Generative AI: 5 Enterprise Predictions for AI and Security — for 2023, 2024, and Beyond Will Seaton
Post Content Our research shows that, mirroring the broader [...]
Post Content Our research shows that, mirroring the broader [...]
Five years ago, I found myself sailing across the Arctic Circle to participate in the North Atlantic Treaty Organization’s largest exercise since the Cold War. Walking down the maze-like passageway,… Read more on Cisco Blogs
Five years ago, I found myself sailing across the Arctic Circle to participate in the North Atlantic Treaty Organization’s largest exercise since the Cold War. Walking down the maze-like passageway, I passed miles of cable supporting the network onboard the large deck amphibious warship, where data would pass through hardware with a familiar “bridge” symbol. Standing watch in the Combat Information Center, we utilized phones with the familiar “bridge” symbol as well. Everything was in sync as it needed to be, which was only possible because we were afforded the best hardware in the industry.
However, after 15 combined years in a uniform and many nautical miles traveled, I decided to begin my transition out of active duty into the Naval Reserves. During transition training, there was palpable anxiety about whether to continue serving in the reserves and how much information to reveal about this decision on future job applications. Just as with medical conditions, you are not required to disclose your military service commitment, but I knew that I did not want to be part of an organization that did not support military service in the reserves or National Guard and wanted to be upfront that there would be times that I might have to step away for training to fulfill my commitments. Ultimately, I knew that the right organization would accept me and my decision to continue to serve in the reserves and that transparency was the best option.
One of my friends was doing a Department of Defense SkillBridge program and told me to check out the opportunities at Cisco. I applied for a few roles, and then things fell into place when I applied and interviewed for a sales role within U.S. Commercial Services Sales. While I lacked industry-specific experience, both the recruiter and hiring manager had faith in my ability to make a valuable contribution to the team. They saw in my background a tenacious will to be successful with fewer resources and the ability to adapt and overcome unknown challenges. They learned, through speaking with me in interviews, that I don’t see failure as an option, and I work to enhance efficiency and effectiveness when achieving a solution. Ever since that day they took a chance on me two years ago, I’ve been fortunate to be embraced by a supportive community of Cisconians, making my transition from a military background to the tech industry exceptionally smooth and seamless, personally and professionally.
This past March, I had the chance to participate in and support Exercise Freedom Shield for my Navy Reserve annual training, an air, sea, and land simulation exercise with the Republic of Korea. I braced myself as I prepared to inform my Cisco leadership of my impending leave of absence. I was actually caught off guard when I was met with nothing but support and encouragement. Their initial reaction was, “How’s your family handling the news? Will they be okay?” I was taken aback by their genuine concern for my family’s well-being. This kind response from my leadership alleviated much of the anxiety I had about the entire situation.
After arriving on the Korean peninsula, I wanted to make the most of the time available before the exercise’s commencement, so I took a train to Seoul to check out the Cisco office in the Gangnam District. Even with a language barrier, I was welcomed by the same supportive culture that I always experience in RTP. After three seemingly long weeks away from family, where the familiar “bridge” logo was present on the watch floor utilizing the world’s finest telecommunication gear, Cisco VoIP phones, my time in Korea came to a close following the successful exercise. Finally, I reunited with my family, and it felt good to be home.
I appreciated the opportunity to put on the uniform again, but I’m even more grateful for a company that is considerate and assists with my time away. Lots have changed for me in the past few years: I once wore steel-toe, non-slip boots, but now wear shoes and flip-flops on the weekend. I hung up my camouflage uniform for a button-down shirt and slacks. I maneuvered warships in formation and now help the team drive sales for some of the world’s most recognizable and fun brands. I used to eat in the wardroom on board with department heads, discussing naval tactics and operations. Now, I eat lunch in the cafe, collaborating with professionals in Business Development, Customer Experience, Operations, Finance, and Engineering. It wouldn’t be feasible without the positive teamwork I’ve been fortunate to be surrounded by. I hope hiring managers and recruiters will look to veterans even more when recruiting new talent because of the incredibly diverse skills we can bring to expand the business and even include a few sea stories along the way. I am forever grateful to Cisco for being my “Bridge to Possible” and the best place to work!
Are you ready to discover your bridge to possible? Find an opportunity now.
Subscribe to the WeAreCisco Blog.
Services Specialist Core Jonathan T. wanted to join a company that supported him in the Navy Reserves and embraced his unique skillset. He found it at Cisco. Read More Cisco Blogs
Zero Trust Network Access (ZTNA) is a secure remote access service that verifies remote users and grants access only to specific resources at specific times based on identity and context policies.… Read more on Cisco Blogs
Zero Trust Network Access (ZTNA) is a secure remote access service that verifies remote users and grants access only to specific resources at specific times based on identity and context policies. This is part 2 in our ZTNA blog series for operational environments. Read the first blog here.
Right now, somewhere in the world a robot arm needs a firmware upgrade, a wind turbine is stalled, and a highway message sign is displaying gibberish. If your business depends on operational technology (OT) or industrial control systems (ICS), you need to allow machine builders, maintenance contractors, or your own experts and technicians to remotely access equipment for configuration, troubleshooting, and updates.
