Connected Britain gave us the opportunity to showcase intSOC 400 and, more importantly, to have some valuable conversations about where network security is heading.
Across those discussions, one thing stood out: organisations aren’t short of security data. The challenge is turning that data into useful intelligence quickly enough to make a difference.
As networks become faster, more distributed and increasingly complex, that challenge is only getting bigger. For Network Detection and Response (NDR), it raises an important question: can security visibility keep pace with the network it is supposed to protect?
Here are some of the themes that stood out from our conversations at the event.
400G changes the visibility challenge
The transition to 100G, 400G and eventually 800G infrastructure isn’t simply a networking challenge. It has significant implications for cybersecurity.
At these speeds, capturing, processing and analysing network telemetry without introducing blind spots becomes increasingly difficult.
Security teams need to know what is actually happening across the network: which systems are communicating, how behaviours are changing and where activity deviates from what should be considered normal.
That makes the quality of the underlying telemetry critical.
With intSOC 400, high-speed network traffic can be converted into unsampled flow telemetry at wire speed, giving security and operations teams visibility into activity across high-capacity networks without relying on sampling.
As network speeds increase, maintaining that level of visibility will become increasingly important.
NDR needs to move beyond generating alerts
Another recurring challenge for security teams is familiar: too many alerts and not enough time to investigate them.
Traditional detection systems have become very good at identifying potentially suspicious activity. But detecting something unusual is only the beginning.
An analyst still needs to understand what happened, determine which systems were involved, correlate different pieces of evidence and decide whether the activity represents a genuine threat.
This is where AI — and particularly agentic approaches to NDR — becomes interesting.
Instead of simply applying AI to generate another score or another alert, AI agents can help investigate network activity, correlate evidence and provide additional context around an incident.
The direction of travel is therefore from:
“Something unusual happened.”
towards:
“Something unusual happened, here is what appears to have happened, here is the supporting evidence and here is what you should investigate next.”
That shift could make NDR considerably more useful to already stretched SOC teams.
The network remains a critical source of truth
There was also an important discussion around the relationship between endpoint security and network security.
EDR remains an essential part of modern security architecture, but endpoints cannot provide complete visibility into everything happening across an organisation.
Endpoints may be unmanaged. Agents can fail or be disabled. Some infrastructure cannot run endpoint agents at all.
Attackers also have to communicate.
Reconnaissance, command-and-control activity, lateral movement and data exfiltration can all leave evidence in network behaviour.
That makes network telemetry an important independent source of security evidence.
Rather than viewing EDR and NDR as competing technologies, organisations increasingly need to consider how endpoint, identity and network telemetry can complement one another.
When one source of visibility disappears, another may still reveal what is happening.
AI flexibility and sovereignty are becoming part of the conversation
AI is now appearing across almost every part of cybersecurity, but organisations are beginning to ask more sophisticated questions about how that AI is deployed.
Where does the model run?
Where does the data go?
Can we use our own models?
Can the technology operate within environments where sensitive network information cannot leave the organisation?
These questions are particularly important for telecommunications providers, critical infrastructure operators, government environments and organisations with strict data-sovereignty requirements.
One of the principles behind intSOC is therefore flexibility around AI. Organisations can deploy their own models and keep network processing on-premises rather than being forced into a single cloud-based AI architecture.
As AI becomes more deeply embedded in security operations, we expect this ability to control both the models and the data they operate on to become increasingly important.
From network visibility to network understanding
Perhaps the biggest takeaway from Connected Britain was that the NDR conversation is evolving.
The objective is no longer simply to collect more network data.
Security teams need technology that can observe increasingly high-speed networks, retain meaningful visibility, identify changes in behaviour and then help analysts understand why those changes matter.
That means bringing together high-performance network telemetry, behavioural detection and AI-assisted investigation.
For us, that is the direction behind intSOC 400: turning visibility at 400G into intelligence that security teams can actually use.
And as networks continue towards 800G and beyond, the ability of security infrastructure to keep pace with the network itself is going to become an increasingly important part of the cybersecurity conversation.
Want to learn more about 400G and 800G network visibility?
Talk to our team about your requirements and book a demo to see how intSOC delivers high-performance network visibility and NDR at 400G and 800G.
Go Back