A firewall can stop unwanted traffic at a network boundary. It cannot tell you whether a caller is who they claim to be, whether a certificate has expired or whether a trusted identity is being misused.
That distinction is becoming critical as telecom networks evolve into highly distributed environments spanning IP voice, 5G infrastructure, cloud platforms, APIs, edge computing and multiple carrier interconnections.
Telecom security therefore cannot be reduced to perimeter defense.
A modern carrier needs to protect connectivity, identity, signaling, credentials, applications, APIs, network functions and the trust relationships between providers.
The numbers reinforce the challenge. Verizon's 2026 Data Breach Investigations Report recorded 5,514 DDoS incidents in its dataset and noted that the median breached entity faced 17 distinct DDoS attacks during the year. (Verizon) Meanwhile ENISA's 2024 telecom security incident report documented 188 incidents reported across EU member states and EFTA countries — a 20.5% increase from 2023. (enisa.europa.eu)
For telecom providers the strategic question is no longer:
"Do we have a firewall?"
It is:
"Can we establish trust and detect risk across every layer of the network?"
Why Firewalls Alone Cannot Secure Modern Telecom Networks
The Perimeter Has Changed
Traditional enterprise security often starts with a straightforward concept:
Trusted network → Firewall → Untrusted network
Telecom networks do not fit neatly into that model anymore.
A modern communications environment can include:
Mobile and fixed networks
4G and 5G infrastructure
SIP and VoIP systems
SBCs
Cloud-native network functions
APIs
Edge infrastructure
IoT devices
Third-party platforms
Roaming partners
Transit carriers
Enterprise communication platforms
There may be no single perimeter.
Nokia describes modern telecom networks as increasingly software-defined, virtualized and interconnected with a larger attack surface that perimeter defenses alone cannot protect. (Nokia Corporation | Nokia)
Firewalls Control Traffic. They Do Not Establish Every Form of Trust.
A firewall can determine whether traffic matches a particular rule.
It does not inherently answer questions such as:
Who owns this telephone number?
Is this caller identity authenticated?
Is the certificate valid?
Has a credential been revoked?
Is this API request coming from an authorized service?
Has a legitimate identity suddenly started behaving abnormally?
Those are identity and trust questions.
That is why telecom security needs multiple control layers rather than one dominant security appliance.
Think of a Firewall as a Gate
A firewall is like the security gate at a major telecom facility.
It can control who or what gets through a particular entrance.
But imagine allowing someone into the facility and then never checking their badge, monitoring their activity or verifying whether their access rights remain valid.
The gate is still useful.
It is simply not the entire security strategy.
Telecom Networks Need Identity Security as Well as Network Security
Connectivity Does Not Prove Identity
One of the most important differences between traditional network security and modern telecom security is the role of identity.
A network can successfully deliver a communication while the identity behind that communication remains questionable.
This is especially important in voice.
A caller ID number alone is not sufficient evidence that the caller is authorized to use that identity.
STIR/SHAKEN Adds a Trust Layer
STIR/SHAKEN addresses this problem by using digital certificates and public-key cryptography to authenticate caller identity.
TransNexus describes the framework as using digital certificates to allow the called party to verify that the calling number has not been spoofed. (TransNexus)
The simplified process is:
Caller → Originating Provider → Authentication → Digital Signature → Certificate → Verification → Terminating Provider
The firewall may still protect the underlying network.
But the certificate-based identity layer answers a different question:
Can the receiving network verify the identity claim associated with this call?
Authentication Becomes a Security Control
That makes caller authentication part of telecom security rather than merely a voice feature.
Consider a financial institution making an outbound call. The firewall may correctly permit the call.The SBC may correctly route the call. The network may successfully deliver it. Yet the customer may still ignore it if the displayed identity looks suspicious. Secure identity therefore protects more than infrastructure. It protects the credibility of the communication itself.
The FCC Recognizes the Importance of Authentication
The FCC describes STIR/SHAKEN caller ID authentication as one of its key tools for combating illegal robocalls. It also notes that non-IP portions of a call path can create gaps because STIR/SHAKEN operates on IP networks. (FCC Docs)
This demonstrates why telecom security needs both network protection and identity assurance.
Certificates Are Security Infrastructure - Not Administrative Files
Every Digital Identity Needs a Trust Mechanism
Digital certificates establish relationships between identities and cryptographic keys.
In telecom environments they can support:
Caller authentication
Network authentication
Secure signaling
Service identity
API security
Device identity
Certificate-based encryption
Nokia has highlighted the growing importance of certificates in 5G because certificate-based security is distributed across the network and can support authentication of sources and recipients. (Nokia Corporation | Nokia)
This changes the way carriers should think about certificate management.
