For large data centre operators, network security is entering a new phase. Networks are becoming faster, more distributed and more complex. AI workloads are growing, 400G and 800G infrastructure is changing the scale of the network, and the amount of data available to security teams continues to increase.
At the same time, artificial intelligence is taking a bigger role in Network Detection and Response (NDR). It can analyse huge volumes of network activity, identify unusual patterns, correlate events and help security teams find meaningful threats among millions of routine interactions.
But as more of that analysis is handed to AI, there is another question data centre CISOs should be asking:
Who controls the intelligence making decisions about your network?
That is not simply a technology question. It is a question of security, governance and control. The network has always been one of the richest sources of security intelligence in a data centre. If organisations are going to place AI between that intelligence and the decisions made by their security teams, they need to understand how those decisions are reached, which models and rules are being used, where data is processed and, ultimately, who is in control.
The data centre security challenge is changing
The modern data centre bears little resemblance to the relatively predictable environments of the past. Today’s facilities support cloud platforms, AI workloads, enterprise applications, hyperscale infrastructure and increasingly critical digital services. Connectivity is expanding, workloads change constantly and the boundaries between traditional infrastructure and the wider digital environment are becoming harder to define.
That creates a much broader security challenge. The UK National Cyber Security Centre and CPNI have previously emphasised the need for a holistic approach to data centre security, bringing together physical, personnel and cyber security. The reason is straightforward. Data centres sit at the heart of the UK’s digital infrastructure, and disruption can have consequences far beyond the facility itself.
Uptime Institute’s 2025 Data Center Security Survey gives some indication of the scale of that challenge. Based on responses from 982 data centre professionals, it found that a majority of operators had experienced a cyber incident during the previous year. For some organisations, the cost of their most significant incident exceeded $50 million.
The causes are revealing too. Phishing was cited by one third of operators as the primary cause of their most impactful cyberattack, followed by ransomware or malware and misconfigured systems.
The point is that the threat to the data centre does not come from one direction. Human behaviour, configuration, infrastructure complexity and increasingly sophisticated attacks all play a part.
For CISOs, that makes visibility essential. But visibility on its own is no longer enough. Security teams also need confidence in how the intelligence coming from the network is being interpreted and acted upon.
When NDR becomes a black box
AI clearly has an important role to play in Network Detection and Response. Modern data centre networks generate far more information than human teams could realistically analyse themselves. Used well, AI can help find unusual behaviour, establish patterns across large datasets and surface activity that might otherwise disappear in the noise.
The problem is not the use of AI. The problem comes when the intelligence behind a detection becomes a black box.
Data goes in. An alert comes out. But how much can the security team actually see, change or control in between? As AI takes a greater role in detection and response, that distinction matters.
The UK National Cyber Security Centre’s guidance on AI and cyber security makes clear that security needs to be considered throughout the AI lifecycle, from development through to deployment and operation. It highlights risks including data poisoning, prompt injection and the potential exposure of sensitive information.
IBM’s 2025 Cost of a Data Breach research reinforces the importance of governance. It found that 97% of organisations reporting an AI-related security incident lacked appropriate AI access controls, while 63% either lacked AI governance policies or were still developing them. At the same time, organisations making extensive use of AI and automation in security reported average breach cost savings of $1.9 million.
So this is not an argument against AI. It is an argument for knowing how AI fits into your security architecture and retaining control over how it is used.
Black-box NDR or open NDR?
For years, security teams have often had little choice but to accept the detection technology inside an NDR platform largely as it was provided.
That approach is increasingly difficult to justify. An open NDR architecture offers a different model. Rather than relying entirely on the intelligence built into a security platform, organisations can bring more of their own intelligence into the equation — their own models, threat intelligence, detection logic and understanding of risk.
That matters because no two data centre environments are quite the same. A hyperscale cloud provider does not have the same network characteristics as a colocation provider. An enterprise data centre does not necessarily have the same traffic patterns as an AI infrastructure operator.
Each has different workloads, applications, users, operating models, compliance requirements and risks. So why should they all depend on exactly the same assumptions about what suspicious behaviour looks like?
An open approach allows detection to adapt to the environment, rather than expecting the environment to adapt to the detection platform. Security teams can use models suited to their infrastructure, incorporate intelligence from sources they trust and develop detection rules around what they know about their own network.
As the environment changes, those models and rules can change with it. That is more than flexibility. It gives the organisation greater ownership of its security intelligence.
Your AI should understand your network
There is an important difference between putting AI on top of network monitoring and making AI part of an organisation’s security architecture. One effectively says: Here is our model. Trust it to understand your environment. The other says: Here is your network intelligence. Use the models, rules and intelligence that make sense for your organisation.
That distinction will become more important as AI moves beyond helping analysts and begins to influence automated detection and response. Security teams need to know more than the fact that an alert has been generated. They need to understand why it was generated, what information contributed to it and whether the assumptions behind it make sense in their environment.
The question is therefore shifting. It is no longer simply: Can AI detect the threat? It is also: Can we understand, govern and adapt the intelligence behind that detection? That is where openness starts to become a security principle rather than simply a product feature.
NDR for the 400G/800G data centre
There is another part of this conversation that cannot be ignored: scale. As data centre networks move to 400G and 800G, network visibility cannot simply mean collecting more packets or generating more telemetry. The real challenge is turning high-speed network traffic into useful security intelligence without creating bottlenecks, overwhelming security teams or introducing new blind spots.
That puts much greater emphasis on the architecture underneath NDR. Being able to analyse network activity at scale matters. But so does being able to decide how that analysis takes place and what intelligence is applied to it.
For a data centre CISO, asking whether an NDR platform “uses AI” is therefore becoming less useful on its own.
Better questions are:
- Can I control how that intelligence is used across my network?
- Can I adapt it to the way my environment actually works?
- And can it operate at 400G/800G speeds and at the scale of modern data centre infrastructure?
The future of NDR should be open
AI will become a bigger part of network security. Given the amount and complexity of data generated by modern infrastructure, that is difficult to avoid. But the organisations that gain the most from it may not be those using the platform with the biggest claims about AI.
They may be the ones that maintain the greatest control over how that intelligence is used. Open NDR gives security teams the ability to combine network visibility with their own models, threat intelligence, detection logic and understanding of risk. It allows detection to evolve alongside the network rather than forcing the network into the assumptions of a fixed security model.
For data centre operators, that is an important distinction. Your network generates the intelligence. Your organisation should have a say in how that intelligence is interpreted. Your security team should be able to decide which models, rules and sources it trusts. And as data centre networks move to 400G, 800G and beyond, the architecture underneath all of this needs to be able to keep up. AI-powered security has enormous potential.
But AI-powered security that you can understand, govern, adapt and control is considerably more useful. That is the real opportunity of open NDR.
See open NDR at 400G/800G scale
IntSOC brings this approach to high-speed data centre environments, combining open-model, AI-powered network protection and response with an architecture built for the demands of modern data centre networks.
But the best way to understand what that could mean for your organisation is to see it in the context of your own environment.
Talk to us and we’ll create a bespoke IntSOC demonstration around your network, your security requirements and the use cases that matter to you.
See how open-model AI-powered network protection and response can work for your data centre — at 400G/800G scale.
Speak to us to arrange your bespoke IntSOC demo.
Click here to arrange your bespoke IntSOC demo.
Go Back