FortiOS 7.2: Enhancing the Only Converged Networking and Security Platform Available Today

The Fortinet Security Fabric is the industry’s first—and only—platform to converge essential networking and security functions and consolidate security point products into a unified platform. And now, Fortinet has announced the release of FortiOS 7.2, which widens that leadership position even further. With over 300 new features spanning the Fortinet portfolio—including new advanced AI-powered services that accelerate the detection and response to threats—FortiOS is better positioned than ever to secure the hybrid networks that organizations rely on to compete in today’s digital marketplace.

Today’s Network Is Different, Not Dead

Too many organizations hear that everything is moving to the cloud. And that as a result, the traditional network will soon be dead. But nothing could be further from the truth. And worse, buying into that myth is putting organizations at risk.

Of course, networks are vastly different from just a few years ago. Digital acceleration has enabled users and devices to access critical resources from any location, fundamentally changing how businesses operate. But this need for consistent user experience does not require them to abandon their networks. Instead, organizations worldwide and across all industries are building hybrid networks that interconnect traditional data centers and campuses with multi-cloud infrastructures, SaaS platforms, branch offices, home offices, and mobile users and devices.

Brandon Butler, a Senior Research Analyst at IDC, recently stated, “The network is foundational for enabling secure, scalable, and efficient use of cloud, edge, and IoT applications.” So, rather than dying, hybrid networks are the enablers of digital acceleration. They allow applications and workflows to move seamlessly from end to end and be accessed by any user or device from any location.

However, organizations need to stop thinking about networking and security as separate strategies to do this effectively. Instead, securing their digital acceleration efforts requires infrastructure and security teams to converge their visions. As applications continue their cloud journey and devices become increasingly visible to everyone, secure networks are vital to connecting these domains.

But to do this, enterprises, small businesses, and service providers alike need to replace isolated point devices that only address a portion of the network with solutions designed to operate as part of an integrated fabric that can see and adapt to the broader network. As network edges and dynamic infrastructures evolve, single-purpose and isolated security solutions only make it more difficult for organizations to deploy and maintain a cohesive and comprehensive security strategy. Instead, organizations must adopt a platform approach that converges operational efficiency and security automation with the underlying network.

The Only Platform Designed to Fully Protect Today’s Hybrid Networks

The Fortinet Security Fabric is the only platform designed to fully protect and dynamically adapt to today’s hybrid networks at any edge, and FortiOS 7.2 is the heart of that platform. FortiOS enables organizations to deploy the Fortinet Security Fabric to every edge, allowing security to dynamically scale and adapt as the network evolves. This expansive, integrated approach also enables the delivery of AI-powered automation that correlates intelligence from across the network and global threat feeds to rapidly detect even the most sophisticated threats and respond in real time.

FortiOS 7.2 enhances the Security Fabric’s award-winning functions and services by extending the definition of what’s possible in networking and security, thereby enabling customers and partners to safely and effectively compete in today’s digital marketplace. And for the foreseeable future, those businesses will rely on hybrid networks. But only by integrating security at the core of those networks will they be able to adapt at speed and scale to secure every edge. Over 20 years of prioritizing research and development have positioned Fortinet as the driving force behind cybersecurity innovation. With FortiOS 7.2, Fortinet is setting new industry standards for converged networking and security. 

High-performance AI-powered threat intelligence and services 

New AI-powered FortiGuard Security Services enable organizations to automate their security systems to stay ahead of never-before-seen attacks, in real-time.  And one of the most significant enhancements is the speed and accuracy with which FortiOS 7.2 can detect and prevent threats, in a coordinated way across an organization’s extended attack surface.

Traditionally, performance-intensive activities like sandboxing suspicious files for out-of-band inspection resulted in a delay in delivering content or having to hunt down malware inside the network when a file turns out to be infected. FortiOS 7.2’s new inline sandbox service resolves this by transforming a traditional detection sandbox capability into real-time in-network prevention to stop both known and unknown malware, with minimal impact on operations. New inline CASB, dedicated IPS, advanced device protection for OT and IoT systems, and additional enhancements to our SOC services portfolio deliver advanced security services to improve our customers’ security postures. Because they are consumed as a service across the Fortinet Security Fabric and ecosystem, this guarantees real-time proactive updates with minimal impact to operations and simplified scaling. Additionally, our new outbreak detection service provides a faster response to outbreak attacks, including immediate alerts and threat hunting scripts that automatically identify and respond to new threats. In addition, all FortiGuard services are powered by trusted machine learning and artificial intelligence. Its accuracy and fidelity are further enhanced through FortiGuard Labs’ analysis of over 100 billion global security events a day observed in live production environments worldwide. 

The critical convergence of networking and security 

One of the most essential functions of a modern security solution is its ability to scale, span, and adapt to a continuously evolving hybrid network. Achieving this requires converging security with the network. Such convergence allows security systems to seamlessly adapt to network changes as it addresses continually evolving requirements. However, the challenge most organizations face is that few security solutions are genuinely able to provide this essential function.

Fortinet’s security-driven network approach was the first platform-based strategy to encompass the entire network development and deployment life cycle. Converging essential network and security functions ensures that security is the central consideration for all business-driven infrastructure decisions. As a result, new edges, applications, and services that expand your attack surface are automatically protected.

FortiOS 7.2 extends Fortinet’s innovation advantage even further by delivering new ways to converge networking and security across critical functions. New ZTNA enhancements make WFA deployments easier to deploy. Improvements to the industry’s most comprehensive portfolio of secure WAN edge solutions—SD-WAN, SD-Branch, 5G, and ZTNA—help teams achieve even better ROI. Advances in automation using new auto-deployment and zero-touch provisioning features increase uptime for the WAN and LAN Edge. And additional upgrades spread across NGFW, identity, micro-segmentation, SASE, AIOps and digital experience monitoring deliver powerful innovation for further networking and security convergence. 

Consolidating security increases efficiency, visibility, and control

Organizations that have taken a best-of-breed approach to security now face the challenge of vendor and solution sprawl. So, in addition to converging network and security, organizations must also begin consolidating the security products deployed across their ever-expanding attack surface to improve visibility, centralize management, orchestrate policy, and automate rapid threat detection and real-time response.

