Wednesday, July 22, 2026

CCIE Coffee Blog: The First Albanian Woman to Become a CCIE: Somea Ferati

 Welcome to the fourth post of the CCIE Coffee Blog, where we highlight the inspiring journeys of Albanians who have achieved the prestigious CCIE certification. It's meant to provide some background info for the CCIE Hall of Fame for Albania and Kosovo. This series contains non-technical content aiming to the inspiration of young Albanians to pursue similar paths like our much respected guests. 

Fig.1 CCIE Coffee Blog

Meet the first Albanian Woman CCIE: Somea Ferati

 Every CCIE journey is unique. Some start in large cities with unlimited access to labs and skilled trainers. Others begin with curiosity, determination, and a dream.

    For Somea Ferati, that journey started in Kosovo and continued in Poland. She reached a major milestone accross 2 countries when she became CCIE Security #70474, and the first Albanian woman to earn a CCIE.


Fig.2 CCIE #70474 Somea Ferati

    While talking to Somea, I realized that this story is about much more than earning a CCIE. It's about curiosity, discipline, consistency, and believing in yourself, even when the path ahead isn't always clear. I've know first hand how hard CCIE is, and her journey reflects what I have also experienced.  It shows that with dedication, resilience, and the right mindset, even the biggest goals are within reach.

I had a chat with Somea about her journey. I hope you enjoy her story as much as I did.


1.  Can you introduce yourself and tell us a little about your journey into networking and cybersecurity?

    I’m Somea, born and raised in Kosovo, a small country that shaped so much of who I became from an early age. My curiosity for computers and systems started in high school, it was a time when technology was becoming an essential part of everyday life, and I saw many young women building strong careers and achieving great things in technical fields. I was eager to become one of them.

    I earned my CCNA and, at the age of 19, started an internship at a networking company in Kosovo, and then a year later at 20, I began working full time as a Network Engineer.

    At the age of 21, I moved alone to Poland and started working at Cisco. It was the biggest challenge that I had, that experience expanded my view of networking and showed me how much more there was to learn in security.


2. What made you decide to go for the CCIE Security certification?

    For me CCIE always felt like a journey for people who were truly determined. It was not only an exam or a title, it represented dedication, discipline, and technical knowledge.

    I saw it as a way to challenge myself and push beyond what felt comfortable. My uncle, Arijan, was one of the first Albanians to earn the CCIE, and I grew up hearing my family talk about this important eight hour exam and the amount of dedication it required. Seeing his journey made it feel real to me. It showed me that someone from our community could reach that level, and eventually I wanted to follow that path in my own way.


3. What was the hardest part of your CCIE journey?

    I believe that when you are alone in a new country, homesickness, full time job and studying can make burnout come very easily.

    But honestly, I did not spend much time thinking about how hard the CCIE journey was. What I remember most is that the more I learned and studied, the more I realized how much more there was to know. It made me curious rather than discouraged. Every new topic showed me another area where I wanted to become stronger.


4. Did you ever think about giving up? If yes, what kept you going?

    Of course. There were times when giving up felt like the easiest thing to do, to just leave it and move on.

    But then I would ask myself what was the purpose of starting if I was not going to give myself a real chance to finish?

    I come from Kosovo, a place where resilience is part of our identity, when we believe in a goal, we keep going until we make it happen.

    For me, giving up was never really an option. I knew that consistency and hard work would matter more than natural ability alone.

    I saw many people with years of experience, while I was still early in my career. I could not control how much experience I already had, but I could control how much effort, discipline, and consistency I gave every day.


5. How did you study for the CCIE, and what worked best for you?

    I did a lot of labbing and spent a lot of time studying the topics. What worked best for me was not only repeating configurations, but also understanding why something worked, why it failed, and how to troubleshoot it.

    One thing that played a very important role was having amazing people around me. This journey taught me that you can achieve so much with the support of family and friends. Having a healthy state of mind was also important, because it allowed me to focus through long nights of studying while working full time.


6. You are the first Albanian woman to become a CCIE. What does that mean to you?

    Albanians are a small nation, but we are full of talent, determination, and ambition. When I realized that I was the first Albanian woman to achieve this, I felt very proud, not only of the achievement itself, but of the opportunity it gave me to be part of a community of people with much more experience than me, people I can continue learning from.