In our last blog we gave a 10,000-foot view of Cisco Secure Equipment Access (SEA) and how it can help to secure remote access to your industrial network. Cisco SEA is a Zero Trust Network Access (ZTNA) solution controlling who can connect, which OT assets they can access, and when. It starts with a default deny posture and offers least-privilege access only once it trusts the user identity.
In addition to restricting access to specific assets and schedules, Cisco SEA can also restrict the access method remote technicians can use to log into an OT asset. If they are using RDP, VNC, SSH, Telnet, or HTTP(S), they only need a web browser—no client software is needed. Cisco SEA proxies all remote access traffic, meaning that users never have direct IP access to the asset or the network. Completely isolating critical resources gives you unmatched security.
In some situations, you might need a full IP communication path between the remote user and an OT asset. Examples are if technicians are using a vendor-specific management software, modifying a PLC program using a native desktop application, or transferring files to and from an asset. To address these advanced use cases, Cisco SEA offers an agent-based ZTNA access method called SEA Plus.
SEA Plus installs a lightweight application on the remote user’s computer to create a secure end-to-end IP connection with the OT asset, enabling any TCP, UDP, and ICMP communications. However, unlike the network extension offered by a VPN solution, traffic always goes through the SEA trust broker, which enforces security policies such as which assets can be accessed, when, and which protocols and ports can be used.
Overall, SEA Plus provides native IP access to operational technology from remote computers, but without the need to design, deploy, and maintain a VPN infrastructure. It also strengthens and simplifies security with highly granular controls tightly restricting access to OT assets as required by the ZTNA least-privilege principle.
Control over the who, what, how, and when of remote access is a giant step toward robust protection of your industrial network and critical infrastructure. But when using SEA Plus, you are granting full IP access to an asset. How can you be sure the user’s computer will not expose the asset to malware or malicious traffic? To gain full trust, you need to verify the device the technician is using to log in.
Good news: Cisco SEA and Cisco Duo work together to automatically check device health before granting access to an asset. When a remote user tries to establish a session using the SEA Plus access method, Duo verifies that the user’s computer complies with your security policies—for example, operating system version and patch level, firewall status, use of antivirus software, and more. If a device does not meet your requirements, the technician cannot gain access.
Summing up: As a hybrid-cloud solution, Cisco SEA avoids the costs and complexity to maintain secure remote access capabilities at scale across your industrial network and critical infrastructure. As a ZTNA solution, it lets you take control back by enforcing least-privilege security policies based on identity and context. And with the integration between SEA and Duo, you can also check the security posture of remote computers—another key aspect of zero trust.
Check back soon for our next ZTNA blog, to learn how Cisco Secure Equipment Access can help you monitor remote access sessions for regulatory compliance, investigating incidents, or training purposes.
In the meantime, make sure you subscribe to our OT Security newsletter, learn more about Cisco Secure Equipment Access (SEA), and have a look at our Cisco Validated Design Guide for assistance on how to implement ZTNA in your operational environment.
Discover how Cisco Secure Equipment Access enables clientless and agent-based ZTNA remote access and checks device security posture by integrating with Cisco Duo. Read More Cisco Blogs
Cisco’s advocacy community, Cisco Insider Advocates, brings our customers together and provides a way for them to make powerful connections, expand their professional and personal networks, and learn… Read more on Cisco Blogs
Cisco’s advocacy community, Cisco Insider Advocates, brings our customers together and provides a way for them to make powerful connections, expand their professional and personal networks, and learn from top experts in their field. One of our goals with our advocacy community is to deepen our relationships with our customers. Our Q&A series allows us to shine a spotlight on some of our most passionate customer advocates as we learn more about their stories and backgrounds.
Today, we have one of the friendliest faces in the community joining us for a chat. I’m excited to welcome Damian Erni from Swisscom.
That’s an interesting question. In Switzerland, you usually start your apprenticeship or your study when you turn 16. At that time, I was very interested in mechanical engineering or building construction.
That’s a long story. I started my professional career in the printing and advertising business as a typesetter and graphic designer. During all those years, I always maintained and supported the IT infrastructure of the companies I was working for. It was kind of a hobby on top of my regular job, which was great fun with a lot of learning. In 1999, during a visit to an IT fair, I met someone from Cisco, who was recruiting for a networking boot camp. I signed up for that opportunity and soon started my IT career as a project engineer, building large MPLS networks globally.
It all began with the fact that Cisco made it possible for me to start my career in IT, many years ago. I’m still thankful for that opportunity. Today, many years later, I continue to be connected to Cisco as an advocate and ambassador of Cisco Insider Advocacy programs, which are fantastic. For the daily business, I can count on the local Cisco team here in Switzerland.
My job is always evolving and that’s what makes it great. Of course, there are lots of challenges in this fast-turning industry, but one of the bigger challenges we face is the shortage of skilled IT workers. At Swisscom, we have several programs to attract young talent, including our “junior program,” which exposes participants to career opportunities in a range of fields. For example, those in the program for system engineers can become certified engineers for Cisco, Dell, or Microsoft with specializations in areas like data center engineering or network engineering.
The Cisco Insider Advocates community is a group of people that are enthusiastic about what they do. They all have an intrinsic motivation to learn and explore technology and are passionate about Cisco. I met some of them at Cisco Live, and it felt as if we had known each other for a long time. We all had a great time during the event and are still in contact since then.
