Securing the digital supply chain

To embed our video on your website copy and paste the code below:

<iframe src="https://www.youtube.com/embed/dqwHcEebaUw?modestbranding=1&rel=0" width="970" height="546" frameborder="0" scrolling="auto" allowfullscreen></iframe>
Guy Daniels, TelecomTV (00:07):
Okay. Hello everyone. Welcome back to session five. If my math is correct, please do take a seat, make sure you've got your teas and coffees and soft beverages. Great. Good to see you all back. Thank you very much. Okay, session number five is securing the digital supply chain. So from semiconductors to software, we know that the technology supply chain is under a high degree of scrutiny. So how can telcos and their partners reduce the dependencies, increase transparency and strengthen domestic and allied supply capabilities to support their sovereign objectives? What are the trade-offs between global efficiency and local resilience? Hopefully that gets us in the mood. We have two guests with us this afternoon, so I'm going to ask them to introduce themselves starting on my immediate right. Oh, and I've got to say, when you speak, please press the little button in front of you.

Raman Mistry, GSMA Open Gateway (01:11):
Thank you guy. Pleasure to be here. Great to meet you all. My name's Raman Mistry, I'm the channel partner lead for GSMA Open Gateway. The channel partner program is a broad church. We have aggregators, CPAs, vendors, hyperscalers system integrators that encompasses and they typically will work with operators or take network APIs from operators and expose them and build innovative new services around that. So my background is mostly been in software, so application development platforms, no-code platforms and ai, but it's also been married with a lot of telco value chain involvement as well.

Beth Cohen, Luth Computer (02:00):
So I'm Beth Cohen and I'm independent having retired from Verizon officially in December and came back as a consultant, which is kind of cool. It's probably the best of both worlds and I've been in the industry for mumble mumble years. Going back to my time at Bolt, Brannick and Newman when I ran the advanced networking labs and was involved in some of the early standards bodies. IETF. The VPN standards has got some of my fingerprints on it. And also my interest in security is I teach security at the college level and I am a big proponent of networks and security really need to be two sides of the same coin. So looking forward to this discussion.

Guy Daniels, TelecomTV (02:55):
Thanks very much Beth and Raman. You're going to give us a three minute introductory talk, so I'll leave it over to you.

Raman Mistry, GSMA Open Gateway (03:03):
Thank you very much, guy. Yeah, as a channel partner lead for open gateway and I work closely with GS MA Fusion, I have the privilege of seeing the side of the telecom's ecosystems that rarely features in traditional supply chain discussions, the role of open programmable interoperable networks that can actually help protect national digital sovereignty. We often talk about sovereignty in terms of hardware and rightly so. Who builds the radio, the manufacturers, the semiconductors. In the previous discussion we talked about protecting energy resources through small nuclear reactors. So these are all essential. But in a world where capabilities are increasingly delivered through software, the virtualization of functions, the ability to access critical digital functions through open standardized interfaces rather than being tied to any single vendor region or propriety stack are things that are really happening. And this is where my role in GSM and Open Gateway infusion are making a strategic contribution.

(04:14)
Our fusion initiative works directly with enterprises, so it's asking enterprises and developers and vertical industry to understand the capabilities that they require to operate secure networks and innovative services. Those demand side requirements feed into GSM Open Gateway and GSM Open Gateway has over 290 network operators spanning over 80% of global connections. And these APIs are used for operators in a harmonized way so that they can be deployed consistently. So it's not about convenience for developers, but it's about creating sovereignty and resilience and risk reduction. So there's lots of services like anti-fraud, identification, quality and demand, which can be accessed through these open standards instead of closed interfaces. So nations and enterprises are no longer dependent on the propriety implementation of any single supplier and we're now entering into an era of AI where autonomous systems and cross border iot supply chains require trustworthy digital primitives. You've seen things like model context protocol, which Anthropic has delivered. It's an open framework or protocol and just recently we've had Google who've come out with their agent to agent protocol, which now they've open source. So these kind of developments are starting to liberalize the market and making sovereignty less of a national issue and more of a global issue.

(06:05)
And finally, I think the evidence is there. There's lots of initiatives that we're seeing within Open Gateway. It's a new frontier for digital infrastructure and open gateway infusion demonstrate that we do not need to choose between sovereignty and openness that can both work in harmony. Thank you.

