Cisco's first-ever "Cybersecurity Readiness Index" revealed that more progress is needed to protect identities, networks, and applications. To better address this need, the vendor today announced the general availability of risk-based authentication and introduced its Business Risk Observability platform at the Cisco Live Amsterdam 2023 event.
The index is based on data from a survey of 6,700 security leaders across 27 global markets. It found respondents selected identity and device management as two of the three top cybersecurity threats, and only 20% of them considered their organizations “mature” in readiness to protect identity.
Cisco noted that threat actors have been increasingly targeting widely-adopted zero-trust technologies such as multi-factor authentication (MFA), while many solutions and authentication controls create too much friction.
To tackle these issues, the networking and security giant rolled out its Duo Risk-Based Authentication that it internally uses to "deliver on [Cisco's] promise of frustrating attackers, but not frustrating users,” Tom Gillis, SVP and GM of Cisco’s Security Business Group, told SDxCentral.
To offer a frictionless experience, Cisco leverages its context, awareness, and ability to understand and assess risk from its Security Cloud security and networking platform, and apply those to the network analytics. This capability allows Cisco to offer functionalities including remembered devices and Wi-Fi Fingerprint, which enable users to authenticate less often in trusted situations.
“It makes a smoother end-user experience, but also applies almost like common-sense logic,” Gillis said.
The Wi-Fi Fingerprint feature allows for setting a baseline for trusted locations without tracking users location to ensure privacy, Cisco Duo Security Advisory CISO J. Wolfgang Goerlich noted in an earlier interview.
“We have the ability to intelligently understand your context, like if you log in and we do a two-factor authentication, and if you're on the same computer, same network, but you want to hop from one application to another, we're not going to prompt you again. … [If] your network has changed, we're going to ask you to re-authenticate,” Gillis explained.
Cisco Duo Addresses MFA FatigueCisco also added verified push capabilities to its “intelligent MFA” to address the MFA fatigue.
When recognizing behavior from known attack patterns or a high volume of MFA push requests – like the measure attackers used to target Cisco last May – Duo will require users to enter a code instead of pushing a confirmation button.
Customers can also make the verified push policy-driven and require a code verification based on a certain application or event, Gillis said.
Cisco also enables users to reset their passwords before they expire to expand its single sign-on (SSO) capabilities.
Business Risk Observability for Application SecurityCisco's survey also found a gap in securing applications and related workloads. It showed only 12% of respondents identified their organizations as "mature" in terms of application security readiness.
Cisco's Business Risk Observability targets this issue by providing a business risk scoring service based on its Kenna Security acquisition in 2021. Kenna Security’s platform uses machine learning (ML) and data science to track and predict real-world exploitations, measure organization risk, and prioritize remediation efforts.
The product integrates the Kenna Risk Meter score distribution with Cisco AppDynamics’ business transitions monitoring and insights, its API and application security capabilities based on its Portshift acquisition, and the Talos team’s threat intelligence.
The service also uses artificial intelligence (AI) and ML on the back end and works with Cisco’s own and third-party vulnerability scanners to provide business risk technical assessment and prioritization, “so the customers can make good business decisions about where to focus on patching and restoring their applications,” Gillis said.
Comments