<span>Monthly Archives</span><h1>March 2019</h1>
    Startups

    Drake invests in esports betting startup Players’ Lounge

    March 28, 2019

    Drake’s latest collaboration isn’t with Kanye or Kendrick, it’s with Marissa Mayer.

    The rap superstar has joined a bevy of Silicon Valley investors, including Strauss Zelnick, Comcast, Macro Ventures, Canaan, RRE, Courtside and Marissa Mayer, to fund Players’ Lounge, an esports startup looking to pit gamers against each other in their favorite titles with some friendly wagers on the line.

    The startup has just announced that it closed $3 million in funding.

    The company, which has been around for five years, got its start as an esports startup looking to organize real-life matches at bars in New York City to play FIFA. That’s obviously not the most scalable business of all time, but last year after joining Y Combinator, the company really dove into a new model that looked to create an online hub for gamers to battle each other in titles of their choosing, with money on the line.

    The company has a heavy emphasis on sports titles, like FIFA 19, NBA 2K19 and Madden 19, but there are also some heavy hitters like Fortnite, Apex Legends and Super Smash Bros. Ultimate.

    Gamers can set a match or join one in head-to-head challenges or in massive 500-person tournaments. The wagers are often a buck or two but can swell much higher. Players’ Lounge takes 10 percent of the bets as a fee. Because it’s a game of skill, not chance, there aren’t many issues with gambling regulations, though a few states still don’t allow the service, the company says.

    The startup plans to use their new cash to beef up their library of playable games and add to their development team.


    Source: Tech Crunch Startups | Drake invests in esports betting startup Players’ Lounge

    Startups

    Startup branding: how much does it really cost?

    March 28, 2019

    Editor’s note: This article is a part of our latest initiative to demystify design and find the best brand designers and agencies in the world who work with early-stage companies — nominate a talented brand designer you’ve worked with.

    A brand is far more than logos and colors. A consistent brand identity not only communicates your company’s purpose and values to customers, but it also shapes your product development cycle and corporate culture. A branding project can help you figure out what and how to communicate your company’s story, but how much does it cost?

    I’ve been a designer for over a decade (and a marketer before that), working with organizations ranging from tiny startups to the Fortune 500; this piece will give you a general idea of branding costs, with the knowledge that these broad numbers may not be applicable in every single case (in fact, you’re likely to find exceptions).

    Bootstrappers and pre-seed startups

    For most startups at this stage, your goal is to establish a proof of concept that can show product/market fit and bring investor dollars. You may only need a logo, website, and basic brand positioning. Isla Murray, Creative Director and Cofounder at Lama Six, also recommends investing your money in designing a beautiful deck: “It will set you apart and allow your message to shine through.”

    Brand strategy and positioning

    Positioning involves understanding who you are as a company, how your product fits the marketplace, and how you communicate your company’s values. This is the most important piece of the branding puzzle and one that’s worthwhile to begin on your own – when you have more funding, your original strategy work will give you a base for conveying your identity to professionals who can take it further. Two suggestions that designers commonly recommend are Positioning: The Battle for Your Mind by Al Ries and Jack Trout and Designing Brand Identity by Alina Wheeler, a primer on brand design.

    Approximate cost: Your time.

    Logo and visual identity

    A brand is a relationship with your audience, and you’ll want to make sure that every interaction with them communicates your message. You’ll almost certainly need to hire a designer for this work. Sites like Fiverr and 99designs offer cheap logos, but independent consultants like Pablo Defendini advise that if you can find a small budget, you’ll get far better results by hiring an experienced professional to create a more polished logo and simple usage guide.

    Approximate cost: $100-$3000.

    Website

    As a UX designer and front-end developer, I often recommend that young companies not spend their limited dollars on building a website from scratch – pre-built, templated websites like Squarespace can get you up and running for minimal cost, and you can buy domain names from a registrar like Namecheap. Customizations will be minimal, but you can’t beat the price.

    Approximate cost: $10-30/month, plus $20/year per domain.

