Cybercrime costs organizations $6 trillion in global damages, according to Cisco CEO Chuck Robbins, who delivered an RSA Conference keynote this morning while his company unveiled a bevy of updates to its security products.

“If we think about cybercrime the way we think about the GDP of countries, it would be the third-largest economy in the world after the U.S. and China,” Robbins said, citing Cybersecurity Ventures’ $6 trillion figure. “And we all know the real cost is not being able to run our businesses, or the reputational damage that you suffer, and the impact on your organizations in the future.”

While 2020 accelerated several trends such as remote workers and cloud-based applications that expanded the threat landscape and helped cybercriminals grow their GDP, Robbins said this hybrid-model of work is here to stay. “There is really no perimeter in the enterprise to defend anymore,” he said. “Those same workers will be mobile, at some point in the future, in coffee shops again, and we have to deal with all that and we have to build security practices around what we know is coming in the future.”

This future requires “an end-to-end security architecture” that Robbins said is “foundational to being able to deal with the complexity” around number of users, connected devices, applications, and data. “And right now there are over 3,500 vendors who are building security solutions for you every day. But we think because of that it’s just so complex, and we need to reimagine the security architecture.”

Cisco SecureX Updates

Cisco, like most major security vendors, says a consolidated security platform is the answer to this complexity problem. And, of course, it’s hoping that the market chooses its platform — SecureX — as the winner.

To this end, Cisco announced several updates to SecureX, which debuted last year at the RSA Conference. A year later, more than 7,000 businesses use SecureX, according to Cisco, and it now is included with every Cisco security product. Cisco executives also teased a “premium version” of SecureX in the future.

This version will include additional security features, and several of those will likely come from Kenna Security, said Gee Rittenhouse, SVP and GM of Cisco’s Security Business Group, during an RSA roundtable discussion. Cisco last week said it reached a deal to acquire Kenna Security, and said it plans to combine the security software vendor’s risk-based vulnerability management technology with its SecureX platform.

“SecureX is built in, and essentially comes with the rest of the security portfolio, but we do expect to have a premium version of SecureX with premium features,” Rittenhouse said during the roundtable. “I think quite a few of the features that Kenna offers will be in that category — they are very, very valuable for customers,” he added, noting Kenna’s feature that helps organizations prioritize their threat landscape. “So we’re still debating that, but you can probably expect most of Kenna to be in a premium release of SecureX.”

Also at the RSA Conference today, Cisco announced updates to SecureX that it says boosts the platform’s extended detection and response (XDR) capabilities and improves unified visibility across endpoint, cloud, and network. This includes a new feature called SecureX Device Insights, which provides visibility and consolidates data from across an enterprise’s endpoint inventory such as device managers, endpoint detection and response, and anti-virus products. It also automates threat response.

Cisco also said it is extending “XDR value” to its endpoint security products via Cisco Secure Client. This is a single, unified endpoint platform from which customers can deploy and manage multiple endpoint agents. Additionally, Orbital Advanced Search doubled the number of built-in queries that can run from within Cisco Secure Endpoint (formerly AMP for Endpoints) to speed up and simplify threat hunting and detection at the endpoint. It now has more than 200 advanced threat hunting queries.

In addition to its XDR updates, Cisco announced new secure access service edge (SASE) integrations and network security features.

Cisco SASE Updates

For its SASE architecture, Cisco added a new integration between Cisco Umbrella and Cisco SD-WAN powered by Meraki.

Cisco Umbrella combines cloud-delivered firewall capabilities with a secure web gateway, cloud access security broker, domain name system security, remote browser isolation, and the SecureX XDR platform

The vendor’s SASE architecture already integrated Umbrella with Cisco’s Viptela SD-WAN, and this new integration automatically extends the Meraki SD-WAN fabric to Cisco’s Umbrella cloud so customers can securely connect to cloud applications with better performance.

Cisco also said Umbrella’s cloud-delivered firewall now includes an additional layer of protection with the Snort 3 intrusion prevention system (IPS) and backed by Cisco Talos threat intelligence team.

“IPS helps organizations of any size meet compliance requirements and avoid a broad range of attacks found in encrypted and unencrypted internet traffic,” wrote Raviv Levi, head of product of Cisco’s Cloud Security organization, in a blog post. “Having the world’s largest private threat research organization (with visibility into over 600 billion internet activities per day) identify thousands of new threats in real-time and automatically protect your distributed users is yet another example of radically simplified security.”

And finally, Cisco will offer its Umbrella security capabilities in a single subscription called Secure Internet Gateways Advantage.

Cisco’s NetWORK Security Vision

Cisco also announced its vision for simplifying network, workload, and multicloud protection. The vendor calls this “NetWORK Security,” and it goes back to Cisco’s network approach to security with integrated NetOps, SecOps, and ITOps.

This includes newly integrated network and workload security where Cisco Secure Workload dynamically informs Cisco Secure Firewall of required policy changes and provides visibility and control wherever the applications live.

The latest version of Secure Firewall Threat Defense, version 7.0, makes Snort 3 IPS available with Cisco Secure Firewall Management Center. Snort 3 is also now included in Cisco SD-WAN powered by Meraki and Umbrella. And adding SecureX to the Secure Firewall Management Center also further simplifies detection and response, the vendor says.

Finally, Cisco also unveiled a cloud-native firewall that it purpose built for Kubernetes environments. In a blog post, Chandrodaya Prasad, the senior director of product management in Cisco’s Security Business Group, calls Cisco Secure Cloud Native “developer-friendly, and the most elastic firewall we’ve ever built.”

It uses Kubernetes “for orchestration, auto-scaling, auto-healing, and real-time responsiveness to microservices changes,” he added. The cloud-native firewall is first available in Amazon Web Services (AWS).