New Feature Announcement of Oracle Cloud VMware Solution at VMware Explore Las Vegas 2023 Audrey Bian on August 22, 2023 at 3:00 pm
Greetings from the kickoff of VMware Explore Las Vegas! We [...]
Greetings from the kickoff of VMware Explore Las Vegas! We [...]
We are pleased to announce Oracle Cloud VMware Solution will [...]
Guest blog from Dave McCarthy, Vice President at IDC One [...]
VMware Cloud on AWS GovCloud (US) is a jointly engineered [...]
With VMware Cloud, customers can choose the best cloud environment [...]
At Cisco, we strongly believe in the power of the Internet. The Internet fosters free expression and accelerates the ability to educate, empower, and inspire people around the world. There has been… Read more on Cisco Blogs
At Cisco, we strongly believe in the power of the Internet. The Internet fosters free expression and accelerates the ability to educate, empower, and inspire people around the world. There has been no greater force in making information more accessible and opportunities more available.
Cisco is proud of its legacy and its leading role in powering the Internet. With nearly 40 years of networking experience, we’ve helped customers and partners make education better, infrastructure stronger, financial services more secure, transportation safer, and first responders faster.
We also recognize the inherent risk of this technology being misused. Navigating this balance – securely connecting billions of people while respecting human rights – is core to who we are at Cisco. Our sales activities are in strict compliance with U.S. export rules and regulations, which are informed and guided by human rights principles. We have supported the United Nations Global Compact (UNGC) since its inception in 2000, aligning our operations and strategies with ten universally accepted principles in the areas of human rights, labor, environment and anti-corruption. And our commitment to human rights continues to evolve to meet new challenges posed by the rapid pace of change across the tech sector.
There has been recent coverage about the Ninth Circuit Court’s revival of a long-dormant lawsuit, which would allow Falun Gong to sue Cisco in U.S. courts for selling off-the-shelf networking equipment in China that may have been used by the Chinese government to mistreat of Falun Gong members in China. This ruling by the Ninth Circuit, if it stands, would open the floodgates for suits against corporations in the U.S. for human right violations merely based on legal exports of goods and services. Cisco is deeply committed to human rights, and as we shared when this case was first filed in 2011, these claims are inaccurate and entirely without foundation. The off-the-shelf networking equipment at issue in this particular case was delivered more than 20 years ago, aligned with global industry standards, and was not modified for government use. Cisco has never customized our networking equipment to help the Chinese government—or any government—censor content, track Internet use by individuals, or intercept Internet communications.
Whether a foreign government violated international law through its treatment of its citizens is a highly sensitive matter of foreign policy, of which the Executive Branch of the U.S. government has comparative responsibility and expertise. Holding U.S. suppliers liable for the activities of foreign governments outside of the U.S., has the potential to not only disrupt the foreign policy efforts of the U.S. government, but also lead to a less connected, interoperable, and equitable world.
With these important issues at stake, Cisco has appealed the court’s decision. We will continue to advocate for a free and open Internet, in large part because of its ability to advance human rights. We will also continue to follow the rule of law, selling products in strict compliance with U.S. trade and export regulations. And without compromise, we will continue to stay true to our core values – respecting human rights across all aspects of our global operations.
At Cisco, we strongly believe in the power of the Internet to foster free expression and accelerate the ability to educate, empower, and inspire people around the world. Making information more accessible and opportunities more available comes with the inherent risk of this technology being misused. Navigating this balance – securely connecting billions of people while respecting human rights – is core to who we are at Cisco. Read More Cisco Blogs
As we celebrate World Entrepreneurs’ Day on August 21, it is interesting to reflect on how an established company like Cisco—a Fortune 500 company with more than 80,000 employees—relates to entre… Read more on Cisco Blogs
As we celebrate World Entrepreneurs’ Day on August 21, it is interesting to reflect on how an established company like Cisco—a Fortune 500 company with more than 80,000 employees—relates to entrepreneurship.
Innovation is at the heart of everything we do at Cisco. In fact, the qualities that define an entrepreneur such as risk taking, creativity, perseverance, and passion are foundational to the way we operate and pursue opportunities to serve our customers and communities. In fact, the very reason Cisco started in 1984 was born from personal desire to solve an urgent issue and need for personal connection.
Len Bosack and Sandy Lerner were not able to email each other from their respective offices at Stanford University because they were on different networks with different local area protocols. They developed the multiprotocol router, and that’s how Cisco was born!
Their entrepreneurial spirit lives on in a company that strives to solve business challenges for our customers today. Not only that, but Cisco also helps businesses large and small to seize the opportunities of tomorrow.
