About (Edit profile)

This author has not yet filled in any details.
So far has created 1829 blog entries.

From frustration to clarity: Embracing Progressive Disclosure in security design Chloe Cooke-Warren on September 1, 2023 at 12:00 pm

This blog was written by Annika Mammen, former User Experience Engineer at Cisco

There are so many areas to consider when dealing with protecting and detecting threats, unfortunately cognitive… Read more on Cisco Blogs

This blog was written by Annika Mammen, former User Experience Engineer at Cisco

There are so many areas to consider when dealing with protecting and detecting threats, unfortunately cognitive overload is one problem that is often overlooked. Remember when search engines had a million news articles, reading suggestions, and market analysis on the home page. Users had to sift through the mountain of information and decide what was the best source for them. This is a prime example of cognitive overload, and this is something most SOC analysts know too well. Too many options and complex steps make users feel frustrated and confused. Their brain is being given too much information to process and gets overwhelmed. When Google came on the scene with a single search bar, users flocked to it because it changed the game. It helped organize data and surfaced up the most relevant pieces of information. The single search bar on the page made it very easy for users to understand what they had to do. A clean results page made it abundantly clear which links were most important. Finally, very few prominent buttons on the page made it easy to know what the next step was.

The same concepts and problems appear in the security space, frustrating SOC analysts and making their jobs much harder. They deal with having too much information, too many choices and no real way to organize the data to help users make better data-driven decisions. To have the best user experience possible, designers leverage a technique called progressive disclosure. It is a pattern used to break down the information into bite sized pieces and feed it to the user as and when needed. A good example of this in everyday life is the average ATM. The first screen just shows a few options like withdraw, deposit, and check account balances. Within seconds, you understand what action you must take to deposit your money. Once you choose an option, it takes you to the next bite sized step. Easy!

Similarly, the security world is filled with alerts, metrics, targets, etc. It is easy to fall into the cognitive overload trap. Cisco XDR uses progressive disclosure to help reduce that cognitive load, support novice and expert users, and help users to focus on high priority incidents and remediate quickly. Now, let us look at how we achieve that.

1. Risk Score

Incidents are ranked based on a color-coded risk score. Immediately the user’s focus is drawn to the high priority incidents that are marked with a red coded score. Novice users who are not familiar with the scoring method can hover over the score and see a popup with an explanation.

2. View Incident Details

Once an incident is selected, a drawer opens on the side. This provides a high-level overview of the incident. In a single glance the user can see the incident status, assignees, description, breakdown of risk score, and assets. The user can assess if this incident must be prioritized without having to leave the page. For further details, they can click on ‘View Incident Details’ to load a detailed page of the incidents.

3. Control Center Tiles

The tiles displayed on the control center give a high-level overview of key metrics to better understand the health of the system without being too granular on the details. A user can create new dashboards or edit existing ones. This also helps the user see patterns and focus on areas that need to be prioritized.

4. Navigation Menu

Often, the overwhelming amount of information and actions that can be taken are spread across numerous screens. It can be easy for analysts to get lost in the maze. With Cisco XDR, we have grouped actions into 7 main categories, which are further broken down into 26 subcategories. We progressively take the user deeper into the product to get them to where they want to go.

5. Investigate Node Map

Mapping out an incident can sometimes look like a map of the Labyrinth. Files, assets, and IP addresses, to name a few, connected with numerous lines can be hard to decipher. Classic cognitive overload problem. XDR has grouped these so only key nodes are displayed in the map. On hover, each key node will expand to show more nodes and the lines connecting them will display more information on the relationship between each node. Clicking on a node will bring up a popup that displays options for further investigation.

Cisco XDR was built by SOC practitioners, for SOC practitioners, and lays out information in a consistent and easy to follow format – first a summary view of the data, then users can drill down to a detailed view of that same data, and finally if necessary (or out of pure interest and curiosity!) users can drill down again to see the raw data view. Using progressive disclosure and this consistent display of information, Cisco XDR helps SOC analysts view the information they need to move forward and take next steps to effectively mitigate threats. No more analysis paralysis, only data-based decisions here!

Visit our XDR product page.

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Secure on social!

Cisco Secure Social Channels

InstagramFacebookTwitterLinkedIn

Share

  Learn how Cisco XDR uses progressive disclosure to reduce the cognitive load on users, helping them to focus on high priority incidents.  Read More Cisco Blogs 

By |2023-09-01T14:58:42+00:00September 1, 2023|Cisco: Learning|0 Comments

Cisco Partners and Sustainability: We Can Help You Do Your Part Abhijeet Karve on August 31, 2023 at 3:00 pm

Environmental sustainability is an expanding focus and topic of discussion for many business leaders around the world. This is a period of great change. Businesses all over the world continue… Read more on Cisco Blogs

Environmental sustainability is an expanding focus and topic of discussion for many business leaders around the world. This is a period of great change. Businesses all over the world continue reshaping their operations to further support the wellbeing, stability, and future of the planet. We are evolving from an economy that extracts resources and eventually discards them, to a circular one which finds new uses for products and their inputs. According to a survey from McKinsey & Co., most people in the world today are attuned to the environmental impacts of their lifestyles, and 66% of consumers prefer to purchase sustainable items. Similarly, a recent IDC study showed that 63% of technology professionals worldwide believe sustainability is a very or extremely important business priority.

Given these trends and Cisco’s status as a global tech leader, our approach to environmental sustainability is holistic, including our operations, our engagement with suppliers, and our efforts to help customers and communities reduce their environmental impacts and adapt to a changing world. As a company, we are committed to leverage our unique strengths to power an inclusive future for all. That is why we are focusing on not just a sustainable future, but a regenerative one.

Get More Involved in Sustainability

There are so many opportunities to dive into sustainability. If you are interested in learning more, here are some links:

The Plan for Possible: Connecting a regenerative future – Cisco Blogs
Environmental Sustainability – Cisco.com
Cisco Environmental, Social, and Governance (ESG) Reporting Hub
Environmental Sustainability – Home page
Grow a sustainable IT Strategy with Cisco Capital and Cisco Refresh

Moreover, we have expanded our sustainability efforts to our valued Partners by offering an Environmental Sustainability Specialization (ESS) Program, which rewards partners for supporting Cisco’s product return pledge and participating in Cisco’s global initiative to responsibly repurpose or recycle end-of-use products. The Specialization enables partners to educate customers, promote product takeback, assist in customers’ move to circular business models, and further their own sustainability practices. Cisco ESS partners in participating countries are exclusively eligible for new incentive offers including incremental discounts of up to 4% on new products registered and additional 3% for incremental accelerator discounts with a commitment to return the used hardware back to Cisco, through Cisco’s Takeback & Reuse Program.

Furthermore, our Environmental Sustainability Black Belt track aims to help partners support customers’ sustainability priorities. If you would like a dedicated learning map on Environmental Sustainability this is for you! You will learn about strategies that can help customers move toward net zero, the circular economy, greenhouse gas (GHG) emissions reductions, and other sustainability initiatives.

Finally, if you know someone (it might be you!) who is leading sustainability initiatives at our Partners or at Cisco – we would welcome you to nominate them as a Partner Sustainability Champion.

By pursuing what’s possible, we can accelerate the transition into the digital age while maintaining the health of the planet — and a climate future we need and desire for future generations to come.

Visit our ESG Reporting Hub for more details on our initiatives.

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with #CiscoPartners on social!

Cisco Partners Facebook    Cisco Partners LinkedIn

Share

  We've expanded our sustainability efforts to our valued Partners by offering an Environmental Sustainability Specialization (ESS) Program, which rewards partners for supporting Cisco’s product return pledge and participating in Cisco’s global initiative to responsibly repurpose or recycle end-of-use products.  Read More Cisco Blogs 

By |2023-09-01T14:58:42+00:00September 1, 2023|Cisco: Learning|0 Comments

Raj Bhat: From Neighborhood Walks to Mount Kilimanjaro Dena Konkel on August 29, 2023 at 12:50 pm

If there’s one thing that Raj Bhat, SDA for Premier Accounts in CX (Customer Experience) knows how to do, it’s how to create a bucket list, one that has taken him to Peru, Tanzania and beyond.

But he didn’t always have one. His list came out of the COVID-19 pandemic when he started walking daily. His walks became hikes and, in the process, Raj says he, “got to know people from all walks of life, their journeys and their adventures, and their stories and life experiences made me want to go to certain places in the world.”

This was the beginning of his bucket list.

When someone in Denver recommended Sky Pond in Rocky Mountain National Park in the winter, he decided to go even though he never skied or hiked in that terrain.

When he met a woman from Peru who was born and raised in a small village along the Inca Trail, he decided to experience the remoteness of the Inca Trail trek to Machu Picchu.

Then while on the trail, he met someone from Tanzania.

“Before we said goodbyes on the trail, he surprised me by singing one of these old Bollywood songs,” said Raj. “He apparently watched the movie a dozen times on a black-and-white television back in Africa!” This led to Raj’s decision to add Mount Kilimanjaro to his bucket list.

Mount Kilimanjaro in northern Tanzania, is a dormant volcano that is also known as Africa’s highest mountain. At 19,340 feet above sea level, it is the highest free-standing mountain above sea level in the world.

Witnessing how dedicated, hardworking, and positive all the sherpas (porters) were despite having to carry enough supplies for the hikers’ seven days on the trail, Raj says, “ They’re definitely not in it just for the money. They respect Mother Nature and worship the mountains. They are very passionate, incredible young human beings dedicated to ensuring every hiker makes it to their goalpost.”

Mount Kilimanjaro has six or seven tracks or routes, each with a different success rate. Raj’s track, the Machame route, has an 80-85 percent success rate, and altitude sickness is the main contributor to summit failures. One person had to abort his attempt to summit in his group of five hikers and 22 sherpas.

There are two more items on his bucket list: Mount Everest Base Camp and Mount Rainier in Washington State. “Once you set out to do something, you need to do it,” says Raj.

