Skip to main content

Network Observability Makes Organizations 3.5X More Likely to Reduce Incident Detection Time

Organizations with a formal observability strategy are 3.5x more likely to detect disruptive incidents quickly compared to those without such a strategy, according to the 2024/25 State of the Network Study from in partnership with TechTarget's Enterprise Strategy Group™ (ESG).

This approach not only shortens incident detection times but also brings additional benefits, such as enhanced security, faster product/service advancements, and improved compliance (78%).


Source: VIAVI Solutions

Network observability provides deep insights into network behavior, performance, and health by collecting, analyzing, and presenting data, enabling administrators to understand and manage the network in real time. True network observability embraces and leverages all network data sets, including flow data, packet data, and metrics. Unlike traditional monitoring, which primarily focuses on identifying and alerting on predefined issues, observability enables IT teams to proactively detect, understand, and resolve incidents in real-time. By adopting an observability strategy, organizations can proactively manage network performance, improve problem resolution, and maintain higher levels of user satisfaction.

"As discovered by VIAVI and ESG, the state of the network is ever more vital to business success, even as it is continuously stretched, evolved, clouded and threatened," added Jim Frey, Principal Analyst, Networking, ESG. "Organizations are recognizing the challenges posed by sprawl in monitoring tools and increasingly complex hybrid network architectures, and those making the move — strategically or otherwise — to network observability are seeing significant improvements. In parallel with operational advantages, this move empowers organizations to pursue convergence of observability and security and enable important new strategies such as continuous threat exposure management."

The report found that companies use a variety of tools including:

■ Network performance monitoring (NPM) – 82%

■ Infrastructure monitoring - 71%

■ Application performance monitoring (APM) - 69%

■ Digital experience monitoring - 62%

■ Asset/inventory management – 58%

■ Log management – 56%

More than a quarter of companies (27%) use all of the above.

Other key findings include:

Reducing Incident Detection Time

Organizations with a formal observability strategy are 3.5x more likely to report significantly shorter times to detect disruptive incidents.

Minimizing tool sprawl

The report found that the average number of monitoring tools is 10, and 38% of respondents use more than 11 tools.

The report also found that companies with 10 or less monitoring tools experienced a 58% shorter average MTTR compared to companies with 11 or more tools, and companies with 11 or more tools were 64% more likely to struggle with comprehensive or automated analysis, such a machine learning or AIOps.

Enhancing Security

The report underscores the critical need for Continuous Threat Exposure Management (CTEM), with 88% of organizations highlighting an urgent need to improve their threat management capabilities, and 83% of companies with observability strategies experiencing enhanced security.

CTEM is an emerging strategy that systematically evaluates and prioritizes risks, allowing organizations to allocate resources more effectively and focus on the most significant threats. By integrating threat exposure management with attack surface management, CTEM helps organizations enhance their security posture and operational resilience, ensuring they can proactively manage and mitigate evolving threats. CTEM programs are now gaining traction, ranking behind patch management and vulnerability assessments only among current methods for managing threat exposure.

Improving Compliance

78% of organizations maintain better compliance with a formal observability strategy.

"Organizations are increasingly recognizing the transformative impact of observability on network management and security," said Chris Labac, VP and GM, Network Performance and Threat Solutions, VIAVI. "This report demonstrates a clear trend toward network observability, not only as a way of enhancing security, achieving compliance objectives, and detecting incidents, but as a key driver of business."

Methodology: The report is based on a survey of 754 respondents from 10 countries.

The Latest

Performance bottlenecks aren't uncommon when it comes to rolling out new technology, regardless of how capable or game-changing that technology might be. Every generation of new tech has encountered roadblocks that had to be overcome before it was truly able to shine. Virtualization forced organizations to rethink resource allocation, cloud transformation had us shift our focus toward scalability and elasticity, and microservices introduced entirely new challenges around observability and distributed systems. There's something different about AI, however ...

Consider a single order represented across order-management, execution, and settlement systems. Each database, message broker, and application may be online and processing its own records correctly. Yet the workflow has failed if related events arrive on different clocks, rely on inconsistent state, or cannot be reconciled before an operational decision must be made ...

AI now exists in almost every IT workflow. In a recent survey of more than 800 IT service professionals, all respondents indicated the use of AI in some form within their organization. But there's a growing paradox: if dashboards are clearing faster and alerts are resolved at unprecedented speed, why aren't IT service desks reporting lighter workloads? The research found that 71% of IT teams said their actual workload has remained flat or increased since adopting AI. This reality appears to contradict what we’ve been told about AI ...

