Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Network Visibility in Cybersecurity Strategy

N-able
04/06/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


So hello everyone. My name is Jim Wagner. I'm one of the product leaders here at Enable, responsible for our cybersecurity software and services. With me is Kevin O'Connor, the head of our research team. And today, the webinar that you have joined, and this is the first of our series, we call it the Enable MDR series, love this name, Managing Security Operations. So we have a whole series of these webinars that are scheduled. We'll get to the next one, which will be at the end. You can sign up for it. So hopefully you enjoy this one. But today, the first one we're kicking off is how to use network visibility in your cybersecurity strategy. But I would introduce Kevin, but I'll let him introduce himself because as talking with him, you know, the last couple of weeks of how much he's, how much he knows about security operations, been involved in investigations, especially against threat actors, which I found to be really interesting. But Kevin, if you would introduce yourself for everyone. Hi, yeah, I'm Kevin O'Connor, the director of threat research here at Ed Luman, MDR, or Enable's MDR company. I've got a really strong background in cybersecurity, been working about 15 years, specifically in cybersecurity. A lot of it was spent at the National Security Agency doing both defensive and offensive, where I got to run into a lot of different, you know, advanced persistent threat groups, you know, crimeware groups, and get to see them operating throughout environments and see exactly what their tactics and techniques are. I also run incident response here at Ed Luman. So I get to see a lot of firsthand, you know, breaches, incidents, see what actually causes them and then see how we can patch those systems up to make sure they don't happen again in the future. So a lot of lessons learned there. Excellent, Kevin, I can't wait to share it with everyone. And for those of you that are joining for the first time, my background working here at Enable, so prior to Enable, for the last little over two decades, almost three decades working at big cybersecurity companies, so Symantec, FireEye was the last one working with Mandiant. So the tools that Kevin creates in order, you know, their uses for incident response, I created tools like that for groups like Mandiant, which we use in incident response. So one reminder, just as a call out of what we, the caveats here in this webinar, is anything that you hear if we talk about futures or future capabilities we might be delivering, just know, don't take it as a promise. Anything that we say here having to do forward looking, future looking, you know, don't take a promise. We can always, you know, change it without actually notifying you. So this is more of an informational webinar. And the second call out would be, we do take questions. I will call out your name maybe and answer all your questions live. And then after the fact, we do follow up of our webinar with any unanswered question and then we'll post those for you to see. So if you look at your top right in this tool, there's a question mark, so don't post in the chat because we probably won't read it. But if you go to the question and post a question, like we have a practice question, we'll run through those in this session live. Now for the next one. So we are going to talk about network visibility when it comes into how do you best protect your environment, your clients and their network, and what could you do about that? So this is all about network visibility, how to increase it, how to leverage it, and we'll hand it off to Kevin. Yeah, so let's kick it off. So the first thing I wanted to talk to everybody about is exactly what is network visibility, right? So you might hear us talk about network visibility, you might hear it mentioned in blog articles. It's certainly been a buzzword for well over a decade now. But what I really want you to take away from this is that network visibility is it's your ability to see, understand and sort of secure all the activity across your network, right across your digital environment. And when I say network, I'm not just talking about those, you know, individual networking components that, you know, send your traffic from one place to another. And we're not just talking about the specific endpoints like the specific computers, we're talking about a holistic approach that looks not just at necessarily, like the hardware that you have deployed in your environment, but also things like third party applications that you might use, you know, SaaS applications, cloud environments, really that holistic approach to your entire, you know, digital architecture and digital environment. So to jump into it, I just wanted to sort of give you some examples of, you know, what are some components that play into network visibility. So, you know, the traditional standpoint in security was always to look at sort of the endpoint. And I think that's because, you know, it's the device that users are most often interacting with, right? Even security professionals, administrators, your end users, you know, your CEO, your C-suite and stuff like that, right? They're all using laptops, desktops, mobile phones. So a lot of the security has been focused on sort of those environments. But what we need to do is look at what are the components of your digital environment beyond just the endpoint, right? So we have a couple of different groups that I just wanted to highlight to you. And one of the biggest ones that, you know, the easiest and the first step you should look at is your network infrastructure, right? So a lot of folks are capturing things like traffic and logs from their endpoint devices, but they're overlooking that core network infrastructure that can give you insight into things like, you know, ingress and egress traffic or even lateral movement traffic. So in network infrastructure, we have your devices like routers that can help identify traffic that's coming in and out of your network. You know, there's switches and stuff you can capture data from, which might show you the traffic that's going what we'd like to call east to west of your network or, you know, sort of going between devices within your network. Firewalls, again, just like routers, are usually at the edge of your network and offer a great place to gain sort of visibility into the network traffic and the types of applications and services that are, you know, coming into and out of your network. And then, of course, towards the more advanced side, you have, you know, specific security appliances like intrusion detection systems and intrusion prevention systems, right? These are a little bit more advanced in the network infrastructure security stack. And depending on the size of the network, they're hard to implement, but they definitely give you that extra oomph to your security. And you need to make sure that, you know, if you're implementing these devices, that you're actually getting the benefit from them. To move on to just some other areas that people often overlook, right? So traffic and data visibility. So looking beyond just the specific network infrastructure that provides traffic to things like, you know, NetFlow specific logs. If you're offering like TLS or SSL encrypted services, right? Like a, let's say instead of this web logs here, which is HTTP, let's say HTTPS, right? Are you collecting the logs from your web services and from your, you know, your TLS negotiation sessions and stuff like that, or your TLS reverse proxy that's serving all your traffic? Generally, are you collecting logs? I also wanted to call out DNS here. I know that enable actually has a product that helps with DNS protection, but that's sort of another area within the network infrastructure that sort of originates on the endpoint a lot of times. But the data often isn't captured there and you can really get it across the network infrastructure as well. But that DNS that actually allows computers to look up and connect to specific domains and stuff, it's just a huge trove of data that can really show you what's going on in your network. Of course, we have cloud and SaaS visibility. So I've mentioned this before, but you have your cloud services providers that might be providing hosting for internal applications or even external applications. These could be things like AWS. For Azure, we have things like cloud-hosted Office 365 through Entra, the Active Directory environments, Google Cloud, Oracle Cloud. And then the other really big thing here are those SaaS apps, right? So those different software applications that you might be subscribed to, everything from Lucidcharts where you're creating architecture diagrams to HubSpot and Salesforce, your CRMs, really any sort of software application that you subscribe to, are you getting the logs from those, right? Are you taking logs from the Atlassian systems that provide JIRA and Confluence? And are you doing things with those logs? Are you inspecting the identity and the access? That really takes us to our next section, which is the identity and authentication. So for this, I like to call out components, things like services that are providing MFA or additional authentication providers for your network. So think about things like Duo and Okta, other MFA policies that might be enforced through something like Office 365. Are you collecting logs and insights from that? Do you actually see what's happening with those secure identities that are then being used to access the services remotely? And then, of course, security and threat detection. So we have things like at the very advanced end, we have managed detection and response systems. We have XDR, things like threat intelligence. All of these can play into network visibility and see what's