    Early-stage, funded startups

    Once you’re paying for experienced help, finding a good fit with a designer is crucial: Trust is the most important factor in a designer-client relationship, and design is ultimately a collaborative process. So take the time to find a contractor or firm that you respect and feel comfortable with.

    Another option: If you already have a strong designer in-house, you might consider setting aside time for them to focus on your brand identity — they’ll cost less, and they already have intimate knowledge of your company values and audience.

    Pricing comes in a wide range depending on your needs: Defindini says he’s worked on identity projects ranging from $5000 for a standalone logo to $200,000 for a complex identity system with multiple brands. Costs are also driven by scope and time. When you receive proposals from firms, be clear about your needs and transparent about what you can afford. Murray says that if clients don’t have a full budget, she’ll look for ways to scope down projects, which might involve reducing deliverables or going through fewer rounds of feedback and iteration.

    Many designers will charge project rates, but if you’re paying by the hour, expect to spend $100-$150/hour for an experienced consultant and $150-$600/hour for a firm depending on their size and location.

    Brand strategy and positioning

    Brand strategy and positioning should drive most of your business decisions, so it’s worth taking the time to do this right. With a smaller budget, a consultant might spend a few days with your company leadership figuring out your core values and how to articulate them. For a larger budget, expect design teams to do more research and a competitive analysis, resulting in deliverables like a communication strategy and voice/tone guidelines for your marketing team.

    More expensive projects may also include things like trainings to make sure your staff correctly and consistently implements your brand. In general, pricing is determined by how many people are working on your branding project and the complexity of your deliverables.

    Approximate cost: $5000-$20,000 (freelancers and small firms), $30,000-$80,000 (large firms).

    Logo and visual identity

    Visual identity is the result of independent research, visual moodboarding, and rounds of feedback and iteration, says Murray. At the end of the process, you’ll typically receive a logo, typeface, color and design elements, and visual brand attributes. Larger-budget projects will typically involve detailed guidance on specific illustration and photography styles, iconography, and more – Murray suggests also including social media visual strategy and Instagram post templates.

    Pricing here increases the more logo variations you need, the more brands you have, and the level of detail required in your visual guidance. Rounds of feedback and iteration add cost, as does the size of the team you hire.

    Approximate cost: $5000-$15,000 (freelancers and small firms), $15,000-$75,000 (large firms).

    Website

    This is the branding piece with the greatest variability in cost, with projects getting more expensive as they require more user research, prototyping, content creation, and engineering work. Pricing is largely dependent on the complexity of engineering requirements and the number of iterations you want to go through.

    Generally, you have static marketing sites on the lower end, websites built on lightweight content management systems (i.e. a custom visual design built to run on WordPress) in the middle, and web applications managing heavy databases or a more robust CMS like Sitecore or Drupal on the higher end.

    Approximate cost: $2000-$20,000 (freelancers and small firms), $30,000-$200,000 (large firms).

    Company name development – for more mature startups

    Many startups find themselves at a stage where they’re well-funded but have a name that no longer fits – what feels right when your company is a month old and bootstrapped with your savings account may not feel the same two years later. A naming agency will develop names that work with your brand positioning, do a competitive analysis to research the tone, strength, and messaging of these names, and pre-screen them for trademark availability. (Note that you’ll typically need to hire a legal team to register the trademark once this is done.)

    Approximate cost: $15,000-$75,000 (naming firm).

    There’s no one-size-fits-all solution

    You may hire one of the top branding agencies in the world or you may have a family member who’s an experienced designer and willing to give you an incredible deal. But no matter who you choose to work with, branding is a vital part of your business that will help you both understand and communicate who you are.


    Source: Tech Crunch Startups | Startup branding: how much does it really cost?

    Startups

    Atom Tickets to challenge MoviePass with a subscription ticket platform for theaters

    March 28, 2019

    MoviePass may still be trying to figure out how to make a movie ticket subscription service financially viable, but it can be credited for at least correctly identifying consumer demand for such a thing. There’s now a market for movie tickets by subscription from it as well as rivals like Sinemia, AMC Stubs A-List, Cinemark Movie Club, and — as of yesterday — newcomer Infinity. Now you can add one more: Atom Tickets, which is today announcing a platform that will allow theaters to build their own movie ticket subscription services.

