OneLayer adds four auto-detections to private cellular platform

OneLayer's Bridge platform now flags four cellular threat patterns automatically, including FCC-listed modems and IMEI spoofing, with no customer configuration needed.

An evenly lit data center server rack holds black network switches, modular servers, and silver rack-mount devices, with neatly bundled black cables secured by Velcro ties, and is flanked by perforated metal panels.

OneLayer has detailed four automatic threat detections added to its Bridge platform for enterprise private cellular networks, covering device-to-device lateral movement, hardware from manufacturers on the FCC's Covered List, SIM and modem identity spoofing, and unauthorised device migration across routers. The Boston-based company says all four are live for every Bridge customer today, with no new hardware or configuration required.

The announcements are framed as outputs of a standing threat-research process: the OneLayer team identifies patterns in device and traffic data that Bridge already collects, validates them against the platform, and ships detections to customers automatically. The company is explicit that the four examples do not represent exhaustive coverage; they are intended to illustrate the research methodology.

The four threat patterns

The most concrete example involves a December 2025 attack on a Polish combined heat and power plant, which serves roughly 50,000 residents. Attackers pivoted from a connected wind farm by opening SSH tunnels across a shared private access point name. OneLayer says Bridge's east-west traffic visibility already flags that activity the moment a tunnel opens, and the company published a technical breakdown on the same day CERT Polska released its follow-up report in August 2026.

The second detection targets hardware supply-chain risk. As the FCC's Covered List of scrutinised overseas manufacturers continues to expand, OneLayer Bridge fingerprints the make, model and chipset of every onboarded device and raises an alert if a modem from a listed manufacturer appears, whether at onboarding or when the list is subsequently updated.

The third pattern addresses SIM-layer attacks. Research published this month demonstrated that a malicious SIM card can issue commands directly to a device's modem, with proof-of-concept work covering EV chargers, industrial routers and telematics units. OneLayer's existing IMEI spoofing detection handles the same identity layer: Bridge fingerprints every device against its known identifier and flags any mismatch on connection.

The fourth detection targets the network edge. Newly disclosed vulnerabilities in widely deployed industrial cellular routers could allow an attacker to impersonate a legitimate device remotely. Bridge tracks the router each device was onboarded against and raises an alert when a device appears behind a different one, whether the migration was intentional or not.

Dave Mor, chief executive of OneLayer, said: "Every one of these threats comes at the enterprise from a different direction: the SIM, the modem, the router, the traffic moving between devices. What enterprises need is one layer of protection across the whole cellular estate."

Market context

Private LTE and 5G networks are expanding rapidly across utilities, manufacturing, logistics and critical infrastructure, largely because they offer lower latency, higher device density and better coverage than Wi-Fi in operational technology environments. That growth is bringing cellular security under the same scrutiny already applied to IT networks, though the tooling remains far less mature. Most enterprise security operations centres have limited visibility into signalling-layer events and device identity at the SIM or modem level, a gap that purpose-built vendors such as OneLayer are positioning themselves to fill.

The FCC's Covered List, which restricts federal procurement of equipment from named manufacturers including Huawei and ZTE, has increasingly influenced private-sector purchasing decisions, particularly among operators in regulated sectors. Its relevance to private cellular deployments is a relatively recent concern, and automated enforcement at the device fingerprinting layer is not yet standard across the market. Competitors in the OT and industrial network security space, including vendors approaching the problem from the IT side, are only beginning to address cellular-specific attack surfaces with comparable depth. OneLayer's research-led, automatic detection model is a differentiator for now, though the durability of that advantage will depend on how quickly the broader security market catches up.