Two years ago, almost every customer conversation about AI started with the same questions: Which model should we use? What can it do? Is it ready for the enterprise? Today, those discussions have moved on. CIOs are far more interested in how to govern AI, integrate it with existing systems, prepare their workforce and make it part of everyday operations. The challenge is no longer to prove that AI can deliver value. It's instead about how to embed AI into the business in a way that's secure, scalable and delivers measurable outcomes ...

Two things happened to production incidents between 2023 and now, and they did not happen at the same speed. The first is that a class of dependency that barely existed three years ago now accounts for one incident in ten. Incidents disclosed by AI model and AI application providers rose from 1.7% of all disclosed unplanned incidents in 2023 to 10.7% in 2026 year to date, roughly a sixfold rise; that counts only incidents at AI companies themselves, so the true share is higher. The second is that the time to close an incident has not come down ...

When an AI assistant gives an incomplete or incorrect answer, teams often blame the model. They adjust prompts, switch models, increase context windows or test a new retrieval strategy. However the model may not be a problem. In many enterprise AI workflows, the problem begins inside the document-ingestion pipeline ...

If you talk to any security or observability teams right now, they're all fighting the same fire: their tooling was built to ingest X, but their sources are pumping Y and soon to be doing Z. The knee-jerk reaction is always the same: we need more platform. However, this reaction is wrong. Let me explain why, because the solution to this problem is foundational, not financial. Instead of hurling yet more money at the problem, make sure you've done what's needed upstream ...

Rapid AI adoption and the unique ways AI workloads operate is redefining the scope and structure of what these teams must deliver. This shift is forcing organizations to rethink how they manage scale, automation, and control, according to The State of SRE and Platform Engineering 2026, a new report from Dynatrace ...

AI is usually talked about as a software tool, but it also depends heavily on the network behind it. Whether a company is using AI for chatbots, automation, monitoring, analytics, or employee support, all of that information has to move across the network in a reliable and secure way. That means AI is not just an application decision. It is also an infrastructure decision. Before organizations rush into AI, they should ask a simple question: Is our network ready to support it? ...

Enterprise AI often lacks governed access to where business processes actually execute. Without that access, AI agents may be able to reason, but they cannot operate reliably across enterprise workflows. For AI agents to effectively carry out workflows, they will require integration-layer context and controls. Organizations can implement these prerequisites by providing AI with managed access to the middleware layer ...

Network Observability Makes Organizations 3.5X More Likely to Reduce Incident Detection Time

Organizations with a formal observability strategy are 3.5x more likely to detect disruptive incidents quickly compared to those without such a strategy, according to the 2024/25 State of the Network Study from in partnership with TechTarget's Enterprise Strategy Group™ (ESG).

This approach not only shortens incident detection times but also brings additional benefits, such as enhanced security, faster product/service advancements, and improved compliance (78%).


Source: VIAVI Solutions

Network observability provides deep insights into network behavior, performance, and health by collecting, analyzing, and presenting data, enabling administrators to understand and manage the network in real time. True network observability embraces and leverages all network data sets, including flow data, packet data, and metrics. Unlike traditional monitoring, which primarily focuses on identifying and alerting on predefined issues, observability enables IT teams to proactively detect, understand, and resolve incidents in real-time. By adopting an observability strategy, organizations can proactively manage network performance, improve problem resolution, and maintain higher levels of user satisfaction.

"As discovered by VIAVI and ESG, the state of the network is ever more vital to business success, even as it is continuously stretched, evolved, clouded and threatened," added Jim Frey, Principal Analyst, Networking, ESG. "Organizations are recognizing the challenges posed by sprawl in monitoring tools and increasingly complex hybrid network architectures, and those making the move — strategically or otherwise — to network observability are seeing significant improvements. In parallel with operational advantages, this move empowers organizations to pursue convergence of observability and security and enable important new strategies such as continuous threat exposure management."

The report found that companies use a variety of tools including:

■ Network performance monitoring (NPM) – 82%

■ Infrastructure monitoring - 71%

■ Application performance monitoring (APM) - 69%

■ Digital experience monitoring - 62%

■ Asset/inventory management – 58%

■ Log management – 56%

More than a quarter of companies (27%) use all of the above.

Other key findings include:

Reducing Incident Detection Time

Organizations with a formal observability strategy are 3.5x more likely to report significantly shorter times to detect disruptive incidents.

Minimizing tool sprawl

The report found that the average number of monitoring tools is 10, and 38% of respondents use more than 11 tools.

The report also found that companies with 10 or less monitoring tools experienced a 58% shorter average MTTR compared to companies with 11 or more tools, and companies with 11 or more tools were 64% more likely to struggle with comprehensive or automated analysis, such a machine learning or AIOps.

