
Overview
Beyond Identity Secure Access is the first Secure-by-Design IAM solution that defends against modern threats with security guarantees.
It delivers a security-first SSO, phishing-resistant MFA, visibility and control over managed and unmanaged devices, robust integrations, and protections over generative AI fraud.
For mid-sized organizations, Secure Access provides the unified platform you need to safeguard authentication and access with robust integrations that help you get more value out of your existing tooling.
For enterprise organizations, Secure Access delivers a modular platform to support your specific needs for authentication, device security, and SSO or supplant existing solutions that fall short on their security promise.
Please reach out for custom and volume-based pricing via Private Offer at https://www.beyondidentity.com/get-demo
Highlights
- Validates a user identity and its association with a verified device that meets security policy to deliver trusted authentication and enforces continuous, risk-based authentication.
- Enables password elimination. Replaces passwords with an authentication platform rooted in asymmetric cryptography leveraging proven standards (including x.509 certificates and the TLS protocol) without any certification management required.
- Provides zero friction, secure digital access for employees, contractors, and developers. It is the 1st foundational step toward today's Zero Trust Security strategy.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Trust Center
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
- Small Market Bundle | Customizable SMB Bundle | $10,000.00 |
- Authentication Essentials | Includes: Phishing-Resistant MFA, Access360, Device 360, Premium Support for up to 1,000 users | $36,000.00 |
- Zero Trust Identity & Device | Includes: Zero Trust Authentication, Access360, Premium Support for up to 1,000 users | $96,000.00 |
- Secure Access Complete | Includes: Secure SSO, Zero Trust Authentication, Access360, Premium Support for up to 1,000 users | $144,000.00 |
Dimensions summary
Top-of-mind questions for buyers
Vendor refund policy
N/A
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Support
Vendor support
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.


Standard contract
Customer reviews
Unified cloud security has simplified zero trust access and protected hybrid users
What is our primary use case?
My main use case for Cisco Secure Access is for one client, where I deployed DNS security. Previously, Cisco DNS security was part of Umbrella; now, it has been moved to Cisco Secure Access. I implemented DNS security, which provided the client with cloud-based DNS security and intelligent proxy features, so they are protected from day-zero attacks with policy management in place. That was one use case for Cisco Secure Access, and for another client, I have recently deployed ZTNA using Cisco Duo MFA.
For a specific example of how I used Cisco Secure Access for one of these clients, I will provide the example of one client where I deployed ZTNA through MFA. The client has around 1500 users working in a hybrid environment, so connecting every user on the VPN, whether hardware-hosted, VM-hosted, or anywhere else, causes unnecessary burden. SASE is the best use case of Cisco Secure Access in the hybrid environment, where if users want to access any of their private applications, they connect to Cisco Secure Cloud. From the cloud, the traffic is tunneled, providing zero-trust access and requiring MFA to access any internal application. This way, since it is cloud-based security, the routing and everything is taken care of in the cloud, avoiding dependency on hardware infrastructure or overusing the link in the data center itself.
What is most valuable?
The best feature that Cisco Secure Access offers is a single platform where DNS security, ZTNA, and everything are in one place, all managed through a single cloud dashboard.
Having everything in a single platform and dashboard has made things easier for me and my clients because everything is available for checking or troubleshooting.
Cisco Secure Access has positively impacted my organization because we are Cisco preferred partners. We deploy everything for our clients, so it is not just about deploying it in our organization. Since we are a preferred partner, many clients requiring Cisco Secure Access are routed to us from Cisco.
After deploying Cisco Secure Access, I received specific positive outcomes and feedback from my clients. For the use case concerning DNS security over the last three months, their AD integration with Cisco Secure Access allows them to create user-based policies for DNS security based on identity and username. They also receive a dashboard to monitor reports on threats and everything online in the cloud. The customer is very happy that they are able to overview their organization, seeing the number of users utilizing maximum applications, the top talkers, and everything.
Cisco Secure Access has greatly impacted protecting my organization and clients from threats such as phishing and ransomware. Because it has ZTNA and is cloud-based with VMs deployed inside the network, it creates best practice tunnels required for accessing applications from day one. Thus, we can deploy with peace of mind without juggling best practices or opening only specific ports.
What needs improvement?
Cisco Secure Access can be improved by providing information about the location of the PoPs where users are connected. The guidelines in KSA say it is mandatory for the PoPs to be regional, similar to how Fortinet SASE discloses its PoP locations.
In terms of needed improvements around documentation and support, the documentation has been good for me. Since I deployed for the first time, I went through Cisco documents, which helped me a lot, and their program on the T-Cloud labs also provided great support. Completing the lab gave me the confidence to deploy for the customer. The documentation and the labs provided by Cisco are very good.
For how long have I used the solution?
I have been using Cisco Secure Access for the last six months.
What other advice do I have?
For others looking into using Cisco Secure Access, my advice is that it is a good solution and they should experience it.
I chose eight out of ten primarily due to only the PoP presence. I would rate the ease of managing Cisco Secure Access through its single cloud-managed console an eight.
In my experience, it is easy to navigate and manage everything from the console, but compared to the FortiGate SASE platform, FortiGate has a unified platform for all their products, while Cisco has each platform operating differently.
I use the Zero Trust Network Access (ZTNA) feature of Cisco Secure Access, and it is a great feature. We do not need to worry about the security of accessing applications from outside the environment. With ZTNA, each application access requires authentication, which is a truly great feature.
This ZTNA approach has positively changed my client's security posture, and there are no significant challenges or surprises. I rate this product eight out of ten.
Zero trust access has strengthened identity-based segmentation and simplified multi-tenant management
What is our primary use case?
I am dealing with Cisco Secure Access products. As a consultant and reseller, I am using it myself with Cisco Secure Access.
You can have tenants with Cisco Secure Access. Tenancy is obviously part of it, so you can have multiple tenants on Secure Access. Especially if you're a managed service provider, you can have multiple tenants where you just have to flip the feature and specify which tenant you're working in. I've used that before to manage multiple infrastructures, and all you have to do is change the tenancy. That is quite useful. It used to be like that for Umbrella as well. Cisco basically just translated it back to Secure Access, so the same feature on Umbrella is on Secure Access as well. We have used it.
How has it helped my organization?
It's a best practice recommendation to have Cisco Secure Access integrated with Cisco ISE. With that integration, you can do your segmentation using security group tags and create a micro-segmentation setup with more security. We do that integration.
It's very useful because you can have visibility, especially in terms of logging and knowing who's doing what with Cisco Secure Access. If you have integration with Cisco ISE, then you have a name to traffic. You can have an identity that shows who is doing this, because it's integrated to your Azure network, your Google Cloud, or Active Directory. This makes investigation easier. Additionally, you can do your segmentation based on users and other criteria.
What is most valuable?
I think Zero Trust Access for application is the feature I find most valuable in Cisco Secure Access.
I only use Cisco Secure Access' AI Access feature for troubleshooting. It has a log feature, and there isn't really any AI element in that. The AI feature is more having an AI tool at the top where you can ask a question to get visibility. You can ask what a log means or ask a question that you want the AI to answer for you. There's an AI icon at the top of the bar, and then you can ask questions. That's basically where the AI feature is. There's no AI in terms of the telemetry unless you ask the AI feature to do it for you. If you want the AI element for that, there's another feature that Cisco has that you have to add as a feature add-on.
Cisco Secure Access has a VPN as a service feature. You have that Zero Trust as well because it's almost a VPN but just for applications. You access the application encrypted, but you don't need a VPN tool to connect. You can just access the application, which is what Zero Trust basically is. If you want VPN as a service, Secure Access has it. If you want to allow remote access for a certain application, then you do the Zero Trust setup, which is also a VPN but you don't need a VPN client to make it work.
Most of the time, I recommend my customers to use Cisco Secure Access' Experience Insights feature for Branch Access, which is basically when you want to tunnel all your traffic. You probably have a gateway in a branch and then you create a tunnel with Secure Access and then you send all clients through that tunnel to Secure Access. Everything including web traffic can be visible. You can also use it for VPN. You can use it to protect applications like I mentioned earlier about Zero Trust. You want to create an application that users can access remotely without using a VPN client, then you can do a Zero Trust setup. You can also do a proxy setup where you send all your internet traffic through Secure Access. These are the four features that I like about Secure Access.
I use Cisco Secure Access' Hybrid Private Access feature for varying the enforcement location for ZTNA private traffic. ZTNA is Zero Trust Networking, the private one.
The policy verification feature helps reduce policy misconfigurations in Cisco Secure Access where you can check to make sure that all your policies are intact. That is something we definitely use, especially if you have a lot of rules going on. You want to make sure that your rules are intact and you don't have any conflicts going on anywhere. That is a feature I always recommend.
What needs improvement?
