Skip to main content
CybersecurityNetwork Security

Cybersecurity Takes Center Stage in Private 5G Network Design

Secure industrial room with network equipment, servers, and monitoring screens.

"Just Get it Running and Keep it That Way!" — Mitch Rappard, Director of Wireless Solutions at Palo Alto Networks.

Why private 5G for governments and militaries raises a new security test

Government agencies and military organizations are increasingly deploying private 5G networks to connect growing ecosystems of sensors and devices. Mitch Rappard warns these networks cannot be built the traditional way with network-led security. Instead, he argues, they require "security-led networking" — security baked in from the beginning and extended from the core to the edge — because the threat environment has evolved, and advanced persistent threat (APT) groups and other malicious actors are now faster and more efficient, helped by artificial intelligence (AI) tools.

What network-led design gets wrong

Rappard lays out a common operational pattern: network professionals focus on bringing connectivity online quickly to meet mission needs — ensuring systems interconnect, devices communicate, and uptime is maximized. Only after deployment are cybersecurity teams asked to implement zero trust and threat prevention. That sequence creates extra work and delays and can leave vulnerabilities that are harder to fix after the fact, mirroring past problems that birthed DevSecOps in application development.

Visibility: know every protocol, device, user, and application

A central problem on private 5G deployments is blind spots. Rappard points to non-cellular devices that lack modems and are brought onto networks via Ethernet to routers; each such connection can create an unknown device and unknown traffic patterns. When multiple devices sit behind the same router, a malicious actor could use them to attack one another. Complete visibility — knowing "every protocol, service, device, user, and application on their network" — is therefore essential, especially for feeding accurate logs into SIEM or SOAR systems that depend on fidelity to operate effectively.

Threat intelligence, unified platforms, and proactive defense

Network security has traditionally been reactive, but Rappard highlights two linked advances that change that calculus. First, accurate and up-to-date threat intelligence — often leveraging AI — enables a proactive posture to identify and defend against threats before they attack. Second, a unified platform approach that lets the entire network share intelligence and IOCs (for example, malware signatures, malicious DNS entries, or malicious URLs) strengthens security by ensuring disparate tools inform one another when a threat is discovered. For agencies wary of cloud models, Rappard notes that on‑prem threat intelligence solutions are available.

Virtual patching to protect the tactical edge

Private 5G networks are often meant to extend connectivity to the tactical edge — remote or austere locations where physical access to equipment for patching is "practically impossible." Rappard stresses timely patch management is critical because AI tools allow attackers to find and weaponize vulnerabilities rapidly. Virtual patching, which uses network-based threat intelligence to shield vulnerable endpoints before physical patches can be applied, is presented as a practical mitigation when physical servicing is infeasible.

What this means for network professionals, cybersecurity teams, and government and military organizations

  • Network professionals and network engineers: expect your core metric — uptime — to increasingly depend on cybersecurity measures. Rappard cautions that resistance to early cybersecurity involvement can undermine the very uptime you are measured on.
  • Cybersecurity teams: the author argues you should be brought into design and deployment from the outset to "shift security to the left" in network projects the way DevSecOps did for applications, enabling zero trust and comprehensive visibility from day one.
  • Government agencies and military organizations: plan for on‑prem threat intelligence options if cloud adoption is a concern, and consider virtual patching capabilities to protect equipment at the tactical edge where physical patching is impractical.

Rappard closes with a pointed operational prescription: for private 5G networks that carry mission-critical communications and data, resiliency and uptime now require cybersecurity to be part of the basic redundancy checklist alongside dual backhaul links and backup power. The central choice facing organizations, he argues, is whether they will accept security as an add-on or adopt security-led networking that integrates visibility, threat intelligence, unified platforms, and virtual patching from the start.

Original story: Security-Led Networking – The Key to Secure, Resilient Private 5G Networks