ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Fixing 5G security

Udo Schneider at Trend Micro describes the private 5G security gaps that enterprises need to fix

 

Poor 5G coverage has been a gripe of long-suffering UK mobile users for some time. But there’s one area where the technology is taking off: private enterprise deployments covering locations as diverse as ports and hospitals. They offer potentially significant benefits to organisations, and the country as a whole, as the national quest for economic growth continues. 

 

But all of this good work threatens to be undermined by skills and security gaps. New research reveals that just a fifth of global organisations even have a dedicated communications technology (CT) security team. Artificial intelligence (AI) offers a tremendous opportunity to tackle this shortfall, but only if used judiciously.

 

The promise of private 5G

Estimates forecast private 5G connections will grow at a CAGR of 65% until 2030 to comprise 13% of total 5G IoT connections globally by then. In the UK, the technology has already been rolled out in locations as varied as the Port of Tyne, South London and Maudsley NHS Foundation Trust, and even offshore wind farms

 

Operators of these networks can expect faster and more reliable connectivity, that can be tailor-made to suit their own specific requirements. Blessed with low latency and high capacity, private 5G networks are particularly well suited to IoT and edge computing use cases—opening the door to innovation-fuelled business growth. But while stricter enterprise oversight helps make these networks more secure than public 5G, private deployments are also an attractive target for threat actors.

 

Risks abound

For one, highly sensitive enterprise data is likely to flow through these networks, attracting the attention of would-be digital thieves and extortionists. Private 5G network architectures also offer an expanded attack surface to aim at thanks to their use of cloud and edge computing, and support for large numbers of IoT devices and other endpoints. Each one of these represents a potential attack vector. 

 

There are also risks associated with network slicing, where single physical networks are segmented into virtual slices. Misconfiguration of these nominally isolated slices could give attackers an advantage. Additionally, private 5G networks introduce a potentially significant number of diverse suppliers to target. If not properly managed, this kind of complexity is the enemy of effective security.

 

It’s reassuring, therefore, that two-thirds of organisations claim to have already conducted a risk assessment on their private networks, with a further 13% in the process of doing so. They seem to understand the threat of ransomware, unauthorised access, vulnerability exploitation and supply chain risks. But only half put a high priority on securing these environments.

 

That’s particularly concerning in the context of an increasingly unforgiving regulatory environment. Depending on the organisation, there could be serious implications for compliance with NIS2, the EU Digital Operational Resilience Act (DORA) and national telecoms laws. Many IT leaders complain they don’t have enough in-house expertise to manage these compliance programmes.

 

Where AI adds value

AI is by no means a panacea. But it does offer some potentially interesting opportunities for closing security gaps. That’s why the vast majority of organisations we polled say they are using these tools, or planning to, in a private 5G context. It’s also telling that usage rates go up for businesses that have already conducted risk assessments on their networks—and theoretically therefore understand more clearly the risks they’re facing.

 

AI-powered security can be deployed in multiple ways. Most obvious is analysis of large data volumes to join the dots that humans may not see—surfacing anomalies indicative of malicious network activity. Advanced tools could also take this a stage further by automating remediation and containment actions. AI could be set to work on internal and external data to predict potential attack vectors and threats. All of which reduces the workload on under-pressure and understaffed security operations teams.

 

The technology can also play an important role in building cyber resilience across private 5G networks and beyond. By continuously monitoring IT, OT and CT systems for vulnerabilities and misconfigurations, and flagging and auto-remediating these, it can close security gaps before they can be exploited. 

 

There’s more. AI can help IT teams embrace a zero trust approach to securing their private 5G networks—and not only through continuous network monitoring and automated classification of sensitive data. It could be utilised to unleash the power of risk-based authentication, where dynamic assessments are made about each log-in attempt based on contextual data points such as device type, behaviour, time, location and so on. It has the potential to further tighten security without impacting the user experience, while freeing IT to work on higher value tasks. 

 

Closing the gaps

Yet to get there, many organisations will need to invest heavily. On average, less than a fifth (18%) of security budgets is currently allocated to private 5G networks. That will need to change. It’s telling that half of those we spoke to hand the job of CT security to their regular IT team. In many cases, responsibility lies with the CTO or CIO rather than the CISO.

 

Without this kind of expertise, AI may even be a source of compliance risk, if the data that security-focused LLMs are trained on isn’t anonymised, and access to such tools isn’t tightly controlled. The truth is that AI can expand the enterprise attack surface if not properly managed.

 

Security by design

The benefits of private 5G are too good for many organisations to ignore. But to fully harness the technology, security must be baked in from the start. That will require a rethink about strategy. Existing tools and processes should be adapted to cover infrastructure like base stations, edge computing environments, network slicing technologies and the 5G core. This may require partnership with a vendor-agnostic security partner. 

 

Our study reveals that a quarter of enterprise security budgets, on average, will be funnelled to private 5G network environments in the next 12 to 24 months. That’s great news. But how this money is spent will be critical to success. 

 


 

Udo Schneider is Governance, Risk and Compliance Lead at Trend Micro

 

Main image courtesy of iStockPhoto.com and Kinwun


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543