Company Check : Ofcom Investigates BT and Three Over 999 Call Failures

Ofcom has opened formal investigations into BT and Three following separate UK-wide mobile network failures this summer that left some customers unable to connect 999 emergency calls.

Two Major Outages

The investigations centre on two major outages, one affecting Three customers in June and another impacting BT and EE customers in July, both of which disrupted basic voice services across large parts of the country. Ofcom said it is examining whether the companies took sufficient steps to prevent the incidents and to protect access to emergency services, which are treated as a critical national function under UK telecoms regulation.

What Happened During The Summer Outages?

The first incident occurred on 25 June, when thousands of customers on the Three network reported being unable to make or receive voice calls. The outage was nationwide and affected not only Three customers but also users on virtual operators that rely on its infrastructure, including ID Mobile. While mobile data services largely remained available, voice calls failed to connect, including calls to emergency services.

Three later said the problem was triggered by “an exceptional spike in network traffic” caused by a third-party software configuration change. The company acknowledged that the disruption affected access to 999 services and informed Ofcom at the time.

A second incident followed on 24 and 25 July, when customers on BT and its mobile network operator EE reported similar problems. In this case, BT attributed the disruption to a software issue that affected call interconnection between networks. As a result, some customers were unable to make or receive calls, including calls to emergency services, despite having signal on their devices.

Ofcom said both incidents caused UK-wide disruption and affected millions of mobile users across the two networks.

Why 999 Call Failures Raise Regulatory Stakes

While mobile outages are not uncommon, failures that prevent access to emergency services significantly increase regulatory scrutiny. For example, under UK law, telecoms providers have specific obligations to ensure that 999 and 112 calls can be made reliably, even during periods of network stress or partial failure.

Ofcom said providers must take “appropriate and proportionate” measures to identify risks to their networks and to plan for scenarios that could compromise availability, performance or functionality. These duties extend beyond preventing outages altogether and include effective monitoring, rapid response and mitigation when failures occur.

In announcing the investigations, Ofcom said it would assess “whether there are reasonable grounds to believe that BT and Three have failed to comply with their regulatory obligations”.

The regulator has not suggested that enforcement action is inevitable, but it does have the power to impose financial penalties, require remedial changes to network design or processes, or issue formal directions if breaches are found.

Network Resilience

Ofcom has placed increasing emphasis on network resilience in recent years, particularly as the UK becomes more reliant on mobile connectivity for essential services. For example, its Network and Service Resilience Guidance sets out expectations for how providers should design and operate networks to reduce single points of failure and limit the impact of incidents.

The guidance states that firms are expected to “identify and reduce the risks of disruption” and to take steps to prevent “adverse effects arising from any such compromises”. Where outages do occur, providers are expected to respond quickly, communicate clearly with customers and learn lessons to reduce the likelihood of recurrence.

Commenting on the investigations, Ofcom said: “The importance of connectivity cannot be underestimated. People rely on their mobile phones to stay in touch, to work, and to contact the emergency services.”

The regulator has made clear that customer impact, including the duration and scale of disruption, will be a central factor in assessing whether obligations were met.

Industry Reaction And Company Responses

Both companies have said they are cooperating fully with the investigation. A spokesperson for BT Group said the company apologised to customers affected by the July incident and would “co-operate fully with Ofcom throughout the investigation”. BT has previously said the outage was caused by a software issue rather than a hardware failure, and that services were restored once the fault was identified.

Three UK said it had engaged openly with Ofcom since the June outage and would continue to do so. The company said the disruption followed a third-party software configuration change that led to unexpected traffic levels on its voice network.

Ofcom has previously made clear that outages can still occur even where networks are designed with resilience in mind, but that providers are expected to have robust processes in place to detect faults quickly, limit their impact, and identify lessons that reduce the risk of similar incidents in future.

The regulator’s guidance stresses that compliance is not limited to preventing failures outright. It also includes effective planning, monitoring and response when services are disrupted, particularly where access to emergency calls is affected.

Previous Enforcement Action

The investigations also take place against a backdrop of previous enforcement action in the sector. For example, back in July 2024, BT was fined £17.5 million after Ofcom found a “catastrophic failure” in its emergency call handling service had prevented around 14,000 999 calls from connecting during a ten-hour outage in June 2023.

Three has also previously been fined by Ofcom. In 2017, the company was ordered to pay £1.9 million after a network failure in 2016 left customers without service. Ofcom concluded at the time that the disruption could have been prevented with better planning and safeguards.

More recently, Three’s UK operations merged with Vodafone to form VodafoneThree, creating the UK’s largest mobile network with around 27 million customers. While the summer outage occurred before the merger was completed, the investigation comes at a sensitive time as the combined business works to integrate networks and systems.

Why The Issue Matters More Now

The timing of the outages has heightened concern because mobile networks are increasingly treated as critical infrastructure. As the UK progresses with the digital landline switchover, many households and vulnerable users are becoming more dependent on mobile connectivity for emergency communication.

Ofcom has repeatedly warned that resilience expectations apply not just to traditional landlines but to all networks that support access to emergency services. The regulator has also highlighted the need for additional safeguards for users who rely on telecare systems, personal alarms or medical monitoring that may depend on voice connectivity.

Government guidance has echoed these concerns, with ministers previously stating that communications providers have statutory obligations to ensure networks are “appropriately resilient”.

What Ofcom Will Examine Next

Ofcom said its investigations will focus on the facts surrounding each incident, including how the faults arose, how quickly they were detected, and what steps were taken to restore services and protect emergency calling. It will also examine whether risk assessments, change management processes and contingency planning were adequate.

The regulator has not set a public timetable for completing the investigations and outcomes could range from no further action if compliance is found, through to enforcement measures if breaches are identified.

What Does This Mean For Your Business?

The investigations place renewed focus on how mobile networks are operated, governed and tested in practice, particularly where basic voice services are relied on for public safety rather than convenience. For Ofcom, the outcome will help clarify how existing resilience rules are being applied in real incidents and whether further intervention is needed to ensure emergency access is protected as networks become more complex and software-driven.

