{"id":13325,"date":"2024-09-19T19:01:23","date_gmt":"2024-09-19T19:01:23","guid":{"rendered":"https:\/\/dmsretail.com\/RetailNews\/reimagining-zero-trust-with-in-office-experience-everywhere\/"},"modified":"2024-09-19T19:01:23","modified_gmt":"2024-09-19T19:01:23","slug":"reimagining-zero-trust-with-in-office-experience-everywhere","status":"publish","type":"post","link":"https:\/\/dmsretail.com\/RetailNews\/reimagining-zero-trust-with-in-office-experience-everywhere\/","title":{"rendered":"Reimagining Zero Trust With In-Office Experience, Everywhere"},"content":{"rendered":"<p> <p><a href=\"https:\/\/dmsretail.com\/online-workshops-list\/\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-496\" src=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png\" alt=\"Retail Online Training\" width=\"729\" height=\"91\" srcset=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png 729w, https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90-300x37.png 300w\" sizes=\"auto, (max-width: 729px) 100vw, 729px\" \/><\/a><\/p><br \/>\n<\/p>\n<div>\n<p><strong>Let\u2019s be honest. Most people don\u2019t trust zero trust.<\/strong><\/p>\n<p>For users, when they hear the words \u2018zero trust\u2019, it sounds like it might take longer to log into work. And if you\u2019re in IT or IT security, you may have more products to buy and integrate into your existing \u2014 already complicated \u2014 security stack. And of course, then there are the audits.<\/p>\n<p>Maybe that\u2019s why so many zero trust projects are stalled.<\/p>\n<p>No matter how you slice it, zero trust access is an elusive but desirable goal for many organizations, and yet most teams haven\u2019t achieved zero trust maturity<sup>1<\/sup> \u2014 especially for securing remote work.<\/p>\n<p>At Cisco, we have designed our solution in a way that overcomes common obstacles by powering a secure, in-office experience anywhere. And we know because we have been on our own zero trust journey with our user communities and IT teams for years now.<\/p>\n<h2><span style=\"color: #6abf4b;\"><strong>Cisco on Cisco: Zero trust access at scale<\/strong><\/span><\/h2>\n<p>We started with an enterprise rollout of Cisco Duo for our remote-first workforce back in 2020, and we are currently deploying Cisco Secure Access. Cisco\u2019s massive and diverse IT infrastructure includes:<\/p>\n<ul>\n<li>1 million IP connected \u201cthings\u201d<\/li>\n<li>27,000 Cisco video devices<\/li>\n<li>62,000 mobile devices<\/li>\n<\/ul>\n<p>\u2026across large campuses, small offices, homes, customer sites, roaming users, and more<strong>.<\/strong><\/p>\n<h3><span style=\"color: #6abf4b;\"><strong>Rapid time to value<\/strong><\/span><\/h3>\n<p>During our first phase in 2020, we rolled out Duo for phishing-resistant multi-factor authentication (MFA) and device posture across our vast user community in only 5 months, which substantially reduced helpdesk tickets and endpoint compromises.<\/p>\n<p>More recently, we deployed Cisco Secure Access, our Security Service Edge (SSE) solution which is optimized for helping ease the transition from legacy VPN architecture to Zero Trust Network Access (ZTNA) with VPN-as-a-Service (VPNaaS). We\u2019re just getting started, but we\u2019ve already seen value.<\/p>\n<p>Because Secure Access eliminates the need for multiple teams to analyze networking and security data, and because it sidesteps complex tasks like IP-user mapping, we\u2019ve seen a <strong>25%<\/strong> reduction in mean time to troubleshoot user connectivity issues. In the past, a single region on-prem VPN enablement process would take weeks to a month. Now by using the VPNaaS capability inside of Secure Access, our teams can enable <strong>5 regions in just 3 hours<\/strong>.<\/p>\n<h3><span style=\"color: #6abf4b;\"><strong>Rapid time to productivity<\/strong><\/span><\/h3>\n<p>Here\u2019s what it\u2019s like for a typical Cisco remote-first employee:<\/p>\n<ul>\n<li>Whether at their breakfast table or in the office, they login \u2018passwordlessly\u2019 on their laptop (via Windows Hello or Mac TouchID) and then Cisco Duo \u2014 behind the scenes \u2014 takes that OS-level trust to all use cases (cross-browser, embedded browser).<\/li>\n<li>By being fully context-aware, Cisco Duo recognizes this as typical user activity, reducing user interaction needed for authentication. That said, any changes to device posture and other contextual risk attributes will prompt our users to reverify trust via risk-based authentication (e.g., Verified Push).