Telecommunications (security) Act (TSA): are VPNs the right solution for secure remote access?


Insight

By Rob Pocock, Technology Director, Red Helix

The initial deadline for the Telecommunications (Security) Act (TSA) 2021 is fast approaching. Drafted in response to our growing reliance on communications technology, and to help protect our networks from an expanding threat landscape, the Act is set to have a major impact on the UK’s approach to security and resilience in the telecoms industry.

The first of the deadlines requires all network operators in the tier 1 category (those with an annual turnover in excess of £1 billion) to action ‘the most straightforward and least resource intensive measures’ by March 31st, 2024. While there is no explicit guidance as to what this means, one of the easier measures to action is the implementation of secure remote access – a necessary measure which will help prevent unauthorised access to telecoms networks and systems.

There are a couple of different solutions that operators can put in place to try and achieve this. The traditional approach would be to use a VPN. In fact, as part of the code of practice, included with the guidance on regulation 4 ‘Protection of data and network functions’, there is a recommendation to use exactly that. Yet, while a VPN may address some of the requirements within the legislation, it is now quite outdated technology and could fall short of achieving others.

To avoid further work later down the line, and to benefit from far more robust network access control, operators ought to consider implementing a Zero-Trust Network Access (ZTNA) solution instead. It is widely recognised as the successor to VPN technology, offering increased security by working to the assumption that all requests have hostile intentions, and uses US military-grade AES-256 encryption to keep connections secure.

The shortcomings of a VPN

VPNs have been around for several years, and work by creating an encrypted tunnel between a user’s device and the network. This creates a point-to-point connection that, in theory, cannot be accessed by unauthorised users. They have, however, seen little change since they first came about in 1996, and their effectiveness in the context of modern cyber security threats is being increasingly questioned.

There are two key reasons for this. Firstly, authentication requirements for the VPN itself are often very basic, requiring little more than a username and password. Secondly, they can make it difficult to control or prevent any over-privileged lateral movement once inside the network. Therefore, if a cyber criminal were to bypass the authentication requirements, there is a chance they’ll be able to access systems and data across the entire organisation.

Of course, using a VPN is no doubt better than not having any access controls in place whatsoever, but it is far from the most secure choice. A VPN is also unlikely to help operators meet some other the more stringent security measures required in the TSA. For example, regulation 7 identifies measures needed to reduce supply chain risks, and regulation 8 outlines further details on the measures required for the ‘prevention of unauthorised access or interference’, both of which would be hard to achieve full compliance with using a VPN alone.

Additionally, there is a section included in the TSA code of practice that states providers should establish the principle of ‘assumed compromise’. This means assuming that network oversight functions are subject to high-end attacks that may not have been detected, and to ensure there are measures in place to make it difficult for the attacker. As lateral movement can be hard to prevent with a VPN, this is another area in which they are lacking.

Improved access control through ZTNA

In contrast, ZTNA has been designed with assumed compromise in mind, operating on the principle that the network is always hostile. Trust is never implicit, meaning users are only granted access to the specific applications and resources they need; with granular policies to determine what, where and when information can be accessed.

Not only does this meet with the requirements outlined in regulation 4 for which a VPN was recommended, but it can go a long way to complying with some of the other regulations as well. ZTNA’s comprehensive approach to network security ticks off most of the measures outlined in regulation 8, alongside many of those included in regulation 7 – by providing control over what third-party suppliers have access to, and limiting any potential damage should they be compromised.

ZTNA is also likely to become more of a significant factor in obtaining or maintaining cyber insurance. Owing to the rise in severity and frequency of cyber attacks, insurers have continued to increase the requirements needed to pass the risk assessment process. While the exact standards may vary between insurance providers, strong access control is one that appears to feature often, and the use of ZTNA will go a long way in demonstrating this.

Ultimately, ZTNA represents a more forward-looking approach to access control, aligning with the broader trend in cyber security of moving towards a more adaptive, dynamic, and user-centric security model. With its emphasis on continuous verification and granular access policies, it is a more robust solution that hits a number of the TSA regulations and will provide operators with stronger protection across their networks.