I joined about four years ago when I was at the local Cisco office for an event. They promoted Cisco Insider Advocates, and I was curious and signed-up. At that time, I didn’t know what to expect. During my time in the community, I got more and more involved in different activities, from being part of a challenge to participation at a panel discussion at Cisco Live. I think for both, the personal and professional side, I get more visibility for my work, and I can count on the support and knowledge of a huge and highly skilled community.
Inspiring would be the best word to summarize my experience. If I compare it to other Cisco Live events, my favorite is still the one in Barcelona in 2019. But every Cisco Live has its own highlights, which I don’t want to miss.
It was a great experience, getting out of my comfort zone and being in the spotlight. We were a group of five advocates. We spoke about the intersection of customer experience and customer advocacy and how we see that happening in practice through the Cisco Customer Experience and customer advocacy programs and initiatives.
As I mentioned earlier, it felt like we’ve known each other for a long time although we’d never met in person. The day we met felt like seeing old friends. You feel that they all share the same passion. We had great fun. I’m looking forward to seeing them all again in 2024 in Amsterdam.
My family and friends
Having a job where I can learn something new every day
A sense of humor
For our customers who have already joined our Cisco Insider Advocates community, say hello to Damian if you haven’t met yet. And if you’re a Cisco customer but aren’t a community member, consider joining. You’ll be able to:
Connect with peers in a gamified, online community
Have an opportunity to meet with Cisco’s executives
Share your feedback, questions, and best practices
Get access to ‘insider’ content and resources
Grow your professional and personal brand
Amplify your company’s success story with Cisco technology
Damian Erni is passionate about technology and enthusiastic about Cisco. Learn how he combines both in his role at Swisscom and through his engagement in Cisco Insider Advocates. Read More Cisco Blogs
The turtle, protected by its hard shell, is a good metaphor for the security model used in most industrial networks. The industrial DMZ (iDMZ) is the shell that protects the soft, vulnerable… Read more on Cisco Blogs
The turtle, protected by its hard shell, is a good metaphor for the security model used in most industrial networks. The industrial DMZ (iDMZ) is the shell that protects the soft, vulnerable center—the industrial control systems (ICS) the business depends on.
But while the iDMZ blocks most threats, some will inevitably slip through. When they do, they can move sideways from device to device, potentially causing downtime and information leakage. Giving traffic free rein once it makes it past the iDMZ conflicts with the zero-trust security principle to never trust, always verify. And as companies look to “digitize” manufacturing and apply more cloud-based services also known as Industry 4.0, more devices need access to production systems.
You can limit the spread of malware that makes it past the iDMZ using a technique called micro-segmentation. The idea is to tightly restrict which devices can communicate and what they can say, confining the damage from cyberattacks to the fewest number of devices. It’s an example of zero-trust in action: instead of taking it on faith that devices only talk to each other for legitimate reasons, you lay down the rules. An HVAC system shouldn’t be talking to a robot, for example. If it is, the HVAC system may have been commandeered by a bad actor who is now traipsing through the network to disrupt systems or exfiltrate information.
So why isn’t every industrial organization already using micro-segmentation? The barrier I hear most often from our customers is a lack of security visibility. To micro-segment your network you need to know every device connected to your network, which other devices and systems it needs to talk to, and which protocols are in use. Lacking this visibility can lead to overly permissive policies, increasing the attack surface. Just as bad, you might inadvertently block necessary device-to-device traffic, disrupting production.
Good news: Cisco and our partner Rockwell Automation have integrated security visibility into our Converged Plantwide Ethernet (CPwE) validated design. With Cisco Cyber Vision you can quickly see what’s on your network, which systems talk to each other, and what they’re saying. One customer told me he learned from Cyber Vision that some of his devices had a hidden cellular backdoor!
Security visibility has three big payoffs. One is awareness of threats like that backdoor, or suspicious communications patterns like the HVAC system talking to the robot. Another benefit is providing the information you need to create micro-segments. Finally, visibility can potentially lower your cyber insurance premiums. Some insurers give you a discount or will increase coverage limits if you can show you know what’s connected to your network.
Once you understand which devices have a legitimate need to communicate, explicitly allow those communications by creating micro-segments, defined by the ISA/IEC 62443 standard. Here’s a good explanation of how micro-segments work. Briefly, you create zones containing a group of devices with similar security requirements, a clear physical border, and the need to talk to each other. Conduits are the communication mechanisms (e.g. VLANs, routers, access lists, etc.) that allow or block communication between zones. In this way, a threat that gets into one zone can’t easily move to another.
Both Cisco and Rockwell Automation provide tools for segmenting the network. Use Cisco Identity Services Engine (ISE) for devices that communicate via any industrial protocol, including HTTP, SSH, telnet, CIP, UDP, ICMP, etc. For your CIP devices, you can enforce even tighter controls over traffic flow using Rockwell Automation’s CIP Security, which secures production networks at the application level. We have several Cisco Validated Designs (CVDs) on a range of security topics, many jointly developed and tested with Rockwell. Examples of our collaboration with Rockwell include Converged Plantwide Ethernet, or CPwE, and the recently added Security Visibility for CPwE based on Cisco Cyber Vision.
