Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Forinet: Sovereignty, AI & Quantum: Top Telecom Security Challenges

Fortinet
06/18/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


provider ecosystem, recording live here at Mobile World Congress, Barcelona, 2026. From securing AI, adoption to threat intelligence, business strategy, security operations and value-added services, we bring expert insight to help service providers grow, stay resilient and ahead of the curve. So let's dive in. I'm your host, Ronan Spira, Director of Telecom Solution Marketing here at Fortinet, and I'm joined today by Filippo Cassini from Fortinet, our own. Filippo, great to have you on the show. Thank you for joining us. Thank you for having me. Great. You meet tens or hundreds, maybe I exaggerate, operators across the globe every year. What would you say is their key three challenges today? Well, considering the current situation, what we hear talking about a lot is sovereign. I start with sovereign because then the other one, which is AI, comes kind of connected because you want to have sovereignty and you want to be able to apply that sovereignty to AI as well. And then quite a bunch of conversation about quantum. Okay. So sovereignty, AI, quantum. In the order you like. Okay. Great. So let's start with sovereignty. Sovereignty. Okay. So what are the key requirements and concerns that are driving sovereignty for telecom operators? Well, I would say different regions across the planet bring up different challenges or different requirements. In the most simple form, this is an upgrade of a set of security controls that companies that telecommunication service providers should implement. Most of them do already. Some of them are in the guiding light. Some of them kind of follow up. But in general, there's a global understanding across the telco world that these are critical infrastructures. They need to be protected. And then the sensitivity to that protection apply to kind of the political environment, if you want, or the different geopolitical, let's say, situations. And eventually those turns into different level of implementation, right? So you have security controls that requires you to do different things, and this becomes technical requirements and things you need to implement in different ways, depending on which country you are. Right. What about the enterprises' requirements? Because service providers provide services to enterprises, so there's this pressure coming in from the customer side, from the enterprise side. Yeah. I mean, there are specific regulations that apply to the service providers themselves. In certain countries, these regulations regard the kind of connectivity services they offer, the kind of facilities they offer to the government. And so this folds particularly to the CSPs. Some of them apply to the enterprise, yes, especially when these enterprises are considered critical. So they get an extra set of regulations that they need to comply to in cyber. Okay. So sovereignty driven by, first of all, regulations and internal needs, but also the customer demands based on requirements. So let's move to the second one you mentioned, which is, well, the third one you mentioned is AI. So we've talked a little bit about AI. I haven't had a chance to tour the event yet, but I'm sure that everybody's talking about AI. Everybody's talking about AI. So how do you see AI deployments actually happening today in server providers? Is it proof of concept on Linux, or is it really in production? Oh, I don't know. There's a lot of... First of all, I love to make distinctions inside the AI, let's say, ecosystem. As everybody knows, the basis of AI is these neural networks, this learning, self-learning kind of... Elon Musk calls it an Excel matrix of infinite complexity. Some of them is simply used as algorithms that helps you take the right decision. Some of them is actually what everybody uses in their phone, which is basically an LLM. And a lot of simpler implementations can be a chatbot, can be an application extensions that help you fill up form automatically. This is what we see more and more. So as far as a company is concerned, this is AI that sometimes it's hidden. So you acquire an application and suddenly this application starts using AI inside, but you have no knowledge of it. So that brings challenges, of course, with data, like how trusted this application is, because who is the third party providing the AI function, et cetera, et cetera. So this is like second level, am I aware of how much AI I have in my company? That's the most simple point of view. There are companies that are actually using it to develop extension. So some of the companies we talk to, say, for example, in industry, they may use algorithms for optimizing the product, make the product faster, make the product more efficient to do certain things. Or they may use AI against an LLM extension to help the user make it more productive. That's what we are doing, for example, in