Back to blog

How does a company operate during an attack?

How Does a Company Operate During a Cyberattack?

NetSenX Team7 min read
incident-responseransomwaregovernancendr

The most dangerous moment of a cyberattack very often does not look like a scene from a movie. There are no red alarms, no dramatic music, and no warning message flashing across every screen. The company continues to work. Someone issues an invoice. Someone approves an order. Production follows the schedule. A salesperson sends an offer. Accounting opens an attachment. An administrator sees another alert that looks similar to dozens of previous ones.

And that is exactly when the problem begins.

Many attacks do not start with spectacular data encryption. Ransomware, data leakage or system shutdown is often only the final stage. Before that, much quieter things may already be happening: unusual logins, network reconnaissance, communication with an external server, attempts to access additional resources, lateral movement, permission testing, data copying or the use of a tool that nobody officially approved.

From the board’s perspective, the company may still look “normal”. Systems are running. People are working. Customers have not noticed anything yet. But from the network perspective, someone may already be checking where the most important data is stored, which systems are critical, and how deep they can move before anyone reacts.

This is one of the biggest illusions in cybersecurity: a company thinks an attack starts when something stops working. In practice, the attack often begins much earlier. It is just that nobody sees it yet or nobody can separate the real signal from ordinary noise.

In mid-sized companies, this problem is especially dangerous. Not because these companies are irresponsible. Quite the opposite many of them are operationally strong. They have good people, systems, procedures, IT providers, antivirus, firewalls, backups and sometimes several different security tools. But attackers do not enter where the company has the best cybersecurity presentation. They enter where there is a gap between systems, an old access, a forgotten integration, a supplier account, unusual traffic or an alert that nobody takes seriously anymore.

That is why it is worth asking an uncomfortable question: do we really know how our company behaves inside the network when everything appears to be working normally?

Because the classic problem today is not only a lack of tools. The problem is that many companies have tools, but still cannot clearly answer one question: what is normal behaviour in our network, and what should already trigger a warning?

Imagine a manufacturing company. Machines are running on the shop floor, the ERP system is active in the office, the warehouse uses a logistics system, the maintenance team has remote access for service providers, accounting receives invoices, and salespeople work from different locations. Each element may seem justified on its own. The problem begins when someone tries to move from one area to another in a way that should not normally happen. An office computer starts communicating with an unusual address. A server that usually does not send large data packages suddenly starts doing it cyclically. A technical account behaves differently than usual. An industrial device appears in traffic nobody expected.

Will the company see it? Will it take it seriously? Will it understand why it matters?

The same applies to IT companies, software houses, system integrators, e-commerce businesses, logistics companies, financial organisations, healthcare providers, manufacturers and service providers. The more data, integrations, APIs, cloud systems, remote access and automation tools a company uses, the larger the area that needs to be monitored. And at the same time, the harder it becomes to do it manually.

The most deceptive thing is that an attack does not always look like an attack. Sometimes it looks like normal user activity. Like system communication. Like an integration. Like an administrative task. Like something that was “probably necessary”. Only later does it turn out that it was the first stage of a larger operation.

That is why modern security cannot rely only on the question: do we know this virus? The more important question is becoming: does this behaviour fit the normal operation of our company?

This is where NDR -Network Detection & Response becomes relevant. It is not about adding another tool that produces hundreds of messages every day. It is about visibility into what is happening in network traffic and the ability to detect behaviours that may indicate command-and-control communication, data exfiltration, network scanning, lateral movement, Shadow IT, unusual sessions or anomalies in IT and OT environments.

But detection alone is still not enough.

In a real company, an alert must be understandable. It cannot be only a technical message that one person in the IT department understands. It has to answer: why is this suspicious, what business impact could it have, what should be checked, and do we have evidence that can later be shown to the board, an auditor, a customer or a regulator?

Because after an attack, a second war begins the war for facts.

When did the incident happen? What exactly was detected? Did personal data leak? Does the supervisory authority need to be notified? Does the incident affect key services? Does it impact customers? Did the company have procedures? Can it prove that it reacted quickly enough? Did the board know what was happening?

In Europe, these questions are becoming increasingly formal. Under GDPR, a personal data breach must generally be reported to the supervisory authority within 72 hours of becoming aware of it, if the breach is likely to result in a risk to the rights and freedoms of individuals. NIS2 strengthens cybersecurity obligations across many essential and important sectors, and significant incident reporting includes early warning, notification and a final report. DORA applies to the financial sector and focuses on digital operational resilience, including the handling of major ICT-related incidents.

This means that for many companies, a cyberattack will no longer be just a “technical problem”. It may become a formal, legal, reputational and board-level matter.

This does not apply only to banks or large corporations. In practice, increasing pressure will affect manufacturing companies, logistics firms, energy organisations, healthcare providers, technology companies, digital service providers, infrastructure operators, companies working with large clients, industrial suppliers and organisations that process important data or support critical processes. Even if a company is not the largest player in the market, it may still be an important link in the supply chain of a larger customer.

And a security chain breaks at its weakest point, not at its largest one.

That is why the worst question after an attack is: “Do we even know what happened?”

The better question should be asked earlier: “Can we see the first signals of an attack before the company starts paying the price?”

NetSenX was created with exactly this gap in mind. It is a SaaS-based NDR platform for European companies that need better visibility of threats, but do not have a large SOC team or the budget for heavy enterprise-class solutions. NetSenX analyses network traffic behaviour, helps detect threats that may be invisible to traditional signature-based systems, and creates alerts that are not only technical, but also understandable and ready to support response, audit and reporting processes.

From the entrepreneur’s perspective, the most important thing is not how many security systems the company has. The most important thing is whether, in a critical moment, the company can move from chaos to decision.

Do we know what is happening? Do we understand why it matters? Do we have evidence? Can we act? Does the board receive a clear picture of the situation, or just another layer of technical noise?

That is the real test of cyber resilience.

Not on the day when everything works perfectly. But when someone is checking how deep they can get into the company before anyone notices.

And here we would like to leave an open question for people managing companies, IT, production, compliance and risk: how does your organisation react to the first signs of an incident? Are alerts taken seriously, or is the team already tired of them? Does the board know what it should see in the first hour of a crisis? Do you have evidence ready, or would you only start looking for it after the fact?

Someone in your network may need to ask these questions before an auditor, regulator or attacker asks them first.

What does a company’s reaction really look like when the first serious signal of a cyberattack appears? What works well, and what usually turns out to be the weakest link in practice?

Further reading: what NetSenX detects and how each alert explains itself, NDR vs EDR vs SIEM for teams without a SOC and how NetSenX compares with other NDR vendors.


Written by the NetSenX Team at TriStiX S.L. Questions: [email protected].

NetSenX Team

TriStiX S.L.