Page 1 of 1

SME Questionnaire Form - June 30

Publication Target Date: June 30


Submission Deadline: June 27


Article Working Title: Stop Treating the Network as a Trusted Utility: What OT Risk Owners Should Be Asking Their Telecom Providers


Editorial Brief: As industrial organizations adopt private 5G, edge computing, network slicing, and telecom-managed connectivity, communications networks are becoming a more important part of the OT attack surface. Recent campaigns, including the China-linked Salt Typhoon intrusions, have shown how telecommunications infrastructure can become a strategic target and a potential pathway for broader cyber operations.

As operational dependence on external connectivity grows, OT risk owners need to look more closely at security visibility, incident response, contractual accountability, resilience, and regulatory exposure. The question is no longer whether telecom networks support industrial operations. It is whether they are being governed, monitored, and tested as part of the cyber-physical risk environment.

About you

First Name

Last Name

Company/Organization

Job Title/Designation (to be used in feature)

Business Email

Short Bio

Upload headshot (JPG/PNG up to 5MB; Square 500×500px, 300 DPI recommended)

Question Set

As industrial organizations increase their reliance on private 5G, edge computing, network slicing, and telecom-managed connectivity, what cyber and operational risks should OT asset owners be adding to their risk registers?

Where do you see industrial organizations underestimating their exposure to telecom-related cyber risk, particularly when connectivity is treated as a background utility rather than a critical operational dependency?

How should cybersecurity responsibility be divided between the industrial operator and the telecom provider when operational communications depend on carrier-managed infrastructure or services?

What questions should critical infrastructure operators be asking telecom providers about security architecture, segmentation, visibility, incident detection, and resilience before relying on them for operational communications?

If a telecom provider or carrier-managed network is targeted by a cyberattack, what information and support should industrial asset owners be entitled to receive, particularly when operational communications or safety-critical processes may be affected?

As industrial environments become more dependent on external connectivity and telecom-managed services, what practical steps should OT risk owners take to ensure these networks are governed as part of the cyber-physical attack surface rather than treated as trusted utilities?

Thank you for your response!