What I find most valuable about Cisco Umbrella is its ease of use. I also value the clearness of the categories. We have not experienced any issues or incidents with the categories. However, we are looking more deeply at the product now.
Network Architect at a government with 1,001-5,000 employees
Easy to use and the categories are very clear
Pros and Cons
- "We are very new users of the solution and are still in the exploration stages, but we are happy with the product thus far."
- "I would like to see Cisco enable us to get objects from the internet. I would also like to be able to choose groups."
What is most valuable?
What needs improvement?
We are very new users of the solution and are still in the exploration stages, but we are happy with the product thus far. However, there are some features available in Fortinet and Palo Alto that are not available in Cisco, like objects, for example. I would like to see Cisco enable us to get objects from the internet. I would also like to be able to choose groups.
For how long have I used the solution?
I have been using Cisco Umbrella for two to three months now.
How are customer service and support?
For most of our technical support needs, we mostly go through our partner. However, for some infrastructure-related inquiries, we have had to contact Cisco's technical support and we were happy with the experience.
Buyer's Guide
Cisco Umbrella
July 2026
Learn what your peers think about Cisco Umbrella. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
906,852 professionals have used our research since 2012.
How was the initial setup?
The initial setup was simple. Deployment at our main sites took about three to four weeks.
What about the implementation team?
We received help from a local partner, NTT Global, during the deployment. They helped us set up Meraki and Umbrella.
What was our ROI?
We hope to see a return on investment with Cisco Umbrella. We have a big team managing the infrastructure, so we hope to save time in the day-to-day protection of the tower, which would be the return on investment.
Globally, we also hope to save time on the LAN. We aim for a single pane of glass management model with the dashboard.
What's my experience with pricing, setup cost, and licensing?
From what I remember about the pricing, Cisco Umbrella is a bit more expensive than the quotes we got from its competitors.
Which other solutions did I evaluate?
We looked at several products, including Fortinet and Palo Alto. We experienced a bug with Fortinet during testing and ultimately ended up going with Cisco Meraki products. We have not had an incident yet with Cisco Umbrella.
What other advice do I have?
The solution helped us save time and this was a major reason we chose it. We expect to save 15% to 20% in time.
We are aiming to consolidate our entire network and LAN infrastructure with Cisco Umbrella. We are on the way to achieving that with this solution.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Architect at a pharma/biotech company with 10,001+ employees
Great end-to-end detection and saves our IT team's time
Pros and Cons
- "I also think that the dashboard view is really helpful. Whenever sites get blocked, we get the details and the users who are connecting to them."
- "There is room for improvement in the dashboard. It could stand to be a bit more detailed. I would also like to be able to customize the dashboard to focus more on what is important for my company."
What is our primary use case?
Our primary use case for Cisco Umbrella is DNS filtering. We also have virtual appliances installed at almost all of our sites.
We refer our end users to the local VAs and also to the public Umbrella DNS. We mostly use it for the guest network. For internal users, we have dedicated virtual appliances installed at every site. We have a number of offices globally and each major site will have one VA.
How has it helped my organization?
Thanks to Cisco Umbrella, we are better able to respond to malicious attacks and block those domains right away.
What is most valuable?
The most valuable features in my opinion are DNS filtering, filtering details, and the ability to block certain web pages. However, we mostly use DNS filtering. I also think that the dashboard view is really helpful. Whenever sites get blocked, we get the details and the users who are connecting to them.
What needs improvement?
There is room for improvement in the dashboard. It could stand to be a bit more detailed. I would also like to be able to customize the dashboard to focus more on what is important for my company. This would be particularly important for the customized dashboard we create for the leadership team. This would help us get information to them quickly.
For how long have I used the solution?
I have been using Cisco Umbrella for the last three to four years.
What do I think about the stability of the solution?
Cisco Umbrella is stable.
What do I think about the scalability of the solution?
We use Cisco Umbrella across multiple offices so it is scalable. For the smallest offices, we use data center VAs and even in that configuration, it is scalable.
How are customer service and support?
Cisco's tech support is OK. I have had only good experiences with them.
They could work on getting on the calls more quickly because it can be difficult to reach them sometimes. This is particularly true during P1 outages.
On the other hand, they do really well with giving us helpful suggestions and additional information when we need it. The documentation is particularly good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did not previously use a different solution. We were blocking things through the Cisco firewall.
Migrating from our previous firewall configuration to Cisco Umbrella was not so difficult. We did not additionally configure the normal firewall policies. All we did with this solution was add an additional layer of security.
How was the initial setup?
The initial setup is not simple. It is quite difficult and cannot be implemented by everyone. You need to have some basic understanding of the product to deploy it. You need to understand DNS filtering and domain blocking and have a working knowledge of DNS and how it works. You should also have experience with virtual machines and VM detecting because Cisco Umbrella is on a VM.
What was our ROI?
We have seen a return on investment from Cisco Umbrella. We have seen many benefits.
What's my experience with pricing, setup cost, and licensing?
We are Cisco partners so we get a discount on the licensing. With the discount, I would say the pricing is OK.
Which other solutions did I evaluate?
We did not evaluate other options. Ultimately, we landed on Cisco because it is more user-friendly than its competitors.
What other advice do I have?
End-to-end detection is mostly used for end users. We make use of it and it works well for us. It helps us find malicious attacks and identify other breaches. Cisco Umbrella is helpful when it comes to remediation as well. Whenever there is a new attack, we receive a notification and we block the domains through the solution.
Cisco Umbrella frees up time for our IT staff, particularly the network operations team. They use this product to find attacks and users who access non-allowed pages. However, I cannot say exactly how much time is saved because it all depends on the day. We have offices across the globe and each is impacted individually by the solution.
Cisco Umbrella has not caused our organization to consolidate tools.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Cisco Umbrella
July 2026
Learn what your peers think about Cisco Umbrella. Get advice and tips from experienced pros sharing their opinions. Updated: July 2026.
906,852 professionals have used our research since 2012.
