Cyber Security
Devices
Everything you need to access your digital world
Editorial
Is this a logical evolution, or a strategic market grab?
The attraction is obvious; connectivity margins are under pressure, customer loyalty is difficult to maintain and cyber security offers recurring revenue in a growing market. Adding security also turns a largely invisible utility into a more strategic relationship.
There is a convincing customer argument too. Telcos already sit in a privileged position. They operate the networks, see vast amounts of traffic and defend critical national infrastructure. If threats can be detected or blocked within that network, before they reach the customer, why wouldn’t security form part of the service?
The difficulty is that proximity to the problem does not automatically make someone qualified to solve it. There is a considerable difference between protecting a network and understanding an organisation’s complete exposure. Cyber risk now stretches across identities, cloud platforms, applications, devices, suppliers and employee behaviour. A telecoms operator may see the connection, but that does not mean it sees the whole business context surrounding it.
Much depends on what “cyber security provider” actually means.
Some operators have invested heavily in security operations, specialist talent, threat intelligence and incident response. Others have assembled portfolios through acquisitions and vendor partnerships. Then there are those whose cyber proposition appears to be a selection of third-party products added to an existing connectivity contract.
Telcos could become powerful cyber security partners and we are already seeing them becoming increasingly acquisitive in this space. Their infrastructure, scale and network visibility give them advantages that many conventional providers cannot easily replicate. As cloud, communications, connectivity and security continue to converge, ignoring that position would make little sense.
But the industry should resist treating cyber security as the next convenient revenue category. Trust will not be earned by bundling a firewall, connectivity contract and security dashboard onto one invoice.
The opportunity isn't in question, but what about the risk of overreach is.. Telecoms operators may be well placed to protect more of the modern business, but first, they must prove they understand what they are asking customers to entrust them with.
For security leaders, the logo on the proposal matters less than what sits behind it. Who monitors the service? Where are the analysts based? What happens at 2am during an active incident? Can the provider integrate with the existing security stack? Does it offer meaningful advice, or does its responsibility stop at the edge of its own network?