COMMENTARY: When we think of buildings that house our most valued assets — like the White House, or Federal Reserve — we picture a fortress. Millions are poured into their formidable defenses. Think vault doors and armed guards at the entrance, keeping an updated log book of everyone who comes and goes. But these security measures are only as good as their weakest link.If thieves can disguise themselves or slip through a back door unnoticed, perimeter defenses alone won’t stop a security breach. Just as organizations use technologies like CCTV and motion detectors to monitor their building’s deepest interior spaces, modern cybersecurity requires comprehensive network monitoring of internal traffic to catch suspicious behavior.[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts.Read more Perspectives here.]The news is full of companies that fail to fully monitor and protect their networks. It’s not hard to find examples of companies that thought they only needed to monitor key access points, or select "crown jewels" in their on-premise environments. This leaves them vulnerable to exploits at the edge of the network — such as a weak password, a misconfigured server, or an unpatched system — that allow criminals to gain access to any number of sensitive assets without anyone knowing they’re there.
How attackers exploit blind spots
Threat actors know most organizations spend the bulk of their security budget on external defenses, focusing on north-south traffic, or inspecting the data entering or leaving a network.While traditional logging and endpoint tools spot basic events like traffic spikes or changes in access permissions, they often fall short in modern network architectures, where thousands of systems communicate every second. This creates a blind spot that modern cybercriminals have learned to exploit.Related reading:
Too often, once attackers breach the perimeter, they can move relatively freely east-west within a network. This internal movement is difficult to detect without proper observability, which can lead to three primary risks: undetected internal threats, ransomware, and data exfiltration.A compromised employee account, for example, could move freely to sensitive data without raising any alarms. Similarly, attackers often stage information on internal servers before moving it out, an activity that goes unnoticed without visibility into internal traffic.
Seeing into internal movement with deep packet inspection
Real-time context of internal traffic is key for security teams to understand who a user is, where they’re going, and what kind of data they’re accessing. This is where comprehensive packet-level observability becomes essential. Using deep packet inspection (DPI), security teams can see into the full context of network activity. Unlike other approaches that only show who is talking within traffic, DPI reveals what they are saying, can spot the subtle anomalies that signal a threat, and helps network and security teams quickly and proactively block suspicious activity.During a security incident, time is a key factor. Recently, attackers gained initial access to Farmers Insurance’s network and moved laterally. The speed of their movement was a key factor in the attacker's success, allowing them to cause widespread disruption before the company could respond. A similar incident occurred within Change Healthcare’s network, which is still impacting patients over a year later. In situations like these, reviewing stored network data going back weeks or even months can enable threat hunters to audit recent network activity and close potential gaps in security by identifying the root cause of the compromise.
Closing the door with a zero-trust strategy
Just like a government building, a large organization’s defenses shouldn’t stop at the perimeter. Especially as IT infrastructures are modernized, a zero-trust architecture becomes increasingly important to protect sensitive information. Comprehensive east-west visibility directly supports this model, giving network and security teams the means to verify compliance with zero-trust policies by continuously monitoring and authenticating internal communications.
East-west visibility: Protecting the most valuable assets with east-west visibility
Ultimately, protecting high-value information like financial records and customer data is a top priority for large organizations. While many security teams already monitor their crown jewels — namely, the servers where their most sensitive data resides — this approach isn’t sufficient.Enterprises with vast amounts of sensitive data can’t afford to neglect implementing east-west observability, just like the White House or Federal Reserve can’t afford to neglect hiring security personnel or internal surveillance cameras. In the end, organizations must shift their focus from simply guarding their borders to actively monitoring and securing every corner within their network.
An In-Depth Guide to Network Security
Get essential knowledge and practical strategies to fortify your network security.
As outlined in The Register, a recent security assessment highlighted significant vulnerabilities within the healthcare sector, particularly concerning compromised gatekeepers and inadequate network security.
The Edge Threat Management (ETM) for VeloCloud SD-WAN packages zero trust branch office security with a common operating system, a uniform enforcement engine, and standardized security policies.