About (Edit profile)

This author has not yet filled in any details.
So far has created 1829 blog entries.

Egress Security: Part of a Holistic, Multidirectional Security Strategy for Today’s Multicloud World Vishal Jain on January 9, 2024 at 1:00 pm

Cloud transformation has given rise to a new era of business innovation and growth. According to Enterprise Strategy Group, more than half of production workloads will be running on public cloud… Read more on Cisco Blogs

Cloud transformation has given rise to a new era of business innovation and growth. According to Enterprise Strategy Group, more than half of production workloads will be running on public cloud infrastructure within the next two years, positioning cloud computing center-stage as the best practice for solving critical business issues and enabling agility. However, the unforeseen by-product of this evolution is complexity, and complexity is the enemy of security.

Decentralized IT infrastructure, expanding attack surfaces, and a lack of visibility and control have made it more difficult than ever to secure enterprise workloads in the cloud. Organizations need to employ a holistic security approach that targets the entire threat chain from initial access to external connectivity and data exfiltration.

The importance of egress security in today’s multicloud world

Today’s threat actors operate under a variety of motives. They may attempt to steal customer information or other proprietary data. They may hijack IT resources for nefarious use. They may take control over critical systems in an attempt to disrupt operations or extract a ransom payment. And they may do several of these things, together, all at once.

The point is—attacks do not stop when the initial breach is made, or the final target has been compromised. Once inside, threat actors or their malicious applications often have to connect with external systems or networks outside the organization to communicate critical telemetry and counterintelligence information and, eventually, extract data. Making things more difficult is the fact that sometimes the threats can communicate with trusted websites or platforms such as GitHub to deliver malware. However, this communication is an opportunity for security teams to detect, identify, and stop malicious activity before real damage has been done.

Egress security often acts as the last line of defense before workloads reach the public Internet or other unauthorized networks. Egress security was rarely an issue when everything sat in a hardened data center behind robust firewalls and applications rarely tried to communicate with outside entities on the public Internet. But what happens when your entire business model relies on continuous, ubiquitous connectivity to tens of thousands of distributed endpoints, web applications, and Software as a Service (SaaS) platforms across multiple public and private cloud environments? Suddenly, egress security gets very real and very complicated.

Unfortunately, existing multicloud security solutions were designed for a world that doesn’t exist anymore and haven’t kept up with the acceleration of cloud transformation. Ensuring data loss prevention (DLP) policies are applied appropriately and consistently across multiple cloud environments is virtually impossible, requiring manual intervention and control using a variety of tools and solutions. Teams across the organization are left on their own for harmonizing the delicate balance between securing users and applications, connecting correct users to the correct applications across multicloud environments, and securely mitigating complexity as they scale. They often have to deploy multiple management consoles and policy management tools while adding yet another tool for log analytics. This multi-tool approach creates disparity, complexity, and confusion—leading to higher risk and cost for organizations. Some organizations use homegrown solutions to consolidate this tool sprawl, but these require manual configuration and updates every time a new cloud provider is added – contributing to uncontrollable tech debt.

Specifically, tool sprawl leads to unwieldy change control processes that are magnified by dynamic environments that limit business agility. This is creating friction between NetOps, SecOps, and cloud teams who find themselves working in silos, separate from each other, the opposite of harmony. The inability to work cohesively is making it hard to achieve high availability, scalability, and resilience in cloud infrastructure.

Cisco Multicloud Defense simplifies egress security

Cisco Multicloud Defense helps security teams gain multidirectional protection across multiple clouds and workloads to block inbound attacks, prevent lateral movement and stop data exfiltration – and it allows you to do this all from a single SaaS platform. Cisco Multicloud Defense alleviates security complexity across public and private cloud environments with consistent policy controls and deep visibility into workloads – including potentially-malicious and unauthorized traffic flowing out of the network such as command and control communications and data exfiltration. Just as critical, security teams can be assured that policies are being applied appropriately and consistently across multiple cloud environments through tag-based policies.

Cisco Multicloud Defense enables egress security through advanced domain and URL filtering capabilities combined with DLP. Working together in a single solution provides unparalleled visibility into all cloud workloads, allowing organizations to automatically detect and analyze outbound communications, identify malicious intent and risk, and block unauthorized connectivity and data exfiltration.

