Latest / The 5G Podcast with Fexingo: Wireless Networks, Carriers, and Mobile Infrastructure / How Private 5G Networks Are Securing Industrial Sites
Transcript
- Lucas: When a German automotive parts manufacturer found its robotic assembly line infected with ransomware last year, the infection vector wasn't a spear-phishing email or a compromised VPN. It was a smart thermostat connected to the same guest Wi-Fi as the production controller. Luna: That's the kind of attack surface people don't think about. A thermostat, of all things. Lucas: Exactly. And it's becoming more common. Industrial control systems were traditionally air-gapped, but over the past decade, manufacturers connected them to broader networks for remote monitoring, predictive maintenance, just-in-time supply chain coordination. Convenience won. And with it came a massive vulnerability. Luna: So where does 5G fit? Isn't it just another wireless technology with the same security problems? Lucas: That's the conventional wisdom, but private 5G networks have architectural features that fundamentally change the security posture. Let me focus on three: sim based authentication, network slicing, and local traffic breakout. Luna: Start with the SIM. It's a tiny chip. How does that matter? Lucas: In a private 5G network, every device — every sensor, robot, camera, controller — gets its own SIM or eSIM. That SIM contains a unique cryptographic key stored in a tamper-resistant element. When the device connects, the network authenticates that key using the same protocols mobile operators have refined over decades. Compare that to Wi-Fi, where the pre-shared key or even 802.1X certificate can be cloned or stolen. Luna: So the SIM is hardware-bound identity. That's hard to spoof. Lucas: Exactly. And it doesn't stop at authentication. Once a device is on the network, the operator can define network slices — logically isolated virtual networks over the same physical infrastructure. So the robotic arm's traffic never touches the same slice as the HVAC system, even if they're both on the same 5G base station. Luna: That's fundamentally different from VLANs, which are often misconfigured and leaky. Lucas: Right. VLANs rely on network switches and proper tagging. A misconfiguration, a rogue access point, or even a cable plugged into the wrong port breaks the isolation. With 5G network slices, isolation is enforced at the core network level, not at the physical layer. And it's programmable — you can dynamically adjust slice parameters based on trust level, data sensitivity, or even time of day. Luna: And the local breakout piece — that's traffic not leaving the factory floor? Lucas: Exactly. In a typical setup, even internal industrial traffic might route through a corporate data center or a cloud gateway. That adds latency and exposure. With a private 5G network, you can deploy a local user plane function right on the factory floor. Traffic between the robot and the controller never leaves the local edge. It's like an air gap, but with wireless flexibility. Luna: So the manufacturer with the thermostat ransomware — could private 5G have prevented it? Lucas: In that specific case, yes. The thermostat was on the same flat Wi-Fi network as the production line. With private 5G, the thermostat would have been authenticated via its own SIM, placed in a dedicated slice for environmental sensors with no access to the production slice, and its traffic would have been routed locally. Even if the thermostat were compromised, the attacker would have had zero lateral movement into the control network. Luna: That's compelling. But are we seeing actual adoption? Or is this still a theoretical advantage? Lucas: Adoption is real and accelerating. The German manufacturer I mentioned deployed a private 5G standalone network in the fall of 2025. They're not alone. According to a report from the Global mobile Suppliers Association, there were over 1,200 private 5G network deployments worldwide as of March this year, and industrial manufacturing is the largest vertical, accounting for about 35 percent. Luna: And security is the stated driver for many of them. I've seen similar numbers. Lucas: The 3GPP's Release 18, which was finalized in mid-2024, included several security enhancements specifically for industrial use cases — things like enhanced security for network slices, support for zero-trust architectures, and better key management for devices that might be physically tampered with. Luna: It feels like the industry is finally getting serious about cyber-physical threats. And it's not just factories. Ports, mines, power grids — all the things we've covered this season. Lucas: Right. Take a modern container port. You have automated stacking cranes, automated guided vehicles, sensor networks monitoring container positions. Until recently, many of these ran on Wi-Fi or proprietary radio. But Wi-Fi's handoff latency when a crane moves across a yard can cause disruptions. And the security model is weak. Luna: Private 5G solves both — seamless mobility and strong identity. Lucas: And because the network is private, the enterprise controls the authentication server, the subscriber database, the encryption keys. They don't rely on a public mobile operator's infrastructure. That's increasingly important for critical infrastructure operators who face nation-state level threats. Luna: Speaking of which, I want to circle back to something. If a private 5G network uses sim based authentication, what happens when a SIM is physically stolen? Or an eSIM is reprogrammed? Lucas: Good question. The standard includes mechanisms for remote SIM provisioning and revocation. In 5G standalone, the network can update the subscriber credentials over the air. So if a device is reported stolen, the operator can invalidate its SIM keys and push new ones to a replacement. Additionally, the network can enforce device-level checks — not just the SIM, but the device's hardware identifier. Luna: That's more robust than Wi-Fi, where you can clone a MAC address trivially. Lucas: Exactly. Of course, no system is perfectly secure. But the baseline for private 5G is significantly higher than what most industrial sites have today. And the cost of deploying private 5G has come down. Entry-level systems from vendors like Nokia and Ericsson now start around $50,000 for a small deployment covering a single facility. Luna: That's accessible for a mid-sized manufacturer. And the security ROI is clear when you consider potential downtime costs. Lucas: Speaking of the show — if today's conversation gave you a usable perspective on why private 5G matters for industrial security, that's exactly the kind of thing that keeps us doing these deep dives. We keep this podcast ad-free, and that's possible because a small group of listeners chips in monthly through buy me a coffee dot com slash fexingo. It's a simple way to support the show if you find value in it. Luna: Yeah, it really does make a difference. Just a few dollars a month from people who enjoy the content keeps us going without any sponsors. Lucas: Now, back to security. One area where private 5G is making inroads is in the energy sector. Utilities are deploying private 5G to secure communication between substations and control centers, replacing older microwave and fiber links that are expensive to maintain. Luna: And the security requirement there is extremely high. A compromised substation could lead to blackouts. Lucas: Absolutely. Private 5G allows utilities to segment traffic so that protective relay commands — which must be ultra-reliable — are on a dedicated slice with priority and encryption. Meanwhile, meter data and video surveillance can be on a separate slice with lower priority. If an attacker compromises the video stream, they can't inject fake commands into the relay slice. Luna: That's the slice isolation in action. And the utility controls the entire core, so they can audit every access attempt. Lucas: Right. And there's a regulatory angle. In Europe, the NIS 2 Directive, which member states are transposing into national law this year, requires critical infrastructure operators to implement stronger network security. Private 5G, with its built-in authentication and isolation, is one of the few technologies that directly addresses those requirements without a massive redesign of existing systems. Luna: So we're at an inflection point where security regulation and technology capability are aligning. Lucas: They are. And the next step is Release 19, expected in 2027, which will include even tighter integration with zero-trust architectures and support for quantum-resistant encryption algorithms. But even today, the tools are available. Luna: It's rare to see a wireless technology that actually improves security posture rather than just adding convenience. Lucas: That's the key insight. For years, wireless was seen as inherently less secure than wired. Private 5G flips that script. Because of its authentication model, its isolation capabilities, and its programmability, it can actually be more secure than many wired industrial networks — especially older ones that rely on serial connections and lack encryption. Luna: So the takeaway is: if you're running a factory, a port, a mine, or a substation, private 5G should be on your shortlist — not just for speed or latency, but for security. Lucas: Exactly. The next time you hear about a ransomware attack shutting down a factory, ask whether that factory had a flat network. Chances are it did. And private 5G is one of the most effective ways to flatten the curve.