Cisco wants the network to become the operating system for AI infrastructure
Cisco’s advantage is not simply the number of switches, routers and security products it sells. Its equipment carries the traffic that connects users, applications, clouds and increasingly accelerators. That position can provide real-time evidence about performance, identity and threats. Splunk adds a data platform that can turn telemetry into investigation and action. The strategic opportunity is to combine the network’s ground truth with software that operates and defends infrastructure. Success would make every connection a source of context and every controller a governed point of response.
AI creates two different markets. Back-end networks connect GPUs inside enormous training and inference clusters, where bandwidth, congestion and optics determine accelerator utilisation. Front-end and enterprise networks connect agents, employees and data across campuses, branches and clouds, where security and observability matter more than peak speed. Cisco can serve both, but the competitive sets and economics differ. The investment debate is whether product breadth finally compounds through common data and control—or remains a portfolio assembled by acquisition.
The business in one map
| Franchise | Role | Moat | Critical variable |
|---|---|---|---|
| Networking | Switching, routing, wireless, optics and network management. | Installed base, software compatibility, reliability, channel and operations knowledge. | Refresh cycles, share, software attachment and customer architecture. |
| AI infrastructure | Silicon One, systems and optics for scale-up, scale-out and front-end traffic. | Silicon-to-system design, Ethernet ecosystem and operational tooling. | Hyperscale adoption, accelerator utilisation and repeat clusters. |
| Security | Network, cloud, identity, application and AI protection. | Traffic position, Talos intelligence, installed controls and cross-domain context. | Platform adoption, efficacy, integration and renewal. |
| Splunk and observability | Ingests, searches and analyses machine data for security and operations. | Query capability, workflows, skilled users and broad data connectivity. | Cloud transition, data economics and Cisco telemetry integration. |
| Collaboration and services | Communications, support, advisory and lifecycle operations. | Enterprise relationships, installed devices and support reach. | Usage, cloud mix, attach and customer outcomes. |
Networking remains a reliability franchise
Enterprise networks are replaced slowly because failure can stop the business. Customers qualify hardware, software, security policy and operations together, then train staff around the environment. Cisco’s installed base, certifications, channel and support create switching costs that extend beyond the box. The moat is strongest in complex estates where consistency and accountability matter more than the lowest port price.
The weakness is architectural transition. Cloud software, merchant silicon, white-box systems and specialist vendors can separate hardware from control. Cisco must keep its silicon and systems competitive while making management valuable across owned and third-party infrastructure. A closed platform may protect share temporarily but lose relevance as customers become multicloud.
AI back-end networking is an accelerator-utilisation market
Thousands of accelerators exchange model parameters and intermediate results. If congestion, packet loss or uneven paths slow collective operations, expensive GPUs wait. Network economics should therefore be measured in job completion and useful compute, not switch throughput alone. Even a small utilisation improvement can justify high-performance fabrics and optics.
Silicon One gives Cisco a programmable architecture spanning routing and switching, while systems, optics and Nexus operations complete the stack. Ethernet benefits from a broad supplier and developer ecosystem and can serve scale-out networks without proprietary dependence. Cisco must prove that congestion control, telemetry and support deliver consistent performance at the largest cluster sizes.
Front-end AI expands the value of secure networking
Agents interact with users, models, tools, APIs and sensitive data across many locations. Traffic becomes more dynamic and identities include non-human actors that can take action. Networks already mediate these connections, giving Cisco an enforcement point for segmentation, policy, performance and threat detection.
This is different from protecting a model endpoint alone. Cisco can observe which agent contacted which resource, from where, using which identity and with what network behaviour. It can combine access policy with application and security telemetry. The value depends on accurate context and fast, safe response; broad visibility without coherent policy simply creates more alerts.
Splunk changes Cisco’s economic centre of gravity
Splunk ingests machine data and lets customers search, correlate and investigate events across security and IT operations. It is used by analysts and engineers who build detections, dashboards and workflows around years of organisational knowledge. That creates skill and process switching costs even when data can technically move elsewhere.