<\/li>\n<li>Remote workers can automatically and transparently access every needed application, some by ZTNA, others by Cisco\u2019s VPN-as-a-Service. They don\u2019t even have to think about how they will access an app \u2026 it just works, thanks to Cisco Secure Access.<\/li>\n<li>When our employees are off our corporate network, their internet access is transparently protected by a variety of integrated cloud-delivered security tools providing DNS-layer security, secure web gateway, CASB, DLP, remote browser isolation and more.<\/li>\n<\/ul>\n<p>\u00a0<\/p>\n<figure id=\"attachment_462848\" aria-describedby=\"caption-attachment-462848\" style=\"width: 744px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-462848\" src=\"https:\/\/storage.googleapis.com\/blogs-images-new\/ciscoblogs\/1\/2024\/09\/zero_trust_access_provides_seamless_user_experience-300x146.jpg\" alt=\"Zero trust access provides a seamless user experience:, with a graph showing the experience\" width=\"744\" height=\"362\" srcset=\"https:\/\/storage.googleapis.com\/blogs-images-new\/ciscoblogs\/1\/2024\/09\/zero_trust_access_provides_seamless_user_experience-300x146.jpg 300w, https:\/\/storage.googleapis.com\/blogs-images-new\/ciscoblogs\/1\/2024\/09\/zero_trust_access_provides_seamless_user_experience-1024x499.jpg 1024w, https:\/\/storage.googleapis.com\/blogs-images-new\/ciscoblogs\/1\/2024\/09\/zero_trust_access_provides_seamless_user_experience-768x374.jpg 768w, https:\/\/storage.googleapis.com\/blogs-images-new\/ciscoblogs\/1\/2024\/09\/zero_trust_access_provides_seamless_user_experience-1536x748.jpg 1536w, https:\/\/storage.googleapis.com\/blogs-images-new\/ciscoblogs\/1\/2024\/09\/zero_trust_access_provides_seamless_user_experience-2048x997.jpg 2048w\" sizes=\"auto, (max-width: 744px) 100vw, 744px\"\/><figcaption id=\"caption-attachment-462848\" class=\"wp-caption-text\">Secure, in-office experience for Cisco\u2019s remote-first workforce \u2014 fast, easy app access from everywhere<\/figcaption><\/figure>\n<p>\u00a0<\/p>\n<h2><span style=\"color: #6abf4b;\"><strong>Challenges with early SSE products<\/strong><\/span><\/h2>\n<p>Sadly, the first-to-market SSE solutions weren\u2019t designed for the remote-first workplace. Instead, most of these vendors started as point products (e.g., CASB, NGFW, SWG, etc.) and then bolted-on additional functionality to qualify as SSE vendors and grab zero trust budget.<\/p>\n<p>The underlying architecture is brittle as a result, with a disjointed and siloed management experience and a lack of identity- and context-awareness. These challenges slow down zero trust adoption, making it difficult for teams to deliver the same consistent and secure experience for all workers connecting to all kinds of applications.<\/p>\n<ul>\n<li><strong>Lack of visibility: <\/strong>Who are my users, what are they accessing, which policies are required, which devices are managed vs. unmanaged, what is their end-to-end digital experience?<\/li>\n<li><strong>User frustration:<\/strong> High latency, dropped connections, confusing authentication and app access workflows, and inadequate performance \u2014 even with common office applications \u2014 and no way of knowing where the performance issues lie<\/li>\n<li><strong>Complicated management:<\/strong> Multiple agents, consoles and policies make it more difficult to enforce the right zero trust access policy everywhere<\/li>\n<li><strong>Costly surprises:<\/strong> Organizations can\u2019t simply stop supporting VPN, as some apps do not work well with ZTNA; plus, evolution to zero trust on your own schedule is a better approach than being pushed into a risky VPN rip-and-replace<\/li>\n<\/ul>\n<p>Given the challenges with these solutions, it\u2019s no surprise that organizations are struggling with their zero trust initiatives. End users and IT teams alike need a better zero trust experience.<\/p>\n<h2><span style=\"color: #6abf4b;\"><strong>Cisco Zero Trust Access<\/strong><\/span><\/h2>\n<p>Our Cisco Zero Trust Access solution is different: Our architecture is purpose-built to <em>provide an in-office experience, everywhere<\/em>. It\u2019s a force multiplier, as it delivers the industry\u2019s most easily managed strong identity security, coupled with leading Security Service Edge (SSE) capabilities.<\/p>\n<p><strong>Beyond happy users, these are the ways your IT and IT security teams will benefit:<\/strong><\/p>\n<ul>\n<li><strong>SSE deployment is eased with a single client <\/strong>\u2014 The multi-functional Cisco Secure Client is a single installer, helping to enhance interoperability and lower cost. Its modular features include ZTNA, VPNaaS and off-corporate-network SWG and DNS-layer security protection.