Back to blog

Breached days ago, and still nobody knows

Your network was breached days ago. You still don't know.

NetSenX Team5 min read
ndrnis2incident-responsemid-market

Picture it: someone got into your network six days ago, and nobody has noticed.

Six days during which someone is moving through your systems. Reading your files. Mapping your network. Quietly exfiltrating data to a server in a jurisdiction you've never heard of. Six days during which your IT manager is drinking coffee, checking dashboards, and seeing nothing unusual — because the attacker already knows where the cameras are.

And most of the time?

You find out because someone else tells you.

A client calls to say their data appeared on a dark web forum. A partner notices anomalous login attempts from your domain. A journalist emails asking for a comment.

That's the reality of enterprise network security in 2025 for companies that aren't Google, HSBC, or Siemens.

And it's about to get dramatically more expensive.

The NIS2 clock is already running

Member states had to apply NIS2 from 18 October 2024, and national laws are now in force or arriving across the EU.

A significant incident needs an early warning within 24 hours and an incident notification within 72 hours. For essential entities, national law must allow fines of at least €10 million or 2% of global annual turnover, whichever is higher.

The EU AI Act adds its own penalties: breaching the obligations for high-risk AI systems, human oversight among them, can cost up to €15 million or 3% of turnover.

Not a warning. Not a "please improve your processes." A fine.

Now here's what makes this particularly uncomfortable:

Most IT managers we speak with know NIS2 exists. They've read the headlines. They've attended the webinar. They have a slide in the board deck that says "NIS2 compliance — in progress."

But almost none of them can answer this question with confidence:

"If something significant happened on your network right now — would you know within 72 hours? And would you have the documentation to prove it to a regulator?"

The silence that follows that question is the real security gap.

The Tool That's Supposed to Solve This Costs More Than Your IT Budget

The gold standard of autonomous AI network security is impressive technology. Real-time threat detection. Autonomous response. Beautiful interfaces.

It also carries annual price tags running into many thousands — or for larger deployments, tens of thousands — of euros per year.

For a hospital network in Kraków, a manufacturing plant in Stuttgart, a hotel group in Alicante, or a logistics company in Lyon — that's not a solution. That's a different problem.

And beyond the cost, there's something deeper that most enterprise security platforms get fundamentally wrong for this market:

They are designed to act autonomously, with minimal human involvement in individual decisions.

That might sound like a feature. For a company with a 24/7 SOC team reviewing every automated action with full context? Maybe it is.

For everyone else?

You wake up to find that a critical OT device has been isolated from the network by an algorithm — during a production run. Or a key API integration has been blocked because the traffic pattern looked suspicious. Or a legitimate employee has been locked out of their account at 2am because they were working from an airport in Warsaw.

Autonomous response without explainability isn't security. It's a different kind of operational risk.

What You Actually Need — And What the Market Isn't Giving You

Let us be specific about what the security gap looks like for companies with 20 to 500 devices:

You need to know what's happening on your network. Not in a 200-page log file that requires a forensics specialist to interpret. In plain language. Right now.

You need it explained. Not "anomaly score: 0.87." Tell me what device, what behavior, what it means, and what regulation it touches.

You need to be the one who decides what happens next. Because you know your network. You know that the finance laptop always pings external servers at 3am because of a scheduled backup. The algorithm doesn't know that. You do.

Human oversight is not a compliance checkbox. It is the only architecture that actually works at this scale.

Where NetSenX fits

NetSenX is a European Network Detection and Response (NDR) platform: it detects attacks from network behaviour, explains every alert in plain language and keeps the evidence of what happened. It watches traffic from a SPAN or TAP port, or from agents on the hosts you choose.

It's a network security platform built specifically for companies that can't afford enterprise-tier tools — and shouldn't need to.

When it finds something suspicious, it doesn't block it. It doesn't send you a cryptic alert code. It tells you, in plain language:

For example: “Device 192.168.1.50 (finance laptop) sent 450 KB to api.openai.com at 03:14. That does not fit this host's usual behaviour and looks like company data going to an unapproved AI service. Suggested action: isolate the host. Your approval is required.”

The analyst decides: approve the action, or mark the alert as a false positive.

Either decision is written to the audit log.

Human oversight is part of the design, not a feature added later.

What to watch for

Shadow AI exfiltration — employees sending company data to ChatGPT, Claude, Gemini, or other AI tools without authorization. Many organisations have no visibility into it at all.

C2 beacons — malware that has already established a foothold on your network, quietly phoning home to a command and control server. Often at 3am. Often disguised as routine update traffic.

Unauthorized OT/ICS commands — write commands to PLCs and SCADA systems that don't match authorized operation patterns. One unauthorized Modbus write to a PLC can halt an entire production line.

Data exfiltration — traffic to Pastebin, MEGA, WeTransfer, or unusual external destinations carrying volumes inconsistent with normal behavior.

NIS2-reportable incidents — once an incident is significant, the Article 23 clock runs: 24 hours for the early warning, 72 hours for the notification and one month for the final report.

For every alert, the useful answer is the same: what happened, on which device, why it matters and what you can do next.

What this is built on

NetSenX is developed by TriStiX S.L. in Alicante, Spain.

We published the research before we built the product. Because if you can't explain how your security AI works, you have no business deploying it to protect someone else's network.

Human oversight is not a feature.

It's the architecture.


Have you ever discovered a breach or security incident in your organization later than you should have? What was the detection gap? What was the cost — financial, operational, or reputational?

The NIS2 clock is ticking for all of us.

Further reading: our NIS2 network monitoring checklist, the NIS2 readiness overview and what NetSenX detects and how each alert explains itself.


Written by the NetSenX Team at TriStiX S.L. This article is general information, not legal advice. Questions: [email protected].

NetSenX Team

TriStiX S.L.