Fortinet Again Named a Gartner® Peer Insights™ Customers’ Choice for Network Firewall

And in addition to extra horsepower, FortiGate Network Firewalls also uniquely support network convergence requirements, including being the only solution to include natively integrated ZTNA enforcement, Secure SD-WAN, wireless WAN, and Wireless LAN management. No other solution can boast so many world-class services running simultaneously on the same platform. And because they all leverage the same OS, organizations that deploy these solutions also realize maximum interoperability, automation, and threat detection and response. It’s innovation like this that has allowed Fortinet to successfully secure enterprise networks end-to-end for over 20 years.

Fortinet Is the Preferred Choice of Customers Worldwide

Network and infrastructure leaders across all industries, including financial institutions, healthcare, and education environments, are tasked with connecting and securing their growing number of enterprise edges. This includes converging OT and IT networks, extending new services to clients and partners, and maintaining optimal user experience while reducing the attack surface and minimizing disruptions for business-critical applications. The unique power, scope, and scalability of the FortiGate Network Firewall are why security leaders across the globe trust Fortinet more than any other vendor to secure their businesses and help deliver value and performance to their stakeholders.

We’re honored to once again be recognized with the Customers’ Choice for Network Firewall. Based on peer-sourced reviews, we think that customers of all sizes and industries have recognized Fortinet for enabling them to optimize their digital acceleration efforts by delivering on the features and performance they need to be successful – all delivered by the same FortiGate solution, running on the same FortiOS operating system, and managed through the same console. It’s why we believe that the FortiGate Network Firewall also received the Gartner Peer Insights Customer’s Choice recognition for WAN Edge Infrastructure for the third year in a row.

In addition to receiving the Gartner Customers’ Choice distinction, Fortinet has again been placed in the top-right quadrant of the Voice of the Customer report. This marks three years in a row that Fortinet has received this recognition from its peers. Another distinction is Fortinet’s impressive score of 4.6 out of 5.0 from 446 reviews—the highest number of reviews of any vendor participant. And of those customers who provided quality reviews, 93% also shared their willingness to recommend the FortiGate Network Firewall to others.

But that’s not all. Digging deeper into the report, were Fortinet was also recognized with a Customers’ Choice recognition for FortiGate Network Firewalls by the Finance and Manufacturing verticals and Services Industries. Regionally, Fortinet again made the Customers’ Choice quadrant for Europe, the Middle East, and Africa (EMEA) and North America. And when rated by category, Fortinet achieved a 4.7/5.0 for product capabilities.  

Here is a sample of reviews provided by customers:

One of the Best Threat Protections Against Cyber-Security Attacks

This is an effective and efficient firewall software that delivers high performance, improved visibility, and multi-layered advanced security to protect our systems against cyber-attacks while also reducing complexity. Many security functions such as Application Control, Antivirus, IPS, Web Filtering, and so on are available in the FortiGate Firewall, which assists our company in protecting our users.

Protect the network from internal and external threats in an efficient manner

Our network is always in the safe zone with FortiGate Next-Generation Firewall end-to-security and the difficult operations of our security center are easily managed by its high performance and efficient capabilities. We have deployed this single security solution that not only simplified our security posture, but also ensured that all of our physical, virtual, and cloud environments were adequately protected, allowing our people to focus on increasing profitability rather than worrying about security. FortiGate Next-Generation Firewall, in my opinion, is an excellent and high-performance security solution that no other solution can match.

Very strong product that supports core NGFW tech like deep-packet inspection

Our organization looked at Palo Alto, Cisco, and Fortinet NGFW products. Fortinet was able to provide the most cost-effective solution without compromising security. We have worked with Fortinet for the last 10 months and been very happy with the sales and technical teams.

Fortinet Security Fabric Is a Game Changer

The Fortinet Security Fabric has been a game changer in how we manage our environment and it brings an excellent view of the network and is easy to configure. The firewalls perform very well, and we have no issues with their throughput. Secure SD-WAN is built in and is easy to setup and manage.

Best Next Generation Firewall for business of any size

The product FortiGate NGFW is robust enough to maintain cyber security in the company, bringing confidentiality and availability to carry out activities that depend on the integration between internal and external networks.

A great all-in-one or purpose-built security solution

Fortinet’s suite of products has been key in allowing us to build a secure and highly flexible network architecture. The overlap and integration of services on the FortiGate units is a key cost-saving measure for smaller organizations while allowing flexibility to expand to dedicated hardware as needed (for example, Wireless LAN Controllers or FortiAuthenticator). Fortinet has done a great job of expanding the functionality in their GUI interface, however there are still times when it is beneficial or even required to go back to the command-line. The support has been truly great with minimal wait times and excellent advance hardware replacement services.

FortiGate Exceeds Expectations

Moving to FortiGate from another vendor was a very smooth process. The ease of installation and integration into our network was great. The firewalls have a full set of next gen features and are simple to work with and troubleshoot. Their support is easy to work with and is responsive. Fortinet has a large suite of products that compliment and integrate with the next gen firewalls.

Best NGFW product

FortiGate is best firewall I have used so far, easy to configure and ready to deploy with minimal configuration we have migrated from other firewall vendor to FortiGate and over all experience is very good, protection level and update frequency of definition other security component is quick.

Simple & Fast to Implement for Cloud Based Architectures!

Great! We implemented FortiGate as part for cloud landing zone to bring in more security for our cloud setup. It was easy for our firewall admins to setup the base.

FortiGates are simple to deploy but provide robust security, routing and SD-WAN features

Deployment and centralized configuration with FortiManager make the product very repeatable for a business with a large WAN infrastructure. With the built in SD-WAN features the product is very robust for the ease of configuration.

Fortinet is a great centralized security solution to increase posture and visibility

Our company deployed FortiGate NGFWs covering data center and branches. All product capabilities performed very well: SD-WAN, VDOMS, integration, reporting. The deployment helped us to simplify the security management and protection, while increasing security posture. FortiGate is an incredible high-performance security solution.

Trusted Advisor for Enterprise Security, Both at the Perimeter and Beyond

In general, the next generation feature set of FortiGate firewalls meet the needs of my fastest growing clients, both in the enterprise data center, or at remote offices.

Gartner Peer Insights ‘Voice of the Customer’: Network Firewalls, Peer Contributors, 29 April 2022.

GARTNER  is a registered trademark and service mark, and PEER INSIGHTS is a trademark and service mark, of Gartner, Inc. and/or its affiliates in the U.S. and internationally and are used herein with permission. All rights reserved.

