- 5g
- Adtran
- Aruba
- Buyers Guides
- BYOD
- Case Studies
- Cisco
- Cloud Computing
- Collaboration
- Cybersecurity
- Data
- Data Security
- EBook
- Features
- Firewalls
- For Fun
- Fortinet
- Higher Education
- Hospitality Solutions
- HPE
- Hybrid Work
- Internet Service
- IT Services
- Juniper
- Lenovo
- Meraki
- Netgear
- Network Security
- Networking
- Optical Transceivers
- Phones
- Power and Protection
- Printing
- Remote Work
- SASE
- SD-WAN
- Security Cameras
- Small Business
- Sophos
- Switches
- Tips
- Ubiquiti
- Used Network Equipment
- Vendors / Brands
- Video
- VoIP
- Wireless
- Zero Trust
- Tech Resources
What Is Cisco Umbrella (And Why You're Seeing Cisco Secure Access?
Max Rotter
Network Security | Video
9 minute read
If you've searched this because you've started seeing Cisco Umbrella referred to as Cisco Secure Access in a vendor quote, a renewal notice, or on Cisco's own site, you're not imagining it. Cisco Umbrella is evolving into Cisco Secure Access, and this guide covers what that actually means for your deployment. Cisco Umbrella is a cloud-native Security Service Edge (SSE) platform designed to protect endpoints, roaming users, and distributed networks from web threats before connection requests clear your infrastructure.
By unifying DNS-layer security, a Secure Web Gateway (SWG), a Cloud-Delivered Firewall (CDFW), and a Cloud Access Security Broker (CASB) into a single tenant dashboard, it acts as your primary recursive resolver. This allows you to stop malware, ransomware, and command-and-control (C2) callbacks over any port or protocol.
Instead of hairpinning traffic back to legacy on-premise appliances or deploying complex hardware at every branch site, Umbrella operates entirely in the cloud. It extends policy enforcement and threat protection to remote users via the Cisco Secure Client (formerly AnyConnect) or lightweight network integrations within minutes.
This guide breaks down how Umbrella functions under the hood, what's actually changing with the Secure Access naming, how it differs from traditional SWG appliances, and how to integrate it into your existing Enterprise security stack.
Cisco Umbrella At A Glance
"Cisco Umbrella" and "Cisco Secure Access" refer to the same underlying platform at different points in its rollout. Cisco is shifting its marketing toward the Secure Access name over time, but the DNS-layer security Umbrella built its reputation on hasn't gone anywhere, and Umbrella DNS remains an active, current product today.
Understanding what is Cisco Umbrella starts with its core function: a cloud security platform that protects users, devices, and networks from internet threats, no matter where people connect from. It plays a central role in the secure access service edge (SASE) model, which consolidates networking and security functions, like a secure web gateway, cloud-delivered firewall, CASB, and DNS security, into one centralized framework instead of a collection of standalone tools.
For IT teams managing distributed workforces, that consolidation means fewer vendor contracts to track, fewer consoles to log into, and one policy set that applies whether a user is on the corporate network or working from a coffee shop.
SIG, SWG, CASB, And Firewall In One Unified Platform
Cisco packages these capabilities under what it calls a Secure Internet Gateway, or SIG. Umbrella bundles several security functions that IT teams usually buy and manage separately. Instead of standing up individual tools for each layer, you get all of them delivered from one cloud service:
DNS-layer security that blocks malicious domains
Secure web gateway with URL filtering for deeper web traffic inspection
Cloud-delivered firewall, including intrusion prevention system (IPS) capabilities, for consistent policy enforcement
CASB for visibility into sanctioned and unsanctioned cloud apps
Advanced threat intelligence from Cisco Talos
Streamlined, cloud-native management dashboard
How DNS-Layer Security Actually Works
Umbrella enforces security at the DNS resolution stage, using Cisco's global network to check where a request is headed before your device gets there. That means threats get blocked before a malicious page loads, not after.
Blocking Threats At The DNS Resolution Layer
Every DNS request from your network routes through Cisco Umbrella's cloud before it resolves. When a request matches a known threat, Umbrella blocks it based on:
Malicious domains and IP addresses flagged by threat intelligence
Malicious websites and other malicious destinations, including phishing pages and malware-hosting sites
Risky or uncategorized cloud apps outside approved policy
Instead of a generic connection error, the user sees a customizable block page explaining why access was denied, which cuts down on help desk tickets from confused employees.
