Health

Duo Unveils First Production Deployment of Foundation AI

Duo Unveils First Production Deployment of Foundation AI


Today marks a major milestone in the evolution of Cisco security. Cisco Identity Intelligence is now the first Cisco product to deliver a customer facing capability powered entirely by a Cisco built artificial intelligence model, Foundation-sec-1.1-8B-Instruct. This achievement represents the beginning of a true Cisco-on-Cisco strategy and proves that Cisco’s own security tuned models are ready for production use at global scale.

Cisco Identity Intelligence helps organizations understand and respond to identity related risk across their entire environment. It continuously monitors identity behavior, giving administrators clear insight into who is logging in, from where access is taking place, and which device is being used. By examining post authentication signals, the system identifies patterns that traditional access controls often miss, including unusual geographic activity, abnormal privilege usage, and indications of MFA fatigue attempts or session hijacking. This expanded visibility enables security teams to take proactive action before attackers advance within the environment.

A key part of this experience is the weekly email digest that Cisco Identity Intelligence sends to administrators. This digest condenses the most important identity events and issues of the week into a clear and actionable summary. It highlights anomalies, risk trends, and opportunities to strengthen identity hygiene. With more than two thousand customers relying on this summary each week, the digest has become an essential touchpoint for maintaining visibility and acting quickly on identity related findings.

Producing such a digest requires an artificial intelligence model that understands identity behavior, can interpret long chains of events, and communicates insights in a way that aligns with how security administrators make decisions. General purpose models can help, but they are not always tuned for the nuance and precision required for identity security and often introduce external dependencies. For this reason, Cisco Identity Intelligence now uses the Cisco Foundation AI model to craft digest content, resulting in summaries that are more accurate, more readable, and more aligned with real security workflows.

From the customer perspective, the workflow stays exactly the same, but the content becomes noticeably stronger. Digest summaries become clearer and more consistent. Prioritization improves, making it easier to identify what demands immediate attention. Insights feel more relevant to each environment, and recommendations are expressed in a more actionable way.

Although customers do not directly see the infrastructure change, they feel the benefit in the form of sharper, more reliable identity insights that help them make quicker and more confident security decisions. This improved experience also increases the value of the Cisco Identity Intelligence interface, encouraging customers to return more regularly to investigate findings, validate activity, and take corrective action.

Cisco Identity Intelligence selected the Cisco Foundation AI model because it offers clear advantages in quality, control, and long-term strategic alignment.

Foundation-sec-1.1-8B-Instruct is trained specifically on cybersecurity and identity scenarios. Its reasoning reflects the way SOC analysts and identity administrators think, enabling it to deliver clearer insights, stronger anomaly explanations, and recommendations that feel natural to security teams.

By using a Cisco built model rather than external systems such as Claude, the team gains predictable behavior, stronger control over quality, and the ability to tune the model to Cisco’s exact standards for identity security. This also supports improved reliability and long-term efficiency.

Because Cisco owns and operates the model, it can be customized and enhanced to support evolving identity use cases with a level of precision that external models cannot provide. The model can run in secure cloud environments, on premises installations, and other controlled settings, giving Cisco and its customers flexibility that aligns with enterprise security and compliance needs.

This milestone was made possible through close collaboration between the Cisco Identity Intelligence team and the Cisco Foundation AI team.

The Duo team conducted multiple rounds of evaluation on real identity digest data to assess accuracy, clarity, and relevance. Based on this feedback, the Foundation AI team improved instruction following, refined identity specific behaviors, and incorporated targeted training updates to ensure consistently high-quality summaries.

With the Duo team’s deep understanding of customer workflows and the Foundation AI team’s expertise with model behavior, both groups created a tuned prompt stack that significantly improved output quality and aligned the model with the analytical style expected in the digest.

The Foundation AI team hosts and serves the model through Amazon SageMaker, allowing Duo engineers to integrate it directly into their production systems with strong reliability and operational control.

The updated digest was piloted with three customers to validate real world performance. Early feedback showed meaningful improvements in accuracy, relevance, and clarity. Customers responded positively to the upgraded summaries, noting faster review times and clearer identification of important identity events.

The deployment of Foundation-sec-1.1-8B-Instruct inside Cisco Identity Intelligence is an important step toward Cisco’s vision for AI native security. Identity workflows, endpoint protection, network analytics, cloud defense, and policy analysis will all benefit from models that are purpose built for enterprise security.

This launch establishes a strong foundation for deeper integrations of Cisco artificial intelligence across the security portfolio and opens the door for even more advanced identity security capabilities.


We’d love to hear what you think! Ask a question and stay connected with Cisco Security on social media.

Cisco Security Social Media

LinkedIn
Facebook
Instagram
X





Source link