{"id":9976,"date":"2022-06-03T10:21:04","date_gmt":"2022-06-03T08:21:04","guid":{"rendered":"http:\/\/nfirjun2026.local\/what-does-security-monitoring-do-for-my-network-security\/"},"modified":"2025-10-20T19:44:23","modified_gmt":"2025-10-20T17:44:23","slug":"what-does-security-monitoring-do-for-my-network-security","status":"publish","type":"post","link":"https:\/\/www.cyber-security-online.nl\/en\/what-does-security-monitoring-do-for-my-network-security\/","title":{"rendered":"What does security monitoring do for my network security?"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"9976\" class=\"elementor elementor-9976 elementor-9919\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-ae9b36a elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"ae9b36a\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-66 elementor-top-column elementor-element elementor-element-74f6534\" data-id=\"74f6534\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-bba0714 elementor-widget elementor-widget-text-editor\" data-id=\"bba0714\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>The goal of our <a href=\"https:\/\/www.cyber-security-online.nl\/en\/managed-detection-and-response-mdr\/\">MDR services<\/a> is to unburden and support your organization in the area of Security Monitoring. NFIR monitors the most common log files of the agreed network components 24\/7\/365 and provides adequate analysis, follow-up actions and reports according to the agreements made. Through logging, monitoring and detection measures, NFIR ensures that cyber threats and attacks can be detected at a very early stage. Through early detection, adequate action can be taken to stop the attack as quickly as possible or, in some cases, even prevent it. Also, central logging -separated from the network- ensures that in the event of an incident, forensic investigation is guaranteed. After all, malcontents could cover their tracks. <\/strong><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-33 elementor-top-column elementor-element elementor-element-0fa9b73\" data-id=\"0fa9b73\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-3420a51 elementor-widget elementor-widget-image\" data-id=\"3420a51\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/www.cyber-security-online.nl\/en\/managed-detection-and-response-mdr\/\">\n\t\t\t\t\t\t\t<img decoding=\"async\" width=\"674\" height=\"784\" src=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/05\/Security-monitoring-blog.jpg\" class=\"attachment-medium_large size-medium_large wp-image-9923\" alt=\"Security monitoring - MDR - cyber security kill-chain\" srcset=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/05\/Security-monitoring-blog.jpg 674w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/05\/Security-monitoring-blog-258x300.jpg 258w\" sizes=\"(max-width: 674px) 100vw, 674px\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-6e8f740 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"6e8f740\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-4b02d10\" data-id=\"4b02d10\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-d1862e0 elementor-widget elementor-widget-heading\" data-id=\"d1862e0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">The importance of adequate logging<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ab08b97 elementor-widget elementor-widget-text-editor\" data-id=\"ab08b97\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>When conducting forensic investigations, maintaining logging with integrity comes back as a concern to our clients. Logging is not only a requirement for compliance goals, but also provides insight into what has occurred from a risk perspective. NFIR hereby takes care, at a minimum, of tuning the detection for the presence of logging and reading in logging in an established format for analysis. Then, easy and fast retrieval of information is a next step that we support clients with. With logging stored outside the system landscape, irrefutable proof of certain behaviors at the system level has become much easier. As a side effect, the preventive effect on malicious behavior of users or hackers is also made transparent, so that it can be mitigated in terms of risk following an integer process. Connection of such logsources requires an integrity check and can then be arranged with simple use cases. This integrity check should ensure that the logging can be trusted by providing visibility and hardening of system usage. Another reason for storing logging is to provide insight about attacks and\/or anomalous behavior and other vulnerabilities. <\/p><p><span style=\"font-style: inherit; font-weight: inherit; color: var(--ast-global-color-3);\">The use of logging is necessary for storing important information from the network. There are two reasons for this:<\/span><\/p><ol><li>Logged data can be analyzed and activated through use cases.<\/li><li>Log data is very important to serve as a forensic basis for digital forensics in case of incidents.