Skip To Content
To Mitigate Cyberattack Damage, Start with the Network

To Mitigate Cyberattack Damage, Start with the Network

A cyberattack often begins with a single hijacked account or application. Yet in today’s AI-driven environment, attacks can unfold faster than ever before, increasing the speed at which organizations must respond to contain them effectively.

In the hands of bad actors, advanced AI models can identify and exploit vulnerabilities in hours, rather than the days or even weeks that a skilled human hacker might require. Hybrid work and the proliferation of connected devices have also multiplied the points where an intrusion can begin, expanding the attack surface and making breaches more difficult to avoid. 

Jon Green, CTO, Networking, at HPE is a longtime cybersecurity leader at the intersection of network security solutions, threat intelligence and enterprise defense. He points out that as attacks move more quickly, enterprises need a new approach to cybersecurity.

“Organizations are struggling to keep up, so the reality now is that there’s going to be some amount of compromise at some point,” says Green. “You have to limit the impact and keep operations going.”

Today, the degree of disruption depends less on stopping an attacker outright than on how quickly defenses respond to contain the threat. Green says that responding effectively starts with the traffic crossing the network. Exchanges between devices and software applications leave traces that allow departures from normal patterns to expose unusual activity, which conventional security solutions may miss. 

Green’s team at HPE has developed and is continuously evolving what the company calls its self-driving network technology. It uses AI and automation to help configure and optimize networks, gather evidence, diagnose problems and recommend or carry out a response. The result is a network that can increasingly monitor itself, while keeping potentially disruptive decisions in human hands.

Why cyberattacks are becoming faster and more sophisticated 

HPE Threat Labs, HPE’s company’s cyber research unit, tracked 1,186 active threat campaigns globally in 2025, spanning many major industries. Its deception network, which uses fake IT assets to mislead and detect attackers, also recorded 44.5 million connection attempts from 372,800 source IP addresses — an indication of how relentlessly attackers scour the internet for openings.

Operating as organized enterprises, the groups responsible for these attacks cleverly automate processes and research the weaknesses of prospective targets. They also take advantage of AI’s generative capabilities to conduct phishing and executive-impersonation fraud en masse, though many break-ins still rely on basic failings, such as weak credentials.

David Hughes, Senior Vice President of SASE and Security, Networking at HPE, spoke in early June at Bloomberg Tech 2026 about how the threat environment has changed.

“In the past, a lot of these attacks required specialized human involvement, so the breadth and speed with which adversaries could move was limited,” said Hughes. “With AI, they can go faster and broader by running more agents in parallel, around the clock.”

The consequences of a breach can escalate quickly, disrupting operations, compromising sensitive data, eroding trust and damaging organizations’ reputations. That’s on top of imposing enormous costs on businesses and government agencies.

“What we do is build more intelligence into the network itself, so companies can react faster, with the goal of curbing damage and reducing costly downtime,” says Green. 

How self-driving networks expose threats

To keep pace, businesses and governments are investing heavily in their digital defenses. Bloomberg Intelligence expects the combined cybersecurity and observability market to reach $338 billion globally by 2033, with annual recurring revenue rising to $233 billion.

Yet larger budgets mean little if enterprises can’t detect the subtle changes that reveal an incursion is underway — including activity on equipment that conventional security features do not monitor. This is where the self-driving approach earns its name.

Rather than waiting for a familiar attack signature, the network can learn how a device normally behaves and raise an alert when it detects a significant anomaly.

Green points to one case in which criminals compromised firmware provided by a security solutions camera manufacturer. The cameras downloaded an update through the normal process, so there were no obvious signs of a problem. But then they began communicating with different parts of the network and contacting external destinations. 

The network could not read the encrypted exchanges, but it could recognize that the cameras’ behavior had changed, which gave the team a reason to investigate.

“Three years ago, we didn’t have this level of correlation,” says Green. “That’s a place where AI can actually pull a lot of small signals together and come to conclusions.”

How smarter networks isolate threats without disruption

Containing a cyberattack begins with detection. Once the source of a threat has been identified, HPE’s solution can then help isolate it, which may reduce the need to cut off a larger section of the network. The affected user or device can remain accessible to IT staff for inspection, while access to other systems may be restricted, reducing the need for a broader shutdown.

That intervention should happen as close to the source as possible; a firewall further upstream may stop traffic from leaving the organization but still fail to prevent infected devices from communicating with others nearby.

To help determine when and where containment is needed, HPE enables IT teams to draw on a continually updated picture of known threats and normal network behavior.

HPE Threat Labs feeds newly identified malicious files, websites and command-and-control addresses into the company’s security solutions software. At the same time, HPE’s rich networking heritage contributes more than two decades of operational data from the cloud-managed networks it oversees.

That information comes together through HPE Marvis, the AI engine at the center of HPE’s Mist, the company’s AIOps platform, which can analyze activity across HPE self-driving networks to help identify threats and likely causes and recommend corrective action.

HPE has spent more than two decades gathering, analyzing and learning from operational network data, turning that experience into a growing body of insights about how networks behave. This foundation of real-world intelligence helps HPE’s AI identify patterns, diagnose problems and determine how networks can be optimized more effectively — and HPE Marvis recognizes when a seemingly ordinary network change may signal a genuine fault or emerging threat.

This foundation of real-world intelligence can help Marvis recognize when a seemingly ordinary network change may signal a genuine fault or emerging threat.

Making the network the core of a cyber resilience strategy

AI does not replace the basic principles of cyber defense. 

Multifactor authentication and company-managed devices make stolen credentials harder to use, while zero-trust policies restrict where each user or machine can go. Segmentation then limits the ground that an intruder can cover when a breach is made.

What has now changed, says Green, is that those safeguards are being built into self-driving systems, placing them within a wider resilience strategy focused on identifying unusual activity and containing it quickly. 

“Something will likely go wrong,” says Green. “When it does, you just want to limit the blast radius.” 

Frequently Asked Questions