For more than 25 years, Cisco Networking Academy has trained people to build and maintain networks utilizing the latest technology. But it has done so much more than that. As part of the process, learners are encouraged to work collaboratively, and the program fosters a mindset of identifying and solving problems.
These are core entrepreneurial skills. Numerous Networking Academy learners have gone on to use those skills, not only in networking, but in business too.
Antonius, from Indonesia, had never encountered a computer until a tsunami brought rescue workers to his hometown, where he saw the value—and opportunity—in tech. He went on to study at Networking Academy and earn CyberOps Associate certification. In one of his first jobs after studying, Antonius used his problem-solving skills to conclude that the network of the large organization where he worked had been hacked, and that rebuilding the system from scratch was the best solution.
Niels, in Belgium, took a different path. After working in kitchens from a very young age, Neils decided to embark on Networking Academy study. “I have been in love with tweaking computers all my life,” he says. While he found the study challenging at times, with support from the Networking Academy community, he went on to attain CCNA certification. Niels credits the program with giving him the self-belief necessary to start his own penetration testing company.
Obviously, the tech revolution has seen a vast increase in the demand for the sort of hard skills that are the basis of Cisco Networking Academy, and those skills continue to be indispensable.
The World Economic Forum found over 85% of organizations surveyed for the 2023 Future of Jobs Report identified increased adoption of new technologies and broadening digital access as the trends most likely to drive transformation in their organization.
The same report, however, finds that technological literacy is only the third in the list of skills businesses see as growing in importance over the next five years. Creative thinking and analytical thinking rank as numbers one and two, respectively.
Recognizing that technical skills alone are not enough for success in today’s business environment, Networking Academy has recently launched several new courses on our Skills For All platform:
Engaging Stakeholders for Success provides essential skills for any professional, regardless of the industry. Learning to effectively engage with stakeholders is a core skill in any workplace. In this course, learners gain the insights and tools to identify, prioritize, and engage with stakeholders for success.
Discovering Entrepreneurship offers a solid foundation for anyone interested in developing entrepreneurial skills. The course covers entrepreneurship fundamentals, including the entrepreneurial perspective, identifying opportunities, and crafting an entrepreneurial story.
Obviously, no course can teach the entrepreneurs of tomorrow how to have the big idea that drives a new business or industry. But by helping learners recognize that idea and teaching them the analytical and personal skills to make that idea grow, we can help them along that journey.
A problem as simple as being unable to send your partner an email saw the founding of the company that would grow into the Cisco we know today. What’s your big idea?
Cisco's Networking Academy trains students in digital skills, but also fosters skills crucial for entrepreneurs. Read More Cisco Blogs
At Cisco Duo, our primary objective is to prevent unauthorized access with a modern and user-friendly access management solution. Security is paramount to organizations of all sizes, and we are … Read more on Cisco Blogs
At Cisco Duo, our primary objective is to prevent unauthorized access with a modern and user-friendly access management solution. Security is paramount to organizations of all sizes, and we are committed to providing secure and streamlined access for the workforce, regardless of their location whether they are at home, in the office or on the road.
In today’s rapidly evolving technological landscape, the importance of robust security measures cannot be overstated. That’s where Duo APIs come into play as a powerful tool, empowering you with resilient security controls for your applications. In this blog post, we’ll delve deeper into the potential and versatility of Duo APIs, their applications across industries, and how they can elevate your security posture to new heights.
Cisco Duo’s Director of Product Management, Boat Agboatwalla, shares insights into Duo Security APIs and their versatile use cases across industries.
Duo’s developer-centric approach, comprehensive documentation, SDKs, OpenAPI specifications (coming soon!), testing environment, and support resources make it easy for developers to integrate Duo’s security solutions into their zero trust architecture.
Auth API: This is a widely used API that enables you to add strong two-factor authentication to the authentication flow of your applications. Soon, you’ll also be able to add Duo’s secure Verified Duo Push functionality through the Auth API, which mitigates MFA fatigue attacks (to request access to our private preview of Verified Duo Push through the Auth API please contact us at duoapipreviews@cisco.com).
Web SDK: The Web SDK is the fastest way for developers to implement the core functionality of the Auth API and enable strong multi-factor authentication via Universal Prompt in their custom website or application. It serves as a simple solution for straightforward Duo MFA Universal Prompt implementations without the need of customization and is very widely used by our customers. The Web SDK is available in Python, Java, Go, PHP, Node.js, and C#(.NET).
