Why a telecom operator needs SOC
A telecom operator is critical national infrastructure. Attacks on operators threaten millions of subscribers, emergency services (112/911), and business communication. NIS2 requires continuous monitoring and incident reporting. But even without regulation — an operator without SOC cannot detect advanced attacks (APT, supply chain) or ensure service continuity. NOC (Network Operations Center) monitors availability but not cybersecurity — a dedicated SOC is needed.
Telecom SOC specifics
Massive monitoring scale
Millions of subscriber endpoints, thousands of network elements (routers, switches, base stations), dozens of BSS/OSS systems. Log volume: terabytes daily.
SOC-NOC integration
SOC and NOC must collaborate: SOC detects threats, NOC executes actions on infrastructure. Shared escalation and communication procedures.
Telecom protocol monitoring
SS7, Diameter, GTP, SIP, BGP — telecom-specific protocols requiring specialized tools and analyst expertise.
Subscriber data protection
Monitoring access to subscriber databases (HLR/HSS), detecting unauthorized location queries, SIM swapping detection.
Multi-level compliance
NIS2, national telecom law, GDPR, telecom regulator requirements — SOC must report to multiple regulators.
Internal vs external vs hybrid SOC
Internal SOC — control over critical infrastructure, deep network knowledge. Requires team of 15-30 analysts (24/7), own SIEM. Cost: $1.2-3.5M/year. For large operators.
SOC as a Service — faster deployment, lower entry threshold. Limitations: less knowledge of operator infrastructure, latency in escalation. For MVNOs and smaller ISPs.
Hybrid model — internal L1/L2 SOC monitoring network infrastructure, external L3 and threat hunting. Best option for mid-size operators and telco group companies.
Telecom SOC implementation plan
Phase 1 (month 1-3): Discovery and planning
- Log source inventory (core, RAN, transport, BSS/OSS, IT)
- Use case definition: DDoS, BGP anomalies, SIM swap, insider threat, APT
- SIEM architecture considering telco log volumes
- SOC-NOC integration planning
Phase 2 (month 4-8): Technical deployment
- Deploy SIEM (Splunk, Elastic, QRadar) with distributed architecture
- Log collectors on network elements
- Integration with telco systems: SS7 monitoring, BGP monitoring, DDoS detection
- Network Traffic Analysis (NTA) tools
Phase 3 (month 9-12): Operationalization
- Rule tuning, traffic baseline development
- IR playbooks for telco scenarios
- NOC process integration (escalation, remediation)
- Analyst training on telco protocols
Phase 4 (ongoing): Maturation
- Threat hunting on telco infrastructure
- SOAR automation
- Purple team exercises with telco-specific scenarios
Cybersecurity for Your Industry
Learn more about cybersecurity in your industry:
Best practices for implementation
Effective implementation requires several key steps:
- Risk assessment and inventory — identify assets, threats, and vulnerabilities specific to your organization.
- Policy development — document requirements, roles, and responsibilities.
- Technical controls — deploy tools and configurations proportionate to identified risks.
- Training and awareness — engage employees in protecting organizational security.
- Monitoring and continuous improvement — regularly verify effectiveness and adapt to the evolving threat landscape.
SOC and NOC answer different questions
Operators already run a network operations centre with twenty-four hour cover, and the temptation to extend it with security duties is strong because the roster already exists. The two functions optimise for opposite things. A NOC restores service as quickly as possible; a security team may need the affected element preserved rather than rebooted, because rebooting destroys the evidence of how it was compromised.
The workable arrangement is not one team but one escalation path with a rule written in advance: which events convert a NOC incident into a security incident, and who has the authority to stop a restoration in order to preserve state. Without that rule the first serious intrusion is cleaned up before anyone can determine its scope. Establishing it alongside the detection scope is part of setting up a security operations centre in an operator’s environment.
Related topics
See also:
