What is our primary use case?
I have used Stealthwatch Cloud in the insurance sector for what we call the software mapping and automating it with other systems to have a level of visibility. Additionally, we use it for incidents response, forensic analysis, and segmentation of the IT architecture.
Cisco Stealthwatch Cloud is typically on the cloud because most of the companies choose it. However, for the government sector, I've used it on-premise, which is the Central Bank of Kenya.
One of my clients Cisco Stealthwatch Cloud wanted to map their IT architecture and have visibility. Additionally, they wanted to do API integration with the next-generation firewalls with IPA's and the cross integration with the antivirus, digital forensic discovery solution that they have within the bank. They wanted to see, how they would automate the IT architecture using Cisco Stealthwatch Cloud.
In case there is a threat the client needs to do automated incident response, and the solution can act on its own. We do a few tests which are very vital, such as formulated policies. We can see what is on the document, on the ground, and how the policy affects the whole IT architecture. We did those kinds of tests and it went live by automating Cisco Stealthwatch Cloud with a cloud solution and other solutions that they had. We were able to prevent an electric fraud of almost $200,000.
What is most valuable?
The logs in Cisco Stealthwatch Cloud are very good when doing the API integration in the team. It is able to give you important information for the correlations.
What needs improvement?
Cisco Stealthwatch Cloud could improve the graphical user interface. It could be a more user-friendly graphical user interface. so that. Not everybody's a cyber security professional, most of the customers that I deal with are not very skilled. The terms that they use in the solution are quite understandable for a normal CIO.
If you're going to sit with a CIO or a CSO to explain to him anything about the solution, most of them are not technical. Their technical skills are approximately 20 to 30 percent. They need to have simple terms, such as some of the other solutions have that they are able to understand. For example, forensic analysis means this. However, that example is a normal word that someone can understand, but some words that they use to describe certain features, are quite hard to understand.
Cisco Stealthwatch Cloud for technical people is user-friendly because they already understand how it works. For those people who are less technical and not very good at security, they might have a difficult time trying to work around to understand the solution. If they do not have the support it will make it even more difficult and they will have to do the troubleshooting themself.
For how long have I used the solution?
I have been using Cisco Stealthwatch Cloud for approximately three years.
What do I think about the stability of the solution?
Cisco Stealthwatch CloudRev is a stable solution. However, it can depend on the kind of deployment that you have. For example, if you have a lot of employees and a lot of end-users, the cloud is more stable because what you do in terms of disaster recovery, you are only doing mirroring. Once you do mirroring, that means that if the main solution has an issue, the mirror itself will pick up automatically. The kind of support you have matters, there is level one, two, and level three from Cisco. In case of any problem, if you have the correct support, Cisco supports can be available for you within five minutes.
They offer you tier one, two, or three engineer support. If you do not have support then the company that is providing that solution for you should provide you some support.
I have people who work for Cisco Stealthwatch Cloud, who are my friends in the UK, who also train people. If you wanted the solution, they would do a use case with you and help you set up a demo environment. They train you on how to do triggers and configurations. They can walk with you throughout the implementation journey. This is something that we have done with many clients and most of them are in Europe.
In Sub-Saharan Africa, we have approximately 10 customers using this solution.
We have global customers across Europe, the Middle East, and Africa. Europe is our biggest base whereby we do over $1 million sales in solutions, such as Cisco Stealthwatch Cloud every year. We have what's called global customers or tier-one customers, in Europe.
What do I think about the scalability of the solution?
Cisco Stealthwatch Cloud is a highly scalable solution. For example, if you have a bank with 10 branches, and then you want to scale to 20 branches. You are able to scale up because it's user-based. If you expand your users, architecture, data center, and DL without a problem.
I used to create an IT access and security roadmap. We could assess in the last five years, how many people you have hired, if you scaled your data center, or scaled your DL. We can be able to predict within the next three to five years, this is how your organization is going to be in size. We are able to create a budget consisting of five years and provide the information on spent money for the year. We can forecast in the next three years, you might need to have a different budget. We can give predictions if new technology is brought in of how to scale, cross integrate, test the formulation policies, all by using servers before you deploy them.
How are customer service and support?
The technical support from Cisco has improved over the years because of the competition. The competition keeps everybody on their toes. I have a lot of clients that are using many different types of solutions, such as Cisco ISE. With that solution, not even an engineer can configure the Cisco ISE, and the technical support has been very good. You are able to tell if a service is good by the monthly and quarterly revenues that are coming in.
You find that professional services are becoming very profitable because they are creating good relationships with the customers, they are happy. Even if it's not Cisco working on the solution, and it is done by someone else, Cisco sends a quality assurance(QA), and CCIE to come and check if the configuration is okay, do an update, and see what other solution would you pass the internal data because if you have Deloitte, KPMG, or PWC auditing, then one thing you need to know is that the solution has been configured with the required parameters.
How was the initial setup?
The installation of Cisco Stealthwatch Cloud is straightforward and this can be solved in two ways. The implementation can be solved by professional services engineers from Cisco or from a company, such as Westcon-Comstor. All your engineers should undergo a three to five-day mandatory training, with the support of Cisco. It's a very straightforward solution. Cisco wants to know what kind of IT architecture you have, how do they cross integrate, and what's your roadmap or what are you looking for to achieve. As long as the customer or the CIO, CSO, or the CTO knows the objective, then Cisco can make sure they meet that objective.
You can have a checklist that you can start ticking one by one and of how it has met the objectives of the company. This process can be done through the demo session. Cisco can do a demo with you and the configuration can be done within two to three days. Within the next two months, you are able to see if you are receiving the feedback you want and have visibility. By the end of the billing month, you can decide, if you want to purchase the solution or not.
What about the implementation team?
We do not need many people for the implementation or maintenance of the solution. If it was to be done by Westcon or Cisco professional services, it will not require more than four people. However, if the people are skilled the process of implementation only needs two people.
What usually happens most of the time, is they will do the first configuration and document each and every stage, then take your end users engineers for a two-week of intensive training. This way the internal engineers are able to manage the solution. If the internal team wants to do an SLA, they can also be trained and do a mandate with Cisco, the technology company that will do this, or distributor. Westcon can do this for you too, they have professional services.
What was our ROI?
I have received a return on investment with Cisco Stealthwatch Cloud.
What's my experience with pricing, setup cost, and licensing?
Cisco Stealthwatch Cloud is an expensive enterprise solution.
The solution is paid for annually unless you have a customer that is offering you this solution through MSP. If it's the cloud or on-premise version, you can have an annual budget or you can choose a supplier who is doing MSP. They can give you it with monthly or quarterly budgets. I know some suppliers who offer such kinds of solutions with monthly, quarterly, half-year, or annual budgets. It depends on the kind of person who is providing you with this solution.
What other advice do I have?
I would recommend Cisco Stealthwatch Cloud to others. It has worked for me, it is profitable, and gives clients the expectations they wanted.
I would rate Cisco Stealthwatch Cloud six out of ten for the people who are not very experienced or for an organization that does not have talent in IT.
If you have an internal technical team that is very experienced, I would rate Cisco Stealthwatch Cloud an eight out of ten.
Overall, I rate Cisco Stealthwatch Cloud a seven out of ten.
*Disclosure: My company has a business relationship with this vendor other than being a customer: