New Cisco AI Assistant looks to drive cloud security automation
The Cisco AI Assistant for Security is the latest automated tool launched by big tech security vendors this year
Cisco has unveiled the launch of a new AI assistant to support security practitioners and automate key processes.
The Cisco AI Assistant for Security marks a “major step in making artificial intelligence pervasive in the security cloud”, the tech giant said.
The AI tool is capable of understanding and supporting security event triage practices, assisting in policy design, and conducting root cause analysis in the wake of an incident.
The firm said this will enable security practitioners to make more informed decisions, augment capabilities and automate complex tasks in their daily workflows.
In addition, the tool is trained on one of the largest security-focused datasets in the world, drawing upon more than 550 billion security events each day spanning the web, email, endpoints, networks, and applications.
Jeetu Patel, executive vice president and general manager of security and collaboration at Cisco, said the launch of the new AI tool will greatly enhance security practitioner efficiency and reduce workloads.
“Today’s announcement is a monumental step forward,” he said. “This advancement will help tip the scales in favor of defenders, empowering customers with AI built pervasively throughout the Cisco Security Cloud.”
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
“To be an AI-first company, you must be a data-first company. With our extensive native telemetry, Cisco is uniquely positioned to deliver cybersecurity solutions that allow businesses to confidently operate at machine scale, augmenting what humans can do alone.”
Cisco AI Assistant for Security: Key features
Key features and capabilities of the AI tool outlined by Cisco include automated firewall support. The assistant will first go live within the firm’s cloud-delivered Firewall Management Center and Cisco Defense Orchestrator.
This will enable administrators to use natural language to curate policies and establish rule recommendations, the firm said. In addition, admins can use the tool to rectify misconfigured policies, improve workflow visibility, and streamline configuration activities.
"Using natural language, an administrator can iterate with the AI Assistant to do things like discover and identify all the policies that control access to an application, define a new policy or rule for the administrator, and implement the policy," Patel said in a blog post.
"The AI Assistant can also identify duplicate or misconfigured security policies from amongst thousands of existing policies and make recommendations for resolving them."
The AI assistant will also help users to improve data center traffic encryption processes through the Encrypted Visibility Engine.
RELATED RESOURCE
Discover how IBM watsonx.data supports a range of current standard technologies for moving, handling, and accessing data
DOWNLOAD NOW
The service analyzes billing of samples, including sandboxed malware samples, to establish if encrypted traffic is transporting malware. AI tools will support administrators using the platform, and improve broader operational security, Cisco said.
“Most data center traffic today is encrypted and the inability to inspect encrypted traffic is a key security concern,” the firm said. “Decrypting traffic for inspection is resource-intensive and fraught with operational, privacy and compliance issues”
AI security tools experiencing a renaissance
Cisco is the latest in a slew of security firms to provide AI-powered tools so far in 2023. Microsoft unveiled its Security Copilot for customers in March, and was hailed as a potential game changer by industry stakeholders.
In May, CrowdStrike unveiled a new generative AI security tool aimed at driving efficiency for frontline practitioners.
The Charlotte AI security assistant operates across the company’s suite of security and threat intelligence platforms to help analysts identify emerging threats and bolster productivity.
The tool provides security analysts with real-time, prompt-based insights into security threats and provides natural language recommendations to mitigate risks.

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.
He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.
For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.
-
Microsoft unveils Maia 200 accelerator, claiming better performance per dollar than Amazon and GoogleNews The launch of Microsoft’s second-generation silicon solidifies its mission to scale AI workloads and directly control more of its infrastructure
-
Infosys expands Swiss footprint with new Zurich officeNews The firm has relocated its Swiss headquarters to support partners delivering AI-led digital transformation
-
Thousands of Microsoft Teams users are being targeted in a new phishing campaignNews Microsoft Teams users should be on the alert, according to researchers at Check Point
-
Microsoft warns of rising AitM phishing attacks on energy sectorNews The campaign abused SharePoint file sharing services to deliver phishing payloads and altered inbox rules to maintain persistence
-
Microsoft just took down notorious cyber crime marketplace RedVDS – and found hackers were using ChatGPT and its own Copilot tool to wage attacksNews Microsoft worked closely with law enforcement to take down the notorious RedVDS cyber crime service – and found tools like ChatGPT and its own Copilot were being used by hackers.
-
These Microsoft Teams security features will be turned on by default this month – here's what admins need to knowNews From 12 January, weaponizable file type protection, malicious URL detection, and a system for reporting false positives will all be automatically activated.
-
Cisco says Chinese hackers are exploiting an unpatched AsyncOS zero-day flaw – here's what we know so farNews The zero-day vulnerability affects Cisco's Secure Email Gateway and Secure Email and Web Manager appliances – here's what we know so far.
-
The Microsoft bug bounty program just got a big update — and even applies to third-party codeNews Microsoft is expanding its bug bounty program to cover all of its products, even those that haven't previously been covered by a bounty before and even third-party code.
-
Researchers claim Salt Typhoon masterminds learned their trade at Cisco Network AcademyNews The Salt Typhoon hacker group has targeted telecoms operators and US National Guard networks in recent years
-
Microsoft Teams is getting a new location tracking feature that lets bosses snoop on staff – research shows it could cause workforce pushbackNews A new location tracking feature in Microsoft Teams will make it easier to keep tabs on your colleague's activities – and for your boss to know exactly where you are.