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences with the vendors listed on the platform, should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

Sourced from Fortinet

A True Converged Platform Starts with a Powerful Network Firewall

Building and managing networks is hard. It requires specialized skills and training, especially today, when networks must be designed to automatically adapt to the constant pressures of digital acceleration. Ironically, this is one of the reasons why so many security products fail to interoperate with the network. Most security developers only have a basic grasp of modern networking, which is why legacy security solutions struggle to adequately protect today’s dynamic networks.

This fundamental lack of expertise is also why so many security vendors have been quick to declare that the network—and by extension, the firewall—is dead. They have wrongly assumed that because so many applications and services have been moved to the cloud that the network as we know it is a dinosaur. Nothing could be further from the truth.

The fact is, the network has never been more important, even in cloud-centric environments. Today, everything is network-centric. The network serves as a center post holding everything together, including distributed data centers, multi-cloud environments, new edges, dispersed IoT solutions, and distributed business-critical applications. Hybrid networks span the entire digital business environment, from campuses to branch offices and from the cloud to at-home workers. Even in highly specialized cloud-centric environments, the network enables cloud on-ramp, interconnects disparate systems, and enables connectivity between multi-cloud environments. It allows applications and workflows to move seamlessly across every edge so critical information can be accessed by any user or device from any location.

But in these new hybrid network environments, security cannot function as a standalone solution. Instead, security must be seamlessly converged with the underlying network, enabling protections to dynamically adapt to a constantly shifting network. And as a result, the management of modern networking and security can also be converged. By centralizing policies for NOC and SOC, changes can be orchestrated and advanced tools like AIOps can span the network. In this way, convergence becomes a powerful enabler of digital acceleration.

In this environment, rather than being dead, the network firewall becomes the foundation of a converged security and networking platform. Building critical network functions such as SD-WAN, LAN edge controllers, ZTNA, and support for 5G directly into a converged networking and security platform enables a security-first approach to networking that ensures that every change is secured by default. A converged platform is the only way to effectively combine network modernization with dynamic security that can seamlessly span every part of the network and adapt in real time to any changes the business requires.

Convergence Is Easier Said Than Done

The clear advantages of convergence are why many security vendors now promote their point solutions as a converged platform. But as with most marketing-driven claims, the truth is often far from reality. Rather than addressing the broad network evolution that is impacting all edges—from the campus and distributed data centers to private and multi-cloud environments to branch offices and remote workers—many vendors are instead focused on the idea of convergence from a niche use-case. And because their efforts are limited to only one piece of the network, their solutions end up creating (rather than addressing) complexity—which enables (rather than prevents) cyber incidents.

One of the most significant contributors to this disconnect is that security vendors have generally failed to innovate on networking capabilities. That should come as no surprise. The network isn’t an area of expertise for most security vendors. And because they don’t understand the importance of today’s hybrid networks, they make absurd claims like the network is dead. So, it’s no surprise when their security solutions fail to address the actual networking needs of their customers.

The other challenge is that few of their touted platforms have actually been converged. While a vendor may own several trendy technologies, usually through acquisition, and even wrap them together inside a management console to make it seem like they work together, the truth is that their solutions really only operate side by side. And as a result, the organizations that invest in them end up compromising on the benefits of true interoperability.

The reason for this comes down to complexity. As any engineer can tell you, weaving together the mature codes of solutions developed in isolation, and only brought together through acquisition, is nearly impossible. Even the most skilled development team working with disparate components will never be able to achieve the interoperability that today’s hybrid networks require. True convergence requires solutions that have been built organically using the same foundational codebase.

FortiGate Is the Foundation of the Industry’s Only True Converged Networking and Security Platform

FortiGate is not just the most deployed network firewall in the world, representing over one-third of all firewall shipments globally. It’s also one of the top SD-WAN solutions on the market. It’s a powerful LAN Edge controller. It’s also a 5G controller. And it’s the only solution that enables universal ZTNA enforcement on-premises and in the cloud, which is crucial for supporting today’s hybrid workforce. Most importantly, FortiGate is the foundation of the industry’s only true converged networking and security platform.

How is that possible? It starts with over 20 years of prioritizing organic innovation with security-driven networking in mind. FortiGate is intentionally powered by:

FortiOS everywhere

Every function provided by FortiGate is built using a common operating system. As a result, its robust security solutions, including its LAN and WLAN controllers, SD-WAN, ZTNA, 5G controller, and other solutions are actually the exact same product. This enables a level of convergence, correlation, interoperability, and automation between every function that no other vendor is able to provide. It also ensures convergence between all its various form factors, including FortiGate appliances, virtual machines, container solutions, SASE, and cloud deployments.

ASIC acceleration

In today’s digital world, performance is king. Security tools have traditionally struggled to provide adequate performance without a significant price tag attached. And even then, certain specialized functions, like inspecting encrypted traffic (which now represents about 98% of all web traffic) have been the Achilles’ heel of security appliances.

Fortinet foresaw this need to provide exceptional performance for both security and networking functions over a decade ago. That is when we delivered the industry’s first—and only—customized security and networking processors. Unlike the off-the-shelf processors used by every other security vendor, these custom ASICs work like GPUs to offload critical security functions. As a result, they deliver an average of 15x more performance for the same price point of competitive solutions.

And the same engineering codebase that enables these physical security processors (SPUs) also enables the delivery of virtual chips (vSPUs) that provide similar acceleration in private and public cloud deployments. The result is unmatched performance and the industry’s highest security compute ratings.

Integrated FortiGuard Security Services

The other value of a converged platform is the ability to coordinate advanced services across on-premises and in-the-cloud deployments to detect and prevent threats at scale. Solutions designed to work together also increase visibility. They enable things like edge threat collection and correlation, coordinated threat response, cross-network automation, and AI-based analysis that spans the distributed network rather than being limited to some small segment.

Hybrid Networks Require a Converged Solution

Converging the network with security is crucial because digital acceleration is rapidly dispersing workers, devices, and data. The only thing holding everything together is the network. And in this environment, traditionally isolated networking and security solutions will never be able to keep up. And worse, cybercriminals are having a field day as the network continues to expand, introducing blind spots and gaps as security struggles to keep new edges under control. Only a truly converged platform offers the automation, management, orchestration, and interoperability advantages that today’s—and tomorrow’s—hybrid networks require.

Find out how the Fortinet Security Fabric platform delivers broad, integrated, and automated protection across an organization’s entire digital attack surface to deliver consistent security across all networks, endpoints, and clouds.