Guy Daniels, TelecomTV (06:27):
Thank you Raman. Thank you very much for that. Got us all thinking before come to the floor for questions. There's a couple of questions we've been developing in advance and this morning was, I think it was Manish who spoke about supply chain choice. Supply chain has cropped up many times this morning in previous panels. I'm not surprised Beth. In fact maybe if I can come to you first on this one. What level of diversification in the supply chain, whether it's core or ran, what is the minimum required to achieve national resilience without incurring ridiculously high extra costs or risk technology fragmentation? How did telcos manage this trade off what we're talking about here?

Beth Cohen, Luth Computer (07:16):
So that's a very difficult question because supply chain is very complex, particularly for the telcos because we are dependent upon hardware vendors, we're dependent upon software vendors. Telcos are not software companies. I know despite what people think, we're technology companies and we're integrators, which is funny because I don't think the telcos are aware of just how much they're integrators, which means we're very sensitive to supply chain. And that's actually a big problem because, and I'll use the example of Huawei, which thank God Verizon never got into and the reason it never got into it was because it does a lot of government work and it was never allowed to use Huawei, but I know that many European operators got into it and some of the American operators got into it and it's a big problem now that people are dependent upon that single supplier. Now there are alternate suppliers to Huawei fortunately, but there are some single supplier type arenas I mentioned earlier this morning about sd-wan.

(08:32)
It's down to basically three operators at this point that develop have sd-wan and there's a couple other areas where it's down to one operator. I think WAN optimization is down to Riverbed, end of story security is there's a lot of security companies, but there's three main ones. So the digital supply chain, there's always that you have to balance the diversity against the efficiency against being dependent upon one operator or proprietary system. I'm a big proponent of open source and standards as a way of leveling the playing field to reduce the risk. But diversity also can mean a multiple vendors in Verizon, the company sells network diversity to Verizon means actually two carriers. That's how detailed it gets down to, oh, it's Verizon and another carrier. So it depends upon the level of risk a given customer wants to get to.

Guy Daniels, TelecomTV (09:58):
Great, thanks Beth. And as you say, it's a complicated question. It's a tricky question, very nuanced. Raman, what about you? Where do you think the operators and also government should focus their diversification efforts?

Raman Mistry, GSMA Open Gateway (10:11):
Just to carry on from Beth's point about integration being a key component, I totally agree with that and obviously integration is supported, but by having interoperable open interfaces, whether it's open source or open standards and along with other organizations like the TM forum and Amplify gsma are great proponents of that standardization and interoperable side of things. And I think again, to try and avoid fragmentation, that interoperability helps. I also agree with Beth in terms of having that plurality of companies that can address the needs of a network or needs of service environment is key to doing that. And again, going back to interoperable interfaces, but if you've got vendors that can talk to each other fairly seamlessly without too much friction, that is a key enabler for this environment.

Guy Daniels, TelecomTV (11:20):
Great, thanks so much Raman. Before I just take it to a slightly different question, any immediate feedback from the audience? Anybody want to Thierry? Yes. Thierry's going to press the button.

Thierry van de Velde, Nokia (11:31):
Okay, so supply chain, let's zoom into software because this is hardware and software as you said, but on software, the average of our customers, and I'm just dealing with core networks, luckily not with Rayos, they have maybe 5, 6, 7 suppliers at least for application software and middleware like cast layers, git, you name it. Right now the practice has been that the suppliers, people download that from a server somewhere in the supplier and they upload that to a local repository. When the project is finished, it's the operator themselves who do this manipulation. Now we are told that this is unacceptable, that we shall in fact deny the rights for employees of the operator to upload software in those repos because one day there will be rogue employees that will be paid in Bitcoin to upload some ransomware there in your repos right inside Verizon. So we are told to say no, secure that with A-C-I-C-D chain whereby it's a robot, it's A-C-I-C-D, it's a orb de calculator, right? OCI release bundle. You know what it is? It's an encrypted and secured package of software that will be opened by a robot inside your operator and that will be the one that has the rights to give us a secure unmodified image coming from the vendor. Okay. Question to you Beth, who will build this robot? Is it each one of these six suppliers or is it going to be Verizon

(13:21)
Building it?

