Secure Networking: If it's connected, it's protected

Introduction

In a rapidly digitizing world, where businesses are shifting online, data resides in the cloud, and remote work has become the standard, security challenges have reached an all-time high. This situation has significantly impacted the telecommunications sector, presenting a unique opportunity for Cisco. I led a diverse UX team, partnering with stakeholders across business units to enhance our network solutions with unparalleled security, guaranteeing the safety of every connection.

Team

Yuanyuan Hu - Product Design Lead
Jean Fitzpatrick - Product Designer
Wei Tien Pang - Product Designer
Wanda Lam - Visual Design Consultant
Madhu Somu - Product Manager
Tahir Ali - Technical Marketing Engineer

Security Trend

Customers felt overwhelmed managing every security vendor for each security domain; more than 75%* of organizations are pursuing vendor consolidation.

Git Bash

Network connections and cyber-attacks are actually born together. When end-users access a file in the cloud, the data travels through different network components and may experience hundreds or thousands of cyber-attacks. With IoT and remote working, the connections become even more distributed, thus facing more threats. In the current market, there are small vendors that specialize in a few aspects of network security, but managing these across multiple locations and platforms adds extra layers of complexity. *Source: Help Net Security

Strategy

Craft a seamless secure networking experience to win both markets.

Git Bash

Cisco has been the industry leader in enterprise networking, yet there isn't a clear leader in cybersecurity that provides end-to-end protection. Given that network and security are inherently related, we saw an opportunity to leverage our strong networking background to offer integrated security solutions and become leaders in this emerging field. Looking at the market share, Cisco is the only big player in the network and security field, which gives us the chance to redefine the competition. In the future, users won't need to worry about connection and security separately. With our secure network solution, we will protect every one of their connections and every bit of data.


User Research

Enterprise users have their own definitions of what is easy.

We've received feedback from stakeholders that our product is perceived as complex, but the reasons behind this perception were unclear to us. I conducted a survey and got 55 responses from our major customers and partners and did the one-on-one interviews with 8 network engineers and 4 seucirty engineers tp understand there current experience and what they are looking for.

What's your ideal experience in managing the network/security?

Git Bash

What level of configuration is typically required at your work?

Git Bash

Simplicity in our context does not equate to being overly simplistic, especially given our diverse enterprise customers, such as those from the public and financial sectors, each with unique compliance and security requirements. Therefore, while we aim to simplify, we also must ensure our solutions are easy to customize to meet the varied needs of our users.

Could you walk me through the current steps of configuring and managing the network/security?

Git Bash

Design Principles

Enterprise customers loved the type of simplicity that is reliable, flexible, and scalable.

Git Bash

Security as a core belief
Wherever and whenever a connection is established, security should be equally important.

Git Bash

Simple setup
Streamline initial network and security setup with automated tools, user-friendly interfaces, and customizable security templates for quick and efficient deployment.

Git Bash

Easy to Customize
Central management of thousands of sites and automation of workflows rather than doing the same thing 1,000 times.

Git Bash

Monitor on the same page
Gain visibility and control over your network security with detailed dashboards, customizable alerts, and topology visualization.

MVP

What is the minimal effort required to get the secure network up and running?


Git Bash

There are customers who want granular control over their network and security, while increasingly, small and medium-sized companies want to move quickly and get their business up and running. Beyond just the part we see on the UI, we are innovating across the entire product lifecycle. We can even pre-load these configurations onto devices during the manufacturing stage, which is more than just providing default configurations as templates. Customers can achieve secured connectivity simply by plugging in a Cisco device, or even without physical deployment if they choose to go virtual. As always, we will allow day-N modifications since network and security needs are always dynamic, depending on actual usage.

💡 Research Insights: We demonstrated our config catalog function to customers and partners. They like the concept and think it would be even better if it were preloaded out of the box.


Plug-and-play experience for day 0



💡 Research Insights: Ideally, all research participants would like one solution that did both out-of-the-box simple workflows and configurations with an option to do more advanced things on the same tool; if have to choose one, they need to give up simplicity


Customize configuration if needed



Configure Hardware

Configure a site with embedded security in moments.

