The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/AI & Data/The Network Effect Video Podcast by Nokia
The Network Effect Video Podcast by Nokia artwork

Hit back on latest cyberthreats

The Network Effect Video Podcast by Nokia · 2025-10-08 · 19 min

0:00--:--

Key moments - from our scoring

Substance score

31 / 100

Five dimensions, 20 points each

Insight Density8 / 20
Originality4 / 20
Guest Caliber9 / 20
Specificity & Evidence4 / 20
Conversational Craft6 / 20

Telecom network security extends far beyond telecommunications - a single compromise can disrupt banking, emergency response, and enterprise operations at national or global scale. Cal Day explores how recent attacks in Europe, Asia, and the US demonstrate the enormous attack surface created by interconnected systems and the critical importance of designing systematic resilience. The discussion covers how threat actors have professionalized, now executing sophisticated DDoS attacks, ransomware campaigns, and AI-enhanced phishing at scale before detection is even possible. Day emphasizes that defenders must adopt automation, zero trust architecture, threat modeling, and real-time observability rather than relying on single-vendor solutions. Industry collaboration around threat intelligence sharing and consistent regulatory standards - including responsible AI adoption - emerges as essential. The episode addresses CISOs and infrastructure operators managing critical systems, offering concrete guidance on network segmentation, red teaming practices, autonomous detection and response, and building business continuity plans that account for inevitable failures across multiple vendor ecosystems.

Key takeaways

  • →A single telecom network breach or software failure can cascade across industries and affect millions of users, making cross-vendor backup systems and business continuity planning essential rather than optional.
  • →Modern threat actors are professional organizations using automation to execute DDoS attacks and deploy ransomware in minutes, requiring autonomous detection and response systems rather than manual SOC operations.
  • →AI is a double-edged sword enabling both faster, more convincing phishing attacks with deepfakes and more sophisticated threat modeling by defenders, making real-time autonomous response increasingly critical.
  • →Zero trust architecture combined with threat modeling, red teaming, and identity-based observability allows organizations to detect anomalous behavior and respond faster than attackers can escalate.
  • →Industry-wide threat intelligence sharing and consistent regulatory standards around security investment and responsible AI adoption create a rising tide that benefits all operators and enterprises.

Guests

Cal Day

Topics in this episode

Network segmentationBusiness continuity planningZero trust architectureRansomwareThreat modelingAI-powered threat detectionDistributed Denial of Service (DDoS)Red Teaming and Blue TeamingAutonomous Detection and ResponseDeepfake Phishing Attacks

Questions this episode answers

What was the impact of recent telecom network breaches mentioned in the episode?

In Europe, a telecom attack disrupted mobile and emergency services; in Asia, identity theft affected tens of millions of SIM cards requiring replacement; in the US, breaches of lawful intercept systems created national security issues.

How fast are modern DDoS and ransomware attacks executed?

Distributed denial of service attacks are now mounted and executed with automation in minutes, often before sophisticated tooling can detect what is happening.

What role is AI playing in both cyber attacks and defenses?

Attackers use AI-generated content for convincing phishing and deepfake voice attacks that raise success rates at scale, while defenders use AI to predict attack paths, detect vulnerabilities, and automate response mechanisms at speed and scale previously impossible.

What is the most important security priority Cal Day recommends for the next 12 months?

Make a concerted investment into security and resilience across every part and layer of the network so that when failures occur - cyber attacks, outages, supply chain failures - there is a systematic ability to detect, respond, recover, and restore business operations.

How should organizations approach network segmentation and ransomware defense?

Strong network segmentation is essential because ransomware spreads rapidly once attackers gain entry; threat modeling in advance combined with well-curated automated response mechanisms enables faster remediation when ransomware is detected.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

8 / 20

The episode touches on real issues - AI-accelerated DDoS, autonomous response, and the blast radius of supply chain failures - but the ratio of actionable insight to filler is poor. Large chunks are spent on boxing metaphors and restating the obvious ('you cannot protect what you cannot see'), leaving little that a working CISO or ops leader wouldn't already know.

distributed denial service. These are now getting bigger, they're getting faster than ever before...executed with automation over in minutes before it's even possible to...detect what is going on
human perception itself is an attack surface

Originality

4 / 20

Almost every frame here is recycled industry boilerplate: the AI double-edged-sword, the weakest-link adage, the rising-tide-floats-all-boats metaphor for collaboration, and generic zero-trust name-dropping. There is no contrarian claim, no first-principles argument, and no take a smart operator wouldn't have heard dozens of times.

