Hi there, I'm Tom Field. I'm senior vice president at editorial with information security media group topic a conversation today is XDR making defenders lives better It's my privilege to be speaking with Carlos Diaz principal engineer threat detection response with Cisco Carlos Thanks so much for taking time to speak with me. Thank you for inviting me to participate Tom It's a privilege speaking to you today in the audience. We'll start here Cisco HXDR has been on the market for a couple of months now What is the early feedback you get from your customers?
You know overwhelmingly positive Tom in essence, I think the feedback we're getting from our XDR approach is how we've been able to Unify our unique depth and breadth on networking as a discipline for those who may not know You know Cisco's the first company that connected the world for us to be interconnected and enjoying a lot of digital transformation services And we've been able to fuse it with our open system Which basically integrates the existing toolkits of customers things like our endpoint security suites EDR IP your email their firewall appliances and as a consequence of our approach to unified I would realize that essentially we can unify these things into a thought process of clues insights and conclusions We presented them essentially security conclusions from all of these telemetry data sources Which allows them to feel that we have anticipated the normal workloads they take in reviewing alerts investigating them as well as Reaching conclusions faster to take other actions during an incident that might be present So Carlos at the start of the conversation I talked about making defenders lives better with the launch of the solution What is your overall message to these defenders? I think that our overall message that we want defenders to know is that Cisco knows you Cisco knows how to relate to you Cisco understands that in order for defenders to be successful There is no one tool to rule them all is the appropriate coexistence of the defenders entire toolkit That must be pretty much tamed and harmonized all the information so that defenders can have fast ways to investigate those incidents respond You know confidently to symptoms that you're seeing but the most pointed aspect of Cisco to the defender My team and I are working on is We believe that every XDR should not be presenting detections of other products We should be presenting curated insights of the security posture at hand So those defenders at all levels executive as well as tactical can make decisions promptly with confidence Girls want to ask you about some key differentiators of your product first of all talk to me about the ability to remediate the highest priority incidents That's a great question Tom I think in essence one of my colleagues Michael Roytman if you don't know who he is he is a prolific one ability management data scientist that he has been able to Understand the way that the cyber insurance industry. It's modeling today impact and consequential loss So with colleagues like Michael Roytman We have been able to understand these disparate data source I'll tell you about the severity that comes from these particular sources put on top of it analytics such as correlation of these data sources and therefore Understand or derive the potential impact and action ability gives a unique score that's already tailored towards the cyber security industry As far as insurance that's as a unique differentiator that allows us to give defenders a way to purposely tackle alert fatigue You ask about a no differentiator that tackles the issue of product fatigue the ability to not be locked into a single tool set Yeah Well, see I think that we understood as an Organization that there are proven market solutions out there very good at what they do and essentially we put ourselves in the shoes of all The customers we interviewed and it was very clear what customers told us customers told us that they love products by competitors Or you know the industry peers if you will and if those things are working what we really learned from that is that they wanted ways that Your entire portfolio spend can be harmonized so that they can scale their security operations center in Understanding the presence of attacks and the consequences of those attacks when we glean that level of understanding from customer speaking We learned that it doesn't make sense for us to lock a customer to a particular toolkit What makes sense is that we're the bridge to possible of how our tax can be clearly understood Another key point Carlos talked to me about the ability to integrate multiple disparate sources of telemetry and threat detection data into one unified solution Another great question Tom. I mentioned earlier when you kicked off the conversation that we believe in our XDR It doesn't make sense for us to show detections from the source products that are producing them for what we call clues So in essence, we believe in an open integrated model where we let customers basically You know integrate all of their clues from all of their products And it's the equivalent that we learned that if this was a healthcare industry every alert or disparate data source is a simple But the fenders don't thrive by knowing that they are discrete simple But the fenders are trying to understand is are there systemic illnesses in the fleet So by us integrating all of these clues together putting our analytics on top of it is how we can give defenders those Systemic symptoms or illnesses that are being experienced and that way they can make a better decision of the attack or impact your experience Now here's a topic we don't discuss nearly enough in this industry.
It's one of your capabilities the ability to uplevel the capabilities of the SOC analysts Well, having been a former SOC manager senior threat intel person is up leveling is hard. There's a lot of demand for cyber talent It's hard to come by it. We're hoping this problem can get better. I just want to practice that So up leveling to us is the ability that a SOC manager like I was in the past if he or she at the moment has only Three, you know practitioners.
How can the technology vehicle make them feel as if they were a team of six a hundred percent growth And what we've learned there is that if we can make in our technology the expressiveness Expressiveness meaning the way that the incidents are clearly labeled the way that they are presenting then essentially It doesn't really make a SOC manager feel that they don't have enough staff because the technology serves as a compliment to the human And that's what we call explicability And when we put all that together we feel that we uplift sock analysts of any skillset when the technology can clearly in layman's term express that A symptom is present and attack is ongoing or it was detergent mutual lives. That's the way we believe we uplevel anyone working in the SOC Let's talk to you about Cisco. Why do you believe that Cisco is best positioned as a vendor to serve these defenders? I think for me, it's very very clear cut.
We connected the world. Why can't we be the ones to help protect it? Basically at a very upfront with you I think that is the capacity. It's the breadth of the network industry that we have been able to demonstrate in a major thought leader But most importantly when we integrate other data sources it tells that Cisco is a company that has enough breadth from all of the network Integrating endpoint processes identity management solutions We have the capacity to actually deliver those signals in ways that it's proven through our conventional business logs Someone came back to something you said today as well as the first time we talked and we discussed what we wanted to talk about in today's interview You emphasized to me that Cisco XDR says to defenders Cisco knows me when you say that what do you mean?
I mean that when when folks you know customers potential customers in general the community Experiences are technology delivery. They understand that we're bringing technology that anticipates the questions. They're going to ask during an investigation We showed at our XDR Defenders understand that the types of information that we have made available and how we connected them for the response orchestration It shows that we understood the way they behave in order to achieve outcomes with and through others in the IT organization And that's the best way we feel we demonstrate the folks that our workflows our interfaces are not just rich and capable but that they were relatable for seamless or frictionless experience and security operations Carlos been excellent conversation. Thank you so much for your very eloquent response and talking about XDR today Thank you so much Tom Can the topic has been XDR making a defenders alive's better?
You just heard from Carlos Diaz his principal engineer threat and detection of response with Cisco for information security media group I'm Tom Field. Thank you so much for giving us your time and your attention today