Sending an email, holding a video meeting, or saving files to the cloud are actions we take for granted in our businesses. But behind this apparent simplicity lies a complex network that sustains telecommunications: networks, devices, providers, data…
And in that sea of constant information, cybersecurity has become an absolutely essential element for business continuity.
We’re no longer just talking about protecting computers or servers, but the telecommunications infrastructure that shapes our lives. From data centers to employees’ smartphones, cybersecurity in telecommunications is a key component of ensuring digital, economic, and social stability.
In an environment such as telecommunications, where the exhibition area is vast and dynamic, a solution such as Kartos is advisable and essential to ensure business continuity and protect reputation and user trust.
Unlike other more reactive approaches, our Kartos solution uses a continuous Threat Exposure Management (CTEM) model.. This means it helps organizations maintain a constant and up-to-date view of all their exposed assets, detect vulnerabilities, and anticipate possible attacks.
Why is cybersecurity so critical in telecommunications?
Telecommunications are the nervous system of our digital society. and cybersecurity in telecommunications is a structural priority for all sectors.
According to the Kaspersky Security Bulletin 2025 report, 20.7% of users in the telecom sector suffered device threats during the past year, and almost 10% of organizations experienced ransomware incidents. According to Check Point data gathered from analyses of the Spanish market, telecommunications ranks among the three most attacked sectors in the country.
A highly exposed sector
Telecommunications is one of the world’s sectors that is attacked the most. It’s no coincidence: Operators manage massive volumes of data, critical network infrastructure, and connections with millions of users. Any security breach can have devastating consequences: service interruptions, theft of sensitive data, espionage, or even attacks on national infrastructure.
Threats are constantly evolving
Cybercriminals never rest. New techniques, exploits, and ways to break into systems are developed daily. From ransomware attacks targeting service providers to signal interception or large-scale identity theft, having an antivirus or firewall is no longer enough.
It is necessary to have tools that proactively analyze and identify weaknesses before they are exploited, and maintain constant surveillance of the digital ecosystem. As we propose with Kartos, continuous threat management makes a substantial difference.
The most relevant threats to the telecom sector in 2026
The threats facing telecom operators in 2026 are all the more dangerous because they intersect and amplify each other:
- APT (Advanced Persistent Threats) Groups: actors with state resources seeking stealthy and prolonged access to critical infrastructure for espionage or sabotage.
- Supply chain attacks: The reliance on multiple suppliers and integrated platforms makes each external supplier a potential entry point.
- Targeted ransomware: Specific campaigns against operators with a high impact on service continuity and high blackmail power.
- SIM swapping and SIM-enabled fraud: Telephone line impersonation to access bank accounts, emails, and corporate systems.
- High-intensity DDoS: Denial-of-service attacks that seek to disrupt critical services and extort operators.
- AI-powered attacks: The use of artificial intelligence by attackers to create more credible phishing campaigns, automate vulnerability scanning, and generate corporate deepfakes.
As Leonid Bezvershenko, senior researcher at Kaspersky GReAT, points out, these threats “do not disappear, but rather intersect with operational risks stemming from automation, quantum cryptography, and satellite integration.”
You may be interested in→ 6 online threats that can affect your business.
Towards a more preventive and strategic approach
The traditional security model, based on reacting once an incident occurs, is no longer enough.. In an environment as changing as the digital one, prevention and anticipation are essential.
The regulatory framework in 2026: NIS2 and its impact on telecommunications
Regulatory pressure on cybersecurity in telecommunications has intensified significantly in 2026. The NIS2 Directive (EU Directive 2022/2555) is the main legal framework that obliges telecommunications operators to strengthen their security measures.
Explore this topic further in the following post-> NIS 2: How does it affect businesses and what measures should be taken to comply with the regulations?
What does NIS2 require of telecommunications operators?
Telecommunications are classified as essential entities underNIS2, which implies the strictest requirements of the directive:
- Mandatory notification of serious incidents within a maximum of 24 hours.
