Basilisk
BASILISK
[setor_telecom]TELECOM & ISPs

Offensive security for telecom and internet providers.

Carriers and providers carry an unusual responsibility: when their infrastructure fails, the medium everyone communicates through fails with it. We test from the subscriber portal to the core, including the equipment sitting in the customer's home.

Why carriers are high-value targets

Compromising a carrier does not grant access to one company. It grants a privileged position over the traffic, identity and location of an entire subscriber base. That is why the sector attracts everything from consumption fraud to strategically motivated actors with the patience and resources for long operations.

  • A position in the network gives potential access to communications and metadata across the base.
  • SIM swap and number hijacking turn the carrier into a vector for banking fraud.
  • The deployed CPE estate is large, heterogeneous and difficult to keep updated.
  • Interconnection with other carriers creates trust between networks you do not administer.

What we test at a carrier

We walk the subscriber journey and the packet journey, looking for where control stops existing.

// portal and self-service

Subscriber area, app and call centre flows: object-level authorisation, ownership transfer, replacement requests and everything leading to a SIM swap.

// OSS/BSS

Provisioning, billing and subscription management. We check whether a role can change a plan, credit or service outside its remit.

// core and signalling

Exposure of network elements, isolation between control and user planes, and what an edge foothold reaches towards the core.

// CPE and field equipment

Routers, ONUs and set-top boxes: default credentials, exposed management interfaces, firmware updates and the remote provisioning channel.

// interconnection and partners

Peering, content partner integrations and resellers — established trust between networks that tends to be verified least.

// internal infrastructure

Segmentation between corporate and service networks, and the path from administrative access to systems that touch the subscriber.

Evidence for regulatory duties

The sector answers to continuity, confidentiality and data protection requirements. The report is written to serve that set.

Confidentiality of communications
Communications content and metadata carry legal protection. Any path allowing improper access to those records is treated as a maximum severity finding.
GDPR
Subscriber records, connection logs and location are personal data, some of it sensitive. We document subject exposure and the technical route of disclosure.
NIS2 and continuity
Providers of public electronic communications fall in scope for risk management and incident handling duties. Findings are framed against those obligations.
Retention integrity
Where records must be retained with integrity, we test whether they can be altered or deleted by someone who should not be able to.

How we run without affecting subscribers

01

Environment separation

We define clearly what carries live subscriber traffic and what is lab. The core only receives active testing on a replica or under specific authorisation.

02

CPE sampling

We test a representative sample of the estate on the bench, not equipment in a customer's home, measuring what would be exploitable at scale.

03

Fraud scenarios

We reproduce the fraudster path through SIM swap and account changes using test accounts, to measure where the process actually holds.

04

Remediation and retest

We prioritise by what reaches the subscriber base first, follow the remediation and retest before the final version.

What you receive

  • Executive report framed in risk
  • Reproducible technical report
  • CPE estate exposure analysis
  • Justified CVSS scoring
  • Subscription fraud scenarios tested
  • Priority by reach across the base
  • Retest of remediated findings
  • Attestation letter for audit

Sector FAQ

Can testing cause an outage for subscribers?

+

No, and the engagement is structured to guarantee it. Core elements and systems carrying live subscriber traffic only receive active testing on a replica or under written authorisation within a specific window. We keep an open channel throughout so any activity can be halted within seconds.

How do you test CPE without touching customer equipment?

+

On the bench. We work with a representative sample of the models in your estate, supplied by you, and assess default credentials, management interfaces, firmware and the provisioning channel. What matters is what would be exploitable at scale, and that is demonstrated in the lab.

Do you test SIM swap fraud?

+

Yes, and it is often one of the most revealing scopes. We reproduce the full fraudster path with test accounts: social engineering against support, self-service flows and account detail changes. The aim is to measure where the process genuinely holds, not just where the system validates.

Does the report meet regulatory audit requirements?

+

It is written for that. It comes in an executive layer, in risk and continuity language, and a technical layer with step-by-step reproduction. We issue an attestation letter for the engagement, which is usually the document accepted by audit and by interconnection partners.

Services applied to this sector

// contact

Ready to uncover your flaws?

First scoping call is free and covered by NDA. Within 48 hours you receive technical proposal, scope and timeline. No bureaucratic forms.