
Autonomous Business Monitoring by Anodot
Comprehensive DNS protection has reduced threats and provides clear visibility into internet traffic
What is our primary use case?
Our main use case for Umbrella is DNS security.
With Umbrella as a product, we inspect all the DNS query traffic coming in. Anything that's going to the internet is inspected with Umbrella DNS security. The policies applied over and the SASE tool help us to inspect and either allow or block or do a private endpoint, which is trusted domain management. The architecture extends quite well with cloud, Azure cloud, on-prem, as well as the agent-based policies.
We are in a POC situation with Umbrella for enabling the SWG, which is an upcoming aspect.
What is most valuable?
The best features Umbrella offers include having an agent, simple installation, and a quick VA installation mode that provides a virtual tunneling sensor for any network. That is quite the best, and compared to real-time detections, it does good work in inspecting and protecting internet domains.
The agents residing as roaming clients in user machines are always on, either in the office or in home networks, doing major work for the protection of user laptops open to the internet. VA sensors are NAT-based connectors directly tunneling to the SaaS, playing a key role in resolving private domains in Azure and AWS.
Umbrella has positively impacted my organization because it has turned a different situation around; we see at least billions of traffic being protected and classified regarding what sort of traffic is going in and out. We also have a good SLT review chat exported as a report every month and week.
The reports help my team by showing both huge reductions in threats at the DNS query level and improved threat protection. The report states how much traffic flow is in the count of millions and billions and how much is blocked with our policies in place.
What needs improvement?
I see a couple of areas for improvement in Umbrella; currently, I do not have a direct option to disable or block the agent at the end-user machine level. That is one issue, and another lack is in the policies where I cannot bypass a set of categories. We have submitted a feature request for these two cases and will have to wait for an update.
I notice a lack of agent availability on Linux platforms; it would be better if we had agent-based protection for Linux machines as well.
Regarding Umbrella's AI capabilities, I think the backend work is not shown well to customers, as I see a lag in providing accurate categorization. The threat intel integrated in the backend does not achieve 100% accuracy since about 10% of domains vary between Cisco representation and other threat intel categorization, which I see as one gap.
The accuracy of Umbrella's output is slightly missing, around 10 to 15%, and it does not provide accurate categorization compared to available market threat intels.
For how long have I used the solution?
I have been using Umbrella for close to eight years.
What do I think about the stability of the solution?
Umbrella is stable; although we experienced some deployment hiccups with agent specific to IPv4 and IPv6, these issues were resolved, resulting in a very stable solution.
What do I think about the scalability of the solution?
Umbrella's scalability is easy to manage, requiring no major configuration changes and facilitated by alignment with the account team for deployment.
How are customer service and support?
Customer support is excellent; we connect weekly with our Professional Services team as needed and extend our meetings based on ongoing projects.
Which solution did I use previously and why did I switch?
I previously used Infoblox Threat Defense, specifically BloxOne Threat Defense, which lacked features compared to Umbrella. The transition occurred six to seven years ago due to major drawbacks in protection accuracy and management features.
How was the initial setup?
Integrating Umbrella with our existing systems was easy; it involved integrating directly with NAT exits and external-facing IPs on Cisco SaaS without difficulty. We were in monitoring mode for a while before switching to protection mode, but redesigning the architecture would not be as straightforward.
What about the implementation team?
We handle user training and onboarding for Umbrella primarily through Cisco Professional Services, who support us in every step, especially during situations such as recent MacBook agent deployments. Until we onboard online, they ensure our policies are updated and effective.
What was our ROI?
I have not seen a significant return on investment as the management perspective requires minimal administrators; once devices are deployed, they function largely on their own, protecting against threats at the DNS level.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup costs, and licensing is neutral; it is not too good or bad, but reasonable for the market. Licensing is based on headcount in our organization, but now we need to consider the impact of adding SWG to our DNS security.
Which other solutions did I evaluate?
We evaluated Netscope and Akamai before choosing Umbrella based on price, features, and Gartner recommendations, which led us to that decision.
What other advice do I have?
