By Cary Wright, VP Product, Endace
Why IPv6 Matters
IPv4’s roughly 4.3 billion available addresses are nowhere near enough for today’s hyper‑connected world. In contrast, IPv6 offers a 128‑bit address space, providing 3.4 x 1038 possible addresses — more than enough for decades of growth. Technologies like Network Address Translation (NAT), private addressing, and CIDR have extended IPv4 far beyond its natural lifespan. These workarounds give organizations a false sense that IPv4 is still sufficient, reducing the urgency to adopt IPv6.
What we observed in Amsterdam
In the Cisco Live EMEA SOC, we inspected 130 billion packets across 32,434 unique IP endpoint devices at the conference, using Splunk to query unique DHCP Client IDs to measure. These included devices connecting to the Wi-Fi and wired networks at the Cisco Live conference network, including attendee laptops, phones, and conference devices such as demo stations, cameras, IOT devices, displays, networking equipment, and any other IP connected device.
Of this traffic, 62% of the data travelled over IPv6, and only 38% over IPv4. This represents a tectonic shift in the move to IPv6. Perhaps this was because we were sitting just a few miles from the Regional Internet Registry for Europe, Middle East and Central Asia (RIPE NCC), or more likely this is because the world is finally ready and moving to IPv6.
Our heaviest day was Tuesday, with 25,609 devices that connected to the network.
Across all this traffic we observed 1.7 million unique IP addresses, most of which were external addresses accessed by attendees and conference devices. Those IP addresses were made up of 386,397 IPv4 addresses, and 1,339,329 IPv6 addresses.
Threat Actors — adopting IPv6 faster than anyone
In the SOC, we have no shortage of data to interrogate, interrogating our Splunk data highlight that threat actors are now heavily favoring IPv6 to conduct their attacks, hijack resources, or compromise systems. Over 99% of malicious URLs and crypto miners used IPv6, telling us that we need to ensure we properly secure our IPv6 infrastructure. Just 1% of our attacks involved IPv4. That indicates a trend that we all need to take notice of.

A Steady Shift — But an Inevitable One
Although the transition has taken decades, IPv6 momentum appears to have crossed an important threshold. With increasing digital demands, rising IPv4 costs, and rapidly expanding device ecosystems, IPv6 isn’t just beneficial — it’s essential.
The future of the Internet is unquestionably IPv6. The challenge now is how quickly the world can get there, and how well we secure it. At Cisco Live EMEA, we saw the world has taken a large and important step forward.
Acknowledgements
This important insight to IPv6 adoption would not have been possible without the great work done by the Cisco Live EMEA SOC team, led by Jessica Oppenheimer and Ivan Berlinson.
Data collected and analyzed was the result of a team, many thanks go to the following team members:
Network Operations Center Liaisons
- Remco Kamerman, Luke Hebditch, Mark Bremner and Scott Neuman
Cisco Security and Splunk SOC Team
- SOC in a Box: Adi Sankar
- Splunk Security Integrations: Paul Pelletier and Kenneth Bouchard, with Josh Wilson and Duane Waddle
- Splunk Threat Researchers: Nasreddine Bencherchali and Paul Pang
- Breach Protection Suite: Mark Pleunes, Ibrahim Yusuf, Piotr Jarzynka, Matt Vander Horst, Yannis Steiakogiannakis and Eric Rennie, with Bilal Qamar
- User Protection Suite: Aaron Woland
- Firewall and Security Cloud Control: Adam Kilgore and Christopher Grabowski
Endace SOC Team
- Co-SOC Leader: Cary Wright
- Endace Engineering: Owen Gallagher, Sundarram Paravastu and Sam Brockelsby
Read related Cisco Team Blogs from the Cisco Live Europe 2026 SOC:
https://blogs.cisco.com/security/emea-soc-2026
For more Endace blogs in our SOC series, see here:
https://blog.endace.com/tag/soc/
Event SOC Website
Visit Cisco’s Event SOC website for full details of the SOC setup, and download the whitepaper written by Jessica Oppenheimer:
https://www.cisco.com/site/us/en/products/security/event-soc-report.html









