Beth Cohen, Luth Computer (13:22):
That's a great question and I think the answer is the robot's not going to fix the problem. And I'll use it as example. The open source community is already being attacked by the rogue states. So there was a major incident a couple of years ago where I think it was North Korea actually unbeknownst to a lot of people in North Korea is actually really good at cyber crime. And in fact apparently much of their government revenue comes from this and was they became part of the build team for some particular piece of very critical software in the open source community and the inserted rogue software into that chain. And that's a big problem. And building robots isn't going to fix that problem

Thierry van de Velde, Nokia (14:22):
For sure. So the suppliers, right, we also have a responsibility when we pick something from open source and there happens to be a ransomware in there, we will be held accountable because we are distributing this open source. Same for Red Hat by the way. Everything is open source at Red Hat and it's then distributed. So that's not the question. The question is, should the employees of the MNO be able to choose which software makes it into the network?

Raman Mistry, GSMA Open Gateway (14:54):
Isn't that usually a decision that the CTO or CIO or head of digital would make rather than an employee

Thierry van de Velde, Nokia (15:02):
Purchasing? Of course, yes. But the actual software image that can contain this malware, if it comes from a rogue employee who has modified this image, then we have a serious problem in our digital supply chain, which is the title of this debate, right

Beth Cohen, Luth Computer (15:19):
Jerry? Yeah, you do have a serious problem and I don't think there's the proper guardrails in there. I mean it's the responsibility of both the supplier as well as the telco to keep the software clean. I do know that many of the telcos, including Verizon, have private instances of a number of the pieces, pieces of software that are used for the development process, which does cut down to a certain extent the amount of wrongness that can happen. But you're not going to stop a rogue employee. That's the bottom line.

Raman Mistry, GSMA Open Gateway (16:02):
It also has to do with internal processes, the CICD processes that we have and making sure you've got robust processes in place to stop that from occurring.

Guy Daniels, TelecomTV (16:13):
Great. I'd love to bring in Diego on this one. Can you come in Diego?

Diego R Lopez, Telefonica (16:16):
Yeah. Well it's more recommend kind of question. It's something that I, things times are changing. This is something that we cannot and we have to live with that it's true that this industry has been around for 100 and something years. We came 100 all last year and we are very much used and the procedures that we are used, our used are very much related to physical stuff, but in the past still we were very much depending of humans that were switching and then we get used to automatic switching and then to electronic switching and the store program changes and things like that. And we learn to do that and confident that we will learn to do that. The point is that there is ongoing work, the problems with these digital supply chain and everything and how do you relate to the responsibilities of who is doing what and where is something that is a problem that is currently active in many other places. And there are heavy investments by governments and by big corporations outside the telco space about this and working on how you can define digital noties evidence that can be used automatically used and at the same time that provide evidence in case of a dispute and you go to the courts in Delaware to sort out the whole thing and we are trying to solve it. It is an issue, I agree, but it's something that we need to work on that

Guy Daniels, TelecomTV (17:56):
We're working on it. Thank you Diego. I do want to move on because you've taken this quite nicely to another question and I'm aware of time and we had a billion dollar question this morning I believe, but we've got another billion dollar question coming up and that is we do hear talk about the potential to create domestic semiconductor software, supply chain, what have you in countries outside of the US or China and whether or not government should focus on supporting this and creating sort of niche strategic components or should they look at a whole end-to-end manufacturing capability. What's the reality of this, Beth? I know you've got very strong views on this, but I've got good feeling that maybe this isn't a realistic proposition.

Beth Cohen, Luth Computer (18:47):
I think the train left the station a long time ago for all the talk about bringing semiconductor manufacturing back to the us. That's a pipe dream that literally never existed. I actually recently read an article that said the peak a US domestic production of semiconductor chips was like in the nineties and it was like 38%. So it was never even the majority. So I think the reality is that that's, that's impossible. It's not cost feasible. It is a global supply chain. It takes a lot of countries to build a cell phone. It takes a lot of countries to build a router. It takes a lot of countries to build a computer and that's just the reality and we have to live with that and getting to rare earths, it is just random where the rare earths are actually kept in random countries ended up getting hit the jackpot so to speak. I think that unfortunately the geopolitical instability right now is a problem, but we can't solve it by just trying to bring the manufacturing back to be local and certainly outside of, I don't think there's any country actually including China that can do it themselves.

