About (Edit profile)

This author has not yet filled in any details.
So far has created 1829 blog entries.

Simplifying Firewall Management: Cisco Defense Orchestrator Nears FedRAMP® Authorization Will Ash on March 4, 2024 at 2:00 pm

Cisco continues its focus on FedRAMP® Authorization for our government customers with yet another solution, Cisco Defense Orchestrator (CDO), which has now achieved FedRAMP In-Process status. With … Read more on Cisco Blogs

​[[{"value":"

Cisco continues its focus on FedRAMP® Authorization for our government customers with yet another solution, Cisco Defense Orchestrator (CDO), which has now achieved FedRAMP In-Process status. With CDO your agency gains an integrated cloud management solution that streamlines and improves efficacy of policy administration across a variety of security solutions. This lets you manage, analyze, and optimize firewalls (FTD, ASA) across on-premises, virtual, and cloud environments with simplicity, increasing your agency’s effectiveness and compliance.

Cisco Defense Orchestrator’s In-Process status comes on the heels of Cisco Meraki achieving FedRAMP agency Authority to Operate (ATO), and reflects our ongoing commitment to provide secure and efficient digital transformation for government agencies. CDO gives your agency’s IT team one place to manage all your network security solutions, regardless of form factor, from cloud to hardware.

How Cisco Defense Orchestrator adds value for government

Did you know meeting FedRAMP requirements is crucial for the modernization of your network? By deploying Cisco Defense Orchestrator (see FedRAMP Marketplace Listing), your agency can maintain a strong security posture and further meet those FedRAMP requirements with:

Improved security posture – CDO effectively manages security policies and configurations to enhance security and reduce vulnerabilities and attack surfaces.
Efficient policy management – Control policies and share objects across various firewall form factors, providing a fully unified experience between on-premises and cloud-based management. This efficiency aligns with FedRAMP’s goal of ensuring secure and compliant operations.
Centralized visibility – With CDO, federal agencies have real-time insight into network traffic and security events, enabling faster threat detection and mitigation by security teams. This visibility is crucial for maintaining compliance with FedRAMP requirements. Plus, CDO’s advanced analytics give you insight into remote user traffic, including visibility and geographic distribution, helping you better manage security.
Automation and orchestration – CDO streamlines security policy changes and orchestrates workflows, saving time and effort while ensuring consistent policy enforcement. It also offers automation and orchestration capabilities, handling routine tasks such as object updates and device onboarding.
Audit and compliance reporting – CDO offers robust reporting capabilities, helping organizations track and document security policy changes. These reports and their detailed information are valuable for demonstrating compliance with FedRAMP standards.
Real-time threat intelligenceCisco’s threat intelligence feeds are integrated with CDO, providing real-time information on emerging threats. This helps federal agencies stay proactive in their security posture, which is essential for FedRAMP compliance.
Scalable security from the cloud – Being a Software-as-a-Service (SaaS) solution, CDO can scale to meet the evolving needs of federal agencies, making it suitable for organizations of various sizes. This scalability aligns with FedRAMP’s goal of supporting the growth and changing requirements of government entities.

Why FedRAMP is important to your agency

As you may know, FedRAMP, short for Federal Risk and Authorization Management Program, is a U.S. government-wide program that standardizes the security assessment, authorization, and monitoring processes for cloud products and services used by federal agencies.

The U.S. government’s FedRAMP program was established to improve the security posture of federal information systems and data by ensuring that Cloud Service Providers (CSPs) meet stringent security standards and requirements by:

Providing a standardized set of security requirements and assessment processes.
Enhancing the security posture of cloud services used by federal agencies by requiring CSPs to undergo a rigorous security assessment process.
Reducing the cost and effort required for federal agencies to assess and authorize cloud services individually.
Allowing interoperability between federal agencies, promoting collaboration and information sharing – a“win-win”for everyone.

Best of all, Cisco’s FedRAMP solutions can also be deployed by state, local, and Tribal governments, allowing them to gain the same high level of security and compliance achieved through the program’s rigid testing and processes.

Remember, FedRAMP is crucial to your agency’s success

If you serve in a federal agency, FedRAMP plays a crucial role in ensuring the security and compliance of your cloud services. Its standardized approach, risk management focus, and emphasis on continuous monitoring helps to protect your data while also streamlining your procurement and adoption of cloud technologies.

By setting high security standards and requiring continuous monitoring, FedRAMP reduces your risk of data breaches and cyberattacks, which is critical for protecting your sensitive government information and keeping our nation secure. That’s why our team at Cisco continues to focus on FedRAMP Authorization for our solutions and why we’re excited that another Cisco solution, Cisco Defense Orchestrator, has achieved FedRAMP In-Process status, and is helping secure America’s future.

Additional resources

For more information on the FedRAMP authorization process, visit Understanding FedRAMP: How Cisco Umbrella is Getting Authorization.
Discover Cisco’s FedRAMP solutions.
See how Cisco serves the U.S. federal government.

Share

"}]]  Cisco continues its focus on FedRAMP® Authorization for our government customers with the addition of Cisco Defense Orchestrator (CDO), which has now achieved FedRAMP In-Process status. Cisco CDO is an integrated cloud management solution that streamlines policy administration across security solutions.  Read More Cisco Blogs 

By |2024-03-05T00:55:58+00:00March 5, 2024|Cisco: Learning|0 Comments

Improved Area Monitoring with New Meraki Smart Cameras Anjana Iyer on March 1, 2024 at 11:27 pm

Meraki’s smart cameras offer businesses an easy-to-deploy way to monitor their physical security, with the added benefit of being managed entirely on the cloud. Various Meraki cameras are deployed in… Read more on Cisco Blogs

​[[{"value":"

Meraki’s smart cameras offer businesses an easy-to-deploy way to monitor their physical security, with the added benefit of being managed entirely on the cloud. Various Meraki cameras are deployed in the Cisco Store, including the outdoor smart cameras MV63 and MV93, which have long been useful in the Cisco Store. The MV63’s wide-angle, fixed-focused lens monitors the entrances and exits of the store, while the MV93’s 360° fish-eye lens offers panoramic wide area coverage, enhancing surveillance capabilities even in low lighting. Both cameras have helped keep the Cisco Store secure by using important features such as intelligent object detection using machine learning, motion search, and motion recap.

Now, these two cameras have indoor counterparts. Launched in February 2024, the Meraki MV13 and MV33 cameras will continue to improve security measures with even clearer footage, high performance, and stronger analytics. Meraki’s latest camera features, attribute search and presence analytics, will further improve these cameras’ capabilities.

Introducing the newest indoor smart cameras, Meraki MV13 and MV33

The new Meraki MV13 has a fixed lens and is ideal for monitoring indoor hallways and spaces. It is easy to deploy and offers some of the best visual components like 8.4 MP image quality and up to 4K video resolution.

Meraki MV13 smart camera

Meanwhile, the Meraki MV33 has a 360° fish-eye lens and 12.4 MP image quality, and can be used to monitor general indoor retail, hospitality, education, and healthcare spaces.

