Network Security, Threat Management, Zero trust, EDR

Why blind spots inside networks put companies at risk

Security concept: Lock on digital screen

COMMENTARY: When we think of buildings that house our most valued assets — like the White House, or Federal Reserve — we picture a fortress. Millions are poured into their formidable defenses. Think vault doors and armed guards at the entrance, keeping an updated log book of everyone who comes and goes. But these security measures are only as good as their weakest link.

If thieves can disguise themselves or slip through a back door unnoticed, perimeter defenses alone won’t stop a security breach. Just as organizations use technologies like CCTV and motion detectors to monitor their building’s deepest interior spaces, modern cybersecurity requires comprehensive network monitoring of internal traffic to catch suspicious behavior.

[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]

The news is full of companies that fail to fully monitor and protect their networks. It’s not hard to find examples of companies that thought they only needed to monitor key access points, or select "crown jewels" in their on-premise environments. This leaves them vulnerable to exploits at the edge of the network — such as a weak password, a misconfigured server, or an unpatched system — that allow criminals to gain access to any number of sensitive assets without anyone knowing they’re there.

How attackers exploit blind spots

Threat actors know most organizations spend the bulk of their security budget on external defenses, focusing on north-south traffic, or inspecting the data entering or leaving a network.

While traditional logging and endpoint tools spot basic events like traffic spikes or changes in access permissions, they often fall short in modern network architectures, where thousands of systems communicate every second. This creates a blind spot that modern cybercriminals have learned to exploit.

Related reading:


Too often, once attackers breach the perimeter, they can move relatively freely east-west within a network. This internal movement is difficult to detect without proper observability, which can lead to three primary risks: undetected internal threats, ransomware, and data exfiltration.

A compromised employee account, for example, could move freely to sensitive data without raising any alarms. Similarly, attackers often stage information on internal servers before moving it out, an activity that goes unnoticed without visibility into internal traffic.

Seeing into internal movement with deep packet inspection

Real-time context of internal traffic is key for security teams to understand who a user is, where they’re going, and what kind of data they’re accessing. This is where comprehensive packet-level observability becomes essential. 

Using deep packet inspection (DPI), security teams can see into the full context of network activity. Unlike other approaches that only show who is talking within traffic, DPI reveals what they are saying, can spot the subtle anomalies that signal a threat, and helps network and security teams quickly and proactively block suspicious activity.

During a security incident, time is a key factor. Recently, attackers gained initial access to Farmers Insurance’s network and moved laterally. The speed of their movement was a key factor in the attacker's success, allowing them to cause widespread disruption before the company could respond. A similar incident occurred within Change Healthcare’s network, which is still impacting patients over a year later. 

In situations like these, reviewing stored network data going back weeks or even months can enable threat hunters to audit recent network activity and close potential gaps in security by identifying the root cause of the compromise.


Closing the door with a zero-trust strategy

Just like a government building, a large organization’s defenses shouldn’t stop at the perimeter. 

Especially as IT infrastructures are modernized, a zero-trust architecture becomes increasingly important to protect sensitive information. Comprehensive east-west visibility directly supports this model, giving network and security teams the means to verify compliance with zero-trust policies by continuously monitoring and authenticating internal communications.

East-west visibility: Protecting the most valuable assets with east-west visibility

Ultimately, protecting high-value information like financial records and customer data is a top priority for large organizations. While many security teams already monitor their crown jewels — namely, the servers where their most sensitive data resides — this approach isn’t sufficient.

Enterprises with vast amounts of sensitive data can’t afford to neglect implementing east-west observability, just like the White House or Federal Reserve can’t afford to neglect hiring security personnel or internal surveillance cameras. In the end, organizations must shift their focus from simply guarding their borders to actively monitoring and securing every corner within their network.

An In-Depth Guide to Network Security

Get essential knowledge and practical strategies to fortify your network security.
Jerry Mancini

Jerry Mancini is senior director for the Office of the CTO at Netscout.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds