Cybersecurity Policy Report, EU 5G Report Warns of Vendors From 'Hostile' Nations, (Oct 9, 2019)
A supplier of 5G network components from a "hostile" nation could be pressured to use its presence in the network to conduct espionage or disrupt critical infrastructure, according to a report issued today by the European Union.
But the report, titled "Coordinated Risk Assessment of the Cybersecurity of 5G Networks," stops short of calling for a ban on the use by European Union member states of equipment made by companies suspected of being controlled by the Chinese government—in particular, Huawei Technologies Co. Ltd.
"Hostile third countries may exercise pressure on 5G suppliers in order to facilitate cyber attacks serving their national interests. The degree of exposure to this risk is strongly influenced by the extent to which the supplier has access to the network, in particular its most sensitive assets," it said.
In identifying threat actors that could endanger the security of 5G networks, the report says threats posed by state-backed actors "are perceived to be of highest relevance. They represent indeed the most serious as well as the most likely threat actors, as they can have the motivation, intent, and most importantly the capability to conduct persistent and sophisticated attacks on the security of 5G networks."
The risk assessment, which distills the findings of assessments provided by EU member states, is one of a series of steps being taken in the EU to orchestrate the deployment of secure and reliable 5G networks. It suggests once again that the EU is unlikely to enact outright bans on particular suppliers but will remain skeptical about Huawei and other companies subject to pressure by adversarial nations.
The report notes that 5G deployment in each member state will be controlled by the governments of those member states but highlights the need for EU-wide coordination. "The interconnected and transnational nature of the digital infrastructures and the cross-border nature of the threats involved mean that any vulnerability in 5G networks or a cyber attack targeting the future networks in one member state would affect the union as a whole. This is why concerted measures taken both at national and European levels must ensure a high level of cybersecurity," it said.
It warns 5G network operators and member states against relying too heavily on a single supplier for 5G components. "Within individual networks, a large degree of reliance on a single supplier (monoculture) creates a dependency on specific solutions and makes it more difficult to procure solutions from other suppliers, especially where solutions are not fully interoperable," the report said.
"As a result, EU-based operators who become overly dependent on a single equipment supplier are exposed to a number of risks caused by that supplier coming under sustained commercial pressure, whether due to commercial failure, being subject to a merger or acquisition, or being placed under sanctions," it said.
"At national and EU levels, a lack of diversity of suppliers increases the overall vulnerability of the 5G infrastructure, in particular if a large number of operators source their sensitive assets from a supplier presenting a high degree of risk," it added.
"Dependency of one or several networks also significantly affects national and EU-wide resilience and creates single points of failure," it said. "Moreover, the presence of a limited number of suppliers on the market can decrease their incentives to develop more secure products. It can also have a negative impact on the leverage available to national authorities and operators to demand higher security guarantees, in particular for smaller member states or operators."
It noted, however, that two of the major suppliers of 5G telecom gear, Ericsson and Nokia, were headquartered in the EU.
Today's report will be followed by the development of a "toolbox" that will guide member states on ways to mitigate risks associated with 5G deployment. That toolbox is expected to be made available by year-end.
In addition, the European Union Agency for Cybersecurity (ENISA) is finalizing "a dedicated threat landscape mapping, which consists of a detailed analysis of certain technical aspects, in particular the identification of network assets and of threats affecting them specifically," the report said.
The expected complexity and ubiquity of 5G services creates "a new security paradigm, making it necessary to reassess the current policy and security framework applicable to the sector and its ecosystem and essential for member states to take the necessary mitigating measures," the report said.
This requires identifying potential gaps in existing frameworks and enforcement mechanisms, ranging from the implementation of cybersecurity legislation, the supervisory role of public authorities, and the respective obligations and liability of operators and suppliers," it added.
MainStory: Cybersecurity