Telia: Findings in 2025 ETSI Audit - Incident Report #1 – Vulnerability management
Telia Company reported a non-conformity identified during their 2025 ETSI audit regarding the timely remediation of critical vulnerabilities. The vulnerabilities were discovered in penetration tests conducted on October 13, 2025, but were not addressed within the required 48-hour timeframe, as mandated by ETSI EN 319 401. Following the audit findings, Telia submitted a preliminary incident report on November 10, 2025, and a full report on November 21, 2025, detailing the incident and corrective actions taken. The CA implemented a remediation plan, including deploying a new server and conducting training to ensure compliance with vulnerability management requirements. The case has been resolved with all action items completed.
- Non-compliance start date identified
- Immediate remediation plan created and affected server shut down
- Incident report closed
- Teliacompany representative — Preliminary incident report submitted detailing non-conformity regarding vulnerability management.
- Teliacompany representative — Full incident report submitted with detailed analysis and remediation steps.
- Teliacompany representative — All action items completed; preparing closure report.
- CCADB representative — Final call for comments on the incident report before closure.