
The Cisco BPT-SEC-ESS brings together key security capabilities within a single subscription to help organisations detect, investigate and respond to cyber threats across endpoints, email and connected environments. It provides centralised visibility into security events, helping IT teams identify suspicious activity, analyse potential risks and take action through a unified cloud management platform.
Key Features of Cisco BPT-SEC-ESS
Subscription-based breach protection platform
Extended Detection and Response (XDR) capabilities
Endpoint protection with behavioural threat detection
Email threat detection and phishing protection
Malware analysis for suspicious files
Centralised cloud management interface
Cross-domain threat visibility
AI-assisted threat prioritisation
Automated investigation and response workflows
Integrated security event monitoring and analysis
Secure Endpoint Advantage:
The Advantage tier of Secure Endpoint includes advanced Endpoint.Detection and Response capabilities:
Defense of endpoints and remote workers against sophisticated malware from the point of entry through propagation to post-infection remediation. Detection and blocking of malware, confirmation of infection, path-tracing behavior analysis, target remediation, and a report on malware impact
Speedy response times and automation of remediation to prevent future attacks, mitigate damage and eliminate the risk of reinfection. Identification of indicators of compromise at both the network and system levels, typically missed by single-purpose detection technologies.
Ability to isolate infected endpoints from the rest of the network to contain threats without loss of forensic data. Fast endpoint reactivation upon completion of remediation.
Use of Cisco Security Intelligence Operations global network of sensors, as well as intelligence collected from the Talos Security Intelligence and Research Group, to provide collective security intelligence protection to benefit from the billions of malware samples analyzed monthly.
Orbital Advanced Search: On-demand deep endpoint search using osquery for capturing forensic data and other observables on an endpoint
Threat Grid Cloud: Access to Threat Grid Cloud Console for in-depth malware threat intelligence
Cisco XDR Essentials: XDR Essentials includes the following capabilities, with all Cisco telemetry sources:
Built by practitioners for practitioners with built-in integrations across the Cisco security portfolio so analysts can detect and respond to the most sophisticated threats.
Native integration of the full Cisco security portfolio so analysts can detect and respond to the most sophisticated threats.
The XDR Essentials package also includes a 2GB per user per month data ingestion limit, 90-day default data retention, plus US-based data residency and sovereignty.
Email Threat Defense:
Cisco Secure Email Threat Defense (formerly known as Cloud Mailbox) is an integrated, cloud-native security solution for Microsoft 365 that focuses on simple deployment, easy attack remediation, superior visibility, and best-in-class efficacy from Cisco Talos. It augments native Microsoft 365 security and provides complete visibility into inbound, outbound, and internal user-to-user messages.
With Cisco Secure Email Threat Defense, customers can:
Detect and block threats with superior threat intelligence from Cisco Talos, one of the largest threat research and efficacy teams
Combat advanced threats using Cisco Secure Email Malware Defense and Cisco Threat Grid
Get complete visibility into inbound, outbound, and internal messages
Leverage fast, API-driven remediation of messages with malicious content
Use an integrated dashboard for search, reporting, and tracking, including conversation view and message trajectory
Enhance Microsoft 365 email security in less than 5 minutes without changing the mail flow

The Cisco UPT-SEC-ADV User Protection Security Suite Advantage Subscription Licence provides a comprehensive set of security capabilities to help protect users, devices and access points across modern working environments. This licence combines identity protection, multi-factor authentication, secure access controls and threat protection features to help organisations reduce security risks while maintaining flexible user connectivity.
Key Features of Cisco UPT-SEC-ADV
Includes Cisco Duo multi-factor authentication (MFA) capabilities
Supports secure single sign-on (SSO) access management
Helps protect user identities and applications from unauthorised access
Provides secure remote access and access control features
Includes security service edge (SSE) capabilities for modern workplaces
Helps identify and respond to email-based threats
Cloud-based security features for user and endpoint protection
Secure Access
Protect users and resources anywhere work is performed with a converged set of security service edge (SSE) capabilities.
Cisco Duo
Decrease the risk of breaches with multi-factor authentication (MFA), single sign-on (SSO), remote access and access control.
Secure Email Threat Defense
Identify the intent and risk that an email-based threat poses to an organisation with advanced, AI-empowered features.
Secure Endpoint
Detect, respond and recover from attacks with a cloud-native solution, reducing remediation times by as much as 85%.

