What should I replace Cisco Umbrella with?
Cisco has announced the end-of-sale and end-of-life of Cisco Umbrella SIG and DNS as it moves customers towards Cisco Secure Access.
Organizations can replace Umbrella function by function, or use its retirement as an opportunity to simplify secure access, internet security, ZTNA and remote connectivity around a more unified architecture.
The transition will not happen overnight. The end-of-sale date is January 31, 2027, existing subscriptions can be renewed until January 31, 2028, and Cisco plans to provide support until January 31, 2029.
For IT teams currently using Umbrella, that creates a useful window to decide what comes next.
Moving to Cisco Secure Access is one option. It is not the only one.
The security market has changed significantly since many organisations originally deployed Umbrella. Secure Web Gateway (SWG), Zero Trust Network Access (ZTNA), Security Service Edge (SSE), DNS security and application access are increasingly being evaluated together.
Here are 10 Cisco Umbrella alternatives worth considering.
Cisco Umbrella Alternatives Compared
| Product | Approach | Key capabilities | Good fit for |
| Cloudbrink | Personal SASE / High-Performance ZTNA | ZTNA, Internet Security, SWG, AI Security, machine and user tunnels, personal SD-WAN, QoE optimization, multi-cloud access | Organizations replacing Umbrella plus VPN/remote-access infrastructure and looking to consolidate security and connectivity |
| Zscaler Internet Access | Cloud SSE/SWG | SWG, TLS inspection, CASB, DLP | Large enterprise environments |
| Netskope One | SSE platform | SWG, CASB, ZTNA, data security | SaaS-heavy organisations |
| Cloudflare One | Cloud security platform | DNS filtering, SWG, ZTNA | Organisations wanting network and security consolidation |
| Palo Alto Prisma Access | Cloud-delivered security | SWG, ZTNA, firewall, threat protection | Existing Palo Alto environments |
| Cato SASE Cloud | SASE platform | Networking, SWG, ZTNA, firewall | Organisations consolidating networking and security |
| DNSFilter | DNS security | DNS filtering, threat blocking, content filtering | Teams primarily replacing Umbrella DNS |
| iboss | Cloud SSE | SWG, zero trust access, browser isolation | Distributed enterprise users |
| Forcepoint | SSE/data security | SWG, CASB, DLP | Data-security-focused organisations |
| Cisco Secure Access | SSE | DNS Defense, SWG, ZTNA, data protection | Organisations wishing to remain with Cisco |
1. Cloudbrink
Cloudbrink™ takes a broader approach to replacing Cisco Umbrella. Rather than treating DNS security, secure web access, ZTNA, remote connectivity and user experience as separate problems, Cloudbrink brings them together in a software-only Personal SASE service.
That makes Cloudbrink particularly relevant for organizations using the retirement of Umbrella to reassess not only internet security, but also VPNs, remote access and the growing number of security products required to protect distributed users and devices.
One policy for users, devices and machines
Cloudbrink OnGuard extends Cloudbrink security and connectivity policies beyond individual user sessions to the device itself.
A secure machine tunnel can become available when the device comes online, before a user signs in. This allows IT teams to apply policies to corporate machines independently of the user session, while managing user and machine activity from the same platform.
Organizations can apply policies including Internet Security, AI Security, ZTNA access controls and Cloudbrink quality-of-experience controls to machine tunnels as well as users.
For enterprises evaluating Cisco Umbrella alongside technologies such as Cisco Secure Access, AnyConnect and other security products, this creates an opportunity to consolidate more of the secure-access stack rather than replacing each function with another standalone service.
High-performance ZTNA instead of a traditional remote-access experience
Cloudbrink combines zero-trust access with personal SD-WAN and application-performance optimization.
The Brink App automatically connects users to nearby software-defined FAST Edges, while the Brink Protocol adapts to changing network conditions including packet loss, latency and unreliable last-mile connectivity.
This matters because security is only effective if employees can work productively with it enabled. Cloudbrink is designed to provide an in-office-like application experience for users working from homes, hotels, public Wi-Fi and geographically distant locations without requiring hardware appliances at the user location.
Secure access without hardware complexity
Cloudbrink is delivered as a 100% software-only service. Its architecture includes:
- High-Performance ZTNA for private application access
- Internet Security for controlling access to malicious and inappropriate internet destinations
- Secure Web Gateway capabilities
- AI Security
- OnGuard machine tunnels for pre-login and machine-level policy enforcement
- Personal SD-WAN and QoE optimization
- FAST Edges positioned close to users
- Multi-cloud connectivity to applications hosted across cloud and private environments
- Centralized visibility and policy management
This means organizations can evaluate Cloudbrink not simply as an alternative DNS service, but as a potential replacement for multiple components of a traditional remote-access and secure-access architecture.
Proven in Cisco replacement projects
The approach has already been used in environments replacing legacy Cisco remote-access infrastructure. One U.S. insurance company moved 300 employees to Cloudbrink on its first day of deployment and more than 600 during the first week. According to its VP of IT, remote-connectivity support calls subsequently “pretty much disappeared.”
