About (Edit profile)

This author has not yet filled in any details.
So far has created 1829 blog entries.

Meet the Cisco Security Risk Score (formerly Kenna Risk Score) Katie Webster on December 14, 2023 at 1:00 pm

In April 2023, we rebranded our risk-based vulnerability management solution, Kenna.VM, to Cisco Vulnerability Management. Today, we are excited to share another milestone in our journey. Effective… Read more on Cisco Blogs

In April 2023, we rebranded our risk-based vulnerability management solution, Kenna.VM, to Cisco Vulnerability Management. Today, we are excited to share another milestone in our journey. Effective immediately, the Kenna Risk Score is renamed to the Cisco Security Risk Score. Additionally, Kenna.VI (and Kenna.VI+) is renamed to Cisco Vulnerability Intelligence, and Kenna.AppSec is renamed to Application Security module.

Cisco Security Risk Score

To strengthen cohesion with the Cisco brand and enhance the user experience, the Kenna Risk Score has a new name: the Cisco Security Risk Score. Despite the new name, the original technology, advantages, and effectiveness of the former Kenna Risk Score will persist and continue to be a crucial component of our risk-based vulnerability management solutions.

The Cisco Security Risk Score (formerly Kenna Risk Score) integrates with Cisco Vulnerability Management’s predictive model to calculate risk scores for each vulnerability. Alongside asset criticality scores, it formulates an actionable risk score from zero (no risk) to 1,000 (maximum risk).

The system factors in both internal and external variables as potential risk indicators. Internal factors consider the frequency, severity, and criticality of each vulnerability within an organization’s environment. External factors consider the CVSS score, the Exploit Prediction Scoring System (EPSS), threat and exploit intelligence data from more than 19 different threat and exploit feeds to determine exploit kit availability, exploit volume and speed, and the vulnerability’s prevalence.

The primary advantage of the Cisco Security Risk Score is its ability to provide accurate risk assessments for vulnerabilities, which empowers you to fully comprehend your organization’s current risk profile and pinpoint the steps you can take to mitigate the most substantial risks. With these insights, your organization can confidently prioritize the vulnerabilities that matter most and significantly enhance its security posture. Learn more about the Cisco Security Risk Score here.

Cisco Vulnerability Intelligence and Application Security module

The remaining Kenna products, Kenna.VI (and Kenna.VI+) and Kenna.AppSec, will be rebranded as Cisco Vulnerability Intelligence and Application Security module, respectively.

Cisco Vulnerability Intelligence (formerly Kenna.VI) gives security teams access to the industry’s richest consolidation of vulnerability intel via UI and API. Cisco Vulnerability Intelligence incorporates rich CVE data from more than 19 threat and exploit intel feeds, including custom-curated sources. Organizations can access these records via an API to use within their existing vulnerability management workflows, or they can search and review CVE data within a user interface (UI). Cisco Vulnerability Intelligence can be purchased standalone or as part of Cisco Vulnerability Management Premier.

The Application Security module (formerly Kenna.AppSec) allows you to proactively manage risk across your applications. This is available as an add-on to Cisco Vulnerability Management.

These new names align our functionality to the broader Cisco Security portfolio, bringing clarity and brand consistency to Cisco Vulnerability Management features and offerings.

Impact of this Change

With these rebranding updates, you’ll start seeing the new names outlined in the blog post mirrored on our webpage, promotional materials, and documentation.

If you’re an existing customer of Cisco Vulnerability Management, Cisco Vulnerability Intelligence (formerly Kenna.VI and Kenna.VI+), or using the Application Security module (formerly Kenna.AppSec), rest assured that these name changes will not impact your experience or the trusted solutions you depend on.

For assistance with product documentation, customer support, or API documentation, we encourage customers to continue using help.kennasecurity.com. This page will remain active until further notice. We thank you for your ongoing support!

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Security on social!

Cisco Security Social Channels

InstagramFacebookTwitterLinkedIn

Share

  This blog details the renaming of Kenna products and features to Cisco-branded names.  Read More Cisco Blogs 

By |2023-12-14T16:52:40+00:00December 14, 2023|Cisco: Learning|0 Comments

Building inclusive AI will accelerate innovation Mary Fernandez on December 13, 2023 at 4:41 pm

This post was authored by Mary Fernandez, Cisco global lead for disability and neuro-inclusion.

Often when we talk about promoting inclusion of disabled and neurodivergent people in society we… Read more on Cisco Blogs

This post was authored by Mary Fernandez, Cisco global lead for disability and neuro-inclusion.

Often when we talk about promoting inclusion of disabled and neurodivergent people in society we exclusively focus on work and education. While equitable access to education and employment are fundamental to participating in society, life isn’t and shouldn’t be just about work.

For example, I’m a newly single blind woman engaged in online dating. As I’m browsing profiles, I want to participate in this amusing, exciting, and sometimes treacherous part of life as fully as anyone else—and that includes wanting to know if my prospective matches’ profile pictures contain any metaphorical red flags. And you may think that because I’m blind, I don’t care about the aesthetics. If so, you would be wrong. For instance, while I appreciate that a shaved head paired with a full luscious beard is the preference for many, it is not the aesthetic for me.

