30 Minutes to
a more secure
enterprise.
Why Cisco Umbrella is the simplest decision you
can make to improve your company’s security.
You have to make some serious security decisions when you’re an
IT leader. That’s because both the volume and sophistication of
attacks are intensifying relentlessly — and it’s clear that conventional
defenses alone are no longer adequate. More effective blocking of
attackers is particularly important because under-the-radar attacks
are wreaking havoc on enterprises that rely on antivirus products,
firewalls, and sandboxing alone.
• S
top command-and-control (C2) callbacks and data
exfiltrations — even if you haven’t yet noticed or pinpointed a
compromised internal host
• D
ramatically reduce security incidents and alerts by
proactively neutralizing them before they occur
Multiple fragmented internet connections are ith a cloud security platform, management of
W
difficult to secure. DNS requests can be unified and secured across
all endpoints.
Enterprise Enterprise
Roaming location B
ISP? ISP2 ISP? Roaming location B ISP2
laptops Internal Windows
DNS server laptops Internal Windows
DNS server
Remote Enterprise
Enterprise
sites location C Remote
Internal BIND server location C
sites
ISP3 Internal BIND server
ISP? ISP3
ISP?
This multidimensional attack would itself be secure VPN connections back to the enterprise),
troubling enough for IT security leaders. However, and an often overwhelming volume of security alerts
the heightened risk caused by new kinds of generated by the multiple generations of “point”
attacks is exacerbated by changes taking place security solutions that IT has accumulated over time.
in the enterprise itself. These changes include an
expanding threat surface, the growing tendency of The bottom line: IT security leaders are looking for
mobile users to connect directly to cloud resoures more effective security strategies that don’t add
via unsecured public Wi-Fi (rather than through complexity to their security operations.
Attacks never get a chance to carry out their malicious work, because
they never touch the network, endpoints, or any protected remote user
outside the corporate network.
91%
of C2 can be
blocked at the
DNS-layer
15%
SWG
Cloud or of C2 bypasses
on-prem web ports 80 & 443
Infected device
• A
decade of DNS leadership. anomalies. In fact, the automated
Ten years of hands-on generation of malicious
experience working with DNS infrastructure by attackers has
technology and data gives Cisco become so commonplace
Umbrelsignificant advantages that it’s not anomalous at all.
when it comes to understanding That’s why Cisco Umbrella has
how both legitimate and developed highly specialized
nonlegitimate parties register models that block 7 million
domains, provision infrastructure, malicious destinations at any
and route IP traffic over the given time — and that often
autonomous system life cycle. detect them before any other
security provider on the planet.
• U
nmatched DNS data volume
and variety. The accuracy and • N
o added latency, 100%
completeness of any analytic uptime service. As a DNS
OpenDNS is the leading
outcome is largely contingent provider, Cisco Umbrella has
provider of network
upon the quality, volume, and crafted a highly resilient network security and DNS services,
completeness of the data environment that boasts 100% letting you connect to the
inputs. As a DNS provider, Cisco uptime since 2006. We also internet with confidence.
Umbrella processes 80 billion peer with more than 500 of
DNS requests for 65 million users the world’s leading internet
and 12,000 businesses every service providers and content
day. By combining that data with delivery networks to ensure
third-party feeds, Cisco Umbrella that our response times are
possesses unmatched visibility some of the fastest worldwide.
into DNS activity worldwide. Use of Umbrella does not add
any latency to our customers’
• D
ifferentiated algorithms and network performance — and
analytics. The statistical models in many cases performance is
required for truly effective and even better than that of their
predictive DNS-layer security incumbent regional provider.
go far beyond simply spotting
Malware
C2 Callbacks
Phishing
Umbrella
HQ BRANCH ROAMING
A mere 30 minutes from now, any business can be more secure than it
was before. That’s the simple reality of DNS-layer security.
60K+ daily malicious destinations
indentified
1. L
ancope Research. “Visual Investigations of Botnet Command and
Control Behavior.” 2013.
80M+ blocked
daily malicious requests
© 2016 Cisco and/or its affiliates. All rights reserved. Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the
U.S. and other countries. To view a list of Cisco trademarks, go to this URL: www.cisco.com/go/trademarks. Third-party trademarks mentioned are the
property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1110R)