{"id":14289,"date":"2026-04-30T11:02:50","date_gmt":"2026-04-30T10:02:50","guid":{"rendered":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/?p=14289"},"modified":"2026-04-30T13:02:58","modified_gmt":"2026-04-30T12:02:58","slug":"why-technical-standards-and-policies-go-hand-in-hand-for-mobile-network-security","status":"publish","type":"post","link":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/general\/why-technical-standards-and-policies-go-hand-in-hand-for-mobile-network-security\/","title":{"rendered":"Why\u00a0technical\u00a0standards and\u00a0policies go\u00a0hand in hand\u00a0for\u00a0mobile\u00a0network\u00a0security\u00a0"},"content":{"rendered":"\n<p>Safeguarding consumers,&nbsp;citizens&nbsp;and enterprises&nbsp;is important as they become increasingly reliant on their mobile phones to access&nbsp;banking, shopping,&nbsp;health&nbsp;and other important services. This requires&nbsp;a&nbsp;coordinated approach where\u202ftechnical standards\u202fand\u202fsupportive policy frameworks\u202freinforce each other.&nbsp;<\/p>\n\n\n\n<p><em>The Case for Technical Standards<\/em>&nbsp;<\/p>\n\n\n\n<p>Technical standards&nbsp;provide a common security baseline that works across borders, vendors, and network generations&nbsp;(e.g. 4G, 5G&nbsp;and 6G).&nbsp;<strong>NESAS<\/strong>&nbsp;(Network Equipment Security Assurance Scheme),&nbsp;developed jointly with 3GPP,&nbsp;defines a globally applicable security baseline for network equipment.&nbsp;It&nbsp;combines&nbsp;standardised security requirements with independent&nbsp;rigorous&nbsp;testing and auditing&nbsp;to provide confidence&nbsp;to mobile operators&nbsp;worldwide. NESAS&nbsp;also&nbsp;allows vendors&nbsp;to&nbsp;demonstrate&nbsp;compliance once.&nbsp;&nbsp;<\/p>\n\n\n\n<p><em>Global Standards Bodies<\/em>&nbsp;<\/p>\n\n\n\n<p>International standards and frameworks can support global and cross-sector collaboration.&nbsp;Alignment with existing industry and international frameworks not only enhances interoperability and strengthens security solutions but also&nbsp;facilitates&nbsp;shared responses to emerging threats.&nbsp;NESAS is one of&nbsp;many&nbsp;globally recognised standards.&nbsp;These&nbsp;include&nbsp;<strong>3GPP<\/strong>&nbsp;(core mobile network specification for 2G to 5G), including authentication, encryption, and signalling security;&nbsp;<strong>ETSI<\/strong>&nbsp;(European telecoms standards), and&nbsp;<strong>IETF<\/strong>&nbsp;(Internet protocols underpinning mobile data).&nbsp;<\/p>\n\n\n\n<p><em>Why&nbsp;standards&nbsp;alone&nbsp;are not sufficient&nbsp;<\/em>&nbsp;<\/p>\n\n\n\n<p>Standards tell us\u202fhow&nbsp;to build secure systems; policy tells us\u202fthat\u202fwe must.&nbsp;The GSMA&#8217;s&nbsp;report&nbsp;<a href=\"https:\/\/www.gsma.com\/newsroom\/press-release\/new-gsma-report-warns-that-fragmented-cybersecurity-regulation-is-raising-costs-and-increasing-risk-for-mobile-operators\/\" target=\"_blank\" rel=\"noreferrer noopener\">The Impact of Cybersecurity Regulation on Mobile Operators<\/a>&nbsp;explains that&nbsp;well-designed policy\u202fstrengthens resilience, while poorly designed policy\u202fincreases risk&nbsp;and costs.&nbsp;<\/p>\n\n\n\n<p><em>Six Principles for Effective Cybersecurity Regulation<\/em>&nbsp;<\/p>\n\n\n\n<p>The GSMA recommends that governments design cybersecurity frameworks around these principles:&nbsp;<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li><strong>Harmonisation<\/strong>: Align cybersecurity policy with international standards wherever possible, to reduce regulatory fragmentation and inconsistency.&nbsp;<\/li>\n<\/ol>\n\n\n\n<ol start=\"2\" class=\"wp-block-list\">\n<li><strong>Consistency<\/strong>: Ensure new policies and frameworks are consistent with existing policy to avoid duplication or conflict.&nbsp;<\/li>\n<\/ol>\n\n\n\n<ol start=\"3\" class=\"wp-block-list\">\n<li><strong>Risk- and outcome-based<\/strong>: Adopt risk-based and outcome-based approaches in the design and implementation of cybersecurity regulation, giving operators flexibility to innovate and deploy effective solutions.&nbsp;<\/li>\n<\/ol>\n\n\n\n<ol start=\"4\" class=\"wp-block-list\">\n<li><strong>Collaboration<\/strong>: Promote a collaborative regulatory culture with industry, supported by secure threat intelligence sharing to strengthen resilience, increase awareness of cyber threats, enable constructive enforcement, and foster a joint approach to combating cybercrime.