Before his bucket list journey and before the COVID-19 pandemic, Raj’s regimen was to spend 30 to 40 minutes each morning doing breathing exercises and yoga.

“I am fortunate to have an opportunity to work for Cisco, an employer that promotes work-life balance,” says Raj. “Some hikes required me to take extended leave of absence which my manager, Anthony Davis, totally supported.”

He credits his ability to better handle conflict, different viewpoints, and “aggressive schedules” to the lessons he learned on the trail from remote parts of the world.

 

For three years in a row, Great Place to Work has recognized Cisco as the #1 company to work for in the United States and over a dozen countries worldwide. We are known for our people, our conscious culture, and our commitment to powering an inclusive future. 

Whether you are early in your career, a seasoned professional, or somewhere in between, Cisco has a wide range of technical and non-technical career opportunities for you to explore. 

Find a lifetime of opportunity at Cisco Careeers

If there’s one thing that Raj Bhat, SDA for Premier Accounts in CX (Customer Experience) knows how to do, it’s how to create a bucket list, one that has taken him to Peru, Tanzania and beyond.

But he didn’t always have one. His list came out of the COVID-19 pandemic when he started walking daily. His walks became hikes and, in the process, Raj says he, “got to know people from all walks of life, their journeys and their adventures, and their stories and life experiences made me want to go to certain places in the world.”

This was the beginning of his bucket list.

When someone in Denver recommended Sky Pond in Rocky Mountain National Park in the winter, he decided to go even though he never skied or hiked in that terrain.

When he met a woman from Peru who was born and raised in a small village along the Inca Trail, he decided to experience the remoteness of the Inca Trail trek to Machu Picchu.

Then while on the trail, he met someone from Tanzania.

“Before we said goodbyes on the trail, he surprised me by singing one of these old Bollywood songs,” said Raj. “He apparently watched the movie a dozen times on a black-and-white television back in Africa!” This led to Raj’s decision to add Mount Kilimanjaro to his bucket list.

Mount Kilimanjaro in northern Tanzania, is a dormant volcano that is also known as Africa’s highest mountain. At 19,340 feet above sea level, it is the highest free-standing mountain above sea level in the world.

Witnessing how dedicated, hardworking, and positive all the sherpas (porters) were despite having to carry enough supplies for the hikers’ seven days on the trail, Raj says, “ They’re definitely not in it just for the money. They respect Mother Nature and worship the mountains. They are very passionate, incredible young human beings dedicated to ensuring every hiker makes it to their goalpost.”

Mount Kilimanjaro has six or seven tracks or routes, each with a different success rate. Raj’s track, the Machame route, has an 80-85 percent success rate, and altitude sickness is the main contributor to summit failures. One person had to abort his attempt to summit in his group of five hikers and 22 sherpas.

There are two more items on his bucket list: Mount Everest Base Camp and Mount Rainier in Washington State. “Once you set out to do something, you need to do it,” says Raj.

Before his bucket list journey and before the COVID-19 pandemic, Raj’s regimen was to spend 30 to 40 minutes each morning doing breathing exercises and yoga.

“I am fortunate to have an opportunity to work for Cisco, an employer that promotes work-life balance,” says Raj. “Some hikes required me to take extended leave of absence which my manager, Anthony Davis, totally supported.”

He credits his ability to better handle conflict, different viewpoints, and “aggressive schedules” to the lessons he learned on the trail from remote parts of the world.

For three years in a row, Great Place to Work has recognized Cisco as the #1 company to work for in the United States and over a dozen countries worldwide. We are known for our people, our conscious culture, and our commitment to powering an inclusive future. 

Whether you are early in your career, a seasoned professional, or somewhere in between, Cisco has a wide range of technical and non-technical career opportunities for you to explore. 

Find a lifetime of opportunity at Cisco Careeers

Share

  If there’s one thing that Raj Bhat, SDA for Premier Accounts in CX (Customer Experience) knows how to do, it’s how to create a bucket list, one that has taken him to Peru, Tanzania and beyond.  Read More Cisco Blogs 

By |2023-09-01T13:23:14+00:00September 1, 2023|Cisco: Learning|0 Comments

Cisco Partners and Sustainability: We Can Help You Do Your Part Abhijeet Karve on August 31, 2023 at 3:00 pm

Environmental sustainability is an expanding focus and topic of discussion for many business leaders around the world. This is a period of great change. Businesses all over the world continue reshaping their operations to further support the wellbeing, stability, and future of the planet. We are evolving from an economy that extracts resources and eventually discards them, to a circular one which finds new uses for products and their inputs. According to a survey from McKinsey & Co., most people in the world today are attuned to the environmental impacts of their lifestyles, and 66% of consumers prefer to purchase sustainable items. Similarly, a recent IDC study showed that 63% of technology professionals worldwide believe sustainability is a very or extremely important business priority.

Given these trends and Cisco’s status as a global tech leader, our approach to environmental sustainability is holistic, including our operations, our engagement with suppliers, and our efforts to help customers and communities reduce their environmental impacts and adapt to a changing world. As a company, we are committed to leverage our unique strengths to power an inclusive future for all. That is why we are focusing on not just a sustainable future, but a regenerative one.

Get More Involved in Sustainability

There are so many opportunities to dive into sustainability. If you are interested in learning more, here are some links:

The Plan for Possible: Connecting a regenerative future – Cisco Blogs
Environmental Sustainability – Cisco.com
Cisco Environmental, Social, and Governance (ESG) Reporting Hub
Environmental Sustainability – Home page
Grow a sustainable IT Strategy with Cisco Capital and Cisco Refresh

Moreover, we have expanded our sustainability efforts to our valued Partners by offering an Environmental Sustainability Specialization (ESS) Program, which rewards partners for supporting Cisco’s product return pledge and participating in Cisco’s global initiative to responsibly repurpose or recycle end-of-use products. The Specialization enables partners to educate customers, promote product takeback, assist in customers’ move to circular business models, and further their own sustainability practices. Cisco ESS partners in participating countries are exclusively eligible for new incentive offers including incremental discounts of up to 4% on new products registered and additional 3% for incremental accelerator discounts with a commitment to return the used hardware back to Cisco, through Cisco’s Takeback & Reuse Program.

Furthermore, our Environmental Sustainability Black Belt track aims to help partners support customers’ sustainability priorities. If you would like a dedicated learning map on Environmental Sustainability this is for you! You will learn about strategies that can help customers move toward net zero, the circular economy, greenhouse gas (GHG) emissions reductions, and other sustainability initiatives.

Finally, if you know someone (it might be you!) who is leading sustainability initiatives at our Partners or at Cisco – we would welcome you to nominate them as a Partner Sustainability Champion.

By pursuing what’s possible, we can accelerate the transition into the digital age while maintaining the health of the planet — and a climate future we need and desire for future generations to come.

Visit our ESG Reporting Hub for more details on our initiatives.

 

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with #CiscoPartners on social!

Cisco Partners Facebook    Cisco Partners LinkedIn

Environmental sustainability is an expanding focus and topic of discussion for many business leaders around the world. This is a period of great change. Businesses all over the world continue reshaping their operations to further support the wellbeing, stability, and future of the planet. We are evolving from an economy that extracts resources and eventually discards them, to a circular one which finds new uses for products and their inputs. According to a survey from McKinsey & Co., most people in the world today are attuned to the environmental impacts of their lifestyles, and 66% of consumers prefer to purchase sustainable items. Similarly, a recent IDC study showed that 63% of technology professionals worldwide believe sustainability is a very or extremely important business priority.

Given these trends and Cisco’s status as a global tech leader, our approach to environmental sustainability is holistic, including our operations, our engagement with suppliers, and our efforts to help customers and communities reduce their environmental impacts and adapt to a changing world. As a company, we are committed to leverage our unique strengths to power an inclusive future for all. That is why we are focusing on not just a sustainable future, but a regenerative one.

Get More Involved in Sustainability

There are so many opportunities to dive into sustainability. If you are interested in learning more, here are some links:

The Plan for Possible: Connecting a regenerative future – Cisco Blogs
Environmental Sustainability – Cisco.com
Cisco Environmental, Social, and Governance (ESG) Reporting Hub
Environmental Sustainability – Home page
Grow a sustainable IT Strategy with Cisco Capital and Cisco Refresh

Moreover, we have expanded our sustainability efforts to our valued Partners by offering an Environmental Sustainability Specialization (ESS) Program, which rewards partners for supporting Cisco’s product return pledge and participating in Cisco’s global initiative to responsibly repurpose or recycle end-of-use products. The Specialization enables partners to educate customers, promote product takeback, assist in customers’ move to circular business models, and further their own sustainability practices. Cisco ESS partners in participating countries are exclusively eligible for new incentive offers including incremental discounts of up to 4% on new products registered and additional 3% for incremental accelerator discounts with a commitment to return the used hardware back to Cisco, through Cisco’s Takeback & Reuse Program.

Furthermore, our Environmental Sustainability Black Belt track aims to help partners support customers’ sustainability priorities. If you would like a dedicated learning map on Environmental Sustainability this is for you! You will learn about strategies that can help customers move toward net zero, the circular economy, greenhouse gas (GHG) emissions reductions, and other sustainability initiatives.

Finally, if you know someone (it might be you!) who is leading sustainability initiatives at our Partners or at Cisco – we would welcome you to nominate them as a Partner Sustainability Champion.

By pursuing what’s possible, we can accelerate the transition into the digital age while maintaining the health of the planet — and a climate future we need and desire for future generations to come.

Visit our ESG Reporting Hub for more details on our initiatives.

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with #CiscoPartners on social!

Cisco Partners Facebook  

By |2023-09-01T13:23:11+00:00September 1, 2023|Cisco: Learning|0 Comments

Black Hat USA 2023 NOC: Network Assurance Jessica Bair on August 28, 2023 at 4:43 pm

The Black Hat Network Operations Center (NOC) provides a high security, high availability network in one of the most demanding environments in the world – the Black Hat event.