going on in your network beyond just that endpoint so you can get that total picture. So you can see it's kind of a mess, right? There's tons of different components. And we've only mentioned maybe a tenth of what there might be in your network. It's highly dependent on what your architecture and your configuration is. So you really do need to spend some time to look at what services you're using in your environment, what you're using them for, what you're providing to your customers so you can figure out exactly what's in place that needs to be secured. Kevin, let me pause you there. Hey, are you suggesting that everyone on this call should use all of these or have all these, should be using all these when it comes to increasing their network visibility? Yes. So that's what I would say, right? Of course, you want as much security as you possibly can implement. But you'll see that environments might not even have all of these components in place, right? So for things like identity and authentication, if you're using something like Microsoft Entra, you might not be using your Duo or your Okta or something like that. Your network might not be large enough to have an IDS or an IPS, or maybe it's too large that you can't handle the traffic. Maybe you don't offer HTTP or any sort of TLS services to log. But there's definitely components here that everybody uses, things like DNS, routers, switches. And then there's components that you're using that probably aren't here as well that you need to consider. Okay. So I see some commonality here. I think through this session, we're going to talk about how these components holistically help improve your security posture. So good call outs and thank you for that. I think we're going to take a poll next. So this is for everyone. So as we talk about some of the components to improve the network visibility, one question that we have, we have a poll is, do you use your organization or do you use intrusion detection or intrusion prevention network-wise in the environment? Do you use it? Do you collect logs from it? Do you monitor it for alert it? Or do you not even know what an intrusion detection, intrusion prevention system is? So looking for responses, we get up to over a hundred. We'll move on, but it's getting some good numbers out there. So in general, what do you think, what's the value of using IDS IPS, Kevin? Yeah, I really wanted to include this question because IDSs and IPSs are kind of seen as like basic and taken for granted in security. They're technologies that are over 20 years old, you know, that are implemented in by tons of vendors. Everybody from Palo Alto to IBM with QRadar has things like IDSs and IPSs. But what we see is that a lot of organizations haven't implemented these, or if they have, they're not actually looking at the logs from them. We'll see that in some of the examples we go through where time and time again, there's data in the network that point to problems that folks aren't looking at. So what type of problems are you referring to? So what would you pick up from an IDS IPS? A lot of times from the IDS or the IPS, you'll be picking up things like indications of potential exploitation or potential like malicious traffic in your network. A lot of times they're really sourced to looking at the specifics of what the traffic is doing to try to identify malicious patterns, or they're looking at what we like to call indicators of things like, you know, known bad IP addresses or known bad domain names, things like that. Hey, I tell you what, I was on the wrong slide, the wrong box here. Now I'm seeing we've got some questions that are coming in. So let's pause just a second, go back to the interactive. One of the questions that came out by Hank, thank you for that. How is IDS and IPS working now that most of our traffic is now using, well, in TLS SSL, so encrypted, we knew we're going to get this question. So Hank, appreciate that. Give us a nice call out there. Go ahead, Kevin. Yeah, I love it. I think we actually talked about it a little bit later. But one of the problems that networks are facing today in terms of network visibility is the encrypting shift to encrypted traffic, right? And that's that TLS SSL protected. So most of your web traffic at this point, hopefully has moved over to HTTPS services, and even things that aren't your typical browser web traffic have hopefully also migrated over to those TLS protected services. So think about things like traffic like automated updates and stuff, which might in the past have been passed over, unsecure, unencrypted, now they're encrypted. And the problem with that is you can't see into it. So you can see what we like to call metadata. So typically you'll be able to see the basic things like where it's going, what port it's to, the size of the traffic, how much traffic there is, but you won't actually be able to see the content of it. So without seeing the content, it's hard to draw conclusions about, is this definitely malicious versus maybe just anomalous? I'd say a debate, especially in large enterprises about whether or not your environment should be doing things like including TLS intercepting proxies. So you'll see this is really common in the finance industry and some other heavily regulated industries where the enterprise will actually decrypt that TLS traffic using a middle man server so that they can get that insight. But a lot of times that's defeating the purpose of TLS and end-to-end encrypted traffic. So you gain a little bit of insight, but you lose, in my opinion, a lot of security. There's still definitely a lot of stuff to pick up though. We see actors still using FTP. We still see them using unencrypted protocols and comms too. Especially with the evolution now, your next gen firewall, so NGFW has integrated the IPS functionality. And IPS and intrusion prevention means if you identify a threat, you can block the threat. IDS means if you're identifying activity, you can forward the log, not necessarily prevent it. So it's sort of an allow, but notify. And it comes into an XDR solution or MDR. They can make better decisions. If you haven't looked into it yet, it's something that we definitely recommend that you do. It'll increase your security posture if you can, if you aren't already a network specialist. Final call out, Kevin, before we go on to the next slide. So we've got some good responses that not everyone on the line knew what IDS IPS was. So it's great. We gave a little education, but Frank Davis called out, what about IOT in your last slide? And yeah, Frank, we just ran out of IOT, definitely important. important, especially getting telemetry from, if there are assets that are critical and could be compromised, which we do see some of the compromises there. But yeah, we just ran out of slide space on those icons, like Kevin mentioned, that's about 10% of visibility. So we didn't want to make the icons too small. Yeah, IoT is huge. And it's something that I look at even in my home network, just at my house alone, I have over 40 IoT devices. If you're definitely, you know, provide almost like a backdoor into your network that you might not be aware of, or have visibility into. So you need to account for that. We'll talk about things like micro segmentation that can help with some of that. Perfect. So next, I want to just show you some examples of what happens when you have that really endpoint focus, you know, view. So we had talked about how, before we get there, I think that it's still true today, when I talk to customers about security, those that are, you know, wherever they're on their maturity cycles, we do see a lot of our partners depend upon AV only, endpoint security only. And they believe that if they just had the right or the perfect amount of endpoint security technology, that's all they need to protect their environment and all the visibility they need. So just kind of reinforcing what you're saying here in your example of being burned at the endpoint of how you're going to illustrate where you need a little bit more. Yeah, and that's the problem, right? So when you have that, that endpoint focus, you're overlooking a lot of what's going on in terms of your IT environment. So I can almost guarantee that every business out there isn't just using applications that are, you know, hosted on their own internal servers or hosted on servers provided by their MSP or IT providers, right? They're using commercial apps that they subscribe to. And that right there provides a whole, you know, interface to your potentially sensitive data that, you know, so if you're familiar with things like 1Password, right, they have really good like logging interfaces, even for sort of like a commercially cloud hosted application, where you can still track what users are doing throughout that sort of application environment without you actually having to control the app. But so what happens here is, you know, when you're too focused on the endpoint, you run into situations like something we found. So in one of the recent cases I was investigating, there was a customer we had that was in the manufacturing or defense industry. You know, they were doing specific, like, you know, industrial manufacturing that downstream led to the Department of Defense and like, you know, different US military force stuff. But they had really great endpoint security. They had really heavily invested in it. They have like a best in class EDR. You know, they had all the logging and monitoring set to pretty much as high as you could go at the endpoint. And all those logs were being collected and, you know, shipped back remotely to the cloud. So they were secure and stuff. And because they were manufacturing, they actually had a really big component of not just their traditional IT environment, but also like that operational environment that runs those SCADA and, you know, industrial control systems. And