FortiOS 7.2 provides enhancements across Fortinet’s entire portfolio of network, endpoint, and cloud solutions that further consolidate security point products into a single broad, integrated, and automated platform. This deeper integration enables advanced vulnerability correlation and virtual patching to provide more comprehensive protection, including better security for IoT devices and advanced process automation so NOC and SOC teams can further simplify and automate their workflows.

In addition to FortiOS, the Fortinet Security Fabric platform is also built around common standards and open APIs that enable organizations to build a robust cybersecurity mesh architecture that includes investments in other security technologies. The Fortinet Fabric-Ready Technology Alliance Partner Program, one of the largest technology alliance ecosystems in the industry, brings together a community of global technology partners with specialized expertise. As a result of more than 400 integrations, customers can now more easily build a hybrid platform of integrated solutions to improve security effectiveness, reduce complexity, and simplify operations.

Fortinet’s Industry Leadership Enables Advanced Security Strategies

Fortinet’s commitment to innovation has led to the world’s most extensive and deeply integrated security and networking solutions portfolio. Our 1,255 patents are nearly three times that of comparable cybersecurity companies. We also regularly submit our products for impartial testing with the most prominent organizations in the industry. Those consistently top-tier results, combined with annual accolades and awards from leading analysts and industry organizations, and a strong commitment to R&D based in the United States and Canada, assure customers they can take a consolidated approach to security without ever sacrificing performance or protection.  

Join the FortiOS 7.2 webinar

Learn more about the latest converged networking and security innovations from Fortinet by joining the FortiOS 7.2 webinar on April 12.

Sourced from Fortinet

Fortinet Named a Gartner® Peer Insights™ Customers’ Choice for WAN Edge Infrastructure for Third Year in a Row

Fortinet Secure SD-WAN Receives Recognition from Analysts 

Fortinet was recognized as a Leader in both the 2021 Gartner® Magic Quadrant™ reports for Network Firewells and WAN Edge Infrastructure using the same FortiGate platform. Fortinet was also ranked first in three out of five Use Cases identified in the 2021 Gartner Critical Capabilities for WAN Edge Infrastructure. These include Security-Sensitive WAN, Remote Worker, and Small Branch WAN.

Similarily, Fortinet has been named a Leader in the IDC MaketScape: Worldwide SD-WAN Infrastructure 2021 Vendor Assessment (doc# US47279821, November 2021) report, and named a top vendor in the 2021 Frost Radar™: Global SD-WAN Vendor Market, 2021 report.

Customers Give Fortinet Secure SD-WAN Rave Reviews

But our greatest achievement, by far, are the glowing reviews we receive from customers of all sizes, both around the world and spanning all industries. In our opinion one way the industry measures customer sentiment is by reviewing the information collected on the Gartner Peer Insights site. Customers are able to rank and provide feedback for the solutions they have deployed in their networks. And when it comes to SD-WAN, we think Fortinet stands second to none, now being recognized for a third consecutive year as a Customers’ Choice for WAN Edge Infrastructure.

Here is a sample of some of the 5-star reviews that Fortinet’s Secure SD-WAN solution has received on the Gartner Peer Insights page:

This Network Engineer responsible for Enterprise Architecture and Technology Innovation, described deploying Fortinet SD-WAN in the United States for a firm with revenue of between $1B and $3B:

https://www.gartner.com/reviews/market/wan-edge-infrastructure/vendor/fortinet/product/fortigate-sd-wan/review/view/3901166

The Fortinet SDWAN project been a great experience! After evaluating several different vendor’s SDWAN solutions we choose Fortinet for the ease of deployment, all the SDWAN capabilities built into the standard licensing, all of which utilize the great FortiGate security features. … Not only do we maintain our security posture, but we get a huge performance boost in the WAN and Internet by being able to use the local egress for intensive products like video conferencing. The last thing I’ll note is the ease of deployment. Once a solid golden image has been created, rolling out to all the branch sites is as easy as loading the config and image onto a USB drive then powering on the FortiGate. The FortiGate automatically upgrades to your desired image code level then loads the golden config. At that point it’s a matter of moving your circuits and switches from the legacy solution to the FortiGate. Assuming you’ve done your homework and got all your IP’s correct, the VPN tunnels automatically establish and everything “just works” within minutes.”

This CISO at a major industrial organization—with revenue of between $1B and $3B—wrote about the experience of deploying Fortinet’s SD-WAN solution across locations in Austria, Germany, France, Chile, Vietnam, and Poland:

https://www.gartner.com/reviews/market/wan-edge-infrastructure/vendor/fortinet/product/fortigate-sd-wan/review/view/3818164

“Overall, we have had a positive experience with the FortiGate Secure SD-WAN. It helped us with cost reduction by reducing MPLS links. After the implementation project, we also faced an improvement in user experience with faster access to applications and reduced downtime. We were able to strengthen our business agility by applying consistent policies across our company.”

A Network Security specialist at a large bank in the UK with revenue of between $3B and $10B, explained:

https://www.gartner.com/reviews/market/wan-edge-infrastructure/vendor/fortinet/product/fortigate-sd-wan/review/view/3801856

“We have had a third party to come in and help with our SDWAN role out with Fortinet and have to say it’s very impressive (we really didn’t need the help it was that straightforward). Ease of use of the Fortinet is second to none and with the SDWAN capabilities being built on an underlying very good NGFW the security is great, reporting is great and visibility really good. Couldn’t recommend this product enough. Really good.”

A Cisco Network Engineer at a national insurance provider in the US with between $3B and $10B in revenue, wrote:

https://www.gartner.com/reviews/market/wan-edge-infrastructure/vendor/fortinet/product/fortigate-sd-wan/review/view/3896070

“Our overall experience has been fantastic. We had a couple of hurdles to jump over since we were migrating off a competitor solution that uses proprietary routing protocols, but overall, our migration has been seamless.”