Sourced from Fortinet

RSA Conference Returns Live and Fortinet Will Be There

Fortinet is delighted to again be a Platinum Sponsor of the RSA Conference 2022 in San Francisco, June 6-9, 2022. We will be situated in the Moscone Center North Hall, where our booth (#5855) will feature four demo kiosks, a live theater, an “Experts Bar,” and a lounge.

Fortinet Booth at RSA Focused on the Latest Security Innovations

Fortinet will display a wide range of productsservices, and technology integrations and have booth events to help everyone from the security novice to the most seasoned cybersecurity professional obtain the advice and solutions they need to successfully secure their organizations.

Our Expert Bar will be staffed with some of the top security engineers in the industry to answer even the most difficult questions about cybersecurity. Our in-booth theater will cover the Fortinet Security Fabric and our broad product portfolio as well as partner presentations. Each presentation will be 15 minutes, followed by a five-minute Q&A. Our team will be thrilled to meet you or get re-acquainted.

Why the RSA Event Is Important

RSA is the event everyone who is anyone in cybersecurity generally attends. It gives cybersecurity experts and business professionals the unique opportunity to attend and give presentations, network with colleagues and competitors, learn the latest, and promote their own technology or solutions.

Anyone new to the cybersecurity industry will find the RSA Conference (RSAC) to be an excellent starting point for learning all the ins and outs. At RSAC, is you will find hundreds of vendors with thousands of solutions on full display, hands-on technology opportunities, chances to ask seasoned security questions, and educational sessions hosted by some of the top minds in cybersecurity.

This year’s theme at the RSAC is Transform. There will be many high-profile industry keynote speakers discussing all the transformation happening in the business world and in the cybersecurity industry.

Fortinet Speakers at RSAC

This year Fortinet will have executives participating in three different sessions.

Speaking Sessions at RSAC: Wednesday, June 8

1) Session Code: PART2-W01: The Importance of a Cybersecurity Mesh Platform in Securing Digital Acceleration
At 8:30 a.m. – 9:20 a.m., Fortinet CMO, EVP Products and Solutions John Maddison will be leading a session focused on securing digital acceleration.

The session abstract: Digital acceleration has caused many organizations to move first and later ask how best to secure and manage changes to their networks—creating a perfect storm for attackers and threats looking to exploit silos, complexities, and visibility gaps that naturally arise from such complex and piecemeal environments. To overcome these challenges, a broad, integrated, and automated cybersecurity mesh platform like the Fortinet Security Fabric is required.

2) Session Code: HT-W01: Botnets Don’t Die: Resurrecting the Dead to Feed on the Living

Also at the same time, 8:30 a.m.–9:20 a.m. on Wednesday, Aamir Lakhani, Senior Security Strategist at Fortinet FortiGuard Labs with be speaking at a session focused on trends in botnets with Joseph Muniz, Security Architect at Cisco. This talk will show that with a bit of creative thinking, attendees can “wake the dead” and control previously believed retired botnets, all equipped with a small army of ready and able hosts. Essentially, participants will learn how to be a cyber necromancer.

Speaking Sessions at RSAC: Thursday, June 9

1) Session Code: KEY-R06S: Mapping the Cybercriminal Ecosystem

On Thursday, June 9 at 2:10 p.m.–3:00 p.m., Derek Manky, Chief of Security Insights & Global Threat Alliances at Fortinet FortiGuard Labs will be a panelist for a session focused on the cybercriminal ecosystem. Although cybercrime is now a national security threat, an in-depth understanding of the cybercriminal ecosystem remains limited. The industry needs a holistic map to conduct effective disruption, allocate resources efficiently, and impose meaningful costs on criminal actors. This panel will discuss the World Economic Forum Centre for Cybersecurity’s mapping project, its results to date, and its future.

Come Visit Fortinet at RSAC!

Plan on stopping by our booth #5855 to experience live, hands-on demos of some of the latest, cutting-edge security solutions in the industry, meet with a friendly security expert, or attend one of our nearly two dozen in-booth sessions. 

For the cybersecurity industry, the RSA Conference held every year at San Francisco’s Moscone Center is a much anticipated event, especially as it finally returns to a live, in-person conference.

Sourced from Fortinet

Fortinet Recognized in the 2022 Gartner® Market Guide for Digital Experience Monitoring

Recently, Gartner released its 2022 Market Guide for Digital Experience Monitoring. This report includes a detailed market analysis, strategic recommendations, and a list of Representative Vendors for digital experience monitoring (DEM). We’re pleased to report that Fortinet’s product FortiMonitor was recognized as supporting two of the three most common use cases for DEM: Endpoint Monitoring and Synthetic Transaction Monitoring.

Getting the User’s Point of View Through Digital Experience Monitoring

With the increase in remote work and the migration of applications to the cloud, customer and employee digital experience has never been more critical to business success. With people working from anywhere, IT staff can no longer simply walk down a hall and visit an employee’s cubicle to troubleshoot problems. To remain productive, remote workers need access to an array of cloud applications.

Because of the pandemic, many business models and workloads have shifted to the cloud as well. The continuing growth of many organizations depends on customers and employees having an exceptional experience. But to understand the user experience, you need to be able to tell what’s going on from their point of view. According to Gartner, “by 2026, at least 60% of infrastructure and operations leaders will use DEM to measure application, services, and endpoint performance from the user’s viewpoint, up from less than 20% in 2021.”

What Is Digital Experience Monitoring?

Because users, applications, and workloads can be anywhere, organizations need DEM solutions to help them troubleshoot issues. With more insight into where the issues are located, IT can fix problems before it affects users. Keeping users connected to their workloads preserves the digital experience for both customers and employees.

Without the right tools, infrastructure and operations teams often struggle to view, measure, and troubleshoot the employee and customer experience. DEM solutions show how users interact with applications and devices. In the report, Gartner recommends that organizations implement DEM solutions to:

  • Reduce the time to troubleshoot user-to-application performance issues 
  • Optimize user-to-application experience and reduce risk of downtime
  • Gain proactive insights about SaaS performance and address issues before users are impacted

How Fortinet Can Help With Digital Experience Monitoring Needs

As organizations embrace digital acceleration, they adopt new network edges, including LAN, WAN, 5G, remote workers, and clouds. And as part of this process, they often unintentionally create complex, vulnerable network environments that are difficult to manage, secure, and monitor.  

Fortinet’s Security-Driven Networking approach offers SD-WAN, NGFW, SWG, ZTNA enforcement, LAN edge, and wireless WAN 5G/LTE all integrated into a single solution and is the industry’s only converged networking and security platform capable of effectively defending today’s highly dynamic environments. Fortinet’s Network Operations solution simplifies and automates network security management across all network edges in a single console, while enabling visibility into the attack surface and the end-user’s digital experience. 

