Cisco Systems, Inc. (CSCO) Earnings Call Transcript & Summary

July 24, 2024

NASDAQ US Information Technology Communications Equipment special 54 min

Earnings Call Speaker Segments

Mark Watts

executive
#1

Hello, everyone, and welcome to you today's webinar. I'm Mark Watts, your Webex producer. At the moment, I'll turn the session over to our first speaker, Jaki Hasan, but first, I have a few housekeeping notes to cover. Firstly, this session will be recorded. [Operator Instructions] And at the end of the session, a survey will automatically pop up in your browser. Please click continue to complete the survey. We really appreciate your feedback. With that, we are ready. So let's get started. Jaki, in a few seconds. It's all yours. You're on mute, Jaki.

Jaki Hasan

executive
#2

Thank you, Mark. Hello, everyone. Welcome to this webinar. My name is Jaki Hasan. I am a solutions engineer based out of Sydney, Australia. And in this session, we'll be looking at our new exciting technology that we are bringing out is called Cisco Identity Intelligence, right? In this session, we'll look at a few things about Cisco Identity Intelligence and how it can help you in your endeavor for a secured environment, and we'll look at how it can help you achieve those security requirements that you may have in terms of identity. So what is the agenda for today? So we first look at why identity security, right? Why is it such a big thing? Then we'll look at what is Cisco Identity Intelligence, then we look at some of these checks which we do in Cisco Identity Intelligence and how they can help you get a measurement of your identity posture in your organization. And in addition to that, how it can help you take reactive actions if there is a breach. The last thing we'll look at -- the second thing we look at is the remediations. And then at the end of the session, we'll do a bit of a dashboard walk-through, then followed by a bit of Q&A as we progress along. So why identity security, right? So think about it. Like if you have your organization, every single user has a user name and password, right? Everyone has a user name and password, and these user names and passwords are kind of your key to your house, it gives you access to your domain, to your network, to your safe place. So if someone has access to this identity and relevant information about this identity, they can easily walk in and create a lot of problems, produce a lot of challenges for your environment, right? So that is why identity security is a critical feature on a security component in today's network environment. So identity has become the attack surface, right? Back in the days -- I'm pretty old. So back in the days, you would have people trying to take down your network using DDoS. They would try to spoof your IP dresses and do weird things with your spoofed IP address. But we still have those attacks, but attacks have become a lot more sophisticated, right? Like if you had DDoS attack, you knew that you're being attacked, right? It took you -- it didn't take you that long to understand or realize that, "Hey, my network is under attack because my services are not reachable, so I'm under attack. I need to take a remediation action to resolve this problem." Now suppose if you have a colleague of yours went on holiday and then a lot of the time, if you have a big enough enterprise, almost you're in the closer colleague circle of that employee, you will not know that, that employee has gone offline and you should not be expecting any log-in attempt from that employee, right? So what actually happens is that if that identity of that colleague is compromised, then people or attackers or bad actors can easily use that or utilize that credentials to log in to your environment and create problems for you, right? So identity has become the new attack surface. One of the things we have seen is that why hack in when you kind of log in? Like back in the days, you would create -- people will come with elaborate tools to kind of crack passwords, right? Like they would have dictionary attacks. They would have brute force attacks to crack user name and password. With today's technology, what is happening is that we are seeing more sophisticated attacks including things like phishing attacks, where the victim is a lot of the time unintentionally, without even knowing, handing in the user name and password to the bad actors, right? So the attackers no longer need to set up this elaborate plan or elaborate tools to brute-force their way into the network. They can simply set up very simple tools or applications and get those details much easier than before. I'll give you an easy example, and this is something I have experienced personally in recent years. I'm based out of Australia. We are recently going through our financial year closure in Australia. And what we do is we do have a bit of tax return at the end of the year, right? And we have this centralized protocol called myGov. I've been receiving a lot of SMS saying that, hey, your employer has submitted your earning income's details to the tax agency, come and log in and verify that it is accurate, right? Just out of curiosity, I have actually clicked into one of the -- on to one of those links. And when I looked at the website, you cannot really tell the difference between that website and the actual authenticating -- the original log-in portal for that application, right? So the attackers are more sophisticated. They're coming up with this elaborate exact replica of websites -- legitimate websites and using those websites to steal your credentials, right? So credentials have become a very critical component of your attack surface. When we look at -- this is just kind of a breakdown of all the attacks we have seen in recent years, and we have looked at the volumes. And when you look at the top 10 attacks that have been carried out and the techniques that have been used, out of top 10, the 4 are account-related or credentials-related, right, or identity-related. So identity is a critical factor in your organization. And when someone has access to your identities, if it is critical enough, they can use that to log in and create a lot of problems for you, right? So that is where Cisco Identity Intelligence comes in and helps you out. The other thing we have is defense in depth. So when we talk to like -- when I speak to my customers and my colleagues, a lot of time we'll see the focus on endpoints like -- protects your endpoints, it is very critical protection network, we're moving to the cloud, protect your cloud native resources. And that is all fine and good, but we don't see that much conversation in terms of protecting your identities, right? Like we have so many different places where these identities are critical, but we're not looking at protecting that identity. So that is where Cisco Identity Intelligence comes in. And one of the terms -- a lot is defense in depth. When you want to protect your network in these days and age, just having the endpoint or the network or the cloud-native detection response is not enough. You need to go beyond that. You need to find out what are some of the other places where it might be vulnerable in your organization, and that can cause a real havoc in your organization and one of them is identity. So when we talk about defense in depth, identity has become a critical component. So what is Cisco Identity Intelligence? It is our identity threat detection and response, right? So this is this new term that has come out is ITDR. So it is our Identity Threat Detection and Response tool. So we are not only detecting. So this tool is not only a detection mechanism, but you can take actions on it as well. So if you have a vulnerable account, you can take additional tasks depending on the platform you're protecting to make sure that someone -- you contain the blast radius of that identity exposure, right? So for example, if you have Azure Entra ID, for example, you can go into your Entra ID through secure identity intelligence and basically end or kill sessions -- or kill active sessions from this portal. Now why are identity attacks are so hard to stop? So one of the things is that lack of visibility across identity system. If there is a small organization, typically, they would have 1 IDP and that makes it quite simple to manage and monitor and keep track of. But when you have a large enterprise, think of some of biggest banks, some of our biggest enterprise customers, they don't have a single IDP. They may have IDPs for different purposes. So these IDPs are working in isolation. And a lot of the time, these IDPs are managed by different teams. And one team may not have the visibility into the other IDP, right? So they're kind of running in isolation. So we are -- in general, organizations have this lack of visibility across their identity system. And the other thing is excessive privileges, right, admin creeps. Like this is -- one of the first things I learn in CISSP is admin creep. So usually, if there's an employee working in an organization for such a long time, typically, what happens is he or she accumulates a lot of credential access as part of different roles that user may have performed within the organization, right? So they may have access to systems. They no longer need as part of their job description, but it is still there. And if someone gets access to the identity of that user, they can easily cause some serious damage to that organization because of all these additional admin creeps that has happened over the years, right? And the other thing is disconnect between authentication and access decision. Like sometimes what happens is we believe, hey, authentication is enough. I've authenticated the user and I can give access to that application -- get access to these applications to that user. But we often fail to take a lot of other additional contexts like where is that user logging in from. Like I know that I'm an organization. All my users are based out of Sydney, and I all of a sudden see a log-in attempt from, say, for example, outside of Australia. Is that normal, right? We don't often take into consideration the context of that log-in attempt or the authentication attempt to control the access. So that makes the identity attacks quite difficult to stop in general. So this is kind of going back to the previous comment that I made is that identity architectures are complex, right? I have seen back in the days when I was doing some -- like support role within Cisco, a lot of the time, customer would have a single identity provider. It was just an on-prem active directory, right? Okta, Azure AD wasn't that much of a thing back in the days. But now when I log in to -- when I go into a customer environment and I assess their IDP footprint, I see a lot of time for different segments they will have on-prem active directory. They'll have an Entra ID for a different segment of the network or their service application segment or they may have Okta for certain other use cases, right, like, for example, the contractors, as an example. And they have a lot of SaaS applications as well, right? A lot of users are -- a lot of customers or organizations are moving to the cloud. So they're using AWS quite heavily. Salesforce is a well-known name across the globe, right, then GitHub, Google. So we have these identities being used in different segments, and there are a lot of time running in isolation. And it makes it difficult for any security or SOC team to kind of get a visibility -- this high-level visibility into this plethora of IDPs that are in place or applications in place, right? So the identity architecture has become complex, too, due to the evolution of organization operational workflow. So what are the key identity security problems that we are trying to address with Cisco Identity Intelligence is that opaque or I would say it's a convoluted identity infrastructure, right? Because you have so