It's a double edged sword. Right?
your chain is as strong as the weakest link

Guest Caliber

9 / 20

Cal Day is a legitimate Nokia security practitioner with apparent carrier-grade network experience, not a career thought-leader, which gives the role credibility. However, the answers stay consistently at a conceptual level and never demonstrate deep hands-on scar tissue or decision-making authority at scale, limiting how much the caliber shows through.

the threat industry, and I use the term industry intentionally here...they are professional grade...professional organizations with a vast ecosystem that they can draw on
there needs to be, you know, mechanisms in place for uh, red teaming, for blue teaming that allow the SOC to use this modern technology

Specificity & Evidence

4 / 20

Every real-world incident is deliberately anonymised: the Europe outage, the Asia SIM theft affecting 'tens of millions,' the US lawful-intercept breach, and the 'endpoint issue' (almost certainly CrowdStrike) are all referenced without a single named company, date, or dollar figure, making it impossible for a listener to verify or build on anything said.

recently uh in Europe, ah, a telecom attack disrupted mobile and emergency services. In Asia we've seen identity theft, uh, affect tens of millions of SIM cards
what was just an endpoint issue...it cascaded across several industries. It affected aviation, it affected healthcare, it disrupted financial systems

Conversational Craft

6 / 20

Questions are competent scene-setters but uniformly broad and never followed up with a probe for specifics; when the guest waves at an unnamed 'endpoint issue' or an unnamed European attack, neither host presses for names, numbers, or lessons. The Simpsons riff is charming but symptomatic of a chat that prioritises banter over extraction.

What have been the biggest shifts in telecom cyber threats over the past year or so and what's driving them?
It reminds me of the quote from Simpsons on Beer. You know, artificial intelligence is the cause of, in the solution to all of our problems.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Share of words spoken

  • Speaker B79%
  • Speaker A13%
  • Speaker C8%

Most-used words

threat12network11security11attack10across10attacks9industry9operations8single8response8systems8cyber7degree7scale7faster7telecom6

Episode notes

Cyber breaches are never far from the news and, as Nokia releases its latest Threat Intelligence Report, Kal De, SVP of Product and Engineering for Cloud and Network Services at Nokia, talks to the Network Effect about the current threat landscape and what businesses should focus on right now.

Full transcript

19 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Hello, I'm Michael Hainsworth. Hollywood loves to show cyber attacks like sucker punches. Hack email here, a frozen laptop there. Today though, in a hyper connected world, one well placed shot to the telecom network can send banking, healthcare, even emergency services to the mat. Meet Nokia's Cal Day.

Speaker B: Make a concerted investment into security, building resilience into every part, every layer of the network and operations so that in the event that something goes sideways, there is an engineered systematic ability to detect, respond, recover, restore business operations. Be that a side of cyber attack, be it an outage, be it a supply chain failure, I would make that as security, as the cornerstone part of reliability and business continuity.

Speaker A: On this edition of the Network Effect, we'll explore how a single failure can ripple across entire economy. How AI is both throwing punches and blocking them. Plus why industry collaboration is the only way to go the distance.

Speaker C: Cal network security is a matter Beyond Telecom.

Speaker B: Oh, 100%. I mean um, the thing Michael, is that when telecom networks are breached, um, it's not just calls that are affected. Uh, the service outages, data leaks can be extraordinarily disruptive across industries. Banking, emergency response, business operations, it can affect millions of users. Um, for instance just recently uh in Europe, ah, a telecom attack disrupted mobile and emergency services. In Asia we've seen identity theft, uh, affect tens of millions of SIM cards needing to be replaced. Uh, and in the US we've had uh, breaches around lawful intercept systems, um, that make it really a national security issue. So it's really about the degree to which all things are connected. Uh, you know, how that's powered but influenced by the telco core that makes the attack surface enormous, um, and affecting enterprise identity, the safety of public systems and so on and so forth. So it's a big, big problem space.

