vendors used.

Imagery illustrating systems and networks

When we first set up the NCSC, I made a big thing about the need for evidence-based cyber security, a scientific approach and being as transparent as possible.

I’d like to think we’ve done a pretty decent job of that over the last few years, but that approach has never been more important than now, with the debate about 5G. Since there’s been so much public discussion about security in 5G networks, I thought it would be useful to explain a bit more about how the NCSC approached the security analysis in the Department for Digital, Culture, Media and Sport (DCMS) Telecoms Supply Chain Review (SCR) and the analysis on the use of high risk vendors (HRVs), including, but not limited to Huawei.

If you’ve not already read my previous blog on 5G security, it’s worth a read before carrying on. Remember that the SCR and the government’s decision about high risk vendors isn’t just about 5G. It’s also about full fibre and other gigabit capable connectivity (that is, really fast broadband for home and business users) and the future of fixed and mobile networks in the UK.

The SCR sought to answer three questions:

  1. How should we incentivise telecoms operators to improve security standards and practices in 5G and full fibre networks?
  2. How can we create sustainable diversity in the telecoms supply chain?
  3. How should we address the security challenges posed by high risk vendors?

The first two of these questions were answered in July 2019 with the publication by DCMS of the SCR report, which is arguably more important than today’s announcement. Unfortunately, the answer to both questions was that we have a lot to do - so that announcement detailed a decision about how to secure these future networks, regardless of the vendors we choose. This also includes ensuring that there’s a sustainable and diverse market to provide the products and services needed to build and run those networks so that in the future we have a real choice of vendors.

Today, the government has answered the third question. I’m going to try to explain the evidence and technical analysis NCSC provided to support the decision. Inevitably, this makes for another long read but, once again, it’s a complicated subject and I think it’s important that the public understands how carefully we’ve approached this, to ensure the long term security of the UK. This whole process has been done under the auspices of the DCMS Telecoms Supply Chain review. It’s worth noting that the security analysis hasn’t fundamentally changed since the review concluded. Due to security and market sensitivities, it’s not possible to publish the full analysis and response, but we do want to explain the work behind our cyber security advice to ministers.

The government asked us to publish advice as a result of the decision. Today, we’re publishing this blogpost to give an overview, a simple explainer of what 5G is and isn’t, the framework by which we determine high risk vendors and manage the associated risk and, for those of you interested in a more technical description, a summary security analysis.