    Representing Kosovo among professionals from different countries means a lot to me.

    I hope this achievement encourages more women to pursue the CCIE and shows them that nothing is impossible when they truly set their minds to it.


7. How has becoming a CCIE changed your career or your life?

    I believe the CCIE will play a huge part in my career and open doors in more beautiful ways than I could have imagined.

    But even before thinking about the future, the biggest change is in the present, the confidence and mindset I gained from this journey. It taught me to trust myself with difficult problems, to stay calm under pressure and not to be intimidated by goals that once felt too big.

    The certification is important, but the person I became while working toward it is just as important.


8. What advice would you give to someone who wants to become a CCIE?

    I wish everyone could experience the journey of dedicating themselves to one big goal, building a routine, sacrificing some comfort, learning from failure, and continuing even when it gets difficult.

    At the end of the day it is not only about the title, it is about the discipline, the dedication, the long hours, and the effort you put into becoming better than you were before.


9. What skills do you think security engineers should focus on in the future?

    AI is already playing a crucial role in almost everything, and I believe security engineers need to understand how to use it responsibly and effectively.

    At the same time, we should not forget the fundamentals, strong networking knowledge, understanding traffic flows and troubleshooting will always matter. The technology will keep changing, but the ability to understand what is happening inside an environment will remain essential.


10. If you could go back and talk to yourself before you started the CCIE journey, what would you say?

Somea:

    There is a photo of me from my second year of high school, wearing my school uniform, during a presentation about dreams in my English literature class.

    I think that photo is worth more than a thousand words. At that age, I already dreamed of becoming an engineer, even though I did not know exactly what the journey would look like.

    Looking back now, I would tell that younger version of myself keep going. You do not need to know every step from the beginning. Just stay curious, work hard, and trust that the path will become clearer with time.

    I wish good luck to everyone reading this especially every young woman and man working toward their dreams and goals.

    Take care of yourself in every way professionally, personally, and with your health.

    We are often far more capable of achieving our goals than we think.



Fig. 3 Somea in High School talking about her dreams



Conclusions

    Somea's story is a reminder that the CCIE is about much more than passing an exam. It is about believing in yourself, staying curious, and showing up every day, even when the journey is difficult.

    Coming from Kosovo, moving to another country at a young age, building a career at Cisco, and becoming the first Albanian woman to earn a CCIE is an incredible achievement. I'm sure her story will inspire many future CCIE candidates, especially young women who dream of building a career in networking and cybersecurity.

Friday, March 6, 2026

Mission Impossible: Cisco Preferred Networking Partner

When I started at TD-K 10 years ago, the Cisco business was pretty much non-existent, and I was the very first networking employee. Back then it was unthinkable that we could reach “Gold” status within a few years, considering the very complex requirements that partners had to fulfill.

Nevertheless, it was a natural step for me to invest in Cisco training and eventually become CCIE certified. At the same time, my team has grown to 9 employees, each of them certified in Cisco.

When the program changed to the new Cisco 360 Partner Program, it suddenly became possible to reach the “Gold” status that I had been aiming for 10 years. The name is different though: Cisco Preferred Networking Partner.

So what is the Cisco Preferred Networking Partner?

The designation is given to Partners who have achieved advanced technical expertise, invested deeply in customer engagement, and built foundational practices. 

Recognized for deep sales and technical skills, lifecycle practices, and the ability to deliver specialized solutions tailored to customer needs. Cisco Preferred Partners can further differentiate their expertise and technical capabilities with specializations aligned to Cisco’s flagship offers and solutions. Said in simpler terms: it is the new “Gold” status.

How did we get there?


The program measures four categories: Foundational, Capabilities, Performance, and Engagement.

Capabilities

Since the program started, we reached the maximum points in Capabilities due to my CCIE certification. I had already spent more than 1000 hours on this, mainly outside office hours. Both our Black Belt certification and Career Certification maturity were above the index from the start. Easy, right?

However, kudos to Cisco for designing the new program to consider individual capabilities. Unfortunately, this was not enough for us to become a Preferred Partner, which was the ultimate goal.