- Implementation of verifiable and auditable risk management measures.
- Direct responsibility of the governing bodies, with the possibility of disqualification for managers.
- Penalties of up to 10 million euros or 2% of global annual turnover.
- Extension of security requirements to the entire supply chain of ICT providers.
In Spain, although the transposition of NIS2 is still going through parliamentary procedures with estimates of entry into force throughout 2026, the competent authorities have already initiated supervisory procedures.
To delve deeper into the regulatory requirements that affect organizations in the sector, we recommend you check out our article on GRC in cybersecurity: Governance, risk and regulatory compliance.
CTEM: continuous management against threats
The traditional IT security model involved periodically reviewing systems, searching for flaws, and applying patches. However, in today’s context, this methodology is insufficient. The key is constant vigilance.
Continuous Threat Exposure Management (CTEM) is a more dynamic and adaptive approach. It allows companies to:
- Know what assets are exposed on the Internet (servers, domains, applications, etc.).
- Detect misconfigurations or vulnerabilities before they are exploited.
- Prioritize what to fix first based on the actual level of risk.
Our tool, Kartos, is explicitly designed to implement this model. Its noninvasive approach allows monitoring without the need to install agents and offers a clear view of any organization’s external security posture.
Artificial intelligence as a defensive ally
By 2026, AI has become a central element in both attacks and defense. The WEF Global Cybersecurity Outlook 2026 states that 94% of cybersecurity industry leaders identify AI as the main driver of change for this year.
In telecommunications, offensive AI has a particularly significant impact, enabling the automation of network endpoint scanning, the generation of customized phishing campaigns at scale, and the cloning of executive identities for B2B fraud. The defensive response requires applying that same processing capacity to detect traffic anomalies, correlate signals distributed across complex infrastructures, and reduce incident response time.
What your company can do now
If you work in a company that relies on digital infrastructure (which is practically all of them), there are some steps you can start considering today:
1. Perform an exposure diagnosis
The first step is knowing which assets of your organization are visible from outside the perimeter and what condition they are in. Do you have domains similar to yours registered by third parties? Are employee credentials circulating on specialized forums? Do any of your providers have expired certificates with active access to your network?
Kartos lets you get this picture of the external exposure without affecting your internal systems, in a matter of hours. You can find more information about how to detect CVE vulnerabilities on your digital surface without touching your internal network.
2. Implement a CTEM strategy
Monitoring must be continuous and automated. Threats don’t wait for you to schedule an audit. The CTEM model ensures that any change to your attack surface—a new lookalike domain, a compromised credential, a misconfiguration—is detected and prioritized in real time.
Also discover how the perimeter cybersecurity approach complements your existing infrastructure to strengthen access.
3. Protect key people
The executives and security officers of the operators are deliberate targets. Their digital identity, credentials, and online reputation are attack vectors that remain outside the corporate perimeter.
Qondar, our personal digital protection platform, extends the logic of CTEM to the individual digital assets of key people in your organization.
4. Teach your team
No tool can replace the human factor. Make sure your team understands the risks and knows how to respond.
Cybersecurity in telecommunications as a guarantee of continuity
In a world where everything is digital, ensuring cybersecurity in telecommunications is not an add-on or a discretionary expense; it is the core of any business continuity strategy. Exposure to threats is constant, regulatory penalties are increasing, and the consequences of an incident can be irreversible for an organization’s reputation and operations.
The question is no longer whether your organization will be targeted. The question is whether you will have enough visibility to detect it before it causes harm.
Kartos helps companies in the telecommunications sector regain control of their external digital security. No installations, no intrusion, no human operation to introduce delays. Just your domain, and a complete, continuous view of everything an attacker could see and exploit.
Do you want to know what’s exposed in your organization right now?
Request a Kartos demo and get a clear, actionable view of your external security posture→ Contact Enthec


