About (Edit profile)

This author has not yet filled in any details.
So far has created 1829 blog entries.

Tech Tools for the Future: Zebras, AI, and Girls in ICT Day on April 2, 2024 at 1:00 pm

I’m excited to announce that Dr. Tanya Berger-Wolf will be joining our special Women Rock-IT broadcast to support International Girls in ICT Day, featuring women who have turned their passion for t… Read more on Cisco Blogs

​[[{"value":"

I’m excited to announce that Dr. Tanya Berger-Wolf will be joining our special Women Rock-IT broadcast to support International Girls in ICT Day, featuring women who have turned their passion for technology into rewarding and successful careers.

Dr. Tanya Berger-Wolf is the Director of the Translational Data Analytics Institute  and a Professor of Computer Science Engineering, Electrical and Computer Engineering, as well as Evolution, Ecology, and Organismal Biology at the Ohio State University (OSU).

As a computational ecologist, Tanya’s research is at the unique intersection of computer science, wildlife biology, and social sciences. She will speak on International Girls in ICT Day, hosted by Cisco Networking Academy’s Women Rock-IT Program. The theme for this year’s event is Are You AI Ready? And for those who may not be aware, AI stands for Artificial Intelligence, which is what Tanya is going to be sharing more about.

Q: What was your motivation to get into computer science, and what was your path to get there?

A: I always wanted to do math. I even declared that when I was five in front of my whole family. So I went straight for math, eventually realizing that the type of math I like is the math that’s the foundation of computer science. I went on to do a theoretical computer science PhD, designing algorithms and doing proofs.

Along the way I met an ecologist who is now my husband and partner. He really charmed me with stories of industrious spiders and shy flowers and took me on nature walks to try to get me over my fear of bugs.

I intentionally switched from a very theoretical computer science PhD to designing computational methods for answering ecological questions.

A zebra’s friend

Q: What inspired you to focus on using AI in conservation and what keeps you motivated in the face of the ongoing extinction crisis?

A: There is both the challenge and the inspiration that keeps me going.

The way I got started in conservation was really on a bet. I was working with biologists who study social behavior of animals such as zebras. I got really curious about how they know who a zebra’s friend is.

After watching them take 20 minutes just to identify one individual zebra using the available technology at the time, the impatient engineer in me said that there had to be a better way of doing it.

They said, “you think you can do better?” And I said, “yeah, you want to bet?”

I literally bet my reputation on being able to identify an individual zebra from a photograph easily.

AI for conservation

The first algorithm we created was developed into an even better algorithm, which we are still curious about. But it turned out it could be very useful in conservation for things like tracking animals, counting them, and even figuring out who’s a zebra or a sperm whale’s friend without putting collars or satellite tags on them.

We realized that we needed to build that technology in a way that non-technical
people could use, without becoming AI experts in the process.

And that’s how Wildbook was born.  Having started creating AI technology for conservation, we realized three things:

just how big the challenges were
how huge the space was to do something to make a difference
how urgent all of this is.

The challenge and urgency keep me going. And most importantly, there’s something meaningful that we can do with AI.

Dr Tanya Berger-Wolf lecturing on AI in biodiversity

How important are digital and AI skills?

Q: How important is it for people to include digital skills in their future education and professional development plans? And why is it so important?

A: I think AI is becoming very quickly a part of pretty much everything that we use and touch. So AI literacy is becoming the basic skill that should be taught in school and everybody should have.

It is particularly important in being able to solve complex problems like biodiversity conservation. Because it is not a problem that’s going to be solved by AI alone or by humans alone. The answer truly is in partnership: the human-machine partnership.

And to be able to partner well with AI, we need to know what that partner is capable of and what’s the best way to have that partnership. And that means having skills that allow us to use AI, to understand AI, and even more importantly, to understand the potential of AI.

Q: What is your advice for any young women starting out in computer science?

A: Not everybody has to do computer science, but anybody who wants to, should have an opportunity to do so. And even more, everybody should have an opportunity to explore it.

Computer science is about getting machines to affect the world. For example, with a few lines of text, we can create a 3D view of the brain with an MRI machine, or understand the past through an ancient genome, or predict the path of a hurricane. This creative process of coding is exciting to me.

Accessible AI and ML learning

Q: AI/Machine learning (ML) has been a subject of academic study for more than half a century. Why was last year such a milestone for this type of technology?

A: Last year it exploded, not because of the algorithm or the math, but it’s about how you make that accessible.

Two things happened simultaneously. Firstly, there was a buildup of data available—with many caveats and asterisks that we’re now revisiting. And secondly, modern machine learning is data hungry.

When you have the hardware to run these complex models and the data to feed it, you can start capturing the complexity of the world. But it would have been esoteric if not for this brilliant interface that allows everybody to interact with it.

And that’s a huge lesson if you want to make any piece of technology useful. It’s not about the technology itself, per se, it’s about how you make it a partner, how you really make it accessible.

Observe. Experiment.

Q: Conservation of nature often faces complex questions about the natural world. Can AI help?

A: In Henri Poincaré’s book Science and Method, he says what we now call the scientific method consists of observation and experiment. And all that a scientist needs to do is look carefully at everything.

AI doesn’t fundamentally change the scientific method. It is still observation and experiment. But just like the microscope, the telescope, or genome sequencing, it expands the types of things that scientists can look at.

The fundamental thing that ML and more broadly AI approaches do is extract complex patterns and complex relationships. So, we can not only look at more things, but we can also look carefully at the complexity of the world.

The role of public data

Q: Does publicly available data help in this quest?

A: There is a lot of publicly available data from digitized biological collections, field studies, and citizen scientists. But the most untapped data by far is from social media posts. People love taking pictures of nature, sometimes unintentionally capturing trees and grass, bugs and spiders.

There’s a lot of information already there but it is disconnected and disorganized, so we’re not taking advantage of it. And we need AI’s help to get useful insights from all of it.

Q: Can AI help discover the undiscovered?

A: If we want to discover new things about the world, we need to take a completely different computational philosophical approach and a new design framework of algorithms.

How do we design interpretable, novelty-discovering, computational approaches that produce a testable hypothesis as an outcome?

Maybe you already have your massive species classification from an images model? Well, good for you! But we’re interested in using these news tools and frameworks to discover something new. A new species? A new trait? A new relationship?

This is one of my favorite quotes from Ada Lovelace, who invented the notion of programming in the 1830s:

“We talk much of imagination. We talk of the imagination of poets, the imagination of artists etcetera. I am inclined to think that in general we don’t know very exactly what we are talking about. It is that which penetrates into the unseen world around us, the world of science. It is that which feels and discovers what is, the real which we see not, which exists not for our senses. Those who have learned to walk on the threshold of the unknown worlds may then with the fair white wings of imagination hope to soar further into the unexplored amidst which we live.”

Ada Lovelace, English mathematician considered to write the first algorithm designed to be carried out by a machine

Register now for the Women Rock-IT virtual event on April 25!

Are You AI-Ready? Unlocking nature’s secrets:
How AI & Data save wildlife and benefit humanity

Check registration page for your local broadcast time.

Share

"}]]  Emma Reid interviews Dr. Tanya Berger-Wolf about how AI is being used in animal conservation. Hear more on our special Women Rock-IT broadcast to support International Girls in ICT Day on April 25, 2024.  Read More Cisco Blogs 

By |2024-04-02T22:55:35+00:00April 2, 2024|Cisco: Learning|0 Comments

Build for Better Code Challenge Focuses on AI and Sustainability on April 2, 2024 at 3:00 pm

During our 10 years of DevNet celebratory webinar on March 14th, Shannon McFarland, VP of Cisco DevNet announced a coding challenge for the DevNet community. We call it the Build for Better Code… Read more on Cisco Blogs

​[[{"value":"

During our 10 years of DevNet celebratory webinar on March 14th, Shannon McFarland, VP of Cisco DevNet announced a coding challenge for the DevNet community. We call it the Build for Better Code Challenge and this year’s topics are AI and sustainability. We give you a bit more than a month, from March 14th to April 22nd to build an application on AI or sustainability or both that will hopefully amaze the judging panel and make you a winner.

