Logo Teldat

 

CARTA: AI-Driven Adaptive Cybersecurity as a Continuous Adaptive Communications Assessment Solution

Continuous, automated protection for networks and systems through real-time risk assessment, AI-powered zero-day threat detection, and coordinated SD-WAN response across the entire infrastructure.

Continuous Adaptive Risk and Trust Assessment – Security that adapts to every threat

Continuous Adaptive Risk and Trust Assessment - Carta - be.Safe XDR

Teldat’s CARTA solution combines XDR, machine learning, and SD-WAN orchestration to detect suspicious behavior in real time, stop threats early, and automatically isolate compromised network segments:

 

  • Real-time behavioral monitoring of network traffic and user activity.
  • Proactive zero-day threat detection through machine learning and pattern analysis.
  • Automated isolation of compromised nodes through SD-WAN orchestration.
  • Native integration with Teldat’s SD-Branch ecosystem and Cloud Net Manager.
  • Zero Trust security with continuous risk evaluation for users and devices.

Continuous Risk and Trust Assessment – The rise of XDR in Cybersecurity

Continuous risk and trust assessment - ai driven adaptive cybersecurity - Teldat

The Extended Detection and Response (XDR) market is growing rapidly, with annual growth rates exceeding 30%. This reflects a major shift in cybersecurity strategy, as organizations move away from isolated security tools toward integrated platforms.

Traditional security models, based on static trust and simple “allow or deny” decisions, are no longer effective against today’s evolving threats. At the same time, 2024 saw a fourfold increase in ransomware attacks, fueled by the rise of Ransomware-as-a-Service (RaaS). Financial institutions and healthcare providers have been among the hardest hit, suffering operational disruption and severe reputational damage as a result of security breaches.

To address this changing landscape, Gartner introduced the CARTA (Continuous Adaptive Risk and Trust Assessment) framework in 2017 as an evolution of Adaptive Security Architecture. CARTA replaces the traditional “trust but verify” model with a dynamic approach that continuously evaluates risk and trust in real time, adapting security policies according to the context and behavior of each user, device, and application.

Meanwhile, hybrid work, cloud adoption, industrial IoT, and highly distributed infrastructures have significantly expanded the attack surface. Organizations now need solutions capable of correlating telemetry across endpoints, networks, cloud platforms, and identities to detect sophisticated multi-vector attacks. According to Gartner, an integrated XDR approach has become essential as modern attacks increasingly cross multiple domains.

Continuous risk and trust assessment to replace traditional static trust model - Teldat

Continuous Risk and Trust Assessment

CARTA replaces the traditional static trust model used after authentication. Users, devices, and applications are continuously evaluated in real time, with access dynamically adjusted according to context and behavior.

AI and zero trust threat detection with machine learning - Carta - Teldat

AI-Powered Zero-Day Threat Detection

Machine learning (ML) algorithms analyze network traffic to detect anomalous behavior linked to unknown malware. Instead of relying on signatures, detection is based on deviations from normal activity patterns.

Automatic response with sd-wan orchestration to prevent threats - carta - Teldat

Automated and orchestrated response

When a threat is detected, the system can automatically isolate compromised nodes through SD-WAN orchestration. This coordinated response reduces exposure time and helps prevent threats from spreading across the network.

Unified multi-domain visibility with xdr and network traffic analysis - Teldat

Unified multi-domain visibility

XDR correlates telemetry from endpoints, networks, cloud environments, and identities within a single platform. This unified visibility helps detect sophisticated multi-vector attacks that might otherwise remain unnoticed.

Understanding CARTA and Adaptive Security

CARTA (Continuous Adaptive Risk and Trust Assessment) is a cybersecurity framework introduced by Gartner that reflects the evolution of traditional security models. While conventional architectures are based on one-time authentication and binary “allow or deny” decisions, CARTA adopts a continuous, context-aware approach to assessing risk and trust.

At the heart of CARTA is the idea that trust should never be permanent. A user authenticated in the morning may present a completely different level of risk later in the day if their behavior deviates from normal activity patterns. CARTA therefore applies a dynamic Zero Trust model built around the principle of “never trust, always verify” for every interaction and action. The CARTA framework is typically structured around three operational phases:

1. Execute: Continuous monitoring supported by real-time analytics and machine learning (ML) to detect anomalous behavior.

2. Build: Integration of security practices throughout the development lifecycle (DevSecOps), incorporating protection measures from the earliest design stages.

3. Plan: Strategic risk assessment that supports informed, proactive business decisions.

XDR (Extended Detection and Response) is the technology that brings CARTA principles into day-to-day cybersecurity operations. Unlike isolated solutions, such as EDR for endpoints, NDR for networks, or CASB for cloud environments, XDR centralizes visibility and correlates telemetry from multiple environments through a unified platform:

1. Endpoints: Computers, servers, and mobile devices.
2. Network: WAN, LAN, perimeter, and lateral traffic activity.
3. Cloud: SaaS applications and IaaS/PaaS infrastructures.
4. Identities: Authentication systems, directories, and privileges.

