Expert Opinions

The Zero Trust Gap Your 5G and Satellite Vendors Aren't Closing

Written by:
Brendan Sullivan, Chief Executive Officer
Brendan Sullivan, Chief Executive Officer
Published on:
September 8, 2026
The Zero Trust Gap Your 5G and Satellite Vendors Aren't Closing

In July, I wrote about Volt Typhoon, the China-linked actor CISA confirmed sits inside U.S. critical infrastructure with an average dwell time of 300 days, doing nothing but living off tools your team already trusts. The argument in that piece was architectural: detection-based security cannot catch an adversary who never does anything that looks abnormal. The fix has to stop the connection before it's established, not flag the activity after the fact.

That argument doesn't stop at the on-premises networks Volt Typhoon has been targeting. It applies with equal, maybe greater, force to the connectivity layer underneath almost everything your organization runs today: 5G, and the satellite networks now built directly into it. So before this series moves to the next actor, it's worth spending one post on the architecture itself. The same pattern that let Volt Typhoon persist undetected (authenticate once, trust indefinitely) isn't a gap an adversary found. In 5G, it's the design.

The security story around 5G is mostly good news. The 3GPP standards body addressed four real vulnerabilities that plagued 4G/LTE for a decade: subscriber identities are now encrypted before radio transmission, eliminating IMSI catchers on true Standalone networks; mutual authentication via 5G-AKA closes the rogue base station attack; user-plane integrity protection stops traffic injection; and the Security Edge Protection Proxy replaces the unauthenticated SS7/Diameter exposure at roaming boundaries.

Give credit where it's due. These were meaningful advances.

But they all share one architectural assumption that security architects need to understand clearly before they draw conclusions about their own risk posture: 5G establishes identity at onboarding and reuses it for the lifetime of a session. Once a SIM is authenticated, the network places no per-session, per-process check on what a device can reach or do. That single assumption is where the attack surface lives, and it remains fully exploitable today, across every 5G deployment your organization touches.

The Gap Is Structural, Not Incidental

Before a CISO can assess the real exposure, there are four things worth understanding about where the 5G security model actually breaks down.

The first is deployment reality. More than 90% of 5G networks today run as Non-Standalone (5G radio over a 4G core). In that architecture, SUCI, 5G-AKA, and SEPP are all bypassed. Every legacy vulnerability from the 4G era remains in force. When someone tells you that 5G is inherently secure, ask them what percentage of their deployment is Standalone. The answer is almost always less than 10%.

The second is SS7. The signaling protocol from 1975 still underpins SMS, location services, and roaming, because 5G must interoperate with 4G and legacy networks. SS7 intercept and location-tracking attacks remain viable against any device that roams or receives SMS. This is not a theoretical concern. It is an actively exploited attack surface used by nation-state actors and commercial surveillance vendors alike.

The third, and the one that matters most for enterprise and government deployments, is that 5G authenticates the SIM card, not the session, the process, or the user. After onboarding, any process on any authenticated device can attempt to reach any network resource. Lateral movement is structurally unrestricted. There is no per-session check standing between a compromised endpoint and the rest of your infrastructure.

The fourth is IoT. Billions of sensors operate on 5G with no endpoint agent, no per-session credential, and no access control between devices. Once provisioned, they are free to probe any connected resource across any network slice. In a manufacturing facility, a utility grid, or a military forward operating base, that is not a theoretical exposure. It is an open path.

The practical consequence: one compromised endpoint (a handset hit with a SIM-swap, an IoT sensor with default credentials, a device force-downgraded to 4G by a rogue cell) can enumerate your infrastructure freely, move laterally across network slices, and relay session tokens that remain valid indefinitely. The attacker is inside before detection is possible.

What Zero Trust Actually Requires in a 5G Environment

Zero Trust is a set of architectural requirements, not a product you can buy and deploy against a checkbox. Applied to 5G networks, four requirements have to be satisfied simultaneously, and none of them are satisfied by the 5G standard itself.

Identity must be verified at every session, not just at onboarding. Every connection attempt from every user, process, and device must carry a cryptographically verifiable identity before any session is permitted to proceed. SIM authentication at provisioning does not satisfy this.

Enforcement must happen before a connection is established. Unauthorized traffic must be stopped before a session exists, not detected after the attacker is already inside. Detection-after-entry is not Zero Trust. It's breach response.

Infrastructure must not be visible to unauthorized entities. A visible node is a targetable node. Returning a firewall rejection tells an attacker that the resource exists, what port it runs on, and something about its behavior under load. Silence, not rejection, is the only mechanism that eliminates the reconnaissance attack surface.

Least privilege must be continuously re-verified. Each identity should receive only the minimum access it requires, enforced freshly on every session, not inherited from an authentication event that happened at device provisioning six months ago.

These four requirements define the gap between the 5G security model and what Zero Trust actually demands. Invisinet's First Packet Authentication closes that gap with a single transport-layer overlay.

The mechanism is a quantum-resilient, one-time-use token (a TAC-ID) injected into the TCP SYN packet at the very start of every session. Our InvisiGate policy enforcement point evaluates the TAC-ID before a session is established. Traffic without a valid token receives no response. The infrastructure does not acknowledge the probe. Because each token is invalidated on first use, intercepted credentials are worthless regardless of what happens at lower layers. Identity-driven microsegmentation runs at Layer 4, without topology changes, without deploying agents on every device, and without re-provisioning existing infrastructure.

The Same Problem Exists in Space, and It's Harder

If your organization uses satellite connectivity (and increasingly, most do), the 5G security argument does not stop at terrestrial cell towers. It extends directly into space, and in several respects the risk is materially worse there.

