(781) 916-2284 [email protected]

Telecom networks are in the middle of a real architectural shift this year. AI is moving from a monitoring add-on to closer integration with the network’s control system, enabling self-healing operations, automated fault detection, and performance optimization with less manual intervention. Cloud-native and edge architectures are replacing monolithic cores. OSS/BSS stacks that have accumulated a decade of technical debt are finally being modernized because none of the above works well on top of them.

None of that matters if the underlying network isn’t secure. Telecom is, by a wide margin, the most targeted sector in one of the fastest-growing attack categories, and every modernization initiative above is also, whether operators frame it this way or not, a security decision. Modernizing and defending the network have become the same project, not two separate ones.

Telecom’s threat surface by the numbers

The scale of what telecom is defending against is worth sitting with. Cloudflare logged DDoS attacks more than doubling in 2025 to 47.1 million, with a single recorded attack peaking at 31.4 Tbps; network-layer attacks tripling to 34.4 million; telecommunications sat at the top of Cloudflare’s target list; and Nokia separately reports terabit-scale attacks now occurring five times more frequently than previously documented. Most of these move fast: 37% of DDoS attacks end within two minutes, leaving no room for a manual response.

Beyond attack volume, telecom risk is shifting toward the software layer. API attacks against enterprises rose 113% year over year, with 61% involving unauthorized workflow abuse, a direct concern for telecom, which is exposing more network functions and OSS/BSS capabilities through APIs to support automation and partner integrations. Third-party and supply-chain compromise now factors into 48% of breaches industry-wide, up 60% year over year, and those incidents take an average of 267 days to identify and contain.

Some risk categories are specific to how telecom actually operates. SIM-swapping fraud generated 121 cryptocurrency-linked complaints and $4.4 million in reported losses to the FBI in 2025 alone. Nation-state actors have treated telecom infrastructure as a strategic intelligence target; FBI and CISA have publicly attributed compromises of multiple U.S. telecommunications companies to PRC-affiliated actors seeking call records and sensitive communications data. And Nokia’s research points to an uncomfortable internal truth: nearly 60% of high-cost telecom breaches stem from insider actions or mistakes, not external attackers, a reminder that access governance and operational discipline matter as much as perimeter defense.

Modernization is expanding the attack surface, not just capability

The same architectural shifts making telecom networks smarter are also making them harder to defend. Replacing monolithic OSS/BSS platforms with microservices-based, cloud-native architectures delivers faster deployment cycles and easier scaling, but it also means more services, more internal APIs, and more integration points, each one a potential entry vector. That’s precisely the layer where the 113% growth in API attacks is landing.

Edge computing compounds this. As processing moves closer to regional data centers and 5G base stations to serve latency-sensitive applications, the perimeter that must be defended physically expands to every edge site, not just the core. As AI moves deeper into network operations (self-healing automation, AI-assisted fault detection, natural-language diagnostics), those systems become high-value targets: an attacker who compromises an automated remediation system doesn’t just steal data; they gain a foothold with the authority to make changes across the network.

What’s next on the horizon

The trends further out don’t change this calculus; they extend it. Open RAN vendor diversification reduces dependence on a small number of equipment suppliers, which improves competition and resilience, but it also means securing a more heterogeneous, multi-vendor supply chain rather than a handful of trusted relationships. Direct-to-cell satellite connectivity and early 6G development will keep pushing the network’s edge further outward, and each coverage expansion also expands what must be monitored and defended. The operators moving fastest toward AI-native operations and cloud-native architecture are also the ones facing the steepest security exposure; they must plan the two together, not sequence them.

The common thread

AI-native operations, cloud-native OSS/BSS, and network security aren’t separate initiatives competing for the same budget; they’re one modernization effort with three faces. ClearBridge’s telecom practice sits at exactly that intersection: our Security & Compliance work runs alongside our cloud, infrastructure, networking, and OSS/BSS engagements for telecom clients, because in this sector those can’t really be separated anymore. If your network operations or security posture is due for a hard look, it’s worth a conversation.