Member Content
The Cybersecurity Layer Nobody Talks About: Telecommunications

By Meagan Carroll, IT Infrastructure and Cybersecurity Analyst,
Union Telephone Company
When people think about cybersecurity they think about firewalls, phishing emails, endpoint protection, and cloud security dashboards. That’s usually where the conversation starts, and where it stops. But beneath almost all of the current security controls is another layer that most organizations don’t think of until something goes wrong: telecom.
The text message that delivers a multi-factor authentication code, the phone call used to verify a customer’s identity, fraud alerts, emergency notifications, contact center operations, remote workforce connectivity, and executive communications during an outage. All of these critical functions depend on telecommunications infrastructure working reliably and securely.
For years, telecom has been viewed as a utility, something separate from cybersecurity. Historically, telecom teams managed carriers, circuits, and voice systems, while security teams focused on identity, threats, and compliance. That distinction no longer reflects reality. Many of today’s most important security controls rely directly on telecommunication services, including SMS-based MFA, voice verification, fraud prevention, helpdesk identity validation, incident response communications and emergency notifications.
As threat actors increasingly target the communications channels organizations use to establish trust and verify identity, telecom has become a critical component of the security stack. If telecom systems fail, or worse, are compromised, the security processes that depend on them can fail as well. Cybersecurity is only as strong as the infrastructure that supports it, and telecom is no longer operating behind the scenes, it’s on the front line.
Threat actors understood the importance of telecommunications to security long before most organizations did. Today’s threat actors are not trying to hack systems in the traditional sense. They’re more often trying to trick trust. SIM swapping, smishing, vishing, caller ID spoofing, toll fraud, MFA fatigue attacks, and AI-generated voice impersonation all target communication channels because that’s where identity and trust reside.
These attacks are often more psychological than technical. Threat actors want to convince people to grant access willingly. That’s a major shift. Cybersecurity is no longer about protecting systems and technology; it is also about protecting trust and the channels of communication that create that trust.
Years of robocalls and caller ID spoofing have conditioned people to distrust calls from unknown numbers. Voicemails are treated with suspicion, even when they’re legitimate. Businesses find themselves unable to reach customers because they’re being conditioned to believe that they can’t.
For banks, healthcare providers, government agencies and other companies, this is more than a problem of operational efficiency. It’s a security issue. If customers stop trusting legitimate communications, every relationship becomes more complicated. Branded calling can help rebuild trust in voice communications, but addressing the ongoing problem of robocalls is just as important. Trust itself has become infrastructure. Security is no longer just about the stability of networks and applications. It is also about the credibility of an organization’s communications.
We tend to think about reliability as an operations problem and security as a cybersecurity problem. In reality though, the two are closely connected. A security control doesn’t provide much value if people can’t use it. If employees can’t receive authentication codes, customers can’t be reached during a fraud event, or incident response teams can’t communicate during a crisis, those controls may still exist on paper, but they aren’t accomplishing their purpose.
Threat actors understand this. Sometimes the easiest way to break trust isn’t by compromising a system at all. It’s by disrupting the communications people depend on to make decisions, verify identity, and respond to incidents. When communication breaks down, confusion increases, response times slow, and trust begins to erode at exactly the moment organizations need it most.
Telecom, cybersecurity, and identity management are becoming more and more integrated. Several solutions are already emerging:
- Verified and branded calling
- Phishing-resistant authentication
- Identity-aware communications
- AI-based fraud detection
- Behavioral trust analysis
- Passwordless authentication
In the future, telecom networks likely will not be just about information. They’ll be able to verify authenticity, detect fraud and enhance identity assurance on the fly when communications happen. Organizations that treat telecom as a separate utility risk leaving a major blind spot in their broader security architecture.
Cybersecurity is no longer limited to servers, endpoints and cloud platforms. It now extends into phone calls, text messages, carrier networks, identity verification systems, and the communication channels that business depends on to keep trust and continuity. Telecom is now one of the core layers of modern cybersecurity.
Organizations that recognize this and integrate telecom into their security and resilience strategies will be better positioned for the next wave of fraud, disruption, and trust-based attacks. The organizations that continue to treat telecom as a utility may discover too late that it has become part of their security perimeter.
To contribute content, please contact comms@ccamobile.org. (CCA members only.)