our management products and by extension in many others in the future. And then there is the third one, which is infrastructure. These are where many CSPs have been investing, which is basically GPU farms, AI farms, whatever you want to call it, which have, of course, the advantage of being sovereign whenever the telco implements locally because they can be provided as a service, particularly to government. It's like my easiest case is the government wants to use an LLM to extend like tax advice. You want to do it on a, you know, locally, of course, you don't want to ask for tax advice for an LLM running in a country that maybe become adversary one day. Exactly. Right. So, yeah, exactly. This is kind of like high level. And by the way, do you find that these concerns and implementations are common to enterprises in telcos or service providers or something which is different and unique in a service provider environment? No, I think the telcos have all the three levels, right? Because they offer it as a service, they use it, they productize LLMs to help their own users, etc., etc. So I would say telcos is where you find the whole ecosystem. They have the entire AI stack. Yes. And maybe different teams are actually dealing with it. Yeah. Yeah. OK. So I think we see a lot of this kind of, and especially maybe, you know, one of the challenges about AI is the fact the models are evolving super fast. So you have an R&D department that is kind of playing with them, that is testing them. And you have probably a red, you know, how do you call it? Oh, got stuck. A red team. Red team, yeah. Just testing. Exactly. And this is also, you know, where a lot of these tests need to be automated, you need to make sure that you find the right, and then market is coming back, say, I want it to be agentic. Yeah. Or you've got to upgrade the model, see what it means, what are the security challenges. So if you look at, you know, the transition between the start of AI and how agentic has come about, and then MCP and so on, it's kind of asymptotic, right? Right. Right. It's going. Yeah. So that's a challenge. Yeah. And it requires continuous innovation, continuous adaptation, continuous upgrade of security challenges. And do you think that there is enough AI risk awareness, or are they aware to the risks that are associated with actually deploying all of this through the stack, and are they aware of that? It's coming in real fast. You see, you know, the developers themselves warning you that they... Oh, the developers themselves. The developers themselves that develop tools today, they are warning you, you know, be careful what you do, because I'm giving you an AI plugged in into this, and I cannot guarantee that it's not going to misbehave, ruin your data, etc., etc. So the warning, it's the first time you see, like, the warning coming from the same people that developed the product. Exactly. Okay. So, last topic. Yes. Quantum. Quantum. Suddenly, I mean, quantum is not new, and this strategy of harvest and decrypt later, harvest now, decrypt later, is not new, we've known it. But there is a sense, and maybe I'm wrong, but you can tell me, there seems to be a sense of urgency suddenly about being quantum resilient, quantum ready. Do you, first of all, agree that this is the case? What drives it, and what are the available solutions? I think it's hard right now to, you know, having, you read papers, you read news, and, you know, this thing seems to be closing in. Maybe you don't get quantum, but you still get very powerful compute. You get machine learning, you get all this kind of fast increasing compute capacity, because you don't need strictly a quantum computer, you could do it, you could simulate the quantum computer behavior with some super powerful computer. And so, more than what we think is kind of the push we get from our customers. So in reality, all the implementations in quantum that we have done, we, you know, we just listen to what our customers are demanding. For example, in the case of PQC, post-quantum, even if the algorithms, I think, are still under evaluation, we have been pushed by the banking sector to, you know, start working on certain ones, because, you know, they employ their own mathematicians that kind of get their own level of confidence, and so tell us, okay, get this one done. So that's, you know, not much what we think even, it's what kind of push we get from our own customers. And then again, they are the ones that hold the information, they are the ones that knows how risky it is, they do their own risk assessments, and as usual, we listen to them. Yeah, exactly. So, just to summarize, before we end this, three top challenges, or key challenges, quantum sovereignty AI. Filippos, thank you so much for your insight and your time. Thank you for having me. And that's all for this episode of Fortinet On Air, recording live at Mobile World Congress Barcelona in 2026. Fortinet On Air is available on YouTube, on all podcast platforms and Fortinet TV.