As part of Fortinet’s Network Operations product portfolio, FortiMonitor empowers IT with performance monitoring of the Fortinet Security Fabric and beyond, delivering insights across heterogeneous and distributed networks to ensure seamless user-to-application interactions.

In the Gartner report, Fortinet was recognized as a Representative Vendor in two of the three DEM technology categories: endpoint monitoring and synthetic transaction monitoring. Our product FortiMonitor provides end-to-end visibility into the overall user experience, no matter where the user resides or where the application is hosted. 

A comprehensive, vendor-agnostic solution, FortiMonitor provides health and performance metrics for FortiGate Next-Generation Firewalls and other Fortinet devices, plus other vendor network devices, infrastructure, cloud service/applications, and user devices, all from a single, SaaS-based monitoring solution.

With FortiMonitor, IT teams can correlate end-to-end performance metrics and more quickly troubleshoot technology issues. FortiMonitor helps bring IT teams together with insights to remediate issues before they affect users and to optimize the employee digital experience, improving business outcomes. It can track the path that data takes from endpoint devices through local networks, VPNs, remote offices, SD-WAN, and on-premises and cloud-based services and applications. Synthetic transaction monitoring (STM) runs from global public nodes, private networks, and employee devices to simulate user transactions. These synthetic checks provide insights into performance at each step throughout a service, so the source of performance issues with SaaS and native applications can be identified, areas for optimization can be proactively addressed, and user experience continuously improved.

To learn more about digital experience monitoring and how you can use DEM solutions to gain visibility into the user experience from the user to the application, including endpoint device, network, application, and infrastructure performance, read the new Gartner® report.

Gartner, Market Guide for Digital Experience Monitoring, 28 March 2022, Mrudula Bangera, et. al.

Gartner is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally, and is used herein with permission. All rights reserved.

Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

Sourced from Fortinet

Not All Firewalls Can Do Zero Trust (But Ours Can)

Zero trust should be a part of any cybersecurity strategy. Because of the increase in the number of Internet of Things (IoT) devices, the fragmenting of the network perimeter, and the new norm of work from anywhere, secure access is more critical than ever. Today’s shifting work and resource structures require security solutions that can span all locations, and zero trust is essential.

To protect systems, networks, applications, and data, companies must take a zero-trust approach to security by implementing strong authentication capabilities, network access control technologies, and pervasive application access controls. When evaluating security products, the solution should be able to provide traffic SSL decryption and zero-trust capabilities for both cloud-based assets and on-premises assets, including providing the internal segmentation and zones of control.

Recently, concerns have been raised about the ability of firewalls to support a zero-trust environment. And that may be true of some next-generation firewalls (NGFW). They aren’t up to the task, particularly in terms of performance if they have SSL decryption turned on. But to discount firewalls entirely is a mistake. If you have the right NGFW with zero-trust network access (ZTNA) built-in across all form factors, you can leverage its extensive capabilities to control access for everyone across an extended network, covering both cloud and on-premises-based applications.

Fortinet NGFWs have unique strengths in supporting zero trust and being part of a complete cybersecurity solution for hybrid networks. No other firewall has ZTNA built-in, or custom security ASIC chips with hardware accelerators for the SSL decryption process.

Here are a few reasons why organizations need ZTNA and the risks the wrong solution can pose to your business.

Risks of Not Having ZTNA

Expanded Attack Surface

Networks are more distributed with more edges than ever before. Because of the pandemic, the walls separating the home and the corporate office have eroded, which has given cybercriminals new, easily exploited ways to gain a foothold into the corporate network. Remote work has led to devices operating outside the corporate network perimeter, significantly expanding the attack surface. Networks are exposed to increased risks because home networks are often poorly secured. Because the same devices that are used to remotely access the corporate network are also being used to access the internet without the protections of the corporate firewall, connected resources are exposed to potentially malicious content. When employees travel, these devices are also used to connect to corporate resources through unsecured public access points.

With ZTNA, users and devices can’t access an application unless they provide the appropriate authentication credentials. ZTNA places applications behind a proxy point, creating a secure, encrypted tunnel for connectivity. Unlike a traditional VPN tunnel that provides unrestricted access to the network and applications, ZTNA connections are granted to individual applications per session. Access is granted only after both the device and user have been verified. Because location is no longer a reliable indicator for access as it is with a VPN, ZTNA policy is applied whether users are on or off the network.

Inconsistent Security

ZTNA should be something that users don’t have to think about. It should work the same way, no matter where the user or the applications happens to be physically located. However, many organizations use different products to secure access when people are working remotely versus in the office. They may use a cloud-based ZTNA service for remote workers but use a different approach for on-premises security. It’s inefficient to use different products and it’s also less secure because it increases complexity and reduces visibility. IT staff must use multiple consoles or dashboards that aren’t integrated and deal with separate policies in multiple places. This lack of central management increases the likelihood of human error and misconfiguration.

User productivity is also affected when accessing applications isn’t the same for the user when they are working from the corporate office and away from it. Inconsistent access can lead to confusion or frustration, particularly if one of the products is challenging to use.

ZTNA should work the same way no matter where the applications or the users may be located. Setting up universal ZTNA with a FortiGate ensures that consistent policies and controls span across all of the operating environments, including across multiple clouds. The same adaptive application access policy is used whether users are on or off the network because ZTNA is built in to FortiOS. This integration with the Fortinet Security Fabric simplifies management and visibility across the network. ZTNA can be implemented incrementally by simply changing settings, so organizations can start with one section of the network or implement specific zero-trust capabilities and add more over time.

Increased Costs and Complexity

Far too many organizations add security onto the network as an afterthought, creating unnecessary complexity and weaker security postures. Essential technologies such as centralized management, integrated network, security operations center solutions, and AIOps are impossible to implement in a fragmented security environment.

According to a Ponemon Institute report, on average, organizations have deployed more than 45 security solutions across their organizations. Because these solutions operate in silos, it adds to network complexity, often using integration workarounds that require constant adjustments. And according to a Fortinet survey, 82% of IT teams with 10 or more security vendors in place spend at least 30% of their time addressing issues related to vendor complexity. Siloed security solutions almost inevitably lead to higher licensing costs and increased workload from the need to respond to security alerts and incidents that cannot be automated.