I think the AI element of Cisco Secure Access is just asking logs, and I think the AI element can certainly be improved. The first question about how AI can enhance telemetry, that feature is not really there. You do have some kind of AI type element in it, but it's not advanced enough. That's where it's lacking. It's quite good because it's cloud-based. Pricing is also an area for improvement. It is really expensive.
For how long have I used the solution?
I have been dealing with Cisco Secure Access for about two years.
How are customer service and support?
If you log a ticket with Cisco, they usually come back really quick. I would say nine out of ten.
What's my experience with pricing, setup cost, and licensing?
The pricing is not too bad because it's per headcount with Cisco Secure Access. You check how many clients you have. If you have 500 users, then you base your pricing on that. It's still expensive though. It's an expensive tool to have. I think they can do better in price. There are companies with better pricing options.
Which other solutions did I evaluate?
FortiGate cloud solution is what I usually recommend instead of Cisco Secure Access. They have something similar as well. If a customer says that Secure Access is too expensive for themselves, I recommend FortiGate because they're not too bad in pricing.
What other advice do I have?
The AI element of Cisco Secure Access should have better guidance on the logs. To be honest, I can't think of anything else because it's quite a robust feature. My overall review rating for Cisco Secure Access is nine out of ten.
Granular access control has protected critical media workflows and now secures high‑stakes events
What is our primary use case?
My main use case for Cisco Secure Access is especially for our security purposes as it provides secure access to only the permitted applications. We work on many applications where different teams come together. They are responsible for different clusters, different domains, different applications, and we are always in a requirement to have the selected level of access to a particular set of people. For that, Cisco Secure Access is a super tool to work with.
Initially, VPNs were used, but the problem with VPNs was that it provides access all at once, and then we cannot continuously perform those verifications.
In my day-to-day operations, we in Synamedia have three business units responsible for three different things: one is control plane, we are into the data plane, and there is a network team as well. Collectively, we are supporting a customer called Astro. There are different applications hosted on the same Kubernetes cluster. The thing is these are different BUs, so we are bound with the responsibilities and our action should be very much limited. To have a better solution where we can ensure that the right set of people have the right set of privileges and access, we have created Cisco Secure Access for different users accordingly. If anything needs to be done on the control plane side of things, that particular team can do it. If it requires only access to the data plane into the Kubernetes clusters, then the people in my team have those accesses, so they cannot touch on the control plane side, and the control plane team cannot touch on the data plane.
The third team, which is on the network side, we don't want to expose our data plane and control plane to them and want to keep the network very much secure with them. So all of us are using the same platform, but we have limited or restricted access, and that's why we can collectively work better ensuring that we are not encroaching into different territories, and everything works very smoothly.
Recently, we conducted the Olympics, where we had teams from Synamedia, Alibaba, and their affiliates, Mina Tech, involved. Since a lot of revenue is involved, it was an Olympic thing, and we cannot risk security. That's why we went with our Cisco Secure Access. Initially, Synamedia was itself Cisco, and then it moved out as a media domain out of Cisco. To ensure that there is a good level of security and proper access, the particular teams which are supposed to perform necessary actions and need to put their scripts on the platform were taking care of that specific domain. The beauty of that is every time you enter into any platform, you have to go through a series of authentication that needs to be handled appropriately. If you fail, then that particular person cannot enter the platform, making it super secure. With events such as NBAs and Olympics, we want it to be very much secured as there are hackers looking for ways to access our system. In that scenario, it becomes very important that we keep all our clusters, platforms, and applications secured with a trusted solution, and that's why we have gone for Cisco Secure Access.
What is most valuable?
I rely on continuous verification and application access the most in my day-to-day work. There are hundreds and thousands of applications running that need to be safe. We cannot just provide access to people since it's a very secured environment; a small mistake can cause bigger problems. Specifically, we operate at three levels on the same platform: Tier 1, responsible for basic monitoring; SROs who are more advanced engineers performing routine actions; and SREs with root privileges. Now, we can create three layers of access: Tier 1 gets access for monitoring only; SROs have privileges for a certain number of applications; and SREs have full access to do whatever is required, ensuring the people with the correct skill set and knowledge have the right access level. With most people working from home, it is crucial to protect our secure data from hackers and malicious attacks because they can exploit systems to bring the entire chain down quickly. It helps that there is a defined process with a series of sequences that need to be followed for logging in, and even post-login, there is a second layer of control ensuring privileges are used correctly without allowing mistakes that could cause platform blunders.
There is a very common threat that happened three or four years back which was ransom. People were knocking into platforms using credentials and taking over servers. An incident happened at MediaKind where they had an attack from a ransom that froze the origin server. Origin server freezing means all data comes from there, and if hackers compromise that and stop streaming, it can collapse the entire media stream, resulting in huge losses for broadcasters and advertisers. MediaKind faced this for around 30-40 minutes because they used the normal VPN. We quickly realized that this wasn't going to work because VPN just uses credentials that anyone can exploit. Later, we moved to Cisco Secure Access, which goes through MFA. You log into a client, then enter Microsoft Entra ID, followed by MFA, and you authenticate through your phone and authenticator. There are policy engines and ZTNA, and only then you can log into applications and perform tasks.
In my opinion, Cisco Secure Access offers excellent features, starting with application-level access, not network access, where each time a particular application needs to be accessed, there is a provision for that instead of giving entire network access. The verification feature is nice as it doesn't work as a one-time authenticator, but a continuous verification process occurs. It's more into a zero-trust model, where if it identifies a deviation, it will not let you go in. Everything is centralized and very secure, considering it's on the cloud.
What needs improvement?
There are times when Cisco Secure Access feels slow; it takes multiple attempts to log in, which can definitely improve. Even using the same password, it may fail at times, and then you get logged out after some time. I would prefer a faster login experience. Also, it only allows connecting to one environment at a time, which can be a challenge during dynamic expansions. If a solution could allow logging into multiple environments simultaneously before disconnecting from one, it would be great. For example, if we handle ten customers and three have issues, we must connect, check, disconnect, and then repeat for the next, which could be streamlined.
The overall experience with Cisco Secure Access is good, but the UI could use some enhancements; it's simple and somewhat outdated. Additionally, having alerts for malicious login attempts that trigger on team channels could really help the team.
For how long have I used the solution?
I have been using Cisco Secure Access for almost eight years, six years here and two years in Ericsson.
What do I think about the stability of the solution?
Cisco Secure Access is quite stable.
What do I think about the scalability of the solution?
Its scalability is excellent, as it handles member logins instantaneously.
How are customer service and support?
Customer support for Cisco Secure Access is very good. After facing an issue recently, I would rate customer support an eight out of ten.
Which solution did I use previously and why did I switch?
Before Cisco Secure Access, we were using VPNs, but we switched because it wasn't very secure; any exposed username and password posed a security threat.
What was our ROI?
We haven't broken down to the level of measuring ROI yet, but in terms of investment, it's been decent. We save effort, not just money, as it simplifies control and management. Previously, we managed numerous licenses for the same set of tasks, whereas with one license from Cisco Secure Access, we can multitask, providing application-level access and proper authenticators, making it a super tool overall.
What's my experience with pricing, setup cost, and licensing?
The pricing, setup cost, and licensing for Cisco Secure Access are quite reasonable by market standards, considering the wealth of features we receive; this is a critical factor for us in ensuring security at a reasonable price.
Which other solutions did I evaluate?
We evaluated other options, including F5 and FortiClient, but found that they were not as good compared to Cisco Secure Access.
What other advice do I have?
For those looking into using Cisco Secure Access, I would say it's a very good solution that fulfills your security needs. Cisco Secure Access is a good tool. I would give this product a rating of nine out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Centralized zero trust access has improved secure remote work while AI consistently strengthens oversight
What is our primary use case?
My main use case for Cisco Secure Access is providing secure remote access to internal applications while enforcing Zero Trust security policies. For example, in a lab environment, I used it to securely connect to internal web applications without exposing them directly to the internet. I also used its Secure Web Gateway to monitor and filter web traffic based on organizational policies. Day-to-day, it helps ensure that only authenticated and authorized users can access specific resources, improving security while maintaining a smooth user experience for remote users.
One thing I appreciated about my main use case and the authentication process with Cisco Secure Access was how it centralizes access management and security policies in a single platform. Once authentication and access rules were configured, day-to-day administration became much simpler. It also provided good visibility into user access and security events, making it easier to identify and investigate potential issues. Overall, it improved security without creating unnecessary friction for end-users, which was one of the biggest advantages.
What is most valuable?
The standout features of Cisco Secure Access are its Zero Trust Network Access, ZTNA, Secure Web Gateway, and multi-factor authentication, MFA, integration. I also appreciate its centralized policy management, which makes it easy to enforce consistent security rules across users and devices. The detailed visibility into user activity and security events helps with monitoring and troubleshooting. Additionally, its cloud-based architecture provides secure access for remote and hybrid users without relying on traditional VPNs, making it both scalable and easy to manage. Overall, these features significantly improve security while maintaining a smooth user experience.
