Traditionally, NetOps and SecOps teams have worked independently. The network team is responsible for keeping the network up and running, which requires deep knowledge of devices on the network and maintaining availability. The security team is responsible for detecting and preventing breaches, including ensuring those devices are hardened and reporting to compliance. Both teams have a vested interest in building network cybersecurity resilience and play complementary roles toward that end. However, differing mandates and the core concept of separation of duties for security and control have kept teams isolated and limited their understanding of their shared goals. Now’s the time for this to change.
In the annual Gartner survey of CISO priorities, cybersecurity resilience topped the list in 2025. So, teams need to find ways to collaborate to answer the call. Fortunately, enterprises are making progress and using network automation to do so.
How to field a team
According to Gartner, 30% of enterprises by 2026 will automate more than half of their network activities, up from under 10% in mid-2023. That’s a notable shift. Even more notable is how enterprises are accomplishing this. Instead of “going it alone,” they recognize that network automation is a team sport.
Here’s what that looks like:
Shared visibility. As a foundation, both teams need to understand who has access to what and what they are doing so they can progress and do their jobs in a more coordinated and efficient way. Modern automation platforms provide the ability to set permissions for consistent access management. When a user performs an activity, it is logged and an audit trail can be generated. Every action can have a notification attached to it, so that anytime an automation runs, the appropriate stakeholders are informed in real time.
Guardrails – not gates. Understanding how things are done is also important. It’s about setting boundaries without blocking progress. Providing the necessary checks and balances to support automation efforts ensures everyone has access to the right resources to do their specific jobs. This includes access to a current, detailed device inventory, and documentation of processes, compliance requirements, and internal policies. A single source of truth also helps bring new users up to speed faster. Additional guardrails include regular permission checks and audits to validate users and outcomes, ensuring best practices and policies are enforced, and anomalies are quickly surfaced for investigation.
Knowing when and where to apply automation. You aren’t going to automate everything – so how do you start? The strategic goal of automation is to ensure success through greater reliability, efficiency, and security. Areas to automate where you’ll get a lot of mileage include:
- Frequent, time-consuming activities. Tasks like backup and device provisioning are very error- prone because they are repetitive. Automation reduces the likelihood of human error because it never “fat-fingers” or tires.
- Essential building blocks. Every device starts from a steady state – a golden image that serves as “home base.” Configuring, deploying across devices, and maintaining that steady state is critical. When configuration drift, a problematic update, or a service disruption happens, you can restore with a single click to recover quickly.
- Compound changes. Updating hundreds or thousands of devices, particularly in multisite or multitenant environments, is complex. Automation makes the job trivial; test on one device, expand to a group of devices, and then deploy at scale.
Reusable assets. Another reason to use automation is to create reusable assets that simplify standard processes fundamental to cybersecurity resilience. For example, configuration checks against internal policies or external standards like Center for Internet Security (CIS) benchmarks can be set to run after every device change as a security best practice. Devices can be automatically groomed back into compliance based on configuration elements administrators have approved and set. The same asset also saves teams time responding to audit requests from compliance.
Best-practice example. Automation helps NetOps and SecOps teams collaborate to prevent, withstand, and recover from disruptions. But what happens when a backup, a configuration change, or a compliance check fails? Anything you can do to reduce errors, accelerate response, and improve security is critical to building resilience.
Ticket creation is a best-practice example and underscores how automation is a team sport. Extending your automations to include a reusable asset that creates a ticket in your IT service management (ITSM) system when an error occurs will speed time to recovery and prevent future errors. IT becomes part of the team, receiving the ticket via instant notifications.
In for the Win
With cybersecurity resilience a top priority, the more team members you can pull in for cross-collaboration, the better your chance for success. Network automation continues to advance, helping teams collaborate and improve reliability, efficiency, and security. If you’re not already shifting to network automation to bridge the NetOps-SecOps gap and strengthen network cybersecurity resilience, it’s time to start.
Comments