DrochaidHorizon3.ai
NodeZero/Industries/Telecommunications
The state of play — Telecommunications, 2026

Ransomware now hits telcos at scale alongside state activity.

Cyble’s 2025 telecommunications threat landscape records 34 ransomware attacks against telcos globally — a fourfold increase in malware-linked incidents since 2021 — running in parallel to nation-state intrusion campaigns already operating inside carrier networks.

600 / 80
organisations in 80 countries targeted by Salt Typhoon since 2019, per the August 2025 joint advisory from 13 countries.
The Hacker News / joint 13-country advisory
444 / 34
recorded cyber incidents in the telecom sector globally in 2025, including 34 ransomware attacks involving groups such as Qilin, Akira, and Play — a fourfold increase in malware-linked incidents since 2021.
Cyble Telecommunications Sector Threat Landscape Report
9.8M
customers exposed in the September 2022 Optus breach — CrowdStrike analysis described the initial access as a "basic web application attack" exploiting an API with insufficient authentication.
CrowdStrike analysis of Optus breach
The trend

Why Telecommunications is in the crosshairs

Five shifts shaping the global and Australian telco threat environment — what Salt Typhoon has exposed, and what regulators are now asking operators to demonstrate.

Salt Typhoon has reframed the sector globally

At least eight US telcos compromised, one to two years of undetected access, and per the Senate Commerce Committee the campaign is still not fully remediated at end of 2025. Senator Cantwell's "seven-year-old unpatched router vulnerabilities" detail captures the systemic failure that made the intrusion possible. Every major telco now has to assume edge infrastructure has been a target of this class of actor.

Lawful-intercept infrastructure is a specific systemic weakness

Salt Typhoon exploited US CALEA wiretapping infrastructure — systems that, by design, provide access to telecommunications metadata and content for lawful intercept. The FCC's ruling that vulnerabilities "are still being exploited" applies with particular force here. Australia's equivalent architecture sits under the Telecommunications (Interception and Access) Act and carries structurally similar risk.

Nation-state adversaries pre-position for disruption, not just espionage

The White House briefing was explicit: "for espionage, but potentially for disruption at a time of crisis or conflict as well." Volt Typhoon's pattern is pre-positioning against US critical infrastructure; Salt Typhoon's is persistent counterintelligence-relevant access. ASIO DG Mike Burgess confirmed in November 2025 that both have attempted access to Australian critical infrastructure, including telecommunications.

Legacy edge infrastructure is the single largest risk category

Cantwell's seven-year-patch-gap and former FCC official Deb Jordan's iPhone analogy capture the operational reality: core and provider-edge firmware often runs unpatched for reasons that range from operational risk aversion to loss of vendor support. Verizon's 2025 DBIR finding that the share of vulnerability-exploitation breaches targeting edge devices and VPNs rose from 3% to 22% lands with double weight in telco.

Ransomware now hits telcos at scale alongside state activity

Cyble's 2025 analysis counts 34 telecom ransomware attacks involving groups including Qilin, Akira, and Play — a fourfold increase on malware-linked incidents since 2021. MVNOs, regional ISPs, and smaller carriers are particularly exposed. Telstra's November 2024 employee-database hacker-forum listing (47,300 staff) and Frontier Communications' April 2024 ransomware breach (750,000+ customer records) illustrate both sides of the exposure.

On the record

What regulators and experts are saying

Senior national security officials said the breach occurred in large part because telecommunications companies failed to implement rudimentary cybersecurity measures. Investigators found legacy equipment not updated in years, router vulnerabilities with patches available for seven years that were never applied, and hackers acquiring credentials through weak passwords.
Senator Maria Cantwell
Ranking Member, US Senate Committee on Commerce, Science and Transportation
Telecom networks are a high-priority target, one that's in the bull's-eye of nation-state programs. We believe this one is for espionage, but potentially for disruption at a time of crisis or conflict as well.
Senior US administration official
White House briefing
December 2024
To date, telecom companies infiltrated in the attack have failed to prove the Chinese hackers have been eradicated from their networks… Experts agree that the attack has not been fully remediated from telecommunications networks, and the FCC's ruling concedes that vulnerabilities are still being exploited.
US Senate Committee on Commerce
Briefing on Salt Typhoon remediation
What is now required