Performance

This is a tough one, especially considering our size. However, all the services I have built were designed with MSP in mind, so our renewal rates are very high and our bookings are increasing. Because of that, we reached 6/10 in the performance score.

Engagement


This category requires a lot of work, both in the completion of deals and adoption of solutions.

While we haven’t done anything specifically to increase the score, we have always created deals for almost all our orders, which eventually improved the score.

Foundational

I left this for last, because most of the work in the past six months has been done in this category. The score is heavily impacted by Customer Success Practice Maturity and Managed Services Practice Maturity. We had already invested in becoming a Select Provider due to its advantages, such as automatic deal approval and fixed discounts, but that was not enough.

We then invested in upgrading to a Premier Provider, both to improve our PVI score and to gain even better discounts and benefits.The process for becoming a Premier Provider is quite complex. It requires an extensive audit that ensures you are delivering Cisco services with the same quality standards used worldwide.

To make this happen, we decided to go for two Cisco Powered Services:

Meraki Access

Meraki Security & SD-WAN

I had already built these services a few years ago, as our company mainly operates as an MSP, but they needed to be formally certified. The audit process was quite complex, but the end result was great. We received a lot of positive feedback from the auditor. You can read some of the comments below.




But was this enough? Not yet. Our score in the Foundational category still needed a boost. So I decided we should pursue the Cisco Customer Success Practice Maturity.

Another audit? Really?...

After submitting a large set of documents and screenshots across all the tools and systems we use to manage customers and solutions, everything was reviewed—and we passed.

This was the final push toward reaching the golden 7.5 points. And funnily enough, I didn’t even notice we had achieved the score until an email arrived with Cisco U All Access Passes for 10 of our employees, which is one of the benefits of the designation.

Conclusion


After literally thousands of hours of work, I’m incredibly grateful that the Cisco business we started from scratch 10 years ago has flourished. Today, we are one of only 8 partners in Denmark, out of 161 Cisco partners, to receive the Cisco Preferred Networking Partner designation. 



Tuesday, September 23, 2025

CIS Benchmark Cisco Meraki: Network Inventory and Asset Management

This post is focusing on building the Center for Internet Security (CIS) Benchmark for Cisco Meraki. CIS is one of the most respected institutions when it comes to security standards, with CIS Controls being one of the most widely used resources for implementing and securing infrastructures. This benchmark is considered a prescriptive configuration recommendation for Cisco Meraki. This section of the Benchmark will focus on Inventory and Asset Management. 

Why do we need a Benchmark?

Following the configuration guides can sometimes be complicated and without having a logical connection between the different documents, it's almost impossible to ensure that all the necessary security features are enabled. In order to streamline the security implementation, it is recommended to follow security standards. One of the most widely used security standards is CIS Controls, due to its very detailed and practical way of describing the technical and organizational safeguards to build a secure infrastructure. I decided to join CIS as an Editor and Subject-Matter Expert to help the community and the rest of the world. 


Fig.1 CIS Editor with focus on Cisco Meraki

Who is this benchmark for?

This benchmark is intended for system and application administrators, security specialists, auditors, help desk, and platform deployment personnel who plan to develop, deploy, assess, or secure solutions that incorporate Cisco Meraki equipment and solutions.

Network Inventory and Asset Management

Inventory Tracking

Each organization in the Meraki Dashboard has an inventory that tracks Cisco Meraki devices and the networks they belong to. The inventory must be kept up-to-date to manage security effectively. Without a full view of the inventory, it is not possible to ensure proper configuration, patching or security for the assets. 

Fig.1 Organization Inventory

Audit Procedure

Log into the Meraki Dashboard, go to Organization -> Configure  -> Inventory and verify that all claimed devices are in use and assigned to a network.

Mapping: CIS 8.1 Control 1.1, 1.2

Tagging and Naming Convention

Implementing device naming convention and device tagging helps in improving operations, troubleshooting and accountability. Without standardized naming, device management is inefficient, especially in larger deployments. In case of incidents, it is very difficult to identify devices and the troubleshooting process becomes slower. Using a well-defined naming and tagging schema helps the technical staff with operations and the compliance staff with meeting requirements. Maintaining the asset inventory, proper naming and tagging introduces extra overhead. The effort is outweighed by better visibility, reduced risk and more efficient operations. There is no service impact when implementing changes.