For telecoms providers, the cases highlight how resilience is being judged across the full lifecycle of network management, from configuration changes and third-party dependencies through to detection, response and communication. The fact that both incidents involved software-related failures rather than physical damage is likely to be closely examined, especially as automation and network virtualisation play a growing role in UK mobile infrastructure.

There are also wider implications for UK businesses that depend on mobile voice services for operational continuity, safety procedures and customer contact. For example, prolonged or widespread loss of calling capability, even where data services remain available, can disrupt frontline operations, lone worker safety and emergency escalation processes. The investigations may prompt organisations to recheck how resilient their own communications arrangements are, particularly where mobile phones are the primary or sole method of contact.

For consumers, emergency services and vulnerable users, the cases reinforce why mobile networks are now treated as critical infrastructure rather than optional utilities. As the digital landline switchover continues and reliance on mobile connectivity deepens, the tolerance for failures affecting 999 access appears to be narrowing. How Ofcom responds, and what it requires of operators as a result, is likely to shape expectations around network reliability and accountability well beyond these two incidents.

News : BT Launches Sovereign Platform For UK Cloud And AI Control

BT has launched a new UK-based sovereign platform designed to give organisations tighter control over their data, systems, and AI infrastructure at a time of rising geopolitical tensions and growing public sector reliance on cloud services.

A New Foundation For Sovereign Services

Sovereign services are digital services run entirely within UK infrastructure and UK legal control, with access restricted to UK-based staff where required. BT’s announcement marks a significant shift in how it intends to support organisations that need clear assurances over where their data is stored, who can access it, and which legal frameworks govern it.

A Foundation Rather Than A Standalone Product

The company describes the platform as a foundation rather than just a standalone product, with sovereign voice, cloud, and AI services set to roll out over the coming months. BT Business also plans to offer sovereign versions of many existing core products by the first half of 2026, giving customers the ability to tailor their level of sovereignty depending on operational need.

BT says all services can be delivered through UK-based infrastructure and, where required, supported exclusively by UK-based staff. This point is central to the offer because it directly addresses concerns from defence, critical national infrastructure, government, and regulated sectors about overseas access, foreign jurisdiction, and long-term control of sensitive data.

Trust In The Infrastructure

Jon James, CEO of BT Business, emphasised the strategic importance of the shift, stating that “sovereignty isn’t simply a matter of compliance or risk management, it’s key to unleashing the potential of AI, and ensuring resilient operations in an increasingly uncertain world”. His message reflects a growing belief across UK industry that the path to widespread AI adoption will require trusted and jurisdictionally clear infrastructure.

Why Digital Sovereignty Is Becoming A Priority

Digital sovereignty has moved quite rapidly up the UK policy and business agenda over the past three years. Organisations have become more dependent on global cloud platforms, while political and regulatory uncertainty has increased scrutiny of where data resides and how it can be accessed. Many firms now define sovereignty as control over infrastructure, access rights, staffing, governance, and long-term operational independence, not solely data residency.

One major driver is the risk of foreign legal reach. For example, frameworks such as the US CLOUD Act have made some UK organisations question whether data stored with large international providers could be subject to external disclosure requirements. This has prompted regulators and sector bodies to look more closely at options that keep critical workloads within domestic borders and under UK law.

Not Just The UK

It’s worth noting here that the shift is not limited to the UK. For example, across Europe, governments have been investing in sovereign cloud capabilities to reduce strategic dependence on non-European providers. In fact, several high-profile contracts, including a £400 million sovereign cloud partnership between Google Cloud and the UK Ministry of Defence, have highlighted the scale of demand. BT’s new platform sits directly within this wider trend and positions the company as a national alternative for organisations that want jurisdictionally clear services delivered by a long-established domestic provider.

What BT Says The Platform Will Deliver

BT’s platform is built on UK-based systems, networks, and data centres, with securely managed environments for customers that need isolation from global infrastructure. Rather than locking all customers into a single approach, BT intends to offer configurable sovereignty levels, allowing each organisation to choose how tightly their operations should be contained.

The first set of services will include sovereign voice, cloud, and AI. These will span everyday communication services, hosted compute environments, and the ability to train, deploy, and run AI models on UK-only infrastructure. The company says later phases will bring sovereign options to more of its existing portfolio, including services used widely across the public sector.

This design reflects the fact that most organisations do not need full sovereignty everywhere. For example, customer service platforms, public websites, and many office systems may work perfectly well on standard cloud platforms. However, defence contracts, encrypted communications, facial recognition systems, citizen-facing platforms, industrial control systems, and healthcare data often demand stricter isolation, UK staffing, or restrictions that prevent foreign oversight.

BT’s offering attempts to bridge those needs by ensuring customers can combine standard services with sovereign options where required, without building entire technology stacks from scratch.

How It Connects To UK AI Strategy

The timing of BT’s sovereign platform is closely tied to the UK government’s efforts to strengthen domestic AI capability. Westminster has repeatedly stated that future economic growth will depend on expanded AI infrastructure, improved compute capacity, and secure environments where sensitive datasets and AI models can be developed and deployed.

Also, the government’s National AI Strategy and its newer Sovereign AI work both emphasise the need for UK control over core intellectual property and training assets. BT is already a founding member of the UK Sovereign AI Industry Forum and contributes to government-backed AI skills programmes. The new platform allows BT to present itself as a core enabler of the next phase of UK AI adoption, giving departments and regulated industries a route to experiment with AI in a tightly controlled environment.

There has also been increasing debate in Parliament about the resilience of AI infrastructure and concerns about over reliance on a small number of global cloud providers. BT’s sovereign model feeds directly into this discussion by offering a domestic environment designed specifically to meet legal, operational, and security expectations for sensitive workloads.

Changing Dynamics In Cloud And AI Competition

BT’s move places the company among a growing set of providers competing to offer sovereign alternatives to the public cloud. The major hyperscalers have already launched or announced sovereign variants of their services, often in collaboration with local partners or within government-led frameworks. These tend to follow a similar pattern, promising that data will stay within specified jurisdictions and that access by overseas personnel can be restricted.

