How We’re Making AI Pervasive in the Cisco Security Cloud Cisco Newsroom: Security
Jeetu Patel shares the three ways Cisco is using AI [...]
Jeetu Patel shares the three ways Cisco is using AI [...]
We recently took a behind-the-scenes tour of Gillette Stadium to [...]
At Partner Summit, Cisco celebrates an unmatched global ecosystem, exciting [...]
Cisco served as Official Network Infrastructure Provider of the FIFA [...]
New integration between Cisco ThousandEyes and Amazon CloudWatch Internet Monitor [...]
I first met Nicole Hoffman, who is a Security Investigator for Cisco Talos and part of our Strategic Analysis, Threat Intelligence and Interdiction team, during the recording of the Talos IR On Air… Read more on Cisco Blogs
I first met Nicole Hoffman, who is a Security Investigator for Cisco Talos and part of our Strategic Analysis, Threat Intelligence and Interdiction team, during the recording of the Talos IR On Air Q1 2023 episode. This was a live broadcast in which we discussed the trends observed by the Talos IR team in the past quarter. Nicole’s team, among many other things, put together these quarterly threats overview. During the On Air recording, I noticed that Nicole had great camera presence and was able to articulate, what most people would consider, complex topics in a language that really anyone would understand. A techie with the gift of gab! I was immediately interested in Nicole’s path into cybersecurity and in general, as a professional.
I graduated high school and initially started a career in the medical field. I went to school to be a medical assistant, and then I started nursing school. I worked for a short time as a phlebotomist, which is a medical professional who is trained to perform blood draws on children and adults, but it was really hard for me to find a job, because my husband was in the military. This meant that we moved often, and this was not expected to change any time soon. At some point I decided to make a career change so that I could have multiple skills that would allow me to find work regardless of where we moved to. My husband, who was a network engineer in the military, already had a lot of Cisco books on CCNA and CCNP preparation. I started studying remotely, making use of all these textbooks and aiming for a career as a cybersecurity engineer. While studying for my CCNA, however, I found it quite boring. It wasn’t until I attended my first cybersecurity conference virtually that I got excited about the topic. The conference was called ATT&CKcon, and the talk that I watched showed how the MITRE ATT&CK framework helped a threat intelligence team track targeted intrusions. To be honest, I didn’t understand all of it, but I found it totally fascinating. I have never looked back.
Originally, they assumed it would be something that wouldn’t stick. I don’t think they assumed I would get as passionate about it as I am now. But my husband was very supportive, maybe partly because he knew he would save money as we already had a lot of textbooks on the topic. Besides, he had a degree in the field and has been in the industry for 20 years now. We continue to support each other. He is such a good person to have around not only as a mentor, but also if I have a question while investigating something or in an area which is outside my technical knowledge. Also, it’s nice to be able to just chat about cyber stuff at home. So yes, I think originally everyone thought it would just be a phase, and I would probably go back into medicine and continue nursing school once my husband got out of the military, but that hasn’t been the case.
I would say that after that first conference, I really enjoyed not only attending conferences in person, but also virtually. I find the research fascinating. A lot of the first jobs I had in cybersecurity were at startups with very little resources and dedicated cybersecurity staff. This meant that I rarely had a group of other threat intelligence professionals in the company that could teach me the way things are done. A lot of times it was a group of interns who were all equally lost trying to find their way through a problem. This is why I came to value people who share their research, do open-source projects, or present their knowledge at conferences. This was a chance for me to learn. I relied on open-source tooling for the bigger part of my work, and it wasn’t until I gave my first conference talk that I realized I could be one of those people who gives back to the community. It was a very heartfelt realization.
The first conference that I spoke at was GRIMMcon in 2020, which is one of my favorite conferences. I later talked at the SANS Threat hunting & Incident Response Summit, and the SANS CTI Summit in 2021 and 2023. I still find it very emotional each time I present. It is something that I look forward to, as a way to pay back and connect with the people that I look up to in our field. But the most exciting thing is that this year, I actually got to speak at ATT&CKcon in October 2023, which is the reason why I’m in threat intelligence. Together with a Talos colleague, we presented a talk about the benefits of creating your own knowledge base using ATT&CK as a taxonomy specifically for tracking adversaries over time. It is very special for me and my family to hold this presentation, closing the circle.
