Cisco Cyber Vision

Cisco Cyber Vision

Beyond OT visibility: Network protection that you can scale

Visibility is the foundation, but protection reduces risk. Secure industrial operations with visibility, segmentation, and secure remote access built into your network.

Turn your industrial networks into powerful OT security assets


How Cisco Cyber Vision helps secure industrial operations at scale

Start protecting industrial operations effectively with deep visibility into OT assets and risks, AI-assisted network segmentation, and secure remote access built in to your industrial network.

Get OT security that scales

Stop deploying dedicated OT visibility and security appliances. Cyber Vision is software built in to Cisco networking equipment, so you get deep visibility into connected assets and can easily scale protection.

Manage OT cyber risks

Inventory industrial assets and their network activities. Prioritize action by identifying vulnerabilities that bad actors are exploiting. Prevent disruptions by detecting malicious traffic and abnormal behaviors.

Protect operations

Segment industrial networks in weeks, not years. Cyber Vision's AI-assisted recommendations let OT teams easily create and manage zones, simulate policies, and enforce them without risking production uptime.

Secure remote access

Empower OT teams with self-service remote access so they can run operations effectively. Enforce least-privilege policies to ensure only the right people have access to required resources for the right amount of time.

Cisco Cyber Vision interface and IE3500 Rugged Series, IE3500 Heavy Duty Series, and Catalyst IE9300 Rugged Series switches

OT security included with select Industrial Ethernet switches

Get Cisco Cyber Vision at no extra cost when you buy a Cisco IE3500 Rugged Series, Cisco IE3500 Heavy Duty Series, or Cisco Catalyst IE9300 Rugged Series switch along with a Network Advantage license.

Comprehensive OT security fused into your industrial network

Turn your network into a sensor

Get 100% visibility into industrial assets. The Cyber Vision sensor is embedded in Cisco switches and routers, eliminating the need for visibility appliances or SPAN collection networks.

Gain visibility even on non-Cisco networks

Deploy sensors by using third-party compute hardware, or use your existing SPAN collection infrastructure to send traffic to the central server.

Control your OT cyber risks

Reduce the attack surface by assessing a detailed inventory of OT assets, vulnerabilities and communication behaviors.

Get alerts on what you care about most

Create custom rules to focus on what you want to control—unexpected behaviors, prohibited vendors or geographies, riskiest vulnerabilities, and more.

Track all asset behaviors

Get a detailed history of all asset behaviors through easy-to-understand tags. Define custom rules to monitor for unexpected events that may indicate early signs of an attack.

Threat-informed vulnerability defense

Prioritize vulnerabilities with risk scores highlighting the ones that bad actors are exploiting. Drive action with MITRE ATT&CK mapping showing you how to secure the attack path.

Detect malware and malicious traffic

Uncover known and emerging threats targeting your industrial network. Cyber Vision comes with the Snort intrusion detection system (IDS) engine and Cisco Talos threat intelligence.

Prevent lateral movement of threats

Easily prevent attacks from spreading across your entire operations by getting the industrial network to control what can communicate to what.

Easily create IEC 62443 zones and conduits

Empower OT teams to drive segmentation. Cyber Vision automatically suggests asset groups and policies between groups.

Simulate policies to prevent disruption

Avoid the risk of blocking legitimate traffic. Simulate the impact of segmentation rules against real traffic before they're enforced.

Enforce segmentation at line rate

Have Cyber Vision work directly with switches to enforce policies at wire speed. No need for additional appliances or complex setup.

Remote access in switches and routers

Easily deploy secure remote access at scale and access OT assets behind NAT boundaries without extra appliances or complex network setup.

Least-privilege zero-trust access control

Never grant access to the entire network. Restrict access to specific assets, based on user, protocol, schedule, posture, and geolocation.

Self-service OT remote access

Let OT teams manage credentials to drive operations without IT bottlenecks. Our web portal centralizes policies for all assets and sites.

Clientless and agent-based access

Users need just a web browser to access assets. If direct IP access is required, security posture can be checked, and port/protocol restrictions can be enforced.

Access that's open only when needed

Make sessions even more secure. Policies can require a privileged user to approve access when a remote user is connecting.

Zero-trust control for jump servers

Keep using engineering workstations as jump servers to access OT assets. Cyber Vision adds zero-trust controls and audit capabilities.

Identity threats detection

Get alerts when remote users try to connect from new or prohibited locations or during unusual hours.

Session recording and auditing

Meet compliance requirements with comprehensive audit trails and the ability to join, record, or terminate sessions.

Simple deployment at scale

Easily install the Cyber Vision software into switches and routers from the central console, Cisco Catalyst Center, or SD-WAN Manager.

Multisite management

Monitor sensors deployed across all your sites and keep their software and threat intelligence current from a single console.

Advanced dashboards

Streamline OT security governance with comprehensive and customizable dashboards powered by the Cyber Vision app for Splunk.

Out-of-the-box integrations

Extend IT security to OT with out-of-the-box integration with Cisco Secure Firewall, Cisco Identity Services Engine, Cisco XDR, Splunk, ServiceNow, and more.

Custom integrations and programmability

Feed IT applications with OT context by using rich, easy-to-use APIs. Automate tasks to implement a programmatic approach to OT security.


Expand your knowledge

Cyber Vision data sheets

Learn more about the features that Cyber Vision offers to help you drive your OT and industrial control systems (ICS) security projects.

OT visibility at scale

Learn why Cyber Vision stands apart for gaining comprehensive visibility, even at the lowest levels of the Purdue model.

Secure remote access purpose-built for OT

Get details on Cyber Vision's secure remote access for OT assets.

Multisite industrial security management

Learn how Cyber Vision and Splunk can help you to easily deploy, monitor, and manage large multisite OT security programs.

4 steps to prepare your OT for NIS2

Find out how Cisco can help you to make your industrial operations compliant with NIS2 regulations.

More OT security resources

Access a wealth of information about Cyber Vision and ICS security.

Industrial security built for OT

Discover how Cisco can help you to protect OT environments and critical infrastructure with comprehensive visibility, segmentation, secure remote access, and threat detection fused into the network.

Get Cyber Vision through cloud marketplaces

Amazon Web Services (AWS)

Optimize applications and workloads running on AWS. Deploy Cyber Vision in the AWS cloud.

Microsoft Marketplace

Connect with Microsoft Azure to optimize your application resources. Deploy Cyber Vision in the Azure cloud.

Google Cloud

Optimize applications and workloads running on Google. Deploy Cyber Vision on Google Cloud.