In recognition of International Day for Persons with Disabilities, which is celebrated annually on December 3, I want to offer food for thought as we lean into technological advances. You see, online dating, AI, accessibility and disability are all closely linked, and if done right will lead to innovative applications which may seem unimaginable.

“Building inclusive AI isn’t about inhibiting speed. It’s about accelerating innovation.”

Accessibility Meets AI

Mary visiting the Louvre Museum in Paris

Back to online dating. Pictures supposedly convey 1000 words, which is why online dating is so inherently visual. One picture tells us about someone’s spirit so deeply we will know if we want to spend 30- plus years with them. So, my dilemma: how do I participate in this social experiment?

One way for me to do that is to use a mobile app that connects blind and low-vision individuals with sighted volunteers through a live video call. I can open the app and ask a sighted person to describe someone’s profile picture.

While this approach is a great improvement over not having any information, it doesn’t give me freedom to participate autonomously in the rich social tapestry we call life. Plus, do you really want to involve a third party to judge how shallow you are based on your swiping directionality? Neither do I!

So that’s where I got creative and leveraged the biggest technological shift in a generation—artificial intelligence (AI). Through a rather cumbersome, but judgment-free process, I take screenshots, run it through an AI-powered image description app, and voila. Man sitting in car with sunglasses, a baseball hat in the dark? Left please.

Disability: The Great Shared Human Experience

My online dating journey certainly is amusing. However, there are deeper implications. Think about how the world treats and includes—or doesn’t—people with disabilities. Even if you are not disabled today, there will almost certainly come a day when you are. You might spend 6-12 weeks using crutches while the leg you broke skiing heals. Or maybe it’s that you will experience the slow progression of a degenerative condition that unfolds over time.

Short-term or life-long, disability is going to be part of the fabric of your life at some point.

Building a World with Disabled Communities

How we harness the power of AI to design a more equitable world for people with disabilities becomes a question of who is building AI and how they are building it.

In most aspects of society, disabled people have been relegated to the sidelines, and seldom expected to be in or promoted to decision-making roles. The narratives we commonly hear about disability and the disabled experience are often informed by non-disabled people who hold deep bias and fear around this topic.

Let’s try a little thought experiment. Picture a disabled woman in your mind right now.

I’m going to guess that the first image to pop into your mind is probably not that of a vivacious, fashion-forward woman of color strutting with her white cane through the streets of Washington, DC, sporting her favorite burnt orange booties. And you certainly will not picture her online dating profile, because we do not associate disability as part of the human experience, but rather as “other.”

Here’s another experiment. What do you think happens when you ask an AI image-generator to create pictures of disabled people?

As one commentator I recently heard speak said, the answer is, “You get a bunch of sad-looking white guys in wheelchairs.”

That served as a bit of a laugh line in his presentation, but it was uncomfortable laughter, because we know why generative AI engines produce images like that. We get out of AI what we put into it. And right now, a lot of bias and assumptions are integrated into it.

The result is that the AI we’re expecting to enrich all our lives, instead may be a promoter of harmful narratives and stereotypes of marginalized communities.

One of these erroneous narratives is that inclusion of disabled and neurodivergent communities inherently equates to slowing progress and innovation: further, that this inclusion may negatively impact the quality of the result to something “less than.”

In our industry, speed has been regarded as one of the defining factors for success and profitability. Hence, the value of inclusion of marginalized communities is in direct contrast to what is seen as a competitive advantage. The data tells us that this is far from the truth. In fact, inclusion of disabled and other marginalized perspectives, rather than being a hindrance, results in outperforming the competition.

But stories and images are powerful. The narratives we breathe in from the moment we are children are hard to dismantle even when we see the numbers. Data isn’t enough to move the needle. Instead, focusing on proactive learning, engagement with the disability community, promotion of disabled and neurodivergent individuals into decision-making positions, and appreciation for and of the time of disabled people, paired with storytelling is truly what can break the biases built into our neural networks.

Inclusion Powers Innovation

Disabled and neurodivergent people live in a world that is not designed for us. So, we create solutions. In fact, some of your most beloved technological advancements were developed by disabled people when we had to find a solution to further participate in day-to-day life.

Did you know that the keyboard on your desk, the electric toothbrush you are hopefully using, and all dictation features across your devices, along with being able to speak with your home assistants, were all results of innovation driven by the needs of the disability community?

Revolutionary technological advances are meant to break rather than build barriers, build connection rather than disconnection, and increase enjoyment, fun and productivity rather than take them away. And while the creativity and needs of the disabled community have launched innovations that make all our lives easier and richer—audio books, anyone?-—many of the technical advances today are excluding and leaving behind disabled and neurodivergent users, because there is a lack of intentionality in building accessible advances which serve all.

I wonder if in our desire for speed we’ve forgotten that to speed up, to create and innovate, sometimes we must pause and wonder, who else can we serve? Technological advances that last and don’t just become an amusing memory in two to three years are those which serve so many people that we cannot imagine our lives without them. Knowing that disability will impact us all at some point in life, thoughtfulness about designing a more accessible world logically follows as a step to creating those kinds of meaningful advances. This is why inclusive AI is so crucial.

So, let’s flip the narrative. Building inclusive AI isn’t about inhibiting speed. It is about accelerating innovation.