The Cisco BPT-SEC-PRE Breach Protection Security Suite Premier Licence provides a broad range of security capabilities to help organisations detect, investigate and respond to cyber threats across users, endpoints, networks and cloud environments. This subscription package combines extended detection and response technologies with advanced threat intelligence, endpoint protection, network visibility and incident response services to support proactive security operations.
Key Features of Cisco BPT-SEC-PRE
Cisco XDR Advantage features with additional managed services
Provides extended detection and response (XDR) capabilities
Secure Endpoint Premier with advanced threat hunting
Secure Email Threat Defense for advanced email threat protection
Secure Network Analytics for network threat detection and visibility
Telemetry Broker for security data management and integration
Talos Incident Response services
Supports technical security assessments and security posture reviews
Cisco XDR Essentials
See more and act faster with AI-driven extended detection and response that integrates with the Cisco security portfolio.
Cisco Secure Endpoint Advantage
Protect the hybrid workforce, maintain resilience and safeguard future operations with simple, comprehensive endpoint security.
Cisco Secure Email Threat Defense
Protect against damaging and costly advanced email threats with unique AI and machine learning models.
Cisco XDR Advantage
Rapidly detect and respond to threats with all features of XDR Essentials, plus integrations with selected third-party tools.
Cisco Secure Endpoint Premier
Identify hidden threats with all features of Secure Endpoint Advantage, plus threat hunting capabilities that uncover advanced attacks.
Cisco Secure Network Analytics
Detect threats in real time with network detection and response that provides organisation-wide network visibility, including public and private cloud traffic.
Cisco Telemetry Broker
Optimise breach protection telemetry by brokering data, filtering unnecessary information and transforming data into a usable format.
Cisco XDR Premier
This licensing package includes all features of XDR Advantage, plus additional managed security services.
Cisco Managed Extended Detection and Response
Cisco security experts provide this managed XDR service, including security validation through penetration testing and selected Talos Incident Response services.
Cisco Talos Incident Response
Talos IR provides proactive and emergency services to help organisations prepare for, respond to and recover from cybersecurity incidents.
Cisco Technical Security Assessment
Assess security posture with guidance on threats, potential risks and the impact on operational resilience.

The Cisco WSA-WSP-1Y-S4 provides a 1-year Web Security Premium Bundle subscription for supported Cisco Web Security Appliance deployments. The bundle combines web reputation, web usage controls and advanced malware protection to help monitor web activity, manage access to online content and identify malicious files and threats passing through web traffic.
Key Features of Cisco WSA-WSP-1Y-S4
Web Security Premium Bundle subscription
1-year subscription term
Web Reputation (WREP) included
Web Usage Controls (WUC) included
Advanced Malware Protection (AMAL) included
Web traffic monitoring and filtering capabilities
Reputation-based protection against potentially harmful websites
Web Reputation Protection
Web Reputation services assess websites and web destinations to help identify potentially harmful locations before users access them. This adds reputation-based controls to the web security functions available through the associated Cisco Web Security Appliance.
Web Usage Controls
Web Usage Controls provide tools for managing access to online content and web activity. Administrators can apply policies to help control the types of websites and content that users can access through the protected network.
Advanced Malware Protection
Advanced Malware Protection adds additional analysis capabilities for identifying potentially harmful files and threats encountered through web traffic. This helps provide further inspection beyond standard web filtering and reputation checks.
One-Year Subscription
The subscription provides access to the Web Security Premium Bundle for a period of one year. It is supplied as a software licence for use with compatible Cisco Web Security Appliance deployments and does not include physical hardware.
Large User-Band Licensing
The S4 user tier covers deployments supporting between 1,000 and 4,999 users, making the subscription suitable for larger Cisco Web Security Appliance installations requiring a broad web security feature set.

Cisco SMA-EMGT-1Y-S4 Email Security Management Bundle provides a one-year subscription. The Cisco Content Security Management Appliance (SMA) centralizes management and reporting functions across multiple Cisco email and web security appliances. It simplifies administration and planning, improves compliance monitoring, helps to enable consistent enforcement of policy, and enhances threat protection.