I rate Umbrella an eight overall, considering the feature requests submitted; I think it is doing well.
I rate it an eight because the score specifically relates to DNS security; I would not give a higher rating due to the two feature requests mentioned. Otherwise, the overall experience with Umbrella is good.
I advise others considering Umbrella to thoroughly test during their POC, especially if agent controls at the management plane and scalability on macOS are critical factors. While Umbrella excels in protection and ROI, these considerations warrant reevaluation.
I found this interview experience good and refreshing, allowing me to reflect on my journey with the product over the years; thank you for the opportunity to share feedback. My review rating for Umbrella is eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Improved web security has blocked malicious domains and provides better visibility into user traffic
What is our primary use case?
My main use case for Umbrella is for our DNS security and proxy. This is what we are required to use to block any unwanted communications, domains, or certain categories which are available on the web internet that we want to restrict for our organization users so that they can avoid going into malicious sites and domains.
I can give a quick specific example of how I have used Umbrella to block or restrict access in my organization through content filtering, by manually adding the domains, AI blocking, blocking of on-size, blocking of unwanted restricted sites, blocking of newly registered domains, blocking of social media platforms and various others.
What is most valuable?
Umbrella offers excellent features including usability; it is simple, easily accessible, and usable. The content filtering, reporting, and researching capabilities are very good and make it user-friendly for everyone.
Those reporting and researching capabilities have been really helpful in our day-to-day operations and have provided insights to understand what is happening so we can strategically plan based on our organization needs.
Umbrella has positively impacted my organization because previously, we were not having any visibility on what was coming in and what was going out. Currently, with the help of Umbrella, we are able to restrict what can go out and what can come inside, which is really helpful for each and every organization, not only for us. Umbrella is doing a great job in this area.
We have seen a couple of reductions in the sites and domains which users were visiting unwantedly or without having information, which drastically reduced, resulting in a positive impact. This is how it is increasing our security posture as well. This was the main objective for acquiring Umbrella within the organization, and the business is pretty much helpful with that.
What needs improvement?
I found Umbrella to be good, and it would be helpful if we could enhance some features related to the AIs and also provide some inputs on a weekly basis regarding what is going on in the market and your best recommendations; probably I am not getting it. We have not subscribed, but if you can guide me on where we can get that information, that would be really helpful.
Umbrella can be improved by providing something on a day-to-day basis so that users can be aware. The improvement of AI facilities or AI recommendations needs to be added, and they should provide the best recommendations based on the traffic they are seeing on a weekly or bi-weekly basis, such as what needs to be blocked and what can be looked after so that the business or the person who is looking into that can find it helpful. That is the main enhancement I can think of right now.
I think I have covered pretty much all the needed improvements for Umbrella that I have not mentioned yet.
For how long have I used the solution?
I have been working in my current field for more than ten plus years. I have been using Umbrella for more than four years.
What do I think about the stability of the solution?
Umbrella is stable.
How are customer service and support?
Umbrella customer support is good.
Which solution did I use previously and why did I switch?
We were not using any solution previously; this is the first one we have purchased.
How was the initial setup?
My experience with pricing, setup cost, and licensing has been good.
I have not found any challenges regarding pricing, setup cost, or licensing; everything is good.
What was our ROI?
I cannot calculate it based on specific metrics, but from a security perspective, it is the best investment and a good investment, probably what we need for our organization.
Which other solutions did I evaluate?
We have not evaluated other options before choosing Umbrella.
What other advice do I have?
I would advise others looking into using Umbrella to definitely look for it and opt for it, as it is a good product based on the organization's needs; I would highly recommend it. I believe this review merits a rating of eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Strict URL blocking has protected our organization and continues to strengthen cyber defense
What is our primary use case?
My main use case for Umbrella is OpenDNS. I use Umbrella with OpenDNS in my organization by ensuring that all external URLs are denied by default. When a user requests access, they raise a ticket to us and we analyze it. If it is a valid URL, we allow the request to grant access. I chose to set it up this way for cybersecurity protection, which addresses a particular challenge we face.
What is most valuable?