even on those really old Windows XP boxes and stuff, they still had, you know, up to date antivirus software and stuff. So their endpoint security was pretty good. But what happened was eventually something got through, right? There was a compromise that was discovered on one of the hosts, which was actually revealed to us through sort of like an anomalous PowerShell execution that was going. And then when we were looking into the PowerShell execution, you know, it was discovered that the host, somebody on the host had downloaded a binary, an application, they had executed it, it exploited the host, this wasn't caught by the antivirus or anything. And because of that, it pretty much just sat there until eventually it ran a command that was, you know, picked up by one of our anomaly detection algorithms, essentially, or our inspection algorithms into PowerShell. And the problem is that they didn't have any sort of visibility in their network. So they weren't doing really good logging, you know, what we like to call that east to west lateral movement. They weren't doing good logging sort of like at the ingress, like the exfiltration point, that ingress, egress point, those routers and firewalls. And they weren't looking at things like their Okta, their Office 365, and their SaaS applications to see if like people's accounts were being abused, essentially. So what happened was, you know, in this compromise, once the device was exploited, and had essentially circumvented the EDR, you know, they were able to have free reign on the network without these folks having visibility into what was happening. And the problem became during the investigation, you know, we had no insight into what other hosts like this, infected host had been talking to, right? Because like the Windows logs weren't reliable, because essentially, the malware was operating at a level below that. So you know, all the logging and all the EDR didn't prevent that compromise. And then because they didn't have the network visibility, we weren't able to see what was going on, right? We had to do a really thorough sort of, you know, investigation on every endpoint to figure out exactly what had happened and where the threat had come from and gone. Devin, let me further illustrate. So we did get a question from Ryan who commented on, he said, I thought S1 took care of this visibility. How does MDR separate? So I think both of us should answer that question. So let me give a point of view to Ryan and everyone on this webinar, is if you think about visibility, it's the more you know, especially if you're an investigator, you're an incident responder, your responsibility is to not just get a notification from an attack or an alert from an endpoint. But your responsibility is to identify the attack, how long has it been there? What are they trying to do? And ultimately try to keep up with business continuity. So removing them from the environment and then better protect yourself for the future. So you have a holistic responsibility. In that role, the more visibility you have, the better off you'll be. Threat actors know that the majority of the businesses out there, consumers out there are endpoint focused, and they've learned to navigate and cut through that activity, not touching the endpoint. So whether it's executing a threat, adding privileges to a server, you know, an account to a server and erasing their footprints, they know how to bypass the endpoint. So if you're just dependent upon endpoint, you're going to be, you're going to lack the visibility of the rest of your environment. And then when it comes to where do you send all this data, this activity and logs, that's what an XDR, extended detection response solution is about. And then MDR is the managed detection response team, like Kevin and those in the roles like Kevin and others that are company like Will, is to then do that on behalf of your clients or on behalf on you, because they're always looking, you know, handling things through automation, manual, visual inspection, doing further research. So that's why from their point of view, the more data, the more information that they have, that they can then try to understand the attack in the environment, the better off it is. So Kevin, your thoughts? Yeah, I mean, I 100% agree with what you had said there. I think the problem is when you look at just like a single solution, no matter who the vendor is, you leave yourself vulnerable to essentially like just relying on that single vendor's solution, and like single vendor security. So oftentimes, we like to practice in security, we call it like defense in depth. And when you appropriately are practicing it, defense in depth, you have to have what we call like, separation of like, like separation of vendors and stuff. So like, not all of your security should be provided by just one specific software vendor, you know what I mean? Like one specific developer, you know, you want to make sure that you're not using s1 for, you know, I don't know if they have like an IDS IPS, but you don't want to use it for IDS IPS, if they have a firewall implementation, and then also like, you know, your EDR as well. So it's the agnostic approach is that there's some philosophies to unify, especially when it comes down to efficiency, try to unify on one vendor. Others are you have multiple vendors, defense in depth, don't be agnostic. But there are also visibility tools that you can leverage, where you're just pulling up the logs of the activity. Firewall firewall logs is a good example of that, or the multifactor, any sort of identity logs can pull in that may not necessarily be security related. So cool. So just to jump back on some of the things we talked about before, right, so those things that are often missed when we talk about network visibility. So right back to my number one, right, that encrypted traffic. So I think these days, 90% plus, right of web traffic is supposedly encrypted. You know, I don't sit on the backbone of Verizon to be able to see that and verify it. But I would believe it based on what I had seen in my, you know, my hacker days. Things like TLS 1.3 make deep inspection harder. You'll see that also with implementations of I think of what is HTTPS 3.0 that's coming. And also like you're seeing a lot of migration of web services from HTTPS to things like QUIC as well, which implement the encryption differently, which can make it more difficult. And again, there's that whole debate that goes on, sort of about whether it's better to decrypt the traffic using things like TLS inspecting proxies or not. It really comes down to your organization's requirements and what you decide risk wise. The other big one is that shadow IT and rogue devices. So rogue devices are kind of obvious to understand, right? That's people coming in with, you know, unmanaged devices, things that don't have, you know, device profiles or any sort of security enforced and connecting them into your network, whether that's over corporate Wi-Fi or guest Wi-Fi that's, you know, improperly routed to, you know, secure services or, you know, services that are supposed to be segmented behind a firewall or something. But the really big thing there is that shadow IT. So when we keep talking, you hear me keep hammering back home this problem with like SaaS apps and stuff like that, and making sure that you have visibility into the logging and insights and authentication happening at those SaaS apps, because that's a big place where we're seeing a lot of exploitation. And to sort of call back to what we were just talking about with the with the S1 stuff, we're seeing a whole family of like malware and exploitation tactics that are what we like to call fileless, which means that they don't even necessarily like put down like traditional files that could be signatured on the endpoint. And I'll actually expand this out to there's a whole family of malware and attacks that aren't even like looking at the endpoint anymore. So you'll see, like, I think it was just last month, there was a new, I'll say, like attack or method that came out, where ransomware attackers were using the built in functionality of AWS to encrypt the data to keep it secure, right? This is what people will do on their S3 buckets, where they upload all that data to AWS, and they keep it, you know, encrypted and safe. What the ransomware actors were doing is once they got access to that, you know, that AWS account by credentials or whatever, they were using those built in AWS services to then encrypt all the data, you know, in the in the legitimate account using the legitimate encryption functionality. And then they essentially had the decryption keys and, you know, took them for themselves and wouldn't give it back. So again, like, that's an attack that goes against you that doesn't even touch the endpoint, there's no opportunity for S1 to catch it. You know, and it could be just as disastrous for the organization. Okay, we got a lot of questions coming in. But I wanted to ask you, so based on this one, we have a few questions on east west traffic or lateral movement. I'm gonna ask you a question. So as an incident responder, as someone who's responsible for going into an environment and really understanding if a threat actor is there or attackers there with company has been breached. If you want to determine east west traffic, if lateral movement has happened, what are the tools that you would hope were deployed or leveraged in an environment that you get that visibility? What would be your ideal? Yeah, well, the ideal would be like logging happening at the layer two level, right? So across all the switches. Yeah. Yeah. Especially like the layer two logging at the switches that are controlling, like the, the, the movement of traffic between like smaller portions of your network, essentially. And it'll help you see, like devices reaching out from maybe like, let's