The NOC partners are selected by Black Hat, with Arista, Cisco, Corelight, Lumen, NetWitness and Palo Alto Networks delivering from Las Vegas this year. We appreciate Iain Thompson of The Register, for taking time to attend a NOC presentation and tour the operations. Check out Iain’s article: ‘Inside the Black Hat network operations center, volunteers work in geek heaven.’

We also provide integrated security, visibility and automation: a SOC (Security Operations Center) inside the NOC, with Grifter and Bart as the leaders.

Integration is key to success in the NOC. At each conference, we have a hack-a-thon: to create, prove, test, improve and finally put into production new or improved integrations. To be a NOC partner, you must be willing to collaborate, share API (Automated Programming Interface) keys and documentation, and come together (even as market competitors) to secure the conference, for the good of the attendees.

XDR (eXtended Detection and Response) Integrations

At Black Hat USA 2023, Cisco Secure was the official Mobile Device Management, DNS (Domain Name Service) and Malware Analysis Provider. We also deployed ThousandEyes for Network Assurance.

As the needs of Black Hat evolved, so have the Cisco Secure Technologies in the NOC:

Cisco XDR: threat intelligence aggregation
ThousandEyes: Network Assurance
Cisco Umbrella: DNS visibility and security
Cisco Secure Malware Analytics (Formerly Threat Grid): sandboxing and integrated threat intelligence
Cisco Secure Cloud Analytics (Formerly Stealthwatch Cloud): network traffic visibility and threat detection
Cisco Webex: incident delivery and team collaboration
Cisco Security Connector: iOS device security and visibility, connected with Meraki Systems Manager

The Cisco XDR dashboard made it easy to see the status of each of the connected Cisco Secure technologies, and the status of ThousandEyes agents.

Below are the Cisco XDR integrations for Black Hat USA, empowering analysts to investigate Indicators of Compromise (IOC) very quickly, with one search. We appreciate alphaMountain.ai, Pulsedive and Recorded Future donating full licenses to the Black Hat USA 2023 NOC.

For example, an IP tried AndroxGh0st Scanning Traffic against the Registration server, blocked by Palo Alto Networks firewall.

Investigation of the IP confirmed it was known malicious.

Also, the geo location in RU and known affiliated domains. With this information, the NOC leadership approved the shunning of the IP.

File Analysis and Teamwork in the NOC

Corelight and NetWitness extracted nearly 29,000 files from the conference network stream, which were sent for analysis in Cisco Secure Malware Analytics (Threat Grid).

It was humorous to see the number of Windows update files that were downloaded at this premier cybersecurity conference. When file was convicted as malicious, we would investigate the context:

Is it from a classroom, where the topic is related to the behavior of the malware?
Or, is from a briefing or a demo in the Business Hall?
Is it propagating or confined to that single area?

The sample above was submitted by Corelight and investigation confirmed multiple downloads in the training class Windows Reverse Engineering (+Rust) from Scratch (Zero Kernel & All Things In-between), an authorized activity.

The ABCs of XDR in the NOC, by Ben Greenbaum

One of the many Cisco tools in our Black Hat kit was the newly announced Cisco XDR. The powerful, multi-faceted and dare I say it “extended” detection and response engine allowed us to easily meet the following goals:

One of the less public-facing benefits of this unique ecosystem is the ability for our engineers and product leaders to get face time with our peers at partner organization, including those that would normally – and rightfully – be considered our competitors. As at Black Hat events in the past, I got to participate in meaningful conversations about the intersection of usage of Cisco and 3rd party products, tweak our API plans and clearly express the needs we have from our partner technologies to better serve our customers in common. This collaborative, cooperative project allows all our teams to improve the way our products work, and the way they work together, for the betterment of our customers’ abilities to meet their security objectives. Truly a unique situation and one in which we are grateful to participate.

Secure Cloud Analytics in XDR, by Adi Sankar

Secure Cloud Analytics (SCA) allows you to gain the visibility and continuous threat detection needed to secure your public cloud, private network and hybrid environment. SCA can detect early indicators of compromise in the cloud or on-premises, including insider threat activity and malware, as well as policy violations, misconfigured cloud assets, and user misuse. These NDR (Network Detection and Response) capabilities have now become native functionality within Cisco XDR. Cisco XDR was available starting July 31st 2023, so it was a great time to put it through its paces at the Black Hat USA conference in August.

Cisco Telemetry Broker Deployment

Cisco Telemetry Broker (CTB) routes and replicates telemetry data from a source location(s) to a destination consumer(s). CTB transforms data protocols from the exporter to the consumer’s protocol of choice and because of its flexibility CTB was chosen to pump data from the Black Hat network to SCA.

Typically, a CTB deployment requires a broker node and a manager node. To reduce our on-prem foot print I proactively deployed a CTB manager node in AWS (Amazon Web Services) (although this deployment is not available for customers yet, cloud managed CTB is on the roadmap). Since the manager node was deployed already, we only had to deploy a broker node on premise in ESXi.

With the 10G capable broker node deployed it was time to install a special plugin from engineering. This package is not available for customers and is still in beta, but we are lucky enough to have engineering support to test out the latest and greatest technology Cisco has to offer (Special shoutout to Junsong Zhao from engineering for his support). The plugin installs a flow sensor within a docker container. This allows CTB to ingest a SPAN from an Arista switch and transform it to IPFIX data. The flow sensor plugin (formerly Stealthwatch flow sensor) uses a combination of deep packet inspection and behavioral analysis to identify anomalies and protocols in use across the network.

In addition to the SPAN, we requested that Palo Alto send NetFlow from their Firewalls to CTB. This allows us to capture telemetry from the edge devices’ egress interface giving us insights into traffic from the external internet, inbound to the Blackhat network. In the CTB manager node I configured both inputs to be exported to our SCA tenant.

 

Private Network monitoring in the cloud

 

First, we need to configure SCA by turning on all the NetFlow based alerts. In this case it was already done since we used the same tenant for a Blackhat Singapore. However, this action can be automated using the API api/v3/alerts/publish_preferences/ by setting both “should_publish” and “auto_post_to_securex” to true in the payload. Next, we need to configure entity groups in SCA to correspond with internal Blackhat network. Since subnets can change conference to conference, I automated this configuration using a workflow in XDR Automate.

The subnets are documented in a CSV file from which the workflow parses 3 fields: the CIDR of the subnet, a name and a description. Using these fields to execute a POST call to the SCA /v3/entitygroups/entitygroups/ API creates the corresponding entity groups. Much faster than manually configuring 111 entity groups!

Now that we have network telemetry data flowing to the cloud SCA can create detections in XDR. SCA starts with observations which turn into alerts which are then correlated into attack chains before finally creating an Incident. Once the incident is created it is submitted for priority scoring and enrichment. Enrichment queries the other integrated technologies such as Umbrella, Netwitness and threat intelligence sources about the IOC’s from the incident, bringing in additional context.

SCA detected 289 alerts including Suspected Port Abuse, Internal Port Scanner, New Unusual DNS Resolver,and Protocol Violation (Geographic). SCA correlated 9 attack chains including one attack chain with a total of 103 alerts and 91 hosts on the network. These attack chains were visible as incidents within the XDR console and investigated by threat hunters in the NOC.

Conclusion

Cisco XDR collects telemetry from multiple security controls, conducts analytics on that telemetry to arrive at a detection of maliciousness, and allows for an efficient and effective response to those detections. We used Cisco XDR to its fullest in the NOC from automation workflows, to analyzing network telemetry, to aggregating threat intelligence, investigating incidents, keeping track of managed devices and much more!

Hunter summer camp is back. Talos IR threat hunting during Black Hat USA 2023, by Jerzy ‘Yuri’ Kramarz

This is the second year Talos Incident Response is supporting Network Operations Centre (NOC) during the Black Hat USA conference, in a threat hunting capacity.

My objective was to use multi-vendor technology stacks to detect and stop ongoing attacks on key infrastructure externally and internally and identify potential compromises to attendees’ systems. To accomplish this, the threat hunting team focused on answering three key hypothesis-driven questions and matched that with data modeling across different technology implementations deployed in the Black Hat NOC:

Are there any attendees attempting to breach each other’s systems in or outside of a classroom environment?
Are there any attendees attempting to subvert any NOC Systems?
Are there any attendees compromised, and could we warn them?

Like last year, analysis started with understanding how the network architecture is laid out, and what kind of data access is granted to NOC from various partners contributing to the event. This is something that changes every year.

Great many thanks go to our friends from NetWitness, Corelight, Palo Alto Networks, Arista and Mandiant and many others, for sharing full access to their technologies to ensure that hunting wasn’t contained to just Cisco equipment and that contextual intelligence could be gathered across different security products. In addition to technology access, I also received great help and collaboration from partner teams involved in Black Hat. In several cases, multiple teams were contributing technical expertise to identify and verify potential signs of compromise.

Bouncing ideas across the team to arrive at conclusion

For our own technology stack, Cisco offered access to Cisco XDR, Meraki, Cisco Secure Malware Analytics, Thousands Eyes, Umbrella and Secure Cloud Analytics (formerly known as StealthWatch).

The Hunt

Our daily threat hunt started with gathering data and looking at the connections, packets and various telemetry gathered across the entire network security stack in Cisco technologies and other platforms, such as Palo Alto Networks or NetWitness XDR. Given the infrastructure was an agglomeration of various technologies, it was imperative to develop a threat hunting process which supported each of the vendors. By combining access to close to 10 different technologies, our team gained a greater visibility into traffic, but we also identified a few interesting instances of different devices compromised on the Black Hat network.

One such example was an AsyncRat-compromised system found with NetWitness XDR, based on a specific keyword located in the SSL certificate. As seen in the screenshot below, the tool allows for powerful deep-packet-inspection analysis.

AsyncRAT traffic record.