<\/li><\/ol>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-bc263c2 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"bc263c2\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-20a618f\" data-id=\"20a618f\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-36513ce elementor-widget elementor-widget-heading\" data-id=\"36513ce\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Use case development<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-55c8391 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"55c8391\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-fe1f02a\" data-id=\"fe1f02a\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5045308 elementor-widget elementor-widget-text-editor\" data-id=\"5045308\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>As a starting point for use case development, we assume the risk of information being compromised by criminals who use it for monetary gain or extortion. This is a risk scenario where modifications by the attacker succeed each other. Consider the growing phenomenon of &#8220;<a href=\"https:\/\/www.cyber-security-online.nl\/en\/fd-speaks-to-nfir-about-dos-and-donts-in-ransomware-attack\/\" target=\"_blank\" rel=\"noopener\">ransomware<\/a>&#8221; as well as the ex-filtration of classified information. Criminals bypass detection measures that indicate the building of such an attack. This requires an understanding of how to detect these build-up activities, these activities are also referred to in the cyber security market as the &#8220;<b>Cyber Security Kill Chain<\/b>. See below for a representation of the common steps involved in this chain that can be taken and result in a successful attack. <\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-32361c6 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"32361c6\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-43ce8fd\" data-id=\"43ce8fd\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-57c21b0 elementor-widget elementor-widget-image\" data-id=\"57c21b0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<a href=\"https:\/\/www.cyber-security-online.nl\/en\/managed-detection-and-response-mdr\/\">\n\t\t\t\t\t\t\t<img decoding=\"async\" width=\"674\" height=\"784\" src=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/05\/Security-monitoring-blog.jpg\" class=\"attachment-medium_large size-medium_large wp-image-9923\" alt=\"Security monitoring - MDR - cyber security kill-chain\" srcset=\"https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/05\/Security-monitoring-blog.jpg 674w, https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2022\/05\/Security-monitoring-blog-258x300.jpg 258w\" sizes=\"(max-width: 674px) 100vw, 674px\" \/>\t\t\t\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-d459b23 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"d459b23\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-14ac4ae\" data-id=\"14ac4ae\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-ca98ad9 elementor-widget elementor-widget-text-editor\" data-id=\"ca98ad9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>  The steps in this &#8220;Cyber Security Kill Chain&#8221; have been developed as an attack scenario. However, it is also possible that other paths could be used leading to a variety of scenarios. Therefore, the translation into use cases remains a constant development that NFIR focuses on based on the constant supply of knowledge from various experiences. <\/p><p>To illustrate, we outline below the possible use cases per attack step, these use cases are usually smooth to implement and provide a good basis. <\/p><p> <\/p><table width=\"602\"><tbody><tr><td width=\"284\"><p><strong><em>Attack step<\/em><\/strong> <\/p><\/td><td width=\"318\"><p><strong><em>Use case<\/em><\/strong> <\/p><\/td><\/tr><tr><td width=\"284\"><p>Discovering vulnerabilities in the environments <\/p><\/td><td width=\"318\"><p>Open RDP ports that are accessed from the outside <\/p><\/td><\/tr><tr><td width=\"284\"><p>Attempts at account abuse and\/or modifying permissions <\/p><\/td><td width=\"318\"><p>Detection of brute-force attacks within the local Windows domain <\/p><p>Detection of brute-force attacks within Azure AD <\/p><\/td><\/tr><tr><td width=\"284\"><p>Attempts at account abuse and\/or modifying permissions: <\/p><p>Communication appropriate to attacks <\/p><\/td><td width=\"318\"><p>Creation of mailbox rules via Exchange Online web portal <\/p><\/td><\/tr><tr><td width=\"284\"><p>Attempts at account abuse and\/or modifying permissions: <\/p><p>Command &amp; Control <\/p><\/td><td width=\"318\"><p>Abnormal login attempts with accounts within Azure AD <\/p><\/td><\/tr><tr><td width=\"284\"><p>Adjusting settings. For example DLP policy, phishing filter. Etc. <\/p><p>Catch all, for analysis <\/p><\/td><td width=\"318\"><p>Monitoring Threat Intelligence findings. <\/p><\/td><\/tr><tr><td width=\"284\"><p>Communication appropriate