Cisco Security and AI

Reimagine security for the agentic AI era


AI agents are transforming how we work, innovate, and defend ourselves. Cisco research and insights help organizations securely navigate the agentic AI era.

AI is redefining enterprise security

Frontier AI is changing how attackers and defenders act. The use and security of AI agents have become a core focus for enterprises in this new era. Explore Cisco research, guidance, and solutions for the agentic era.

3 priorities shaping security and AI

Agents supercharge external attacks

Frontier AI shrinks the time from vulnerability discovery to exploitation, with AI agents from malicious actors supercharging external attacks.

Agents are a new insider threat

AI agents introduce a new kind of insider risk, with a new class of identities, access, and actions that need to be secured across their lifecycle.

Agents can fight back at machine speed

AI agents can help security teams defend, investigate, and respond at machine speed.

Glasswing: Mythos demands a new model for infrastructure

Frontier models like Anthropic's Mythos and OpenAI's GPT-5.5-Cyber are changing what defenders and attackers can find, connect, and act on.

Cisco has seen what this shift means for the infrastructure the world runs on. We need a new operating model for resilient infrastructure - and we need it in months.

Expert perspectives on AI security

Nick Biasini speaks with an interviewer in the ISMG Studio.

How skilled attackers weaponize AI faster

Cisco Talos' Nick Biasini explains why attacker expertise shapes AI's impact across vulnerability research, phishing, ransomware, and malicious tooling.

Amy Chang speaks with an interviewer in front of a city skyline.

Open AI Supply Chain Provenance Explorer

Cisco's Head of AI Threat Research, Amy Chang, introduces her team's free AI Supply Chain Provenance Explorer tool.

Amin Karbasi speaks with an interviewer in the ISMG Studio.

How SLMs can strengthen code security

Cisco Foundation AI's Amin Karbasi explains how Antares, an open-weight small language model (SLM), helps analysts locate vulnerable code while keeping sensitive source code local.

Tom Gillis and Russel Smoak discuss resilient infrastructure for frontier AI.

Mythos demands a new model for infrastructure

Cisco executives Tom Gillis and Russel Smoak go over a new operating model for resilient infrastructure in the face of frontier AI.

A person uses a laptop displaying security analytics dashboards.

AI Models, Right-Sized for Security: The Case for SLMs

Join Cisco Foundation AI experts to learn how security-specific small language models can improve workflows while supporting speed, privacy, cost efficiency, and flexible deployment.

AI security research and resources

FAQ

Find answers to frequently asked questions about Security in the AI Era.

Agentic AI refers to autonomous systems that don't just answer questions (like a chatbot) but actually take actions—executing complex, multi-step workflows, calling APIs, and interacting with enterprise tools at machine speed. Because these agents act as "non-human employees" with elevated privileges, traditional human-centric security models are insufficient. They require a specialized approach that can govern autonomous behavior, verify non-human identities, and prevent "action sprawl."

Frontier AI refers to the most advanced, large-scale, general-purpose artificial intelligence models that sit at the leading edge of current technology. Unlike narrow AI designed for a single task (like identifying spam), frontier AI systems are capable of a wide range of tasks, including complex reasoning, coding, and interacting across multiple formats like text, images, and audio.

AI agents achieve machine speed by utilizing distributed architectures, such as Cisco Hypershield, which place enforcement points directly at the workload level using technologies like eBPF. This decentralized approach allows the system to detect and neutralize threats in milliseconds, bypassing the latency inherent in traditional manual triage and centralized perimeter security. By automating the investigative workflow, AI agents can respond to attacks at the speed of the network itself.

Insider threats and risks in AI security involve individuals with legitimate access—such as employees, contractors, or even the AI agents themselves—compromising the system either through malicious intent or unintentional negligence. Unlike traditional threats, AI-specific risks often center on the sensitivity of training data and the high degree of autonomy granted to AI agents.

Small Language Models (SLMs) are lightweight AI systems with significantly fewer parameters than Large Language Models (LLMs), allowing them to run efficiently on local devices rather than massive cloud clusters. While LLMs are general-purpose giants, SLMs are specialized tools optimized for specific domains. This architectural difference results in near-instant response times, lower computational costs, and enhanced data privacy since information can stay within a secure local network.

In professional workflows, SLMs improve efficiency by automating routine, domain-specific tasks—like code generation or document summarization—with high accuracy and minimal latency.

Connect outcomes to practice

Learn more about Cisco Solutions for AI