ARMOR In Action with Cisco: Ensuring Comprehensive Security Coverage for Your Production-Ready AI Factory
In this article
- Mapping Cisco's Portfolio to ARMOR Domains
- 1. Cisco AI Defense
- 2. Cisco Identity Services Engine (ISE)
- 3. Cisco Duo with Identity Intelligence
- 4. Cisco DUO Enhanced with Astrix
- 5. Isovalent (Cilium)
- 6. Splunk
- 7. Cisco Hypershield
- 8. Cisco Hybrid Mesh Firewall and Secure Workload
- 9. Cisco Secure Application
- 10. Cisco Secure Access (SSE)
- 11. Cisco Talos Threat Intelligence and Incident Response
- 12. Cisco Nexus Smart Switches
- Looking Ahead: Agentic AI, Non-Human Identity, and the Quantum Era
- Download
As AI shifts from a pilot to a business-critical system, security becomes a defining factor in an AI deployment's success. That is exactly why WWT built ARMOR, our AI Readiness Model for Operational Resilience. ARMOR is a vendor-agnostic AI security framework delivered by WWT, developed with input from NVIDIA and strengthened through real-world collaboration with the Texas A&M University System. ARMOR gives security leaders a clear and practical way to organize AI risk through expert guidance across seven security domains: governance, risk and compliance, model protection, secure AI operations, infrastructure security, identity security, data security, and secure development lifecycle which results in cyber resilient architecture.
ARMOR's seven domains focus on key elements of securing AI systems and related processes, helping organizations understand security control points inside and between these systems, and in their interactions with the surrounding environment. This is key to understanding how AI security mechanisms mesh with traditional security solutions and is vital to identifying present gaps. ARMOR also accommodates organizations at different maturity levels. ARMOR is a real-world-tested AI security framework that was shaped through two-way collaboration with a lighthouse customer who served as the first testing ground.
Cisco uniquely delivers end-to-end AI security aligned across all six ARMOR domains through its , an enterprise architecture designed by Cisco and NVIDIA and operationalized by WWT for real-world environments. Cisco Secure AI Factory with NVIDIA is built on a simple idea. You do not get resilient AI by stacking controls, you get it by designing security as part of how AI is built and run. In the sections ahead, we'll show exactly how Cisco's portfolio maps to each ARMOR domain.
Cisco uniquely delivers end-to-end AI security aligned across all seven ARMOR domains through its Secure AI Factorywith NVIDIA, an enterprise architecture designed by Cisco and NVIDIA and operationalized by WWT for real-world environments. Cisco's Secure AI Factorywith NVIDIA is built on a simple idea: you do not get resilient AI by stacking controls, you get it by designing security as part of how AI is built and run. In the sections ahead, we'll show exactly how Cisco's portfolio maps to each ARMOR domain.
Mapping Cisco's Portfolio to ARMOR Domains
Cisco's Secure AI Factory with NVIDIA delivers unified security across all seven ARMOR domains, giving organizations a scalable, actionable framework for governing and protecting AI systems as they become essential to business operations. The approach emphasizes strong infrastructure protection, operational resilience, and secure model deployment. The mapping below illustrates the high-level coverage of Cisco's broad range of solutions:
Focusing a bit closer, Cisco's Secure AI Factory demonstrates a focused and specialized approach in alignment with ARMOR:
With the entire portfolio mapped, now let's look at how each solution within Cisco Secure AI Factory with NVIDIA powerfully drives security across the ARMOR domains.
1. Cisco AI Defense
ARMOR Domains: GRC, Secure AI Operations, Model Protection, Secure Software Development Lifecycle, Data Security
Cisco AI Defense is the primary control plane for governing, protecting, and operating AI models across the enterprise Secure AI Factory. Cisco AI Defense provides both a model‑agnostic gateway between users and LLMs and API‑level controls for embedding runtime guardrails directly into AI workflows. Some key capabilities and alignment areas are:
- Shadow AI Discovery: Identifies unauthorized or unmanaged AI applications and model usage across the cloud, bringing previously unknown AI assets under centralized governance and audit control.
