Is my corporate network compromised? 10 signs — and the invisible attacks
When something is off on the network, there are often visible signs — slow systems, unusual logins, odd messages. This article puts the most important ones in context and explains why the most dangerous attacks often show no signs at all — and what that means for the question of whether everything is really fine.
Published: June 5, 2026 · 8 min read · AEGYS DATALYTICS editorial
Would I even notice?
There are two ways this thought arises. Sometimes there is a concrete trigger: a system behaves oddly, a sign-in comes from a foreign country, a customer flags a strange email. Often it is simply a calm, reasonable question someone in charge asks themselves without anything happening: would I actually notice if something on our network were wrong?
Both paths lead to the same place. And both deserve an honest answer — no soothing platitude, but no alarm either. Because the most important property of a successful attack is not the damage it does, but how long it stays undetected.
This article shows two things: the typical visible signs by which a compromise can be recognised — and the case that shows no signs and is precisely for that reason the most dangerous.
Ten visible signs that a network might be compromised
None of these signs alone is proof. If several appear together, follow up.
- Unusual network activity — heavy traffic at night or outside business hours without an obvious reason.
- Sign-ins from unusual locations — access from countries where your company has no presence.
- Systems restart unexpectedly or become slow without a clear cause.
- Unknown programs or services — new applications, processes, or services that no one installed.
- Changed or encrypted files — content missing, renamed, or suddenly unreadable.
- Suspicious emails sent in your company's name — customers or partners report messages you did not send.
- Security software warnings that pile up or appear suddenly.
- Disabled protections — antivirus or logging won't start, or has been switched off.
- New or altered user accounts — accounts no one created, or changed permissions.
- Outside reports — customers, partners, or authorities point out something you did not notice yourself.
Important: This list describes the visible case. It is helpful — but it is not complete. The most dangerous attack is not on this list, because it relies on producing none of these signs.
The attack that shows no signs
The signs above share one thing in common: they appear when an attack disrupts — when something crashes, gets encrypted, or stands out. Ransomware, for example, wants to be seen, because it extorts.
The more dangerous case is the quiet one. An attacker who has made it into a network and has no interest in being noticed behaves as inconspicuously as possible. They move carefully between systems ( lateral movement), observe, harvest credentials, exfiltrate data bit by bit — and avoid anything that would generate a visible symptom. No crash, no encryption, no alert. On the surface, everything keeps running normally.
How real this is, is shown by a number from the largest independent incident analyses in the industry: according to the IBM Cost of a Data Breach Report and Mandiant M-Trends, the average time before an attacker on the network is detected at all is measured in weeks to months. That long, activity runs — without anyone noticing, because none of the familiar signs appear.
That is exactly the difficulty: anyone waiting for visible symptoms only catches the loud attacks. The quiet ones stay — by definition — invisible as long as no one actively looks.
Two kinds of attacks
Visible symptoms only capture one half.
The loud attack
e.g. ransomware — wants to be seen
- • Systems crash
- • Files get encrypted
- • Security alerts pile up
- • Ransom note appears
The quiet attack
wants to stay undetected
- • observes silently
- • harvests credentials
- • exfiltrates slowly
- • avoids every symptom
From a feeling to a defensible answer
When visible signs alone are not enough, there is only one way to cleanly answer the question "is anything running here that shouldn't be?": look at what is actually being communicated on the network.
That is something different from a virus scan on individual machines or a glance at existing logs. A single machine only shows what is happening on itself. Logs only show what connected systems reported. The communication on the network, by contrast, shows the actual behaviour: which systems talk to which destinations? Is anything leaving that can't be explained? Is something moving laterally between internal systems?
This view does not come from a gut feeling, but from a structured analysis of real network activity — independent of whether any single system shows a symptom or not.
Put briefly: Visible signs are a reason to look more closely — but their absence is not proof that everything is fine. Security comes not from waiting for symptoms, but from actively inspecting real network activity.
An independent view of what is actually happening
AEGYS DATALYTICS answers exactly this question. A compact appliance — AEGYS Pulse — is connected passively to the network and reads along with what is actually being communicated. From that, a structured analysis emerges: which systems talk to which external destinations, are there unusual lateral movements, is data leaving that doesn't match the normal operating picture.
The result is not a pile of data, but a clear assessment — as a basis for a decision. On request as a point-in-time reality check, for example after a suspicion or as a precaution, or ongoing as continuous visibility.
Unsure whether everything on your network is fine?
In 15 minutes, you'll know whether a closer look makes sense for your situation — and what it would cost.
15 minutes to get oriented. If it's not a fit, we'll say so.
Frequently asked questions about signs of compromise
Sources
- IBM Cost of a Data Breach Report — ibm.com/reports/data-breach
- Mandiant M-Trends Report — cloud.google.com