The best features Umbrella offers in my experience include OpenDNS and the ability to block URLs. Umbrella positively impacts my organization by protecting us from cybersecurity threats and malware. I think Umbrella can be improved regarding AI capabilities.
What needs improvement?
I think Umbrella can be improved regarding AI capabilities. I believe some tasks need to be automated, especially the repetitive tasks.
For how long have I used the solution?
I have been using Umbrella since 2023, so it has been three years.
What other advice do I have?
I don't have anything else to add about my main use case with Umbrella. So far, I don't have a specific example of how the advanced URL blocking feature has helped my team or made things easier from the support perspective. I don't wish to add anything else about the features.
I don't have specific outcomes to share, but it has been helpful so far without seeing fewer incidents or noticeable changes in security metrics since using Umbrella. Regarding Umbrella's AI capabilities, I think its governance and security are good. I find the accuracy and reliability of Umbrella's AI output to be good, with an accuracy and reliability rating of eight overall. The accuracy and reliability of Umbrella's AI output is good, and it is fine without any improvements needed. My overall review rating for Umbrella is 9.
Umbrella has streamlined daily planning and supports data-driven decisions for our organization
What is our primary use case?
What is most valuable?
I rate Umbrella an eight out of ten because of its diverse features. I think it has been helpful. The software itself is very helpful for companies that are into enterprise systems. It helps give you a very good modeling of what your request and your mission and vision is for your company. It helps to make the process seamless and more effective.
What needs improvement?
I wish Umbrella could make the whole process more user-friendly. It should be more user-friendly for people to be able to use because it is a bit sophisticated.
For how long have I used the solution?
I have been using Umbrella for the past five months.
What other advice do I have?
My advice to others looking into using Umbrella is to tailor it to actually know what their request is and tailor it in the same process because Umbrella is a very wide model with specifications where you could just look at what your objectives are, what your goals are, and probably tailor it to serve the purpose or the main objective of the organization. I definitely recommend Umbrella and would rate this product an eight out of ten.
Web filtering has protected users from harmful sites and supports safe browsing every day
What is our primary use case?
I have been using Umbrella for actual deployment at my client site and have also been maintaining it, so I have experience over the last one year.
My main use case for Umbrella is its excellent security feature for web security related to any type of URL blocking or dangerous sites, and it works well.
A specific example of how I use Umbrella's web security features is that end users visit many sites and do not know which sites are usually good for them, so using Umbrella DNS security automatically blocks the harmful sites.
I create policies for exceptional users and give them special permissions to visit any site.
What is most valuable?
In my opinion, DNS security is the best feature Umbrella offers.
The DNS security feature stands out for me because its deployment is easy and its maintenance is easy.
I hoped Umbrella would help make our company safe from dangerous sites, and after installing it, I found it very helpful for my company.
I saw many incidents happening and noticed that the best feature is its capability to block URLs that have a backend server, which I think is the best feature in Umbrella that works behind the scenes on the web server.
What needs improvement?
I think the accuracy and reliability of Umbrella's output is 100% in blocking all bad sites; however, one problem is that it sometimes blocks valid URLs. For example, regarding the backend where some URLs communicate with the backend, I want to manually check it and then allow it.
I acknowledge that every device has a downside, and I still do not know which sites are bad for the user.
I find Umbrella very user-friendly, so there are no challenges or confusing aspects.
For how long have I used the solution?
I am working almost five years in my current field.
What do I think about the stability of the solution?
Umbrella is stable.
What do I think about the scalability of the solution?
Umbrella easily handles more users or traffic, demonstrating good scalability.
How are customer service and support?
I have never used the customer support portal and find it very user-friendly, so I do not need to use it.
Which solution did I use previously and why did I switch?
Umbrella is my first solution; I have not used a different solution before.
What was our ROI?
I have not seen a return on investment since I do not get involved with business aspects, so I have no idea regarding saving money, time, or needing fewer employees because of Umbrella.
What's my experience with pricing, setup cost, and licensing?
I do not have any idea about the pricing, setup cost, and licensing because another team calculates it.
Which other solutions did I evaluate?
I did not evaluate other options before choosing Umbrella, as our client chose Umbrella.
