- 35 unmanaged devices out of 47 at a customer site lacked endpoint agents, creating a security blindspot.
- 370,000 AI investigations completed across 5 million network anomalies in production environments.
- Gigabytes of video data exfiltrated monthly from compromised CCTV cameras undetected by conventional tools.
Experts would likely conclude that automated network investigation platforms like Illuminate IQ are becoming essential for MSPs to address the growing security risks posed by unmanaged IoT and OT devices, particularly in environments with limited human resources.
The Unagentable Blindspot: Why Automated Investigation is the New Frontline for MSPs
SYDNEY – September 30, 2026 – Walk into any modern enterprise environment, and you will find a network divided. On one side are the managed devices—laptops, servers, and workstations carefully monitored by endpoint detection agents. On the other side is a rapidly expanding shadow network of payment terminals, IP cameras, VoIP handsets, and smart printers. These unmanaged devices operate without traditional security software, creating a massive blindspot that cybercriminals are increasingly eager to exploit.
For Managed Service Providers (MSPs) tasked with securing these complex, fragmented environments, the sheer volume of unmonitored hardware presents an operational nightmare. The industry has long relied on deep packet inspection and network monitoring to keep an eye on this traffic. However, this approach has historically generated a relentless flood of alerts, pushing already stretched IT teams to the brink of alert fatigue.
Today, a subsidiary of Fusion Broadband known for its SD-WAN technology launched a potential remedy. Nepean Networks has introduced Illuminate IQ, a managed network intelligence platform specifically designed to investigate abnormal network behavior before handing a completed finding to an engineer. By focusing on the "unagentable" devices that traditional security cannot reach, the platform highlights a critical shift in cybersecurity strategy: moving from alert generation to automated, pre-investigated decision-making.
Securing What Endpoint Agents Cannot Touch
The fundamental flaw in modern endpoint security is that it requires an operating system capable of hosting a software agent. As operational technology (OT) and Internet of Things (IoT) devices proliferate, the percentage of network-connected hardware that can actually run an endpoint agent is shrinking.
Cybersecurity agencies globally have repeatedly issued advisories regarding firmware-level exploits and data exfiltration originating from embedded and IoT hardware. Because these devices often feature hardcoded credentials, outdated firmware, and proprietary protocols, they are prime targets for establishing persistent footholds within corporate networks.
The newly launched platform addresses this exact vulnerability. In one production use case highlighted by the developer, a fleet of CCTV cameras at a customer site was quietly uploading gigabytes of video every month to infrastructure in a high-risk country. The organization had no business relationship with the destination, but the traffic bypassed conventional inspection tools because it was fragmented across thousands of small flows and utilized an unrecognized proprietary protocol.
Rather than simply flagging an anomaly, Illuminate IQ compared the cameras' behavior against their own historical baselines and peer devices. It tested whether the destination was a legitimate manufacturer service, identified the cameras as the initiators of the transfer, and escalated the activity as suspected firmware-driven data exfiltration. The system provided the evidence required for immediate remediation, rather than leaving a human analyst to piece together the puzzle from raw logs.
The Alert Fatigue Crisis in Managed Services
The human impact of the cybersecurity skills shortage is felt most acutely within the MSP sector. These organizations manage diverse client environments, often without the luxury of dedicated, round-the-clock Security Operations Center (SOC) staffing. Traditional Security Information and Event Management (SIEM) tools and raw network telemetry often exacerbate this problem by burying technicians under an avalanche of false positives.
"Our technicians manage a number of customer environments, and it simply isn't practical to have a dedicated security analyst watching every network 24/7," said Andrew Cunningham of Data Central, an early adopter of the platform. "Illuminate IQ acts as the first line of investigation, surfacing the events that truly matter. It gives us visibility into cameras, printers, and other connected devices that were previously difficult to monitor, while our team remains in control of every response and decision."
At one specific 47-device customer site monitored by the platform, only 12 devices were capable of running endpoint agents. The remaining 35—which included payment terminals and embedded systems—produced no useful logs and ran no security software. Without automated network-level investigation, those 35 devices represented an open door to the broader network.
Automating the Investigation, Not the Decision
The artificial intelligence driving this new wave of network detection is fundamentally different from the automated remediation tools of the past. While some platforms attempt to automatically block traffic or isolate devices based on suspected threats, such aggressive automation can inadvertently disrupt critical business operations—like taking a hospital's VoIP system offline during a false positive.
Illuminate IQ is advisory by design. It automates the heavy lifting of the investigation—examining device history, destination context, live threat intelligence, and peer behavior across the fleet—but leaves the final decision to a human engineer.
"Seeing the traffic was the easy part," said Jason Maude, founder of Illuminate IQ at Nepean Networks. "The hard part is deciding whether something unusual actually matters. We built Illuminate IQ to do that investigative work first. The goal isn't more visibility. It's turning visibility into a decision."
A key differentiator in this investigative process is fleet comparison. A compromised device might look perfectly normal when compared against its own recent history, especially if the compromise occurred before the baseline was established. However, when compared against thousands of similar devices operating across independent networks globally, the anomaly becomes glaringly obvious. The platform separates what it definitively knows from what it suspects, returning a finding with concrete evidence and a recommended next action.
Benchmarking Against the NDR Landscape
The market for Network Detection and Response (NDR) is already crowded with heavyweights like Darktrace and Vectra AI, alongside endpoint-focused giants like Microsoft Defender. Darktrace, for instance, is renowned for its enterprise immune system approach, using unsupervised machine learning to detect subtle anomalies. Vectra AI excels in real-time threat prioritization across cloud and data center environments.
However, these enterprise-grade tools often require highly trained SOC analysts to interpret their sophisticated behavioral alerts. The Australian technology provider is carving out a specific niche by targeting the mid-market MSP sector, where the primary constraint is human capital. By delivering a pre-investigated finding rather than an alert that requires further hunting, the platform directly addresses the resource limitations of channel partners.
Furthermore, while Extended Detection and Response (XDR) solutions are gaining traction, they still rely heavily on data aggregated from endpoint agents. For the unagentable blindspot, network behavior remains the only reliable source of truth.
Integration and the Evolving Network Landscape
The deployment architecture of Illuminate IQ reflects a broader industry trend toward the convergence of networking and security. The platform is available immediately on existing SD-WAN nodes or as a standalone network sensor, entirely managed through the company's multi-tenant Antares portal. This allows MSPs to leverage their existing infrastructure investments without deploying complex new hardware stacks at every client site.
The system is designed to sit alongside existing firewalls, identity platforms, and SIEMs, feeding them high-fidelity, completed investigations rather than raw data. According to the company, the platform has already completed more than 370,000 AI investigations across 5 million network anomalies in production environments spanning Australia, South Africa, the United States, and Canada. Crucially, when the system determines an anomaly is benign, the finding explicitly explains why, building trust with the engineers relying on its intelligence.
As the perimeter of the modern enterprise continues to dissolve into a web of connected, unmanaged hardware, the old model of logging everything and hoping a human catches the anomaly is no longer viable. The intersection of artificial intelligence and network security is shifting from merely identifying that something has changed to understanding why it changed. By automating the investigative legwork and preserving human oversight for the final call, the industry is finally beginning to close the gap on the unagentable blindspot.
Topics & Related
Threat Landscape
📝 This article is still being updated
Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.
Contribute Your Expertise →