Network Manager at a consultancy with 501-1,000 employees
It is user-friendly and very easy to manage, but their support should be more efficient
Pros and Cons
- "It is user-friendly. It is easy to manage the solution."
- "I am a network administrator, and for me, it is the best solution because it is easy to manage."
- "Their support should be improved. It is necessary that the support is efficient. It is not really easy to get a resolution for an issue from Cisco support. They should be faster and more efficient."
- "Cisco Umbrella's support is not really efficient. When we have a problem, it is difficult to have good support."
What is our primary use case?
We are using it for user navigation. We have another solution for the server, and Umbrella is used for the people in the company for web access and security purposes. It helps to avoid security problems and authorize different types of access to the users for different web services.
How has it helped my organization?
I am a network administrator, and for me, it is the best solution because it is easy to manage. It is also effective for web access for the users.
With the old solution, we had a lot of restrictions because it was old technology and it was very important to provide different types of access. Umbrella is a cloud solution, and we can add access to new services or websites. It is a good product.
It is totally transparent for the users. When you have Cisco Umbrella on your computer, you cannot really see the product. It is very important for the users to not see the product.
It is very easy to manage, which is really important. We do not have time to manage this solution, and it is really important to have a good performance without any action or monitoring from my team. We work with Umbrella every day, but we don't need to make any changes on Umbrella because it is working.
It is easy to maintain network connectivity consistently across all workplaces, and it has been a good experience for our employees.
It provides resilience on all the sites. We have five sites, and all the sites have Umbrella.
What is most valuable?
It is user-friendly. It is easy to manage the solution.
What needs improvement?
Their support should be improved. It is necessary that the support is efficient. It is not really easy to get a resolution for an issue from Cisco support. They should be faster and more efficient.
For how long have I used the solution?
I have been using this solution for about three to four years.
What do I think about the stability of the solution?
It is very stable. I do not have a problem with this. We only had one bug three months ago, and we had a problem with the support, but before that, it has been a good experience.
What do I think about the scalability of the solution?
It is scalable. We deployed it on different sites of the company. We use it for a lot of different services.
We have about 600 users, but we have 1,000 licenses. We might increase its usage.
How are customer service and support?
Cisco Umbrella's support is not really efficient. When we have a problem, it is difficult to have good support. It is not really easy to resolve a problem with Cisco support. Three months ago, we had a problem with it, and the support was not very efficient. I would rate them a six out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We had a French solution. It was an old solution, and it was not sufficient for the company. Cisco Umbrella has been the best for our company.
How was the initial setup?
It is not really easy, but because we have experts with us, it was not complex for us. We did this in one month because it was really important to give good services to the users.
What was our ROI?
We have seen an ROI, but it is hard to provide metrics.
What's my experience with pricing, setup cost, and licensing?
We did a good negotiation, and at the moment, its price is fine.
Which other solutions did I evaluate?
I didn't look at other options. I only tested Cisco Umbrella.
What other advice do I have?
It has probably helped us to remediate threats more quickly. It is a good solution for user devices but probably not for servers.
I would rate it a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director of Security
Helped us monitor activity and find bad actors who had managed to grab and control some of our domains
Pros and Cons
- "Any time someone went off the network, the AnyConnect client had the Umbrella agent built in, and it would realize when their computer connected that they were not on the corporate network. It would monitor and they would have pretty close to the same rules that they had to follow when they were in the office, regarding what kind of website browsing they could do."
- "Cisco's Umbrella client product is superb, it worked so well for us and was easy to deploy."
- "The design of the screens could be improved. Sometimes you're trying to look for information, for what you think is critical that should be on that first screen of the dashboard so that you can quickly take screenshots to have people help out, but you have to hop between screens to find little pieces of evidence."
What is our primary use case?
In my previous company, there was a gap in being able to put controls on users when they were away from the network. We thought, "Okay, Umbrella can do this for us," and it was at a reasonable cost for our security budget.
How has it helped my organization?
With Umbrella, it didn't matter if the users were in the office or they were going to go out. When I trained them I said, "If you go to Target, Starbucks, or anywhere else you can get on a hotspot, you're going to be covered with our rules, so we can make sure you're protected and that our company device is protected."
It gave our users, from all of our sites, something like a first line of defense, including monitoring all the exit points of our offices. We also used Cisco AnyConnect on everybody's laptop so that any time they were out, we were making sure to secure their machine and keep an eye on it.
Having a single pane of glass allowed us to quickly monitor and find out what was happening at that moment. We could see active connections going to a public address on the internet. At one point there were so many of them, thousands and thousands to one public address, which was more than normal. I had to contact Cisco support, and say, "This is what I'm seeing. Something's not right," and they said, "You're right." In the main screen, we switched over to investigation and we found that it was a bad actor. The bad actor was checking for domains that are flying around, and he found a few of ours that weren't paid for. He bought them and then he started controlling where they were going by redirecting them. That raised a big red flag for our company. They never had any idea that that had been going on for a very long time.
There were other bad actors who had some of our domain names as well. I had to work with legal and we actually purchased back a few domain names from people. As a result, we taught our guys internally, "When you do a domain and you're going to do tests in the lab, make sure that we put purchase orders in. It's so cheap, let's buy them so that we have control of them, and not allow this again." That was a big awakening.
Another benefit of Cisco Umbrella was related to our wireless. If we had a vendor come to our company, I'd have to get permission for him to use our wireless. I'd have to put in a ticket with his machine name, the IP he would have, and ask for a two-hour window. But I could tell that vendor, "In the same way that you are helping us with the product we purchased from your company, we're going to help protect you at no charge. When you get on our wireless, we're going to have it set up so that everything you do is monitored, just like everybody else here in the company. Even though you don't work for our company, you'll be protected and that will help protect us." They would stare at me, and I'd say, "I know a lot of companies don't do that, but we're doing that because we want to make sure you have a good experience and that we have a good experience by staying safe."
What is most valuable?