many different IDPs, it kind of becomes convoluted what is doing what. And you don't often have a lot of visibility across all of them at the same time. Then no centralized insight because if you have different teams working in isolation, there is no centralized insights into this IDP. Like a lot of the time, security team who works in isolation from the accounting team, the finance team, the network team if the organization is big enough. So there is no centralized insights in terms of identity provider solutions, right? So different segments may end up using different identity provider. Then if you have a multinational company, something like Cisco, then the problem gets worse, right, because then for one region, you might be using a different identity provider, for another region, it's something completely different. Then the other thing is that a lot of the time, these identity providers or these applications kind of work in isolation. They produce a lot of alerts. They give you a lot of visibility with all due credits to these applications. They do provide a lot of logs, but one of the challenges is that they don't -- like there's -- it's difficult to get these alerts or these logs that are coming out that kind of reviewed or investigated in isolation, right? There is no correlation happening between these logs that are coming in from different providers. So that is another challenge. So if I have to put it in a simple way, you're missing the forest for the tree in simple terms. Then fail protection, right? A lot of the time, we're seeing a significant push from multi-factor-authentication, but what happens is that a lot of the time when we have gone in and run these identity assessments for different organizations, we have come across that MFA coverage is incomplete. Even though the customer has or the organization has MFA, but a lot of users may not have adopted the MFA capabilities, right? So we're seeing incomplete solutions in place or they're probably using weak forms of MFA. Like, for example, if you're using SMS as an MFA tool, it is very easy to get an eSIM to knock the actual physical SIM out of the network and you can easily redirect all -- the bad actors can redirect all the SMS to the electronic SIM rather than the actual owner of that phone. Then identity and device trust, right? When I say that, what I mean by is that identity and device trust is not just the user name and password or the posture of that device. It is the surrounding context as well. Where is that user of that device is logging in from? How many times has that device try to log in, right? So there are a lot of additional context that should be taken into consideration, which are often missing and that results in a very weak protection for these identities. And a lot of the time -- the other one is the [indiscernible] enforcement, right? So typically, when you're trying to provide enforcement for these identity breaches, it makes it difficult because a lot of the time -- for user experience perspective, a lot of organizations simply do basic posture check but they didn't go more than that or they have very static access policies, which is not dynamic. So if -- say for example, if I go back to my example before, if an employee has gone on holiday, if that employee is logging in from a different region than Australia, static access policy typically will allow that configuration of that access to go with. It will allow -- it will not take into the context of that connection. The other thing with the [indiscernible] enforcement is that it is either block or allow, right? You're either granting access or blocking access to applications. You cannot make a dynamic enough a lot of the time, right? So that makes it another challenge. And the other thing is delayed response to risk because you have so many different disparate identity solution. By the time you have gone through all the laws and all the investigation, all the due diligence, the horses may have left the barn already, right? The horse has already bolted. The system has already been compromised. And by the time you go and take a responsive action, the damage has been done. So this is where Cisco Identity Intelligence comes in, like I've given you all the problems. So the solution is -- one of the solutions is Cisco Identity Intelligence. So what is the benefit of it? I don't normally spend on this -- too much time on this -- on the slide, but what we do is that we provide a vendor-agnostic approach to your log processing and response. So when it comes to detecting -- integrating with multiple different platforms to get more granular and overarching visibility, that is where Cisco Identity Intelligence really shines. In addition to that, we also correlate users with devices and service accounts, right? Like users may have multiple accounts, multiple devices. We correlate all those information and give you a comprehensive visibility into your organization. In addition to that, we also take into consideration behavior analytics of a user. So for example, if we see a user logging in between 9 to 5 every single day to a certain application, then all of a sudden one day, we see that user logging in, I don't, like 11:00 at night, that will be considered as a suspicious log-in, right, because that is traditionally outside of the behavior that we have experienced for that user from the past. So Cisco Identity Intelligence provides you with the behavioral analytics of that user activities as well. So here, you have all these different applications that you're running. And one thing that I would like to highlight is that Cisco Identity Intelligence is not an in-line solution. It is not that something that sits in the network traffic part of your authentication process. It is kind of sitting on the side by side to your identity providers, your different SaaS applications. And it is basically consuming all the logs from these different applications, different service providers and it is generating this user machine service-related or app-related or data-related behavioral analytics. So when it comes to running, deploying or adopting Cisco Identity intelligence into your organization, the overall impact or downtime is minimal because it is running side by side, it is not in line, so you don't need to make any changes to your typical user authentication process. It is just sitting there, sitting in the corner, it is gathering all the data, and it is providing you with the analytical output of what it is seeing within your organization. So here's the question. Why not just use the IDPs, right? So this is the challenge here is that all these IDPs, they provide you a tons of information, they provide you a lot of logs, they provide you with a lot of analytics, but the challenge here is that they all run in isolation. So when you want to get the comprehensive visibility across your whole organization, then that is where they kind of fall short because they don't talk to each other a lot of the time, right? They can only detail what they see. So what might happen is that say, for example, you may have a user in Okta and you may have a user in your HR information system, say, for example, Workday. If you're just focusing on the Okta logs and you see that our user has been logging in like in weird hours and weird times of the day, you might think, okay, it might be that the user is on a holiday or working from some remote location, I will not pay that much attention to it. But in your Workday, what you might find out is that, that user may have left the organization, right? The user may have left the organization. He's no longer with the organization, but Okta will not tell you that. Typically, what will happen is that Okta will basically just tell you, hey, the user is trying to log in, but it will not tell, hey, the user should not be even in the system because the user has left the organization a long time back, right? So these tools are running in isolation. So a lot of the time what happens is they don't talk to each other, so they don't give you the comprehensive visibility. I see a question, what is the difference between Cisco Identity Intelligence and SIEM like Splunk. So with SIEM, what happens is that you can collect all the logs into a SIEM. But when it comes to doing the actual behavioral analytics, you need to create them yourself. They're not built into Splunk itself, right? So you need to still go and create those detection mechanisms, all the analytical algorithms to make sure that all the -- when all the logs are coming in, you analyze those logs in appropriately and correlate them and provide a nice output. Splunk or SIEM doesn't provide that, the Cisco Identity Intelligence does. It has the behavioral analytics built in, so it takes a lot of those tasks away from you, so you can focus more on the attacks themselves. I hope that answered the question. So the other thing is that CII brings together all the info. So all these information that we have, CII, Cisco Identity Intelligence brings all this information together. So it is -- everything comes into one analytical system. We do the analytics for you, and we provide you with nice little outputs on what is happening across the organization. And when I do the dashboard demo, you'll see what I mean. But it does help with that analytical piece of side of things for all the logs that are coming in. The other thing is that it greatly reduces noise from the IDPs, right? So if you're looking at a lot of these IDPs and if you're looking at these logs in isolation, sometimes they may feel like a lot of -- there might be a lot of noise in it. We sort that out for you because we are correlating all the data. So we take a lot of noise out for you, and you don't have to worry about any of that. We do the analytics for you and provide you with the nice little output. And we work closely with the well-known identity providers and multi-factor providers out there, right? Obviously, Duo is one because it is Cisco. We are one Cisco, but we also work closely with Okta and Microsoft to come up with some of the features that usually goes into the product itself. So that gives you a better capabilities in terms of taking actions or detection mechanisms within these IDPs. So what is happening with our Cisco Identity Intelligence. So what is happening is that you have all these different disparate tools running in isolation, providing with a ton of information, but it doesn't really create a clear picture of your organization, right? So with Cisco Identity Intelligence, what happens is it puts everything together into one bucket, and it gives you that visibility into your organization as a whole. It gives you that holistic approach and visibility into organization so you're basically looking at the forest, not just the trees anymore. So I'll give you a real-life example of a detection. I mean when I go through the dashboard, you'll see a lot more of this as well. It's basically just a nice little identity graph. So what we're doing is we're looking at a specific user, what's all the identity providers that user is using, and then what are some of the application and authentication mechanisms that user is utilizing, right? But just looking at that graph, what you can see is that, that user is logging in from multiple different locations, right? He is logging in from Virginia, Australia. He is logging in from California, South Africa, Singapore, Hong Kong. So it is coming -- that user's coming from all over the places, right? So just by looking at the graph, you can see something is wrong. Why is that user is logging in from so many different places. It basically definitely raises a lot of concerns. But here's the thing, right? If you look at the 2 identity providers, if you're just looking at Entra ID, Entra ID may have given you a bit more, but Duo with the additional visibility, it helps you find the -- it gives you that additional reach in terms of your