The Fortinet ZTNA solution simplifies security with a single access policy for all locations managed centrally. And because a firewall performs the ZTNA enforcement, all of the firewall policies can be enforced on that traffic as well.

Lateral Threats

When networks are set up as a flat, open environment without any security inspection past the perimeter, hackers who manage to breach the network perimeter can easily move laterally to seek valuable resources, sow malware, and disrupt business. Replacing perimeter-based VPNs with the zero-trust model provided by ZTNA ensures that whenever a user or device requests access to a resource, they are verified before access is given.

Incomplete Security

Although ZTNA is often associated with cloud application access, many organizations don’t have all their applications in the cloud. Users require access to cloud applications, but they often need access to applications located at a data center or branch location as well. For complete security, ZTNA should be used everywhere. It shouldn’t matter where the applications or the users are located. Having ZTNA everywhere ensures consistent policies and controls across all operating environments. For ZTNA to be everywhere, it can’t be a cloud-only solution. Firewall-based ZTNA provides universal coverage for all hosted locations, including SaaS applications.

The Right Solution for ZTNA Everywhere

Firewalls aren’t all created equal, but if you have a FortiGate, you’ve taken the first step toward ZTNA everywhere. Fortinet uses the client-initiated ZTNA model, which uses an agent on a device to create a secure tunnel. With FortiOS version 7.0 and above, a Fortinet infrastructure can be turned into the newest part of a zero-trust architecture. FortiGate NGFWs and FortiClient endpoint protection employ ZTNA capabilities with simplified management. The same adaptive application access policy is used whether users are on or off the network because ZTNA is built in to FortiOS.

Because the ZTNA components are tightly integrated into the Fortinet Security Fabric, management and visibility across the network are simplified. By starting with a firewall and assembling the other pieces of the ZTNA solution under the umbrella of a single, integrated platform, organizations can implement zero-trust strategies that work no matter where their users, devices, or resources may be located.

Learn more about how Fortinets ZTNA solution improves secure access to applications anywhere, for remote users. 

Sourced from Fortinet

Securing Hybrid IT is a Reality, Embrace it with FortiGate NGFW

Much has been written about how some applications and data have moved out of the corporate data center to the cloud. And now, after years of hype, cloud adoption has passed the “gee-whiz” novelty phase and reached a level of maturity. The pandemic required workforce and technology changes that accelerated the move to the cloud. Gartner reports that 65.9% of spending on application software will be directed toward cloud technologies in 2025, rising from 57.7% in 2022.

The cloud has many benefits. But despite what many vendors imply, it’s certainly not the only technology enterprises are using. On-premises deployment can offer better customization and flexibility of upgrades and security than cloud.

Another very important dimension is the speed and scale that on-premises applications offer to end-customers, partners, and corporate users. Additionally, these applications must meet some SLAs and deliver the optimal user experience that was available before any security solution was deployed.

At many enterprises, applications and data aren’t contained solely in the cloud or exclusively within a corporate data center. They are distributed across hybrid multi-cloud and data center networks that are in a constant state of flux. With this ever-expanding and highly dynamic attack surface, organizations need to provide consistent security and policy everywhere to defend against attacks yet still retain the flexibility to adjust to rapidly changing business requirements.

Hybrid IT Needs Consistent Security Everywhere

Hybrid networks make sense for many organizations because they can take advantage of the strengths of a given technology where it’s appropriate. In situations where flexibility and scalability are critical, the cloud is a good option. But for workloads where the administrative control, compliance, or unpredictable costs from a cloud provider are a concern, keeping workloads on-premises is a better choice. Data plays a critical role in this dichotomy and weighs in on any decision to move any application to cloud with a plain question: Is this data going with the application or staying locally – now or for the foreseeable future?

Although hybrid networks have advantages for the business, they also significantly increase the attack surface, leaving it more vulnerable to increasingly diverse and sophisticated cyberattacks. Today, organizations need to secure more locations, devices, applications, and services than ever before. The environment is also in a state of constant flux; and as the network perimeter has become more fragmented, many organizations end up with security teams and tools operating in silos, which limits visibility and control.

In a hybrid network, security needs to be everywhere and able to adapt as the network it is protecting continually expands and adjusts to shifting business requirements. Data may reside across the distributed networks and edges created by the Internet of Things (IoT) and mobile end-user devices. Additionally, because of the increase in remote and mobile workers, the security policies and enforcement need to follow both applications and workflows.

Instead of using multiple single-purpose security products that increase complexity and make sharing of threat intelligence almost impossible, organizations should look for a unified platform solution that converges security and networking. This platform should start with a next-generation firewall (NGFW) capable of securing hybrid networks. FortiGate NGFW enables organizations to secure any network edge at any location, providing more visibility and coordinated end-to-end security with AI/ML-powered FortiGuard services. Delivering consistent policy and optimal user experience, the FortiGate NGFW is designed to secure hybrid IT architectures by offering additional applications that provide:

  • Converged networking and security that culminates as integrated zero trust network access and provides the foundation to build a zero-trust strategy
  • Seamlessly integrated SD-WAN capabilities that include advanced routing capabilities that make it possible for it to peer with wide-area network (WAN) providers and interconnect with a wide array of local-area network (LAN) vendors
  • Ultra-high scalability with purpose-built security processing units (SPUs)
  • Contextual threat intelligence sharing while acting as a core component of the Fortinet Security Fabric to make effective security decisions
  • Visibility with high-performance SSL inspection and the ability to detect threats in encrypted paths without performance degradation. Post decryption is augmented with advanced content and web filtering capabilities
  • Flexible and dynamic micro- and macrosegmentation to help prevent the lateral spread of malware
  • Unified management, automation, and orchestration across the Fortinet Security Fabric for a unified security strategy that is designed to span dynamic, hybrid environments

FortiGate NGFWs for Secure Hybrid IT

Today’s hybrid networks require consistent security everywhere, but most security solutions aren’t designed with networking in mind and most networking solutions do not have security that is natively integrated. Organizations with hybrid networks need to establish and maintain consistent security across the network with consistent protection, visibility, and control across even the most distributed and dynamic environments. Additionally, the organizations need to provide granular access control to applications with dynamic trust, constant authentication, and posture check.

With multiple form factors, the FortiGate NGFW can operate at any edge to integrate networking and provide consistent policy enforcement, easy-to-manage centralized policy orchestration, real-time intelligence sharing, and correlated threat response.

Learn more about FortiGate NGFW solutions and the FortiGate 3000F.