I was able to make use of Cisco Umbrella because it acts like a proxy. The company also had content security, which I used on-prem with Blue Coat products. Any time someone went off the network, the AnyConnect client had the Umbrella agent built in, and it would realize when their computer connected that they were not on the corporate network. It would monitor and they would have pretty close to the same rules that they had to follow when they were in the office, regarding what kind of website browsing they could do.
The single pane of glass management was one of the really good features. From that single pane, not only could you look at what was happening security-wise, such as what was being blocked by domains and IPs, but you could check for your roaming users. With a deployment of AnyConnect, or just the Umbrella agent, on 5,000 machines, you could watch the main glass and see how many roaming users were out there that had it on their machines. And even if they were in the office, it was always active, talking to Cisco's cloud.
You could see numbers. I was able to watch, as we were deploying, how many people were getting the agent. I could see activity such as how many blocks we were getting, what types of blocks they were, and whether they were in categories. I would ask why those users were going to those categories that they shouldn't be going to. Maybe we needed to just refresh them with an email saying, "Hey, remember, we don't do this kind of thing."
Cisco's Umbrella client product is superb. It worked so well for us and was easy to deploy.
What needs improvement?
The design of the screens could be improved. Sometimes you're trying to look for information, for what you think is critical that should be on that first screen of the dashboard so that you can quickly take screenshots to have people help out, but you have to hop between screens to find little pieces of evidence.
They should work with their customers to find out, when they're troubleshooting, if they're going through multiple screens just to get little pieces of information. Maybe they could design an overall security screen for an event and pull that stuff in so that it's on one screen, rather than having to go search for it. Right now, you're always going back and looking on the left-hand side, going down the column, and trying to remember where something you need is. You have to click all over the place to go find what you're looking for.
For how long have I used the solution?
I used it at my previous company for about four years.
What do I think about the stability of the solution?
It was always up. We never had any problems. It was always there.
What do I think about the scalability of the solution?
Scaling was very simple. Since we were using a VPN, we had Cisco AnyConnect on all the user machines, with Umbrella built into it, and that deployment was just blasted out and it was seamless.
How are customer service and support?
The Cisco Umbrella support group was wonderful; very strong. I loved it. I never had one issue with them. They were willing to be there with us, and walk us through things every bit of the way.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We didn't have a whole lot going on in terms of security and when I got a new manager, he asked, "How do we protect the people when they're out in a store?" That's when we saw that's where the flaw was. We were protecting everything on-prem but the gap we found was that when users were traveling around, we were not seeing where they were going. We were holding them to a standard internally, but when they were outside they were doing whatever they wanted.
How was the initial setup?
What a simple product. It's a fast deployment. Then, you can start designing how you want to do your policies and what you're going to block. But once we told them what public addressing they were going to see, within a few hours we would see them go green. We said, "It's already seeing the data. Let's start applying policies, and we can start controlling all this."
What was our ROI?
We looked at metrics. As I mentioned, one of the benefits we received was finding the bad actors who had collected our domains that weren't paid for. That helped us to put the magnifying glass to use and say, "Hey, we have something going on."
I also worked with an outside company that Cisco purchased. I sent them our data from Umbrella and they actually mapped out our data and found bots on our network. There weren't many, but there were a few. The guy shared that with me on the screen and said, "If you buy the service to have us be part of your Cisco deployment, we'll take your data, continually analyze it, and give you reports."
There was one bot in particular that was just sitting there. The guy at the other company said, "That bot that you're seeing, it's asleep. Look again in a few hours," and it popped up. He said, "It just woke up at that point to try to do a command call." He said, "But we're blocking them, so you're not getting any threats." We didn't know that we had bots in there, and that was a big benefit.
I also had to run numbers for reports. One of them looked at our category-blocking on Umbrella, such as blocks of alcohol sites, social media, weapons, government. I would provide monthly reports to show how many blocks we had from our users trying to go to these types of categories, and it really woke up management: "Wow. That thing is blocking."
Our investment in this worked, and we were showing it by numbers. It wasn't only that we found bots and bad actors, but we were also controlling things by blocking phishing and categories. It was protecting us and no one was able to get past those blocks.
What's my experience with pricing, setup cost, and licensing?
The pricing was marvelous. We only had to pay for licenses and they worked a very nice deal with us. It was a much better way to go because it was within budget. It was an easy cost for us to handle.
Which other solutions did I evaluate?
We did not evaluate any other options. We invited Cisco to come in and do a demonstration, and it was so strong. I also come from a Cisco background of many years. In addition, the industry reviews rated them very well and we took that as our lead.
When they came in and showed us what they could do and how easy it was to monitor every one of our sites within a day, after we put in our external public addresses, it was a no-brainer. It was up and live by the next day, after just a few hours. It was easy to use and set up and we could use it like our internal proxies. We could manage the content and know what was going on and investigate things. We knew what sites people were going to. It was wonderful. Everything we needed was there. We didn't have to go any further, and we knew Cisco would have our back.
What other advice do I have?
All the users understood why we were putting the security control in place, to show that not only were they going to be protected at work on company-owned devices, but whenever they would go outside, we were also going to help. We had to mitigate the chances that they would get something on their machines and make sure that we stopped anything that shouldn't come in and affect our network or expose us to anything.
With Cisco Umbrella, employee morale was very high. We hardly had any complaints at all. One of the reasons is that, when doing regular security troubleshooting, we would go to Umbrella as our first line investigation. We might find a domain or IP that was being blocked by Cisco, something they consider a risk. We would check it out and if it didn't look to be bad we could bypass the block and allow that AD group or set of users to go to that site, because they had to do business as usual. With that ability, we had very few problems, if at all. Overall, it was smooth, with everybody happy, including management. They were happy that we had our first line of defense and that it worked out very well.
I introduce Umbrella to any company that I'm involved with. Cisco is already taking the correct steps right now, as a CASB for any cloud activity as well as DLP. Once they circled around to help companies with protection when they move to the cloud, that was the right direction. I'm not using Umbrella every day anymore, but I'm a proponent of it as a first defense for your company at a reasonable cost. And you don't have hardware to manage. You just rely on Cisco, get your support contract, and work with them to have them help fix things.