Meraki MV33 smart camera

Faster search, smarter insights

Meraki simultaneously launched two new features: attribute search and presence analytics.

The attribute search feature is an easier and faster way of parsing through video footage based on a person’s clothing color (both top and bottom) as well as a vehicle’s color and make. In the event there is a suspicious person or theft, this feature would allow security teams to quickly filter through footage by these attributes from up to four cameras, thus improving store security measures.

Meanwhile, the new presence analytics feature includes area occupancy analytics and line-crossing analytics. These will allow security teams to define areas to be analyzed and then accurately gain insights on people movement in those spaces.

Both the MV13 and MV33 will add to Meraki’s broader portfolio of cameras, giving organizations more flexibility and ways to monitor all areas of their buildings with ease, including in the Cisco Store. Attribute search has been incorporated into both the indoor Meraki MV13 and outdoor Meraki MV63, while presence analytics is now available on all second and third generation cameras. By creating tracking areas and easily being able to adjust those lines, security teams can customize what they monitor and then receive analytics that help them identify suspicious activity and gain insights into crowds.

The new MV13 and MV33 smart cameras will be deployed in the Cisco Store in San Jose, California this week! To get a sneak peek, watch our Tech Lab expert Brian Domine showcase the two cameras at Cisco Live EMEA in Amsterdam.

Interested in learning more about the Meraki MV13 and MV33? Request a demo now.

Share

"}]]  Improve store monitoring with the newest Meraki smart cameras and features.  Read More Cisco Blogs 

By |2024-03-02T08:51:17+00:00March 2, 2024|Cisco: Learning|0 Comments

You’re automated for success with Cisco’s Continuing Education program David Major on February 29, 2024 at 11:40 pm

The tedious task of logging Continuing Education (CE) credits can be a frustrating speed bump in the certification journey. The Learning and Certifications team gets that and has added automation to… Read more on Cisco Blogs

​[[{"value":"

The tedious task of logging Continuing Education (CE) credits can be a frustrating speed bump in the certification journey. The Learning and Certifications team gets that and has added automation to help streamline the credit submission process. We’re talking about less manual data entry, fewer manual submission headaches, and a more seamless learning and recertification experience.

Cisco introduced Continuing Education automation a few months ago, but what does it really mean for you as a Cisco certification holder interested in recertifying? Let’s dive into the solutions Cisco’s automated Continuing Education program brings to the table, making your recertification journey smoother and more focused on learning.

Ditch CE claims with a streamlined recertification progress

The automated Continuing Education program awards credits as you complete eligible training. Using your cisco.com ID, the system recognizes you as a certified individual and applies credits within 24 hours of your completed training. So you can focus on learning and watch your recertification progress take care of itself.

Enjoy hassle-free certification mapping: Follow these steps for a seamless experience

Ensure your Cisco ID matches your active certification profile and open a support case if you’re not sure.
Enroll by logging in to the Continuing Education portal with the same Cisco ID and accepting the user agreement.
Monitor Continuing Education credits and track your recertification progress.
Then let the system handle the rest!

Focus on learning, control your timeline, we’ll handle the rest

Your recertification is now tailored to your training completion date. And with three years after recertification until your next deadline, you have time to track and monitor your progress, controlling your timeline and exploring your passions as you complete training at your own pace. Cisco’s commitment is to let you enjoy your learning journey while they take care of the administrative side.

The benefits of embracing Cisco’s automated Continuing Education program are not just theoretical; they’re tangible and transformative.

Experience continuous learning and look toward future plans

While we’re not fully automated yet, we’re working toward full automation for your future Continuing Education experience. Some examples include:

Full automation for all eligible activities
Streamlined/consolidated experience within Cisco U.
Enhanced recertification progress tracking
Added functionality for candidates to manage which Continuing Education credits apply toward recertification

We heard your feedback and changed our tracking process 

We recognized our tracking system had requirements that limited the way your credits rolled over. But don’t worry; we’ve changed the process. In fact, we’ve recalculated and reapplied any credits that did not roll over before, so now all your well-earned credits will roll over to the next recertification cycle for Associate-, Specialist-, and Professional-level certifications. If you have any questions or concerns regarding your certification status or Continuing Education credits, please open a support case.

Happy Learning!

Sign up for Cisco U. | Join the Cisco Learning Network.

Follow Cisco Learning & Certifications

Twitter | Facebook | LinkedIn | Instagram | YouTube

Use #CiscoU and #CiscoCert to join the conversation.

Share

"}]]  Cisco's Learning and Certifications team has streamlined and automated the credit submission process for recertification. We’re talking about less manual data entry, fewer manual submission headaches, and a more seamless learning and recertification experience.  Read More Cisco Blogs 

By |2024-03-01T20:50:14+00:00March 1, 2024|Cisco: Learning|0 Comments

Cisco Live Melbourne SOC Report Christian Clasen on March 1, 2024 at 1:00 pm

Executive Summary. 1

The Team… 2

Team Leaders. 2

Core Infrastructure and Threat Hunting. 2

Threat Hunting. 2

Build and Operation. 2

SOC Architecture. 2

Cisco Secure Access Enables ZTNA for SOC… Read more on Cisco Blogs

​[["value":"

Executive Summary. 1

The Team… 2

Team Leaders. 2

Core Infrastructure and Threat Hunting. 2

Threat Hunting. 2

Build and Operation. 2

SOC Architecture. 2

Cisco Secure Access Enables ZTNA for SOC Admins. 4

Powering XDR with the Cisco Secure Portfolio. 6

Analyst Stories. 9

New Domain Investigations. 9

Mirai Botnet Attempts. 11

Log4j Attempts. 14

SERVER-WEBAPP LB-Link Multiple BLRouters command injection attempt (1:62009:1) Dinkar Sharma, Aditya Sankar 16

Threat hunting and Noise reduction in XDR Private Intelligence. 18

DNS Statistics. 23

Executive Summary

Cisco has long provided security services to third party events such as the Black Hat and RSA conferences, as well as the Super Bowl and the Olympic games. These services come in the form of both products (Umbrella, XDR, Malware Analytics, and more) and skilled SOC analysts who build and operate the infrastructure and hunt for threats from both inside and outside the event networks.

This year, the team was tapped to build a similar team to support the Cisco Live Melbourne 2023 conference. This report serves as a summary of the design, deployment, and operation of the network, as well some of the more interesting findings from three days of threat hunting on the network.