3GPP Release 17 established the first formal specifications for 5G New Radio over Non-Terrestrial Networks, enabling satellites to function as 5G base stations. Commercial Satellite Direct-to-Device services (standard handsets communicating directly with LEO satellites without specialized ground hardware) entered commercial deployment in 2025-2026, with Starlink Direct-to-Cell as the leading example.

The security model inherited by NTN is identical to the terrestrial 5G model, with the same gaps intact. Current NTN deployments are functionally NSA-equivalent: the 5G radio connects to terrestrial core infrastructure, and the same authentication bypasses that affect 90% of terrestrial 5G apply identically here. A compromised NTN-attached IoT sensor has the same unrestricted lateral movement as its ground-based counterpart. There is no per-session identity check standing between it and any other connected resource.

Three additional factors make the satellite environment structurally worse. LEO constellations require high handover rates as satellites pass overhead, and each handover is a transition that can be exploited to insert a rogue satellite ground terminal emulating a legitimate node. Geographic coverage is continental or global: a single exploited NTN node does not create a local incident; it creates a globally scoped lateral movement path across agriculture, maritime, energy, and critical infrastructure IoT simultaneously. And high-latency links (GEO at roughly 600ms round-trip, LEO at 20-40ms) create real operational pressure on conventional challenge-response authentication schemes that require multiple round trips. First Packet Authentication eliminates that pressure by embedding identity in the first packet, so the authentication decision costs nothing in additional latency.

Starlink and StarShield introduce their own specific concerns. Starlink's security architecture (transport encryption, proprietary routing protocols, signed firmware) addresses confidentiality in transit. It does not enforce per-session Layer 4 identity. A compromised user terminal has unrestricted lateral movement within its network segment, the same structural gap as everywhere else. StarShield, SpaceX's defense-oriented service currently comprising at least 183 satellites, shares hardware, ground stations, and laser cross-link infrastructure with the commercial Starlink constellation. An attack on the commercial side creates spillover exposure to military assets. That is both an operational and an attribution risk. Peer-reviewed research has also documented authorization and policy-enforcement gaps in Starlink's user terminal architecture, including gRPC interface exposure and firmware vulnerabilities: attack surfaces that are underexplored and underdefended.

There is also a vendor concentration argument that CISOs responsible for mission-critical connectivity need to take seriously. A single April 2026 Starlink outage disrupted active Pentagon drone tests. When a private actor controls connectivity infrastructure for military operations, vendor concentration stops being a commercial resilience issue and becomes a national security one.

The architecture argument is the same across all three domains. FPA deployed as a transport-layer overlay on Starlink-connected or NTN-connected infrastructure enforces per-session identity, eliminates reconnaissance exposure, and contains lateral movement from compromised terminals, independent of whatever encryption and routing protocols the underlying network provides.

What This Means for a CISO Today

If you operate any infrastructure that touches 5G (enterprise, private network, or MVNO connectivity) and you have not addressed per-session identity enforcement at the transport layer, you have lateral movement exposure that 5G itself does not close. That exposure is structural, not misconfiguration. It is inherent to how the standard was designed.

If you use Starlink, StarShield, or any NTN-connected IoT at scale, the same exposure applies with broader geographic scope and the added complexity of shared infrastructure risk.

Zero Trust claims from your network vendors and connectivity providers are probably accurate within a limited frame: they address the problems their architecture was designed to address. The question is whether those controls extend to per-session identity enforcement at the TCP transport layer, before connection establishment, for every user, process, and device on the network. For most 5G and satellite deployments, the honest answer is no.

That is the gap. It is addressable with a transport-layer overlay that requires no changes to your existing infrastructure. What it requires is recognizing that the authentication event at onboarding is not the same thing as Zero Trust.

What Was Built to Hide Is Now Being Exploited

Step back from the protocol details for a moment and look at what the last decade of 5G and NTN engineering was actually solving for. Getting a call to drop off a cell tower, hand seamlessly to a satellite, and hand back again without you ever noticing took the 3GPP standards body roughly ten years and seventeen spec revisions to get right. Virtual SIM credentials, cross-network handshakes, "connect to whatever signal is strongest" logic: all of it engineered so that connectivity could disappear into public infrastructure and stay there, invisible, regardless of whether the nearest node was a tower or a satellite. That was a good idea a decade ago. In a world where 4G became 5G, and 5G became non-terrestrial 5G running over constellations like Starlink, it's an even better idea today, which is exactly the problem.

"Disappear into public infrastructure and stay hidden" is not just a description of good network engineering. It's also a description of how a nation-state intelligence service would want to operate inside a target's telecommunications backbone. The U.S. government reached that conclusion years ago: it's why Huawei was pushed out of American networks and placed on an export embargo list in the first place. The concern was never abstract: hardware embedded that deep in public infrastructure, built by an untrusted vendor, is positioned to listen to everything that moves through it.

Last year, that concern stopped being theoretical. The federal government confirmed that all four of the largest U.S. cellular carriers had been breached, with call records tied to roughly 4 million Americans exposed. The actor behind it has a name: Salt Typhoon. And the mechanism it rode in on is the same structural gap this piece has been walking through: a network built to authenticate a device once, hide it inside trusted infrastructure, and never re-check it again.

That's where we're headed next. In the next piece, we'll go inside the Salt Typhoon breach itself: how a network designed to make connectivity invisible became the thing an adversary hid inside of, and what per-session, transport-layer identity would have changed.

Brendan Sullivan is the CEO of Invisinet Technologies. Invisinet's First Packet Authentication technology is patented and currently deployed in U.S. government and critical infrastructure environments. For more information, visit invisinet.com.

Table of contents
sign up for newsletter
Receive updates on Invisinet’s solutions and security insights.