FortiMail Receives High Marks in ICSA Labs Testing

Greater Transparency on the Efficacy of Security Solutions Helps IT and Security Pros Make Better Decisions

In our industry, the threat landscape is always intensifying and the volume of threats increasing. This puts tremendous pressure on IT and security professionals to scale up to handle more with the resources they have, as well as be continually rethinking what aspects of their security infrastructure are working well against the increasing sophistication of what is coming across the wire and into mailboxes.

As an example, we know through various data points including analysis from Fortinet’s FortiGuard Labs, that ransomware attacks have increased as much as ten-fold in the last 18 months. This is a staggering development and one that should trigger IT and security pros to reevaluate their security postures. Given that as much as one-third or more of ransomware attacks are email-based, this means organizations should take a fresh and hard look at their current email security practices.

Third-party independent testing firms help organizations better understand which solutions in the marketplace are more effective versus others. They expend significant time and money in devising testing regimes to evaluate vendor solutions and help expedite the evaluation process.

Commitment to Independent Testing

Fortinet believes strongly in testing our solutions through independent testing labs and making the results available. We believe this helps our customers in knowing the outcomes they can expect from our products and solutions. In fact, when it comes to testing of email security solutions, Fortinet tests our FortiMail solution with three different third-party vendors: ICSA Labs, SE Labs and Virus Bulletin.

Sourced from Fortinet

Ukraine Crisis Cyber-Readiness Checklist

With Russian military operations currently underway in Ukraine, the question of whether cyber warfare will also be employed remains unanswered. While we have seen cases of destructive cyber actions focused on Ukraine, at this point attribution is not possible. 

As a result of these actions, there is a heightened sense of concern being felt by many organizations. Our focus here is to protect organizations by helping them prepare for potential cyberattacks. For that, we have put together this cyber readiness checklist. While many of these suggestions are standard cyber hygiene protocols and best practices, being reminded of doing the basics never hurts, especially when there are so many other concerns. In the same way that hand washing helps in our fight against COVID-19, simple actions can also go a long way towards fighting against cyberthreats. 

Key Takeaways

  1.  Patching: Ensure that all systems are fully patched and updated
  2.  Protection Databases: Make sure your security tools have the latest databases 
  3.  Backup: Create or update offline backups for all critical systems
  4.  Phishing: Conduct phishing awareness training and drills 
  5.  Hunt: Proactively hunt for attackers in your network using the known TTPs of Russian threat actors
  6.  Emulate: Test your defenses to ensure they can detect the known TTPs of Russian threat actors 
  7.  Response: Test your incident response against fictitious, real-world scenarios
  8.  Stay up to Date: Subscribe to threat intelligence feeds like Fortinet Threat Signals 

Detailed Actions

  1. Patching: Threat actors often target unpatched vulnerabilities in a victim’s network. As a result, the first line of defense should always be patch management and running fully patched systems. For organizations interested in focusing on specific vulnerabilities, CISA maintains a list of specific CVEs used in the past by Russian threat actors. But the better approach is to simply focus on being up to date all the time. This is also true for air-gapped environments, and now is a good time to ensure that these systems have been patched as well. And remember, patching is important not only for workstations and servers but also for security and networking products.
  2. Leverage Protection Databases: FortiGuard Labs continuously creates new detection rules, signatures, and behavioral models for threats that are discovered in our extensive threat intelligence framework. These are quickly propagated to all Fortinet products. Make sure that all protection databases are updated regularly.
  3. Backup Critical Systems: Many attacks come in the form of ransomware or wiper malware. The best defense against the destruction of data by such malware is to keep up-to-date backups. It is equally important that these backups are kept offline since malware often tries to find backup servers to destroy backups as well. The current crisis is a good opportunity to check whether backups really exist (not just on paper) and run recovery exercises with the IT team.
  4. Phishing: Phishing attacks are still the most common entry points for attackers. Now is a good time to run a phishing awareness campaign to heighten the awareness of everybody at your organization and to ensure they know how to recognize and report malicious emails.
  5. Hunt: The sad truth is that if your organization plays any sort of role in this conflict, then adversaries may already be in your network. Running threat hunting engagements can be vital in detecting adversaries before they install spyware or cause serious destruction. For threat hunting, you can use the known Tactics, Techniques, and Procedures (TTPs) below. 
  6. Emulate: The TTPs listed below can be also used to evaluate whether your security infrastructure is able to detect them. Running emulation exercises can uncover configuration problems and blind spots that attackers might leverage to move around in your network undetected.
  7. Response: A quick and organized incident response will be crucial when a compromise is discovered. Now is a good opportunity to review procedures for responding to an incident, including disaster recovery and business continuity strategies. If you have your own incident response team, you can run tabletop exercises or fictitious scenarios to ensure everything will run smoothly should a compromise occur.
  8. Stay up to Date: it is crucial that the actions listed here are not performed just once. Staying up to date and patched, monitoring vulnerabilities, and maintaining threat awareness are actions that must be performed continuously. One way to learn about the newest threats as they are discovered is to follow the FortiGuard Threat Signals.

Tactics, Techniques, and Procedures

For hunting for adversaries in your networks CISA recommends the following TTPs:

Tactic

Technique

Procedure

Reconnaissance [TA0043]

Active Scanning: Vulnerability Scanning [T1595.002]

 

Russian state-sponsored APT (Advanced Persistent Threat) actors have performed large-scale scans to find vulnerable servers.

