Cisco — known for its dominance in networking — is now making strides to establish itself as a major player in the security industry, including a long list of security-related updates and announcements at the Cisco Live 2023 event.
Cisco Chairman and CEO Chuck Robbins has repeatedly stated that security is becoming a top priority and growth driver for the company.
“We are a networking company by origin and you can't be in the networking business without also being in the security business,” Jeetu Patel, EVP and GM of security and collaboration, told SDxCentral. “You can't be in the connectivity business without being in the protection business.”
“We're investing very heavily in security to be a world-class security platform … we've been a very formidable player in security for a while because billions of dollars of revenue [is] coming from it.”
They're good, but are they top 3 good?Gartner Distinguished VP Analyst Peter Firstbrook acknowledged security is a rapidly growing market with “a changing of the guard now” as some traditional top players are stumbling. And Cisco senses this opportunity as it is also related to the vendor’s primary goals to shift from hardware to software and subscription revenue.
But “are they winning? I would say that not as much as they could have, especially given their scale,” Firstbrook told SDxCentral, adding that sometimes, security is just “an add-on” to Cisco networking customers’ purchases.
Firstbrook argues the vendor “has the prerequisites, but not the track record” to become a top 3 security powerhouse.
In comparison, Microsoft, which is known for its Operating System, software, cloud and now artificial intelligence (AI) services, “is the one vendor that's really executing on security,” he added.
According to Gartner’s 2022 estimation, Microsoft had the biggest market share at around 9.7%, while Cisco accounted for around 1.8% of the total spend in the security market.
As a global networking giant, Cisco sees its networking customers as potential buyers for its security services.
“There's a massive install base we have in both, and there's a massive number of customers that we haven't gotten to yet … The majority of our security customers today happen to be networking customers, but a minority of the networking customers actually buy security from us today. So think about how many more we can sell to,” Patel said. “When networking and security kind of merge, that's where we shine.”
Firstbrook agreed that network security is Cisco’s biggest strength. But he noted the category has declined in terms of the importance of security, as now network security accounted for around 26% of total security spending, compared to 40% in 2014. The fastest-growing sectors in security are data security and cloud workload security.
The ongoing consolidation/integration issueSo, where does Cisco’s security business have room for improvement?
Firstbrook noted the two main themes that Chief Information Security Officer (CISO) are asking for are consolidated security functions for better productivity and more visibility. He added organizations are looking for integrated and out-of-box products or managed services that are “brain-dead easy” to use.
Gartner’s recent report showed 75% of security buyers say they want to buy more from large vendors, while actively trying to consolidate the number of vendors and products. “And so that combined with 65% of organizations can't find enough staff. Those are the two biggest influences in this market,” he said.
Cisco has been continuing to address this consolidation and integration customer demand by introducing its Security Cloud strategy, which unified its 27 security services into a few product suites such as its most recent extended detection and response (XDR) and security services edge (SSE) offerings.
Patel emphasized the company's commitment to a common set of policy objects, telemetry and design frameworks across its Security Cloud.
But Firstbrook pointed out that Cisco's integration efforts have been slow. He used SSE as an example and noted Cisco has the biggest VPN deployments in the world, but its VPN is distinct from its Umbrella security service and Cloud Access Security Broker — a component of SSE.
Cisco’s SSE offering has “levels of integration, but it's still not one single product and one single agent or one single management console, one central policy database; there are still separate components to those three objects,” he said.
Additionally, Cisco's integration efforts have been delayed by its history of acquiring companies without fully integrating their technologies into its platform immediately, Firstbrook added. Meanwhile, competitors like Microsoft and CrowdStrike have been taking a more homegrown and building-their-own kind of approach, which means they have “more integrated stuff right out of the gate.”
The battlefields Cisco needs to win in securityTo earn a top 3 position, Cisco needs to accelerate its integration efforts and effectively compete in key battlegrounds such as the SSE market, XDR space, endpoint security and identity protection, Firstbrook noted.
Given Cisco’s strength in networking and network security, “they should have already owned that [SSE] space already,” he said, but “they haven't won that battle [with Zscaler], so that's their biggest opportunity.”
Firstbrook also listed Microsoft, Trend Micro and Proofpoint as security vendors who have done a good job of consolidating their services.
Another opportunity lies in the emerging XDR market, where Cisco needs to compete with existing players like Splunk, Palo Alto Networks, Microsoft Sentinel and Google Chronicle. “They're all going after the same space, which is if I own your data and I have the management console that you use to resolve incidents, then I can probably sell you more, so that is a critical one for them to win,” he said.
Firstbrook also highlighted the endpoint space as a potential growth area for Cisco, with 50% of endpoints still lacking endpoint detection and response (EDR) solutions. By leveraging its network-centric products, Cisco also could target late adopters in industries like IoT, manufacturing and retail.
The last one is the identity and access management market. Credential misuse breaches are becoming a prevalent attack vector. The Verizon Data Breach Investigations Report found that 86% of breaches involved the use of stolen credentials, while only 10% of web Application breaches involve the exploitation of an actual software vulnerability.
Cisco's acquisition of Duo has positioned it as a major player and there are opportunities to further invest in identity protection devices to compete with vendors like SentinelOne and CrowdStrike and enhance their overall identity stack.
Is Cisco becoming a top 3 security vendor?Cisco has a massive amount of opportunity in the security market, as no vendor has a dominant share yet. “The sky's the limit … We can all take our fair share,” Patel said. “And there's plenty of room to grow the core business — the networking business — as a result of the strong security offering,”
Firstbrook pointed out execution will tell if Cisco can become a dominant player in the security market. “This is the year to see,” he said. “This year, they cycled through some new leadership in the security group. Tom Gillis is there now and he's a pretty good mover and shaker so hopefully they get stuff done.”
“They certainly have all the prerequisites for it, but they just haven't demonstrated any competency in it,” he concluded. “And if they continue on their existing trajectory, they will probably be a major player in this market. Will they be a top-three player? I don't think so unless they can change this trajectory and really do some good work on integration and software development.”
Comments