(P) How to achieve cybersecurity for 5G networks: a multi-stakeholder approach fostered by Huawei
5G is a hot topic nowadays, as it plays a role the digital transformation of multiple industries and economies. Even hotter is the debate on the cybersecurity of 5G networks, which can be achieved if all stakeholders in the process,…

5G is a hot topic nowadays, as it plays a role the digital transformation of multiple industries and economies. Even hotter is the debate on the cybersecurity of 5G networks, which can be achieved if all stakeholders in the process, including network operators, infrastructure vendors and governmental agencies, collaborate on different layers to secure these mobile communication networks.
The cybersecurity debate around 5G goes from uniform standards to independent verifications, effective risk management, to trust, assurance and joint responsibility, or security requirements and assessment framework.
Huawei Technologies USA debated these topics at its 17th annual Huawei Analyst Summit earlier this year. A webinar focusing on “Cybersecurity Standards and Testing in Europe” brought together panelists from Huawei and from international institutions which focus on cybersecurity: Andy Purdy, Huawei Technologies USA Chief Security Officer; Bob Xie, Cyber Security Officer of Huawei Western European Region and Director of Cybersecurity Transparency Centre Brussels; Professor Chris Mitchell from Royal Holloway, University of London; and Jon France, Head of Industry Security at GSMA. They shared their insights on uniform standards and independent verification, and why these are all necessary for effective risk management.
Comprehensive, credible, internal and external testing of all network elements is a critical component of effective, trustworthy cybersecurity. Independent external testing is also essential to certify compliance with industry standards by equipment vendors, network operators, and service providers.
Huawei takes a multi-layered, “many hands, many eyes” approach to trusting and verifying cybersecurity. “We believe that trust should be based on facts,” said Bob Xie, Huawei’s cybersecurity officer for the Western European Region and lead for its Brussels-based Transparency Centre. “And facts should be verifiable. And the verification should be based on the common standard,” he said. Huawei has verification steps, both internal and independent, built into its product development process.
The Transparency Center in Brussels, led by Xie, helps customers, government officials and others to learn about Huawei’s cybersecurity strategy and practices as they relate to supply chain, R&D and products. It is also open to all for testing and validation of Huawei products.
Cybersecurity frameworks that must reference recognized standards, are also of utter importance, said Xie’s colleague Andy Purdy, chief security officer for Huawei Technologies USA. Recognized standards are those developed by 3GPP and GSMA for 5G and NESAS-SCAS for telecom equipment, while frameworks must also include independent conformance and testing protocols, Purdy said.
Markets need to offer incentives to encourage all telecom equipment suppliers to provide greater assurance and transparency, and these would complement government regulations. Purdy suggested that IT&C buyers should use risk-informed procurement requirements for assurance and transparency. Telecom equipment buyers, in collaboration with other stakeholders, should call on vendors to compete not just on functionality and price, but also for cybersecurity practices and transparency. This would motivate suppliers to compete to drive greater security assurance and transparency to achieve market leadership.