What other advice do I have?
Umbrella is very user-friendly, the GUI is very understandable, and the traffic and detection are also fine and excellent. I give Umbrella a rating of nine out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Security platform has reduced phishing risks and provides silent DNS protection for remote users
What is our primary use case?
Umbrella serves as my main DNS layer security and visibility tool, which is essential to the first line of defense for any outbound traffic day to day. Every DNS request is checked against Umbrella's threat intelligence before it resolves, meaning that malware, phishing, and command and control callbacks are blocked at an earlier stage. It typically fits into daily operations through web filtering and policy enforcement, enforcing acceptable use policies across the user and site, for example by blocking categories such as gambling or adult content while allowing business-critical domains. Threat protection automatically stops the connection to malicious domains, IPs, and URLs, reducing the number of incidents that reach firewall points, allowing the firewall SOC team to spend less time chasing alerts. Regarding visibility, Umbrella provides insight into traffic from laptops and mobile devices outside the corporate network, which is especially useful for distributed teams. My daily use includes reviewing Umbrella's dashboard for blocked requests, top destinations, and policy hits, with this report data often exported for compliance frameworks such as NIST or ISO. Umbrella integrates seamlessly with existing systems such as firewalls by Palo Alto, FortiGate, and Cisco ASA, not replacing them but acting as a complementary layer that reduces risks before traffic reaches those devices.
What is most valuable?
Umbrella has really helped my team specifically during a phishing campaign targeting remote users. A few employees received emails with links looking like a legitimate Microsoft 365 login page, which were crafted to bypass basic email filters. However, when users clicked them, Umbrella intercepted the DNS request and blocked the domain before the page could even load. Instead of relying on users to recognize the fake login, Umbrella's threat intelligence stopped the connection outright, preventing credential theft and saving the SOC team from having to run a full incident response cycle. This day-to-day difference shows the value of Umbrella's silent protection, which reduces downstream alerts in the firewall and SIEM team, providing confidence that even if something slips past email security, Umbrella will catch it at the DNS layer.
Umbrella fits into the workflow as a quiet backbone for security operations, providing baseline protection, reducing noise, covering the remote workforce, and enabling reporting compliance. These are key factors, as Umbrella is not something the team constantly interacts with but is woven into the workflow as a preventive visibility and driving layer, making everything downstream more effective.
The best features of Umbrella are its DNS layer security, cloud delivery, simplicity, and integrated threat intelligence, which together provide fast, reliable protection against malware, phishing, and ransomware. These features are valued most for blocking threats before connections are established, ensuring consistent security for both on-network and remote users. Key features include DNS layer security, cloud delivery protection, threat intelligence, visibility, Secure Web Gateway, Cloud Access Security Broker, Firewall as a Service, Data Loss Prevention, and Remote Browser Isolation.
Regarding how I use the Secure Web Gateway and Cloud Access Security Broker features, they extend Umbrella beyond just DNS filtering and are valuable because they give the team deeper control and visibility. Secure Web Gateway stops threats that hide behind legitimate domains or encrypted traffic, reducing reliance on decryption by catching malware at the gateway and giving confidence that even if the DNS layer allows a domain, the SWG layer will still inspect and block malicious payloads. Cloud Access Security Broker is useful for monitoring SaaS app usage, such as Office 365, Google Workspace, and Dropbox, helping identify shadow IT with employees using unsanctioned cloud apps, and enforcing policies such as blocking the upload of sensitive data to personal cloud storage. It prevents data leaks while providing visibility into cloud adoption threats across the workforce, balancing productivity with risk management. Together, SWG and CASB make Umbrella more than just a DNS filter, giving layered control over both traffic and application usage, critical in a hybrid workforce where employees continuously access SaaS platforms from different locations. In practice, SWG protects against external threats while CASB addresses internal risks such as data leaks, making them valuable to the team.
