Cisco Systems, Inc. (CSCO) Earnings Call Transcript & Summary

July 11, 2023

NASDAQ US Information Technology Communications Equipment special 47 min

Earnings Call Speaker Segments

Jon Oltsik

attendee
#1

Hello, and welcome to our webinar. I'm Jon Oltsik, distinguished analyst and fellow from ESG Price Strategy Group. And I'm joined by Briana Farro, who is the Director of XDR Product Management at Cisco. Welcome, Briana.

Briana Farro

executive
#2

Hey Jon, it's a pleasure to be here with you today.

Jon Oltsik

attendee
#3

It's always good to see you, too. So, we're going to talk about how a risk-based XDR approach improves threat detection and response. And Briana, coming out of RSA, that was topical then, still topical today.

Briana Farro

executive
#4

That's right, Jon. Very top of mind, especially for us, but in the industry in general right now.

Jon Oltsik

attendee
#5

And we'll talk about why that is true. So let's start by looking at the state of security operations. This is research we did in -- over about 6 months ago. As you can see, roughly in the neighborhood of 300 respondents to our survey, they were all security people or IT people with responsibilities for security. So this puts the state of security operations. 52% of those that we surveyed, Briana said that security operations are more difficult today than they were 2 years ago. And what we -- what you see on the slide in terms of the data is that percentage, that 52%, we asked them, "Well, why is this the case?" And they said, "The threat landscape is evolving and changing rapidly. The attack surface is continually changing and evolving. And the volume and complexity of security alerts have increased." Briana, we hear this all the time. It's making our lives and security professionals more miserable. Is this consistent with what you see?

Briana Farro

executive
#6

It's absolutely consistent with what we see, Jon. And most importantly, I think that top one, the threat landscape evolving and changing rapidly, what we're starting to see is that there are more and more complex threats out there. More adversaries understand how to dwell within an organization and how to slowly creep throughout the environment. So while there are certain attacks that will come out in our organization hard and fast with a specific goal, there's more time to do reconnaissance within organizations and really try to understand what value there could be to attacking that organization. When you think about really, really complex threats like all of those documented campaigns that are out there and things like Turla, which is the current MITRE Round 5 Engenuity testing pod. When we think about that, those used to be the types of attacks that would be very specifically targeted at nation states or very specific -- of victims. Nowadays, we don't necessarily see that being the case. We have those larger complex threats happening in a multifactor situation, but occurring for the regular average everyday business. And folks like you and I, that's really important, because as much as we're here to try to consult and to guide and to provide solutions for these organizations, [indiscernible] as well. So we need to think about it from both aspects and how we can help these works.

Jon Oltsik

attendee
#7

Yes. Well said. I mean, when we talk about evolving and changing, remember that the threat actors are sophisticated, they're well organized, they're using nation state-type tools. So it's -- the battlefield is tilted.

Briana Farro

executive
#8

The battlefield is tilted, and even that attack surface continuously changing or the volume of the events increasing, it's because that attack surface is changing, right, Jon? I mean, I'm sure you all are speaking to customers all the time about how they are going to have visibility or secure a new vector that's bringing -- coming up in their environment, especially with the massive shift to virtual and remote working that's happening. And I think you and I would probably both agree that some of these things aren't necessarily new. Even some of the techniques that our adversaries are using are not new. They're just coming up with fun new ways -- fun for them -- to put these techniques together to do that and [indiscernible] the space.

Jon Oltsik

attendee
#9

Yes, I totally agree. It's that part of the tilted battlefield. And here's us. This is how we're defending ourselves. So some people have seen some research that says the average enterprise has over 75 tools. This is specifically for security operations. But the largest percentage, nearly half, have 26 to 50 different tools. That's a lot of tools.

Briana Farro

executive
#10

Yes. That's a lot of tools. And an organization needs to be able to rely on the ability for these tools to be brought together in a meaningful way. So on your last projection, we just saw that there's more and more events. Well, there's partly more events because there are more tools. When you add different types of techniques and you add different types of vectors, you're going to have more options for visibility and for detection and protection and remediation at those different layers. But at the same time, those things need to come together meaningfully. And so from our perspective, with these traditional tools coming into play, there's better visibility by far. No question from our perspective, Jon, with the more information that you have. And I'd love to hear your thoughts on that for our audience here today as well. Do you agree that the more visibility you have, the better you're going to be able to understand what's happening in your environment?

