Dominic Jainy is a seasoned IT professional whose career has been defined by navigating the complex intersections of artificial intelligence, machine learning, and blockchain. As the telecommunications industry undergoes its most radical transformation yet, Dominic’s insights into the shift toward cloud-native infrastructure provide a critical roadmap for understanding modern connectivity. He has dedicated his career to exploring how these digital-first technologies can be harnessed across various industries, making him a uniquely qualified voice on the resilience and security of the systems that now power our global economy.
This discussion explores the fundamental shift of 5G from physical, air-gapped hardware to a software-defined environment, where traditional network reliability is now replaced by the complexities of cloud-native architecture. We examine the rising tide of cyber threats, including the specific vulnerabilities found in private 5G deployments and the cascading nature of software failures. Furthermore, we look at how rigorous international regulations and the need for market differentiation are forcing operators to treat network resilience not just as a technical requirement, but as a vital strategic opportunity.
The shift from traditional air-gapped hardware to a cloud-native 5G environment is often described as a double-edged sword. How do you view the fundamental risks associated with this transition to a software-defined network?
The transition is truly a paradigm shift because we are moving away from the physical safety of isolated cables and towers into a world where everything is governed by code. While this allows for incredible agility and the birth of new use cases, it means the “enduring problems” of software are now the primary headaches for telecommunications providers. We are looking at a future where, by 2030, 5G will account for 88% of all connections globally, which creates a massive, sprawling attack surface that simply didn’t exist in the era of hardware-centric 4G. It is a bit unsettling to realize that the same vulnerabilities that plague web applications are now threatening the very backbone of our communication systems. When you connect a network core to the open internet, you aren’t just opening a door for innovation; you are potentially handing a skeleton key to every threat actor on the planet.
We have seen instances where software failures lead to massive service disruptions. Could you walk us through how a single software update can escalate into a national outage?
The fragility of these virtualized environments was laid bare in early 2026, when a major operator saw a staggering 2 million people lose service simultaneously. This wasn’t a case of a physical tower falling over or a cable being cut; it was a ghost in the machine likely caused by faulty maintenance on a 5G Standalone core. Specifically, a failed update to a Virtual Network Function, or VNF, acted like a falling domino, triggering a chain reaction of collateral damage across the entire network architecture. In the old days, hardware failures were localized and physical, but in a software-defined world, a single line of bad code can “cascade” through the virtualized core with terrifying speed. It transforms what should have been a routine maintenance window into a high-stakes crisis that can paralyze an entire country’s digital life in minutes.
Cybersecurity remains a top priority, yet 5G seems to introduce new paths for lateral movement. What can we learn from recent breaches regarding how attackers exploit these interconnected systems?
The interconnectivity of 5G is its greatest strength, but for a hacker, it represents a direct highway from the network perimeter to the most sensitive data. We saw a chilling example of this in 2025 when a South Korean carrier was breached through a backdoor that allowed attackers to access the Home Subscriber Service and eventually the network core itself. This was only possible because the operator failed to segment the network, leaving no walls between internet-facing systems and the critical “brains” of the operation. Similarly, the “Salt Typhoon” attacks across the US between 2024 and 2025 demonstrated how sophisticated actors could exploit Network Repository Functions to move laterally through 5G slices. These actors weren’t just looking to disrupt service; they were farming massive amounts of proprietary and personal data, moving like shadows through the complex web of virtual functions.
Private 5G networks are becoming popular for smart factories and docks, but they often lack the security rigor of mainstream networks. What are the specific vulnerabilities that keep you up at night regarding these discrete systems?
Private networks are often the “weak link” in the chain because they frequently rely on a mix of generic servers and open-source software like Open5GS. Researchers have already proven that these environments are ripe for “container escape” attacks, where a compromise in a single cloud container can lead to total domination of the host server. There is a specific, almost surgical vulnerability involving GTP-U tunneling where an attacker can use a simple mobile phone to send anomalous data packets to the User Plane Function. When the system hits an unhandled exception error, it crashes the entire service, effectively executing a DDoS attack with minimal effort. It is alarming to see that many operators even skip encryption on the N3 interface just to squeeze out a bit more speed, leaving data wide open to manipulation by anyone who can get close enough to the radio access network.
With the rise of the UK’s Telecommunications Security Act and the US’s National Strategy to Secure 5G, how is the regulatory landscape changing the way operators must manage their vendors?
The days of light-touch regulation are over, and operators are now facing a reality where resilience is a legal mandate with sharp teeth. Under the UK’s framework, for example, a non-compliant operator could face a fine of 10% of their global turnover, or a stinging £100,000 for every single day that they remain out of compliance. These regulations, along with the EU’s NIS2, classify 5G as critical infrastructure, which means operators are now legally responsible for the security of every third-party component and API they use. They are being forced to gain “deep visibility” into their networks, auditing and vetting every supplier to ensure that a failure in a minor software patch doesn’t become a national security event. This shift is turning the procurement process into a rigorous security gauntlet, where “good enough” is no longer an option when millions of pounds are on the line.
What is your forecast for the 5G market as resilience moves from a backend technical requirement to a front-facing business strategy?
I believe we are entering an era where security and uptime will become the primary ways that telecom companies compete for customers. Currently, the market feels like a race to the bottom where consumers think every provider is selling the same commodity, but that perception is about to change. Operators who invest heavily in resilience will be able to market themselves as the “safe harbor” for data and connectivity, which is an incredibly powerful message in an age of constant breaches. We will see the emergence of “premium” tiers of service where guaranteed resilience and military-grade encryption are the main selling points, rather than just raw download speeds. Ultimately, those who view these new regulations as a strategic opportunity rather than a chore will be the clear winners in the increasingly crowded race for global revenue.