    The idea here is that the exhibitors themselves — not startups — should be involved in establishing the business model that’s right for them. Atom Tickets will instead provide the underlying technology and support that makes such a thing possible.

    The new platform, called Atom Movie Access, will be offered to exhibitors across North America. It provides a fully digitally booking platform for subscribers through the Atom Tickets app. That means subscribers can also take advantage of Atom Tickets’ other benefits — like reserving seats in advance, inviting friends through their contacts, pre-ordering concessions for quick pickup where available and checking in using a phone instead of paper tickets.

    On the back end, Atom Tickets will also handle the payment processing, customer service, fraud detection and anti-abuse measures. The latter is particularly important for movie ticket subscriptions, as MoviePass noted that as much as 20 percent of its customers were abusing the service, which significantly contributed to its financial issues.

    In addition, the platform will allow subscribers to be able to make complex transactions in-app, like redeeming a free movie while also buying full-priced tickets for a guest in one sale. It also supports things like being able to choose between an included free screening or saving it for later, the company says, and allows for the creation of differently tiered plans. For example, there can be plans for both individuals or groups and tiers for standard and premium movie formats.

    “Atom Tickets is an innovative ticketing platform that enables exhibitors to reach and engage new and incremental audiences,” said Matthew Bakal, chairman and co-founder of Atom Tickets, in a statement about the launch. “We’ve always believed in being a valuable partner to exhibitors, starting with the core functionality of our app, which allows for marketing promotions at specific locations, integrating exhibitor loyalty plans and giving customers the ability to pre-order concessions. Now with Atom Movie Access, we’re thrilled to provide the technology that will enhance the direct-to-consumer relationship of moviegoers with their favorite theaters.”

    There are still several unknowns about the new platform — most notably the pricing for exhibitors. In an interview with Variety, Bakal suggested it would not be prohibitive as Atom Tickets would instead take a cut of subscriptions. The report also noted that no theaters have signed up yet, but the pitching will begin in earnest at a trade show next week in Las Vegas.


    Source: Tech Crunch Startups | Atom Tickets to challenge MoviePass with a subscription ticket platform for theaters

    Startups

    Moolah Mobile partners with Surge to offer free mobile service with ads

    March 28, 2019

    Moolah Mobile is teaming up with SurgePhone Wireless to offer people a new way to pay their cell phone bills — by putting ads on their homescreens.

    Moolah CEO Vernell Woods (pictured above) said the startup has already been offering gift cards and other rewards to users who view its homescreen ads. So this is a similar model, except instead of earning gift cards, the ads are subsidizing cell phone service from Surge.

    The ads show up on users’ homescreens during interstitial moments between using apps, so the goal is to offer free service without consumers having to change their behavior. Woods said all that ad time adds up, with “the average person who’s using their phone on a consistent basis” viewing “easily between two to three hours” of homescreen ads each day. And that’s enough to pay for the “equivalent” of Surge’s $10 monthly plan.

    On the other hand, if for some reason a subscriber isn’t hitting the necessary total, Woods said they can also earn more points by accepting offers or taking surveys.

    Moolah isn’t the only company using advertising to make previously paid products free. Just last week, I wrote about PreShow, a startup promising a free movie ticket for watching 15 to 20 minutes of ads. (Not everyone was crazy about the idea.)

    Moolah Mobile screenshot

    But Woods said he’s doing this because he wants to make wireless service more affordable to people in low-income communities. In the announcement, Moolah investor Tip “T.I.” Harris said it’s “one of the few tech companies I’ve seen who truly want to help everyday people have access to technology.”

    But could this also be seen as a way to harvest personal data from a vulnerable population? Woods said he wants to protect against that with a blockchain initiative set to launch this fall, allowing users to see exactly what data is being shared with advertisers.