For organizations approaching the Cisco Umbrella transition, that combination of Simplicity, Security and Speed makes Cloudbrink worth evaluating when the goal is bigger than replacing DNS filtering alone.
2. Zscaler Internet Access
Zscaler Internet Access is one of the established enterprise alternatives to Cisco Umbrella.
It provides a cloud-native Secure Web Gateway with TLS/SSL inspection, URL filtering, cloud application controls, CASB and data loss prevention.
Zscaler is particularly relevant for larger organisations that want to move internet security away from traditional perimeter appliances and apply consistent policies to users regardless of location.
Its broader feature set also means the evaluation can be more involved than replacing a standalone DNS filtering service.
3. Netskope One
Netskope One combines Secure Web Gateway, CASB, zero-trust access and data security capabilities.
Its strength is visibility and control around cloud applications and SaaS usage. This makes it worth considering for organisations where the Umbrella replacement project is also part of a broader cloud security programme.
Rather than concentrating primarily on DNS requests, Netskope can provide deeper controls over how users interact with cloud applications and organisational data.
4. Cloudflare One
Cloudflare One combines networking and security services on Cloudflare’s global network.
Cloudflare Gateway provides DNS, HTTP and network filtering. Its HTTP filtering can inspect full URLs and request content, while its broader Zero Trust platform provides application access and security controls.
This makes Cloudflare One an option for organisations wanting to combine DNS security, Secure Web Gateway and zero-trust access rather than deploying separate products for each function.
5. Palo Alto Networks Prisma Access
Prisma Access extends Palo Alto Networks’ security platform into a cloud-delivered environment.
It combines technologies including Secure Web Gateway, Zero Trust Network Access and cloud-delivered firewall capabilities.
For organisations already running Palo Alto Networks firewalls and security products, Prisma Access may provide a more natural path towards consolidating remote-user and cloud security policies.
Teams should nevertheless compare licensing, deployment requirements and operational complexity against their actual Umbrella use case.
6. Cato SASE Cloud
Cato approaches the problem through a broader Secure Access Service Edge architecture.
Instead of treating DNS filtering, remote access, WAN connectivity and internet security as independent services, Cato combines networking and security through its cloud platform.
That makes it particularly relevant when the end of Cisco Umbrella coincides with a wider SD-WAN, firewall or remote-access review.
For organisations that only need DNS-layer protection, however, a complete SASE deployment may be considerably broader than required.
7. DNSFilter
DNSFilter is one of the closer alternatives for organisations primarily using the DNS security capabilities of Cisco Umbrella.
It provides cloud-based DNS threat protection and content filtering, with deployment options for both networks and roaming users.
That narrower focus can be an advantage when the requirement is simply to prevent users from connecting to malicious, phishing or prohibited domains.
The distinction is important. DNS filtering operates at the domain level. Organisations requiring deeper inspection of HTTPS traffic, application activity or sensitive data should evaluate an SWG or SSE platform as well.
8. iboss
iboss provides a cloud-delivered Security Service Edge platform aimed at securing users regardless of where they connect.
Its capabilities include Secure Web Gateway, zero-trust access and other cloud security controls.
It is therefore more comparable with the broader SSE direction of the market than with a simple DNS filtering product.
Organisations considering iboss should assess how much of that broader platform they actually need and how it fits with existing identity, endpoint and network security tools.
9. Forcepoint
Forcepoint is another established option for organisations considering an Umbrella replacement as part of a wider security project.
Its portfolio includes Secure Web Gateway, cloud application security and data loss prevention.
The emphasis on protecting sensitive information can make Forcepoint particularly relevant where data security and compliance are major requirements.
As with the other broader SSE platforms, IT teams should compare the complete architecture rather than looking at DNS filtering alone.
10. Cisco Secure Access
The most direct migration path is also the obvious one: remain with Cisco.
Cisco Secure Access is Cisco’s strategic SSE platform and the intended successor to Umbrella. Cisco says Secure Access DNS Defense retains Umbrella’s DNS-layer security while adding capabilities including malware scanning, data loss prevention and broader zero-trust controls.
For organisations already heavily invested in Cisco, this may reduce some of the disruption associated with moving vendors.
The Umbrella end-of-life announcement is still a useful point at which to compare alternatives rather than automatically migrating. Existing architecture, security requirements, remote-user performance, administration and licensing should all form part of that evaluation.
What Should IT Teams Look for When Replacing Cisco Umbrella?
The first question is not necessarily which vendor replaces Umbrella. It is what part of Umbrella needs replacing.
An organisation primarily using Umbrella DNS has very different requirements from one using Secure Internet Gateway capabilities across a large distributed workforce.
Start by identifying whether you need DNS threat protection, full HTTPS inspection, SWG, ZTNA, CASB, DLP or a combination of these capabilities.
Remote-user experience should also be tested rather than assumed. Security architecture can affect latency, application responsiveness and the amount of traffic that needs to pass through external infrastructure.
Cisco Umbrella’s end-of-life provides IT teams with time to run those tests. With support continuing until January 2029, organisations do not need to make an immediate change, but they do have a clear deadline for deciding what their next secure access architecture should look like.