Cisco Digital Network Architecture (Cisco DNA) is your team’s bridge to an intent-based network. It is an open, extensible, software-driven architecture that accelerates and simplifies your enterprise network operations, while lowering costs and reducing your risk. Only Cisco provides a single network fabric that is powered by deep intelligence and integrated security to deliver automation and assurance across your entire organization at scale. Cisco DNA gives IT time back from time-consuming, repetitive network configuration tasks so you can focus on the innovation your business needs.
Cisco DNA Automation and Assurance are built on a Software-Defined Networking (SDN) controller, rich contextual analytics, network virtualization and the limitless scalability of the cloud.
This is an entirely new era of networking.
Most Cisco routers, switches and wireless systems shipping today support Cisco DNA now or with a software update. And with new software subscription offers to choose from Cisco DNA Premier, Cisco DNA Advantage, and Cisco DNA Essentials—you can benefit from new innovations activated through software.
Key Features of Cisco Umbrella DNS Security Essentials
SecureX is a cloud-native, built-in platform experience that connects Cisco Secure portfolio with your infrastructure. It is integrated and open for simplicity, unified in one location for visibility, and maximizes operational efficiency with automated workflows
Block domains associated with phishing, malware, botnets, and other high risk categories (cryptomining, newly seen domains, etc.)
Prevent web and non-web callbacks from compromised systems
Enable web filtering using 100+ content categories
Create custom block and allow lists
Pinpoint compromised systems using real-time security activity reports
Discover and block shadow IT (based on domains) with the App Discovery report
Protection for managed and unmanaged iOS and Android mobile devices
Create policies and view reports by user (Active Directory), network (egress IP), network device, internal subnet, or roaming device
Use customizable block pages and bypass options
Access to Umbrella’s APIs and ability to retain logs with Amazon S3 bucket
User Protection
Protects users on the corporate network through integration with networking devices.
Remote Browser Isolation
Protects off-network users through integration with Cisco AnyConnect or the standalone roaming client.
DNS-Layer Security
Blocks domains associated with malware, phishing, botnets and other online threats.
Secure Web Gateway
Performs web filtering based on domains and domain categories.
Traffic Forwarding
Discovers and blocks shadow IT based on domain activity.
Policy Management
Creates security policies and provides user-based reporting through Active Directory integration.
Management
Integrates with existing tools and workflows using APIs for enforcement, reporting, management and deployment.
XDR and Threat Intelligence
Integrates with Cisco SecureX to aggregate security intelligence across Cisco products.
Reporting and Logs
Retains logs with Amazon Web Services integration using customer-managed or Cisco-managed Amazon S3 buckets.

The Cisco ADD-EP-PRE Security Suite Secure Endpoint Premier Add-On provides advanced endpoint security capabilities to extend existing Cisco security subscriptions. This add-on delivers enhanced endpoint visibility, threat detection, investigation and response features, helping security teams identify suspicious activity, analyse threats and take action across connected devices. The licence integrates with Cisco security services to provide additional endpoint protection capabilities for users requiring expanded security coverage.
Key Features of Cisco ADD-EP-PRE Security Suite Secure Endpoint Premier
Advanced endpoint threat detection and response capabilities
Machine-learning-based behavioural monitoring
Protection against malware, ransomware and fileless threats
Continuous endpoint activity monitoring
Dynamic file analysis using secure sandboxing technology
Endpoint isolation to help contain infected devices
Risk-based vulnerability visibility and scoring
Orbital Advanced Search for threat hunting and investigation queries
Remote Scripts powered by Orbital for response actions
Malware Analytics Cloud for advanced file analysis and threat intelligence
Host Firewall management through console or API
Threat Hunting by Cisco Talos security researchers
Next-generation endpoint protection
Block threats using powerful machine-learning-based behavioral monitoring engines and protect against fileless malware and ransomware.
Continuous monitoring
Monitor all endpoint activity nonstop and provide run-time detection and blocking of abnormal activities on the endpoint.
Dynamic file analysis
Use our built-in, highly secure sandboxing environment to analyse suspect files in detail.
Endpoint isolation
Stop threats from spreading with one-click isolation of an infected endpoint.
Device control
Will allow visibility and control over USB mass storage devices.
Risk-based vulnerability framework
Scannerless visibility, context, and actionable risk scores.
Orbital Advanced Search
Accelerate threat hunting and investigations with 200+ pre-defined vulnerability, IT operations, and threat-hunting queries. A Click-to-Demo for this feature is available..
Remote Scripts powered by Orbital
Used in combination with Secure Endpoint’s isolation feature, Remote Scripts can cut off lateral movement and persistence, speeding up recovery times..
Malware Analytics Cloud
Use advanced sandboxing techniques to perform in-depth dynamic file analysis and deep malware threat intelligence.
Host Firewall
Centrally manage network traffic and enable fast, more effective response in console or through API.
Threat Hunting by Talos
Get integrated, continuous hunting by elite Cisco threat hunters with detailed alerts and clear remediation instructions.