Raman Mistry, GSMA Open Gateway (20:22):
Thanks both. I would agree that, I mean I think that's such a tall order to try and establish the whole value chain within one country, especially when things are moving away from pure hardware and into software. As my opening remark talked about virtualization of functions and putting them into software. So I think there'll be more liberal framework through, as we said about network APIs and open programmable interfaces. So I think it probably wouldn't make any economic sense for anyone to own that whole supply chain. And I think the reality of the market and the way things are going is you want to have a level of interworking with other countries and organizations as well.

Guy Daniels, TelecomTV (21:19):
Thanks very much Raman for that. Now just before we move on, I do like to keep an eye on opinions and trends from outside of the telecoms industry. And I think I can use the clicker for this myself. I can use the clicker. So this came into my inbox this week from one of the substack I follow. This is from, I dunno if you're aware of it as as ours exponential view. If you're not, it's a well recommended read the free or paid, but he was putting together a thesis here on sovereign ai and what just caught my eye here was as he's determined it there, the sovereign AI stack, which includes infrastructure there in the middle, but it also below that silicon and of course energy generation at the bottom, power generation and grid, which I know Dean mentioned earlier on. And obviously above that the foundational models and data and the trends from various nation states to up their infrastructure programs to build out that capacity to a greater or lesser degrees. And in the course of discussion this, and as I say, it's well worth looking at if you can, it came up with a line which I've just pulled out. I quite like this line. I haven't got my head around this yet. The era of the borderless internet has come to an end. The era of the sovereign stack has begun discussed. So slightly leading remark there, but any comments from the floor about this so far? Dean, that's good to you.

Dean Bubley (22:52):
That sentence just kills the idea of 6G AI native dead.

Guy Daniels, TelecomTV (22:59):
Oh, that's another one to get your head around. Say that again Dean, because we don't think the rest of the room digested that properly. Can you

Audience member (23:04):
Phrase that as a question?

Dean Bubley (23:09):
Yeah, exactly. Discuss. No, I mean essentially what that says is that the idea of a single global standard for AI is almost impossible and therefore the idea of a single global standard for AI native 6G is equally impossible if not more. And I think that's a major issue because you've just highlighted the fact that there's going to be all sorts of different sovereign interventions, which completely, I mean to be honest, it will mess with all standards which are in telecoms, which are AI dependent. But I'm picking that one out because it's something I've been looking at recently, but that just clarified it, that stack.

Beth Cohen, Luth Computer (23:58):
Can I comment on that? So you bring up a great point, but the fact is the telecom industry relies on standards. It can't run without standards. And I live the development of the standards, right? I worked for both Branick and Newman back in the nineties when we were developing the standards that are underpin the entire telecom and internet stack. So to go back to being sovereign and saying, oh, well we're going to do it our little way every single little country, it's just unfathomable. You just can't do it.

Raman Mistry, GSMA Open Gateway (24:38):
Yeah, I agree. I mean that just leads to fragmentation. It doesn't help the industry grow, it doesn't help the supply chain grow. And I don't think that's a good way.

Audience member (24:50):
There's

Raman Mistry, GSMA Open Gateway (24:51):
A couple more comments. Yeah, Monica?

Audience member (24:53):
So actually I have a question for Dean. I guess it's okay. So standards are crucial. We need standards, but do we need a standard for ai? It's like do we need a standard for software? I mean just the concept because AI is just something that allows you to do things. So you do need the standard to have the interfaces. So I can use AI the way I want you do it too, and we can talk to each other, but not AI as a standard. So maybe,

Dean Bubley (25:23):
But if you mandated this is the standard for AI lifecycle management and this is the standard for AI federation between operator A and operator B, what happens when you roam? If you've got a certified phone which is designed to work against your national AI ran and then you roam to somewhere else, which is not certified against, does it work or does it just fall back to 4G, which

Audience member (25:55):
Opens up the security holes, but it's not ai. I mean it's just like whatever you need. So it's more like old school kind of standard. I mean because a lot of time people just talk about these ai, you need to, well, you can just standardize everything. This is not a standard for everything. I mean maybe you are on the same

Raman Mistry, GSMA Open Gateway (26:19):
Page. There are obviously, which I said in my opening speech standards evolving around AI in a way it might be used in telco in terms of the work that's going on in agen AI and things like MCP, the model context protocol and stuff. And we're seeing a lot of interested in that in things like autonomous networks, et cetera. So I think those kind of standards will be fairly, my assumption is that those would be fairly universally adopted because there is that impetus in those areas.