A future-proof solution

As the first deadline for the TSA approaches, network operators are faced with a choice. Either use traditional VPN technology to achieve secure remote access or to implement the more advanced ZTNA.

Despite their long-standing presence within the industry, VPNs fall short in addressing modern cyber security challenges, owing to their basic authentication processes and limitations in controlling internal network movements. ZTNA, on the other hand, offers a robust solution operating under the principle of ‘assumed compromise’, ensuring stringent access controls and aligning with several of the TSA’s requirements.

While continuing to use a VPN may seem like the most straightforward approach, and can help operators to meet the first ‘least resource intensive’ deadline, it is likely to be only a temporary solution. ZTNA is an easy to implement alternative that offers a more comprehensive, adaptable, and future-proof strategy – so why settle for something inferior when the option for better security is already present?

Report: Three quarters of wireless customers considering switching provider 


Insight

The latest global report from Salesforce sheds light on customer’s shifting priorities and why communication service providers (CSPs) must adapt to improve customer retention 

In 2024, it is easier than ever for customers to jump from service provider to service provider in search of the best deal and the best experience. In fact, the latest report from Salesforce suggests that constantly being on the lookout for a better offer is deeply ingrained in the CSP customer mindset, with 76% of wireless customers considering switching, while 78% of broadband customers said they were at least somewhat likely to use tech provider instead of their current provider, if available.  

To make matters worse, the report also notes that 50% of wireless customers and 47% of fixed broadband customers feel that threatening to switch providers is actually an effective way of ensuring that they get the best deals from their existing providers. 

So, why is customer loyalty seemingly so low in the telecoms sector? And how can CSPs and reduce churn? 

The answers, of course, are deeply nuanced. Customer expectations have increased enormously as their lives have grown increasingly digitalised. Not only do customers today demand greater speeds and reliability from their CSP, they also want a more seamless and flxible relationship with their provider.  

Automated interactions are becoming the norm, providing the CSPs with a huge boost in efficiency and potentially cost-reduction, but these automated services are often failing to deliver the excellent quality customers demand. The report suggests that only 22% of B2C customers would describe their provider’s automated services as ‘excellent’, while over half admitted to never having used their providers self-service.  

This is not solely an online issue either. In fact, expectations for excellent service are only increased when it comes to in-store interactions, with the report finding that less than a quarter of B2C customers would describe their experience as pleasing or efficient. 

Ultimately, this report reflects an industry in which customers remain sceptical of their provider’s ability to meet their needs and CSPs must work diligently to change their mindset when it comes to defining excellence in customer service.  

You can access the full Salesforce report, which surveyed 500 telecoms experts and 6,000 customers, here: Trends in the Communications Industry. 

This report is being published at a pertinent time for the UK connectivity market, with industry discussions beginning to move beyond infrastructure rollout and towards full fibre and 5G adoption. Indeed, the country’s fibre market, which at its peak contained more than one hundred altnets, is starting to consolidate, making customer experience and service differentiation more important than ever in ensuring a positive ROI. 

Against this backdrop, achieving excellence in customer service is expected to be at the forefront of next month’s Connected North conference live in Manchester, with specialists from throughout the telecoms industry coming together to discuss key issues and the shifting connectivity landscape.  

Get the full report here Trends in the Communications Industry and join the discussion at Connected North now.  

Also in the news:
BT wins £26m contract to connect UK schools
Apple fined €1.8bn by European Commission over Spotify row
Japan to reduce regulatory pressure on incumbent NTT

Chinese telcos launch open API to tackle fraud with OTPs

The GSMA has announced that China Mobile, China Telecom and China Unicom have commercially launched an open API from the GSMA Open Gateway initiative that will help reduce mobile fraud, while CITIC Telecom, Huawei and ZTE have joined the initiative.

According to the GSMA, all three telcos have launched the One Time Password (OTP) API, which is designed to improve the security of mobile apps and online services. The service enables users to receive an OTP to provide proof of possession of a phone number and verify their identity.

The GSMA says the OTP API is more secure than single-factor authentication and a better solution for in card-not-present payment scenarios. Applications for the OTP API include onboarding to digital services, verifying high-value transactions and account management features such as resetting passwords.

The GSMA said the rollout represents China’s first commercial open API launch since signing up for the GSMA Open Gateway initiative in June 2023.

