Back to blogs

Blog | JUL 20, 2026

When You Cannot Trust the Path, Prove the Data

Data NotarizationCyber Security

Utilities, oil and gas operators and manufacturers are connecting field assets over carrier networks and private 5G just as analysts declare the path untrustworthy. Rented or owned, the answer is the same: data that carries its own proof.

In short: analysts now tell OT risk owners to treat telecom connectivity as part of the attack surface, and regulation will not make the path trustworthy for you. The durable answer sits at the data layer, not the network layer: telemetry that carries tamper-evident proof of its integrity, and remote commands that prove their authenticity, independently of any network they cross.

The end of the trusted utility

In June 2026, Industrial Cyber published a feature with an unusually blunt title: stop treating the telecom network as a trusted utility. Analysts from Takepoint Research, Analysys Mason and Appledore Research argued that as private 5G, network slicing, edge computing and carrier-managed connectivity move into operational environments, telecom infrastructure has become part of the cyber-physical attack surface, and belongs on the OT risk register.

Jonathon Gordon of Takepoint Research put the core problem precisely. The real exposure, he argued, is "loss of trust in the communications path, not just loss of the link". Operators ask whether the connection is up, he noted, rather than whether the path is trusted, monitored and recoverable, and he listed loss of telemetry integrity among the risks that now belong on the register.

The same month delivered a second signal. The UK government downgraded telecom security measures that had been planned in the wake of the Salt Typhoon espionage campaign, after providers argued the requirements were unfeasible or too expensive. Among the rollbacks: the proposed requirement for an independent signalling intrusion detection system, designed to catch evidence that existing controls had already been bypassed, was reduced to a recommendation.

Read those two developments together and the conclusion is uncomfortable. The analyst community says the path can no longer be assumed trustworthy. The regulatory trajectory says no one is going to force it to become trustworthy either.

Where this bites first

This is not an abstract concern. In energy and utilities, distribution substations, metering infrastructure and distributed renewable assets increasingly report over carrier-managed cellular links. In oil and gas, telemetry from remote well sites and pipeline infrastructure travels paths the operator neither owns nor sees. In manufacturing, private 5G campuses now carry data from mobile assets, automated guided vehicles and retrofitted brownfield equipment that predates modern security assumptions.

Gordon draws a useful distinction between the two dependency profiles these sectors face. Commercial connectivity concentrates risk in carrier infrastructure the asset owner cannot control or inspect: limited forensic visibility, unclear incident notification, weak contractual rights when something goes wrong. Private 5G shifts the profile rather than the conclusion: more control means more inherited responsibility, from SIM and device management to segmentation enforcement and edge workloads, often across unclear ownership boundaries between OT, IT, telecom teams and integrators.

Whether the path is rented or owned, the operational question is identical: can you establish, independently, what happened to the data that crossed it?

What Salt Typhoon actually proved

Salt Typhoon deserves precision, because it is often cited loosely. It was an espionage campaign attributed to Chinese state-linked actors, disclosed in late 2024, that compromised major telecommunications carriers to intercept communications and metadata. There is no public evidence that it manipulated data in transit, and it did not target industrial telemetry.

What it proved is arguably worse than a manipulation story. Three facts stand:

First, some of the most heavily defended commercial networks in the world were penetrated and held for extended periods without detection. Detection, as a strategy, failed at scale.

Second, the full scope proved unknowable even afterwards. In the UK, neither the government nor the telecom industry has confirmed whether domestic networks were compromised at all, even as the National Cyber Security Centre acknowledged Chinese activity targeting critical sectors globally, including a cluster observed in the UK. Operators who depend on those networks cannot establish, after the fact, what happened on the paths their data travelled.

Third, the access came through the network infrastructure itself: the routers and edge devices that carry the traffic. A position on the routing fabric confers the technical capability to alter or redirect what passes through it, whether or not that capability was exercised.

And Salt Typhoon is not the only relevant campaign. Volt Typhoon, a separate Chinese state-linked operation, was assessed by US agencies as pre-positioning inside critical infrastructure networks for potential disruptive action. The adversaries who can sit on the path have demonstrated the intent to be there when it matters.

The honest lesson is this: if your basis for trusting operational data is the health of the network it crossed, that trust is now unverifiable in exactly the situations where it matters most. The question "was our data touched?" has no answer unless the data can answer it itself.

Why the current answers stop short

The industry's instinctive responses all try to rebuild trust in the pipe, and each falls short of proof.

Private 5G moves the risk, it does not remove it. Ownership brings inherited responsibility rather than immunity, and the vulnerability classes that exposed carrier networks apply to private deployments too.