After positive identification of the AsyncRat activity, we used the Arista wireless API to track the user to a specific training room and notified them about the fact that their device appeared to be compromised. Sometimes these types of activities can be part of a Black Hat training classes, but in this case, it seemed evident that the user was unaware of the legitimate compromise. This little snippet of code helped us find out where attendees were in the classrooms, based on Wireless AP connection, so we could notify them about their compromised systems.

A simple Arista API implementation that tracked where users were located on the conference floor.

Throughout our analysis we also identified another instance of direct malware compromise and related network communication which matched the activity of an AutoIT.F trojan communicating over a command and control (C2) to a well-know malicious IP [link to a JoeBox report]. The C2 the adversary used was checking on TCP ports 2842 and 9999. The example of AutoIT.F trojan request, observed on the network can be found below.

Example of AutoIT.F trojan traffic.

Above traffic sample was decoded, to extract C2 traffic record and the following decoded strings appeared to be the final payload. Notice that the payload included hardware specification, build details and system name along with other details.

AutoIT.F decoded trojan traffic sample

Likewise, in this case, we managed to track the compromised system through the Wi-Fi connection and notifiy the user that their system appeared to be compromised.

Clear Text authentication still exists in 2023

Although not directly related to malware infection, we did discover a few other interesting findings during our threat hunt, including numerous examples of clear text traffic disclosing email credentials or authentication session cookies for variety of applications. In some instances, it was possible to observe clear-text LDAP bind attempts which disclosed which organization the device belonged to or direct exposure of the username and password combination through protocols such as POP3, LDAP, HTTP (Hyper Text Transfer Protocol) or FTP. All these protocols can be easily subverted by man-in-the-middle (MitM) attacks, allowing an adversary to authenticate against services such as email. Below is an example of the plain text authentication credentials and other details observed through various platforms available at Black Hat.

Cleartext passwords and usernames disclosed in traffic.

Other examples of clear text disclosure were observed via basic authentication which simply used base64 to encode the credentials transmitted over clear text. An example of this was noticed with an Urban VPN (Virtual Private Network) provider which appears to grab configuration files in clear text with basic authentication.

Base64 credentials used by Urban VPN to get configuration files.

A few other instances of various clear text protocols such as IMAP were also identified on the network, which we were surprised to still be use in 2023.

iPhone Mail using IMAP to authenticate.

What was interesting to see is that several modern mobile applications, such as iPhone Mail, are happy to accept poorly configured email servers and use insecure services to serve basic functionalities, such as email reading and writing. This resulted in numerous emails being present on the network, as seen below:

Email reconstruction for clear text traffic.

This year, we also identified several mobile applications that not only supported insecure protocols such as IMAP, but also performed direct communication in clear text, communicating everything in clear text, including user pictures, as noted below:

Images transmitted in clear text.

In several instances, the mobile application also transmitted an authentication token in clear text:

Authentication token transmitted in clear text.

Even more interesting was the fact that we have identified a few vendors attempting to download links to patches over HTTP, as well. In some instances, we have seen original requests sent over HTTP protocol with the “Location” header response in clear text pointing to an HTTPS location. Although I would expect these patches to be signed, communicating over HTTP makes it quite easy to modify the traffic in MitM scenario to redirect downloads to separate locations.

HTTP download of suspected patches.
HTTP download of suspected patches.

There were numerous other examples of HTTP protocol used to perform operations such as reading emails through webmail portals or downloading PAC files which disclose internal network details as noted on the screenshots below.

Clear text email inbox access.
PAC files observed in clear text, disclosing internal network setup.

Cisco XDR technology in action

In addition to the usual technology portfolio offered by Cisco and its partners, this year was also the first year I had the pleasure of working with Cisco XDR console, which is a new Cisco product. The idea behind XDR is to give a single “pane of glass” overview of all the different alerts and technologies that work together to secure the environment. Some of Cisco’s security products such as Cisco Secure Endpoint for iOS and Umbrella were connected to via XDR platform and shared their alerts, so we could use these to gain a quick understanding of everything that is happening on network from different technologies. From the threat hunting perspective, this allows us to quickly see the state of the network and what other devices and technologies might be compromised or execute suspicious activities.

XDR console at the very beginning of the conference.
XDR console on 10:35 a.m. on Aug. 5, 2023.

While looking at internal traffic, we also found and plotted quite a few different port scans running across the internal and external network. While we would not stop these unless they were sustained and egregious, it was interesting to see different attempts by students to find ports and devices across networks. Good thing that network isolation was in place to prevent that.

The example below shows quick external investigation using XDR, which resulted in successful identification of this type of activity. What triggered the alert was a series of events which identified scanning and the fact that suspected IP also had relationships with several malicious files seen in VirusTotal:

XDR correlation on suspected port scanner.

Based on this analysis, we quickly confirmed that port scanning is indeed valid and determined which devices were impacted, as seen below. This, combined with visibility from other tools such as Palo Alto Networks boundary firewalls, gave us stronger confidence in our raised alerts. The extra contextual information related to malicious files also allowed us to confirm that we are dealing with a suspicious IP.

XDR correlation mapping to additional attributes.

Throughout the Black Hat conference, we saw many different attacks spanning across different endpoints. It was helpful to be able to filter on these attacks quickly to find where the attack originated and whether it was a true positive.

XDR correlation on specific IP to identify connectivity to malicious domain and traffic direction.

Using the above view, it was also possible to directly observe what contributed to the calculation of malicious score and what sources of threat intelligence could be used to identify how was the malicious score calculated for each of the components that made up the overall alert.

A breakdown of XDR correlation of threat intelligence on specific IP.

It’s not just about internal networks

In terms of the external attacks, Log4J, SQL injections, OGLN exploitation attempts, and all kinds of enumeration were a daily occurrence on the infrastructure and the applications used for attendee registration, along with other typical web-based attacks such as path traversals. The following table summarizes some of the observed some of the successfully blocked attacks where we have seen the biggest volume. Again, our thanks to Palo Alto Networks for giving us access to their Panorama platform, so we can observe various attacks against the Black Hat infrastructure.

A summary of the most frequent external attacks observed during Black Hat 2023.

Overall, we saw a sizeable number of port scans, floods, probes and all kinds of web application exploitation attempts showing up daily at various peak hours. Fortunately, all of them were successfully identified for context (is this part of a training class or demonstration?) and contained (if appropriate) before causing any harm to external systems. We even had a suspected Cobalt Strike server (179.43.189[.]250) [link to VirusTotal report] scanning our infrastructure and looking for specific ports such as 2013, 2017, 2015 and 2022. Given the fact that we could intercept boundary traffic and investigate specific PCAP (packet capture) dumps, we used all these attacks to identify various C2 servers for which we also hunted internally, to ensure that no internal system is compromised.

Network Assurance, by Ryan MacLennan and Adam Kilgore

Black Hat USA 2023 is the first time we deployed a new network performance monitoring solution named ThousandEyes. There was a proof of concept of ThousandEyes capabilities at Black Hat Asia 2023, investigating a report of slow network access. The investigation identified the issue was not with the network, but with the latency in connecting to a server in Ireland from Singapore. We were asked to proactively bring this network visibility and assurance to Las Vegas.

ThousandEyes utilizes both stationary Enterprise Agents and mobile Endpoint Agents to measure network performance criteria like availability, throughput, and latency. The image below shows some of the metrics captured by ThousandEyes, including average latency information in the top half of the image, and Layer 3 hops in the bottom half of the image with latency tracked for each network leg between the Layer 3 hops.

The ThousandEyes web GUI can show data for one or many TE agents. The screenshot below shows multiple agents and their respective paths from their deployment points to the Black Hat.com website.

We also created a set of custom ThousandEyes dashboards for the Black Hat convention that tracked aggregate metrics for all of the deployed agents.

ThousandEyes Deployment

Ten ThousandEyes Enterprise Agents were deployed for the conference. These agents were moved throughout different conference areas to monitor network performance for important events and services. Endpoint Agents were also deployed on laptops of NOC technical associate personnel and used for mobile diagnostic information in different investigations.

Coming into Black Hat with knowledge of how the conference will be set up was key in determining how we would deploy ThousandEyes. Before we arrived at the conference, we made a preliminary plan on how we would deploy agents around the conference. This included what kind of device would run the agent, the connection type, and rough locations of where they would be set up. In the image below you can see we planned to deploy ThousandEyes agents on Raspberry Pi’s and a Meraki MX appliance

The plan was to run all the agents on the wireless network. Once we arrived at the conference, we started prepping the Pi’s for the ThousandEyes image that was provided in the UI (User Interface). The below image shows us getting the Pi’s out of their packaging and setting them up for the imaging process. This included installing heatsinks and a fan.

After all the Pi’s were prepped, we started flashing the ThousandEyes (TE) image onto each SD-Card. After flashing the SD-Cards, we needed to boot them up, get them connected to the dashboard and then work on enabling the wireless. While we had a business case that called for wireless TE agents on Raspberry Pi, we did have to clear a hurdle or wireless not being officially supported for the Pi TE agent. We had to go through a process of unlocking (jailbreaking) the agents, installing multiple networking libraries to enable the wireless interface, and then create boot up scripts to start the wireless interface, get it connected, and change the routing to default to the wireless interface. You can find the code and guide at this GitHub repository.

We confirmed that the wireless configurations were working properly and that they would persist across boots. We started deploying the agents around the conference as we planned and waited for them all to come up on our dashboard. Then we were ready to start monitoring the conference and provide Network Assurance to Black Hat. At least that is what we thought. About 30 minutes after each Pi came up in our dashboard, it would mysteriously go offline. Now we had some issues we needed to troubleshoot.

Troubleshooting the ThousandEyes Raspberry Pi Deployment

Now that our Pi’s had gone offline, we needed to figure out what was going on. We took some back with us and let them run overnight with one using a wired connection and one on a wireless connection. The wireless one did not stay up all night, while the wired one did. We noticed that the wireless device was significantly hotter than the wired one and this led us to the conclusion that the wireless interface was causing the Pi’s to overheat.