visibility, right? Duo -- so Entra ID is providing with a lot of information, but what Duo is kind of confirming that, right? It is definitely confirming, hey, we do see some weird authentication attempts from different locations for that user so that is the real-life example of a detection. Just by looking at the graph, you know that something is wrong because that user is logging in from multiple different locations. The other thing is that -- we are providing with Cisco Identity Intelligence is that we're providing a combined view of all your users, right? And your user may exist in your Okta, that user may exist Entra ID, it may exist in Duo. So what we're doing is that we are giving you a confidence of visibility into all your users from all your sources. And we correlate all the information from all these sources for every single user. And the other cool thing about Cisco Identity Intelligence is that it provides you with this nice little 360 view, right? So for example, I showed you the traffic flow graph that gives you a lot of quick visibility to what that user is doing. But in addition to that, it's also telling you -- like giving you a static posture of that user, like how many times has that user attempted to log in, how many times has that failed, does that user have any outstanding checks? I'll tell the checks in the next segment, but bear with me for now. So with this 360 view, we're giving you a lot of visibility into individual users and their posture at any given time. And this is all being done from 1 single dashboard and the sources of multiple defined identity providers you have across your organization. Cool. So the next thing is checks, right? So what are checks? So when we talk about checks in terms of Cisco Identity intelligence, what we're talking about is that what are some of the things that are going wrong within your organization? We saw -- what we do is we do checks for different things. And they're typically classified into 2 types, proactive and reactive. And when someone passes a check, that means there's nothing wrong with that user. If someone fails a check, that means that user is doing something that is out of the ordinary and concerning that you definitely should go and review and take necessary steps, if required. So checks are like signatures, right? So if you have -- if you're familiar with the IPS or if you're familiar with the antivirus running on your endpoints, they all have signatures, right? So they have all seen some kind of attack in the past, and they have created a signature based on those attacks or those malicious files that have come through. So in Cisco Identity Intelligence, what we have done is that we have seen certain kind of behavior or a log patterns from different identity providers. Typically, those are correlated with certain type of attacks. And what we have done is that we have taken all those knowledge that we have from those analytical information we had in the past, and we have put them into -- converted them into checks and put them into the dashboard. So this is the key difference. So that coming back to that question, what is the difference between CII and SIEM, this is the key difference. These checks, if you have a SIEM, you need to go and create these checks yourself, we have this built in, right? So these are built in. So what usually happens is once we have collected the data, we will run those data against a specific check, like specific signature or type of attack. And if those checks fail, that means that we definitely to go and review what is happening in that -- for that the user or for that activity, so we can take the right remediation steps. So what is the difference between proactive and reactive checks? So proactive checks are think of things like when we first do these integrations with Cisco Identity Intelligence and your identity providers, one of the proactive checks would be is like does or do all your users have multi-factor authentication turn-on right? Think of it more like a posture of that user or the identity posture of all of your users within your organization. Does your device -- does the user have a multi-factor authentication turn-on? Does the user have the right user type assigned to that user, right? Is that user using the right -- the secured way of multi-factor authentication rather than just using SMS? So these are posture checks and these are the proactive checks we run within Cisco Identity Intelligence. But then we have the reactive ones. Reactive ones are the ones that we use behavioral analytics for. So this is where we will look at all the logs that are coming in, and we'll review the different logs. We'll look at how that user has been authenticating for the last 30 days, last 60 days. And then based on the baseline of all the logs and the behavior that we have gathered from those logs, we will generate checks, if something deviates from the traditional behavior. So like the example I used before, if your users are logging -- working from 9 to 5 for the last 60 days, then all of a sudden one day, you see that user is logging in at 11 p.m. at night, that is a deviation from the standard behavior, right? That is something that reactive check will pick up and will alert you on. So that is the difference between proactive and reactive. Proactive is more static checks in your organization's identity posture. Reactive is based on the real life access authentication logs, events and so on and by analyzing the behavior of your environment for last 30 or 40 or 60 days, and then generating deviations or identifying deviations from the norm within your organization. So what happens when a check is matched? Like say, for example, you have a user that has -- doesn't have the strong multi-factor authentication configured like they're probably using SMS, they're not using Duo Push, so how -- what do you do in that case, right? So in that case, you can send notifications out. We can generate -- we can integrate with several