Picture a doorman at the entrance of your business. He checks who’s allowed in, turns away visitors who don’t belong there, and simply waves through the regular staff. Now imagine that the key this doorman uses can be copied by anyone. That’s roughly what’s happening with Cisco Identity Services Engine (ISE). Cisco warns that a critical flaw in this system is being actively exploited. That’s not a small thing, because ISE isn’t just another part of your network: it is the gatekeeper.
Why this flaw goes deeper than a typical security issue
We’ve previously written about the risk of a departed employee still being able to log in because an account wasn’t disabled in time. Annoying, but contained: one account, one risk. This flaw goes a layer deeper. Cisco ISE is the system that decides who and what gets access to your network in the first place: a laptop, a printer, a scanner on the shop floor, a supplier logging into the guest wifi. ISE checks identity and decides whether the gate opens.
If that system itself has a weak spot, the problem isn’t one key but the key-cutting machine itself. Someone exploiting this flaw can pose as a trusted device or user and get in without anyone immediately noticing. That’s why Cisco classifies this as critical, and why active exploitation is already being reported.
What this means for your business
If you use Cisco ISE, the first question is simple: has the update already been applied? But even if you don’t use it, this news is still relevant. Many businesses in wholesale, manufacturing, and transport & logistics run their own network infrastructure with a comparable system that decides who gets access, under a different brand name but with the same function. So the real question is broader: do you know who at your company determines network access, and is that system up to date?
This is part of what we call IAM: identity and access management, meaning the whole set of rules and systems that governs who gets access to what. Not just employees, but also devices, suppliers, and visitors. An unpatched access server is, in that sense, nothing more or less than a front door that can no longer be locked.
Measure first, then patch and set policy
Our experience is that businesses often want to start with the technical fix: patch quickly and move on. Understandable, but incomplete. You simply can’t make good policy about something you don’t have visibility into. Before doing anything, first map out which systems at your company determine network access, who manages those systems, and which devices and users hold which rights. Only with that overview can you patch in a targeted way and establish who is allowed to manage access going forward, and how often that gets checked.
Policy comes before technology here. Installing an update is a technical action, but who is allowed to approve that update, who can add new devices to the network, and who checks this periodically: that’s policy. Without that policy, you solve today’s problem but find yourself in the exact same spot at the next vulnerability.
And when you tighten access policy, bring people along before you make anything mandatory. Explain to employees and suppliers why certain access will now be checked more strictly. Support prevents people from looking for workarounds, which would undermine the policy immediately.
What you can do right now
A few steps you can take without much effort:
- Check whether Cisco ISE, or a comparable system, runs at your company, and who manages it.
- Ask whether the latest security update has been applied and when this was last checked.
- Make a simple list of all the systems at your company that determine network access.
- Record who manages this and how often it gets reviewed.
- Make sure this doesn’t remain isolated as a technical fix, but becomes part of a broader access policy.
That way, a single flaw becomes the reason to build something structural: knowing, in a demonstrable way, who is allowed on your network, instead of simply trusting that it’s fine.
A few questions we’re often asked
We don’t use Cisco, so is this even relevant to us?
Even without Cisco ISE, you almost certainly have a comparable system that determines network access, whether from a different vendor or through your firewall and switch configuration. The question that remains is the same for every business: do you know who manages that system, and is it demonstrably up to date?
How do I know if our system is vulnerable?
Ask your ICT administrator or supplier explicitly whether the Cisco ISE flaw applies to your setup and whether the update has already been applied. If you don’t manage this yourself, this is a good moment to ask who does, and how you stay informed about it.
What if patching isn’t possible right away, for example because production processes can’t afford downtime?
Then it’s especially important to know, in the meantime, who has access and which devices are allowed on the network, so you limit exposure until you can find a moment to update. Talk to your ICT partner about temporary measures, such as restricting external access to the management system itself.
Is this also relevant to NIS2?
Yes. NIS2 requires, among other things, that you can demonstrably show who has access to your systems and how you monitor that. An up-to-date overview of your access systems, including patch status and management responsibility, is exactly the kind of evidence that helps you move toward being demonstrably ready for NIS2.
Curious who actually determines network access at your company? We help businesses map that out first, so that patching and policy can follow in a targeted way.