Command & Control: Threat actors need to communicate back to an owned server to confirm a breach, receive further instructions and control affected systems. Cisco Multicloud Defense uses artificial intelligence (AI) and machine learning (ML) to identify these unauthorized communications, alert security teams of the breach, and automatically apply policies that severe connectivity.

Data exfiltration: Traditional DLP solutions rely on several technologies to identify and block critical data flowing out of the organization. Cisco Multicloud Defense integrates these DLP capabilities with egress filtering to stop the loss of information before it is too late.

Keeping multicloud environments secure without impacting productivity or agility

Cisco Multicloud Defense provides security throughout the entire threat chain – from initial breach to data exfiltration. Egress security gives organizations the ability to identify suspicious or abnormal behavior that may alter the controlled flow of data inside and outside of the network. However, expanding threat surfaces and IT complexity in today’s environments make it hard to detect, analyze, and eventually stop unauthorized external connectivity and data exfiltration using traditional means. Cisco Multicloud Defense greatly simplifies security across complex environments, ensuring that organizations can take full advantage of the ever-evolving multicloud world.

To learn more about Cisco Multicloud Defense:

Take the Multicloud Defense product tour
Request a Multicloud Defense demo

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Security on social!

Cisco Security Social Channels

InstagramFacebookTwitterLinkedIn

Share

  Cisco Multicloud Defense allows security teams to detect, analyze, and protect workload traffic outside the organization with simplified egress security.  Read More Cisco Blogs 

By |2024-01-09T22:54:15+00:00January 9, 2024|Cisco: Learning|0 Comments

Cisco Allowed Me To Start My Family, Stress-Free Allison Grant on January 9, 2024 at 1:00 pm

Becoming a parent looks different for everyone. Some are blessed for this journey to come swiftly. For others, the road is bumpier and has many pit stops along the way. After all, one in six couples… Read more on Cisco Blogs

Becoming a parent looks different for everyone. Some are blessed for this journey to come swiftly. For others, the road is bumpier and has many pit stops along the way. After all, one in six couples struggles with fertility. And after a year and a half of trying to conceive, I found myself facing the real possibility of IVF being the most likely path to parenthood for my husband and me.

Photo by CLJ Photography

Realizing this, I began seeking career opportunities matching my skillset and goals with employers offering fertility benefits. Having previously worked in the IT (Information Technology) industry, Cisco was at the top of my list. Admittedly, when I applied, it felt like a long shot. Even after three interviews, I was still sure the odds were so low of being selected. But somehow, I did it. They chose me. What they did not know when they chose me was that working at Cisco would allow me to start my family without the stress of the heavy financial burden that comes with undergoing infertility treatments.

The reality is it costs an average of $12-40K out of pocket for ONE round of fertility treatments with no insurance coverage. One of the best parts of not having the heavy financial burden of IVF was that I could show up 100% for my job, feeling extremely motivated to make an impact.

Don’t get me wrong, fertility treatments take a lot of time with appointments, procedures, phone calls, coordinating medications, and can quickly become super overwhelming and take up a lot of emotional bandwidth. Not to mention, stress has a direct impact on creativity and production. So, while Cisco supported me medically and financially, my manager was there for me emotionally. I am so thankful I opened up and shared my journey with her. She was understanding and encouraging throughout the entire process because even while undergoing treatments, I was highly motivated and working hard — and still am — to understand the massive scope of projects the team I had just joined works on.

Photo by L&I.T Photography

Along with keeping my stress low and leaning on my incredible support system, I have found throughout this process how valuable sharing my experience with others has been, and doing so has allowed me to surround myself with an even larger support system and become part of a support system for others. After all, with one in six couples struggling with infertility, it’s affecting friends, family, AND coworkers.

Now, I am happy to say that I just returned from maternity leave, where I spent just over four blissful months with my new super smiley baby girl. I love being a mom, and I am so thankful to have had so much time with her — another incredible benefit of joining Cisco — but also found myself excited to return to work.

I recently told a friend, after referring her for a position at Cisco, “I want all my favorite people working here with me because I love working at Cisco.”

We work hard here, but we are all human beings at the end of the day, and coming across such a large company that values people individually and respects their time and needs seems like such a rare find. I find comfort in knowing I show up to work every day for a company that shows up for me. I look forward to making a continued impact and love the flexibility and opportunities that come with working at Cisco!

