Cisco Systems, founded in 1984 and headquartered in San Jose, has grown into a global networking and telecommunications leader, supported by over 71,000 employees across more than 80 countries and inclusion in major market indexes. Beyond core networking hardware, Cisco has expanded through acquisitions and product development into areas such as VoIP, wireless, cloud, and information security, with major acquired assets like WebEx becoming billion-dollar business units. In security, Cisco offers a broad portfolio spanning firewalls, network security, web/email/cloud security, identity and access control, and advanced malware protection, strengthened by acquisitions including Sourcefire and Threat Grid.
As cyberattacks become more persistent and multi-vector, and the traditional perimeter model erodes, the emphasis of security has shifted from primarily preventing intrusions to continuously monitoring environments to quickly uncover, analyze, contain, and remediate threats. Traditional signature-based tools and classic intrusion detection are described as insufficient against sophisticated attacks that may remain hidden for months. SIEM platforms, while widely adopted, are portrayed as increasingly ineffective due to alert overload and false positives, even when staffed by dedicated teams. A newer generation of security analytics tools applies big data techniques to correlate signals across sources, detect anomalies in real time, and automate analyst workflows.
Cisco Advanced Malware Protection (AMP) addresses this shift by combining preventive controls with continuous monitoring and correlation across multiple “control points” (endpoints, network, cloud, email, web gateways, data centers, and virtual environments). AMP tracks files throughout their lifecycle, generates context-rich alerts when malicious behavior emerges, and enables response actions such as quarantine and network-level containment. Its effectiveness is reinforced by integrations with Cisco Talos threat intelligence and Threat Grid analysis, while a unified browser-based console and shared ecosystem across deployments aim to reduce alert volume and prioritize incidents via risk scoring. Despite strong coverage and deployment flexibility, AMP is characterized as not fully meeting the breadth and extensibility of a true security analytics platform, with cost and centralized administration limitations noted.
See All Locations
See All Locations