Real-Time Threat Intelligence From Cisco Talos
Cisco Talos is the threat research team behind Umbrella's intelligence. Talos and Umbrella's cloud infrastructure process more than 620 billion DNS requests a day from over 30,000 organizations worldwide, which gives Umbrella the visibility to catch new and emerging threats early, often before a static blocklist would.
Extending Protection To Roaming And Remote Endpoints
A lightweight client installs on user devices so protection travels with them, on or off the corporate network. Cisco has been migrating users from the legacy Umbrella Roaming Client to Cisco Secure Client, so the delivery method is actively changing, but coverage for roaming users stays consistent throughout the transition.
Cisco Umbrella Vs. Traditional Secure Web Gateways
Traditional secure web gateways run on hardware appliances installed at every location you support. Umbrella works differently:
Traditional secure web gateway (hardware appliance):
Requires procurement, shipping, and an install window at each site
Needs firmware and license updates on every device
Routes traffic through a central location, adding backhaul latency
Ages out and needs replacement over time
Cisco Umbrella (cloud-delivered):
No hardware to buy, ship, or install
Enforces protection at the DNS layer before a connection is made
Extends to a new site or remote user in minutes
Updates and scales centrally through Cisco's cloud, with no on-site maintenance
That difference in time-to-protect matters most when you're onboarding a new office or securing a remote hire on short notice.
How Cisco Umbrella Fits Into Your Existing Security Stack
Umbrella is built to work alongside your existing security tools instead of replacing them, so you're not tearing out gear that's still doing its job. In practice, that includes:
Exporting Umbrella logs to a SIEM platform like Splunk for correlation with other security data
Connecting to Cisco SecureX and XDR (extended detection and response) to bring DNS-layer alerts into the same console as your other security events
Integrating with Cisco ISE or a third-party identity provider, such as Okta or Azure AD, to apply DNS policy based on user identity rather than just IP address
That gives you a combined view of alerts and response actions across your environment, so you can investigate and act on a threat without switching between separate tools.
Operational Benefits For IT And Security Teams
The benefits below matter most for IT teams managing a network without a fixed perimeter: multiple locations, remote users, and cloud apps that don't sit behind a single firewall. Each one ties back to the same DNS-layer mechanism covered above, applied to a specific operational problem.
Faster, Simpler Deployment Across Multiple Locations
Because Umbrella runs from the cloud, rollout doesn't depend on a site-by-site setup:
Deploy across every location at once instead of scheduling individual installs
No shipment or install window to wait on per site
Especially useful for SMBs managing several offices with a small IT team
Lower Remediation Costs When A Breach Occurs
Blocking threats at the DNS layer, before they reach a device, limits how far an incident can spread:
Fewer compromised endpoints to clean up after an incident
Lower recovery costs relative to threats that reach the network
A clearer ROI case for budget-conscious IT managers
Faster Threat Detection And Containment
Visibility at the DNS layer moves detection earlier in the attack chain:
Spot suspicious activity before it reaches an endpoint
Contain threats without waiting for a post-damage alert
Reduce the window between initial compromise attempt and response
Centralized Visibility Into Network Activity
Umbrella gives you one view of internet activity across users, devices, and locations:
Single dashboard instead of pulling data from multiple systems
Supports both security monitoring and policy enforcement
Consistent reporting across every site, not just headquarters
Shadow IT And Cloud App Visibility
Umbrella's CASB capability shows you which cloud apps your team is actually using:
Surfaces unsanctioned apps IT never approved
Supports acceptable-use policy enforcement, blocking specific malicious sites or entire categories
Reduces shadow IT risk before it becomes a bigger problem
Matching Cisco Umbrella And Secure Access Tiers To Your Network Needs
Cisco Umbrella and Cisco Secure Access aren't single products each. Both split into multiple product lines, and every one of those lines comes in more than one tier, which is exactly why Cisco's own site currently shows legacy and current naming side by side.
Umbrella covers DNS-layer security through two product lines: DNS and SIG (Secure Internet Gateway). Each comes in an Essentials or Advantage version, with Advantage building on Essentials rather than replacing it. Secure Access carries that same DNS-layer foundation into three product lines of its own, each also sold in Essentials and Advantage tiers:
Umbrella DNS (Essentials or Advantage): Core DNS-layer security and malicious-domain blocking. This is Umbrella's baseline tier.
Umbrella SIG (Essentials or Advantage): Everything in Umbrella DNS, plus the secure web gateway, CASB, and cloud-delivered firewall bundled into Cisco's Secure Internet Gateway.