    “No personal information should be going to advertisers without users knowing about it,” he said, adding that companies “definitely should not be making money off” personal data without giving users a cut of the profits.

    The subsidized wireless service should be available on Surge Volt Android devices with Moolah install kits, as well as through SIM Starter Kits distributed by Surge. Moolah and Surge said they will roll this out in Florida, Virginia, Georgia and Texas initially, with an aim of reaching 40,000 locations by the end of the year.


    Source: Tech Crunch Startups | Moolah Mobile partners with Surge to offer free mobile service with ads

    Tech News

    Moolah Mobile partners with Surge to offer free mobile service with ads

    March 28, 2019

    Moolah Mobile is teaming up with SurgePhone Wireless to offer people a new way to pay their cell phone bills — by putting ads on their homescreens.

    Moolah CEO Vernell Woods (pictured above) said the startup has already been offering gift cards and other rewards to users who view its homescreen ads. So this is a similar model, except instead of earning gift cards, the ads are subsidizing cell phone service from Surge.

    The ads show up on users’ homescreens during interstitial moments between using apps, so the goal is to offer free service without consumers having to change their behavior. Woods said all that ad time adds up, with “the average person who’s using their phone on a consistent basis” viewing “easily between two to three hours” of homescreen ads each day. And that’s enough to pay for the “equivalent” of Surge’s $10 monthly plan.

    On the other hand, if for some reason a subscriber isn’t hitting the necessary total, Woods said they can also earn more points by accepting offers or taking surveys.

    Moolah isn’t the only company using advertising to make previously paid products free. Just last week, I wrote about PreShow, a startup promising a free movie ticket for watching 15 to 20 minutes of ads. (Not everyone was crazy about the idea.)

    Moolah Mobile screenshot

    But Woods said he’s doing this because he wants to make wireless service more affordable to people in low-income communities. In the announcement, Moolah investor Tip “T.I.” Harris said it’s “one of the few tech companies I’ve seen who truly want to help everyday people have access to technology.”

    But could this also be seen as a way to harvest personal data from a vulnerable population? Woods said he wants to protect against that with a blockchain initiative set to launch this fall, allowing users to see exactly what data is being shared with advertisers.

    “No personal information should be going to advertisers without users knowing about it,” he said, adding that companies “definitely should not be making money off” personal data without giving users a cut of the profits.

    The subsidized wireless service should be available on Surge Volt Android devices with Moolah install kits, as well as through SIM Starter Kits distributed by Surge. Moolah and Surge said they will roll this out in Florida, Virginia, Georgia and Texas initially, with an aim of reaching 40,000 locations by the end of the year.

    Source: Tech Crunch Mobiles | Moolah Mobile partners with Surge to offer free mobile service with ads

    Startups

    Forge acquires IRA Services to expand offering for private company shares

    March 28, 2019

    Forge, the marketplace for trading private company shares formerly known as Equidate, announced that it will be acquiring custodial trust company IRA Services for a purchase price of $55 million.

    IRA Services is a trust company that provides custodial services for retirement accounts managed by individuals and mid-to-large sized Institutions. Stripped of financial jargon, the primary function of a custodian is to hold on to (or maintain “custody” of) its clients’ securities and keep them safe from potential external complications such as theft or otherwise.

    Many custodians, like IRA Services, also provide administrative services such as collecting the actual dividend payments made to the owner of a stock, and advisory services such as helping clients understand what they can and should invest in.

    Since its founding in 2014, Forge has been one of the primary marketplaces where employees and early investors of leading startups can monetize privately-held shares without having to wait years for an IPO, exit or liquidity event.

    Forge also creates value by providing some of the world’s leading private equity and institutional investors with high-demand access to some of the top pre-IPO companies, having worked with several high-profile companies like Spotify.

    By acquiring IRA Services, Forge can expand its support offerings for private market securities, and more importantly, can move closer to becoming a one-stop shop for private market investors who will no longer have to transfer shares acquired with Forge to an external custodial trust.

