I have implemented
Cisco Umbrella for one of our customers. I did an installation of two virtual appliances onsite, on-premises, and all the DNS redirection is done to the Umbrella cloud. The customer uses it primarily in the office for their DNS queries to the Internet and also internally, as the virtual appliances redirect to the internal DNS servers.
The most valuable aspect is that it is hosted with Cisco and can detect any new anomalies, acting almost like an
XDR. It provides zero-day protection by detecting any new suspicious DNS queries. Another key aspect is its DNS layer security, which helps in creating scheduled reports and allows access to these reports through the Umbrella dashboard. I can export the reports to PDF, CSV, or Excel files, and even generate reports as needed. Furthermore,
Cisco Umbrella has improved the security of my customer's organization because all DNS queries pass through the platform. They are able to see reports and get ratings of different sites their users try to access. If a machine is attempting to access compromised sites, it can pinpoint the machine to prevent it, thus narrowing down the attack surface.