Imagine this: You’re the CISO of a successful medium-sized company located within a critical industry like telecommunications, helping maintain and roll out critical network nodes across a country. Your role extends beyond technical controls and includes being responsible for safeguarding national-scale infrastructure while also ensuring its compliance with relevant regulations. 

Being one side of a public private partnership (PPP) means that you, as a CISO, are caught between a rock and a hard place: How can you ensure long-term resilience while keeping procurement costs in mind? Good security isn’t cheap—particularly in an industry with such scattered infrastructure. So, something has to give. If it is security, well, then you’re off to a bad start, since nation-state actors are already likely to be inside your network.

Key points of this article:

  • Negotiations for robust security expenditures often fail due to budgetary constraints. In an ideal world, resilience is not a budgetary, but a strategic concern.
  • Especially in telecommunications, scattered infrastructure with centralized control combining IT + OT + human oversight makes for a Swiss-cheese-like attack surface.
  • This is especially troubling for companies in critical sectors, where evasive, often nation-aligned attackers seek yearslong persistence, siphoning off data, or waiting for the right opportunity to strike.
  • Quiet incidents, however, are just as problematic as “loud” ones. The right strategy to root out adversaries requires concerted action inspired by standard practices with some pragmatic thinking applied along the way.

Working realities

PPPs represent a nexus of affairs between risk tolerance, financial reality, and political pressure. Project managers work with limited resources, and even more stringent government requirements (not to mention regulations), to bring their tasks to completion. 

In critical sectors like telecommunications, these limits become even more concrete. For example, a CISO might know that a certain vendor’s offer (of a router’s design, let’s say) is far more robust than the lower‑cost alternative, but the procurement committee pushed by the public partner may insist on the latter because the project’s budget is already stretched thin. Or perhaps the public partner must do someone a favor.

Therefore, something must give. Either the public partner yields on the budget, or the private partner goes along with the proposed alternative. In any case, what must “give” can’t be security. 

In an age where digital sovereignty and vendor blacklists are a part of strategic discourse, and where bad actors loom large on the horizon, critical infrastructure’s decision matrix must include resilience as a prime criterion. This goes for both sides of a PPP, and even more so when we consider the implications of flawed infrastructure’s impact on end users—you wouldn’t want someone to listen in on your state’s military comms, would you? Surely not a good look for either side of the contract.

The trouble is someone will listen in. Perfect prevention is an illusion hinging on vendor marketing that sees detection as a hindrance, rather than as a boon. A company that is aware of an incident is much further along toward remediation than one waiting for the trap to shut. So, if your prevention hinges on low capex and even lower operating costs, then what you need to build is a system of prioritized resilience, where pragmatism meets strategic foresight.

Threat actors digging in

Let’s work with the contemporary reality. Threat actors are virtually everywhere. Just a simple online search can return a list of results with one or two malicious URLs, all seemingly legitimate.

If your billion-dollar search provider can’t filter out all those bad apples, then how can you be sure that your telco doesn’t already have a few worms eating their way in? 

Sure, the OT stuff along with all the ground systems are probably safe … if they’re not connected. But we both know that’s not true. Specifically in telecommunications, it’s all about making those connections for others. But beyond this simple mission statement, those on ground systems must be linked to operation centers to ensure their continuous operation, and in cases that they don’t, redundancy must be in play as well. Again, all directed from a central point of organization via various IT endpoints. 

All right, the CISO might think—we’ll deal with that via network segmentation, maybe airgap those individual network points. That could work. But it’s not an infallible solution effective in and of itself, and since proprietary security costs more, the public contract issuer might not be willing to pay for it unless your company is willing to fork over the cost difference.

For our imagined CISO, this is chaos personified. For a threat actor, it’s free real estate

Infrastructural threat actor madness

Scattered networks have the tendency to be informationally exposed. Operation centers also tend to be run by humans. When you put two and two together, you get a group like Lazarus infiltrating a VoIP software developer providing phone services to hundreds of thousands of customers, then spreads malicious codes to the service’s clients located in critical industries like aerospace, healthcare, and hospitality.

Other advanced threat groups like OilRig and BladedFeline have similarly targeted telecommunications companies.

Having access to a “connected” industry eliminates the need for individual access. In telecommunications, the risk is even greater because data is constantly in transit, making it more vulnerable to an adversary-in-the-middle attack.

To network or not

It’s not just telcos that are the epitome of “connections.” From the top, MSPs and IT service providers are targets due to how deeply they’re embedded in client systems, while education infrastructure providers are sought out by bad actors for a similar reason. Exposure, therefore, is not limited by company premises at all.

