The European Union warned the risk of increased cyberattacks by state-backed entities but refrained from singling out China and its telecoms equipment market leader Huawei Technologies as threats.
The comments came in a report prepared by EU member states on cybersecurity risks to next generation 5G mobile networks seen as crucial to the bloc’s competitiveness in an increasingly networked world.
The authors ignored calls by the US to ban Huawei equipment, drawing a welcome from the Shenzen-based company after it faced accusations its equipment could be used by China for spying.
“Among potential actors, non-EU states or state-backed are considered the most serious and most likely to target 5G networks,” the European Commission and Finland, which currently holds the rotating EU presidency, said in a joint statement.
“In this context of increased exposure to attacks facilitated by suppliers, the risk profile of individual suppliers will become particularly important, including the likelihood of the supplier being subject to interference from a non-EU country,” they said.
Huawei, which competes with Finland’s Nokia and Sweden’s Ericsson, said it stood ready to work with European partners on 5G network security. It always denied its equipment can be used for spying.
“This exercise is an important step toward developing a common approach to cybersecurity and delivering safe networks for the 5G era,” a Huawei spokesman said.
“We are pleased to note the EU delivered on its commitment to take an evidence-based approach, analysing risks rather than targeting specific countries or actors.”
Tom Ridge, a former US secretary of homeland security, took a different view of the report. He said Huawei’s close ties to the Chinese government meant it would have to comply with legislation requiring it to assist with intelligence gathering.
“If countries needed more reason to implement stricter security measures to protect 5G networks, this comprehensive risk assessment is it,” said Ridge, a member of the advisory board of Global Cyber Policy Watch.
Fifth-generation networks will hook up billions of devices, sensors and cameras in ‘smart’ cities, homes and offices. With that ubiquity, security becomes even more pressing than in existing networks.
“5G security requires networks are built leveraging the most advanced security features, selecting vendors that are trustworthy and transparent,” a Nokia spokesperson said, adding the company was the only global vendor capable of providing all the building blocks for secure 5G networks.
EU members differ on how to treat Huawei, with Britain, a close US ally, leaning to excluding it from critical parts of networks. Germany is creating a level playing field in which all 5G vendors should prove they are trustworthy.
The report warned against over-dependence on one telecoms equipment supplier.
“A major dependency on a single supplier increases exposure to a potential supply interruption, resulting for instance from a commercial failure and its consequences,” it said.
European network operators, including Germany’s Deutsche Telekom typically have multi-vendor strategies they say reduce security risks from relying on a single provider.
“The Commission’s 5G assessment recognises security isn’t just a supplier issue,” said Alex Sinclair, chief technology officer of the GSMA, a global mobile-industry trade group.
“We all have a role to play – from manufacturers to operators to consumers – and we are taking responsibility for our part in the security chain seriously.”
The EU will come up with a so-called toolbox of measures by the end of the year to address cyber security risks at national and bloc-wide level.
The European Agency for Cybersecurity is finalising a map of specific threats related to 5G networks.