The Cisco WSA-WSP-5Y-S2 provides a five-year Web Security Premium Bundle subscription for supported Cisco Web Security Appliance deployments covering between 100 and 499 users. The bundle combines web reputation, web usage controls and advanced malware protection to help monitor online activity, manage access to web content and inspect traffic for potentially harmful files and threats.
Key Features of Cisco WSA-WSP-5Y-S2
Web Security Premium Bundle subscription
Five-year subscription term
Supports 100 to 499 users
Web Reputation (WREP) included
Web Usage Controls (WUC) included
Advanced Malware Protection (AMAL) included
Web traffic monitoring and filtering capabilities
Web Reputation Protection
Web Reputation services assess websites and online destinations to help identify potentially harmful locations before users access them. This provides reputation-based controls for web traffic passing through the associated Cisco Web Security Appliance.
Web Usage Controls
Web Usage Controls provide tools for managing access to online content and web activity. Administrators can apply policies to help regulate the websites and content available to users through the protected network.
Advanced Malware Protection
Advanced Malware Protection adds additional analysis capabilities for identifying potentially harmful files and threats encountered through web traffic. This provides further inspection alongside web filtering and reputation-based security controls.
S2 User-Band Licensing
The S2 user tier covers deployments supporting between 100 and 499 users, making the subscription suitable for Cisco Web Security Appliance installations requiring web reputation, usage controls and advanced malware protection.
Five-Year Subscription
The five-year term provides extended access to the Web Security Premium Bundle for supported Cisco Web Security Appliance deployments. This subscription is supplied as a software licence and does not include physical hardware.

The Cisco WSA-WSP-1Y-S2 provides a one-year Web Security Premium Bundle subscription for supported Cisco Web Security Appliance deployments covering between 100 and 499 users. The bundle combines web reputation, web usage controls and advanced malware protection to help monitor online activity, manage access to web content and inspect web traffic for potentially harmful files and threats.
Key Features of Cisco WSA-WSP-1Y-S2
Web Security Premium Bundle subscription
One-year subscription term
Supports 100 to 499 users
Web Reputation (WREP) included
Web Usage Controls (WUC) included
Advanced Malware Protection (AMAL) included
Web traffic monitoring and filtering capabilities
Reputation-based website protection
Web Reputation Protection
Web Reputation services assess websites and online destinations to help identify potentially harmful locations before users access them. This provides reputation-based controls for web traffic passing through the associated Cisco Web Security Appliance.
Web Usage Controls
Web Usage Controls provide tools for managing access to online content and web activity. Administrators can apply policies to help regulate the websites and content available to users through the protected network.
Advanced Malware Protection
Advanced Malware Protection adds additional analysis capabilities for identifying potentially harmful files and threats encountered through web traffic. This provides further inspection alongside web filtering and reputation-based security controls.
S2 User-Band Licensing
The S2 user tier covers deployments supporting between 100 and 499 users, making the subscription suitable for Cisco Web Security Appliance installations requiring web reputation, usage controls and advanced malware protection.
One-Year Subscription
The one-year term provides access to the Web Security Premium Bundle for supported Cisco Web Security Appliance deployments.