&nbsp;<\/li>\n<\/ol>\n\n\n\n<ol start=\"5\" class=\"wp-block-list\">\n<li><strong>Security-by-design<\/strong>: Encourage a proactive, security-by-design approach to mitigating cyber risks.&nbsp;<\/li>\n<\/ol>\n\n\n\n<ol start=\"6\" class=\"wp-block-list\">\n<li><strong>Capacity-building<\/strong>: Strengthen the institutional capacity of cybersecurity authorities to ensure a whole-of-government approach and effective application of policy and regulation.&nbsp;<\/li>\n<\/ol>\n\n\n\n<p>When regulation follows these principles,&nbsp;mobile&nbsp;operators can direct resources toward genuine&nbsp;threat and&nbsp;risk mitigation rather than compliance&nbsp;for the sake of compliance.&nbsp;\u202f&nbsp;<\/p>\n\n\n\n<p><em>Regional and&nbsp;country&nbsp;examples<\/em>&nbsp;<\/p>\n\n\n\n<p><strong>EU&nbsp;\u2013 NIS2 Directive<\/strong>&nbsp;<\/p>\n\n\n\n<p>The EU&#8217;s revised Network and Information Security Directive (NIS2)&nbsp;treats&nbsp;telecoms as essential infrastructure and mandates risk-management measures, incident reporting, and supply-chain security.&nbsp;It references ETSI and 3GPP standards,&nbsp;so&nbsp;operators can&nbsp;leverage&nbsp;existing compliance work rather than&nbsp;starting from scratch.&nbsp;<\/p>\n\n\n\n<p><strong>US&nbsp;\u2013&nbsp;NIST and&nbsp;CSRIC<\/strong>&nbsp;<\/p>\n\n\n\n<p>In the US, the NIST Cybersecurity Framework is co-developed with industry input, while the Communications Security, Reliability and Interoperability Council (CSRIC) brings regulators and telecoms experts together to shape cybersecurity guidance collaboratively.&nbsp;<\/p>\n\n\n\n<p><strong>APAC&nbsp;\u2013 Singapore&#8217;s Cybersecurity Act<\/strong>&nbsp;<\/p>\n\n\n\n<p>Singapore&#8217;s&nbsp;Infocomm&nbsp;Media Development Authority (IMDA)&nbsp;designates&nbsp;critical information infrastructure, including mobile networks, and mandates audits, incident reporting, and risk assessments.&nbsp;Alignment with international standards&nbsp;is explicitly encouraged,&nbsp;and the IMDA regularly seeks mobile operator feedback on draft standards,&nbsp;facilitating&nbsp;trust and cooperation between the public and private sectors.&nbsp;&nbsp;<\/p>\n\n\n\n<p><strong>LATAM&nbsp;\u2013 Emerging Frameworks<\/strong>&nbsp;<\/p>\n\n\n\n<p>Latin American regulators are increasingly recognising the link between cybersecurity policy and connectivity investment. Countries that adopt outcome-based approaches,&nbsp;rather than prescriptive checklists,&nbsp;can&nbsp;target their investments in innovative solutions to improve network&nbsp;security&nbsp;and resilience.&nbsp;&nbsp;<\/p>\n\n\n\n<p><em>The&nbsp;2026 Security Landscape Report<\/em>&nbsp;<\/p>\n\n\n\n<p>The&nbsp;<a href=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/gsma-mobile-telecommunications-security-landscape-2026\/\" target=\"_blank\" rel=\"noreferrer noopener\">GSMA&nbsp;Mobile Telecommunications Security Landscape 2026<\/a>\u202fis an annual report providing a comprehensive analysis of the&nbsp;current and emerging security threats&nbsp;and strategies across the mobile telecoms landscape. The&nbsp;report&nbsp;explains how multi-layered defences&nbsp;combining international standards, industry best practices, company-specific controls, and risk-driven measures&nbsp;offer the most effective response&nbsp;to network security threats.&nbsp;Policies&nbsp;that&nbsp;mandate&nbsp;baseline compliance while allowing flexibility for innovation&nbsp;support&nbsp;this layered approach.\u202f&nbsp;<\/p>\n\n\n\n<p><em>The Cost of Getting It Wrong<\/em>&nbsp;<\/p>\n\n\n\n<p>Fragmented or overly prescriptive regulation creates&nbsp;real harm. The GSMA estimates that mobile operators spend\u202f<strong>$15\u201319 billion annually<\/strong>\u202fon core cybersecurity activities today, rising to\u202f<strong>$40\u201342 billion by 2030<\/strong>. When compliance obligations overlap or conflict, resources shift from threat detection to audit preparation. One operator reported that\u202f80&nbsp;per cent&nbsp;of their security operations team&#8217;s time\u202fgoes to compliance tasks rather than incident response.\u202fHarmonised, outcome-focused policy avoids this trap.&nbsp;<\/p>\n\n\n\n<p><em>Key takeaways<\/em>&nbsp;<\/p>\n\n\n\n<p>Technical standards and policy&nbsp;go hand in hand.