Cisco Telemetry Broker and Cisco SecureX – The Future of Security Analytics

I recently attended the informative Cisco presentation at Data#3’s JuiceIT digital, entitled: Telemetry Architecture – The Future of Security Analytics. TK Keanini, CTO of the Security Business Group at Cisco, spoke about the “The big picture” where he said, “Telemetry feeds analytics and analytics delivers outcomes.”

This really resonated with me, as telemetry is one of the key, if not the key ingredient when it comes to gaining visibility in your environment so you can protect against cyberthreats and orchestrate your response.

Today, it is not uncommon for multiple solutions (or telemetry consumers) to require the same information. This can lead to complex configuration on a telemetry provider to accommodate this and in many cases, it is not possible at all.  With trends such as remote working and digital transformation now a reality, it’s become imperative that security technologies and teams do not work in a silo. Not only do security solutions have to work with one another to adequately defend today’s networks, but they must also work with other technologies. In the IT and networking realms, integration fosters the automation and collaboration levels necessary to effectively and efficiently defend against ever-changing threats.

We know that threats can slip through gaps in coverage and that they can get lost amidst siloed telemetry, give conflicting alerts and that security teams simply don’t have enough resources to deal with them, even when they’re identified. This is an industry problem of not enough eyes on the screen and complex remediation processes.

How do you get more visibility into your environment and reduce the level of complexity?

The answer is security through insights – and what better way to get insights than through your own telemetry data. This is where Cisco Telemetry Broker comes into play. The Cisco Telemetry Broker provides you with the ability to not only broker your telemetry, but also filter and transform, allowing you to gain control over what telemetry is sent and how. These very insights can then be used to practically secure your environment by utilising tools such as Cisco SecureX.

You may be asking yourself what does SecureX have to do with Telemetry?

That is a great question. Cisco SecureX is a cloud-native tool that connects to the entire Cisco Secure Platform. A direct feed from the Cisco Telemetry Broker into Cisco SecureX enables visibility into your environment and allows you to react proactively to cyberthreats.

By connecting all of the solutions in your Cisco security portfolio and many additional security, IT, and networking technologies from both Cisco and third parties, Cisco SecureX substantially decrease the manual steps necessary for detecting, investigating and remediating attacks. The goal is to simplify security via a single console that streamlines operations and conserves resources. This enables traditionally separate solutions and teams working together for a more robust defence against ever-increasing cyberthreats.

When we break this down to ensure we meet this goal, we look at visibility with context first. Cisco SecureX provides unified visibility with a customisable dashboard that allows you to maintain context around security incidents. This is important if we access our organisations’ readiness to respond to threats. That brings us to our second goal – accelerated threat investigations and incident management through aggregating and correlating global telemetry and local context all into a single view.

These goals allow you to orchestrate your responses and enable your teams to automate routine tasks using prebuilt workflows that align with everyday use cases or to build your own workflows with the no-to-low code, drag-and-drop canvas within Cisco SecureX.

What are the key capability takeaways of Cisco SecureX?

There is a ton of functionality that Cisco SecureX can provide your organisation. In fact, too much to cover in one blog. However, let’s break down the key capability takeaways of Cisco SecureX:

  • Visibility with Context – Context created through other security solutions to strengthen protection against cyberthreats
  • Threat Response – Adds context from Cisco security products to accelerate response
  • Orchestration – Easily automate to specific use cases
  • Integration – Cisco SecureX does not just work with Cisco Solutions, it works with third party solutions too.

Why Data#3?

One of the areas that we focus on in our Security Practice at Data#3 is helping our customers to gain the visibility required to derive actionable intelligence that can be used to proactively secure their environment. I have seen how Cisco Telemetry Broker and Cisco SecureX can achieve this for our customers and we want to make sure you do to.

As part of JuiceIT, Data#3 is offering a 90-day free trial of Cisco Telemetry Broker and a free Cisco SecureX activation for up to 30 customers.

We will work with you to activate up to three Cisco security solutions on the Cisco SecureX platform.  This includes a workshop, technical discovery session and the activations.

As a Cisco Gold Partner, Data#3 is the safe pair of hands to help with your ever-changing security environment. Please reach out to your Data#3 account manager to take advantage of this offer.

Tags: Cisco, Cloud Security, Cybersecurity, JuiceIT, JuiceIT 2021, SecureX



Why would you deploy SASE?
If Secure Access Software Edge (SASE) with Cisco Meraki is the destination, what does the journey to get there look like?

Firstly, let’s set the scene. The term SASE was first mentioned by Gartner Analysts in July 2019 and Gartner continues…

Data#3 named (HPE) Platinum Partner of the Year and Aruba GreenLake Partner of the Year
Data#3 enjoys double scoops at HPE/Aruba awards night

December 08, 2022; Brisbane, Australia: Leading Australian technology services and solutions provider, Data#3, is proud to announce that it has…

Azure BaaS
Protecting Data in a Cloud World: Will Backup as a Service be what Keeps Your Business Online Through a Crisis?

Very few organisations could run in a technology-free environment, so naturally, strong IT departments put considerable effort into business continuity…

Azure Site Recovery
Beyond Backup: The Role of Azure Site Recovery in Business Continuity

In the first of our Azure Backup blog series, we discussed the value of data, and the critical importance…

Delivering the Digital Future, Securely – for Western Australia
Delivering the Digital Future, Securely – for Western Australia

Data#3, proudly sponsored by Cisco, Microsoft and Palo Alto Networks, are pleased to present to you: Delivering the Digital Future,…

K-12 Video Period
Securing the school network amidst escalating threats

Security threats are now a routine problem for increasingly connected education institutions. The good news is that a new generation…

Protecting Data in a Cloud World: What You Need to Know About Azure Backup

Welcome to part 1 of our 3-part blog series, exploring data protection options and considerations for when you’re operating in…

The Southport School Revisited
The Southport School: Four Years On

How have their investments in wireless networking and security paid off after four years? Download Customer…