Audit Procedure

Verify if the organization has implemented a naming convention schema. Then log into the Meraki Dashboard.

Go to Organization -> Network -> Wireless -> List Verify that the wireless devices have proper naming and tags describing location and ownership.

Go to Organization -> Network -> Switching -> Switches Verify that the Switches have proper naming and tags describing location and ownership.

Go to Organization -> Network -> Security & SD-WAN -> Appliance Status Verify that the Firewalls have proper naming and tags describing location and ownership.

A similar approach should be followed with Mobile Gateways, Cameras and Sensors.

Mapping: CIS 8.1 Control 1.1

Unofficial recommendation. 

Due to the nature of the Benchmark, I won't be able to provide a very detailed guideline in implementing a naming convention and tagging schema. This is very different from organization to organization, and it needs to make sense to the staff that will be using it. There are though some generic guidelines I can provide in this blog post. Some of the key principles to keep in mind are:
  • Documented schema - A document should be written with the structure, so existing and new engineers can easily understand the naming
  • Uniqueness - Every device should have a name that is unique within the domain where it's used.
  • Clarity - The name or tag should make sense and be easy to read. 
  • Scalability - The schema should provide the possibility to add new devices without the risk of running out of space
  • Structure - The name should be split in sections, where each is representing a specific component. 
In medium-sized networks, one of the most common structures I use is BuildingCode-RoomNumber-RackIdentifier-DeviceType-DeviceID. 

Structure: BB-RR-N-DD-II

BB -> Building number (HQ - Headquarters, WH - Warehouse etc.)
RR ->  Room Number ( 204 - Server Room, 103 - Kitchen)
N -> Rack Identifier (R1, R2)
DD -> Device Name (FW, SW, AP)
II -> Device Identifier (01, 10)

While this model might not fit to any customer size, some of the sections can be omitted or expanded based on the installation. Be careful with making too long names or using special characters, which might cause confusion and difficulty in automation. 

Conclusion

The CIS Meraki Benchmark is an important resource to implement and maintain a resilent network. By keeping an up-to-date inventory and using proper naming and tags, we provide better visibility, simplified operations and troubleshooting. Periodical reviews ensure consistency and reduce risk introduced by unauthorized and undocumented assets. 

Call-to-Action

CIS Benchmarks are built by community members like you and me. We need more people like you to come with input and make sure that we are providing real, practical advice to the rest of the world. Please join: CIS WorkBench / Benchmarks

References

https://documentation.meraki.com/General_Administration/Organizations_and_Networks/Organization_Menu/Manage_Tags

https://documentation.meraki.com/General_Administration/Organizations_and_Networks/Renaming_a_Network_or_Organization

https://developer.cisco.com/meraki/api-v1/update-device/

https://developer.cisco.com/meraki/api-v1/update-network/





Thursday, September 18, 2025

CIS Benchmark Cisco Meraki: Administrative and Dashboard Access

This post is focusing on building the Center for Internet Security (CIS) Benchmark for Cisco Meraki. CIS is one of the most respected institutions when it comes to security standards, with CIS Controls being one of the most widely used resources for implementing and securing infrastructures. This benchmark is considered a prescriptive configuration recommendation for Cisco Meraki. The first section of the Benchmark will focus on Administrative and Dashboard Access. 

Why do we need a Benchmark?

Following the configuration guides can sometimes be complicated and without having a logical connection between the different documents, it's almost impossible to ensure that all the necessary security features are enabled. In order to streamline the security implementation, it is recommended to follow security standards. One of the most widely used security standards is CIS Controls, due to its very detailed and practical way of describing the technical and organizational safeguards to build a secure infrastructure. I decided to join CIS as an Editor and Subject-Matter Expert to help the community and the rest of the world. 


Fig.1 CIS Editor with focus on Cisco Meraki

Who is this benchmark for?

This benchmark is intended for system and application administrators, security specialists, auditors, help desk, and platform deployment personnel who plan to develop, deploy, assess, or secure solutions that incorporate Cisco Meraki equipment and solutions.