The Team

Team Leaders

Christian Clasen, Shaun Coulter

Core Infrastructure and Threat Hunting

Freddy Bello, Luke Hebdich, Justin Murphy, Ryan MacLennan, Adi Sankar, Dinkar Sharma

Threat Hunting

Cam Dunn, Jaki Hasan, Darren Lynn, Ricky Mok, Sandeep Yadav

Build and Operation

SOC Architecture

Ryan MacLennan, Aditya Sankar, Dinkar Sharma

Security Operation Centers (SOCs) need to work with multiple products to get the data needed to efficiently find threats.  The more data a SOC can receive, the richer and more accurate the detections will be. To make sure we get the data we designed the SOC with most of the Cisco Secure portfolio and other supporting products.  We are using the below products on-prem:

Secure Network Analytics
Firepower Threat Defense
Firewall Management Center
CSRv 1k
Nexus Data Broker
Cisco Telemetry Broker Manager
Cisco Telemetry Broker node
Splunk

And we are using the below SaaS products:

Secure Access
XDR
Secure Cloud Analytics (SCA)
Umbrella
Cisco Defense Orchestrator (CDO)
Secure Endpoint
Orbital
Secure Malware Analytics

How all these products integrate is in the diagram below.

This diagram does not go over what the Cisco Live Network Operations Center (NOC) deployed or was using as enforcement measures. As such, those devices and policies are outside the scope of this blog.

Looking at the above image we see the conference network data coming into the Network Operations Center’s data center (DC) on the left side. Our SOC is being fed the same data the Cisco Live NOC is seeing using a Nexus Data Broker. The broker sends a copy of the data to the Cisco Telemetry Broker and that normalizes the data and sends it to multiple other destinations that we control like Secure Cloud Analytics and Network Analytics.

The broker sends another copy of the data to our physical Firepower Threat Defense. The Firepower Threat Defense is managed using a virtual Firewall Management Center (FMC) and is not doing any enforcement on the traffic. We did set up the below:

Network Analysis Policy
Security Over Connectivity IPS policy
File policy including all files doing a malware cloud lookup
Dynamic Analysis
Spero Analysis
Storing Malware

Logging at the beginning and end of connections
DNS sent to Umbrella
Secure Malware Analytics integrated
Security Analytics and Logging (SAL) integration
XDR integration

In the NOC DC, we have a Splunk instance running that is receiving logs from the FMC and from Umbrella.  Then Splunk sends its logs up to XDR for additional enrichment in investigations.

Slightly to the right of the NOC DC, there is a cloud with SOC Analysts in it.  This is the internet that we used to connect to our internal resources using Secure Access. We used Secure Access in conjunction with a virtual CSR to connect to internal resources like the FMC and Secure Network Analytics.  The deployment of this is delved into further in the next section.

On the bottom left, we have Secure Client deployed around the conference to send NVM and EDR data to XDR and Secure Endpoint. Lastly, we have all the products in the orange dotted box sending data to XDR and third-party feeds being fed into XDR too.

Cisco Secure Access Enables ZTNA for SOC Admins

Christian Clasen, Justin Murphy

Security operators, not unlike systems administrators, need unique and elevated access to network resources to accomplish their objectives. Mission critical infrastructure hidden behind firewalls and segmented management networks have traditionally been made accessible by remote access VPN solutions. With the development of Zero Trust Access (ZTA) solutions, it is possible to provide a more transparent and efficient way to enable SOC analysts with the access they need without sacrificing security. In the Cisco Live Melbourne SOC, we are using Cisco Secure Access to provide this ZTA to our crew and enable them to manage infrastructure and threat hunt from anywhere while supporting the event.

There are several benefits ZTA provides over traditional VPN.  While VPN provides per connection authentication and posture for network access, ZTA checks identity and posture per application.  Instead of giving blanket access to the management network or having to write rules based on source IP, all rules in Secure Access are per user, per application, giving very granular control and logging to all the security consoles.  This provides a natural audit log of who is accessing what.  Because Secure Access is a cloud service, it can provide secure connectivity from anywhere meaning we cannot participate in threat hunting and troubleshooting inside the SOC, but also from our hotel rooms or wherever we happen to be when needed. It is fully compatible with Secure Client VPN and so our connectivity to Cisco corporate is not impacted when required.

The first step in setting up ZTA access was to create a back-haul connection between the SOC infrastructure and Cisco Secure Access. This was accomplished by deploying a Cisco CSR1000v virtual router and configuring it with two IPsec tunnels. The tunnels are authenticated using email-formatted strings and passphrases configured in the dashboard.

Secure Access supports both static and dynamic routing when making private applications available on the router side of the tunnels. Since we had a basic network setup and the CSR was not the default gateway for the security appliances, we opted for static routes to the SOC management subnet. We sourced the tunnels from two loopback interfaces, and added a slightly higher route metric to the backup tunnel to make sure it was only used in the case that the first tunnel was down. Lastly, we added NAT statements to make sure everything sourced from the router used the internet router interface’s IPv4 address. This solved any issues with return traffic from the appliances.

In Secure Access, we then configured private resources and made them available over both clientless and client-based connections. This solved out management access issues and allowed us to concentrate on our SOC duties rather than our connectivity.

Powering XDR with the Cisco Secure Portfolio

Ryan MacLennan, Aditya Sankar, Dinkar Sharma

An XDR is only as good as the underlying security controls that power it. Cisco XDR is powered by integrations; the more integrations configured the more powerful Cisco XDR becomes. At Cisco Live Melbourne we had numerous Cisco and 3rd party integrations operational in our XDR deployment. Below is an image drawn on a whiteboard at Cisco Live Melbourne which we used to discuss the integrations with the SOC visitors.

On the right side of the image is the Nexus Data Broker. This is ingesting a SPAN of the conference network and distributing it to multiple tools. The SPAN is sent to a flow sensor to enable deep visibility into east-west and north-south traffic using Cisco Secure Network Analytics. This serves as our on-prem NDR with full capabilities to create custom security events and is integrated with XDR through Security Services Exchange. Security Services Exchange keeps a secure web allowing XDR to query the Secure Management center for alerts involving specific IP addresses. The web socket is initiated from inside to outside on TCP 443 so poking holes in an edge firewall is not required for connectivity.

Next the SPAN is sent to a passive mode Firewall. Cisco Secure Firewall conducts deep packet inspection using the full set of Snort 3 rules. These intrusion detections, including security intelligence events and malware events are sent to Security Services Exchange for enrichment during XDR investigations. Through CDO, the security events along with the connection events are sent to XDR for analytics which can produce anomaly detections and create incidents in XDR (this form of event streaming was known as SaL SaaS). The Firewall is the heart of any network and is a valuable source of data for Cisco XDR.

Lastly, the SPAN is sent to ONA (observable network appliance). This VM converts the SPAN to IPFIX and forwards it to XDR for analytics of all the conference traffic. There are over 60 detections in XDR that can be triggered from this netflow. The alerts can be corelated together based of similar characteristics into attack chains. These attack chains are then promoted to XDR as single incidents. This level of correlation in XDR allows the security analyst to spend less time triaging alerts and more time focused on the alerts that matter.

Using the eStreamer protocol, the Firewall sends logs with additional meta data to Splunk. These logs are indexed in splunk and visualized using the  Cisco Secure Firewall App for Splunk. Splunk also integrated directly with Cisco XDR using Security Services Exchange for on-prem to cloud connectivity. With the Cisco XDR and Splunk integration, investigations in Cisco XDR will query Splunk for logs containing the observables in question. The results are then visualized in the XDR investigation graph. In our case this allowed us to use XDR investigate to not only query the Firewall security events but also query the connection events that were indexed in Splunk.