Why participate and how do you win?

Why would you want to participate? Besides the chance of being one of the three teams winning $500 in credits for the Cisco Store, you will also receive mentorship from DevNet experts, get a chance to make an impact on a global stage and be recognized as the winners of the Cisco DevNet code challenge!

As mentioned, the topics of the challenge this year are AI and sustainability. In order to decide the winners, the judging panel will look for originality of the idea, quality of code and relevance to this year’s topics. While using Cisco products and technologies to build your submission for the challenge are encouraged, they are not mandatory. We want to encourage you to build your solution with as few limitations and encumbrances as possible. Anyone can participate to this coding challenge including Cisco employees and their families.

Example use cases

We also wanted to give you a few examples of use cases that would fit AI and sustainability topics for this challenge. Again, these use cases are given to you just as suggestions and for inspiration purposes, don’t feel like you must work on and solve these specific ones. We’ve split the example use cases in three categories: energy consumption, smart buildings and energy efficiency and green coding.

Energy consumption use cases

Under energy consumption a possible use case could be to build an AI-driven carbon footprint minimizer. Utilizing the Cisco Observability Platform for example, your AI will analyze power utilization, develop carbon emissions models, and offer smart ways to decrease the carbon footprint of digital infrastructures. This tool will enable developers and businesses to quantify and mitigate their environmental impact.

Another use case for energy consumption could be building a smart energy dashboard with automation components. Picture a dashboard that not only tracks power consumption in real-time but also identifies opportunities to cut down on energy waste. Your mission would be to collect power consumption data and display it through an intuitive dashboard interface. Then, elevate your solution by coding automation scripts that interact with Cisco networking hardware, like shutting down PoE ports after hours to conserve energy.

Smart buildings and energy efficiency use cases

For smart buildings and energy efficiency a possible use case could be a Cisco-enhanced smart presence-aware lighting system. Redefine smart lighting with your coding expertise by leveraging location data from Cisco wireless networks and video cameras to intelligently control PoE lights. You can utilize the capabilities of Cisco software to ensure that lighting responds dynamically to the presence or absence of people in a space, thereby conserving energy.

A second use case for smart buildings and energy efficiency could be an AI-driven climate control advisor. You could use a solution like the Cisco Observability Platform to integrate data from temperature sensors, HVAC systems, and weather applications to feed into an AI that not only suggests improvements in power utilization but also provides future energy consumption predictions. Your application can lead to optimized climate control strategies and a marked reduction in energy waste.

Green coding use cases

For green coding use cases, think of an eco-friendly programming language selector AI. Create an AI bot that helps determine the most energy-efficient programming language for a given task. Envision a tool that recommends the optimal programming language for a specific task with minimizing power usage in mind.

Another possible use case for green coding could be the code efficiency enhancer AI. This AI bot epitomizes smart and eco-friendly coding by accurately estimating and analyzing code power consumption and CPU cycles. Your solution will not just analyze code but it will also suggest enhancements to streamline code for superior efficiency and sustainability.

What do you want to build?

As mentioned before, all these use cases are just for inspiration purposes, and you are more than free to come up with your own use cases or improve on the ones above. Also keep in mind, you can use the free DevNet sandboxes as a testing ground for your solution in the challenge.

You can find additional details about this coding challenge here. If you have questions please reach out to the DevNet community. Or you an leave me a comment in the space below. We wish you good luck on this code challenge and are super excited to see the ideas and solutions that you all are coming up with!

Share

"}]]  AI driven applications focused on energy consumption, smart buildings, and green coding are increasingly in demand. Do you want to try a project?.. Get help from mentors?.. Join the Build for Better Code Challenge.  Read More Cisco Blogs 

By |2024-04-02T22:55:34+00:00April 2, 2024|Cisco: Learning|0 Comments

Re-architecting Broadband Networks on April 2, 2024 at 3:00 pm

This is Part II of a three-blog series on solutions to overcome challenges associated with bridging the digital divide.

In the previous blog (see Bridging the Digital Divide with Subscriber Edge),… Read more on Cisco Blogs

​[[{"value":"

This is Part II of a three-blog series on solutions to overcome challenges associated with bridging the digital divide.

In the previous blog (see Bridging the Digital Divide with Subscriber Edge), we discussed the traditional broadband network design. In this blog, we will focus on a new architecture for broadband networks, and the challenges that they address.

Moving to a distributed architecture

The ability to enable subscriber functions on different layers or devices in the network provides an opportunity to optimally position subscriber edge in the network to help fit economical and user-experience needs. For example, given that video amounts to more than 75% of the volume of total subscriber traffic, flexible termination allows for the efficient offload of video traffic closer to the subscriber through careful placement of content caches and the addition of peering points. Distributed termination of subscribers improves the overall user experience as the traffic follows a more ideal path that optimizes capacity usage and supports lower latency for demanding applications.

With this distributed architecture, communication service providers (CSPs) can save costs by reducing unneeded bandwidth upgrades of the entire network through traffic offload further downstream. However, with more distributed placement of subscriber edge functions using different termination models, CSPs may face challenges with scaling, managing, and operating subscriber services networks.

To solve these challenges, Broadband Forum defined the Control and User Plane Separation (CUPS) model for the Broadband Network Gateway (BNG) in TR-459 (see Figure 1). CUPS enables distribution of user/data planes closer to the subscriber, allowing the control plane function to be centralized. This is a significant change from the traditional BNG architecture—where control plane and user plane functions are tightly integrated and performed by the same device. This new distributed architectural approach takes advantage of CUPS to offer newer broadband services and use cases that are different from traditional offerings.

Centralizing the control plane function helps lower operational costs in a distributed subscriber edge function that can be non-uniform with varying requirements on scalability, form factor, and role.

CUPS also enables new revenue streams or models, which were not possible with the traditional architecture, such as differentiated service plans. For example, service providers can offer a day/night plan, where subscribers are provisioned or moved to a smaller set of user planes during the night for cost savings and potential sustainability benefits.

Customers can also offer tiered plans with Platinum, Gold, and Best-Effort, based on redundancy capabilities to help protect premium subscribers from user plane, access, or site failures. With the control plane no longer tightly integrated with the user plane, and complete visibility of all user planes, CUPS enables higher flexibility for CSPs to seamlessly move subscribers to different nodes without disruption.

Figure 1. New CUPS architecture view

The latest development by the Broadband Forum is Issue 2 of TR-459 Multi-Service Disaggregated BNG with CUPS specification (see Figure2), which enables improved resiliency, scalability, and faster deployment times to help provide a better end-user experience with a more reliable and consistent service.

Figure 2. MS-BNG functions separating into control plane and user plane (from BBF TR-459i2)

In the third blog, we will share details on the Cisco Subscriber Edge solution, including the architecture, technical advantages, and customer benefits.

Get started today reimagining your gateway architecture with

Cloud Native Broadband Network Gateway

Share

"}]]  This second blog in a three-part series discusses solutions to overcome challenges associated with bridging the digital divide.  Read More Cisco Blogs 

By |2024-04-02T22:55:34+00:00April 2, 2024|Cisco: Learning|0 Comments

Cisco Secure Application makes it easier than ever to secure your cloud native applications and sensitive data on April 2, 2024 at 3:00 pm

With Cisco Secure Application on the Cisco Observability Platform, customers have more flexibility and choice when it comes to tackling their most difficult security challenges.

Managing an… Read more on Cisco Blogs

​[[{"value":"

With Cisco Secure Application on the Cisco Observability Platform, customers have more flexibility and choice when it comes to tackling their most difficult security challenges.