Jon Oltsik

attendee
#11

Absolutely. We are seeing organizations collect, process and analyze more security data. Now you have to do that in a well organized, properly staffed way, but absolutely, any blind spot is an opportunity for a threat actor to circumvent your controls.

Briana Farro

executive
#12

And we think also, to your point about being able to do that in an organized way, we feel that solutions providers, whether that's through a services model or a build application model, need to be thinking through this meaningful way of using this visibility. As was mentioned on your prior statistics that everybody is bringing a lot of data to the table, that's great, but it should be the burden of the solutions provider and to take this information, analyze it and organize it for you and put it together in a meaningful way that allows you to act faster. Because these tools, while there's security on these particular statistics, we're going to see more and more, I think, non-security events coming in to inform security events. And in order to bring all that together with meaningful context, we should expect that a solution does that for an analyst. The analyst no longer has time to go through that, especially when the longer it takes me to figure something else, the more impact it might have in my environment.

Jon Oltsik

attendee
#13

Yes, very true. So as a result of all of these tools and all of the [indiscernible] and all of these alerts and all the things we just talked about, Briana, 2/3 of enterprise organizations are actively consolidating the number of security tools in use for lots of reasons. So of those organizations that are consolidating, we asked them,"Why are you doing so?" Well, they want to optimize costs. Cost is always important, especially with the economic uncertainty we face. The need to speed investigations and response, that really speaks to what you just talked about is, if all of that data is around different tools, if I have different interfaces, if I need different skill sets, that adds time. And what we haven't talked about yet and I have to talk about it is, we're in the middle of a global cybersecurity skill shortage that isn't getting better. So every time we add another tool, we have to ask ourselves, "Can we staff this appropriately?" Do we have someone who can train on this? How does that tool interact with other tools and other processes? So consolidation is sort of a way to get around that or to address those kinds of concerns. 32%, the need to improve data correlation. Again, if data is over here and data is over here, unless we have some way to bring that together, we are using human analysis and human consolidation. And then about 1/3 at our current security operations technology stack is overly complicated. There's a surprise, Briana, overly complicated, creating undesirable management overhead. So too many tools, we're consolidating for these reasons. What do you think?

Briana Farro

executive
#14

I think we could spend hours on these statistics, Jon. And maybe we will take a little bit more time to go through this than some of the other talking points that I know we're going to probably discuss today. But I think that the optimization of a process for security operations teams and practitioners is absolutely a requirement. How that optimization occurs is probably a consolidation of all of these things, and cost is going to come in so highly because most organizations do not have their security budget as their top line item. We just talked about how we're customers of these organizations. If I'm a car manufacturer or I'm a health care organization or I'm a government entity, I have a mission statement that is to protect my environment for what I need to deliver to you as a consumer or as a civilian, as a service. But protecting it and the budget to protect that is not necessarily my primary budgetary option or requirement. So the cost optimization has to be there. But by default, that cost optimization may not always equate to a consolidation of tools for a lot of organizations. And you mentioned the [ pirates ] because not every tool is going to do all things that an organization needs it to do, especially from specific vectors, endpoint, network, cloud, we could continue going through that path. You may need different tools to connect and protect and defend your environment in different ways. I also think that you may or may not be able to invest in all of those tools. So that's a secondary piece. And you mentioned the staffing. The staffing is a big issue. And I know for people joining us today, it may sound like that's a recurring statement. Maybe you're tired of hearing it. When I was a practitioner, I was tired of hearing things like mean time to value and things like optimization and security shortages for resources as well, but it's a reality. And as Jon just mentioned, like, it's not going anywhere, right, Jon? That is just getting worse and worse and worse and worse. And especially as we see certain people retire from the workforce, you're not only going to lose potential practitioners, you're going to lose seasoned and experienced practitioners who were doing these types of investigations and forensic analysis prior to all these tools coming into place. So I think that cost optimization is huge. But what we need to be looking at in the industry is how the speed of investigation and responding and that data correlation helps that optimization by default, even in a single solution set. And I really think that that's what extended detection and response brings to organizations. There's previous sets of type [indiscernible] tools out there, SIM store, others going back. Jon and I -- you and I have been in the industry for a long time, many years trying to solve the problem. But the correlation piece is what most of those I don't think have hit on so far. And what do you think when you're speaking to all the great customers you speak with, Jon? What are they expecting in that correlation when they talk about correlation?