Combining an iDMZ with micro-segmentation is like blending the protective abilities of a turtle and a lizard. Like the turtle’s shell, the iDMZ helps keep predators out. And like lizards who can drop their tails if a predator gets hold, micro-segmentation limits damage from an attack.
Bottom line: To get started with micro-segmentation—and potentially lower your cyber insurance premiums—use Cyber Vision to see what devices are on your network and what they’re saying.
Network Security within a Converged Plantwide Ethernet Architecture Design and Implementation Guide
Deploying CIP Security within a Converged Plantwide Ethernet Architecture Design Guide
CPwE Identity and Mobility Services
CPwE Industrial Demilitarized Zone
Industrial Automation Security Design Guide 2.0
Industrial cybersecurity needs granular security policies. This requires visibility into what assets are connected. Learn how Cisco and Rockwell are enabling OT visibility into CPwE with Cyber Vision. Read More Cisco Blogs
In 2020, I joined Cisco fresh out of college, which just so happened to align with the inaugural year of the Cisco DevNet certification track. It was the same year Cisco consolidated all of its CCNA… Read more on Cisco Blogs
In 2020, I joined Cisco fresh out of college, which just so happened to align with the inaugural year of the Cisco DevNet certification track. It was the same year Cisco consolidated all of its CCNA certification tracks into one foundational certification. The CCNA was (and still is) part of our everyday language, thanks to its immense popularity, but it was the all-new DevNet technology track I found most intriguing.
Cisco DevNet certifications focus on integrating network infrastructure with software applications, automation, and programmability. DevNet certification savored both my taste in software development and networking. Little did I know that event would leave such a great mark on my career.
At the time they were announced, there were two certification levels, Associate and Professional, before adding the DevNet Expert certification. I was targeting passing my DevNet Associate certification exam, 200-901 DEVASC, before the end of my internship. Going through the blueprint was overwhelming due to the vast amount of Cisco technologies and the breadth of topics listed.
The official DevNet Associate course came to my rescue. I went through the course twice and passed my exam in June 2020.
It was indeed euphoric to achieve my first official Cisco certification, making entry into the DevNet Class of 2020… but it left me wanting more!
I hadn’t intended to stop with my DevNet Associate certification. My goal was to progress further by obtaining the DevNet Professional certification, which involves passing two Professional-level exams: the DevNet core and a concentration exam. I kept the momentum going and started preparing for my DevNet core (350-901 DEVCOR) exam.
The DevNet Associate exam exposed me to the testing environment and the tricky nature of the questions, but I was well aware that the DEVCOR exam would be a tough nut to crack and would require more discipline and hard work. Completing the official course, along with several foundational courses on Cisco technologies, significantly boosted my confidence.
I passed my DEVCOR in November 2021 and earned the Cisco Certified DevNet Specialist – Core certification. Passing the DEVCOR exam marked a significant milestone, especially because it’s required for DevNet Professional certification and is a prerequisite for the DevNet Expert certification. (Before taking a Cisco Expert-level practical exam, candidates need to pass the core exam in that technology track.)
DevNet opens up the automation and programmability realms, but knowledge of the underlying Cisco products is fundamentally important in creating innovative solutions. Once I realized that, my focus shifted toward learning the nitty-gritty of Cisco products, tools, and solutions.
Due to DevOps’ sheer relevance in the technological world, I chose it as my specialization, taking the 300-910 DEVOPS exam to complete my DevNet Professional concentration requirement. In turn, passing that exam would also earn me a Cisco DevNet Specialist certification: the Cisco Certified DevNet Specialist – DevOps certification.
Given the short nature of the exam, the room for error was marginally small. I maintained a systematic study plan and followed three key strategies:
Read the material at least twice.
Train muscle memory by doing a ton of hands-on exercises.
Revise the material regularly.
My eyes were still on the prize. I was just one Cisco exam away from getting DevNet Professional certified.
And at last, the long-awaited day arrived.
I sat down for my exam, feeling a little nervous, but I held onto my self-belief. Just before submitting the last question, I paused for a minute, thinking of how far I have come in this journey and what a wholesome learning experience it has been. I submitted my exam in anticipation and was left numb after seeing a message saying, “Congratulations…” That unknown state of mind did not allow me to read the message completely. I felt immensely relieved to see all the hard work pay off, achieving what I had long dreamt of.
They say, “When you are surrounded by five intelligent people, you become the sixth.” I have been over blessed to be surrounded by not five—but five hundred—intelligent people in the Cisco Learning & Certifications family. I am immensely grateful for the support and learning I have received from the leaders and engineers who inspired me to achieve these feats.
Finally, to help you get started on your DevNet learning and certification journey, here are my top recommendations:
Find Cisco DevNet exam study tips from the DevNet Certifications Community on the Cisco Learning Network.
DEVASC Study Materials
DEVCOR Study Materials
Sign up for Cisco U. | Join the Cisco Learning Network.
Use #CiscoU and #CiscoCert to join the conversation.