Sourced from Fortinet

How Fortinet’s Security Awareness Training Can Help Protect Employees

Over the past two years, we’ve seen a number of developments across the threat landscape coupled by the increased hybrid workforce that have created tremendous urgency for organizations to up their game when it comes to security awareness training. At Fortinet, we believe that all organizations should be deploying awareness programs for all employees and users to truly protect their most-important digital assets and as part of their security strategy. These programs must be designed in a programmatic way to prove effective in changing employee behavior whereby employees are more cyber aware and able to spot malicious threats and other risks for their organizations. 

Today, Fortinet introduces a new Security Awareness and Training service to provide organizations further protection against threats through employee training and education.

Risks Resulting From the Evolving Threat Landscape and Hybrid Workforce

The intensifying threat landscape complicated by the shift to hybrid workforces has made it even more challenging for organizations to protect their digital assets. There’s been a tremendous increase in the intensity of the threat landscape over the last 24 months. IT and security teams saw huge increases in phishing, impersonation, and ransomware attacks, with ransomware rising to be the chief concern for these professionals. For instance, according to the Verizon Data Breach Investigations Report for 2021, phishing’s involvement in successful breaches jumped to 36% versus 25% in the prior reviewed period. Impersonation rose by 15x. And ransomware’s involvement in successful breaches doubled to 10%. Separately, Fortinet’s threat research group, FortiGuard Labs, saw a 10.7x increase in ransomware attacks hitting devices over the June 2020 to June 2021 period.

At the same time, the traditional workday has fundamentally changed with the significant increase in remote and hybrid work as a result of the pandemic. For instance, in Upwork’s “Future Workforce Report 2021: How Remote Work is Changing Businesses Forever,” the authors conclude: “Our study predicts that fully remote workers will represent 27.7% of the workforce, compared to 20.4% who will be partially remote. Both numbers have increased from when we last ran this survey in November 2020.” These two factors have resulted in cyber attackers focusing on social engineering, phishing tactics, and more toward employees who can many times be an organization’s weakest link.

Introducing the Fortinet Security Awareness and Training Service

Employees represent high-value targets for threat actors. As a result, organizations can’t overlook the risk introduced by an untrained workforce where a simple error or moment of poor judgment opens to the door to a threat actor.

Created by the Fortinet Training Institute, the new Security Awareness and Training service helps IT, security, and compliance leaders build a cyber-aware culture where employees recognize and avoid falling victim to cyberattacks. For compliance-sensitive organizations, the service also helps leaders satisfy regulatory and industry compliance-training requirements. Benefits of the new service include:

  • Curriculum from the award-winning Fortinet Training Institute: The service is designed by the Fortinet Training Institute, which provides cybersecurity certification and training through its various programs.
  • Alignment to NIST 800-50 and NIST 800-16 guidelines: The service is aligned to the National Institute of Standards and Technology (NIST) guidelines NIST 800-50 and NIST 800-16, providing training and awareness that is engaging and relevant on topics such as: information security, data privacy, physical security, password protection, and internet security.
  • Intelligence-driven training: Leveraging FortiGuard Labs threat intelligence, the Security Awareness and Training service provides training informed by developments observed across the threat landscape. 

Confidence in Trained Employees

In Fortinet’s 2022 Email Security Report, we asked IT and security professionals how confident they were in their employees’ ability to spot a malicious email. Surprisingly, 88% indicated they were “Moderately” to “Extremely” confident in their employees. Meanwhile, 66% indicated that their confidence had grown in the last 12 months.

Why is confidence so high? We then inquired as to what security awareness and related capabilities were organizations using. You can see the results below.

As you can imagine, respondents may be using one, two, or all of these capabilities to train employees.

From these results, we can extrapolate that IT and security professionals are seeing a clear, positive impact to their organizations in terms of a reduction in the risk of a major breach, and as likely, a reduction in the burden on IT caused by HelpDesk inquiries, such as the remediation of compromised systems and other lower-impact employee-created problems.

Not All Security Awareness Training Is Equal

It’s important to give credit to various compliance frameworks that require many organizations to conduct security awareness training as part of their controls requirements. Some of these frameworks will likely become more detailed in their requirements or recommendations in the future for how organizations should conduct security awareness training. In fact, in PCI DSS version 4.0, requirement 12.6.3, published March 2022, does a considerable job of outlining best practices for security awareness training for organizations subject to PCI DSS, expanding significantly on this topic versus version 3.2.1

However, not all security awareness training works to change behavior and turn your workforce into part of your overall security posture. We see many organizations take a minimalist approach to security awareness training. Usually, this is the result of a reactive approach to security that is likely complying with some type of requirement their organization is being subjected to by a partner or by some type of regulatory or industry compliance framework.

To change behavior, IT and security teams need to apply a programmatic approach. This approach involves conducting numerous touch points, formats, and tools across a span to educate, test, and reinforce as well as adapt learning to achieve the desired outcome. This is where Fortinet’s new Security Awareness and Training service can help organizations implement a unique training program for all employees to be cyber aware.    

Conclusion

At Fortinet, our own guidance is that all organizations should have a security awareness training program in place that achieves the aim of changing employee behavior and helps IT and security teams enhance their organizations’ overall security postures. This is best done through a programmatic approach that is ongoing, incorporates a number of elements to educate, test, reinforce, and adapt learning to address changes in the overall threat landscape as well as the needs of the organization’s risk profile. Learn more about Fortinet’s new Security Awareness and Training service to help achieve exactly that.

Learn more about the Fortinet free cybersecurity training initiative and Fortinet’s Training Institute, including the NSE Certification program, Academic Partner program, and Education Outreach program which includes a focus on Veterans.

Sourced from Fortinet

CISO Q&A: Convergence, Consolidation, and FortiOS

Whether it’s a new project, procedure, or branch location, business changes depend on a fast, secure network. And supporting major digital initiatives such as work from anywhere (WFA) or converging IT and OT networks require organizations to look closely at both the operational and security implications. As organizations move forward with projects that affect the network, they need to ensure their security can keep up with today’s complex and fast-evolving threats.

Fortinet Field CISOs, Joe Robertson, Ricardo Ferreira, and Alain Sanchez share their perspectives about how organizations can stay ahead of challenges such as new, automated attacks, the expanding attack surface, and networking and security silos. 

Why is the convergence of networking and security so important today?

Joe: For most organizations, networks and security were separate for a long time. But that was an artifact of technology history, not because they were fundamentally different environments. When you think about it, every threat traverses a network somewhere, so the network is the logical place to catch, block, and quarantine threats and malware.