Contracts deliver assurances, not evidence. Annika Nitschke of Analysys Mason argued in the feature that operators should demand verifiable evidence of controls and demonstrable assurance rather than contractual statements. She is right, and it is also true that few providers can supply independently verifiable proof of what happened to a customer's traffic, because their own visibility has limits.

Regulation is being negotiated downward. The UK rollback shows that security requirements on carriers are subject to commercial lobbying. Building an assurance model on the assumption of ever-stricter carrier regulation is building on sand.

Channel encryption is necessary but insufficient. TLS and VPNs protect a session between two termination points while the session lives. Industrial reality involves protocol translation at gateways and brokers, carrier-managed edge infrastructure, and legacy devices that cannot support modern cryptography. And a transport session cannot testify: six months later, in an audit or an incident investigation, it offers no evidence of what the data was when it left the source.

Move the trust from the path to the payload

There is a different architectural answer: stop trying to make the path trustworthy, and make the data provable instead.

Cryptographic notarization binds tamper-evident proof to operational data at the earliest integration point. From that moment, the integrity of every notarized dataset and stream can be verified end to end and after the fact, by the asset owner or by a third party, independently of any network, carrier or intermediary. If data was altered anywhere along the way, verification fails, the alteration is provable, and consumers can reject the data before it drives a decision or a record. Notarization does not prevent interference; it makes integrity a matter of evidence rather than assumption. Proof begins where notarization begins: at the earliest integration point, typically an edge gateway, and, where assurance requirements demand it, embedded in the device firmware itself. When the carrier cannot tell you whether your path was compromised, you can still answer the only question that matters operationally: this data verifies, or it does not.

The same logic applies in the other direction, and with higher stakes. Manipulated telemetry coming up misleads; a manipulated command going down acts. Remote access, vendor maintenance and remote configuration increasingly ride the very connectivity now under question. Cryptographically verified remote commands, covering configuration and setpoint changes with a full audit trail, ensure that a setpoint pushed to a remote substation or a configuration change sent to a field gateway is authentic and authorised regardless of the trustworthiness of the link it crossed.

Both capabilities are covered by granted patents, and both are complementary to the detection and monitoring layer most operators already run. Detection watches what an adversary does on your network. Proof establishes what your data is. After Salt Typhoon demonstrated that sophisticated intrusions can evade detection for extended periods, proof is the layer that tells you what you can still trust.

One note for environments with stricter flow requirements: where information must move strictly one way, from the OT side outwards, the command path can be disabled entirely by policy, giving verifiable one-way data flow across the IT/OT boundary. We cover verifiable IT/OT data transfer in more depth in Verifiable Data Sharing for OT/IT Trust and Access and Why IoT/OT Security Must Evolve Beyond the Network.

What belongs on the risk register now

The practical moves follow directly from the analyst guidance. Capture path trust and telemetry integrity explicitly as operational risks, not just link availability. Ask providers for demonstrable, verifiable assurance rather than contractual language. And instrument the data layer itself, so that your evidence of integrity does not depend on any provider's network, cooperation or visibility. An evidence-based data layer also supports compliance with the reporting and integrity expectations emerging under NIS2 and the readiness demands of the EU Cyber Resilience Act.

Ready to use: we have packaged this guidance as a one-page download, five risk statements and ten provider questions, ready to paste into your risk register and your next provider review. Get the Risk Register Language Pack

The AI deadline

Everything above assumed a human somewhere in the loop, someone who might notice when a number looks wrong. Industrial AI removes that assumption. Agents and models consume telemetry at machine speed and act on it without scepticism, and the analyst commentary already lists AI workloads among the dependencies riding external connectivity. As EU AI Act obligations phase in and frameworks such as the NIST AI Risk Management Framework take hold, the requirement crystallises into two preconditions: verifiable inputs and verifiable actions.

You cannot deploy AI against data you cannot prove, and you cannot let AI act through channels you cannot verify.

The trusted utility era is over. That is not a reason to distrust your providers; it is a reason to stop outsourcing a question they were never able to answer for you. The link being up was never the same as the data being true. Now you can prove the difference.

Tributech provides trustworthy data infrastructure for industrial and OT environments: cryptographic data notarization, secure remote commands and a queryable digital twin knowledge graph, accessible to AI agents via MCP. See how notarized telemetry works in an OT environment or get the OT Risk Register Language Pack.

Download the Risk Register Language Pack

Get five risk statements and ten provider questions for telecom and private 5G connectivity risk in your OT risk register.

Thomas Plank
CEO, Tributech

Blog | JUL 20, 2026

Contact us

You want to unleash the full potential of your data? Contact us for a first discussion about your data strategy.