The incident had been running for 11 days when the IT team noticed.

Not because monitoring caught it. Because a user complained about slowness.

The logs existed. The anomaly was there. No one was watching.

  • NETWORK VISIBILITY FOR SME INFRASTRUCTURE THE THREE PILLARS

You cannot defend what you cannot see. Visibility is the prerequisite for every other control.

1. SNMP v3 — DEVICE HEALTH AND STATE

SNMP polls devices for CPU, memory, interface status, and error counters.

Never deploy SNMPv1 or v2c — community strings travel in plaintext. SNMPv3 with authPriv provides authentication and encryption. Use it exclusively.

CPU above 80% — routing storm, DDoS, or misconfiguration. Interface errors signal physical or duplex issues. Interface utilization above 90% — congestion.

  • 2. SYSLOG EVENTS ARE INTELLIGENCE

Every device generates logs: authentication events, configuration changes, ACL hits. Ship everything to a central SIEM. Minimum retention: 90 days.

Alert on: — Configuration changes outside maintenance windows. — Authentication failures on management interfaces. — Interface flapping repeatedly. — ACL deny spikes. Reconnaissance looks like denied traffic at volume.

  • 3. NETFLOW WHO IS TALKING TO WHOM

NetFlow exports flow records: source IP, destination IP, port, protocol, bytes transferred.

This is your lateral movement detector. A workstation connecting to twenty other workstations is anomalous — flag it immediately.

4. BASELINE FIRST, ALERT SECOND

Alerting without a baseline produces noise. Teams learn to ignore alerts.

Capture one week of traffic and SNMP counters. Set thresholds at 150–200% of baseline. Deviations become meaningful signals.

5. MINIMUM VIABLE VISIBILITY STACK

SNMPv3 polling every 5 minutes on all devices. Syslog centralized, 90-day retention. NetFlow on the perimeter router, 1:1 sampling. Alert on: CPU spikes, auth failures, config changes, ACL spikes, lateral flows.

This runs on a single server. No budget excuse for blind infrastructure.

Silent networks are not secure networks. They are unmonitored ones.

The attacker who ran undetected for 11 days was not sophisticated. The network was not watching.

What is the longest a security event went undetected in your environment?
Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.