A Representative Vendor in Gartner Market Guide for NDR Again

We’re excited to share that Sangfor Technologies (Sangfor) has been recognized once again as a Representative Vendor in the Gartner Market Guide for Network Detection and Response¹ (NDR) with its product, Sangfor Cyber Command. This marks the second time in a row that Sangfor has received this recognition since the Market Guide’s first publication in 2020. It follows Sangfor’s recent inclusion as a Key Player in the Gartner Competitive Landscape: Network Detection and Response². We view these recognitions as testaments to Sangfor’s continuous commitment to innovation in NDR and meeting organizations’ evolving security needs.

A Closer Look at NDR

NDR stands at the forefront of cybersecurity technology, offering a robust solution for detecting and responding to advanced threats. According to Gartner, “Network detection and response (NDR) products detect abnormal system behaviors by applying behavioral analytics to network traffic data. They continuously analyze raw network packets or traffic metadata within internal networks (east-west) and between internal and external networks (north-south). NDR products include automated responses, such as host containment (through integration) or traffic blocking, directly or through integration with other cybersecurity tools. NDR can be delivered as a combination of hardware and software appliances for sensors, some with IaaS support. Management and orchestration consoles can be software or SaaS.”

We believe the importance of NDR is evident in Gartner’s recommendation that “Enterprises should strongly consider NDR solutions to complement signature-based network security tools and network sandboxes. Many Gartner clients have reported that NDR tools have detected suspicious network traffic that other perimeter security tools had missed.”

Exploring Sangfor Cyber Command

Sangfor Cyber Command is a cutting-edge NDR platform designed to help organizations proactively detect and respond to sophisticated and unknown security threats lurking within their networks. It bolsters an organization’s IT security through vigilant monitoring of all network traffic, integrating and correlating security events from various sources, and applying AI-driven network traffic analysis and behavior analysis, all aided by global threat intelligence. Additionally, the integration of SOAR capabilities within the Cyber Command platform equips users to respond automatically to identified threats. 

Aligning with Market Trends

The Market Guide offers insights into the market direction of NDR, including a shift towards Hybrid Network NDR, Extended Detection and Response (XDR), and Augmented NDR.

Hybrid Network NDR

Cyber Command supports both on-premises and IaaS (AWS, Azure, GCP) deployment, addressing the growing trend towards cloud network activity as a significant source of security incidents. Gartner predicts that “By 2029, more than 50% of incidents discovered by NDR technology will come from cloud network activity, up from less than 10% today.”


Cyber Command integrates seamlessly with a wide range of third-party endpoint and network security tools. This integration is crucial for the aggregation of diverse data telemetry, enhancing the visibility into network activities. Furthermore, Cyber Command’s ability to ingest network-layer traffic data significantly amplifies the network visibility of the XDR solution, making it a valuable addition to existing security infrastructure without incurring additional costs and complexity.

Augmented NDR

Regarding Augmented NDR, the Market Guide notes that “New analytics overlays are emerging, leveraging natural language processing (NLP) and the summarization features of LLMs. They gather events and alerts from existing security controls, including EDR, NDR and SIEM products, and sometimes also pull threat intelligence from separate sources, then present summarized findings.” Sangfor offers its own security LLM with the upcoming launch of Sangfor Security GPT, a generative AI assistant that promises to revolutionize threat detection and streamline incident investigation and response. Stay tuned for the release!

A Call to Action for Security Leaders

Gartner recommends that “security and risk management leaders in charge of evaluating and comparing NDR vendors should first define rationalized metrics (for example, ‘percentage of critical incident,’ ‘percentage of false positive,’ ‘mean time to categorize as false positive’ or ‘improvement in mean time to detect for ransomware incidents’). These metrics are more relevant for detection systems like NDR that should trigger a lower number of alerts.” 

Sangfor invites organizations to experience Cyber Command first-hand through a proof of concept (POC) and evaluate its suitability for their cybersecurity requirements. To learn more about Cyber Command and arrange a business inquiry, contact us here, or write to us at marketing@sangfor.com.

1.Gartner Inc., Market Guide for Network Detection and Response, By Jeremy D'Hoinne et al., Published March 29, 2024
2.Gartner Inc., Gartner Competitive Landscape: Network Detection and Response, By Christian Canales and Thomas Lintemuth, Published March 6, 2024

GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved. Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

Listen To This Post


Get in Touch

Get in Touch with Sangfor Team for Business Inquiry

Related Articles


Sangfor HCI is China’s Top Hyperconverged Infrastructure in 2023

Date : 18 Apr 2024
Read Now

Sangfor Recognized as a Representative Vendor in Gartner® Market Guide for Full-Stack Hyperconverged Infrastructure Software

Date : 15 Apr 2024
Read Now
Press Release

Introducing Sangfor Omni-Command: An Intelligent XDR Solution Ready to Revolutionize Your Cyber Defense

Date : 08 Apr 2024
Read Now

See Other Product

Cyber Command - NDR Platform
Endpoint Secure
Internet Access Gateway (IAG)
Sangfor Network Secure - Next Generation Firewall
Sangfor Access Secure