Guy Daniels, TelecomTV (27:00):
Can I just ask you, do you think there's a possibility of standards creep moving away from traditional telecom standards, heartlands into these other areas which could be detrimental moving forward? Or are you confident that the standards organizations and related bodies are going to do the right thing and know what they're doing and will just continue the way they are?

Raman Mistry, GSMA Open Gateway (27:31):
I think our purposes will be to try and do the right thing, but to try and bring everyone along with us. So we talk a lot to operators, to channel partners, to everyone actually within the telco value chain to try and work to a common consensus. GS MA, that's that's part of its core principles and that's what we will work to. So we don't want to see fragmentation. We want to see liberalization and interoperability.

Guy Daniels, TelecomTV (28:00):
Thanks very much. We come across the room because I'm sure based on this previous conversation or this current conversation, we've got some more thoughts, Kristian.

Audience member (28:08):
Yeah, I wanted to go back to the supply chain aspects. I think Beth presented in a very sensible approach. I mean, clearly nobody can do everything. And your claim on that slide obviously claim your claim on your slide. I certainly wouldn't believe in that sovereign stack myself. But what could you expand a little bit more? I mean as we can't have one stack, no country practically can do it themselves. What are key aspects there? Maybe asking you, Beth, with your vast experience, what do we need to really think about as an industry as we go into

Beth Cohen, Luth Computer (28:42):
The same era? Yeah, I mean obviously there's geopolitical issues, but we do really need to think about if, again, I'm a big supporter of standards and open source as a way of leveling the playing field and it benefits the entire ecosystem. I'm the chair of the anate project, which Silva is based on actually. And the premise of the ATE project was to build reference architectures and reference models of infrastructure to support telco workloads because everybody was going off and doing all their this and that and the other thing, and it costs the telcos tremendously to run all these non-standard proprietary stacks. It costs Red Hat. It costs Red Hat to maintain all these proprietary stuff. So it benefits the entire industry to have reference models and reference architectures to go back to. So the TTE project, which is quite mature at this point, it's kind of boiled down to two reference architectures, OpenStack, which is widely used all across the telco industry at this point and Kubernetes or container-based as I like to say, which is also becoming more and more widely used. And the idea was that it would actually be used straight out, but it isn't used that way. It's mostly used as everybody reads it and says, oh yeah, I'll take this, I'll take this, I'll take piece out of it. But it still has gotten us further along on that standardization and flattening the playing field. So that applies to supply chain.

Guy Daniels, TelecomTV (30:37):
Thank you. Beth, we have a related question at the back.

Audience member (30:40):
Yes, Brooke from SUSE. I'm really curious, how do you value the security certifications as a vendor? We spend a lot of money, time, energy in getting the certification for you. Like ISO 27 0 1 makes it possible for you common criteria. How do you value those?

Beth Cohen, Luth Computer (30:58):
So they are valuable. It doesn't stop telcos from doing their own testing. Pen tests are super important and any kind of, but having those certifications still saves time and energy and money because that means the telcos aren't starting from scratch. So yes, telcos do really value that stuff, but it might not appear that way. Then they go ahead and do a bunch of testing on their own. Anyhow,

Raman Mistry, GSMA Open Gateway (31:32):
Just to follow up, yes, I agree that's really important. Just in terms of what we do in GSMA, we do certification of Camara APIs, Camara APIs, those are defined through the Linux Foundation. And we have a robust tech, so we test the operator's APIs as well as channel partners as well. And then we have a deployment map which shows all the operators that have got Camara. So that's really important. This is to drive that liberalization and democratization of the marketplace because if a channel partner has built a anti-fraud service in Spain and it's using the same APIs as an operator, say AL in Singapore, then theoretically it's built once and deploy to multiple, they can take that to Singapore and offer the same service in that region. So testing the certification is imperative to help the whole interoperability and standardization in the industry.

