AI is reshaping network operations with Forward Networks
Networks are more critical than ever, yet their operational models have remained largely unchanged for decades, relying on manual CLIs, spreadsheets, and often outdated diagrams. This traditional approach struggles to keep pace with the rapid evolution of applications, end users, and adversaries, resulting in extremely high operational workloads due to the sheer complexity of modern networking. Enterprise networks are being fundamentally reshaped by AI, cloud, and data-intensive workloads, requiring reliable, high-performance, and secure infrastructure. While companies have increased visibility into network packets and application performance, these methods cannot answer foundational questions about network inventory, connectivity, security posture, compliance, or whether network behavior aligns with its intended design, akin to reactively treating symptoms in medicine without full diagnostic imaging.
Forward Networks addresses this challenge by pioneering a shift from reactive symptom measurement to a proactive, comprehensive understanding of the network, analogous to full-body imaging scans in medicine. Twelve years ago, the company developed a mathematically accurate digital twin of the network, building on PhD research that broke down complex network behaviors into mathematical primitives. This mathematical underpinning enables the creation of provable assurances for critical aspects such as compliance, security, reliability, and availability. The digital twin is built by exhaustively collecting configuration and protocol state data from every packet-moving device across on-premise infrastructure (switches, routers, firewalls, load balancers, Wi-Fi, SD-WAN) and cloud environments (AWS, Google, Microsoft, IBM), along with security vulnerability data, performance metrics, and contextual business data. This rigorous modeling even accounts for potential device behaviors under varying conditions and firmware changes through extensive testing.
This centralized, mathematically sound digital twin provides instant, accurate answers to a wide range of questions, from inventory and connectivity to security properties, compliance, and the impact of changes. It facilitates a major operational shift by eliminating the “toil” of manual data extraction and cross-referencing, enabling network, security, and compliance teams to collaborate around a single source of truth. Forward Networks clients reportedly experience over $14 million in annual ROI and significantly improved operational confidence. Building on this robust foundation, the company has now introduced Forward AI, a conversational interface that enables users to ask complex questions in plain English and receive trusted answers, making network knowledge effortless. This innovation leverages the digital twin’s “ground truth” to support safe, trusted, and agentic operations, human-supervised, fundamentally transforming how organizations interact with and manage their critical networks.
Presented by David Erickson, CEO, Forward Networks. Recorded live at AI Infrastructure Field Day in Santa Clara on January 29th, 2026. Watch the entire presentation at https://techfieldday.com/appearance/forward-networks-presents-at-ai-infrastructure-field-day/ or visit https://techfieldday.com/event/aiifd4/ or https://www.forwardnetworks.com/ for more information.
Transcript
My name's David Erickson. I'm the CEO and co-founder of Forward Networks. We're, we're happy to be here.
We love this, we love this program. So today I'm gonna set up a little bit about the problem statement, what we've been up to as a company, and then we'll lead into what's new and exciting that we have to, to share with you today. So, at the beginning, let me, let me talk a little bit about some of the problems that we see in networking today and what Forward Networks is doing to help with them.
Networks are more critical than ever, yet there's far too many similarities in how we operate these today and how we've operated them for decades. We love our CI, you can take those out of our cold dead hands. We love our Excel, our notepad plus plus mops.
We love our printed out Vizio diagrams network, Vizio diagrams that we slam in a drawer or maybe put on the wall. And in the back of our head, we know that the minute they were printed out, they're probably out of date. But why, why does this matter?
The reason is because the customers of our networks, the applications, the end users and the adversaries are evolving at a rate far faster than we are opera, than we are evolving. Our operational models and our humans that are tasked with maintaining, evolving these networks, they're experiencing incredibly high operational workloads. And this is largely due to just the sheer complexity of modern networking.
So Cisco published some research last year in 2025, and they've discovered that, uh, the belief is that enterprise networks are fundamentally being reshaped. Uh, and this is largely due to AI workloads, cloud workloads, uh, and also very data intensive workloads. And that 94% of the CIOs that they pulled as part of this research felt that the bulk of that was gonna happen in the next two years.
And lastly, AI is not something that's just in a lab any longer. It's not being beta tested. Incredible quantities of dollars are being invested into ai, and it is being deployed en mass across our networks.
And AI requires reliable, performant, secure networks. Over the last decade, companies have really raised the bar on application delivery and end user experience. Applications have become more available, more responsive, and more distributed by design.