In the bottom right of the image is the conference network. The endpoints used at the demo stations in World of Solutions had the Cisco Secure Client agent installed on them. This offered XDR granular visibility into the endpoint using Cisco Secure Endpoint. Additionally, the NVM module sends Netflow directly from the endpoints to XDR for analytics and correlation. These endpoints are cloud managed from XDR making it easy to make changes to profiles if needed.

Umbrella was used as the DNS provider for the entire conference. Umbrella is directly integrated with XDR for enrichment during investigations. The Umbrella roaming client was installed on the endpoints using Cisco Secure Client. XDR Automation also used the Umbrella reporting API to notify the SOC team on Webex if there were any DNS requests in security categories detected by Umbrella.

The SOC also took advantage of plenty of 3rd party intelligence sources in conjunction with Talos threat intelligence. Another new addition to the SOC was the use of Cisco Secure Access to provide seamless connectivity to our on-prem appliance. This really streamlined our investigation and allowed the entire team to have access to our security tools from anywhere at the conference or at our hotels.

In summary, Cisco XDR was used to its maximum potential with a litany of Cisco integrations as well as 3rd party integrations. Cisco XDR will continue to advance with more integrations, correlations and data ingest capabilities!

Analyst Stories

New Domain Investigations

Ryan MacLennan

During the conference we saw resolutions of many new domains that hadn’t been seen by Umbrella’s global DNS resolvers.  While checking on these domains we saw an ngrok domain come up Umbrella.

ngrok is a reverse proxy application often used by developers to test webhook implementations, but this warranted further investigation. We took the URL of the domain and tossed it into Malware Analytics to investigate the site manually.

Malware Analytics returned a threat score of 85.  That is quite high and tells us that it is worth investigating further. But we need to look at the detonation recording and see where this ngrok URL is redirected to, to determine if it actually is malicious.

Initially the page went to a ngrok splash page:

Continuing to the site showed that it goes to a Grafana monitoring instance.

We see that it is using HTTPS and is secured from sniffing out the username and password in clear text.  This concluded the investigation.

Mirai Botnet Attempts

Luke Hebditch, Ryan MacLennan

During the conference we noticed many intrusion events linked to ISAKMP packets coming towards the firewall.

They were all considered to be attempts for the Zyxel unauthenticated IKEv2 injection attack.

Investigating the data in one of the packets showed a command injection attempt. Buried in the packet is a command that attempts to download a file and pipe it into bash to run it immediately. This is a common technique to gain persistence or bypass security measures. These kinds of attempts are generally blocked.

Looking at our logs, we saw our IDS would block this but since the SOC is out-of-band, we only have the analytics we can use at the time.

To further investigate this issue, we spun up a sandbox in Secure Malware Analytics and ran these commands to see what it is trying to do.

The initial command tries to download a file called “l.”  In the “l” file we found these commands being run in the file:

kill -9 $(ps -ef ]]  This year, the team was tapped to build a similar team to support the Cisco Live Melbourne 2023 conference. This report serves as a summary of the design, deployment, and operation of the network, as well some of the more interesting findings from three days of threat hunting on the network.  Read More Cisco Blogs 

By |2024-03-01T20:50:14+00:00March 1, 2024|Cisco: Learning|0 Comments

Seamless shopping with Room & Board Adriana Soto Ruiz on February 29, 2024 at 8:23 pm

In the bustling world of retail, the customer experience reigns supreme. Retailers are continuously seeking innovative ways to enhance customer engagement and satisfaction. One pioneer in this… Read more on Cisco Blogs

​[[{"value":"

In the bustling world of retail, the customer experience reigns supreme. Retailers are continuously seeking innovative ways to enhance customer engagement and satisfaction. One pioneer in this endeavor is Room & Board, a modern furnishings retailer, which leverages advanced technology to redefine the retail experience for its clientele.

Redefining Customer Engagement

Room & Board places a strong emphasis on building lasting relationships with its customers. Central to this commitment is the provision of personalized services, such as its renowned free design service. Whether in-store or remotely, customers receive expert guidance tailored to their individual preferences and needs. By harnessing technology, Room & Board ensures a seamless and immersive shopping journey for each customer.

Fortified by a Secure Networking Foundation

To support its customer-centric initiatives, Room & Board has partnered with Cisco to establish a secure networking infrastructure. Cisco Meraki MR access points and cloud-managed switches provide reliable wireless coverage and performance across Room & Board’s retail locations. Moreover, the adoption of secure access service edge (SASE) architecture enhances the security and scalability of the network, safeguarding customer data and optimizing operational efficiency.

Streamlining Operations for Optimal Efficiency

Operational efficiency is crucial in delivering exceptional customer experiences. Room & Board streamlines network and security operations through Cisco’s integrated solutions, empowering its IT team to focus on strategic initiatives. By consolidating management systems and leveraging comprehensive data insights, Room & Board enhances agility and responsiveness, ensuring seamless operations across its retail locations.

Your trusted technology partner in retail

Room & Board exemplifies the transformative impact of technology on the retail experience. Through strategic partnerships with Cisco, Room & Board has redefined customer engagement, setting a new standard for excellence in the industry. From personalized services to secure networking foundations and streamlined operations, Room & Board continues to innovate and elevate the retail experience for its customers. As the retail landscape evolves, Room & Board remains committed to harnessing technology to deliver unparalleled experiences and drive sustained success in the retail industry. Explore our portfolio explorer to uncover more retail use cases and discover how innovative technology is transforming the shopping experience.

Share

"}]]  Explore how Room & Board transforms the retail experience with innovative technology, prioritizing seamless customer engagement and operational efficiency for an unparalleled shopping journey.  Read More Cisco Blogs 

By |2024-03-01T08:49:36+00:00March 1, 2024|Cisco: Learning|0 Comments

Investing in partnerships for inclusion and innovation: a spotlight on Astia and Kiva Julie Rose on February 29, 2024 at 8:03 am

The Social Impact Partner Spotlight series highlights various Cisco non-profit organization partners that are helping transform the lives of individuals and communities. This blog features Cisco’s par… Read more on Cisco Blogs

​[["value":"

The Social Impact Partner Spotlight series highlights various Cisco non-profit organization partners that are helping transform the lives of individuals and communities. This blog features Cisco’s partnership with Astia and Kiva, in honor of the incredible work these organizations are doing to advance investment opportunities to Black, Indigenous, and People of Color-owned businesses in the United States and globally.  

Cisco Social Innovation Investments (SII) and the Cisco Foundation partner with nonprofits globally to invest in equitable and innovative tech-enabled solutions that provide meaningful and scalable impact, especially in underserved communities. Supporting opportunities and partnerships that level the playing field for promising but often overlooked entrepreneurs and companies is a key driver of Cisco SII and the Cisco Foundation’s ability to make long-lasting impact on a local, national, and global scale. Learn more about two of Cisco’s partners, Astia and Kiva, who are leading impactful work in providing opportunities and resources for entrepreneurs and their businesses– and learn about ways to support both organizations.   