Powering an Inclusive Future for All

Cisco’s Connected Disability Awareness Network (CDAN) lit up Cisco buildings globally in recognition of #PositivelyPurple and International Day of Persons with Disabilities

Through the tireless work of disabled advocates, the United Nations recognized how deeply disability is intertwined with humanity when it first proclaimed December 3, as International Day of Persons with Disabilities more than 30 years ago.

This year, the theme for IDPWD was “United in action to rescue and achieve the sustainable development goals for, with and by persons with disabilities.”

Celebration is stopping to acknowledge and feel joy and pride in all that we have accomplished. Yes, you may celebrate having to yell at your Alexa today because it didn’t understand what you asked and went off on a tangent. Know that the same home assistant helped someone turn on their oven because we did not build touch screens with motor disabilities in mind.

But celebration is also a commitment to growth, to saying, “Where do we go next and how do we do it better?” Designing with the disability community, prioritizing accessibility from the moment you think of an idea, actively including those of us who interact with the world differently, that’s how we truly celebrate and honor difference.

Artificial intelligence is the biggest development in tech in a generation. It has the power to make our world a more inclusive place. Now is the time for everyone involved in AI to commit to building it for, with, and by persons with disabilities—then maybe someday it will power full inclusion. Plus make it more efficient for me to decide whether to swipe right or left as I seek a life partner.

Share

  Artificial intelligence is the biggest development in tech in a generation. It has the power to make our world a more inclusive place. How we harness the power of AI to design a more equitable world for people with disabilities becomes a question of who is building AI and how they are building it.  Read More Cisco Blogs 

By |2023-12-14T04:50:16+00:00December 14, 2023|Cisco: Learning|0 Comments

(20)24 x 7 Tech Trends: AI Readiness, Adoption and Integration Liz Centoni on December 13, 2023 at 6:00 pm

Technology continues to evolve at an unprecedented pace and predictions about coming trends are always a topic of debate – what’s real, what’s hype.

While there’s always a wave of excitement around th… Read more on Cisco Blogs

Technology continues to evolve at an unprecedented pace and predictions about coming trends are always a topic of debate – what’s real, what’s hype.

While there’s always a wave of excitement around the next big thing, I think the last year has been different. Advancements in AI, especially generative AI (GenAI), are leading to a once-in-a-generation shift. This is opening vast new opportunities and transforming industries, modes of operation, and career paths.

Not surprisingly this year, I’ve got lots on AI with predictions that are filled with “Automated Inspiration.”

The Cisco AI Readiness Index revealed that 95% of respondents have an AI strategy in place or under development, but only 14% are fully ready to integrate AI into their business. What will it take for organizations to adopt and integrate AI? How can innovators leverage change to remain competitive? Where and how will innovation and trust intersect?

These insights and questions have inspired my predictions for coming tech trends in 2024.

1. GenAI will fast expand into the business world with GenAI-powered NLIs, customized LLMs, tailored B2B applications and business context.

Natural language interfaces (NLIs) powered by GenAI will be expected for new products and more than half will have this by default by the end of 2024. GenAI will also be leveraged in B2B interactions with users demanding more contextualized, personalized, and integrated solutions. GenAI will offer APIs, interfaces, and services to access, analyze, and visualize data and insights, becoming pervasive across areas such as project management, software quality and testing, compliance assessments, and recruitment efforts. As a result, observability for AI will grow.

We will also see the rise of specialized, domain-specific AI models and a shift to smaller, specialized LLMs with higher levels of accuracy, relevancy, precision and niche domain understanding. For instance, LLaMA-7B models – often used for code completion and few-shotting – will see increasing adoption. Moreover, multi-modality combination of various data types such as images, text, speech, and numerical with intelligence processing algorithms will expand B2B use cases. This will result in better results in areas such as business planning, medicine, and financial services.

2. A movement for responsible, ethical use of AI will begin with clear AI governance frameworks that respect human rights and values.

Adoption of AI is a once-in-a-generation technology shift and it is sitting at the intersection of innovation and trust. Yet, 76% of organizations don’t have comprehensive AI policies in place. There is mostly general agreement that we need regulations/policy and industry self-policing and governance to mitigate the risks from GenAI. However, we need to get more nuanced, for example, in areas like IP infringement, where bits of existing works of original art are scraped to generate new digital art. This area needs regulation.

We must also ensure that consumers have access to and control over their data in the spirit of the recent EU Data Act. With the rising importance of AI systems, available public data will soon hit a ceiling and high-quality language data will likely be exhausted before 2026. Organizations need to shift to private and/or synthetic data which opens the possibility for unintended access and usage.

There is plenty that organizations can do on their own. Leaders must commit to transparency and trustworthiness around the development, use, and outcomes of AI systems. For instance, in reliability, addressing false content and unanticipated outcomes should be driven by organizations with RAI assessments, robust training of LLMs to reduce the chance of hallucinations, sentiment analysis and output shaping. In 2024, we will see companies of every size and sector formally outline how responsible AI governance guides internal development, application, and use of AI. Until tech companies can credibly show they are trustworthy, you can anticipate governments creating more policies.