So we've seen the technology stacks shift to keep up. We've got virtualized networks, we have cloud and multi-cloud architectures, we have SaaS, we have microservices. But again, what didn't really change is our operational approach.
Teams are now managing applications and systems that change faster, that interact more tightly and leave less margin for error. And this rate of change, this is a rate of change and a complexity problem for all of us. And AI is only making that worse due to the velocity, the scale, and the blast radius that comes from it.
And so in the last few years, we have been steadily increasing the level of visibility that we have into network packets, into network performance. We've taken that and we've brought it up to the application level. So we get similar kinds of visibility there.
And that's, that's been great. It's has expanded our understanding of what's going on in these environments. That's all positive.
But this approach just fundamentally cannot understand nor answer whole classes of basic yet critical questions such as what's in my network? How is it connected? How is that changing over time?
What is the security posture? What is the attack surface of my network? Is it compliant?
And even is the behavior that this network exhibits in line with the intent that I had when I designed and built it? Lemme just share, uh, an analogy that I think might be helpful from the, the medical world. So for the last hundreds, maybe thousands of years, we have been reactively measuring with instruments and tools, symptoms that people who have had problems, patients are exhibiting.
And we've done this with humans, doctors that have been incredibly highly trained years and years and years of expertise and experience, which also makes it avail an availability problem to get to these people. As we've probably also all experienced, um, and as a species we've kinda limped by with this methodology for a very long time, we've made it work, but it's been far from optimal. And so in the latter half of the 20th century, there were major technological breakthroughs that allowed us to have full body imaging, scanning of our bodies with CT scans, with MRIs.
And this fundamentally changed and, and gave doctors access to full 3D images of our systems. And that totally changed the operational model that they have for diagnostics on us as humans and also how they prescribed treatment plans going forward. And we can all certainly imagine a future where the cost of those scans, the cost of the equipment, continues to decrease, such that we're using these routinely in our lives to even do preventative things on very minor medical, medical challenges.
12 years ago when we founded Forward Networks, we recognized that networking was still firmly on the left side of this diagram. And that had to change. We needed to help it move to the right side.
And I'm happy to report o over the last dozen years that the team at Forward Networks has had those and made those amazing technological breakthroughs happen and done all of the hard work to move the network to that right side of the diagram to the future. And we have built a mathematically accurate digital twin of the network. You're gonna hear me use this term mathematically a number of times in the remaining part of the presentation to kill will use it later as well.
And I want to, I want to give it a little bit of the definition 'cause I think it's important and it's distinguishing in the approach and what we do. So the background of the platform that we have is based on math. My co-founder Payman, his PhD research at Stanford was all about how do you take a global incredibly complicated network and break down all of its behavioral pieces into math and actually using math, using functions, using transformations, using mathematical primitives to do that?
And you might ask why, why? Okay, great, but why? The incredible thing that comes out of that is you, because it's now broken down using math, you can create mathematical proofs of things that are critical to you.
Imagine compliance, imagine security, imagine reliability and availability. All of those things become possible because of the underlying mathematics that are the underpinning the core of everything that we do at Forward Networks. This is not marketing spin.
This is critical core elements that are unique to forward networks. So what is the input? What, what does it take to build this twin other than the math?
So we have to exhaustively go out and collect from every single device in the network that moves packets, think collection of configuration and protocol state from every single one of those protocols that are operating inside the network. And we do this across switches, routers, load balancers, firewalls, wifi, sd-wan, you name it. If it's moving packets, we are collecting all of the data necessary from it to be to create this behaviorally accurate replica.
We also do this in the cloud. So as you're, as you're all aware, clouds create a network abstraction that we use as consumers of those clouds, and we can go to all of them and collect the same level of data about that abstraction to be able to answer similar questions about cloud and multi-cloud architectures. So I think the Amazons, Googles, Microsoft's, IBM's all of the, all of their clouds.
Hey David. Uh, question. Yeah.
Ray Silverton Consulting. We've had, uh, recent networking discussions about policy-based load balancing and things of that nature. You mimic that in queuing theory math or something like that.
We do, we break down the configuration of these load balancers so we can show you what behind the load balancers is available, what is the path through them, all of that information. So it's almost on a, um, seemed like it was a packet by packet level basis. They could route it differently or you know, something of that nature.
