Persistence, pre-positioning and shared dependencies in the security of Italy and Europe
For an in-depth, confidential analysis of this Node (internal dossier and MST assessment), Request a confidential contact https://csr-italia.org/en/contatti/ contatto riservato
The security of telecommunications is usually framed around the single attack: a vulnerability exploited, a device compromised, a campaign attributed to a hostile group. This perspective, while necessary at the technical level, does not fully capture the strategic dimension of the problem.
Telecommunications networks are not a sector like any other. They carry the communications of public administration, underpin financial and healthcare services, connect energy and logistics infrastructure, and enable the operations of businesses and institutions. The devices at the edge of networks — routers, firewalls, gateways and remote-access systems — govern the passage between different environments and are often the point where internal networks, suppliers and external services meet.
For this reason, the compromise of a telecom network or of an edge access point should not be assessed solely by its immediate damage. The decisive question is a different one: whether that access can be maintained over time, used to observe the system, and transferred toward organisations, infrastructures or sectors other than the one initially hit.
Strategic risk therefore does not coincide with the intrusion. It arises when a contained access can become persistent, transferable and systemic.
From attack to pre-positioning
The traditional cybersecurity paradigm assumes a relatively recognizable sequence: an attacker penetrates a system, deploys malicious tools, steals data, or disrupts a service. The most advanced cyberespionage campaigns reveal a different dynamic.
The objective may not be an immediate result. Instead, it may be to secure a privileged position within the infrastructure: a silent presence from which to monitor traffic, collect information, modify configurations, or prepare further access.
This marks the shift from opportunistic exploitation to pre-positioning.
Access of this kind is valuable precisely because it can remain unused or largely undetected for extended periods. It does not necessarily require conspicuous malware. Valid credentials, existing administrative tools, and seemingly ordinary configurations can allow hostile activity to blend in with routine network management.
Persistence also changes the nature of the threat. An intrusion is no longer merely an incident to be contained: it can become a latent capability, available for intelligence collection or activation during a future crisis.
Campaigns publicly linked to state-sponsored groups targeting telecommunications infrastructure illustrate this shift. In recent years, national authorities in several countries have confirmed compromises of networks and edge devices, with dwell times lasting several years in some cases.
However, focusing the analysis on a single actor would be reductive. The same attack surfaces—edge devices, remote access systems, identity infrastructure, and relationships with suppliers—can be exploited by intelligence services, state-sponsored groups, criminal organizations, and intermediaries specializing in the sale of network access.
The actor and intent may change. The structural exposure remains.
Why telecommunications and edge form a Strategic Node
Telecommunications networks and edge access points can be understood as a Strategic Node: the category used by CSR’s systemic analysis methodology—the Multi-System Tension Framework—to identify structures whose significance derives not only from their individual value, but also from the connections and dependencies they enable.
The Node comprises at least three layers.
The first consists of primary infrastructure: backbones, submarine cables, transit points, edge devices, remote access systems, management planes, and interfaces supporting sensitive functions.
The second comprises trust-based dependencies: managed service providers, systems integrators, shared cloud infrastructure, and relationships of trust between networks and organizations. These actors are not merely external components. They participate in managing access, identities, configurations, and operational continuity.
The third layer consists of the exposed sectors: public administration, defence, energy, transport and ports, finance, and healthcare. These sectors are not necessarily the initial targets, but they depend on the shared networks and services through which a compromise may spread.
This architecture explains why risk cannot be measured simply by counting vulnerable devices. The relationships must also be examined: which functions an infrastructure concentrates, how many organizations depend on the same provider, which privileges cross organizational boundaries, and how effectively the respective environments are segregated.
A technically limited point of access can perform a systemic function far greater than its individual scale would suggest.
The channels of transferability
Transferability is the characteristic that distinguishes a local incident from a systemic risk. It can emerge through several channels.
The first is the transition from an edge device to trusted downstream networks. An edge device is not merely a machine exposed to the Internet: it is a point of mediation between environments with different levels of trust. If compromised, it may provide a favourable position from which to observe or attempt to reach more sensitive segments.
A second channel is the management plane. Administrative accounts, service credentials, and native tools can enable persistent activity that is difficult to distinguish from routine administration. In this case, the real objective is not control over a single device, but the ability to operate through identities regarded as legitimate.
A third channel is represented by shared systems integrators. A provider managing systems and services for numerous organizations acts as an efficiency multiplier, but may also create a concentration of risk.
Compromise of the provider does not automatically imply compromise of its clients: much depends on the segregation of environments, privilege management, and access architecture. Nevertheless, a shared dependency creates the conditions under which a single weakness may affect multiple organizations.
A similar dynamic applies to shared cloud infrastructure. Concentration can improve security, standardization, and response capabilities compared with fragmented legacy systems. At the same time, it increases the systemic value of the shared environment.
The decisive issue, therefore, is not whether concentration is inherently positive or negative, but whether it is accompanied by effective isolation, access control, and the ability to prevent propagation between public administrations and services.
Relationships of trust between networks also require attention. Peering, transit arrangements, and interconnections do not automatically provide a lateral-movement capability, but they may expand the observable surface and create conditions favourable to transfer towards other organizations.