The China launch is the latest in a slew of announcements by operators launching Open APIs in Thailand, Indonesia, South Africa, Sri Lanka and Uzbekistan, among others, mainly to address mobile and online fraud. In China alone, the Ministry of Public Security reportedly tackled 391,000 cases of telecom and online fraud between January and November 2023.

“As instances of online fraud continue to grow in both scope and scale globally, the GSMA Open Gateway is equipping developers with the tools they need to protect users in the digital space,” said GSMA director general Mats Granryd in a statement.

Meanwhile, the GSMA also revealed that CITIC Telecom, Huawei and ZTE have become the latest Chinese companies to commit to the Open Gateway initiative.

The GSMA said these new partnerships will help to drive demand and uptake of Open Gateway APIs in China and support the initiative’s “go-to-market” strategy, which was announced at MWC 2024.

Under that strategy, GSMA Open Gateway will focus on three go-to-market commercial channels for open API adoption: the network cloud marketplace (i.e. cloud providers including AWS, Google Cloud, Microsoft Azure and Vonage), strategic technology partners and resellers such as Infobip, Nokia, and Ericsson, and operators going direct to market through their enterprise and innovation divisions.

MORE ARTICLES YOU MAY BE INTERESTED IN…

VX Fibre and Freedom fibre complete merger 


News 

Consolidation continues in the alnet market in the latest of a string of mergers 

UK fibre altnets VX Fibre and Freedom Fibre have completed their merger which was announced last December, following regulatory approval. 

The newly combined group will operate as name Freedom Fibre under their CEO Neil McArthur and his management team, and will have a network of 300,000 (which is up from the figure of 285,000 given in December). 

“This strategic merger leverages the strengths of both Freedom Fibre and VX UK to create a larger, stronger, and more diverse business backed by two significant investors with ambitions for growth,” said Freedom Fibre’s CEO, Neil McArthur. We are delighted to be joining forces with the VX team and are hugely excited about the future potential of the newly combined business.”  

VX UK mainly operates in and around Stoke-on-Trent, but has fibre assets in Bristol and Colchester. Freedom Fibre, which was launched in 2020, offers wholesale-only services on its network, and had a long-term partnership with leading UK broadband provider TalkTalk.  

Speaking to the financial times in January, Greg Mesch, CEO of the UK’s largest altnet CityFibre, said it is aiming to make as many of five acquisitions over the next two years. “Investment is drying up but I think that’s creating the opportunity to consolidate the network,” Mesch said. According to the article, the company is already in exclusive talks with two other altnets. 

Catch Greg Mesch at this year’s Connected North event, 22-23 April in Manchester. Secure your tickets now! 

Also in the news:
VEON exits Kyrgyzstan to focus on key markets
BT pledges to upgrade payphones nationwide
Spanish govt buys 3% stake in Telefonica, eyes 10%

Teletalk and Banglalink launch beta national roaming service

Select customers of Bangladesh state-owned telco Teletalk are reportedly now able to roam onto the network of rival telco Banglalink as part of a beta launch for a national roaming service to help Teletalk cope with availability problems.

According to the Daily Star newspaper, the « pre-commercial launch » of the national roaming service, which commenced on Tuesday, only enables some Teletalk customers to roam onto Banglalink’s network. The service currently doesn’t allow Banglalink customers to roam onto Teletalk’s network during the pre-commercial period.

Teletalk users will be charged the normal rates regardless of which network they happen to be using. The report says Banglalink will not earn any revenue from Teletalk during the pre-commercial roaming period.

Banglalink said the two telcos have successfully trialled the roaming service, and are currently finalising commercial agreements for a nationwide commercial launch, which is expected to take a few months, the report said.

The report added that Robi Axiata has received approval from the Bangladesh Telecommunication Regulatory Commission (BTRC) to hold a trial for the roaming service, and is ready to start once it receives a response from Teletalk.

The roaming service plan is intended to help Teletalk keep its customers connected, as a fair chunk of its base stations are vulnerable to power outages. According to the report, the backup batteries in over 21% of Teletalk’s base stations cannot provide more than one minute of backup power in the event of a power outage. Meanwhile, 40% can only provide one hour of backup power.

Power outages have become more frequent in Bangladesh in the past year due to extreme weather, as well as declining forex reserves and currency value that make it more difficult to pay for fuel imports, according to media reports.

MORE ARTICLES YOU MAY BE INTERESTED IN…

Vodafone Germany to cut 2,000 jobs 


News

The company says the move will save €400 million over the next two years 

Vodafone Germany has announced today that it will cut 2,000 jobs over the next two years as part wider company restructuring. 

The company, which currently employs 15,000 people within Germany, said that staff would be relocated where possible, though specific numbers were not provided.  

The job cuts are part of cost-cutting measures announced by new Group CEO Margherita Della Valle in May last year, in which 11,000 jobs are expected to be cut globally over the next three years. 

 “Vodafone wants to make itself even simpler, faster, leaner and therefore more powerful in the next two years,” said the press release from Vodafone Germany. “In addition to more efficient processes and optimised structures, the focus is on even better interaction options and simpler products and services for customers.”  

Vodafone has been reshaping its operations globally for some time in an attempt to combat debt and its relatively flat growth in highly competitive markets.  

In October last year, the company sold 100% of its Spanish unit to Zegona Communications for €5 billion and, just last week, Vodafone Italia was sold to Swisscom in its entirety in the latest step towards its “reshaped European footprint”.  

The company is also in the process of merging its operations in the UK with CK Hutchison’s Three. 

In a company announcement, Della Valle explained that “going forward, our businesses will be operating in growing telco markets – where we hold strong positions – enabling us to deliver predictable, stronger growth in Europe”. She also highlighted a major focus on the B2B sector, saying it held the “biggest opportunity” for revenue growth. 

In related news, Vodafone Germany announced earlier this month that Marcel de Groot, the company’s head of private customer business, would take over as CEO, replacing the outgoing Philippe Rogge. 

Keep up to date with the latest international telecoms news by subscribing to the Total Telecom daily newsletter 

Also in the news:
BT wins £26m contract to connect UK schools
Apple fined €1.8bn by European Commission over Spotify row
Japan to reduce regulatory pressure on incumbent NTT

Telecom Egypt and Tejas aim to boost local manufacturing sector

Telecom Egypt and Indian telecoms vendor Tejas Networks announced on Monday they have signed a Memorandum of Understanding (MoU) to boost telecoms R&D and manufacturing facilities in Egypt, as well as train up local skillsets.

Under the MoU, which was also signed by Egypt’s Information Technology Industry Development Agency (ITIDA) and the National Telecom Institute (NTI), Telecom Egypt and Tejas will cooperate to establish local manufacturing and R&D facilities for fibre-to-the- home (FTTH) products.

The MoU also covers setting up technical support services in Egypt for customers within the country as well as for the larger Africa and Middle East region.

Meanwhile, Telecom Egypt, Tejas, ITIDA and NTI will work to build up the capacity of Egyptian engineers and technicians to work on state-of-the-art telecom and networking technologies.

Egypt’s Minister of Communications and Information Technology Dr. Amr Talaat said the MoU is the result of discussions that began in January 2023 between Egypt and India to enhance cooperation in ICT technologies.

“It is a comprehensive agreement that seeks to promote localization of world-class communications products, inject new Indian investments into Egypt, create job opportunities, and develop research cadres in various fields of communications,” he said in a statement.

Eng. Mohamed Nasr El-Din, CEO and MD of Telecom Egypt, said the MoU is “aimed at providing Telecom Egypt with the latest communications technology in the world while ensuring that it provides the highest quality of infrastructure services.”

Yogesh Verma, VP of Middle East and Africa (MEA) at Tejas, said the MoU would enable the company to bring its experience with India’s Bharatnet (Rural Broadband Project) and NKN (National Knowledge Network) projects to Egypt.

“Tejas has been operating in MEA for over a decade now and has extensive knowledge and insights about the local requirements and operating conditions to roll out cost-effective and scalable networks,” he said. “This MoU provides a great platform for us to expand our business in MEA while deepening our collaboration with Telecom Egypt and other customers in the country.”

MORE ARTICLES YOU MAY BE INTERESTED IN…