TL;DR

  • Sovereignty has become the top priority for telecom operators globally, driven by evolving regulations for critical infrastructure and varying geopolitical requirements across regions that mandate different technical security implementations.
  • Service providers engage with AI across three distinct layers: hidden embedded AI in applications, purposeful productivity enhancements and service extensions, and infrastructure-level GPU farms offering sovereign AI-as-a-Service capabilities.
  • Quantum readiness urgency is accelerating beyond theoretical concerns, with banking and critical infrastructure customers conducting independent risk assessments and demanding post-quantum cryptography implementations ahead of formal standardization.
  • The rapid evolution of AI models—from basic LLMs to agentic frameworks—creates continuous security challenges requiring automated testing, red team validation, and constant adaptation as new capabilities emerge asymptotically.

Sovereignty as a Critical Infrastructure Imperative

The conversation opens with sovereignty emerging as the foremost concern for telecommunications operators globally. Filippo Cassini explains that sovereignty requirements vary significantly across regions based on geopolitical contexts, but fundamentally represent an evolution of security controls for critical infrastructure protection. Service providers face dual pressures: regulatory compliance requirements specific to their operations and connectivity services, plus cascading demands from enterprise customers—particularly those designated as critical infrastructure themselves. These sovereignty concerns directly influence how operators architect their networks, select vendors, and implement security frameworks, with different countries imposing varying technical implementation requirements based on their specific threat landscapes and political environments.

AI Deployment Across the Telecom Stack

Cassini distinguishes three distinct AI implementation layers within service provider environments. The first involves embedded AI that operators may not even be aware of—applications incorporating machine learning algorithms or LLM capabilities without explicit disclosure, raising data trust and third-party risk questions. The second layer encompasses purposeful AI integration for productivity enhancement and service optimization, from industrial process improvements to customer-facing chatbot extensions. The third represents infrastructure-level investments: GPU farms and AI-as-a-Service offerings that enable sovereign AI capabilities, particularly for government applications like tax advisory systems that require local data residency. Telecommunications operators uniquely engage with all three layers simultaneously, often with different teams managing each aspect, creating complex governance and security challenges as models evolve rapidly and new paradigms like agentic AI emerge.

Quantum Readiness Driven by Customer Urgency

While quantum computing threats have been theoretically understood for years, Cassini notes a marked acceleration in customer urgency around quantum resilience. This pressure stems not only from the prospect of true quantum computers but from increasingly powerful classical computing capabilities that could simulate quantum-level cryptographic attacks. Fortinet's post-quantum cryptography implementations have been directly driven by customer demands—particularly from the banking sector, which employs its own mathematicians to evaluate algorithm confidence levels and pushes vendors toward specific implementations even as standards remain under evaluation. The harvest-now-decrypt-later threat model has moved from theoretical concern to active risk assessment, with organizations holding sensitive long-term data conducting their own risk analyses and demanding quantum-safe solutions ahead of formal standardization timelines.

Chapters

0:00 - Introduction & Podcast Overview
0:50 - Top Three Telecom Challenges
1:32 - Sovereignty Requirements & Drivers
3:40 - AI Deployment Landscape
7:20 - AI Risk Awareness
9:00 - Quantum Readiness Urgency
11:21 - Closing & Podcast Information

Key Quotes

1:01 "Considering the current situation, what we hear talking about a lot is sovereign. I start with sovereign because then the other one, which is AI, comes kind of connected because you want to have sovereignty and you want to be able to apply that sovereignty to AI as well."
2:11 "There's a global understanding across the telco world that these are critical infrastructures. They need to be protected."
5:04 "You acquire an application and suddenly this application starts using AI inside, but you have no knowledge of it. So that brings challenges, of course, with data, like how trusted this application is, because who is the third party providing the AI function."
8:34 "The developers themselves that develop tools today, they are warning you, you know, be careful what you do, because I'm giving you an AI plugged in into this, and I cannot guarantee that it's not going to misbehave, ruin your data, etc."
10:30 "In the case of PQC, post-quantum, even if the algorithms, I think, are still under evaluation, we have been pushed by the banking sector to start working on certain ones, because they employ their own mathematicians that kind of get their own level of confidence."

FAQ

How do sovereignty requirements differ across regions for telecom operators?