Astia

“Astia’s investment team came to the table with the expertise, they made calls on my behalf and took investor meetings with me – they breathed life into the funding process. Within a mere four months of Astia saying yes, we had significant investors on our cap table, and we achieved an oversubscribed round.”
– Tanya Van Court, Founder & CEO, Goalsetter 

Less than 3% of venture capital is invested into women-led startups with women CEOs, and a mere 0.3% is deployed into companies led by Black or Latina women. Astia is a global pioneer investing in innovative, women-led companies. With a reputation for innovating on the venture capital model, Astia is a beacon of success for investors and entrepreneurs. Its mission is to level the investment playing field for companies led by women, with a particular emphasis on doing so for Black and Latina CEOs. To address the intersectionality of race and gender, Astia established a clear focus via an effort called Astia Edge, a program designed to redress the funding imbalance. Learn more about their findings and focus in this Bloomberg interview with Astia’s CEO and download the Edge whitepaper. 

Cisco funding and strategic guidance have enabled the development of an underlying technology platform, Astia Connect. Via Connect, 5,000+ experts around the globe connect with 1,000+ companies each year, elegantly eradicating bias from the investment decision-making process by leveraging technical tools and proven processes. Connect enables multistage, community-driven screening (Expert Sift™) and connections. Cisco’s support has enabled Astia to scale its impact from working with dozens of entrepreneurs each year, to serving hundreds of companies each year. 

In 2023, Astia reviewed 1,033 companies, including those led by 100 Black women and 46 Latina CEOs. This represents more than $2.2B in investment opportunities. The current Astia Fund portfolio companies represent:

Employees: 54% women, 36% people of color
Leadership: 70% women, 30% people of color
Board: 61% women, 39% people of color
Solutions addressing 14 of the 17 UN Sustainable Development Goals

Successful outcomes of some of these companies include: 

Tanya Van Court, Founder & CEO, Goalsetter (in orange blouse) participating in a panel discussion

Candesant: in 2023 launched Brella SweatControl Patch, FDA cleared, for the treatment of excessive underarm sweat, forging a new path forward for aesthetic clinicians and the patients they treat. Brella received the 2023 Allure Magazine Best of Beauty Breakthrough Award

Goalsetter: Nationally recognized for its real-world approach to family-focused financial education, Goalsetter is a goal-based savings and smart spending platform that provides families with both engaging educational media and the foundational tools for building wealth and was chosen by Apple as one of the top 24 apps for 2024 in their exclusive feature, “Our Favorites: 24 Apps for 2024.” with Tanya Van Court being honored by in American Banker’s Most Influential Women in Fintech  
Mae Health: a digital health solution on a mission to improve the health and quality of life for underserved mothers, babies, and those who love them, selected as a finalist for the Massachusetts eHealth Institute’s Women’s Health Challenge and spotlighted in the 2024 Digital Health New York 100 

Interested in helping with Astia’s effort to level the investment playing field? Join in two meaningful ways: 

Become an Astia Advisor: an international community of industry experts, investors and serial entrepreneurs who are dedicated to seeing more women succeed in high-growth entrepreneurship.
Invest in one of the Astia Funds: Astia invests through a family of funds which enable investors to assert their values through investments. 

Kiva 

“Since our founding, Kiva has been committed to addressing the finance gaps that exist for underserved communities worldwide and this work has extended into the U.S., where countless entrepreneurs lack access to the financing they need to start or grow their businesses. We are thrilled to partner with Cisco in supporting Black and African American entrepreneurs through 0% interest loans, leading to more thriving businesses and communities across the country. We can’t thank Cisco enough for their transformational support of this critical work.”
– Brit Heiring, Director of Communications, Kiva 

Kiva is an international nonprofit founded in 2005 with a mission to expand financial access to help underserved communities thrive – providing equitable access to financial products and services to traditionally excluded populations. Black, Indigenous, and People of Color-owned businesses are three times more likely to be turned away by banks than non-minority-owned businesses, (NerdWallet). Kiva envisions a financially inclusive world where all people hold the power to improve their lives – focusing on four key areas of support: women, refugees, systemically marginalized entrepreneurs in the U.S., and people impacted by climate change. 

Kiva U.S. borrower and small business owner, Shawn

Cisco’s funding and strategic guidance have provided support for a variety of Kiva initiatives, investing in early-stage ideas and experimentation, and helping Kiva to successfully replicate and scale those initiatives globally. This includes initiatives to design and test innovative loan products in new markets and sectors, and the adaptation of Kiva’s global model for the U.S. market.  Cisco has also donated our technology to enable Kiva to scale their reach in a secure, efficient, and effective manner. 

In 2021, Cisco provided support to help Kiva accelerate lending and capacity building to aspiring and existing underserved small business owners in the U.S. and expand their Hubs model to nearly a dozen new cities. That work has continued to further increase support to black entrepreneurs in the U.S. via Cisco’s Social Justice grant-making program.  

Today, Kiva U.S. operates in all 50 states, with 40+ Hub partners and 100+ trustee partners. In 2023, Kiva reached 10,000 borrowers, a 49% increase since 2020. And, of the $69M in 0% interest loans funded over the course of the program, 72% has supported Black, Indigenous, and People of Color entrepreneurs and 36% has supported Black entrepreneurs, like Kiki

Kiva U.S. borrower and small business owner, Renee

To better understand and measure the impact on these borrowers’ lives, Kiva partnered with 60 Decibels in 2022 to interview both Kiva borrowers and non-borrowers. The results speak for themselves: 

Without a Kiva loan, 1 in 4 borrowers would’ve had to close their business 
3 in 4 borrowers wouldn’t have been able to find a good alternative for financing 
73% of Kiva US borrowers saw their business outlook improve 

Now, looking ahead, Kiva is committed to supporting an additional 7,500 systemically marginalized people in the U.S. by 2028. 

Cisco is proud to continue to support Kiva in reaching Black, Indigenous, and People of Color communities in the U.S. with financial access. See how you can get involved, too: 

Read more about Kiva’s impact outcomes for U.S. borrowers
Learn more about Kiva’s commitment to supporting systemically marginalized communities in the U.S. 
Make a loan to support a Black, Indigenous, and/or Person of Color entrepreneur in achieving their business goals.  

Share

"]]  This Social Impact Partner series blog features Cisco’s partnership with Astia and Kiva, in honor of the incredible work these organizations are doing to advance investment opportunities to Black, Indigenous, and People of Color-owned businesses in the United States and globally.  Read More Cisco Blogs 

By |2024-02-29T19:52:39+00:00February 29, 2024|Cisco: Learning|0 Comments

Wireless and the CiscoLive Network Operations Center Jason Davis on February 28, 2024 at 7:09 pm

It is a privilege to serve in the CiscoLive NOC. Our team of 60 people worked hard to pre-stage, implement, and monitor the event held earlier this month at the RAI Amsterdam.

The RAI Amsterdam as… Read more on Cisco Blogs

​[[{"value":"

It is a privilege to serve in the CiscoLive NOC. Our team of 60 people worked hard to pre-stage, implement, and monitor the event held earlier this month at the RAI Amsterdam.

The RAI Amsterdam as seen from the south at the nhow hotel

As you can imagine it takes quite a bit of planning and effort to transform an empty conference venue into the showcase we intend for customers, partners, press and employees. The wireless involved setting up a pair of Catalyst 9800-80 wireless LAN controllers to serve the main conference of 506 Cisco Catalyst 9120, 9130, 9124 and 9166I series APs. A second pair of Catalyst 9800-80 wireless LAN controllers served the Keynote area of 92 Cisco Catalyst 9104 series APs. Finally, a third pair of Catalyst 9800-40 wireless LAN controllers served the Meeting Village and Breakout areas of 138 Cisco Catalyst 9166I/D1 (Wi-Fi 6E) series APs. The NOC team took over the management of the RAI Amsterdam’s existing APs from their WLCs to our event WLCs. Some fill-in AP installs were done to augment coverage and for the keynote area.

Back of house NOC work area with wireless antennas to be deployed

             

Progressive build-out of the CiscoLive World of Solutions in RAI Amsterdam Hall 1

We heavily rely on monitoring and management solutions like Catalyst Center, Umbrella, and ThousandEyes, to name a few. In my regular role at Cisco as part of the DevNet team we evangelize network programmability, automation, and the use of APIs. So, I tend to focus on adding additional value in the NOC through extracting the embedded telemetry and instrumentation in our products through using open source and ‘made to spec’ programs.

A typical dashboard used by the NOC may be created by a Python script extracting NETCONF/YANG, SNMP MIB or CLI ‘show command’ data from a device, then normalizing the information for injection to InfluxDB, then rendering with Grafana.

The NOC demo area in RAI Amsterdam Hall 7

A ‘built to spec’ dashboard showing an HA pair of 9800 WLCs and their operational states

Total wireless clients by controller cluster and IEEE standard

Heatmap showing wireless client counts, transmit/receive utilization, and channel utilization, per AP

Our newest dashboard, created this year for CiscoLive Amsterdam, was a Sankey diagram depicting the wireless client count splits across SSIDs, WPA and wireless protocol capability.

Sankey diagram identifying splits of wireless clients across SSID/WPA and wireless capability

This dashboard helped us to understand if some clients could have a better wireless experience if they used a more optimal SSID/WPA selection. What we could see are some clients defaulted to or picked the ‘CiscoLive’ SSID serving WPA2, the second generation Wi-Fi Protected Access wireless security protocol.  However, 9% of these were also Wi-Fi 6E (6 GHz) capable.  We know the Wi-Fi Alliance mandated support for WPA3 security for Wi-Fi 6, so all 802.11ax radios must support WPA3. Those clients could have received a better experience connected to the ‘CiscoLive-WPA3’ SSID, as mentioned on the back of the attendee badges.  Sometimes problems are solved technologically – other times, socially.

We are also interested in the adoption rates and ratios of clients to IEEE standard. A few dashboards helps us specifically identify those clients by SSID and others without the SSID categorization.

Wireless client distribution by SSID and wireless standard

Dashboard showing ratios of wireless clients by wireless standard

The event saw the maximum number of wireless clients, 16024, on the second day, February 7 at 12:06 CET.  In that 20.17% of the clients were using Wi-Fi5 (802.11ac), and 75.97% were Wi-Fi6 (802.11ax 5GHz).  Comparing this to last summer’s CiscoLive US in Las Vegas, we grew from 66.8% Wi-Fi6.  Finally, compared to last year’s CiscoLive Europe in Amsterdam 2023, we grew from 62% Wi-Fi6.  Considering the years spent on Wi-Fi 5 (802.11ac), it’s nice we’re seeing migration to newer capabilities.

Moving forward we will build even more reports and dashboards to gain other insights about adoption and how we can make technology even more seamless.

Here’s a YouTube video with more background

Share

"}]]  See how we transformed an empty conference venue into the showcase we intend, while also extracting the embedded telemetry and instrumentation in our products through using open source and ‘made to spec’ programs.  Read More Cisco Blogs 

By |2024-02-29T19:52:39+00:00February 29, 2024|Cisco: Learning|0 Comments

Cisco Accelerates Convergence of IT and Operations Technologies Jason W. Gallo on February 29, 2024 at 2:00 pm

Internet of Things (IoT) remains one of the stronger markets in which customers are considering investing. In fact, according to IoT Analytics, a global research firm, the IoT market will grow at a… Read more on Cisco Blogs

​[[{"value":"

Internet of Things (IoT) remains one of the stronger markets in which customers are considering investing. In fact, according to IoT Analytics, a global research firm, the IoT market will grow at a CAGR of 19.4% from 2022 until 2027. Across industries and geographies, organizations are investing to connect IT to their businesses’ critical Operational Technology (OT) areas.

In industries such as manufacturing, utilities, smart buildings and beyond, IT/OT convergence remains a top priority as they merge business processes, insights and controls into a single environment. IT and OT teams play a key role in their organization’s transformation – improving internal processes, business decision making, productivity and competitiveness.

Cisco’s IoT portfolio uniquely positions partners to capture this IT/OT convergence. We’ve seen where the industry is headed and are providing an innovative Operational Technology Supplier route to market (OT Supplier RTM), driving the sale of Cisco’s best-in-class IoT portfolio. Furthermore, this OT Supplier RTM expands Partners’ opportunity to create services, particularly new managed service offers for OT customers’ use cases. Thus, for the Cisco portfolio, the OT Supplier RTM introduces new choices for OT customers – both who they want to purchase from and new services they want to consume.

Bridging the Gap Between IT/OT Convergence and Suppliers

The OT Supplier RTM model is a great example of how Cisco and our partners are working together in new ways to achieve the outcomes that customers need. It enables OT Suppliers to leverage Cisco’s Industrial IoT and Meraki IoT portfolios, guidance, technical expertise, platforms, and lifecycle services. It includes strategic relationships with OT Suppliers that work with integrators throughout the OT/IT space and predictable discounting for IoT products and stocking.

Coupling Cisco’s comprehensive IoT portfolio with innovative go-to-market planning, the OT Supplier RTM aligns companies that want to find more innovative and strategic solutions for optimizing their operational business processes.

Customers report (in the IDC Cisco Partner Value: The End-Customer Viewpoint Dec. 2023 by Paul Edwards) that vendor specializations are among the top three criteria for selecting a partner. Cisco’s Solution Specializations offer partners more opportunities to showcase their capabilities and differentiate themselves in the market. Cisco offers several Solution Specializations that match customer needs, including our Industrial IoT Specialization and Commercial IoT Specialization launched at the beginning of February 2024.

Driving GTM Innovation with an Expanded Partner Ecosystem

This initiative develops incremental business opportunities with the OT Suppliers partner ecosystem. The first OT Suppliers to be part of the OT Supplier RTM are Wesco, Industrial Networking Solutions, Madison Technologies and Routeco, who support a significant channel of Industrial Integrators. These OT Suppliers will work alongside Cisco’s industry leading global distributors.

Cisco and our partners are greater together – and the initial feedback from our OT Supplier ecosystem shows that together, we are laser focused on delighting our customers:

“Wesco is pleased to further our stack of IT/OT solutions by incorporating Cisco OT-centric products, including industrial switching, routing, CURWB, and Meraki IoT, to support our customers globally. Cisco’s new partner Route-to-Market (RTM) model makes Cisco’s best-in-class IoT portfolio more accessible to our integrator partners, helping us together drive innovation and meet the demand for converged IT/OT solutions.”– Tara Dunning, VP Sales, Global Security & Network Infrastructure, Wesco

“The Cisco OT Supplier RTM model has been a useful tool for unlocking more opportunities in this space. Cisco has taken a big step toward meeting the Industrial OT market in a way that makes sense for these types of customers and ecosystem partners.”– Richard Rogers, President, Industrial Networking Solutions

“This unique partnership with Cisco enables us to offer our customers advanced IIoT and Meraki IoT solutions, expert OT support and increased value for our systems integrator and end user [channel]. It’s fundamental to enabling Industry 4.0 across operational environments we target. This partnership is about so much more than product access; it’s about shaping the future of industrial connectivity, fostering IT/OT convergence, and fast-tracking digital transitions in critical operational environments. Our commitment is to create lasting value and resilient technology solutions in these environments, ensuring our clients and our [Industrial Integrators] stay at the forefront of innovation, and the OT Supplier RTM model enables that.”– Paul Calabro, CEO, Madison Technologies

“Industrial customers continue to rapidly digitize their environments with the help of seasoned OT industry partners. The OT Supplier initiative will allow us to broaden our scope and provide customers with the advanced networking and security technology they need to accelerate the digitization of the industrial world. Together, Cisco and our partners will pave the way for new and exciting opportunities.”– Stefan Leitl, VP Global IIoT Sales, Cisco

Within Cisco’s expanded ecosystem of partners are Industrial Integrators focused on digitization, physical security, lighting, electrical, building control systems, solar power, and electrical vehicle charging. Over time, we believe the OT Supplier RTM model will also open up more opportunities that Cisco and our partners can capture together as new buying centers seek to access Cisco’s Industrial IoT networking, and Meraki Smart Cameras & Sensors.

The convergence of IT and OT allows Cisco partners to access new budgets and build relationships with new buyers. In the long term, despite market fluctuations, the IT/OT convergence has shown itself to be a resilient business investment area, as the wave of digitization is rapidly expanding beyond businesses’ carpeted spaces.

For more information, visit Cisco OT Supplier Route-to-Market
or contact us at ask-ots@cisco.com for details

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with #CiscoPartners on social!

Cisco Partners Facebook  |  @CiscoPartners X/Twitter  |  Cisco Partners LinkedIn

Share

"}]]  The convergence of IT and OT is an opportunity for Cisco partners to capture new budgets and build relationships with new buyers. Cisco's IoT portfolio uniquely positions our partners to capture this IT/OT convergence.  Read More Cisco Blogs 

By |2024-02-29T19:52:38+00:00February 29, 2024|Cisco: Learning|0 Comments

Promoting Sustainable Livelihoods in South America and the Amazon Alex Wilkins on February 29, 2024 at 2:00 pm

This is the second blog in our three-part series about Cisco Foundation climate grantees working in the Amazon and South America region. You can read our first blog, about how Cisco Foundation… Read more on Cisco Blogs

​[[{"value":"

This is the second blog in our three-part series about Cisco Foundation climate grantees working in the Amazon and South America region. You can read our first blog, about how Cisco Foundation Grantees prioritize Indigenous leadership to protect the Amazon Basin. This series will introduce you to eight Cisco Foundation Climate Impact & Regeneration grantees working to support preservation and protection of the Amazon basin through three main avenues, all of which are deeply entangled and in tandem serve to promote enduring environmental protection and preservation: Prioritizing Indigenous Sovereignty, Promoting Sustainable Livelihood Opportunities, and Scaling Innovative Financing Opportunities.

This blog was constructed in partnership with my colleagues at Kara Solar: Nantu Canelos and Oliver Utne; Andes Amazon Conservancy, Rebecca Allen; Terraso, Derek Caelin; and Risaralda Model Forest, John Rodríguez.

The Amazon rainforest is a biodiverse tropical ecosystem that spans nine South American countries, is home to over 500 Indigenous groups, and contains 10% of the world’s biodiversity. Not only does the Amazon bioregion positively impact broader South America, but it supports life around the world by stabilizing global temperatures and rainfall patterns. Yet, the region is facing enormous pressure from industrial practices such as gold mining, oil drilling, and deforestation for timber and agricultural land. It is clear that urgent action is needed to protect the future of the Amazon and its surrounding ecoregions, but to navigate highly complex sociocultural and geopolitical dynamics can be a daunting task.

Fortunately, a pathway through such complexity known as ‘sustainable livelihood opportunities’ or ‘sustainable development’ is rising to the forefront of modern conservation discourse. The term emerged from the United Nations (UN) Conference on Environment and Development summit in Rio de Janeiro in 1992, often known as the “Earth Summit.” Not only did this summit establish the UN Framework Convention on Climate Change, along with several other high-impact commissions, but it prominently highlighted how environmental, social, and economic factors are deeply entangled, and can be pursued in harmony with one another on a global scale.

According to the WWF (formerly World Wildlife Fund for Nature), many of the most important strategies for protecting terrestrial ecosystems in the Amazon combine traditional conservation methods with sustainable landscape management practices. A multitude of opportunities and methods are rising to the forefront of modern discourse around South American ecosystem protection through practices like agroforestry and sustainable fishing. The key for these opportunities is to identify alternatives to destructive practices like intensive logging, and co-create participatory management with local communities.

What does this look like in practice? It’s my pleasure to introduce you to three Cisco Foundation grantees that are working to provide sustainable economic empowerment to local, often Indigenous, communities throughout the Amazon and its connected, neighboring ecosystems across South America.

Transportation sovereignty empowered by Kara Solar

A group of Wajana-Aparaí women in a solar energy workshop in Aldeia Bona, Parú d’Este, in Tumucumaque indigenous land, Brazil. Aldeia Bona is the most populated community in the region and is home to a solar boat and community solar center since 2023. Credits: Fundación Kara Solar

Kara Solar formed in 2018 from an alliance between the Achuar people in Ecuador, and a multi-disciplinary engineering, design, and development team, with a clear vision to empower Indigenous communities in the Amazon with solar energy.

According to Kara Solar’s Executive Director, Nantu Canelos, the “lack of access to electricity in Indigenous communities limits our ability to access technology, improve the health and well-being of our people, and develop business that economically support our communities.” Kara Solar seeks to alleviate these pressures through three interconnected approaches: solar river transport, training Indigenous electrical technicians, and localized community energy grids.