Admin API: This API lets developers integrate and manage a wide range of administrative functions, including managing users, devices, admins, policies, and integrations, as well as programmatically reading authentication, administration, and telephony logs.
OIDC Auth API: This is an open ID Connect (OIDC) compliant authentication protocol to add strong two-factor authentication to your web applications. The OIDC Auth API also supports Duo Universal Prompt. Adding Duo using the OIDC API requires custom development and some understanding of your application’s language and authentication process.
Device API: Duo’s Trusted Endpoints feature adds a layer of security by ensuring that only known and registered, or corporate managed devices can access Duo protected applications and resources. This API is for Trusted Endpoints policy which uses Duo Device Health App to establish trust.
By providing the necessary tools and support, Duo empowers developers to efficiently incorporate Duo’s powerful authentication and access management capabilities into their solutions.
With an extensive network of over 250 partners, Duo boasts a robust ecosystem of integrations using Duo APIs with popular applications, identity providers, and security technologies.
BioConnect: BioConnect uses the Auth API endpoint and REST API to enable ‘Duo at the Door’. What that means is that the integration of Link Solution with Duo’s MFA , protects access to physical spaces such as facility doors, data centers, MDF & IDF closets, or small space enclosures such as narcotic safes and key cabinets. BioConnect Link allows you to retrofit your existing access control readers or upgrade your mechanical locks with a small IoT device that installs like a network appliance. It leverages a cloud-based software platform to add Cisco’s Duo MFA to physical access points and to future proof your organization with remote updates, security monitoring and flexible Multi-Factor Authentication, including one-time access authorization with time-based passcodes for critical spaces.
Blumira: Blumira’s SIEM and XDR platform analyzes and identifies threats early using data from different sources, including authentication providers, such as Duo. IT admins can set up Blumira’s Cloud Connectors using Duo Admin API credentials in minutes to start collecting logs and automatically apply detection rules. Blumira’s platform notifies users of risky and suspicious activity like Duo user account lockouts, fraudulent Duo user reports, unusually high number of MFA requests, user authentication MFA bypass, and users set to bypass status. With every finding, Blumira also provides easy-to-follow playbooks to instruct users on how to respond to their Duo alerts or reach out to Blumira’s SecOps team available 24/7 for critical priority issues.
Cigent Technologies: Utilizing Auth API, Cigent Data Defense™ adds Duo’s risk-based multi-factor authentication to shield sensitive data on user endpoints from access by cyber criminals and malware. The Cigent and Duo integration helps prevent the execution of ransomware, extortion, and data theft, reducing financial and reputational loss. Cigent integrates with both endpoint and SOC technologies to be threat aware. During a threat condition, or by policy for specified content types, users will be required to use multi-factor authentication to access protected files. Data protection policy can be set by file type (extension), folder, and partition (Cigent Secure Vault). The protection can also extend beyond files on the local PC, to cover file shares, clouds (e.g., OneDrive), and external media. Watch this webinar to learn more.
Oort: Identity-based attacks are on the rise, and security teams need improved ways to protect their ever-expanding identity infrastructure. Oort seamlessly connects via Auth API, Device API, and Admin API to an organization’s Duo instance, providing visibility into users, devices, authentications, and activities. Oort combines these with HR data and data from other IdPs and applications to create a single, unified user inventory. Oort continually monitors for posture weaknesses and identity threats, alerting security teams in near real-time and providing easy one-click response actions that leverage Duo’s APIs. This includes IP threats, MFA flood attacks, suspicious activity, and more. The Oort data science team creates and maintains these detections, enabling security teams to focus their time on what matters most.
The benefits are clear:
Leverage existing infrastructure: Embracing Duo’s integration capability allows organizations to effortlessly infuse our powerful security solutions into their current infrastructure. By doing so, you can maximize the value of your existing investments while fortifying your security posture.
Scale with confidence: As your organization evolves and expands, you need a security solution that grows with you. Duo’s offerings are designed with scalability in mind, accommodating the needs of small businesses as well as large enterprises. Embrace growth without compromising on security.
Would you like to be next to build an integration with Duo?
We offer an open platform for anyone to come and build an integration with Duo at no cost. Vendors interested in becoming a Duo Technology Partner can apply here or contact techpartners@duo.com to learn more.
Additionally, GitHub libraries can be used out of the box to integrate quickly with Duo.
We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Secure on social!
