How NetOps and SecOps Can Work from the Same Network Evidence
NetSecOps is being embraced by a growing number of organizations, as economies of scale, cross-training opportunities, streamlined incident response, and improved visibility demonstrate the value of this model. At the same, the priorities and workflows of NetOps and SecOps must remain distinct to ensure both security and performance objectives are consistently met.
Joining forces does not always mean melding into one homogenous group. Access to the same pool of network-derived context allows each team to investigate issues faster, reduce friction and redundancy, and draw more confident conclusions.

Differing Priorities
The inherent differences between NetOps and SecOps priorities created a natural divergence in tools, tactics, and data sources. Traditionally, NetOps worked to safeguard network performance and availability by monitoring changes in latency, bandwidth, packet loss, and other leading indicators of degradation. This focus made application and user-experience context essential.
Evolving in parallel were SecOps developing advanced tools and practices to protect networks, applications, and assets from cyber threats while proactively identifying and eliminating vulnerabilities. With these clear objectives in mind, security teams developed strategies to systematically triage alerts and optimize metrics like mean time to detect (MTTD) and mean time to respond (MTTR).
The Importance of Shared Evidence
Despite the inherent differences, readily apparent overlaps and interdependencies helped the NetSecOps model gain momentum. For example, a malware infection might initially be detected as degraded server performance, while seemingly suspicious traffic can be caused by a harmless DNS misconfiguration or system backup. These overlaps often led to duplicated efforts or time-wasting confusion over roles and responsibilities.
Shared tools and evidence in the form of metadata, flow, telemetry, and forensic data help minimize duplicate investigations and unnecessary delays, while allowing teams to categorize and prioritize issues more efficiently. Rich metadata acts as a continuous intelligence layer to drive appropriate responses. Tailored workflows then avail forensic evidence to NetOps as needed to pinpoint the clients, applications, or servers responsible for performance issues.
SecOps call upon the same trove of forensic storage and threat intelligence to reconstruct security incidents in vivid detail, search for indicators of compromise (IoC), and prioritize alerts.
Specialized data for Specialized Workflows
As the power of AI, machine learning, and advanced analytics take network monitoring and investigation practices to the next plateau, a hierarchy of available data sources begins to emerge. Each layer provides another source of actionable intelligence and insight.
- Metadata
Basic information on IP addresses, packet sizes, port numbers, and other readily available information, when combined with intelligent solutions providing structure and analysis, can deliver the insight and context needed to determine ownership and next steps, for either performance or security-related issues. Rich metadata provides teams with useful clues and signals from every packet that passes through the network, along with the wisdom to know when additional evidence is needed.
- Flow & telemetry
Flow-derived metadata, combined with other network and application metadata helps teams build a more complete picture of each network conversation. This includes source and destination IP addresses, the precise amount of data transferred, and the duration of the connection. Authentication logs, registry changes, system events, and simple network management protocol (SNMP) information are part of a long list of telemetry sources available to provide additional insight into the relationships between users, infrastructure, and cloud-based applications.
- Forensic evidence
Forensic evidence in the form of captured packets provides the proof both NetOps and SecOps need to complete complex investigations and conclusively identify root cause. Unabridged historical data provides a window into who was communicating on the network at any time. NetOps utilize this information to gain more insight into traffic patterns and bottlenecks or to optimize network configurations. Captured packets also close the compliance loop for SecOps by reconstructing the precise timing, source, application, and data associated with a security incident.
- Threat intelligence
The evidence-based knowledge known as matches live traffic behavior against known attacker techniques, indicators of compromise (IoCs), and vulnerabilities, providing another layer of visibility and insight before, during, and after an incident. Although the name implies that this important capability belongs in the security category, threat intelligence is also useful in shared investigations, helping both NetOps and SecOps to investigate incidents more thoroughly, reduce false positives, and improve decision-making.
Observer Apex is the NetSecOps Intelligence Layer
Despite the common misconception, NetSecOps is not about collapsing teams into one function. Instead, shared metadata-rich visibility and purpose-built workflows allow the whole to become greater than the sum of its parts. VIAVI harnesses a wealth of available network data and threat intelligence to provide the context, direction, and concrete evidence needed to support the distinct NetOps and SecOps objectives. As part of the multi-faceted Observer Platform, Apex also produces an intuitive end-user experience (EUE) score for every network transaction, and on-demand application dependency mapping for immediate multi-tier visibility.