&nbsp;Standards provide the engineering blueprint for secure networks; policy ensures that blueprint is followed consistently and that gaps are addressed as threats evolve. For mobile network users&nbsp;&#8211;&nbsp;whether individuals,&nbsp;enterprises&nbsp;or governments&nbsp;&#8211;&nbsp;this combination is the foundation of trust in a digitally connected world.&nbsp;<\/p>\n\n\n\n<p>Policymakers can strengthen that foundation by embracing risk-based, harmonised frameworks that reference international standards. Operators, in turn,&nbsp;are engaging&nbsp;constructively with regulators, sharing&nbsp;threat intelligence, and investing&nbsp;in the layered defences that standards enable.&nbsp;Collaboration is key.&nbsp;<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Safeguarding consumers,&nbsp;citizens&nbsp;and enterprises&nbsp;is important as they become increasingly reliant on their mobile phones to access&nbsp;banking, shopping,&nbsp;health&nbsp;and other important services. This requires&nbsp;a&nbsp;coordinated approach where\u202ftechnical standards\u202fand\u202fsupportive policy frameworks\u202freinforce each other.&nbsp; The Case for Technical Standards&nbsp; Technical standards&nbsp;provide a common security baseline that works across borders, vendors, and network generations&nbsp;(e.g. 4G, 5G&nbsp;and 6G).&nbsp;NESAS&nbsp;(Network Equipment Security Assurance Scheme),&nbsp;developed jointly [&hellip;]<\/p>\n","protected":false},"author":66,"featured_media":13375,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_oasis_is_in_workflow":0,"_oasis_original":0,"_oasis_task_priority":"","footnotes":""},"categories":[1],"tags":[],"algolia_discover_type":[1549,1553],"class_list":["post-14289","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general","algolia_discover_type-article","algolia_discover_type-resource"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v24.3 (Yoast SEO v24.3) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Why\u00a0technical\u00a0standards and\u00a0policies go\u00a0hand in hand\u00a0for\u00a0mobile\u00a0network\u00a0security\u00a0 - Security<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/general\/why-technical-standards-and-policies-go-hand-in-hand-for-mobile-network-security\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Why\u00a0technical\u00a0standards and\u00a0policies go\u00a0hand in hand\u00a0for\u00a0mobile\u00a0network\u00a0security\u00a0 - Security\" \/>\n<meta property=\"og:description\" content=\"Safeguarding consumers,&nbsp;citizens&nbsp;and enterprises&nbsp;is important as they become increasingly reliant on their mobile phones to access&nbsp;banking, shopping,&nbsp;health&nbsp;and other important services. This requires&nbsp;a&nbsp;coordinated approach where\u202ftechnical standards\u202fand\u202fsupportive policy frameworks\u202freinforce each other.&nbsp; The Case for Technical Standards&nbsp; Technical standards&nbsp;provide a common security baseline that works across borders, vendors, and network generations&nbsp;(e.g. 4G, 5G&nbsp;and 6G).&nbsp;NESAS&nbsp;(Network Equipment Security Assurance Scheme),&nbsp;developed jointly [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/general\/why-technical-standards-and-policies-go-hand-in-hand-for-mobile-network-security\/\" \/>\n<meta property=\"og:site_name\" content=\"Security\" \/>\n<meta property=\"article:published_time\" content=\"2026-04-30T10:02:50+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-30T12:02:58+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2025\/09\/GettyImages-1199992530.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1519\" \/>\n\t<meta property=\"og:image:height\" content=\"1500\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"ehenderson@gsma.com\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"ehenderson@gsma.com\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Why\u00a0technical\u00a0standards and\u00a0policies go\u00a0hand in hand\u00a0for\u00a0mobile\u00a0network\u00a0security\u00a0 - Security","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/general\/why-technical-standards-and-policies-go-hand-in-hand-for-mobile-network-security\/","og_locale":"en_GB","og_type":"article","og_title":"Why\u00a0technical\u00a0standards and\u00a0policies go\u00a0hand in hand\u00a0for\u00a0mobile\u00a0network\u00a0security\u00a0 - Security","og_description":"Safeguarding consumers,&nbsp;citizens&nbsp;and enterprises&nbsp;is important as they become increasingly reliant on their mobile phones to access&nbsp;banking, shopping,&nbsp;health&nbsp;and other important services. This requires&nbsp;a&nbsp;coordinated approach where\u202ftechnical standards\u202fand\u202fsupportive policy frameworks\u202freinforce each other.