NetWitness and Lumifi Cyber have partnered to deliver managed detection and response across both IT and operational technology environments. The offer combines NetWitness’ analytics, telemetry, and investigation capabilities with Lumifi’s SOC operations and detection engineering. The focus is on organizations that already run security tools but lack the resources to operationalize them, especially as monitoring requirements expand beyond traditional IT into industrial and critical infrastructure systems.The service is built around continuous monitoring, threat hunting, and ongoing detection updates. Lumifi contributes a mature library of detections, correlations, and enrichment content designed to improve the effectiveness of existing NetWitness deployments. This approach is meant to shorten the gap between technology investment and measurable security outcomes by turning visibility into active detection and response. For customers facing persistent skills shortages, the model shifts day-to-day security operations to a practitioner-led service.The partnership also reflects the reality of converged environments where OT systems are increasingly tied to enterprise identity, cloud services, and segmented IT networks. That connectivity introduces new attack paths, but it also allows the same analytics and monitoring used on the IT side to extend into operational systems. Effective coverage in these environments depends on detections that are tuned to each organization’s processes, assets, and risk profile rather than relying on generic content.By combining a telemetry and analytics platform with a detection-focused MDR service, the joint solution is positioned as a way to operationalize security across hybrid and industrial environments without requiring customers to build their own 24/7 capability. As attacks continue to target operational systems, the model centers on making OT visibility part of routine security operations instead of treating it as a separate, specialized project.