This conundrum had us confused because we have our own Pi’s, with no heatsinks or fans, using wireless at home and they never overheat. One idea we had was that the heatsinks were not cooling adequately because the Pi kits we had used a thermal sticker instead of thermal paste and clamp like a typical computer. The other was that the fan was not pushing enough air out of the case to keep the internal temperature low. We reconfigured the fan to use more voltage and flipped the fan from pulling air out of the case to pushing air in and onto the components. While a fan placed directly on a CPU should pull the hot air off the CPU, orienting the Raspberry Pi case fan to blow cooler air directly onto the CPU can result in lower temperatures. After re-orienting the fan, to blow onto the CPU, we did not have any new heating failures.

Running a couple of Pi’s with the new fan configuration throughout the day proved to be the solution we needed. With our fixed Pi’s now staying cooler, we were able to complete a stable deployment of ThousandEyes agents around the conference.

ThousandEyes Use Case

Connectivity problems with the training rooms were reported during the early days of the conference. We utilized several different methods to collect diagnostic data directly from the reported problem areas. While we had ThousandEyes agents deployed throughout the conference center, problem reports from individual rooms often required a direct approach that brought a TE agent directly to the problem area, often targeting a specific wireless AP (Access Points) to collect diagnostic data from.

One specific use case involved a report from the Jasmine G training room. A TE engineer traveled to Jasmine G and used a TE Endpoint Agent on a laptop to connect to the Wi-Fi using the PSK assigned to the training room. The TE engineer talked to the trainer, who shared a specific web resource that their training session depended on. The TE engineer created a specific test for the room using the online resource and collected diagnostic data which showed high latency.

During the collection of the data, the TE agent connected to two different wireless access points near the training room and collected latency data for both paths. The connection through one of the APs showed significantly higher latency than the other AP, as indicated by the red lines in the image below.

ThousandEyes can generate searchable reports based on test data, such as the data shown in the prior two screenshots. After capturing the test data above, a report was generated for the dataset and shared with the wireless team for troubleshooting. 

Mobile Device Mangement, by Paul Fidler and Connor Loughlin

For the seventh consecutive Black Hat conference, we provided iOS mobile device management (MDM) and security. At Black Hat USA 2023, we were asked to manage and secure:

Registration: 32 iPads
Session Scanning: 51 iPads
Lead Retrieval: 550 iPhones and 300 iPads

When we arrived for set up three days before the start of the training classes, our mission was to have a network up and running as soon as is humanly possible, so start managing the 900+ devices and check their status.

Wi-Fi Considerations

We had to adjust our Wi-Fi authentication schema. In the prior four Black Hat conferences, the iOS devices were provisioned with a simple PSK based SSID that was available everywhere throughout the venue. Then, as they enrolled, they were also pushed a certificate / Wi-Fi policy (where the device then went off and requested a cert from a Meraki Certificate Authority, ensuring that the private key resided securely on the device. At the same time, the certificate name was also written into Meraki’s Cloud Radius.

As the device now had TWO Wi-Fi profiles, it was now free to use its inbuilt prioritisation list (more details here) ensuring that the device joined the more secure of the networks (802.1x based, rather than WPA2 / PSK based). Once we were sure that all devices were online and checking in to MDM, we then removed the cert profile from the devices that were only used for Lead Retrieval, as the applications used for this were internet facing. Registration devices connect to an application that’s actually on the Black Hat network, hence the difference in network requirements.

For Black Hat USA 2023, we just didn’t have time to formulate a plan for the devices that would allow those that needed to have elevated network authentication capabilities (EAP-TLS in all likelihood), as the devices were not connecting to a Meraki network anymore, which would have enabled them to use the Sentry capability, but instead an Arista network.

For the future, we can do one of two things:

Provision ALL devices with the same Wi-Fi creds (either Registration or Attendee) Wi-Fi at the time of enrolment and add the relevant more secure creds (cert, maybe) as they enroll to the Registration iPads ONLY
More laboriously, provision Registration devices and Session Scanning / Lead Retrieval devices with different credentials at the time of enrolment. This is less optimal as:

We’d need to know ahead of time which devices are which used for Session Scanning, Lead Retrieval or Registration
It would introduce the chance of devices being provisioned with the wrong Wi-Fi network creds

When a Wi-Fi profile is introduced at the time of Supervision, it remains on the device at all times and cannot be removed, so option 2 really does have the opportunity to introduce many more issues.

Automation – Renaming devices

Again, we used the Meraki API and a script that goes off, for a given serial number, and renames the device to match the asset number of the device. This has been quite successful and, when matched with a policy showing the Asset number on the Home Screen, makes finding devices quick. However, the spreadsheets can have data errors in them. In some cases, the expected serial number is the device name or even an IMEI. Whilst we can specify MAC, Serial and SM device ID as an identifier, we can’t (yet) supply IMEI.

So, I’ve had to amend my script so that it, when it first runs, gets the entire list of enrolled devices and a basic set of inventories, allowing us to look up things like IMEI, device name, etc., returning a FALSE if still not found or returning the Serial if found. This was then amended further to search the Name key if IMEI didn’t return anything. It could, theoretically, be expanded to include any of the device attributes! However, I think we’d run quickly into false positives.

The same script was then copied and amended to add tags to devices. Again, each device has a persona:

Registration
Lead Retrieval
Session Scanning

Each persona has a different screen layout and application required. So, to make this flexible, we use tags in Meraki Systems Manager speak. This means that if you tag a device, and tag a setting or application, that device gets that application, and so on. As Systems Manager supports a whole bunch of tag types, this makes it VERY flexible with regards to complex criteria for who gets what!

However, manually tagging devices in the Meraki Dashboard would take forever, so we can utilise an API to do this. I just had to change the API call being made for the renaming script, add a new column into the CSV with the tag name, and a couple of other sundry things. However, it didn’t work. The problem was that the renaming API doesn’t care that the ID that is used: MAC, Serial or SM Device ID. The Tagging API does, and you must specify which ID that you’re using. So, I’d changed the Alternative Device ID search method to return serial instead of SM device ID. Serial doesn’t exist when doing a device lookup, but SerialNumber does! A quick edit and several hundred devices had been retagged.

Of course, next time, all of this will be done ahead of time rather than at the conference! Having good data ahead of time is priceless, but you can never count on it!

Caching Server

Downloading iOS 16.6 is a hefty 6GB download. And whilst the delta update is a mere 260MB, this is still impactful on the network. Whilst the download takes some time, this could be massively improved by using a caching server. Whilst there’s many different ways that this could be achieved, we are going to research using the caching capability built into macOS (please see documentation here). The rational for this is that:

It supports auto discover, thus there’s no need to build the content caching at the edge of the network. It can be built anywhere, and the devices will auto discover this
It’s astoundingly simple to set up
It will be caching both OS (Operating System) updates AND application updates

Whilst there wasn’t time to get this set up for Black Hat USA 2023, this will be put into production for future events. The one thing we can’t solve is the humongous amount of time the device needs to prepare a software update for installation!

Wireless

Predictably (and I only say that because we had the same issue last year with Meraki instead of Arista doing the Wi-Fi), the Registration iPads suffered from astoundingly poor download speeds and latency, which can result in the Registration app hanging and attendees not being able to print their badges.

We have three requirements in Registration:

General Attendee Wi-Fi
Lead Retrieval and Session Scanning iOS devices
Registration iOS devices

The issue stems from when both Attendee SSID and Registration SSID are being broadcast from the same AP. It just gets hammered, resulting in the aforementioned issues.

The takeaway from this is:

There needs to be a dedicated SSID for Registration devices
There needs to be a dedicated SSID throughout Black Hat for Sessions Scanning and Lead Retrieval (This can be the same SSID, just dynamic or identity (naming changes depending on vendor) PSK)
There needs to be dedicated APs for the iOS devices in heavy traffic areas and
There needs to be dedicated APs for Attendees in heavy traffic areas

Lock Screen Message

Again, another learning that came too late. Because of the vulnerability that was fixed in iOS 16.6 (which came out the very day that the devices were shipped from Choose2Rent to Black Hat, who prepared them), a considerable amount of time was spent updating the devices. We can add a Lock Screen message to the devices, which current states: ASSET # – SERIAL # Property of Swapcard

Given that a visit to a simple webpage was enough to make the device vulnerable, it was imperative that we updated as many as we could.

However, whilst we could see with ease the OS version in Meraki Systems Manager, this wasn’t the case on the device: You’d have to go and open Settings > General > About to get the iOS Version.

So, the thoughts occurred to me to use the Lock Screen Message to show the iOS version as well! We’d do this with a simple change to the profile. As the OS Version changes on the device, Meraki Systems Manager would see that the profile contents had changed and push the profile again to the device! One to implement for the next Black Hat!

The Ugly….

On the evening of the day of the Business Hall, there was a new version of the Black Hat / Lead Retrieval app published in the Apple App Store. Unfortunately, unlike Android, there’s no profiles for Apple that determine the priority of App updates from the App Store. There is, however, a command that can be issued to check for and install updates.

In three hours, we managed to get nearly 25% of devices updated, but, if the user is using the app at the time of the request, they have the power to decline the update.

The Frustrating…

For the first time, we had a few devices go missing. It’s uncertain as to whether these devices are lost or stolen, but…

In past Black Hat events, when we’ve had the synergy between System Manager and Meraki Wi-Fi, it’s been trivial, as inbuilding GPS (Global Positioning System) is not existent, to have a single click between device and AP and vice versa. We’ve obviously lost that with another vendor doing Wi-Fi, but, at the very least, we’ve been able to feed back the MAC of the device and get an AP location.

However, the other frustrating thing is that the devices are NOT in Apple’s Automated Device Enrollment. This means that we lose some of the security functionality: Activation Lock, the ability to force enrollment into management after a device wipe, etc.