Jon Oltsik

attendee
#15

Correlation is sort of a 2 -- double-edged sword in that if you have a big staff who really understands its tool and really understands the data that's coming in, how that data relates to data points relate to each other, you can build good correlation rules. But that's the exception, not the rule. And so for the rest of us, for the 90% of the market or so, correlation rules are kind of very simplistic and they don't get to the detection capabilities that we really need.

Briana Farro

executive
#16

I agree with you. And this is where we need to be building in and taking advantage of those things like automated [indiscernible] back-end. So AI is a big topic right now, more so for things like generative AI and interaction-style models. But AI and machine learning concepts for modeling analytics into event correlation is not new. And things like large language learning models and other types of modeling for AI should absolutely be built into solution sets to improve and create that correlation between different types of telemetry sources. I also think with the cost optimization piece, if it makes sense for an organization to consolidate on maybe a single brand of solutions, it's important for vendors to provide native telemetry sources and native solution tools that will help for all of those different vectors that we just talked about. But where possible or where for a customer, it does not make sense to consolidate and they've already put an investment in time and that knowledge learning that you spoke about to understand the solutions that they're using, we as an industry need to meet customers where they are. We need to be able to take a non-native to our portfolio telemetry solutions, and we should be able to deliver consistent detection and response to outcomes regardless of whether or not we're working with our known telemetry or not. And that's going to increase that time to value. When you talk about onboarding of a new solution and the cost or time of staff being able to leverage that, that will help that onboarding value immediately.

Jon Oltsik

attendee
#17

Yes. And I hold that thought, because we're absolutely going to get to the XDR portion. So really quickly, here's what we see in terms of security operation spending. So 88% of organizations will increase their security operations spending over the next 12 to 18 months. Now this research was conducted with full visibility into the economic uncertainty that we're experiencing. And still, people are increasing their security operation spending. So really quickly, Briana, what that tells me is what we're doing isn't working. Or at least it's not -- it's inadequate. And we need to spend more because of the things we talked about: the attack surface; the threats; the number of alerts. We have to get our arms around that, and we're willing to spend accordingly.

Briana Farro

executive
#18

I think that makes sense, Jon. And it's unfortunate that, that is the situation. But at the same time, if we go back to the first set of statistics of the landscape constantly evolving and the landscape is constantly changing, we need to evolve those movements and those -- that evolution may require an increased spend by organizations to attain what they need to defend against -- defend their environment against attackers.

Jon Oltsik

attendee
#19

Yes. And personally, coming out of RSA, I'm convinced we're at a tipping point with security operations. And it is because of the things we talked about. So it's not something we can patch. We can't just add another tool, hire another person. We really need to think strategically about this. And let's talk about how we do that moving forward. So what about XDR, Briana? So first of all, we want to know what the heck XDR is. And so 61% of those that we surveyed said they're very familiar with XDR, okay. And that's up, by the way, from 29% a couple of years ago. So does that mean we know what XDR is? No, it doesn't. When we asked people, well, what is XDR, 55% said it's an extension of EDR. That mindset has been pervasive in the industry. 28% say XDR's Detection and Response product suite, and XDR Detection & Response product suite from a single security vendor. And 16% say XDR is an integrated and heterogeneous security product architecture designed to interoperate and coordinate on threat prevention, detection and response. Interestingly, smaller organizations tended to say XDR is just EDR plus. Larger, complex, multinational, large organizations, like I said, were much more likely to say XDR is an integrated and heterogeneous security product architecture. So we're all over the board here, Briana, help me out. Help me out.