The convergence of security and networking is extremely logical and has been coming for a long time now. In fact, when Fortinet started over 20 years ago, this convergence of the network and security was part of Ken Xie’s vision when he founded the company.

Ricardo: I agree. If you look at cybersecurity trends, you realize that there’s an increased need to protect data, people, and devices everywhere. When computers were linked to just a set of ethernet cables and a server somewhere, there was relatively minimal danger of attack. But now, every human being has two or three devices, and they can connect to almost anywhere in the world and be connected from almost anywhere. Networks are a victim of their success. The growth and distributed nature of networks now mean more people and devices are exposed to more threats from bad actors. The explosion of network edges, new environments, new types of clouds, and endpoints means we can’t have the same security mindset we had a few years ago. Now we need to have real-time security to be proactive in our defense.

Alain: Every convergence carries change. Remember the big wave created by voice and data convergence? Not only does it affect the infrastructure, the management platform, but also the organization, the team, the budget, and the policy. In the case of networking and security, we’re even reaching the next level of change. Such ability to literally embed security in the network unleashes creativity. CISOs can become the “inspirers” in an organization. Like a race car with excellent brakes, the converged security and network discipline, can turn the corner of innovation faster.

The terms consolidation and convergence are often used interchangeably. Could you explain the difference?

Joe: Convergence is about different interacting technologies that are no longer separated. I mentioned the convergence of networking and security, but you also see convergence in networks that connect with each other, such as the convergence of operational technology with traditional IT networks.

Consolidation is something totally different. It is talking about product consolidation. For example, your organization might have a lot of products from different vendors in the network environment. Each of those products behaves differently and has different interfaces, management consoles, and configuration methods. Having so many products makes it difficult for the technical team to manage everything. So consolidation is about reducing the number of vendors, so there are fewer consoles and interfaces to deal with. Of course, the assumption is that a given vendor uses a single interface for multiple types of security or network devices.

Ricardo: Risk management can be an important aspect of consolidation. Risk management is a top priority for CISOs; as such it’s important to have a consolidated single source of truth that shows the risk profile, so data-driven security decisions are appropriate to the organization’s risk appetite. Consolidating products also consolidates security data sources across your environment, to be viewed through a single dashboard.

Joe: Also, in a highly regulated environment, such as banking, having documentation of your status and proof that you are following the regulations is essential. Providing proof of compliance is easier to do in a consolidated environment than if you’ve got dozens of different devices. And because environments are so dynamic, having real-time visibility into your risk and compliance posture is critical.

Alain: Consolidation addresses a particular pain point of the IT and security community: too many point solutions, too many platforms, too many correlations to make between heterogeneous platforms. The typical number of different network and security vendors averages 60. Convergence calls for a multi-domain convergence that, as said earlier embraces technology, protocols, but also operations and budget planning.

How can you detect unknown threats before they infiltrate the network?

Alain: Artificial intelligence (AI), and more specifically Machine Learning (ML), play a significant role as a proactive detection defense line. The main idea is to create a map of what baseline traffic looks like. It’s like recognizing the way you drive, typical revs of changing gear, itinerary, parking habits. So that when the network is stressed in a different way the gap between baseline traffic and actual is detected. Someone might have stolen your car keys (access credentials in the IT world) and consequently gotten access to your car, but the way the vehicle is driven, it is clear, it is not you.

Ricardo: As threats evolve, it’s essential to have a platform powered by artificial intelligence that consumes security-enriched data such as threat intelligence. In FortiOS 7.2, platform features like in-line sandboxing, inline CASB, advanced protection for OT and IoT, and many others consume threat intelligence data from Fortiguard Labs. Fortiguard Labs analyzes more than 100 billion security events per day, which are translated into security-enriched data to detect unknown threats, contributing to an organization’s resilience.

The other benefit is that automation with AI improves scalability. If you are relying only on people to review logs or risk profiles, it doesn’t scale. But automating with AI using the threat intelligence from FortiGuard Labs helps ensure that the platform can react proactively to those threats and block them effectively.

How are threats evolving?

Joe: Something you need to keep in mind is the dwell time of an attacker. That’s the amount of time an attacker has access to the network and is rooting around in it. The problem is that in the past, dwell time was measured in months. Reducing that time period to days, hours, or minutes is one of the significant advances of FortiOS 7.2.

Because the rate of exploit is increasing and attacks are happening more quickly, there’s simply too much data for people to go through in a security operations center (SOC). That’s why using AI and ML to stop unknown threats is so important.

Ricardo: Building on what Joe said, according to the Global Cybersecurity Outlook 2022 from the World Economic Forum, the average time it takes an organization to detect a threat is more than 280 days. Think about the damage an attacker can do with access to systems in all that time. That statistic highlights the need for automation with AI and ML to detect novel threats but also to counteract existing threats. People tend to forget about the old threats, but if you look at statistics from FortiGuard Labs, new threats are present, but outdated threats are still making the rounds as well. They don’t just go away. Attackers continue to use old methods because those old methods still work when people don’t patch or update their systems.

Joe: Another reason for the AI advancements in FortiOS 7.2 is because the bad guys are using AI too. They are using it to create new malware variants. They’re creating not just hundreds but thousands and tens of thousands of versions of the same malware that’s just different enough that signature-based tools don’t detect it. That’s why we need to use AI to catch the malware that’s being generated by AI.

Alain: A next generation of threats are emerging that take advantage of the very innovation that propels digital acceleration. In this perspective Log4j is quite representative of this new generation of threat. For starters, being able to reproduce in a remote server all the conditions of a crash is extremely useful. Like the forensic police would take notes, pictures, and samples of a crime scene to make sense of it all in a remote lab, the process exploited by the Log4j attack weaponizes this process. Today we are witnessing a whole family of attacks that turn innovation into weapons. Hence the importance of a holistic cybersecurity platform that addresses the various steps involved in the attack scenarios.

Sourced from Fortinet

The Battle of AI & ML in the Cybersecurity World

CTO Collective Series

Whether we realize it or not, artificial intelligence (AI) and machine learning (ML) play a part in every second of our lives. From the moment we wake, smart devices decide what time to turn on our heaters and our lights, social media uses complex algorithms to select what news to promote to us, and Google Maps navigates us through our day. Even while we sleep, AI monitors our sleeping patterns—with the proliferation of smart devices like Google Home and Apple Watches—identifying when we have had a good night’s sleep and even monitoring our health.

ML and AI in our daily lives have slowly changed how we interact with technology. We use this technology for good by helping the elderly with virtual chatbots, preventing poaching, and providing real-time translation for migrants.