Managing an organization’s security posture is extraordinarily complex — new bad actors, exploits and threats are constantly bubbling up. Meanwhile, organizations have a deep responsibility for their customer and user data safety, as well as legal obligations for data handling from regulations like GDPR (General Data Protection Regulation), HIPAA (Health Insurance Portability and Accountability Act), and PCI DSS (Payment Card Industry Data Security Standard) among others! One seemingly small breach can be catastrophic for a brand’s bottom line and can erode customer trust forever.

As the amount of data created and used grows exponentially, the need to ensure that it’s secure is more important than ever. However, traditional solutions lack the shared business context needed to rapidly assess risks and align teams based on potential business impact. With the breadth of Cisco’s portfolio, we are uniquely able to provide the Observability organizations need to tackle their most difficult security challenges.

Meeting Teams Where They’re at On Their Observability Journey

Observability enables teams adopting a devsecops framework to secure their applications efficiently. However, not all organizations are structured the same way even though they may have similar security objectives. Recognizing this, we are now introducing Cisco Secure Application as a standalone Cisco Observability Platform application. Previously, IT teams who wanted to deploy Cisco Secure Application would need to do so coupled with cloud native application performance monitoring from Cisco Cloud Observability. Now, they can secure their cloud-native applications and protect their sensitive data at scale, without additional commitments. 

This new, standalone application supports two, separate modules: the new Data Security module and the Cloud Security module.

Keeping Sensitive Data Compliant and Secure

Failure to protect your consumers’ Personally Identifying Information (PII) and other sensitive data could result in hefty fines (GDPR noncompliance, for example, could lead to fines up to €20 million, or 4% of previous year’s annual revenue) and permanently damage a brands’ reputation.

The new Data Security module  helps teams regain control and proactively secure their sensitive data, while also ensuring its compliance with the regulatory standards. Using leading AI technologies, it helps:

Unlock deep data visibility by automatically discovering and classifying sensitive data at scale
Efficiently control and secure data from both internal and external threats with continuous monitoring
Save time and effort by avoiding manual tasks and ensuring your data is compliant with the latest regulatory standards
Provide GenAI-powered alerting and guidance to expedite remediation of security issues

Gone are the days of tedious, manual updating to ensure data is safe and compliant. Now, IT owners can feel confident that they are comprehensively protecting their sensitive data. Visit the new Data Security webpage to learn more.

Helping Triage the Threats That Matters Most

With data and tools becoming increasingly distributed within IT and providing growing number of attack surfaces, it can be difficult to know where the threats are and how to address them. Cisco’s Cloud Security Module can help by providing real-time vulnerability analytics and business risk observability for cloud native applications. What I love, and is unique to Cisco, is that by combining the strength of our portfolio, we can not only help organizations identify security issues  across application entities, but we can also help teams triage the threats that carry the most impact  to the business and act with real-time guidance and actions.

More Options, Better Security

With the new standalone Cisco Secure Application on the Cisco Observability Platform, teams now have more choice in how they address their cloud native application and data security needs. With the visibility and actionable insights to quickly locate, prioritize, and remediate security issues, organizations can feel confident in their ability to secure cloud native applications and safeguard sensitive data at scale — ultimately protecting their reputations and revenue.

Share

"}]]  With Cisco Secure Application on the Cisco Observability Platform, customers have more flexibility and choice when it comes to tackling their most difficult security challenges.  Read More Cisco Blogs 

By |2024-04-02T22:55:33+00:00April 2, 2024|Cisco: Learning|0 Comments

Pave the Way for New Revenue with Transport Slicing Automation and Assurance on April 1, 2024 at 3:00 pm

Excellence in service matters. Whether you are a mom-and-pop operation or a multibillion-dollar business spanning multiple industries, keeping customers happy and satisfied is essential. No one knows… Read more on Cisco Blogs

​[[{"value":"

Excellence in service matters. Whether you are a mom-and-pop operation or a multibillion-dollar business spanning multiple industries, keeping customers happy and satisfied is essential. No one knows this better than telecommunication (telecom) providers—who experience close to 40% customer churn due to network quality issues, according to McKinsey.

For telecom providers, delivering an outstanding digital experience means smarter troubleshooting, better problem-solving, and a faster route to market for innovative and differentiated services. As if delighting customers and generating new revenue weren’t enough, there is also the added pressure of keeping operational costs low.

For operators of mass-scale networks, that can be a tall order. The good news is that innovative solutions like transport slicing and automated assurance are creating opportunities for service providers to build new revenue streams and differentiate services on quality of experience (QoE) with competitive service-level agreements (SLAs). In this blog post, we will explore how transport slicing and automated assurance can revolutionize the network landscape and transform service delivery, paving the way for financial growth.

Simplify and transform service delivery

Despite ongoing transformation efforts, telecom and high-performance enterprise networks are becoming increasingly complex and challenging to manage. Operations for multivendor networks can be even more complicated, with their various domains, multiple layers of the OSI stack, numerous cloud services, and commitment to end-to-end service delivery.

Complexity also impacts service performance visibility and how quickly you can find, troubleshoot, and fix issues before customer QoE is impacted. To understand the customer experience and differentiate services with competitive enterprise SLAs, you need real-time, KPI-level insights into network connections across domains and end-to-end service visibility. To confront these challenges, many service providers have been attempting to simplify network operations while reducing the cost of service delivery and assurance.

So, how do you streamline increasingly busy transport network operations? For one, advanced automation and orchestration tools can automate intent-based service provisioning, continuously monitor SLAs, and take corrective action to maintain service intent. Automated assurance, for example, can proactively monitor service performance, as well as predict and remediate issues before customers are impacted. This reduces manual work and allows for quicker reaction times to events that impact service.

With leading-edge platform and automation capabilities, you can deliver a wide range of use cases with a unified interface for visualization and control to manage network services effectively. This makes complex multidomain transport networks more accessible and easier to operate, which can help improve capital efficiency, enhance OpEx utilization, and accelerate new service launches.

The operational agility created by simplifying network operations allows you to adapt quickly to market changes and customer needs. You can assure services while securing new revenue streams and capitalizing on emerging service delivery opportunities.

Leverage transport slicing for the best outcomes

Simplifying network operations is only one part, because the one-size-fits-all approach to network infrastructure is no longer sufficient as your customers demand more personalized, flexible, and efficient services. This is where transport slicing can help, by offering a new level of customization and efficiency that directly impacts the service quality and service guarantees you can offer.

Network slicing is typically associated with delivering ultra-reliable 5G network services, but the advantages of transport slicing reach well beyond these areas. Network as a service (NaaS), for example, addresses enterprise customers’ need for more dynamic, personalized networks that are provisioned on demand, like cloud services. Using transport slicing, you can create customized virtual networks that provide customers with tailored services and control, while simplifying network management.

For telecom providers, transport slicing and automation will be critical to managing service level objectives (SLOs) of diverse, slice-based networks at scale. The transport layer plays a critical role in service delivery, and automation is essential to simplify operations and reduce manual workflows as slicing and enterprise services based on slicing become more complex.

Together, transport slicing and automation fundamentally change how network services are delivered and consumed. And while the slicing market is still in early stages of adoption, end-to-end slicing across domains offers a level of efficiency that translates into direct benefits through faster service deployment, enhanced performance, cost savings, and the ability to scale services quickly.

A complete, end-to-end automated slicing and assurance solution

Traditionally, the service monitoring and telemetry required to do any service-level assurance was an afterthought—built separately and not easily integrated into the service itself. Now, you can leverage the power of network slicing while ensuring each slice meets the stringent performance criteria your customers expect, as well as enable closed-loop automation based on end-user experiences at microsecond speeds. For example, tight integration between Cisco Crosswork Network Automation and Accedian’s performance monitoring solution provides a more complete, end-to-end automated slicing and assurance approach.

You can create and modify network slices based on real-time demand, and then leverage performance monitoring tools to not only assure the health and efficiency of these slices, but also provide empirical data to validate SLAs. You can use predictive analytics and real-time insights to identify and mitigate issues before they impact service quality, enabling increased network uptime and enhancing customer experience.

