Cisco Umbrella is a cloud-delivered security service that protects users from internet threats before a connection is made. Its core job is DNS-layer security. Every time a device looks up a domain, Umbrella checks the request against Cisco Talos threat intelligence and the organisation’s policy, then either resolves it or returns a block page.
This stops malware, phishing and command-and-control callbacks at the earliest possible point, whether the user is in the office, on home Wi-Fi or travelling. Because it runs in Cisco’s cloud, there is no appliance to install, and laptops stay protected off the network through the Umbrella module in Cisco Secure Client.
Umbrella began life as OpenDNS, which Cisco acquired in 2015 for $635 million. Over time the product grew beyond DNS filtering. The Secure Internet Gateway (SIG) packages added a web proxy with HTTPS inspection, a cloud-delivered firewall, CASB for cloud app visibility and data loss prevention.
In practice, organisations use Umbrella for three things: blocking malicious domains, enforcing acceptable-use content filtering, and seeing which domains users and devices are reaching. It does not provide access to private applications, which is the job of zero trust network access (ZTNA) products.
Cisco has since announced that Umbrella DNS and SIG are evolving into Cisco Secure Access, with end of sale set for 31 January 2027, so teams reviewing the product today should factor that migration into their plans.