Dark Trace, Splunk

Roundtable session: Data security, detection & sovereignty

Insight into threats, without dependence on the internet

Increasingly, organizations—particularly within government and critical infrastructure—configure their IT and OT environments based on data security, detection, and sovereignty. Central to this is governance over data, control over detection, and predictability of the environment. This increasingly translates into on-premises and (partially) isolated networks, aligning with requirements regarding security, compliance, and continuity.

In this context, the need for sovereign detection is growing: network detection that takes place entirely within the organization's own network, without structural dependency on cloud platforms or continuous internet connectivity. Analysis, detection, and follow-up thereby remain under the direct control of the organization.

At the same time, insulation in itself is no guarantee of safety.

During this roundtable session, we will explore how organizations combine data security, detection, and sovereignty within isolated environments. We will discuss how to gain visibility into network behavior and threats without disrupting operational stability, and how monitoring, detection, and response are configured across multiple network layers within existing architectures.

The reality of isolated networks

Isolated or air-gapped networks are often viewed as environments with a lower risk profile. In practice, however, incidents still occur, including via:

  • Suppliers and maintenance parties  
  • Removable media such as USB  
  • Temporary or controlled connections  

At the same time, it is often missing: 

  • Continuous monitoring of network traffic  
  • Insight into lateral movement within the network 
  • Context to properly interpret deviations 

As a result, threats can move through the environment unnoticed and only become visible at a late stage.

During the session, we will discuss, among other things: 

  • how detection works in air-gapped and isolated environments
  • which network data can be collected without impact on production
  • how to integrate detection and network data within existing SIEM and SOC environments
  • organizing monitoring, detection, and response across multiple network layers
  • the role of machine learning in recognizing anomalous behavior in isolated networks
  • how “human-in-the-loop” is ensured in detection and follow-up
  • the position of NDR within a broader security architecture
  • Practical examples from environments with high security and compliance requirements

Considerations in practice 

Benefits:
Isolated environments offer organizations maximum control over data and infrastructure. This aligns well with requirements regarding security, compliance, and sovereignty. Moreover, the absence of external dependencies contributes to predictability and manageability.

Points of attention: 
The availability of current threat intelligence is more limited, and updates often occur via controlled or manual processes. Additionally, integration within existing architectures requires extra attention, especially when multiple security and detection layers converge.

Programme:

13:00 – Walk-in
13:30 – Start of session: Introduction and context: Data security, detection, and sovereignty in critical environments
13:45 – Security in air-gapped and critical environments
14:15 – Detection approach and case study
14:45 – Break
15:00 – In-depth: detection challenges and architectural choices
15:30 – Open discussion and Q&A
16:15 – Wrap-up and key insights
16:30 PM – Closing

Speakers 

Olivier van Arkel
Darktrace Expertise Center, SMT

Tristan Marsman
Information security advisor, SMT

For whom is this session relevant? 

This session is intended for professionals responsible for the security and monitoring of critical IT and OT environments.

Relevant for organizations within: 

  • Governments  
  • Critical infrastructure  
  • Industry and production  

Typical roles: 

  • IT and Security Managers 
  • SOC managers and analysts 
  • OT and ICS specialists 
  • Security architects and engineers 

With responsibilities such as:

  • Setting up and managing segmented or isolated networks
  • Monitoring network behavior and threats
  • Integration of security tooling within existing environments
  • Ensuring continuity and compliance

Why participate?

During this session, you will gain insight into how detection in isolated environments is set up in practice and develop an understanding of the key considerations within this type of architecture. In addition, we offer concrete tools to improve visibility, and you will gain insight into the role of network data within existing monitoring. Naturally, there will also be room for substantive questions in a small-scale setting.

Practical information

Date: Thursday 25 June

Location:
SMT office
Louis Braillelaan 10
2719 EJ Zoetermeer
The Netherlands

Lunch: included

Contact

For questions about this event:
Olivier van Arkel
Expertise Center Darktrace – SMT
Email: olivier.vanarkel@smtware.com
Phone: +31615082596

Details

Ntb
13:00 - 16:30
Louis Braillelaan 10
2719 EJ Zoetermeer

This roundtable session offers insight into how organizations recognize and analyze behavior and threats within isolated networks, and jointly translate this into an effective monitoring and detection approach.

Sign up


Note: If the form is not visible, please try it in another browser, accept the cookies, and check if any blockers (such as ad blockers) are disabled in your browser.

Gain insight into threats within isolated networks in one afternoon.

During this roundtable session, we will exchange experiences on how to make behavior and risks visible within air-gapped and segmented environments, despite limited connectivity, and translate this into an effective monitoring and detection approach.

Multiple events

SMT Experience Center

During a visit to the SMT Experience Center, you will discover how organizations combine data from IT, OT, and security environments to better understand processes, identify risks earlier, and make better-informed operational decisions.

On request
between 09:00 en 17:00
Louis Braillelaan 10,
2719 EJ Zoetermeer
View event

Webinar AI versus AI: protect your organization against a new generation of email attacks?

Dark Trace

During this webinar, we will show you how to better protect Microsoft 365 against a new generation of AI-driven email attacks. You will gain practical insights into how AI can be used to detect, investigate, and automatically stop advanced phishing, Business Email Compromise (BEC), and other modern email threats faster.

Thursday 24 September
10: 00 - 10: 45
Online
View event