I'm a firm believer in Cisco Umbrella and I would definitely use it everywhere I go. I'm speaking to companies in the health industry and telling them, "Guys, you can't just have four people working on security and think you're going to do everything in the world to protect your hospital. You're going to end up on the news." I try to introduce them to this type of solution, to at least have something there to mitigate and help out.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network Administrator
Video Review
Saves us a lot of time and a lot of effort in isolating the actual issue
Pros and Cons
- "A single pane of glass saves time... This does have a lot of options available for us to see who's doing what, what trends, what errors. We can set up our alerting through it as well. It is definitely a great dashboard."
- "As far as the IT infrastructure team goes, we're all happy with the product; it definitely takes a lot of load off of our plate and it's been functioning very efficiently and effectively, doing everything we need it to do."
- "Something on our end that might make it better is alerting going to our ticketing system. It's not something that we have discussed, but that would be a proactive option for us to provide a learning experience for the staff."
What is our primary use case?
We use Umbrella to monitor user activity and make sure that our staff isn't clicking on malicious links. We also use it to protect us by being more proactive on links that are already known to cause harm or potential hacks. Overall, it's keeping everything in a safe box.
How has it helped my organization?
We had a lot of challenges with staff clicking on ad links, random Google search links. Most staff want to shop during the day or in their downtime and were clicking on random links and then causing potential network issues, bugs, and causing network downs. Umbrella has helped us limit that.
It has provided our organization with more stability. Even though staff would like to shop using certain links, it gives us the option to educate them: "Hey, some of these links, just don't click on those." We are pretty lenient. We understand people want to shop and do other things at work. We try to keep it work-related, but safe.
Everyone really just wants to be able to click and do what they do, just like at home. But for the IT side of it, it does benefit us by limiting all of the extra activity. It does give us some comfortability that we aren't going to wake up, or even come in in the afternoon, and the whole network is down because someone went to buy some shoes or they clicked on a malicious email and caused a chain reaction.
It's very important for our organization to support the hybrid workers because we're a health clinic. A lot of staff are going to be away, but with the COVID numbers still out there, we want to be able to provide the same support that we did before COVID. We want to give the same flexibility, the same availability to our patients, that we had in the past. Being remote or having hybrid, it does give us a different range of opportunities to implement different workflows. They can reach out with more telecommunication, more video conferencing, rather than having a patient drive out to a site to seek support. We can do remote assistance and, with Umbrella, it still gives us the opportunity to be secure through those communication links.
We don't really have metrics at this particular time for it, but just [anecdotally] from past troubleshooting, having to diagnose maybe five different areas, this saves us a lot of time and a lot of effort in isolating the actual issue. We can just open up Umbrella, go to the specific area that we feel is impacted, or just look at one of the key dashboards that are on the portal and identify the issue.
It's very easy to maintain network connectivity with Umbrella. Before, we were having a lot of issues, but since Umbrella has been implemented, we really haven't had to touch it. It's kind of self-sufficient.
The solution is a lot more proactive. It does have its own features where it constantly uploads known threats and blocks those. It takes a lot of the guesswork out of our environment, but it also gives us an opportunity, if there are some questionable links, to diagnose those without it impacting the environment.
What is most valuable?
The best feature is the visibility. We're able to see the specific user names of whoever clicked on a certain link. It also gives us a threat detection level. It allows us to maintain more [awareness of] who's doing what they shouldn't be doing. The most valuable asset of it is giving us the ability to categorize who should have access to what type of sites.
This solution does give us a single-pane-of-glass for this particular instance. We do have several products implemented that we manage, which this hasn't integrated with yet, but we have just been made aware of the SecureX implementation and we are looking into implementing that and bringing that into another single-pane-of-glass, but with more options available.
A single pane of glass saves time. It saves effort and the headache of having to open up multiple links and go to different dashboards for troubleshooting different areas. This does have a lot of options available for us to see who's doing what, what trends, what errors. We can set up our alerting through it as well. It is definitely a great dashboard.
The dashboard, the single pane, is very helpful, it's very visual. Everything is straightforward there; it's definitely important for management. Even when we bring it to upper management and explain why this product is beneficial for us, this gives us a good breakdown and makes a lot of details available for us.
What needs improvement?
So far, I haven't seen any areas that need improvement. As far as what we need it to do, it's doing just that. It's comfortable for us. It's working beyond our expectations. Something on our end that might make it better is alerting going to our ticketing system. It's not something that we have discussed, but that would be a proactive option for us to provide a learning experience for the staff.
For how long have I used the solution?
We've had Umbrella implemented for about two years.
What do I think about the stability of the solution?
The stability is very great. Once it's deployed and you do your due diligence to make sure that everything is communicating and in sync, we've hardly had to touch it.
What do I think about the scalability of the solution?
For our environment, it doesn't seem to have any issues with the amount of users and staff. We have been constantly growing since we deployed it without any impact. No negative impact is forecasted.
How are customer service and support?
The support has been really good. I have only had to utilize support about three times. It's been more of a training area: "How do I get to this area?" and "What does this actually do? How can this benefit me?" From there, it still has been stable and smooth and doing everything that we expected it to do.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We had a different overall firewall solution, which was a Sophos firewall. But since we migrated away from that, we implemented the Firepower firewall and, in addition to that, added in Umbrella.
The reliability wasn't really there, with Sophos always having issues, even from the endpoint perspective. We had issues across the board and it was management's decision to look into a new solution.
How was the initial setup?
We just did one deployment through a virtual machine and that manages all of our routers and all of our users. We haven't had to do multi-site configurations or deployments. It goes towards the organization, uploads all of our users, and all of our statistics, and maintains things from there.
What was our ROI?
I'm not sure of the actual cost that went into it, but it's definitely a productive product for us.
What other advice do I have?
The solution doesn't require almost any maintenance, unless you're doing triple checks, upgrades, or just being proactive in different areas. But for the most part, once it's deployed, you just give it about a week or two to check your levels and make sure everything is the way that you intend the product to work.
As far as the IT infrastructure team goes, we're all happy with the product. It definitely takes a lot of load off of our plate. We don't have to deal with certain sites being blocked. We have been able to set expectations, where these particular users have access to these types of sites, and certain sites are just blocked. That's just the company standard. From the staff perspective, they want to be able to browse freely, but we were able to set those expectations and guidelines and that we're working in the best interests of the site.
I'll rate it a 10 out of 10. It's been functioning very efficiently and effectively, and it's doing everything we need it to do. It takes a lot of load off of our team.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Consultant at KRS Systems
Protects endpoints wherever they are, always pushing people to the right locations to avoid malicious intent
Pros and Cons
- "The most valuable thing is how easy it is to deploy. We did it with 9,000 users at my last job, and it took a week to get to all the endpoints. Doing that without having to physically touch all those endpoints was very simple."
- "Umbrella is probably one of the best tools out there in all the security landscape."
- "I'd like to see improvement in its overall integration with all the other platforms. There's some integration between Umbrella and Meraki, but an overall Cisco problem is that there are so many different tools, and finding easy, seamless ways of connecting everything together is always a challenge."
- "I'd like to see improvement in its overall integration with all the other platforms."
What is our primary use case?
I deployed it as an end-user management solution in a large IT practice, and for our end-users to have secure internet access. I've also advised on it as a consultant for companies wanting to use it to deploy SASE-type solutions.
How has it helped my organization?
It's really hard to have a firewall everywhere. It's also really hard to have somebody follow a user on the internet and make sure that they're doing things securely. Having a tool that's on an endpoint that you know is always connected and always pushing people to the right locations, avoiding redirects and malicious intent, has been the biggest benefit for us.
We were exposed to ransomware attacks at a very early stage in our company. Cisco Umbrella is one of the ways that we have found to help prevent ransomware attacks. It also helps prevent users from going to places that they shouldn't be going to, beyond just firewalls and email security. It is an extra level of protection that really helps make us feel comfortable at night.
The fact that Cisco Umbrella helps support hybrid work is really the key, having an endpoint protected wherever it is, whether it's on or off your network. That's what everybody on the planet is looking for right now.
It has also, 100 percent, helped us remediate threats more quickly.
What is most valuable?
The most valuable thing is how easy it is to deploy. We did it with 9,000 users at my last job, and it took a week to get to all the endpoints. Doing that without having to physically touch all those endpoints was very simple.
The single pane of glass management makes it very easy to manage your rollout. We get a lot of "single panes of glass" and, eventually, you need a pane of panes of glass. But it's always good to have a clear and graphical view, and Umbrella's is nice and easy to read. Definitely, of the panes of glass that we do have, it's one of the easiest to use.
The single pane of glass is good to group users together and separate people out. Some people need different types of security. Some people are more vulnerable. Some have more highly valuable assets, like C-suite people. It's really good to be able to have end-users defined inside of that. You don't have to jump around. You don't have to figure out who's who. It's all done through one pane of glass.
What most people don't realize is that it's running in the background, which is a really nice aspect when it comes to security. Often, when you deploy a security tool, it takes up CPU performance. Everything slows to a grind. But Umbrella is so simple and easy and it doesn't affect the end-user experience. It's the best of all worlds. It's nice when people realize that they're being protected when they go to the wrong site. I think people are happy that they're protected, but it's nice that they rarely notice it.
It's generally easy to maintain network connectivity, but with Umbrella, the nice part is that whichever connectivity you're on, you're always secure. With Umbrella, as long as you're online, you're going to be protected.
What needs improvement?
I'd like to see improvement in its overall integration with all the other platforms. There's some integration between Umbrella and Meraki, but an overall Cisco problem is that there are so many different tools, and finding easy, seamless ways of connecting everything together is always a challenge. Always, with Cisco tools, there is the issue of finding ways to have fewer windows to look at and how to make those tools work together better.
For how long have I used the solution?
I have been using Cisco Umbrella for over six years.
What do I think about the stability of the solution?
It's a cloud service. Beyond the actual tool working, the most important thing is its availability.
As long as the internet connectivity is up, I've never had a problem with Umbrella not being there. It's a tool that we have never been concerned will go down while our internet connectivity is up.
Security always has to be there. As long as your security tools are available, that's when you can be the most secure. With Umbrella, especially, we have never had an issue where it was out and we needed protection. It's probably one of the most resilient tools available on the planet. For sure, it's amazing.
What do I think about the scalability of the solution?
I'm sure there are bigger customers than us, but we had 9,000 endpoints secured in a month's time without a blip in the system or in performance. For us, it has been impressive.
How are customer service and support?
Meraki and Umbrella support are great. We have never had an issue with Umbrella, so we haven't had to evaluate support there. But whenever we have had issues with the integration between Meraki and Umbrella, Meraki support has been amazing.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did not have a previous solution.
How was the initial setup?
It was pretty straightforward. We loaded the client into Meraki Systems Manager, and then we were able to push it to all devices inside our network that had Systems Manager. It was pretty much three clicks.
We had full Meraki stacks as most of our network deployment. We were 100 percent cloud on our solutions. Umbrella sits in between our on-premises networks or between our users at home and between our cloud applications that we use at our clinic and office locations.
What about the implementation team?
We did it in-house.
What was our ROI?
The return is that you don't get breached. It's a hard thing to quantify because if you don't get breached, you don't know what the value of that breach would have been. By not being breached and by being able to mitigate ransomware attacks, there is definitely return on investment.
What's my experience with pricing, setup cost, and licensing?
The pricing is great and very competitive with the rest of the market.
With everything to do with security, you should never worry about price because it's all about risks. The cost of $20 to $30 a license for Umbrella might protect you from $4 to $5 million worth of ransomware. It depends on your risk profile.
Which other solutions did I evaluate?
We evaluated Zscaler as well. The difference between Zscaler and Umbrella was that Umbrella was a lot simpler to deploy and a lot easier to manage. Zscaler requires way more customization and it has some slightly different use cases than Umbrella. For us, Umbrella was more what we were looking for and generally easier for us to manage.
What other advice do I have?
For C-suites that want more security resilience in their organizations, I would tell them to adopt cloud technologies as much as they can. Try to find things that will help you scale because, when you keep things on-premises, you have to be the cloud provider yourself. Tools that other people have already stretched across, and on whose service you can rely, are generally going to be better than what you can do yourself. Either that or it's going to be very expensive for you to provide that service in-house.
Umbrella is probably one of the best tools out there in all the security landscape. It's very valuable to all people who are looking to deploy secure internet access. Everything has been perfect as far as we have used it.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Network Engineer at a educational organization with 1,001-5,000 employees
We feel more confident knowing that we can block phishing attempts or any type of malware that is DNS-related
Pros and Cons
- "It has improved our organization from a security posture perspective, and we feel more confident now knowing that we can block phishing attempts or any type of malware that is DNS-related, which is a very nice feature that provides peace of mind."
- "We would like them to add more features to Cisco Umbrella."
What is our primary use case?
We use Cisco Umbrella for DNS security. We also have the roaming clients deployed on user laptops.
We use it for roaming clients. We also push all our DNS traffic to Umbrella. We do not allow any other DNS traffic. That is kind of how we have fully implemented Umbrella.
We were looking to bridge the gap for DNS security, especially for mobile clients. We wanted to be able to put that roaming client on their PCs and kind of bring that together.
How has it helped my organization?
It has improved our organization from a security posture perspective. We feel more confident now knowing that we can block phishing attempts or any type of malware that is DNS-related. This is a very nice feature that provides peace of mind.
Umbrella has absolutely helped us remediate threats more quickly. In fact, it has blocked a lot of threats that may have been able to go through in some instances. Knowing that they are blocking it and being able to find the PC that potentially has the threat on it, that has been very beneficial.
Umbrella has been very good for employee morale. It makes our job a little bit easier.
Cybersecurity resilience is very important for our organization right now. Umbrella does a good job of blocking ransomware, malware, bad threat actors, and phishing attempts.
What is most valuable?
Being able to control policy sets has been a very nice feature. Being able to have appliances that are separate, where we can send DNS traffic, has been very beneficial as well.
It is a good product for helping workers feel safe, secure, supported, and included. Having the roaming client is probably one of the key factors in being able to do that.
Cisco Umbrella provides single-pane-of-glass management, which is pretty important for my organization. We have a lot of products, including security products, that we manage. Being able to see a lot of those data sets in a single pane of glass is very beneficial for my team. We enjoy having it. It is very easy to use.
It is not very difficult to maintain network connectivity.
What needs improvement?
We would like them to add more features to Cisco Umbrella.
For how long have I used the solution?
We have been using Umbrella for about four years.
What do I think about the stability of the solution?
Stability has been great. Obviously, there have been some hiccups here and there on the connectivity side. That is out of our control, but it is understandable, as things are in the cloud. I have had more issues with Amazon than I have had issues with Umbrella, where I have had a very good experience.
What do I think about the scalability of the solution?
It is very scalable. If I had more sites, all I would have to do is deploy more VMs and point traffic that way, which is very nice.
We are using roaming clients. We are also using the DNS appliances that we have deployed. I have over 15,000 users and 10 locations. We have deployed each appliance at every location, and then point traffic to that. There are 20 different servers that we are using for Umbrella.
How are customer service and support?
The technical support has been very good. I have not had to open many tickets. I have only opened two in the five years that we have had it. Those two times, the support was very nice and supportive. I would rate them as 10 out of 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We have actually been using Umbrella since it came out. Previously, we just ran our own DNS. From a security product perspective, Umbrella has been the only DNS solution that we've used.
How was the initial setup?
The initial setup is very straightforward. There is a lot of documentation available.
What about the implementation team?
It was deployed in-house.
What was our ROI?
We have seen ROI. We can show our leadership that we are blocking and preventing things from coming into our network. Not only that, but from a threat perspective, if any of those things were able to infiltrate, then possibly the remediation damages would be way more than the cost that I am paying for Umbrella today.
What's my experience with pricing, setup cost, and licensing?
As an educational partner, we get better licensing structures. We are very happy with that. It has been very nice that Cisco has partnered with the educational sector to bring that.
What other advice do I have?
Look for all the gaps that you have in your network, then try to find a product that is more rounded to essentially fill those gaps.
I would rate Umbrella as 10 out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Network Engineer at a computer software company with 201-500 employees
Blocks a lot of threats and that means we don't have to remediate them
Pros and Cons
- "The most valuable features for us include tenant lock, content filtering, and DLP solutions, looking for PII and information being exfiltrated."
- "Overall, Cisco Umbrella is pretty easy to use, pretty easy to deploy, and it does what we want it to do."
- "There are a couple of different pieces that have different portals. I know they're working on getting them all into one portal, but that's probably the biggest thing that needs improvement right now. It's not a single pane of glass yet."
- "I don't think our workers like it all that much. It has actually made employee morale worse because we block a lot of stuff."
What is our primary use case?
We were looking to solve multiple challenges, from DLP all the way through to regular content filtering offsite for our hybrid and remote employees.
How has it helped my organization?
Using Cisco Umbrella has brought us into compliance with our customers on a number of points.
Also, it's very important that the solution helps support hybrid work. That was one of the main reasons we got it. About 45 to 50 percent of our employees are either fully remote or hybrid. We needed a solution that would follow them home.
In addition, it's very helpful for securing infrastructure from end to end and detecting threats. It's blocking a lot of stuff, so we don't even have to remediate. It's blocking things before they get to us.
Resilience in cyber security is very helpful and this product has increased our security posture quite a bit.
What is most valuable?
The most valuable features for us include
- Tenant lock
- Content filtering
- DLP solutions, looking for PII and information being exfiltrated.
Also, the policies are applied wherever you go, and that's good.
What needs improvement?
There are a couple of different pieces that have different portals. I know they're working on getting them all into one portal, but that's probably the biggest thing that needs improvement right now. It's not a single pane of glass yet.
For how long have I used the solution?
I've been using Cisco Umbrella for about a year.
What do I think about the stability of the solution?
We haven't had any issues with the stability of the product.
What do I think about the scalability of the solution?
The scalability is very good and that's another one of the reasons that we chose this product. You can slowly ramp up the policies. You don't have to build it all at once. We started small and have been deploying more and more of the features of the full SIG Essentials package that we have. We can add more users when need be. It scales on a policy and a user and a deployment basis.
We have about 400 end-users and five sites. We use the AnyConnect module on the local workstations.
How are customer service and support?
The solution's technical support has been very good. I haven't had to call them very much, but the technical support has been good when I have needed it.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
Previously, our users were only in-house and we had internal firewalls that were doing a lot of this work. But now that they're hybrid, we had to come up with a new solution.
Which other solutions did I evaluate?
We evaluated Prisma because we have Palo Alto firewalls, but it was more expensive and more difficult to set up.
What other advice do I have?
I don't think our workers like it all that much. It has actually made employee morale worse because we block a lot of stuff. But that's not really the product's fault. It's our policy. It makes things a little bit more cumbersome for them, but it definitely makes us feel safer.
I would tell leaders who want to build more resilience within their workplaces to do it. It's important because one hack and your business is done. Your reputation is everything in this day and age. Being resilient and being able to recover from that type of stuff before you're actually exfiltrated is a big deal.
Overall, Cisco Umbrella is pretty easy to use, pretty easy to deploy, and it does what we want it to do.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
With the reduction in risk, we spend less time on end-user support
Pros and Cons
- "The Global Block List is one of the most valuable features because it's really easy to block domain names as well as URLs. Sometimes you don't want to block the whole site, you just want to block one URL. The Global Block and Allow Lists are the best features for us."
- "It has improved our company a lot because we now see where the users are going and prevent them from going to malicious websites."
- "There are some situations where we would like to block things for specific user groups. I know that Umbrella does that, but it's not that easy.... when you want a specific task for specific rules and policies for user groups, you have to go three levels down in the menu, and it's hard to find where you do that task."
What is our primary use case?
One of our purposes for acquiring Umbrella was to block phishing links that we get in emails and to manage risky websites. We're using it for our internal network and the roaming client for external users.
Blocking malicious websites and preventing users from going into them, as well as the phishing attacks that usually come with malicious links, were the challenges. With Umbrella we can block them.
We use it in our Active Directory domain and for about 175 users. We use it on desktop computers and on laptops for external users. It's all on-premises, protecting servers and workstations.
How has it helped my organization?
It has improved our company a lot because we now see where the users are going and prevent them from going to malicious websites. It has reduced, by a lot, the chances of hackers getting into our organization.
With Umbrella, it's our IT staff who we feel secure. Sometimes the end-users, our clients, don't fully understand the purpose of the tools when we install them, such as the roaming client. And sometimes they get false positives and they don't fully understand why. But for us, as IT admins, we feel a lot more comfortable with the tool in place, because we know that it's unlikely our users will go to a malicious website. Umbrella is protecting us.
Umbrella has also helped us remediate threats more quickly. It's really good for securing our infrastructure from end to end. Umbrella's footprint is really small. If you want to secure infrastructure, such as servers, you don't have to install an agent. You just have to use DNS forwarders and point them to the umbrella servers. That's easier. It helps us protect our infrastructure for sure.
What is most valuable?
The Global Block List is one of the most valuable features because it's really easy to block domain names as well as URLs. Sometimes you don't want to block the whole site, you just want to block one URL. The Global Block and Allow Lists are the best features for us.
Cisco Umbrella also provides a single pane of glass for management. It's really helpful and it's important for us because we have multiple locations. Without a single pane of glass, if you want to block websites you have to go to every location, in each firewall, one by one. But when you have a single management portal, it's a lot easier.
The user experience is good because, as IT and admins, it's easy to use. But that's not only for admins, it's also true for the clients because they know the reason a website is blocked. The user experience is pretty smooth because they can report a false positive or a malicious website that has not been blocked in Umbrella. We are happy with the user experience.
And when it comes to applying and maintaining network connectivity consistently across all workplaces, Umbrella is excellent. We can track, among the different locations that we have, where the users are trying to get to. That means the risk of disruption is reduced by using Umbrella. And in that way, Umbrella contributes to maintaining network connectivity.
The user interface is pretty nice. Once you know how to do tasks, it's easy.
What needs improvement?
There are some situations where we would like to block things for specific user groups. I know that Umbrella does that, but it's not that easy. When you go to the Global Allow and Block Lists, that's the easy part. But when you want a specific task for specific rules and policies for user groups, you have to go three levels down in the menu, and it's hard to find where you do that task.
Also, the policies are not that easy to manage.
For how long have I used the solution?
I have been using Cisco Umbrella for around a year and a half.
What do I think about the stability of the solution?
The stability is really good. They have about 99.99 percent uptime. I can't think of a significant disruption in the service.
What do I think about the scalability of the solution?
We are a small organization, but from what I have seen, it is very scalable.
How are customer service and support?
We have never requested support.
How was the initial setup?
The initial deployment was straightforward.
The solution is on-premises but the management is cloud-based.
What about the implementation team?
We did it all by ourselves.
What was our ROI?
We have seen return on investment by reducing the risk we had in the past. That has saved us from having to invest a lot of time in support, which is something we had to do when a user didn't know what they were doing and got infected. We now spend less time on end-user support.
What's my experience with pricing, setup cost, and licensing?
The pricing is pretty fair. It's good.
Which other solutions did I evaluate?
In my former company, we used Area 1 for DNS protection, not Umbrella. I knew OpenDNS before it became Umbrella. In fact, I used OpenDNS for my personal accounts. In my current company we evaluated Area 1, but in the end, we loved Cisco's support and that is one of the reasons we went with Umbrella. But, obviously, the features in Umbrella are pretty good.