Briana Farro

executive
#20

I believe it is probably -- or has. I'll make a little bit of a bolder statement there. It has been all of those things, Jon. What we, I think, need to think about is what does it need to be today and moving forward? But let's break these down a little bit for a second. A lot of the XDR solutions in the market are based off of EDR solutions. They started from a solution that was EDR-based and it was a viable, if not market-leading solution in the EDR space that started to recognize that, that correlation that we were discussing of bringing information together, whether that was information from a single source to something like endpoint -- endpoint and cloud data as we move more to a hybrid working model or endpoint and network data was really, really critical. So they started to extend, all puns intended, into the extended detection and response phase. But I really believe that it can and should be all of these things. XDR is much more than just an extension of EDR. If the X is being done properly, an XDR solution should be coming to an organization with the mindset of I am here to ingest information from multiple sources, specifically across multiple telemetry sources and data points and countermeasure points. And I want to bring that information together to consistently show you a correlated event, as we spoke about earlier. The endpoint data is very foundational because there's so much information we can see on an endpoint. It goes beyond some of the other vectors of which we have limited visibility on to process detail and connections that are happening. But network data is absolutely as foundational as are many other types of sources. And when we say network data, Jon, it's a really broad term, I think. That can encompass e-mail, it could encompass DNS data, it could encompass proxy data. What you're actually putting into a box, this network is probably much broader than 1 thing, then it can be extended through those terms. But that other -- that other network telemetry is very, very foundational to putting this correlation together to truly help you understanding what's happening in your environment. And then when we think about this homogenous- or heterogeneous-type solution, a current XDR solution needs to be able to provide both. So I started to mention earlier native telemetry sources and countermeasures, as well as third-party. You mentioned it again, a smaller organization may have made a certain purchase and is looking to simply extend that purchase but may or may not realize that they're not even missing key pieces of telemetry if they don't have email security or they don't have network detection capabilities. That's a huge piece that they may not recognize. And if they have a vendor that they're working with that can provide all of those things and ingestible and analyzed by XDR, then maybe that homogenous solution is great for them. If you're a larger organization like the ones you mentioned earlier that have a huge staff that can actually go through a lot of this analysis, and they can break down all of those different events through rules or build rules to try to correlate that information together, you're absolutely working with a wide mix of tools from different vendors that may or may not have invested [indiscernible] at a point in time, but are something that, that organization is invested in. They have knowledge in, it would take a lot for them to lift and shift. So even in a model where that organization may want to move off of some of those tools, you have to be able to ingest telemetry from those tool sets if for no other reason, then support their migration path. But certainly, because they may want to continue to use those tools, they see value in them, they purchased them in the first place, and they want to make that -- they want to continue with that investment.

Jon Oltsik

attendee
#21

So XDR is kind of all things to all people.

Briana Farro

executive
#22

I think that's why you've seen this go from 29% to 61%. There's a lot of definitions out there. At the end of the day, though, I'd love to hear, I think, more so what your definition of XDR lies in. For us, it is consistent detection and response across multiple vectors and telemetry sources where detection without response is insufficient and response without a clear understanding of the detection is impossible.

Jon Oltsik

attendee
#23

Well, then you're going to like our definition.

Briana Farro

executive
#24

Let's hear it, Jon.

Jon Oltsik

attendee
#25

This is what ESG believes, that -- and I'll read it. XDR is an integrated suite of security products spanning hybrid IT architectures, kind of on-prem and cloud, designed to inter-operate and coordinate on threat prevention, detection and response. XDR unifies control points, security telemetry, analytics and operations into 1 enterprise system. Now we've been talking about SOAPA since 2016. SOAPA stands for security, operations and analytics platform architecture. XDR, to me, is SOAPA. Now what I'm learning is -- and I've learned this at this year's RSA is -- you can't be dogmatic about this definition. Sources of telemetry need to be heterogeneous, as we've talked about. But it's really gathering the right data and putting together the right analytics and then automating the responses. Different organizations will do that differently, but Cisco has got a unique approach because of its footprint, Briana. So tell us about that.

Briana Farro

executive
#26

Absolutely, Jon. I think, first off, salute on the definition and on your statement of the industry needing to kind of solidify on a common version of this definition. Different companies and different firms may have slightly different versions of how they would spell this out or different interpretations. But the fact that the response can no longer be a very light version of this lingering R and XDR when detection is really only what's happening, that is not sufficient in 2023 and beyond. The fact that detection is no longer just bringing a bunch of events together in an aggregated way and presenting them to the analysts for the analysts to figure it out, that is insufficient. That is not correlation and detection across multiple heterogeneous sources. So to your point, when Cisco looks at this, we are a network provider at heart at the beginning of time. And we know the network better than anybody else. So we really started to look at this by saying, well, endpoint telemetry is foundational. Network in all of those variations that I mentioned previously, e-mail, DNS, proxy, cloud-based, et cetera, is very, very important, especially when you about the hybrid IT architecture here, that's when we start to get, especially into those cloud-based or we can bring up other acronyms in the industry, but like Zero Trust and cloud edges where people need to understand how communication to their resources in a time we're stealing data or encrypting data for malicious purposes is king. We need to bring that together. So the way that Cisco is really thinking about this, Jon, is that network telemetry is key. It's really, really important to have that network traffic analysis.

