← All insights
compliance mandates7 min read

Secure by design meets lawful intercept: the probe-free architecture debate

The CISA secure-by-design guidance and similar frameworks from NCSC and ENISA share a common thread: reduce the attack surface of network infrastructure, eliminate unnecessary data concentration points, and design for breach containment. Lawful intercept infrastructure, as currently implemented, sits awkwardly against each of these principles. The response from the security community has ranged from acknowledging the tension to advocating that operators eliminate or minimise intercept points entirely. Neither extreme is a viable compliance position.

Where the tension is real

Intercept infrastructure — mediation devices, delivery functions, and the interfaces between them — is by design a concentration point for sensitive communications data. It requires privileged network access, often has broad visibility into traffic flows, and is a high-value target precisely because of what it can access. The Salt Typhoon compromise demonstrated that these systems, when inadequately secured, represent exactly the kind of attack surface that secure-by-design frameworks are designed to eliminate.

The tension is not imaginary. An operator genuinely following secure-by-design principles would minimise exactly the kind of persistent, privileged, network-wide access that a comprehensive LI system requires. The question is not whether the tension exists but how to manage it within a binding legal obligation.

What probe-free actually means in practice

Some architecture discussions use "probe-free" to mean eliminating passive deep-packet inspection probes in favour of native network element interfaces — using the 3GPP X1/X2/X3 LI interfaces built into 5G SA core elements rather than deploying external probes. This is a legitimate and technically sound direction that reduces the number of privileged access points and aligns with the vendor security posture for modern core elements.

Others use "probe-free" to mean reducing intercept coverage to avoid maintaining systems that regulators could require be expanded. This is not a compliant architecture position. CALEA and equivalent frameworks impose capability obligations that are not discretionary, and enforcement actions for capability gaps are a real and growing risk.

A constructive path forward

The most defensible architectural direction combines native LI interfaces in the 5G core with rigorous security hardening of the mediation and delivery layer — restricted network access, zero-trust authentication for LI management interfaces, encryption of warrant metadata at rest, and separation of LI management from the data plane. This reduces the attack surface without reducing coverage.

Operators should also maintain detailed audit trails of access to LI systems: every warrant processed, every interface queried, every administrative action logged. This is good security practice and provides the evidence trail that regulators increasingly expect to see. Security and compliance in this domain are not opposing requirements; they are both served by the same discipline of knowing exactly what the system can do and being able to prove it.

Yaana Technologies

Ready to audit your intercept stack?

Talk to the Yaana team about secure-by-design infrastructure for your network.

Request a Meeting →