Key capabilities of an XDR/CARTA solution include:

– Behavior-based detection: Machine learning algorithms identify anomalous activity without relying on known signatures, making them highly effective at detecting zero-day threats.
– Event correlation: Connecting seemingly unrelated alerts to reconstruct the full context of a multi-vector attack.
– Automated response: Containment actions such as endpoint isolation, IP blocking, and session revocation can be executed automatically or triggered with a single click.
– Threat intelligence: Enriching alerts with global threat intelligence to provide context and help prioritize incidents more effectively.
– Forensic analysis: The ability to investigate historical events in order to determine the scope and entry point of an attack.

The adoption of XDR is being driven by several factors, including the shortage of cybersecurity professionals, which is increasing the need for automation; the consolidation of security tools, helping reduce alert fatigue and the costs associated with traditional SIEM platforms; and the growing need to respond to attacks that, according to Gartner, span multiple domains 84% of the time. Gartner also predicts that XDR will become the standard cybersecurity approach for organizations of all sizes.

CARTA and adaptive security - xdr- machine learning - zero trust cybersecurity

Teldat’s CARTA Solution: be.Safe XDR

CARTA architecture

Teldat implements the CARTA framework through the integration of four coordinated components that work together to deliver continuous, adaptive protection:

1- Remote Site Equipment (Teldat Firewalls): Teldat firewalls form the foundation of the network infrastructure and operate as distributed sensors. They capture network telemetry, which is then sent to the cloud analytics platform for processing.

2- be.Safe XDR: A SaaS-based threat detection service that analyzes network traffic using machine learning (ML) algorithms. The platform identifies malware patterns, anomalous activity, and zero-day threats that cannot be detected through traditional signature-based approaches. It also provides threat intelligence through REST APIs, enabling integration with other systems.

3- CloudWall: A SaaS platform designed to identify compromised nodes across the network topology. It continuously maps the security status of network assets, highlighting devices that exhibit suspicious behavior or have been confirmed as compromised.

4- Cloud Net Manager (CNM): A SaaS orchestration platform responsible for coordinating automated response actions. When be.Safe XDR or CloudWall detects a threat, CNM can dynamically adapt the SD-WAN topology to isolate compromised nodes. This helps contain threats quickly while reducing the need for manual intervention.

CARTA architecture - continous and adaptive risk - xdr cybersecurity

SD-Branch ecosystem integration

CARTA with SD-Branch connectivity, sd-wan controller, xdr and ngfw - Teldat

Teldat’s CARTA solution integrates natively with the broader SD-Branch ecosystem, enabling unified management of both networking and security environments:

– be.Manager: Lifecycle management for devices, inventory, ZTP, and firmware updates.

– be.Analyzer: Centralized monitoring with dashboards, alerts, and security event auditing.

– be.SD-WAN Controller: SD-WAN management platform that receives instructions from CNM to dynamically modify routes and isolate threats.

– be.Safe Pro: Centralized management of NGFW security policies and cybersecurity profiles for enhanced perimeter protection.

CARTA’s key capabilities

– Zero-Day Detection: Machine learning (ML) algorithms identify unknown threats through behavioral analysis rather than relying on traditional signatures.

– Integrated SD-WAN Response: The ability to automatically adapt the SD-WAN topology in real time to isolate threats.

– SaaS Model: Cloud-based deployment with no need for additional hardware at branch locations.

– Exportable Intelligence: REST APIs enable integration of threat intelligence with existing SIEM platforms.

– Unified Console: Centralized management of networking (SD-WAN, LAN, WLAN) and security (NGFW, XDR) through CNM.

– Contextual Analysis: Correlation of network events with user and application behavior.

Carta's key capabilities with sd-wan, saas model, ngfw, xdr and zero day detection - Teldat

Continuous Adaptive Risk and Trust Assessment – CARTA’s Use cases

CARTA - xdr -sd-wan - centralized console - Teldat

Financial services and banking

Real-time protection against ransomware and fraud, with continuous compliance monitoring and detection of anomalous transactions.

CARTA use case for hospitals and medical sector - Teldat

Healthcare and hospitals

Protection for patient data and connected medical devices, helping ensure continuity of care during cyberattacks.

CARTA use case to protect different scenarios in industrial and ot environments - Teldat

Industry and OT environments

Protection for converged OT/IT environments, with threat detection across SCADA systems, industrial IoT, and supply chain networks.

Financial services and banking

Real-time protection against ransomware and fraud, with continuous compliance monitoring and detection of anomalous transactions.

Challenge

Cybercriminals increasingly target financial institutions. In 2024, 65% of organizations in  the  sector were affected by ransomware, making financial services one of the most heavily impacted industries by cybersecurity breaches. Groups such as ALPHV/BlackCat and LockBit have targeted banks, credit unions, and mortgage providers, causing operational disruptions lasting days or even weeks.

