Detect and respond

Network detection & response (NDR)

Some devices can't run security software, and a firewall only sees traffic going in and out. Watch what's happening inside your network too.

The risk

Printers, cameras, door entry systems, older machines and equipment installed by suppliers often can't run security software, so nothing is watching them.

Once an attacker is inside, they move between systems on your internal network, which a firewall at the edge doesn't see.

What it does
  • Watches traffic inside your network from a passive sensor, adding no delay and no single point of failure
  • Spots attackers moving between systems, and devices talking to attackers' servers
  • Finds unmanaged, IoT and rogue devices you might not know about
  • Analyses encrypted traffic without having to decrypt it
  • Can tell Sophos Firewall to block a malicious device automatically
  • Detections flow into XDR and MDR for investigation
Who it's for

Businesses with lots of devices that can't run security software, such as manufacturing, healthcare and offices full of connected equipment, and anyone already using XDR or MDR who wants to see the network too.

How we supply it

By default we supply the licence and you (or your IT provider) deploy the sensor. It needs a switch port that mirrors your network traffic, which we can set up for you at our standard day rate.

What's under the hood

Sophos NDR — a virtual appliance for VMware, Hyper-V or AWS, included in the subscription and licensed by users and servers. Sophos Firewall also has NDR built in as part of its Xstream Protection bundle.

Questions
A firewall watches traffic going in and out of your network. NDR watches traffic between devices inside it, which is where an attacker moves once they're in.
It's at its best feeding them, where someone investigates what it finds.
Usually not. It runs as a virtual appliance on an existing VMware or Hyper-V host, or in AWS. Certified hardware is available if you don't have one.

Not sure what you need?

Tell us a little about your business and we'll recommend the controls that matter most for it — no obligation, and no jargon.

Talk to us → or see every security area →