Telecom Needs More Than Threat Intelligence. It Needs Risk Determination.


How telecom teams can connect adversary activity to their critical dependencies and turn intelligence into action.
Telecom teams have access to vast amounts of threat intelligence. The harder question is: Which threats put our operations at risk?
- A supplier’s name in a threat report is only the starting point. What matters is how that activity connects to your systems, data, and services.
- Risk determination closes that gap. It establishes what demands attention, why, and what action to take.
- iCOUNTER carries the finding through to remediation. CTOS determines risk, engages affected third parties, and tracks fixes to completion.
Know what the threat means. Act on the evidence.
A Third-Party Threat Can Become Your Operational Risk
In July 2024, AT&T disclosed that attackers had accessed an AT&T workspace on a third-party cloud platform and stolen customer call and text interaction records. The records included information about communications, but not the contents of calls or messages. AT&T’s disclosure described exposure within its cloud workspace, rather than establishing a breach of the platform provider’s own systems.
Understanding AT&T’s exposure required knowing which environment was affected, what data it held, and how it connected to the business.
For telecom security teams, that is the gap between learning about a threat and determining what it means for their organization. Intelligence identifies activity. Risk determination connects that activity to the dependencies that could put customer data, network operations, or service delivery at risk.
The Supplier’s Name Is Only the Starting Point
Telecom providers depend on equipment manufacturers, software suppliers, cloud platforms, managed service providers, and contractors. Those relationships carry different levels of access and operational importance.
A managed service provider may administer network systems. A software supplier may support a customer-facing application. A cloud partner may hold subscriber information.
Knowing that one of those organizations is being targeted raises questions:
- Does the activity involve the service you use?
- Are the exposed credentials connected to your environment?
- Could the affected technology interrupt a critical operation?
Consider an illustrative example: credentials associated with a managed service provider appear for sale. Their significance depends on what they access. An account used to administer network systems presents different implications from an account in an unrelated environment.
That is risk determination. It provides the missing layer between threat collection and operational response.
Salt Typhoon Shows Why Technical Context Matters
The Salt Typhoon campaign underscored the stakes of telecom targeting. In December 2024, U.S. and international agencies warned that PRC-affiliated actors had compromised major telecommunications networks in a broad cyberespionage campaign. Their joint guidance focused on improving visibility and hardening communications infrastructure.
The campaign should not be thought of only as a third-party breach. Its relevance here is the need to connect knowledge of an adversary with the infrastructure and access paths an organization actually operates.
Knowing that telecom is being targeted establishes urgency. Understanding whether the activity intersects with your technologies and dependencies helps establish what deserves action.
Shared Intelligence Still Needs Organization-Specific Context
The industry is strengthening collaboration. In May 2026, eight communications companies announced the formation of the Communications Cybersecurity Information Sharing and Analysis Center, or C2 ISAC, to support faster, more actionable information sharing. C2 ISAC’s announcement emphasizes that no single company sees every threat.
Shared intelligence expands what providers can see. Each provider still needs to establish how a finding relates to its own environment.
An indicator associated with a technology supplier might warrant urgent investigation for one operator and have little relevance to another. A compromised account might affect a critical service, or a business unit with no connection to the operator.
That is why telecom providers need to connect Third-Party Risk Management with real-time threat intelligence. One provides supplier context. The other provides threat context. Risk determination connects the two.
How iCOUNTER Connects Intelligence to Remediation
iCOUNTER addresses this need through Ecosystem Risk Determination at the Edge of Intelligence Collection.
Its Counter Threat Operating System (CTOS™) combines intelligence collection, customer-specific risk determination, and response in a managed service. iCOUNTER owns and operates its global collection infrastructure and evaluates activity against the organization’s ecosystem before delivering validated findings into internal workflows.
For telecom teams, that connects external activity to the third parties and dependencies behind their operations:
- Collect and determine. CTOS collects signals such as credential exposure, adversary targeting, and compromise activity. Using a digital twin of the customer’s ecosystem, it correlates those signals with the organization’s dependencies to determine whether they represent operational risk.
- Prioritize and engage. Findings are prioritized by potential impact and the customer’s risk framework. Validated risks arrive with supporting evidence and prescribed next steps, while iCOUNTER engages affected third parties.
- Coordinate remediation and track the fix. iCOUNTER coordinates remediation with the affected third party and tracks it to completion with evidence. This managed approach reduces the work customers must take on to move a finding through investigation and resolution.
If exposed credentials are tied to a managed service provider supporting your network, a validated finding could lead to engagement with that provider to revoke the credentials, investigate associated access, and confirm corrective action.
By identifying signs of targeting and active compromise, iCOUNTER creates opportunities to address exposure before a formal breach notification arrives.
Help Security, Risk, and Network Teams Act Together
Different teams contribute essential context to a third-party threat:
- Threat Intelligence understands adversary activity and the evidence behind a finding.
- Third-Party Risk Management contributes supplier context and established engagement processes.
- Network and security operations understand technical dependencies and potential service consequences.
iCOUNTER gives those teams evidence-backed findings and a defined action path, while managing third-party engagement and remediation coordination. That helps connect their expertise without leaving them to assemble every external signal from scratch.
Existing assessments, ratings, and security tools retain their roles. CTOS adds Counter Threat Operations across the extended ecosystem, connecting live threat activity to action.
How One Global Telecom Provider Put This into Practice
A global telecommunications provider working with iCOUNTER already had established Threat Intelligence and Third-Party Risk Management programs. Its leadership wanted to connect them around a practical question: Which third parties are facing threats that matter to us, and where should we act first?
The provider selected an initial population of critical third parties. Using CTOS, the teams established a common approach to detecting adversary activity, determining its relevance, prioritizing findings, and guiding investigation, supplier engagement, or remediation.
The engagement established a shared operating model for evaluating evidence and deciding where action was warranted.
Know What the Threat Means. Act on the Evidence.
For telecom providers, the value of intelligence depends on connecting it to the systems, data, and services they need to protect.
With iCOUNTER, that connection extends through risk determination to managed remediation. Telecom teams gain a clearer understanding of their exposure and a service that helps address it across affected third parties.

%201.avif)

.avif)