TechValidate Research on Cisco Secure Endpoint

These pages present data that TechValidate has sourced via direct research with verified customers and users of Cisco Secure Endpoint. TechValidate stands behind the authenticity of all published data. Learn more »



1,530 Customers Surveyed

11,558 Data Points Collected

186 Published TechFacts

14 Published Charts

28 Published Case Studies



Featured Research Collections for Cisco Secure Endpoint

Curated collections and slideshows of TechValidate research data on Cisco Secure Endpoint.



Selected Research Highlights


Cisco Advanced Malware Protection Customer Research

Better Together: AMP for Endpoints + AMP for Email Strengthens Security

AMP for Endpoints enables my organization to:

Improve security effectiveness
88%
Detect threats faster
86%
Increase visibility into potential threats
79%

Cisco Advanced Malware Protection Case Study

HCL Technologies

Introduction

This case study of HCL Technologies is based on a March 2017 survey of Cisco Advanced Malware Protection customers by TechValidate, a 3rd-party research service.

“Deploying AMP for Endpoints alongside other AMP deployments has helped my organization uncover threats faster and improve overall security effectiveness.”

“Organizations today are under the constant threat of cyber attack and security breaches happen every day. Given today’s threat landscape, ‘point-in-time’ technologies, such as sandboxes or antivirus are only one part of a required solution since advanced malware can evade these defenses. Cisco AMP has provided the visibility, context, and control to not only prevent cyber attacks, but also rapidly detect, contain, and remediate advanced threats from they evaded front-line defenses and get inside.”

“AMP detected 100% of exploits in testing, demonstrating its leadership in identifying the malicious software used to breach and compromise systems. AMP detected 99% of Web-based malware delivered via browsers and 98% of malware using e-mail to enter organizations. AMP detected malware employing every evasion technique tested, such as code designed to defeat sandbox and virtual machine based analysis and detection. AMP delivered faster time to detection than all other vendors.”

Challenges

The business challenges that led the profiled company to evaluate and ultimately select Cisco Advanced Malware Protection:

  • Chose AMP for Endpoints for the following reasons:
    • Superior protection from advanced threats and hackers
    • Rapid time to detection of threats
    • Endpoint visibility into file activity and threats
    • Ability to continuously monitor file behavior
    • Retrospective alerting to uncover stealthy attacks
    • Ability to quickly understand the threat and what it’s trying to do
    • Simple, easy to use management interface

Use Case

The key features and functionalities of Cisco Advanced Malware Protection that the surveyed company uses:

  • Deployed the following in addition to AMP for Endpoints:
    • AMP for Networks (AMP on Cisco Firepower NGIPS)
    • AMP for Firewall (AMP on a Cisco ASA or NGFW Firewall)
    • AMP for Web (AMP on Cisco WSA, AMP on Cisco CWS)
    • Cisco Threat Grid

Results

The surveyed company achieved the following results with Cisco Advanced Malware Protection:

  • Was able to do the following with AMP for Endpoints:
    • Improve security effectiveness
    • Detect threats faster
    • Increase visibility into potential threats
    • Remediate advanced malware
    • Accelerate incident response
  • Evaluated the following companies prior to signing up with AMP for Endpoints:
    • TrendMicro
    • Symantec
    • McAfee
  • Prevented/Detected/Defeated the following with AMP for Endpoints:
    • Advanced malware or advanced persistent threats (APTs)
    • Zero-day threats
    • Drive-by-attacks
    • Malicious email attachments
    • File-less or memory-only malware
  • Reduced threat detection time by by more than a month with AMP for Endpoints.
  • Experienced improvements in the following areas after deploying AMP for Endpoints:
    • Mean time to detection of previously unseen and/or unknown threats
    • Breach probability and business risk
    • Organization’s security posture
    • Executive confidence in the security of the organization
    • Investigation speed and/or quality
    • Visibility into endpoints, vulnerabilities, and threats
    • Time to remediation

Cisco AMP for Endpoints Case Study

S&P 500 Telecommunications Services Company

Introduction

This case study of an S&P 500 telecommunications services company is based on a January 2020 survey of Cisco AMP for Endpoints customers by TechValidate, a 3rd-party research service. The profiled company asked to have their name blinded to protect their confidentiality.