Sovereignty requirements vary based on geopolitical contexts and political environments in different countries. While there's global understanding that telecom networks are critical infrastructure requiring protection, the specific technical implementation requirements and security controls differ significantly depending on the country's threat landscape and regulatory framework. Some regions have more stringent requirements than others, particularly around vendor selection, data residency, and government access to facilities.

What are the three layers of AI deployment in service provider environments?

The first layer is embedded AI that may be hidden within applications, raising data trust concerns. The second layer involves purposeful AI integration for productivity and service optimization, such as chatbots or process improvements. The third layer is infrastructure-level AI—GPU farms and AI-as-a-Service offerings that provide sovereign capabilities, particularly for government applications requiring local data residency. Telecom operators uniquely engage with all three layers simultaneously.


Categories:
  • » Webinar Library » Fortinet
  • » Cybersecurity » Network Security
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Cloud Security
  • AI & Machine Learning
  • Compliance & Governance
  • Network Security
  • Webinar
  • Digital Sovereignty
  • Telecommunications Security
  • AI Infrastructure
  • Post-Quantum Cryptography
  • Critical Infrastructure Protection
  • AI Risk Management
  • Regulatory Compliance
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Forinet: Sovereignty, AI & Quantum: Top Telecom Security Challenges

              Upcoming Webinar Calendar

              • 06/23/2026
                01:00 PM
                06/23/2026
                The AI-Powered VMware Alternative
                https://www.truthinit.com/index.php/channel/2009/the-ai-powered-vmware-alternative/
              • 06/24/2026
                11:00 AM
                06/24/2026
                LATAM: Accelerating Insights on AI Through an Engaging Webinar Series
                https://www.truthinit.com/index.php/channel/2012/accelerating-insights-on-ai-through-an-engaging-webinar-series/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/
              • 06/30/2026
                01:00 PM
                06/30/2026
                Mastering Active Directory Certificate Services for Long-Term Success
                https://www.truthinit.com/index.php/channel/2018/mastering-active-directory-certificate-services-for-long-term-success/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                How to Prevent Your AI from Taking Control of You
                https://www.truthinit.com/index.php/channel/2021/how-to-prevent-your-ai-from-taking-control-of-you/
              • 07/02/2026
                10:00 AM
                07/02/2026
                When the cloud goes dark: Resilience lessons from hybrid threats
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-when-the-cloud-faces-challenges/
              • 07/07/2026
                01:00 PM
                07/07/2026
                A Comprehensive Demonstration of DLP Solutions and Strategies
                https://www.truthinit.com/index.php/channel/2030/a-comprehensive-demonstration-of-dlp-solutions-and-strategies/
              • 07/09/2026
                01:00 PM
                07/09/2026
                Agentic Trust in Practice: Enhancing the Human Experience
                https://www.truthinit.com/index.php/channel/2026/agentic-trust-in-practice-enhancing-the-human-experience/
              • 07/14/2026
                11:00 AM
                07/14/2026
                Discover the Latest Innovations in Netwrix 1Secure During This Technical Session
                https://www.truthinit.com/index.php/channel/2014/discover-the-latest-innovations-in-netwrix-1secure-during-this-technical-session/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers Revealed at the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-revealed-at-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Insights and Strategies for Effective Data Privacy and Protection Practices
                https://www.truthinit.com/index.php/channel/2000/insights-and-strategies-for-effective-data-privacy-and-protection-practices/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                23

                The AI-Powered VMware Alternative

                06/23/202601:00 PM ET
                • Jun
                  24

                  LATAM: Accelerating Insights on AI Through an Engaging Webinar Series

                  06/24/202611:00 AM ET
                  • Jun
                    25

                    Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                    06/25/202601:00 PM ET
                    • Jun
                      30

                      Mastering Active Directory Certificate Services for Long-Term Success

                      06/30/202601:00 PM ET
                      • Jul
                        01

                        Schutz von KI in Anwendungen, Agenten und APIs.

                        07/01/202604:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version