Jon Oltsik

attendee
#27

Yes. And I'll support you on that because -- 2 things. One is, when I asked, when we did some research and said, "Okay, how do you know if something's wrong in your environment? How do you know you're under attack?" Between 50% and 60% said, "We look at what the network is telling us." So it's some anomalous connection. It's anomalous connection to an external website. It's lateral movement across the network. So that's point 1. Point 2 is, we've been doing this forever. So if you think about it, what did we use before we talked about XDR and SIM? We used ethereal. We used wire shark. We did full packet capture. So there's history and culture here. And so I tend to agree that while EDR does capture some network traffic, let's look at the network itself. So I totally agree with you. And -- and so it looks like our definitions are pretty consistent with each other.

Briana Farro

executive
#28

Very much so.

Jon Oltsik

attendee
#29

So Briana, we talked about network telemetry as an important source. And I totally agree with you. But can you give us an example of an attack that you may not be able to detect through other sources of telemetry where the network is really tantamount?

Briana Farro

executive
#30

Yes, absolutely, Jon. Actually, what we're showing right now is an example of a DNS tunneling attack. And with DNS tunneling attacks, what you'll see is that there's an exfiltration of data that happens over UDP as a protocol and Port 53. And those are very standard. If you were to shut those down in your environment, your environment would probably come to a halt because you couldn't process DNS traffic. So as you can see here, I might start out with something like a singular connection where I'm using that path to exfiltrate data. But over time, what we would start to see is either multiple connections or large packets on -- abnormally large packets that are an anomaly for DNS traffic coming across that protocol or port or a combination of both. And these are the types of things that you wouldn't be monitoring for per se on an endpoint-specific area. You might see things like maybe an extra DNS traffic, but you wouldn't see things like the volume of the traffic coming across that. But in a network layer, you would be analyzing that. So things like a firewall or an IDS solution or even an MDR solution would be able to provide that visibility. And that would be really critical, because you would have active data exfiltration happening in your environment. So your ability to catch this either over time or quickly if it were happening in bulk is very, very critical. And actually, it's 1 of the reasons why we are supporting not only having network telemetry into our solution, but for Cisco XDR, we've built in some network detection capabilities by default.

Jon Oltsik

attendee
#31

So we asked people, okay, given -- and we gave them this definition of XDR, and we'd say -- well, we asked them, "What would you like to see? So what would the most important outcome be in terms of security efficacy." And this is what we got. So 36% said extending and enhancing our threat detection and response capabilities across the growing attack surface. So to me, that's really looking at cloud. It's saying, "What's going on in the cloud that I can relate to a kill chain?" And sometimes that will be the start of an attack, sometimes that will be the end of an attack. But we need to understand not just on-premise resources but cloud-based resources. 1/3 of those respondents said improving the fidelity and prioritization of security alerts to make it easier to triage and respond to events. And that's the risk-based aspect. So I'm getting all of these alerts. I'm hopefully rolling them up into incidents, so I know the attack pattern. But then when I go to respond, I want to respond to attacks or to threats that really target my critical assets or assets that are particularly vulnerable, that have a direct path to my critical assets. And that's the risk-based XDR component that we talked about upfront, Briana.

