EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.
How EY can help
-
Seamless, strategic cybersecurity operations can give you the confidence to focus on innovation and growth. EY Cybersecurity Managed Services can help.
Read more -
Find out how EY Technology Managed Services can help organizations improve operational efficiency, fuel innovation and build the confidence to transform.
Read more
AI-enabled cyber attacks are increasing the urgency for telecom organizations to rethink how they detect, investigate and respond to threats. Attackers are using automation and AI to accelerate reconnaissance, identify vulnerabilities and execute attacks in minutes or seconds. As the time between discovery and exploitation shrinks, security teams have less room for manual investigation, fragmented decision-making or delayed response.
For telecoms, the challenge is especially acute. Large distributed environments, legacy systems, high volumes of customer and operational data, third-party ecosystems, ongoing M&A activity and nation-state threat exposure all increase operational risk. These factors make telecom environments difficult to secure at speed and scale. They also create significant operational complexity. A single security incident may span enterprise IT, telecom networks, operational technology (OT), cloud platforms, customer-facing systems and third-party networks, requiring security teams to correlate vast amounts of data and make decisions under significant time pressure.
The result is a widening gap between the pace of AI-enabled threats and the capacity of traditional security operations centers (SOCs) to respond. Closing that gap requires more than new cybersecurity tools. It requires a clearer view of where the current SOC model is under strain, where automation can reduce risk and where human judgment remains essential.
Here are the steps leaders can take to assess their current model and move their SOC into the future.
1. Identify the foundational challenges
Before changing the SOC model or investing in additional cybersecurity software, telecom leaders should assess the operational problem they are trying to solve. The most important questions are not only technical. They are also questions of scale, governance, consistency and accountability, such as:
- How can security operations scale without a proportional increase in cost?
- How do we maintain consistent standards across multiple networks, entities and environments?
- How do we respond to the shrinking window between vulnerability discovery and active exploit – now measured in hours or days instead of weeks or months?
- How do we protect both customer-facing and backend environments from AI-enabled attacks?
- How do we prioritize the highest-risk alerts while reducing analyst fatigue?
- Where can we leverage AI, and where is human judgment still essential?
The answers to these questions should give leaders a sharper view of where current security operations are most exposed and where change can create the greatest value. From there, they can prioritize the areas where AI-enabled automation can reduce manual effort, improve consistency and accelerate responses while also defining the points where human oversight is required to manage risk and accountability.