Speaker C: Tell me about those solutions though. You mentioned problems in Europe can lead to troubles in Asia. What kind of lessons should enterprise take away from recent outages that disrupt critical services?

Speaker B: Yeah, 100%. So you know, I think it starts with um, recognizing that a single breach, a ah, single software failure can have a massive blast radius. The effects can be national, at uh, national scale or indeed at global scale. Um, so if we think about what happened recently, uh, with what was just an endpoint issue, uh, uh, but that particular issue, uh, that was in the public news, um, really had a very damaging impact, um for thankfully a short amount of time. But it cascaded across several industries. It affected aviation, it affected healthcare, it disrupted financial systems. So I think you know, from a lesson standpoint the first thing to Recognize is that a single attack can have a very, very broad blast radius. And so business continuity systems, backup systems that don't just focus on a single vendor space, but that we're really cross cutting across multiple vendors can help restore services, restore, you know, business operations, keep things up and running even when one particular provider fails. And you know, assuming that um, provider failure, you know, is at some point inevitable, um, it is important to have institutionalized, well curated practices as to how quickly um, a given operator can respond, ideally with automation and you know, choosing security tools that really are, I wouldn't say bespoke but are well tailored to by design, a ah, particular environment, overly invasive solutions. On the other hand, you uh, know, open up new risks. And so it's very, very important to stay to the leading edge, Stay close to the leading edge. And so simple upgrade maintenance, uptime procedures, um, are things ah, to pay a lot of attention to.

Speaker C: Yeah, I wouldn't give CISO's troubles to a monkey on a rock. You know, it was not that long ago that we would be talking about ransomware as the big threat. What have been the biggest shifts in telecom cyber threats over the past year or so and what's driving them?

Speaker B: Yeah, well, you know, um, the threat industry, and I use the term industry intentionally here. Um, they are professional grade, uh, unfortunately, um, they're very good at what they do. Um, I would characterize, you know, the quote unquote best. Most advanced threat actors being professional organizations with a vast ecosystem that they can draw on, um, attackers themselves, bad actors are getting more and more patient. Um, it's not just a smash and grab type, you know, motion. Um, they are sticking around for a long, long time, um, you know, months or more. Um, and you know, the kind of attacks that we see, you know, especially the common ones that you know, take advantage of the distributed nature of you know, carrier grade networks mounting DDoS type attacks, distribution, distributed denial service. These are now getting bigger, they're getting faster than ever before. Um, and they're often over you know, like they're mounted and you know like executed with automation over in minutes before it's even possible to, without mature sophisticated tooling to detect what is going on. Um, and this entire, you know, situation is obviously being significantly made worse by AI now, you know, a ah, new vector in this whole equation that makes it far easier for attackers to craft sophisticated convincing points of entry, um, do exploit vulnerabilities in new and kind of interesting ways. Uh, for instance, scams, phishing, uh, attacks that leverage AI and they're adapting their tactics on the fly. So uh, the good news is that uh, the cyber industry is fighting back. Uh, also leveraging AI uh to spot, uh, subtle threats, to detect vulnerabilities and automate responses. And therefore, you know, really the whole ethos has now got to be constant observability and response in real time, ideally, predictably.

Speaker A: Every fight starts with feeling out the opponent, quick jabs, testing for weak spots. Cal has shown us how a single strike against the telecom network can ripple across industries, exposing just how wide that attack surface really is. But once the bell rings for the next round, the fight escalates. Now ransomware, AI driven attacks, all of these things are heavy combinations designed to send entire sectors to the mat.

Speaker C: What do recent ransomware attacks on critical infrastructure reveal about systemic vulnerabilities?

Speaker B: One thing again we should remember, right? Um, an attacker only has to succeed once, you know, it goes down to the uh, you know, the old adage of your chain is as strong as the weakest link. A single vendor compromise or a single overlooked aspect of the system can disrupt the whole network or entire sectors. It's not just the initial target. And once inside, um, by design, the ransomware often spreads rapidly, right? So increasing the blast radius, uh, because many organizations, you know, just to say something very basic, lack m strong network segmentation. Um, essential services are very, very attractive for attackers because this creates a maximum disruption, it creates the maximum pressure, uh, for instance in a ransomware situation for a strong quick payout. So these um, things are, you know, the kind of systemic areas that it's really worth characterizing. Not just the attack surface, but doing threat modeling, um, that in advance gives um, a given enterprise, a given operator insight into what could go wrong. And then planning um, a carefully well curated automated response mechanism so that remediation can happen as quickly as possible.