All is not lost though: Because the devices are enrolled and supervised, we can put them into Lost Mode which locks the device, allows us to put a persistent message on the screen (even after reboot) and ensure that the phone has an audible warning even if muted.

You can find the code and guide at this GitHub repository and the guide in this blog post.

SOC Cubelight, by Ian Redden

The Black Hat NOC Cubelight was inspired by several projects primarily the 25,000 LED Adafruit Matrix Cube (Overview RGB LED Matrix Cube with 25,000 LEDs

By |2023-08-31T13:53:52+00:00August 31, 2023|Cisco: Learning|0 Comments

Cisco Secure Access will enable MSSPs to provide comprehensive SSE capabilities Nathaniel Hang on August 25, 2023 at 3:00 pm

At Cisco Live 2023, Cisco announced Cisco Secure Access — a cloud-delivered Security Service Edge (SSE) product that provides comprehensive security capabilities converged in one solution, providing Zero Trust Network Access (ZTNA), Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Firewall-as-a-Service (FWaaS), DNS security and filtering, and Remote Access VPN capability in a unified management experience with centralized policy creation and aggregated reporting capabilities.

Traditionally, these security functions were supported by multiple point solutions; with products and their respective functions stitched together to address evolving IT requirements and secure the network. While this approach can and has worked, it significantly increases the complexity, and results in an environment that is difficult to monitor and manage effectively due to multiple administrative interfaces, less than optimal integrations, and gaps in security due to multiple point product solutions and vendors. This often results in high complexity, less security efficacy, high operational costs, and a poor end-user experience.

To address this problem, Cisco Secure Access was designed and built with three main guiding principles:

Better for users – Deliver a universal experience that seamlessly and securely connects any user to any app over any port or protocol.
Easier for IT – Simplify deployment and operations with a single console, unified client, and centralized policy management.
Safer for everyone – Mitigate risk with advanced security to maintain business continuity and avoid the repercussions of a security breach.

Comprehensive integration is key to effective security

A typical enterprise has roughly 76 security related tools in their arsenal to address various security needs, and a multi-vendor patchwork approach to solving threats places the burden of security tools integration on the end-customer, exacerbating the problem of operational complexity and resulting in increased costs. Previous generation SSE products also had many issues such as a lack of support for certain types of applications, complex product packaging, and requiring costly add-on features to get desired functionality. With SD-WAN now evolving towards SASE (or SD-WAN with SSE), the transition from multi-vendor solutions towards single-vendor solutions is also accelerating due to the need to simplify the environment and enable better security efficacy and efficiency. In fact, according to a recent Gartner survey, 75% of organizations are now seeking to consolidate security solutions and reduce the number of vendors in order to improve their risk posture.

Cisco Secure Access is the logical next-generation SSE platform of choice

Cisco Secure Access differentiates from the competition; it provides the most flexible ZTNA offering on the market, combining VPN-as-a-Service (VPNaaS) with client-based and clientless ZTNA, which makes it capable of supporting ANY application over ANY port or protocol, including Internet based, SaaS, and private applications. In short, “users simply login and get to work” in the most efficient and secure way available.

Unlike traditional ZTNA that is built with a reverse proxy architecture, Cisco takes a unique approach through a more modern Zero Trust access relay architecture. This reduces the attack surface and enables an enhanced level of enterprise privacy by giving organizations more control over their data and inspection points. It enables them to easily create policies that enforce whether specific traffic is routed through cloud security or directly to their edge security device.

Secure Access supports the key network use cases and provides unified security functions while with a unified management dashboard with a new and intuitive admin interface designed with simplicity, efficiency, and efficacy in mind. Secure Access is a SSE product that provides comprehensive, best-of-breed security capabilities such as:

Secure Web Gateway (SWG) – providing proxy web traffic, URL filtering, content filtering, and advanced application controls.
Cloud Access Security Broker (CASB) – provides cloud app discovery, risk scoring, blocking, cloud malware detection, and tenant controls.
Data Loss Prevention (DLP) – provides the ability to define and quarantine files that violate DLP rules, preventing leakage of sensitive information for supported applications.
Firewall-as-a-Service (FWaaS) – provides Layer 3/L4/L7 firewall functionality with IPS using Snort 3 technology.
DNS-layer security – prevents or limits visits to nefarious web sites, or by blocking access to designated website categories.
Remote Access – provide VPN and/or client based ZTNA for managed endpoints, or clientless ZTNA access for unmanaged endpoints with optional device posture verification (e.g., geolocation, browser type, and/or Operating System type/versions).
Remote Browser Isolation (RBI) – protects users and organizations from browser-based threats.
Secure Malware Analytics and Sandboxing capabilities – advanced sandboxing with threat intelligence into one unified solution to protect organizations from malware.
Digital Experience Monitoring – integration with ThousandEyes, enabling unparalleled visibility and ability to translate insights into actions to help resolve issues quickly and assure digital experiences across any network.

Cisco Secure Access integrates with Cisco Catalyst SD-WAN products and provides comprehensive visibility, policy controls, and reporting capabilities; one dashboard to see traffic, set policies, and analyze risk. Built on the Cisco Security Cloud, Secure Access combines all core capabilities to create a frictionless, end-user experience. It is supported by research, expertise, and intelligence from Cisco Talos; the world’s largest commercial security and threat intelligence entity, where teams of data scientists and security researchers are able to take advantage of Artificial Intelligence (AI)/Machine Learning (ML) technologies along with extensive security intelligence to enable improved security efficacy with faster detection, stronger threat correlation, deeper visibility and insights, and reduced exposure.

Massive partner opportunity as customers are transitioning towards Managed Services and business outcome based offerings

If you are a Cisco partner and offer network services to your end customers, now is the time to consider adding or supplementing security services on top of your network services offering for the following reasons:

According to a Gartner report, the Secure Access Secure Edge (SASE) and SSE market is massive with a ~36% CAGR and a world-wide opportunity approaching ~$10 BILLION by 2025!
Approximately 65% of enterprise customers are looking to adopt SSE in the next two years in order to safeguard their infrastructure/environments and improve their risk posture.
According to a 2023 Cisco Cybersecurity Readiness Index, approximately 85% of customers felt that they were not adequately prepared to handle cybersecurity threats due to distributed/complex environments making securing network connectivity difficult.

The next chapter in managed security services is here

For Cisco Partners—particularly Managed Security Service Providers (MSSPs)—there is a huge opportunity to help customers achieve a frictionless end-user experience, simplify their IT operations, and lower their security risk. Customers are now shifting towards leveraging MSSPs who can provide Network and Security as-a-Service support to address their evolving business requirements.

Per the 2023 Cisco Cybersecurity Readiness Index:

More than half (55%) of companies globally fall into the Beginner (8%) or Formative (47%) stages – meaning they are performing below average on cybersecurity readiness.
Approximately 82% of respondents said they expect a cybersecurity incident to disrupt their business in the next 12 to 24 months.
Approximately 86% of respondents said their organizations plan to increase their cybersecurity budget by at least 10% over the next 12 months.

To that end, customers are seeking the guidance of MSSPs and are looking for business outcomes such as:

Comprehensive 24x7x365 monitoring and accountability.  MSSPs that can provide around the clock monitoring of the infrastructure and be responsible for proactively monitoring the environment, managing, and respond accordingly.
MSSPs further differentiate by offering tangible and additional benefits to customers, such as faster time to identify and resolve problems, increased operational efficacy, application of industry best practices, all while improving overall end user experience and delivering the desired business outcomes with agreed to service levels.  This results in lower operating costs, better efficiencies of scale, reduced business risk, which ultimately translates to freeing up precious time/resources so that customers can focus on their core business functions and not managing their IT.
Providing expertise and an even more premium experience by combining SASE/SSE with XDR, resulting in further enhanced security efficacy, faster and more accurate threat detection and response, and stronger security posture.

Cisco Partner-Enabled Managed Services offering and benefits

If you are a Cisco partner and would like to find out how to monetize this opportunity, please register for the upcoming session of the Managed Services Voice of the Engineer. In this session, our team from the Americas Partner Organization (APO) will provide an overview of Cisco Secure Access and how it can be offered as part of a Partner-Enabled Managed Services offering and explore the benefits that can be attained for both Cisco partners and your customers. If you are interested in becoming a Cisco Partner, you can learn more by visiting Cisco’s Partner Program and Cisco Partner-Enabled Managed Services.

 

Register for the Managed Services Voice of the Engineer session.

Learn more about everything that Cisco Secure Access has to offer.

 

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with #CiscoPartners on social!

Cisco Partners Facebook    Cisco Partners LinkedIn

Share

  Cisco Secure Access is simply the most flexible ZTNA offering on the market, combining VPN-as-a-Service (VPNaaS) with client-based and clientless ZTNA. It supports ANY application over ANY port or protocol, including Internet-based, SaaS, and private applications. In short, “users simply login and get to work” in the most efficient and secure way available.  Read More Cisco Blogs 

By |2023-08-31T13:15:04+00:00August 31, 2023|Cisco: Learning|0 Comments

My Experience as a First-Time Cisco Live Speaker Akhila Pamukuntla on August 29, 2023 at 7:54 pm

When I stepped into the world of technology, I never imagined I would see this day so early in my career. Since I’m a fairly recent addition to the Cisco family, the opportunity to attend Cisco Live in Las Vegas was already momentous. Little did I know this experience would surpass all expectations. I found myself embracing a role I never anticipated: Speaker!

I don’t know if you can imagine my initial shockwaves when I received an unexpected invitation to assist a seasoned expert with a 4-hour lab session. I wasn’t just excited. I was humbled to know someone recognized my potential and trusted me with such responsibility.

I am going to take you behind the scenes of Cisco Live for a glimpse into what speakers experience. You’ll view the other side of the speaker curtain, see what it’s like to prepare, and even find some humor in my first-time story.

