Amid an increasingly sophisticated threat landscape and a widening cybersecurity talent gap, the demand for machine-scale security and response capabilities has never been greater. In response, Cisco has introduced new initiatives to help organizations address these evolving challenges.
Improved Threat Detection and Response with Cisco XDR and Splunk Security

Security teams are inundated with thousands of threat alerts daily. Cisco XDR addresses this challenge by correlating telemetry across network, endpoint, cloud, email, and more, using agentic AI to surface what matters most to organizations. Integrating several new features, Cisco XDR will deliver decisive AI-powered responses to stop attacks faster than ever. The new Instant Attack Verification integrates data from the Splunk platform, endpoints, networks, threat intelligence, and more—and uses agentic AI to automatically create and execute tailored investigation plans. This feature swiftly investigates, confirms threats, and enables security teams to automate responses with confidence to stop attacks. New automated XDR Forensics capabilities provide deeper visibility into endpoint activity, increasing the accuracy of investigations. Additionally, a new XDR Storyboard visualizes complex attacks, empowering security teams to understand threats in seconds and decisively respond faster.
To further help organizations strengthen their digital resilience, Splunk Enterprise Security (ES) and Splunk SOAR 6.4 enhance defenses against known and unknown threats for better visibility, accurate detections, and integrated and automated workflows that increase efficiency. Organizations that combine Splunk ES and SOAR with Cisco XDR will gain enhanced network visibility and detection to expedite investigations and stay ahead of threats. With its broad range of solutions, Cisco is helping organizations build an SOC of the future—one that leverages agentic AI to identify threats faster, accelerate resolutions, and deliver significant productivity gains. Splunk SOAR 6.4 is now generally available, and Splunk Enterprise Security 8.1 will launch in June.
Security for AI and AI for Security and ServiceNow Integration
Building on the recent launch of AI Defense, Cisco announced a new integration as part of a deepened relationship with ServiceNow to enable confident and secure AI adoption at scale. The initial integration will combine Cisco AI Defense with ServiceNow SecOps to enable more comprehensive AI risk management and governance.
Cisco also introduced Foundation AI, a team of AI and security experts that joined through the Robust Intelligence acquisition, focused on developing cutting-edge technology to address the fundamental security issues of the AI era. The Foundation AI team has released the first open-source reasoning model designed specifically to enhance security applications. They will also introduce benchmarks to evaluate cybersecurity models on real-world use cases, along with additional tools and building blocks for teams to use in adapting the models. These models and tools aim to foster collaboration between top security experts and machine learning engineers, while providing essential infrastructure that cybersecurity teams can immediately leverage.
Additionally, a new set of AI Supply Chain Risk Management security controls will help customers secure AI application artifacts. Even before deploying models in production, enterprises face security vulnerabilities, such as malware in AI model files and poisoned datasets downloaded from open-source repositories. By combining AI model threat assessment and detection with comprehensive network enforcement, enterprises can accelerate their AI adoption and innovation. This includes identifying and blocking malicious AI model files before they enter the enterprise; automatically detecting and blocking AI model files with risky or restrictive open-source software licenses that pose intellectual property and compliance risks; and flagging and enforcing policies against AI models originating from prohibited suppliers.
Enhanced Industrial IoT Security Solutions
As industry digitization accelerates and industrial AI emerges, critical infrastructure and industrial networks are increasingly exposed to cyber threats. Enhancing the Cisco Industrial Threat Defense solution and further extending IT security into industrial settings, these new integrations with Cisco Cyber Vision include: Cisco Vulnerability Management and Splunk Asset and Risk Intelligence to help prioritize OT cyber risks; Cisco Secure Firewall to help automate industrial network segmentation and better protect operations; and the Splunk OT Security add-on in Splunk ES to unify IT and OT visibility within the SOC, helping detect threats traversing domains to secure global enterprises.
Learn more about Industrial Cybersecurity Challenges and Solutions.