When a telecommunications network stops working, the problem rarely ends with a loss of connectivity. Banks, hospitals, transport, government agencies, industries, and emergency services depend on these networks to keep functioning. Telecommunications infrastructure has become a cross-cutting pillar of the digital economy and, for that very reason, an especially attractive target for cyberattacks. In 2026, protecting this infrastructure means much more than shielding equipment and servers: it means guaranteeing continuity, recovery capacity, and visibility across an increasingly distributed ecosystem.

 

The infrastructure we normally don't see

We are used to thinking about telecommunications from the user's point of view: mobile coverage, fiber, connection speed, or the availability of a service.

Behind that lies a much more complex infrastructure.

Access networks, base stations, transport systems, data centers, management platforms, DNS, cloud services, authentication systems, and multiple providers form a technological chain in which a disruption can spread far beyond the point where it started.

This interdependence explains why the European Union considers electronic communications one of its highly critical sectors.

The NIS2 Directive expressly includes providers of public electronic communications networks and publicly available electronic communications services within the scope of critical digital infrastructure.

The question, therefore, is no longer just about protecting a network.

It is about protecting an infrastructure that other infrastructures depend on.

 

The new interface doesn't have to be a store

The change may seem subtle, but its implications for e-commerce are significant.

Until now, a brand competed to attract users to its website or app. The experience was designed for people to browse categories, filters, recommendations, and product pages.

With AI agents, part of that browsing can disappear.

Consumers might not visit ten stores to compare ten products. They could delegate that task to an agent that checks different sources and returns a reasoned selection.

This shifts the center of gravity of e-commerce: the webpage no longer has to be the starting point of the commercial relationship.

And a new question arises for brands: how does a product gain visibility when the one deciding what to show is not directly a person, but an artificial intelligence system?

The answer, among other things, comes down to the quality and structure of the data. Catalogs, availability, prices, features, delivery conditions, return policies, and reputation must be correctly interpretable by systems that don't read a store exactly the way a person does.

The product needs to be understandable both to the consumer and to the machines that mediate its discovery.

 

The paradigm shift: from security to resilience

For a long time, cybersecurity has been associated mainly with keeping an attacker out.

That goal remains fundamental, but in critical infrastructure it is not enough.

No connected environment can assume zero risk. The question becomes how capable an organization is of detecting, containing, responding to, and recovering from a threat once it manages to get past the defenses.

This is one of the reasons NIS2 raises the focus on risk management, incident response, continuity, and supply chain security. The European Commission notes that the directive broadens the regulatory scope and strengthens obligations related to risk management and incident reporting.

In telecommunications, this view is especially relevant.

A disruption can simultaneously affect millions of users and organizations that depend on connectivity to provide essential services.

 

From requirements to emergent behavior 

Another challenge is validation.

In a conventional system, we can check whether a function meets a given requirement. In an SoS, some of the most important capabilities do not belong to a single component.

An intelligent transportation system can combine connected vehicles, traffic lights, urban sensors, control centers, navigation systems, and data platforms. None of them, on its own, provides intelligent mobility.

The capability emerges from the interaction.

This means testing must also evolve. It is no longer enough to verify components in isolation. It is necessary to analyze scenarios, collective behaviors, edge conditions, and possible changes during operation.

The specialized literature notes precisely that Systems of Systems require recurring adaptation during operation due to the uncertainty and variability of the environment.

 

5G: more capabilities, more exposure surface

The move toward 5G opens up new possibilities for industry, connected vehicles, critical communications, and the Internet of Things.

It also changes the security model.

Networks are increasingly software-defined, distributed, and virtualized. The line between physical infrastructure and network functions becomes less clear, while the number of components involved in delivering a service keeps growing.

ENISA works specifically on 5G security and the development of measures tied to the 5G Cybersecurity Toolbox, in addition to advancing a European cybersecurity certification scheme for 5G.

Security, therefore, must be built into the architecture from the start.

It shouldn't appear only once the network has already been deployed.

 

The risk is also in the supply chain

A modern telecommunications infrastructure depends on numerous manufacturers, integrators, technology providers, and external platforms.

This widens the security perimeter.

An organization can have solid internal controls and still be exposed to vulnerabilities originating in a component, provider, or external service.

Supply chain security has become precisely one of the elements highlighted by the European cybersecurity framework. The European Commission includes supply chain security and vulnerability management among the elements of the national strategies required by NIS2.

This forces a shift in a common question.

It is no longer enough to ask: "Is our infrastructure secure?"

We must also ask: "What is happening with everything our infrastructure depends on?"

Visibility to detect earlier

Resilience starts with knowing what is happening.

In distributed infrastructures, monitoring events, assets, configurations, and communications is essential to identify anomalous behavior before it turns into a disruption.

But visibility isn't about accumulating more data.

It's about being able to connect it.