From a features point of view, I want to highlight core items that make Umbrella feel concerning a complete security platform rather than just a DNS filtering solution. Features such as Firewall as a Service, Data Loss Prevention, Remote Browser Isolation, reporting, and analytics work together with SWG and CASB to provide a layered defense model. DNS security stops threats at an early stage, while SWG inspects and filters web traffic, CASB controls SaaS usage, and prevents shadow IT, with Firewall as a Service, DLP, and RBI extending protection to border traffic and data leakage. This consolidation of multiple security functions into one cloud delivery platform reduces complexity while improving coverage, which is invaluable to the team.
Umbrella has positively impacted my organization primarily in two areas: risk reduction and operational efficiency, representing the overall positive impact. It essentially becomes a silent backbone, preventing incidents before they happen and reducing noise downstream in the firewall and SIEM. Umbrella provides measurable proof to stakeholders of improved security posture, allowing the team to spend less time firefighting and more time on proactive projects while leadership receives clear metrics showing ROI.
I see Umbrella's positive impact reflected in areas such as phishing incidents, SOC efficiency, and remote workforce coverage. For compliance and audit proof, during a phishing campaign, Umbrella blocked access to malicious domains at the DNS layer before users reached fake login pages, stopping requests instantly. This prevented credential theft and saved the SOC team from a full incident response cycle, clearly demonstrating both risk reduction and time savings. In summary, Umbrella has led to fewer incidents, faster audits, and more efficient SOC operations, with metrics that leadership can refer to as proof of ROI.
What needs improvement?
While Umbrella is strong, there are areas where it could improve based on daily use. Some aspects that my team often wishes were better include reporting depth, policy granularity, false positive whitelisting, integration with other tools, and cost considerations. Overall, Umbrella effectively blocks threats early and provides visibility, but if Cisco enhances reporting and policy flexibility and integration, it would make the platform even more powerful and reduce the need for workarounds. Improvements in reporting depth, such as enabling the team to find the root cause easily, would be beneficial, as would making reports more visually appealing with graphs and color combinations, similar to other platforms concerning Forti Manager and Palo Alto.
Regarding the needed improvements, I have noticed some key areas, particularly around integration and policy management, which tend to be pain points in daily use. Challenges include integration with third-party SIEMs, endpoint tools, SD-WAN, and managing multi-vendor firewall policies, as well as the regularity of whitelisting workflows. Although Umbrella excels at blocking threats early, if Cisco can enhance integration breadth and policy flexibility, it would alleviate frustrations for teams managing a hybrid multi-vendor environment, making Umbrella not just a strong security layer but also a smooth operational fit.
For how long have I used the solution?
I have been using Umbrella for the last three years, which has provided me more confidence in using it, and it is a very nice product.
What other advice do I have?
From my perspective, Umbrella's AI capabilities are designed with governance and security in mind, which is one reason it is trusted in enterprise environments. Governance ensures policy enforcement, shadow IT control, and compliance alignment, while the security aspect features threat intelligence at scale and adaptive blocking that reduces human error. For my team, Umbrella's AI means more than just blocking threats; it supports governed cloud usage and secures traffic intelligently. The governance side ensures compliance and visibility, while the security side guarantees resilience against evolving threats.
In summary, Umbrella's AI capabilities make it both a security shield and a governance tool, helping organizations stay compliant while reducing risk.
Regarding Umbrella's AI capabilities and the accuracy and reliability of its output, I find them generally very accurate and reliable, which is why they are trusted as the first line of defense. My overall rating for this review is nine out of ten.
Centralized DNS security has reduced web threats and supports proactive policy management
What is our primary use case?
My main use case for Umbrella is its effective DNS layer security against malware, phishing and ransomware threats, which helped me to centralize cloud-based management with minimal infrastructure requirement. It is easy to deploy and manage across multiple locations.
In my day-to-day work, I use Umbrella for creating DNS layers and allowing VPN, proxy, and permitting access to sites and websites.
Occasionally, Umbrella blocks main business websites, requiring recurring manual review and whitelisting. Policy changes may take some time to propagate across all the endpoints.
How has it helped my organization?
Umbrella has positively impacted my organization by significantly improving web security and reducing exposure.
I have noticed fewer incidents, and its security detail threats have been provisioned to be a reliable security platform that continues to provide valuable proactive threat prevention and centralized policy and performance.