say, a user subnet to a, you know, application subnet or like an administrative subnet or something like that. Seeing that kind of traffic is really important, especially like when we talked about like, where you can't necessarily trust the endpoint, because like the endpoints been exploited at some points, you need that extra layer of visibility to be able to even say that something's happening, right? Because the endpoint can lie to you, essentially, in that case. So you need some sort of like secondary verification to say, yeah, there was no traffic going on between these two devices. You know, the other things we like to see, right. Things like SNMP, SNMP trap servers, you know, all that kind of logging setup. Really what I consider the basics that you don't see a lot. Yeah. Yeah. Hey, perfect. And then we are getting questions from that or people are, our attendees are asking for a little bit of advice. Here's one more we'll cover, and then we'll move on to the, to your next topic. But they asked was, as a small business, can one have visibility to the, how can one have visibility to the shadow SaaS world, which proliferates daily? Yeah. It's making sure you make smart choices about your providers for those SaaS applications. So we talked about like a password manager, right? So making sure that like the password manager you pick has those types of security features built in, right? Does it have detection built into it? Does it have, you know, logging exports or any sort of logs that you can see, you know, can you see when your users are logged in, you know, making that smart choice when you're picking the application from the get-go and then also making sure that you have systems like, you know, MDR or other applications, seams and stuff that can integrate those logs, right. And present them to you in a, in a unified interface. Okay. Excellent. I think we have another poll coming up and more questions that are coming. So, so which technology have you implemented here? So looking for everyone to respond. So we put some four pre-selections here. Have you implemented endpoint security, network security, vulnerability, scanning, threat intelligence, excuse me. And the other, put it into the chat of other, into the chat. So of other technology that you have implemented. And if you don't have access. And if you don't have access to the chat, do we mean questions, or did you mean the chat? Let's see. So go ahead and put it into the question section. I don't know if we have chat access. So what technology have you implemented for your partners, for your environment, for your clients? And I like these options, because it kind of gives you a broad sense to let you know sort of like some of the major areas that you might want to look at providing to your partners, to your customers, if you don't already. All of these are pretty critical and important, and there's definitely services out there to fill that. So answers we are getting, we've got two so far. We have Sysmon Detection, which is good, Threat Down Endpoint Protection, and Secure Cloud Analytics. And also the reasons why you've implemented, so what you've implemented, really talking about security here, are getting security visibility. We'll see if we get a couple more. And we have one that's AdLumen, thank you, yeah. Cove Backups, okay, now we're having the Enable fans are coming in saying, hey, but I've done the Enable product solutions and services. Thank you, Adam, appreciate that. Bluemira, okay, cool, so keep adding those in, we'll go on. It's good to see what you've implemented, what you've done that is critical for you, so let's go. So why is all this important, right? I just gave you an example of why looking at the endpoint can lead to disaster. But what I wanna do now is give you some examples of some recent attacks and things like that that have happened across the space where network visibility has caused disaster, because something I really want everybody to take away today is that one of the biggest risks of having poor network visibility is not knowing when you're compromised. And that's what we're gonna see here in these two cases is there was compromise, but they didn't know. They didn't have the insight or the ability to say, hey, something is up here, something's wrong. There's terabytes of traffic or gigabytes of traffic destined out of our network to a server in Belarus, right? And the first one is this recent one, which was the espionage on US telecommunications networks that came out. So telecommunications providers, including AT&T, Verizon, and T-Mobile, and this is important because those three really together make up a huge portion of the US backbone for commercial traffic, for commercial internet traffic, essentially. So you can think of Verizon, not just as a cell phone provider, but they actually provide the fiber optic connections between the huge data centers across the US and stuff like that. And what actually happened is Chinese state-sponsored hackers, in this case it was Salt Typhoon, which again is associated with the Chinese MSS, Ministry of State Security, focusing on cyber espionage and counterintelligence, they essentially went out and were able to hack all of these different telecommunications providers. They used a bunch of different methods, mostly exploiting vulnerabilities that had patches issued, but hadn't been updated in the networks yet. And once they were in those networks, the hackers were able to move laterally and they were able to remain undetected for something like 18 months. The group has been active since at least 2019, so I'm sure these operations have been going on against them for at least that long. Wait, wait, wait, wait, wait, wait, wait, hold on, sorry. You said 18 months. 18 months, it looks like. So during the investigation, they found that the first signs of this intrusion had gone back 18 months from the discovery, which was, I want to say, I think initially in 2023, but publicized in 2024. Okay. And that's in the US, and these are, sorry, these are in large enterprise telecommunication systems that should be looking for these things because they are large targets, right? So I think the key takeaway there that when you're being compromised, if you're looking for an alert to let you know that you've been compromised, chances are it wasn't a, there's a probability there that it wasn't a one-off alert and that was the first time that they were in there, they could have been in there for quite a bit. So this is pretty routine, especially in the larger organizations, but we're also starting to see into the smaller organizations, the compromise may have occurred a while ago, they erased their footprint so you don't see them, and then may enter in months, if not years later, because they've got access. And so they pull up their database of who they've hacked and how long they've been there, and that's when they'll do an entry point because that's just the way it is. Yeah, and a big thing here was that when they actually infiltrated these systems, there wasn't the visibility for that lateral movement for them to actually see the attackers moving into things like these providers have court-authorized wiretapping systems that these Chinese intelligence agencies were essentially accessing. So imagine the FBI has a wiretap on whoever, the Chinese government was essentially hacking Verizon to then get access to that wiretap data as well. So you can imagine how large the spying operation went, the amount of data that had to be expelled. And the real issue was, not the real issue, but one of the problems was, like we mentioned, the data was encrypted so they couldn't necessarily see the content of it, but there was also no anomaly detection going on, right? So they couldn't see, hey, data's going to places where it doesn't normally go or shouldn't go, or there's an abnormal amount of data going. Like none of that was in place across, I think there were nine different telecommunications firms that were part of this exploitation campaign, so. And another example where the attackers were able to move laterally undetected is that traditional, is that Colonial Pipeline Ransomware, right? So I like this one because everybody's heard of it, everybody knows about the impact because there was a rising gas prices, there were gas availability issues on the East Coast because of it. But this is when that dark side ransomware group hacked the Colonial Pipeline company that provides natural gas and stuff like that. They have a huge pipeline from the Gulf all the way up to the East Coast to distribute oil and gas. And the attackers were able to get into the network, like the traditional IT network. And the problem was, they didn't actually initially, or I don't even know if they ever figured out if they infected the operations network, which actually ran the systems, but because there was no segmentation between the IT and the operational networks, they actually had to shut everything down because they didn't know what was compromised, right? They didn't have any sort of detection of the encrypted data that was exfiltrated. And again, this is a ransomware operation, so they did take a bunch of data and hold it for hostage. And there was no detection on the encrypted exfiltration once again, right? There was nothing looking at whether or not data should be going to an endpoint that it's not. And that lateral movement was the really big issue, right? They were able to move potentially laterally from the IT network to the operational network, which would have caused huge issues. And they didn't have the network visibility to say that that didn't happen. So that's why they had to preemptively sort of shut it down. And it all started with a compromised VPN account that didn't have MFA. So it just goes to show how something as simple as not having MFA on just one portion of your enterprise infrastructure can cause