different notification tools like Slack, Webex, ServiceNow, for example. And we can generate notifications the most appropriate for your organization and create a notification either for the admin, for the user and so on or whomever may be responsible to enforce those checks in your organization. So notifications when a check is matched -- so what would happen is that when notification is matched and one of the cool things about Cisco Identity Intelligence is that it doesn't -- a lot of the time, you'd see a lot of security tools, it doesn't give you a lot of this explanation in terms of what a check is. But Cisco Identity Intelligence does a great job in terms of that. So what would happen is that you'll see when you go into one of those checks, it will give you additional details into what that check is. And it also gives you a bit of educational materials. So if you're not aware of this attack or this check, you can go into that education material and learn from that, right? The other cool thing about this one is that what is -- when you have checks -- when you have different checks running in, this is more from a compliance perspective, what are some of the frameworks these checks address, right? Like here, you can see here that no MFA configure is required NIST, right, it is required in CIS, it is required in ASD Essentials 8. So from this page, you got a lot of details on these checks that are -- that is Cisco Identity Intelligence is running, and you can learn a lot from these pages. The other cool thing about -- this is what I see from a lot of other organization as well. This is a common request. So I know that one of my users have failed this authentication, how do I educate the user without having an IT admin or a SOC admin go and talk to the user, right? So we do have educate the end user built into the product itself. So what would happen is that when that user gets a notification for, say, example, no MFA configured, we'll provide that educational link to that user as well. So we'll send that user an e-mail with additional details on the checks why he have failed and what action should be taken to remediate that failure. So this is a simple e-mail that we have sent out. So what we're doing is that, "Hey, you don't have your multi-factor authentication turned on. You should turn that on. Here is a nice educational video why multi-factor authentication is critical and how it can save you from an online attack, right." So we provide you with the nice educational material built into the product itself. The other cool thing about Cisco Identity Intelligence is that it has remediation built in. It's not only detecting, but it does give you the option to take actions as well. Now here's the thing. The remediations are source specific, so not all sources will support the same remediation. Like, for example, reset MFA is applicable only to Okta and Duo only. Then, for example, if you want to reset or disconnect a session -- an active session, that is available from both Okta and Azure AD, right? So depending on the type of integration that you have in place with different platforms, we do provide different kind of remediation actions for the checks that have failed. So the other thing about this one is that when you need to do a remediation action. So let me take a step back. So Identity Threat Detection and Response, right? So when we're detecting, what we are doing is that we are consuming logs from different locations, different IDPs, and we're processing that, right? So we're actually in a read-only mode. But when it comes to remediation from Cisco Identity Intelligence platform itself, it is to actually go in and talk to those identify provider and get them to taken action, right? So you do need to provide that right access to your IDP. So once Cisco Identity intelligence has been integrated with that IDP, it has the right access to make that judgment that -- make that appropriate API call so that identity platform can take the appropriate steps to either disconnect the multi-factor authentication or disconnect an active session. The other thing is that when it comes to remediation, we recommend -- do you recommend that you should use CII all the time or do you recommend -- you may already have a lot of mature organization, may already have remediation steps built into their SOAR or tools like XDR, right, different automation tools that they have in their organization. Typically, we recommend that -- leverage that so use the input from Cisco Identity Intelligence, put that information into our XDR or SOAR and build it into your already mature remediation actions. If you don't have anything, the Cisco Identity Intelligence is there. It can provide you with a backup. But if you already have something, we typically recommend rather coming up with something new, just make this Cisco Identity Intelligence is a part of that remediation process by taking the analytics from it, plugging into XDR and have all the remediation actions taken in your XDR or your SOAR. The other cool thing is that we do provide context or specific remediation menus, like this is coming back to the point is that not all identity providers have the same capabilities. So what will happen is that when you're using Okta or when you're using Slack or you using Entra ID, we do provide the specific remediation actions available for those specific identity providers. I see a question. Can we integrate CII in a pure Windows AD environment? At this point in time, no, but that is something in -- we have in the works. Stay tuned for that. We will have more details on that shortly. Cool. I do realize that it says Q&A, but what I want to do now is that before I go into the Q&A, I would like to take you through the dashboard of Cisco Identity Intelligence just to give you a bit of a visibility into what it looks like. So let me quickly log in. Perfect. So here is the landing page for Cisco Identity Intelligence, right? So we can spend like a whole hour