Skip to main content

Help us improve the Digital Marketplace - send your feedback

SOMERFORD ASSOCIATES LIMITED

Cisco XDR - Extended Detection and Response

Cisco XDR is a cloud-native extended detection and response solution that integrates data from multiple security tools to detect, prioritise, and remediate threats faster. It uses AI-driven analytics and Cisco Talos intelligence to reduce false positives, automate responses, and enhance security team productivity with guided workflows and flexible licensing.

Features

  • Improve alert accuracy by correlating weak signals into actionable incidents.
  • Reduce alert volume by automating correlation and threat confirmation processes.
  • Centralize configuration with weighted guidance to prioritize security improvements efficiently.
  • Share threat intelligence instantly across sensors and third-party integrations.
  • Enhance threat detection using AI analytics to reduce false positives.
  • Accelerate incident response with automated, guided playbooks for remediation.
  • Boost analyst productivity by filtering noise and automating repetitive tasks.
  • Unify visibility across network, cloud, endpoint, email, identity, and applications.
  • Simplify investigations with consolidated views and deep context of incidents.
  • Prevent ransomware impact by triggering backup and recovery early.

Benefits

  • Improve alert accuracy by correlating weak signals into actionable incidents.
  • Reduce alert volume by automating correlation and confirmation of threats.
  • Centralize configuration with weighted guidance to prioritize security improvements efficiently.
  • Share threat intelligence instantly across sensors and third-party integrations.
  • Enhance threat detection using AI-powered analytics to reduce false positives.
  • Accelerate incident response with automated, guided playbooks for remediation.
  • Boost analyst productivity by filtering noise and automating repetitive tasks.
  • Unify visibility across network, cloud, endpoint, email, identity, and applications.
  • Simplify investigations with consolidated views and deep context of incidents.
  • Prevent ransomware impact by triggering backup and recovery early.

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@somerfordassociates.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 0 8 7 7 0 7 1 4 0 3 3 3 4 7

Contact

SOMERFORD ASSOCIATES LIMITED Penny Harrison
Telephone: 07897075103
Email: info@somerfordassociates.com

About your service

Service categories

Application Development and Deployment

Analytics and business intelligence

  • Advanced and predictive analytics
Multi cloud support
Yes

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
A minimum of 100 endpoints is required.
System requirements
  • Will vary depending on the deployment type and licensed features.
  • Please contact us to discuss.

User support

Email or online ticketing support
Yes
Support response times
Mon-Fri 9am-5:30pm excl bank holidays customers receive an initial response within one business hour
User can manage status and priority of support tickets
No
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
We provide support from priority 1 to priority 4 cases on any existing configuration or part of the platform that is in total or partial failure as well as not working as expected. We also provide configuration guidance and recommendations for use cases. Each customer receives their own Account Manager who works closely with Support and ensures that cases can be followed up. Somerfords Support desk is available as a value added service in addition to the maintenance and support purchased alongside the license.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Onboarding services which includes configuration, in-person training and/or online training. Access to online documentation and further training as required for new Administrators of the service.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Cisco support services will work with the client to delete or extract their data as required.
End-of-contract process
If the contract is not renewed by the end-of-service contract renewal date, the customer will lose access to subscription entitlements, service, and support.

A request can be made to TAC to delete any data.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
No
Service interface
No
User support accessibility
WCAG 2.2 AA
API
Yes
What users can and can't do using the API
Cisco XDR’s API enables users to manage incidents, intelligence, and device data, and to configure integrations with Cisco and third-party products. Users can set up the service by providing configuration details like API keys, which are verified before enabling integrations. Upon order acceptance, users receive a subscription claim code to provision the service via Security Cloud Control.

Through the API, users can automate workflows and response playbooks using a low-to-no-code editor, with Python support for advanced customization. They can also manage user roles and permissions to control access to API functions, including read, write, and delete actions.

Limitations include the need to test automated workflows in non-production environments, licensing requirements for some integrations (e.g., Meraki MX Advantage), and role-based permission restrictions. Not all third-party products are supported out-of-the-box, but Cisco’s advanced services can assist with custom integrations. The service does not guarantee protection against all malware or malicious attacks.

Overall, Cisco XDR’s API provides comprehensive setup, configuration, and management capabilities with role-based access control and operational considerations to ensure secure and effective use.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Users can customize Cisco XDR through several key features:

Automation and Workflows: Users can create automation workflows using a low-to-no-code editor or Python for advanced customization, enabling faster incident response by automating repetitive tasks.

Integrations: Cisco XDR supports over 100 built-in integrations with Cisco and third-party security products. Users can configure these or develop custom integrations via APIs and Cisco’s GitHub resources to enrich data and execute response actions.

APIs: Multiple APIs allow users to manage incidents, investigations, casebooks, and automation workflows. Users can set up targets, account keys, and trigger workflows programmatically, as well as extract and enrich observables using the Cisco Threat Intelligence Model (CTIM).

Dashboard Customization: Dashboards can be tailored with tiles showing data from integrations, including verdicts, sightings, and telemetry.

Data Management: Users can purchase additional data ingestion capacity and extend data retention periods beyond default limits.

Role-Based Access Control: Access to API functions and service features can be controlled through roles and permissions.

