Skip to main content

The vendor who built your core should not be the only one who gets to say it is secure.

Palo Alto, Nokia and NETSCOUT all sell capable telecom security products, and Nokia also sells the network. Independent, specification-driven assessment of individual 5G core network functions is a different job from buying another platform.

In service, not experimental

Our telecom work is assessment and hardening for operators and regulators running live national networks, built from the 3GPP specification down to individual core network functions. The same team red-teams those network functions and defends production financial and industrial systems.

Side by side

AttributeRepresented by UnstratTelecom & 5G network securityPalo Alto Networks5G-Native Security1United StatesNokiaNetGuard Cybersecurity Dome2FinlandNETSCOUTArbor Sightline3United States
What is being sold123Independent assessment and hardening: core-network assessment, network-function security and zero-trust architecture for national operators and regulatorsA product portfolio mapped to 5G security use cases: ML-Powered NGFW for 5G, Prisma Cloud, Cortex XSOAR and Cortex XpanseAn AI-driven XDR platform for communication service providers, consolidating security data across 5G domainsA network-wide visibility and DDoS detection and mitigation platform based on flow telemetry
Depth into the 5G core123Specification-driven assessment down to individual 5G core network functions built from the 3GPP specificationSixteen named use cases covering user traffic, slicing, IoT, MEC, core, roaming, RAN, RAN sharing, private networks, vulnerability and compliance management, CI/CD, runtime defence for CNFs and VNFs, SBA security, SOC automation and attack-surface managementSecurity data consolidated across core, transport, RAN and cloud, with threat scoring at network-element levelRouter and interface level flow visibility rather than 5G network-function analysis
Zero-trust architecture123Zero-trust architectures for national telecom infrastructureStates service providers can deploy a Zero Trust architecture for 5G network infrastructureNot described as zero trust in this documentNot addressed
Published scale limits123Not publishedNot published in this documentNot published in this document25,000,000 unique BGP routes, 5,000 monitored routers, 200,000 monitored interfaces and 20,000 managed objects
Automation and analyst support123Not published for this service. Our AI SOAR is offered separatelyCortex XSOAR mapped to the 5G SOC automation use case, with Cortex Xpanse for attack-surface managementCustomisable response playbooks and a telecom-focused GenAI assistant built on Microsoft Azure OpenAI, using MITRE ATT&CK and FiGHTSightline with Sentinel uses Flowspec for network orchestration, matching attack vectors to Flowspec rules automatically
Named operator deployment123Not publishedNot published in this documentClaro Colombia, described as Colombia's largest 5G deployment with over 1,000 secure network sitesNot published in this document
Independence from the network equipment vendor123A regulator asking whether the core is secure gets a weaker answer from the company that built the core.Independent of the vendors who supplied the networkIndependent of the radio and core equipment vendorsNokia is itself a supplier of 5G core, transport and RAN equipmentIndependent of the network equipment vendors
Licensing model123Not publishedNot published in this documentModular design allowing flexible deployment; commercial terms not publishedPerpetual Flex licences, a site licence covering the whole network, or an annual subscription
Origin and political exposure123Independent, non-aligned origin, with no political exposure to any major-power ecosystemUnited StatesFinland, with the GenAI assistant built on Microsoft Azure OpenAIUnited States

Competitor values are quoted from the vendor documents listed under Sources, as published on the date shown. Configurations vary, so treat every row as a starting point for the evaluation rather than a like-for-like test result.

What the table means

Marking your own homework

Nokia's NetGuard Cybersecurity Dome is a serious platform, with multi-domain correlation across core, transport, RAN and cloud, element-level threat scoring and a documented deployment at Claro Colombia across more than 1,000 sites. It is also sold by the company that builds 5G cores, transport and radio. If the question in front of a regulator is whether the national core has been implemented securely, an assessment from its supplier answers a narrower question than the one being asked. That is not an accusation against Nokia; it is a structural limit on who can credibly answer.

Products are not assessments

Palo Alto's sixteen use cases are the best public checklist of the 5G attack surface, from slicing and roaming through to runtime defence for containerised network functions. NETSCOUT publishes hard scaling limits, up to 25 million BGP routes and 200,000 monitored interfaces, which tells an operator exactly what the platform will carry. Both are things you install. Neither tells you whether your AMF, SMF or UPF was configured and implemented in a way an attacker can defeat. That question is answered by building the threat model from the 3GPP specification and testing against it, which is what we do.

The sovereignty problem is the network itself

Every other national capability rides on the telecom layer, so a compromise here cascades into finance, defence and civil administration at once. Nations increasingly find that their core, their security overlay and their AI assistant all come from the same small set of foreign suppliers, with an AI service built on a US hyperscaler in the middle of it. An independent, non-aligned assessment does not remove the dependency. It does mean somebody who is not part of that supply chain has looked at what you depend on.

Questions buyers ask

Who can independently assess a national 5G core network?

Look for a team that works from the 3GPP specification rather than from a scanner, and that has no commercial relationship with the equipment vendors. We assess down to individual 5G core network functions and red-team them. Nokia's NetGuard Cybersecurity Dome and Palo Alto's 5G-native portfolio are strong products, but a product deployment and an independent assessment are different procurements, and a regulator generally needs the second one.

What are the main security risks in a 5G core network?

Palo Alto's public use-case list is a good starting checklist: user traffic, network slicing, IoT, MEC, the core itself, roaming, RAN and RAN sharing, private networks, vulnerability and compliance management, CI/CD, runtime defence for containerised and virtual network functions, service-based architecture security, SOC automation and attack-surface management. The risks that show up in our own testing are usually in the implementation of individual network functions and the interfaces between them, which a use-case checklist will not find for you.

Should a telecom operator buy security from its network equipment vendor?

It is convenient and the integration is usually better. The cost is independence. Nokia sells both the network and NetGuard Cybersecurity Dome, and a report from a supplier about its own equipment carries an obvious conflict, however competent the work. The common resolution is to buy platform security wherever integration is best, then commission assurance from someone with no stake in the equipment decision.

How do you protect a national network from DDoS at carrier scale?

That is a specific product problem and NETSCOUT's Arbor Sightline is the reference answer, with published capacity for 25 million BGP routes, 5,000 monitored routers and 200,000 interfaces, plus Flowspec-based orchestration through Sightline with Sentinel. We do not compete with it and would not pretend to. Our contribution is making sure the core, the network functions and the trust architecture behind the mitigation layer are sound.

Sources

  1. 1. Palo Alto Networks, 5G-Native Security (at a glance, 2022) (copy held on this site)Retrieved: 2026-07-31 · The sixteen numbered 5G security use cases and the mapping of each to ML-Powered NGFW for 5G, Prisma Cloud, Cortex XSOAR and Cortex Xpanse.
  2. 2. Nokia, Defend your network with NetGuard Cybersecurity Dome (copy held on this site)Retrieved: 2026-07-31 · Multi-domain XDR across 5G core, transport, RAN and cloud, the GenAI assistant built on Microsoft Azure OpenAI, and the Claro Colombia deployment reference.
  3. 3. NETSCOUT, Arbor Sightline (data sheet) (copy held on this site)Retrieved: 2026-07-31 · Scaling limits table, Sightline with Sentinel Flowspec orchestration and the three licensing models. NETSCOUT's own resource page serves the document through a gated viewer, so the copy retrieved is a distributor-hosted mirror of the same data sheet.
Next step on this comparison

Send us the requirement and the systems you are weighing. We will map this table onto it.