Administrative and Dashboard Access

Administrative Accounts

There are 2 basic types of dashboard administrators: Organization and Network. Organization administrators have access to the entire organization with all the networks, while network administrators are limited to the individual networks and their devices. We need to make sure to use named accounts that are not shared, in order to minimize the risk of unauthorized access and ensure accurate audit trails. We also need to go through the list periodically and revoke access as necessary. 

Fig.2 Administrative and Dashboard Access (Beta)

Audit Procedure

Log into the Meraki Dashboard, go to Organization -> Configure -> Administrators, and go through the list to make sure there are no shared logins, like "info", "support", "VendorX" etc.

Mapping: CIS 8.1 Control 5.

Network Admin Accounts

Network access need to be granted only where required, preferably in read-only mode. If network-level administrators are granted more privileges than required, they may accidentally or maliciously alter configurations across the networks that they have been granted access to. This can cause service outages, security policy violations or exposure of sensitive data. It is necessary to do periodical review and revoke unnecessary access. 

Audit Procedure

Log into the Meraki Dashboard, go to Organization -> Configure -> Administrators, and go through the list of network accounts to make sure there are no shared logins, like "info", "support", "vendorX" etc.

Mapping: CIS 8.1 Control 5

Role-Based Access Control

Accounts with higher privileges than necessary pose significant security risks. Implementing Role-Based Access Control reduces the attack surface. Failure to implement proper role-based controls in the Meraki Dashboard increases the risk of unauthorized or excessive administrative access. Overprivileged accounts can cause accidental or malicious changes to the organization. Organizational data might also be exposed.

Fig.3 Role-Based Access Control (Beta)

Audit Procedure

Log into the Meraki Dashboard, go to Organization -> Configure -> Administrators, verify the organization and network level access for all accounts, with focus on the custom role assignments. Audit Camera access permissions. Verify if the existing roles match the documented process of the organization for assigning role-based access account. Compare results to the last dated role-based access control audit.

Mapping: CIS 8.1 Control 6.8

Multi-Factor Authentication

Enforcing Two-Factor Authentication protects from unauthorized access in case the password of the administrator is compromised. This reduces the risk of account takeover, unauthorized configuration changes and security breaches.If two-factor authentication (2FA) is not enforced for all Meraki Dashboard logins, accounts are only protected by passwords, which can be targeted with phishing, credential stuffing, and brute-force attacks. A compromised administrator account without MFA can provide attackers with full access to network configurations, client data, and security policies, leading to potential service disruption and security breaches.

Fig.4 Multi-Factor Authentication

Audit Procedure

Log into the Meraki Dashboard, go to Organization -> Settings -> Security. Verify that "Two-Factor authentication" is enabled. Go to Organization -> Configure -> Administrators and verify that users are using 2FA. 

Mapping: CIS 8.1 Control 5.2

Audit Logs

Audit logs need to be enabled and reviewed regularly to ensure accountability, detection of unauthorized changes and support investigations. Without proper audit logging and regular review, malicious or unintentional changes can cause security breaches, service disruption and compliance violations. Audit logs help to mitigate these issues by providing historical data. Audit logs are enabled by default in Cisco Meraki and can't be disabled. Periodical audit procedure should be established to ensure traceability and detect unexpected changes.

Audit Procedure

Log into the Meraki Dashboard, Go to Organization → Monitor → Change Log. Verify that audit logs are being collected. Audit logs can also be fetched through API to external systems like a SIEM. Verify that the periodical review procedure is in place. 

Mapping: CIS 8.1 Control 8.2

Conclusion

The CIS Meraki Benchmark is an important resource to implement and maintain a resilent network. By enforcing named (non-shared) accounts, role-based least privilege, enabling MFA, and reviewing access regularly, you significantly lower the risk of misconfigurations, data exposure, and service interruptions.

Call-to-Action

CIS Benchmarks are built by community members like you and me. We need more people like you to come with input and make sure that we are providing real, practical advice to the rest of the world. Please join: CIS WorkBench / Benchmarks

References





Friday, February 28, 2025

Ethical Hacker: Why should you learn networking?

Ethical Hacker: Why should you learn networking?