And a System and Network Manager for a large retailer in France, $1B to $3B, described their experience with Fortinet’s SD-WAN solution this way:

https://www.gartner.com/reviews/market/wan-edge-infrastructure/vendor/fortinet/product/fortigate-sd-wan/review/view/3946164

“Installation is simple, fast, and easy to use. Administrators are quickly autonomous and have a good level of monitoring.”

We are honored to have been recognized as a 2022 Gartner Peer Insights Customers’ Choice for WAN Edge Infrastructure. When looking for a critical networking and security solution, peer reviews from organizations that are your size and in your own industry are invaluable. From our view, Gartner Peer Insights is an excellent source that provides that level of feedback.

To learn more about Gartner Peer Insights Customers’ Choice or to read the reviews written about our products by IT professionals, please see the WAN Edge Infrastructure page on Gartner Peer Insights

To all of our customers who submitted reviews, thank you! These reviews mold our products and our customer journey, and we look forward to building on the experience that earned us this distinction. If you have a Fortinet story to share, we encourage you to weigh in on Gartner Peer Insights.

 

1 Gartner, “Top Strategic Technology Trends for 2022: Cybersecurity Mesh, Felix GaehtgensJames HooverHenrique TeixeiraClaudio NeivaMichael KelleyMary RuddyPatrick Hevesi, 18 October 2021”

Gartner Peer Insights ‘Voice of the Customer’: WAN Edge Infrastructure, Peer Contributors, 24 March 2022

Overall Rating 4.6/5 based on 134 reveiwes as on December 2021.

2021 Gartner® Magic Quadrant for WAN Edge Infrastructure, September 2021, – ID G00736367 By Analyst(s): Jonathan Forest, Naresh Singh, Andrew Lerner, Evan Zeng

2021 Gartner® Critical Capabilities for WAN Edge Infrastructure, September 2021 – ID G00738187 By Analyst(s): Jonathan Forest, Naresh Singh, Andrew Lerner, Evan Zeng

Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s Research & Advisory organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences with the vendors listed on the platform, should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

GARTNER, PEER INSIGHTS, GARTNER PEER INSIGHTS CUSTOMERS’ CHOICE BADGE and MAGIC QUADRANT are trademarks and service marks of Gartner, Inc. and/or its affiliates and are used herein with permission. All rights reserved.

Sourced from Fortinet

FortiEDR Blocks 100% of Attacks in MITRE Engenuity ATT&CK® Evaluation for the Second Year in a Row

With cybercriminals continuing to “pound away at organizations (approximately 150,000 individual detections per week) with a variety of new and previously seen ransomware strains,” according to a recent FortiGuard Labs threat report, this year’s MITRE ATT&CK® Evaluations are exceptionally important. MITRE ATT&CK published their Evaluations for Enterprise, and Fortinet FortiEDR endpoint detection and response blocked 100% of the attacks. This is the second year in a row that FortiEDR blocked all attacks, and there was a 32% increase in its ability to detect substeps with nearly 100% of all techniques identified.

The MITRE ATT&CK Evaluations assess the ability of cybersecurity products to detect known adversary behavior. To provide objective insights into product capabilities, MITRE uses its Adversarial Tactics, Techniques & Common Knowledge (ATT&CK) knowledge base to emulate the tactics and techniques observed in real-world hacker behavior.

This round of evaluations focused on the Wizard Spider and Sandworm threat groups. Wizard Spider is a financially motivated criminal group that has been conducting ransomware campaigns since August 2018 against a variety of organizations, ranging from major corporations to hospitals. Sandworm is a destructive threat group known for carrying out notable attacks such as the 2015 and 2016 targeting of Ukrainian electrical companies and 2017’s NotPetya attacks.

The FortiEDR Results

FortiEDR participated in all of the test scenarios, except the single Linux test, which will be performed next year. In the nine scenarios, FortiEDR detected and cataloged 97% of the 90 non-Linux steps used in the test and blocked all attacks. Additionally, 93% of the substeps were detected using “technique,” which connects a technique-level description with the technique under-test for an endpoint detection and response (EDR) solution. Our growth in the ability to diagnose threats using the MITRE framework enable FortiEDR to be a reliable tool for organizations.

As Gartner® notes, “Threat detection is hard. Security and risk management technical professionals must defend their organization against hundreds of known, and possibly even more unknown, threats. The MITRE ATT&CK framework has evolved to provide a common taxonomy for threats and foundation for threat detection1.”

By embracing this standard, FortiEDR has become more intuitive to security operators, especially when threat hunting.

The results show how the mature threat hunting, detection, and prevention capabilities in FortiEDR benefit from its onboard artificial intelligence and machine learning technologies. Because FortiEDR doesn’t rely on signatures (but still uses them in the cloud), future cyberattacks that utilize tactics and techniques similar to the ones in the evaluation are likely to be blocked, even without pre-existing threat intelligence about them.

Of note, Fortinet recently collaborated via the MITRE Engenuity Center for Threat Informed Defense and found that 90% of all cybercriminal techniques sighted in the last 28 month fell into only 15 categories. So the demonstrated ability to not only understand but also block based on these techniques gives organizations confidence in their ability to protect against even previously unknown ransomware campaigns.  (Of note, more than 2/3 of these most common techniques were part of the Round 4 ATT&CK Evaluation.)

FortiEDR has a unique approach to deep system activity monitoring called “code tracing.” The benefits of this patented technology were apparent in the evaluation results. To remain stealthy and unobtrusive, advanced threats often violate one or more legitimate operating system instructions. By correlating the operating system’s outbound communication or file modification instructions with the preceding operating system instruction flow, FortiEDR can detect and prevent malicious actions in real-time.

The MITRE ATT&CK Evaluations demonstrate how well the true single-agent, behavior-based endpoint protection platform (EPP) and EDR approach, along with the code tracing in FortiEDR work to detect and prevent threats.

About FortiEDR

The FortiEDR solution comprehensively secures endpoints in real time, both pre- and post-infection. It delivers real-time, automated endpoint protection with orchestrated incident response across any communication device, all in a single integrated platform. FortiEDR defends everything from workstations and servers with current and legacy operating systems to point-of-sale and manufacturing controllers. Built with native cloud infrastructure, FortiEDR, which is also available in the Google Marketplace, can be deployed in the cloud, on-premises, and as a hybrid deployment.