What is most valuable?
The best features that Umbrella offers are for centralizing, which is easy for centralized cloud management with minimum infrastructure requirement.
The centralized cloud management from Umbrella has helped me and my team significantly, as it is easy for deployment and management across multiple locations.
Umbrella demonstrates strong governance and security capabilities, utilizing its AI-driven threat detection and web security features. The platform effectively leverages threat intelligence and automated analysis to identify and block malicious domains, phishing attempts, and emergency cyber threats. The strong security tools with AI-assisted threat detection and prevention, centralized policy management and governance across users, devices, and locations, with detailed visibility into web activity and security events are significant strengths. Integration with Cisco's broader security ecosystem enhances overall threat intelligence.
What needs improvement?
Regarding improvements for Umbrella, faster policy synchronization would improve responsiveness when business-critical sites need immediate access. Enhancement improvements such as a more customizable dashboard and reporting options would help administrators better analyze web traffic and security events. Additionally, advanced filtering and scheduled reporting would be beneficial, and improved troubleshooting tools that provide more detailed information on why a website was blocked would help IT teams resolve access issues faster. A more user-friendly diagnosis could reduce support tickets.
Regarding Umbrella's AI capabilities, its strong DNS layer security helps block malware, phishing, ransomware, and malicious domains through centralized policy management and regular control for specific user groups and business units. Enhanced reporting and audit capability for compliance review, improved website categorized accuracy to reduce false positives, and faster policy projections with real-time policy updates would be valuable enhancements.
For how long have I used the solution?
I have been using Umbrella for three years.
What do I think about the stability of the solution?
Umbrella is stable.
What do I think about the scalability of the solution?
Umbrella is highly scalable and well-suited for organizations. Its cloud-native architecture allows for easy expansion without requiring additional on-premises infrastructure. New users, devices, and locations can be onboarded easily through centralized policy management and deployment tools, providing consistent security and policy enforcement across remote users and branch offices.
How are customer service and support?
Customer support for Umbrella is responsive and effective, providing opportunities for faster resolution on complex access issues.
Which solution did I use previously and why did I switch?
We did not use any different solution before; from the beginning, we have been using Umbrella and do not want to switch to any other solutions.
How was the initial setup?
Our experience with Umbrella's pricing, setup cost, and licensing has been positive overall. The setup cost with the initial deployment was straightforward and did not require significant infrastructure investment due to its cloud-based architecture. The licenses are simple to manage and scale well with organizational growth. User-based licenses provide flexibility and are subscription-based. Although Umbrella may be priced higher, the security features, centralized management, threat protection, and ease of deployment provide good value for the investment.
What was our ROI?
We have seen a positive return on the investment from Umbrella. The platform has helped reduce security risk by proactively blocking malicious websites, phishing attempts, and other threats at the DNS layer before they reach the end users. This has resulted in fewer security incidents, reduced time spent on remediation, and lower operational overhead for our IT team. Additionally, its cloud-based deployment model has eliminated significant infrastructure requirements.
What's my experience with pricing, setup cost, and licensing?
Our experience with Umbrella's pricing, setup cost, and licensing has been positive overall. The setup cost with the initial deployment was straightforward and did not require significant infrastructure investment due to its cloud-based architecture. The licenses are simple to manage and scale well with organizational growth. User-based licenses provide flexibility and are subscription-based. Although Umbrella may be priced higher, the security features, centralized management, threat protection, and ease of deployment provide good value for the investment.
Which other solutions did I evaluate?
We did not evaluate other options before choosing Umbrella; we directly chose Umbrella.
What other advice do I have?
My advice to others looking into using Umbrella would be to clearly define your security requirements and web access policy before deployment. Umbrella is an effective DNS layer security solution that provides strong protection against phishing, malware, ransomware, and other web-based threats. Organizations should take advantage of its centralized policy management, reporting capabilities, and integration options to maximize its value. It is important to plan for website categories, reviews, and exception processes since legitimate business websites may occasionally require whitelisting. Integrating Umbrella with endpoint management solutions can further enhance visibility and policy enforcement. I would recommend Umbrella for organizations looking for a reliable, scalable, and cloud-based web solutions architecture. I give this product a rating of nine out of ten.