What else is there to love about working at Cisco? Check out our benefits and perks!

Subscribe to the WeAreCisco Blog.

Featured banner image by CLJ Photography
Share

  The cost of infertility treatments can be overwhelming, but when Partner Marketing Manager joined Cisco, she was able to start a family and have a career she loves.  Read More Cisco Blogs 

By |2024-01-09T22:54:15+00:00January 9, 2024|Cisco: Learning|0 Comments

Customer Success Stories – Year in Review Adam Neiberg on January 9, 2024 at 1:00 pm

Did you miss some of the great financial services customer success stories Cisco produced in 2023? These stories are a testament to clients achieving their goals with Cisco at their side. The stories… Read more on Cisco Blogs

Did you miss some of the great financial services customer success stories Cisco produced in 2023? These stories are a testament to clients achieving their goals with Cisco at their side. The stories cut across institutions, big and small, geographies and architectures.

Below is a short summary of all the new 2023 financial services customer success stories. If you want to learn more about them, then click the title to read the full story. These are in English but occasionally we do have stories translated into other languages or completed in another language solely. Also at Cisco conferences and events we often have customers present but unfortunately most of the time these presentations are not turned into formal customer stories, but alas we have the following new 11 stories from 2023.

2023 Financial Services Customer Success Stories

How Deutsche Börse Is Transforming Its Digital Future

Solution: ThousandEyes

Deutsche Börse Group, an international exchange organization, manages around 150 IT applications covering the entire financial market transaction process. During the COVID-19 pandemic, they utilized ThousandEyes to identify user connectivity issues for remote workers and resolve denial-of-service attacks. As a pioneer of digital transformation, the company is moving more business processes to the cloud, aiming to be among the first European companies to have a core financial system cloud-based.

Banco Millennium Atlântico: charts new digital path with Cisco HyperFlex Systems

Solution: HyperFlex

To achieve its digital strategy, Banco Millennium Atlântico replaced their legacy infrastructure with Cisco HyperFlex Systems, significantly improving management, security, flexibility, and scalability. The switch allowed ATLANTICO to consolidate servers and racks, saving costs and space, while also enhancing performance and redundancy across their data centers. This simplification allowed staff to focus on strategic initiatives like application development and cloud operations, and enabled the creation of a private cloud with self-service capabilities.

FAB: Improving availability and performance of customer-facing applications with Cisco Full-Stack Observability (FSO)

Solution: Full-Stack Observability

First Abu Dhabi Bank (FAB), the UAE’s largest bank, prioritizes customer-focused services and progress. FAB embarked on a digital transformation, leveraging Cisco’s AppDynamics and ThousandEyes to monitor 180+ applications, significantly boosting service availability and reducing downtime. Their shift towards a DevOps mindset aims to enhance customer experiences further, emphasizing proactive monitoring and fostering a culture of continuous improvement.

BNP Paribas Personal Finance brings financial dreams to life

Solution: AppDynamics

BNP Paribas Personal Finance has improved its customer service quality by using Cisco AppDynamics to monitor and optimize its loan application process. The solution provides visibility across more than 50 IT workflows, allowing the team to identify and resolve issues five times faster than before. As a result, the bank can maintain its standard of processing and responding to every customer’s request in 30 seconds or less, even during peak demand periods like Black Friday.

PREMIER Bankcard invests in exceptional customer service and online experience

Solution: AppDynamics

First PREMIER Bank partnered with AppDynamics and Xigent to monitor their banking and corporate websites and troubleshoot online, mobile, and call-center experiences. This initiative has resulted in improved visibility of IT performance and quicker problem resolution, transforming their IT operations. Notably, it has also led to enhancements in the bank’s website, call centers, and the successful relaunch of its mobile app. Moving forward, PREMIER plans to extend this visibility to its cloud environment.

AIA Makes Hybrid Work Possible

Solution: IP telephony

AIA China, with offices across the country, switched to IP telephony from traditional phone systems for cost-effective communication. Initially, they faced issues with outdated software and slow updates from a different vendor. Evaluating their needs, they turned to Cisco for cutting-edge, regularly updated technology and improved support. The transition to Cisco also significantly reduced costs. Amid pandemic-induced remote work, the Cisco solution supports a flexible hybrid model, enhancing user experience and further saving costs, prompting consideration of permanent hybrid work.