However, where BT differs is in its identity as a UK network operator with deep experience delivering secure services across critical national infrastructure. Many public bodies and national security entities already rely on BT networks, which gives the company an advantage when pitching sovereign solutions to organisations that value long-term familiarity and existing contractual relationships.

Tighter Competitive Environment

That said, it seems the competitive environment is tightening. For example, customers will expect clarity on how BT’s sovereignty controls work in practice, including separation mechanisms, encryption key management, supply-chain validation, and how third-party cloud integrations will operate. Pricing will also shape adoption, particularly for organisations comparing sovereign infrastructure to more flexible or lower-cost global services.

How UK Organisations May Use The Platform

The platform is likely to attract interest from organisations that already operate under strict data governance rules. For example, government departments, defence contractors, NHS bodies, financial services firms, and utility providers typically require enhanced assurance for systems that affect public safety, national security, or critical service delivery.

There is also potential demand from organisations eager to explore AI but held back by internal concerns over data governance on global clouds. The ability to run AI training, inference, and storage within a UK-only environment may help those teams secure approval for projects previously seen as too sensitive for overseas infrastructure.

Leadership teams assessing the platform will likely weigh sovereignty needs against operational factors such as cost, performance, support, and integration with existing tools. The platform adds a new option for organisations planning multi-year digital programmes where jurisdiction, resilience, and data control are becoming central issues.

Criticisms And Challenges

BT’s announcement has generated interest, although it has also prompted questions from analysts and industry groups about how the platform will work at scale. One challenge concerns technical transparency. For example, BT has not yet released detailed public specifications covering encryption key ownership, workload isolation, or how sovereign environments will interact with existing cloud platforms. Organisations that rely heavily on hybrid architectures may want to understand whether the sovereign model restricts integration with major hyperscalers or introduces performance constraints.

Cost is another area of scrutiny. Sovereign infrastructure, by definition, cannot benefit from the same global economies of scale as large public clouds. Some customers may find that the additional controls, staffing requirements, and operational constraints create higher baseline costs, especially for AI workloads that require significant compute power. Procurement teams will want clear pricing structures before moving sensitive workloads into a new environment.

There are also questions around long-term capability. For example, critics note that while BT has a strong national footprint, sovereign cloud is a rapidly evolving field where global providers invest billions in AI acceleration, specialised chips, and high-density data centre capacity. BT will, no doubt, face some pressure to demonstrate that its sovereign services can match the reliability, performance, and feature velocity that organisations have come to expect from major cloud platforms.

Analysts also point out the strategic challenge of defining sovereignty in practical terms. Different sectors interpret the concept differently, ranging from strict jurisdictional control to broader concerns about supply chains, operational autonomy, and algorithmic transparency. BT will need to show how its platform can meet these varied expectations without creating unnecessary complexity for customers.

Data portability and vendor lock-in are emerging talking points as well. For example, some technology leaders argue that the success of sovereign services will depend on whether customers can easily move workloads between sovereign and non-sovereign environments as their needs change. If the platform creates heavy dependencies, organisations may become more cautious about adopting it for mission-critical systems.

What Could This Mean For Your Business?

The reality for many organisations is that decisions about sovereignty will become more central as AI adoption expands and regulatory expectations rise. BT’s sovereign platform may, therefore, give UK businesses a clearer path to experiment with advanced technologies while keeping tighter control over data, operations, and long-term risk. This is likely to appeal to firms that have been wary of placing sensitive workloads on global platforms, particularly in sectors where compliance and resilience drive technology strategy. Public sector stakeholders may also see value in a domestic provider offering infrastructure shaped around UK legal frameworks rather than adapting global services to fit local needs.

There is also a wider implication for the UK technology landscape. For example, a national operator entering the sovereignty space adds competition, which could prompt further investment and higher standards across the market. It also gives policymakers another lever as they seek to build a more self-reliant digital foundation for AI and cloud services. For suppliers and service partners, the shift towards sovereign options may open new opportunities, although it will also require clearer alignment with UK-specific governance models and operational rules.

It’s worth noting here that much will depend on execution. For example, customers will want to see how BT’s approach works in practice, whether it scales effectively, and how it compares to sovereign offerings already emerging from international cloud providers. If BT can demonstrate that its model delivers both control and capability, the platform could become a significant part of the UK’s digital infrastructure story. If not, organisations may continue to mix and match global solutions while waiting for greater clarity. Either way, the launch marks a change in how sovereignty is being approached and signals that UK organisations now have a new option as they navigate the next generation of cloud and AI adoption.

Tech Insight : BT Promises 5G Standalone for 99% Of UK By 2030

BT has committed to delivering full 5G Standalone coverage to 99 per cent of the UK population by the end of the decade, laying out a detailed plan that raises pressure on rivals and calls for regulatory support to finish the job.

Announced At Connected Britain 2025

BT’s announcement came during Connected Britain 2025 (a UK telecoms and connectivity conference), where the company’s chief security and networks officer Howard Watson confirmed that its mobile division EE is targeting 99 per cent population coverage for what it now brands “5G+” by 2030. The goal, Watson said, puts EE at least four years ahead of rival networks.

“To make the benefits of this technology clearer for customers, we’ll use the term 5G+ rather than the technical industry shorthand 5G SA or 5G Standalone,” he wrote in a company blog published the same week. “It’s the same game-changing network, but in language that’s simple and relatable.”

Aligns With Government’s Ambition

The commitment aligns with a UK government ambition, first outlined in 2023, for Standalone 5G in all populated areas by 2030. However, BT made clear that achieving this level of nationwide service would depend on cooperation from ministers to speed planning decisions, reduce costs, and improve access to spectrum.

Speaking at the same event, BT Group CEO Allison Kirkby described the telecoms sector as facing “peak government-inflicted costs” due to high spectrum licence fees, business rates and compliance charges. She called for reforms to enable faster and more cost-effective mobile infrastructure deployment.

What Is “Standalone 5G” And Why Does It Matter Now?