This new model of transportation provides communities with “travel and energy sovereignty,” or the ability for communities to implement and manage resilient transportation and energy systems in their own territories, on their own terms. Nantu illustrates the importance and elegance of travel sovereignty: “it improves the quality of life of Indigenous communities and helps to conserve the environment.”

Kara Solar technicians training to install Starlink internet systems, part of a new initiative to create a technical services cooperative and generate sustainable income providing commercial services. Credits: Fundación Kara Solar

To bring this to life, Kara Solar provides training programs, localized supply chains, innovative financing mechanisms, and technical implementation. They now support a fleet of 9 boats, and 3 community solar energy grids which currently serve over 3000 people. A critical part of this model is training Indigenous technicians, which ensures the capacity to address mechanical breakdowns is local and therefore more readily available, and it provides a source of income to those who have newly developed technical skills.

“Kara” is an Achuar word for a vision that becomes real. Kara Solar’s vision is clear, ambitious, and in alignment with Cisco’s priority to accelerate the transition to clean energy while supporting resiliency and capacity.

According to Nantu, “Our vision for the future is one in which Indigenous communities move independently and autonomously with solar powered river transportation and use solar energy to illuminate homes and businesses, access technology and information, improve the health and well-being of community members, protect territories, and promote sustainable development. We are working to protect Indigenous culture and ensure that future generations are able to use technology to create new solutions that benefit the environment and humanity. We seek the protection of forests for the well-being of humanity.”

Andes Amazon Conservancy’s Edible Forest Initiative supports food sovereignty

Nursery in the Shuar community of Tunants, Ecuador where 20,000 trees are growing

Andes Amazon Conservancy (AAC), and their new sister nonprofit organization Biocorredores Amazónicos, seek to maintain critical connectivity, or “eco-cultural corridors” among the landscapes between the Andes Mountains and the Amazon basin by centering Indigenous-led conservation in Ecuador and innovative land-use planning. AAC currently engages with 75 Indigenous communities.

One of AAC’s flagship programs, the Edible Forest Initiative, contributes to AAC’s overall goal of creating a 175-mile-long corridor and protecting 6 million acres of land.

According to Executive Director Rebecca Allen, “Communities participating in the Edible Forest Initiative are planting 20,000 culturally relevant native fruit and nut trees over 300 acres of carefully chosen land.”

Shuar family of Kunkup tends trees in the Nursery

When these trees reach maturity, in an anticipated 5-years’ time, they will not only connect vast swaths of rainforest, but cash crops will also provide an essential foundation for local economies, as well as food security. This is what AAC refers to as “food sovereignty”: a reduced reliance on extractive industries that enables local, sustainable, and self-defined food systems.

The Edible Forest Initiative program is an example of how economic empowerment and food sovereignty are not diametrically opposed to ecosystem and climate resilience. Not only do trees sequester carbon and retain water, but the nurseries are strategically situated in areas that need immediate restoration and are critical for safeguarding biodiversity.

Tree roots along deforested streams and riverbanks provide soil stability, preventing erosion and runoff, and can help address those challenges. According to Rebecca, “With the guidance of conservation land-use planning, Indigenous communities make the deliberate choice to prohibit human development in these riparian areas, thus contributing to the preservation of [ecosystem] quality for both present and future generations.”

Sustainable Landscape Management in Bosque Modelo Risaralda supported by Terraso

Workshop for the city of Mistrató, Bosque Modelo Risaralda using the Restoration framework // Taller municipio de Mistrató, Bosque Modelo Risaralda en marco del proyecto Restauracción II

*Please note: statements were provided in Spanish, and John Rodriguez’ original quotes can be found at the bottom of the article.

Terraso, a social enterprise from Tech Matters, seeks to put agency back in the hands of people who play a significant role in shaping their local landscapes, such as pastoralists, smallholder farmers or Indigenous people. Though these local landscape leaders can play a crucial role in managing and preserving their land, they often lack the technical instruments to bring together key collaborators, build a shared understanding, or communicate to potential donors. Terraso provides tools for participating landscapes to map and manager their territories, while providing a platform to visually tell stories about their work.

I recently had the opportunity to hear some of these stories directly from one of Terraso’s partners, the Bosque Modelo Risaralda Landscape Partnership (BMR), in Colombia, who have spent the last 25 years leading a participatory landscape management model. Covering an area of 359,000 hectares, the alliance in Risaralda unifies research universities, community organizations, governmental institutions, and donors to promote biodiversity and strengthen livelihoods through sustainable production systems. It is this collaborative effort that, according to Bosque Modelo Risaralda Manager, John Rodriguez, “will provide our socio-ecosystems with resilience in the face of climate change.”1 John affirms their belief “that it is not possible to conserve biodiversity and ecosystem services without simultaneously promoting sustainable livelihoods.”2

“Restoration Watchers,” a group of local boys and girls from Bosque Modelo Risaralda // “Vigías de la restauración”, grupos de niños y niñas del Bosque Modelo Risaralda

One specific example within BMR is the Cuchilla de San Juan coffee growers’ association (story map in Spanish), which promotes maintenance of coffee plantations through environmentally sustainable practices, such as utilizing shade trees alongside coffee bushes. A small group of local producers have restored their plantations with native species, minimized use of agrochemicals, reduced water usage, and included young people in business planning. According to John, these types of “innovations in agricultural sectors can provide flexible finance systems furthering sustainable practices and healthy lives.”3

BMR is one of many examples of integrated landscape management practices within South America that are beginning to use Terraso’s services and platform to share their successful practices with other landscape leaders and attract potential donors. Terraso and the Cisco Foundation both believe that shifting high-quality tools, information, and investments to local leaders to increase their own capacity will lead to better environmental and economic outcomes for us all.

Rather than continuing an aged paradigm of “hands-off” conservation, these three Cisco Foundation partners working in and around the Amazon are prioritizing the integration of economic livelihoods and environmental preservation with community-designed, locally driven, and culturally appropriate programs.

Our partners showcase how stable environments, inclusive societies, and thriving economies can work together to promote resiliency in our changing climate.

Footnotes:

1 –  “En el Bosque Modelo Risaralda creemos que este trabajo mancomunado por las sostenibilidad es importante porque es la manera de preparar nuestros socioecosistemas para ser resilientes a los cambios, especialmente el cambio climático y el cambio global.”

2 – “Creemos que no es posible conservar la biodiversidad y los servicios ecosistémicos si al mismo tiempo no garantizamos modos de vida sostenibles”

3 – “La innovación en los sectores productivos agrícolas, la preparación social para el cambio climático, las innovaciones financieras para modos de vida sostenibles”

Share

"}]]  Meet Cisco Foundation grantees working to secure both economic opportunity and ecosystem preservation in and around the Amazon.  Read More Cisco Blogs 

By |2024-02-29T19:52:38+00:00February 29, 2024|Cisco: Learning|0 Comments
Go to Top