Cisco contributes an enormous source of network, identity, endpoint and application telemetry. Splunk provides the query and workflow layer that can make this data useful across Cisco products. The combination is strategically sound if it lowers investigation time, improves network operations and lets customers search data where it resides instead of paying to copy everything into one expensive store.
The acquisition risk is integration by branding. Separate consoles, licences, schemas and sales incentives can preserve the customer’s original fragmentation. Cisco must create shared data models, identity, policy and workflows while keeping Splunk open to competing infrastructure. Splunk loses strategic value if it becomes a reporting screen only for Cisco equipment.
Data economics determine the observability moat
Telemetry volume grows faster than budgets. Charging primarily for central ingestion can force customers to discard useful data or restrict new use cases. Federated search, tiered storage and workload-based controls let customers retain evidence in the appropriate location while still investigating across it. This is essential for AI, whose agents and models generate new traces, prompts and tool events.
Splunk’s durable advantage is not storing every byte. It is helping operators decide which data matters, search it quickly and convert results into action. Cisco’s network context can improve that judgement, but commercial packaging must reward broader visibility rather than punish it. Consumption growth that reflects useful workloads is healthier than price increases on existing logs.
Security breadth becomes valuable only through shared context
Cisco spans firewalls, access, identity, DNS, cloud security, application protection and detection. The theoretical platform benefit is strong: identity and network behaviour can enrich detections, while one response workflow can change policy across several controls. Talos research supplies threat intelligence across the estate.
Customers judge efficacy and operational simplicity, not portfolio count. Acquired products often arrive with different architectures and consoles. Cisco must reduce policy duplication, improve time to investigate and preserve best-of-breed interoperability. A platform earns consolidation when shared data makes each control better, not when procurement receives a larger bundle discount.
Agentic operations are the integration test
AI agents can investigate incidents, propose changes and execute routine remediation faster than human teams. Cisco Cloud Control aims to give people and agents a common environment across networking, security, compute, observability and collaboration. Splunk can supply evidence; Cisco controllers can take action.
The control risk is substantial. An agent with network privileges can spread a mistaken policy at machine speed. Safe automation needs scoped identity, approval boundaries, simulation, rollback and a complete audit trail. The platform advantage comes from closing the loop carefully: observe, reason, recommend, approve, act and verify.
Cisco participates in AI through five routes
| Route | Assets | Value | Main uncertainty |
|---|---|---|---|
| Hyperscale fabrics | Silicon One, 8000 systems and optics. | Higher accelerator utilisation and open scale-out networking. | Concentrated buyers and intense specialist competition. |
| Enterprise AI networks | Campus, branch, data centre and wireless. | Capacity, segmentation and reliable agent-to-application access. | AI may not accelerate every refresh cycle. |
| AI security | Identity, access, firewalls, AI Defense and Talos. | Protect models and agents while governing their actions. | New controls must integrate with existing security stacks. |
| Observability | Splunk, ThousandEyes and application telemetry. | Correlate model, application, network and infrastructure behaviour. | Data cost and integration can limit visibility. |
| Operational agents | Cloud Control, controllers and workflow agents. | Move from diagnosis to governed remediation. | Trust, permissions and responsibility for automated change. |
The recurring-revenue transition needs careful interpretation
Software subscriptions, support and observability create more visible revenue than periodic hardware purchases. Hardware can also carry software entitlements and lifecycle services. This improves predictability and aligns payment with ongoing value, but does not remove product cycles. A network refresh still depends on customer budgets, installed capacity and architecture.
Investors should distinguish recurring billing from recurring customer value. Contract duration and annualised revenue are useful, but retention, expansion and product usage show whether software is compounding. Financing a hardware purchase over time does not create a software moat. Splunk and security must grow through new workloads and operational outcomes.
Campus renewal is a separate AI infrastructure cycle
Many enterprise networks were installed before hybrid work, pervasive cloud applications and AI agents changed traffic patterns. Wireless density, encrypted traffic, segmentation and cloud-managed operations can justify a coordinated refresh across switching, routing and access. AI may add bandwidth, but the stronger driver is operational: more devices and non-human identities require better visibility and policy at every connection.