The Cisco WSA-WSE-1Y-S2 provides a one-year Web Security Essentials Bundle subscription for supported Cisco Web Security Appliance deployments covering between 100 and 499 users. The bundle combines Web Reputation and Web Usage Controls to help assess the safety of websites, manage access to online content and apply web access policies across the protected user base.
Key Features of Cisco WSA-WSE-1Y-S2
Web Security Essentials Bundle subscription
One-year subscription term
Supports 100 to 499 users
Web Reputation (WREP) included
Web Usage Controls (WUC) included
Website reputation assessment
Web content access management
Web usage policy controls
Web Reputation
Web Reputation services assess websites and online destinations to help identify potentially harmful locations before users access them. This provides reputation-based information for web traffic passing through the associated Cisco Web Security Appliance.
Web Usage Controls
Web Usage Controls provide tools for managing access to online content and web activity. Administrators can apply policies to help regulate the websites and content available to users through the protected network.
S2 User-Band Licensing
The S2 user tier covers deployments supporting between 100 and 499 users, making the subscription suitable for Cisco Web Security Appliance installations requiring web reputation and usage control capabilities.
One-Year Subscription
The one-year term provides access to the Web Security Essentials Bundle for supported Cisco Web Security Appliance deployments. This subscription is supplied as a software licence and does not include physical hardware.

The Cisco BPT-SEC-ADV Breach Protection Security Suite Advantage subscription provides a collection of security capabilities that help organisations detect, investigate and respond to cyber threats across endpoints, email and network environments. This suite combines extended detection and response technologies with threat intelligence, endpoint protection and security analytics to provide visibility into suspicious activity and support faster incident response.
Key Features of Cisco BPT-SEC-ADV Breach Protection Security Suite Advantage
Cisco XDR Advantage capabilities
Provides extended detection and response (XDR) functionality
Secure Endpoint Advantage
Secure Email Threat Defense
Secure Network Analytics
Telemetry Broker capabilities
AI-driven threat detection and investigation workflows
Integrates Cisco security data for improved threat visibility
Supports endpoint, email and network threat monitoring
Helps identify, investigate and respond to security incidents
Cisco XDR Essentials
See more and act faster with Al-driven extended detection and response that integrates with the Cisco security portfolio
Cisco Secure Endpoint Advantage
Protect the hybrid workforce, stay resilient and protect ‘what’s next’ with simple, comprehensive endpoint security
Cisco Secure Email Threat Defense
Protect against damaging and costly advanced email threats with unique AI and machine learning models
Cisco XDR Advantage
Rapidly detect and respond to threats with all features of XDR Essentials plus integrations with select third-party tools
Cisco Secure Endpoint Premier
Catch hidden threats with all features of Secure Endpoint Advantage plus threat hunting that uncovers advanced threats
Cisco Secure Network Analytics
Detect threats in real time with network detection and response that offers enterprise-wide network visibility, including public and private cloud traffic
Cisco Telemetry Broker
Optimises Breach Protection telemetry by brokering data, filtering unneeded data and transforming data to a usable format.

The Cisco UPT-SEC-ESS User Protection Security Suite Essentials subscription provides essential security capabilities to help protect users, identities and access points across modern working environments. This package combines identity protection, secure access controls, email security and endpoint protection features to help reduce security risks while supporting secure user connectivity across locations and devices.
Key Features of Cisco UPT-SEC-ESS User Protection Security Suite Essentials
User protection capabilities for securing access to applications and resources
Cisco Duo Essentials for multi-factor authentication (MFA)
Single sign-on (SSO) access management capabilities
Secure remote access and identity verification features
Secure Email Threat Defense features for identifying email-based threats
Secure Access
Protect users and resources anywhere work is done with a converged set of security service edge (SSE) capabilities.
Cisco Duo
Decrease the risk of breaches with multi-factor authentication (MFA), single sign-on (SSO), remote access and access control.
Secure Email Threat Defense
Identify the intent and risk that an email-based threat poses to an organisation with advanced, AI-empowered features.