In addition to ransomware, financial institutions must defend against transaction fraud, credential theft, and insider threats. Regulations such as PCI-DSS, DORA, and banking supervisory guidelines require advanced detection, response, and auditing capabilities that traditional SIEM platforms often struggle to provide efficiently. At the same time,  the shortage of cybersecurity professionals makes it difficult to maintain a fully staffed 24/7 Security Operations Center (SOC).

Solution

Financial services and banking using carta, xdr, sd-wan and unique console - Teldat

Teldat’s CARTA solution continuously monitors network traffic to detect anomalous behavior associated with ransomware, data exfiltration, and lateral movement. be.Safe XDR analyzes transaction patterns in real time to identify fraudulent activity. When a threat is detected, Cloud Net Manager (CNM) can automatically isolate the affected network segment by dynamically adapting the SD-WAN topology, containing the incident within seconds. Integration with be.Analyzer enables the generation of audit reports required for regulatory compliance, while REST APIs allow alerts to be forwarded to existing SIEM platforms.

Why Teldat?

Teldat delivers an XDR solution fully integrated with the SD-WAN infrastructure, enabling automated threat isolation through dynamic network adaptation. Its SaaS-based model requires no additional hardware and combines machine learning-based zero-day detection with support for financial regulatory compliance.

Healthcare and hospitals

Protection for patient data and connected medical devices, helping ensure continuity of care during cyberattacks.

Challenge

The healthcare sector has become one of the primary targets for cyberattacks, with 92% of organizations experiencing at least one security incident in 2024, making it the industry with the highest economic impact from security breaches. Hospitals are especially vulnerable because ransomware attacks can disrupt patient care, turning cybersecurity into a matter of life and death. The rapid growth of connected medical devices (IoMT), telemedicine platforms, and cloud-based electronic health records has significantly expanded the attack surface. In addition, many medical devices still rely on legacy operating systems that cannot be easily patched. Regulations such as HIPAA and GDPR require strict protection of patient data, with severe penalties for non-compliance.

Solution

CARTA - healthcare sector - hospitals - xdr, sd-wan, cloud net manager - Teldat

Teldat’s CARTA solution continuously monitors all network traffic, including traffic generated by IoMT medical devices. be.Safe XDR detects anomalous behavior associated with ransomware attacks or patient data exfiltration without relying on signatures that legacy systems are unable to generate. CloudWall identifies compromised devices in real time, while Cloud Net Manager (CNM) can automatically isolate them from critical clinical networks, containing threats without interrupting hospital operations. The SaaS-based architecture also enables deployment without additional hardware in healthcare environments already saturated with equipment.

Why Teldat?

Teldat protects healthcare environments containing legacy medical devices through behavior-based threat detection without requiring agents on endpoints. Its integrated SD-WAN response automatically isolates threats while ensuring continuity of patient care, with built-in HIPAA and GDPR compliance support.

Industry and OT environments

Protection for converged OT/IT environments, with threat detection across SCADA systems, industrial IoT, and supply chain networks.

Challenge

The industrial sector accounted for 18.6% of all ransomware incidents in 2025, making it one of the most heavily targeted industries. The convergence of OT (Operational Technology) and IT networks has exposed SCADA systems and PLCs originally designed decades ago without modern cybersecurity protections. Attackers exploit the combination of legacy OT infrastructure and poorly secured IIoT devices to disrupt production, steal intellectual property, or carry out extortion campaigns. A successful attack can halt manufacturing operations for days, causing severe operational and reputational damage.

The digitally connected supply chain further increases the risk, as a compromised supplier can become an entry point into the manufacturing network. Critical dependence on uptime also pressures many organizations into paying ransoms to restore operations quickly.

Solution

CARTA to protect industry and ot environments with xdr, cloud net manager and sd-wan support - Teldat

Teldat’s CARTA solution continuously monitors OT/IT traffic to detect anomalous communications involving SCADA systems or PLCs that may indicate an ongoing attack. be.Safe XDR identifies industrial malware patterns without requiring agents on legacy OT equipment. When suspicious activity is detected, Cloud Net Manager (CNM) can automatically isolate the affected OT network from the Internet and corporate environments, allowing production to continue operating in isolation while the incident is investigated. CloudWall provides full visibility into connected IIoT devices.

Why Teldat?

Teldat delivers agentless OT threat detection designed for legacy SCADA environments. Its automated SD-WAN response can isolate production networks while maintaining uptime. CloudWall provides full visibility into IIoT assets and supports compliance with industrial cybersecurity regulations.

Read our latest Blog Posts

Easy network deployment with Corporate ZTP

Easy network deployment with Corporate ZTP

Zero Touch Provisioning is a method that can be implemented in different types of businesses, whereby the implementation of some technological parts of their limited ecosystem is optimally solved through the use of automated processes generally based on software and...

read more