“AMP for Endpoints has greatly expedited our incident response efforts by providing forensic data we didn’t have access to with other products.”

Challenges

The business challenges that led the profiled company to evaluate and ultimately select Cisco AMP for Endpoints:

  • Invested in Cisco AMP for Endpoints because they:
    • Needed to protect against advanced threats
    • Needed tools to enhance their threat hunting capabilities
    • Watned better forensics and visibility into what was happening on the endpoint on an alert
  • Considered the following vendors before selecting Cisco AMP for Endpoints:
    • Microsoft
    • Symantec
    • TrendMicro

Use Case

The key features and functionalities of Cisco AMP for Endpoints that the surveyed company uses:

  • Other Cisco Security products used in addition to Cisco AMP for Endpoints:
    • Umbrella
    • Email Security
    • NGFW (Next-Generation Firewall)
    • DUO (Multi-Factor Authentication/MFA)
    • AnyConnect
  • Rates Cisco AMP for Endpoints on the following features:
    • Antivirus feature: blocking known malware: extremely satisfied
    • Exploit prevention feature: protecting against file-less malware: extremely satisfied
    • Threat detection and response feature: continuous file monitoring (file and device trajectory): extremely satisfied
    • Threat intelligence: ability to understand unknown threats to their environment: extremely satisfied
    • Multi-platform/OS support: extremely satisfied

Results

The surveyed company achieved the following results with Cisco AMP for Endpoints:

  • Most prominent benefits realized from their investment in Cisco AMP for Endpoints:
    • Realized better overall protection/prevention against file-less malware, ransomware, and other advanced threats
    • Experienced faster and more accurate threat detection and remediation
    • Experienced faster, more effective incident response
    • Enhanced threat hunting capabilities
  • Experienced the following after implementing Cisco AMP for Endpoints:
    • Improved threat detection and remediation speed and quality: 50% to 74%
    • Improved incident response speed and effectiveness: 50% to 74%
  • Cisco AMP for Endpoints helped their security team to better protect their environment from:
    • Zero-day threats
    • Ransomware
    • Cryptomining
  • Their confidence in protecting their endpoints against malware and other threats has improved now that they have Cisco AMP for Endpoints as part of their security strategy.
  • Reduced their time to detection of threats by more than a day after implementing Cisco AMP for Endpoints.

Cisco AMP for Endpoints Customer Testimonial

Overall, the speed and effectiveness of investigating and pinpointing the origin of security incidents has greatly improved. Integration with other Cisco services has already aided in recent events.

Network Administrator, State & Local Government

Cisco Advanced Malware Protection Customer Testimonial

Cisco AMP has enabled my team to immediately respond to potential and real threats in a faster, more efficient manner. Additionally, this product proved, upon installation, to quickly quarantine threats.

Charles Brown, Network Manager, Arkansas Highway & Transportation Department

Cisco AMP for Endpoints Customer Research

In addition to Cisco AMP for Endpoints, what other Cisco Security products are you currently using?

AnyConnect
64%
Umbrella
62%
ISE (Identity Services Engine)
48%
NGFW (Next-Generation Firewall)
46%
Email Security
40%
Threat Response
38%
Threat Grid
28%
DUO (Multi-Factor Authentication/MFA)
27%
Stealthwatch
21%
I don’t own any of these Cisco Products
4%
Other
3%


More to Explore



About Cisco Secure Endpoint

The sooner threats are detected, the faster businesses can recover. Secure Endpoint offers advanced endpoint protection across control points, enabling your business to stay resilient.

Cisco Secure Endpoint Website   Cisco Website