Securing Internet Access with Cisco Umbrella and Cisco Secure Access
As organizations adopt cloud applications, hybrid work and direct internet access, traditional perimeter security alone is no longer enough. Users now connect to business applications from offices, homes and remote locations. Therefore, organizations need consistent security controls wherever users connect.
Cisco Umbrella provides cloud-delivered internet security that helps organizations identify and block threats before users connect to malicious destinations. Its DNS-layer security can help protect against phishing, malware, ransomware and other internet-based threats.
However, Cisco’s cloud security strategy is also changing. Cisco Umbrella is transitioning toward Cisco Secure Access, Cisco’s broader Security Service Edge (SSE) platform. Secure Access builds on DNS security while extending protection through capabilities such as Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Firewall as a Service (FWaaS), Zero Trust Network Access (ZTNA) and data protection.
In this guide, we examine how Cisco Umbrella works, its key security capabilities, deployment considerations and the transition to Cisco Secure Access.

Securing enterprise internet access with Cisco Umbrella and Cisco Secure Access.What It Is and Why It Matters
Originally launched as OpenDNS in 2006 and acquired by Cisco in 2016, Umbrella operates at the DNS layer — the earliest point at which a threat can be intercepted.Before a device connects to an internet resource, it usually performs a DNS lookup. At this stage, Cisco Umbrella evaluates the request against threat intelligence from Cisco Talos. If the destination is malicious or violates policy, Umbrella can block the request before the connection is established. No malware downloads, no phishing pages loaded.
The scale behind this is significant: Umbrella processes 620 billion internet requests daily from over 30,000 customers across 190 countries, blocking over 170 million malicious DNS queries every day. For leadership, this means the threat intelligence underpinning the platform is among the most comprehensive available commercially.
Crucially, Umbrella is entirely cloud-delivered — no hardware, no appliances. It protects users on-network, in branch offices, and fully remote, all managed through a single console.
Key Capabilities
| DNS Security | is the entry point and immediate value driver. It provides full visibility into every internet-bound request made by users and devices, enabling categorical blocking — adult content, gambling, newly registered domains — deployable in hours without endpoint agents. IT teams gain instant insight into shadow IT, risky cloud applications, and compromised endpoints attempting to reach known-malicious destinations. |
| Secure Web Gateway (SWG) | moves beyond DNS to inspect full HTTPS web traffic, providing URL-level filtering, SSL inspection, and file scanning. This addresses threats hosted on legitimate cloud platforms that DNS alone cannot catch. |
| Cloud-delivered firewall(CDFW) | provides Layer 3/4 visibility and control over all internet-bound traffic — logging all activity and enforcing rules based on IP, port, and protocol. For leadership, this replaces physical firewall appliances at branch offices and for remote workers, reducing both hardware costs and management overhead. |
| Cloud Access Security Broker (CASB) | provides visibility and control over cloud application usage. Umbrella telemetry shows that Generative AI tool usage across enterprise networks increased 100% year-over-year — CASB gives IT teams the ability to discover, assess, and control which AI tools and cloud applications are in use, including data movement involving PII, PCI, and PHI. This directly supports audit readiness and compliance obligations. |
| Remote Browser Isolation (RBI) | executes browsing sessions in an isolated cloud container, keeping threats away from the endpoint entirely. This is especially valuable for high-risk users such as finance, legal, and executive staff |
| AI-Powered Threat Detection | is a recent and material capability addition. Cisco has integrated AI-driven Domain Generation Algorithm (DGA) detection into Umbrella, achieving a 30% increase in real detections and a 50% improvement in accuracy. DGA-based communication is one of the most common techniques used by ransomware to establish command-and-control channels — catching it earlier and more accurately directly reduces breach risk. |


Competitive Landscape
Umbrella uses per-user licensing and also packages the features and benefits using various offerings. And, to note the direct competition to the solution is from the following key vendors
| Zscaler | Market-leading SSE, strong ZTNA architecture |
| Akamai | Strong DNS heritage, broad CDN integration |
| Palo Alto Prisma Access | Deep integration with Palo Alto NGFW estate |
| Fortinet | Cost-effective for existing Fortinet customers |
| Netskope | Best-in-class CASB and data protection |
Deployment Requirements
Umbrella operates over standard DNS ports with minimal firewall changes required:
| Ports and Protocol | Source/Destination |
| UDP 53 | Endpoints/208.67.222.222 Endpoints/208.67.220.220 |
| TCP 53 | Endpoints/208.67.222.222 Endpoints/208.67.220.220 |
| HTTPS 443 | Required for SWG, CASB, dashboard |
The Cisco Umbrella root certificate must be deployed to managed endpoints using the Roaming Security module — distribute via MDM or Group Policy as part of standard rollout.
How Cisco Umbrella DNS Security Works
DNS-layer security provides an early opportunity to stop internet threats. Before a user connects to a website or cloud service, the device typically sends a DNS request to resolve the domain name.
Cisco Umbrella evaluates these requests and applies security and organizational policies. If a domain is associated with malware, phishing, ransomware or other malicious activity, the request can be blocked before the connection is established.
In addition, Cisco uses threat intelligence from Cisco Talos together with statistical analysis, machine learning and AI-based detection. This helps identify both known threats and emerging malicious infrastructure.
Cisco is now extending these capabilities through Cisco Secure Access – DNS Defense. As a result, organizations can begin with DNS-layer security and later expand toward a broader Security Service Edge (SSE) architecture as their security requirements grow.
Conclusion: From Cisco Umbrella to Secure Internet Access
Securing internet access is no longer limited to protecting traffic behind the traditional enterprise perimeter. Users now connect from branch offices, home networks and remote locations while accessing SaaS applications, cloud platforms and internet services.
Cisco Umbrella provides a strong foundation through DNS-layer security, web protection, cloud security controls and threat intelligence. However, organizations should also consider Cisco’s broader transition toward Cisco Secure Access and Security Service Edge (SSE).
For IT and security leaders, the key question is not simply whether DNS security is required. Instead, organizations should determine how DNS security, Secure Web Gateway, CASB, Zero Trust access, data protection and cloud-delivered security fit into their wider cybersecurity architecture.
A successful deployment should begin with an assessment of existing internet traffic, security policies, remote-user requirements, cloud applications and compliance needs. From there, organizations can determine whether DNS-layer protection is sufficient or whether a broader SSE architecture is required.
Need Help Designing Your Secure Internet Access Strategy?
TREZBON helps organizations evaluate, design and integrate enterprise networking and cybersecurity solutions around their operational and security requirements.
Whether you are assessing Cisco Umbrella, Cisco Secure Access, DNS security, SSE or Zero Trust architecture, our team can help you identify the right approach for your environment.
Ready to strengthen your internet security architecture?
Contact TREZBON to discuss your cybersecurity and secure access requirements:
🌐 https://trezbon.com/#contact
For more technical articles on cybersecurity, networking and infrastructure, explore the NETWORK BACHELOR Cybersecurity section.
The port and protocol table is clean and accurate. Good to see the certificate deployment requirement called out explicitly — that catches a lot of teams off guard during rollout. Would have liked to see VA version details for the virtual appliance deployment but overall solid.