A proactive approach towards network management helps you use resources more efficiently, decrease complexity, and ensure customer satisfaction is prioritized—all while creating new opportunities for innovative revenue streams through highly differentiated and competitive service offerings. Ultimately, automated slicing and assurance drives greater operational excellence.

Fix problems before customers notice

Competition remains fierce in the telecom market, as service providers strive to meet B2B customers’ demand for high-quality services, fast service provisioning, and performance transparency. Speed is a differentiator, and customers notice immediately when service disrupts. Customers are willing to pay a premium for critical network performance, service insights, and enhanced SLAs that promise immediate resolution. To meet this demand, you need the ability to find and fix problems before customers notice.

Transport slicing and automated assurance are at the forefront of this challenge, enabling service providers to not only deliver services faster and more reliably, but to also have confidence those services will have the performance and QoE that customers expect.

The right network automation capabilities can drive simplified, end-to-end lifecycle operations, including service assurance that’s dynamic, intelligent, and automated. This paves the way for revenue-generating, premium services and delivering the outstanding experiences your customers expect.

Share

"}]]  For telecom providers, delivering an outstanding digital experience means smarter troubleshooting, better problem-solving, and a faster route to market for innovative and differentiated services. Innovative solutions like transport slicing and automated assurance are creating opportunities for services providers to create new revenue streams and differentiate services on quality of experience with competitive service-level agreements (SLAs).  Read More Cisco Blogs 

By |2024-04-01T21:50:55+00:00April 1, 2024|Cisco: Learning|0 Comments

Cryptocurrency and Blockchain security due diligence: A guide to hedge risk on April 1, 2024 at 4:30 pm

Blockchain technology has experienced remarkable adoption in recent years, driven by its use across a broad spectrum of institutions, governments, retail investors, and users. However, this surge in… Read more on Cisco Blogs

​[[{"value":"

Blockchain technology has experienced remarkable adoption in recent years, driven by its use across a broad spectrum of institutions, governments, retail investors, and users. However, this surge in blockchain use and cryptocurrency investment has raised concerns among governments and regulatory bodies. The decentralized nature and cross-border capabilities of blockchains, along with a rise in scams, hacking incidents, and other illicit activities have underscored the need for scrutiny. This concern is heightened by the absence of comprehensive regulatory measures.

This blog provides guidance for both individuals and organizations on the essentials of risk due diligence when considering the adoption or investment in blockchains, cryptocurrencies, and tokens. It is important to note this guidance is not intended as financial advice. Instead, its main goal is to help users identify and steer clear of scams and investments that may entail substantial risks. Nevertheless, for financial advice that is customized to individual situations, readers are encouraged to seek the counsel of a qualified professional.

The heightened risk associated with blockchain and cryptocurrencies for adopters and investors can be attributed to a general lack of understanding and transparency in relation to their cybersecurity aspects and dependability. Adding to this risk is the rise of unique attack types specific to the blockchain environment, which differ from traditional security issues. Blockchain security, by its very nature, often diverges from standard cybersecurity practices originating from its decentralized, immutable, and cryptographic nature.

This divergence has led to the emergence of new threats that are not commonly known among many users. Examples include 51% attacks, smart contract vulnerabilities, Finney attacks, and Vector76 attacks, which are not typically covered by conventional cybersecurity measures. Most attacks on blockchains revolve around smart contract and consensus mechanism exploitation which are not present in contemporary IT or OT centralized digital environments.

To better emphasize the need for in-depth understanding of the security and reliability features of blockchains and cryptocurrencies, we’ll examine two real-world blockchain attacks. These attacks led to considerable financial repercussions, serving as cautionary tales about the potential risks involved. These incidents include the Poly Network Cross Chain Contract Exploitation and Ethereum Classic 51% attack.

Case 1: Poly Network Cross Chain Contract Exploitation

The Poly Network hack occurred on the August 10, 2021, with $600 million stolen in more than 12 different cryptocurrencies. The hackers exploited a bug to mismanage access rights between two smart contracts handling token transfers between different bridged (linked) blockchains and divert the funds to three malicious wallet addresses.

The attacker exploited the functionality “EthCrossChainData,” which records a list of public keys that authenticate the data coming from the blockchain, allowing the attacker to modify the list to match its own private keys and redirect funds to the selected malicious wallets. This kind of hacking incident might have been prevented with the implementation of thorough vulnerability assessments of the source code. A notable issue is the insufficient information provided to investors and adopters regarding the inherent risks associated with cross-chain transactions. These risks stem from the complex coding necessary to execute such operations, often not fully understood by those involved.

Case 2: Ethereum Classic 51% Attack

The Ethereum Classic blockchain suffered four “51% attacks,” in which a single entity gained control over most of the network’s computing power by introducing many network clients/nodes with high computational capacity overshadowing the computational power of legitimate nodes. This opened the door for adversaries to manipulate network transactions and steal Ethereum Classic coins. Investors and adopters are often unaware of the risks entailed in proof-of-work consensus mechanisms that facilitate low hashrates.

The hashrate originates from the processing power of validator nodes that lend their computational power to validate and secure blockchain transactions. In the case of a low hashrate, attackers can exploit the network by overpowering it. This can have a significant impact for investors, as they can lose a significant amount of their money. Such incidences could be mitigated by monitoring the hashrate of the blockchain network to enforce proactive measures once the hashrate falls under a threshold, all while monitoring on-chain activity for double spend attempts.

Blockchain Assessment Methodology

Adopters, investors, and large organizations are primarily concerned with selecting digital assets that are reliable and secure to safeguard against the loss of value, whether through fraud or other unforeseen complications. Therefore, we’ll focus on presenting an empirical methodology to mitigate associated risks. It aims to guide the selection of reliable, and secure blockchains, cryptocurrencies and tokens, providing a framework for safer investment and adoption decisions.

The proposed methodology centers around nine fundamental pillars: Blockchain Type, Consensus mechanism, Team, Whitepaper, Source code, Historical hacks and vulnerabilities, Wallet distribution, Governmental and Legal Scrutiny and Liquidity. Although the attributes currently used to assess blockchains and cryptocurrencies are deemed adequate, it is important to recognize that these criteria are likely to evolve alongside the progression of blockchain technology and cryptocurrencies. Future changes and enhancements in these technologies can be inferred from new features that developers introduce to blockchain systems and cryptocurrencies that are often described in their whitepapers or on GitHub pages.

Blockchain Type

Blockchain type refers to the access rights and degree of control that users have over a specific blockchain. There are four main types of blockchains:

Public: Anyone can read and write (transact) on a public blockchain such as Bitcoin. This is the most accepted type of blockchain in terms of security and reliability as all stakeholders have visibility on all transactions and on-blockchain data. In most cases, public blockchains have also a high degree of decentralization, which minimizes attacks related to high-influence nodes in the network.
Private: Only the owning organization(s) can read and write on the blockchain and, usually, only a handful of nodes can write on the ledger (e.g., Hyperledger). Although such networks are usually faster than public blockchains, they are not transparent, and stakeholders can manipulate blocks at will to the extent that they can even impact the immutability of blockchain by altering previous transactions or delete blocks.
Consortium: Like private blockchains, consortium blockchains (e.g., Ripple) also offer little to no transparency and are often highly centralized. The only difference is that consortium blockchains compromised of multiple organizations instead of a single entity.
Hybrid: Hybrid blockchains inherit architectural designs from public and private blockchains (e.g., Komodo). The degree to what characteristics a hybrid blockchain inherits depends on a specific solution and its purpose. Usually, a large part of the activities and transactions take place on the background as part of a private ledger (blockchain), where the results of those activities are broadcasted on a public blockchain. While hybrid blockchains improve performance, they compromise the trustless and fully transparent nature of user-blockchain interactions. In these systems, users are required to place complete trust in the organization(s) overseeing the private components of the transactions.

