Vulnerability management is a race against time. Cisco and Isovalent are closing that time window. Protect your fleet in moments, not months. Now, teams are shielding their network infrastructure from emerging vulnerabilities without requiring downtime or patches. Isovalent’s runtime sensor brings rapid scale deployment of new compensating control policies, shielding devices and preventing new CVE’s from being exploitable. If there is a specific use case you want to learn more about, feel free to navigate directly below or reach out for a personal demo. Addressing the vulnerable time window Attackers start working on exploits in mere hours after the CVEs are published. The average time-to-exploit (TTE) for vulnerabilities has significantly decreased, with a Mandiant report indicating an average TTE of just 5 days, alarmingly faster than the 32 day average observed before. On the defender's side, Verizon's 2024 Data Breach Incident Report “found that it takes around 55 days to remediate 50% of critical vulnerabilities once patches are available”. There is a clear mismatch between when a CVE is starting to be exploited, and when they are patched. It’s also clear that patching is not a simple one-click-fix-all while keeping services uninterrupted and compatible. Patching takes time to coordinate for system downtime, validate that upgrades won’t break other software dependencies, get approvals to apply the patch on target systems, scan systems after upgrade to confirm remediation, and so much more that disrupts resource-constrained teams from focusing on core functions. In all, it often feels like an outsized amount of work and coordination throughout the lengthy time it takes to complete. Now, instead of focusing on far off patching cycles, teams are mitigating CVEs on their network devices before upgrading the operating system, using Isovalent with Cisco Live Protect. When you have a vulnerability there will be a compensating control, a shield, that will be applied to the vulnerability within minutes. And then over time as you have a patch, the vulnerability will get taken away. Jeetu Patel, President and Chief Product Officer at Cisco Isovalent + Cisco gives teams the tools to apply compensating controls and monitor infrastructure health across all Nexus switches. This co-engineered approach solves the challenges of traditional patching cycles and keeps network infrastructure secure while upgrades are scheduled out. The result is immediate protection for critical assets, simplified policy management, and assurance that your network remains resilient when new vulnerabilities emerge. Networking and SecOps teams can maintain uptime, safeguard workloads, and meet compliance requirements without requiring code changes or operational downtime. Towards a safer patching cycle The Cisco Nexus and Isovalent team have come together to bring out the best in our strengths across networking and security, and ultimately fix a necessary gap in the patching cycle. It doesn’t matter whether it’s your toaster, laptop, or servers, vulnerabilities are constantly in an endless cycle of being discovered and patched. Now, this collaboration makes patching Nexus switches almost at your leisure with compensating controls immediately applied directly to the switch. CVEs are constantly published and the network infrastructure is naturally an exploitable target until patches are made available. There has always been this clear need to prevent vulnerabilities from being exploited in the gap between CVE announcement and time-to-patch. Due to the foundational nature of the networking layer, networking teams often delay patching network infrastructure and operate with known security vulnerabilities. Patching a completely new version of the OS can be operationally complex with a lengthy qualification process or lead to downtime with rebooting the switch, router, firewall, or other device. Before, a typical patching cycle might follow: New vulnerability is disclosed Attackers and defenders learn of the new CVE Defenders determine when they can patch. Considerations include: What impact the patch has on existing software When the next agreed downtime for patching is scheduled How critical is the vulnerability +and more questions that weigh up the risk and timeline Attackers begin exploiting the CVE Defenders make determination on the above and set a target patching date Attackers continue exploiting the CVE Target patching date arrives, defenders apply the patch and restart systems [Often 55+ days after discovery] Attackers can no longer exploit the CVE Now! New vulnerability is disclosed Attackers and defenders learn of the new CVE Defenders push a lightweight compensating control policy. Production infrastructure remains uninterrupted Attackers can no longer exploit the CVE Patch when convenient How does Isovalent’s compensating control work? Compensating controls work by detecting and blocking exploit conditions at runtime, such as suspicious network traffic or unauthorized process execution, even when the underlying software has not been patched. These