Finally, backbones, submarine cables, and landing points concentrate the transit of large volumes of communications. The ability to read content depends on encryption and the point of access, but metadata, routing information, and the availability of data flows retain significant intelligence and strategic value.
None of these mechanisms, on its own, proves the existence of a systemic compromise. Taken together, however, they show how risk can propagate through infrastructure and dependencies connecting different sectors.
The Italian dimension
For Italy, this issue is particularly significant. The digital transformation of public administration, migration towards shared infrastructure, reliance on qualified systems integrators, and the Mediterranean centrality of transit networks deliver clear benefits, but they also increase the importance of certain shared dependencies.
The answer cannot be a return to fragmentation. Dispersed, outdated, and inconsistently managed systems are not necessarily more secure. The challenge is to govern concentration by making it possible to verify the segregation of environments, the distribution of privileges, and the ability to contain an incident before it crosses organizational boundaries.
The quality of coordination is equally decisive. Telecommunications, digital services, and critical infrastructure are managed by a range of public and private actors. No single organization has a complete view of the phenomenon. An operator may detect a local anomaly; a provider may observe a recurring problem; an authority may hold information from multiple sectors. Without timely information sharing, these signals remain isolated fragments.
The system’s adaptive capacity therefore depends not only on technology, but also on how quickly operators, supply chains, and public authorities can recognize a common pattern.
A European question
The transnational nature of telecommunications prevents the problem from being confined within national borders. Devices, services, providers, and transit infrastructure operate across multiple jurisdictions. Cyberespionage campaigns exploit this technical continuity, while institutional responses often remain divided by organization, sector, or state.
For Europe, the challenge is to transform national confirmations into shared knowledge. A case identified in one country may provide useful information to operators using similar technologies or architectures in other Member States. The value of cooperation lies not only in exchanging technical indicators, but also in the ability to recognize common patterns of exposure, persistence, and transfer at an early stage.
The European framework for network security and incident reporting—the NIS2 Directive—strengthens this capacity. Rules, however, produce results only when supported by operational procedures, institutional trust, and communication timelines compatible with the speed of the threat.
In this context, digital sovereignty does not simply mean national ownership of a technology or infrastructure. Above all, it means understanding and governing the dependencies on which essential functions rely.
Four public priorities
The first priority is to reduce transferability. Networks, services, and relationships with providers must be designed so that the compromise of one component does not automatically grant access to connected environments. Segmentation, separation of privileges, and isolation between organizations must be verifiable conditions, not merely design claims.
The second priority is to protect the management and identity plane. Administrative access must be regarded as critical infrastructure in its own right. Security cannot be limited to endpoint protection: it must also cover service accounts, strong authentication, traceability of changes, and periodic reviews of privileges.
The third priority is to govern concentration. Shared cloud infrastructure and systems integrators can strengthen overall security, but only if systemic risk is explicitly assessed. The greater the number of organizations dependent on the same environment, the more rigorous the requirements for segregation, oversight, and operational continuity must be.
The fourth priority is to improve the system’s memory. Persistent activity may emerge long after the initial access. Without adequate logging and sufficient retention of network and administrative data, it becomes difficult to reconstruct dwell time, distinguish an isolated incident from a broader campaign, and determine which organizations were exposed.
These priorities must be accompanied by a methodological rule: always distinguish fact from attribution. An incident may require an immediate response even when definitive evidence of the actor’s identity is not yet available. Caution in attribution must not lead to inaction; equally, operational urgency does not justify public conclusions that go beyond the available evidence.
Designing for containment
No complex system can base its security on the assumption that every hostile access attempt will be prevented. Growing interdependence, the proliferation of edge devices, and increasing reliance on shared services make this expectation progressively less realistic.
Strategy must therefore incorporate an additional principle: assume that a localized compromise may occur and design the system so that it does not become systemic.
This means shifting the focus from preventing intrusion alone to limiting its consequences. It means asking not only whether a device is vulnerable, but which networks it can reach; not only whether a provider is trustworthy, but which privileges it concentrates; and not only whether a shared environment is protected, but how effectively it separates the organizations it hosts.
Telecommunications networks and edge access points are where these questions converge. They constitute the infrastructure through which different sectors communicate and, for that very reason, may become the infrastructure through which risk is transferred.
The conclusion is not a generic call for “more cybersecurity.” It is a matter of design and governance: reducing uncontrolled dependencies, making privileges visible, and preventing a single point of access from moving undetected across the entire system.
Resilience does not mean the absolute absence of compromise. It means preventing a local compromise from becoming a collective crisis.
Further reading and sources
Internal resources:
- CSR Analysis Methodology (MST Framework)
- Risk Assessment
- Resilience and Security
- Global Strategic Analysis
External resources:
- ENISA — European Union Agency for Cybersecurity
- ACN — Italian National Cybersecurity Agency
- NIS2 Directive — European Commission
For an in-depth, confidential analysis of this Node (internal dossier and MST assessment), Request a confidential contact https://csr-italia.org/en/contatti/ contatto riservato
CSR Italia — Center for International Studies and Relations analyses geopolitics and security through its proprietary MST methodology (Multi-System Tension Framework). Telecommunications networks and edge access points are among the strategic nodes examined using this approach.