How NEXT Insurance Found the Best Way to Keep Pace with the Modern Work Environment

Solution: Meraki

NEXT Insurance, a leading digital insurtech company, enhanced its IT infrastructure by integrating Cisco Meraki, overcoming issues with slow Wi-Fi connectivity. The technology provided stable wireless connections, remote maintenance capabilities, improved security, and significantly reduced in-office internet connection issues. The ability to perform remote maintenance saved thousands of hours, and the system’s stability improved productivity and employee satisfaction.

Embracing hybrid transformation across a growing enterprise

Solution: Webex suite

Broadridge, a global fintech provider, has streamlined its hybrid work transformation using the Webex Suite to create a remote-first work environment. This has enabled seamless collaboration, improved user experiences, and significant cost savings. The company also leverages Webex’s artificial intelligence capabilities for real-time language translation, enhancing diversity, equity, and inclusion. With the help of Webex Control Hub, Broadridge can track system performance and provide valuable metrics to its leadership team.

JazzCash transforms digital financial platform experience with Cisco AppDynamics

Solution: AppDynamics

JazzCash, Pakistan’s largest digital wallet, uses Cisco AppDynamics to monitor its services. The observability solution enables JazzCash to analyze data across its entire stack, improving user experience and business performance. It helps the company identify patterns, trends, and anomalies, enabling quick issue resolution. Furthermore, the tool allows JazzCash to track end-user journeys and develop new offers and promotions. As a result, JazzCash has not experienced any glitches and downtime has been virtually eliminated.

Ensuring availability and quality of financial services with AppDynamics

Solution: AppDynamics

Mitsubishi UFJ NICOS has improved its customer-facing application performance and automated reporting processes using AppDynamics. The solution allows the company to easily monitor application performance, analyze performance issues, and manage system operations more effectively. By providing real-time visibility into application performance, the system has streamlined collaboration between the operation and development teams. The company plans to further expand the use of AppDynamics to gain more insights into customer service usage and business impacts.

Helping a leading UK bank integrate Facebook Messenger into its customer contact strategy

Solution: Webex CPaaS

This UK High Street bank wanted to incorporate Facebook Messenger into their contact center’s customer support strategy as the customer experience journey through the contact center was pivotal. Webex CPaaS solutions helped reduce call volume and increase positive feedback all while allowing customers to get instant support through one of their favorite messaging channels.

There’s more to customer stories

For all the financial services customer stories plus other industries check out the full customer story listing.  Also view these stories in application in the Cisco Portfolio Explorer to support use cases.

If your institution feels invigorated to share how a Cisco technology has improved your business then reach out to your account manager or partner to get into contact with us about customer success story options.

Share

  Here is a summary of the 11 customer success stories published in 2023. These stories are a testament to how Cisco has helped clients achieve their technology goals. The stories cut across institutions, big and small, geographies and architectures.  Read More Cisco Blogs 

By |2024-01-09T22:54:14+00:00January 9, 2024|Cisco: Learning|0 Comments

Leveraging a digital twin with machine learning to revitalize bridges Andrew Nolan on January 9, 2024 at 5:00 pm

As you drive across a bridge you might think of the impact it’s having on your commute, but have you ever considered the impact you’re having on the bridge itself? Until recently, this impact was lar… Read more on Cisco Blogs

As you drive across a bridge you might think of the impact it’s having on your commute, but have you ever considered the impact you’re having on the bridge itself? Until recently, this impact was largely left to projections based on historical engineering practices, rather than real-time data. In this blog, we will explore how Thomas Braml, Professor of Civil Engineering and the team at the University of the Bundeswehr Munich have used Cisco technology to implement a repeatable solution for bridges that reduces the cost of bridge maintenance and optimizes the design of new bridges to align with real data rather than forecasted use.

Bridges are constantly changing, but at what rate?

Despite the strong materials used in bridge construction, wear and tear occurs over time, which can lead to costly bridge maintenance or even rebuilding. The key issue with this maintenance practice is the lack of accurate and historical data – how do we know the exact rate of flex for a steel beam? How do we know the annual expansion of a crack in the concrete supports? How do we know the right moment to call for maintenance? These questions are typically answered by sending an engineering team to a bridge, which may or may not result in repairs. Either way, this is costly, and the data collected represents just one point in time.

