Veilig & weerbaar

Cisco flaw hits the gatekeeper of your network: what now?

Cisco warns of active exploitation of a flaw in Identity Services Engine, the system that decides who gets access to your network. That strikes at the core of your access security.

All articles

Picture a doorman at the entrance of your business. He checks who’s allowed in, turns away visitors who don’t belong there, and simply waves through the regular staff. Now imagine that the key this doorman uses can be copied by anyone. That’s roughly what’s happening with Cisco Identity Services Engine (ISE). Cisco warns that a critical flaw in this system is being actively exploited. That’s not a small thing, because ISE isn’t just another part of your network: it is the gatekeeper.

Why this flaw goes deeper than a typical security issue

We’ve previously written about the risk of a departed employee still being able to log in because an account wasn’t disabled in time. Annoying, but contained: one account, one risk. This flaw goes a layer deeper. Cisco ISE is the system that decides who and what gets access to your network in the first place: a laptop, a printer, a scanner on the shop floor, a supplier logging into the guest wifi. ISE checks identity and decides whether the gate opens.

If that system itself has a weak spot, the problem isn’t one key but the key-cutting machine itself. Someone exploiting this flaw can pose as a trusted device or user and get in without anyone immediately noticing. That’s why Cisco classifies this as critical, and why active exploitation is already being reported.

What this means for your business

If you use Cisco ISE, the first question is simple: has the update already been applied? But even if you don’t use it, this news is still relevant. Many businesses in wholesale, manufacturing, and transport & logistics run their own network infrastructure with a comparable system that decides who gets access, under a different brand name but with the same function. So the real question is broader: do you know who at your company determines network access, and is that system up to date?

This is part of what we call IAM: identity and access management, meaning the whole set of rules and systems that governs who gets access to what. Not just employees, but also devices, suppliers, and visitors. An unpatched access server is, in that sense, nothing more or less than a front door that can no longer be locked.

Measure first, then patch and set policy

Our experience is that businesses often want to start with the technical fix: patch quickly and move on. Understandable, but incomplete. You simply can’t make good policy about something you don’t have visibility into. Before doing anything, first map out which systems at your company determine network access, who manages those systems, and which devices and users hold which rights. Only with that overview can you patch in a targeted way and establish who is allowed to manage access going forward, and how often that gets checked.

Policy comes before technology here. Installing an update is a technical action, but who is allowed to approve that update, who can add new devices to the network, and who checks this periodically: that’s policy. Without that policy, you solve today’s problem but find yourself in the exact same spot at the next vulnerability.

And when you tighten access policy, bring people along before you make anything mandatory. Explain to employees and suppliers why certain access will now be checked more strictly. Support prevents people from looking for workarounds, which would undermine the policy immediately.

What you can do right now

A few steps you can take without much effort:

  • Check whether Cisco ISE, or a comparable system, runs at your company, and who manages it.
  • Ask whether the latest security update has been applied and when this was last checked.
  • Make a simple list of all the systems at your company that determine network access.
  • Record who manages this and how often it gets reviewed.
  • Make sure this doesn’t remain isolated as a technical fix, but becomes part of a broader access policy.

That way, a single flaw becomes the reason to build something structural: knowing, in a demonstrable way, who is allowed on your network, instead of simply trusting that it’s fine.

A few questions we’re often asked

We don’t use Cisco, so is this even relevant to us?

Even without Cisco ISE, you almost certainly have a comparable system that determines network access, whether from a different vendor or through your firewall and switch configuration. The question that remains is the same for every business: do you know who manages that system, and is it demonstrably up to date?

How do I know if our system is vulnerable?

Ask your ICT administrator or supplier explicitly whether the Cisco ISE flaw applies to your setup and whether the update has already been applied. If you don’t manage this yourself, this is a good moment to ask who does, and how you stay informed about it.

What if patching isn’t possible right away, for example because production processes can’t afford downtime?

Then it’s especially important to know, in the meantime, who has access and which devices are allowed on the network, so you limit exposure until you can find a moment to update. Talk to your ICT partner about temporary measures, such as restricting external access to the management system itself.

Is this also relevant to NIS2?

Yes. NIS2 requires, among other things, that you can demonstrably show who has access to your systems and how you monitor that. An up-to-date overview of your access systems, including patch status and management responsibility, is exactly the kind of evidence that helps you move toward being demonstrably ready for NIS2.


Curious who actually determines network access at your company? We help businesses map that out first, so that patching and policy can follow in a targeted way.

Newsletter

Practical IT insights, once a month

What happened, what it means for your business and one thing you can do today. No sales talk, unsubscribe anytime.

We only use your address for the newsletter. See our privacy statement.

Questions about your own IT?

Take the free scan and see how your own IT is doing, instead of leaving it at general knowledge. Want to talk it through? A no-strings intro call is always an option.

Free and no-strings, no sales pitch.

May we measure what helps you?

Analytical cookies show us which pages help you and which don't, so we can improve the site. No ads, no selling of data. We only place them after your consent. Read our cookie policy.

You can change your choice later via ‘Cookie preferences’ at the bottom of every page.