The vendor who built your core should not be the only one who gets to say it is secure.
Palo Alto, Nokia and NETSCOUT all sell capable telecom security products, and Nokia also sells the network. Independent, specification-driven assessment of individual 5G core network functions is a different job from buying another platform.
Our telecom work is assessment and hardening for operators and regulators running live national networks, built from the 3GPP specification down to individual core network functions. The same team red-teams those network functions and defends production financial and industrial systems.
Side by side
| Attribute | Represented by UnstratTelecom & 5G network security | Palo Alto Networks5G-Native Security1United States | NokiaNetGuard Cybersecurity Dome2Finland | NETSCOUTArbor Sightline3United States |
|---|---|---|---|---|
| What is being sold123 | Independent assessment and hardening: core-network assessment, network-function security and zero-trust architecture for national operators and regulators | A product portfolio mapped to 5G security use cases: ML-Powered NGFW for 5G, Prisma Cloud, Cortex XSOAR and Cortex Xpanse | An AI-driven XDR platform for communication service providers, consolidating security data across 5G domains | A network-wide visibility and DDoS detection and mitigation platform based on flow telemetry |
| Depth into the 5G core123 | Specification-driven assessment down to individual 5G core network functions built from the 3GPP specification | Sixteen named use cases covering user traffic, slicing, IoT, MEC, core, roaming, RAN, RAN sharing, private networks, vulnerability and compliance management, CI/CD, runtime defence for CNFs and VNFs, SBA security, SOC automation and attack-surface management | Security data consolidated across core, transport, RAN and cloud, with threat scoring at network-element level | Router and interface level flow visibility rather than 5G network-function analysis |
| Zero-trust architecture123 | Zero-trust architectures for national telecom infrastructure | States service providers can deploy a Zero Trust architecture for 5G network infrastructure | Not described as zero trust in this document | Not addressed |
| Published scale limits123 | Not published | Not published in this document | Not published in this document | 25,000,000 unique BGP routes, 5,000 monitored routers, 200,000 monitored interfaces and 20,000 managed objects |
| Automation and analyst support123 | Not published for this service. Our AI SOAR is offered separately | Cortex XSOAR mapped to the 5G SOC automation use case, with Cortex Xpanse for attack-surface management | Customisable response playbooks and a telecom-focused GenAI assistant built on Microsoft Azure OpenAI, using MITRE ATT&CK and FiGHT | Sightline with Sentinel uses Flowspec for network orchestration, matching attack vectors to Flowspec rules automatically |
| Named operator deployment123 | Not published | Not published in this document | Claro Colombia, described as Colombia's largest 5G deployment with over 1,000 secure network sites | Not published in this document |
| Independence from the network equipment vendor123A regulator asking whether the core is secure gets a weaker answer from the company that built the core. | Independent of the vendors who supplied the network | Independent of the radio and core equipment vendors | Nokia is itself a supplier of 5G core, transport and RAN equipment | Independent of the network equipment vendors |
| Licensing model123 | Not published | Not published in this document | Modular design allowing flexible deployment; commercial terms not published | Perpetual Flex licences, a site licence covering the whole network, or an annual subscription |
| Origin and political exposure123 | Independent, non-aligned origin, with no political exposure to any major-power ecosystem | United States | Finland, with the GenAI assistant built on Microsoft Azure OpenAI | United States |
Competitor values are quoted from the vendor documents listed under Sources, as published on the date shown. Configurations vary, so treat every row as a starting point for the evaluation rather than a like-for-like test result.
What the table means
Marking your own homework
Nokia's NetGuard Cybersecurity Dome is a serious platform, with multi-domain correlation across core, transport, RAN and cloud, element-level threat scoring and a documented deployment at Claro Colombia across more than 1,000 sites. It is also sold by the company that builds 5G cores, transport and radio. If the question in front of a regulator is whether the national core has been implemented securely, an assessment from its supplier answers a narrower question than the one being asked. That is not an accusation against Nokia; it is a structural limit on who can credibly answer.
Products are not assessments
Palo Alto's sixteen use cases are the best public checklist of the 5G attack surface, from slicing and roaming through to runtime defence for containerised network functions. NETSCOUT publishes hard scaling limits, up to 25 million BGP routes and 200,000 monitored interfaces, which tells an operator exactly what the platform will carry. Both are things you install. Neither tells you whether your AMF, SMF or UPF was configured and implemented in a way an attacker can defeat. That question is answered by building the threat model from the 3GPP specification and testing against it, which is what we do.
The sovereignty problem is the network itself
Every other national capability rides on the telecom layer, so a compromise here cascades into finance, defence and civil administration at once. Nations increasingly find that their core, their security overlay and their AI assistant all come from the same small set of foreign suppliers, with an AI service built on a US hyperscaler in the middle of it. An independent, non-aligned assessment does not remove the dependency. It does mean somebody who is not part of that supply chain has looked at what you depend on.
Questions buyers ask
Who can independently assess a national 5G core network?
Look for a team that works from the 3GPP specification rather than from a scanner, and that has no commercial relationship with the equipment vendors. We assess down to individual 5G core network functions and red-team them. Nokia's NetGuard Cybersecurity Dome and Palo Alto's 5G-native portfolio are strong products, but a product deployment and an independent assessment are different procurements, and a regulator generally needs the second one.
What are the main security risks in a 5G core network?
Palo Alto's public use-case list is a good starting checklist: user traffic, network slicing, IoT, MEC, the core itself, roaming, RAN and RAN sharing, private networks, vulnerability and compliance management, CI/CD, runtime defence for containerised and virtual network functions, service-based architecture security, SOC automation and attack-surface management. The risks that show up in our own testing are usually in the implementation of individual network functions and the interfaces between them, which a use-case checklist will not find for you.
Should a telecom operator buy security from its network equipment vendor?
It is convenient and the integration is usually better. The cost is independence. Nokia sells both the network and NetGuard Cybersecurity Dome, and a report from a supplier about its own equipment carries an obvious conflict, however competent the work. The common resolution is to buy platform security wherever integration is best, then commission assurance from someone with no stake in the equipment decision.
How do you protect a national network from DDoS at carrier scale?
That is a specific product problem and NETSCOUT's Arbor Sightline is the reference answer, with published capacity for 25 million BGP routes, 5,000 monitored routers and 200,000 interfaces, plus Flowspec-based orchestration through Sightline with Sentinel. We do not compete with it and would not pretend to. Our contribution is making sure the core, the network functions and the trust architecture behind the mitigation layer are sound.
Sources
- 1. Palo Alto Networks, 5G-Native Security (at a glance, 2022) (copy held on this site)Retrieved: 2026-07-31 · The sixteen numbered 5G security use cases and the mapping of each to ML-Powered NGFW for 5G, Prisma Cloud, Cortex XSOAR and Cortex Xpanse.
- 2. Nokia, Defend your network with NetGuard Cybersecurity Dome (copy held on this site)Retrieved: 2026-07-31 · Multi-domain XDR across 5G core, transport, RAN and cloud, the GenAI assistant built on Microsoft Azure OpenAI, and the Claro Colombia deployment reference.
- 3. NETSCOUT, Arbor Sightline (data sheet) (copy held on this site)Retrieved: 2026-07-31 · Scaling limits table, Sightline with Sentinel Flowspec orchestration and the three licensing models. NETSCOUT's own resource page serves the document through a gated viewer, so the copy retrieved is a distributor-hosted mirror of the same data sheet.