Enhancing Security

The report underscores the critical need for Continuous Threat Exposure Management (CTEM), with 88% of organizations highlighting an urgent need to improve their threat management capabilities, and 83% of companies with observability strategies experiencing enhanced security.

CTEM is an emerging strategy that systematically evaluates and prioritizes risks, allowing organizations to allocate resources more effectively and focus on the most significant threats. By integrating threat exposure management with attack surface management, CTEM helps organizations enhance their security posture and operational resilience, ensuring they can proactively manage and mitigate evolving threats. CTEM programs are now gaining traction, ranking behind patch management and vulnerability assessments only among current methods for managing threat exposure.

Improving Compliance

78% of organizations maintain better compliance with a formal observability strategy.

"Organizations are increasingly recognizing the transformative impact of observability on network management and security," said Chris Labac, VP and GM, Network Performance and Threat Solutions, VIAVI. "This report demonstrates a clear trend toward network observability, not only as a way of enhancing security, achieving compliance objectives, and detecting incidents, but as a key driver of business."

Methodology: The report is based on a survey of 754 respondents from 10 countries.

The Latest

Performance bottlenecks aren't uncommon when it comes to rolling out new technology, regardless of how capable or game-changing that technology might be. Every generation of new tech has encountered roadblocks that had to be overcome before it was truly able to shine. Virtualization forced organizations to rethink resource allocation, cloud transformation had us shift our focus toward scalability and elasticity, and microservices introduced entirely new challenges around observability and distributed systems. There's something different about AI, however ...

Consider a single order represented across order-management, execution, and settlement systems. Each database, message broker, and application may be online and processing its own records correctly. Yet the workflow has failed if related events arrive on different clocks, rely on inconsistent state, or cannot be reconciled before an operational decision must be made ...

AI now exists in almost every IT workflow. In a recent survey of more than 800 IT service professionals, all respondents indicated the use of AI in some form within their organization. But there's a growing paradox: if dashboards are clearing faster and alerts are resolved at unprecedented speed, why aren't IT service desks reporting lighter workloads? The research found that 71% of IT teams said their actual workload has remained flat or increased since adopting AI. This reality appears to contradict what we’ve been told about AI ...

Two years ago, almost every customer conversation about AI started with the same questions: Which model should we use? What can it do? Is it ready for the enterprise? Today, those discussions have moved on. CIOs are far more interested in how to govern AI, integrate it with existing systems, prepare their workforce and make it part of everyday operations. The challenge is no longer to prove that AI can deliver value. It's instead about how to embed AI into the business in a way that's secure, scalable and delivers measurable outcomes ...

Two things happened to production incidents between 2023 and now, and they did not happen at the same speed. The first is that a class of dependency that barely existed three years ago now accounts for one incident in ten. Incidents disclosed by AI model and AI application providers rose from 1.7% of all disclosed unplanned incidents in 2023 to 10.7% in 2026 year to date, roughly a sixfold rise; that counts only incidents at AI companies themselves, so the true share is higher. The second is that the time to close an incident has not come down ...

When an AI assistant gives an incomplete or incorrect answer, teams often blame the model. They adjust prompts, switch models, increase context windows or test a new retrieval strategy. However the model may not be a problem. In many enterprise AI workflows, the problem begins inside the document-ingestion pipeline ...

If you talk to any security or observability teams right now, they're all fighting the same fire: their tooling was built to ingest X, but their sources are pumping Y and soon to be doing Z. The knee-jerk reaction is always the same: we need more platform. However, this reaction is wrong. Let me explain why, because the solution to this problem is foundational, not financial. Instead of hurling yet more money at the problem, make sure you've done what's needed upstream ...

Rapid AI adoption and the unique ways AI workloads operate is redefining the scope and structure of what these teams must deliver. This shift is forcing organizations to rethink how they manage scale, automation, and control, according to The State of SRE and Platform Engineering 2026, a new report from Dynatrace ...

AI is usually talked about as a software tool, but it also depends heavily on the network behind it. Whether a company is using AI for chatbots, automation, monitoring, analytics, or employee support, all of that information has to move across the network in a reliable and secure way. That means AI is not just an application decision. It is also an infrastructure decision. Before organizations rush into AI, they should ask a simple question: Is our network ready to support it? ...

Enterprise AI often lacks governed access to where business processes actually execute. Without that access, AI agents may be able to reason, but they cannot operate reliably across enterprise workflows. For AI agents to effectively carry out workflows, they will require integration-layer context and controls. Organizations can implement these prerequisites by providing AI with managed access to the middleware layer ...