3. Consumers and companies will face increased risks from AI-generated disinformation, scams, and fraud, prompting tech companies and governments to work together for solutions.

In 2024, AI-enabled disinformation, scams, and fraud will continue to grow as a threat to businesses, people, and even candidates and elections. In response, we’ll see more investments in detection and risk mitigation. Inclusive new AI solutions will guard against cloned voices, deepfakes, social media bots, and influence campaigns. AI models will be trained on large datasets for better accuracy and effectiveness. New mechanisms for authentication and provenance will promote transparency and accountability.

In keeping with the G7 Guiding Principles on AI regarding threats to democratic values, the Biden administration’s Safe AI Executive Order, and the EU AI Act, we’ll also see more collaboration between the private sector and governments to raise threat awareness and implement verification and security measures. We’ll see cooperation to sanction rogue actors and ensure regulatory compliance. Businesses must prioritize advanced threat detection and data protection, regular vulnerability assessments, updating security systems, and thorough audits of network infrastructures. For consumers, vigilance will be key to protecting identities, savings, and credit.

4. Quantum progress but not quantum leaps as the future of cryptography and networking will continue to take shape.

We will see adoption of post-quantum cryptography (PQC) – even before it is standardized – as a software-based approach that works with conventional systems to protect data from future quantum attacks. PQC will be adopted by browsers, operating systems, and libraries, and innovators will experiment by integrating it into protocols such as SSL/TLS 1.3 which governs classic cryptography. PQC will also start to trickle down to enterprises as they aim to ensure data security in the post-quantum world.

Another trend will be the growing importance of quantum networking which in 4 or 5 years – perhaps more – will enable quantum computers to communicate and collaborate for more scalable quantum solutions. Quantum networking will leverage quantum phenomena such as entanglement and superposition to transmit information. QKD as an alternative or a complement to PQC depending on the level of security and performance required, will also leverage quantum networking. Quantum networking will see significant new research and investment by government and financial services which have high demands for data security and processing.

5. Unleashing the future of AI-driven customization, enterprises will embrace the power and potential of API abstraction.

In the year ahead, businesses will seek innovative ways to leverage the immense power and benefits of AI without the complexity and cost of building their own platforms. Application programming interfaces (APIs) will play a pivotal role. APIs will increasingly act as an “abstraction layer” – seamless bridges that integrate a multitude of pre-built AI tools, services, and systems with little development or infrastructure setup. With access to a vast array of AI capabilities through APIs, teams will automate repetitive tasks, gain deeper insights from data, and enhance decision making.

This year will also mark the beginning of a race to API-driven customization where organizations can choose and combine APIs from various providers, easily tailoring AI solutions to meet unique and novel requirements. Flexibility and scalability will foster effortless collaboration with external AI experts, startups, and research institutions, fueling an exchange of ideas and breakthrough advancements. In fact, these curated “model garden” ecosystems are already taking shape and in 2024 we’ll them really take off

6. You can’t greenwash AI – advancements will drive even more energy usage while unlocking new energy networking and efficiency paradigms.

Sustainable energy plays a vital role in addressing climate change. Selecting smaller AI models with fewer layers and filters specific to use cases, companies will begin to reduce energy consumption costs compared to general systems. These dedicated systems are trained on smaller, highly accurate data sets and efficiently accomplish specific tasks. In contrast, deep learning models use vast amounts of data.

The fast-emerging category of energy networking, which combines the capabilities of software-defined networking and an electric power system made up of direct-current micro grids, will also contribute to energy efficiency. Applying networking to power and connecting it with data, energy networking offers comprehensive visibility and benchmarking of existing emissions and an access point for optimizing power usage, distribution, transmission, and storage. Energy networking will also help organizations measure energy usage and emissions more accurately, automate many functions across IT, smart buildings, and IoT sensors, and unlock inefficient and unused energy. With embedded energy management capabilities, the network will become a control plane for measuring, monitoring, and managing consumption.

7. ‘Shift left’ will yield collaboration, modern converged platforms, and a little help from AI, to reveal a new programming experience – and better software.

As organizations continue to “shift left”, software development will change with novel tools, approaches, and technologies. Programmers will leverage platforms and collaboration – and even a little help from AI – to centralize toolkits and unlock newfound efficiency so they can focus on delivering exceptional digital experiences. For instance, they’ll wield CNAPP, cloud security posture management (CSPM), and cloud workload protection platforms (CWPP) to combat tool sprawl, streamline workflows, and eliminate the burden of managing disjoined tools.

Some will continue struggling with disparate point solutions, leaving security gaps and software supply chain issues. Innovators will use AI to speed up delivery and handle tedious tasks like testing for defects and errors. Along the way, collaboration tools and AI assistants will be trusted companions as teams tackle the intricacies of security, observability, and infrastructure. They will also use AI-derived insights to navigate the intricacies of components, protocols, and tools. Humans checks and balances must ensure AI-based decisions are fair, unbiased, and aligned with ethical and moral values. We believe AI should augment human decision making, not replace it entirely.

AI has emerged as both a catalyst and a canvas for the future. It’s already in our homes, our cars, our offices – and in our pockets. As we marvel at the progress we’ve made in a short time, we must also balance the benefits and the risks.