The Cisco L-ASA-V-30S-1Y Adaptive Security Virtual Appliance ASAv30 provides virtual firewall and VPN capabilities with a 2 Gbps throughput licence and one-year subscription term. This electronic licence enables organisations to deploy Cisco ASA security features within supported virtual environments, helping protect network traffic through stateful inspection, access controls and secure connectivity across cloud and virtual infrastructures.
Key Features of Cisco Adaptive Security Virtual Appliance ASAv30
Adaptive Security Virtual Appliance ASAv30 licence
1-year electronic subscription licence
2 Gbps stateful inspection throughput
Virtualised firewall deployment
Supports secure network traffic inspection
Supports deployment across supported cloud and virtual platforms
Uniform Security across Deployment Domains
You gain uniform security across physical and virtual deployment domains with multiple hypervisors. Increasingly, customers are deploying some parts of an application on physical infrastructure and other parts on virtual infrastructure. Even on a virtual infrastructure, customers use multiple hypervisors to deploy their applications. ASAv, along with ASA, normalizes the deployment options. One security policy can be deployed for both physical and virtual appliances.
Ease of Management
The Adaptive Security Virtual Appliance offers the Representational State Transfer (REST) API, an HTTP-based interface. With it, you can change your security policies and monitoring status and otherwise manage the device. An ASA can be introduced into Software-Defined Networking (SDN) environments and easily used with custom policy-orchestration systems.
Ease of Provisioning
You can provision the virtual appliance within a matter of minutes with a predetermined configuration. You can quickly deploy security services to match the speed of application deployment. With Smart Software Licensing, the virtual appliance can automatically obtain the entitlements while giving you a single, holistic view of the resources being consumed within your enterprise.

The Cisco E2SF-E-CES-ADV-10 provides ten Secure Email Cloud Advantage licences through the Security Choice EA 2.0 programme, giving users access to cloud-hosted email protection with advanced security and compliance capabilities. The Advantage tier includes protection against spam, malicious URLs and malware, along with features such as data loss prevention, email encryption and advanced malware analysis for covered users.
Key Features of Cisco E2SF-E-CES-ADV-10
Secure Email Cloud Advantage licensing
Includes 10 user licences
Cloud-hosted email security service
Supplied through Security Choice Enterprise Agreement (EA) 2.0
Unlimited malware analysis samples within the applicable service limits
Safe unsubscribe functionality
Anti-spam, Sender Domain Reputation and URL-filtering
Cisco's proven security applications and features better protect against spam, malicious domains and URLs.
Outbreak filters
Instantly recognize and quarantine suspected threats until they are determined to be safe.
Antivirus
Spend less time on alerts and more time on bigger projects. Provides the first layer of defense to users as an antivirus engine for email scanning.
Secure Email malware defense and analytics
Performs dynamic analysis of advanced malware threats. Includes file reputation with our Secure Malware Analytics built-in sandboxing capabilities.
Graymail detection
Allows users to safely receive legitimate marketing emails.
Data loss prevention
Powerful rules and techniques help create disclosure policies to track and prevent unauthorized users from sharing confidential data through email.
Secure Email Encryption Service
Provides content encryption service for outbound emails.
Safe unsubscribe
Allows users to safely unsubscribe from marketing emails.
Ten-User Licensing
With ten covered user licences, this subscription is suitable for deployments requiring cloud email security for a defined group of mailboxes. The licensing is delivered through the Cisco Security Choice EA 2.0 programme and is subject to the applicable agreement terms.