to attacks: <\/p><p>Catch all, for analysis <\/p><\/td><td width=\"318\"><p>NFIR analyzes and combines threat info from firewall with other log sources to provide a holistic view. <\/p><\/td><\/tr><\/tbody><\/table>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-c35356b elementor-widget elementor-widget-heading\" data-id=\"c35356b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">In a nutshell<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-244a965 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"244a965\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-78dee8d\" data-id=\"78dee8d\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-93f68d7 elementor-widget elementor-widget-text-editor\" data-id=\"93f68d7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>  The first step is to link your log sources via a so-called log collector with the 24\/7 functioning SOC, for Network Monitoring. Information from log sources from, for example, an intrusion detection system (IDS), firewall, Active Directory, endpoint detection, Microsoft365, Windows event logs are linked to our SIEM.  <span style=\"font-style: inherit; font-weight: inherit; color: var(--ast-global-color-3);\">You then work with our team to determine what the use cases are that specific alerts should go off on. Critical notifications will be sent to you from our SIEM\/SOC immediately via email or text message and\/or you will be called. Your ICT department can take action on this. Our service is managed: we only alarm when necessary. <\/span><span style=\"font-style: inherit; font-weight: inherit; color: var(--ast-global-color-3);\">Once the service has been running within your organization for a while, you will have a service manager as standard who will go through all the reports with you each month and advise on how the MDR process can be further optimized.<\/span><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-c5bcbc1 elementor-section-full_width elementor-section-height-default elementor-section-height-default\" data-id=\"c5bcbc1\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-no\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-756c72fa\" data-id=\"756c72fa\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-74e8d3bc elementor-cta--skin-classic elementor-animated-content elementor-bg-transform elementor-bg-transform-zoom-in elementor-widget elementor-widget-call-to-action\" data-id=\"74e8d3bc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"call-to-action.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-cta\">\n\t\t\t\t\t<div class=\"elementor-cta__bg-wrapper\">\n\t\t\t\t<div class=\"elementor-cta__bg elementor-bg\" style=\"background-image: url(https:\/\/www.cyber-security-online.nl\/wp-content\/uploads\/2019\/08\/Security-Monitoring_LQ-1024x348.jpg);\" role=\"img\" aria-label=\"security monitoring , security monitoring , cybermonitor , cybersecurity , safeharbour , security monitoring\"><\/div>\n\t\t\t\t<div class=\"elementor-cta__bg-overlay\"><\/div>\n\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-cta__content\">\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t<h2 class=\"elementor-cta__title elementor-cta__content-item elementor-content-item\">\n\t\t\t\t\t\tInterested in our Managed Detection and Response (MDR) solution?\t\t\t\t\t<\/h2>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-cta__description elementor-cta__content-item elementor-content-item\">\n\t\t\t\t\t\t<a href=\"https:\/\/www.cyber-security-online.nl\/en\/managed-detection-and-response-mdr\/security-monitoring\/\">Security monitoring<\/a><br>\n\t\t\t\t\t<\/div>\n\t\t\t\t\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-cta__button-wrapper elementor-cta__content-item elementor-content-item \">\n\t\t\t\t\t<a class=\"elementor-cta__button elementor-button elementor-size-md\" href=\"https:\/\/www.cyber-security-online.nl\/en\/contact\/?your-subject=Security%20monitoring\">\n\t\t\t\t\t\tGet in touch with us\t\t\t\t\t<\/a>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7c9e0f63 elementor-widget elementor-widget-spacer\" data-id=\"7c9e0f63\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"spacer.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-spacer\">\n\t\t\t<div class=\"elementor-spacer-inner\"><\/div>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-50282375 elementor-widget elementor-widget-accordion\" data-id=\"50282375\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"accordion.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-1341\" class=\"elementor-tab-title\" data-tab=\"1\" role=\"button\" aria-controls=\"elementor-tab-content-1341\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What is Security Monitoring?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-1341\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"1\" role=\"region\" aria-labelledby=\"elementor-tab-title-1341\"><p>Security monitoring involves monitoring network traffic and analysing log files in order to detect threats, vulnerabilities and cyber attacks at an early stage. NFIR offers a fully automated solution, so that you no longer need to interpret data yourself. Via a dashboard you can view all notifications and take action if necessary.