“The audience is not against you; they’re rooting for you,” he said.

“They’re there to learn something.”

First impressions of Cisco Live Las Vegas

Akhila Pamukuntla takes the Cisco. U Theater stage to present.

When I arrived in the vibrant city of Las Vegas for Cisco Live, I was struck by the grandeur and scale of Cisco Live. The excitement in the air was visible as attendees and exhibitors from all corners of the globe flooded the Mandalay Bay Convention Center.

Standing in the middle of the busy convention halls, I saw teams diligently setting up booths and displays. I felt nervous yet exhilarated.

My first session on Jupyter Notebook was also the opener for the Cisco U. Theater. Before taking the stage, I was apprehensive at the thought of addressing such a large audience, but I felt confident. I drew strength in knowing I was well-prepared and passionate about the topic. Plus, I had supportive mentors around me.

With a deep breath, I took the stage. I was ready—ready to deliver the session that would set the tone for an incredible week of learning.

In November 2022, Hank Preston, Principal Engineer, asked me to assist him with his four-hour, instructor-led lab session. I was pretty excited because I didn’t think many Cisconians got to go to Cisco Live this quickly in their career. But I was also nervous because it was Hank, a celebrity in the networking field. I didn’t know how I would be able to present. But of course, I said yes, and we started putting the lab together.

Cisco U. had recently been introduced to the world. So the Cisco U. Theater was set up at the Learning & Certifications (L&C) booth, and they asked speakers from L&C to present on any topic they wanted to in the Cisco U. Theater. I chose Jupyter Notebook (a sort of command line interface [CLI] for Python) because I had used it a lot in college, and it was different than what everyone else would present.

How I became a Cisco Live speaker

Akhila Pamukuntla and Hank Preston practice their Cisco Live sessions.

It all began in November 2022 when Hank Preston, Principal Engineer, asked me to assist him with his 4-hour, instructor-led lab session. I was pretty excited. After all, I didn’t think the chance to attend Cisco Live was all that common for people like me—those so early in their Cisco career, that is.

But I was also nervous. This was Hank Preston. Hank is pretty much a celebrity in the networking field. At the thought of pairing up with him, I wondered how I would be able to present. But of course, I said yes. And we started putting the lab—our lab— together.

Just when I thought Hank’s lab session was my only focus for Cisco Live Las Vegas, I was invited to speak at the Cisco U. Theater!

About the Cisco U. Theater

We recently introduced the world to Cisco U., a new digital learning experience that offers modular, bite-sized learning in your moment of need. The Cisco U. Theater is an iteration of this concept, offering short lightning talks on specific tech topics. One of the best parts of the theater is Cisco Live attendees can drop in at a moment’s notice as they visit the Learning and Certifications Booth in the World of Solutions.

So when the team offered me the chance to present on my choice of topic, I chose Jupyter Notebook. Jupyter Notebook is a sort of command line interface (CLI) for Python. I had used it a lot in college, and it was different from what everyone else would present in the Cisco U. Theater.

Akhila Pamukuntla and Raymond Viscaina present, “What Happens When I Click Start Lab?”

So here I was thinking I was there to help with a lab session, but then I was asked to speak at the Cisco U. Theater! Not long after, my manager, Raymond Viscaina, Engineering Leader, asked me to assist him with his theater session, What Happens When I Click Start Lab. I couldn’t believe it. Now I had to prep for two theater sessions and a lab session. What a bonus!

Getting through prep sessions

Akhila Pamukuntla and Hank Preston prepare before Akhila’s Cisco U. Theater Session.

Surreal. It’s the only word I can think of to describe the prep for the lab session with Hank. However, as for my solo session in the theater, I was too focused on my presentation to think about almost anything else.

I was lucky enough to have Engineering Leader Joe Rinehart assigned as my mentor a few weeks before the event. As I practiced my solo session with Joe, some of the tips he gave included: “Practice often, practice in front of a mirror, and space matters.

He said I should find a space like an empty room or theater, which is a lot different than practicing in your bedroom. So, I went to my local library and asked for an empty room. With me, pre-event blueprints of the theater and a map of the booth layout. I even had a photo of Cisco Live Amsterdam’s crowd at the Cisco U. Theater to prepare me for the volume of attendees in Las Vegas, despite hearing Las Vegas would be much greater in scale.

About two weeks before I left, I was using every tool in my arsenal to visualize the event, mentally preparing myself. And that’s when I realized my session was the opening session—the very first Cisco U. Theater session of the week.

Until that moment, I didn’t even know what time or day I was presenting; I just kept practicing. But when I saw the date was Monday at 10 a.m. Pacific Time, I realized no other speaker was scheduled before me. Well, you can imagine my reaction.

I was terrified.

Presenting on the big day

Akhila Pamukuntla presents in front of a full theater.

Not only was I the first speaker to present in the theater, but the Learning and Certifications Booth was the first sight for attendees upon entering the World of Solutions. The WoS also opened at the exact same time as my session, and attendees were ready and waiting. I became a bundle of nerves when I saw the onslaught of people.

Before we started, we had to test my microphone. First, they put it on my T-shirt. That didn’t sound right. So, then they gave me a headset. That didn’t work out, either. My head is kind of small, so we had to work a little harder to get it to fit.

“Speak louder,” they said. They kept telling me, repeatedly, to speak louder during the mic test. I felt like I was yelling. I soon realized I had to speak louder because more people would be entering the World of Solutions during the presentation. No pressure, I thought.

When I finally started speaking to the crowd, I saw Joe, my pre-Cisco-Live prep mentor. I immediately recalled something important he said during those sessions.

“The audience is not against you; they’re rooting for you,” he said. “They’re there to learn something.”

My session was streaming live on the Cisco Training and Certification LinkedIn page and on the Cisco U. by Learning and Certifications YouTube Channel. My family was watching. No pressure.

When I first started my presentation, I could feel my voice shaking. Maybe three to five minutes into it, though, I realized it wasn’t as bad as I thought it would be. I tried to make eye contact with as many people as I could. I was still a bit scared. What if they didn’t react?

But with every head nod, I felt my confidence grow. I was making sense to them. And that kept me going.

During my talk, I asked the audience questions. “How many of you are familiar with Jupyter and have used it before?” My goal was to get them engaged. That was one of Hank’s tips. You need to know if they’re with you. (And yes, a few people had heard of Jupyter and had even used it before.)

An engaged crowd at the Cisco U. Theater.

Next up, a demo. I was actually showing them Jupyter Notebook live, in real time. The lines of code were already written, with me executing and explaining each step as I went through it. I noticed people typing along, taking notes as I continued.

Finally, I had made it through. And what a relief! After that, my other presentations fell into place; the Cisco U. Theater session with my manager, plus the 4-hour lab session with Hank. Ironically, although I was in a smaller room, I was more nervous there. And the one part I had practiced the most was the part I slightly stumbled over! I got through that as well, though. I must say, looking back at my experience, I learned a lot about presenting from being a speaker at Cisco Live. But the thing that I will always remember is how I got there: my mentors.

Mentors make all the difference

When I reflect on the whole Cisco Live experience, I realize I went through quite a transformation. Initially, the fear of presenting in front of a crowd and being surrounded by professionals overwhelmed me. However, looking back now, I realize it was the incredible individuals I encountered and the meaningful conversations we shared that made my experience truly unforgettable.

It wasn’t just the colleagues and peers around me. It was also those whom I presented to. It was every unexpected message I received on LinkedIn, asking to learn more about the topic of my session. It was when I was singled out and stopped by attendees on the aisles of Cisco Live to express their appreciation for my theater session.

The support and encouragement I received after my theater session reassured me. I had made a positive impact. But that’s not all. Speaking at Cisco Live sparked newfound confidence within me. It has taught me that it’s the people and the connections we form that ultimately make any experience meaningful and memorable. And I can’t wait to do it again.

Thanks for reading! I invite you to watch my first session as a Cisco Live Speaker below.

Watch “Jupyter Notebooks,” by Akhila Pumukuntla, presented in the Cisco U. Theater at Cisco Live 2023 Las Vegas.

 

Join the Cisco Learning Network today for free.

Follow Cisco Learning & Certifications

Twitter  Facebook

By |2023-08-31T13:15:04+00:00August 31, 2023|Cisco: Learning|0 Comments

Returning to Cisco: Discovering Company Values and Culture Matter the Most Janene Baker on August 29, 2023 at 12:00 pm

So, what happens when the Great Resignation turns into the great resurrection back to the company you first loved? Well, you get me, Janene Baker, a Talent Acquisition leader who, almost two years ago, was a part of the trend of employees who left for newer and what could’ve been perceived as better opportunities at other companies.

Cisco and I have a lot of history. When I talk about my career journey, I tell everyone I built and grew my career at Cisco. I worked my way up from an individual contributor to leading leaders during my 11-year tenure here. When I left, I thought I was at a point where it made sense to try something new, and sometimes that new thing seems big, shiny, and very appealing.

So, I took the leap, and I left Cisco.

On the surface, all was great. I was learning new skills and meeting new people — so my move was not for nothing, right? However, something was missing. I realized when you make a big life change, you learn more about yourself and what you truly value. I discovered — for me — it’s not about a role in a company with instant name recognition. I began to miss working at a place that aligned with who I am at my core. I longed to work for a place like Cisco that values and sees its employees and their well-being so much that they created “A Day for Me” each quarter, allowing them to prioritize themselves. I wanted to work for a company that takes a stand on social justice and backs it up with action through programs like OneTen, an initiative committed to unlocking potential, hiring, and advancing Black employees. I missed having the flexibility to live out the coined phrase “One Company, Many Careers” and be supported by leaders like our Chief People Officer, Kelly Jones, who embodies this exact expression and supported my development. At my core, I missed the Conscious Culture embedded in who Cisco is as a company.

When the stars aligned and I had the opportunity to return to Cisco, there was never a second guess or a second thought. It was an emphatic YES!