Today stakeholders must make hard decisions about bridge maintenance with this limited data set, which could result in a significant repair job or a complete rebuild. This has significant cost implications and can also lead to significant CO2e emissions resulting from the construction and production of required materials.

A cutting-edge solution to a centuries-old problem

To better understand the historical and day-to-day wear, the industry is moving towards a standard of leveraging a variety of sensors to measure key data points across a bridge. These sensors send their data to a cloud backend to be processed with algorithms to create a “digital twin” of the bridge for live monitoring and predictive maintenance. The team at the university has now created a model using this digital twin approach, which gives stakeholders a data-driven framework to accurately validate when and if a bridge needs maintenance.

The sensors being leveraged provide data such as acceleration, temperature and strain measurements to create a picture of the current state of the bridge. Before this data can make it to its destination, Cisco Edge Intelligence software can process, buffer, aggregate, and eventually enrich this data at the edge through its Data Logic feature – allowing customers to write scripts to quickly adjust data payloads in-transit before the data leaves the edge. Once the data is ready for transit,  Cisco Catalyst IR1101 Rugged Series Routers provide the critical network infrastructure and connectivity to a central data center. These industrial routers provide trusted Cisco networking, while also being certified for a wide range of temperatures that can be experienced at these bridges.

After this data is collected in the data center, the digital twin model developed by the University of the Bundeswehr Munich team is leveraged to provide live and historical insights. These insights can identify key historical events which might lead to maintenance concerns, and the digital twin also allows customers to predict and forecast issues. With the ability to accurately model the variety of scenarios occurring on the bridge – combined with the real telemetry from sensors – customers now can accurately predict and plan for a variety of scenarios without ever leaving their office.

Innovation coming to a bridge near you

Maintaining these critical pieces of infrastructure requires careful consideration of the cost involved:

The price tag of refurbishing or rebuilding a bridge.
How shutting down a bridge will affect traffic.
The impact on the environment associated with the construction.

By adding sensors to a bridge and connecting it to a digital twin model, customers now have a real-time and historical model of their bridge’s life story. They can identify the exact moment a bridge needs maintenance and possibly extend its life by decades. In addition, we can help our planet by making sure construction occurs only when necessary, which can reduce CO2e emissions.

The solution created by the University of the Bundeswehr Munich in partnership with Cisco allows for implementation of an intelligent digital twin for bridges. This model provides critical telemetry information and historical data to inform precise maintenance windows, which can reduce emissions by reducing required construction projects.

Cisco Connected Roadways

This project is part of the overall initiative to transform transportation infrastructure through Cisco solutions. Learn more about other Cisco solutions in Roadways.

Learn more

Cisco Catalyst IR1100 Rugged Series Routers
Cisco Edge Intelligence
Universität der Bundeswehr München
Cisco IoT for Roadways and Intersections

Share

  Learn how the University of the Bundeswehr Munich used Cisco technology to develop a digital twin model for bridges that predicts maintenance windows based on telemetry, reducing costs and optimizing the design of new bridges with real data rather than forecasted use.  Read More Cisco Blogs 

By |2024-01-09T22:54:13+00:00January 9, 2024|Cisco: Learning|0 Comments

February 1, 2024: A Date All Email Senders Should Care About Bradley Anstis on January 9, 2024 at 1:00 pm

For any organization sending bulk email or high email volumes to Google and Yahoo accounts, there’s one date you should have flagged on your calendar. On February 1st, guidance indicates you’ll need t… Read more on Cisco Blogs

For any organization sending bulk email or high email volumes to Google and Yahoo accounts, there’s one date you should have flagged on your calendar. On February 1st, guidance indicates you’ll need to pay attention if you are sending over 5000 emails a day into Google and Yahoo mailboxes.

So, What Is the Issue?