Briana Farro

executive
#32

That's right, Jon. In order to really classify what's happening in the environment, the information that you're receiving from the event -- and to your point, from the endpoint, when those more seasoned analysts would say, I looked at the network, I looked at firewall logs or other sources, IDS logs to understand what was happening, there were times where they didn't have details from EDR the way that they do today. And so that traffic was very, very valuable for them. So when we look at the correlation of that information, that's going to provide me a level of data that's very, very valuable if I can take a network telemetry event and an endpoint event or multiple network telemetry events and put them together to say, "Hey, what's happening in this segment of my environment and this segment of my environment is the same, and it's happening on Jon's machine and Briana's machine." That's the first key piece. But then there's contextual analysis of, what does Jon do for us? And what information does he have access to? What does Briana do for us? And what information does she have access to? And in that context, I as a user am an asset to the organization. This is a thing that we're working on. Whether those are corporate environments or home systems that now introduce a whole new extra layer of potential vulnerabilities that could be in play with exploits that could be associated with them, access to those systems that I as a corporate environment may not be able to control, that is additional context that allows us to say if 1 or more users is being attacked, if 1 or more devices is being attacked, if 1 or more networks is being attacked. And those assets have this level of priority in our environment and categorization in our environment of being a super user. And they have access to certain information and they have administrative access to gain to it. That is a really important key aspect into putting an incident in a certain priority with that contextual awareness for an analyst to say, "I need to work on this first. The tool put this up at top for me. And they told me that 1 of the reasons I need to work on it first is because Jon and Briana, our analyst environment and our product development environment, are under attack right now." And there's even an additional context we can take in from that -- from those countermeasures because a lot of these telemetry sources are also responsive countermeasures. Has any action been taken? Was there a quarantine put in place, were any files deleted, were any processes stopped, were any blocks occurred, were any blocks that occurred at a network layer. All of that would contribute to the contextual awareness of what is actually happening in that incident, including the fact that it's a larger incident, and a single telemetry source would be able to tell us in the first place. And that context allows us to calculate risk and that risk allows us to prioritize appropriately for the analysts.

Jon Oltsik

attendee
#33

Yes. Well said. And that -- I understand that risk and the granular nature that you talked about is so important for an analyst. And if you can't do that through an integrated solution, then that adds time, that adds effort on to an investigation. I would be remiss if I didn't also say that 29% said creating a centralized management hub for security operations, that's kind of what XDR is meant to do, isn't it?

Briana Farro

executive
#34

It's absolutely what it's meant to do. And when we look at this from a Cisco perspective, it's actually a really interesting point that you bring up. We have been very specific to say that with our solution, we will be presenting XDR incidents. And when folks like you asked us, "What do you mean by that, Briana?" I will say things like, "I'm not simply going to pull singular EDR events in when your EDR solution has handled it." You've purchased that solution for the value that it provides. So you're trusting it to be the countermeasure that it is doing what it needs to do. So you're going to let that happen. So now let's shift the model of how you think about things. is every single individual EDR event an incident? In a dashboard, the way that it came into your SIM today where an L1 analyst simply needs to go, "This was handled. This wasn't handled. This was handled. This wasn't handled," and pump it up to an L2. Or should that L1 analyst be able to say, "I didn't even get anything from EDR because it was handled. The stuff that I got from EDR was analyzed against the rest of my entire environment, and now this is an incident for us." So that centralized security hub from our perspective is not truly centralized unless it's across your entire environment because what are you centralizing if you're not looking at your entire environment in 1 place and analyzing against that entire environment in 1 place where then responsive action can also be taken?

Jon Oltsik

attendee
#35

Yes, that's the centralized hub, and that is reducing the number of alerts that we talked about right up front. So this is an important 1 to close on. So I've heard this a lot. XDR is going to replace SIM. XDR is going to replace e-mail security. The question was, which 1 of these statements most closely aligns with the impact you think XDR will have on your organization's security operations environment? And half of the people -- just over half said XDR will supplement current security operations technologies. And then 44% -- well, XDR will help to consolidate current security operations technologies. This is an important point because we've invested lots of money, time, resources into technologies for security operations to simply throw the baby out with the bath water. In other words, what we can't do -- and as a vendor, I'm sure you know you can't do and say to people, "Just replace this, this, this, and this." [indiscernible] great. That's a really difficult project. You're crossing organizational lines in some cases. People like what they have, in some cases, but it may not coalesce into a greater solution. So what do you see here, Briana?