Compared with similar secure access solutions, Cisco Secure Access stands out because of its tight integration with the Cisco security ecosystem and its unified cloud-native platform. Instead of managing multiple separate tools, administrators can enforce consistent security policies from a single console. I also found the Zero Trust approach and detailed visibility into user activity to be stronger than many traditional VPN solutions. These features make it easier to secure remote users while simplifying management, making the platform a good fit for organizations with hybrid or distributed workforces.
What needs improvement?
Cisco Secure Access is a strong platform, but there are a few areas that could be improved. The initial setup and policy configuration can be complex, especially for organizations new to Zero Trust architecture. The user interface could be more intuitive, making advanced features easier to locate and configure. Reporting and analytics could also provide more customizable dashboards and detailed insights. Providing broader integration and simpler troubleshooting guides would help administrators resolve issues more quickly and improve the overall management experience.
I think Cisco Secure Access could benefit from deeper integrations with a wider range of third-party identity providers, SIEM platforms, and endpoint security solutions to simplify deployment in mixed-vendor environments. I would also like to see more built-in troubleshooting tools and guided policy recommendations, which would reduce the learning curve for new administrators and make ongoing management more efficient.
The reporting tools and third-party integrations could be more flexible and user-friendly. These are areas for improvement, but they do not outweigh the platform's overall strengths and value.
For how long have I used the solution?
I have been using Cisco Secure Access for approximately six months.
How was the initial setup?
The authentication process for users in Cisco Secure Access was generally straightforward and easy to configure. Integrating it with an identity provider and enabling multi-factor authentication, MFA, was smooth, and the user onboarding experience was simple. The main challenge was configuring access policies correctly for different user groups during the initial setup, as it required careful planning and testing. Once those policies were in place, authentication became reliable and seamless. Overall, the setup was manageable, and the platform provided a secure, yet user-friendly login experience.
What other advice do I have?
I would confidently recommend Cisco Secure Access to organizations looking to modernize secure remote access.
Cisco Secure Access has a strong approach to AI governance and security. I appreciate that its AI-driven capabilities are supported by Zero Trust principles, identity-based access controls, and continuous monitoring. The platform provides good visibility into user activity and helps detect suspicious behavior while maintaining strict security policies. From a governance perspective, centralized policy management and detailed audit logs support compliance.
I believe there is still room for improvement.
I find the AI capabilities of Cisco Secure Access to be accurate and reliable for most security-related tasks. The platform consistently identifies potential threats, provides relevant security insights, and helps prioritize alerts, which reduces manual effort for administrators. In my experience, the recommendations are generally actionable and aligned with security best practices. While no AI system is perfect and some alerts may require manual verification, the overall accuracy is high enough to improve operational efficiency and support faster decision-making. I would consider its AI output trustworthy for day-to-day security operations. I gave this review a rating of 9.
Secure access has strengthened DNS protection and unified threat visibility for our environment
What is our primary use case?
I have been working with Cisco Secure Access for the past five years. We have multiple use cases for Cisco Secure Access, with most of them associated with DNS filtering security. We use it as a replacement for secure internet, providing web filtering. Instead of giving a web filtering or proxy solution, we provide it as a DNS filtering solution where it helps us to stop the traffic even before reaching the malicious server. In normal traditional proxy solutions, end user traffic generated from the system and endpoints reaches the malicious or unauthorized servers, and then while getting a response back to the end-user machine, the proxy blocks that particular request or response sent from the server. In this case, what Cisco is providing is a DNS security advantage license and a security gateway. They have a higher role where they can control the traffic when the traffic is generated from the end-user endpoint machine itself. That itself is an advantage for controlling our traffic to the public IP of the malicious and unauthorized servers. That is one key advantage which we have for this use case.
We also provide secure access for people who want to access the internal application from outside. We give AnyConnect, which checks whether they are connecting to the network from the proper device assigned to them. If not, we can block that particular device for a time interval if we see that the device is vulnerable. These are the kinds of use cases we are working with Cisco Secure Access.
What is most valuable?
Cisco Secure Access ZTNA feature helps in securing standard applications because it actually monitors every given interval as we configure. It checks for the security posture at every interval even after the device is connected. If a device gets connected and infected through some kind of malicious software or by using pen drives, it eventually gets isolated when Cisco Secure Access ZTNA finds that it does not fall under the given compliance. We have to give some security checks, and based on those checks, it will verify the security posture in ZTNA.