On that day, any email domain sending more than 5000 emails on a daily basis will need to meet a minimum set of email authentication standards along with other controls in order for email to get delivered. Those who don’t meet those standards will see their emails rejected or bouncing back. (It’s also a good time to consider how your organization deals with email bounce backs!). The standards that Google and Yahoo are asking you to meet in order to send email to their users are email authentication protocols, also known as being DMARC compliant. So many organizations are not compliant or doing a bad job when it comes to email authentication, that it’s easily allowing threat actors and scammers to spoof their domains to successfully send unwanted and malicious email to their victims, which can include employees, customers, and partners.

How Do I Become Compliant?

So, what is email authentication and how do you become DMARC compliant?  First, email authentication refers to any technique that helps detect when messages don’t actually originate from the Internet domain they claim to have been sent from. Some examples include DomainKeys Identified Message (DKIM) and Sender Policy Framework (SPF).  To be DMARC compliant means that you are publishing a DMARC policy via DNS records across all your organization’s domains and that your sending sources are correctly authenticated and aligned. DMARC passes or fails a message based on how closely the message From: header matches the sending domain specified by either SPF or DKIM. This is called alignment. A DMARC policy allows a sender to indicate that their messages are authenticated with SPF and/or DKIM and tells a receiving mail gateway what to do if neither of those authentication methods passes – such as junk or reject the message.

DMARC removes guesswork from the receiver’s handling of these failed messages, limiting or eliminating the user’s exposure to potentially fraudulent and harmful messages. DMARC also provides a way for the email receiver to report back to the sender about messages that pass and/or fail DMARC evaluation, enabling them to quickly see any instances of unauthorized usage of their domains.

Besides working with your IT team and third party senders to authenticate your email traffic with SPF and DKIM and ensuring a DMARC record with at least a policy of “none”, there are other steps you should take as outlined by Google and Yahoo; such as ensuring your sending servers have valid forward and reverse DNS; that the connections are secured with TLS 1.2 or later; that your complaint rates stay low; and that your marketing platform supports one-click unsubscribe and includes a clearly visible unsubscribe link in the message body.

While email authentication and becoming DMARC compliant might sound complex, once you understand the basic concepts it can be more straightforward, especially if you are using a DMARC implementation and reporting service like the domain protection from Cisco’s SolutionsPlus partner Red Sift. These types of tools make the entire process much simpler and with Red Sift OnDMARC, it also includes AI capabilities that help you get to your goal of being DMARC compliant much faster than other platforms. This is a project that needs to be done carefully, for example if you forget to configure any of your authorized email senders then their email could be inadvertently blocked. These issues can be eliminated when you follow a solid project plan and use a respected platform.

What Are the Benefits of These Changes?

From a market viewpoint, this is great news because with Google and Yahoo enforcing these new requirements, more organizations will be forced to become DMARC compliant. This will reduce spam and unwanted email by helping to defeat exact domain impersonation attacks. While Microsoft has not yet imposed similar guidelines, they are recommending that their customers follow Google and Yahoo’s guidance.

For email receivers, this means that the email getting into their customer’s mailboxes should be more trustworthy. This won’t eliminate all spoofing issues as you may still see scams being sent from domain typo squatting, which is where a solution like Cisco’s Secure Email Threat Defense can provide additional protection.

The biggest benefit is for the email sender, as being DMARC compliant provides much better chances of your authenticated email successfully making it to the users you want it to get to. Plus, with the DMARC reports coming back to your organization from receiving email servers, you can identify unauthorized domain usage much more quickly, so you can react appropriately.

How Can Cisco Help Me Get Started?

We are now offering a 30-day free trial of domain protection from Red Sift OnDMARC that includes a consultation at no cost. This is a great first step for any organization looking to start their journey towards DMARC compliance and meet the minimum requirements for Google and Yahoo.

Start your free trial today.

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Security on social!

Cisco Security Social Channels

InstagramFacebookTwitterLinkedIn

Share

  On February 1st, important changes will be made for bulk emails going to Google and Yahoo mailboxes. Find out why DMARC is such an important part of this guidance.  Read More Cisco Blogs 

By |2024-01-09T22:54:13+00:00January 9, 2024|Cisco: Learning|0 Comments

NRF 2024 Know Before You Go Tim Coogan on January 8, 2024 at 5:13 pm

The future of retail is coming into focus, and consumers want it fast.  

They want a convenient, personalized journey that accommodates their lifestyles and preferences. However, to deliver this s… Read more on Cisco Blogs

The future of retail is coming into focus, and consumers want it fast.  