💡 Research Insights:
     - Users didn't know that Cisco has embedded security in the devices, so we need to show it.
     - Most of our customers have asked Cisco to create default configurations and policies for them.

Git Bash

In the Day-0 configuration, my focus was on simplicity and visualization. In the design, we recommended a bundled solution that includes both router and firewall, ensuring that all connections are protected by default. Starting from an industry-based site template, we transformed our product into a real service, so that users don’t need to deal with the complexity of network infrastructures but can enjoy secured connectivity right away. The mini topology diagram not only serves functional needs to aid users with configuration but also serves as a marketing piece that showcases how Cisco treats security and connectivity as equally important.

Define Policy

Users can use the Cisco default for common use cases and customize it if they want.

💡 Research Insights:
    - Users are thinking about policies from the business perspective rather than network device perspective.
    - Matching criteria used in different types of policies are similar, so they should be reusable.
    - Users want to group policy and configuration for similar sites and deploy them at once.

Git Bash

Policy group - create policy based on business intent rather than each device.

Git Bash

In designing this Policy Manager, I aimed to create a solution that meets the needs of customers of all sizes while making it very relevant to individual customers. The idea is to always start from a default policy and provide a simple way for users to customize. This is based on our observation in the field: when our sales engineers present different types of policies, users always ask for examples. We started to build our library, and I proposed a design idea to make it available in the product and accessible to all users.

💡 Research Insights: We provided a default application policy but didn't explain it to users, so they could not trust it.

App policy - Simplification and visualization

Git Bash

💡 Research Insights: Users liked the conventional rule table for policies like security and routing.

Security policy - Unified rule builder

Git Bash

The policy manager was also designed for scalability. Instead of managing policies for individual sites, we group sites with similar intent and set their policies together but let AI optimize individual policies based on daily usage.

Respond to Threats

Manage connectivity and security from one dashboard.

💡 Research Insights: Security companies all have their niches, so users need to mix and match different solutions from different vendors. Jumping between 5+ dashboards is normal.

Git Bash

I designed this dashboard to present complex network security data in a user-friendly and accessible manner. It provides an overview of all threats and uses a timeline to allow for detailed analysis. I began with basic charts from our traditional firewall and then upgraded the dashboard with data from Cisco and third-party integrations. All information, from user authorization to file inspection, is integrated into this one dashboard, offering users a comprehensive overview. Thus, users can adopt a clear approach to managing their security and connectivity, instead of juggling many fragmented tasks.

Enhance with Integrations

Explore full-stack security offerings from Cisco or vendors of your choice.

💡 Research Insights: We had integrated with Cisco and mainstream third-party security products, but most users and even our colleagues didn't know what they were.

Git Bash

We offer a premium experience to users who opt for the full-stack Cisco solution, achieved through deep integration and automation. Simultaneously, we ensure an optimized experience for integrating with third-party vendors. As highlighted in the market share chart and security journey diagram, the landscape is populated with numerous vendors and specialized security solutions. After designing a few integrations successfully, I identified recurring patterns. This led me to propose a strategy for centralizing and standardizing the integration experience. This approach not only streamlines operations but also showcases our comprehensive coverage in security, cloud, and analytics to our users. It demonstrates our commitment, as a market leader, to maintaining an open and extendable platform and seeking the best for our customers.

Results

Our simple and flexible experience has secured a 34% YoY growth and proved the value UX can bring.

Git Bash
Git Bash

In 2023, the AI policy automation I designed was mentioned in the annual Cisco Live opening note.

"While you are here, you can also check Thousandeyes WAN insights… This is now automated with Cisco Catalyst SD-WAN. You see the recommendations, you can just actually implement these recommendations with one click."
- Jonathan D, EVP of Cisco Networking, Cisco Live Opening Keynote, 2023

In 2024, it's the first time our product gained a demo slot. This could not have been done without our constant innovation and pursuit of great design.

"You can simply apply your security policy and you're able to deploy it to branch sites. It is literally that easy. This enables you to rapidly deploy scalable, highly secure SASE-based architecture with just a few clicks."
- Jonathan D, EVP of Cisco Networking, Cisco Live Opening Keynote, 2024