If, like Mohit, you enjoy both software development and networking, then Cisco DevNet certifications has plenty to offer by integrating network infrastructure with software applications, automation, and programmability. Here are Mohit's top recommendations to help you get started on your own DevNet learning and certification journey. Read More Cisco Blogs
Security Operations Centers (SOC) are responsible for detecting and responding to potential cyber threats in real-time. With the increasing complexity of cyberattacks, it’s important for SOC teams to… Read more on Cisco Blogs
Security Operations Centers (SOC) are responsible for detecting and responding to potential cyber threats in real-time. With the increasing complexity of cyberattacks, it’s important for SOC teams to have comprehensive coverage of MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) tactics, techniques, and procedures (TTPs). Today we’re discussing the importance of having comprehensive coverage of MITRE ATT&CK TTPs in security operations, and how Cisco technology can help to achieve this goal.
MITRE ATT&CK is a globally recognized framework that outlines various tactics, techniques, and procedures based on observed behaviors and used by threat actors during a cyberattack. The framework is divided into two main categories: tactics and techniques. Tactics represent the overall goal of an adversary, while techniques represent the specific methods used to achieve that goal. Procedures are the specific steps taken to execute the technique.
The cyberthreat landscape is constantly evolving, and new TTPs are being developed every day.
One type of attack that has been gaining popularity is living-off-the-land binary (LOLBin) exploitation. This type of attack has been leveraged by nefarious threat groups such as Volt Typhoon, BlackTech in addition to Jaguar Tooth malware, using legitimate tools and software already present on a victim’s system to carry out malicious activities. These attacks are difficult to detect because they do not involve the use of malware or other malicious software that would be flagged by traditional endpoint security solutions. Instead, attackers use tools such as PowerShell, WMI, and other built-in Windows utilities to achieve their objectives.
One way to protect against living off the land attacks recommended by this is to monitor system processes and network activity looking for suspicious behavior. This defense can be done using the combination of endpoint and network security controls and an extended detection and response solution on top to detect and correlate anomalies found in system activities and network traffic patterns, so security teams are timely alerted on potential attacks.
By having a comprehensive understanding of the various tactics, techniques, and procedures used by attackers, SOC teams can quickly identify and mitigate any potential threats before they cause significant damage.
Cisco is announcing the launch of Breach Protection to protect against the constantly evolving techniques used by threat actors. Cisco Breach Protection provides a comprehensive understanding of attacks by mapping observed adversary behaviors to MITRE ATT&CK tactics, techniques, and procedures (TTPs) in real-time.
Cisco Breach Protection is available in three tiers – Essentials, Advantage and Premier. Each tier is designed to cater to specific organization needs and delivers a range of outcomes to ensure complete coverage:
Breach Protection Essentials covers most attacks that an organization will encounter by combining email, endpoint (EDR), and XDR into a turnkey offer. Most attacks today still leverage a phishing email to deliver malware exploiting an endpoint vulnerability or use an endpoint application (termed living off the land attack) to escalate privileges, establish persistence or traverse laterally. Cisco Breach Protection provides detection and response to these types of attacks and adversaries like Wizard Spider and Sandworm.
Breach Protection Advantage covers all the attacks an organization is likely to encounter, especially attacks on very complex environments like IT/OT/IIoT or from very sophisticated nation-state threat actors like BlackTech, Volt Typhoon, or Jaguar Tooth. By combing network telemetry and network-based detections from cloud and traditional on-premises infrastructure, only Cisco can cover the full range of attacks seen in the wild today.
Breach Protection Premier delivers all the above capabilities to an organization that doesn’t have enough human resources to manage their Security Operations or is looking to fully outsource their SOC operation by wrapping the offer with managed services that delivers an Incident Response retainer, penetration testing services, red/blue/purple teaming activities, and managed detection and response.
All the above is available to customers who also already have 3rd party security products. The technical outcomes are the same regardless of whether customers choose à la carte Cisco products, an EA or the Breach Protection suite. But for customers who choose the suite they can achieve the outcomes listed above at very attractive financial terms and a superior total cost of ownership without having to deal with the challenges of stitching together multiple 3rd party vendors, dealing with multiple 3rd party purchase orders, or managing multiple different consoles.
In today’s evolving cyberthreat landscape, having comprehensive coverage of MITRE ATT&CK TTPs is crucial for SOC teams. It ensures that they are equipped to detect and respond to any potential threat quickly. By analyzing the TTPs used in previous attacks like ransomware, SOC teams can develop a better understanding of the tactics used by threat actors and develop more effective strategies to prevent future attacks. So, if you’re looking to enhance your SOC’s capabilities, make sure you have complete coverage of MITRE ATT&CK TTPs leveraging Cisco Breach Protection!
Learn more about Cisco Breach Protection.
We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Secure on social!
Cisco Secure Social Channels
InstagramFacebookTwitterLinkedIn
Security Operations Centers (SOC) are responsible for detecting and responding to potential cyber threats in real-time. With the increasing complexity of cyberattacks, it’s important for SOC teams to have comprehensive coverage of MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) tactics, techniques, and procedures (TTPs). Today we’re discussing the importance of having comprehensive coverage of Read More Cisco Blogs
Co-authored by Roland Wagner, CODESYS.
Virtualization is well accepted in enterprise IT. Creating virtual versions of computing resources such as servers and storage, enables the consolidation of… Read more on Cisco Blogs
Co-authored by Roland Wagner, CODESYS.