Unlike the earlier wave of 5G services launched across the UK, which used 5G radio access layered onto legacy 4G infrastructure, Standalone 5G (or 5G SA) uses a fully independent 5G core. This delivers significantly lower latency, better uplink performance, and allows for network slicing, which is a method of reserving parts of the network for critical services such as emergency communications, remote surgery, or live industrial control.

Voice over 5G (also known as VoNR, or Voice over New Radio) is another key feature. EE has already rolled this out on compatible handsets, allowing calls to remain on the 5G network instead of switching down to 4G or 3G.

100 Times More Capacity Than 4G

Watson said EE’s 5G+ network has been engineered to deliver up to 100 times more capacity than 4G, unlocking bandwidth for high-traffic areas such as city centres, stadiums and transport hubs.

In terms of progress, it seems that by August 2025, EE had already crossed the halfway mark, with Standalone 5G covering more than 34 million people. That number is expected to rise to over 41 million by spring 2026, with new cities added each quarter. EE only declares a location “live” once its outdoor coverage exceeds 95 per cent, a move the company says ensures a more reliable user experience.

The Technology Behind It

BT’s 5G+ plan relies on three major infrastructure changes, which are:

1. EE has deployed more than 1,500 outdoor small cells across the UK, including 500 in the past 12 months alone. These units improve coverage and capacity in busy or difficult-to-serve areas by offloading traffic from macro base stations.

2. The company is rolling out Ericsson’s AIR 3284 radio units, which support triple-band FDD (frequency division duplexing) and massive MIMO (multiple-input, multiple-output) capability. These radios are the first of their kind in Europe and offer four times greater uplink capacity than standard 5G radios, making them particularly useful for business applications involving video upload, conferencing, and real-time data feeds.

3. EE is using Advanced RAN Coordination (ARC), a new Ericsson system that allows base stations up to 50 kilometres apart to share capacity dynamically. According to BT, this has improved average download speeds by up to 20 per cent in test locations.

The company says hundreds more high-capacity radio units and coordination nodes will be deployed before 2030.

Competition

BT’s announcement comes amid growing competitive pressure in the UK mobile market. For example, Virgin Media O2 (VMO2) claims to have the UK’s largest 5G SA network, now reaching over 70 per cent of the population, and recently unveiled its first “Giga Site” in Paddington, combining low, mid and high band spectrum with dual-band Nokia massive MIMO. The company says the site is capable of delivering more than 10 Gbps throughput, and it plans to build 1,000 more across the country during 2026.

Meanwhile, Vodafone and Three completed their merger in June, forming VodafoneThree, which has pledged £11 billion in investment over the next ten years to deliver one of the most advanced mobile networks in Europe. This includes upgrades to support Standalone 5G and spectrum sharing across the newly combined business.

BT’s 99 per cent target is, therefore, not just an infrastructure roadmap, but is also designed to send a strategic signal to customers, investors and government that the company intends to retain a leadership position in UK mobile quality.

What Makes 5G SA So Different?

For consumers, the benefits of 5G SA are likely to be most visible in terms of more consistent service, reduced latency, and fewer signal dropouts in busy locations. For example, faster call setup times using VoNR and fewer video buffering events are some of the everyday improvements EE expects to deliver.

However, for business customers, the advantages are more substantial. For example, network slicing can provide guaranteed quality of service for critical applications, while improved uplink performance supports use cases such as remote diagnostics, live video monitoring, and industrial automation.

It’s worth noting here that EE has already trialled network slicing in some public settings, including at Belfast’s Christmas Market in 2023, where a dedicated slice ensured that payment systems remained reliable during peak visitor hours.

BT is also keen to highlight the role 5G SA could play in transforming public services, especially in transport. For example, railways and remote areas have long posed challenges for mobile coverage due to signal obstructions and infrastructure limitations. BT says targeted interventions, such as using smart coordination, small cells and new spectrum, will be required to solve these persistent gaps.

What Needs To Happen For The 2030 Target To Be Met?

While BT says it does not require direct subsidies to hit its 99 per cent target, it argues that the final stages of rollout will be difficult without regulatory support. The company is, therefore, calling on the UK government to:

– Reform planning rules to make it easier and faster to deploy infrastructure.

– Increase spectrum availability, especially in high-demand frequency bands.

– Remove or reduce annual spectrum licence fees, which BT says penalise operators for ongoing investment.

BT also wants regulators to take a more active role in addressing persistent coverage gaps along rail corridors, coastlines and other difficult environments.

Without these changes, the risk is that operators focus investment in profitable urban zones, while rural and hard-to-reach areas are left behind.

Challenges and Objections

Covering the last few per cent of the population is expected to be the most difficult and expensive part of the rollout. For example, rural areas often require long backhaul connections, more masts per user, and careful navigation of local planning restrictions.

Planning objections to new masts or small cells can also delay urban densification, where building height rules and community resistance frequently limit placement.

Device support is another potential issue. While most flagship smartphones now support Standalone 5G, it should be noted that not all models do, and ensuring features like VoNR and slicing work reliably across different hardware and software environments adds complexity for both operators and enterprise customers.

There is also some scepticism from some users who feel that previous 5G announcements have overpromised and underdelivered. Indeed, it seems that independent benchmarking studies have repeatedly found UK 5G performance to be well below that of other European countries. In this context, EE’s decision to rebrand its network as “5G+” rather than simply “5G SA” is likely an attempt to distance the new offer from earlier disappointments.

Even so, rivals are unlikely to stand still. For example, Virgin Media O2 continues to expand its footprint and spectrum holdings, having recently acquired 78.8 MHz of additional spectrum from Vodafone. VodafoneThree, with its larger combined scale, is also expected to accelerate deployments and extend its reach into rural regions.

What Does This Mean For Your Business?

Delivering 5G Standalone to 99 per cent of the UK population by 2030 would represent a major upgrade in national mobile infrastructure, with clear practical benefits for users and businesses alike. For companies relying on fast, low-latency connections to run logistics systems, cloud platforms or video services, the ability to access reliable standalone 5G in more locations could support better performance, more automation and greater service resilience.