A seemingly minor behavior in one part of the network can take on a different meaning when combined with simultaneous changes in other systems. That is why event correlation, threat intelligence, and the automation of certain detection and response capabilities are becoming increasingly important.

ENISA itself identifies operational preparedness, risk management, collaboration, and information sharing as relevant dimensions for assessing the maturity of critical sectors. In its NIS360 assessment, telecommunications ranks among the subsectors with the highest maturity level within digital infrastructure, although challenges related to operational preparedness persist.

 

Preparing for the incident that hasn't happened yet

A critical infrastructure doesn't prove itself resilient by never having suffered an incident.

It proves itself resilient when it is able to keep operating — or quickly recover its operation — once the incident occurs.

This requires combining technology, processes, and people.

Continuity plans, response procedures, segmentation, redundancy, vulnerability management, periodic testing, recovery mechanisms, and coordination between teams are all part of a single strategy.

Moreover, the response cannot be limited to the cybersecurity department. A serious disruption can involve operations, engineering, and technology teams, providers, business leaders, and public authorities.

The security of a critical infrastructure is, ultimately, a multidisciplinary problem.

 

Regulation as an accelerator, not a destination

NIS2 is raising the bar for critical infrastructure operators. In June 2025, ENISA also published a technical guide to help digital infrastructure and managed service entities implement the security measures set out in the European framework.

But complying with a regulation shouldn't become the end goal.

The real question is whether an infrastructure can withstand an environment in which attacks evolve, technologies change, and dependencies increase.

Because a network can formally meet every requirement and still be vulnerable to an unexpected combination of events.

Resilience demands going a step beyond the checklist.

 

Telecommunications as trusted infrastructure

The strategic importance of telecommunications will keep growing as digitalization moves toward services that are more autonomous, connected, and data-dependent.

The arrival of 5G and 5G Advanced networks, the growth of edge computing, the virtualization of network functions, and the gradual incorporation of artificial intelligence are making architectures more flexible, but also more complex.

In this scenario, protecting telecommunications doesn't just mean defending a network against an attacker.

It means preserving a digital society's ability to keep functioning.

And that difference — between security and resilience, between protecting assets and guaranteeing continuity — will become increasingly decisive for critical telecommunications infrastructure.

Last news

Flèche précédente pour naviguer dans l'actualité Flèche suivante pour naviguer dans l'actualité
Image de l'article Critical telecommunications infrastructure security: protecting the backbone of the digital world
Expertise 30 September 2026

Critical telecommunications infrastructure security: protecting the backbone of the digital world

Image de l'article Agentic Commerce:  when Artificial Intelligence becomes the  buyer
Expertise 24 September 2026

Agentic Commerce: when Artificial Intelligence becomes the buyer

Image de l'article Systems-of-Systems Engineering:  designing when  the system is no longer alone
Expertise 15 September 2026

Systems-of-Systems Engineering: designing when the system is no longer alone

Image de l'article SII Group expands its Manufacturing Engineering services to support the aerospace industry's new pace of transformation.
Corporate 2 September 2026

SII Group expands its Manufacturing Engineering services to support the aerospace industry's new pace of transformation.

Image de l'article SII strengthens its capabilities in the aerospace and defense sectors through the acquisition of Airtificial’s and Aertec Solutions’ activities
Corporate 14 July 2026

SII strengthens its capabilities in the aerospace and defense sectors through the acquisition of Airtificial’s and Aertec Solutions’ activities

Image de l'article Edge-to-Cloud Orchestration: the key to connecting intelligence, data, and operations in real time.
Innovation 15 June 2026

Edge-to-Cloud Orchestration: the key to connecting intelligence, data, and operations in real time.

Image de l'article Autonomous QA Platforms: When Testing Starts Making Decisions on Its Own
Innovation 3 June 2026

Autonomous QA Platforms: When Testing Starts Making Decisions on Its Own

Image de l'article SII Group Spain Strengthens Its Commitment to the Convergence of Engineering and Digitalization at ADM Seville 2026
Corporate 25 May 2026

SII Group Spain Strengthens Its Commitment to the Convergence of Engineering and Digitalization at ADM Seville 2026

Image de l'article Multimodal AI Systems: when artificial intelligence starts to understand the world the way humans do
Innovation 14 April 2026

Multimodal AI Systems: when artificial intelligence starts to understand the world the way humans do

Image de l'article SII Group Spain takes part in MWC Barcelona 2026 and Talent Arena, consolidating its role in building the digital future
Events 23 March 2026

SII Group Spain takes part in MWC Barcelona 2026 and Talent Arena, consolidating its role in building the digital future

Image de l'article IoT and Digital Twins: connected intelligence redefining energy management
Innovation 17 March 2026

IoT and Digital Twins: connected intelligence redefining energy management

Image de l'article Smart Network Deployment: The Engine Driving Telecommunications Transformation
Innovation 11 March 2026

Smart Network Deployment: The Engine Driving Telecommunications Transformation