FortiEDR includes machine learning-based next-generation antivirus, application communication control, automated endpoint detection and response (EDR), real-time blocking, threat hunting, incident response, and virtual patching capabilities. FortiEDR also leverages the broader Fortinet Security Fabric architecture by integrating with Security Fabric components such as FortiGate, FortiNAC, FortiSandbox, and FortiSIEM. FortiEDR offers:

● Superior real-time pre- and post-execution protection
● Robust detection of high-value, at-risk activity without overwhelming security teams
● A unified approach to protection, detection, and automated response

Visit the MITRE Engenuity site for the full FortiEDR results and more information about the MITRE Evaluations. And for more details about FortiEDR, read Assess Your Endpoint Security.

[1] Gartner, How to Use MITRE ATT&CK to Improve Threat Detection Capabilities, Joshua Ammons, 30 July 2021, GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved.

Sourced from Fortinet

Security in Service Providers’ Evolution Towards Micro-Services Architecture

Service providers (SPs) look to enhance their value to enterprise verticals with the delivery of value-add applications on top of connectivity. Cloud-native technologies and architecture are the tools enabling them to do so like never before.

One of the main components of cloud-native is the use of micro-services architecture, running in containers as an efficient, agile, and fast way for applications to get deployed and upgraded.

The evolution of SPs towards cloud-native architectures and tools is ongoing, defined by technological, operational, and commercial considerations, such as technology maturity and feasibility, scalability limitations, human resources expertise, know-how, and revenue-generating use case viability, etc.

This approach of evolution rather than revolution in service provider networks and services is now being accelerated with the deployment of cloud-native 5G cores, the gradual build of edge compute sites, the availability of cloud hyperscalers’ cloud-native tools and platforms, and the growing acceptance of micro-services and containers as the de-facto applications deployment and operation architecture.

Containerized Security Functions from Fortinet

Cloud-native is driving the need to deploy security to meet specific technology and architecture aspects of these critical environments. Such solutions must secure the cloud-native ecosystem, from the application development phase to the ongoing operations of the production platform.

Fortinet develops and delivers a comprehensive set of security solutions for the end-to-end value creation and delivery for these environments. This year our solutions will expand to deliver fast, agile, and efficient containerized security functions.

These containerized security functions leverage Fortinet’s 20 years of experience and know-how in security to cover multiple security use cases across on-premises and cloud, such as IPS, segmentation and perimeter security, as well as service provider specific use cases such as mobile RAN security and carrier grade-NAT.

With one of the smallest footprints in the industry, a limited containerized version of FortiOS has already been deployed in embedded devices with very limited resources and space, such as the Linksys CPE, car onboard systems, or industrial devices. This small container image serves as the basis for more powerful and scalable containerized security functions for SPs networks.

As truly multi-platform functions, they will run on both x86 and ARM platforms with the same level of functionality and be available on the major K8S distributions, such as OpenShift or Tanzu, as well as public cloud container environments, such as AWS EKS, Azure AKS, and Google GKE.

The gradual introduction of containerized security functions will allow us to continue and accompany our SP customers in their journey towards greater value generation on cloud-native platforms and allow them to secure existing and future use cases that require a range of containerized security functions.

But containerized security functions are not enough. More is needed to empower SPs security in their cloud-native environments.

Containerized Security Functions are Only Part of Securing SPs’ Cloud Native Environments

The below diagram provides a glimpse into Fortinet’s holistic approach to accompanying service providers in their journey to operational cloud native platform as service and value delivering platforms. The building blocks of our solutions are based on the following three key principles: 

1. Embed security visibility and control into DevOps pipelines
2. Secure the operational cloud-native environment

a. Kubernetes infrastructure and control plane
b. Secure the container workloads and their supply chain

3. Secure the runtime environment

a. Kubernetes nodes and associated user plane
b. Application-level security
c. Compliance requirements

Hybrid Stack Protection is Required  

Some microservices applications run in containers on a virtual machine, while others are on bare metal Linux. The evolution to cloud-native passed through a hybrid environment where legacy and new coexist must be secured – not as separated silos and bereft of integration which introduces complexity and unnecessary barriers to effective security visibility, detection, and response.

Take mobile network operators for example where 4G infrastructure based on VMs and legacy solutions coexist with 5G standalone networks and services based on cloud-native technologies. There are a wide set of common services delivered via both platforms and securing this hybrid stack is required. As MNOs search to provide beyond connectivity type of services to the business segment, the criticality of these hybrid environment is growing and with it, internal and external demands for security and compliancy.

There is a distinct need to integrate security visibility, monitoring, and protection across a hybrid stack including the Linux host, VMs, containers, applications, and services. These must provide security for the entire telco cloud where interdependencies such as relations between application-VM/container-host are covered.

Security in such a hybrid stack is enabled by the Fortinet Security Fabric which brings together the concepts of networking and security convergence and consolidation to provide comprehensive cybersecurity protection throughout the service provider environments and locations.​ The Fortinet Security Fabric also provides the one of the largest cybersecurity ecosystems in the industry, providing 3rd party integrated security solutions for service providers to attain advanced security across their digital infrastructure.

Use Case Considerations Are Paramount

Other than the need to secure the end-to-end service creation and delivery in a service provider’s cloud native and micro-services environment, another important consideration is the use case itself:

  1. What is the service provider trying to achieve? (The business objective)
  2. How will it be achieved? (Technologies, platforms, and tools to be used)
  3. What are the security considerations? (Internal and external risk, compliancy requirements)
  4. What are the security solutions? (Specific to the use cases and within the overall security infrastructure in place)

Use case considerations introduce factors such as cost, time to market, operational limitations, physical space, predictability, performance, latency, and other considerations that may have a significant impact of the technology and solutions deployed to achieve the business objective of a specific use case.

This is also true for the security aspect and is therefore important that Fortinet support any solution to secure a service provider’s objectives and use cases as well as the technologies they use, either legacy, virtualized, cloud-native, or hybrid.

With that in mind, Fortinet solutions span physical, virtual, containerized, and SaaS form factors to enable the best possible fit to service providers’ hybrid environments and many use cases, while providing common functionality, integration, and automation regardless of the form factor.

Learn more about how Fortinet secures the evolution to the telco cloud model to drive efficiency, agility, and growth.

Sourced from Fortinet

From the Shotgun Approach to Triple Extortion: The Evolving Ransomware Threat

In the (relatively) brief history of computer crime, many kinds of attacks have, for one reason or another, become obsolete and faded from view. Ransomware, however, is only becoming more of a threat. Since the first known attack in 1989, damage from ransomware has continued to grow in scope and severity. No organization can afford to wait it out and hope for some painless universal solution. According to a Fortinet survey, 67% of businesses and organizations have been targeted by ransomware. 

Pests to Predators

Ransomware began as more of an inconvenience than true impact to a given business — a few computers locked here or there, with ransom maybe paid if something important wasn’t backed up. But ransomware gangs refined their techniques over time, researching their targets to pinpoint the greatest operational impacts: preventing the mission from being accomplished, whether that was making widgets, providing health services, or something else. More pain caused, bigger ransoms, more money.

How It Got Even Worse

Ransomware began as a crime of opportunity, with attackers almost randomly infecting vulnerable machines and seeking ransom – the shotgun approach. Things have changed.

The U.S. government’s Cybersecurity and Infrastructure Security Agency (CISA) has noted just a few of the ways ransomware has become more effective and costly:

  • Ransomware groups are sharing information about victims with each other. This makes follow-up attacks more likely.
  • Moving from “big-game hunting” to smaller victims. Ransomware groups have seemed to learn that high-profile attacks bring more law-enforcement disruption, so they are diversifying their target lists to more mid-sized victims.
  • Attempting “triple extortion.” The first ransom demand is now often just the starting point. Because attackers control the machines and siphon data out, they now threaten to:
    • Publicly release sensitive information (this can be customer information, personally identifiable information [PII], or other types)
    • Disrupt Internet access or other important services
    • Embarrass the victim by revealing the attack, which can lead to issues with partners, shareholders, and other interested parties

Some Ways to Improve Readiness…

Although overall ransomware remains a top concern, there are proactive measures organizations of almost any size can, and should take, to minimize the impact of a ransomware incident. Although there is a range of technical controls available to prevent, detect, and respond to ransomware, there are also process, practice, and awareness moves in addition that can position organizations to handle a ransomware attack much better.  A partial list of these proactive measures includes:

  • Ransomware Playbook: Have you documented, in detail, the right steps to take at the right time when ransomware appears? Ransomware has several wrinkles that a “normal” malware incident does not.
  • Ransomware Tabletop Exercise (TTX): Actually going through a ransomware incident is a very stressful and usually expensive proposition – but you can learn a lot through a well-done practice action to make sure all detection, response, and recovery is on the same page.
  • Ransomware Assessment: Do you think you have a good idea of how your environment, security controls, incident response, and remediation plans are matched against the latest ransomware threats? Or maybe aren’t sure? An objective, third-party assessment can show areas for improvement and where you can get the biggest bang for the buck.

…And Why Readiness Makes Financial Sense

Every business has different approaches to risk tolerance, security spending, and cost/benefit analysis, but some raw numbers can be helpful in putting ransomware into a business perspective. Two numbers in particular are useful: the average cost of recovering from an attack and the average ransom demand.

The average cost of a single ransomware incident was US$713,000 a few years ago.

The cost of just paying the ransom has been rising, reaching US$178,254 in 2020.

Just basic consideration of those raw numbers suggests that getting ready for ransomware – making response and recovery more efficient in addition to just preventative controls – could lead to a good return on the investment. It should be noted that the numbers above do not capture reputational damage, loss of customer confidence, and other costs that are difficult to quantify but are real.

Conclusion

Ransomware is obviously not going away any time soon, and will probably remain at peak levels as FortiGuard Labs research shows. Organizations that haven’t been hit yet can continue to ride their luck, or they can take a good look at where they stand and become a harder target. And on the other side of an attack, if the worst has indeed happened, recover as smoothly and thoroughly as possible.

How Fortinet Can Help

To help navigate ransomware effectively, our Incident Readiness Subscription Service can help organizations with a rapid and effective response when an incident is detected and also help better prepare for an unforeseen cyber incident through readiness assessments, IR playbook development, and IR playbook testing (tabletop exercises).

Emergency Incident Response Service

Learn more about how Fortinet Security Fabric solutions protect the entire organization against ransomware attacks as well as from infection and spread.

Sourced from Fortinet

3 Trends Driving Federal Government Cybersecurity Initiatives

Because many areas of the Federal government are involved with the safety and security of the country, Federal agencies have to consider the implications of almost every security decision they make. Although private sector organizations and state or local governments are occasionally targeted by nation-state adversaries, Federal agencies are consistently in the crosshairs. The cybercriminals targeting agencies are not only motivated by money, they also may want to steal data, intellectual property, and national security information. These crimes are often more difficult to detect and may include the use of sophisticated Advanced Persistent Threats (APT). Protecting against these threats is critical to national security and in the case of elections, public perception and confidence in systems.

In making decisions about security solutions, agencies have to go beyond a standard risk versus benefit analysis that a private company might use. In areas such as national defense, healthcare, and financial systems, agencies can’t discount the magnitude of the risks to critical systems that protect society and human life. But agencies don’t have unlimited funds either. They have to deal with the realities of fixed budgets, the availability of skilled staff, and various other priorities competing for dollars. 