For BT, the 99 per cent target seems to set out a clear intention to lead on mobile quality and capacity, not just coverage. The wider deployment of high-performance radios, small cells and core upgrades also gives the company a way to differentiate itself from rivals and reinforce its role in supporting essential digital services. For the government, the message is that planning delays, spectrum costs and regulatory friction are now a real constraint on further progress. If ministers want mobile operators to finish the job in rural areas, rail corridors and harder-to-reach environments, those barriers will need to be addressed.

That said, the challenges are still pretty substantial. For example, extending full standalone coverage to the last few per cent of the population will require continued investment, cooperative local planning, and more progress on handset compatibility across different devices.

Security Stop-Press: Scammers Exploiting Landline Switchover to Steal Payments

Consumer champion Which? has warned that telephone fraudsters posing as BT are exploiting the UK’s digital landline switchover, tricking consumers into sharing payment details under false threats of disconnection.

Which? says the scam callers have been telling victims the switchover requires immediate payments or confirmation of financial details, using the now-defunct January 2025 deadline to create urgency. Victims report receiving calls where they are being pressured with threats of service termination. Which? also reports that the scammers have targeted both landline and mobile users and are often armed with personal details to appear credible.

BT has confirmed that the switchover to Voice over Internet Protocol (VoIP) involves no charges, and customers will only be contacted via official channels. Legitimate providers will never request payment information for this process.

To avoid falling victim, the advice is to never share personal or payment information during unsolicited calls, verify any claims directly with your provider, and use call-blocking services. Businesses can educate employees, implement secure protocols, and promptly report scams to Action Fraud to help combat these threats.

Featured Article : Would You Be Filmed Working At Your Desk All Day?

Following a recent report in the Metro that BT is carrying out research into continuous authentication software, we look at some of the pros and cons and the issues around employees potentially being filmed all day at their desks … under the guise of cyber-security.

Why Use Continuous Authentication Technology? 

Businesses use continuous authentication technology to enhance security, i.e. to add an extra layer of protection. As the name suggests, this type of software continuously verifies users throughout their session, rather than relying solely on traditional one-time authentication methods like passwords or PINs. This approach is designed to mitigate risks such as session hijacking, whereby unauthorised users gain access after the initial login, or insider threats where someone might misuse another’s logged-in session. Continuous authentication essentially helps detect abnormal behavior in real-time, flagging up potential breaches or fraud by monitoring unique patterns such as typing style, mouse movements, or facial recognition. By integrating this technology, businesses may hope to reduce security vulnerabilities, safeguard sensitive data, and improve compliance with industry regulations, all while maintaining a seamless user experience, i.e. it’s happening automatically in the background.

BT Trialling Continuous Authentication Technology 

BT is reported to be trialling BehavioSec’s behavioral biometrics technology at its Adastral Park science campus near Ipswich. This software is used for continuous authentication, where it monitors users’ unique behavior patterns, such as how they type, move the mouse, or interact with their devices, to confirm their identity. However, in the case of BehavioSec’s technology, it doesn’t usually require the use of a camera, i.e. the user doesn’t need to filmed by a webcam all day. Instead, it can rely on analysis of a user’s behaviour patterns by looking at factors such as keystroke dynamics, mouse movements, touchscreen gestures, and device interaction patterns (e.g. how the user holds their phone, scrolls through pages, or interacts with specific applications). In the recent Metro story however, the reporter witnessed a demonstration of the system that did use facial recognition and required continuous filming of the user with a webcam/front-facing camera to detect whether the user’s face was consistent with expected dimensions.

BT is exploring this technology as part of its broader efforts to improve cybersecurity, particularly in response to the growing threat of cyberattacks and data breaches. The trials of BehavioSec’s behavioral biometrics technology are part of BT’s research into how it can use innovative technology to better protect digital assets and infrastructure, especially in enterprise and government contexts. For example, back in 2022, BT said it would be taking security to a new level so that even if an attacker obtained a device, any ongoing work session would end, locking the device, because their biometrics wouldn’t match that of the device user’s known biometrics.

Systems Using Cameras? 

There are, however, many such continuous authentication systems now available which require a camera being trained on a user’s face. A few prominent examples include:

– FaceTec’s ZoOm. This is a 3D facial recognition solution that uses the front-facing camera of devices (it can use a webcam) to authenticate users, e.g. by carrying out “Liveness Checks, Face Matches & Photo ID Scans”. It’s often used in applications requiring high security, such as financial services or identity verification systems, and biometric security for remote digital identity.

– FacePhi. This (Spanish) biometric solution for facial recognition is widely used in the banking, healthcare, and fintech sectors for secure access to mobile banking apps and fraud prevention. The software uses a camera to identify users and offers continuous authentication by tracking facial features during interactions.

– IDEMIA’s VisionPass. This system combines 3D facial recognition with AI and uses cameras to recognise faces and continuously verify identities, even in challenging conditions like low light or with face masks. It’s generally deployed in secure facilities, airports, and government buildings for access control and ongoing authentication.

– Trueface. This AI-powered facial recognition technology integrates with existing security systems, such as cameras in corporate offices, to provide continuous authentication. Trueface can recognise and track users in real-time, improving access security and is used in corporate offices, airports, and law enforcement for continuous identification and authentication.

Other popular systems that use similar methods include Clearview AI, Neurotechnology’s Face Verification System, AnyVision, and ZKTeco’s FaceKiosk.

It’s also worth noting here that the “big tech” companies’ versions, such Apple’s Face ID, Google’s Face Unlock (Pixel Devices), and Microsoft Windows ‘Hello’ are also facial recognition-based authentication systems that are classed as continuous authentication technology. However, for the purposes of this overview, we’re focusing on the kinds of systems that businesses may use for their own employees.

Issues 

The usage of facial recognition (e.g. by law enforcement) has had its share of criticism in recent years. However, the thought of businesses using a camera to continuously film an employee, even if it may be for security purposes, such as continuous authentication, raises several serious issues and concerns. For example:

– An invasion of privacy. With constant surveillance, employees may feel that their privacy is being violated. Cameras can capture not only work-related activities but also personal moments, which may lead to discomfort and a sense of being micromanaged. Cameras might inadvertently record personal or sensitive information, such as confidential discussions, which could be accessed or potentially misused.