Trust between people and the AI systems and tools they use is fundamental and non-negotiable. That means providing clarity on what AI can and cannot do with new data transparency and responsibility frameworks, new efforts to educate people and businesses about how disruption might happen, teaching the skills that will be needed for new AI-enabling and -enabled jobs, and new ways to collaborate with the best interests of people at heart.

It’s an exciting time. I look to the year ahead with a sense of optimism and awe based on my deeply held belief that trust is the necessary ingredient for every new tech wave to take hold. What’s good for the world is good for business. Together, let’s advance the promise of AI with confidence.

Explore the Cisco AI Readiness Index 

Share

  In just the past year, AI’s impact accelerated in startling ways. Many businesses are struggling to keep up, so Cisco is highlighting seven tech trends we expect to see in 2024 — and AI is integral across them all. Explore the novel ways in which you can leverage AI to unlock access, create business agility and deliver exceptional experiences.  Read More Cisco Blogs 

By |2023-12-14T04:50:15+00:00December 14, 2023|Cisco: Learning|0 Comments

Cybersecurity career training for the real world Mary Kate Schmermund on December 13, 2023 at 1:00 pm

Riccardo Nobili’s passion for cybersecurity career training is palpable. Not only is Nobili the Head of Network at Leroy Merlin, a global home improvement and gardening retailer, but he is also a Read more on Cisco Blogs

Riccardo Nobili’s passion for cybersecurity career training is palpable. Not only is Nobili the Head of Network at Leroy Merlin, a global home improvement and gardening retailer, but he is also a Cisco Networking Academy instructor where he enables students to become future cybersecurity defenders. If you’re also passionate about cybersecurity, check out our open opportunities.

Scalable: Networks and student growth

As the Head of Network at Leroy Merlin, Nobili is accountable for all parts of the network being up and running. To do this, Nobili must ensure that the infrastructure is scalable and monitored with his team. “The network is fundamental for us and we have to guarantee it,” he said.

 “One of the best investments a person can make is specializing in cybersecurity.”
– Riccardo Nobili

Trained as a network engineer, Nobili’s interest in cybersecurity expanded with advances in firewalls. His passion led him to teach internal courses at Elmec Informatica, where he worked as a consultant, for technicians who wanted to learn more about the inner workings of their systems. Leading these courses awakened an interest in teaching for Nobili who is driven by the progress of his students. By imparting his wisdom in those courses, Nobili felt prepared when Cisco Networking Academy invited him to share his knowledge as an instructor in 2014.

Cybersecurity career training from real world experience

Nobili is particularly satisfied when students who begin his course without technical fundamentals leave with comprehensive knowledge to troubleshoot networking challenges. What differentiates the education Cisco Networking Academy provides? “All the teachers are people like me, working professionals with real life experiences,” Nobili said.

“All the teachers are people like me, working professionals with real life experiences.”
– Riccardo Nobili

Because of that experience, teachers can instruct from their real world, day-to-day knowledge. Drawing from relevant business and enterprise expertise, instructors inform their students of the challenges and solutions they face on a daily basis.

Nobili explained that in university, students may only be taught from a standard and potentially outdated curriculum. However, at the Cisco Networking Academy, the gap between study and work is lessened. He also finds benefit in the community of learners and instructors who share relevant tips in the Cisco forums and community portals.

Want to join the security field?

To fully prepare for the cybersecurity field, Nobili believes it’s essential to have a complete understanding of how the infrastructure works and how it’s connected. Nobili suggests gaining a general view of IT and networking before specializing. He recommends deepening your expertise in cybersecurity only after understanding how all the components work independently and together.

“Security is one of the most important fields that exists.”
– Riccardo Nobili

“Security is one of the most important fields that exists and is always expanding as the systems become more complex and infrastructure more critical,” Nobili said. “One of the best investments a person can make is specializing in cybersecurity.”

Pursue your cybersecurity passion

If you’re ready to pursue your passion for cybersecurity in a meaningful way, visit our open roles.

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Security on social!

Cisco Security Social Channels

InstagramFacebookTwitterLinkedIn

Share

  Learn directly from Cisco Networking Academy instructor, Riccardo Nobili, about the best ways to prepare for the cybersecurity field.  Read More Cisco Blogs 

By |2023-12-13T16:02:55+00:00December 13, 2023|Cisco: Learning|0 Comments

Cisco XDR: SLEDs “SOC in a Box” Norman St. Laurent on December 13, 2023 at 1:00 pm

For State, Local, and Education (both Higher Ed and K-12) (SLED) entities the Security Operations Center (SOC) is a required tool in the toolbox and a necessity for Cyber Insurance.  Threats to data … Read more on Cisco Blogs

For State, Local, and Education (both Higher Ed and K-12) (SLED) entities the Security Operations Center (SOC) is a required tool in the toolbox and a necessity for Cyber Insurance.  Threats to data and information are ever evolving, and better safeguarding the security of SLED entities is a must.

The cornerstone of a robust defense is the SOC. In this blog, we’ll explore how Cisco XDR simplifies and enhances the operations of SLED-focused SOCs, helping them achieve security and resilience goals in an open and collaborative manner.

