Cisco Umbrella DNS and the road to Cisco Secure Access – DNS Defense
Cisco Umbrella defined the industry, making DNS-layer security a critical first line of defense for over 30,000 customers. For years, this approach provided the visibility and control necessary to protect organizations from threats on the internet.
But as the “office perimeter” disappeared and hybrid work became the norm, the threat landscape shifted. Today’s AI-driven attacks and cloud-based vulnerabilities require a more modern and advanced platform.
To meet these challenges, Cisco Umbrella DNS has evolved to Cisco Secure Access – DNS Defense. Secure Access builds on Umbrella’s strengths while delivering new, advanced capabilities designed for today’s evolving risks.
What’s the difference between Umbrella DNS and Secure Access – DNS Defense?
Cisco Secure Access – DNS Defense has all of Umbrella DNS features plus adds Cloud Data Loss Prevention (DLP) to safeguard sensitive data, built-in malware protection to scan and remove malware from cloud file storage apps, and unified policy management that makes deployment and management easy.
It’s backed by Cisco’s global network of recursive DNS resolvers and advanced AI-driven detection, to deliver faster, more comprehensive threat blocking.
For existing Umbrella DNS customers, Cisco provides an upgrade process designed to transfer configurations and convert existing policies into the rules-based policy model used by Secure Access. Learn more about the upgrade offer for existing customers.

What is Cisco Secure Access – DNS Defense?
Cisco Secure Access – DNS Defense is a cloud-delivered security service that uses the Domain Name System (DNS) layer to help prevent users and devices from connecting to malicious or unwanted internet destinations—plus so much more.
Proactively block threats like phishing, ransomware, malware, and DNS tunneling before they reach you with our cloud-delivered security. DNS Defense goes beyond standard DNS security by including cloud DLP and advanced malware protection, helping you keep your sensitive data and files secure across all your cloud applications. Because DNS requests typically occur before a connection to an internet destination is established, DNS Defense can identify and block many threats before they reach your network or endpoints, and its unified policy management makes deployment and management easy.
DNS Defense serves as a foundational DNS security product that can expand to a full Security Service Edge (SSE) solution over time, allowing organizations to evolve and expand their security protection at their own pace.
What threats does Secure Access – DNS Defense protect against?
DNS Defense helps protect users, devices, and networks from internet-based threats while reducing the number of threats that reach other security controls.
Malware, phishing, and ransomware: DNS Defense can block access to domains associated with malware, phishing, botnets, ransomware, and other high-risk activity before a connection is made.
DNS tunneling and advanced threats: AI-based detection helps identify techniques such as DNS tunneling and Domain Generation Algorithms (DGAs), which attackers can use for command-and-control communications, lateral movement, or data exfiltration.
Risky and unwanted destinations: Organizations can use web content filtering and policy controls to restrict access to categories or specific destinations based on their security, acceptable-use, or compliance requirements.
Threats to files and data in cloud apps: DNS Defense also extends beyond DNS-layer protection. Available capabilities include cloud malware protection and Cloud Loss Prevention (DLP) to help identify malicious files and sensitive data in supported cloud applications.
Built on Cisco’s global DNS infrastructure
Cisco operates a global recursive DNS service with more than 50 DNS points of presence. DNS requests are resolved through this infrastructure while DNS Defense evaluates destinations for security risks and applies organizational policies.
Cisco processes more than 800 billion DNS requests each day, providing broad visibility that contributes to its DNS threat intelligence. Cisco Talos threat intelligence further informs DNS Defense using threat research, statistical analysis, machine learning, and other detection techniques.
Start with DNS security and expand when you need to
DNS Defense can be used as a DNS-centric security solution without requiring an organization to purchase or deploy the full Cisco Secure Access Security Service Edge (SSE) platform.
Organizations that later need additional security capabilities can expand to other Secure Access capabiliites, including Zero Trust Network Access (ZTNA) and Secure Internet Access. This provides a way to begin with DNS-layer security while maintaining a flexible path to a broader SSE architecture as requirements change.
See how DNS Defense can protect your organization
Evaluate DNS-layer protection for your users, devices, and networks with a Cisco Secure Access – DNS Defense free trial.
Learn more about Cisco Secure Access – DNS Defense
Explore Secure Access – DNS Defense
Block threats before they can reach your network and endpoints.
DNS Defense data sheet
Learn about solution highlights and get a detailed description of features and packaging.
DNS Defense At-a-Glance
Get an overview of Secure Access – DNS Defense and its benefits.
Umbrella DNS and Secure Access – DNS Defense FAQs
Is Secure Access – DNS Defense the same as Cisco Umbrella DNS?
Secure Access – DNS Defense is the successor to Cisco Umbrella DNS. It retains Umbrella’s DNS-layer security while adding an additional advanced capabilities, including cloud malware scanning, cloud DLP and more.
What is happening to Umbrella?
Cisco is beginning a planned end-of-sale and end-of-life transition for Cisco Umbrella, with Cisco Secure Access becoming the strategic platform for cloud-delivered security. This does not mean existing Umbrella services will stop immediately. Customers will continue to receive service and support according to their subscription terms and Cisco’s published end-of-life milestones, providing time to plan and complete their transition.
Secure Access is replacing Umbrella because it builds on Umbrella’s proven cloud security capabilities while delivering them through a broader, unified Security Service Edge platform. It retains DNS-layer protection through Secure Access DNS Defense and adds capabilities such as secure web access, zero-trust access to private applications, more granular access controls, centralized policy management, and consistent protection for users wherever they work.
What if I’m a current Umbrella DNS customer?
Customers may continue to purchase new Cisco Umbrella subscriptions through the End-of-Sale (Jan 2027) and renew existing subscriptions through the End-of-Renewal (Jan 2028) date. Support remains fully active until the End-of-Support date in January 2029.
Cisco is providing tools and guidance to help customers upgrade. During the migration, supported Umbrella configurations and policies can be copied into Secure Access, traffic can be moved in phases, and Umbrella continues operating until the transition is completed. Customers should work with their Cisco account team or partner to confirm which end-of-sale dates apply to their subscription and develop an appropriate migration plan.
We recommend you take advantage of the special budget-friendly upgrade to Secure Access migration offer for existing Umbrella customers. Click to learn more about the Secure Access upgrade offer.
How does DNS-layer security work?
DNS translates domain names—such as the name of a website—into the IP addresses computers use to connect to internet resources.
DNS Defense uses this step as an early point of enforcement. When a user or device requests a domain, DNS Defense evaluates the request and applies your organization’s security policies. Requests to malicious or prohibited destinations can be blocked before the connection is established.
This approach provides protection across ports and protocols without requiring every internet connection to be inspected first.
What threats can DNS Defense block?
DNS Defense is designed to help prevent connections to domains associated with malware, phishing, ransomware, botnets, command-and-control activity, and other high-risk destinations. It also includes AI-based capabilities for detecting threats such as DNS tunneling, Domain Generation Algorithms and more.
Do I need to purchase the full Cisco Secure Access platform to use DNS Defense?
No. Organizations can use DNS Defense as a DNS-centric security solution. If additional capabilities are needed later, they can expand to other Cisco Secure Access services, including ZTNA and Secure Internet Access.
Does DNS Defense provide more than DNS security?
Yes. In addition to DNS-layer security, DNS Defense includes capabilities beyond traditional DNS filtering. Depending on the package and configuration, these include web content filtering, cloud DLP, cloud malware protection, and more.
Want to strengthen your security with Secure Access – DNS Defense?