- Runtime Guardrails: Inspects AI prompts and responses in real time to prevent prompt injection, jailbreaking, and model extraction, preserving model integrity during production use. Inspection can be done via gateway, API, or MCP connection.
- Automated PII Masking and Data Redaction: Enforces privacy by design by stripping sensitive data from prompts before they leave the enterprise environment, reducing the risk of data leakage to external LLMs.
- SaaS, Hybrid, or On-prem: Deploy AI Defense how you want, with options to have Cisco host everything, just the administrative plane, or have everything on premise for the strictest data policies.
- Model Validation and Red Teaming: With the use of over 1,400 tests model validation enables pre-production and continuous validation of model behavior, helping organizations test for safety, misuse, and policy violations before and during deployment.
- AI Interaction Logging and Telemetry: Generates detailed records of AI usage and policy enforcement that feed centralized operations and compliance reporting workflows.
- Supply Chain Security: Scan online models files before use to ensure secure components are used when building. Additionally, admins can setup a schedule scan of their Model Context Protocol (MCP) server to catch tool drift or malicious tooling, or use runtime guardrails to control requests going through their MCP connections.
2. Cisco Identity Services Engine (ISE)
ARMOR Domains: GRC, Infrastructure Security, Identity Security, Data Security
When identity becomes the common control plane, accountability and auditability get easier, and the rest of the security stack can build on a solid foundation. Cisco ISEestablishes identity as the foundation of trust across the Secure AI Factory. A few highlighted features include::
- Identity-Based Access Control: Authenticates users, devices, and service accounts are distinctly identified before granting access to AI infrastructure, datasets, and management consoles.
- Zero Trust Policy Enforcement: Enforces least privilege access based on identity, and device profiling rather than MAC Address or network location preventing unauthorized access to sensitive AI resources. Respond at machine speed with to threats detected in your environment by dynamically changing access of affected endpoints.
- Identity Auditing and Logging: Identify humans and machines on network with profiling and Identity assurance. Produces detailed identity and access logs that support governance, compliance reporting, and accountability requirements.
- Data Access Governance: Ensures that only authorized users and systems can interact with sensitive training data and AI outputs.
3. Cisco Duo with Identity Intelligence
ARMOR Domains: Identity Security, GRC, Infrastructure Security
Identity is the connective tissue of the Secure AI Factory; the control plane where human users, devices, service accounts, and AI agents all seek access. Cisco Duo Identity and Access Management (IAM) and Cisco Identity Intelligence establish and continuously verify that trust. Key capabilities and alignment areas are:
- Strong and Passwordless Authentication: Duo IAM enforces multi-factor and passwordless authentication for users accessing AI infrastructure, datasets, and management consoles.
- Risk-Based and Continuous Validation: Duo Risk-Based Authentication and Cisco Identity Intelligence continuously evaluate identity risk and posture, adapting access decisions rather than trusting a single point-in-time login.
- Federated and Machine Identity: Duo supports federated identity and, together with Duo Desktop and ISE, extends identity management to machine and workload identities.
- Compromised-Identity and Agent Detection: Cisco Identity Intelligence detects anomalous or compromised identities and helps drive toward least-privilege and zero-standing-privilege models.
- Identity Governance and Accountability: Provides the identity foundation for governance, giving auditors a clear record of who accessed which AI resources and when.
4. Cisco DUO Enhanced with Astrix
ARMOR Domains: Identity Security, GRC, Model Protection, Secure Software Development Lifecycle, Data Security
Autonomous agents, service accounts, API keys, and OAuth tokens now vastly outnumber human users, and each is an identity that can be abused. Astrix purpose-builds non-human identity (NHI) security and agentic AI identity, as a part of Cisco DUO, Astrix complements Cisco Secure Access, and Cisco Identity Services Engine (ISE). Core capabilities and alignment areas include:
- NHI Discovery and Lifecycle Management: Provides purpose-built NHI lifecycle management across enterprise systems and AI pipelines.