Guy Daniels, TelecomTV (32:45):
Thanks very much. Cause I was going to talk to you about APIs and how you basically ensure that layer is secure and trusted across other territories. So you covered that there. Thanks very much for that. But I'd really like to get on if I can to another aspect, and we talk about sovereignty and we talk about national sovereignty, but what about the concept of trusted regions or friendly allies if you like, perhaps friendly today but maybe not friendly tomorrow. Is there any valid strategy here to adopt for operators to collaborate across regions on these issues or even build out across regions?

Beth Cohen, Luth Computer (33:32):
Yeah, I think so. I think the EU is a good starting point here. Yes, NAFTA was, but whatever. But I understand that Canada and Mexico are actually just kind of jumping over the us so I think there are shifting alliances, but I think there is still real value in those regional collaborations and alliances. I'm not going to say that NATO is useless. I think it's very powerful and it should hold. I'm praying it holds. So yes,

Raman Mistry, GSMA Open Gateway (34:12):
Thanks Beth Ram. Yeah, I would agree, especially somewhere like Europe. You've got things like the EU AI Act and GDPR and other things that are trying to standardize things across the region. Perhaps that might be shared across infrastructure such as energy as well. You could have several companies sharing energy resources when you get these small reactors, et cetera coming through. So yeah, I could see that there could be some regional standardization that could occur in the future.

Guy Daniels, TelecomTV (34:50):
Yeah. Okay. Thanks very much and it's certainly something we've been talking about earlier today as well about this. We've got a couple more questions and I'm going to come first of all to Mike at the front.

Audience member (35:01):
Thanks for the reference to fraud and security, Raman as you just referred to, but I'd like to just take it a bit further to open source, if I may. How can we secure the digital supply chain with all of the open source suppliers, but minimize the risk of some suppliers that might be in that open source supply chain. There may be some from unwelcome countries, for example, or some that might not be so welcome because they bring cyber attacks with them. How can we do this? Good question.

Guy Daniels, TelecomTV (35:34):
You want to go first, Beth? I'll

Beth Cohen, Luth Computer (35:35):
Be happy to talk. I actually think the open source community has a better chance of protecting itself than the proprietary. There's the zero day alliance and obviously there's zero day attack. Hunters out there looking for zero day of vulnerabilities and open source has, since it's open, it means that pretty much anybody can go in and keep looking for those attacks. In fact, the one that I mentioned earlier was found by somebody who was using the code and was like, well wait, this is not right. And he went in and he found it. And so I think that the open source community just has a much better chance of doing it, of being able, because it's open and everybody can see it.

Raman Mistry, GSMA Open Gateway (36:32):
Beth, do you want to come in? I agree with that. I don't think I've got further, but I agree with everything you said

Audience member (36:38):
There. Can I just say I think that needs to be made more visible and better understood for everybody to agree with you? Agree. I'm not sure it's well understood today.

Beth Cohen, Luth Computer (36:48):
I agree with you that it's not that well understood today. Think I've heard other people say this, that that's the strength of open source. I think that when that attack happened a couple years ago, everybody was a little surprised and was kind of taken aback. But on the other hand, I should point out that attack took two years for it to be done. The attack that Israel did against Hezbollah took 10 years to infiltrate the supply chain of the pagers. So these are things that take a long time to do.

Guy Daniels, TelecomTV (37:26):
Great. Thanks very much. Beth, I'm going to come across to this side of the room at the back here if another question?

Audience member (37:31):
Yeah, following on to Mike's question. So I think everybody can look into open source and we've debated, I think there was general consensus that open source is a good thing for the supply chain, but who controls open source, who governs it? And that really depends on not only the licenses, we didn't want to talk about the legal aspects, but also on the actual control. For example, Raman, you said you're so happy that Google contributed something, but Google of course, controls, is the project continually funded? Who is allowed to issue merger requests? Who is deciding on the mergers? In which direction does the interface evolve? Google can just say like, oh yeah, we want the world to think this way. Now we are just spending a little bit of money and it has a huge lever in favor of future Google business. And the other question about open source is open source is kind of community driven, random in good way, random movement, right?

(38:29)
Standardization is a very peer review driven model. In the original SDO model, all peer review peer groups of the society are to be heard not in all industry forms. Usually the ones they pay most have the most say in industry forms, but still there is some sort of different governance. And how do you rate that? Is it wise to base a whole new industry like Kamar for example, purely on contributions of people in Goodwill and under different kind of governance schemes like Linux Foundation driven by the US government funded a lot, Google funded by themselves, et cetera, et cetera.

