Telecoms security duties need a register that links networks, suppliers and incidents.

Under the Telecommunications (Security) Act and its regulations, providers must manage security risk across their networks and suppliers and tell Ofcom about security compromises. When suppliers, controls and incidents are tracked in separate places, showing that duty is met takes longer than meeting it. ERM+ keeps them linked.

Who this page is for

  • Telecoms and broadband providers
  • Network operators
  • Phone-paid and premium rate services

Typically 100 to 1,000 employees, established and regulated, with the risk register, supplier oversight and resilience work still run largely by hand.

What you are asked to show, and where ERM+ holds it

Telecommunications (Security) Act 2021

What it asks

Appropriate and proportionate measures to identify and reduce the risk of security compromises, set out in the Security Measures Regulations and Code of Practice.

What ERM+ holds

Security risks mapped to network functions, the controls that address them and the evidence those controls were applied.

Security compromise reporting

What it asks

Significant security compromises reported to Ofcom promptly, with the facts to hand.

What ERM+ holds

Incident records with impact, timeline, affected services and suppliers captured when the incident is raised.

Supplier risk

What it asks

Control over the risks introduced by third-party suppliers, including managed service providers with network access.

What ERM+ holds

A supplier register linked to the access each supplier holds, the risks it creates and the incidents it has been part of.

Consumer and phone-paid rules

What it asks

Effective oversight of the partners and promoters that deliver services to consumers.

What ERM+ holds

Partner due diligence, issues and remediation tracked against the services they deliver.

A summary to frame the conversation, not legal advice. The first call establishes exactly which requirements apply to your firm.

If Ofcom asked for your supplier risk evidence tomorrow, how many places would you pull it from?

  • Suppliers hold the keys

    Managed service providers and vendors often have privileged access to the network, and their risks sit outside your core register.

  • Incidents need facts fast

    When a security compromise is reportable, the time goes into working out which services and suppliers were involved.

  • Evidence is scattered

    Control testing, supplier reviews and incident logs live with different teams, so assembling a view for Ofcom is a project every time.

Who usually owns this

CTO / CIO

Also: Head of IT, Head of Technology Risk

What you are dealing with
ICT risk, vendor management, business continuity and incident response are yours, and they are tracked across tools that do not talk to each other.
What ERM+ gives you
ICT risks, systems, suppliers and incidents linked to the services they support, with continuity and resilience evidence in the same record.
Usually prompted by
An incident, a vendor failure, or a resilience test that exposed a gap.

Built by practitioners, priced below enterprise GRC

More than 50 years of risk experience between the co-founders and over 500 with our senior associates. Implementation in weeks, not months.

Meet the team

“ERM PLUS significantly reduced the time and resources for achieving regulatory compliance in risk and prudential management.”

Head of OpRisk · Asset Management Firm

“The expertise and professionalism of the ERM Plus team are unparalleled. Their strategic guidance and hands-on approach have been instrumental in achieving our business goals.”

Head of Risk · Retail Brokerage Firm

Twenty minutes will tell us both whether there is anything worth exploring.

We look at what you capture today, what your regulator will ask for, and whether there is a gap. If there is nothing there, no need to take it further.

A gap check, not a pitch. No project, no budget conversation, no access to sensitive data.