Underreported, undisclosed, and unaware

There are lots of stories reporting on breaches, but what about those that haven’t yet been made public?

Sometimes disclosure is the worst thing a company can do, especially when incident response is still ongoing—you don’t want to invite more trouble. It is true that reporting is required by authorities, like the SEC in the US, (filings are a veritable source of breach stories for security writers, after all) but there are exceptions:

  1. Not every company is required to be registered under the SEC.
  2. Bodies like the Information Commissioner’s Office in the UK, or various national authorities in the EU (local CSIRT/DPA), require covered entities to report incidents within roughly 24 to 72 hours, but the conditions differ, and not every business entity is required to do so.

A great example of this dichotomy is the difference between reporting rules for the EU’s GDPR and NIS2.

There’s also something to be said about quiet breaches. Initial access brokers often infiltrate company systems under a SOC’s nose, later selling said access to another threat actor. Alternatively, you might have an advanced APT do the same, waiting for the right time to strike.

The last is perhaps the most interesting exception of all. Around 33% of all breaches go unnoticed—until a business receives a ransom note, at least. Reasons include skills-related issues, low cyber hygiene, and complexity challenges. This view is supported by ESET’s SMB Cyber Readiness Index 2026 findings, where the top three challenges identified are phishing, unpatched vulnerabilities, and a lack of security monitoring—all of which align to the issues described above.

The same visibility problem does not stop at the company perimeter. In Forrester’s Security Survey 2026, security decision-makers who had experienced an external attack, 22% had come from an attack or incident involving their external ecosystem1,  with consequences regarding downstream supply chain attacks (22%2), resulting in increased focus on third-party relationship management for at least 18%3,4

This response shouldn’t be shocking—third parties are where risk becomes difficult to manage. Even when a company has reasonable controls in place internally, attackers may find their way in through a supplier, a software dependency, or another trusted external partner. In a connected business environment, trust alone is not enough.

Examples of quiet incidents

Now, let’s go back to our telco example from the introduction. This is where things go from bad to worse. It’s not uncommon for a telecommunications (or other) company to face a so-called “quiet incident,” in which malware deployment can go undetected for months, or even years.

For example, in 2025, it was discovered that South Korea’s SK Telecom had been the victim of a breach stemming from a quiet malware attack circa 2021–2022, which allowed attackers to infiltrate its systems, move laterally, and exfiltrate sensitive data. MSIT’s findings showed that the company had virtually no password or other safety measures in place to protect its servers, while the OSs in use were outdated as well. The result? The leakage of the data of nearly 27 million users, and a 134.8 billion won ($96.9 million) fine.

This shouldn’t be surprising, as according to Nokia, telecommunications companies have become heavily targeted by stealthy campaigns, with 63% of operators having faced at least one living-off-the-land attack in 2024. According to one testimony mentioned in Nokia’s report, actors like Salt Typhoon are likely to place entry points for an attack to take place years down the line. This echoes the SK Telecom case and raises a troubling point regarding the frequency of such attacks.

Not just telcos

Quiet incidents are common across critical infrastructure. Recently, the UK’s Information Commissioner’s Office reported on a utilities company breach (originally disclosed in 2022), where the attack had begun two years prior to the discovery—exposing the data of 663,887 customers and employees as a result.

Which resilience practices to apply? A pragmatic approach

Let’s get to the point. How can a telco-based CISO make sure that their hardware/software in use is secure? Maybe a better question is … how can they anticipate such an eventuality? Because it’s not a yes or no situation. A practical starting point is to assume that compromise is possible, or that parts of the environment may already be compromised, and prepare accordingly. For a telco, resilience cannot depend on perfect prevention. If Nokia’s report is to be believed, then more than half of all operators can be in danger at any time.

It doesn’t take much to compromise a business these days. The more complex its environment, the more cautious it should be about the integrity of its infrastructure. It’s one thing to protect a few computers via a central console, but it’s another thing to protect a vast array of antennas, satellites, offices, stations, etc.

With this context in mind, the safest move is to turn to government-mandated regulations, even those of foreign governments. Why? It’s simple—security mandates exist to raise the bar for collective resilience overall, already including a lot of useful advice. In our case, the CISO should read the EU’s Directive 2009/140/EC5,  specifically Article 13a on security and integrity of networks, along with ENISA’s minimum security measures guidance6,  the latter of which lasers in on concrete measures across seven domains:

1. Governance and risk management: Covering measures related to security policies; addressing risk, roles and responsibilities; and third-party risk management.