Watch the following video to learn more about Cisco XDR:

Cisco XDR: A Game-Changer for SLED Entities – A “SOC in a Box”

State and local governments, along with educational institutions, have increasingly become targets for cyber threats. These threats have the power to cause significant damage, and now use tactics and techniques that were once reserved for high-value targets.  Cyberattacks like malware, ransomware, and phishing are increasing, and with 100,000 different local, state, law enforcement, tribal, townships, cities, municipalities, and county governments cyber criminals have a very big landscape to choose from in SLED. Current security tools struggle to detect and investigate sophisticated threat actors like BlackTech, Volt Typhoon or Wizard Spyder. Funding constraints also pose problems in SLED environments. This creates a situation where some of these entities are viewed as ripe for the picking by threat actors.

Built for SecOps pros by SecOps pros

Cisco XDR is a unified threat detection, investigation, mitigation, and hunting solution that integrates the entire Cisco security portfolio and select third-party tools – endpoint, email, network, and cloud, along with superior threat intelligence. Your teams can now go from endless investigation to remediating the highest priority incidents with greater speed, efficiency, and confidence.

According to Security Intelligence, the number of cyber-attacks targeting government agencies increased by 95% in 2022 compared to the previous year.  The article also notes that in 2022, 89 education sector organizations fell victim to ransomware attacks impacting 45 school districts and 44 colleges and universities.

Tight budgets within SLED limit their ability to build adequate defense in depth.  Cisco XDR can quickly help provide a comprehensive solution that protects SLED environments against evolving cybersecurity challenges. By integrating detection and response capabilities, Cisco XDR simplifies SOC operations, enabling proactive threat mitigation.

Cisco XDR is an affordable unified security solution that integrates and correlates data from multiple security products across an organization’s networks, cloud, endpoints, email, and applications.  It is a “SOC in a Box” that helps security operation teams to detect, prioritize, and respond to threats efficiently.

The Growing Need for Extended Detection and Response

Agencies and departments now use more devices, applications, and tools than ever before, and this complexity has created a persistent and growing security challenge.   The typical SLED detection and response model is built upon self-contained point security solutions, which are pieced together and require lots of staffing resources to maintain.  To this point, these traditional security measures are no longer sufficient to combat advanced threats. SLED entities need an XDR approach that goes beyond mere detection. Security leadership and their teams are demanding better efficacy, experience and higher ROI.

Cisco XDR steps in as the all-inclusive solution for identifying, investigating, and remediating threats. Cisco XDR is comprehensive, providing prioritized and contextualized telemetry, and actionable insight on what steps can be immediately taken. Cisco XDR improves visibility and creates true context across an environment, while enabling unified detection from a single investigative viewpoint that supports fast accurate threat response. Cisco XDR also elevates productivity even further through automation and orchestration, and includes other advanced user-friendly SOC necessities such as:

Playbook driven automation
Guided incident response
Threat hunting
Alert prioritization, and
Breach pattern analysis.

This “SOC in a Box” immediately gives SLED SOC environments improved advanced threat detection, response efficiency, and investigation powers.

Automation and orchestration are essential concepts in the field of computer and network security, particularly from a Security Operations Center (SOC) point of view. These concepts help SOC teams streamline their processes, improve response times, and enhance overall security posture. Here’s a breakdown of what automation and orchestration mean in the context of a SOC in a SLED environment:

Automation

Automation in a SOC refers to the use of technology and scripts to perform repetitive and predefined tasks without manual intervention. These tasks can include activities such as log analysis, threat detection, incident response, and vulnerability scanning. The goal of automation is to reduce the workload on security analysts and speed up the detection and response to security incidents. Automation can handle routine, well-defined tasks, allowing human analysts to focus on more complex and strategic aspects of security.

Examples of automated tasks in a SOC include automatically blocking IP addresses associated with malicious activity, generating alerts, and enriching security alerts with additional context (from additional security tools).

Orchestration

Orchestration goes a step further than automation by integrating various security tools, processes, and workflows into a coordinated and streamlined system. It involves creating workflows and playbooks that define how different security tools and processes should work together to respond to specific security incidents.  Orchestration aims to ensure that different security solutions communicate and collaborate effectively. It includes connecting various security technologies.  SOC orchestration helps improve response coordination, reduces the likelihood of errors, and enhances overall security incident management by providing a standardized, repeatable process for incident response.

Cisco’s Open Approach to XDR

What sets Cisco XDR apart is its open and collaborative approach. Rather than relying on closed, proprietary systems, Cisco embraces interoperability. This means that SLED SOC environments can integrate Cisco XDR into their existing ecosystems, ensuring a seamless and efficient security framework that works in harmony with other tools and technologies.  SLED entities cannot afford clunky vender integrations that make It harder and more time consuming for SOC analysts to investigate.

Cisco XDR is an open extensible solution, with turnkey integrations with a variety of third-party vendors allowing security operation teams to quickly adopt a unified and simple approach to their security across their security stack.

Building an Effective XDR Solution

An effective XDR solution requires multiple sources of telemetry and up-to-the-minute threat intelligence. Cisco Talos, the world-renowned threat intelligence research team provides this crucial data. By leveraging these sources, Cisco XDR helps SLED SOC teams detect and prioritize threats more effectively. Now, streamlined investigations and rapid threat remediation have become standard operating procedures.