Don’t spend your time, money, and effort getting a bunch of certificates before you know what you really want to do. I see a lot of people come in and they immediately start getting focused on certificates. Some of those certifications cost thousands of dollars and are a big investment of your time and money. I did one of the entry-level more affordable certifications, Sec+, and it has been very useful for getting a foot in the door, but I would say, don’t spend a bunch of time and money and effort, especially if you’re going to school already. There’s only so much you can absorb, and your brain is probably already fried. Before you sign up for anything, first do your research, look at the type of things you would be doing in the job, and only search for certificates that would potentially benefit that specific role.
I would say there are two parts to it. First, if you enjoy having your own research or having your own blog. or anything that you want to share with the community (without having to necessarily ask permission or have someone edit it and change your vision), then having your own blog is super useful. Even if it has nothing to do with cyber, you could still share it with people and you could still build up a social presence.
Having this social presence, especially in the remote workforce, is a way for you to not only promote yourself, but also network with other professionals. I’ve met so many people just by writing a blog, and then someone says, ‘oh my gosh, I love this blog. It really resonated with me.’ One of my best friends in the field, John Doyle, wrote a blog about burnout, which really connected with me. When I read it, I was deep in the pit of burnout, but I was in denial. After reading that blog, I reached out to John to thank him.
The other part of keeping an active social presence has to do with skills marketability. It’s important to promote yourself, promote your own brand, especially when things do not go as planned and maybe you get laid off or the company hits hard waters. You can then always reach out to some of the people that you’ve met through networking and see if there’s anything that they can do to potentially get you a new job.
The importance of soft skills and just talking to people. When you’re first starting out in a career field, it can be very intimidating. Luckily, I had a mentor early on who would tell me ’If you really want to learn about the field, you want to learn about the different types of jobs out there or if you want to go work somewhere, talk to the people that work there. Say hey, can we go get a coffee? Can I just ask you a few questions?’
This was actually how I got my first job in cyber. I asked the CEO of a small local company if he wanted to have coffee, and he ended up hiring me while we were at the cafe. It’s really important to not forget that people are just people, even if they’re in a position of power and soft skills are really important.
We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Security on social!
Cisco Security Social Channels
InstagramFacebookTwitterLinkedIn
Meet Nicole Hoffman, a Security Investigator for Cisco Talos, who shares about her career journey in cybersecurity in this blog. Read More Cisco Blogs
You hear a lot about zero trust microsegmentation these days and rightly so. It has matured into a proven security best-practice to effectively prevent unauthorized lateral movement across network… Read more on Cisco Blogs
You hear a lot about zero trust microsegmentation these days and rightly so. It has matured into a proven security best-practice to effectively prevent unauthorized lateral movement across network resources. It involves dividing your network into isolated segments, or “microsegments,” where each segment has its own set of security policies and controls. In this way, even if a breach occurs or a potential threat gains access to a resource, the blast radius is contained.
And like many security practices, there are different ways to achieve the objective, and typically much of it depends on the unique customer environment. For microsegmentation, the key is to have a trusted partner that not only provides a robust security solution but gives you the flexibility to adapt to your needs instead of forcing a “one size fits all” approach.
Now, there are broadly two different approaches you can take to achieve your microsegmentation objectives:
A host-based enforcement approach where the policies are enforced on the workload itself. This can be done by installing an agent on the workload or by leveraging APIs in public cloud.
A network-based enforcement approach where the policies are enforced on a network device like an east-west network firewall or a switch.
While a host-based enforcement approach is immensely powerful because it provides access to rich telemetry in terms of processes, packages, and CVEs running on the workloads, it may not always be a pragmatic approach for a myriad of reasons. These reasons can range from application team perceptions, network security team preferences, or simply the need for a different approach to achieve buy-in across the organization.
Long story short, to make microsegmentation practical and achievable, it’s clear that a dynamic duo of host and network-based security is key to a robust and resilient zero trust cybersecurity strategy. Earlier this year, Cisco completed the native integration between Cisco Secure Workload and Cisco Secure Firewall delivering on this principle and providing customers with unmatched flexibility as well as defense in depth. Let’s take a deeper look at what this integration enables our customers to achieve and some of the use cases.
The journey to microsegmentation starts with visibility. This is a perfect opportunity for me to insert the cliché here – “What you can’t see, you can’t protect.” In the context of microsegmentation, flow visibility provides the foundation for building a blueprint of how applications communicate with each other, as well as users and devices – both within and outside the datacenter.