issues. Yeah, thanks for properly scaring me with the fear, uncertainty, doubt here, which I think for me, it's always the most exciting part when we talk about the, you know, defending the threatscape, but also what are the threats that are out there, personal experience like you're conveying, which opens the door to the next poll that we have is when it comes to technology and security technology or technology in general to secure environment, the question is, what do you depend on the most? What does that single piece that you would say, okay, as long as I have this deployed, I'm secure. Is it an XDR, the software that brings it all together, the heart of a security operation center? Is it the managed team, the MDR notifying you? Is it firewalls? Is it endpoint security? Is it a SIM? And is there other, go ahead and post those in the questions as a question. Let me know if there's other technology that is your go-to technology that you feel the most confident about. I get an answer from Robert on anomaly detection. So it'd also be good if you tell me what it is and why you depend on that. So we do have quite a few people on the line. So please, let's see if we get a couple more responses. Yeah, I really like this question because it just gives me insight, which is important when we're doing research and figuring out how to defend everybody into what portions of your infrastructure help you sleep easiest at night, right? Is it knowing that you have your firewall configured really tightly and that no traffic that you've explicitly permitted is allowed out? Or is it that you have that anomaly detection to see if data is being leaked out of your network or those kinds of components? Yeah, Adam is commenting on ThreatLocker is a good front end and now the answers are pouring in. Excellent, everyone. So Mike has his EDR firewall MFA, so multi-factor authentication. Way to go, Mike. Keith, firewall, because that is the foundation of networking device that everyone has, but don't take advantage of to harden it down. So kind of blocking the traffic unless you explicitly know about it. Put in some IDS IPS rules in there. Secure cloud analytics for North, South, East, West and incorporate with other tools per file normal behavior. That's a really good way to do it, Robert. So get a feel for your standard behavior. And when you see an anomaly or some activity outside of that, then take notice and investigate further. I was involved in a breach at a company and that was the one thing that they noticed is they had a good foundation, a baseline for their traffic. And then one day there was a little bit of a blip and not everyone noticed, but one individual was like, hey, what is that? And then they asked the question, they got into the logs, they did a bit of research, pulled in the team. They called a red alert, if you will, or code red, what they call. And then further, they found out that there was an actual breach that happened. So good one out there. All right, so good answers that are coming in. DNSS filter. Thank you again for the enabled products. Appreciate that, especially because I'm responsible for them. Users reporting change in their dev device behavior. That's also very good. We do talk about how the users are the worst culprits because of the ones that are clicking links and opening up an attachments and whatnot and saying yes to log into my account, but also a great source of crowdsourcing. When an individual notices something, it may not just be a performance issue or compatibility issue, but it could be an attack that they noticed and no one else did. So excellent response, everyone. All right, well, let's jump into, so what are some strategies for improving network visibility, right? So the biggest thing really is deploying the network telemetry and sensors and making sure that you have the log collection from the components that make up your network, essentially, right? Your IT environment. When we say network, we mean your IT environment. Yeah, this goes back to that page we showed where we showed like all those different services and different places where you can be collecting data, security-relevant data for your environment, making sure that you have those in place, right? Talking about things like NetFlow, which is often overlooked, even your simple like SNMP logging and stuff like that between network devices, and then all the way up to sensors, like we said, IDS, IPS. They can get incredibly expensive and incredibly specific, or they can be even cheaply implemented through open source and span ports into VMs and stuff. The biggest one I like to highlight is using some sort of MDR or XDR. I would say it seems kind of fall under this, but at that point, you're missing a lot of like the managed detection portion of it. But the reason I highlight those types of tools is because they specialize in having integrations to support your IT environment, essentially. So like a good MDR should be like platform agnostic, right? It should support you being able to upload your logs from either Azure or AWS or Oracle Cloud, right? Because who knows what your organization or what your customers are using, right? Even within your customer base, there might be a mix of, you know, Duo and Okta. So you have to make sure that your MDR system supports like, you know, all those different, you know, there's how many different EDR platforms and stuff like that are there. And then having that single planet blast that it offers, right, which lets you see the logs across all your devices, search them, you know, and see like across all your services and devices, right? Like that's just invaluable. Not having that means you have to go to 30 different places, right? Which is just not achievable, especially when you're managing at scale. The other big one is leveraging threat intelligence. We also throw in AI and machine learning with this. Machine learning, I also include that anomaly detection as part of that. Those are huge, right? Those cases where there was a lot of exfil where these attackers were what we like to call lingering or loitering for months. You know, there was a large amount of exfil over that period and just some basic, you know, anomaly detection algorithms would have really shown them that something was up and led to further investigation hopefully. Threat intelligence is good because especially when you're dealing with like e-crime actors, a lot of times their infrastructure, you know, IP addresses and domains and stuff like that associated with their campaigns and attacks do get exposed because they have such a wide commercial breach that they're going after, a wide commercial range they go after, that when you have threat intelligence systems, you have the opportunity to, you know, potentially detect on those types of IOCs and stuff like that being present in your environment, you know, letting you know something's up. Microsegmentation, this is also just really called segmentation in your network, right? Making sure that you, you know, separate out your administration networks from your user networks, from your services traffic networks. We talked about with the colonial pipeline, right? Making sure your traditional IT systems are segmented from your operational systems, right? In the case of anything like a SCADA or, you know, ICS, industrial control system type thing. And then again, integrating that cloud because especially the way cloud can be used, it's essentially an entire separate network that is like joined with yours, right? At least that's the way it can be used, right? AWS can provide a whole different networking space, you know, VPCs and all the different things and all the different things like, you know, endpoints or API gateways that can come with it. And if you don't have insight into what's going on in your cloud environment, and you have one, then you're essentially missing, like half of what's going on, right? So you really need to make sure that you're looking at that in addition to your network and your endpoints. It's really like that third really important portion, I would say. And then of course, the SaaS applications, that I keep driving home. So I think with that, we actually have a poll that we wanted to ask you guys. So I think it's poll four. So part A, part B, I believe. So here's part one, here's a multi-select, which of the following best practices have you implemented for your customers? Do you use strong passwords? So there's, I mean, there's a standard list of best practices that you go, you do a search for that, and it'll give you the list. If you're trying to advise your customers and not be product-centric or security technology-centric, which is what we're doing here, this is a list that you would come up with. So this would be the common sense of security. You may know it, but my question for you is, have you implemented these? So, and there's going to be a part two for it. So are you using strong passwords? Like I'm seeing that a few are, but 89%. So MFA, yes. Regularly updating software, I'm seeing some say yes. Implementing firewalls, conducting security assessments. And so this is good. You know, for example, on the strong passwords, even I have a conversation with my wife, she's still not using the strongest of passwords. She's still trying to memorize them, but, you know, for each their own, but there are some impacts to that. Now getting the answers here, we got 60% that have voted. Let's go to the next question, the part two of the poll. And the part two, how about data encryption? That's either at rest or in motion. So point-to-point encryption, data transfer from cloud to your endpoint on your file folder, access control with least privilege, security awareness training, incident response planning, not only just doing investigations, but if something happens, have you gone through actual practice sessions? Like we do tabletops here at Enable