– The effect on employee trust and morale. Continuous filming can create an atmosphere of distrust between employees and employers. Workers may feel they are being monitored for reasons beyond security, leading to an atmosphere of fear, plus a decrease in morale and engagement (and ‘quiet quitting’).

– Psychological stress. Constant camera surveillance can lead to stress or anxiety among employees, affecting their overall well-being and productivity, which could obviously be counterproductive for the company.

– Data security and misuse. For example, video recordings of employees can contain sensitive biometric data, which, if compromised through a data breach, could have serious consequences. Biometric data is immutable, i.e. once stolen, it cannot be changed (like a password). There is a risk of video footage being misused, either by internal parties or external hackers. The footage could be exploited for purposes other than security, such as inappropriate monitoring of behavior or harassment.

– Ethical concerns. These could arise if employees are not fully aware of the extent and purpose of the surveillance, or if they feel coerced into accepting it as a condition of employment. Also, filming employees all day can be viewed as excessive (overreach), especially if less invasive alternatives exist. Monitoring behavior to this degree may cross ethical boundaries of acceptable workplace practices.

– Legal implications. Many regions have strict privacy laws (e.g. GDPR in Europe, CCPA in California) that require companies to obtain explicit consent for continuous surveillance and ensure the proportionality and necessity of such measures. Non-compliance could lead to legal consequences, fines, or lawsuits for a business. In some countries (or US states, for example) there are labour laws that protect employees from invasive workplace monitoring. Continuous surveillance may violate these protections if it is deemed too intrusive.

– The Potential for bias and discrimination. Among other things, this could include algorithmic bias. If the continuous authentication system relies on facial recognition, there is a risk of bias against certain groups, such as racial minorities or those with disabilities, due to known issues with facial recognition accuracy across diverse demographics. Also, employees may worry that the surveillance data could be used for purposes other than security, such as evaluating performance, which could lead to discrimination or unfair treatment.

– Technical reliability, e.g. false positives/negatives. Continuous authentication systems relying on cameras may fail, leading to false positives (unauthorised users being granted access) or false negatives (legitimate users being denied access). This can disrupt work and erode trust in the system.

While continuous authentication aims to enhance security, using cameras to film employees all day raises significant challenges. Companies need to carefully balance security needs with privacy rights, ethical considerations, and legal compliance to avoid potential negative consequences. For example, in 2020, H&M (the German multinational clothing retailer) was fined €35.3 million by the Hamburg Data Protection Authority in Germany for violating GDPR due to excessive and invasive surveillance of employees.

What Is ‘Emotional Analysis’ And Why Is It Causing Concern? 

Some continuous authentication software can now use ‘emotional analysis’. This refers to the use of AI to detect and interpret human emotions through cues like facial expressions, voice tones, or body language. Its purpose is to monitor and assess workers’ emotional states, such as stress, engagement, or satisfaction. It could help a business by providing insights into employee well-being and productivity, identifying signs of burnout or disengagement, and enabling management to respond proactively to improve workplace morale, increase efficiency, and enhance overall performance through better support and tailored interventions.

However, its usage also raises significant concerns around privacy, accuracy, and bias. The technology is often inaccurate, particularly across different demographics, leading to misinterpretation of emotions. Its use in workplaces for employee monitoring can create a sense of invasion and stress, eroding trust, and morale. There are also ethical and legal issues, with fears of misuse for micromanagement or even manipulation of behavior, making its widespread deployment highly controversial.

Susannah Copson, legal and policy officer with civil liberties and privacy campaigning organisation Big Brother Watch has described ‘emotion recognition technology’ as “pseudoscientific AI surveillance” and has called for it to be banned.

What Do Rights Organisations Say? 

Big Brother Watch is strongly opposed to the unchecked growth of workplace surveillance tools, calling them an invasion of privacy, harmful to employee well-being, and in need of stricter regulation to protect workers’ rights. Big Brother Watch recently held an event at the UK at the Labour Party conference to launch its report on workplace surveillance in the UK, highlighting its increasing use by bosses and their employers, and its negative effects on employees.

Big Brother Watch argues that workplace surveillance technologies, such as keystroke logging and AI-powered emotional analysis, invade employee privacy, erode trust, enable micromanagement, and harm mental health, potentially violating privacy laws like GDPR, while calling for stricter regulation to protect workers’ rights.

How Much Has Workplace Surveillance Increased?

A recent report by ExpressVPN, titled the “2023 State of Workplace Surveillance,” highlights a significant increase in workplace surveillance. Some key findings include:

– 78 per cent of employers are using some form of employee monitoring tools in 2023, up from 60 per cent before the COVID-19 pandemic.

– 57 per cent of employers implemented new surveillance tools specifically due to remote work conditions caused by the pandemic.

– 41 per cent of companies now use software to track keystrokes, screenshots, or record the activity of employees’ screens.

– 32 per cent of employers monitor employee emails and messages, while 25 per cent track employee location using GPS or IP data.

A Growing Market 

This surge in monitoring reflects the growing reliance on digital surveillance tools to manage remote workforces. Regarding the market for identity and access management (IAM) and cybersecurity solutions, Gartner reported in its “Market Guide for User Authentication” that continuous authentication is gaining traction due to increasing concerns about cybersecurity and the limitations of traditional login methods.

A MarketsandMarkets report has also noted that the global user authentication market, which includes continuous authentication solutions, is projected to grow from $13.9 billion in 2022 to $25.2 billion by 2027. A 2022 Verizon Data Breach Investigations Report also noted that 61 per cent of breaches involve stolen credentials and pushed companies to adopt continuous authentication as a preventive measure.

What Can Employees Do? 

If employees are concerned about continuous camera monitoring such as that used with some continuous verification systems, the (realistic) options they have are to:

– Review company policies to understand the purpose and limits of the surveillance.

– Raise concerns with HR or management to request less invasive alternatives, like fingerprint or password-based methods.