Here, focus less on documenting risk and more on behavioral change. The key issue is ownership—who actually owns the risk, who is accountable for reducing it, and who has the authority to make decisions when something goes wrong. ESET PRIVATE Advisors see this especially in SMBs or less mature organizations, where cybersecurity responsibilities are often spread informally across IT, management, and external providers, but the same gap can exist in large enterprises as well. 

Without a clear ownership structure, governance remains theoretical—policies may exist, but no one is truly responsible for making them work. And it’s all good when policies are written down, but practice is what makes the master. Governance should be tied to budget/operational concerns directly to raise the stakes for accountability. It’d be difficult to force change otherwise.

2. Human resource security: Protecting human personnel, including users, via background checks, security training, and violations handling.

Human risk isn’t necessarily a knowledge/skill issue. It’s more about how identity is defined, protected, and monitored over an employee/user’s lifecycle. For telcos, this matters because employees, contractors, suppliers, and privileged technical users may all have access to sensitive systems at different points in time. Access should, therefore, follow the person’s actual role, change when that role changes, and disappear when the relationship ends. It’s one reason why deleting unused company accounts is a simple but powerful practice.

3. Security of systems and facilities: Managing on-site resilience, including access controls, supplier considerations, and physical protection.

Company premises have expanded to employees’ homes, hotels, conference booths, and more. The “facility” now includes cloud, SaaS platforms, and supplier infrastructure. Security in this context is more about control over execution (production) environments, wherever they reside. 

4. Operations management: All about continuous asset management.

Asset tracking is only beneficial when criticality and exposure are commensurate with it. A flat list of systems does not tell you where the risk really is. A telco needs to know which assets support critical services, which are internet-facing, which depend on third parties, which are running vulnerable software, and which would cause real disruption if compromised. It’s a lot like threat detection: You might have all those incidents clearly visible in your dashboard, but are they correlated based on their severity, business impact, and exposure? If not, you don’t exactly know where the risk really is and where to act first.

5. Incident management: Detection, response, incident communication and reporting.

Incidents expose gaps quicker than an audit. That is why incident management cannot be treated as a document set, but as a practiced capability. Crisis simulations, tabletop exercises, red-team scenarios, and regular playbook walkthroughs help reveal where decision-making, escalation, communication, and technical response break down before a real incident occurs. Playbooks often assume ideal conditions that rarely exist—with clear communication, fast action, and concentrated response. It’s likely that response will stall (due to comms gaps, for example), or that incidents will go undiscovered. As such, design for imperfect execution under duress, something that an exercise like NATO Locked Shields prepares participants for brilliantly.

6. Business continuity management: Perhaps the most important domain, continuity ensures that in a crisis, the company can recover as quickly as possible without long-term disruption. Before recovery can be planned, the organization first needs to understand what is truly critical—not in a generic asset-inventory sense, but in terms of which services, systems, suppliers, data flows, people, and operational processes the business cannot function without.

Everyone has a plan, but execution can be iffy. Recovery assumptions often don’t match actual dependencies, with some critical systems remaining unrecoverable. A few questions can set the tone for this domain, including what truly needs to be recovered first, which non-critical systems might become critical during disruption, and just how long can a business really operate in a degraded mode.

7. Monitoring, auditing, and testing: In other words, applying lessons learned from incidents, periodic testing and assessments, and compliance monitoring.

Focus on feedback loops instead of activities. The signal-to-noise ratio can throw off even the best security analyst, while audits and testing are periodic, not continuous. The question is, how effective is your approach in applying change? If a finding turns up year after year, then maybe your change management is not good enough.

So, what can CISOs expect following the long-term implementation of these measures?  For one, much improved resilience, courtesy of better visibility, asset management, and substantiated incident expectations. Incident management is especially important since it is what ensures operational continuity when all else fails.

How quiet incidents turn real

A lot can turn up when a modicum of security skill is applied in practice. In one related ESET MDR story, following enrollment in the service (working on a standardized level of operation), the team uncovered a hidden, monthslong adversary operation running within business systems—all despite some preexisting security controls in place. This quickly became a “loud” incident, as the adversary (FIN7) responded to MDR actions with increased vigor following every response action.

Ultimately, what won the battle was fast, decisive thinking on the part of ESET’s MDR team, with new playbooks and strategies being developed in tandem to prevent future recurrence. 

Conviction lowers the stakes

A confident CISO can sell anything. But the strongest argument is not that the solution has a price; it is that the problem already has one. Downtime, regulatory exposure, customer churn, incident response costs, emergency procurement, reputational damage, and loss of trust all carry a cost, whether the organization budgets for resilience or not. 