just on this page, but I want to keep it very simple. So I'll quickly run through it. So one of the first thing you see is that what are some of the integrations we have in place? So what are some of the sources of logs that are sending the logs into Cisco Identity Intelligence right now? So here, you can see we have AWS. We have Azure AD. We have G Suite, then, for example, GitHub, right? So we have this different integration with the different SaaS or IDPs. So these are some of the sources we are consuming the logs for. Then what the other one is doing is that it is giving you a nice overview of your identities, like how many identities do you have in your organization, right? How many identities you have? So I have like, for example, 235. Didn't you expect looking at this number of identities you have and then you have MFA status. You can see that like more than half don't have MFA configured. So this is the proactive check that I was telling you guys about. This is more of doing a posture or a health assessment of your identity in your organization. You can see you have 235 users, not everyone has posture -- sorry, multi-factor authentication. Then out of all the ones that have multi-factor authentication, 21 of them don't have strong MFA configured, right? They might be using SMS, phone calls or whatever. They're not using something like a Duo Push, for example, or Okta Push. So this gives you a nice little overview of your -- this is part of that proactive check, and this is giving me a nice little snippet into your identity posture at this point in time. Then it also tells you like how many administrators you have in your organization? For example, I see I have 5 administrators. But if you see, you have 235 users and you see 235 administrators, that is a concern, right? That will be definitely a big concern. But here, you can see we have 5 authentication -- 5 administrators. We have like 3 administrators for GitHub. So it gives you a last little breakdown of how many admins you have per identity provider or SaaS application. It gives you a nice little view of that in this dashboard. It also tells you some of the administrators that have logged in. So these are not actual users that are logged in. These are the actual administrators to these applications, right, where they're logging in from. And then we're looking at certain weird things. Like, for example, just from this page, you can see that, hey, Rudy has logged in from a new ISP, then he's connecting from Moscow. Like he should be coming from something like U.S.A., but he is logging in from Moscow or Reykjavik, right? So this is giving you a last overview of what your admins are doing, where they're coming from, do you see anything malicious? Because a lot of the time, a lot of the attacks will use admin accounts. So it is a nice little overview of your admin level posture within your environment at any given time. Then we're also looking at how many -- what are some of your user sources, right? Bulk of the time, I've seen this kind of flip around. Typically, Azure AD would be the biggest one, then Okta would have a subset. But in this case, we have more users coming in from Okta then Azure AD, right? But it gives you a last little breakdown of all your user sources. The other thing is that it gives you a nice little visibility into what kind of multi-factor authentication mechanisms are in play in your organization? Do you see a lot of users using push? Like we see a lot of users using Duo Push. Some are using Okta Push. But bulk of the user is using SMS, right. And as we -- everyone knows, SMS is not always safe because it's easy to replicate a phone number to an eSIM. So technically, people should be using push or some other mechanism like a hardware token instead of SMS. So this gives you a last little visibility into that. The other thing that it allows us to do is that we can actually go into a Cisco Identity Intelligence, and we can actually say, hey, these are some of my very sensitive applications, monitor them, right? Show me how many users are -- accounts are using this application, how many accounts are not using this application, right? So you may have, say, for example in your Jamf, you may have 53 users. None of them are using it. But then you have your Concur, you have around 53 users again, but 12 of them are using it. 41 isn't, right? So why those 41 users are not using it, right? So what this -- the other benefit of this is that just by looking at this graph, you can go and say, hey, I may not need 53 licenses for my Concur. SAP is a very expensive application. So what I need to do is how I just end up using -- reducing my license count. I was expecting 53 users to use it, but then COVID happened and now we only have 12 users using it, right? So I may cut back on my license usage for Concur and save money that way. So it gives you a nice little overview into are we really getting the right return on investment for these expensive applications that you're buying within your organization. It gives you a nice little overview into that as well. Before I go further, I think there's a question. How can company implement CII if they already have a SIEM implemented? The logs are already shipped to the SIEM, right? So you can run both of them side by side. So here is the thing, if you already have a lot of these checks that we are talking about right now, if you already have that configured within your SIEM, then Cisco Identity Intelligence may be a redundant solution for you, right? But if your SIEM is just collecting logs, it is for long-term storage, it is not being any analytical -- analytics on these different logs that are coming in, that is where Cisco Identity Intelligence can complement your SIEM, right? It is not the same itself, but it can complement your SIEM by doing that analytical -- analytics of your logs or you -- rather than you having to go and create this analytical models in your SIEM itself. Okay. Then the other thing it