
5-Agent AI Platform for Network Operations. From syslog to fix in 16–20 seconds. Human-in-the-loop, not human-in-the-way.
Eduard Dulharu, CTO — vExpertAI GmbH (CCIE)
Eight focused segments, each building the case for autonomous network operations.
0–10 min
The Problem
Alert fatigue, 3% automation, DORA is live
10–20 min
Why Now
DORA enforcement, NIS2, €100M/day exposure
20–35 min
Live Demo
5 agents, real routers, 16-second E2E
35–45 min
Architecture
ACP / A2A / MCP stack, fine-tuned models
45–60 min
ROI
€309K savings, 226% ROI, 3.7 month payback
60–75 min
Partnership
3 offers, revenue model, pilot scope
75–90 min
Client Fit
Projecting into your clients' environments
90+ min
Next Steps
Name a client, agree a 3-week follow-up
Ask these to any enterprise NOC director. The answers are the business case.
How many alerts does a NOC with 1,000 devices receive per day?
2,000 – 10,000
At TotalEnergies scale: 100,000/day. 70% are false positives.
What % of network operations is fully automated today?
< 3%
After decades of Ansible, Terraform, playbooks — 97% is still human labor.
Were your banking clients DORA-compliant on January 17, 2025?
Very few.
Automated network incident detection is mandatory. The deadline has passed.

This is not a 'nice to have' conversation. It is a compliance crisis with a named deadline and a daily financial penalty.

AI diagnoses, generates, verifies. Human approves or rejects. One decision.
AI diagnoses, generates, verifies. Human approves or rejects. One decision.
5 fine-tuned 7-8B models. Each domain-expert. OSPF, BGP, Security, Interface, Design.
3-pass Digital Twin gate. Graph sim → FRR clone → Confidence score. Tested before shown.
Every layer uses an industry-standard protocol. Click any layer to explore its components.
The LLM can be wrong. Every proposed fix is tested in an isolated clone before a human ever sees it. A bad fix never reaches the approval queue.
Live Network vs. Isolated Digital Twin — step-by-step animated walkthrough
Three real-world scenarios on live Cisco CSR1000v routers. Run each simulation to see the AI pipeline in action.
Stability Agent · Qwen-2.5-7B
EXECUTION TIMELINE
Misconfigure hello timer on R1
neighbor down event triggered
AI collects live OSPF data via MCP
show ip ospf neighbor · show run
Diagnoses timer mismatch
hello 10s vs 40s dead timer conflict
Proposes fix
no ip ospf hello-interval
Digital Twin validates
OSPF adjacency restored to FULL
Card sent to human approval
gate score 1.0 — safe to apply
Select any vendor (Cisco, Juniper, Palo Alto, Fortinet), enter platform + version + features, and get a CVE list, DORA/PCI compliance gaps, and AI-proposed remediation in ~30 seconds.
HOW IT WORKS

400 incidents/month baseline. Conservative estimate. From go-live.
Choose the engagement model that fits CNS's timeline and risk appetite.
Three CNS clients with immediate fit. Pain mapped to solution. Deployment timeline indicated.
Banking (SG Group) · DORA regulated
MTTR 4–8 hours. DORA requires 4-hour reporting. Every day is a compliance liability.
scanner.vexpertai.com generates the ICT risk register. AI NOC cuts MTTR to minutes. DORA Article 17+18 satisfied on day one.
Energy · Global estate · NIS2 scope
100K alerts/day. BGP instability between trading systems. Compliance documentation manual.
AI NOC handles routing protocol diagnosis autonomously. Audit trail is the compliance artifact. SecNumCloud deployment available.
Manufacturing · Global supply chain
35+ countries, mixed-vendor gear, no unified NOC visibility. Security policy drift across acquisitions.
Vendor-agnostic platform. Cisco + others. Security agent handles ACL drift. Champion program trains local IT teams.
All deployments: on-premise or OVHcloud SecNumCloud · Vendor-agnostic · Zero config data leaves client perimeter
Every objection has been heard. Every answer is grounded in architecture.
AI hallucinations are dangerous
The LLM cannot SSH to routers — it can only PROPOSE. 3 gates before any human sees it: confidence scorer → graph simulation → FRR container clone. Safer than your L1 engineer at 3am.
We already have Dynatrace / Splunk
We integrate with them. We add the reasoning layer on top. Not a replacement — an orchestrator. Your existing stack stays. We make it intelligent.
How is this different from Cisco AI?
Cisco requires all-Cisco gear. 90% of enterprises are mixed-vendor. We're vendor-agnostic. And Cisco sends your config to their cloud — we run 100% on-premise.
Data sovereignty / ANSSI compliance?
Zero data leaves client perimeter. OVHcloud SecNumCloud deployment available. AWS and Azure are NOT SecNumCloud certified — we are the only credible sovereign answer.
What if the pilot fails?
Fixed scope, fixed price, success criteria in the contract. Milestone payments — you only pay for what's delivered. Risk is bounded by design.
The timing isn't right
DORA is already enforced. NIS2 enforcement starts 2027 — 18 months away. Sales cycle is 3–6 months. Start now or you're in the crisis window.
25–30% to production. 9 sprints · ~9 months. CNS shapes what AI SOC looks like in production.
Triage Agent
4-track ML engine. Eliminates noise before it reaches humans. Sub-30s detection.
Investigation Agent
Evidence-grounded root cause. Pulls from SIEM, EDR, network flows. Every verdict requires citations.
Security Agent
Detects AI-generated threats via behavioural ML, malware analysis, semantic phishing + TLS fingerprinting.
Hunt Agent
Proactive threat hunting across network graph. Connects dots across hosts, users, and time.
Remediation Agent
Human approval gate + pre-registered rollback. Every action reversible. Nothing touches production unvalidated.
Not a signed contract. A name and a date for a joint technical scoping call. 10-week pilot, fixed scope, milestone payments.
Formal co-development partnership terms. Revenue-sharing model. MOU scope. DORA/NIS2 compliance module joint IP.
"Two things before we leave. First — name one client for the 10-week pilot. Not a signed contract today. A name and a date for a joint call. Second — agree a 3-week follow-up where we present the formal co-development terms. Can we agree on both today?"