The Cisco FWM-FPR1140 provides a Security Cloud Control Firewall Management subscription for one Cisco Firepower 1140 appliance, enabling cloud-based administration, monitoring and visibility for supported firewall deployments. The licence supports centralised management through Cisco Security Cloud Control, helping administrators configure and monitor the associated FPR1140 from a cloud-based platform while reducing the need for direct local management.
Key Features of Cisco FWM-FPR1140
Cloud-based firewall administration
Remote monitoring and firewall visibility
Supports management of compatible ASA or FTD deployments
Helps manage firewall configuration from a central cloud platform
Simplify operations and strengthen security using AIOps
AIOps provides predictive insights and automation to empower administrators simplifying operation, enhance security posture, boost operational efficiency and reduce costs.
Eliminate misconfigurations and optimize rules for simplified operations
The Policy Analyzer and Optimizer detects duplicate, redundant, shadowed, expired, overlapping, and mergeable rules. Apart from spotting anomalies, it delivers accurate implementation recommendations. You can download a change log and report from this service to keep your policy optimized.
Management of hybrid environments (ASA, FTD and Multicloud Defense)
Streamlined workflow and integration between cloud security and on-premises/data center firewalls, you can now share objects and create VPN tunnels between Cisco Firewalls and Multicloud Defense. Static object sharing enables consistent policy outcomes across hybrid environments, eliminating administrative overhead and reducing potential for misconfiguration. Site-to-cloud VPN tunnels allow assets deployed across hybrid environments to communicate with one another via a secure connection.
Management of the SASE experience
Delivers a single-vendor SASE experience by enabling both NetOps and SecOps teams to manage Catalyst SD-WAN and Cisco Secure Access capabilities from a single, AI-powered control center. By unifying networking and security operations, organizations can simplify onboarding, streamline provisioning, and gain consistent visibility into their distributed environments - all while reducing operational silos and the administrative overhead of navigating across multiple dashboards.
Optimization for your existing platforms
Upon onboarding, Security Cloud Control will immediately be able to identify and flag common issues across firewalls that have been in production for years. After assessing and identifying all risks, you will now be able to swiftly remediate issues across all devices in bulk - bringing your devices to a consistent and more secure state.
ASA-to-FTD migration
It is now easier than ever to migrate your environment from ASA to Cisco Threat Defense (FTD), thanks to Security Cloud Control’s embedded migration wizard. Manage both ASA and FTD from a single UI, enabling you to transition to NGFW in your own timeline!
Templates for consistent policy design
Using Security Cloud Control, you can now create, apply, and manage a consistent policy design across disparate devices from a single place. Our template feature allows you to create a “gold configuration” that can be replicated and customized. Once you are done, you can export and apply your standardized configuration to any new platform.
Simplified firewall OS upgrades
Often one of the most time-consuming and frustrating challenges that our customers face is maintaining the firewall OS for both features and vulnerabilities. Using Security Cloud Control, you can reduce the time it takes to perform Cisco ASA or Cisco Threat Defense (FTD) image upgrades by up to 90 percent. We take the guesswork out of planning and enable you to perform the upgrade in bulk across all your devices at once.

The Cisco FL-VPERF-8P-200 provides an additional 200 Mbps of IPsec performance for compatible 8-port Cisco ISR 1100 Series routers. This software licence is intended for deployments requiring greater encrypted traffic capacity, allowing supported routers to handle higher IPsec throughput while retaining the security and VPN capabilities provided by the underlying Cisco IOS feature set.
Key Features of Cisco FL-VPERF-8P-200
Additional 200 Mbps IPsec performance
Software licence for compatible Cisco ISR 1100 Series routers
Supports increased encrypted traffic capacity
Intended for IPsec VPN performance requirements
Additional IPsec Performance
The licence adds 200 Mbps of IPsec performance to supported 8-port ISR 1100 Series routers, providing additional capacity for encrypted network traffic and VPN connections.
Compatible ISR 1100 Series Routers
This software licence is intended for compatible 8-port Cisco ISR 1100 Series routers, including selected ISR 1111, ISR 1112, ISR 1113, ISR 1116, ISR 1117 and ISR 1118 models. Compatibility should be confirmed against the specific router model and software release before purchase.
For Encrypted Network Traffic
The additional throughput is intended for deployments that rely on IPsec-based connectivity, including VPN traffic between sites and other supported secure network connections. The licence works alongside the router's applicable security feature licensing.

The Cisco SAL-CL-TA-OVRG provides additional capacity for Security Analytics and Logging Total Network Analytics and Detection usage when subscribed data limits are exceeded. It allows organisations to continue collecting and analysing network security data through Cisco cloud analytics services while maintaining visibility into network activity, events and potential threats.
Key Features of Cisco SAL-CL-TA-OVRG
Monthly overage licence for Cisco Security Analytics and Logging
Extends Total Network Analytics and Detection data capacity
Supports additional security event and network data ingestion
Provides visibility into network activity and security events
Helps monitor unusual network behaviour and potential threats
Works with Cisco cloud-based analytics services
Supports analysis of network traffic and security information
Helps maintain continuous security monitoring when usage exceeds limits
Usage-based capacity expansion for changing data requirements
Managed through Cisco Security Analytics and Logging services
Network Activity Monitoring
Security teams can continue analysing network information and events collected through Cisco Security Analytics and Logging. The service helps identify patterns, review activity and support investigations using centralised cloud-based analytics.
Scalable Security Analytics
Built for environments with changing data volumes, the licence allows organisations to add capacity when required. It supports ongoing monitoring requirements without interruption to existing security analytics processes.