Briana Farro

executive
#36

I think that depending on the organization, most likely either consolidating current security operations technologies or supplementing current security operations technologies will fall into play. And here's what I mean by that. I really feel that the 52% is the more accurate representation of what's going to happen. If you go back to what I just said about bringing in information from multiple security solutions in order to conduct actually extended detection and response, you didn't hear me say once that Cisco's XDR solution is your EDR. And it's your e-mail security, and it's your proxy and SASE Edge. It is not those things. It is an XDR solution. And is going to bring information in to conduct that correlated analysis not just in a historical fashion in -- not just -- excuse me, in a historical fashion or a just-in-time fashion, but consistently analyzing across the data that you provide. And then there was a piece that actually we didn't get a chance to talk too much about, Jon, yet. But when people are discussing improving that meantime, to responding and resolution, there's a piece of that, that comes with the detection being better, faster, automated and presenting a clear understanding of what's happening in your environment so that the analyst doesn't have to go through all of those other steps they work today. But the second piece of that is that R that I mentioned has been really lightly hit upon by a lot of the XDR solutions in the market prior. We should guide people through responses. Today, customers have processes. They have playbooks potentially that they put together to allow an organization and an analyst to know how to respond either in all or in very specific situations. The solution should take that responsive action more seriously. And by taking that responsive action more seriously, it should have a clear definition of the steps that an analyst needs to take. It should potentially take some of those automatically, especially with the approval of the organization to do so. And that response capability should be built in to not only guide the analyst through what's happening, but go ahead and take that action. And take that action in a way that the analyst doesn't need to know more about the environment than they do. So for example, if I have 2 different EDR solutions in my environment because it happens, the analyst shouldn't have to spend time figuring out which EDR solution to quarantine a device on. That would slow down the time to respond and remediate, right? We want that to be quick. So I bring that up because you are going to potentially not need certain solutions. If an XDR solution is properly building in capabilities for you that you have in the past. If you are using a SOAR solution today to deliver security outcomes, and now your XDR solution has that capability built in, maybe you are able to replace something like a SOAR solution. If you have a SIEM solution that you're leveraging solely for security operations today, and it's already a great process that you have that all of your teams contributing to those investigations are in 1 place in your security operations and they're all contributing to the SIEM, then maybe it is something that you could look at. But an XDR solution is not going to do things like the low retention and storage for regulatory compliance. That's not its goal, that's not its focus. It should deliver security outcomes as you need for detecting faster responding sooner and consistently doing so across all of your environment. So I think it's most likely going to supplement current technologies. It will not replace those countermeasures we have in place. We need those to do their job. They are the response of control that we will kick off an action to from the XDR solution. It will not replace certain regulatory compliance requirements and other reasons why customers use other solution tools. But depending on the maturity of a security operations team and how much of that work they do themselves and how expensive their tool set is, it could potentially consolidate some of those operations and those tools for an organization.

Jon Oltsik

attendee
#37

I think that will happen over time. I think some of the replacement maybe happen over time, but that's a gradual, evolutionary kind of situation. It's not something that you want upfront.

Briana Farro

executive
#38

Yes, agreed. And that's exactly why it's so important for XDR solutions to be built in a heterogeneous model. Because, as you said, we certainly would not expect somebody to rip and replace the solution, especially on their endpoints, there's a lot of disruption to that, a lot of effort that they would -- they have put into their environment today. It is possible that in the same way, they might gradually replace solutions in time, but that could move to a more homogenous model for them with a specific vendor that they've chosen for something like XDR. But overall, we need to be flexible and meet customers where they are, and the solution will be providing additional advantage to the environment, which is why it might be something that organizations will have to add to their budget for that spend that we talked about earlier. But ideally, it's starting to solve those problems we see today, that an organization is saying, "I can't just keep adding to my tool set to do this. I need a solution that's going to bring my tool sets together in a way that's meaningful, contextual, risk-oriented for me and allows me to action and respond sooner."

Jon Oltsik

attendee
#39

Boy, that was a good summary there. And as I think about this presentation, I think we talked about some of the challenges people have. Those are not new, but I'd say the scale of them is increasing, which is why I think we're at a tipping point. The solution area is confusing. A lot of CISOs I talked to say, "Jon, I know I need to do something. I just don't know where to start." And so a flexible XDR architecture can give you that ability to start small and grow. But as we discussed, it really does have to do things that can help you improve security efficacy, operational efficiency and enable the business, which we really didn't talk about. But at the end of the day, that's what's most important. And Briana, you talked about how Cisco is approaching this. How would you summarize what we just talked about?

