Verder naar navigatie Doorgaan naar hoofdinhoud Ga naar de voettekst

The growing importance of Privileged Access Workstations to the UK telecommunications sector

Why providers need to think beyond the device

door Chris Proctor

06 oktober 2026

Since receiving Royal Assent in 2021, The UK Telecommunications Security Act (TSA) is reshaping how telecommunications providers secure their fixed-line and mobile networks.

Whilst UK telecoms providers have been bound by the TSA since 2021, and the associated regulations issued in 2022, the Telecommunications Security Code of Practice recommended compliance timeframe for Measures related to Privileged Access Workstations (PAWs) of 31 March 2027 is moving a theoretical security control to a practical implementation challenge for larger providers. However, one of the most common misconceptions is that a PAW is simply a hardened end user device or virtual desktop. In reality, successful PAW deployments require organisations to rethink privileged access, administrative boundaries, identity architecture, third-party support models, operational workflows and implementation of browse-down architectures.

Through our work with telecoms providers, a recurring challenge for our clients is that many environments were not originally designed with segregated privileged administration in mind. Shared cloud tenants outsourced remote support models, legacy infrastructure, operational technology platforms and complex supplier ecosystems can significantly increase the number of users who potentially require privileged access.

In several of our recent engagements, the requirement for PAWs has become an architectural catalyst, driving discussions around:

  • Separate administrative tenants
  • Dedicated privileged identities
  • Stronger authentication controls and,
  • Improved segregation of critical services

Another common lesson from the work we are doing is that organisations cannot simply deploy PAWs and assume they’ll achieve TSA compliance. User journeys must first be understood, including the associated processes and business workflows. Network engineers, cloud administrators, security teams, developers and third-party suppliers all have different access requirements. Poorly designed solutions risk creating operational friction that encourages workarounds. Successful PAW implementation programmes therefore focus on user-centred design, ensuring privileged administrators can still perform their duties and collaborate with others, whilst reducing exposure to credential theft, lateral movement and management plane compromise.

During a recent round table with clients from the UK telecoms sector a further theme was discussed around the importance of privileged identity segregation. Many organisations currently operate privileged and standard accounts within the same identity estate. Emerging target architectures discussed across multiple engagements converge around dedicated administrative environments, separated Microsoft Entra tenants, FIDO2-based authentication, dedicated PAWs and tightly controlled trust relationships between privileged and production environments. This approach reduces attack paths and makes it easier to demonstrate compliance and assurance outcomes.  

The challenge extends beyond internal teams. Telecoms providers frequently depend on managed service providers, cloud providers and other third party suppliers. A key consideration is determining which privileged users genuinely require PAWs and how suppliers will access in-scope systems. Shared administration models can dramatically increase the PAW population and create both operational and commercial challenges. As a result, many providers are discovering that privileged access requirements influence wider hosting, tenancy and support model decisions.  

Perhaps the most important lesson is that there is no universal PAW design. From our experience PAWs are not a product that can simply be purchased and deployed. Every organisation must balance security, usability and operational requirements. The most successful programmes begin with discovery, privileged user journey mapping and architectural assessment before moving into detailed design, implementation and assurance.  

As the March 2027 TSA milestone approaches, providers that delay these decisions may find themselves attempting to solve far more than an endpoint challenge. Those starting now have an opportunity to use PAWs as the foundation for stronger management-plane security, improved privileged access governance and more resilient telecoms operations.

PAWs should not only be viewed as a compliance requirement

When implemented well alongside other key elements such as appropriate identity management, PAWs provide a practical mechanism for reducing management-plane risk, strengthening operational resilience and improving confidence in the security of critical telecoms infrastructure. The organisations making the most progress are those treating PAWs as an enabler of modern privileged access architecture rather than as a stand-alone endpoint security project.  

NCC Group is helping providers with tailored support to develop clear and implementable plans based around the TSA requirements for PAWs and is engaged in implementing those plans where requested. 

Chris Proctor

Chris Proctor

Telecoms Practice Associate Director, NCC Group UK

With 23 years of experience in the global telecommunications market, Chris supports NCC Group's clients with their security requirements, particularly regarding their regulatory obligations.

He's held previous roles at Nokia and the UK’s Lead Government Department for telecommunications, DCMS. Our clients benefit from Chris's rich insights he gathers from his ongoing engagements with the sector's affiliated organisations such as Ofcom, GSMA, and NCSC. 

Learn more

If you would like to discuss how we can help your organisation design and implement a successful Privileged Access Workstation programme please get in touch and to learn more about the TSA visit our website.