Secure Access DNS Defense (Essentials or Advantage): The Secure Access equivalent of Umbrella DNS, also sold as EDU packages for education customers.
Secure Access Secure Internet Access, or SIA (Essentials or Advantage): Adds a secure web gateway, CASB, data loss prevention, and cloud-delivered firewall on top of DNS-layer protection. SIA also ships in a site-based version built for onsite users only, and that version is Essentials only, it doesn't have an Advantage tier.
Secure Access Secure Private Access, or SPA (Essentials or Advantage): Adds zero trust network access and VPN as a service on top of SIA, for teams building toward a full SSE deployment.
A single-site team mainly looking to block malicious domains and reduce phishing exposure typically starts with Umbrella DNS or Secure Access DNS Defense. A team managing multiple locations, a remote workforce, or a growing list of sanctioned and unsanctioned cloud apps usually needs the added inspection and control in SIG, SIA, or SPA to cover that broader surface area.
If you're not sure which tier fits, start with what you're trying to solve, DNS-layer blocking alone or a fully unified platform, and confirm exact tier names, feature breakdowns, and pricing with your Hummingbird Networks rep before you commit. Cisco is actively transitioning naming across both product families, so what's current can shift between your first conversation and your renewal.
FAQs
Is Cisco Umbrella being discontinued, and do I have to migrate to Secure Access?
No. Umbrella isn't being retired, and there's no forced cutover you need to take action today. The Secure Access name is rolling out gradually, and your existing DNS-layer protection keeps running through the transition. If Secure Access shows up on a renewal or quote, that's the naming catching up, not a new product you have to redeploy. Your Hummingbird Networks rep can confirm what, if anything, changes for your specific contract.
How much does Cisco Umbrella cost?
Umbrella is priced per user, per year, and the total depends on which tier you choose and how many people you're covering. The DNS-layer tiers cost less than the fuller Secure Internet Access or Secure Private Access packages that add web gateway, CASB, and firewall features. Actual pricing varies by deployment size, term length, and active promotions, so the fastest way to get a real number is a quick quote from Hummingbird Networks.
Is there a free trial for Cisco Umbrella?
Yes. You can try Umbrella's DNS-layer protection before committing, which is a low-risk way to see what it actually blocks on your own network traffic. A trial usually takes only a few minutes to turn on since there's no hardware involved. Hummingbird Networks can set up a trial and help you read the results, so you're comparing tiers based on your environment rather than a generic demo.
What does it actually take to deploy Cisco Umbrella?
For network-wide DNS protection, you point your routers or DNS forwarders at Umbrella's global resolvers, and requests start filtering through Cisco's cloud right away. For laptops and devices that leave the office, you push the Cisco Secure Client so protection follows the user off-network. There's no appliance to rack and no traffic to reroute through a central site, which is why rollout across several locations can happen in one sitting rather than site by site.
Does Cisco Umbrella replace my firewall?
For most teams, no. Umbrella adds a DNS layer that sits in front of your firewall and blocks malicious destinations before traffic ever reaches it, but it doesn't take over everything an on-network firewall handles for internal traffic and segmentation. A cloud-delivered firewall is available starting with Umbrella SIG and carried through the higher Secure Access tiers, which some distributed teams use to reduce on-site hardware over time. Whether that fits depends on how much of your traffic still runs through a physical location.
Does Cisco Umbrella work with Cisco Meraki?
Yes. Umbrella integrates directly with Cisco Meraki, so you can apply DNS-layer security across a Meraki MX or MR deployment without standing up separate infrastructure. For teams already running Meraki, that means extending threat blocking to every site the Meraki network touches and managing it from familiar tools. If Meraki is the backbone of your environment, it's worth mapping the integration before you settle on an Umbrella tier.
Start Protecting Your Network With Cisco Umbrella
Cisco Umbrella gives SMB IT teams a way to secure a distributed network without adding hardware, headcount, or hours of manual work. Hummingbird Networks helps you match the right tier, Umbrella DNS through Secure Access SPA, to your environment, so you get the firewall, web gateway, threat intelligence, and CASB capabilities you need in one cloud-delivered service, with support from a team that knows Cisco and Meraki. Whether you're running Umbrella DNS today or already seeing Secure Access show up on a renewal, the underlying protection, and the team helping you manage it, stays the same.
Need network security your IT team can count on? Contact us to discuss your network security needs.