I wondered what people would think about me coming back just shy of being gone for two years. Well, let me tell you — it was like a homecoming party, and that’s when I knew I was right back where I needed to be. It’s been surreal coming back to the place that took a chance on me very early in my career and propelled me into my current leadership journey. It’s been humbling being back at the place that supported me personally through time off for my wedding all those years ago. Don’t even get me started on the benefits I was afforded when I became a new mom, not once, but three times here as I continued to grow my career. That’s a blog post all its own! It’s been fun seeing the work never stop, only evolve, and I can jump back in to continue building that Cisco bridge I know and love so much.

To my fellow Cisconians, before you assume the grass is greener on the other side, I encourage you to think about what motivates you; the true values you want to see in a company. Have that bold conversation with your leader about your development, growth, and needs because I can tell you — this Cisco culture is one that’s hard to beat (Hence the reason we’ve won #1 Best Workplace in the U.S. three years in a row!).

If you’re not at Cisco yet and wondering what all the hype is about, check out our Cisco careers here!

Subscribe to the We Are Cisco Blog.

So, what happens when the Great Resignation turns into the great resurrection back to the company you first loved? Well, you get me, Janene Baker, a Talent Acquisition leader who, almost two years ago, was a part of the trend of employees who left for newer and what could’ve been perceived as better opportunities at other companies.

Cisco and I have a lot of history. When I talk about my career journey, I tell everyone I built and grew my career at Cisco. I worked my way up from an individual contributor to leading leaders during my 11-year tenure here. When I left, I thought I was at a point where it made sense to try something new, and sometimes that new thing seems big, shiny, and very appealing.

So, I took the leap, and I left Cisco.

On the surface, all was great. I was learning new skills and meeting new people — so my move was not for nothing, right? However, something was missing. I realized when you make a big life change, you learn more about yourself and what you truly value. I discovered — for me — it’s not about a role in a company with instant name recognition. I began to miss working at a place that aligned with who I am at my core. I longed to work for a place like Cisco that values and sees its employees and their well-being so much that they created “A Day for Me” each quarter, allowing them to prioritize themselves. I wanted to work for a company that takes a stand on social justice and backs it up with action through programs like OneTen, an initiative committed to unlocking potential, hiring, and advancing Black employees. I missed having the flexibility to live out the coined phrase “One Company, Many Careers” and be supported by leaders like our Chief People Officer, Kelly Jones, who embodies this exact expression and supported my development. At my core, I missed the Conscious Culture embedded in who Cisco is as a company.

When the stars aligned and I had the opportunity to return to Cisco, there was never a second guess or a second thought. It was an emphatic YES!

I wondered what people would think about me coming back just shy of being gone for two years. Well, let me tell you — it was like a homecoming party, and that’s when I knew I was right back where I needed to be. It’s been surreal coming back to the place that took a chance on me very early in my career and propelled me into my current leadership journey. It’s been humbling being back at the place that supported me personally through time off for my wedding all those years ago. Don’t even get me started on the benefits I was afforded when I became a new mom, not once, but three times here as I continued to grow my career. That’s a blog post all its own! It’s been fun seeing the work never stop, only evolve, and I can jump back in to continue building that Cisco bridge I know and love so much.

To my fellow Cisconians, before you assume the grass is greener on the other side, I encourage you to think about what motivates you; the true values you want to see in a company. Have that bold conversation with your leader about your development, growth, and needs because I can tell you — this Cisco culture is one that’s hard to beat (Hence the reason we’ve won #1 Best Workplace in the U.S. three years in a row!).

If you’re not at Cisco yet and wondering what all the hype is about, check out our Cisco careers here!

Subscribe to the We Are Cisco Blog.

Share

  Talent Acquisition Manager Janene B. left Cisco in pursuit of something new but returned, realizing she needed a career and a company aligning with who she is at her core.  Read More Cisco Blogs 

By |2023-08-31T13:15:04+00:00August 31, 2023|Cisco: Learning|0 Comments

Manufacturing Leadership Summit: Five Takeaways Paul Didier on August 30, 2023 at 5:03 pm

Co-authored by Carlos Rojas and David Gutshall.

Manufacturing was front and center at Cisco Live US 2023, with several of the world’s leading manufacturers coming together to share experiences and dis… Read more on Cisco Blogs

Co-authored by Carlos Rojas and David Gutshall.

Manufacturing was front and center at Cisco Live US 2023, with several of the world’s leading manufacturers coming together to share experiences and discuss technology trends, challenges, and innovations. For example, Dr. Henning Löser, Head of the Audi Production Lab at Audi AG, joined the Cisco team for an Innovation Talk and Cube interview about the convergence of information technology (IT) and operational technology (OT). Dr. Löser shared details about the company’s innovative plans to virtualize key production assets with the goal to increase flexibility, lower costs, reduce maintenance, and improve security. A journey toward what Audi calls the Edge Cloud for Production (EC4P) platform.

We also hosted a Manufacturing Leadership Summit that brought together industry leaders from auto, renewable energy, pharmaceuticals, food and beverage, heavy industry, etc. for a more intimate discussion of experiences, challenges, and innovations. I sensed an undercurrent of positive energy and mutual respect as these leaders shared their stories around increasing levels of digitization, improving security, and deploying wired and wireless networks in new and existing plants and production lines. Many discussions focused on how to best drive IT/OT convergence, especially driven by tools like Cisco Catalyst Center (formerly known as Cisco DNA Center). Attendees also discussed efforts to boost visibility and cybersecurity. And we heard about the push to upgrade networking in existing plants and invest in wireless networks for automated guided vehicles (AGVs) and other mobile assets.

Having mulled over what I heard at Cisco Live US, I’ve landed on these five takeaways.

Takeaway #1: Manufacturing is heading towards a technology paradigm shift

As manufacturers increase digitization on factory floors, they can no longer look to individual pieces of hardware for certain features or functions. Instead, they need to invest in software that can provide the needed capabilities.

This paradigm shift was a key message emerging from the iTalk about Audi’s collaboration with Cisco. As Dr. Löser has noted, “To increase security, decrease support requirements, and improve flexibility, Audi is developing its Edge Cloud for Production (EC4P) platform. EC4P virtualizes production assets and relies on software-defined networking by Cisco IoT and Enterprise solutions that provide a scalable, resilient, secure and deterministic network.”

By making this shift from hardware to software, manufacturers can avoid significant maintenance headaches and reduce capital outlays. They can improve security and flexibility – all by streamlining hardware and virtualizing core computing assets like programmable logic controllers (PLCs), Human-Machine Interfaces (HMIs), and industrial personal computers (IPCs). The IoT Manufacturing Industry Summit provided evidence that this shift is already possible, with Roland Wagner – who leads Product Marketing at Codesys – demonstrating the readiness of the virtual PLC live.

Takeaway #2: Security remains top of mind

In a pre-event survey, manufacturing leaders expressed concerns about cybersecurity, with visibility and risk assessment topping their priorities. Another common barrier: lack of accuracy in knowing their own asset inventory, traffic flows, and what each asset is connected to. And yet, as manufacturers work to enable further digitization initiatives, they need to do more than achieve that kind of baseline visibility. They also need to establish access policies to segment their network so they can more precisely control network activity and prevent malware spread.

We often think about cybersecurity in terms of prevention and defense. Interestingly, one manufacturer shared how its cybersecurity investments produced a tangible return. This company used Cisco networking and security technology to address insurance-company inquiries into cybersecurity within its production environment. Having sound, defensible answers paid off in the form of significantly lower insurance premiums – which helped fund additional investments.

Takeaway #3: There’s plenty of appetite for wireless technologies in production environments

I was impressed with the level of demand for wireless technologies. When it comes to 5G and private 5G, though, there seems to be a lot of appetite but few, if any, real-world deployments. It seems that by combining other wireless solutions – namely WiFi and Cisco Ultra-Reliable Wireless Backhaul – companies can support many of their business needs and use cases, especially around mobile assets, such as Automated Guide Vehicles and AMRs that require reliable wireless connectivity.

Takeaway #4: Collaboration is critical to success

Cisco IoT has long advocated for stronger IT-OT partnerships. During the summit, it was fascinating to hear that nearly every customer reiterated the importance of IT-OT collaboration in powering the success of manufacturing digitization initiatives.  Most of the attending companies and speakers had OT involvement showing the trend towards deeper collaboration.

Informally, I heard some manufacturing leaders voicing being impressed by Dr. Löser openness about Audi’s EC4P vision and journey. From my perspective, it’s a willingness to acknowledge that all automotive manufacturers are facing some common problems – and a recognition that it will take an ecosystem (that includes competitors) response to solve them. By the way, I don’t think automotive is the only manufacturing segment where this kind of collaboration will be vital!

Takeaway #5: Solutions need to be simple, scalable, and easy to use

The summit affirmed that the manufacturing industry has made significant progress in digitization. Companies now want to take the next steps toward cloud, virtualization, and advanced security – the capabilities that Cisco can enable with our scalable, resilient, and secure industrial networking. I observed significant interest in several of our solutions, including Secure Equipment Access and the recently announced SKUs within the Cisco Catalyst IE9300 Rugged Series switches. Both meet the need for simplicity, scalability, and ease of use.

Whether you joined us in Las Vegas or are catching up remotely, here are some ways you can engage with Cisco and learn about our solutions:

Tune in to the iTalk featuring Audi’s EC4P vision and journey.
Watch a brief interview with Dr. Löser.
Learn more about Cisco Industrial Wireless solutions.
Schedule a free non-obligation 1-on-1 consultation with our manufacturing experts via our manufacturing contact form.

Share

  Industry leaders discussed the technology paradigm shift in manufacturing, and challenges and innovations around security, wireless technologies, and IT/OT collaboration.  Read More Cisco Blogs 

By |2023-08-31T01:11:32+00:00August 31, 2023|Cisco: Learning|0 Comments
Go to Top