– Seek legal advice if monitoring violates privacy laws, or report it to a regulatory body like the ICO (in the UK).

– Consult with a union to negotiate privacy protections, if applicable.

– Document their issues for potential disputes and familarise themselves with their rights under local privacy and employment laws.

What Does This Mean For Your Business? 

The rise of continuous authentication software, particularly that using facial recognition and behavioural biometrics, highlights the tension between advancing cybersecurity and respecting employee privacy.

While the primary aim of these systems may be to offer ongoing, seamless security by monitoring users throughout their work sessions, the methods employed, such as continuous video surveillance or behavioural tracking, have raised significant ethical and privacy concerns. The promise of enhanced protection against cyberattacks, session hijacking, and insider threats is compelling, especially in industries where data security is paramount. However, the potential downsides of this technology can’t be ignored.

One of the key concerns is the invasion of privacy. Employees may feel uncomfortable or even violated if they know that cameras or other tracking mechanisms are monitoring their every move. The potential for these systems to inadvertently capture non-work-related activities, or even sensitive personal interactions, adds to the unease. Continuous surveillance risks creating an atmosphere of distrust between employers and employees, fostering a sense of being constantly watched, which could have a detrimental effect on morale. In extreme cases, this might lead to disengagement, lower productivity, or even a rise in ‘quiet quitting,’ as employees withdraw emotionally from their work due to feeling over-monitored.

Also, there are concerns about the psychological impact of constant surveillance. The knowledge that a camera or biometric system is perpetually tracking your behaviour can lead to stress, anxiety, and a feeling of being under perpetual scrutiny. This could, paradoxically, undermine the productivity gains that continuous authentication aims to protect. Employees working under these conditions might find it difficult to focus or perform optimally, especially if they perceive the surveillance as intrusive or excessive.

In addition to these privacy and security concerns, there are ethical and legal considerations. In many jurisdictions, privacy laws require companies to obtain explicit consent for such monitoring and ensure that the measures are proportionate and necessary. Failure to comply with these regulations could lead to hefty fines or legal action (as seen in the case of H&M’s €35.3 million fine in Germany).

There are also the issues of bias and discrimination. Facial recognition technologies have been shown to be less accurate across diverse demographic groups, potentially leading to unfair treatment of certain employees. If continuous authentication systems generate false positives or negatives due to these biases, it could create additional hurdles for employees from minority groups, further entrenching workplace inequalities. There is also the risk that the data gathered could be used for purposes beyond security, such as monitoring productivity or evaluating performance, which could lead to unfair assessments or discrimination.

Despite these challenges, it is clear why businesses are keen to explore continuous authentication technology. The ever-present threat of cyberattacks, data breaches, and insider threats has made it essential for organisations to find new ways to secure their digital assets. Continuous authentication offers a promising solution by providing ongoing verification without disrupting the user experience. However, businesses must tread carefully, ensuring that these systems are deployed in ways that respect employee privacy, comply with legal requirements, and avoid creating a toxic work environment.

As continuous authentication (seemingly inevitably) becomes more widespread, it will be crucial for businesses to engage in transparent communication with employees about how these systems work, why they are being implemented, and what safeguards are in place to protect their privacy. Offering alternative, less invasive methods, such as fingerprint recognition or password-based systems, may help alleviate some concerns. Ultimately, the successful adoption of continuous authentication will depend on striking the right balance between robust security measures and the protection of employee rights and well-being.

Tech News : EE and Plusnet Customers To Get Refund From BT

After an Ofcom investigation that found BT didn’t give clear and simple information to customers who signed up to deal with its subsidiaries EE and Plusnet, BT has been told it must refund early exit fees and let existing affected customers walk away penalty-free.

What Happened? 

Under new consumer protection rules, known as ‘General Conditions’ (GCs), that came into force in June 2022, phone and broadband companies, of which BT is both, must give consumers and small businesses the details of a contract, as well as a summary of its key terms, before they sign up. These details must include the price, the length of the contract, the speed of the service, and any early exit fees.

UK Telecoms regulator, Ofcom, says that it opened an investigation into BT after it received information that two of BT’s wholly-owned subsidiaries, EE and Plusnet, may not have been providing the required documents to some customers.

The Findings 

Ofcom says its investigation revealed that since the introduction of the new rules on 17 June 2022, EE and Plusnet made more than 1.3 million sales without providing customers with the required contract summary and information documents. Ofcom found evidence that 1.1 million customers were affected by this between 26 June and 30 September 2023, i.e. they were not given contract information before they signed up as is required under the new rules.

Other key findings by Ofcom were that:

– Despite telling Ofcom in February 2022 that it was confident the deadline to meet the new rules would be met, evidence showed that BT knew as early as January 2022 that some of its sales channels would not meet the deadline.

– In some cases, BT deliberately chose not to comply with the rules on time.

– Ofcom says that whereas other providers dedicated the resources required to meet the implementation deadline for the new rules, BT may have saved costs by not doing so.

– Some sales channels are still non-compliant, and BT is still not providing the required information at the right time to some customers.

The Outcome 

The outcome of Ofcom’s findings in this case are that:

– Ofcom has issued a £2.8 million fine to BT, although this includes a 30 per cent discount as a result of BT’s admission of liability and its completion of Ofcom’s settlement process.

– The 1.1 million customers affected have been given the opportunity to request the information and/or cancel their contract without charge.

– For those customers who left BT before the end of their contract and were charged an early exit fee, BT must refund those early exit fees, and let existing affected customers walk away penalty-free.

Other Action 

Other actions that BT has been instructed to take by Ofcom in relation to this case include:

– Identifying and refunding any affected customers who may have been charged for leaving before the end of their contract period, within five months of Ofcom’s decision.

– Within three months, contacting the remaining affected customers who are still with BT and have not already been contacted, to offer them their contract information and/or the right to cancel their contract without charge.

– Amending remaining sales processes that are still non-compliant within three months of Ofcom’s decision.