- Secret Discovery and Vaulting: Finds exposed secrets, recommends vaulting, and integrates with secret managers to govern the credentials that AI agents and build pipelines rely on. In the SDLC, this includes CI/CD secret discovery and OAuth/PAT governance for build pipelines.
- RBAC/ABAC and Zero-Standing-Privilege: Analyzes role- and attribute-based access for NHIs and OAuth scopes, and detects and removes standing privilege on service identities and tokens.
- Continuous NHI Risk Scoring: Establishes behavioral baselines for non-human identities and continuously scores risk, enabling faster detection of anomalies.
- Agentic AI Identity: Provides agent identity discovery, posture, behavior monitoring, and automated revocation — the identity backbone for governing AI agents securely.
Data-Access Governance for NHIs:
Maps NHI access to sensitive data stores, supports NHI-to-data-access lineage, and governs encryption keys, API keys, and KMS service identities.
5. Isovalent (Cilium)
ARMOR Domains: Secure AI Operations, Infrastructure Security
Isovalent delivers container networking, observability, and security optimized for AI workloads. Primary areas of alignment and capabilities include:
- eBPF-Based High Performance Networking: Provides low latency, kernel level networking and security enforcement designed for high bandwidth AI environments.
- Granular Workload Segmentation: Enables identity aware segmentation at the [KD1] service level within Kubernetes clusters, limiting lateral movement between AI microservices.
- Deep Observability: Offers fine-grained visibility into service-to-service communication, supporting real-time monitoring and troubleshooting of AI workloads.
- Telemetry Integration for Operations: Feeds detailed network and workload telemetry into centralized security operations platforms for correlation and response.
6. Splunk
ARMOR Domains: GRC, Secure AI Operations
ARMOR's Secure AI Operations and Cyber Resilience domains depend on centralized visibility and response. Splunk acts as the operational "brain" of the Secure AI Factory. Notable features include:
- Centralized Telemetry Aggregation: Ingests logs and signals from all layers of the Secure AI Factory, including identity, infrastructure, network, and AI protection layers.
- AI Specific Threat Correlation: Detects adversarial AI attacks such as prompt injection, model poisoning, and misuse through holistic information and event analysis.
- Compliance and Audit Dashboards: Provides a single pane of glass for governance reporting and regulatory audits.
- Incident Detection and Response Enablement: Supports rapid investigation and remediation of AIrelated security events.
7. Cisco Hypershield
ARMOR Domains: Infrastructure Security
ARMOR highlights the need for autonomous, resilient infrastructure protection. Cisco Hypershield delivers this through Alternative, kernel level security. Hypershield reduces exposure time and operational burden while maintaining performance. Core capabilities include:
- Enabling Semi-Autonomous Defense to the Secure AI Factory: providing policies that limit exploitation and lateral movement between AI workloads.
- Virtual Patching: Realtime protection that defends against zero-day vulnerabilities without impact to service uptime.
8. Cisco Hybrid Mesh Firewall and Secure Workload
ARMOR Domains: Infrastructure Security
Cisco Hybrid Mesh Firewall delivers consistent security across hybrid and multi-cloud AI environments. Once AI workloads span data centers and cloud, consistency becomes the hard part, and Cisco Secure Firewall (as part of the Cisco Hybrid Mesh Firewall architecture) acts as the multi-tenant enforcement layer across on-prem and cloud environments, especially when paired with identity and network telemetry from ISE. Key capabilities and alignment areas are:
- Unified Policy Enforcement Across Environments: Applies the same segmentation and access policies to AI workloads running on-premises and in the cloud.
- Identity-Aware Traffic Control: Integrates with Cisco ISE to ensure traffic decisions are based on verified identity.