<\/p>\n<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-1342\" class=\"elementor-tab-title\" data-tab=\"2\" role=\"button\" aria-controls=\"elementor-tab-content-1342\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">How is network traffic monitored?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-1342\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"2\" role=\"region\" aria-labelledby=\"elementor-tab-title-1342\"><p>NFIR Insights, our security monitoring service, analyses all data from the connected detection sources and displays that processed data in an easy to interpret dashboard environment. NFIR&#8217;s security monitoring specialists automatically process the log data received on the basis of use cases, which are determined together with the customer. When monitoring network traffic, all information, including reports of suspicious activity, ends up in a dashboard. This way you are quickly informed of activities on your network and you can intervene adequately in case of suspicious activities.<\/p>\n<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-1343\" class=\"elementor-tab-title\" data-tab=\"3\" role=\"button\" aria-controls=\"elementor-tab-content-1343\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">How can monitoring security help protect my network?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-1343\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"3\" role=\"region\" aria-labelledby=\"elementor-tab-title-1343\"><p>Monitoring your network can help detect malicious behaviour early on. If you want to protect your network, it is best to start monitoring your network. You gain insight into your network, you are quickly informed of suspicious activities and you can take appropriate action if a suspicious situation arises.<\/p>\n<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-1344\" class=\"elementor-tab-title\" data-tab=\"4\" role=\"button\" aria-controls=\"elementor-tab-content-1344\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">How is network traffic monitored?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-1344\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"4\" role=\"region\" aria-labelledby=\"elementor-tab-title-1344\"><p>NFIR Insights, our security monitoring service, analyses all data from the connected detection sources and displays that processed data in an easy to interpret dashboard environment. NFIR&#8217;s security monitoring specialists automatically process the log data received on the basis of use cases, which are determined together with the customer. When monitoring network traffic, all information, including reports of suspicious activity, ends up in a dashboard. This way you are quickly informed of activities on your network and you can intervene adequately in case of suspicious activities.<\/p>\n<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h4 id=\"elementor-tab-title-1345\" class=\"elementor-tab-title\" data-tab=\"5\" role=\"button\" aria-controls=\"elementor-tab-content-1345\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><i class=\"fas fa-plus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><i class=\"fas fa-minus\"><\/i><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What is the significance of SIEM and SOC?<\/a>\n\t\t\t\t\t<\/h4>\n\t\t\t\t\t<div id=\"elementor-tab-content-1345\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"5\" role=\"region\" aria-labelledby=\"elementor-tab-title-1345\"><p>NFIR offers a scalable, manageable and affordable solution with its <a href=\"https:\/\/www.cyber-security-online.nl\/en\/siem-and-soc\/\">Security Information and Event Management (SIEM)<\/a> and the implementation of a <a href=\"https:\/\/www.cyber-security-online.nl\/en\/siem-and-soc\/\">Security Operation Centre (SOC)<\/a>. We offer our SIEM as a fully automated solution, where you no longer have to interpret data yourself. The outputs are reports that your IT department can take action on. <a href=\"https:\/\/www.cyber-security-online.nl\/en\/siem-and-soc\/\">Read how we take the worry out of your life and what results you will achieve when implementing our SIEM and SOC solution<\/a>.  <\/p>\n<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t\t<script type=\"application\/ld+json\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is Security Monitoring?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<p>Security monitoring involves monitoring network traffic and analysing log files in order to detect threats, vulnerabilities and cyber attacks at an early stage. NFIR offers a fully automated solution, so that you no longer need to interpret data yourself. Via a dashboard you can view all notifications and take action if necessary.