A certificate is not simply something an engineer downloads once a year.
It is a security credential.
Certificate Expiration Is a Security Event
Every certificate has a lifecycle.
Issue → Deploy → Monitor → Renew → Rotate → Revoke
If the lifecycle is managed manually then the security process depends on people remembering predictable events.
That creates unnecessary operational risk.
A missed certificate renewal can cause authentication failures.
A compromised private key can create a much more serious security incident.
An incorrectly deployed certificate can break verification even when the rest of the network is functioning.
Automation Makes the Trust Layer More Resilient
Peeringhub provides an STIR/SHAKEN Certificate Authority service designed for voice providers with certificate enrollment, delegated signing, attestation controls and developer automation. (peeringhub.io)
Its ACME implementation supports the certificate workflow from account authorization through ordering, challenge processing, CSR submission and certificate retrieval. (doc.peeringhub.io)
It also supports certificate issuance, renewal and revocation through its ACME API. (peeringhub.io)
The strategic benefit is straightforward:
Security controls become more reliable when their lifecycle is automated.
Signaling and Application Layers Need Their Own Protection
Telecom Attacks Do Not Always Look Like Malicious Traffic
A firewall is particularly useful when malicious traffic is distinguishable from legitimate traffic.
But telecom attackers increasingly exploit protocols and services that already belong inside the network.
Nokia has highlighted GTPDOOR as an example of malware that can blend into routine telecom network traffic while exploiting the GTP-C protocol to establish covert communication channels. (Nokia Corporation | Nokia)
This creates a difficult problem. The traffic may pass through legitimate infrastructure. The protocol may be valid. mThe network connection may be allowed. Yet the behavior can still be malicious.
Protocol Awareness Matters
Telecom security therefore needs visibility into protocols such as:
SIP
Diameter
GTP
SCTP
HTTP APIs
DNS
Network management protocols
Security systems need to understand what normal behavior looks like for those environments.
Application Security Is Equally Important
Modern telecom infrastructure increasingly depends on APIs.
Those APIs can connect:
Customer systems → Provisioning → Network functions → Identity systems → Billing → Analytics
An attacker who compromises an API credential may not need to attack the firewall at all.
They may simply use legitimate API access to perform unauthorized actions.
Fortinet has similarly argued that for advanced 5G use cases a stateful firewall alone is insufficient and that API security, application security and IoT security may also be required across distributed environments. (Fortinet)
The lesson is clear:
Security needs to understand the application behavior happening inside the network rather than only the packets entering it.
Monitoring and Threat Detection Must Operate Continuously
Prevention Is Only One Part of Security
A firewall is primarily a preventive control.
But no preventive control is perfect.
Telecom providers also need to answer:
What is happening right now?
That requires monitoring.
Static Rules Cannot Catch Every New Threat
Attackers can:
Change infrastructure
Rotate credentials
Abuse legitimate services
Exploit new vulnerabilities
Move laterally
Blend into normal traffic
Target third-party connections
A rule that blocked yesterday's behavior may not identify tomorrow's.
Nokia's current telecom security guidance emphasizes runtime security because attackers increasingly seek persistence within normal network operations rather than simply causing obvious disruption. (Nokia Corporation | Nokia)
Security Operations Need Telecom Context
A generic security alert saying:
"Unusual traffic detected."
may not mean much to a telecom engineer.
A more useful signal might be:
"Unexpected SIP authentication behavior from a previously stable carrier interconnection."
Or:
"Certificate validation failures increased sharply for a specific originating provider."
Or:
"A provisioning API is making abnormal requests outside its established pattern."
Context turns an alert into an investigation.
Identity Monitoring Complements Network Monitoring
Peeringhub's platform includes tools for decoding STIR/SHAKEN Identity Headers and inspecting certificates. Its Identity Header Parser exposes fields including attestation, origination, destination, x5u, algorithm and signature status. (peeringhub.io)
Its Certificate Inspector can examine certificate content and provide issuer, subject, validity and OCN context. (doc.peeringhub.io)
This creates a useful security chain:
Network Event → Identity Header → Certificate → Signature → Provider Identity → Trust Decision
A firewall sees traffic.
Identity-aware tooling can help explain who is behind the communication and whether the associated trust evidence is valid.
Telecom Security Must Protect the Supply Chain and Trust Relationships
Carriers Rarely Operate Alone
Telecom networks depend on interconnected organizations.
