Amid an uptick in security threats targeting modern applications, Cisco launched the Cisco Secure Application (formerly known as Security Insights for Cloud Native Application Observability), a new module built on its Full-Stack Observability Platform and designed to expand the business intelligence risk insights into the cloud environment.

Cisco’s recent research revealed that 92% of surveyed technologists worldwide admitted that the rush to meet customer demands has compromised application security during software development. A recent Red Hat study showed 93% of surveyed companies had a Kubernetes security incident in the past year.

The Cisco Secure Application aims to address these challenges by delivering visibility and actionable business risk observability to the hybrid cloud environment.

Earlier in February, Cisco introduced business risk observability as an enhancement to its Full-Stack Observability application security solution, now part of the Cisco Full-Stack Observability Platform, based on its existing visibility and security capabilities.

It “provides a business risk scoring solution that brings together Kenna Risk Meter score distribution and Business Transactions from Cisco AppDynamics, and also integrates with Panoptica for API security and Talos for threat intelligence,” Liz Centoni, Cisco EVP and chief strategy officer, wrote in a blog post.

The function has been for more traditional application platforms like .NET framework, Java and Node.js, Carlos Pereira, fellow and chief architect of Cisco’s strategy, incubation and applications, told SDxCentral. “What this launch now brings to the table is that same functionality for everything cloud native.”

“Now we bring Cisco intelligence to make what's the likelihood of exploitation in real time, data threat response and map this to the business impact,” he added.

How Cisco Secure Application works

Besides the product integrations from business risk observability, the Cisco Secure Application also relies on Panoptica for both API security and container and serverless runtime security. The new function enables users to:

  1. Locate and highlight: It can identify and highlight security issues across application entities such as containers, pods and business transactions.
  2. Prioritize: Use a business risk score to prioritize issues based on application performance data and potential business impact context from Cisco’s cloud-native application observability and security products.
  3. Accelerate: The function is designed to speed up the security incident response time with real-time remediation guidance on how to address the most impactful vulnerabilities.
The security and observability convergence

The new Cisco Secure Application serves a wide range of stakeholders within an organization, from the CISOs to DevSecOps teams, Pereira noted.

While the CISO office may use the business risk observability for compliance and risk analysis, DevSecOps can integrate it into their pipelines for both pre- and post-deployment application visibility and remediation automation decisions, he added.

“I feel even more strongly that observability and security are coming together,” Pereira said. “One of the reasons is because both look the same, similar data; logs are a classical example.”

“I believe the buyer is less concerned, the user who owns the operation is going to use those tools [like Cisco Secure Application],” he added. “I see more of this is being used for the DevSecOps, the ITOps people that want to make sure that I have visibility out to applications in the business.”