logo_header
  • Topics
  • Research & Analysis
  • Features & Opinion
  • Webinars & Podcasts
  • Videos
  • Event videos

Security is no longer reactive. It has to predict, prove and act

The Telco AEGIS - Autonomous Ecosystem for Generative Intelligence and Security Catalyst shows how an autonomous, agentic security lifecycle can help communications service providers detect, validate and mitigate advanced threats across complex telecom environments.

Ailis Claassen
30 Jul 2026
Security is no longer reactive. It has to predict, prove and act

Security is no longer reactive. It has to predict, prove and act

From fragmented controls to autonomous telecom security

Telecom security is operating in a more complex, multi-protocol, and multi-vendor environment. Critical signaling, roaming and control-plane environments such as SS7, Diameter, GTP and 5G SBA expose sensitive capabilities, including location intelligence, while security controls remain fragmented across network, IT, roaming and interconnect domains.

This fragmentation limits operators’ ability to build a real-time, unified view of threats. Without shared telemetry and contextual insight, it is difficult to detect and validate attacks consistently, particularly when changes are deployed without systematic pre-validation.

The result is a reactive security posture that struggles to keep pace with advanced threats, from location tracking abuse to signaling exploitation and more sophisticated attacks. Operators face growing pressure to respond faster while reducing fraud losses, false positives, and reliance on scarce expert resources.

An agentic closed loop for threat detection, validation and response

The Catalyst, Telco AEGIS – Autonomous ecosystem for generative intelligence and security, introduces an agentic and autonomous telco security lifecycle that moves operators from manual, reactive processes to a continuous, intent-driven and evidence-based closed loop.

The solution combines AI-powered orchestration, reusable automated playbooks, and the Model Context Protocol to monitor behavior, assess risk, validate proposed security changes, and trigger mitigation actions. This enables operators to test and prove changes before deployment, reducing the risk of misconfiguration or unintended service impact. Participating carriers can share structured threat intelligence so attacks that span multiple networks, invisible to any single operator, become detectable and actionable.

The Catalyst is also grounded in TM Forum assets, including TMFC028, TMF693, TMF688, TMF724A, IG1239A1 and IG1255. These assets support a standards-aligned approach to orchestration, interoperability, and autonomous operations across complex telco domains.

Because every action is traceable, explainable, and auditable, the lifecycle is designed to strengthen trust as well as speed. Burman Noviansyah, VP Cyber Security at Telkomsel, said the Catalyst “delivers an agentic, governed, and fully autonomous security lifecycle” that can transform how CSPs detect, respond to and prevent evolving threats, from fraud and signaling abuse to sophisticated national-level attacks.

Faster response, lower cost and more trusted security decisions

The project team expects the solution to reduce fraud and signaling abuse losses, lower false positives, and decrease reliance on specialist security resources. Its business impact statement points to lower cost, faster response, more than 30% automation, and more than 95% pre-validated security changes.

For security teams, this means faster mean time to detect and mean time to respond, with more consistent decision making across domains. For operators, it provides a stronger basis for security assurance, helping demonstrate that decisions are governed, evidence-based, and aligned to defined operating intent.

For the wider industry, Telco AEGIS provides a practical model for applying agentic AI to telecom security in a controlled and standards-aligned way. It shows how autonomous operations can be extended beyond network management into threat prevention, validation, and response.

That wider value is significant as digital services become more dependent on trusted connectivity. By making security actions more transparent and verifiable, the Catalyst supports more resilient networks and stronger confidence in the infrastructure underpinning enterprise, government and consumer services.