Exeon NDR Managed: network visibility without sensor sprawl
ANOMAL runs Exeon NDR as a managed service for Swiss environments. It centrally analyses network metadata from existing sources (firewalls, switch flows, proxies) without additional inline sensors. The service focuses on threats invisible to endpoints, particularly in OT, IoT and BYOD zones. The ANOMAL SOC handles detections 24/7 with clear response playbooks and Swiss data sovereignty.
Why NDR alongside EDR and cloud logs
EDR sees what happens on managed endpoints. Cloud and identity logs cover SaaS and accounts. Between these layers sits a blind spot: agentless devices (OT, IoT, printers, medical equipment, guest devices) and lateral movement between zones. That is where NDR comes in. The glossary entry NDR (Network Detection and Response) explains the definition and how it works. See EDR vs MDR for the distinctions between NDR, EDR and MDR.
How this compares to neighbouring topics
| Model | What it sees | Where it stops |
|---|---|---|
| EDR | Processes, files, memory and registry on managed endpoints. | Not on OT, IoT or guest devices; no east-west view across the network. |
| Exeon NDR (managed) | Network metadata from firewalls, switch flows, DNS and proxies across all zones. | No endpoint response such as process kill or isolation; that is EDR's job inside the SOC playbook. |
| SIEM | Log correlation across many sources, often with long retention. | Without NDR metadata, the network-behaviour perspective is missing. |
| Inline IDS/IPS | Packet inspection at a single break point in the network. | Scales poorly across zones; encrypted traffic limits signature approaches. |
How Exeon NDR works
- Exeon collects metadata from existing network sources (firewalls, switches, DNS, proxies, VPN concentrators). It requires no additional inline sensors or packet capture.
- Exeon analyses behaviour over time and relationships between assets. Encrypted traffic remains readable at the metadata layer.
- Exeon establishes a baseline for each environment and zone. It prioritises deviations based on movement towards crown jewels and OT boundaries.
- Exeon processes data in Switzerland in compliance with revFADP (revised Federal Act on Data Protection) and ISG. It does not transfer payload data outside the environment.
Exeon is a Swiss vendor (ETH Zurich spin-off). ANOMAL operates the platform as a managed service in Switzerland. Data sovereignty and regulatory attribution remain unambiguous.
Typical use cases
- Manufacturing and OT: visibility between IT and OT zones, detection of lateral movement without an agent on PLCs and HMIs. See SOC for manufacturing.
- Healthcare and laboratories: unmanaged medical devices and research systems in segregated segments.
- BYOD and guest networks: anomalies from devices that will never receive an EDR agent.
- Regulated institutes: additional evidence layer for FINMA and ISG questions. See FINMA requirements and ISG reporting duty.
Operating model by ANOMAL
- 24/7 triage and investigation inside the ANOMAL SOC, correlated with EDR and cloud signals.
- Response playbooks per alert type; the actual action (isolation, block, rule change) runs through the responsible systems.
- Monthly reporting with top findings, baseline drift and evidence for brokers and regulators.
- Quarterly governance with rule updates and zone review.
See MTTD and MTTR for detection and response speeds across the SOC. SOC as a Service Switzerland provides the full operating definition.
Placement in SOC operations
Exeon NDR completes network visibility in a modern SOC. Together with EDR and identity logs, it forms the visibility base for 24/7 detection. SOC as a Service Switzerland describes the full operating model, including roles, playbooks and governance.
Frequently asked questions
Does Exeon NDR replace our EDR?
NDR and EDR complement each other. EDR sees processes on managed endpoints, while NDR sees behaviour on the network, including agentless devices. Together they form the basis for reliable detection. See [EDR vs MDR](/en/soc/soc-siem-edr-xdr-mdr-terms).
Do we need additional sensors in the network?
You generally do not need additional sensors. Exeon draws metadata from existing firewalls, switches, DNS and proxies. In OT-adjacent zones, we check during scoping whether we need to extend log ingestion. Inline boxes with packet capture are not part of the operating model.
Where is the data processed?
Exeon processes data in Switzerland. It processes only network metadata and excludes payload data. This maintains a consistent basis for mapping revFADP (revised Federal Act on Data Protection), ISG and FINMA requirements.
Does Exeon NDR also fit small environments?
For very small environments without segmentation the value is limited. NDR becomes valuable with multiple zones, an OT or IoT footprint or regulatory evidence needs. For SME size classes see [SOC for SMEs](/en/soc/soc-for-sme).
How quickly can Exeon NDR become operational?
Connection and baseline typically take a few weeks as part of the [SOC onboarding](/en/soc/soc-onboarding-switzerland). Afterwards detection runs 24/7 through the ANOMAL SOC; rule fine-tuning happens in the quarterly reviews.
Related terms
- NDR Network Detection and Response (NDR) analyses network traffic to detect attacks, without needing an agent on the systems.
- Anomaly Detection Anomaly detection identifies deviations from the usual behaviour of accounts, devices, or network traffic and reports them for review.
- Lateral Movement Lateral Movement describes how attackers move from system to system and escalate privileges after initial access.
- Command and Control (C2) Command and Control (C2) is the channel attackers use to remotely control compromised systems and exfiltrate data.
- SIEM A Security Information and Event Management (SIEM) system collects logs from many sources, makes them searchable and analyses them with detection rules.