Consumers expect mobile services to be secure and should be able to trust those services without needing to understand the rules behind them. Unfortunately, poorly designed regulation can help criminals by weakening that protection.
Mobile operators already invest US$15–19 billion a year in core cybersecurity, rising to an expected US$40–42 billion by 2030. To make the most of this investment, regulation should focus on the threats most likely to harm consumers. Instead, misaligned rules such as forcing operators to report the same incident several times, in different formats, to different authorities, diverts time and expertise from actually preventing attacks and restoring services quickly.
The GSMA’s global report The Impact of Cybersecurity Regulation on Mobile Operators sets out a more effective approach: clear, predictable rules that target genuine security risks rather than fragmented or duplicative compliance. This allows operators to invest where it matters most – building stronger networks, closing vulnerabilities and responding faster when incidents occur. The report contains six principles for policymakers:
- Harmonisation with international standards
- Consistency across policies
- Risk- and outcome-based obligations
- Collaboration between regulators and industry
- Security-by-design
- Capacity-building for regulators
Why does this matter for consumers? Cyber threats evolve faster than legislation, so rigid rules that prescribe a particular technology or process can quickly become obsolete and slow down innovation. Well-designed frameworks:
- Focus on outcomes
- Direct efforts to where risk is highest
- Speed up the adoption of new technologies
- Strengthen consumer safeguards as risks evolve
Operators can’t protect consumers and society on their own. They’re part of a wider ecosystem made up of various organisations including digital platforms, banks, governments, regulators and law enforcement, all playing a key role in preventing cyberattacks that exploit both individuals and technology. Yes, consumers should protect themselves, but any approach that puts the responsibility solely on them is doomed to fail.
The six principles in the report apply globally and to markets at different stages of cybersecurity policy development. For countries with less mature digital frameworks, they guide the development of digital policy, ensuring that as it evolves, it supports operators and their customers. For countries with more advanced digital frameworks, they will help governments to consolidate and align existing rules, so operator investment is targeted with efforts focused on tackling threats and making services safer and more secure, enhancing trust and confidence in digital services.