HomeIntelligenceBrief
🔓 BREACH BRIEF⚪ Informational📋 Advisory

Cisco Deploys Unified SOC/NOC with Splunk for MWC Barcelona, Delivering Real‑Time Visibility in Hours

Cisco’s security team integrated Splunk Cloud with multiple Cisco telemetry sources to create a unified SOC and NOC for the 2024 Mobile World Congress. The approach enabled rapid dashboard creation and cross‑domain correlation, offering a repeatable model for enterprises managing third‑party security and network services.

🛡️ LiveThreat™ Intelligence · 📅 April 09, 2026· 📰 blogs.cisco.com
Severity
Informational
📋
Type
Advisory
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
blogs.cisco.com

Cisco Unifies SOC and NOC with Splunk for MWC Barcelona, Achieving Real‑Time Visibility in Hours

What Happened – Cisco’s security team leveraged Splunk Cloud to fuse Security Operations Center (SOC) and Network Operations Center (NOC) data for the 2024 Mobile World Congress in Barcelona. Within a single afternoon the team built a full‑featured NOC dashboard and enabled cross‑domain correlation of network and threat telemetry.

Why It Matters for TPRM

  • Demonstrates the speed and flexibility of a unified data platform for large‑scale events, reducing MTTR for third‑party vendors.
  • Highlights the value of consolidating disparate Cisco telemetry streams (Secure Access, XDR, FTD, Meraki, Catalyst, Spaces) into a single analytics layer.
  • Provides a repeatable blueprint for organizations that rely on multiple security and networking vendors to meet compliance and service‑level expectations.

Who Is Affected – Telecommunications & event‑venue operators, large‑scale conference organizers, MSPs/MSSPs delivering managed SOC/NOC services, and any enterprise using Cisco and Splunk in a hybrid environment.

Recommended Actions

  • Review contracts with SOC/NOC service providers to ensure they can ingest and correlate multi‑vendor telemetry.
  • Validate that your organization’s Splunk (or comparable SIEM) deployment is configured for rapid dashboard creation and cross‑domain analytics.
  • Incorporate unified SOC/NOC architecture requirements into third‑party risk assessments and continuous monitoring programs.

Technical Notes – The deployment used Splunk Cloud as a “single pane of glass,” ingesting data via native connectors from Cisco Secure Access, Cisco XDR, Cisco Firewall Threat Defense (including the Secure Firewall 6160), Cisco Meraki, Catalyst Center, and Cisco Spaces. No new vulnerabilities were disclosed; the focus was on operational efficiency and real‑time visibility. Source: Cisco Security Blog

📰 Original Source
https://blogs.cisco.com/security/powering-mwc-barcelona-building-a-unified-soc-and-noc-with-splunk-in-record-time/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

🛡️

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.