In evaluating blockchain risk levels, public blockchains typically present the lowest risk. Their open-source nature fosters transparency in their operations, making their processes and transactions more visible and accountable. Hybrid blockchains carry a moderately higher risk due to their semi-transparent nature, where not all elements are publicly accessible or controlled by users.

Private and consortium blockchains represent the highest risk category. These blockchains require users to place complete trust in the controlling entities, as they lack the transparency and decentralization of public blockchains. This heightened risk is due to the potential for misuse or mismanagement by the controlling parties.

To accurately determine the type of blockchain and mitigate risks, particularly when it comes to token (creation of crypto tokens can be created with minimal effort making them ideal for scams), it is advisable to adopt three methodologies:

Analysis of the project’s website and associated whitepaper describing the crypto project to verify its value and reliability, an example would be the Ethereum whitepaper.
Visit the GitHub page containing the source code of the cryptocurrency or token of interest to validate its opensource and transparent nature, such as Ethereum’s GitHub
Use blockchain explorers to make sure that transactions in the blockchain of interest are visible and transparent to users. Websites like Blockchain.com can be used to explore transactions.

Typically, all the mentioned sources should be accessible for public blockchain initiatives. If any of these sources is unavailable, the associated risks notably escalate.

Consensus mechanism

A consensus mechanism is a fault-tolerant algorithm used in blockchains to achieve agreements on a single state of the network among distributed processes or multi-agent systems, such as cryptocurrencies. Consensus mechanisms in cryptocurrencies are used by validating nodes (e.g., miners) to validate and accept transactions originating from decentralized computing agents. Four types of consensus mechanisms exist:

Proof-Based (Pox): There are two main types of proof-based algorithms, proof-of-work (PoW) and proof-of-stake (PoS).
Proof-of-Work: A decentralized consensus mechanism that requires miners to use their computational power to validate transactions and mine new tokens in a blockchain network. This is achieved by solving an arbitrary mathematical puzzle that prevents fraud on the network. Proof-of-work is extensively used in cryptocurrency and is generally a secure method for validating blockchain transactions. However, the security and reliability of such networks are heavily reliant on the computational power (hash-rate) and decentralization degree of mining nodes. If the aggregated computation power of miners is low or highly centralized, it is possible that attackers overpower the security of the network and damage the integrity and reliability of a blockchain by manipulating transactions which can incur significant disruptions including loss of money.
 Proof-of-Stake: Like proof-of-work, mining nodes in proof-of-stake blockchains validate block transactions in a decentralized manner. However, instead of verifying transactions in proportion to the processing power a miner holds in this case is relative to the percentage of the total coins that a miner holds. Although, this improves energy consumption and lowers mining costs, it poses significant security risks in the case where a small number of mining nodes own the largest percentage of coins in a network or where the largest holders collude to manipulate the blockchain for profit, such as price manipulation or apply policies in a blockchain that will ultimately benefit the major stakeholders.

DAG: Directed Acyclic Graphs (DAG) is an alternative to traditional consensus blockchain mechanisms that aims to improve speed, scalability and reduce costs. The main difference from other blockchains is on the data structure. Instead of storing data/transactions on a blockchain and passing this information to all the nodes in the network, DAG networks can perform point-to-point transactions without broadcasting it to the network for verification due to their tree-like structure and high-connectivity between nodes. Although DAGs are more effective than legacy blockchains, they are also vulnerable to several attacks that can damage the integrity of a network due to the low volume of authentications and transactions on the network, including manipulating nodes in the network, leaving them susceptible to various traditional networking, and blockchain-specific attacks.
PBFT (Practical Byzantine Fault Tolerance): The main objective of PBFT algorithms is to decide whether to accept a piece of information that is submitted to a blockchain or not. Each node in the network maintains an internal state. When a node receives a transaction, they use the message in conjunction with their internal state to perform a computation. This computation will result into the decision about the message. The decision is then shared with other nodes in the network. The final decision is determined based on the total decisions from all nodes. Compared to proof-of-work, a high hash rate is not required for verification as PBFT relies on the number of nodes confirming a transaction. Once sufficient responses are reached, the transaction is verified as a valid transaction. Like proof-of-work, PBFT can be a secure medium for verification only when sufficient nodes exist in the network that are operated by different parties.

The selection of a consensus mechanism Is a complex task, as each has its advantages and disadvantages in terms of security and reliability. In principle, proof-of-work is secure when a blockchain network is populated with many miners maintaining a high hash rate for verifications, making it restrictive for adversaries to use their own hash rate against the legitimate users and take over blockchain transactions.

Websites such as Blockchain.com can provide information on the hash rate of various blockchains. In terms of proof-of-stake blockchains, they can only maintain their secure operations when there is a healthy distribution of the cryptocurrencies or tokens to various wallets and users (the method to audit crypto distributions is visited later in the paper). DAG mechanisms are very susceptible to man-in-the-middle attacks aiming to manipulate the integrity and availability of transactions. PBFT mechanisms are generally safe, but susceptible to attacks when small number of nodes operate in a blockchain network, allowing potential adversaries to implement attacks that can influence most of the network stakeholders, such as Sybil attacks, and make decisions for the entire network.

Team

This factor evaluates the openness of the team behind a blockchain, cryptocurrency or token. While blockchain and cryptocurrencies fundamentally support decentralized and semi-anonymous transactions, the anonymity of the development team can markedly raise the risk of monetary loss due to a lack of accountability. This anonymity heightens the danger of fraudulent activities such as rug-pulls or price manipulation.

Reputable digital currency projects typically disclose their team’s identities and credentials, providing assurance to users and investors about the legitimacy of their project. It should be straightforward to research a crypto project’s team. Increased difficulty in finding information about the team substantially raises the risk associated with investing in or adopting the project. Basic research on a crypto team can be conducted using the following resources:

Social Networks (LinkedIn, X, Instagram, Facebook, Reddit, etc.).
YouTube
Cryptocurrency-related forums and communities such as Bitcointalk and CryptoCompare.
Podcasts and interviews with the operators.

It is also important to consider how long the team has been operational. A shorter operational history suggests a higher risk. For instance, if all social media and YouTube content related to the team were created within the past five days, and there is little evidence of significant project development, this could indicate a potential rug-pull scenario.

Whitepaper

Whitepapers and roadmaps are crucial, serving as the bedrock for comprehending, assessing, and partaking in various crypto projects. A whitepaper serves as the foundational document, offering an in-depth exposition of the project’s technical underpinnings, its mission, the problem it intends to address. It covers the cryptocurrency’s technical aspects, consensus mechanism, security features and tokenomics, thus equipping potential investors and developers with a deeper understanding of the project. These documents are instrumental in fostering transparency, which in turn cultivates trust and credibility — essentials in a sector brimming with innovation and investment prospects. For investors, whitepapers and roadmaps are critical tools for evaluating risks and making decisions.

As regulatory scrutiny escalates in the crypto world, whitepapers can signify a project’s dedication to regulatory compliance, an increasingly vital factor for long-term viability. A well-crafted whitepaper and roadmap thus empower investors and users to make informed choices, distinguish genuine projects from fraudulent ones, and engage with the crypto community more responsibly and knowledgeably.

Whitepapers should be easily available in a project’s website, such as the whitepaper for Avalanche. A whitepaper that is not easily comprehensible or appears hastily assembled, a scenario now more plausible with generative AI, might indicate a dubious project.

Source Code (GitHub)

Checking a cryptocurrency project’s GitHub repository is vital for several reasons. It offers insight into the project’s development activity and the competence of its development team. By examining the frequency and quality of code commits, pull requests and issue discussions on GitHub, potential investors and users can gauge the project’s commitment to ongoing development and the team’s ability to deliver on their promises. A regularly updated and active GitHub repository is a positive sign, indicating that the project is actively maintained and progressing towards its goals.