    “Investors across asset classes want the ease, transparency, and security provided by a seamless investing experience from trading through to settlement to custody,” said IRA Services president Patrick Hughes. “In bringing together Forge and IRA Services, we look to deliver an unparalleled end-to-end investing experience for private markets investors.”

    What differentiates IRA Services from other custody providers, and what makes the company particularly attractive to Forge, is that it specialized in deals involving alternative and non-traded asset classes. As a result, the company already maintains systems and workflows that are structured to deal with private securities and associated complexities.

    Additionally, IRA Services’ API, which automates and supports the process of connecting custody accounts directly to investment platforms, is becoming increasingly valuable as the exchange market for private company shares, as well as average transaction size and volume, continues to swell.

    Pending necessary agency approvals, the combined entity also intends to become both a registered broker-dealer and separate non-fiduciary trust company, meaning the company will be able to provide custodial services for clients even when they’re investing in assets outside of the Forge platform.

    Satisfying growing needs of a budding market

    The acquisition fits squarely into Forge’s long-term vision of being a leading institution in the rapidly growing private markets. “We believe that the private markets are where innovation is happening and there needs to be an institution that provides services that enable that whole ecosystem,” Forge CEO Kelly Rodriques said in a conversation with TechCrunch.

    Rodriques believes that creating secure and transparent custody services for private market securities can provide millions of new investors with access to a space that is currently limited to around 400,000 private equity players, early-stage investors and early employees.

    In Rodriques’ view, broadening the marketplace to more investors creates serious network effects and a significant positive flywheel. Having more participating private company investors creates more liquidity, which not only entices other investors to play in the space but also attracts more private companies to partner with Forge and provide access to their shares.

    At the same time, innovative startups are continuing to grow larger in size, with more than 250 private companies around the world boasting valuations of $1 billion or greater. Companies are also opting to stay private for longer due to the growing availability of late-stage capital, the desire to operate strategically without the scrutiny of the public markets and quarterly performance requirements, or otherwise.

    As a result, locating sources of secure daily liquidity is becoming a bigger need for more private companies. Forge believes that with its growing set of offerings and the credibility it has earned from working with key regulators and several of the world’s largest financial institutions, Forge is well-positioned to be the go-to solution for secondary market investors and companies alike.

    “Our long-term hope is that our technology will be used to make the private market ecosystem stable, safe and sound,” Rodriques told TechCrunch.

    The near-term outlook for Forge doesn’t look too bad either. Forge almost doubled its trading volume in 2018, surpassing just shy of $2 billion worth of transactions, with the company expecting another billion dollars in transactions by the end of the year.

    As with any large acquisition, particularly in the financial services sector and particularly in the US, the companies will have to receive the requisite regulatory approvals to complete the deal in full. While the companies haven’t expressed an official expected close date for the deal, Forge expects the regulatory process will take anywhere from two-to-four months.

    The trust side of the business will transition its name to Forge Trust once the deal closes to better reflect the custodial services gained through IRA Services and the new company’s full suite of capabilities. Additionally, IRA Services CEO, Edwin Blue, will retire from the company, though current IRA Services employees will continue to operate from the firm’s existing offices.

    To date, Forge has raised around $88.5 million in venture capital, according to data from Crunchbase, with backing from a number of Silicon Valley heavy hitters including Peter Thiel, Tim Draper, Scott Bannister, Charlie Cheever, and others.


    Source: Tech Crunch Startups | Forge acquires IRA Services to expand offering for private company shares

    Tech News

    UK report blasts Huawei for network security incompetence

    March 28, 2019

    The latest report by a UK oversight body set up to evaluation Chinese networking giant Huawei’s approach to security has dialled up pressure on the company, giving a damning assessment of what it describes as “serious and systematic defects” in its software engineering and cyber security competence.

    Although the report falls short of calling for an outright ban on Huawei equipment in domestic networks — an option U.S. president Trump continues dangling across the pond.