Managed Services: Cisco offers managed detection and response services with expert guidance, threat briefings, and incident response playbooks for further customization and support.

Scaling

Independence of resources
As resources are consumed by other clients the IAAS provider would automatically increase the capacity required for all clients using the service to not be affected by any latency.

Analytics

Service usage metrics
Yes
Metrics types
As per Public cloud provider.
Reporting types
Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Cisco

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure

Data importing and exporting

Data export approach
Using Cisco API.
Data export formats
Other
Other data export formats
Json
Data import formats
Other
Other data import formats
Json

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Cisco’s IAAS provider has a 99.6% uptime and a 24x7x365 service.
Approach to resilience
Cisco’s IAAS provider maintains data center resilience through its global infrastructure, which uses multiple, isolated Availability Zones (AZs) within each Region. Within each data center, they have redundant power systems, including uninterruptible power supplies (UPS) and generators, along with constant monitoring and security measures.
Outage reporting
Public Dashboard: https://status.tdr.cisco.com/

Email Alerts

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Cisco XDR restricts access in management interfaces and support channels by leveraging unified identity management through Cisco Security Provisioning and Administration, which provides single sign-on (SSO) and acts as the native or delegated Identity Provider (IdP) across selected Cisco products. This ensures controlled, authenticated access to the management interfaces. Additionally, Cisco XDR integrates API-based communication with secure authorization for product integrations, enabling secure and managed access to data and response actions. Enhanced support services and secure backend access for cloud components further restrict and control support channel access.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
Between 6 months and 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Cisco follows a comprehensive information security program that integrates people, processes, policies, and technology to protect its infrastructure and data. The company fosters a security-conscious culture through training programs, anti-phishing campaigns, and a code of business conduct emphasising data protection and ethical behaviour. Enforces a broad range of security policies covering areas such as acceptable use, access management, application security, cloud security, incident management, cryptographic controls, data protection, and network access. These policies align with industry standards like ISO 27001 and are regularly reviewed and enforced.

Security processes include vulnerability analysis, penetration testing, risk assessments, and incident management coordinated with its Computer Security Incident Response Team (CSIRT). Access and asset management controls ensure proper authentication, authorization, and auditing. Data protection policies specify classification, labeling, and cryptographic key management. Monitoring and logging practices support compliance and incident investigation. Physical security controls at data centers include card readers, biometric devices, video surveillance, and 24x7 monitoring by Cisco’s Security/Facility Operations Centers.

Cisco also offers security assessments, architecture reviews, and design services to help customers maintain robust defences. For cloud services like Cisco Intersight, security policies cover access management, auditing, cryptographic controls, data protection, using an out-of-band architecture to separate management from production data,
Software Security Code of Practice
No

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Cisco's change management process is designed to enable beneficial changes while minimizing service downtime and ensuring that all change requests are recorded, reviewed, authorized, planned, tested, implemented, and documented in a controlled and consistent manner.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
All servers and applications are kept up to date with the latest tested patches in the production environment, leveraging Cisco Talos threat intelligence and vulnerability scanners that identify vulnerabilities, malware, and potential threats.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Cisco identifies potential compromises through continuous monitoring of indicators of compromise (IOCs) using advanced tools like XDR, SIEM, endpoint security, and identity access management. These analyze behavior, threat intelligence, and logs to detect suspicious activity early. Upon detection, automated incident response playbooks guide containment, mitigation, and remediation.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Cisco’s incident response process is managed by the Product Security Incident Response Team (PSIRT), which follows predefined procedures for common security events. Users report incidents through designated channels such as psirt@cisco.com. PSIRT investigates, prioritizes, and coordinates responses globally, adhering to ISO/IEC 29147:2018 guidelines. Incident reports include vulnerability details, impact assessments, and remediation steps, and are publicly disclosed with CVE identifiers when applicable. Cisco also provides incident reports via tools like Firepower Management Center, which generate detailed summaries and timelines. The process emphasizes rapid response, transparency, and collaboration with customers and security researchers to mitigate risks effectively.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Full features and functionality for 60 days (with allowance for 1 30-day extension).

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
1%
Between £250,000 and £500,000
1%
Between £500,001 and £1,000,000
1%
Between £1,000,001 and £2,500,000
1%
Between £2,500,001 and £5,000,000
1%
Over £5,000,001
1%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
No
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
SGS
ISO 9001 accreditation date
Tuesday 15 March 2022
What the ISO 9001 doesn’t cover
As our staff are a fully remote workforce the company physical office location is not covered. Clause 7.1.5 (calibration) is not in the scope. ISO 9001 does not cover financial processes.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
F416f438-c625-443c-8b8d-a1b8f3b804e3
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
8d0e7cb8-30a3-4374-b713-d15f8d7f0c7d
Other security certifications
Yes
Any other security certifications
IASME Cyber Assurance Level 1 Certificate

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Plans for positive actions with community groups.
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Offering a range of quality opportunities with routes of progression if appropriate, e.g. T Level industry placements, students supported into higher level apprenticeships.
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Other measures to offer development opportunities for the target cohort(s) in the contract workforce
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Creation of outreach activities to create a pipeline of employees for the future contract delivery
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@somerfordassociates.com. Tell them what format you need. It will help if you say what assistive technology you use.