Skip to content
BCN-T2-NET-003Tier 2 · RegulatoryNetwork

Missing Intrusion Detection Coverage

No detection capability at network boundaries or across critical segments.

Remediation SLA
30 days
Tier
2 · Regulatory
Domain
Network
Escalation
Security manager review at 14 days

What this finding is

Network-based detection is absent or covers only part of the estate — commonly present at the internet edge but absent between internal segments, or deployed for on-premises networks with no equivalent for cloud workloads. The finding also covers deployed sensors producing alerts that no process consumes.

Why it is Tier 2

Detection is explicitly mandated by PCI DSS, NIST CSF, and ISO 27001, making its absence a direct audit deficiency. It is Tier 2 rather than Tier 1 because detection does not prevent compromise — it bounds dwell time. An estate with strong preventive controls and no detection is in a materially better position than the reverse, which is why Beacon does not treat this as an emergency, but the gap directly determines how long an intrusion runs before anyone notices.

Most common misclassification

Endpoint detection is sometimes recorded as satisfying this finding. EDR and network detection cover different traffic and different techniques; frameworks that require network-based detection are not satisfied by endpoint coverage alone.

How to detect it

  1. 1Map deployed sensors against network topology and identify segments with no coverage — east-west traffic is the usual gap.
  2. 2Confirm cloud workloads are covered by an equivalent capability, since traditional appliances do not see cloud-internal traffic.
  3. 3Test with a benign, agreed detection trigger and confirm the alert reaches a human, which is the control that actually matters.
  4. 4Review alert disposition: a high false-positive rate that has led to alerts being ignored is functionally equivalent to no coverage.

How to remediate it

Steps are ordered. The first step is the one that reduces exposure fastest, which is not always the one that closes the finding.

  1. 1Prioritise coverage at the regulated-environment boundary, which is where assessors look first.
  2. 2Deploy cloud-native detection (GuardDuty, Defender for Cloud, Security Command Center) for cloud workloads rather than attempting to route traffic to on-premises appliances.
  3. 3Route alerts into a monitored queue with a defined triage owner and response time, and tune out false positives rather than allowing them to accumulate.
  4. 4Establish a recurring detection test so coverage is verified continuously rather than assumed between audits.
  5. 5Document coverage and tuning decisions as evidence.

How to verify the fix

A benign detection trigger executed in each covered segment produces an alert that reaches the triage queue within the defined time, evidenced by the ticket rather than by the console.

Mappings

Attacker techniques

  • T1562.001Impair Defenses: Disable or Modify Tools

Compliance mappings

  • PCI DSS v4.0
    11.5.1 — intrusion detection and prevention
  • NIST CSF 2.0
    DE.CM-01 — networks are monitored
  • ISO/IEC 27001:2022
    A.8.16 — monitoring activities

Tools that surface this

SuricataZeekGuardDutyPROWLER