Briana Farro

executive
#40

I would agree with everything that you said, Jon. And as organizations are trying to figure out how they bring XDR into their environment, we feel that they should be making certain demands, honestly. They should be expecting consistent detection and response across whatever telemetry sources they were providing into place. They should be expecting correlation that is happening in an analytical level that does not require building rules in order to do so with guided responsive capabilities that are suggested and provided based off of the event at hand. And with infused threat intelligence. We didn't talk about that much, but as a cybersecurity solutions provider, you cannot deliver quality solutions without a well put together threat analyst team, which Cisco has in Talos. That team helps inform our understanding of the threat landscape. And with the understanding of the threat landscape, we can infuse that intelligence into the correlation that we conduct that allows for that additional risk-based prioritization, which is including that contextual asset awareness and environmental analysis. So we think that organizations should not accept an XDR solution that is below those certain standards, but also that allows them to do what's right for their environment in being able to bring in what they have already invested in and allow them quick onboarding and adoption with value.

Jon Oltsik

attendee
#41

That's great. And I'm glad you brought up threat intelligence. I'm a big fan of threat form defense. And so I'm going to ask you 1 more question before we finish, and that is we didn't talk about minor attack support. MITRE ATT&CK has become sort of the lingua franca of security operations. I'm a big fan, so how do you support MITRE ATT&CK?

Briana Farro

executive
#42

Absolutely. As part of our prioritization analysis, we actually take an understanding of the tactic and technique, or more specifically, the TTP, the consolidated version of that into account. And we have an understanding from our data science team coming from some of the vulnerability solution sets that we have in place in our portfolio, of how CISOs actually, Jon, are looking at vulnerability and exploitation analysis. So when they tend to look at a vulnerability and where they need to take action or where mitigation can be the stop gap to make sure that they're comfortable until they can patch their entire environment against the 1,000 vulnerabilities that come out in a day, a lot of the way that CISOs and CFOs and Boards are looking at it is, what's the impact financially potentially to my environment if we are breached by an exploit of this vulnerability? So our solution set takes into account the likelihood that, that TTP being in use, whether it's to exploit a vulnerability or just being able to be used as a tactic and technique in your environment, what is the likelihood of impact and particularly potentially financial loss around that? We use that when we see the tactics and techniques involved to understand the potential risk alongside the asset context for evaluating a prioritization score. And that's just how we've chosen to do it within our specific solution set. But in general, to your point, the MITRE tactics and techniques are a common language. I would say that they're a more common language across security operations teams, most likely than our industry standards because other industry standards may be widely adopted by certain verticals and not others where you may have a certain security maturity level that is more advanced to understand some of those other standards. MITRE and the ATT&CK enterprise framework or the ATT&CK mobile framework, they're very commonly used. They're built into solution sets today, and analysts are able to understand them. So those mappings should be very clearly outlined. They can help an analyst understand how bad the incident is just by seeing how far down the tactic span the attack has happened. And then by using those TTPs to understand the actual potential impact and the risks associated with that, that can be infused alongside the threat intelligence of a certain campaign or threat actor being known to use that technique into prioritizing an incident.

Jon Oltsik

attendee
#43

Great. Well, Briana, thank you. This was great. I learned a lot. And hopefully, our audience did too. And how can people learn more from Cisco?

Briana Farro

executive
#44

Absolutely, Jon. Thanks so much for that opportunity. People can go to our Cisco website or you can Google Cisco XDR, as Jon mentioned, for RSA, it was exciting for us. We had a big launch event there. So there's plenty of information on our website and ways to outreach to someone. If you don't have an aligned account team to get more information, we'd love to speak to you more about your needs, the outcomes that you are expecting and how we could potentially provide those for you. And Jon, thanks so much for the conversation today.

Jon Oltsik

attendee
#45

My pleasure Briana, thank you.

Operator

operator
#46

I'd like to thank you all for attending the event. We hope you found it informative. And as a reminder, please take a moment to complete the confidential survey that has been posted in the chat panel. It will also pop up in your browser as you exit. Thank you for joining, and have a great day.

Read the full transcript via the API

You're viewing the first half of this call. Get the complete Cisco Systems, Inc. transcript — plus 248,000+ transcripts from 12,000+ companies, speaker segments, AI summaries and full-text search — through the EarningsCalls.dev API.

Get the API View API docs →

This call discussed

For developers and AI pipelines

Programmatic access to Cisco Systems, Inc. earnings transcripts and 248,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.