GitHub also provides a level of transparency and accountability that is essential in the cryptocurrency space. The open nature of GitHub allows anyone to scrutinize the codebase, which can reveal any vulnerabilities or security issues. It also enables the community to participate in code reviews, offer reports and bug fixes, and suggest improvements. This collaborative approach enhances the project’s security and reliability. Conversely, projects with closed or inactive repositories raise red flags, as they may be less transparent, or worse, potentially abandoned, or fraudulent. Obtaining access to GitHub repositories should be a simple as a google search. The highest the number of users interreacting with the code and the longer the time of existence for a project the highest the confidence should be.

Historical hacks and vulnerabilities

This attribute considers if a blockchain, cryptocurrency or token was compromised or is vulnerable to attacks. It is normal to find that a crypto project has been compromised at a point of time, however, the exploitation methodology used for these attacks and vulnerable code should be revised to ensure that the source code is patched and secured. In the case that a project is not concerned with vulnerability management and best security practices, it renders the project elevated risk due to a high likelihood of a future compromise.

To determine if a project has a history of vulnerabilities and threats, a straightforward approach is to consult news outlets that specialize in reporting on these issues within the cryptocurrency sector. A prime resource for this information is Rekt, covering all reported exploitation across different blockchains and platforms. Additional sources that can also prove useful include Cointelegraph, CryptoSlate and Substack.

Wallet Distribution

The wallet holder distribution describes the number of coins or tokens held by each wallet for a specific project. This metric only applies for cryptocurrencies or tokens that are leveraging public or hybrid blockchains where the transactions are publicly accessible. If a wallet holds a large distribution of a cryptocurrency or token, there is a significant risk for network manipulation.

Such information can be found in the respective blockchains of interest (e.g., Etherscan for Ethereum) or in cryptocurrency and token price tracking tools such as CoinMarketCap. It’s important to remember that, in some cases, adversaries may split their holdings of tokens across multiple wallets to give the appearance of lower token accumulation in a network. It should be noted that addresses holding significant amounts of cryptocurrencies are often associated with exchanges or smart contracts. This is a typical scenario, and these addresses usually shouldn’t be factored into analytical assessments, unless there is reason to believe that an exchange or smart contract address is operating with malicious intent. Such nuances are crucial in accurately interpreting the distribution and concentration of tokens within a network.

Governmental and Legal Scrutiny

The exponential adoption of blockchain has seen severe scrutiny by governments and regulators around the globe. Such case is the lawsuit from the U.S. Securities and Exchange Commission against Ripple, accusing the defendant of conducting an $1.3 billion unregistered securities offering.

Legal and governmental scrutiny can significantly increase the risks of investing and adoption due to potential loss of value. Such losses can be partial or complete in the case where a government orders a company to cease operations (in the case of a centralized crypto project). To minimize such risks, adopters and investors alike must warrant that their crypto project of interest is not a target of governmental and legal scrutiny. When vetting a cryptocurrency project, it’s crucial to consider the influence of certain governmental entities and organizations that play a significant role in shaping global legal frameworks and policies for cryptocurrencies. These key entities typically set the standards and regulations that impact the crypto industry, and consulting their guidelines and policies is an essential step in the evaluation process. These prominent bodies include:

International Monetary Fund
European Central Bank
FATF
Bank for International Settlements
US Securities and Exchange Commission

Another useful source to help the reader better understand the current efforts on cryptocurrency regulation in different jurisdictions is the cod3x, crypto council for innovation and Atlantic Council.

Liquidity

Liquidity plays a critical role in assessing the reliability of cryptocurrency and token projects. Low liquidity can significantly impede an investor’s ability to trade, particularly when trying to exit their position (sell). Additionally, it leaves the crypto project susceptible to price manipulation, as even a small amount of capital can drastically affect the price. This environment is ripe for schemes like pump-and-dump or rug-pulls. High liquidity, conversely, makes price manipulation more challenging, requiring substantial capital to impact the market meaningfully.

However, it’s worth noting that low liquidity doesn’t always signify a lack of potential. While it often points to a newly conceived project lacking substantial backing, some major crypto projects began with limited liquidity and organically grew over time. Therefore, liquidity should be considered alongside other project features for a more comprehensive evaluation.

To assess the liquidity of a crypto project, CoinMarketCap is a useful tool. Key metrics to focus on include the fully diluted market cap, which reflects the total value of the cryptocurrency if all coins were in circulation, and the circulating supply, indicating the currently available coins in the market. Extremely low values in either metric could pose significant risks. Additionally, if the circulating supply is a small fraction of the fully diluted market cap, it may indicate potential risk, as large releases of coins into circulation could lead to substantial price fluctuations and manipulation. Such details are often outlined in a project’s whitepaper and website and should be carefully reviewed.

Auditing Use Cases

To better demonstrate the use of the proposed auditing methodology and the need for due diligence in evaluating crypto projects, we will apply this framework to three hypothetical examples of cryptocurrencies and tokens. These cases will focus on public blockchains, as private or hybrid blockchains often function as “black boxes.” In such blockchains, there is limited transparency regarding their internal workings, thus requiring a higher degree of trust.

Token “X”
Coin “Y”
Coin “Z”
Blockchain Type
Public
Public
Public
Consensus Mechanism
Proof-of-Work (high hash rate)
Proof-of-Stake (low distribution)
Proof-of-Work (low hash rate)
Team
Unknown
Known
Known
Whitepaper
Yes – Low quality, rushed, limited value
Yes – good quality
Yes – good quality
Source Code

(Git hub)

Yes – Project created 10 days ago with only two accounts linked to the project
Yes – more than 1,000 active users and developers
Yes – more than 500 users and developers
Historical hacks & Bugs
No
Yes – but vulnerabilities fixed
Yes – 51% attacks
Wallet Distribution
80% belongs to 2 private wallet addresses
40% belongs to a private wallet address
Healthy distribution, first 40 addresses hold 11% of crypto
Governmental and Legal Scrutiny
N/A
N/A
N/A
Liquidity
$90,000
$ 6,000,000
$ 100,000,000
Risks

The team is unknown.
Whitepaper shows no innovation and no substance.
 Limited financial backing.
GitHub page exists for just two weeks with little following.
Majority of the tokens are distributed in just two addresses, owned by the creators.

A high-risk investment that can be susceptible to price manipulation or a rug-pull.

Low liquidity combined with a consensus mechanism tied to stake ownership can allow threat actors to gain control over the network with a relatively small investment.

The project appears reliable and promising, yet its low liquidity poses a risk to the security of its consensus mechanism.

The network remains vulnerable to attacks due to its history of 51% hacks and ongoing low hash rate, with previous issues of adversaries overpowering the network not yet resolved.

The project looks reliable; however, 51% attacks are still possible that can lead to loss of cryptocurrency.

Conclusion

The rapid expansion of blockchain technology has garnered attention and concern from governments due to its decentralized nature and regulatory challenges. There is still a need for companies to be aware of the risks posed by these technologies, including the threat of scams and unique blockchain vulnerabilities. We hope this post serves as a guide for safe adoption and investment, stressing the importance of professional advice for financial decisions. The aim is to educate a wide audience on navigating the complex landscape of blockchain technology safely and responsibly. Always seek expert guidance, stay updated with the latest developments, and prioritize security in your blockchain endeavors.

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Security on social!

Cisco Security Social Channels

InstagramFacebookTwitterLinkedIn

Share

"}]]  Blockchain adoption and crypto investments are peaking, along with scams. Ensure safety in this bull run by being diligent.  Read More Cisco Blogs 

By |2024-04-01T21:50:54+00:00April 1, 2024|Cisco: Learning|0 Comments

7 Common Cybersecurity Mistakes Made by SMBs on April 1, 2024 at 5:30 pm

Being an SMB isn’t easy. It’s often tough to respond to the latest cybersecurity threats at scale due to resource constraints and knowledge gaps. But make no mistake, guarding your company’s data is i… Read more on Cisco Blogs

​[[{"value":"

Being an SMB isn’t easy. It’s often tough to respond to the latest cybersecurity threats at scale due to resource constraints and knowledge gaps. But make no mistake, guarding your company’s data is imperative, not only for protecting your business but also your customers.

