VIDEO: Cisco SVP Security Chris Young

Transcription

um now I I know that you're the SVP of security technically is your title I know that's a relatively new role in in Cisco just give me a little bit of color as to what that's all about and what your responsibilities are so I got to Cisco about a year ago a little bit over a year so last year's RSA conference was uh brand new for me in my role at Cisco although I've been here many times because I used to work at RSA been around security for for quite a few years now um but my responsibility is is um primarily focused on uh security products for the company so all the firewall web email IPS VPN even Cloud security and identity Services businesses that we have you know across Cisco uh fall into that product portfolio as well as responsibility for our govern Global Government Solutions team which is uh really focused on it's it's a group that that kind of specializes in how um we interface um and think about our product as they relate to governments and specific requirements that governments have for the products whether those be certifications or adaptation that need to be that needs to be done for the government now across those individual groups certainly there's the core routing switching there security post pieces there's specific security uh Cloud I know you know L Tucker has his own area for cloud so how do you from an organizational point of view is that a lot of dotted lines of of responsibility and how does that work well there's I mean think about think of security in two different ways there's there's kind of security as an industry vertical you know where we have products that are security products which is kind of like what this conference a lot of this conference is about like particularly the vendors out here on the show floor but then there's security as a horizontal which is what you're pointing out which are security capabilities the security levels of of our products themselves so you know for example how we use encryption How We Do embedded security how we securely develop products those are all elements of you know that that you know different components of my team will work with other teams across Cisco to help deliver either best practice or embedded components so for example uh we have a team that that's in my organization that that builds common crypto crypto toolkits that then get propagated across Cisco platforms so that you know those those platforms can be kind of up to speed with the Next Generation encryption capabilities can be fips 140-2 compliance for the government uh so that's kind of think about that as security as a baseline across all of our products then a level up from that is the architectures for security uh capabilities that do need to integrate with the rest of the rest of the company so our team our team drives and champions the trust SE dark architecture across the multiple platforms that that have to build trust into the architecture um we and we do a number of things we program manage a lot of it we work across the different teams we help them implement it we help them test and architect uh we we do a lot of the validated design work around that embedded architecture like truss SEC um they do have to do those individual teams do have to do the development for trustsec but we help them kind of design validate um Implement in some cases but ultimately yes the individual product teams are the ones who ultimately are responsible for building that capability into their their platforms got it yeah so through the through the security office you know for Cisco right John Stewart is our our so there's a team within that group that you know does look at the the vulnerab you know potential vulnerabilities of products how you know um what could what you know sort of we test products we understand now each team is responsible for their own testing their own validation you know we do help them with secure development life cycle best practices so they do test and validate against that as they go through their overall development life cycle practices but I do have a team um that does have the ability to kind of do some checks and balances on what the broader set of platform teams are building and works with them on making sure that the right level security is insured before something ships and that's all coming up to you so if I understand it correctly you've got uh internal responsibility as it were on products that are shipping and then responsibility on product direction as well correct from a security perspective from a security perspective uh which makes sense uh good uh it's a good Baseline so now I'm fully aware uh cuz I know it's a new responsibility it's a new role Cisco never had that before so is it something where uh manag man agement uh I know there's a new chief operations officer where they said this is a discipline that we need or is this a case where you came in and you functionally created your own function and your own responsibility I I think there was you know the sort of the the a well-kept secret across Cisco I think for years has been that there's been a tremendous amount of security being done in various places in the company you know whether it's being driven by specific platform teams architecture teams like the trust SE team uh the internal security teams like John Stewart's team and others that were all doing you know sort of doing aspects of security whether that was to ship a security product or whether that was to ensure the Baseline levels of securi across our our product portfolio uh the realization that that I think John and other senior leaders came to maybe a little bit before I got there I'm not exactly sure whether it was a year before six months before I got there um was that they wanted to uh really have more of a focused leader for security across the company whether that be about the level of security and the architecture um in our product set across the different broader architectures like routing and switching and data center Etc um as well as delivering security products capabilities that the market is going to consume for their their kind of targeted security needs and uh your chief executive is a very engaged individual what sort of uh metrics have been pushed down uh Beyond on just you know Financial metrics or is it just Financial metrics that are your your your kpis Etc and the dashboard indicators on which these measures your success success of your group so security is a good business and and everyone at Cisco recognizes that and and the expectation is that we're going to be competitive there we're going to grow the businesses that we have for security um but we're also um we're also very very serious about making security a part of our overall set of architectures a great example of that is Unified access sure um so ice our identity Services engine as well as the truss SEC architecture are a major part of our overall unified access architecture at the Enterprise networking the wireless teams are driving and we're really unifying wired and wireless access for for Enterprises public sector organizations as well and our security capabilities in particular the identity Services engine and trustsec are a core part of that so while that's a you know while we have responsibility for the product element of that you know the the the participation uh in the unified access overall architecture is critical um again not just for the Standalone revenue from ice but for the the overall value proposition that Cisco brings to its customers around wired and wireless accessing perspec I mean from a from a metrics perspective you know we're looking at we look at revenues we look at um number of users number of organizations so it's kind of that security ver as a vertical and security as a horizontal balance that we're striking so I think that you know again the expectation is we have a good security business we have a lot of industry-leading security capabilities and products in our portfolio we do a lot of security services that roll up through our services organization um all of which we expect to continue to grow and to deliver value around but then there's also this element of security as part of our other architectures and you know a lot of the success for that there will be some elements measured in Revenue but there will also be some elements around adoption around the value proposition that customers give us and then the direct feedback as you know Cisco is very engaged with our customers we have a lot of dialogue through a lot of different vehicles with our customers with our Channel partners and so that feedback will be part of the validation that we get around okay how well are we doing at delivering security as part of our architecture when you look at your job and the the width and breadth of the Cisco portfolio and the width and breadth of the threat landscape what's the is the biggest challenge is it just uh reporting up to your Opera management is it you know dealing with difficult clients or is it some kind of operational or technical issue I think the the the biggest thing for us is is really delivering on you know the value that the network can bring to the overall security architecture uh and that's that's a big you know that's a big challenge because when you're Cisco and you you run so much of the it infrastructure from the data center to the network and now ultimately out to the you know to the wireless access that most of our new devices are leveraging as their core access point um you know your customers Look to You to provide security across that entire expanse of infrastructure and so our you know our our focus is to simplify yet be broad at the same time and that's I would say that's an opportunity U but it takes a lot of work to be able to do that as well and I think that's uh that's something that we're committed to and I think the what you're seeing from John and from other Executives as they're talking about security publicly and what they've you know that what they've done with us internally is to really put that focus in the right place uh and to you know to take the long-term view you know if you listen to any comments that John's made publicly about security over the course of the last year he's committed to the long-term architecture uh where we do continue to drive uh great security capabilities in our Standalone appliances where needed uh but also making sure security is really a core part of the other large architectures that Cisco is bringing to Market whether that be Data Center Enterprise service provider collaboration Etc and so I think that's our opportunity as well as our challenge but I do believe that that we can do both we have to do both and it's going to benefit our customers over the long term

This transcript was generated automatically from the video's captions and may contain errors.

Published: Mar 11, 2013
Updated: Jul 16, 2021
1 minute read

At the end of 2011, Chris Young joined Cisco as the leader of the company’s new security and government group, tasked with overseeing a massive portfolio of security products and initiatives.

In a video interview with InternetNews.com at the RSA conference, Young detailed his role and his challenges at the world’s largest networking vendor and where security fits into the mix.

Read the full story at EnterpriseNetworkingPlanet:
How Chris Young is Securing Cisco’s Security Business

Sean Michael Kerner is a senior editor at InternetNews.com, the news service of the IT Business Edge Network, the network for technology professionals Follow him on Twitter @TechJournalist.

Sean Michael Kerner

Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.