Cisco has embedded its operational technology (OT) security functionalities, including zero-trust network access (ZTNA), directly into its industrial switches and routers, aiming to make it simple for network managers to deploy OT security at scale.

Traditional methods of securing OT environments often involve deploying dedicated appliances for visibility, threat detection, network segmentation and secure remote access. These methods are increasingly seen as complex, costly and sometimes impractical.

Cisco addresses these challenges by embedding OT security features directly into industrial switches and routers, Vikas Butaney, SVP and GM of Cisco networking, SD-WAN, multicloud and industrial IoT, noted in a blog post. “This means that the Cisco network sees everything that connects to it, assesses the OT security posture, enforces security policies, enables zero-trust remote access and more.”

Cisco embeds ZTNA into switches and routers

Cisco launched Secure Equipment Access earlier this year, which is designed to streamline and secure remote access to OT assets and bring ZTNA to industrial workflows.

The solution “is built directly into their industrial switches and routers, eliminating the need for additional hardware and simplifying secure remote access to OT assets sitting behind network address translation (NAT) boundaries,” Forrester wrote in its latest OT security solutions Wave report.

“It allows machine builders to access the machines they have deployed into the end customer,” Samuel Pasquier, VP of product management at Cisco, told SDxCentral. “One of the particularities that we do is we do validated design, so we take our technology and we test it with third parties to de-risk the deployment for customers.”

Pasquier explains that the primary benefit of integrating Secure Equipment Access directly into industrial switches and routers is simplifying remote access for end users while maintaining visibility and control. “You are the closest from the endpoint,” Pasquier said.

For example, “as a factory owner, you can decide which vendor can access which machine, it will use the cloud to only connect to this switch and only give connectivity to this particular machine,” Pasquier said. “It's a very easy solution and very simple to deploy, and it gives you one pane of glass where you can record the session, you can schedule the session, you can also see who has asked to do and what they do on the machine.”

Forrester identifies Cisco as an OT security leader

Forrester's Wave report identified Cisco as a leader in the OT security market, along with Palo Alto Networks.

It noted, “Cisco Industrial Threat Defense is a comprehensive solution to protect, detect, and remediate across IT and OT environments.”

Cisco Industrial Threat Defense is the vendor’s pre-integrated OT solution that unifies visibility across both IT and OT networks with the Splunk security platform. It combines with Cisco’s extended detection and response (XDR) capabilities to help security teams correlate events, detect advanced threats faster and orchestrate remediation across their entire security stack, according to Butaney.

“Cisco’s OT innovation strategy focuses on building a comprehensive platform through internal development and strategic acquisitions like Splunk. Its roadmap includes tighter cloud integration to unify IT and OT domains,” Forrester noted.

Cisco integrates with Splunk for OT compliance

Forrester pointed out in the report that Cisco’s OT security solution doesn’t offer comprehensive regulatory compliance tracking, scoring, reporting, and workflow capabilities, forcing customers to track IEC 62443 and NERC CIP compliance within Splunk or outside the platform.

The Splunk integration will enhance the visibility, reporting, and security information and event management (SIEM) capabilities, Pasquier said.

The reporting capabilities from Splunk can help customers handle the compliance requirements, Pasquier added. “When you are in the industrial world, you have NERC [CIP] compliance, you may have [IEC] 62443 compliance. You have a lot of compliance that you need to do. So today, Splunk has the ability to derive those reports,” Pasquier explained.

The vendor aims to enhance the capabilities further by integrating more data from its offerings like Cisco Cyber Vision to provide richer and more detailed reports.

“We already integrated Splunk with our industrial networking portfolio and our industrial security, and the integration is just going to get better. So wait another six to 12 months and you will see a lot of news on that front,” Pasquier said.