What other advice do I have?
Once our end-users understood why we use Umbrella, that it was for improving our organization's security, it improved their morale. Nowadays, they are aware of cyber threats and they know that Umbrella is one of the tools that we use to prevent a breach. They feel more secure now.
Resilience helps a lot in cyber security. One of the things that makes Umbrella great is that you don't have to detect threats by yourself. Wherever in the world a new threat is detected, it's in the Global Block List of Umbrella and we don't have to manage those threats one by one.
That kind of resilience is more and more important for our organization every day. Fortunately, our C-level now understands the risks and what the organization could lose. They understand the impact. With the support of management, cyber security is really important for our organization.
I would tell the leaders of other organizations who want to build more resilience that cyber security is more important now because we are serving our internal and external customers. The problem with a cyber security risk, a threat or a disruption in IT services, is that it will probably cause us to stop producing what we produce. Our customers will have a bad experience, and that means it is not only a financial issue but one of reputation. I would tell such leaders to always keep cyber security in mind because it's not just about your IT guys, it's for the whole organization.
It's an excellent product. It has worked really well. The only reason I don't give it a 10 out of 10 is, as I mentioned, that there are some tasks that could be done more easily.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Manager at Infinite Energy Center
Allows us to see threats in real time and be more proactive
Pros and Cons
- "If it didn't have a single pane of glass, we would not be using it. The single pane of glass gives you a one-stop shop. It's like going to Home Depot. You find all your stuff there. You can see all your threats and your endpoints. It's a very important feature and makes things very simple."
- "Cisco Umbrella allows us to see threats in real time."
What is our primary use case?
In general, we use it for the security of our network.
How has it helped my organization?
We wanted to get an idea of what's happening outside of our network and what's coming to our network. We had no way to know before and we were just sitting there waiting for something to happen. At least now we can be proactive.
It has helped us to be more secure. Cisco Umbrella allows us to see threats in real time. We can also see if there are any bad actors inside of our network who are trying to do malicious things. It gives us a quick glance at the situation, at where we are and how vulnerable we are.
Another definite benefit is that it has helped us to remediate threats more quickly.
What is most valuable?
It's very important that the solution helps support hybrid work. In the past, we might have had one or two people who were working from home because of illness or pregnancy. Now, with 60 percent of our people working from home, Cisco Umbrella has really helped us out with threats that they might not even know exist on their side. We can monitor them and be proactive about them.
Also, if it didn't have a single pane of glass, we would not be using it. The single pane of glass gives you a one-stop shop. It's like going to Home Depot. You find all your stuff there. You can see all your threats and your endpoints. It's a very important feature and makes things very simple.
Another point is that it's very easy to maintain network connectivity.
For how long have I used the solution?
I have been using Cisco Umbrella for about eight years.
What do I think about the stability of the solution?
The stability of Cisco Umbrella is very good.
What do I think about the scalability of the solution?
I haven't had to scale it, but I would assume the scalability would be good.
How are customer service and support?
We haven't contacted them from the time we were up and running.
Which solution did I use previously and why did I switch?
We did not have a previous solution.
How was the initial setup?
The deployment was straightforward.
What about the implementation team?
I used an integrator, Harness LLC, and the experience with them was all good.
What was our ROI?
Our ROI is due to the level of threats that we don't have to deal with, threats that are being blocked by Cisco Umbrella.
What's my experience with pricing, setup cost, and licensing?
There is room for improvement when it comes to the cost.
Which other solutions did I evaluate?
We looked at Trend Micro, but that was several years ago.
What other advice do I have?
Look for programs that have a track record and that are proven. No matter what any individual might say, that person can't do it by themselves. They have to have support, and Cisco Umbrella is a good support.
Resilience in cyber security is like raising kids. You really can't stop. You have to be resilient continually. Every day is a different challenge. Just because you're good on Tuesday doesn't mean you're going to be good on Wednesday.
Cyber security resilience has been key for us, with people going home to work or to other places to do their jobs. That resilience keeps them working and keeps our network safe.
I love it. It's almost like trying to look at WiFi. You can't see the WiFi signal with your naked eye. It's the same with threats. You can't see them by just walking around the building. With a tool like Cisco Umbrella, you can see what you have and how to fix it.
For our employees, it means that their systems are working. They have no idea what we're doing behind the scenes to keep their systems working, unfortunately. I wish I could say, "Hey, guys, today Cisco Umbrella stopped 84 threats."
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Cisco Umbrella Report and get advice and tips from experienced pros
sharing their opinions.
Updated: July 2026
Product Categories
Domain Name System (DNS) Security Secure Web Gateways (SWG) Internet Security Cloud Access Security Brokers (CASB) Cisco Security PortfolioPopular Comparisons
Fortinet FortiGate
Cloudflare
Cloudflare One
Cisco Secure Firewall
Prisma Access by Palo Alto Networks
Zscaler Zero Trust Exchange Platform
Zscaler Internet Access
Cisco Identity Services Engine (ISE)
Cato SASE Cloud Platform
Netskope
Check Point Harmony SASE (formerly Perimeter 81)
Mimecast Advanced Email Security
Cisco Secure Email
Buyer's Guide
Download our free Cisco Umbrella Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which is the better security solution - Cisco Umbrella or Zscaler?
- Which product do you prefer: Cisco Umbrella or Palo Alto Networks DNS Security?
- Which is the better security solution - Cisco Umbrella or Microsoft Cloud App Security?
- What are the pros and cons of Cisco Umbrella vs. Zscaler SASE for a large global enterprise?
- What are the differences and similarities of Symantec Fireglass and Cisco Umbrella?
- Which solution is better: Cisco Umbrella or Palo Alto Networks DNS Security?
- When evaluating DNS Security, what aspect do you think is the most important to look for?
- Why is Domain Name System (DNS) Security important for companies?
- What DNS security tool do you recommend?
- Why is domain name system security important?
