Networking is arguably the most vital component of the current internet and IT infrastructure, the backbone of today’s technology. Imagine a world where computers, servers and other IT systems wouldn't be able to communicate with each other. That would basically kill the modern internet and most of the technology as we know it. As an ethical hacker, your job is to understand the logic behind networking, because that’s how you find vulnerabilities and misconfigurations. 



Fig.1 Mr. Robot reading CCNA 

So where do you learn networking from?

The golden standard for learning the basics is Cisco CCNA. While it doesn’t teach you anything about hacking, it helps with understanding the fundamentals of how networks are built. It covers one of the many domains you have to master to become a great ethical hacker.

How can an ethical hacker use networking knowledge?

Let's look at some of the attacker tactics and techniques in the MITRE ATT&CK framework, one of the most widely used knowledge bases, and compare some of the tactics and techniques to the topics addressed in the CCNA blueprint. The CCNA topics are only scratching the surface, since hacking is not the focus, but there is a ton of useful information to build solid knowledge on many protocols exploited by hackers.  While there is no 1-to-1 mapping between the attack techniques and the CCNA blueprint topics, we can find a few crossing points between the two. 


Network Reconnaissance & Scanning (MITRE Tactic: Reconnaissance & Discovery)


Ethical hackers gather intelligence on a target using IP addressing, subnets, VLANs, and open ports.

Tools like Nmap, Wireshark, and Netcat help with network mapping. 


CCNA Topics:

1.0 Network Fundamentals – Understanding IP addressing, subnets and VLANs helps hackers map networks. 

2.0 Network Access – Layer 2 discovery (CDP, LLDP, ARP) - Protocols used for reconnaissance. 

3.0 IP Connectivity - Routing Concepts and layer 3 protocols (OSPF, Static Routing) - Identification of network topologies. 


MITRE Techniques:

T1595 – Active Scanning (Port & Service Discovery)

T1046 – Network Service Scanning

T1018 – Remote System Discovery

T1071 – Application Layer Protocol for Command & Control


Exploiting Network Vulnerabilities (MITRE Tactic: Initial Access & Execution) 


Attackers exploit weaknesses in TCP/IP, HTTP, FTP, and SSH to gain unauthorized access. MITM attacks like ARP poisoning and DNS spoofing can intercept or redirect network traffic.


CCNA Topics:

2.0 Network Access - (Telnet, SSH, HTTP, HTTPS)

4.0 IP Services - Understanding NAT, DNS, SSH 

5.0 Security Fundamentals - Understanding 

Device Security - Administrative Access, Device Hardening. 


MITRE Techniques:

T1189 – Drive-by Compromise

T1203 – Exploitation for Client Execution

T1557 – Man-in-the-Middle (MITM)

T1040 – Network Sniffing


Wireless Attacks (MITRE Tactic: Credential Access & Privilege Escalation)


Wi-Fi hacking targets weak encryption (WEP, WPA, WPA2) and uses deauthentication attacks.

 

CCNA Topics:

5.0 Security Fundamentals (WLAN, WPA, SSID, Authentication)


MITRE Techniques:

T1602 – Network Sniffing for Credentials

T1556 – Modify Authentication Process

T1078 – Valid Accounts 


Post-Exploitation & Data Exfiltration (MITRE Tactic: Lateral Movement & Exfiltration)


Once inside a network, ethical hackers move laterally using pivoting, port forwarding, and VPN tunneling. DNS tunneling and C2 servers are used for exfiltrating data.

CCNA Topics:

IP Connectivity - Routing Concepts - helps with pivoting and lateral movement.

Network Automation - Learning basic scripting, which could help with exfiltration techniques. 


MITRE Techniques:

T1570 – Lateral Tool Transfer

T1095 – Non-Application Layer Protocol (ICMP, UDP for Covert C2)

T1048 – Exfiltration Over Alternative Protocol (DNS Tunneling)

T1071.004 – Exfiltration Over C2 Channel


Conclusion

Networking is the backbone of the modern technology.  Whether you are an ethical hacker, IT technician or security analyst, understanding how networks work will make you more effective in doing your daily job. CCNA being the golden standard in learning networking is one of the certifications to consider for building the fundamental knowledge in protocols, infrastructure and communication. 


References

MITRE ATT&CK framework: MITRE ATT&CK®
CCNA Blueprint: CCNA Exam Topics