When the Regulator Audits Your Tooling Too
A national operator is critical infrastructure, and the security stack protecting it is inside the assessment scope. Whitespots runs on your own infrastructure, so the platform that holds your vulnerabilities is as auditable as the network it protects.
The security stack is auditable too
When a national regulator reviews how you protect the network, a platform you host and control is a shorter conversation than a vendor cloud.
Asset discovery at operator scale
Subscriber portals, regional brands, campaign microsites and forgotten staging hosts — discovered continuously rather than at assessment time.
OSS, BSS and everything between
Billing, provisioning, self-care apps and network-facing services in one findings model instead of one tool per department.
Incident-ready records
Short notification deadlines assume you can already say what was affected and when it was known. That is a data question, answered in advance.
What Operator Security Teams Run Into
The application layer of a telecom operator is unusually wide and unusually old at the same time — and national-security rules apply to it.
Surface nobody has a full list of
Acquisitions, regional brands, MVNO tenants and a decade of marketing sites mean there are more assets than any hand-maintained inventory lists.
Tooling inside the assessment scope
A cloud scanner holding a live map of your unpatched systems is itself a supply-chain question, and one a national regulator is entitled to ask about.
Notification clocks that start early
Significant-incident reporting is measured in hours, not weeks. Reconstructing what was known and when, after the fact, is not compatible with that.
Vendor code you cannot patch
Network functions arrive as vendor software. You still own the risk, so you need the finding recorded and tracked even when the fix is someone else's release.
What the Frameworks Actually Require
Telecom-specific obligations that reach the application layer, plus the horizontal ones that reach it hardest.
risk-management measures
Essential and important entities must implement measures including vulnerability handling and disclosure, security in network and information systems acquisition, development and maintenance, and supply-chain security.
How Whitespots helps
Every change scanned, with automatic validation, notifications and per-severity SLAs, dependency and container coverage for the supply chain, and quality gates in development.
incident reporting
An early warning within 24 hours of becoming aware of a significant incident, and an incident notification within 72 hours.
How Whitespots helps
A dated record of what was known about each affected system, so the first report is an export rather than an investigation.
telecom providers in scope
The EECC security articles 40 and 41 were deleted from 18 October 2024. Public electronic communications providers now fall under NIS2 regardless of size, and medium-sized providers are essential entities.
How Whitespots helps
Application-layer risk measured continuously and expressed per service, which is the granularity a national authority asks for.
Guideline on Security Measures under the EECC
Security objectives written for the former EECC security articles, each with three sophistication levels — including change management and regular security scans and testing of critical systems.
How Whitespots helps
Maturity here is mostly about repeatability and evidence — both produced by running the process in one place rather than four.
equipment security assurance
An assurance scheme for network equipment vendors, covering secure development lifecycle audit and product security testing against defined requirements.
How Whitespots helps
For vendors: development-lifecycle evidence per release. For operators: a place to record findings in vendor-supplied products you cannot patch yourself.
security of processing
Regular testing, assessing and evaluating of technical measures protecting subscriber data, including traffic and location data.
How Whitespots helps
Continuous testing on infrastructure inside your own perimeter, so subscriber-adjacent code is never processed by an outside party.
References reflect published text as of August 2026 and describe obligations rather than a certification we grant. National transposition of NIS2 varies — confirm scope, thresholds and deadlines with your regulatory affairs function.
What Whitespots Gives a Telecom Security Team
Built for infrastructure that is large, partly vendor-supplied, and permanently in scope.
Your map of unpatched systems never leaves your network
-
A short answer when the regulator asks about tooling You host it, you control it, you can show it.
-
Zero outbound data No code, findings, logs or usage data leave your servers.
-
Fits restricted network zones Runs in segments with no internet access.
Find the hosts nobody listed, before an attacker does
-
Forgotten hosts come to light Dormant staging and campaign sites are found, not assumed gone.
-
Acquisitions join the queue on day one Discovery runs continuously, not at assessment time.
-
Every brand and region in one view Findings grouped by brand, region and business unit.
Vendor risk stays tracked even when the patch isn't yours
-
Vendor flaws followed to the fix Each finding has a vendor owner and is tracked to their release.
-
One queue instead of one tool per department Any scanner, pentest or manual result lands in the same model.
-
A dated answer to "how long was it open?" Full history from first detection to closure.
A 24-hour incident notice becomes an export, not an investigation
-
Know what was affected, and since when Every finding dated per system from detection onwards.
-
Separate evidence per national authority Scoping per legal entity across a multi-country group.
-
Audit-ready at any moment Exportable reports for authorities and internal audit.
Where It Lands
The four things an operator security function is usually asked to produce.
- Scenario
A national authority reviews your security tooling
With Whitespots platformA platform you host, control and can show them, with no external data flow.
- Scenario
A significant incident starts a 24-hour clock
With Whitespots platformWhat was known about the affected systems, and when, exported rather than reconstructed.
- Scenario
An acquisition brings unknown infrastructure
With Whitespots platformDiscovery enumerates it, and its findings enter the same queue as everything else.
- Scenario
A vendor network function ships a vulnerable component
With Whitespots platformRecorded, owned and tracked to the vendor's release rather than lost in email.
Already Running at National Operators
National mobile operators are among the platform's larger deployments. Names are withheld here pending each customer's sign-off.
National mobile operator
Deployed inside the operator's own network zone so no vulnerability data crosses the perimeter.
National mobile operator · second market
Uses continuous asset discovery across regional brands and campaign sites that no inventory covered.
What Telecom Teams Ask First
Can it be deployed in a segmented or restricted network zone?
Yes — that is the normal shape here. The platform is self-hosted, so it can sit inside whichever zone your architecture requires, including environments with no outbound internet access. What it can scan is then a question of network reachability, not licensing.
How does this help with a 24-hour incident notification?
The hard part of an early warning is stating what is affected while the investigation is still running. A per-finding record with dates and affected systems turns that first report into an export. It does not write the report for you, but it removes the archaeology.
Most of our network functions are vendor software. What is the point of scanning?
You still own the risk and still have to report on it. The value is in recording the finding, assigning a vendor owner, tracking it to their release, and having that history when an authority asks how long a known issue stayed open.
We have far more assets than our inventory lists. Where do we start?
With external discovery. Enumerating what is actually reachable usually changes the shape of the programme more than adding another scanner to the systems you already knew about.
We operate in several countries under one group. Does that fit?
Yes. Scoping and roles are per-entity and per-region in a single instance, so each national authority gets evidence about its own operator without a separate installation.
Put the Security Platform Inside the Perimeter It Protects
Start with a free external scan of the assets a regulator can already see, or talk to us about a deployment inside your own network zone.