with Ed Blumen and then network monitoring for suspicious activity. So these are the, so seeing some numbers here, let's see if we can get to that 60% vote count. I'd add conditional access managed SOC with O365 M365 anomaly detection integration. Good call out there, Ed Blumen's releasing our, what we call the breach prevention for Microsoft. And so that's a subset of our managed detection response services. We're about to release something new. I think that's a good call out of how to better protect yourself in O365 environment, which we have here. So there was a little product services plug there. Thank you for that. Geolocation, O365 geolocation. Oh, some good ads there. We'll make sure to share these around as we post our questions. We're getting to about 54% and got some good responses. Not like the last, the part one, I see fewer and fewer that have implemented these. Now, one question we got asked earlier was, Hey, are you going to show us all this, how to better protect yourself against the breach? How to the actually working? Well, that's the next session, which we'll get to. This session was about network visibility, going beyond the endpoint. What's the value of, what do we gain from it? And then we'll go into the, you know, how, how to actually leverage all that visibility in another session. So Kevin. Yeah. So I wanted to wrap it up by just showing you guys something like an MDR, right? So I think a lot of folks are missing. I know that everybody's it environment is complicated and has all these different portions and components to it. All these different, what we call integrations. Right. And I really want to stress that whether it's at Lumen or it's another platform, you do need that central place where you're aggregating those security logs so that you can draw that bigger picture, you know, across your environment. I mean, just imagine you're a detective and you're trying to like solve a case and you only have, you know, one very specific piece of evidence, right. You're not going to be able to see the bigger picture. You're not going to be able to do your investigation and draw the appropriate conclusions. You know, it's just, it seems almost obvious, but you know, it's not something that a lot of people have necessarily, you know, so what I'd like to highlight here just about AdLumen is you can see like the differences in integrations that it has, right. So you can see a good MDR or SIEM type platform and things like that, or XDR is going to get right AWS, Azure. We can see there's also like, you know, Jira, CrowdStrike, Silance, ConnectY, Cisco AMP. You can just see like the diversity of vendors and things that it supports. You could also see here, right, like firewall. So you can ingest your logs into the platform so that you can start meshing up the analytics between your firewall and your user endpoint data and your, you know, Azure O365 logs, right. Start building things like cross integration detections, which are really that next step in securing your environment, being able to tie the different pieces together for that really big full security picture. That leads to the next question, the services that the MDR offers. Here's a little bit of a plug, but to give you an example. Kevin, do you want me to? Yeah, no, these are just some of the, so MDR services, right. The big important thing for AdLumen is that we're multi-tenant management so that where, you know, we have the ability for your organization to manage multiple customers within it, right. Something that I really like about our platform is that you can actually search all your data, right. So not only are we aggregating all of the data from all of these different applications, but it's fully searchable and aggregated, you know, aggregatable by you, which is something that a lot of platforms don't offer. A lot of times it's like a black box where you just kind of send your data and expect them to do all the detecting and alerting on it without being able to actually, you know, see it for yourself or start looking at those pieces of evidence to draw your own conclusions. And again, things like MDR services can provide 24 seven coverage, you know, who's on call for your business when, you know, a user at seven o'clock pops a Windows Defender, you know, malware that wasn't remediated by Defender, right? Who's going to deal with that? Who's going to disconnect their account or their endpoint? And really just offers you that full visibility and control into your network, right? Being able to see all the pieces beyond just that one single device. Now, as a partner of ours, if you want to offer these services to your customers, to your clients, absolutely, you can take advantage of the platform. So we call it the extended detection response platform. It gives you all the capabilities we have at hand. You can offer that for your clients. Now, if you're early on in the journey, you know that your clients need this service, you want to offer it to them. That's where we offer the services as EdLumen Enable, where we'll do the MDR service. We'll offer the 24 seven. We have automation, we'll help with the ingestion. We'll do this work of getting it in and not only detecting the threats, but automatically responding to them. So do as much automation as possible. So remediate the activity, remediate the threats. And then anywhere along that journey in that spectrum of a journey from just starting doing it yourself to having us doing it, if you want to co-manage it together, we can do that as well. So just letting you know, it's not all about just the MDR, but if you are a security operations, you are doing the security for your customers. We can help in that and give you the software that we use to find the threats. Now, the last poll coming up, because we are coming close to the session is, do you want to hear more about MDR and what we're going to be doing? We got one no, but we're getting a few more yeses. So let's see if we can get everyone, how many people we can get to vote on this. We can get to a 99% on the vote. We do, we are getting more and more of you who want to hear more about your specific needs because every environment is different. I do have some questions about recommendations. Should I use this app versus that app? Which are all good questions, but it does come down to your need and your environment. Yeah. MDRs are really becoming a basic component of security these days. Like back, I remember 10 years ago, having something like Splunk implemented in your network that was collecting data from all your different components was seen as being like, yeah, I'm advanced. I'm on top of it. We have full visibility. But these days, that's just the basics. That's the basics, what's expected of people. And if you have a breach and you have customers and you have to explain yourself, it's going to be difficult if you're not set up. Yeah. That journey is beyond the alert driven, response driven, that level one, if you will, but more into the security operations for your customers. So we are seeing a huge adoption from our MSPs that are moving into security and need to have those services for their customers. Okay. A good response amount. Let's go on to the final slides. As we close out, we do have the Q&A that we've already done. So let's go on. We did that all along. Our next slide. So let's do a call out here. So our next webinar. So this one was about visibility. And like I mentioned, this is a series that we'll be doing. So it'll be myself and Kevin, or Will will join from our MDR team, or the three of us, but the next one, so use the QRC. That'll be Thursday, March 27th. So about a month from now, another hour long session. Cyber threats are evolving. Your security strategy should too. So here's where we're going to show you the risk and we're going to show you how to stop the breach. We're going to show you the value of it, really give you that demonstration of what's going on so you can get in depth into the console. So hopefully you can attend. And then with our final slide, we want to talk about Empower. All of us are prepping for Empower in Berlin. Hopefully you can join. Here's another QR code. You can sign up. Kevin's going to be there on stage. I'll be joining him. We'll be live talking about the threatscape. What are we seeing? We're going to scare you a little bit more. Also, hopefully introduce some of that real hands-on investigations as Kevin was doing, but really... Yeah, I love that Empower's in Berlin. It's a hacker city, so it's the perfect place to have Empower, I think. It's a great environment for it. We'll make sure everyone turns off their phones and we'll put up some fake Wi-Fi for people to log in to see if we can breach them and leave USBs around. So coming to Empower, you'll hear from all of Enable and then Lumen teams for all of our solutions that are out there. Really good on security, but that's what we're trying to show everyone, how much we know. And I think that might be it. Yeah. Thank you so much for the session. Emma introduced a link for the event for anyone that wants to sign up. So as a call-out, so next session, as we talked about, the Security Operations Center, the questions. If you have any final questions you want us to answer, we will answer them and then send them after the fact. And then Emma's send out a link. If there's something more you want from our webinars, if this doesn't meet your need, you want something different from us, you want different assets, different presentations, if you hate me being the host, give us that feedback. We'll definitely listen to it if we like it and incorporate that into our future sessions. So thank you for attending our series, the first of our series, which is the Enable MDR series, Mastering Security Operations, which hopefully by the end of our series, you'll be able to master it or look to us and we can do that for you. So thank you all.