Guy Daniels, TelecomTV (39:04):
Thought provoking questions as always. Thanks very much. Raman, would you want to just jump in out here?

Raman Mistry, GSMA Open Gateway (39:10):
Yeah, I mean you raised some good points there. I mean, from my experience, there's for example, the Linux Foundation, which you pointed, which are the kind of the arbiters of the MAPI specification. They fairly robust governance procedures in place. And I think that's the only way that you can operate this, is you've got to have fairly governance and you've got to make sure that there's no one party that's having overdue influence in terms of weight roll out. So there's a very consensus led discussion that happens around what are the APIs we've got today? What are the ones that you're going to have on the roadmap? It's all driven through that community. I think as long as you've got strong governance in place, that's only going to help that kind of open source community.

Guy Daniels, TelecomTV (40:05):
Beth, you to add?

Beth Cohen, Luth Computer (40:06):
Yeah, yeah, sure. So I'm involved in the open source as well. By the way, ANT is in GSMA, as you know, it flows down into it. I've been involved in the OpenStack community for many years. There is a risk there that a given company will kind of dominate the ecosystem of a given project. But what I've found is over time, the projects that are most successful are the ones that have multiple sources of support, not just Google. And so when Google pulls their funding, it doesn't just die. And there's plenty of open source projects out there that are just dead. And that's okay because it's an evolving ecosystem. And if nobody's interested anymore, then it goes away or it just gets archived.

Guy Daniels, TelecomTV (41:10):
Okay, thank you. Great. Thanks so much. One final question in the three minutes we have remaining.

Audience member (41:16):
Yeah, so my question is also on the flip side of the sovereignty. So if I'm a Chinese, whatever, and I don't have access to whatever hardware, I just run my workloads out of Singapore, how is that? Should we be worried about it? A security supply chain, whatever point of view? It's sort of like the opposite of Sonoran,

Beth Cohen, Luth Computer (41:39):
Right? That is a problem, yes. Although on the flip side, companies that do business in China have a real hard time setting up VPNs because China blocks them. So that's a serious problem because China of course has the great firewall and Turkey has a firewall too. There's a couple other countries that are doing it. So yeah, cyber warfare is definitely becoming a bigger and bigger problem.

Audience member (42:07):
Oh, I'm not talking about people that, I mean just big players that just do it with the government allowing it because they actually want it. So is that a concern, is not individuals doing it?

Beth Cohen, Luth Computer (42:20):
Yeah, I think it depends.

Raman Mistry, GSMA Open Gateway (42:26):
I mean, I don't see that would, in my view, any of that would be because a lot of these big organizations are part of lots of consortia or standardizations bodies, so it wouldn't be in their interest to do that. So I don't really see that happening, but that's my view.

Audience member (42:46):
I know it's happening,

Beth Cohen, Luth Computer (42:48):
But that it's definitely happening for sure. But again, it depends upon what their reasons for doing it. And I'll use the example of TikTok, which you better believe they are collecting data on US citizens. And now there's this old, the Congress stepped in and said that they couldn't stay in the US and then the administration changed and things are different now, but who knows where that's going. If you don't think your data's out on the dark web, you are sadly mistaken because it is out there, every single one of us.

Guy Daniels, TelecomTV (43:31):
What a really gloomy, depressing way to end our session. Thanks, but an important way as well. And this question you asked Monica, it's great. And we should follow up in the break because it's time for a break now. Our 45 minutes is whizzed by, so coffee and hopefully cake is served next door, 20 minutes until the next session, the final session of the day. But now please give a warm applause to our two guests. Thank you very much.


Please note that video transcripts are provided for reference only – content may vary from the published video or contain inaccuracies.

Panel Discussion

This session examines how telecoms and their partners can reduce dependencies, increase transparency and strengthen domestic or allied supply capabilities to support sovereign objectives. Panellists debate the trade-offs between global efficiency and local resilience.

Recorded December 2025

Participants

Beth Cohen

Telco Industry Analyst, Luth Computer

Raman Mistry

Channel Partner Engagement Lead, GSMA Open Gateway