&nbsp; The Case for Technical Standards&nbsp; Technical standards&nbsp;provide a common security baseline that works across borders, vendors, and network generations&nbsp;(e.g. 4G, 5G&nbsp;and 6G).&nbsp;NESAS&nbsp;(Network Equipment Security Assurance Scheme),&nbsp;developed jointly [&hellip;]","og_url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/general\/why-technical-standards-and-policies-go-hand-in-hand-for-mobile-network-security\/","og_site_name":"Security","article_published_time":"2026-04-30T10:02:50+00:00","article_modified_time":"2026-04-30T12:02:58+00:00","og_image":[{"width":1519,"height":1500,"url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2025\/09\/GettyImages-1199992530.jpg","type":"image\/jpeg"}],"author":"ehenderson@gsma.com","twitter_card":"summary_large_image","twitter_misc":{"Written by":"ehenderson@gsma.com","Estimated reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/general\/why-technical-standards-and-policies-go-hand-in-hand-for-mobile-network-security\/","url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/general\/why-technical-standards-and-policies-go-hand-in-hand-for-mobile-network-security\/","name":"Why\u00a0technical\u00a0standards and\u00a0policies go\u00a0hand in hand\u00a0for\u00a0mobile\u00a0network\u00a0security\u00a0 - Security","isPartOf":{"@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/general\/why-technical-standards-and-policies-go-hand-in-hand-for-mobile-network-security\/#primaryimage"},"image":{"@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/general\/why-technical-standards-and-policies-go-hand-in-hand-for-mobile-network-security\/#primaryimage"},"thumbnailUrl":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2025\/09\/GettyImages-1199992530.jpg","datePublished":"2026-04-30T10:02:50+00:00","dateModified":"2026-04-30T12:02:58+00:00","author":{"@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/#\/schema\/person\/06397f185befa1985d4ee28109cc2759"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/general\/why-technical-standards-and-policies-go-hand-in-hand-for-mobile-network-security\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/general\/why-technical-standards-and-policies-go-hand-in-hand-for-mobile-network-security\/#primaryimage","url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2025\/09\/GettyImages-1199992530.jpg","contentUrl":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2025\/09\/GettyImages-1199992530.jpg","width":1519,"height":1500,"caption":"Light painting."},{"@type":"WebSite","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/#website","url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/","name":"Security","description":"GSMA Security","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Person","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/#\/schema\/person\/06397f185befa1985d4ee28109cc2759","name":"ehenderson@gsma.com","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/5174b854e8868f2475d4b9d5d155fc08?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/5174b854e8868f2475d4b9d5d155fc08?s=96&d=mm&r=g","caption":"ehenderson@gsma.com"}}]}},"featured_image_url":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-content\/uploads\/2025\/09\/GettyImages-1199992530.jpg","_links":{"self":[{"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/posts\/14289","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/users\/66"}],"replies":[{"embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/comments?post=14289"}],"version-history":[{"count":3,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/posts\/14289\/revisions"}],"predecessor-version":[{"id":14295,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/posts\/14289\/revisions\/14295"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/media\/13375"}],"wp:attachment":[{"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/media?parent=14289"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/categories?post=14289"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/tags?post=14289"},{"taxonomy":"algolia_discover_type","embeddable":true,"href":"https:\/\/www.gsma.com\/solutions-and-impact\/technologies\/security\/wp-json\/wp\/v2\/algolia_discover_type?post=14289"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}