Virtualization is well accepted in enterprise IT. Creating virtual versions of computing resources such as servers and storage, enables the consolidation of multiple physical resources into a single virtual environment. This allows for more efficient utilization of hardware and better resource management. The value derived includes reduced capital expenditures, lower maintenance costs, increase flexibility and improved cybersecurity.
However, virtualization is not so prevalent in industrial environments. Industrial Automation and Control Systems (IACS) hardware resources in these environments, such as Programmable Logic Controllers (PLC), Industrial PCs (IPC), and Human Machine Interfaces (HMI), have existed as discrete resources. With digitization, the number of such hardware resources has risen rapidly and so has the time and expense of monitoring, updating, and troubleshooting, which could require extended downtimes and productivity losses. An additional consideration is Industry 4.0 that increases the amount of compute resources in production systems with data collection and analysis.
IACS compute assets can be virtualized to reap its benefits, but it requires special considerations. Manufacturing processes are significantly more sensitive than IT processes to network issues like delay, latency, jitter, and packet loss.” Since virtualization removes direct or close connectivity of compute assets with the controlled machines, the network must step up and adhere to stricter performance requirements.
Virtualization can bring several benefits in industrial sectors. Manufacturers can consolidate PLCs, IPCs, HMIs, Gateways, and other physical compute resources currently on their factory floors onto local virtual machines which run on a hyperconverged compute and storage infrastructure. Existing PCs and workstations (IPCs and HMIs) can be replaced by thin clients with a smaller footprint connected to the corresponding virtual desktop. Virtual PLCs (vPLC) running in the hyperconverged infrastructure would interface with the sensors, actuators, and machines they control via the converged network. This arrangement has many advantages:
Scalable and agile operations: Virtualization enables manufacturers to easily scale their operations by adding or removing virtual machines as required. It also facilitates the deployment of new applications or updates without disrupting production processes. Adapting to changing conditions, product redesigns, etc., is easier by updating operating parameters in software IACS.
Increased security: Removing discrete hardware from the factory floor minimizes the potential avenues that an attacker can exploit to gain unauthorized access to manufacturing assets and processes. Virtualization can improve the security of IACS by isolating critical control systems. By separating networks and implementing security measures at the virtualization layer, manufacturers can minimize the risk of unauthorized access or malware propagation.
Improved disaster recovery: Virtualization allows for efficient backup, replication, and restoration of virtual machines, making disaster recovery planning and execution more streamlined. It enables manufacturers to recover from system failures or disasters, reducing downtime and minimizing any impact more quickly on production.
Better sustainability: Consolidation of compute and storage resources into a set of central services helps reduce the total energy requirements. In addition, easier access to more processing data can help increase efficiencies, reduce waste, and lower energy consumption.
Testing and development: Virtualization provides an ideal environment for testing and development activities. Manufacturers can create virtual replicas of their production systems for testing new software, configurations, or system updates, ensuring they do not impact the actual production environment.
In summary, as Dr. Henning Loeser from Audi (see interview link below) states, manufacturers can move from a model where they buy a new “box” to get more features in the plant to one where they buy new software to get more features.
Figure 1. From direct wired to virtualized control systems powered by CODESYS
IACS virtualization requires specific networking requirements to ensure the reliable and secure operation of virtualized systems. Some key networking considerations for IACS virtualization include:
Support for tunneling Layer 2 protocols: Virtualization of IACS moves PLCs with direct or a simple Layer 2 connection to controlled equipment, to a data center, which necessitates traversal through routers, requiring Layer 3 communication. However, since several popular control protocols operate at Layer 2, these protocols need to be tunneled as payload in Layer 3 packets to avoid large, cumbersome, and fragile VLAN deployments.
Improvements in redundancy: A resilient network helps preserve production continuity by maintaining high availability, eliminating packet loss, and ensuring continuous communications even during failure of individual components.
High bandwidth: The network equipment and infrastructure must be capable of supporting a higher bandwidth and corresponding throughput to handle the volume of traffic that can be expected to increase once virtualization places more packets on the network.
Determinism: QoS mechanisms should be implemented to prioritize and ensure that critical control system traffic is given higher priority over non-critical traffic. This helps prevent delays or interruptions in real-time control communications in a deterministic manner and provide consistent networking experience for the IACS applications.
Visibility, security, and access: The production network should support strong in-depth security measures to protect the virtualized IACS environment. This can include built-in security sensors designed to monitor and analyze IACS traffic, strong access controls, and effective segmentation to maintain zones of trust and minimize malware propagation. Network security should be considered at both the virtualization layer and the physical network layer. Moreover, the network should provide zero-trust network access (ZTNA) for staff and other personnel to securely log into production assets for regular monitoring and maintenance.
Scalability and flexibility: The network infrastructure should be scalable to accommodate the growing demands on virtualized systems. This includes considering factors such as network capacity, scalability of switches and routers, and the ability to add, remove, and reconfigure virtual machines as needed.
Network monitoring: Continuous monitoring of the network infrastructure is important to detect and respond to any anomalies or security incidents promptly. Network monitoring tools and techniques can help identify performance issues, network bottlenecks, or potential security breaches.
Cisco industrial networking incorporates advanced innovations that can help virtualize IACS assets. Cisco products and solutions in networking, management, computing, and security provide the basis of this virtualization.
