How carriers turn trust and security into architecture

Carriers are rebuilding their networks with security. Instead of layering applications on top of one another, operators are embedding protection directly into the fabric they already own. The network itself becomes the control point. That approach matters more as nation-state actors take direct aim at carrier infrastructure, and as IT and OT environments merge inside enterprise and critical-infrastructure customers. Carriers that can update, patch, and apply compensating controls to live equipment without downtime hold an advantage over vendors who still treat security as a bolt-on product.

AI gives carriers a larger role in governance than they've ever had. Every enterprise AI project creates dozens of non-human identities, including agents, workloads, and models that move between clouds, data centers, and carrier networks around the clock. Enterprises want answers on where their data lives, who governs the agents, who trains the models, and who carries the liability when something goes wrong. Carriers that operate under tight trust frameworks, responsible AI guardrails, and clear data-residency practices become the ones enterprises lean on. They keep sensitive information close to its purpose and keep agent behavior inside the lines.

The commercial upside for carriers is substantial. Connectivity alone no longer defines the growth factor. Operators are stepping into the role of technology infrastructure providers built around fiber, edge compute, secure data movement, and agent-ready platforms. None of the AI economy runs without the network, which puts carriers in a rare position to monetize governance, sovereignty, and control alongside connectivity. In an environment where trust is the perimeter, the carriers that own the network own the trust layer sitting on top of it, along with the customer relationships that come with it.


Tom Gillis:

The firewall is just melting into the fabric of the network. We're going to reimagine how that firewall operates, break it into a million little pieces, and embed it into Cisco infrastructure everywhere. I'll say this is the A team, this is the varsity team. Nation state actors are targeting infrastructure. Infrastructure means switches, routers, firewalls, and load balancers.

Masum Mir:

In the industries, IT and OT is starting to come together. IT, OT is starting to come together. The security posture, because when you go to enterprise and critical infrastructure, security needs to be upfront thought out. It cannot be bolt-on. It has to be designed in.

Steve Saunders MBE:

As applications, agents, workloads and machines move continuously between clouds, enterprises and carrier networks, the question is no longer where the edge is. The question is who can be trusted? Welcome to Carrier 2.0. I'm Steve Saunders, and we're calling this episode Trust is the New Perimeter.

One of the assumptions that our industry likes to make is that networking and security are separate problems. One team builds the network, another team protects it.

Speaker 5:

Did you see the memo about this?

Steve Saunders MBE:

Yeah.

Speaker 5:

Did you get that memo?

Steve Saunders MBE:

And for a long time, that worked, until it didn't.

Tom Gillis:

These very sophisticated nation-state actors are targeting infrastructure. Infrastructure means switches, routers, firewalls, and load balancers.

Steve Saunders MBE:

That's a different attack plane and it changes everything. For years, we worried about protecting users, but increasingly, carriers are protecting the infrastructure itself.

Tom Gillis:

Firewall is just melting into the fabric of the network, and it's not just the firewall we know and love today. We're going to reimagine how that firewall operates, break it into a million little pieces, and embed it into Cisco infrastructure, everywhere.

Steve Saunders MBE:

That's not just a technical observation. It's an architectural one. Historically, security has been a reactive craft. Something broke, a vulnerability appeared, a new threat emerged, so we added another layer of security, another appliance, another product.

Speaker 6:

Why don't you just make 10 louder and make 10 be the top?

Speaker 7:

These go to 11.

Steve Saunders MBE:

But increasingly, the industry is moving in the opposite direction.

Masum Mir:

In the industries, IT and OT is starting to come together. IT, OT is starting to come together. The security posture, because when you go to enterprise and critical infrastructure, security needs to be upfront taught out. It cannot be bolt-on. It has to be designed in.

Rana Desouky:

The third pillar is security, and how do we infuse security more into the network fabric? And that's going to become really critical in the era of AI.

Gurudatt Shenoy:

So we are integrating, for example, security into all of our portfolio, and then integrating things like IP and optical, so convergence of different technologies so that we can increase the value of Cisco infrastructure as a platform.