TSRMP Rules are now live

The telecommunications security regime under the SOCI Act commenced 4 April 2025, with CIRMP obligations for existing nominated telco assets in force since 4 October 2025 across an expanded asset scope

Telecommunications carriers and carriage service providers are subject to the SOCI Act CIRMP obligations as critical infrastructure entities. The CIRMP must address four hazard vectors: cyber and information security, personnel, supply chain, and physical security. For the cyber hazard vector, entities must adopt one of five approved frameworks — ASD Essential Eight, NIST CSF, ISO/IEC 27001, C2M2, or AESCSF. The former Telecommunications Sector Security Reforms (TSSR) have been replaced by the TSRMP Rules 2025, which align with the SOCI CIRMP structure. Carriers must also comply with carrier licence conditions and obligations under the Telecommunications Act 1997.

Legislation
SOCI Act — Critical Infrastructure Risk Management Program

Federal legislation covering telecommunications as a critical infrastructure sector. Since April 2025, the TSRMP Rules moved telco obligations from the Telecommunications Act into the SOCI Act. Carriers and CSPs must maintain a CIRMP addressing four hazard vectors: cyber, personnel, supply chain, and physical security. NodeZero directly validates controls under the cyber hazard vector across CPE, OSS/BSS, and cloud infrastructure. For the cyber vector specifically, entities must also adopt one of five approved frameworks which define the detailed technical controls.

Your chosen CIRMP cyber frameworkSelect one
Also in effect

A cascade of new obligations

Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.

TSRMP Rules 2025 (asset scope expansion)

4 Apr 2025

Part 14 of the Telecommunications Act has been repealed. All telco security obligations now sit under the SOCI Act via CIRMP. Asset scope has expanded to include CPE, OSS/BSS, cloud infrastructure, IT support systems, and third-party integrations — adding thousands of assets to compliance scope.

Cyber Security Act 2024 (ransomware reporting)

30 May 2025

Mandatory ransomware payment reporting to ASD within 72 hours for all entities with $3M+ annual turnover. Telecommunications carriers are high-value ransomware targets due to network criticality and service continuity pressure. Dual reporting obligations apply — both TSRMP and Cyber Security Act.

Cyber Incident Review Board

30 May 2025

Independent review board can examine significant cyber incidents affecting critical infrastructure, with statutory power to require information and documents. Telecommunications operators should be able to reconstruct control failures for a potential no-fault post-incident review.

Smart Device Security Standards

4 Mar 2026

Mandatory minimum cyber security standards for internet-connected devices sold or distributed in Australia. Telecommunications operators managing CPE and IoT networks must audit device inventory, replace non-compliant equipment, and validate firmware update mechanisms.

CIRMP maturity uplift

Jun 2026

The Enhanced CIRMP Rules 2026, registered 9 June 2026, lift the minimum cyber-framework maturity to level 2 across nine critical infrastructure asset classes, phasing in over 24 months to June 2028. Telecommunications assets sit under the parallel TSRMP rules — but the regulatory direction on maturity floors is the same. NodeZero provides attack-based evidence that an uplifted posture actually holds.

Government intervention powers

20 Dec 2024

Enhanced Response and Prevention Act 2024 allows the Minister for Home Affairs to issue directions to operators with "seriously deficient" security programs. Directions can mandate specific control implementations with defined compliance windows and penalties for non-compliance.

Platform credentials

The only autonomous pentesting platform that is:

SOCI / TSSR
Control-by-control
Carrier obligations
Essential Eight
Mapped ML1–3
ASD baseline
Gartner Peer Insights
4.7 / 5
Customers' Choice (Oct 2025)
310,332
Pentests run
7,013 orgs
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Validate your compliance posture before regulators do

See how NodeZero tests across the expanded TSRMP asset scope in your environment