The cybersecurity world has been at the forefront of this technology in the last decade, using ML/AI in various applications such as tackling huge volumes of malware, detecting spam and business email compromises, analyzing network traffic, using facial recognition, and more. It’s hard to get away from a vendor’s presentation without hearing about their ML and AI nowadays. This blog will demystify and hopefully bring some new angles to our readers in the decision-making around “ML-enabled” security solutions.

What Are ML and AI?

Let’s start with simple definitions of machine learning and AI. Machine learning involves enabling computers to learn how to do something. This requires input such as training data and knowledge, while AI is the goal of applying the knowledge learned. AI attempts to solve data-based business or technical problems, assisting users in the decision-making process or making judgment itself (if we programmed it in such a way). When it needs to, it can be used to rapidly analyze large sets of data that no human brain could possibly process and can come up with AI-assisted decisions and conclusions on an issue. 

Is AI perfect? Not always. Any computer program is only as good as its writer, and any ML or AI is only as good as the information it has been fed. There are well-known examples of programmatic biases in some AI algorithms and examples where chatbots have gone rogue after being trained with the wrong data. So, while there is still work to be done, these algorithms can deliver significant benefits over even more fallible humans.

AI-Driven Malware – Myth or Reality?

Despite a large amount of hype and clickbait, there is little evidence to support the belief that criminal cyber gangs are already using AI to help generate new strains of malware, however there is evidence that AI/ML is being used in other areas to circumvent protective security measures:

  • Generating deep fake videos and images to phish users and bypass security measures. This is particularly prevalent on social media sites to create fake identities.
  • Solving CAPTCHAs to bypass authentication protections.
  • To gather open source intelligence on organizations in order to target attackers.

AI in Defensive Security: Use Case Is King

When considering investment priorities among security solutions, evaluate the use cases you’re trying to achieve. Understand how threats are evolving and what tactics and techniques black-hats use. Then ask why you couldn’t stop these attacks with the investment you have so far. It’s pretty easy to get caught up with the AI/ML hype. But customers are starting to move cleverly to consider practical use cases, whether this is detection, forensic, hunting, or mitigation.

How Does Fortinet Use AI?

The big change in the malware industry that triggered the need for AI was heuristics and adaptive malware. We went almost overnight from a volume of malware that could be handled manually to a situation with exponential growth in the number of samples. We had to adapt and take advantage of AI and ML to support our malware analysts.

Fortinet has been in the AI business for more than a decade. At a high level, Fortinet uses AI and ML in multiple areas:

Video Overview: Use of ML & AI across the Fortinet Security Fabric platform

Find out how the Fortinet Security Fabric platform delivers broad, integrated, and automated protection across an organization’s entire digital attack surface to deliver consistent security across all networks, endpoints, and clouds. Explore how Fortinet is revolutionizing security operations with self-learning AI.

Sourced from Fortinet

AI (Artificial Intelligence) and Machine Learning in the Cybersecurity Battle

The Role of Artificial Intelligence and Machine Learning

Whether we realize it or not, artificial intelligence (AI) and machine learning (ML) play a part in every second of our lives. From the moment we wake, smart devices decide what time to turn on our heaters and our lights, social media uses complex algorithms to select what news to promote to us, and Google Maps navigates us through our day. Even while we sleep, AI monitors our sleeping patterns—with the proliferation of smart devices like Google Home and Apple Watches—identifying when we have had a good night’s sleep and even monitoring our health.

ML and AI in our daily lives have slowly changed how we interact with technology. We use this technology for good by helping the elderly with virtual chatbots, preventing poaching, and providing real-time translation for migrants.

The cybersecurity world has been at the forefront of this technology in the last decade, using artificial intelligence and machine learning in various applications such as tackling huge volumes of malware, detecting spam and business email compromises, analyzing network traffic, using facial recognition, and more. It’s hard to get away from a vendor’s presentation without hearing about their ML and AI nowadays. This blog will demystify and hopefully bring some new angles to our readers in the decision-making around “ML-enabled” security solutions.

What Are Machine Learning and Artificial Intelligence?

Let’s start with simple definitions of machine learning and artificial intelligence. Machine learning involves enabling computers to learn how to do something. This requires input such as training data and knowledge, while AI is the goal of applying the knowledge learned. AI attempts to solve data-based business or technical problems, assisting users in the decision-making process or making judgment itself (if we programmed it in such a way). When it needs to, it can be used to rapidly analyze large sets of data that no human brain could possibly process and can come up with AI-assisted decisions and conclusions on an issue. 

Is artificial intelligence perfect? Not always. Any computer program is only as good as its writer, and any ML or AI is only as good as the information it has been fed. There are well-known examples of programmatic biases in some AI algorithms and examples where chatbots have gone rogue after being trained with the wrong data. So, while there is still work to be done, these algorithms can deliver significant benefits over even more fallible humans.

AI-Driven Malware – Myth or Reality?

Despite a large amount of hype and clickbait, there is little evidence to support the belief that criminal cyber gangs are already using AI to help generate new strains of malware, however there is evidence that artificial intelligence and machine learning are being used in other areas to circumvent protective security measures:

  • Generating deep fake videos and images to phish users and bypass security measures. This is particularly prevalent on social media sites to create fake identities.
  • Solving CAPTCHAs to bypass authentication protections.
  • To gather open source intelligence on organizations in order to target attackers.

AI in Defensive Security: Use Case Is King

When considering investment priorities among security solutions, evaluate the use cases you’re trying to achieve. Understand how threats are evolving and what tactics and techniques black-hats use. Then ask why you couldn’t stop these attacks with the investment you have so far. It’s pretty easy to get caught up with the AI/ML hype. But customers are starting to move cleverly to consider practical use cases, whether this is detection, forensic, hunting, or mitigation.

How Does Fortinet Use Artificial Intelligence?

The big change in the malware industry that triggered the need for AI was heuristics and adaptive malware. We went almost overnight from a volume of malware that could be handled manually to a situation with exponential growth in the number of samples. We had to adapt and take advantage of artificial intelligence and machine learning to support our malware analysts.

Fortinet has been in the AI business for more than a decade. At a high level, Fortinet uses artificial intelligence and machine learning in multiple areas:

Video: artificial intelligence and machine learning across the Fortinet Security Fabric

Find out how the Fortinet Security Fabric platform delivers broad, integrated, and automated protection across an organization’s entire digital attack surface to deliver consistent security across all networks, endpoints, and clouds. Explore how Fortinet is revolutionizing security operations with self-learning AI.

Read more from the CTO Collective series.

Sourced from Fortinet