Trends Driving Federal Cybersecurity Initiatives

1. Network and IT Modernization

An unfortunate reality is that many of the systems used in the Federal government need modernization. And as agencies have digitized their systems, the “IT footprint” has grown dramatically. The human and compute resources required to assess, procure, and maintain assets at government agencies are immense, particularly when you include operational technology (OT) and industrial systems with traditional IT. As they work to modernize IT, agencies need to consider where consolidation, cloud and “as a service” models make the most sense. Vendor and product sprawl is an issue along with finding the best value for the overall infrastructure. For example, instead of purchasing a point-product, choosing a next-generation firewall (NGFW) with Zero Trust Network Access (ZTNA) and SD-WAN capabilities built-in offers an opportunity to consolidate. This type of consolidation across multiple locations can dramatically reduce the number of components that must be managed and improve overall visibility and control because fewer management consoles and dashboards are needed.

2. Zero Trust Architecture

In May 2021, the White House issued an Executive Order (EO) with the goal of improving the nation’s cybersecurity. Part of the EO directs agencies to advance toward a zero-trust architecture. In January 2022, the Office of Management and Budget (OMB) explained what that directive entails, stating that “the new strategy will serve as a comprehensive roadmap for shifting the Federal Government to a new cybersecurity paradigm that will help protect our nation.”

A zero-trust architecture strategy is a systematic approach that replaces implicit trust with explicit trust after verification, and it’s critically important to any modern cybersecurity strategy. With zero trust, any time an application, user, or device wants to communicate with something else, the transaction must be authorized before access is granted.  Additionally, cybersecurity tools and capabilities are configured to provide situational awareness as inputs into the authorization decision, such as if the source or target is potentially infected by malware.

The move to a zero-trust architecture is a transition from the previous mindset of acquiring individual tools to solve usually disparate cybersecurity problems. This approach led to the current security tool sprawl problems many agencies are working to address now. Some agencies have over 50 tools in their environment. Shifting to a holistic outcome-based approach based on zero-trust principles will ease management burdens and improve the overall security posture. As the OMB succinctly points out, the “Federal Government can no longer depend on conventional perimeter-based defenses to protect critical systems and data.” Digital transformation requires security transformation, and zero trust goes to the heart of the problem.

3. Increased Coordination and Collaboration

The third trend driving change is the need for greater participation and coordination with other agencies and the private sector. This collaboration may be in the form of sharing threat intelligence and best practices for deploying security solutions that share data and insights to help break down silos. Cybersecurity is a problem for everyone, and solving problems alone can be a monumental task. By working together, government and industry can more quickly identify, contain, and eradicate threats. Cybersecurity aside, many government operations are also increasing work with cloud and network service providers to help them scale and modernize infrastructure.

Simple and Scalable Zero-Trust Architecture

For agencies, setting up a zero-trust architecture is a radically different approach than before. The good news is, solutions already exist that meet the EO mandate from the White House and the guidance being provided by the Federal Government. Zero trust network access (ZTNA) provides a consistent level of security regardless of the user’s location. Today, at many organizations, ZTNA is replacing prior technologies such as VPN for remote access. The best approach is to set up “universal ZTNA” so access works the same way everywhere, both on-premises and off.

To start, agencies need to examine the security gaps in their organization from a zero trust architecture perspective and then look at vendors to see how they can deliver the solutions to help them meet the requirements outlined in the EO. Instead of the piecemeal approach of the past, agencies can implement universal ZTNA by starting with a next-generation firewall (NGFW) that functions as they core of their zero trust architecture. This holistic approach delivers unified visibility, automated control, and coordinated protection to secure endpoints, networks, and application access.

Fortinet implements ZTNA access control through a combination of FortiClient client software, FortiGate firewalls that serve as access proxies, and identity management services. And those agencies that already have FortiClients and FortiGates can use the ZTNA capability by simply upgrading to FortiOS 7.0 or above.

Learn more about protecting government data and infrastructure against cyber threats. 

Sourced from Fortinet

From Medieval to Modern – a Zero Trust Story

In medieval times, kings protected themselves and their assets by locking them away in castles built with impenetrable walls. A moat with a drawbridge provided a single route into and out of the castle. Not long ago, corporate networks were designed the same way—a clear, defined network perimeter with gateway security.

Traditional VPN solutions operate much like the concept of the castle, moat, and drawbridge. They provide a way for the owner to restrict access into the castle. However, they both have similar flaws:

  • An attacker masquerading as someone else can gain access and cause havoc (think: the Trojans)
  • Once an attacker is within the perimeter walls, they can roam around unimpeded.

Digital transformation has forced technology to move rapidly, replacing the concept of a clearly defined network edge with many diverse network edges and applications and data distributed in many different locations, including the HQ and private and public clouds. With these distributed networks comes a need for a new, modern way of thinking about remote access to address the following concerns:

  • Users are no longer always in the office. Today, users can be located anywhere in the world, connecting on multiple types of devices. Yet, they still need to be able to do their job.
  • Data and applications can be in many different locations. The corporate network is no longer the only place to access all your data and applications. With the growth of SaaS and the cloud, it is critical that all locations can be accessed securely and consistently.
  • While users need to be able to access these applications, access should be highly controlled according to risk to prevent unauthorized data leakage and the propagation of malware around networks.

Sourced from Fortinet

Fortinet Earns Frost & Sullivan’s 2021 North America Product Leadership Award for Healthcare

Frost & Sullivan recently assessed the North American healthcare cybersecurity industry and recognized Fortinet with the 2021 North America Product Leadership Award. Each year, Frost & Sullivan’s Product Leadership Award recognizes the company that offers a product or solution with attributes that deliver the industry’s best quality, reliability, and performance.

Securing Patient Care

As healthcare organizations accelerate their digital innovation and patient care initiatives, their security infrastructure must be able to keep up with the new network edges being put in place along with the increasingly complex and fast-evolving threat landscape.

According to Ojaswi Rana, Best Practices Research Analyst at Frost & Sullivan, “One major industry challenge in healthcare is the lack of interoperability between health systems, platforms, and devices, preventing security solutions from monitoring threats at an enterprise level. Skilled resources are another issue that hampers many healthcare organizations from effectively managing cybersecurity. However, Fortinet’s Security Fabric platform addresses these challenges with its cybersecurity mesh architecture approach offering centralized management, automation, and integrated solutions that work in concert, establishing itself as a trailblazer in the healthcare cybersecurity industry.”

