Broadband Provider
News

Telecoms Firms Face New Security Breach Reporting Rules Under Ofcom Proposals

Julian GloverJulian Glover
4 Mins Read
Share
Telecoms Firms Face New Security Breach Reporting Rules Under Ofcom Proposals

Britain's telecommunications regulator wants mobile operators to report serious security breaches faster and with more precision, proposing new rules that would force companies to alert authorities within 24 hours when incidents affect substantial portions of their networks.

Ofcom opened a consultation on Tuesday proposing revised guidance for how telecoms firms report security incidents, setting specific numerical thresholds that determine when operators must notify the regulator.

10% Threshold Triggers Reporting

Under the proposed framework, mobile network operators would need to report any security incident affecting at least 10% of their customer base or network infrastructure. The threshold applies to both the number of users impacted and the geographic coverage area affected.

The proposals stem from obligations under the Telecoms Security Act, which requires operators to maintain solid systems protecting their networks whilst providing detailed information to regulators about security incidents.

"These clearer reporting thresholds remove ambiguity about when operators must notify us," an Ofcom spokesperson stated. "We're establishing a consistent framework across the industry."

24-Hour Notification Window

Telecommunications companies would face a 24-hour deadline to submit initial incident reports once they detect a qualifying security breach. That preliminary notification must include the nature of the incident, estimated impact, and immediate mitigation steps taken.

A follow-up detailed report would be required within 72 hours, outlining root causes, affected systems, number of customers impacted, and remediation plans.

The proposed requirements apply to mobile network operators including EE, Vodafone, O2, and Three, though fixed-line broadband providers may face similar obligations depending on the incident's scope.

Categories of Reportable Incidents

Ofcom's consultation document outlines specific categories of security incidents requiring mandatory reporting. These include unauthorised access to network infrastructure, distributed denial-of-service attacks affecting service availability, data breaches exposing customer information, and supply chain compromises affecting network equipment.

Physical security breaches, such as unauthorised access to cell towers or data centres, would also trigger reporting requirements if they meet the 10% threshold.

The regulator wants operators to assess impact based on multiple metrics: total customer numbers affected, geographic regions where service degraded, duration of service disruption, and types of services compromised.

Industry Response Expected

Telecommunications industry bodies have until March 2025 to submit responses to the consultation. Ofcom plans to finalise the guidance by summer 2025, with new requirements taking effect in autumn.

Several mobile operators privately expressed concerns about the administrative burden, particularly regarding the 24-hour initial reporting deadline. "Accurately assessing the scope of a sophisticated cyberattack within 24 hours presents real challenges," a network security director at a major operator said, speaking on condition of anonymity.

However, cybersecurity experts generally support tighter reporting frameworks. "Prompt incident notification allows regulators to coordinate responses across multiple operators and identify systemic vulnerabilities faster," explained Dr Sarah Mitchell, a telecommunications security researcher at Imperial College London.

Escalating Security Threats

The proposed changes come as UK telecommunications networks face mounting security pressures. The National Cyber Security Centre reported a 47% increase in significant cyberattacks targeting critical national infrastructure in 2024 compared to the previous year.

Mobile networks represent particularly attractive targets because of their role in emergency services communications, financial transactions, and government operations.

Ofcom's consultation follows several high-profile security incidents affecting British telecoms operators in recent years, though specific details remain classified under security protocols.

International Alignment

The proposals align Britain's telecommunications security framework with European Union standards established under the Network and Information Systems Directive. Similar reporting requirements exist in France, Germany, and the Netherlands, where operators face penalties for failing to notify regulators promptly.

Australia implemented comparable rules in 2023, requiring telcos to report security incidents affecting more than 30,000 customers within eight hours.

Penalties for Non-Compliance

Whilst Ofcom's consultation doesn't specify penalties for non-compliance, the Telecoms Security Act grants regulators powers to impose fines up to £100,000 or 10% of annual revenue, whichever proves greater.

Operators could also face enforcement orders requiring specific security improvements or, in extreme cases, restrictions on network operations.

The regulator emphasised that reporting requirements serve protective rather than punitive purposes. "We want operators to report incidents without fear that notification itself triggers sanctions," the Ofcom spokesperson noted. "The goal is improving collective security across the sector."

Consultation Scope

Beyond reporting thresholds, Ofcom's consultation addresses how operators should categorise incident severity, what technical details reports must contain, and how quickly operators should update regulators as situations evolve.

The proposals also cover coordination between multiple operators when security incidents affect shared infrastructure, such as backhaul networks or interconnection points.

Smaller mobile virtual network operators (MVNOs) that lease network capacity from major carriers would need to report incidents affecting their specific customer base, even if the underlying infrastructure operator also files a report.

Technical Implementation

Ofcom proposes establishing a secure online portal where operators submit incident reports using standardised templates. The system would automatically flag incidents requiring urgent regulatory attention based on predefined criteria.

Operators would receive acknowledgement within four hours of submission, with assigned case managers for significant incidents affecting multiple providers or critical services.

The regulator expects to share anonymised incident data across the industry quarterly, allowing operators to learn from peers' experiences without compromising competitive information.

Telecommunications companies now have three months to review the proposals and submit detailed responses addressing practical implementation challenges, resource requirements, and potential unintended consequences of the stricter reporting framework.

Share
Julian Glover
Written by

Julian Glover

Julian Glover covers UK home and business broadband, comparing providers, explaining new tech, and helping readers find the right deal for their household.

Related Articles