Layered DNS security has protected users and simplifies URL whitelisting and blacklisting
What is our primary use case?
My main use case for Umbrella involves whitelisting and blacklisting of URLs. I want to provide feedback on Umbrella as it functions. Umbrella provides strong DNS layer security and blocks malicious domains before connections are established. We would like to whitelist or blacklist the URLs that we want to utilize on our client side. The dashboard is relatively easy to use and provides good visibility into DNS requests and security events. Integration with other Cisco security products is beneficial, and reporting and analytics could be more customizable. Policy management can become complex in larger environments with multiple user groups. Troubleshooting blocked domains sometimes requires a very deep investigation. More granular reporting and easier policy inheritance would improve administration. Roaming client protection is valuable for remote customers, and threat intelligence backed by Cisco Talos is a strong advantage.
I can provide a quick specific example of how I have used Umbrella for whitelisting or blacklisting URLs by checking in VirusTotal as well as a few of the McAfee sites, and based on that, we will blacklist or whitelist the URLs.
What is most valuable?
The best features Umbrella offers include content filtering, protection for remote users, and DNS security, malware, and phishing protection.
Out of those features, I find myself relying on DNS security the most because it is essential for my needs.
Umbrella has positively impacted my organization by ensuring that if anyone wants to access any of the URLs, the URL will be blocked. If they want to access that particular URL, it needs to be whitelisted. Umbrella will help us to block or whitelist the URL based on malicious activity.
A specific outcome that shows how Umbrella has benefited my organization is that it saved a lot of time, and before security events occur, it filters all the URLs. Whether they are malicious or phishing URLs, it will blacklist those and will not approve that.
What needs improvement?
While Umbrella provides good visibility, reporting and dashboard customization could be improved by being more flexible, especially for management and compliance reporting. When a domain is blocked, administrators sometimes need to navigate multiple logs and dashboards to identify the exact policy or rule responsible. Simplified troubleshooting would improve this experience.
More customizable reporting, simplified policy management for large environments, and enhanced troubleshooting capabilities could be included.
Regarding Umbrella's AI capabilities, its governance and security can use threat intelligence from Cisco Talos to identify malicious domains, phishing sites, and emerging threats. Machine learning and predictive analysis can be leveraged to detect newly registered or suspicious domains before they are widely known threats. For example, AI-powered investigation summarizes and explains why a domain was blocked.
Its accuracy and reliability of output are notable since it provides reliable threat detection using Cisco Talos threat intelligence, machine learning, and domain reputation analysis. In my experience, the accuracy is generally good with effective identification of malicious and phishing domains. However, there can occasionally be false positives where legitimate sites are blocked and require review or whitelisting. The platform is highly reliable for DNS layer protection, but providing more transparency into AI-driven decisions and improving the explanation of why a domain is flagged would further enhance administrative confidence.
For how long have I used the solution?
I have been using Umbrella for eight plus years.
What do I think about the stability of the solution?
Umbrella is stable.
What do I think about the scalability of the solution?
Regarding Umbrella's scalability, it is highly scalable and well-suited for organizations of different sizes from small businesses to large enterprises. Since it is a cloud-delivered service, it can support a growing number of users, devices, and locations without requiring significant on-premises infrastructure. In my experience, scaling protection to remote users and multiple sites is relatively straightforward through centralized policy management.
How are customer service and support?
The customer support was great, as they would solve the issue immediately based on the priority after we raise a request.
Which solution did I use previously and why did I switch?
I have not used any other solution; Umbrella is the only one I am using.
Before choosing Umbrella, we did not evaluate other options. Our client chose only Umbrella, and it has been the best option so far.
What other advice do I have?
My advice for others looking into using Umbrella is to consider that it would be helpful for all clients to better whitelist and blacklist the URLs that are malicious and phishing ones, as it will add more security or a layer of security to the companies. I would rate this product a nine out of ten.