The integration between Secure Workload and Secure Firewall enables the ingestion of NSEL flow records to provide network flow visibility, as shown in Figure 1. You can further enrich this network flow data by bringing in context in the form of labels and tags from external systems like CMDB, IPAM, identity sources, etc. This contextually enriched data set allows you to quickly identify the communication patterns and any indicators of compromise across your application landscape, enabling you to immediately improve your security posture.
Figure 1: Secure Workload ingests NSEL flow records from Secure Firewall
The integration of Secure Firewall and Secure Workload provides two powerful complimentary methods to discover, compile, and enforce zero trust microsegmentation policies. The ability to use a host-based, network-based, or mix of the two methods gives you the flexibility to deploy in the manner that best suits your business needs and team roles (Figure 2).
And regardless of the approach or mix, the integration enables you to seamlessly leverage the full capabilities of Secure Workload including:
Policy discovery and analysis: Automatically discover policies that are tailored to your environment by analyzing flow data ingested from the Secure Firewall protecting east-west workload communications.
Policy enforcement: Onboard multiple east-west firewalls to automate and enforce microsegmentation policies on a specific firewall or set of firewalls through Secure Workload. (For more on this capability, Topology Awareness, read my colleague’s blog Topology Matters).
Policy compliance monitoring: The network flow information, when compared against a baseline policy, provides a deep view into how your applications are behaving and complying against policies over time.
Figure 2: Host-based and network-based approach with Secure Workload
This use case demonstrates how the integration delivers defense in depth and ultimately better security outcomes. In today’s rapidly evolving digital landscape, applications play a vital role in every aspect of our lives. However, with the increased reliance on software, cyber threats have also become more sophisticated and pervasive. Traditional patching methods, although effective, may not always be feasible due to operational constraints and the risk of downtime. When a zero-day vulnerability is discovered, there are a few different scenarios that play out. Consider two common scenarios: 1) A newly discovered CVE poses an immediate risk and in this case the fix or the patch is not available and 2) The CVE is not highly critical so it’s not worth patching it outside the usual patch window because of the production or business impact. In both cases, one must accept the interim risk and either wait for the patch to be available or for the patch window schedule.
Virtual patching, a form of compensating control, is a security practice that allows you to mitigate this risk by applying an interim protection or a “virtual” fix to known vulnerabilities in the software until it has been patched or updated. Virtual patching is typically done by leveraging the Intrusion Prevention System (IPS) of Cisco Secure Firewall. The key capability, fostered by the seamless integration, is Secure Workload’s ability to share CVE information with Secure Firewall, thereby activating the relevant IPS policies for those CVEs. Let’s take a look at how (Figure 3):
The Secure Workload agents installed on the application workloads will gather telemetry about the software packages and CVEs present on the application workloads.
A workload-CVE mapping data is then published to Secure Firewall Management Center. You can choose the exact set of CVEs you want to publish. For example, you can choose to only publish CVEs that are exploitable over network as an attack vector and has CVSS score of 10. This would allow you to control any potential performance impact on your IPS.
Finally, the Secure Firewall Management Center then runs the ‘firepower recommendations’ tool to fine tune and enable the exact set of signatures that are needed to provide protection against the CVEs that were found on your workloads. Once the new signature set is crafted, it can be deployed to the north-south perimeter Secure Firewall.
Figure 3: Virtual patching with Secure Workload and Secure Firewall
With Secure Workload and Secure Firewall, you can achieve a zero-trust security model by combining a host-based and network-based enforcement approach. In addition, with the virtual patching ability, you get another layer of defense that allows you to maintain the integrity and availability of your applications without sacrificing security. As the cyber threat landscape continues to evolve, harmony between different security solutions is undoubtedly the key to delivering more effective solutions that protect valuable digital assets.
Learn more about Cisco Secure Workload and Cisco Secure Firewall
Sign up for a Secure Workload workshop
We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Security on social!
Cisco Security Social Channels
InstagramFacebookTwitterLinkedIn
Discover the flexibility of achieving zero-trust microsegmentation with Cisco Secure Workload and Secure Firewall, combining host-based and network-based enforcement, along with virtual patching for added defense. Read More Cisco Blogs
The collaboration between Cisco and Amazon Web Services (AWS) in the Europe, Middle East, and Africa (EMEA) region—combining each company’s market leading strengths—continues to deliver impressive out… Read more on Cisco Blogs
The collaboration between Cisco and Amazon Web Services (AWS) in the Europe, Middle East, and Africa (EMEA) region—combining each company’s market leading strengths—continues to deliver impressive outcomes for our customers, notably within the Financial Services Industry (FSI).