“Fortinet’s innovative product solutions and leadership in the convergence of networking and security are revolutionizing the healthcare cybersecurity market, positioning it as a market leader,” said Koustav Chatterjee, an industry principal for Frost & Sullivan. “The company’s broad, integrated, and automated capabilities earn its customers’ trust as a long-term healthcare cybersecurity vendor.”

Fortinet’s broad portfolio of cybersecurity solutions is built with integration and automation in mind, enabling more efficient, self-healing operations and a rapid response to known and unknown threats. With digital and remote care needs, increasingly sophisticated threats, and ongoing digital acceleration initiatives, this is more important than ever.

The Fortinet Security Fabric is a platform built around a common operating system and management framework to enable broad visibility, seamless integration, and interoperability between critical security elements, and granular control and automation.

About the Award

Frost & Sullivan Best Practices awards recognize companies in various regional and global markets for demonstrating outstanding achievement and superior performance in leadership, technological innovation, customer service, and strategic product development. Industry analysts compare market participants and measure performance through in-depth interviews, analyses, and extensive secondary research to identify best practices in the industry.

Learn more about how Fortinet healthcare solutions can help you enable the latest advances in patient care while protecting against cyberattacks.

View the full Frost & Sullivan Best Practice award

Sourced from Fortinet

MITRE Sightings Report Provides Guidance on Key Cyberattack Techniques

It’s common knowledge in the cybersecurity industry that attackers are evolving, and their attacks are becoming more sophisticated. As a result, the harm and cost to targeted victims and organizations are also steadily increasing. This situation demands a smart and innovative response from security practitioners because no organization can defend against every threat. Trying to protect against all the adversarial TTPs (tactics, techniques, and procedures) threat actors deploy would be extraordinarily costly and difficult to maintain for most enterprises.

Perhaps the greatest challenge is scale. More than 370 attack techniques have been documented to date, and every quarter or so, another technique or implementation of a technique appears. Keeping track of attack techniques and launching appropriate and timely countermeasures can overwhelm most defense systems and security professionals. Narrowing down the scope and scale of potential attacks is a critical first line of defense. Fortunately, help is on the way in the form of a just-published research paper titled 2021 ATT&CK Sightings Report that addresses the question: “Which of these techniques do we need to prioritize and prepare to fight?”

The Sightings Report is based on a research project run by MITRE Engenuity’s Center for Threat-Informed Defense (Center) in collaboration with Fortinet’s FortiGuard Labs and several other Center participants. The researchers analyzed more than one million attacks using the MITRE ATT&CK® framework, collected over 28 months (April 1, 2019, to July 31, 2021), to provide contextual, actionable threat intelligence to explain how attackers are conducting their nasty business.

This threat intelligence report provides crucial visibility into which TTPs are being used the most by cyber adversaries. Its “high resolution” visibility helps security professionals identify those threats they are most likely to face. This enables them to quickly prioritize and fine-tune their defenses, including what security technologies to deploy and where.

The research from the Sightings Report paints “a picture of common adversary behavior, including which techniques adversaries use, how their use changes over time, and how adversaries sequence techniques. Defenders can use this information to create a threat-informed defense against what they are most likely to see, not just the latest cyberthreat headlines.”

The Extremely Useful Takeaway

The biggest takeaway from the research data is that 90% of all attacks arise from only 15 techniques across six tactics. This intel is extremely useful as it significantly narrows down the most likely threats from the entire corpus of more than 370 possible techniques across 14 tactics.

The MITRE ATT&CK framework has been the de facto standard for mapping and responding to cyberattacks of all types. Using it to analyze aggregated global threat data from various sources and then presenting according to the prevalence of potential attacks gives defenders a unique opportunity to change the economics of the attack cycle. Instead of testing for all techniques and their respective defenses—which can be very costly and time-consuming—defenders can now prioritize specific techniques and build defenses around them while focusing their red team efforts on trying new strategies for implementing those techniques.

The Top Tactics

A deeper look at those six tactics that account for 90% of all attacks reveals even more helpful information. Five of those tactics involve defensive evasion, which involves exploiting security gaps to prevent detection. The report’s detailed analysis of this tactic provides crucial insight into how attackers try to get around security holes, enabling defenders to identify similar weaknesses in their defenses and effectively close those gaps. It also identifies which parts of the ATT&CK matrix attackers focus on to best hide their efforts.

The second most common tactic employed is privilege escalation, which makes sense given that most enterprise systems today are protected using privilege isolation. This information helps security teams assess and correct their internal functions, such as using admin user privilege levels for basic tasks like emailing and browsing. Remember that attackers will struggle to take over a system when an unprivileged user is compromised.

It’s All in the Technique

Many of the specific techniques identified in the report are heavily focused on “living off the land.” This means using legitimate systems, tools, or functions already present on a system to move around the device or network without attracting attention. T1053 (Schedule Task/Job) is the most common of these techniques, representing over 24% of all sightings. It is followed by Command and Script Interpreter (T1059), representing 15.77%. These techniques have been employed across all major platforms, attacking Linux, Windows, and macOS. The other techniques combined accounted for less than 11% of all sightings.

Zero-trust strategies can play a critical role in defending against these techniques. Again, quoting from the report, “Adversaries are attempting to appear as legitimate users. Therefore, creating strong baselines and restricting permissions is key to detecting and disrupting adversary behaviors.”

This information gives defenders an upper hand in effectively preparing and hardening their systems since it’s clear from the global data on these TTPs that attackers are trying to appear as legitimate users. Without strong baselines of normal end-user behavior and company-approved applications and the ability to restrict access to systems and resources based on policy, detection and mitigation of threats designed to look like “normal” behavior can be nearly impossible.

Fortunately, defenders aren’t left to figure out how best to defend against these threats. The report also provides deeper insight into how organizations can go about detecting and containing these threats using open-source tools and intel, as well as which techniques are generally seen together to facilitate proactive threat hunting, which is one of the most potent actions cyber defenders can take to lessen the impact of an attack.

