A
system for the cybersecurity of
telecommunications networks (100), comprising: a cloud-native zero-trust control plane (1) configured to generate and enforce access policies for
telecommunications workloads, network functions and application
programming interfaces; an identity, device and context engine (2) configured to determine an identity context for at least one entity that includes a participant, a device, a network function, a service or an administrator; a
telecommunications telemetry acquisition and streaming layer (3) configured to acquire multiparameter
telemetry data from at least one telecommunications domain which includes a
radio access network, a
core network, an IP
transport network, an edge cloud or an OSS / BSS domain; a
feature engineering and normalization layer (4) configured to transform the collected
telemetry data into standardized features for analysis; an ML-based engine for
anomaly detection and
threat assessment (5) configured to detect
anomalous behavior and output a
threat assessment based on standardized features and identity context; a correlation,
threat intelligence, and explainability module (6) configured to correlate the
anomalous behavior with the telecommunications topology context and generate an explainable security alert; and a
dashboard (7) for automated response,
orchestration and
compliance monitoring, configured to trigger one or more remediation actions based on the
threat assessment and to log the remediation actions for audit purposes, where the
system (100) performs a continuous review of the entity and enforces least-privileged access according to a zero-trust framework, while using
machine learning to detect cyber anomalies.