RackTop Systems
RackTop Perspective

Your security stack watches everything except the data

Endpoints, networks, identities, email, cloud posture: modern security programs instrument all of it. The one thing almost nobody instruments is the file data attackers are actually after.

RackTop Systems•July 12, 2026•5 min read

Key takeaways

  • Security budgets cluster around perimeter, endpoint, and identity, all of it upstream of the data.
  • Walk the stack during a credentialed theft and every tool answers correctly within its domain while the data walks out the door.
  • The moment of harm is always a sequence of file operations, and file operations are exactly what the stack does not model.
  • Shipping NAS logs to the SIEM disappoints: partial, delayed, and without per-identity baselines to score them.
  • Instrumenting the data layer closes the gap, and hands the SOC pre-correlated telemetry instead of another raw feed.

Walk through a typical enterprise security stack and count the layers: EDR on the endpoints, detection on the network, MFA and conditional access on identities, filtering on email, posture management on cloud. Now ask what watches the file shares, the place where the intellectual property, patient records, contracts, and designs actually live. In most environments, the answer is a set of NTFS permissions written years ago and a partial audit log nobody reads.

This is an odd place to have a blind spot, because data is the one asset every serious attack has in common. Ransomware encrypts it. Extortion crews steal it. Insiders walk out with it. The tools upstream see fragments of the approach (a process here, a login there), but the moment of harm is a sequence of file operations, and file operations are exactly what the stack does not model.

Why the gap persists

Partly it is organizational: storage belongs to infrastructure, security tooling belongs to the SOC, and neither owns the seam. Partly it is historical: NAS vendors competed on speed and capacity for thirty years, and telemetry rich enough for behavioral detection never made the roadmap. So security teams work with what they can get: logs shipped from a platform that was never designed to explain what its users are doing.

We started RackTop on the conviction that this is backwards. The storage system is the only component that sees every read, write, and delete along with the user, host, path, rate, and history behind it. It is the natural enforcement point, the way the identity provider is the natural place to enforce authentication. Treating it as a passive bystander wastes the best vantage point in the environment.

Walk the stack and ask one question

Take each layer in turn and ask what it sees when a valid account starts stealing files. Email security saw a message six weeks ago and passed it; its job ended at delivery. EDR sees a signed process making network calls, which is what every process does; there is no agent on the NAS serving the files anyway. The identity provider saw a successful MFA login this morning and granted a session; it does not see what the session does next. Network detection sees SMB traffic to a share the account is permitted to reach, which is indistinguishable from Tuesday. The SIEM sees whatever these tools forwarded, which is to say: nothing abnormal.

Every layer answered correctly within its domain, and the organization is still losing terabytes. That is not a tooling failure; it is a coverage failure. The behavior that defines the attack, file operations wildly outside that identity’s norm, occurs in a domain none of the deployed tools model.

The moment of harm is a sequence of file operations

Reduce any data attack to its final act and it looks the same. Ransomware is a burst of reads followed by high-entropy writes and renames, thousands per minute. Exfiltration is a long series of reads at machine speed, often at night, often walking directories the account has never entered. Insider theft is the same reads at human speed, spread across weeks. These sequences are unambiguous when observed at the storage layer with identity context, and completely invisible one layer up, where they dissolve into permitted traffic.

This is also why shipping NAS audit logs to the SIEM, the standard compensating control, disappoints in practice. Native logs are partial, expensive to collect at file-operation volume, and delayed; and the SIEM lacks the per-identity behavioral baselines to score them. A raw event stream without a model is storage for alerts nobody wrote.

What changes when the data layer can see

With behavioral detection at the storage layer, the attacks that slip between upstream tools become visible: the credentialed account reading at machine speed, the service account touching directories it has never touched, the encryption run in its first seconds. Every operation is scored against that identity’s own baseline, on the controller, and the response is inline: the offending session is terminated in under a second, before the sequence completes. The stack stops ending one layer short of the thing it exists to protect.

The SOC gains rather than loses. Instead of a raw log feed, the data layer streams high-fidelity, pre-correlated telemetry: who, from where, which files, at what rate, and what the platform already did about it. Alerts arrive with the evidence attached, and the forensic record answers the scoping questions, what was read, exactly, that determine disclosure. Closing the blind spot does not add another console to babysit; it removes the guesswork from the ones already open.

Closing the seam without another silo

The organizational gap deserves as much attention as the technical one. Storage teams own uptime; security teams own detection; the file share sits in the seam. The practical fix is not a new committee but a platform that serves both owners at once: infrastructure gets enterprise NAS with the performance and protocols it already needs, and security gets detection, response, and audit on the same system, with no agents to deploy and no new pipeline to build. When the storage is the sensor and the enforcement point, the seam closes by architecture instead of by meeting.

Frequently asked questions

The blind spot is the file data itself. Most security programs instrument endpoints, networks, identities, email, and cloud posture, all of which sit upstream of the data, and then leave the file shares to a set of NTFS permissions written years ago and a partial audit log nobody reads. Ransomware, extortion, and insider theft all converge on that same layer, so the stack ends one step short of the asset it exists to protect.
EDR is an endpoint control, and the NAS serving the file shares typically cannot run an agent, so the reads and writes that make up the theft never pass through anything EDR can see. On the machines it does cover, a signed process opening files the account is permitted to open is what every process does. What separates theft from work is the shape of the file activity measured against that identity’s own history, and that shape is only legible on the controller handling the operations.
Forwarding NAS audit logs to a SIEM rarely works as a detection control. Native storage logs are partial and delayed, file-operation volume makes them costly to collect, and the SIEM carries no model of what normal looks like for each identity, so the events land as a raw stream nobody has written rules against. BrickStor SP scores every operation inline on the controller instead, then forwards pre-correlated telemetry: user, host, files, rate, and the action already taken.Active Defense
Security for the file shares usually belongs to neither team, and that unowned seam is why the gap persists. Storage sits with infrastructure, which answers for uptime, capacity, and performance; detection sits with the SOC, which answers for alerts it can act on. Neither side is funded to instrument the file share itself. The fix is not a new committee but a platform that serves both owners at once, so infrastructure gets the enterprise NAS it already needs and security gets detection, response, and audit on the same system.BrickStor SP

What Cyberstorage actually means

RackTop shipped inline storage-layer defense in October 2020, nine months before the category had a name. Here is what the architecture does.

The Data Security Blind Spot in Enterprise Storage | RackTop