Green LightGreen Light
All news
Protection with No Blind Spots
EventsFollow-upCiscoMUK

Protection with No Blind Spots

Cisco Experts on the Three Frontiers of the Modern Network

On June 4, a closed-door business conference for IT executives and cybersecurity specialists titled “Silk Road 2.0” was held in Tashkent, organized by Green Light and MUK Group Uzbekistan, a distributor. The speakers discussed three key issues: how to build a secure corporate network, manage infrastructure from the cloud, and stop a cyberattack before it causes real damage.

Материалы мероприятия

Запросите презентации и материалы «Шёлковый путь 2.0» - пришлём по заявке.

The Network as a Foundation

Alexander Morgun, Technical BDM at MUK Group, spoke of the corporate network as the foundation of infrastructure. The corporate network is no longer just a collection of cables and switches; today, it determines a company’s ability to operate in an environment characterized by hybrid offices, distributed applications, and an ever-expanding attack surface.

Four trends are reshaping infrastructure requirements right now:

  1. The workplace has become hybrid: employees work from anywhere and expect the same quality of connection everywhere.
  2. Applications no longer reside in a single data center. They are distributed across clouds, edge nodes, and corporate servers, and the Internet has become the new core of the corporate network.
  3. The security perimeter is gone. Zero Trust and cloud-based security tools are replacing the traditional network perimeter firewall.
  4. Operations management is shifting toward AIOps: machine learning is taking over observability and automation in areas that previously required a human engineer.

The Cisco Catalyst 9000 Series is the answer to these requirements. It is a unified, software-defined ecosystem spanning from the access layer to the core, running on the common Cisco IOS XE operating system and managed centrally through Cisco Catalyst Center.

The three-tier campus network model - access, distribution, and core layers - has been around for a long time. But its current implementation is fundamentally different from what was built ten years ago. Catalyst 9000 switches support hot firmware updates without session loss and built-in IPsec. Other models in the series, such as the Catalyst 9300X, are equipped with an x86 processor for running Docker applications directly on the hardware.

Post-quantum cryptography is a separate topic. The HNDL (“Harvest Now, Decrypt Later,” Harvest Now, Decrypt Later) works as follows: an attacker intercepts encrypted traffic today, stores it in an archive, and waits for the advent of a quantum computer capable of breaking classical encryption. Cisco 8000 Series Secure Routers already implement post-quantum cryptography algorithms based on NIST standards. This provides concrete protection against a threat that is expected to materialize within the next few years.

The Cisco 8000 is a platform for network and security convergence at the WAN perimeter. The product line includes an integrated firewall, SD-WAN capabilities with intelligent application-based routing, and support for the SASE architecture. Performance has increased significantly compared to the previous generation: the C8300 model, for example, delivers up to 10 times higher IPsec throughput.

Александр Моргун, Technical BDM в MUK GroupProtection with No Blind SpotsProtection with No Blind Spots
1 / 4

The Cloud Instead of a Server Room

Nodirbek Ikromov, Pre-Sales Engineer, MUK Group, focused on the issue of management: how to administer a distributed network without an engineer at every location. When a company has dozens or hundreds of branches, a different operating model is needed.

Cisco Meraki manages switches, access points, SD-WAN gateways, IP cameras, and IoT sensors through a single browser-based dashboard. Today, the platform serves more than 4 million customer networks and over 14 million active devices in 190 countries. 75% of Fortune 500 companies use Meraki in their infrastructure.

People often ask about Meraki’s architecture: If management is cloud-based, what happens if the internet connection is lost? The answer is that all user traffic goes directly through the customer’s network, bypassing the cloud. The cloud is used solely for management purposes: configuration updates, telemetry, and analytics. If the connection is lost, the network continues to operate normally.

The platform’s key principle is zero-touch provisioning. All you need to do is connect a new device to a power source and the network: it automatically finds the dashboard, downloads the configuration, and becomes operational. For companies with an extensive branch network, this isn’t just a convenience - it’s an operational necessity. All you need to do is ship the equipment to the location and complete the deployment remotely.