XDR and Cyber Insurance for SLED Entities

Cyber insurance offers financial protection against losses incurred due to cyber-related incidents. The implementation of XDR solutions like Cisco XDR can significantly impact cyber insurance premiums and coverage for SLED entities. It demonstrates a proactive approach to security, which insurers often reward.

Conclusion

Operating a SOC in a SLED environment requires adherence to best practices. These practices include robust incident response strategies, and comprehensive threat detection.

For SLED entities, the “SOC in a BOX” concept is not just an idea; it’s real with Cisco XDR.  Cisco XDR is a practical approach to safeguarding the data and operations of State, Local, and Education entities, including law enforcement. It was designed to help SOC analysts detect and respond to threats more quickly and effectively by providing a unified view of security data across multiple security tools and data sources.

SLED SOC teams can have their analyst at any skill level perform advanced tasks elevating productivity and improving decision making times.

Cisco XDR is at the forefront of this “SOC in a BOX” transformation, providing SLED SOC teams with the tools they need to stay ahead of the ever-evolving cybersecurity threats. With an open approach, effective threat detection, and important considerations for cyber insurance, Cisco XDR is that tool in the toolbox SLED entities need in their quest for a secure and resilient future.

Related Links / Resources

Cisco XDR: Security Operations Simplified eBook
An XDR Primer: The Promise of Simplifying Security Operations
Cisco XDR: At a Glance (pdf)
XDR: More than just another SecOps Tool (pdf)

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Security on social!

Cisco Security Social Channels

InstagramFacebookTwitterLinkedIn

Share

  Learn how Cisco XDR simplifies and enhances the operations of SLED-focused SOCs, helping them achieve their security resilience goals.  Read More Cisco Blogs 

By |2023-12-13T16:02:55+00:00December 13, 2023|Cisco: Learning|0 Comments

What Should We Expect for State and Local Government IT Priorities in 2024? Mike Witzman on December 13, 2023 at 2:00 pm

As we wrap up 2023, it is a great time to reflect on the current state of technology in state and local governments and look ahead to the priorities for the coming year. As we enter 2024, we are… Read more on Cisco Blogs

As we wrap up 2023, it is a great time to reflect on the current state of technology in state and local governments and look ahead to the priorities for the coming year. As we enter 2024, we are seeing IT leaders in government crystalizing their efforts in four key areas:

cybersecurity
digital services
artificial intelligence (AI)
and modernizing transportation infrastructure.

Cybersecurity continues to be top tech priority

Maintaining the security of networks and the data they carry continues to be the primary concern of top government officials and has been for the last 10 years, according to NASCIO’s annual survey of State CIOs. As the volume and impact of malware and breaches continue to rise, states are evolving their security capabilities and focusing on cyber-resilience to quickly react and recover from security incidents.

Most states are also leveraging Federal Infrastructure and Investment Jobs Act (IIJA) grants to improve the security posture of their local government and schools, which can add the responsibility for State CIOs and CISOs to coordinate whole-of-state security plans. This heightened coordination and information sharing (plus sometimes resource sharing) is needed most in the smallest and under-resourced cities, counties, and schools.

States have conducted assessments to identify the capabilities and needs of their local governments and schools. They are focused on addressing fundamental needs such as training, endpoint protections, e-mail security, and multi-factor authentication.

While approaches differ by state, everyone is focusing on ensuring the sustainability of their approach beyond the IIJA funding window. States are also establishing centers of excellence, fusion centers and cyber ranges, often in partnership with local Universities or state network providers. These partnerships are delivering fundamental cybersecurity education, leading table-top exercises to better prepare for breaches, and in some cases creating regional security operations centers (SOCs) to provide security monitoring services for local governments and schools in the region.

While many States require local governments and schools to notify the State of security breaches, several have a long-term goal of sharing real-time security telemetry to create a more complete picture of threats and bad actors across their State.

Delivering digital government services still of high importance

Serving residents faster and at a lower cost by deploying secure and reliable digital government services also remains a top priority in state and local government. From online tax payments to virtual renewals of licenses and permits, digital services accessible from mobile devices are becoming the norm.

States and cities are consolidating portals to present a single face of government, with a single resident identifier and login for all services. This represents an intentional shift from agency-centric to resident-centric service delivery and can significantly lower the barrier for residents to identify the services they need and meet qualifications for.

Cities are also leveraging video technology to connect residents in need with government workers directly, allowing them to get timely and personal service without the scheduling and travel to a government office. The City of El Paso, Texas El Paso Helps initiative is a prime example of this shift.

States creating policy guardrails for appropriate use of AI

Just over a year after the public release of ChatGPT, Generative AI has taken center stage in the technology conversation (see what Cisco is doing with Generative AI). State CISOs are leading the policy creation for proper use of AI, and requiring registration of AI capabilities in all government systems and commercial applications used by agencies to ensure they follow the rules for appropriate use.

As Generative AI technology rapidly advances, the definitions of proper use will need to be adjusted. AI is widely viewed as a tool to augment humans in conducting their work, not as a tool to make decisions. With persistent workforce shortages across government agencies, government agencies are interested in technologies like AI-powered chatbots to continue to meet the needs of residents with their reduced workforce — especially in critical services that often experience spikes in demand (such as unemployment service at the beginning of the COVID-19 pandemic).