controls are enforced in real-time, preventing exploitation while allowing normal operations to continue. Isovalent’s Runtime Security makes this possible with enforcement points embedded into the heart of your networking gear. Isovalent’s runtime security leverages eBPF-powered enforcement points deeply integrated into networking and runtime layers, providing continuous, real-time visibility and control without performance trade-offs or code changes. These policies allow Networking and SecOps teams to dynamically insert compensating controls into live workloads, meeting the requirements of modern, cloud-native environments. Deep context at minimal overhead to monitor critical system events with zero performance impact. Accelerated time-to-value by deploying instantly and dynamically. Zero code changes needed, achieve full visibility without touching application code. Cloud-native ready, created to simplify monitoring across multi-cloud and Kubernetes environments. Works across releases to remove version-matrix headaches. As the creators of eBPF, Isovalent abstracts the value of eBPF for networking teams, making it easy to build and apply runtime policies at scale without needing to be an eBPF expert or kernel engineer. Teams get the ideal identity-aware enforcement point, without added overhead. Isovalent uses eBPF to hook directly into the kernel, and run programs that detect and react on events. For example, programs can be written to evaluate system calls, tracepoints, kernel functions, userspace functions, sockets, network layer information, and so much more happening right in the kernel. On the Cisco Nexus switches use case, policies are deployed to protect switches from conditions needed to exploit a known vulnerability. The switch is then protected even when a fix is unavailable or a patch is unable to be deployed. For example, if a vulnerability requires a specific unauthorized network packet sequence or process spawn to be exploited, Isovalent’s enforcement detects and blocks these conditional actions at the runtime layer, effectively neutralizing the attack vector for unpatched machines. Below, we see Isovalent monitoring the runtime file operations of Workload A for suspicious read/write operations to sensitive files. Policies both monitor and enforce, so teams can build alert workflows or stop events from executing in real-time. How to protect a fleet of switches with Isovalent + Cisco Nexus? Applying these policies across your Cisco Nexus switches is straightforward under a unified Cisco approach. Isovalent’s runtime security integrates directly with Nexus devices, allowing you to centrally deploy and manage dynamic security policies at scale, without disruption or code changes. This approach delivers real-time threat mitigation and consistent policy enforcement across your entire switch fleet, whether on-premises or in cloud-connected environments. As announced at Cisco Live US 2025, all of this becomes streamlined with Cisco Live Protect. Giving teams one single source to manage, monitor, and deploy compensating controls to Cisco Nexus switches, expanding over time across the Cisco fleet. With Cisco Live Protect, teams get one central security console to stay informed and in control of their environment. Let’s expand on the workflow. The central Nexus dashboard provides an overview of network devices and health. Devices are scanned for CVE’s, and relevant CVE’s are escalated for review. A compensating control is available for review and deployment. To deploy the compensating control, admins select the target workloads to push out the policy. From here, admins can monitor devices for performance, investigate alerts, and review exploit logs for any triggered policies. See Splunk + Cisco + Isovalent all together, the video below walks through protecting Cisco Nexus 9000 with Isovalent compensating control policies, surfacing rich metadata into a Splunk dashboard. Want to protect your datacenter today? Vulnerability management demands rapid action and minimal disruption to business operations. And yet historically, it’s been relegated to static and stagnant patching cycles. Cisco and Isovalent provide a new approach to closing the gap between vulnerability disclosure and protection, allowing organizations to deploy compensating controls within minutes and reduce the risk window for new threats. Cisco Live Protect brings these capabilities together in a single solution. With eBPF-powered enforcement integrated at the runtime layer, Cisco Nexus switches incorporate dynamic, real-time defenses that prevent exploitation even before patches become available. Do you know the approach used by Live Protect can also apply in other places in your environment - patching network devices is one thing but your applications and servers also need patching when CVEs are disclosed. With Isovalent Runtime Security, patch your entire infrastructure in minutes. Ready to secure switches and more without downtime? Reach out for a personalized demo or explore our solution briefs to learn how Isovalent helps global leaders scale and succeed.