Is the telecom industry overlooking supply chain cybersecurity threats?

The telecom industry could be overlooking critical cybersecurity threats in supply chains. The information comes to light as telecommunication cyberattacks surge. However, Squire Technologies has committed itself to continually working to improve defences to secure networks.
The dependencies inherent in critical telecommunication infrastructure exponentially increase the number of people at risk in a supply chain cyberattack. Squire Technologies recognises the vital role it plays in strengthening networks against attacks and protecting customers, subscribers and wider society. Thus, they have committed to continually improving systems and processes as information suggests supply chains are vulnerable to attacks.

There is growing evidence that cybercriminals see software supply chains as vulnerable points of attack with big payoffs. However, there are reports that Chief Information Security Officers (CISOs) might not be paying enough attention to supply chain risks.
Three of the USA’s top national security organisations recently warned of the increasing risk to communication infrastructure from cyberattacks. Improving supply chain security was one of the five recommendations they made to help safeguard networks.
How bad are supply chain cybersecurity threats?
The World Economic Forum is warning businesses about supply chain threats. Their concern centres on a proliferation of malicious packages in open-source software repositories and reliance on third-party suppliers.
The WEF’s Global Cybersecurity Outlook (GCO) 2025 report suggests supply chain vulnerabilities are the top ecosystem cyber risk. The report shows that 54% of large organisations consider supply chains as their main obstacle to cyber resilience.

Additionally, the publication, Insurance Business, recently reported that supply chain cyberattacks increased by 481% between 2023 and 2024. Furthermore, the GCO 2025 report warns that 66% of organisations see AI as the biggest cybersecurity threat. Yet, businesses are introducing AI tools without vetting the threat.
Reported cyberattacks on US telecom companies, M&S, SolarWinds, Okta and others, highlight the growing threat to software supply chains. However, businesses don’t seem to be paying supply chain cybersecurity threats enough attention.
BAE Systems 2022, ‘Mitigating cyber risk in telecoms’ report shows that 54% of telcos don’t have a full cybersecurity strategy. BAE Systems also identifies supply chain risks as a top threat for telcos due to a high likelihood of attack. Unfortunately, Ivanti’s 2025 State of Cybersecurity Report, shows 48% of organisations, across all sectors, haven’t identified the most vulnerable and potentially devastating systems and components in their software supply chains. Why?
Supply chain cybersecurity decision-making in focus
CISOs are the most influential stakeholders in determining cybersecurity priorities. However, despite software supply chain cyberattacks surging, supplier risks are low on the list of priorities. The 2024 National CIO Review shows, that the top four priorities over the next two years for IT security departments’ are internally facing. So, what is making them less concerned about addressing supplier risk?

Ivanti shows that 74% of businesses feel that vendors should either be entirely or partly responsible for software security; are feelings potentially driven by:
- Budget and resource restrictions
- Skills gaps (In the case of smaller business)
- A belief that smaller businesses aren’t a target for cybercriminals.
An additional driver could be the favouring of established relationships. Moody’s 2023 cyber survey shows businesses are 17% less likely to conduct a cybersecurity review of an existing vendor than a new vendor; paving the way for attacks like the SolarWinds attack.
Supply chain management needs suppliers and customers to collaborate. However, critical telecommunication infrastructure is too important for leaders to simply have faith.
Budgeting consequences of cybersecurity threats
TMForum’s 2023 Cybersecurity strategies survey suggests that CISOs have the most influence over cybersecurity requirements. However, Splunk, part of Cisco, reports that one in five Chief Information Security Officers have felt pressured not to report compliance issues.

Additionally, Splunk reports that a massive 71% of CISOs don’t think they have the budget to complete cybersecurity plans and security goals. So, potentially, only three in ten suppliers have adequate security protections in the view of their CISOs. In some cases, this budget restriction leads CISOs to make cuts to projects, weakening security protections.
As in many organisations, the issues at the top filter down. Failing to properly plan for security risks at the board level can have repercussions further down.
Supply chain security needs never-ending improvement
Hackers continually change their tactics. So, guidance on protecting supply chains is always evolving. The UK Department for Science, Innovation and Technology‘s 2025 report, “Open Source Software Best Practices and Supply Chain Risk Management”, highlights the mountain of guidance business leaders can consult when executing supply chain management.
A lot of guidance focuses on open-source software risk management, but the UK’s National Cyber Security Centre (NCSC) probably has the best single point. Businesses should “Encourage the continuous improvement of security within your supply chain.”
In addition to an array of network security products, like the 5G Security Edge Protection Proxy (SEPP), Diameter Edge Agent (DEA) and network monitoring tools like MavenShield Fraud Prevention Gateway, Squire Technologies continually seeks to improve defences to protect networks.
Part of its process is to properly vet its suppliers and ensure it is in line with or outperforming regulations.

Earlier in 2025, the company was independently assessed by KSV1870 and awarded an A Rating. The rating indicates that Squire Technologies offers an Advanced Cyber Protection Level for businesses with heightened security requirements. This is in accordance with the European Union’s new NIS 2 framework for cybersecurity that focuses heavily on supply chain security.
Additionally, last year the business introduced multi-factor authentication (MFA) into its graphical user interface. The MFA provides more protection for customers, and Squire Technologies also uses it internally.
Some of Squire Technologies’ cyber security processes include:
- Secure signalling protocols like TLS
- Real-time alerts for signalling anomalies
- Redundant planes for resiliency (including geo-redundancy)
Today, open-source software is included in almost all software. Squire Technologies uses GPG signatures (RFC 4880) for authentication to verify that software packages are unmolested.
Similarly, Squire Technologies engineers use hashes to ensure software files are as intended when making deployments and upgrades.
Squire Technologies is proud of its ISO 9001 certification. The independent evaluation is an internationally recognised confirmation of the standards and quality of procedures and systems that customers can have confidence in.


“Security is of the utmost importance for us at Squire Technologies. We like to build a rapport with customers to ensure we are working together, continually strengthening our defences.
“Our multi-factor authentication and secure processes go beyond what is required. However, I’m always interested to hear from customers about ways they think we can do more because critical telecommunication infrastructure is so important for everyone.”
Bradley Knight, Chief Operating Officer at Squire Technologies
Contact one of our team to learn more about Squire Technologies’ security products and systems.

5G Core Products
Experience the full functionality of 5G core network technology!
Our 5g products can help you achieve 5G monetisation, extend the life of existing infrastructure, optimise 5G SA and 5G NSA coverage for your subscribers, extend network functionality, streamline 5G routing and manage high-volume traffic, harmonise 5G network functions and increase 5G standalone core network security.
