Tue, 21 Jul 2026

The hidden complexities of modern telcos in the AI era

Photo by Qeis Ismail: https://www.pexels.com/photo/metal-communications-tower-against-blue-sky-37888038/

As telecommunication operators modernise their networks and adopt AI-driven services, hidden complexities make cyber resilience more challenging for them than for other industries.

Research found that the telecommunications sector was among the most targeted industries in the first quarter of 2025, recording 2,664 weekly attacks, only trailing behind the education sector (4,484) and the government sector (2,678).

Ananth Nag

Ananth Nag, general manager and vice president, Asia Pacific, Rubrik, believes the industry is among the most complex sectors for cyber resilience because it is central to national connectivity.

"Telcos connect people, digital services and, in many cases, other critical infrastructure sectors. They are also an attractive target for threat actors," he said.

Nag shares the hidden complexities of modern telcos, the implications of AI adoption in the industry and what security leaders can do to address the risks.

Hidden complexities

Compared to other industries, securing telecommunications is more complex due to various factors.

According to Nag, one of the hidden complexities is that telcos operate across two major environments: network and IT infrastructure.

"The network environment keeps connectivity services running, and the IT infrastructure supports daily operations such as customer onboarding and billing. Any disruption across either side can have a direct impact on service continuity, customer trust and regulatory confidence."

Moreover, Nag said telcos have a much larger attack surface, operating vast infrastructure and software systems.

"Many of these environments have grown organically over 15 to 20 years, which means they carry a lot of legacy architecture and data."

Adding to this complexity are the massive volumes of customer and operational data.

"Because they are regulated, some of this data has to be retained for years, or even decades. That means resilience is not just about protecting today's systems; it is also about managing long-term archival requirements," he explained.

"For telcos, cyber resilience is harder because their environment is large, layered, regulated and deeply interconnected," he said.

For telcos, cyber resilience is harder because their environment is large, layered, regulated and deeply interconnected. Ananth Nag

Cyber resilience in an increasingly complex environment

Modern telcos manage a mix of legacy infrastructure, cloud-native applications, edge computing and AI workloads. In an increasingly complex environment, organisations must change how they approach cyber recovery and data resilience.

Related:  Malicious player selling stolen data detected 

Nag said, "Legacy infrastructure, cloud-native applications, edge environments and AI workloads are increasingly interconnected, which means an incident in one part of the environment can affect networks or internal systems very quickly."

He urged organisations to adopt repeatable recovery readiness rather than static recovery planning.

"They need to identify their most critical services, map the data and systems that support them, define clear Recovery Time Objectives (RTOs), and regularly test whether they can recover from a clean state," he said.

Nag added that organisations should regularly test recovery plans to determine whether they can execute an operational recovery plan every quarter, recover within defined timeframes and restore clean recovery points.

Preparing for cyber risks in the AI era

AI adds another layer of complexity.

Introduced into an already complex environment, AI accelerates risk by increasing both the speed and scale of attacks, making vulnerabilities easier to exploit.

"Telcos need the ability to measure the impact of a breach quickly and orchestrate recovery reliably. The goal is to restore trust in the network, the service, and confidence that the organisation can continue operating even when prevention fails," he said.

With AI becoming more deeply embedded in network operations and customer services, telecom leaders should prepare for new cyber risks that evolve much faster than traditional models were designed for.

"AI adds another layer of speed and complexity to an environment that is already challenging to defend and recover," Nag said.

AI adds another layer of speed and complexity to an environment that is already challenging to defend and recover. Ananth Nag

When used maliciously, the technology can quickly identify vulnerabilities, chain them together and move laterally across complex environments at machine speed.

"For telcos, which often operate a mix of platforms, a localised incident can quickly become a broader service disruption," Nag said.

Aside from AI, attackers are increasingly using identities and credentials to gain access and move across telco environments, causing wide disruptions that affect customer onboarding, billing and network operations.

"Telecom leaders therefore need to think about cyber risk not only as a security issue, but as a continuity and trust issue. Telcos are critical to how people, businesses and essential services stay connected," he said.

Related:  PodChats for FutureCISO: Risk quantification strategies in 2023

He added that cyber resilience affects not only technical operations but also customer trust, regulatory confidence and operational continuity.

Preparing for the future

Looking ahead, as operators continue investing in 5G, AI and next-generation network infrastructure, there are changes that telecom CTOs should make today to ensure data resilience.

"As the complexity of modern telco environments grows, data resilience should be a core architectural principle rather than an afterthought," Nag said.

He suggests that CTOs should first prioritise complete visibility into where critical data resides, how it moves across hybrid environments, and who or what has access to it.

"Consistent security policies across cloud and on-premises environments are essential to reduce operational blind spots and ensure critical assets receive the same level of protection regardless of location," he said.

The Rubrik executive also underscored the importance of data resilience.

"Telcos manage short-term operational data that must be recovered quickly, as well as long-term regulated data that may need to be retained for years or decades. Treating both in the same way creates cost and operational pressure. CTOs should therefore modernise how data is protected and recovered based on business criticality," he said.

He finally urged technology leaders to treat recovery readiness as a competitive advantage.

"A recovery plan that sits on paper is very different from one that has been tested consistently under realistic conditions," he emphasised.

Nag suggested that leaders assess whether their teams can "execute recovery consistently, whether they can recover within defined timelines, and whether they can do so when multiple systems are affected at once."

"As telco environments become more AI-driven and software-defined, resilience cannot be measured only by uptime. It has to be measured by the organisation's ability to recover trusted data, restore critical services and continue operating after an incident," he concluded.

A recovery plan that sits on paper is very different from one that has been tested consistently under realistic conditions. Ananth Nag

Unlocking hidden complexities

There is no need to hide: the telecommunications industry is complex, interconnected, and highly vulnerable.

However, operators need not worry. As complexity increases, so do wisdom, technology and organisational resilience.

Related Stories

MORE STORIES