This success has not gone unnoticed, as demonstrated by two partnership accolades awarded in recent weeks.
During Cisco Partner Summit 2023 in November, AWS was honored as the Cisco Co-Sell Partner of the Year, both globally and in EMEA.
This award is a testament to both companies’ relentless efforts to deliver top-notch performance for our customers, also evidenced by our triple-digit co-sell growth with AWS. Our co-sell motions are dedicated to the optimal, secure deployment and operation of our customers’ hybrid cloud environments.
In addition to our partnership and functioning as one team, we leverage our extensive range of technologies and services to help ensure our mutual customers enjoy outstanding experiences that meet and surpass their desired outcomes.
Later that same month, Cisco was recognized as the AWS Global ISV Partner of the Year, at AWS Re:Invent 2023, reflecting our outstanding ability to collaborate and innovate in a variety of ways.
The full range of Cisco software—security, observability, networking, and collaboration—is now globally available through AWS Marketplace. These software offerings include Cisco Enterprise Agreements (EAs), enabling consumption across our comprehensive portfolio and providing our customers the choice of where they purchase Cisco software.
Notably, selling through AWS Marketplace has boosted win rates by up to 27%. Customers appreciate this model for its simplified procurement, provisioning, and deployment of SaaS solutions in the cloud, resulting in an 80% increase in spending on third-party ISV applications in the AWS Marketplace.
Additionally, buying Cisco software through AWS marketplace allows customers to effectively utilize their Enterprise Discount Program (EDP) commitments, as budget spent on Cisco software can be directly applied—on a dollar-for-dollar basis—toward fulfilling EDP commitments.
The Cisco and AWS partnership was also showcased in October 2023, at the Cisco and AWS Roadshow in Dubai. That event spotlighted the dynamic synergy between the two industry leaders, drawing a diverse, engaged crowd from industries like Financial Services and Retail and from the public sector. Those sectors, in which Cisco and AWS both have significant influence, highlight the broad scope and powerful impact of our alliance.
For example, there has been a notable shift in banking operations from traditional branches to online and mobile platforms in the EMEA region. Despite this, the broader Middle East and Africa (MEA) region still encompasses approximately 59% of adults without bank accounts, representing a substantial untapped market. The financial technology sector in MEA is expected to surpass US$3.45 billion by 2026. To help meet that need and capitalize on the opportunity, the Cisco and AWS partnership merges Cisco expertise in networking, security, observability, and infrastructure solutions with AWS prowess in cloud services and data analytics.
The Cisco and AWS partnership enables organizations to bolster their security posture, improve digital experiences and application performance, increase operational agility, streamline processes, and leverage data for innovation. By modernizing and fortifying their technological infrastructure, companies can maintain compliance with industry-specific regulations while simultaneously improving their agility and operational efficiency.
The Cisco and AWS collaboration is revolutionizing operations and establishing new benchmarks in the FSI and other industries. Harnessing our collective “greater together” expertise, we’re helping our customers—including those within the EMEA region, such as the United Kingdom and Ireland (UKI), Northern Europe, and MEA—redefine their business landscape, foster renewed innovation, and lead the charge toward a future that is more secure, agile, and directed through data-derived insights.
We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with #CiscoPartners on social!
Cisco Partners Facebook | @CiscoPartners X/Twitter | Cisco Partners LinkedIn
The collaboration between Cisco and Amazon Web Services (AWS) in the Europe, Middle East, and Africa (EMEA) region—combining each company’s market leading strengths—continues to deliver impressive outcomes for our customers, notably within the Financial Services Industry (FSI). Read More Cisco Blogs
IT leaders face the challenge of managing a growing set of often disparate technologies and successfully delivering them to a wide audience of end users who demand simple experiences. However,… Read more on Cisco Blogs
IT leaders face the challenge of managing a growing set of often disparate technologies and successfully delivering them to a wide audience of end users who demand simple experiences. However, today’s technology landscape is complex and fragmented.
Simplifying IT requires us to rethink our processes and what we mean by “experience.”
