Hybrid work has fundamentally altered the way businesses operate. Over the last few years, collaboration platforms such as Microsoft Teams and Zoom have become essential infrastructure for everyday communication, enabling employees to work across offices, homes, and remote locations. While this flexibility has improved productivity and employee satisfaction, it has also created new challenges for IT and security leaders tasked with protecting increasingly distributed environments.
In this discussion, Kristian speaks with Darren Anstee, Chief Technology Officer for Security at NetScout about why securing unified communications infrastructure has become such a pressing issue. Drawing on his experience monitoring the evolving threat landscape, Anstee explains how attackers are now targeting the systems that keep businesses connected, recognizing that disruption to collaboration can quickly become disruption to the organization itself.
As Anstee explains early in the discussion, businesses have realized the operational value of collaboration in a post-pandemic world. “Having everyone work together and having teams communicate across the organization can be very valuable in terms of productivity,” he says. However, attackers have recognized this value too. The same tools that enable agility and flexibility also represent attractive targets for cybercriminals looking to interrupt operations or create widespread disruption.
The Growing Risks Facing Hybrid Environments
One of the key themes explored throughout the conversation is the complexity that hybrid work introduces from a security perspective. In a traditional office environment, infrastructure is largely centralized and controlled by corporate IT teams. In hybrid environments, employees are spread across homes, shared workspaces, and branch offices, often relying on networks and devices that businesses cannot fully manage or monitor.
Anstee highlights how this makes identifying the source of problems significantly more difficult during a cyber incident. If collaboration tools suddenly stop working, organizations may struggle to determine whether the issue is caused by a cyberattack, an internet outage, a local ISP problem, or another operational failure entirely. “The first issue here is that it can be quite difficult to figure out where the problem actually is,” he explains.
The discussion also explores how investigations become more complicated after an incident occurs. Security teams often rely on logs, packet traces, and monitoring data to understand the scope of an attack and determine regulatory or operational impact. In highly distributed environments, gathering this information can become a major challenge. Employees may be operating on unmanaged networks, using different internet providers, or accessing systems from locations outside corporate visibility.
Another major issue raised is the increasing focus attackers place on collaboration infrastructure itself. Rather than directly targeting revenue-generating applications, attackers are now looking for weaker secondary systems that can still cause significant disruption. According to Anstee, firewalls protecting office connectivity have become especially attractive targets because disabling them can effectively cut entire groups of employees off from collaboration tools and cloud services.
He points specifically to distributed denial-of-service attacks, commonly known as DDoS attacks, as a growing concern. These attacks aim to overwhelm infrastructure with traffic until systems can no longer function normally. “If you exhaust the state in a firewall, new sessions can’t be established and everybody behind that firewall loses connectivity,” Anstee says. In a hybrid workplace, where communication platforms underpin day-to-day business activity, even short periods of downtime can create widespread operational disruption.
Building Resilience Into UC Infrastructure
While the challenges are significant, the conversation also focuses heavily on practical ways organizations can strengthen resilience across their communication environments. For Anstee, the first priority is clear: protecting internet-facing firewalls and connectivity infrastructure must become a central part of security strategy.