They want a convenient, personalized journey that accommodates their lifestyles and preferences. However, to deliver this seamless, omni-channel retail experience, retailers need to unify their end-to-end value chain. 

What’s the ultimate driver for this integrated, simple retail model? Technology, partnered with data. 

NRF (National Retail Federation) is Retail’s Big Show, and it’s happening next week in New York City! This year’s theme is “Make it here and make it matter.” And what better place to showcase how technology is influence our customers’ futures? 

At Cisco, we see a bright future for retail. We are helping retailers envision their market potential by connecting the unconnected through our robust technology portfolio. We are making it matter, more than ever. 

So, are you in? 

Here’s what you need to do and what you need to know regarding Cisco at NRF 2024: 

We want to see you there! So, register for NRF! You can explore our microsite for the latest information.  
Join the conversation and visit Cisco at our NRF Booth #5639 to experience and check out what’s possible for your retail business with our secure, intelligent solutions.  
Schedule a meeting with a Cisco Subject matter expert or with me. Our team is available for onsite meetings to help discuss your specific business needs. Contact your sales representative to schedule a meeting. 
There is more for you to explore through our demo and theater sessions during the event, topics including: rich personalized engagement, loss & fraud detection, drive-thru optimization, smart facilities, behavioral insights, and many more.

See you in New York City! 

  Visit our Cisco at NRF webpage for more details on our presence at the show. 

Share

  Between customer expectations and an experience that delivers, there's a bridge. Cisco is showcasing how we help retailers thrive at NRF 2024. Here is what you need to know to register and get connected. Visit Cisco at NRF Booth #5639.  Read More Cisco Blogs 

By |2024-01-08T21:51:02+00:00January 8, 2024|Cisco: Learning|0 Comments

Easy Firewall Implementation & Configuration for Small and Medium Businesses Ian Thompson on January 8, 2024 at 8:34 pm

Big corporations are not the only ones that have to worry about cybersecurity. Small and medium businesses (SMBs) are routinely targeted to steal passwords, payment information, email content, and… Read more on Cisco Blogs

Big corporations are not the only ones that have to worry about cybersecurity. Small and medium businesses (SMBs) are routinely targeted to steal passwords, payment information, email content, and more.

A good firewall is important not only to protect your information but also your reputation. After all, your customers trust you with their data, and losing it to bad actors is no way to keep their trust. Here at Cisco, we’ve developed industry-leading firewalls designed specifically for the needs of SMBs. Our Secure Firewalls for small businesses help simplify security, with streamlined implementation at a price point that is affordable. They are also highly customizable, allowing them to scale to your needs as your company grows.

Once you have a firewall that meets your needs, you should look at implementing and configuring your firewall like you’re building an army. Sure, that might sound daunting, but it’s much easier than you think. And Cisco is here to help!

Below, we’ll outline what you need to do to implement an impenetrable firewall easily.

First, What is a Firewall?

A firewall is a piece of physical hardware or installed software that checks for incoming traffic and decides whether to block it or allow it through into your network. Imagine it as a militarized checkpoint, with a guard stationed, ready to check the credentials of everyone asking to come through.

The type of firewall you choose depends on your specific SMB needs. Maybe you want the enhanced security and flexibility a physical hardware firewall can provide. Or perhaps you’re focused on cost-effectiveness and reducing the number of devices due to limited space, which is common with software firewalls. Whichever you choose one thing to look for is that your firewall is compatible with the bandwidth your business receives. You can find this in the product’s specs, but make sure you know the maximum bandwidth your business receives and choose a firewall that accommodates your needs. Beyond that, properly setting it up is paramount, which we’ll outline below.

Implementing A Firewall — Step-by-Step

Firewall implementation is not difficult, provided you follow the steps laid out below. It should take IT a few hours to complete the process, but you should see at most fifteen minutes to an hour of downtime. Cisco Meraki firewalls offer simplified setup and management, that make setting up your firewall a breeze.

If you don’t have a dedicated IT team, managed IT services can help provide the technical assistance you need to set up your firewall. For example, Cisco Meraki gives you access to Cisco Talos’ top security analysts, who can help set up your firewall to your exact needs and provide additional security recommendations.