    The report, prepared for the National Security Advisor of the UK by the Huawei Cyber Security Evaluation Centre (HCSEC) Oversight Board, also identifies new “significant technical issues” which it says lead to new risks for UK telecommunications networks using Huawei kit.

    The HCSEC was set up by Huawei in 2010, under what the oversight board couches as “a set of arrangements with the UK government”, to provide information to state agencies on its products and strategies in order that security risks could be evaluated.

    And last year, under pressure from UK security agencies concerned about technical deficiencies in its products, Huawei pledged to spend $2BN to try to address long-running concerns about its products in the country.

    But the report throws doubt on its ability to address UK concerns — with the board writing that it has “not yet seen anything to give it confidence in Huawei’s capacity to successfully complete the elements of its transformation programme that it has proposed as a means of addressing these underlying defects”.

    So it sounds like $2BN isn’t going to be nearly enough to fix Huawei’s security problem in just one European country.

    The board also writes that it will require “sustained evidence” of better software engineering and cyber security “quality”, verified by HCSEC and the UK’s National Cyber Security Centre (NCSC), if there’s to be any possibility of it reaching a different assessment of the company’s ability to reboot its security credentials.

    While another damning assessment contained in the report is that Huawei has made “no material progress” on issues raised by last year’s report.

    All the issues identified by the security evaluation process relate to “basic engineering competence and cyber security hygiene”, which the board notes gives rise to vulnerabilities capable of being exploited by “a range of actors”.

    It adds that the NCSC does not believe the defects found are a result of Chinese state interference.

    This year’s report is the fifth the oversight board has produced since it was established in 2014, and it comes at a time of acute scrutiny for Huawei, as 5G network rollouts are ramping up globally — pushing governments to address head on suspicions attached to the Chinese giant and consider whether to trust it with critical next-gen infrastructure.

    “The Oversight Board advises that it will be difficult to appropriately risk-manage future products in the context of UK deployments, until the underlying defects in Huawei’s software engineering and cyber security processes are remediated,” the report warns in one of several key conclusions that make very uncomfortable reading for Huawei.

    “Overall, the Oversight Board can only provide limited assurance that all risks to UK national security from Huawei’s involvement in the UK’s critical networks can be sufficiently mitigated long-term,” it adds in summary.

    Reached for its response to the report, a Huawei UK spokesperson sent us a statement in which it describes the $2BN earmarked for security improvements related to UK products as an “initial budget”.

    It writes:

    The 2019 OB [oversight board] report details some concerns about Huawei’s software engineering capabilities. We understand these concerns and take them very seriously. The issues identified in the OB report provide vital input for the ongoing transformation of our software engineering capabilities. In November last year Huawei’s Board of Directors issued a resolution to carry out a companywide transformation programme aimed at enhancing our software engineering capabilities, with an initial budget of US$2BN.

    A high-level plan for the programme has been developed and we will continue to work with UK operators and the NCSC during its implementation to meet the requirements created as cloud, digitization, and software-defined everything become more prevalent. To ensure the ongoing security of global telecom networks, the industry, regulators, and governments need to work together on higher common standards for cyber security assurance and evaluation.

    Seeking to find something positive to salvage from the report’s savaging, Huawei suggests it demonstrates the continued effectiveness of the HCSEC as a structure to evaluate and mitigate security risk — flagging a description where the board writes that it’s “arguably the toughest and most rigorous in the world”, and which Huawei claims shows at least there hasn’t been any increase in vulnerability of UK networks since the last report.

    Though the report does identify new issues that open up fresh problems — albeit the underlying issues were presumably there last year too, just laying undiscovered.

    The board’s withering assessment certainly amps up the pressure on Huawei which has been aggressively battling U.S.-led suspicion of its kit — claiming in a telecoms conference speech last month that “the U.S. security accusation of our 5G has no evidence”, for instance.

    At the same time it has been appealing for the industry to work together to come up with collective processes for evaluating the security and trustworthiness of network kit.

    And earlier this month it opened another cyber security transparency center — this time at the heart of Europe in Brussels, where the company has been lobbying policymakers to help establish security standards to foster collective trust. Though there’s little doubt that’s a long game.

