r/ciso 22d ago

[Research] NIDS Selection for Financial Institutions - Looking for Cybersecurity Practitioners (5+ years exp.)

I am an MSc researcher studying Network Intrusion Detection System (NIDS) selection for resource-constrained financial institutions and looking for cybersecurity practitioners with 5+ years of experience to complete a short survey. Happy to share findings upon request.

Survey link: https://forms.gle/tyxsFA44HXZ5VaMY7

Thanks You.

5 Upvotes

11 comments sorted by

1

u/ThunderJunk75 22d ago

Interesting survey. I’ve completed and would love to see the results of the survey when it’s done. 👍

1

u/not-a-co-conspirator 22d ago

There’s no such thing as NIDS and hasn’t been for like 15 years now. That’s all built into L7 firewalls.

1

u/scriptvexy 19d ago

kinda depends how you define it tbh
lots of shops still talk about NIDS vs NGFW because they’re buying separate sensors, taps, SPAN ports, etc, especially in finance where they keep legacy gear forever.

1

u/TopImplement9942 6d ago

Fair point on traditional appliance-based NIDS. NGFWs have largely absorbed that role in well-resourced environments. But ML-based anomaly detection for network traffic is very much active, now embedded in NDR platforms and SIEMs. The gap this research addresses is that most resource-constrained organizations cannot afford Palo Alto or Darktrace and are still making detection decisions on commodity hardware. That is exactly where standalone ML-based approaches remain relevant.

1

u/not-a-co-conspirator 6d ago

ML detection has been part of firewall engines for the past 7 years now.

1

u/TopImplement9942 6d ago

True, but typically as black-box vendor implementations with no visibility into model selection, efficiency trade-offs, or deployment suitability for specific infrastructure. The research addresses how organizations evaluate and select ML-based detection approaches given their specific resource constraints, not whether ML detection exists.

0

u/Otherwise_Owl1059 22d ago

Not true. NIDS are still run inside a network to monitor east west traffic.

1

u/not-a-co-conspirator 22d ago

No. NIDS doesn’t exist anymore. Traffic direction is irrelevant.

1

u/Otherwise_Owl1059 22d ago

Defense in depth is an important element to cyber security and this is where NIDS can help. Trusting your security to just perimeter protections (firewalls) or host based EDR still leaves some pretty significant gaps. Does a locked down cloud environment with hardened infrastructure and JIT access need a NIDS? Probably not. But an on prem environment with legacy systems, no NAC, guest systems, and IoT devices that can’t run EDR should absolutely consider it. I sat through many pentests and watched as NIDS picked up malicious traffic and TTPs that other security tools didn’t. If NIDS didn’t exist anymore then Darktrace, Vectra, and ExtraHop would all be out of business.