RackTop Systems
RackTop Perspective

Your security stack watches everything except the data

Endpoints, networks, identities, email, cloud posture: modern security programs instrument all of it. The one thing almost nobody instruments is the file data attackers are actually after.

RackTop SystemsJuly 12, 20265 min read

Key takeaways

  • Security budgets cluster around perimeter, endpoint, and identity, all of it upstream of the data.
  • Walk the stack during a credentialed theft and every tool answers correctly within its domain while the data walks out the door.
  • The moment of harm is always a sequence of file operations, and file operations are exactly what the stack does not model.
  • Shipping NAS logs to the SIEM disappoints: partial, delayed, and without per-identity baselines to score them.
  • Instrumenting the data layer closes the gap, and hands the SOC pre-correlated telemetry instead of another raw feed.

Walk through a typical enterprise security stack and count the layers: EDR on the endpoints, detection on the network, MFA and conditional access on identities, filtering on email, posture management on cloud. Now ask what watches the file shares, the place where the intellectual property, patient records, contracts, and designs actually live. In most environments, the answer is a set of NTFS permissions written years ago and a partial audit log nobody reads.

This is an odd place to have a blind spot, because data is the one asset every serious attack has in common. Ransomware encrypts it. Extortion crews steal it. Insiders walk out with it. The tools upstream see fragments of the approach (a process here, a login there), but the moment of harm is a sequence of file operations, and file operations are exactly what the stack does not model.

Why the gap persists

Partly it is organizational: storage belongs to infrastructure, security tooling belongs to the SOC, and neither owns the seam. Partly it is historical: NAS vendors competed on speed and capacity for thirty years, and telemetry rich enough for behavioral detection never made the roadmap. So security teams work with what they can get: logs shipped from a platform that was never designed to explain what its users are doing.

We started RackTop on the conviction that this is backwards. The storage system is the only component that sees every read, write, and delete along with the user, host, path, rate, and history behind it. It is the natural enforcement point, the way the identity provider is the natural place to enforce authentication. Treating it as a passive bystander wastes the best vantage point in the environment.

Walk the stack and ask one question

Take each layer in turn and ask what it sees when a valid account starts stealing files. Email security saw a message six weeks ago and passed it; its job ended at delivery. EDR sees a signed process making network calls, which is what every process does; there is no agent on the NAS serving the files anyway. The identity provider saw a successful MFA login this morning and granted a session; it does not see what the session does next. Network detection sees SMB traffic to a share the account is permitted to reach, which is indistinguishable from Tuesday. The SIEM sees whatever these tools forwarded, which is to say: nothing abnormal.

Every layer answered correctly within its domain, and the organization is still losing terabytes. That is not a tooling failure; it is a coverage failure. The behavior that defines the attack, file operations wildly outside that identity’s norm, occurs in a domain none of the deployed tools model.

The moment of harm is a sequence of file operations

Reduce any data attack to its final act and it looks the same. Ransomware is a burst of reads followed by high-entropy writes and renames, thousands per minute. Exfiltration is a long series of reads at machine speed, often at night, often walking directories the account has never entered. Insider theft is the same reads at human speed, spread across weeks. These sequences are unambiguous when observed at the storage layer with identity context, and completely invisible one layer up, where they dissolve into permitted traffic.

This is also why shipping NAS audit logs to the SIEM, the standard compensating control, disappoints in practice. Native logs are partial, expensive to collect at file-operation volume, and delayed; and the SIEM lacks the per-identity behavioral baselines to score them. A raw event stream without a model is storage for alerts nobody wrote.

What changes when the data layer can see

With behavioral detection at the storage layer, the attacks that slip between upstream tools become visible: the credentialed account reading at machine speed, the service account touching directories it has never touched, the encryption run in its first seconds. Every operation is scored against that identity’s own baseline, on the controller, and the response is inline: the offending session is terminated in under a second, before the sequence completes. The stack stops ending one layer short of the thing it exists to protect.

The SOC gains rather than loses. Instead of a raw log feed, the data layer streams high-fidelity, pre-correlated telemetry: who, from where, which files, at what rate, and what the platform already did about it. Alerts arrive with the evidence attached, and the forensic record answers the scoping questions, what was read, exactly, that determine disclosure. Closing the blind spot does not add another console to babysit; it removes the guesswork from the ones already open.

Closing the seam without another silo

The organizational gap deserves as much attention as the technical one. Storage teams own uptime; security teams own detection; the file share sits in the seam. The practical fix is not a new committee but a platform that serves both owners at once: infrastructure gets enterprise NAS with the performance and protocols it already needs, and security gets detection, response, and audit on the same system, with no agents to deploy and no new pipeline to build. When the storage is the sensor and the enforcement point, the seam closes by architecture instead of by meeting.

See data-layer defense in action

A 30-minute demo shows Active Defense stopping an attack inline, immutable recovery, and surgical rollback — mapped to your environment.

The Data Security Blind Spot in Enterprise Storage | RackTop Systems