<\/li>\n<li><strong>More secure \u2014 and simpler \u2014 multi-factor authentication<\/strong> \u2014 Today, attackers often do not hack into enterprises \u2014 they simply log in. Duo evaluates identity behavior and attributes before, during and after login to ensure secure access and adjust authentication strength automatically based on contextual risk.<\/li>\n<li><strong>Fewer support calls <\/strong>\u2014 Unlike other ZTNA solutions using legacy protocols with performance limitations, Cisco\u2019s underlying internal transport (Vector Packet Processing, or VPP) is faster and more reliable with modern protocols including QUIC and MASQUE.<\/li>\n<li><strong>No management updates, no site visits<\/strong> \u2014 <u>All elements<\/u> of the Zero Trust Access solution are cloud-managed, and, aside from client activity, all security is cloud-delivered, globally.<\/li>\n<li><strong>Ongoing management simplified<\/strong> \u2014 Compared to solutions that have separate consoles for internet access security, ZTNA, and VPN, Cisco\u2019s Zero Trust Access collapses these functions into one, increasing visibility, enabling more comprehensive security policies, and saving you precious time.<\/li>\n<li><strong>Superior mobile support <\/strong>\u2014 Our partnerships with leading mobile device manufacturers, like Apple and Samsung, have led to industry-first operating system-level integration for more dependable connectivity.<\/li>\n<\/ul>\n<h2><span style=\"color: #6abf4b;\"><strong>Start making zero trust easier, effective and efficient<\/strong><\/span><\/h2>\n<p>Only Cisco Zero Trust Access provides strong identity security coupled with a comprehensive, easy-to-manage SSE. This enables you to deliver a consistent in-office experience everywhere, ensuring that security does not hinder productivity.<\/p>\n<p>And because our Cisco Secure Access SSE solution has not only ZTNA, but integrated VPNaaS as well, you can undertake your zero trust journey on your timeline, not one that is dictated by the limitations of other vendors.<\/p>\n<p><strong>Discover more about Cisco Zero Trust Access, and how it can transform your security approach, by registering for an upcoming <\/strong><strong>workshop<\/strong><strong> or exploring a product <\/strong><strong>tour<\/strong><strong> of Cisco Secure Access.<\/strong><\/p>\n<p>\u00a0<\/p>\n<p><small><sup>1<\/sup>Based on research from Cisco\u2019s latest Security Outcomes for Zero Trust report<\/small><\/p>\n<hr\/>\n<p style=\"text-align: center;\"><em>We\u2019d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Security on social!<\/em><\/p>\n<p style=\"text-align: center;\"><strong>Cisco Security Social Channels<\/strong><\/p>\n<p style=\"text-align: center;\"><strong>Instagram<\/strong><br \/><strong>Facebook<\/strong><br \/><strong><a href=\"https:\/\/twitter.com\/CiscoSecure\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a><\/strong><br \/><strong>LinkedIn<\/strong><\/p>\n<p>Share:<\/p>\n<p>\n  \t<\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><script async defer src=\"https:\/\/platform.instagram.com\/en_US\/embeds.js\"><\/script><br \/>\n<br \/><p><a href=\"https:\/\/dmsretail.com\/online-workshops-list\/\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-496\" src=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png\" alt=\"Retail Online Training\" width=\"729\" height=\"91\" srcset=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png 729w, https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90-300x37.png 300w\" sizes=\"auto, (max-width: 729px) 100vw, 729px\" \/><\/a><\/p><br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Let\u2019s be honest. Most people don\u2019t trust zero trust. For users, when they hear the words \u2018zero trust\u2019, it sounds like it might take longer [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":13326,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-13325","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts\/13325","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/comments?post=13325"}],"version-history":[{"count":0,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts\/13325\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/media\/13326"}],"wp:attachment":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/media?parent=13325"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/categories?post=13325"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/tags?post=13325"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}