Meraki MV cameras eliminate the need for network video recorders, video management systems, and separate storage servers in a video surveillance system. Storage is built directly into the camera - the retention period varies by model and ranges from 60 to 120 days. Analytics run on the device, and video is accessed through the same dashboard used to manage switches and access points. Heat maps, people counting, and human detection are generated from metadata without the need for additional software.

Нодирбек Икромов, Pre-sale Engineer MUK GroupProtection with No Blind SpotsProtection with No Blind Spots
1 / 3

When the intruder is already inside

Baisal Sheraliev, Senior Security Engineer at Green Light, discussed layered defense against targeted attacks. A typical modern attack chain looks like this: a personalized phishing email - the user clicks on a link - is redirected to a malicious website - an unauthorized process is created on their device. This process connects to other machines on the network or directly accesses data. Traditional security solutions view each of these steps as an isolated event and do not link them into a unified picture of the attack. Cisco XDR (Extended Detection and Response) is the platform at the heart of the Cisco Breach Protection Suite architecture. XDR collects telemetry from all layers of the infrastructure: network, endpoints, email, cloud, and firewalls. Machine learning algorithms correlate individual signals and construct an attack chain from them. Instead of a flood of thousands of disparate alerts, you get a single incident card with full context. Incidents are formed from alerts sharing common indicators: the same host, IP address, file hash, or username. Generative AI summarizes the essence of the incident: which assets are affected, the attack timeline, and the entry point. The time from detection to understanding is reduced from hours to minutes. Response is automated through built-in SOAR capabilities (Security Orchestration, Automation, and Response). An analyst configures the rules once, and the system then operates at machine speed: it isolates the infected host, blocks the malicious domain, and revokes compromised credentials. The Breach Protection Suite consists of several components:

  • Cisco Secure Endpoint - EDR agent (Endpoint Detection and Response). It analyzes all processes and files in real time and isolates the device from the network when a threat is detected.
  • Cisco Secure Email Threat Defense protects against email-based threats: phishing, corporate email compromise, account takeover, and malicious attachments. It checks the sender’s and URL’s reputation, scans files, and detects social engineering attacks - attacks where the file itself is clean but the email text is manipulative.
  • Cisco Secure Malware Analytics is a sandbox for unknown files. A suspicious object is run in an isolated environment; the system monitors its behavior and makes a determination based on behavioral analysis, rather than just a hash.
  • Cisco Secure Network Analytics - machine learning-based network traffic analytics. The system builds a model of the baseline behavior for each host and network segment, then responds to anomalies: unusual data volumes, non-standard connections, and signs of lateral movement by an attacker.
  • The Network Visibility Module extends the standard NetFlow (a protocol for collecting network traffic data) by adding endpoint context to network flows - such as the user name, process name, executable file hash, and parent process.
Байсал Шералиев, Senior Security Engineer Green LightProtection with No Blind SpotsProtection with No Blind Spots
1 / 3

Three Milestones - One Architecture

Networking, management, and security are no longer three separate projects with different vendors, teams, and consoles. In Cisco’s integrated architecture, the Catalyst switch knows which devices are connected to a port via ISE, the 8000 router shares telemetry with XDR, and the Meraki camera becomes part of the same sensor ecosystem as the access point.

In the event of an incident, the difference is fundamental: standalone products see only fragments, while an integrated platform sees the full picture of the attack. The time from the first alert to threat containment is reduced from hours to minutes.

Today, investing in networking equipment and investing in cybersecurity are part of a single architectural challenge. As a Cisco Preferred Partner for Security and Services, Green Light designs and integrates Cisco solutions in Central Asia. The company employs more than 10 certified engineers, including those with the highest level of certification - Cisco Certified Internetwork Expert (CCIE) - who cover the entire Cisco technology stack.

If you want to build a reliable infrastructure with a high level of security, Submit a request or contact us using the contact information provided - and Green Light's experts will help you choose the optimal configuration of Cisco solutions for your business needs.

Материалы мероприятия

Запросите презентации и материалы «Шёлковый путь 2.0» - пришлём по заявке.