Speaker C: You mentioned um, AI driven attacks, uh, and how sometimes the attack is over before we even knew it began. What does the rise of AI driven attacks mean for detection and response?

Speaker B: If we think about what, you know, modern generative technologies, you know, large language models are making possible, right? It's adoption across adversaries, it's multiple state link groups, um, that are experimenting and being able to model, um, you know, in an interactive way, new scenarios, new and you know, imagine new threat vectors that um, and they're doing that much more effectively, much faster than you know, what they've been able to do before. Um, if you consider Michael, human, um, beings represent a significant point of vulnerability. Human perception itself is an attack surface. We um, are Seeing um, the evolution of um, voice phishing attacks now leverage AI with deep fakes and they are really really good. So AI crafted phishing, uh, raises success rates uh, at a distressingly high degree. Um, they're more convinced, convincing uh, you know, they're you know, fundamentally able to you know, fool people, you know, much more effectively, much faster and at far greater scale than what we've ever you know, seen before. Uh, but you know, if we consider defense getting into AI, um, there are you know, systems now that predict potential attack paths, um, you know, shifting from the manual operations that you know, the SOC would leverage before to things that are far more autonomous. And again I say the speed of response and remediation um, is extraordinarily important. And the scale at which we're looking at these threat vectors, um, it cries for autonomy and to a certain degree for things to be autonomous, detection to be autonomous, response to be autonomous, remediation to be autonomous.

Speaker C: It reminds me of the quote from Simpsons on Beer. You know, artificial intelligence is the cause of, in the solution to all of our problems.

Speaker B: Right? It's a double edged sword. Right? Um, there are certain things that have now become possible and are becoming possible in ways that leverage um, automation and take it to the next level. Right? It is one thing to have a number of automation, um, a number of operations that are automated. It is an entirely different thing for to introduce true autonomy into the network. Um, this is now, you know, is becoming possible. Now we have to find safe uh, means to deploy this technology um, because the opportunity um, or the risk of error is enormous. Um so but you know, the industry is iterating rapidly, the advances are faster than we've ever seen before and the benefits will be proportional. That being said, um, the reality is on the, you know, unfortunate, you know, like hardline reality is that um, the threats are also going to keep pace with the opportunities. So it's a double edged sword, you know, like we are now going to be able to do things at a scale that we have never been able to do before. But uh, we're also going to have to realize that the risk factors, the threat vectors, um, are probably going to keep pace with those advancements and introduce the need to do things differently with a higher degree of um, focus on systems that are tailored, designed and engineered to meet those threats again, ideally, predictively, but at least with very, very fast response mechanisms.

Speaker A: In the fight against cyber threats, the first rounds are brutal. Ransomware lands heavy blows, weak links leave enterprises exposed and AI give hackers at a faster Jab. But defenders aren't standing still. They're learning to duck, they're learning to leap, they're learning to counter punch. So when the bell rings for the next round, collaboration may be the key. You need a good corner man or a woman to keep us in the fight.

Speaker B: Threat intelligence must be actionable, right? It's one thing to have. It is entirely true that, um, you cannot protect, um, what you cannot see. And you know, for carrier grade networks that have planetary scale, that have nationwide scale, that are vast, that are complex, um, covering voice, data, transport, access, um, we are talking about systems that have evolved over time and become more complex, not simpler. Um, so it starts with, yes, visibility. It starts with, you know, threat modeling and um, threat intelligence. But it is extraordinarily important that it not just be a dashboard, um, that it has to enable the SOC with yes, a great degree of visibility, but things that allow them to go, if uh, you like, on the offensive proactively. So there needs to be, you know, mechanisms in place for uh, red teaming, for blue teaming that allow the SOC to use this modern technology to constantly be not just vigilant but, but rehearse practice. Um, you know, like the response mechanisms to these unusual patterns, suspicious behaviors. Um, there needs to be a very, very close, uh, you know, eye on, um, leveraging identity through, you know, zero trust patterns, um, that allow not just defense in depth, um, but really observing, given the Persona, given the activities that that Persona is engaged in, um, what are suspicious behaviors, what are unusual patterns and being able to have rehearsed mechanisms and tooling that allow the combination of insights across the organization to build a fuller picture that can be responded to faster when something anomalous is detected.