A call may move through:
Enterprise → VoIP Provider → Transit Carrier → Wholesale Carrier → Mobile Network
A 5G service may depend on:
Operator → Cloud Provider → Network Function Vendor → Edge Platform → Application Provider
Every external relationship creates another trust boundary.
Third-Party Risk Is Growing
Verizon's 2025 DBIR reported that third-party involvement in breaches doubled to 30% in its dataset. (Verizon)
For telecom providers this matters because connectivity itself depends on relationships with external infrastructure.
A carrier can maintain strong internal security while still being affected by weaknesses in an interconnected provider.
Identity Governance Must Extend Beyond the Firewall
Security teams should understand:
Which providers are authorized
Which customers own which numbers
Which credentials belong to which systems
Which certificates belong to which providers
Which APIs have access to which services
Which interconnections are trusted
Which identities have changed
This is where telecom security begins to resemble modern identity security.
The question is no longer only:
"Can this system connect?"
It becomes:
"Should this identity be trusted to perform this action?"
Authentication Helps Create Accountability
A verified identity creates stronger evidence around who performed or originated an action. In voice networks that may mean linking a caller identity to an authenticated service provider. In APIs it may mean linking requests to authenticated applications. In infrastructure it may mean linking certificates to authorized network functions. That accountability becomes increasingly important as telecom networks become more distributed.
A Layered Telecom Security Architecture Is the More Sustainable Model
Think in Security Layers
A modern telecom security architecture can be structured around several complementary layers.
Layer 1: Network Security
Protect network boundaries and traffic flows.
Examples include:
Firewalls
DDoS protection
Security gateways
Network segmentation
Layer 2: Protocol Security
Understand and protect telecom-specific protocols.
Examples include:
SIP security
GTP security
Diameter security
SCTP controls
Layer 3: Identity Security
Establish who is authorized.
Examples include:
Digital certificates
STIR/SHAKEN
IAM
Mutual TLS
Identity validation
Layer 4: Application and API Security
Protect software interfaces that control network services.
Examples include:
API authentication
Authorization
Rate limiting
Application security
Credential management
Layer 5: Detection and Response
Identify abnormal behavior.
Examples include:
SIEM
XDR
Threat intelligence
Behavioral analytics
Runtime detection
Layer 6: Operational Security
Make the controls themselves reliable.
Examples include:
Certificate lifecycle management
Key rotation
Configuration governance
Audit trails
Automated remediation
The important point is not to purchase six separate products simply to create six layers.
The objective is to ensure that no single control is expected to solve a problem it was never designed to solve.
Comparing Telecom Security Approaches
Peeringhub: Identity and Trust Infrastructure
Peeringhub approaches telecom security from the identity layer.
Its platform focuses on STIR/SHAKEN certificate infrastructure with certificate enrollment, delegated signing, attestation controls, Identity Header parsing, certificate inspection, STI-CR hosting, OCN lookup and automated certificate lifecycle management. (peeringhub.io)
Its ACME API supports certificate issue, renewal and revocation while its Python tooling provides workflows for certificate operations and STIR/SHAKEN development. (peeringhub.io)
This makes Peeringhub complementary to perimeter security rather than a replacement for it.
A carrier can have a firewall protecting network traffic while using an identity infrastructure layer to validate communications and credentials.
Nokia: End-to-End Telecom Security
Nokia takes a broader network-security approach.
Its current cybersecurity portfolio includes DDoS mitigation, network security, XDR, identity access management and certificate lifecycle management. Nokia explicitly distinguishes telco network security from conventional IT security because telecom environments prioritize service availability and require knowledge of telecom protocols and standards. (Nokia Corporation | Nokia)
This makes Nokia's approach broader across the telecom infrastructure stack.
Fortinet: Distributed Security Controls
Fortinet positions its telecom security approach around distributed protection for 4G and 5G infrastructure including user and control planes. Its material emphasizes that advanced 5G environments can require API security, application security and IoT security in addition to firewall capabilities. (Fortinet)
The architectural difference is useful:
Firewall-centric security: protects network boundaries.
Network-security platforms: protect broader infrastructure and traffic behavior.
Identity infrastructure: establishes trust in identities and credentials.
A mature telecom security program may need all three.
TransNexus: Voice Trust and STIR/SHAKEN
TransNexus focuses heavily on voice authentication and robocall mitigation.
Its STIR/SHAKEN materials describe certificate-based caller authentication and verification while its 2026 reporting continues to track attestation and robocall trends across participating providers. (TransNexus)
This makes it a relevant comparison for carriers evaluating the voice-security portion of a broader telecom security architecture.