    Meanwhile, critics of Huawei can now point to impatience rising in the U.K., despite comments by the head of the NCSC, Ciaran Martin, last month — who said then that security agencies believe the risk of using Huawei kit can be managed, suggesting the government won’t push for an outright ban.

    The report does not literally overturn that view but it does blast out a very loud and alarming warning about the difficulty for UK operators to “appropriately” risk-manage what’s branded defective and vulnerable Huawei kit. Including flagging the risk of future products — which the board suggests will be increasingly complex to manage. All of which could well just push operators to seek alternatives.

    On the mitigation front, the board writes that — “in extremis” — the NCSC could order Huawei to carry out specific fixes for equipment currently installed in the UK. Though it also warns that such a step would be difficult, and could for example require hardware replacement which may not mesh with operators “natural” asset management and upgrades cycles, emphasizing it does not offer a sustainable solution to the underlying technical issues.

    “Given both the shortfalls in good software engineering and cyber security practice and the currently unknown trajectory of Huawei’s R&D processes through their announced transformation plan, it is highly likely that security risk management of products that are new to the UK or new major releases of software for products currently in the UK will be more difficult,” the board writes in a concluding section discussing the UK national security risk.

    “On the basis of the work already carried out by HCSEC, the NCSC considers it highly likely that there would be new software engineering and cyber security issues in products HCSEC has not yet examined.”

    It also describes the number and severity of vulnerabilities plus architectural and build issues discovered by a relatively small team in the HCSEC as “a particular concern”.

    “If an attacker has knowledge of these vulnerabilities and sufficient access to exploit them, they may be able to affect the operation of the network, in some cases causing it to cease operating correctly,” it warns. “Other impacts could include being able to access user traffic or reconfiguration of the network elements.”

    In another section on mitigating risks of using Huawei kit, the board notes that “architectural controls” in place in most UK operators can limit the ability of attackers to exploit any vulnerable network elements not explicitly exposed to the public Internet — adding that such controls, combined with good opsec generally, will “remain critically important in the coming years to manage the residual risks caused by the engineering defects identified”.

    In other highlights from the report the board does have some positive things to say, writing that an NCSC technical review of its capabilities showed improvements in 2018, while another independent audit of HCSEC’s ability to operate independently of Huawei HQ once again found “no high or medium priority findings”.

    “The audit report identified one low-rated finding, relating to delivery of information and equipment within agreed Service Level Agreements. Ernst & Young concluded that there were no major concerns and the Oversight Board is satisfied that HCSEC is operating in line with the 2010 arrangements between HMG and the company,” it further notes.

    Last month the European Commissioner said it was preparing to step in to ensure a “common approach” across the European Union where 5G network security is concerned — warning of the risk of fragmentation across the single market. Though it has so far steered clear of any bans.

    Earlier this week it issued a set of recommendations for Member States, combining legislative and policy measures to assess 5G network security risks and help strengthen preventive measures.

    Among the operational measures it suggests Member States take is to complete a national risk assessment of 5G network infrastructures by the end of June 2019, and follow that by updating existing security requirements for network providers — including conditions for ensuring the security of public networks.

    “These measures should include reinforced obligations on suppliers and operators to ensure the security of the networks,” it recommends. “The national risk assessments and measures should consider various risk factors, such as technical risks and risks linked to the behaviour of suppliers or operators, including those from third countries. National risk assessments will be a central element towards building a coordinated EU risk assessment.”  

    At an EU level the Commission said Member States should share information on network security, saying this “coordinated work should support Member States’ actions at national level and provide guidance to the Commission for possible further steps at EU level” — leaving the door open for further action.

    While the EU’s executive body has not pushed for a pan-EU ban on any 5G vendors it did restate Member States’ right to exclude companies from their markets for national security reasons if they fail to comply with their own standards and legal framework.

    Source: Tech Crunch Mobiles | UK report blasts Huawei for network security incompetence