
Cisco is shifting its cybersecurity strategy toward what it calls “built-in resilience,” as organizations contend with growing numbers of security products, cloud environments, SaaS applications and artificial intelligence systems.
The company’s security leadership in India and South Asia says the expansion of disconnected security tools can make it harder for organizations to detect and respond to threats quickly.
Sandeep Agarwal, Cisco India & South Asia CTO for Security, said nearly 84% of organizations surveyed reported that managing more than 10 security solutions slows detection and response. His comments were reported by Financial Express.
The figure comes as enterprises increasingly operate across multicloud and hybrid environments while adding SaaS applications and AI systems to their technology infrastructure.
Cisco argues that adding more standalone security products to this environment can create additional complexity. Its proposed approach is to make security controls part of the infrastructure itself rather than relying solely on separate products that sit alongside it.
The strategy is built around reducing fragmentation and bringing security, network, application and IT information together. Cisco has described this approach as a move away from what Agarwal called “bolt-in security.”
Cisco’s 2025 Cybersecurity Readiness Index provides broader data on the issue. The study surveyed 8,000 business leaders with cybersecurity responsibilities across 30 markets.
The research found that 77% of respondents said too many cybersecurity solutions slowed their ability to detect, respond to and recover from incidents. It also found that 70% of organizations were using more than 10 point security solutions, while 26% were using more than 30.
Cisco said the survey assessed organizations across five areas: Identity Intelligence, Machine Trustworthiness, Network Resilience, Cloud Reinforcement and AI Fortification.
The research also highlighted a cybersecurity skills problem. Some 86% of respondents said the shortage of cybersecurity talent was a challenge, while 53% said they had more than 10 cybersecurity positions to fill.
Confidence in existing defenses was also limited. Only 34% of respondents said they were very confident in the resilience of their current cybersecurity infrastructure, while 71% believed a cybersecurity incident could disrupt their business within the following 12 to 24 months.
In India, Cisco identified Network Resilience as the most difficult of the five areas, with 34% of respondents ranking it as their organization’s most challenging area to protect.
Cisco’s India data also showed low levels of maturity in several areas. Only 10% of Indian organizations were classified as Mature for Identity Intelligence, 14% for Machine Trustworthiness and 7% for Cloud Reinforcement.
The company found that AI is already being used extensively in Indian security operations. More than 96% of respondents said their organizations were at least partly using AI for threat intelligence, while 88% were using it for threat detection.
AI was also being used for threat response by 74% of respondents and for incident recovery by 80%. However, only 26% said they were fully automating defenses for threat detection.
Cisco’s global research also points to rising security risks associated with AI. It found that 86% of respondents had experienced at least one AI-related security incident during the previous 12 months.
The reported risks included model theft or unauthorized access, cited by 43% of respondents; AI-enhanced social engineering at 42%; data poisoning at 38%; prompt injection at 35%; and training-data exposure at 26%.
Cisco’s response increasingly centers on using the network as a security control point. In its Secure Networking strategy, the company says security should be integrated into the network so organizations can protect network flows, verify identities and apply policy consistently.
The company is also linking this strategy to AI agents, which can interact with large language models, applications, databases and external tools.
In February 2026, Cisco announced additional capabilities under Cisco AI Defense, including AI supply-chain security, an AI bill of materials, MCP governance, multi-turn red teaming, real-time agentic guardrails and greater visibility into agent-to-tool interactions.
Cisco also introduced AgenticOps for Security, which the company said can analyze firewall traffic, capacity, health and configuration data, provide recommendations and autonomously remediate some issues while maintaining security and compliance controls.
The company’s broader security portfolio includes Secure Access, Duo, SASE, Hybrid Mesh Firewall, Hypershield, AI Defense, Splunk Enterprise Security, Cisco Talos and Identity Services Engine.
Cisco’s strategy therefore does not represent a move away from security products. Instead, the company is positioning its products as part of a more integrated architecture that connects networking, cloud, identity, applications, AI and security data.
The approach also builds on Cisco’s integration of networking and security technologies and its use of telemetry across security and observability operations.
For enterprises dealing with multiple cloud platforms, SaaS applications and emerging AI systems, Cisco’s argument is that security cannot depend indefinitely on adding another separate tool every time a new environment or threat appears.
The company is instead pushing for security capabilities to be embedded into the infrastructure and managed through more connected systems.
That strategy puts the network at the center of Cisco’s broader cybersecurity approach while extending the same model to cloud environments and AI systems.
Discover more from Aree Blog
Subscribe now to keep reading and get access to the full archive.