Conviction, then, is the premeditated, thoroughly researched argument that moves the needle. A public partner has likely heard multiple confident sellers in their time, but when a private actor can show what inaction could realistically cost, the case for investing in resilience becomes much harder to dismiss. 

In other words, in an effort to curtail spending, that low-cost router might make sense, but in the face of a potential statewide telecoms network disruption, cyberespionage, or a breach leading to a lawsuit—the cost difference goes in favor of the more expensive, but secure, option. And that is the real point: This is not just a question of choosing the right technology stack. 

“Cybersecurity is not an IT problem to be delegated downward and forgotten. It is a business resilience issue, a question of operational continuity, public trust, regulatory exposure, and, in the case of telecoms, national infrastructure,” commented Enrik Biath, Senior Cybersecurity Consultant at ESET. “The technical choice matters, but the larger decision is about how much risk the organization is willing to carry, who owns that risk, and whether the business can survive the consequences if that choice fails.”

Partnerships matter. ESET PRIVATE Advisory helps organizations treat cybersecurity not as an isolated IT function, but as a business continuity priority. Backed by 30+ years of experience and global threat research, our advisory work supports and strengthens compliance, awareness, and crisis readiness—helping teams anticipate, withstand, and adapt to threats while protecting continuity and core operations.

ESET PRIVATE Blog Banner 2

FAQ: Extracting embedded adversaries

What is a quiet cyber incident?

A quiet cyber incident is a compromise that remains hidden for an extended period, often because attackers avoid noisy tactics and blend into normal network activity. These incidents can involve credential misuse, lateral movement, data exfiltration, or long-term persistence, making them especially dangerous for critical infrastructure operators that depend on continuous availability and trust.

Why are telecommunications companies attractive targets for cyberattacks?

Telecommunications companies are attractive targets because they connect people, businesses, government services, and critical systems at scale. A successful compromise can give attackers access to sensitive data, communications pathways, supplier ecosystems, and infrastructure dependencies, making telcos valuable targets for espionage, disruption, and long-term strategic positioning.

How can CISOs improve cyber resilience in critical infrastructure?

CISOs can improve cyber resilience by treating security as a business continuity concern rather than a narrow IT function. That means identifying critical assets and dependencies, assigning clear risk ownership, monitoring exposed systems, testing incident response plans, managing third-party risk, and preparing the organization to operate under degraded conditions if prevention fails.

Why is prevention alone not enough to protect business networks?

Prevention alone is not enough because modern attackers often bypass controls through stolen credentials, trusted suppliers, unpatched systems, or legitimate administrative tools. Strong prevention still matters, but it must be paired with detection, response, monitoring, and recovery capabilities so organizations can identify intrusions early and contain damage before it spreads.

What should organizations do if they suspect an attacker is already inside their network?

Organizations should avoid panic-driven actions and move quickly toward structured incident response. The first steps are to preserve evidence, validate the scope of compromise, isolate affected systems where appropriate, review privileged access, involve internal and external response teams, and communicate carefully with legal, regulatory, and business stakeholders as the investigation develops.

 

Additional references:
1) Base: 1,777 security decision-makers who have experienced a breach in the past 12 months who can identify the types of breach(es). Source: Forrester’s Security Survey, 2026, © 2026 Forrester Research, Inc. All trademarks are property of their respective owners.
2) Base: 1,953 security decision-makers who have experienced a breach in the past 12 months. Source: Forrester’s Security Survey, 2026, © 2026 Forrester Research, Inc. All trademarks are property of their respective owners.
3) Base: 1,953 security decision-makers who have experienced a breach in the past 12 months. Source: Forrester’s Security Survey, 2026, © 2026 Forrester Research, Inc. All trademarks are property of their respective owners.
4) Forrester’s Security Survey, 2026, © 2026 Forrester Research, Inc. All trademarks are property of their respective owners.
5) European Parliament & Council of the European Union. (2009). Directive 2009/140/EC of the European Parliament and of the Council of 25 November 2009 amending Directives 2002/21/EC on a common regulatory framework for electronic communications networks and services, 2002/19/EC and 2002/20/EC (Article 13a, Security and integrity of networks). Official Journal of the European Union, L 337, 54–55. https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ:L:2009:337:FULL. Accessed: 13.05.2026
6) Dekker, M., Dupré, L., & Liveri, D. (n.d.). Technical guidelines for minimum security measures (pp. 7–14). European Union Agency for Network and Information Security (ENISA). https://www.mca.org.mt/sites/default/files/consultations/technical-guidelines-for-minimum-security-measures.pdf. Accessed: 13.05.2026