Summary
- Corero has secured a five-year contract worth $3.4 million with an unnamed Tier-1 UK fixed and mobile telecommunications provider.
- The deployment combines on-premises DDoS protection with a UK-based security operations capability and includes Layer 7 TLS protection.
- Existing Telecommunications Security Act duties are already influencing procurement, while the separate Cyber Security and Resilience Bill remains proposed legislation.
Britain’s telecom security regime is beginning to show up directly in purchasing decisions, with an unnamed Tier-1 fixed and mobile operator signing a five-year DDoS protection contract whose architecture reflects regulatory demands around resilience and operational control.
Corero Network Security has secured the $3.4 million contract alongside one of its strategic alliance partners, providing the operator with a managed service built around its SmartWall ONE DDoS protection technology and CORE platform. The deployment will also include Layer 7 Transport Layer Security protection, extending the service beyond simpler volumetric attacks against network capacity.
The customer has not been named, although Corero describes it as a leading UK provider of fixed, mobile, and connectivity services and places the contract within the country’s critical national telecommunications infrastructure. Its system will be deployed on premises, while Corero’s UK security operations centre forms part of the service model.
The company also announced a separate three-year contract worth $500,000 with an unnamed neocloud provider, initially covering two data centres with the possibility of expansion. Corero says it now protects three large neocloud operators, linking the established telecom resilience market with a newer group of infrastructure providers built around high-density AI computing.
The UK telecom contract is the more revealing of the two because security requirements have become considerably more prescriptive since the Telecommunications (Security) Act 2021 introduced a strengthened statutory framework for public telecom networks and services. Detailed requirements sit alongside the Electronic Communications (Security Measures) Regulations 2022 and the Telecommunications Security Code of Practice.
Security requirements become buying criteria
The regime requires public telecom providers to take appropriate and proportionate measures to identify, prevent, and manage security risks while maintaining the availability of networks and services. Ofcom has oversight responsibilities, which means operators need evidence that controls exist and can withstand regulatory scrutiny rather than relying solely on broad security policies.
That changes infrastructure procurement because technical architecture can become part of a compliance decision. Corero says its on-premises deployment and UK security operations capability were important to the customer, reflecting a preference for greater control over systems protecting nationally important communications services.
There is an important distinction in the company’s regulatory framing. Corero refers to both the Telecommunications Security Act and the Cyber Security and Resilience Bill when describing the pressures affecting the customer, but the former is existing law while the latter remains proposed legislation intended to reform the wider Network and Information Systems regime.
Proposed regulation can still influence investment before it becomes law because large infrastructure operators rarely wait until a final compliance deadline before adjusting systems with lengthy procurement and deployment cycles. The planned cyber reforms would expand regulatory coverage, strengthen incident reporting, and increase scrutiny of critical suppliers and managed service providers, extending the broader push towards demonstrable resilience across essential digital services.
The telecom regime already gives operators enough reason to examine where security technology is operated, who can administer it, how attacks are detected, and whether a supplier can provide evidence about service availability and incident response. Those questions increasingly belong inside tender evaluation rather than remaining solely with security teams after a product has been selected.
AI infrastructure creates another resilience market
Corero’s smaller neocloud contract points towards a related market emerging around AI infrastructure. Neocloud providers have built businesses around specialised accelerator capacity, leaving availability central to the economics of services where expensive computing hardware generates revenue only while customers can reach and use it.
DDoS protection therefore moves alongside power, cooling, networking, and physical security as part of the operating infrastructure behind AI capacity. Disruption to a conventional corporate website can damage sales or reputation, while an outage affecting a heavily utilised computing platform can also strand costly hardware and interrupt customer workloads running across the estate.
Those economics help explain why security vendors are following AI investment into the data-centre market. As operators add capacity and enterprise customers run more production systems on specialist infrastructure, expectations around resilience begin to resemble those applied to established cloud and communications providers.
Corero’s contracts remain modest beside the capital being committed to telecom networks and AI data centres, but they show two sources of demand converging around the same security function. One is regulatory, with communications providers required to demonstrate stronger control over critical networks; the other is commercial, as AI infrastructure providers attempt to protect expensive capacity and service availability.
For security suppliers, that convergence creates an incentive to package technical protection with operating models that answer questions about jurisdiction, monitoring, incident response, and governance. The customer is buying more than traffic filtering when the location of the security operation and the way the service is managed become part of the selection criteria.
The UK telecom contract therefore provides a practical view of what a more regulated cyber market can look like. Rules written around resilience ultimately have to be implemented through networks, services, people, and procurement decisions, and the spending now appearing around DDoS protection shows those obligations moving further into the technology stack.