Low Cost, High Return Intelligence

With this research paper, the Center has provided the cybersecurity community with valuable, up-to-date intelligence that can be widely used to prioritize defensive actions. And it provides it in a low-cost way while providing a high return. Because of the specific insight and guidance it provides, cyberdefenders worldwide can build threat-informed defenses using curated, high-fidelity data.

Security is everyone’s responsibility, and if we have more secure organizations, the internet and the digital economy will be more stable and predictable. And that’s a win for everyone.

Fortinet has been at the forefront of cybersecurity innovation and research for more than 20 years. We are proud to have been able to leverage this expertise in our participation in the Sightings research project with the Center.

Read and learn more in the report or view the infographic.

Sourced from Fortinet

Industrial 5G Requires an Enhanced Security Model

Organizations utilizing digital solutions have moved faster and further than their peers recently, in everything from production efficiency to product customization, delivering improvements in speed to market, service effectiveness, and new business-model creation. 5G can significantly enable and accelerate industrial transformation and innovation like no other communications and networking technology, enabling data-driven use cases, such as augmented reality-based maintenance, precise real-time asset tracking, mobile robots, and closed-loop process control. 

Using digital technologies such as 5G is top of mind for many, and this nascent demand is creating new 5G supply players, ecosystems, services, and business models to capitalize on this unique opportunity. And within this enterprise landscape, industrial verticals are the early adopters. The adoption of 5G technology by enterprises will support and accelerate Industry 4.0, but enhanced security considerations and architectures are required in 5G-enabled industrial environments.

When it comes to core technology in critical enterprise use cases, security is fundamental and it can be a barrier or an enabler for 5G adoption in enterprise verticals. A Verizon 5G business report places security and compliance concerns as the second challenge or barrier to 5G adoption by enterprises. Security is top of mind on the enterprise demand side, and therefore must be top of mind for the industrial 5G supply side.

Security Considerations in Industrial 5G Environments

5G is consumed by enterprises as the need dictates. A private 5G network empowers enterprises to have complete control and customization, better transparency, data privacy, and flexibility. On the other hand, private 5G can be expansive, complex, and lengthy to implement and maintain. Consuming public 5G is significantly more cost-effective and rapid but offers less control and customization. It is likely that private and hybrid (a combination of private and public 5G consumption) 5G networks will be the popular 5G enterprise consumption form. However, recent studies show that some organizations considering 5G would rather use private 5G networks than public, due to the critical and sensitive nature of industrial environments, processes, and operations.

Security in Pre-5G Industrial Environments

Historically air-gapped from the internet, OT systems now depend on information from enterprise and third-party IT systems to effectively manage operations in real time. However, this improved agility and effectiveness come at the cost of increased risk. Many of today’s OT systems face all the threats that IT systems face. Security in these environments has been mostly implemented based on the classical ISA99 Purdue model reference architecture, which outlines the key infrastructure layers used in ICS environments and the boundaries between them where security is required.

A key to a Purdue reference architecture is its hierarchical nature, whereby each layer within the segments can only interface and communicate with the layer above and below it. Therefore, the establishment of horizontal enforcement boundaries between segments and layers.

5G Introduction Mandates an Enhanced Purdue Reference Architecture

When introducing 5G in an industrial environment with 5G-capable devices and platforms within the different Purdue model layers, the hierarchical nature of data flow between the layers is no longer valid. 5G-connected devices, platforms, and applications can now send and receive data directly via flows that do not necessarily pass through the Purdue model-defined enforcement boundaries. This mandates the addition of an additional security boundary at the 5G domain with the following high-level functionalities:

  • OT/Industrial Internet of Things (IIoT) security visibility and control
  • 5G network security
  • Industrial applications security

Deploying 5G use cases in production will take time as devices, applications, 5G technology, experience, and know-how are mature and reliable enough to be deployed. It is essential that alongside this evolution of 5G deployments in enterprise verticals that the appropriate security considerations are taken and implemented throughout the industrial environment, including the 5G network, services, and overall use cases.

Holistic Security in 5G-enabled Industrial Environments

5G is only an enabler for many new industry vertical use cases. Delivering these use cases requires an integrated ecosystem of technologies and partners: OT/IIoT vendors, ICS vendors, 5G vendors/providers, industrial applications providers, hyperscalers, and integrators. Many organizations assume that a private 5G network will inherently keep them safe, which is not necessarily always the case. 5G private networks are rarely entirely isolated from the enterprise IT environment or external environments (partners, integrators, public cloud, etc.) and may be exposed to internal and external attacks and risks.

An increase in OT and IIoT exposure, the mobility of users and devices on the network, and the interplay among the enterprise, mobile network operators, IoT manufacturers, and OT vendors and suppliers all also contribute to 5G security challenges, whether the network is private or not.

When considering security in industry verticals, the security of such an end-to-end supply chain and ecosystem must be considered. Furthermore, organizations must consider the capacity and knowledge required to manage the rapidly expanding landscape of connected OT.

Fortinet Security Fabric Platform as an Enabler for Industrial 5G

The security of an industrial environment is only as strong as its weakest link. With the ongoing OT-IT convergence, assets digitization, and digital transformation initiatives, the introduction of 5G into industrial environments represents a complex technology that expands the industrial attack surface. The above and other security considerations should be structurally, methodologically, and proactively implemented as enablers for impactful 5G adoption in enterprise verticals. The Fortinet Security Fabric is a unique security platform that encapsulates IT, OT, IIoT, and 5G security with broad visibility, control, and value-add services, empowering 5G providers, industrial enterprises, and system integrators to secure critical traditional and 5G-enabled use cases over private, public, and hybrid 5G networks and services.

In addition to the broad portfolio of Fortinet security solutions, specialized OT and 5G solutions can be integrated seamlessly with the Fortinet Security Fabric through the ecosystem of Fortinet Fabric-Ready Partners.

Learn more about how the Fortinet Security Fabric protects 5G ecosystems.

Check out this White Paper to learn more about the Security Considerations in Industrial 5G Environments.

Subscribe to Fortinet’s Cybersecurity Podcast and join Fortinet’s top experts as they discuss today’s most important cybersecurity topics.

Sourced from Fortinet