shows you is that how many different countries you're connecting from? Like I'm based out of Australia. So a lot of my customers are Australian-based, right? We seldom to see any authentication from outside of Australia. So just by looking at this graph, all of a sudden, you wake up in the morning and you see that -- as a SOC admin, you see that, hey, some of my -- or one of my user is trying to attempt a connection from outside of Australia, right? Why is that? So just by looking at this graph, it gives you a nice little visibility into your identity posture at that point in time. Let's take a look at some of the checks. So again, like the checks are basically the behavioral analytics that we have in place. It could be proactive. It could be reactive. We have all of them in this 1 location. Like here, we can see, right, like this MFA configured. It's a fairly simple check, right? But to check this in your SIEM, you need to go and say, hey, you need to create a logic within your SIEM, something like, "Hey, when I see all the logs from Splunk, show me how many users are logging in without a multi-factor authentication or a secondary authentication." If all your users are doing primary authentication, then you can create that report within our Splunk, but the difficulty here is that you need to go and create that check manually, right? And just think about it, if you need to do this for a lot of additional checks as well, then it kind of gets out of hand. So Cisco Identity Intelligence can simplify that for you by having all these checks in place already built in. Then if you look at the second one, this is the example that I used before. Like say, for example, I have my Workday and my Okta pushing logs into the SIEM, but what is happening is the SIEM is telling me, "Hey, this user has attempted to log in several times in the last 10 minutes, but it doesn't really correlate that information that's coming in from your Workday." SIEM by default or without you creating that link between -- the logs between what Workday and Okta, it will not tell you, "Hey, admin, I don't see this user in Workday," so that means the user has already left the organization. Why is he still trying to authenticate against Okta or why does that user still exist in Okta, right? So SIEM will not tell you that by default, but Cisco Identity Intelligence it will because it is seeing the logs from the Workday and it's seeing the logs from Okta and it can say, "Hey, I don't see this is in Okta. What does that mean? Does this mean that this user has left the organization? Go on check, right?" So here, you can see I have a user, who's in the IDP, but not in the HR system. So this is the nice little check that has built in, right? So you don't need to create the logic for it. We already have the logic built in and you just need to go and implement. Let me take a look at a few other ones as well. Then some of the -- so this one is more of a static posture than same thing with this one, no strong MFA configured, it is a static posture. Let me take a look at something that is more of behavioral analytics, inactive user, provider type missing, rare browser activity, right? So this is one of the dynamic checks. So within Cisco Identity Intelligence, you can say that, hey, in my organization, I have an enterprise browser, I don't expect my user to use something like a Vivaldi browser or a Brave browser, right? They should be always using something like an enterprise Chrome. So when the same user tries to access an application using something like Vivaldi or Brave, then this can flag that behavior, right? So it is based on the behavior, and it's not a static posture check. It is more dynamic because it doesn't happen every single day. So it is a behavior-based analytics that we are providing. So these are -- we have quite a lot of checks built into the product itself by default, but the cool thing about this one is that every single attack that -- or check that you go in, it gives you a nice little details as to what that check is? And what are some of the recommended actions that you can take, right? Also tells you what are some of the frameworks this check is measuring against and what are some of the IDPs that these checks are compatible for. Like this is compatible with Entra ID, Okta ID or Google Workspace. So that is the check side of things. And I know we have -- I know we have 6 minutes left. So that is pretty much the end of the presentation. Mark, I'm happy to take questions if there are any.

Mark Watts

executive
#3

No more questions at this stage.

Jaki Hasan

executive
#4

Perfect. Awesome. So thank you again for joining this webinar, ladies and gentlemen. I really appreciate that. If you -- there is a survey at the end of the session, please do fill it out. I apologize, Mark if that was your line. What I would like to do is if you do like to try this out -- try Cisco Identity Intelligence out, please reach out to your Cisco sales representative, and we can organize this identity assessment session for you. So if you do have any questions or if you do -- if you're interested, please do reach out to sales representative, and we'll be more than happy to run this for you in your organization. With that, Mark, back to you.

Mark Watts

executive
#5

Thank you. We'd like to thank you all for attending the event. We hope you found it informative. A special thank you to Jaki for speaking today. And as a reminder, please take a moment to complete the confidential survey that has been posted in the chat panel. It will also pop up in your browser as you exit. So thank you for joining, and have a great day.

This call discussed

For developers and AI pipelines

Programmatic access to Cisco Systems, Inc. earnings transcripts and 248,000+ others is available through the EarningsCalls.dev REST API. Plans from $24.99/month — full transcripts, speaker segments, full-text search, and the recently-added /api/v1/transcripts/recent polling endpoint for ETL pipelines.