# Surviving the Mythos Era: Richard Bejtlich on Why Network Detection and Response Matters Now
The cybersecurity industry has long been plagued by oversimplified narratives about how threats move through networks and how defenders should respond. Network Detection and Response (NDR) represents a pragmatic correction to years of mythology that has left organizations vulnerable—a point security veteran Richard Bejtlich has been emphasizing with increasing urgency as breach patterns reveal the limits of traditional detection approaches.
## The Mythos Era: Breaking False Narratives
For decades, cybersecurity strategy has been built on a series of incomplete assumptions. The industry promoted the idea that strong perimeter defenses, endpoint protection, and SIEM systems would catch most threats. Breaches kept happening anyway. Another myth held that attackers operate in neat, linear stages—reconnaissance, weaponization, delivery, exploitation, installation, command-and-control, and exfiltration. In reality, threat actors operate with far more flexibility, moving laterally through networks in ways traditional monitoring tools weren't designed to detect.
Bejtlich, who has led security operations at organizations ranging from Fortune 500 firms to government agencies, argues that the security industry has been slow to reckon with a fundamental truth: most breaches aren't prevented by blocking initial access—they're caught (or should be) during the dwell phase, when attackers establish persistence and move laterally.
"We've been chasing myths instead of embracing what the data actually tells us," Bejtlich has emphasized. The data is clear: breach investigations consistently reveal that attackers spend days, weeks, or even months inside networks before being detected. The question isn't whether they'll get in—it's whether defenders can see them while they're there.
## What Network Detection and Response Actually Does
NDR is fundamentally different from the prevention-first models that dominated for years. Rather than trying to stop every threat at the door, NDR platforms focus on analyzing network traffic and behavior to detect compromise after it occurs.
Key capabilities include:
Unlike endpoint detection and response (EDR), which operates at the individual machine level, NDR sees the entire network. This perspective matters because attackers don't stay confined to a single endpoint—they move, they pivot, they establish multiple footholds. A sophisticated attack that evades endpoint-level detection might leave unmistakable traces in network behavior.
## The Evidence from Real Breaches
Recent breach investigations have validated Bejtlich's thesis. In high-profile incidents—from the SolarWinds supply chain compromise to ransomware campaigns targeting hospitals and critical infrastructure—analysis has revealed a consistent pattern: attackers spent significant time moving laterally and establishing persistence before triggering their final payload.
A few examples illustrate why network-level visibility proved critical:
| Incident Type | Detection Challenge | NDR Advantage |
|---|---|---|
| Supply Chain Compromise | Legitimate software updates mask malicious code | Network behavior reveals C2 traffic and lateral scanning |
| Ransomware Pre-Staging | Encrypted files on endpoints appear normal during reconnaissance | Unusual internal traffic, privilege escalation attempts, and encryption tool execution are visible network-wide |
| Insider Threats | User identity is difficult to verify when credentials are compromised | Anomalous data flows and access patterns stand out against behavioral baselines |
| Targeted APT Activity | Sophisticated tools evade endpoint security | Multi-step exploitation and persistence mechanisms generate network signatures |
In each case, the attacker's presence *within the network* created detectable anomalies that endpoint tools alone might have missed.
## Why the Industry Was Slow to Adopt This Model
The resistance to network-centric detection stems partly from historical infrastructure decisions. Many organizations built their security stacks around endpoint and perimeter tools because those were the available options when they made their investments. SIEM systems, while powerful for log aggregation, often lack the depth of protocol-level insight that modern NDR platforms provide.
There's also a cultural component. The security industry's mythology has long centered on prevention—the idea that a perfect defense is possible, that sophisticated enough firewalls and endpoint protection will stop the bad guys. This narrative is more appealing (and more marketable) than the reality: attackers will get in, and the question is how fast you can find and evict them.
Bejtlich has been blunt about this: the industry has oversold prevention and undersold detection. Organizations have spent billions on tools that promise to keep threats out, only to discover that once a capable attacker is inside, most of those tools are largely irrelevant.
## The Business Case and Practical Implementation
For many organizations, implementing NDR doesn't require ripping out existing security infrastructure. NDR complements EDR, SIEM, and threat intelligence efforts by adding a network-centric lens.
Implementation typically involves:
1. Deploying sensors on network segments to capture and analyze traffic
2. Establishing behavioral baselines that reflect legitimate user and system activity
3. Integrating threat intelligence to correlate observed behavior against known TTPs
4. Building response playbooks that define automated and manual actions based on confidence levels
5. Training analysts to interpret NDR findings and investigate alerts efficiently
Organizations that have invested in NDR report faster mean time to detect (MTTD) and mean time to respond (MTTR)—measurable reductions in breach dwell time.
## Implications for Enterprise Security
The argument for NDR isn't that prevention is unimportant—it's that detection and response represent a more reliable layer of defense. This reframing has profound implications:
## HackWire Analysis
Bejtlich's case for NDR cuts through marketing-driven cybersecurity narratives to address a hard truth: the industry has built most of its defensive infrastructure around a prevention model that, while useful, is fundamentally incomplete. Years of breach investigations show the same pattern—threats dwell undetected for months not because sophisticated attacks are unstoppable, but because defenders aren't looking at the right place (the network) or asking the right questions (what traffic patterns indicate compromise?).
The "Mythos Era" Bejtlich references is the period when the security industry could still maintain the fiction that defense-in-depth, endpoint protection, and firewalls alone would keep organizations safe. That era is over. The data from real breaches is unambiguous: attackers routinely evade perimeter and endpoint defenses. The organizations that contain them quickly are those with network-level visibility.
What's particularly important is that NDR isn't a moonshot technology—it's a mature category with proven effectiveness. The barrier to adoption isn't technical; it's organizational inertia and the sunk costs in existing security stacks. That's a solvable problem if leadership makes detection a strategic priority rather than an afterthought.
For defenders, the key takeaway is clear: assume breach, but make compromise visible. This means investing in NDR capabilities, integrating them with existing tooling, and building security teams that can act on the intelligence networks provide. For vendors, it means moving beyond marketing claims about "preventing everything" and instead competing on the ability to detect what slips through—because something always will.
— HackWire Editorial
## Related Coverage