TL;DR

  • Network visibility requires looking beyond endpoints to include network infrastructure, cloud services, SaaS applications, and identity systems—encrypted traffic and lateral movement create blind spots that endpoint-only strategies cannot address.
  • Major breaches like Salt Typhoon (18-month undetected compromise of US telecom providers) and Colonial Pipeline demonstrate that even large enterprises fail to detect attackers when network visibility and segmentation are inadequate.
  • Implementing comprehensive visibility means deploying and actively monitoring IDS/IPS, collecting logs from cloud environments and SaaS apps, implementing network segmentation, and using anomaly detection to identify unusual traffic patterns.
  • Managed detection and response (MDR) services have evolved from advanced capabilities to baseline requirements, providing 24/7 monitoring, automated response, and cross-integration detections that correlate security events across multiple sources.
  • N-able's AdLumen MDR platform offers multi-tenant management with fully searchable security data across diverse integrations, supporting MSPs from self-service XDR to fully managed services depending on their security operations maturity.

The Network Visibility Challenge

This webinar addresses a critical gap in cybersecurity strategy: the lack of comprehensive network visibility beyond endpoint security. Jim Waggoner, VP of Product Management at N-able, and Kevin O'Connor, Head of Threat Research with 15 years of cybersecurity experience including work at the NSA, explain how organizations create security blind spots by focusing exclusively on endpoint protection. They demonstrate that true network visibility requires a holistic approach encompassing network infrastructure (routers, switches, firewalls, IDS/IPS), traffic and data visibility (NetFlow, DNS, TLS logs), cloud and SaaS applications, identity and authentication systems, and advanced threat detection platforms. The session emphasizes that modern networks are complex ecosystems where encrypted traffic, lateral movement, and multi-cloud environments create challenges that endpoint-only strategies cannot address.

Real-World Breach Examples

The presenters illustrate the consequences of poor network visibility through two major incidents. The Salt Typhoon espionage campaign against US telecommunications providers (AT&T, Verizon, T-Mobile) went undetected for 18 months, with Chinese state-sponsored hackers accessing court-authorized wiretapping systems because there was no anomaly detection for lateral movement or data exfiltration. The Colonial Pipeline ransomware attack forced a complete shutdown because the company couldn't determine whether the operational technology network was compromised, as there was no segmentation or visibility between IT and OT environments. These cases demonstrate that even large enterprises with significant resources fail to detect breaches when network visibility is inadequate, and that the average dwell time for attackers can extend to months or years before discovery.

Implementing Comprehensive Visibility

The webinar provides practical guidance for improving network visibility through specific technologies and best practices. Key recommendations include deploying and actively monitoring IDS/IPS systems (which many organizations have but don't properly utilize), implementing network segmentation to separate administrative, user, and operational traffic, integrating cloud environment monitoring (AWS, Azure, O365) as a critical third pillar alongside network and endpoint security, and collecting logs from SaaS applications and identity providers. The presenters emphasize that threat intelligence, while valuable for detecting known bad actors, must be combined with anomaly detection to identify unusual traffic patterns, data volumes, or destinations. They introduce managed detection and response (MDR) services as a solution for organizations lacking the resources to aggregate and analyze security data from multiple sources, positioning 24/7 monitoring and automated response as baseline requirements rather than advanced capabilities.

