---
title: 'Network detection & response (NDR)'
url: 'https://triplepoint.org.uk/security/detect-and-respond/network-detection'
markdown: 'https://triplepoint.org.uk/security/detect-and-respond/network-detection.md'
date: '2026-09-28'
description: 'Network detection and response (NDR) for UK businesses. Watch traffic inside your network for attackers moving between systems, including devices that cannot run security software.'
---

# Network detection & response (NDR)

The riskPrinters, cameras, door entry systems, older machines and equipment installed by suppliers often can't run security software, so nothing is watching them.

Once an attacker is inside, they move between systems on your internal network, which a firewall at the edge doesn't see.

 What it does- Watches traffic inside your network from a passive sensor, adding no delay and no single point of failure
- Spots attackers moving between systems, and devices talking to attackers' servers
- Finds unmanaged, IoT and rogue devices you might not know about
- Analyses encrypted traffic without having to decrypt it
- Can tell Sophos Firewall to block a malicious device automatically
- Detections flow into XDR and MDR for investigation

 Who it's forBusinesses with lots of devices that can't run security software, such as manufacturing, healthcare and offices full of connected equipment, and anyone already using XDR or MDR who wants to see the network too.

 How we supply itBy default we supply the licence and you (or your IT provider) deploy the sensor. It needs a switch port that mirrors your network traffic, which we can set up for you at our standard day rate.

 What's under the hood**Sophos NDR** — a virtual appliance for VMware, Hyper-V or AWS, included in the subscription and licensed by users and servers. Sophos Firewall also has NDR built in as part of its Xstream Protection bundle.

 Questions Isn't this what a firewall does?+A firewall watches traffic going in and out of your network. NDR watches traffic between devices inside it, which is where an attacker moves once they're in.

 Do we need XDR or MDR as well?+It's at its best feeding them, where someone investigates what it finds.

 Does it need extra hardware?+Usually not. It runs as a virtual appliance on an existing VMware or Hyper-V host, or in AWS. Certified hardware is available if you don't have one.

[← Back to Detect and respond](https://triplepoint.org.uk/security/detect-and-respond)

## Not sure what you need?

Tell us a little about your business and we'll recommend the controls that matter most for it — no obligation, and no jargon.

[Talk to us →](https://triplepoint.org.uk/contact?about=Network%20detection%20%26%20response%20%28NDR%29) or [see every security area →](https://triplepoint.org.uk/security)

---

## Navigation

- Parent: [Threat detection and response](https://triplepoint.org.uk/security/detect-and-respond.md)
- Previous: [24/7 managed detection & response (MDR)](https://triplepoint.org.uk/security/detect-and-respond/mdr.md)
- Next: [Identity threat detection (ITDR)](https://triplepoint.org.uk/security/detect-and-respond/identity-protection.md)