How Carriers Can Move Beyond Firewall-First Security
1. Map the Complete Attack Surface
Document:
Network boundaries
Cloud environments
APIs
Network functions
Voice systems
Certificates
Interconnections
Third-party providers
Customer-facing applications
The objective is to identify security gaps between systems.
2. Build an Identity Inventory
Know:
Who owns each identity
Which numbers belong to which customers
Which certificates belong to which provider
Which APIs have access
Which credentials are active
Which credentials should be revoked
3. Automate Certificate Operations
Use automated workflows for:
Issuance
Renewal
Rotation
Revocation
Publication
Monitoring
Peeringhub's ACME service provides a standards-based route for automated STIR/SHAKEN certificate lifecycle operations. (doc.peeringhub.io)
4. Monitor Identity as Closely as Traffic
Track:
Authentication failures
Certificate failures
Attestation changes
Identity Header errors
Suspicious calling patterns
API authentication anomalies
5. Segment Critical Functions
Separate critical network functions where practical.
A compromise in one environment should not automatically provide unrestricted access to another.
6. Protect the Control Plane
The control plane can be as important as the traffic itself.
Protect provisioning systems, APIs, management interfaces and signaling infrastructure.
7. Prepare for DDoS and Availability Attacks
Security is not only about confidentiality.
For telecom providers availability is security.
A network that is technically secure but unavailable to customers is still failing its security objective.
Verizon's 2026 DBIR data reinforces the scale of the availability challenge with thousands of DDoS incidents in its dataset. (Verizon)
8. Make Security Observable
Security teams should be able to answer:
What happened?
Where did it happen?
Which identity was involved?
Was the identity authorized?
Which credential was used?
What changed?
What action should happen next?
That is much more powerful than simply knowing that a firewall blocked a packet.
Why Telecom Security Is Becoming an Identity Problem
The most important shift in telecom security is that networks are becoming increasingly distributed.
Cloud
5G
Edge
APIs
Virtualized network functions
Wholesale interconnections
Enterprise communication platforms
IoT
Every new connection adds another relationship that needs to be trusted.
ENISA's work on 5G security emphasizes that modern networks require security controls across new architectures and operational processes rather than relying on a narrow security perimeter. (enisa.europa.eu)
That changes the security equation.
The traditional model was:
Protect the network.
The modern model is:
Protect the network + verify identities + secure credentials + monitor behavior + control access + preserve trust.
This is why digital certificates matter. This is why STIR/SHAKEN matters. This is why API security matters. This is why identity validation matters.
And this is why certificate lifecycle management increasingly belongs inside the telecom security strategy.
Conclusion: The Strongest Telecom Security Strategy Has Layers
Firewalls remain important.
They should remain part of a carrier's security architecture.
But they cannot be expected to solve every security problem created by modern telecom infrastructure.
They cannot independently validate caller identity. They cannot manage every certificate. They cannot determine whether a legitimate credential is being abused. They cannot guarantee that authentication information survives every network transition. They cannot provide complete visibility into application behavior.
And they cannot replace security operations.
Modern telecom security requires a broader architecture built around network protection, identity assurance, certificate security, application protection, continuous monitoring and operational resilience.
The threat landscape makes this increasingly urgent. ENISA recorded 188 telecom security incidents across participating European countries in 2024 which represented a 20.5% increase over 2023. (enisa.europa.eu) Verizon's 2026 DBIR also demonstrates that DDoS remains a persistent challenge with 5,514 incidents represented in its dataset. (Verizon)
For voice providers specifically the trust layer is becoming equally important.
STIR/SHAKEN uses certificates and cryptographic signatures to establish verifiable caller identity. (TransNexus) Peeringhub builds around this identity layer with STIR/SHAKEN CA services, certificate inspection, Identity Header validation, STI-CR hosting, OCN lookup and automated certificate lifecycle management. (peeringhub.io)
Its ACME infrastructure supports automated certificate workflows while its developer tooling allows providers to integrate certificate operations into their existing systems. (doc.peeringhub.io)
The bigger lesson is simple:
A firewall protects the boundary. Trust infrastructure protects the identity. Monitoring protects the operation. A resilient telecom security strategy needs all three.
Carriers that treat security as a layered architecture will be better positioned to protect modern communications infrastructure without creating blind spots between network security and identity security.
Build security beyond the perimeter
Explore Peeringhub's STIR/SHAKEN trust infrastructure to strengthen certificate management, caller authentication, identity validation and automated trust operations across your telecom environment.

Post a Comment