Unified experiences show us what’s possible when technologies, applications, and networks all work as one. Simplifying the end-to-end journey, which includes back-end systems and end-user experiences, comes with challenges, risks, and opportunities.
With insights from a panel of cross-sector IT leaders, we can examine what we’re simplifying and how that leads to superior experiences.
Whether driven by internal or external forces, innovation typically results in more systems and greater complexity. A closer look often reveals a patchwork of new and legacy systems that are burning through budgets, confusing customers, and squeezing profits.
A big part of this complexity stems from backward compatibility with legacy systems. It’s not so much a matter of redundant old systems taking up valuable resources, but rather maximizing value and operations efficiency across both old and new systems. This challenge lies at the heart of simplifying IT.
Graeme Howard, former CTO and CIO of Covea Insurance, points to legacy systems as a challenge for his organization’s digital transformation. “We built out a huge number of new platforms and new functionality, but we also had many legacy platforms that were far too expensive to change.”
In the process of driving customer experience, hyper-personalization, and data enrichment, legacy systems can pose a significant obstacle. Graeme encourages leaders to persevere and push through such challenges.
Focus on first impressions, Graeme argues. If it’s difficult for a customer or internal user to log onto a system or buy a product, that could mean losing customers and business.
Simplifying IT for better experiences isn’t just about hiding the complexities of our processes from the customer. It’s also about including customers in the design of those experiences. Whether starting from scratch or taking on a complex project of integrating new and legacy systems, IT can no longer dictate to the user.
Instead of relying on customers to create their own demand for our products and services, Archana Jain, CTO at Zurich Insurance Group, understands simplifying IT as the opportunity to reach insurance customers with products and services, when and how they need them. Alongside traditional methods of insurance, she poses a simple question to get her industry thinking: “Can we offer [customers] insurance when they need it, as opposed to having something static forever and forever?”
For example, if a customer wants to go on holiday, instead of a lengthy process of booking travel insurance for flights, hotels, and car rentals, Jain suggests simplifying that experience through a partner so the customer can buy insurance with one click. That thinking conceptualizes travel insurance within the customer’s travel-planning journey, not as a stand-alone task. It’s a win for everyone.
As IT leaders, we can be nimble in how we lead digital transformation. For superior experiences, how we responsibly simplify IT must extend to how we manage risk. Change for the sake of change, or moving too fast for stakeholders to keep up, can expose organizations to unnecessary risk.
Technologists leading successful IT simplification strategies can balance business value, business case, and legacy systems. Joanna Pamphilis, UniCredit’s Senior Vice President and CDIO, is one such leader. She believes organizations should be practical about the need to eliminate legacy systems, and deliver value while leading responsible change.
Jain at Zurich Insurance Group says operational alerts are a great example of how technology that is designed to improve a process can, ultimately, complicate it. How often do we hear stories of overburdened IT operations teams with piles of server, network, device, and security alerts (among others) with no way of sorting the high priorities from the quick fixes from the FYIs? But technology is also the answer to simplifying that same operation without completely unravelling the infrastructure.
According to Jain, Zurich Insurance Group’s IT operations team were handling thousands of alerts designed to pick up events like server issues. Ironically, the technology deployed to manage risk created the risk of not having the human resources to investigate every alert—and the risk of an unreliable user experience. To solve this challenge, Zurich now uses artificial intelligence (AI) to filter out the unnecessary alerts so their IT operations team can better focus on actionable items.
Consolidating customer, employee, and other types of data is a critical step in becoming proactive about risk and the customer experience, according to Ronald Martey, CISO at GCB Bank. He wants leaders to investigate different elements and systems, and ask, “What kind of data can I move onto the cloud that will not impact privacy and security regulations?”
From pioneering digitalization to pivoting to hybrid work, every era of digital transformation has been about optimizing organizations’ need to serve customers and grow businesses efficiently, reliably, and safely.
The process of simplifying IT requires us to assess our entire business, from customer interactions to back-end systems, and the role of data. It’s about rethinking our traditional methods and modernizing them, without the rush to rip out and replace everything.
The era of simplifying IT will test you, just like every era before it did, but the ultimate reward of a more simplified IT infrastructure is unified experiences that connect your customers and teams through technologies, applications, and networks that all work as one.
In today’s increasingly complex and fragmented technology landscape, organizations must deliver experiences that are reliable, secure, and seamless. Read More Cisco Blogs
DNS is often the first step in the cyber kill [...]