Cisco is well placed because campus purchases favour validated architectures, support and channel expertise. A customer replacing a large estate can standardise management and security for many years. The risk is that refresh demand is pulled forward, creating a strong order period followed by digestion. AI language should not turn an ordinary lifecycle replacement into a permanently higher growth assumption.
The quality of the cycle depends on software attachment. Cloud management, identity, assurance and observability should remain useful after the hardware ships and expand across the installed base. If renewal and usage persist when equipment orders normalise, Cisco has converted a refresh into a stronger recurring relationship. If not, revenue remains tied mainly to boxes and backlog.
The channel is both distribution and an integration layer
Partners design, install, finance and support much of Cisco’s enterprise estate. Their customer knowledge lets Cisco reach organisations that cannot operate complex infrastructure alone. Certifications and service practices reinforce switching costs because replacing the vendor also changes skills, processes and support relationships. This is particularly valuable as networking, security and observability converge.
AI creates a new services opportunity: prepare data, redesign networks, govern agents and automate operations. Partners can turn Cisco products into business outcomes and spread Cloud Control beyond the largest customers. But the model creates distance from end users, and incentives can favour transaction volume over software adoption. Cisco needs telemetry that reveals actual use and partner economics that reward successful operation.
At hyperscalers the channel advantage is much smaller. These buyers design their own networks, purchase at enormous scale and demand direct engineering. Cisco must win there through silicon, optics and job economics. The enterprise and hyperscale motions should share technology without confusing their commercial models.
Acquisition discipline remains an unresolved part of the thesis
Cisco has repeatedly purchased software and security capabilities to move beyond mature networking. Acquisitions can bring a user community, data platform or architecture faster than internal development. They can also create overlapping products, intangible costs and sales bundles that obscure organic performance. Splunk is large enough that its integration will define the credibility of the broader strategy.
The strategic case is stronger than simple cost synergy. Splunk should improve Cisco’s products by giving them a common investigation layer, while Cisco should provide differentiated telemetry and distribution to Splunk. That requires preserving the engineers, community and openness that made Splunk useful. Forced migration or preferential treatment of Cisco data could weaken customer trust.
Investors should ask whether combined products win new workloads and improve retention, not merely whether expenses are removed. A successful acquisition creates capabilities neither company could deliver alone and raises customer switching cost through accumulated operating knowledge. A failed one adds revenue but leaves the portfolio no more coherent.
The financial model mixes several kinds of durability
Campus hardware follows multi-year replacement cycles; hyperscale infrastructure can arrive in concentrated orders; security and collaboration depend on subscriptions and seats; observability grows with data and workload; support follows the installed base. Group stability comes from diversification, but the components should not be valued as if they share one recurrence pattern.
Hardware gross margin reflects product mix, components, discounting and manufacturing efficiency. Software can carry attractive incremental economics but requires continuing research, cloud infrastructure and customer success. Splunk also introduces consumption and cloud-hosting costs. The best mix shift occurs when software increases the useful life and value of Cisco hardware, rather than simply replacing one revenue label with another.
Cash generation gives Cisco room to invest, acquire and return capital, but mature cash flow should not excuse weak growth quality. The relevant long-term proof is organic expansion across security, observability and AI operations alongside competitive networking. Buybacks add value only after product investment and integration earn an adequate return. Working capital also matters: large AI and campus orders can move inventory, backlog and cash between periods, so revenue growth should be tested against shipment quality, customer acceptance and subsequent renewal.
Competitive landscape
| Competitor | Advantage | Cisco response | Evidence to watch |
|---|---|---|---|
| Arista | Focused cloud networking, operating consistency and strong hyperscale relationships. | Silicon-to-optics breadth, enterprise reach and integrated operations. | AI cluster share, customer breadth and software adoption. |
| NVIDIA | Accelerator-linked networking, proprietary scale-up and complete AI rack. | Ethernet openness, multi-vendor systems and enterprise distribution. | Ethernet performance and Cisco content in mixed-accelerator clusters. |
| Palo Alto Networks and Zscaler | Focused security platforms and cloud-native policy architectures. | Network enforcement, identity, telemetry and Splunk workflows. | Security platform consolidation, renewal and efficacy. |
| Observability platforms | Cloud-native developer experience and application-first telemetry. | Splunk search, security workflows and network-to-application context. | Cloud growth, data economics and developer adoption. |
| White box and cloud-native control | Lower hardware cost and customer-controlled software. | Reliability, integrated support, custom silicon and lifecycle operations. | Merchant-silicon share and hardware gross margin. |
A scale checkpoint, not a quarterly thesis
The markers describe architecture, not profitability. Hyperscale orders can be large and concentrated; enterprise refreshes can be cyclical; software growth can be offset by data cost. The durable thesis depends on the installed network generating better context and more recurring value across the portfolio.