Below, we’ve listed the seven most common security mistakes SMBs make and the best ways to address each.

1.) Weak Password Practices

Yes, this is still an issue in 2024. We would like to note that we totally understand the issues we all face with the sheer number of passwords we manage between work and our personal lives. For many, there is nothing worse than forgetting a password and having to go through confusing password retrieval processes to get back to work. However, we’re here to tell you that getting hacked is far worse than the inconvenience of waiting for that retrieval email.

According to LastPass, 81% of breaches are due to weak passwords, and while the retrieval process can be excruciating, it won’t lead to your company’s or your customer’s data being stolen. So, here are a few ways to improve your password to stop hackers in their tracks:

Keep your password secret. Tell NO ONE.
Use a different password for every login.
Password length is better than complexity… but make them complex, too.
Use multi-factor authentication (more on that later).

And when it comes to storing passwords, the days of keeping a log in our desk drawer are long over. Secure password management tools are designed to enhance online security by providing a centralized and encrypted solution for storing and managing complex passwords. Effective password management tools also often include features such as password strength analysis, two-factor authentication support, and secure password sharing options, contributing to a comprehensive approach to safeguarding digital identities.

2.) Failing to Keep Software Up to Date

Hackers are always on the lookout to exploit weaknesses in systems. And since humans design these systems, that means they are inherently imperfect. For this reason, software is always going through updates to address security concerns as they arise. Every time you wait to update your software, you’re leaving you and your customers at risk to yesterday’s security hazards.

You should always ensure your software is up to date to help prevent your company from becoming an open target. Closely monitor your applications and schedule time to check for the latest updates. That few minutes can be the difference between keeping your data safe or leaving yourself open to a cyberattack.

3.) Gaps in Employee Training and Awareness

Phishing scams are not highly technical in nature – they rely on human trust and lack of awareness to breach our cybersecurity efforts. This is the very reason why phishing scams have become the most common form of cybercrime in the world, leading to stolen credentials that give hackers free-range access to your data systems.

It’s vital that your employees be able to identify some of the telltale signs of a phishing scam. These include:

Checking to see if the email is sent from a public address. A legitimate company will likely not send an email using “gmail.com” as an address.
Verifying the spelling of the address. Many phishers try to trick your eye into believing that an address is legitimate by using tricky spelling. If you ever get an email from “Cicso.com,” we promise you that’s not us!
Is the email written well? A vast number of phishing emails originate from outside the U.S. Most hackers are not going to go through all the trouble to learn the nuances of American English before they start their life of cybercrime. If an email is poorly written, that’s a good indication you may be reading a phishing email.
Looking out for unusual links and attachments that are designed to capture credentials.
Is the email unusually urgent or pushy? Many phishing emails try to exploit employees’ good nature or desire to do a good job by assuming the role of a company leader and demanding they provide information they urgently need.

4.) Not Having an Incident Response Plan

We’ve talked a lot about ways to defend against a cyberattack, but what about after a cyberattack has occurred? It’s crucial that SMBs have a way to address cyberattacks if they occur, not only to reduce the damage caused but also to learn from mistakes and take corrective measures.

Your incident response plan should be a written document that goes over all the ways to address a cyberattack before, during, and after an event. It should outline the roles and responsibilities of members who should take the lead during a crisis, provide training for employees at all levels, and detail the steps each person should take.

This document should be reviewed throughout the company regularly and continually improved upon as new threats emerge.

5.) Neglecting to Use Multi-Factor Authentication

Sure, multi-factor authentication (MFA) can be a hassle when you need to login in a hurry, but as we stated earlier, a cyberbreach will have a far more negative impact on your business than the few minutes of productivity you lose. MFA adds an extra layer of security to your data and is very easy to set up. Most cybersecurity tools on the market have some form of MFA, so there’s really no reason to go without it. It’s especially important in today’s multi-device workplace, where employees have access to company data from work, home, or wherever they might be.

Which leads us to…

6.) Ignoring Mobile Security

Remote work continues to grow year after year. As of this 2024, over one-third of workers in the U.S. who are able to work remotely do so, while 41% work a hybrid model. As remote work continues to become the norm, more and more employees will rely on mobile phones for their day-to-day work needs.

That makes mobile security more important than ever since employees can now literally take vital company data with them on the go, outside the confines of the office. SMBs can protect mobile devices in several ways:

Require employees to password-protect their mobile devices.
Encrypt data just in case these devices are compromised.
Install specialized security apps to further protect information from hackers looking to access them on public networks.
Make sure employees have a way to quickly and easily report lost or stolen equipment.

7.) Not Having a Managed IT Service

Handling all your cybersecurity needs can be a chore, which is why managed IT services can help SMBs fill the gap so you can focus more on running your business.

Managed IT services like Cisco Meraki allow SMBs to protect against cyberattacks at scale with the help of Cisco Talos’ top security analysts. Our team will help you defend your systems from the latest security threats. The Talos team will work to bolster your incident response using the latest best practices and continually monitor your systems to respond to threats quickly.

If you’re looking for other ways to protect your SMB from emerging cybersecurity threats, our team is happy to work with you to find the right tools and best practices to protect your business. Contact a Cisco expert today, and we’ll uncover the right solutions for your specific security needs.

Share

"}]]  Being an SMB isn’t easy. It’s often tough to respond to the latest cybersecurity threats at scale due to resource constraints and knowledge gaps. But make no mistake, guarding your company’s data is imperative, not only for protecting your business but also your customers. Below, we’ve listed the seven most common security mistakes SMBs make  Read More Cisco Blogs 

By |2024-04-01T21:50:53+00:00April 1, 2024|Cisco: Learning|0 Comments

Rev Up to Recert: Network Assurance Learn and earn CE credits for free on April 1, 2024 at 5:00 pm

Given my role in supporting technical education over the last 10 years, I’m often asked one question: “What should I be learning?”

My answer: Follow the A technologies: APIs, automation, aRead more on Cisco Blogs

​[[{"value":"

Given my role in supporting technical education over the last 10 years, I’m often asked one question: “What should I be learning?”

My answer: Follow the “A” technologies: APIs, automation, applications, and now artificial intelligence (AI).

Given the recent emergence of observability as a capability for employability, the “A” I recommend to network engineers, DevOps practitioners, and IT professionals is assurance.  

What is network assurance?

For those new to assurance, its power lies in its ability to detect network anomalies and provide insights on remediation before those anomalies escalate into serious problems. This capability drives the demand for assurance—most importantly, how and when engineers can use this new data and insights to make decisions. 

As modern network infrastructure grows increasingly complex, demands on the network change and become more challenging. As such, the ability to look at the network stack — from the top down and the bottom up — is a requirement for high-performing networks and applications. That’s why network assurance has emerged as a critical skill. Network assurance is the practice of predictively addressing potential issues, optimizing network operations, and aligning network performance with business objectives. Cisco has tools that support this function, including Cisco ThousandEyes. 

Rev Up to Recert: Network Assurance

The criticality of these skills and the value they present to organizations across the globe are the reasons we’ve announced our new Enterprise Network Assurance Specialist certification (launching May 20, 2024) and selected the Leveraging Cisco Intent-based Networking DNA Assurance | DNAAS Learning Path for our new Rev Up to Recert free training offer. Rev Up to Recert is a program where you can access premium learning for a limited time, with active Cisco Certification holders gaining the added benefit of accumulating Cisco Continuing Education (CE) credits for free.