DNS security has protected endpoints and servers and provides compliant, low‑overhead protection
What is our primary use case?
My main use case for Umbrella is DNS security, by securing end users to utilize a security DNS. I have deployed Umbrella in proxy mode, and we have two appliances in our environment. Our Active Directory gets all the DNS queries from the Umbrella appliances, and the Umbrella appliances reach DNS and Cisco Security Cloud. Our end users utilize it from the Active Directory.
What is most valuable?
The best features Umbrella offers secure the DNS queries for our environment, including servers and endpoints. What makes the security feature stand out for our servers and endpoints is that most of the DNS queries come from trusted sources. Umbrella has positively impacted my organization by providing a layer of security on the DNS level. I can share specific outcomes including improved compliance with NCA regulation that resulted from using Umbrella.
What needs improvement?
Umbrella can be improved by adding DHCP services to be a full DDI solution, as most customers today are looking for a full DDI solution. Exporting reports for all the DNS queries, including how much reached and what has been blocked, can give full visibility for the protection. Additionally, adding DDoS protection services to the DNS cloud would provide more layers of security.
For how long have I used the solution?
I have been using Umbrella for three years.
What do I think about the stability of the solution?
Umbrella is stable.
What do I think about the scalability of the solution?
Umbrella's scalability is great.
How are customer service and support?
Cisco Customer Support always answers on time, which is very helpful. I would rate the customer support a nine on a scale of one to ten.
Which solution did I use previously and why did I switch?
I previously used Infoblox as a different solution before switching to Umbrella.
Which other solutions did I evaluate?
Before using Umbrella, I did not evaluate any other options.
What other advice do I have?
I would rate Umbrella an eight on a scale of one to ten. I chose that number because of the ease of deployment of Umbrella, as well as its easy use and low operational headache. My advice for others looking into using Umbrella is to make sure to deploy Umbrella appliances on-premises to utilize the proxy services. The interview was great, and I have no changes to suggest for the future.
Improved threat protection has reduced incidents and now needs better user browsing performance
What is our primary use case?
The main use case for Umbrella is that I am using it for SASE. I am using Umbrella for blocking malicious domains before connection happens, then protecting remote and hybrid users also without forcing full VPN. I am using it for web content filtering as well. Visibility into internet traffic, lightweight client protection, and the cloud delivered secure web gateway are part of my workflow. These include HTTP inspection, file inspection, URL filtering, SaaS control, and CASB.
What is most valuable?
The speed feature of Umbrella is the most useful feature and the one I find most valuable. For BYOD users, I am using the speed feature which stands out for me.
Mostly from SWG, HTTP inspection is an advantage, file inspection is an advantage, and URL filtering is also an advantage regarding the features of Umbrella.
Umbrella has positively impacted my organization as I am getting fewer phishing and malware incidents. Users are very happy with Umbrella.
I measure those improvements by getting lower incident response, fewer endpoint cleanup, less time to investigate commodity phishing, and fewer repetitive user tickets. I am able to achieve almost net zero incidents.
What needs improvement?
User experience of Umbrella can be improved, with less backhauling traffic, better browsing performance, and fewer VPN dependency complaints.
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
Which solution did I use previously and why did I switch?
Before Umbrella, I used a Firewall VPN which was not a full-fledged Umbrella SASE. I am seeing Umbrella for the first time. I was evaluating Palo Alto before choosing Umbrella.
What was our ROI?
I have mostly seen time saved as a return on investment. I am not investing more than 30 minutes of time every day, so you can analyze how much time we are saving.
Which other solutions did I evaluate?
We were evaluating Palo Alto as well for SASE, but finally, we decided to go with Cisco SASE and Cisco Umbrella because of the relationship we have.
What other advice do I have?
My advice is to go ahead with Umbrella. It is a very nice product with good customer support plus a return on investment. You are investing $1 and you are getting a value of $10. People should go ahead with Umbrella. It is a very good product. Please go ahead, buy the product, and contact your Cisco account manager. They will help you, and the customer support team will assist you as well. Please try the demo. I am providing this review with an overall rating of 7.5 out of 10.