I mean, you have that sort of fine granularity. Yeah. So there are certainly scenarios where the chip set is going to take actions based on let's say the current traffic load level that's going into there.
What we will model is all possible ways that it can behave. And then you can reason about that. 'cause sometimes like the hashing algorithms, algorithms and things of that nature are not exposed out, right?
They're proprietary to that particular vendor. So we'll show you all possible ways and you can validate for yourself that each of those ways is in fact what you expect. And that's how we will model and present that.
Is a model using primarily for diagnostics or is it for performance, uh, assessment evaluation or Great question. Let me get there in just a minute. Okay, thank you.
Okay, so I, I've spoke about the network and the cloud collection. We also bring in security data. So we are collecting all of the vulnerabilities that are being disclosed by vendors.
We're bringing that into the platform. I'll talk about that in just a minute. What we do with it.
Also performance. So think counters of links, CPU and memory. And then last but definitely not least is business data.
So if you have structured or unstructured business data or data out of other applications, we can bring that in, provide context to all of the networking, enrich it, and get multiplicative value out of it. So that's, that's all the data that's flowing into the digital twin. Once we have it, then we do all of our mathematical behavioral analysis on it and we get to the insights and the value.
So we know everything about the behavior of how the network works with this digital twin. So we can answer questions about inventory, what's in it, how does it behave? How is it changing over time?
What are the security properties? Am I compliant? What's happening across this change window?
Is it having the intent that I expected? It's a, it's a wide ranging set of information that we can offer to our customers. And we'll talk a little more about ROI later as well.
But all of this is available via our UI and API effectively, instantly. It's incredibly responsive and you'll see it all live, uh, in the next session. This is not just for networking teams, this is also for security teams, for compliance, for anybody that's operating business revenue generating applications or just critical internal applications, they can all consume this.
And the best part is having a centralized platform that everybody collaborates around to understand, get answers, make insights, and make everything in the business work together more quickly. So once you have forward networks in your environment, you can make this operational shift from the old world where I'm sure many people around this table are familiar, having to go out and manually research and spend hours and hours extracting data from various locations in the network, trying to fuse that together, talking to your peers and the organization to attempt to build up some confidence in what you're trying to do or what's happening. Maybe reaching out to forums or Reddit, trying to ask the internet for assistance.
All of that you can leave in the past and you can shift to this new operational model where you have all of the data available within the digital twin, one click away or a couple clicks away. And all of that is instant around the things that I spoke about earlier. Behavior, what is in the inventory, security, compliance, all of these use cases apply incredibly well there.
So this is, uh, Frederick Van Hern from Hyphens Consulting. So what do you do with, uh, like firmware changes, the behavior can change. So yeah, you deal with firmware changes.
Yeah. So that goes to how do we know that our digital twin is correctly mirroring what's happening in the production network? So we have a, a, a whole fleet of equipment that we have bought or borrowed from our vendor partners.
That is, we are walking through all of the firmware versions, including the new ones. We have whole packet test harnesses set up to these to automate an incredibly deep set of, of validations to ensure that we understand precisely how this device will behave based on any kind of configuration input, uh, as well as, uh, peers that are, you know, running all the distributed protocols. So we're, we're confident and we are validating this with real packets on a 24 by seven basis.
'cause that makes it a lot more complex. Right? The amount of combination Absolutely.
Exponential. Exactly right. And when we formed the company, we knew that this was the problem space that we had to solve and frankly, we're solving on behalf of all of our customers, right?
'cause the customers would need to do this too. They need to understand maybe not to the breadth and depth they'd have to know, you know, for their particular use case. But for us to solve it universally, we're taking that work away from them and they're, they're shifting that burden to us and we're solving it on their behalf.
So do you also mirror your network traffic into this network? Great question. We do not.
So the only input that we need to build the digital twin is the configuration and the state out of these devices. We don't need any of the actual packets. So how do you know the, the, the changes you make will be be valid for the traffic that you're getting?
Yeah, so that's, that goes back to the behavioral model. So you'll see some of this in in the demo later, but if you're like, let's, let's give an example. If your intent is I need to open a firewall rule to allow this new flow for this application to work end to end, we model all of that and we'll validate the before and the after of that change to tell you, yes, this new cap, this new flow is possible given the network.
This is Marian Newsom. I have a quick question. Yeah.
Uh, where in the architecture does this sit? Is this like downstream or upstream from like NetOps and security ops? I would say it's across all of those to be honest.
Okay. Uh, one of the, one of the beautiful things again is historically you've seen this separation where the security teams and the network teams are operating their own pieces of software that are attempting to gather sometimes overlapping, somewhat, sometimes distinct data out of the network. And we are bringing one unique platform to bear that covers all of it.
Okay. Thank you. I guess you'll get into the new section of this slide, so I'll wait.
Yeah, thank you Very shortly. Thank you. Okay, so just closing out on this slide, our, our software helps people de-risk operations and improve confidence, and that's a major, major shift in their operating cadence.
You don't need to take my word exclusively for this. Uh, IDC went and interviewed a bunch of our customers and determined that on average they're experiencing over $14 million in ROIA year. And dollars and cents obviously important.
But I think just another, another piece that's, that's not on the slide here is humans that have to do this work every single day, keeping these networks up secure. It's a lot of toil, a lot of toil, and we're eliminating the majority of that toil. So that software is handling the collection, the analysis, the normalization, and then humans can move up the stack and do things they enjoy that are more strategic for the business.
Now What have we been up to, aside from all of this, this great work? What have we been doing the last 12 years? We've been deploying this software across some of the biggest, most complex, most secure, most mission critical networks on the planet.
And this is, this is battle proven, battle tested hardware at the biggest of the big. And it has again, changed the way that they operate networks. We routinely here, we can't imagine operating our network any longer without forward networks, but it is not exclusively for the biggest networks out there.
If you operate a network that is critical to your employees or your business or your mission, we can help and we can help substantially. And we have small customers all the way up to large, but you can know that if it works on the largest, most complex, it will work for you. Mm.
So David Ray Lu Yeah. Consultant, you mentioned it was hardware. This is actually a software solution, or It is software.
Okay. Yeah. Yep.
We, we can deploy as a SaaS or on-premise. Okay. Yep.
So we've, we've done all of this using a beautiful modern graphical user interface and of course the API behind that. But as with even the easiest to use graphical user interface, there is still a little bit to learn. And we're gonna demo this to you in a minute.
So you, you see just a hint of this now, but we'll get into it. And that little bit of learn is still represents a little bit of a barrier to entry. You gotta know where to go inside the ui, you gotta know how to get the data, put it together.
And so we, we thought, and we wondered could we lower that bar even further? Could we make it, could we make knowing the network effortless? And I'm excited to introduce to you today forward ai where we have done that.
We have created a interface that is conversational in English that you can come to and ask substantially any question that you want that has network, network security and business data behind it. And we can get you those answers. This enables safe, trusted agentic operations.
Again, reminder on how we used to have to manually go and get data string together, workloads make that all happen. So, So David, yeah. Um, does this mean you support an MCP server so that LLMs and things of that nature can actually access your model?
We do. And Nikhil we'll cover that in just a minute. We, we, we are a want to be a fantastic player in the ecosystem supporting data in and data out.
So these, because of having the digital twin, which is the underpinning data for what we are doing, it allows these trusted, safe agentic operations, still human supervised of course, but you can work and operate far faster. And that is, is the incredible thing that is being introduced today. It's not vaporware.
So this exists today. We've had, uh, a set of customers that have been testing this, and I just wanted to share a quote from one of them where they indicated that yes, they can ask those questions in plain language and get trusted answers with ground truth and real network data. And for them they felt like it was like turning the lights on in a dark room.
It was that, that level of impact in their operation. So David, um, how do you deploy, I mean you, do you go out with agents and understand the configuration or, or they provide that configuration to you? Or, or what's the, what's the deployment look like?
Yeah, so we will deploy either on premise in one or multiple VMs like a small cluster, or if you're using SaaS, all of the computation exists in the cloud and you deploy a small lightweight application on premise that does the collection. So it is, it is the discovery agent into your network to help you figure out all the devices that exist there. And then it goes and collects all of the information and then either keeps it on premise in the on-premise instance or moves it up to SaaS for all the computation in the SaaS instance.
Alright. Lastly, and I'm gonna hand this over to Nikhil. If you like what you see today, there is more coming.
We're incredibly excited about for forward ai. We're incredibly excited about moving the operational model forward and really helping people get into that future. Uh, but we, we have a, a deep roadmap where we're excited to continue to disrupt and, and bring change to this world.