- Micro-Segmentation of AI Workloads: Cisco Secure Workload enforces micro-segmentation to contain lateral movement between AI services.
- Hybrid AI Workload Protection: Secures AI services as they move from development to production across different deployment models.
9. Cisco Secure Application
ARMOR Domains: GRC, Secure Software Development Lifecycle
Cisco Secure Application protects the AI software supply chain, while Cisco TALOS prioritizes remediation by risk. A few features include:
- CI/CD Pipeline Scanning: Identifies vulnerabilities, hardcoded secrets, and misconfigurations in AI and system build pipelines.
- Secure Build Integrity Verification: Ensures AI application and container integrity, limiting tampering and data manipulation before deployment.
- Dependency and Library Validation: Confirms that AI frameworks and components are free from known exploits.
- Application Security Posture Management: Continuously assesses the security posture of AI applications throughout their lifecycle, supported by pre-production model validation from Cisco AI Defense.
10. Cisco Secure Access (SSE)
ARMOR Domains: GRC, Data Protection
Cisco Secure Accessprotects data across AI usage scenarios. Some core capabilities include:
- Secure Remote Access to AI Resources: Enables controlled access for distributed users interacting with AI systems.
- Data Loss Prevention Controls: Prevents sensitive data from being shared with unauthorized third-party AI services or models.
- Remote Browser Isolation: Control users access to the internet by isolating sessions to risky sites, or control the browser completely with enterprise browsers.
- Policy Enforcement and Reporting: Supports governance requirements through consistent enforcement and auditability.
11. Cisco Talos Threat Intelligence and Incident Response
ARMOR Domains: Secure AI Operations
Security teams move faster when they have context, and Cisco Talos Threat Intelligence works to bring that context to secure AI operations. Feature highlights cover:
- Threat Intelligence Feeds: Supplies continuously updated intelligence on emerging threats, including AI focused attack techniques.
- Detection Enrichment: Integrates into agnostic SOC environments.
- Incident Response and Recovery: help teams respond to and recover from AI-related security events, supporting business continuity.
- Operational Resilience Support: Helps security teams adapt detection and response strategies as AI threats evolve.
12. Cisco Nexus Smart Switches
ARMOR Domains: Infrastructure Security
In high performance AI, security cannot introduce a bottleneck, and Cisco's DPU enabled switching is designed to provide performance at scale. Cisco's Nexus Smart Switches with DPUs offload security tasks such as encryption, telemetry, and enforcement to the hardware layer, including integration with NVIDIA BlueField DPUs. In contrast, Nexus 9000 switches serve as the high-performance networking fabric for NVIDIA DGX SuperPOD deployments, delivering the low-latency connectivity essential for AI training clusters. Reliable high-throughput networking is part of what makes 'secure and scalable' AI possible, not an afterthought,
Looking Ahead: Agentic AI, Non-Human Identity, and the Quantum Era
The seven-domain model is built to evolve with the threat landscape. Across the portfolio, Cisco is advancing capabilities that ARMOR flags as emerging priorities: agentic AI governance and MCP security in AI Defense; the SOC of the Future in Splunk with the AI Assistant for Security; purpose-built non-human identity security through Astrix (part of DUO); DPU-layer security in Nexus Smart Switches; and quantum-resistant protections for the post-quantum era. Identity security, spanning human, machine, and agent identities, sits at the center of this roadmap, because governing the agentic workforce starts with knowing and trusting every identity in the factory. Ready to get started?
At WWT we're setting a New Standard for Enterprise-ready AI with Cisco Secure AI Factory with NVIDIA. Cisco Secure AI Factory with NVIDIA delivers a comprehensive, ARMOR-aligned approach to AI security. Whether you're beginning your AI security journey or looking to mature your program, For organizations getting started with ARMOR, the journey begins with visibility and prioritization. Access the ARMOR dashboard, connect with us for an ARMOR briefing, and take the next step toward secure, resilient AI.