Insight into threats, without dependence on the internet
Increasingly, organizations—particularly within government and critical infrastructure—configure their IT and OT environments based on data security, detection, and sovereignty. Central to this is governance over data, control over detection, and predictability of the environment. This increasingly translates into on-premises and (partially) isolated networks, aligning with requirements regarding security, compliance, and continuity.
In this context, the need for sovereign detection is growing: network detection that takes place entirely within the organization's own network, without structural dependency on cloud platforms or continuous internet connectivity. Analysis, detection, and follow-up thereby remain under the direct control of the organization.
At the same time, insulation in itself is no guarantee of safety.
During this roundtable session, we will explore how organizations combine data security, detection, and sovereignty within isolated environments. We will discuss how to gain visibility into network behavior and threats without disrupting operational stability, and how monitoring, detection, and response are configured across multiple network layers within existing architectures.
The reality of isolated networks
Isolated or air-gapped networks are often viewed as environments with a lower risk profile. In practice, however, incidents still occur, including via:
- Suppliers and maintenance parties
- Removable media such as USB
- Temporary or controlled connections
At the same time, it is often missing:
- Continuous monitoring of network traffic
- Insight into lateral movement within the network
- Context to properly interpret deviations
As a result, threats can move through the environment unnoticed and only become visible at a late stage.
Network Detection & Response (NDR) enables the detection of behavior and anomalies at the network level, even in environments without internet access. Detection takes place locally, within the local network, while maintaining data control, compliance, and operational continuity.
During the session, we will discuss, among other things:
- how detection works in air-gapped and isolated environments
- which network data can be collected without impact on production
- how to integrate detection and network data within existing SIEM and SOC environments
- organizing monitoring, detection, and response across multiple network layers
- the role of machine learning in recognizing anomalous behavior in isolated networks
- how “human-in-the-loop” is ensured in detection and follow-up
- the position of NDR within a broader security architecture
- Practical examples from environments with high security and compliance requirements
Considerations in practice
Benefits:
Isolated environments offer organizations maximum control over data and infrastructure. This aligns well with requirements regarding security, compliance, and sovereignty. Moreover, the absence of external dependencies contributes to predictability and manageability.
Points of attention:
The availability of current threat intelligence is more limited, and updates often occur via controlled or manual processes. Additionally, integration within existing architectures requires extra attention, especially when multiple security and detection layers converge.
Programme:
13:00 – Walk-in
13:30 – Start of session: Introduction and context: Data security, detection, and sovereignty in critical environments
13:45 – Security in air-gapped and critical environments
14:15 – Detection approach and case study
14:45 – Break
15:00 – In-depth: detection challenges and architectural choices
15:30 – Open discussion and Q&A
16:15 – Wrap-up and key insights
16:30 PM – Closing
Speakers
Olivier van Arkel
Darktrace Expertise Center, SMT
Tristan Marsman
Information security advisor, SMT
For whom is this session relevant?
This session is intended for professionals responsible for the security and monitoring of critical IT and OT environments.
Relevant for organizations within:
- Governments
- Critical infrastructure
- Industry and production
Typical roles:
- IT and Security Managers
- SOC managers and analysts
- OT and ICS specialists
- Security architects and engineers
With responsibilities such as:
- Setting up and managing segmented or isolated networks
- Monitoring network behavior and threats
- Integration of security tooling within existing environments
- Ensuring continuity and compliance
Why participate?
During this session, you will gain insight into how detection in isolated environments is set up in practice and develop an understanding of the key considerations within this type of architecture. In addition, we offer concrete tools to improve visibility, and you will gain insight into the role of network data within existing monitoring. Naturally, there will also be room for substantive questions in a small-scale setting.
Practical information
Date: Thursday 25 June
Location:
SMT office
Louis Braillelaan 10
2719 EJ Zoetermeer
The Netherlands
Lunch: included
Contact
For questions about this event:
Olivier van Arkel
Expertise Center Darktrace – SMT
Email: olivier.vanarkel@smtware.com
Phone: +31615082596