New Lumu Defender Capabilities Provide Visibility Beyond the Network
Cyber Security / Threat Intelligence & Incident Response | 4 min read
Lumu, the creators of the Continuous Compromise Assessment® security model, has announced significant new upgrades to Lumu Defender — its flagship Network Detection and Response (NDR) solution — at the RSA Conference. The enhanced platform now extends Continuous Compromise Assessment beyond the network to include endpoints, cloud environments, and user identity behaviours, giving security teams unified visibility across their entire digital ecosystem in a single, real-time solution.
Why the Threat Landscape Demands Broader Visibility
The past year has marked a strategic shift in attack methods, with threat actors pivoting away from high-profile malware toward increasingly sophisticated, stealth-based tactics. The rise of AI-driven attacks, the growing use of legitimate tools instead of malware (Living-off-the-Land techniques), and attackers quietly leveraging cloud applications for data exfiltration are creating more opportunities for criminals to exploit security blind spots and bypass existing point solutions. Fragmented defences lead to fragmented visibility — and today's attackers are deliberately engineered to exploit those gaps.
"To successfully navigate today's dynamic compromise landscape, security teams must increase their attack visibility and correlation across networks, endpoints, identities, and email — covering on-premises environments, public and private cloud environments, and roaming devices. Fragmented security defences lead to fragmented visibility, and today's attackers leverage these blind spots to bypass existing security solutions. Attacks have evolved, so visibility and response must too. With the expanded capabilities in Lumu Defender, we're redefining Continuous Compromise Assessment by not only detecting threats in real time across networks, identities, endpoints, and cloud, but also integrating with other elements in the stack to automate responses."
— Ricardo Villadiego, CEO, Lumu
Three New Visibility Pillars: Endpoint, Identity, and Cloud
Endpoint Attack Visibility
Lumu Defender continuously observes endpoint behaviours for suspicious or out-of-the-norm activity, identifying compromise at the device level. The enhanced Lumu Endpoint Agent can now perform host isolation — automatically blocking confirmed malicious activity in compromised devices and eliminating the need for manual intervention on legacy antivirus or EDR tools. This automated response capability turns the agent from a passive data collector into an active defender.
Identity Visibility
The platform now profiles normal login patterns for admin accounts and highlights anomalies such as unexpected login times or frequencies, as well as brute force attempts — surfacing abnormal login failures and probing activity. Lumu Defender provides security teams with early visibility into compromised accounts before privilege escalation or lateral movement occurs, empowering teams to stop intrusions before broader access is achieved.
Cloud Visibility
With attackers increasingly using legitimate cloud storage providers to exfiltrate data under the cover of normal SaaS traffic, Lumu Defender now monitors for suspicious transfers, destinations, volumes, timing, and accounts in cloud environments. Security teams gain early, actionable visibility to stop data theft and investigate insider risk or compromised identities before damage escalates.
Industry Validation: The Case for Unified NDR
"In an era where attackers trade brute force for behavioural evasion, network threat visibility has become the anchor of modern security operations. NDR is especially powerful when combined with other control points such as endpoint, data, identity, and applications. This unified context is what allows security teams to move past the noise and uncover a single source of truth regarding a potential compromise."
— Chris Kissel, Research Vice President, Security & Trust, IDC
Lumu Defender's expanded capabilities are available now. Organisations can learn more or meet the Lumu team at RSAC booth North 4400, or visit lumu.io for more information.
Key Takeaways
- • Lumu Defender now extends Continuous Compromise Assessment beyond the network to cover endpoints, cloud environments, and user identity behaviours — delivering unified visibility across the entire digital ecosystem.
- • The enhanced Lumu Endpoint Agent performs automatic host isolation — blocking confirmed malicious activity without requiring manual intervention on legacy antivirus or EDR tools.
- • Identity visibility surfaces anomalous login behaviour and brute force attempts before privilege escalation or lateral movement can occur — stopping intrusions at the earliest stage.
- • Cloud visibility monitors SaaS traffic for suspicious transfers, destinations, and volumes — closing the exfiltration blind spot attackers are increasingly exploiting through legitimate cloud applications.
- • All expanded capabilities are available now — unveiled at RSA Conference 2026 and validated by IDC as a critical evolution of NDR in the age of behavioural evasion and AI-driven attacks.
