Formerly known as Wikibon

Cisco’s Security Strategy Shifts Toward AI Trust and Infrastructure-Level Enforcement

Cisco is advancing a security strategy designed for an environment in which AI agents, applications and infrastructure interact at machine speed. In a conversation at Cisco GSX, Peter Bailey, senior vice president and general manager of Cisco Security, described a platform approach that brings together networking, security, identity and Splunk observability. Key elements include security embedded directly into network infrastructure, centralized policy with distributed enforcement, and just-in-time identity controls for AI agents and machines.

The strategy addresses a practical enterprise challenge: traditional security architectures were built primarily for human users, relatively predictable applications and traffic patterns that could be routed through centralized inspection points. AI changes those assumptions. Agentic systems act autonomously, communicate across a growing set of tools and data sources, and may generate significantly more east-west traffic. Securing that environment will require controls that are faster, more distributed and more context-aware.

Platform Momentum Reflects Demand for Consolidation

Cisco entered its fiscal 2027 year with momentum in security, following 14% year-over-year growth in fourth-quarter security bookings to $2.2 billion. Bailey attributed that progress partly to Cisco’s expanding platform strategy, including the integration of Splunk and more recent investments in identity.

Many enterprises continue to operate fragmented security environments with different products, policy engines and operational teams. That fragmentation increases overhead and can produce inconsistent controls. A platform can simplify operations, but consolidation alone does not guarantee better outcomes. The value depends on how effectively products share context, coordinate policy and support cross-functional workflows. “We’re having customers that are buying multiple products across the family,” Bailey said. “It’s also a lot easier, frankly, to sell a platform attach than it is to sell point to point.”

For customers, the relevant measure will not be the number of products assembled under one portfolio. It will be whether the platform reduces complexity, improves visibility and shortens the time required to identify and contain risk.

Security Moves Closer to AI Workloads

One of Cisco’s central architectural arguments is that security must be distributed closer to applications and workloads. As AI adoption increases east-west traffic inside data centers, routing traffic through centralized appliances for inspection can add latency and create potential bottlenecks.

Cisco’s Smart Switch represents an early implementation of this approach. By embedding Layer 3 and Layer 4 firewall capabilities into the switch, Cisco aims to provide stateful inspection and segmentation at line rate. Hypershield, which Bailey said had recently become generally available, provides core technology for this distributed model. “Security can’t be an add-on, can’t be an afterthought, [and] has to be designed into the architecture,” Bailey said. “We need to be able to run at machine speed [with] autonomous policy response.”

The potential business benefit is the ability to strengthen security without forcing enterprises to choose between protection and application performance. Centralized policy combined with distributed enforcement could also help organizations apply more consistent segmentation across data centers, campuses, branches and workloads.

Distributed enforcement expands the number of control points, making policy consistency, change management and visibility essential. The architecture must demonstrate line-rate performance, predictable behavior and integration with existing environments.

AI Agents Require a New Identity Model

AI agents introduce a different security problem from conventional human or machine identities. Agents may make non-deterministic decisions, access multiple resources and execute actions far faster than human operators. Existing access models often rely on standing privileges or long-lived credentials, increasing the potential impact of a compromised or misbehaving agent.

Cisco’s response emphasizes authentication, least-privilege authorization, behavioral monitoring and just-in-time access. Its announced partnership with Teleport is intended to add privileged-access capabilities based on short-lived cryptographic credentials for machines and agents. A credential can be issued for a specific task and then expire, reducing the persistence of access. “The mindset has to shift,” Bailey explained. “We need to understand how to authenticate an agent, be able to authorize it to do certain things, watch its behavior, and take action if it does something different.”

This is a logical extension of Zero Trust. Rather than treating an authenticated agent as permanently trustworthy, organizations will need to evaluate its identity, intended purpose, requested resource and current behavior continuously. That becomes especially important as Model Context Protocol, or MCP, connects agents to tools, databases and services.

Bailey outlined several inspection points for agent activity, including endpoints, proxies, gateways and switch infrastructure. A comprehensive strategy will likely require multiple layers, particularly across hybrid and multicloud environments.

From Security Control to AI Business Enabler

The most significant takeaway is that security is becoming a prerequisite for realizing returns on enterprise AI investments. Business teams want to deploy AI quickly, while security leaders must manage data exposure, misuse and autonomous actions. If organizations cannot establish confidence in how agents operate, promising AI initiatives may remain stuck in pilots or face limits that constrain their value.

Cisco refers to the desired outcome as AI trust: confidence rooted in identity, visibility, enforcement and observability. Its network, security and Splunk assets provide useful building blocks. The challenge will be turning them into a coherent operating experience.

Enterprise buyers should look for evidence in four areas: consistent policy across domains, measurable reduction in operational complexity, machine-speed detection and enforcement, and clear governance for agent identities and actions. They should also assess interoperability, because most large organizations will continue to operate heterogeneous estates.

Why It Matters

AI is not simply adding another application workload. It is changing the speed, volume and autonomy of enterprise activity. Security architectures designed around centralized inspection and human-paced decisions will struggle to keep up.

Cisco’s direction reflects a broader industry shift toward security embedded in infrastructure, informed by shared context and enforced wherever workloads and agents operate. If the company can deliver that model consistently across networking, identity, security and observability, it could help customers reduce friction between AI adoption and risk management. Ultimately, that will be the test of the strategy: whether stronger security accelerates responsible AI deployment rather than becoming another obstacle to it.

For more information on Cisco’s Security Strategy, please visit the website.

Article Categories

Join our community on YouTube

Join the community that includes more than 15,000 #CubeAlumni experts, including Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger, and many more luminaries and experts.
"Your vote of support is important to us and it helps us keep the content FREE. One click below supports our mission to provide free, deep, and relevant content. "
John Furrier
Co-Founder of theCUBE Research's parent company, SiliconANGLE Media

“TheCUBE is an important partner to the industry. You guys really are a part of our events and we really appreciate you coming and I know people appreciate the content you create as well”

Book A Briefing

Fill out the form , and our team will be in touch shortly.
Skip to content