<\\\/p>\\n\"}},{\"@type\":\"Question\",\"name\":\"How is network traffic monitored?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<p>NFIR Insights, our security monitoring service, analyses all data from the connected detection sources and displays that processed data in an easy to interpret dashboard environment. NFIR&#8217;s security monitoring specialists automatically process the log data received on the basis of use cases, which are determined together with the customer. When monitoring network traffic, all information, including reports of suspicious activity, ends up in a dashboard. This way you are quickly informed of activities on your network and you can intervene adequately in case of suspicious activities.<\\\/p>\\n\"}},{\"@type\":\"Question\",\"name\":\"How can monitoring security help protect my network?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<p>Monitoring your network can help detect malicious behaviour early on. If you want to protect your network, it is best to start monitoring your network. You gain insight into your network, you are quickly informed of suspicious activities and you can take appropriate action if a suspicious situation arises.<\\\/p>\\n\"}},{\"@type\":\"Question\",\"name\":\"How is network traffic monitored?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<p>NFIR Insights, our security monitoring service, analyses all data from the connected detection sources and displays that processed data in an easy to interpret dashboard environment. NFIR&#8217;s security monitoring specialists automatically process the log data received on the basis of use cases, which are determined together with the customer. When monitoring network traffic, all information, including reports of suspicious activity, ends up in a dashboard. This way you are quickly informed of activities on your network and you can intervene adequately in case of suspicious activities.<\\\/p>\\n\"}},{\"@type\":\"Question\",\"name\":\"What is the significance of SIEM and SOC?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"<p>NFIR offers a scalable, manageable and affordable solution with its <a href=\\\"https:\\\/\\\/www.cyber-security-online.nl\\\/en\\\/siem-and-soc\\\/\\\">Security Information and Event Management (SIEM)<\\\/a> and the implementation of a <a href=\\\"https:\\\/\\\/www.cyber-security-online.nl\\\/en\\\/siem-and-soc\\\/\\\">Security Operation Centre (SOC)<\\\/a>. We offer our SIEM as a fully automated solution, where you no longer have to interpret data yourself. The outputs are reports that your IT department can take action on. <a href=\\\"https:\\\/\\\/www.cyber-security-online.nl\\\/en\\\/siem-and-soc\\\/\\\">Read how we take the worry out of your life and what results you will achieve when implementing our SIEM and SOC solution<\\\/a>.  <\\\/p>\\n\"}}]}<\/script>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>The goal of our MDR services is to unburden and support your organization in the area of Security Monitoring. NFIR monitors the most common log [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":9923,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_seopress_titles_title":"Read more \" Make cyber threats and attacks visible with Security Monitoring","_seopress_titles_desc":"Meta description: Are you looking for a solution for Security Monitoring? NFIR provides a managed solution that allows you to monitor network traffic to detect threats, vulnerabilities and cyberattacks early. Learn more with our managed detection & response (MDR) services.","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"none","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"both","_seopress_redirections_param":"","_seopress_redirections_type":301,"_seopress_analysis_target_kw":"","_seopress_news_disabled":"","_seopress_video_disabled":"","_seopress_video":[],"_seopress_pro_schemas_manual":[],"_seopress_pro_rich_snippets_disable_all":"","_seopress_pro_rich_snippets_disable":[],"_seopress_pro_schemas":[],"site-sidebar-layout":"default","site-content-layout":"default","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"default","adv-header-id-meta":"","stick-header-meta":"default","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[29],"tags":[],"class_list":["post-9976","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-media-en"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/posts\/9976","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/comments?post=9976"}],"version-history":[{"count":0,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/posts\/9976\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/media\/9923"}],"wp:attachment":[{"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/media?parent=9976"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/categories?post=9976"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cyber-security-online.nl\/en\/wp-json\/wp\/v2\/tags?post=9976"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}