For those who want to learn how to leverage monitoring tools, automate operations, improve security, and increase the overall efficiency of the network and network teams, this is a fantastic opportunity:

Rev Up to Recert: Network Assurance gives you free access to the Leveraging Cisco Intent-based Networking DNA Assurance | DNAAS Learning Path in Cisco U. from April 1  to May 6, 2024. And, if you are actively Cisco Certified, the DNAAS Learning Path is eligible for 16 CE credits you can apply towards completing your recertification requirements.

Cisco DNA Assurance (now called Cisco Catalyst Assurance) exemplifies this next frontier in network management skills, making the DNAAS Learning Path an excellent primer for the new Enterprise Network Assurance certification.

What you’ll learn

In the DNAAS Learning Path, you’ll be putting theory into practice, learning how advanced AI/ML features within Cisco Catalyst Assurance enable engineers to isolate the root cause of a problem and take appropriate actions to quickly resolve the issue. In addition to building fundamental assurance skills, you’ll also build skills to use monitoring, insights, and data to streamline network operations.  

These days, given the rapid pace of innovation and invention, the need to continue learning is as omnipresent as it is overwhelming; knowing what to learn can be a skill in and of itself. And knowledge isn’t just power — it’s a survival tool in the tech jungle. As we wade through the alphabet soup of “A” technologies, I hope assurance rises to the top of your list for learning.

Here’s to transforming a challenge into an opportunity, one “A” at a time. Hope to see you revving up your learning and recertification journey this month during Rev Up to Recert: Network Assurance! Leave me a comment below if you’ll be revving up this month with the Cisco learning community. And if you are currently Cisco Certified, let me know which certification you’re revving up to recertify. Thanks for reading!

Rev Up to Recert: Network Assurance

Get free access to the Leveraging Cisco Intent-based Networking DNA Assurance | DNAAS Learning Path.

Available April 1 – May 6, 2024. Get started now

Meet ENNA, the New Cisco Enterprise Network Assurance (ENNA) Specialist Certification

Sign up for Cisco U. | Join the Cisco Learning Network.

Follow Cisco Learning & Certifications

Twitter | Facebook | LinkedIn | Instagram | YouTube

Use #CiscoU and #CiscoCert to join the conversation.

Share

"}]]  Ahead of the new Enterprise Network Assurance Specialist certification release, the Rev Up to Recert program emphasizes the importance of learning network assurance, offering free access to the Leveraging Cisco Intent-based Networking DNA Assurance | DNAAS Learning Path from April 1 to May 6, 2024.  Read More Cisco Blogs 

By |2024-04-01T21:50:53+00:00April 1, 2024|Cisco: Learning|0 Comments

Cisco at NAB 2024: Committed to Delivering Next-Level Experiences That ‘Wow’ on April 1, 2024 at 8:12 pm

We are less than two weeks away from the National Association of Broadcasters (NAB) 101st Show happening once again in Las Vegas, Nevada. As a decade-long returning attendee, I am always excited to… Read more on Cisco Blogs

​[[{"value":"

We are less than two weeks away from the National Association of Broadcasters (NAB) 101st Show happening once again in Las Vegas, Nevada. As a decade-long returning attendee, I am always excited to be with customers, partners, and colleagues, shaking hands and engaging in stimulating conversations about the next wave of innovation hitting the media and entertainment industry. With new technology features, expanded partnerships, and growing customer momentum, I am looking forward to highlighting Cisco’s cutting-edge solutions and services to our booth visitors this year. 

Our leadership in this space continues to grow as we innovate across our portfolio to transform the way broadcasters, content providers, venues, sports teams and leagues are harnessing the power of AI and other emerging technologies and taking audience experiences to the next level.    

This year, we will showcase our comprehensive portfolio and demonstrate Cisco’s strategy and innovation across three key areas:   

Enabling dynamic IP production and workflows   
Transforming content delivery, devices, and network assurance   
Operationalizing the fan experience with cutting-edge, technology-centric venues

Enabling Dynamic IP Production  

The broadcast industry’s evolution to IP requires sustainable technology to provide great multicast visibility and flexibility to allow integration of multiple multicast and/or unicast, on-premises and cloud domains. Visitors to the Cisco booth can expect to see our flagship solution, Cisco IP Fabric for Media (IPFM), on display at the Cloud Native Media Production- Anywhere demo to show how we are enabling these transitions to IP aligned with SMPTE 2110. With several hundred deployments across the globe, Cisco IP Fabric for Media continues to serve as the foundation to address broadcaster’s audio and video requirements. 

Cisco IPFM includes features for Non-Blocking Multicast (NBM), Network Address Translation (NAT), and now, Protocol Independent Multicast flooding mechanism with Source Discovery (PFM-SD). These components provide end-to-end multicast, live traffic visibility, simplified and flexible deployment at scale, innovations in NBM active, and both PTP and RTP flow monitoring. With our simplified network management and operations tool for provisioning IP-based media fabrics, Cisco Nexus Dashboard Fabric Controller (NDFC), users can now take advantage of an expansive view of the network with 2022-7 visibility and enhanced Events UI Tab to capture critical fault notifications. 

Together with Intel, we will be highlighting our innovative solution for Cloud Native Media Production which uses cloud-native architectures with open standards and open-source software to power new media workflows and help speed digital transformation. 

Transforming Content Delivery, Devices, and Network Assurance 

Together with our partner Qwilt, we will be showcasing Global Edge Cloud for Content Delivery, highlighting how together we are creating a more efficient way to deliver highly distributed live and on-demand content. Our joint solution, serving over one billion unique subscribers globally, provides Quality-as-a-Service by pushing content caching and delivery out to the embedded edge of the carrier network. 

Comprised of Cisco’s edge infrastructure and Qwilt’s Open Edge platform, the solution based on open caching is helping meet the ever-increasing demand for content delivery and edge cloud services and improving re-buffering time, time to first frame (TTFF), average bitrate (ABR) and error rate for live-streamed content delivery.  

We’ve seen a growing need for trusted collaboration tools and devices to help drive engaging virtual and hybrid entertainment experiences, and to connect teams across the globe. In the Cisco Devices: Be there, from Anywhere demo, we will highlight intuitive and interoperable device experiences that are designed to make remote and hybrid collaboration seamless and distraction-free, on any meeting platform. The native Microsoft Teams experience on certified Cisco collaboration devices is designed for frictionless employee experiences. 

Accedian will take center stage in our Cisco Critical Network Assurance demo, highlighting how the most recent addition to Cisco’s observability portfolio is providing industry-leading network performance monitoring and assurance to help enable seamless operations for content providers, service providers, and more.  

Operationalizing the Fan Experience 

One of my personal favorites, and arguably the cornerstone of our Sports, Media and Entertainment portfolio, is our best-in-class VisionEDGE solution for IPTV & Dynamic Digital Signage in partnership with Wipro. A solution that truly “wow’s”, VisionEDGE provides dynamic content management solutions and high quality experiences to every fan, in every seat at venues all over the world including (but not limited to) Allegiant Stadium here in Las Vegas, CITYPARK in St. Louis, Etihad Stadium in Manchester, GEODIS Park in Nashville, Santiago Bernabéu Stadium in Madrid, and SoFi Stadium and Hollywood Park in Los Angeles (host of Super Bowl LVI). 

As you make your way across the show floor at the Las Vegas Convention Center during NAB be sure to check out the Cisco Booth, #W2743 in the West Hall, and see for yourself how Cisco and our impressive ecosystem of partners are forging a path of innovative new experiences for the media and entertainment industry. 

To learn more, visit the Sports, Media and Entertainment section of the Cisco Portfolio Explorer or book a meeting with us here.

Share

"}]]  Between reacting to expectations and elevating experiences, there's a bridge. Cisco is showcasing how we help our customers thrive at NAB 2024. Here is what you need to know to get connected. Visit Cisco at NAB Booth #W2743 in the West Hall.  Read More Cisco Blogs 

By |2024-04-01T21:50:52+00:00April 1, 2024|Cisco: Learning|0 Comments
Go to Top