Establish Your DefensesFirst things first, you want to secure your firewall. This means ensuring your firewall recognizes who it should trust and blocking out all others. This will ensure hackers are turned away, and your employees and leadership have free access to communicate.

Following these simple steps below will get you there:

Update the firmware so your firewall is up to date. Delete, disable, or rename default user accounts. Also, change any default passwords to more secure ones. It’ll be embarrassing if a hacker can breeze through your firewall as “admin” using the passcode YOURCOMPANYNAME. Create a structured hierarchy of all the people you assign to manage your firewall. Limit their privileges based on their responsibilities within your company. You want to be sure who accessed what – and why. Limit the areas where people can make changes to your firewall configuration.

Wall Off Your ResourcesNext, you want to establish the important groups within your network that need the most protection. The best way to do this is to create structured network zones of assets based on their importance and level of risk. These can include things like data servers, email servers, client data, etc. These groups are often called demilitarized zones (DMZ). It’s best to create many network zones to offer the most protection throughout your network.

Keep in mind the more network zones you create, the more you’ll need to manage. Make sure to establish a well-defined IP address structure that correctly assigns these zones to your firewall interfaces and subinterfaces, which are either physical ports that connect to other devices or virtual representations that let you extend your network.

Cisco Secure Firewalls provide multi-layered defense across all networks, workloads, and applications protecting your company’s resources against cyber-attacks from all angles.

Assign Guard Stations Access Control Lists (ACLs) grant access in and out of your network zones. These act as armed guards, checking the IDs and credentials of everyone who comes through and denying those you can’t show the goods. These ACLs are applied to each firewall interface and subinterface.

ACLs must be very specific in detail, including the exact source or destination IP addresses. They should also be equipped with a “deny all” rule, which ensures you filter out any unapproved traffic into your network. Specificity here is key. Each interface and subinterface should have inbound and outbound

ACLs applied to them to authorize only the traffic you want. Finally, you should disable all firewall administration interfaces to restrict them from public access to protect your firewall configuration from prying eyes.

Set Up Additional ServicesYes, your firewall can do a bit more than just grant access. There are additional services you may want to set up depending on your network needs. Here are some common ones:

Dynamic Host Configuration Protocol (DHCP): Assigns and manages IP addresses to a specific network device.Intrusion Prevention System (IPS): Monitors traffic and scans it for malicious activities, often taking preventive actions against potential threats.Network Time Protocol (NTP): Synchs the time across all your network devices.Cisco Secure Firewalls feature customizable security allowing you to tailor your security based on specific requirements and industry standards. Gain access to cloud-based management and logging, threat defense, and remote access VPN for remote workers and clients.

Test Your DefensesNow that you’ve configured your ideal firewall, it’s time to test it to ensure everything is set up properly. You want to throw everything you have at it, including penetration testing and vulnerability scanning protocols, to see if you can find any holes in your defenses. During this time, you want to make sure you have a secure backup of your firewall configuration, just in case something goes wrong (you don’t want to lose all that hard work).

Finally – Maintain, Maintain, MaintainMaintaining a solid firewall means staying on top of it. You should ensure the firmware is up to date, check your firewall’s configuration rules every six months, and run vulnerability tests often to identify any weaknesses early and address them accordingly. This may seem like a time-consuming process, but it’s more about maintaining a routine schedule.

There’s also the issue of scalability. As your business grows, so will your security needs. Cisco has designed firewalls with security needs that adapt alongside your growing business. Stay safe across traditional, hybrid, and multicloud environments. With the help of Cisco Talos security analysts, you can always be on top of the latest security solutions, whatever your company’s size.

If you’re unsure which is the right firewall solution for you or need help boosting your current cybersecurity, our team is here to help. You can get a free trial of Cisco Meraki’s industry-leading cloud-first platform, or you can contact a Cisco expert today, and we’ll help get you on the right track.

Share

  Big corporations are not the only ones that have to worry about cybersecurity. Small and medium businesses (SMBs) are routinely targeted to steal passwords, payment information, email content, and more. A good firewall is important not only to protect your information but also your reputation. After all, your customers trust you with their data, and  Read More Cisco Blogs 

By |2024-01-08T21:51:01+00:00January 8, 2024|Cisco: Learning|0 Comments
Go to Top