Figure 2: Architectural schematic for control systems virtualization
Catalyst Industrial Ethernet switches provide high-capacity packet switching and lossless resiliency required for uninterrupted connectivity of IACS equipment. Coupled with their support for industrial protocols, resiliency features, edge-compute capabilities, security sensing and applying or enforcing segmentation through access control, make them the industrial switches of choice.
Cisco Catalyst Center, the network management platform, directs all functions of the network from onboarding devices, configurations, performance monitoring, proactive troubleshooting, access policies, etc., and ensures that the network is always ready.
Cisco Identity Services Engine (ISE) is a comprehensive security policy management platform that is used to ensure secure network access and enforce security policies. It allows organizations the control over who can access their network and what resources they can access.
Cisco Cyber Vision running within Cisco industrial networking equipment provides visibility to identify connected assets, network traffic, and security vulnerabilities. Using this level of visibility, you can define zones and conduits as per ISA/IEC 62443 and use ISE, Catalyst Center, and Cisco industrial switches to enforce segmentation.
Cisco Unified Computing System (UCS) brings together compute, networking, and storage in a single system to power your applications, including virtualization. As compared to traditional servers that are monolithic, complex to deploy, and even more complex to adapt to workload demands, UCS is a unified system on which you can provision and balance resources to meet virtualization workloads easily.
The CODESYS Development System is an integrated development system (IDE) in accordance with IEC 61131-3 for programming the control logic and contains various textual and graphical editors. Additional functions can be configured in the CODESYS Development System, e.g., user interfaces/HMI screens, fieldbus and I/O configuration, safety-relevant logic functions, data exchange with various other participants in the network, as well as coordinated motion control systems or robot kinematics.
Admittedly, virtualization of IACS is not mainstream, and it may not be on your radar quite yet. But with all the benefits it can offer, it is easy to see how it will be a gamechanger soon. In fact, Audi, the German manufacturer of technologically advanced luxury cars has embraced virtualization and is transforming its production lines. Watch Dr. Henning Löser, head of Production Labs, Audi, explains why Audi turned to Cisco industrial IoT solutions to create its next-generation smart factories. It’s not too early to start laying the networking foundation for the future of manufacturing.
If you are visiting SPS IPC Drives 2023, that runs from November 14-16 in Nuremberg, Germany, don’t miss the joint Cisco and CODESYS demonstration of virtual controllers in manufacturing environments in the CODESYS booth (#677 in hall 7).
For more information on this or any other topic related to manufacturing automation, please schedule a free, no-obligation, conversation with one of our experts.
Virtualization of control systems in a manufacturing environment can be hugely beneficial provided you build a flexible, scalable, deterministic, and secure network to ease transition to a centralized pool of virtual machines. Read More Cisco Blogs
We hear you loud and clear! You asked us to simplify our tools even more, give you more flexibility, enhance access to APIs and our Technical Assistance Center (TAC), and create opportunities for you… Read more on Cisco Blogs
We hear you loud and clear! You asked us to simplify our tools even more, give you more flexibility, enhance access to APIs and our Technical Assistance Center (TAC), and create opportunities for you to add specialized value – especially as we transition to a software and as-a-service paradigm.
You ask, and we work hard to deliver!
At Partner Summit today I announced that we are integrating Cisco Lifecycle Advantage into Cisco PX Cloud and releasing Partner Advanced Support for Managed Services Providers.
Cisco Partner Advanced Support will enable Managed Services Providers (MSPs) to deliver premium-level support with the added benefit of guided access to API integrations that build on MSPs’ own individual existing services.
Partner Advanced Support is a service that moves Cisco partners who are specializing in a managed services route to market from analog to true-digital support.
With timely, scalable automated syncing on all cases, Partner Advanced Support offers instant digital mirroring of all problem tickets opened by the partner and faster, prioritized access to experts in Cisco’s TAC – a global organization that provides around-the-clock, award-winning technical support services online and over the phone.
This solution enables MSPs to have faster access to the right resources within Cisco TAC, access to Cisco automation and AI via the smart-bonded digital interface, and leverage APIs (which provide insights and telemetry) in order to create new differentiated services in a new outcome-based service model.
We are integrating Cisco Lifecycle Advantage into Cisco PX Cloud, to reduce how many tools partners need to have a comprehensive view of a customer’s lifecycle data through a single pane of glass.
Three hundred plus partners who already have Cisco PX Cloud access now have the ability to look at Cisco Lifecycle Advantage data, accessing the same data via the cloud to digitally scale.
Through this integration, partners will be able to access Cisco a co-branded digital customer engagement.
I am proud of how far our team has come in responding to your requests – and as always, there is more to come to set you up for success – so we appreciate your continued feedback. Because we are greater together!
At Cisco we are creating more business value for our customers through customizing Cisco tools for our partners. Read More Cisco Blogs
We have an exciting summary of announcements for our partners this year at Cisco Partner Summit 2023. The exciting aspect of these announcements is the broad portfolio they represent with products,… Read more on Cisco Blogs
We have an exciting summary of announcements for our partners this year at Cisco Partner Summit 2023. The exciting aspect of these announcements is the broad portfolio they represent with products, programs, platforms, and tools to assist with partner productivity and profitability. These are aligned to Customer Priorities and incorporated throughout Partner Summit Keynotes, Breakout Sessions, Press Releases and more. The Partner Launch Experience will be a great resource for you to explore.