The MDR Solution Framework

N-able's approach through its AdLumen MDR platform addresses the complexity of multi-source security data aggregation. The platform supports integrations across diverse vendors and technologies (AWS, Azure, CrowdStrike, Cisco, firewalls, O365, Jira, and others) to provide cross-integration detections that correlate events across different security layers. Unlike black-box solutions, AdLumen offers multi-tenant management with fully searchable data, allowing MSPs to manage multiple customers while maintaining visibility into raw security events. The service model spans a spectrum from self-service XDR platform access for mature security operations teams to fully managed 24/7 MDR services with automated threat remediation for organizations early in their security journey. The presenters position this as part of a broader shift where centralized security log aggregation and analysis—once considered advanced—is now a baseline expectation for any organization handling customer data or facing regulatory compliance requirements.

Chapters

0:00 - Introduction and Speaker Backgrounds
3:25 - Defining Network Visibility
5:22 - Components of Network Visibility
10:07 - Poll: IDS/IPS Implementation
13:01 - Encrypted Traffic Challenges
29:05 - Poll: Security Technologies Implemented
31:00 - Real-World Breach Examples
42:46 - Best Practices for Network Security
45:04 - Poll: Security Best Practices
48:02 - MDR Platform Overview
52:11 - Poll: Interest in MDR Services
53:45 - Closing and Next Webinar

Key Quotes

1:11 "I've got a really strong background in cybersecurity, been working about 15 years, specifically in cybersecurity. A lot of it was spent at the National Security Agency doing both defensive and offensive, where I got to run into a lot of different, you know, advanced persistent threat groups, you know, crimeware groups, and get to see them operating throughout environments and see exactly what their tactics and techniques are."
4:03 "Network visibility is it's your ability to see, understand and sort of secure all the activity across your network, right across your digital environment. And when I say network, I'm not just talking about those, you know, individual networking components that, you know, send your traffic from one place to another. And we're not just talking about the specific endpoints like the specific computers, we're talking about a holistic approach that looks not just at necessarily, like the hardware that you have deployed in your environment, but also things like third party applications that you might use, you know, SaaS applications, cloud environments, really that holistic approach to your entire, you know, digital architecture and digital environment."
33:00 "Chinese state-sponsored hackers, in this case it was Salt Typhoon, which again is associated with the Chinese MSS, Ministry of State Security, focusing on cyber espionage and counterintelligence, they essentially went out and were able to hack all of these different telecommunications providers. They used a bunch of different methods, mostly exploiting vulnerabilities that had patches issued, but hadn't been updated in the networks yet. And once they were in those networks, the hackers were able to move laterally and they were able to remain undetected for something like 18 months."
34:11 "When they actually infiltrated these systems, there wasn't the visibility for that lateral movement for them to actually see the attackers moving into things like these providers have court-authorized wiretapping systems that these Chinese intelligence agencies were essentially accessing. So imagine the FBI has a wiretap on whoever, the Chinese government was essentially hacking Verizon to then get access to that wiretap data as well."
35:46 "The attackers were able to get into the network, like the traditional IT network. And the problem was, they didn't actually initially, or I don't even know if they ever figured out if they infected the operations network, which actually ran the systems, but because there was no segmentation between the IT and the operational networks, they actually had to shut everything down because they didn't know what was compromised, right? ..."
13:17 "Most of your web traffic at this point, hopefully has moved over to HTTPS services, and even things that aren't your typical browser web traffic have hopefully also migrated over to those TLS protected services. So think about things like traffic like automated updates and stuff, which might in the past have been passed over, unsecure, unencrypted, now they're encrypted. And the problem with that is you can't see into it."
11:00 "IDSs and IPSs are kind of seen as like basic and taken for granted in security. They're technologies that are over 20 years old, you know, that are implemented in by tons of vendors. Everybody from Palo Alto to IBM with QRadar has things like IDSs and IPSs. But what we see is that a lot of organizations haven't implemented these, or if they have, they're not actually looking at the logs from them."
30:01 "One of the biggest risks of having poor network visibility is not knowing when you're compromised. And that's what we're gonna see here in these two cases is there was compromise, but they didn't know. They didn't have the insight or the ability to say, hey, something is up here, something's wrong. There's terabytes of traffic or gigabytes of traffic destined out of our network to a server in Belarus, right? ..."
48:18 "I really want to stress that whether it's at Lumen or it's another platform, you do need that central place where you're aggregating those security logs so that you can draw that bigger picture, you know, across your environment. I mean, just imagine you're a detective and you're trying to like solve a case and you only have, you know, one very specific piece of evidence, right. You're not going to be able to see the bigger picture."
52:57 "MDRs are really becoming a basic component of security these days. Like back, I remember 10 years ago, having something like Splunk implemented in your network that was collecting data from all your different components was seen as being like, yeah, I'm advanced. I'm on top of it. We have full visibility. But these days, that's just the basics. That's the basics, what's expected of people."

Categories:
  • » Cybersecurity » Network Security
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Network Security
  • Security Operations
  • Threat Intelligence
  • Cloud Security
  • Webinar
  • Best Practices
  • Technical Deep Dive
  • Network Visibility
  • Managed Detection and Response
  • Intrusion Detection Systems
  • Network Segmentation
  • Encrypted Traffic Monitoring
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Network Visibility in Cybersecurity Strategy

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Aug
                    06

                    Mitigating Risks of Sensitive Data Exposure in AI Platforms

                    08/06/202604:00 AM ET
                    • Aug
                      06

                      Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks

                      08/06/202602:00 PM ET
                      • Aug
                        07

                        Discover DLP Memories: The Evolving Triage Agent That Learns Each Shift

                        08/07/202611:00 AM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/06/2026
                          04:00 AM
                          08/06/2026
                          Mitigating Risks of Sensitive Data Exposure in AI Platforms
                          https://www.truthinit.com/index.php/channel/2058/mitigating-risks-of-sensitive-data-exposure-in-ai-platforms/
                        • 08/06/2026
                          02:00 PM
                          08/06/2026
                          Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks
                          https://www.truthinit.com/index.php/channel/2064/same-tactics-enhanced-velocity-the-impact-of-ai-agents-on-identity-attacks/
                        • 08/07/2026
                          11:00 AM
                          08/07/2026
                          Discover DLP Memories: The Evolving Triage Agent That Learns Each Shift
                          https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-evolving-triage-agent-that-learns-each-shift/
                        • 08/07/2026
                          11:30 AM
                          08/07/2026
                          Refreshing Beverage Ideas Paired with Essential Cybersecurity Insights
                          https://www.truthinit.com/index.php/channel/2063/refreshing-beverage-ideas-paired-with-essential-cybersecurity-insights/
                        • 08/13/2026
                          12:00 PM
                          08/13/2026
                          Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                          https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights and Strategies with Cyera
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version