Speaker C: And this isn't something that can be done solo. So how does the industry collaborate to uh, play a role, working together to defend against systemic risk?

Speaker B: Correct. Uh, look, m. You know, Michael, I think there's very fortunately and um, very beneficially for everyone, um, a hardened security posture and better, um, understanding of how the threat landscape is evolving is a rising, rising tide that you know, I think everybody agrees, floats everyone's vote, right? It's in everyone's interest, uh, for companies, industry, you know, defense, uh, industry verticals to share threat information. And indeed this is happening across companies, across sectors that basically makes everybody more aware, everybody smarter. Um, I think there's an opportunity and I think this too is broadly recognized that um, the regulations that are being developed, um, from you know, standards bodies across the world, um, government agencies that um, are pushing for a higher Degree of transparency and cooperation is entirely to everyone's benefit. To make collaboration and embrace that, you know, trend pattern, to make collaboration a necessity. Right.

Speaker A: Um, but how do you balance regulatory

Speaker C: compliance with the need for innovation?

Speaker B: Innovation in the absence of um, being able to do it safely is extremely hard. And I think it is important that um, there be a consistent approach, um, to how investment is made into security, hardening of posture, responsible innovation, let's put it that way. Right. So let's take an example. You know, the adoption of AI has to be done in ways that do not compromise the security posture, uh, of industry, enterprise or networking. Right? This is what regulation is ideally designed to do, the embracing of regulations with consistency and sharing. How do operators, how do enterprises um, build product, innovate, um, while paying attention to um, security, responsible AI. This is to everyone's benefit. And so I think, you know, these are two sides of the coin. And doing it collaboratively with transparency and cooperation benefits everyone. Everybody gets smarter and everybody does it to a certain degree, consistently.

Speaker C: If you had to pick one key priority for the next 12 months, what would it be?

Speaker B: If I had to pick one key priority for the next 12 months, it would be to make a concerted investment into security, building resilience into every part, every layer of the network and operations so that in the event that something goes sideways, there is an engineered systematic ability to detect, respond, recover, restore business operations, be that a side of cyber attack, be it an outage, be it a supply chain failure. I would make that as security, as the cornerstone part of reliability and business continuity.

Speaker A: Cal's message is clear. This isn't street brawl, it's a heavyweight title fight. Cyber threats, they keep coming at us from every angle. They're faster, they're harder. And now we've got AI adding more power to every swing. The only way to last all 12 rounds is to build resilience into every layer of the network to protect economies, public safety, trust as well. And as Cal reminds us, the next punch, it's inevitable. At the end of the day, the organizations that will still be standing are the ones that train for the hit, guard for their vulnerabilities, and know when to counter with an AI of their own. And that's called the network effect. I'm ah, Michael Hainsworth. Thanks for stepping into the ring with us.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Mythos And The Disappearing Patch WindowAI Proving Ground Podcast · on Network segmentation96 / 100
  • From Compliance Theater to GRC Infrastructure: Why AI Breaks Traditional GRC ft Jasmine Kaur, Principal of Security & Assurance Engineering @ CoreWeaveSecurity & GRC Decoded · on Threat modeling96 / 100
  • How GTT Rebuilt Global Security For The AI EraWhat's Up with Tech? · on Zero trust architecture91 / 100
  • Operational Resilience, Risk Management and Crisis Decision-Making with Bruce McIndoeRiskMasters · on Business continuity planning87 / 100
  • How Zalando Deployed GenAI Without Handing Attackers the Keys with Florence MottayCyber Leaders · on Ransomware87 / 100
  • Canvas Breach Breakdown: What 9,000+ Outages Teach Us About SaaS RiskSecure AF · on Business continuity planning85 / 100

More from The Network Effect Video Podcast by Nokia

All episodes →
  • Today's next generation factory
  • Data centers and the AI era
  • The next big thing in voice
  • Smart grids are critical to net zero
  • Business at the speed of light
Explore the best B2B AI & Data podcasts →
All The Network Effect Video Podcast by Nokia episodes →