Cisco Talos influences threat detection and response capabilities in the organization because Cisco Talos is a threat intelligence machine for the Cisco brand. They have integrations with Talos in all the solutions, whether it is EDR, Umbrella, or SecureX. Basically, they provide integrations with each and every engine, and the point I want to make is that Talos intelligence is inbuilt within Cisco Secure Access itself.
SecureX incorporates all the other Cisco products. SecureX covers integration with all the Cisco solutions provided. For example, we can integrate SecureX with EDR, XDR, Cisco Secure Access, switches, routers, and Cisco firewalls, including email security solutions. In a Cisco environment, we can have full visibility, and this is what I see when protecting against threats such as phishing and ransomware—Cisco Secure Access is effective.
What needs improvement?
There is one particular disadvantage of Cisco Secure Access, and the main thing is pricing. Apart from that, I do not think it has any other disadvantage. One more thing adding to that is that in some cases, for some of our clients, we have issues with latency while they are accessing their internal resources from their home locations. However, we were able to address it partially with the help of Cisco documentation.
Managing Cisco Secure Access through a single cloud-managed console is neither very easy nor very complex. It is acceptable, but they can improve the simplicity of the console.
Pricing and simplicity could be improved, but I do not see any other main parts for improvement with Cisco Secure Access.
For how long have I used the solution?
I have been working with Cisco Secure Access for five years now. Overall in the business, I have eight years of experience.
What do I think about the scalability of the solution?
Cisco Secure Access is a cloud solution, so it is pretty much scalable.
How are customer service and support?
Cisco customer service is average. It is neither good nor bad. I would rate Cisco customer service five out of ten points. For the support, I would say they could be faster. Two or three years ago, Cisco support was very good, rated around eight or nine, but now the support engineers seem unaware of what their product is capable of. I have seen issues where I needed to explain use cases multiple times and escalate them multiple times to get solutions, leading me to rate them five now.
How was the initial setup?
Cisco Secure Access installation process is quite straightforward, but we do have to do some manual work such as preparing a script.
What was our ROI?
If you have a Cisco environment, it will give the best ROI. Everything must be of Cisco product family only, starting with EDR, XDR, mail security, switches, firewalls, and access through ZTNA. If you have every solution with Cisco, you can see a very good ROI because you do not need to invest much on staffing for analyzing each and every console separately. Everything will be monitored, and all those logs from various Cisco solutions will be coming under one console, which helps in clarifying what we have and any security loopholes in our environment that security teams need today.
I cannot quantify ROI specifically, such as ten percent or twenty percent, as it varies based on the environment. For a fully Cisco environment, it could be around sixty percent to seventy percent ROI or more, but if it is not a fully Cisco environment, it would be much less due to various integrations with other third-party solutions, which are not at a very granular level. Therefore, the ROI is greater with more Cisco solutions and less with fewer solutions.
Which other solutions did I evaluate?
While comparing Cisco Secure Access with competitors, Trend Micro would be an exact competitor. Trend Micro gives many solutions under a single console, such as Trend Vision One, and they have also incorporated AI security. However, when it comes to XDR solutions, there are several in the leader quadrant such as SentinelOne and CrowdStrike, but SecureX has not emerged as a leader in the XDR space. Cisco Secure Access itself is good, as we have not seen any attacks in Cisco environments, but as per compliance, we should not rely on a single vendor in our environment. Trend Micro is a leader quadrant product and has been a major provider for many enterprise banks, especially in large enterprises, making it one of the good competitors for Cisco Secure Access.
For the CASB functionality with Cisco Secure Access, I have not worked that much on CASB for Cisco Secure Access. When it comes to CASB, we have solutions such as Forcepoint, CloudSEK, Netskope, or Zscaler. With these products, we have plenty of CASB use cases. I have not worked with Cisco Secure Access on CASB.
What other advice do I have?
I mentioned both the advantages and the use cases of Cisco Secure Access. Usually, what we do is block QUIC traffic because the QUIC traffic is based out of UDP on port 443. By initially blocking QUIC protocol traffic, if the customer specifically asks, we will enable QUIC traffic for particular applications alone. Since it is part of best practice, we usually block it. However, in some use cases, we have enabled the QUIC protocol and provided bypassing instructions for those UDP protocols. The basic reason we block QUIC protocols is that it is a safe encrypted protocol. We cannot inspect QUIC traffic using inspection engines in web proxy or SecureX, as established with HTTPS and HTTP. That is why we prefer to block QUIC protocols, but it does work well when enabled. I give this product an overall review rating of eight.