Without the right IT infrastructure there will be no AI projects. And through recent Cisco research (Cisco AI Readiness Index Survey – launching soon) we know that 70% of the IT infrastructure is not available. Cisco, through its partners, is providing simplified solutions to help customers get their infrastructure AI-ready faster. We are introducing converged and hyperconverged infrastructure solutions to help customers simplify and accelerate new Validated Designs (CVD) for AI, and partners can deploy accelerated compute and high-performance storage on proven solutions for their customers.
Partners will have the ability to extend observability use cases with Cisco’s Full-Stack Observability Platform. Developers of these modules are built from day one on the Open Telemetry Framework and anchored on metrics to drive an open and scalable single source of insight across the technology stack and provide business impact. Partners will unlock developing applications and modules to tackle additional important use cases. Modules being announced will provide Fintech in claims and eCommerce, SAP Observability, Campus Analytics, Service Level Objective, MLOps, and Cloud Carbon Insight capabilities.
We are excited that security suites and Cisco’s Security Cloud – our AI-driven, open, integrated, API-based platform – is now a reality. The new Security Suites are designed around key customer outcomes delivering better efficacy, better experiences, and better economics. These security suites address customer needs in three areas: User, Cloud, and Breach Protection. Cisco is also enhancing partner profitability by offering up to 30% in blended margin.
There is strong momentum by providing new Solution Specializations. These specializations are better positioned for our partners and aligned to Cisco strategy and innovations. These specializations count towards Integrator levels and are key to maximizing incentives. This will be a gradual shift from Architecture Specializations to Solution Specializations. In the announcement, we are launching SMB and in the second half of fiscal year 2024 we will also provide Secure Networking, IoT (Industrial and Non-Industrial), Network Security, and Zero Trust.
Also, as part of our partner program we will combine the best elements of Cisco’s most valued partner incentives into a single, integrated incentive. The new incentive model will reward partners for selling Cisco’s hardware, software, and as-a-service solutions across the entire customer lifecycle and routes-to-market. Phased implementation begins early in second half fiscal year 2024.
Cisco is taking bold steps to advancing outcome-driven solutions for Managed Service Partners. With this support comes first-ever support features, including new partner managed-ready offers. Expanding security will include Managed XDR, Managed Firewall and Secure Networking MSP Campaign. There’s also a new MSP Express for SMB offer to capture a growing SMB market opportunity. Drive preference in buying programs with expanded offer coverage for MSEA and MSLA, including the availability of FSO (AppDynamics and ThousandEyes) on MSLA.
The Partner Experience Platform is adding functionality that will assure partners that Cisco is investing for and with them – everything we do or innovate is to help them differentiate and succeed. We are doing this along three critical areas for partners with Growth, Profitability, and Productivity
In the growth area we are adding Growth Finder which automatically delivers prescriptive insights from best practices and partner-specific AI modeling to identify, size and prioritize recurring revenue attrition and greenfield opportunities (and identify competitive threats). We will also drive recurring business with Lifecycle incentives down to the customer level by identifying a la carte opportunities that can be combined with an Enterprise Agreement.
We believe the new Environmental Sustainability Estimator in PXP (available exclusively to Cisco Environmental Sustainability Specialization (ESS) specialized partners) will calculate savings related to energy consumption and carbon dioxide equivalent (CO2e) emissions that may be realized by migrating from specific Cisco hardware.
With profitability, see what you’re leaving on the table for services practice and CSPP rebates, and optimize VIP rebates with dynamic product mix modeling. Also, manage 100% of Cisco incentives and funds with lower administrative burden and third-party spend and greater Lifecycle Incentives 2.0 telemetry.
For productivity we are adding Auto-Renew simplification to enable the majority of Cisco Software in a “Netflix” model, but you control the low-touch to high-applied to the customer. Scale down-market with DISTI BDMs, augmenting Cisco’s coverage with Disti Partner View (DPV). Understand APIs and XML resources to help accelerate your business model with the Cisco Automation and Digitization hub.
Cisco Journeys is a huge addition to enable partners to a step-by-step guide for achieving business outcomes, faster, in top priority areas such as managed services, Meraki, security, and 16 other journeys.
The Cat 9300-M Series, which takes all of the power our customers love in the Catalyst Switches, but allows it to be natively managed via the Meraki Dashboard. The first 9300-M PIDs became available on October 17th, and there are more on the way including ones that support UPOE+.
Also, ThousandEyes will now be a native capability in the Meraki Dashboard. Think about that—more than one million MX routers now have the ability to be instant ThousandEyes vantage points.
For Powering Hybrid Work, there are fantastic innovations which were announced at the WebEx ONE event – but in the context of Partner Summit, we’ll combine these innovations together with other key parts of the Cisco portfolio, to drive the Hybrid Work Solution and in the Reimagine Workspaces Growth Sprint.
We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with #CiscoPartners on social!
Cisco Partners Facebook | @CiscoPartners Twitter | Cisco Partners LinkedIn
We have an exciting summary of announcements for our partners this year at Cisco Partner Summit 2023. The exciting aspect of these announcements is the broad portfolio they represent with products, programs, platforms, and tools to assist with partner productivity and profitability. Read More Cisco Blogs