Steve Saunders MBE:

That's a very different philosophy. Security is no longer sitting beside the infrastructure. Increasingly, it is becoming part of the infrastructure.

Tom Gillis:

Having the ability to have a single system that can implement security in software, but also put it into the fabric of the network using silicon, particularly Silicon 1 [inaudible 00:04:02] that powers our smart switch technology, that's something no other company in the world can do, and I think is really transforming the way we think about security.

Steve Saunders MBE:

Security must change because the things we're securing are changing. For the longest time, the network just connected people, but increasingly, it's connecting software, applications, agents, even machines.

Kelly Ahuja:

Because for each human, when you're doing some nice AI project, you actually may be spawning 80 to 100 non-human identities according to Gartner. Now, all these identities are going to live everywhere.

Steve Saunders MBE:

So the issue now is no longer simply protecting users. It's governing behavior.

Lee Kwang Yong:

We're creating carrier agents to be able to monitor and track what agents are thinking, responding to our customers. At the same time, we are also very cognizant about governance.

Shazia Sobani:

We have a very, very tightly-knit, trusted AI framework and adoption policies across TELUS, and that's what allows us to continue to grow the trust with the customers.

Steve Saunders MBE:

The playing field has moved. It's no longer just about authentication. It's about trust.

Speaker 10:

It's not a lie if you believe it.

Steve Saunders MBE:

And that one word just kept appearing in all of the interviews I did for this episode of Carrier 2.0, trust. Not speed, not bandwidth, trust.

Ryan Asdourian:

Speed of trust is something I've believed in for a long time, and our customers can't trust us from an external point of view if we don't trust each other internally.

Shazia Sobani:

At the root of it sits our trust with the customers and their trust with us. Our customers actually are responding very well to it when we keep their data close to where it is supposed to be and stays close to the objective of why the data was collected.

Steve Saunders MBE:

The trust matters because AI is forcing enterprises and industries to make decisions they never had to make before. Where does the data live? Who controls the models? Who governs the agents? Who owns the outcome? And who's liable if something goes wrong? That means that trust eventually becomes a much larger question. Control, jurisdiction, authority, sovereignty, who actually governs the system?

Philippe Ensarguet:

Everything we and what our customer are about to build need to be resilient by design, and building a resilient system is about how we will integrate sovereignty, how we will integrate trust, how we will use a core foundation that are able to leverage the way we want to have resilience.

Logan Wolfe:

We tend to, at Kyndryl, frame sovereignty as a fundamental risk mitigation approach.

Steve Saunders MBE:

So these days, the question is no longer whether the system works or whether the system's secure. The question is who controls it?

There's another side to this story, the commercial side. Carriers have always monetized connectivity, minutes, megabits, coverage. Today, that is not enough.

Ryan Asdourian:

We're turning into a technology infrastructure company, and that is where we're investing in fiber, edge computing, secure data movement.

Gurudatt Shenoy:

Service providers, they are in a tremendously good position if you ask me, because none of this happens without the network, and they are the network providers in almost every case.

Lee Kwang Yong:

A future-ready service provider must be able to deploy AI proficiently, scale and adopt with AI trends, and more importantly, have the governance and framework in place to be able to train, to be able to govern, and the guardrails so that we use AI responsibly.

Kelly Ahuja:

The next growth opportunity for service providers is about helping their customers govern, secure, and control their digital infrastructure.

Steve Saunders MBE:

That has the potential to become a very different business model for carriers, and potentially a much larger and more profitable one.

Carriers have always treated security as a product, something you bought, installed, managed, or paid somebody else to do all of those things. But increasingly, it looks more like a property of the architecture itself.

Tom Gillis:

We're thinking about how can we make our infrastructure inherently more secure? How can we make it easier to update? How can we apply a compensating control to a switch or a router without rebooting that switch or router?

Steve Saunders MBE:

Because in the AI economy, trust isn't built around the perimeter. Trust is the perimeter. I'm Steve Saunders. Thank you for joining me for Carrier 2.0. I hope I'll see you next time. Bye for now.

Hi, there. If someone shared this episode with you, that means they like you. Please, hit subscribe and catch up on all the episodes.

The editorial staff had no role in this post's creation.