The real 5G mobile internet connectivity race is to secure not only the network but also the ecosystem of devices and applications attached to the network, former Federal Communications Commission (FCC) Chairman Tom Wheeler said in a new paper published by the Brookings Institute.
In the report, entitled Why 5G Requires New Approaches to Cybersecurity, co-authors Wheeler and David Simpson, former chief of the FCC’s Public Safety and Homeland Security Bureau, contend that securing 5G networks is central to national security. “To build 5G on top of a weak cybersecurity foundation is to build on sand,” the authors wrote.
In a nod to the bigger picture, Wheeler and Simpson make a case that failing to move beyond the Huawei spying issue masks some larger issues concerning 5G security. “Policy leaders should be conducting a more balanced risk assessment, with a broader focus on vulnerabilities, threat probabilities, and impact drivers of the cyber risk equation” rather than becoming so immersed in Huawei. “China is a threat even when there is not Huawei equipment in our networks,” they said.
According to Wheeler and Simpson, with the advent of 5G technology comes these five cyber dangers:
“We shouldn’t be surprised that the networks of the 21st century are the new attack vectors, but these are different because they are expanded to an almost infinite number of attack vectors,” Wheeler told The Hill.
The authors acknowledge that what needs to be done to secure 5G networks is “both important and not without cost.” They argue, however, that these are not normal times and require a “departure from traditional practices.”
This “new reality” justifies the following corporate and governmental actions:
Key #1: Companies must recognize and be held responsible for a new cyber duty of care. This spans:
Key #2: Government must establish a new cyber regulatory paradigm to reflect the new realities. This spans:
In concluding, the authors chided the Trump administration and Congress for sitting on their hands on 5G cybersecurity. “Congress should not have to pass legislation instructing the Trump administration to act on 5G cybersecurity,” they wrote. “The whole-of-the-nation peril requires a whole-of-the-economy and whole-of-the-government response built around the realities of the information age, not formulaic laissez faire political philosophy or the structures of the industrial age.”