The legacy of Cisco Umbrella
For years, Umbrella has been recognized as the gold standard for DNS-layer security, providing a critical first line of defense for organizations worldwide. By blocking threats before a connection was even established, it gave IT teams the visibility and control they needed to keep their networks safe. It’s a powerful solution that has set the foundation for how we protect the modern internet.
However, the threat landscape has evolved rapidly since Umbrella’s foundations were laid. Today’s attackers are more sophisticated, and with hybrid work, the proliferation of cloud-based applications, and AI-based threats, a more modern and advanced solution is required.
This shift is why Cisco Umbrella has evolved to Cisco Secure Access. Rather than simply updating an old tool, we built a modern security platform from the ground up to address the challenges of today’s hybrid world. Secure Access isn’t just a replacement; it is the evolution of everything that made Umbrella successful, enhanced with the capabilities required for today’s risks.
What is Cisco Secure Access?
Cisco Secure Access is a cloud-delivered Security Service Edge (SSE) solution that helps organizations securely connect users, devices, applications, and AI agents wherever they are.
Grounded in zero trust, Secure Access brings security and access functions together in a cloud-managed service. It protects access to the internet, SaaS applications, and private applications while giving IT and security teams centralized policy, visibility, and control.
Cisco Secure Access combines core SSE capabilities—including Zero Trust Network Access (ZTNA), Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), and Firewall as a Service (FWaaS)—with additional security, data protection, and access capabilities in a unified solution.
.
How does Cisco Secure Access work?
Secure Access evaluates who or what is requesting access, what resource is being accessed, and relevant security context before applying policy.
This allows organizations to control access based on identity, device posture, application, destination, risk, and other contextual information rather than relying primarily on a user’s location on the corporate network.
For IT and security teams, Secure Access centralizes policy creation, reporting, and management. A unified client also helps reduce the need for users to interact with multiple security agents and sign-in processes.
What does Cisco Secure Access protect?
Secure Access provides security and access controls across all your internet and SaaS private applications—whether modern or legacy.
Private applications: Zero Trust Network Access provides granular, application-specific access to private resources in data centers and cloud environments. Access is denied by default and granted according to policy and context. For applications or traffic that aren’t suited to ZTNA, VPN as a Service (VPNaaS) provides secure private access, including support for legacy applications.
Internet and SaaS applications: Secure Web Gateway capabilities inspect and control web traffic to help protect users from malicious websites, infected files, phishing, ransomware, and other internet threats.
Cloud Access Security Broker: CASB capabilities provide visibility and control over SaaS application usage, helping organizations identify and manage sanctioned and unsanctioned applications.
Sensitive data: Data Loss Prevention provides controls designed to identify sensitive information and reduce unauthorized data movement across internet, SaaS, private application, and endpoint channels.
Generative and agentic AI: Secure Access provides visibility and controls for generative AI applications and model repositories. AI Access capabilities help organizations identify shadow AI, control how AI applications are used, and reduce risks such as sensitive data exposure.
Zero trust for agentic AI: Secure Access also extends zero trust security to agentic AI, providing controls for autonomous AI agents and their interactions with identities, applications, APIs, tools, and data.
Key functions and features of Secure Access
Apply zero trust to access: Secure Access uses identity, device posture, contextual information, and least-privilege policies to determine access. With ZTNA, users can be given access to the specific applications they’re authorized to use instead of broad access to the underlying network.
This approach can help reduce the attack surface and limit an attacker’s ability to discover resources or move laterally if an account or device is compromised.
Monitor the user experience: Secure Access includes Experience Insights, powered by ThousandEyes, to provide visibility into digital experience across users, networks, and applications.
This information can help IT teams determine whether an access problem originates with a user’s device, network connectivity, an application, or another part of the connection path and troubleshoot problems more quickly.
Support security and compliance requirements: Secure Access includes security and data protection controls that can help organizations address regulatory and compliance requirements. Secure Access has also achieved FedRAMP authorization for specified capabilities supporting U.S. government requirements.
Simplify operations with Cisco Cloud Control: Secure Access is part of Cisco Cloud Control, which provides a foundation for connecting these security capabilities with a broader Cisco operating environment as the organization’s requirements evolve.

Start with the security capabilities you need
Organizations do not need to adopt every Secure Access capability at once—there is flexibility to roll out capabilities based on your unique needs and priorities. Those looking primarily for DNS-layer security can start with Cisco Secure Access – DNS Defense.
Organizations with broader requirements can use Secure Access for capabilities such as secure internet and SaaS access, ZTNA, VPNaaS, data protection, AI security, and digital experience monitoring.
Secure Access Architecture
Evolution of Umbrella to Secure Access FAQs
What is Cisco Secure Access?
Cisco Secure Access is Cisco’s cloud-delivered SSE solution. It combines ZTNA, Secure Web Gateway, CASB, Firewall as a Service, and additional capabilities for secure private access, data protection, AI security, and digital experience monitoring. It is part of Cisco Cloud Control, which provides a unified operating experience across Cisco technologies.
What is happening to Umbrella?
Cisco is beginning a planned end-of-sale and end-of-life transition for Cisco Umbrella, with Cisco Secure Access becoming its strategic cloud security platform. Existing Umbrella services will not stop immediately. Customers will continue to receive service and support according to their subscription terms and Cisco’s published end-of-life milestones, providing time to plan and complete their transition.
Secure Access builds on Umbrella’s proven capabilities while delivering them through a broader, unified Security Service Edge platform. It retains DNS-layer protection through Secure Access – DNS Defense.
Cisco is providing existing customers with tools and guidance to support the upgrade. Umbrella policies and configurations can be transferred to Secure Access, traffic can be migrated in phases, while Umbrella continues operating during the transition. Customers should work with their Cisco account team or partner to confirm applicable dates and develop a migration plan.
What if we’re a current Umbrella customer?
Customers can renew existing subscriptions through the End-of-Renewal date in January 2028. Support remains fully active until the End-of-Support date in January 2029. However, we recommend you take advantage of the special budget-friendly upgrade to Secure Access offer with migration assistance for existing Umbrella customers. Click to learn more about the Secure Access upgrade offer.
What is the difference between Cisco Secure Access and SSE?
SSE is an architecture that delivers security and access functions from the cloud. Cisco Secure Access is Cisco’s modern SSE solution, combining the core elements of SSE with additional security and operational capabilities.
What is Security Service Edge (SSE)?
Security Service Edge, or SSE, brings security services traditionally delivered by separate products into a cloud-delivered architecture. Instead of relying on a traditional network perimeter to protect access to applications and data, SSE delivers security controls from the cloud and applies them wherever users and resources are located.
Is Cisco Secure Access a VPN replacement?
Secure Access can use ZTNA to provide application-specific access as an alternative to traditional network-level VPN access. However, not every private application or traffic type is suited to ZTNA. Secure Access also provides VPN as a Service for applications and use cases that require VPN-based access.
What does Cisco Cloud Control add to Secure Access?
Cisco Cloud Control gives Secure Access customers a broader operating environment that connects security with Cisco networking, observability, and infrastructure technologies. It provides centralized management, shared context across supported Cisco products, and AI-assisted capabilities designed to simplify policy management, investigation, troubleshooting, and other operational tasks.
Does Secure Access protect AI use?
Yes, Secure Access provides visibility and policy controls for generative AI applications and model repositories, including controls designed to reduce sensitive-data exposure. Secure Access also extends zero-trust principles to agentic AI interactions involving autonomous agents, identities, applications, APIs, tools, and data.
Want to strengthen your cybersecurity with Secure Access?