Analyst Spotlight
Carlos Gómez Gallego
Chief Technology Officer, APJ Region
HPE Networking
The Network: Your Most Under-Utilised Security Asset
When organisations talk about cybersecurity, the conversation often starts with endpoint protection, identity, firewalls, SIEM platforms and increasingly, AI. Yet sitting underneath all of these technologies is a security asset that is frequently overlooked: the network itself.
Every device that connects to an organisation’s wired or wireless infrastructure creates an opportunity to understand, assess and control risk. The network sees who or what is connecting, what they are connecting to, where they are connecting from and, critically, how they behave once connected. This makes the network an incredibly powerful security enforcement point.
Modern wired and wireless infrastructure provides far more than connectivity. With the right architecture, it can continuously identify devices, measure security posture, analyse intent and enforce policy. A laptop belonging to an employee should have a very different level of access from an unknown IoT device, a contractor’s phone or a device exhibiting suspicious behaviour. Just because an IoT requires internet access, it does not mean it requires full internet access. Modern network infrastructure can provide application firewall services, URL filtering and IDS/IPS. This allows organisations to control traffic right at the network layer in addition to traditional perimeter or cloud enforcement points.
Network access control can bring together identity, device posture, location, authentication and security policy to make an informed decision about network access. Rather than simply asking “Is this user authenticated?”, organisations can ask “Should this specific device, belonging to this user, be allowed to access this resource right now?” That is the fundamental principle of deploying with a Zero Trust framework as your North Star. The network becomes an active security control rather than simply the plumbing that carries traffic. It can dynamically segment users and devices, restrict access, quarantine compromised endpoints and provide valuable telemetry to security teams.
The opportunity is real. Organisations have already invested heavily in their wired and wireless infrastructure but barely leverage the security features that come with it. By integrating that infrastructure with NAC, identity, and security platforms, they can turn an existing connectivity investment into a strategic security enforcement layer. Security can and should start the moment a device attempts to connect to the network. The infrastructure you have is a great security asset already under your control