Industry · Telecom · GCC

Penetration testing for telecom — protecting subscribers and critical infrastructure

Telecom operators hold subscriber data at national scale and carry communications a country depends on, which makes them critical national infrastructure and a prime target. We deliver penetration testing across the subscriber, BSS/OSS and IT estate, aligned to NCA ECC and national frameworks.

TelecomBSS / OSSSubscriber DataNCA ECCCNICST / TDRA
Telecom Security: Critical National Infrastructure · NCA ECC 2-11 · CSCC 6-Month · BSS/OSS · Subscriber Data · Sector Regulators · PDPL Telecom Security: Critical National Infrastructure · NCA ECC 2-11 · CSCC 6-Month · BSS/OSS · Subscriber Data · Sector Regulators · PDPL
// TL;DR

Telecom operators are critical national infrastructure: they hold subscriber data at national scale, carry essential communications, and increasingly run digital and payment services. That makes them a top target and a heavily regulated one. In Saudi Arabia they fall under the NCA ECC (penetration testing control 2-11) and, for critical systems, the CSCC with its six-month testing interval, with sector regulators like CST (Saudi), TDRA (UAE) and CITRA (Kuwait) adding telecom-specific requirements and national PDPL laws governing subscriber data. We test the subscriber-facing estate, the BSS/OSS systems that hold subscriber and billing data, the internal IT network, and the infrastructure around the core — focused on protecting subscriber data and preventing a pivot toward critical systems.

// 01 Why telecom needs penetration testing

Few organisations concentrate as much risk as a telecom operator. They hold personal data on essentially the entire population they serve — identities, locations, communications metadata, billing and increasingly payment information. They carry the communications that government, business and emergency services depend on. And they are steadily becoming digital-service and fintech providers in their own right. Any one of those would make an operator a serious target; together they make telecom one of the most attractive targets for both criminal groups and state-level adversaries.

That is why every GCC country treats telecom as critical national infrastructure and mandates regular security testing. For an operator, penetration testing is both a regulatory requirement and a practical necessity: a breach can expose millions of subscribers at once and, in the worst case, disrupt communications a nation relies on.

// 02 The regulatory drivers

Telecom operators answer to two layers of regulation: the national cybersecurity framework that applies to them as critical infrastructure, and telecom-specific sector regulators.

LayerFramework / bodyTesting implication
National (Saudi)NCA ECC + CSCC (critical systems)Control 2-11; CSCC every 6 months for critical systems
Sector (Saudi)Communications, Space & Technology Commission (CST)Telecom-specific security requirements
Sector (UAE)TDRANational telecom / digital-government requirements
Sector (Kuwait)CITRANational framework and cloud residency
Data protectionPDPL (Saudi, Bahrain, UAE)Obligations over subscriber personal data

Because an operator can be subject to several of these at once, we scope a single engagement against the applicable set and map findings to each control reference — the same convergence approach we use across the GCC. Our requirements finder lays the national frameworks side by side.

// 03 What we test for a telecom operator

01

Subscriber-facing estate

Self-care portals, mobile apps and their APIs — authentication, authorisation, and whether a subscriber can only access their own account.

02

BSS / OSS

Business and operational support systems that hold subscriber, billing and provisioning data — a high-value target that concentrates personal data.

03

Internal IT & network

The corporate IT network and Active Directory, and the segmentation between IT and the systems around the core.

04

Infrastructure & management

Management and support systems around network infrastructure, assessed with the care their criticality demands.

// 04 What we commonly find

CriticalAccess control

Broken authorisation in subscriber APIs

Self-care and app APIs that authenticate a subscriber but let them access other subscribers' accounts, plans or data by changing an identifier — a mass-data-exposure risk at telecom scale.

HighData

BSS/OSS over-exposure

Business and operational support systems reachable from the corporate network with weak access control, concentrating subscriber data behind a thin barrier.

HighSegmentation

Weak IT-to-core segmentation

Insufficient separation between the corporate IT estate and the systems around the network core, so an IT foothold moves closer to critical systems than it should.

MediumThird party

Partner and integration exposure

Roaming partners, resellers and third-party integrations with excessive standing access into subscriber systems.

// 05 Reporting for a regulated operator

A telecom report must satisfy the national regulator and the sector authority, and account for the sheer scale of subscriber data at stake. We map every finding to the applicable control — ECC 2-11, CSCC for critical systems, and the sector and PDPL obligations — and express severity in terms of subscriber-data exposure as well as technical risk, because a single authorisation flaw can affect millions of records. Subscriber data encountered during testing is handled with appropriate care, and because retesting is included, you can evidence closure to the regulator and demonstrate the periodic testing posture the frameworks require. For operators whose critical systems have OT characteristics, we apply the appropriate operational-technology care.

// 06 Frequently asked questions

Why do telecom operators need penetration testing?

They are critical national infrastructure holding subscriber data at scale and carrying essential communications — a top target, and mandated to test by national regulators.

Which regulations apply?

National frameworks (NCA ECC + CSCC in Saudi Arabia), sector regulators (CST, TDRA, CITRA) and national PDPL laws over subscriber data.

What does it cover?

Subscriber portals and APIs, BSS/OSS, the internal IT network, and infrastructure/management systems around the core.

How often?

Periodically under the NCA ECC; at least every six months for critical systems under the CSCC, plus sector and risk-based cadences.

UG

Usama Gul

Founder & Penetration Testing Lead, CyberFortify

Leads telecom engagements across the subscriber, BSS/OSS and IT estate — mapped to the NCA ECC, CSCC and sector-regulator requirements, at the scale telecom demands.

Telecom operator due for testing?

We scope engagements across your subscriber, BSS/OSS and IT estate, protect subscriber data throughout, and map findings to the NCA ECC, CSCC and your sector regulator — retest included.

Schedule scoping call → Check my framework →