{"id":23385,"date":"2025-12-04T12:29:02","date_gmt":"2025-12-04T11:29:02","guid":{"rendered":"https:\/\/telecomkh.info\/?p=23385"},"modified":"2025-12-04T12:32:20","modified_gmt":"2025-12-04T11:32:20","slug":"new-gsma-report-warns-that-fragmented-cybersecurity-regulation-is-raising-costs-and-increasing-risk-for-mobile-operators","status":"publish","type":"post","link":"https:\/\/telecomkh.info\/?p=23385","title":{"rendered":"New GSMA report warns that fragmented cybersecurity regulation is raising costs and increasing risk for mobile operators"},"content":{"rendered":"<p><strong>The mobile industry, supported by the GSMA, calls for harmonised, risk-based and collaborative policy frameworks to strengthen global cyber resilience<\/strong><\/p>\n<p>The GSMA released a major new independent study, The Impact of Cybersecurity Regulation on Mobile Operators, revealing that mobile operators are spending between US $15-19 billion annually on core cybersecurity activities, a figure expected to rise to US $40-42 billion by 2030. Despite this significant investment, mobile network operators, who form the backbone of digital economies worldwide, are impacted by poorly designed, misaligned or overly prescriptive regulation, which results in unnecessary costs, diverting resources from genuine risk mitigation, and in some cases increasing exposure to cyber threats.<br \/>\nMichaela Angonius, GSMA Head of Policy and Regulation, said: \u201cMobile networks carry the world\u2019s digital heartbeat. As cyber threats escalate, operators are investing heavily to keep societies safe \u2013 but regulation must help, not hinder, those efforts. This report makes clear that cybersecurity frameworks work best when they are harmonised, risk-based and built on trust. When done poorly, regulation can redirect critical resources away from real security improvements and toward compliance for its own sake.\u201d<\/p>\n<p><strong>A global perspective<\/strong><br \/>\nDeveloped in partnership with Frontier Economics, the report draws on economic analysis and operator interviews representing the Africa, Asia Pacific, Europe, Latin America, Middle East and North America regions. It highlights how the fast-changing nature of cyber threats is driving up the costs and complexity for mobile operators across the globe, making collaboration between governments in different jurisdictions and engagement with industry vital in avoiding unnecessary costs for those operators present in multiple markets.<\/p>\n<p><strong>Policy misalignment is creating unnecessary burdens:<\/strong><br \/>\nThe study identifies widespread challenges across markets, including:<br \/>\n\u2022 Fragmented and inconsistent regulation, forcing operators to comply with overlapping or contradictory requirements from multiple agencies.<br \/>\n\u2022 A proliferation of reporting obligations, sometimes requiring the same incident to be reported multiple times in different formats.<br \/>\n\u2022 Prescriptive \u201cbox-ticking\u201d rules that mandate tools or processes rather than focusing on real-world security outcomes.<\/p>\n<p>One operator reported that up to 80% of their cybersecurity operations team\u2019s time is spent on audits and compliance tasks, rather than threat detection or incident response.<br \/>\nDespite these pressures, operators emphasised that ensuring safe and secure mobile networks is a priority for their customers and for society as a whole in a digitally connected world.<\/p>\n<p><strong>Six principles for effective cybersecurity regulation:<\/strong><br \/>\nThe report outlines a blueprint for governments and policymakers to build more secure and efficient frameworks, and design cybersecurity policies according to six core principles:<\/p>\n<p><strong>\u2022 Harmonisation:<\/strong> Align cybersecurity policy with international standards where possible, to reduce regulatory fragmentation and inconsistency.<br \/>\n<strong>\u2022 Consistency:<\/strong> Ensure new policies and frameworks are consistent with existing policy to avoid duplication or conflict.<br \/>\n<strong>\u2022 Risk- and outcome-based:<\/strong> Adopt risk- and outcome-based approaches in the design and implementation of cybersecurity regulation, giving operators flexibility to innovate.<br \/>\n<strong>\u2022 Collaboration:<\/strong> Promote a collaborative regulatory culture with industry, supported by secure threat intelligence sharing.<br \/>\n<strong>\u2022 Security-by-design:<\/strong> Encourage a proactive, security-by-design approach to mitigating cyber risks.<br \/>\n<strong>\u2022 Capacity-building:<\/strong> Strengthen the institutional capacity of cybersecurity authorities to ensure a whole-of-government approach and effective application of policy and regulation.<\/p>\n<p>The report warns that unilateral, fragmented approaches heighten vulnerabilities and create inefficiencies for global operators.<br \/>\nMichaela Angonius added: \u201cCybersecurity is a shared responsibility. To protect citizens and critical societal services, regulators and operators should work together, guided by a common set of principles. When policy is coherent and outcomes-focused, the entire digital ecosystem becomes safer.\u201d<\/p>\n<p><strong>A call for coordinated global action:<\/strong><br \/>\nThe mobile industry, supported by the GSMA, is calling on governments and regulators to minimise unnecessary burdens on mobile operators by collaborating and building trusted frameworks and mechanisms that foster innovation to enable mobile networks to remain secure, resilient, and capable of supporting the digital services that societies increasingly rely on.<\/p>\n<p><span style=\"color: #999999;\"><em>Above, photo by Paul Hanaoka on unsplash<\/em><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The mobile industry, supported by the GSMA, calls for harmonised, risk-based and collaborative policy frameworks to strengthen global cyber resilience The GSMA released a major new independent study, The Impact of Cybersecurity Regulation on Mobile Operators, revealing that mobile operators are spending between US $15-19 billion annually on core cybersecurity activities, a figure expected to &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/telecomkh.info\/?p=23385\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> \u00abNew GSMA report warns that fragmented cybersecurity regulation is raising costs and increasing risk for mobile operators\u00bb<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":23388,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[24],"tags":[],"_links":{"self":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts\/23385"}],"collection":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=23385"}],"version-history":[{"count":2,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts\/23385\/revisions"}],"predecessor-version":[{"id":23389,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/posts\/23385\/revisions\/23389"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=\/wp\/v2\/media\/23388"}],"wp:attachment":[{"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=23385"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=23385"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/telecomkh.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=23385"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}