Cisco Secure Social Channels
InstagramFacebookTwitterLinkedIn
Dive into advanced security with Cisco Duo APIs. Explore partner integrations, versatile applications, and industry use cases. Read More Cisco Blogs
As our nation works towards a common goal of strengthening its critical infrastructure by deploying advanced cybersecurity, federal grants are one of the sources available to state and local… Read more on Cisco Blogs
As our nation works towards a common goal of strengthening its critical infrastructure by deploying advanced cybersecurity, federal grants are one of the sources available to state and local governments, Tribal nations, and electric utilities to fund their planning and deployment priorities. In 2022, the federal government (Department of Homeland Security) provided $1 billion in cybersecurity grants to state and local governments (and territories) through the State and Local Cybersecurity Grant Program (SLCGP). SLCGP funds cybersecurity planning, training, and mitigation initiatives, such as implementing security technologies, hiring cybersecurity professionals, and conducting vulnerability assessments. The first round of SLCGP allocations to states in FY 2022, $185 million, has been distributed and states are authorized to spend. Congress also appropriated $400 million for FY 23, $300 million for FY 2024, and $100 million for FY 2025. The deadline for States to apply for FY 23 grant is October 6, 2023. A total of $374,981,324 is available for FY23 to 56 states and territories.
Software, service, and equipment costs are allowable if intended to be used to address cybersecurity risks and threats. States may spend their portion of the funds on ransomware protections, data backups, basic cybersecurity protections, risk management frameworks as well as training and awareness. In addition to eligible equipment costs, funds may be used to purchase maintenance contracts or agreements, warranty coverage, licenses, and user fees in support of a system or equipment.
All of the 56 states and territories are eligible for the program though Florida did not participate in FY 23. States are required to pass down 80% of total funding to local and tribal governments which will then apply directly to their state’s Cybersecurity Planning Committee for funding.
Implementing multi-factor authentication (MFA)
Implementing enhanced logging
Data encryption for data at rest and in transit
End use of unsupported/end-of-life software and hardware that are accessible from the internet
Prohibiting the use of known/fixed/default passwords and credentials
Ensuring the ability to reconstitute systems (backups).
A Cybersecurity Risk Assessment is a prerequisite for a SLCGP grant because risk assessment remediation priorities are addressed in each entity’s grant application. The Cybersecurity and Infrastructure Security Agency (CISA) provides risk assessment tools and services at no cost and without commitment to sharing outcomes.
In addition to the above funding, The Tribal Cybersecurity Grant Program (TCGP) is a separate $30 million grant for Tribal nations. Under TCGP, federally recognized Tribal nations are the only eligible entities and do not apply for funding through states. Details and application dates have not yet been announced by the Department of Homeland Security.
SLCGP grants are funded from the Department of Homeland Security directly to State Administrative Agencies (SAAs), which are often the agencies responsible for emergency services and information technology. SAAs are the decision-makers on how 80% of the grants will be subgranted to local and rural governments. States may subgrant to local governments both cybersecurity products and services provided by or procured through the state.
Every state applicant of SLGCP funds is required to develop a statewide plan and a statewide advisory group. The advisory groups will also be influential in the selection of products and services procured by state and local governments.
Although much of the cybersecurity funding conversation is happening at the federal and state level, local government and Tribal nation information security leaders are also creating and implementing cybersecurity plans and convening official and advisory meetings.
Cisco customers will soon be apply and compete for $250 million in funding from the Rural and Municipal Utility Advanced Cybersecurity Grant and Technical Assistance Program (RMUC). This funding is over five years to help utilities improve incident response, enhance their workforce cybersecurity skills, and strengthen their systems, assets, and processes. The RMUC Program will offer technical and financial support to help municipal and rural utilities enhance operational capabilities, deploy cyber platforms, and increase their access to cybersecurity support services. The Department of Energy completed the Request for Information process and a Notice of Funding Opportunity is forthcoming at a date to be announced.
Year one of four years of grants for cybersecurity planning and mitigation is already in the hands of states and will be subgranted to local governments, including rural local governments and Tribal nations. So they’re already busy preparing or competing for grants for planning, training, deployment, and operations. FY 2023 grant applications from states and territories are due October 6, 2023.
That’s why now is the time to act. Our public funding team at Cisco is here to help state, local, and Tribal Nation governments understand their pain points and their plans. We encourage you to become an active part of the outcome conversation and engage your Cisco Public Funding Advisor for support. The application process can be cumbersome, but we at the Cisco Public Funding Office are glad to help.
As our nation works to secure critical infrastructure, federal grants are now available for state and local governments, Tribal nations, and electric utilities. Get up to speed on all the details. Read More Cisco Blogs
Introduction The rapid advancement of technology has led to an [...]