The investment debate
| Question | Bull case | Bear case | What resolves it |
|---|---|---|---|
| Can Cisco win AI fabrics? | Silicon One, optics and Ethernet operations deliver strong job economics. | Specialists and accelerator-linked stacks own the largest clusters. | Production share, repeat orders and sustained utilisation. |
| Does Splunk make the portfolio compound? | Shared telemetry improves networking, security and operations. | Integration remains commercial and consoles stay fragmented. | Common workflows, data models and measurable investigation speed. |
| Can security regain relevance? | Network context and agent controls create differentiated efficacy. | Specialists innovate faster and customers reject broad bundling. | Platform adoption, retention and independent workload wins. |
| Is subscription quality improving? | Software and services expand with customer outcomes. | Contract presentation masks cyclical hardware economics. | Usage, expansion, renewal and organic software growth. |
| Can agents operate infrastructure safely? | Closed-loop telemetry and control reduce downtime and labour. | Permission errors create unacceptable operational risk. | Approved production actions, rollback success and incident reduction. |
| Does breadth help or slow Cisco? | One platform captures more context and simplifies accountability. | Acquired architectures and incentives preserve silos. | Cross-product adoption, release cadence and customer operating cost. |
What could break the thesis
| Risk | Transmission | Why it matters | Early signal |
|---|---|---|---|
| AI network share loss | Hyperscalers standardise on rival fabrics or internal designs. | Cisco misses the fastest-growing network architecture. | Narrow customer concentration and weak repeat clusters. |
| Splunk integration failure | Data, licences and teams remain separate. | The largest strategic acquisition does not improve the platform. | Low cross-sell and duplicated consoles. |
| Security complexity | Customers keep specialists because Cisco policy is inconsistent. | Network position fails to create security advantage. | Weak retention and limited multi-product deployments. |
| Hardware digestion | Customers pause after campus or AI refresh cycles. | Revenue and channel inventory reverse quickly. | Falling orders, lead times and backlog. |
| Agentic control incident | Automated action causes outage, exposure or policy error. | Trust in the unified control plane collapses. | Customers restrict agents to read-only tasks. |
| Data-cost backlash | Telemetry pricing forces customers to reduce ingestion or switch platforms. | Observability loses the data required for AI operations. | Lower retention, aggressive filtering and federated alternatives. |
How to judge Cisco from here
Start with AI-network production. Follow repeat customers, cluster size, optics content, job completion and sustained utilisation. Orders show demand; operational performance consistently over multiple hardware generations shows whether Cisco has earned a durable position.
Then test integration. Splunk, ThousandEyes, security and network controllers should share context and reduce investigation-to-remediation time. Customers should adopt cross-domain workflows because they work better, not because a bundle makes separate products cheaper.
Finally, evaluate recurring value. Software usage, expansion and retention must grow independently of hardware financing. Agentic operations should move from advice to narrowly governed production actions with audit and rollback. Cisco’s installed base becomes an AI moat only if it produces trusted automation. Each automated change should leave evidence of the initiating identity, data used, approval, expected result and verified outcome.
Bottom line
Cisco has credible assets at every important layer of AI networking: silicon, systems, optics, enterprise access, security, telemetry and operations. Splunk can turn the network from a transport layer into a source of operational context, while Cisco controllers provide a path from observation to action.
The challenge is cohesion. Breadth becomes a moat only when common data makes each product better and customers can operate the estate with less effort. If integration remains a sales construct, specialists will keep winning individual control points and Cisco will retain hardware cyclicality without platform economics.