5 ways to tackle your network security challenges

Paul Yarwood, Enterprise Networks Architect at Block, outlines where to focus and what to deploy to keep your network secure.

The complexities of modern networks and attack surfaces make it incredibly difficult to boil network security down to a few key considerations. There’s just so much to look out for, and recent threat intelligence reports highlight that best.

So, let’s start by looking at what the network security landscape looks like right now:

  • Preventable gaps in coverage and inconsistently applied controls directly contribute to 90% of incidents investigated.
  • Phishing and vulnerabilities remain the highest initial access vectors, both being the initial access vector in 22% of incidents
  • AI has become a force multiplier for attackers, increasing attack speed, scale, and effectiveness, as well as exposing novel attack vectors.
  • Attackers begin scanning for vulnerabilities within 15 minutes of announcement.
  • 22% of attacks in 2025 reached the exfiltration state in under one hour, with the median across all attacks being two days.
  • 65% of initial access is driven by identity attacks (stolen credentials, session hijacks, mis-scoped privileges etc).
  • The National Institute of Standards and Technology (NIST) shows that 2026 is well on track to exceed 50,000 disclosed vulnerabilities for the first time, indicating that the frequency of vulnerability disclosure is also ramping up.

So what can we do to tackle some of the network security challenges we face?

1. Zero Trust principles

Adopting Zero Trust principles is the best thing we can do to harden our infrastructure and protect our endpoints right now.

Zero Trust is really a logical progression of the ‘defence-in-depth’ approach we’ve all used for years. However, the major difference is that we want to remove implicit trust from the system, meaning we need a much better understanding of the endpoints, workloads, applications, and data we’re trying to protect. Once we have this, we need the rigour to apply security rules in line with Zero Trust.

There’s a significant benefit to mapping and fully understanding these data flows. You can begin adding security policy rules to enforce least privilege network access, which massively reduces the internal attack surface.

Does this mean I’m saying you need to go and buy a ZTNA solution? Honestly, no, not really. But you will need an infrastructure capable of network authentication, multi-layer segmentation, and the integration of security inspection capabilities typical of modern software-defined networks to achieve this at scale.

2. Consistent controls application

Software-defined networks really help with the challenge of applying consistent controls. Centralised controller-driven configuration enables consistency through template-driven architectures and automation workflows.

Cisco has taken this function further with the recently announced Cisco Cloud Control, which unifies network infrastructure management across domains to further simplify operations.

Configuration is important in ensuring compliance with policy. Auditing capabilities alongside this also helps understand the health of security controls over time and can trigger actions to remediate problems before they can be exploited.

However, you should also consider adopting posture assessment for access to network resources. This allows you to gain visibility and confidence into the operational state of endpoint security controls in your estate.

In this scenario, the network acts as an ‘honest broker’ to identify and force remediation of clients that don’t conform to expected controls. This greatly improves security hygiene in an environment and reduces risk considerably.

3. Cross domain visibility and control

A longstanding challenge with securing networks is when different network regions have differing controls, with limited integration, and no common view of policy or enforcement metrics.

The industry is recognising this and moving towards a common control mechanism. A clear example here is Cisco Common Policy, which allows segmentation policy to be unified between campus, datacentre, firewall, and cloud regions.

Additionally, innovations such as the Hybrid Mesh Firewall provides for a unified policy model that disaggregates Firewall controls from physical firewall hardware. The Cisco Hybrid Mesh Firewall is managed from the Cisco Cloud Control console, with enforcement points possible across firewalls, network components, cloud, and workloads. This provides centralised visibility and control over security functions and telemetry by removing obstacles to implementing Zero Trust principles.

In all cases, visibility remains paramount to effective detection and response. Security responders require telemetry visibility from multiple sources to be effective. Cisco address this through a tiered approach.

Cisco XDR provides an aggregation platform to correlate events, enrich events with threat intelligence, and provide SOAR capabilities to automate responses. This enables Tier 1 and 2 analysts to accelerate incident triage and management. These capabilities are then extended with Splunk Enterprise Security, which allows for complete custom detections to be written as well as threat hunting and advanced investigations to be conducted.

4.Vulnerability management programmes

Vulnerability disclosures are increasing and weaponisation is occurring faster than ever, as the latest results from NIST confirms.

Cisco recently announced Live Protect, an exciting innovation in network infrastructure that allows vulnerabilities to be mitigated at runtime. This means you can apply compensating protections against vulnerabilities in real-time, without downtime.

These ‘shields’ provide interim protection to the network infrastructure until the permanent security patch can be applied. So, the cycle of disruptive and costly emergency patching can be eliminated, without compromising protection.

Network-level protection remains imperative for endpoints. Next Generation Intrusion Prevention Systems, as well as malware detection and blocking, should be a key consideration, particularly for endpoints that can’t be protected with endpoint detection and response systems. This is where multi-layer segmentation really comes into its own, allowing security service insertion at critical junctures, while providing micro-segmentation for isolation within a secured enclave.

A big focus right now is moving security services as close the endpoint, application, workload, or data set as possible. Again, technologies such as Cisco Hybrid Mesh Firewall aid with this approach, as enforcement can be flexibly applied using appropriate components for each network region.

5. Defence automation

While I wanted to avoid talking about AI, in 2026 it’s largely inevitable! The reality is Agentic AI is the current hot trend within many IT sectors, and network security is no exception.

I’ll freely admit to being somewhat leery of vendors’ claims for AI efficacy (hallucinations, AI risks, cost and environmental impacts are all too real). But it’s impossible to not see the potential security benefits for intelligent workflows that never sleep, never tire, and execute at machine speed.

Organisations will have to adopt automation in network security operations to have any realistic chance of defending against attackers leveraging AI as force multipliers, in much the same way the Security Operations Center (SOC) has embraced automation for years.

How quickly and how fully you choose to adopt such practices is largely dependent on risk appetite within your organisation. But automating simple, time-consuming, and low risk tasks is an excellent starting point to gain confidence and real-world benefits.

A really simple example is leveraging threat intelligence integration to automatically update IOC blocks on network infrastructure from trusted intelligence providers. However, actions such as infrastructure patching and dynamic modification of network access permissions in response to changing security postures will need to move towards agentic models to reduce response time while managing the risk profile of the action itself.

Network architecture is key to your security

We all know there isn’t a single solution that’s going to solve the security challenges we’ve discussed here, and that’s unlikely to be the case any time soon. The pace of change is too fast, especially as attackers harness more automation and AI.

That means the focus of security strategy has to shift towards building secure foundations that can enforce policy consistently, provide full visibility, and adapt quickly as risks change.

Essentially, network architecture has become just as important as the security tools themselves and if you’re a network leader, it will no doubt remain at the top of your agenda for the foreseeable future.

Are you looking for extra defences for your network?
Let’s talk about your security.