Unacceptable 

Ofcom’s Enforcement Director, Ian Strawhorne, said: “When we strengthened our rules to make it easier for consumers to compare deals, we gave providers a strict timeline by which to implement them. It’s unacceptable that BT couldn’t get its act together in time, and the company must now pay a penalty for its failings.”  

Also, Rocio Concha, Director of Policy and Advocacy for consumer organisation ‘Which?’ said: “It’s absolutely right that Ofcom is fining BT for not providing EE and Plusnet customers with clear contract information before they signed up – as some people will have been hit with pricey exit fees they never should have faced.” 

What Does BT Say? 

BT has been reported as saying that it is sorry, will “implement the remedial actions” required by Ofcom and has “taken steps to proactively contact affected customers and arrange for them to receive the information and be refunded where applicable.” 

What Does This Mean For Your Business? 

Ofcom’s ruling against BT is a reminder to telecoms companies and service providers about the importance of compliance with the latest regulatory requirements. For BT, this incident highlights the critical need for transparency and accountability in customer communications, especially in a competitive market where trust is paramount. The £2.8 million fine (which some commentators say should have been higher) and the mandated refunds are examples of the financial and reputational risks associated with non-compliance.

For other providers, this case is a cautionary tale that emphasises the need to adhere to consumer protection rules and the potential consequences of failing to do so. It also shows that companies that decide to push boundaries in their marketing campaigns must think more carefully about these strategies, ensuring that their promotional activities do not leave customers in the dark about what they are signing up for. In an industry where bundling services into complex contracts is common, maintaining clarity and simplicity within customer interactions is still essential to avoid regulatory scrutiny and potential penalties.

For customers, this case may see them benefit (a little) from increased regulatory oversight and assurances that providers must comply with clear guidelines, thereby helping them make more informed decisions about their service contracts. Also, the knowledge that you can exit contracts without penalty in cases of non-compliance should be reassuring and help consumers from being unfairly trapped in agreements they did not fully understand.

Sustainability-in-Tech : Green BT Street Cabinets To Become EV Charging Points

In line with the government’s aim to increase the number of electric vehicle (EV) charging points from 50,000 to 300,000 by 2030, the BT Group has announced that it will be repurposing its old, green street cabinets to EV charging points.

60,000 New EV Charging Points 

The move, as part of a pilot scheme beginning in Scotland “in the coming weeks” will see BT’s end-of-life green street cabinets being repurposed to add 60,000 new chargers nationwide.

Green Boxes 

BT’s green boxes, a familiar sight on many streets, have traditionally been used to house cabling for phone lines and broadband but BT says the cabinets are slowly becoming obsolete as fibre-optic broadband is rolled out across the country. The company says that when the boxes reach the end of their life the old broadband equipment can be recycled, and EV points housed there instead.

Easy To Repurpose 

The BT Group says green boxes can be converted simply by using a small device to supply renewable energy to an on-street charging point, without the need to create a new power connection. The technology can actually be deployed in cabinets which are either in use or due for retirement.

Huge Step 

Tom Guy, Managing Director at BT Group said: “Our new charging solution is a huge step in bringing EV charging kerbside and exploring how we can address key barriers customers are currently facing.” 

Other Ideas 

An insufficient number of charging stations and whether charging points are available at home (or at work) have long been seen as major challenges to the growth of EV ownership in the UK (along with other factors like the price of EVs).

Some of the many suggestions for other potential kerbside solutions include:

– Lamp posts, especially in residential areas where traditional charging stations might be impractical, and they already have an electrical connection, which can be modified to include charging points.

– Parking meters. This would save space plus make use of the existing power supply and payment systems.

– Utility poles (similar to lamp posts), which have an existing power supply and are widely distributed, making them a viable option for EV charging.

– Street furniture such as benches, bus shelters, or other street furniture with integrated solar panels which could be equipped with charging capabilities.

– Retired/classic telephone boxes (only available now in some areas) can (and have been) repurposed as EV charging points, combining cultural heritage with modern technology.

– Bollards could be equipped with charging technology.

– Public toilets, which have been getting scarcer due to closures from council cuts, already have electricity for lighting and heating, and could be adapted to include EV charging points.

– Solar-powered recycling bins with built-in Wi-Fi and charging capabilities are one suggestion of an innovative way to combine waste-management and EV charging.

– Pop-up, temporary charging hubs / mobile charging stations, in areas with high demand, using existing power sources or portable generators.

What Does This Mean For Your Organisation? 

The innovative repurposing of BT’s green street cabinets essentially kills two birds with one stone, breathing new life into old infrastructure while tackling the UK’s lack of EV charging points. It’s one step in the right direction towards sustainable technology and environmental responsibility and it sounds as though it has the potential to make a major contribution (60,000) to the UK’s target of having 300,000 EV charging points by 2030. However, bear in mind that this is still only a pilot scheme.

It also seems like quite a practical option for a broad segment of the population. For organisations operating in the EV sphere, this expansion could also open new avenues for growth and innovation, as the increased infrastructure will likely stimulate demand for electric vehicles.

Environmentally, the repurposing of existing structures for EV charging aligns with green initiatives and carbon reduction goals and utilising existing assets, such as BT’s green boxes, is a way to reduce the environmental impact of constructing the necessary new EV charging stations in the UK. It also highlights how sustainability can be achieved through intelligent innovation, rather than just new construction.

Exploring the other potential kerbside solutions, like integrating charging capabilities into lamp posts, parking meters, and even public toilets, underscores the potential for creative solutions to the EV charging challenge. A versatile approach like this could well be the key to meeting the challenge of insufficient charging points in a faster, more affordable way at scale.

However, it’s still important to acknowledge that there are other remaining challenges within the EV market, such as the high initial cost of EVs, the need for widespread adoption of renewable energy sources to truly realise the environmental benefits of EVs, and the technical challenges associated with rapidly scaling up EV charging infrastructure. Addressing these issues requires a concerted effort from both the private and public sectors, with continued innovation and investment in sustainable technologies being paramount.

That said repurposing BT’s green street cabinets, alongside other innovative kerbside solutions, could offer a blueprint for how we can meet our environmental targets while fostering the growth of the EV market in the UK.