Zurück zum Blog

From Open Interfaces to Open Risks: Securing the Path to xG

Reflections from the xG-ALOE User Forum 2026.

Reflections from the xG-ALOE User Forum 2026

A forum built around real deployments

On June 24–25, 2026, the open enterprise networks community gathered at Fraunhofer IIS in Nuremberg for the first xG-ALOE User Forum, organized by the Fraunhofer-Gesellschaft (Heinrich Hertz Institute HHI and the Institute for Integrated Circuits IIS). The forum brought together users, system integrators, technology providers, and research institutions to share experiences with open campus networks and to look ahead to the evolution from 5G towards xG enterprise networks.

The format was intentionally designed to be practice-oriented: parallel tutorial tracks and expert-led sessions spanning regulation, O-RAN architectures, testing, monitoring, positioning, service quality and security. The exhibition area kept the conversation flowing between talks, with live demonstrations and plenty of opportunity for the kind of open exchange that only happens when vendors, researchers, operators, and end users share the same room.

The security slot: a joint session with the BSI

Under the title "Securing the Evolution to xG: Insights into 5G and Future Telco Network Security," Heiner Grottendieck (Head of Division SZ31 at the Federal Office for Information Security - BSI) and I, Felix Klement, combined a national-regulatory perspective with academic and applied research.

In the first part of the session, the BSI provided an insight into its 5G/6G Competence Centre and the TEMIS security laboratory in Freital. There, they have a carrier-grade test environment in which end-to-end networks from Ericsson and Nokia, alongside non-public Open RAN-based networks from Airpuls and CampusGenius, are operated side by side. The talk then turned to the heart of the matter: why the security of private 5G networks is actually important.

Our part of the session, entitled “From Open Interfaces to Open Risks”, focused on architectural aspects: how is the transition to open, decentralized networks changing the security landscape; what specific vulnerabilities is our research uncovering; and how operators can realistically assess and strengthen their security posture.

People need pressure to change and security is exactly that kind of change

One of the most honest moments of the forum came from the user side. In the panel on day 2, moderated by colleagues from brown-iposs, one conclusion stood out for its striking simplicity: most users just want "a better Wi-Fi." At a reasonable price, of course.

That expectation is the whole challenge in a single sentence. Security adds complexity. Security adds cost. It rarely shows up in a glossy demo, and it never makes the dashboard look greener. When the buyer's mental model is "Wi-Fi that just works", security is the first thing quietly traded away and vendors, competing on price and simplicity, are happy to oblige by shipping protective options switched off by default.

So why insist on it anyway? A few concrete points from the session make the case:

  • Standard-compliant is not the same as secure. 3GPP provides strong building blocks but many are optional, and vendors frequently ship them disabled. Disable user-plane integrity on a factory network, for instance, and an attacker who reaches the user plane can manipulate traffic and inject commands into machines while every dashboard stays "green."
  • The breach is often operational, not protocol-level. The way in is usually an unpatched VPN, a default credential, or a "trusted" LAN that extends core trust to the entire IT infrastructure of a factory or hospital, rather than via a sophisticated attack on 5G signalling.
  • Nobody is regulating your private network. The BSI/BNetzA Security catalog is mandatory only for public networks. Private networks fall outside it; de facto unregulated. As the BSI put it bluntly: if you run a private 5G network, you are the operator, and the responsibility is yours.
  • The consequences are physical. Production stoppages, property damage, personal injury, and theft of sensitive data are not abstractions when a private 5G core is wired into industrial or clinical systems.

The encouraging news is that operators don’t have to start from scratch. The BSI/BNetzA security catalog (which was created for public networks) is just as suitable as a ready-made blueprint for a private network and can be seamlessly extended to secure the open interfaces and cross-vendor supply chain associated with O-RAN. And this is precisely where the pressure for change is becoming more urgent: it is not slowing down on the path to xG, but is actually intensifying. Every step toward more open, more disaggregated, and more AI-driven networks brings with it additional interfaces, vendors, and control loops, and thus a larger attack surface that ultimately must be secured. There are a multitude of options and effective tools available for this, but they must be used. The security decisions an operator makes today form the foundation upon which the next generation will be built. Therefore, properly securing networks today is not a detour on the path to xG. Rather, it is the prerequisite for staying on that path.

Conclusion: security needs its seatbelt moment

If there is one idea I want readers to take from this forum, it is that security is a remarkably versatile topic and not only in the technical sense. It is shaped at least as much by external factors: economics, regulation, vendor incentives, and, above all, human attitudes. At its core, security is partly a societal problem. Before any security control matrix helps, people have to genuinely believe that security is needed.

The seatbelt is the analogy we keep returning to. Exactly five decades ago, almost nobody thought seatbelts were necessary; they felt like an inconvenience that solved a problem most drivers were sure they would never have. Today, buckling up is as automatic as putting on your socks in the morning and driving without a seat belt feels deeply wrong. Security in private networks needs exactly that transition: from a half-heartedly accepted add-on to something so normal and so obviously desirable that operating without it would feel just as unthinkable as driving without a seatbelt.

And it is worth being honest about the second half of the story: security is an iterative process that will never be fully "solved." The architecture of our systems keeps changing. The threat landscape keeps changing. Attacker capabilities keep changing. Even the very scope of what we mean by "security" keeps expanding. Yesterday it was signalling, today it is AI models and supply chains. Security has to evolve continuously, in line with everything it protects.

That is precisely the work we are committed to at CipherCell, and it is why alliances like xG-ALOE matter: they are where the ecosystem builds the shared understanding and the trust that the path to xG will depend on.


Interested in learning more about xG-ALOE? Visit xg-aloe.de. To talk with us about assessing and strengthening the security posture of your private 5G or O-RAN deployment, get in touch with the CipherCell team.

Alle Beiträge Kontakt aufnehmen