The Cisco E3S-SA-SIA-E provides a Secure Internet Access Essentials subscription licence for one user under the Cisco Enterprise Agreement 3.0 programme. It supports cloud-delivered protection for internet and SaaS application access through capabilities such as DNS security, secure web gateway functions, cloud-delivered firewall controls, cloud access security broker features and secure connectivity options for users working across different locations and devices.
Key Features of Cisco E3S-SA-SIA-E
Secure private access using Zero Trust Network Access and VPNaaS for managed and unmanaged devices; includes posture assessment.
Secure internet access enabled through roaming security, VPN tunnel, IPsec tunnel, PAC files, ` proxy chain, and SD-WAN integration.
DNS protection and Cloud Delivered Firewall for layer 3 and layer 4 controls of web and private apps.
Secure web gateway capabilities including proxy for web traffic, URL filtering, content filtering, advanced app controls.
CASB - Cloud app discovery, risk scoring, blocking, cloud malware detection; SaaS app activity controls and tenant controls.
Malware analytics (sandbox) for suspicious files. Limited to 500 samples per day.
Experience Insights (Digital Experience Monitoring) provides end-to-end monitoring of end-user experience when accessing the Internet and corporate resources.
Secure Internet Access
Secure Internet Access Essentials provides cloud-delivered protection for users connecting to internet and SaaS applications. The service supports multiple traffic-routing methods, including roaming security, VPN tunnels, IPsec tunnels, PAC files, proxy chains and SD-WAN integration.
Secure Web Gateway Protection
Secure web gateway capabilities provide controls for web traffic through proxy services, URL filtering, content filtering and advanced application controls. These features help administrators apply access policies to web activity and internet-based applications.
DNS and Cloud Firewall Controls
DNS protection helps monitor and control domain-based requests, while the Cloud Delivered Firewall provides Layer 3 and Layer 4 controls for supported web and private application traffic.
Cloud Application Visibility
CASB capabilities provide cloud application discovery, risk scoring and blocking functions, together with cloud malware detection and controls for SaaS application activity and tenants.

The Cisco E2SF-F-FTD-V-10S provides Virtual Threat Protection licensing for a Cisco Secure Firewall Threat Defense Virtual deployment in the 10S performance tier. This subscription supports virtual firewall deployments requiring threat protection capabilities, allowing organisations to apply security controls to virtual network traffic while managing the associated FTDv instance through supported Cisco management platforms and has URL Filtering.
Key Features of Cisco E2SF-F-FTD-V-10S
Subscription-based software licensing
Provides threat protection capabilities for virtual firewall traffic
Supports virtualised firewall deployments
Robust connectivity and portability
Deploy appliances everywhere, from your data center to your branch office, with the portability of one license to support virtual deployments across public or private clouds.
Automatically scale firewall capacity in response to real-time traffic demands with native auto-scale support, while clustering delivers high-performance throughput and resilience across distributed cloud environments.
Superior visibility
Leverage the AI-powered Encrypted Visibility Engine (EVE) to gain insights into and control over encrypted traffic, including Transport Layer Security (TLS) 1.3, thereby eliminating the need to decrypt traffic.
Protect networks against zero-day vulnerabilities with SnortML, a machine learning-based exploit detection technology integrated into the industry-leading Snort 3 intrusion prevention system (IPS) and powered by the Cisco Talos Intelligence Group.
Simplified management
Manage hundreds of firewalls across various global branch locations using a single unified manager, available in both on-premises and cloud-delivered platforms.
Accelerate and simplify firewall deployment across public cloud environments with Cisco Multicloud Defense, providing centralized orchestration, consistent policy management, and streamlined operations.
Seamless integration
Achieve comprehensive, end-to-end protection through native integration with Cisco Umbrella ®, Cisco Secure Access, and Cisco Endpoint Security.
Optimize application performance and user experience through seamlessly integrated SD-WAN capabilities, accelerated by Zero-Touch Provisioning (ZTP).