States have increasingly created the position of chief data officer and chief privacy officer to ensure the privacy of resident data as it is managed within and between agencies. By harnessing the power of data, states can gain valuable insights into resident needs, monitor trends, and inform policymaking. This evidence-based approach can lead to more effective and efficient public services in critical areas that touch multiple agencies like homelessness or opioid abuse.

States and cities are also focused on modernizing transportation infrastructure

Departments of Transportation (DoTs) are connecting traffic lights and adding cameras to move traffic more efficiently. They are also using these technologies to preempt stoplights, allowing ambulances and other first responders to reach people in need faster while responding better to accidents and road conditions (learn more).

Transit authorities are upgrading payment systems, delivering free and easily accessible secure WiFi to passengers, improving end-to-end journey management, and adding digital signage to promote events and community resources.

Transportation agencies also have significant data about historical ridership to improve efficiency and make data-driven decisions about routes based on time, weather, or events. Given the reach of transportation and city assets such as streetlights, projects like these can often be the start of a broader smart city strategy that expands into public safety and digital equity.

The ongoing push for IT modernization continues in 2024

As we discussed, cybersecurity remains the top concern for government leaders. But their emphasis on cloud services, digital government, data management, and analytics underscores a commitment to broader digital transformation. 2024 will see state and local governments continue to modernize infrastructure. The focus will be on simplification and automation, partly due to the persistent IT and cyber talent shortages, but also due to the need for improved flexibility and responsiveness to agency needs. 2024 should be a year of transition from policy creation around Generative AI to active use within the approved policy frameworks.

As technology and resident expectations evolve rapidly, government IT leaders continue to lead the way. We look forward to seeing new priorities and opportunities emerge in the new year.

Learn more: state and local government priorities 2024

Cisco Cybersecurity for Government
Cisco Public Funding Office
Cisco for State and Local Government

Share

  As we enter 2024, we are seeing IT leaders in state and local government crystalizing the new year's focus in four key areas. Find out what they are how they can impact your agency in the coming year.  Read More Cisco Blogs 

By |2023-12-13T16:02:54+00:00December 13, 2023|Cisco: Learning|0 Comments

Tonsley Innovation District Attracting Global Attention Reg Johnson on December 13, 2023 at 2:54 pm

If there is a single precinct in Australia that embodies what’s possible with digital innovation, it’s the Tonsley Innovation District in Adelaide. Tonsley was a response to a unique set of cha… Read more on Cisco Blogs

If there is a single precinct in Australia that embodies what’s possible with digital innovation, it’s the Tonsley Innovation District in Adelaide. Tonsley was a response to a unique set of challenges in South Australia more than a decade ago:

The closure of the Mitsubishi car assembly plant which was one of the State’s major employers but also a very visible economic shift
A recognition that South Australia needed to take control of its own destiny and create future jobs based around technology, innovation and new industries

The vision for Tonsley has proven to be transformative and a powerful demonstration of economic renewal. The magnitude and distinctive nature of the site itself creates a unique space to perform innovation and collaboration at a scale that has not seen before in Australia. A powerful demonstration of success is that Tonsley now employs more people on site than when the Mitsubishi car assembly plant was operating on the same site. Tonsley’s trajectory – and Cisco’s part in it as a strategic partner of Flinders University – is explored in a short video and details the many contributions that Cisco has made to Tonsley’s success:

A long-standing partnership with Flinders University – who bookends the site with TAFESA – spanning research and teaching. The centrepiece of our partnership has been the Digital Health Research Chair (Professor Trish Williams) – located at Tonsley in a dedicated Digital Health Design Lab – which is approaching its 10-year anniversary
Establishment of Innovation Central Adelaide at Tonsley where companies and governments can experiment with technology to solve problems and convert opportunities. Innovation Central Adelaide is linked to other innovation centres across Australia under the banner of the National Industry Innovation Network (NIIN)
Investment in the Factory of the Future at Tonsley which is showcasing what’s possible with digital innovation in advanced manufacturing but also providing an important vehicle to increase the supply of technology skills to South Australia. Our skills focus extends into the Cisco Networking Academy which partners with both Flinders University and TAFESA on site at Tonsley

Over the past 10 years I have watched Tonsley grow into a globally significant innovation district that is laying the foundation for the South Australian economy for years to come. Perhaps Flinders University’s Vice Chancellor Prof Colin Stirling sums it up best:

Tonsley’s a really special place. It’s a place that we have helped to bring forward from having been a former car manufacturing plant, to now one of Australia’s leading innovation districts. An innovation district that’s attracting attention globally.  You need partners. You need partnerships. You need partners who get it. And Cisco definitely get it”. 

Professor Colin Stirling, Vice Chancellor, Flinders University

For more information on how Cisco can support your education needs,

explore all of our solutions at Cisco for Education.

Share

  What is possible with digital innovation? Learn how Tonsley Innovation District has proven to be transformative and a powerful demonstration of economic renewal.  Read More Cisco Blogs 

By |2023-12-13T16:02:53+00:00December 13, 2023|Cisco: Learning|0 Comments
Go to Top