Hi there, I'm Tom Field. I'm Senior Vice President of editorial with Information Security Media Group. Topic of conversation today is Cisco Cloud Protection. My privilege to be speaking with Sean Bays, his security products marketing with Cisco.
Sean, thanks so much for taking time to speak with me today. Thanks for having me, Tom. So we have seen an unprecedented cloud migration over the past few years, and I know you see organizations across all sectors and sizes, where do you see these organizations struggle most in securing their multi-cloud environments today? Well, Tom, it's a big question.
And if you step back a little bit, and you take a look at it, you have to ask yourself the reason, right, why cloud adoption, right? And the reason is for the agility of flexibility and increased productivity, right? It's a bit of innovation, if you will. And you're seeing that across hybrid, single cloud, multi-cloud environments.
Those benefits have sort of like this unforeseen consequences, complexity at its highest level, right? Because within the cloud, you have ephemeral natures of constructs, they spin up, they spin down. This is what gives us the agility and the flexibility, and the increased productivity. So visibility becomes a really, really big issue.
Understanding what's going on across my environment. In my cloud environments, yes, but still on-prem, right? And in my private cloud, because those are still part of the equation, that's not going anywhere. And so the idea is to be able to securely scale, but in order to do that, with so many things, you need to understand what you have first, right?
So visibility is the key. Consistency is another issue. How do I maintain security consistency across my data center, my private, public cloud environments? And then how do I meet compliance needs?
Because that's massively important. Just internal compliance requirements and external compliance requirements. And then with speed, you start to see all of the automation and the development of applications and cloud native applications. So manual security practices and processes, they're having a hard time keeping up with the speed of innovation, if you will.
So Sean, if we tackle visibility, how would you say Cisco is helping customers gain comprehensive visibility and improve deficiencies across these environments? So I'm going to step back again for a moment and say, hey, historically, what security has done to address these types of issues is we've created a single product that will be created to address one use case or area, right? Perhaps visibility of an application or visibility in an asset. The problem is that you start to get a multitude of these point-point products and then large organizations will inherit more and you start to get sort of a brittle security stack, if you will, where they're doing their jobs right, but because of the manual processes, because of the multitude of tools, you'll actually have configuration issues, right?
And then you'll have new blind spots or gaps between the tools and you have new silos to come up. It's not that the tools aren't doing their jobs right, is that you get so many, right? That you almost get, you get inconsistent, right? Or even conflicting information for your visibility.
So what we've done is we've stepped back and we've designed a flexible framework to address multi-cloud security, hybrid multi-cloud security to be proper. And there are different layers of visibility. It can even say unparalleled in this sense because what we've done is we've brought together different aspects to address large use cases and give our customers visibility across the spectrum so they can understand what are my applications really doing? What are those workloads that run the applications doing?
Who are they talking to? Are they supposed to be talking to that other application, right? Or that production server or even that user device? And understanding what each one of those are doing, not just in the cloud but on-prem and in the private cloud as well.
And then giving them the visibility and their vulnerabilities across their entire environment clouds and on-prem data centers again, visibility. Understanding what their cloud native applications and assets are doing. Even as they're spun up maybe for an hour, maybe for a day, maybe for Black Friday, right? It's not for a wholesale.
Just for, you know, today's sale maybe, you've got all these new constructs that are there, but you need to be able to track these and understand what they're doing in order to secure them. So we're bringing all this to bear holistically and you also have to secure the traffic to and from the clouds and between what we call the virtual private clouds. Think of clouds as a gated community and with the negated community you have virtual private clouds which are like the houses, right? And you've got to secure those houses.
You're not securing with the gated community but you've got to get those houses secured because that's yours. John, you mentioned vulnerabilities. Talk about how you're helping customers to utilize a data-driven approach to threat prioritization and of course problem remediation. Well, there's vulnerabilities, I hate to say but they're everywhere, right?
Operating system state is what have you. So what we do is we take a risk-based approach to this and we look at it holistically. Again, on-prem and across clouds, right? Across your clouds.
And we bring in global threat intelligence from 19 exploit and threat intel feeds and 19 billion security events. And we take over 12 billion managed vulnerabilities and we match those with your, we bring in feeds from your infrastructure, your application, the internet of things, okay? And we run this against algorithms and patented processes powered by data science and machine learning to get predictive modeling. All right, so that was a lot of words.
But the point being is we've got all this information, this great information in that we bring in across your environments. And we run it against these algorithms. The point being is we want to help security practitioners do more with less so they can prioritize their vulnerabilities. So that if I take care of these top 100 or 95 or 50 even vulnerabilities, then the 10,000 vulnerabilities downstream will be affected in a positive way.
Does that make sense? It does. And Chris, I'm thinking we covered a lot in just a short period of time here. We started this conversation by talking about where organizations struggle.
If you were to sum it up, how is Cisco most helping customers today respond directly to their cloud security challenges? So what we've done is we brought together a flexible framework of solutions to address the entire gamutive issues. No, I'm not saying every issue out there, right? But at the end of the day, it's your applications and data that power your business.
We need to protect those applications in the cloud on-prem and as they maybe are distributed across clouds in on-prem. And this framework, what it does is it enables business growth. So we integrate with existing automation toolchains, right? CICD toolchains, for example, for developers.
Security wants to become a enabler, not a blocker for innovation for the business. So we have to help those businesses scale up, down, sideways, wherever they need to go. Some of those applications that are on-prem, for example, they're perfectly good. There's nothing wrong with them.
But they're not cloud native, but they need to protect those. So we have a solution for that. And some of those applications will scale in across clouds. So part of our solution handles that as well, from a common interface.
And then they'll have new applications and cloud native constructs. And we make sure they understand what's going on there and that they can see the constructs within match it to best practices and understand the compliance needs there. And while all that's going on, you need to ensure that your traffic tuned from clouds between clouds, that that's all secure. One of the issues out there right now is that every cloud provider has its own dialect, its own language, if you will, almost, right?
And so when you go to an Amazon or an Azure, you are having to provision security in their dialect. And so you need the expertise and training to do that. And you're having to do it manually almost. So what we've done with one of our innovations is we actually have a single interface, if you will, where you can now manage all of your clouds from and your cloud traffic to and from those clouds between the VPCs to protect the workloads and the applications that are running there.
And what that does is it simplifies your cloud operations massively and it reduces your overhead, your training, which brings greater efficiencies and less configurations, which means greater efficacy. All right, Sean, if you were to sum it up in a word or phrase or sentence, what would it be? Cisco cloud protection. It provides complete protection from ground to cloud.
Very well said. Sean, I appreciate your time today. Thanks for speaking with me. Thanks for sharing your insights.
Thank you very much, Sean. Thanks for having me. Again, the topic has been Cisco cloud protection. You've just heard from Sean Bays.
He's been a security product marketing at Cisco for an information security media group. I'm Tom Field. Thank you so much for giving us your time and your attention today.