Phishing for Information [T1598]

Russian state-sponsored APT actors have conducted spearphishing campaigns to gain credentials of target networks.

Resource Development [TA0042]

Develop Capabilities: Malware [T1587.001]

Russian state-sponsored APT actors have developed and deployed malware, including ICS-focused destructive malware.

Initial Access [TA0001]

Exploit Public Facing Applications [T1190]

Russian state-sponsored APT actors target publicly known vulnerabilities, as well as zero-days, in internet-facing systems to gain access to networks.

Supply Chain Compromise: Compromise Software Supply Chain [T1195.002]

Russian state-sponsored APT actors have gained initial access to victim organizations by compromising trusted third-party software. Notable incidents include M.E.Doc accounting software and SolarWinds Orion.

Execution [TA0002]

Command and Scripting Interpreter: PowerShell [T1059.003] and Windows Command Shell [T1059.003]

Russian state-sponsored APT actors have used cmd.exe to execute commands on remote machines. They have also used PowerShell to create new tasks on remote machines, identify configuration settings, exfiltrate data, and execute other commands.

Persistence [TA0003]

Valid Accounts [T1078]

Russian state-sponsored APT actors have used credentials of existing accounts to maintain persistent, long-term access to compromised networks.

Credential Access [TA0006]

Brute Force: Password Guessing [T1110.001] and Password Spraying [T1110.003]

Russian state-sponsored APT actors have conducted brute-force password guessing and password spraying campaigns.

OS Credential Dumping: NTDS [T1003.003]

Russian state-sponsored APT actors have exfiltrated credentials and exported copies of the Active Directory database ntds.dit.

Steal or Forge Kerberos Tickets: Kerberoasting [T1558.003]

Russian state-sponsored APT actors have performed “Kerberoasting,” whereby they obtained the Ticket Granting Service (TGS) Tickets for Active Directory Service Principal Names (SPN) for offline cracking.

Credentials from Password Stores [T1555]

Russian state-sponsored APT actors have used previously compromised account credentials to attempt to access Group Managed Service Account (gMSA) passwords.

Exploitation for Credential Access [T1212]

Russian state-sponsored APT actors have exploited Windows Netlogon vulnerability CVE-2020-1472 to obtain access to Windows Active Directory servers.

Unsecured Credentials: Private Keys [T1552.004]

Russian state-sponsored APT actors have obtained private encryption keys from the Active Directory Federation Services (ADFS) container to decrypt corresponding SAML (Security Assertion Markup Language) signing certificates.

Command and Control [TA0011]

Proxy: Multi-hop Proxy [T1090.003]

Russian state-sponsored APT actors have used virtual private servers (VPSs) to route traffic to targets. The actors often use VPSs with IP addresses in the home country of the victim to hide activity among legitimate user traffic.

For Additional TTPs Review These Known Actors

How Fortinet Can Help

Fortinet provides multiple opportunities for organizations to mitigate serious cyberattacks and investigate possible breaches. Below are just a few popular examples of the technologies and solutions Fortinet offers.  

  • Fortinet Cyber Threat Assessment: Secure network architectures need to constantly evolve to keep up with the latest advanced persistent threats. There are two ways to find out if your solution isn’t keeping up—wait for a breach to happen or run validation tests.

  • Managed Detection and Response: Fortinet helps customers better understand the cybersecurity risks they face and improve how they identify and react to threats. 

  • Fortinet Virtual Patching solutions: FortiGuard Labs protects against specific exploits. 

  • FortiGuard Incident Response Service: The FortiGuard Incident Response Service provides organizations in the midst of a cybersecurity incident (including targeted ransomware attacks), with experienced staff, expert skills, and powerful tools. 

  • FortiGuard IPS and Anti-Virus: Services and engines utilize a variety of techniques including multiple machine learning and artificial intelligence strategies to protect our customers against advanced and zero-day threats.

Further Reading 

Sourced from Fortinet

A Cyber-Readiness Checklist and Guide

With Russian military operations currently underway in Ukraine, the question of whether cyber warfare will also be employed remains unanswered. While we have seen cases of destructive cyber actions focused on Ukraine, at this point attribution is not possible. 

As a result of these actions, there is a heightened sense of concern being felt by many organizations. Our focus here is to protect organizations by helping them prepare for potential cyberattacks. For that, we have put together this cyber readiness checklist. While many of these suggestions are standard cyber hygiene protocols and best practices, being reminded of doing the basics never hurts, especially when there are so many other concerns. In the same way that hand washing helps in our fight against COVID-19, simple actions can also go a long way towards fighting against cyberthreats. 

Key Takeaways

  1.  Patching: Ensure that all systems are fully patched and updated
  2.  Protection Databases: Make sure your security tools have the latest databases 
  3.  Backup: Create or update offline backups for all critical systems
  4.  Phishing: Conduct phishing awareness training and drills 
  5.  Hunt: Proactively hunt for attackers in your network using the known TTPs of Russian threat actors
  6.  Emulate: Test your defenses to ensure they can detect the known TTPs of Russian threat actors 
  7.  Response: Test your incident response against fictitious, real-world scenarios
  8.  Stay up to Date: Subscribe to threat intelligence feeds like Fortinet Threat Signals 

Detailed Actions

  1. Patching: Threat actors often target unpatched vulnerabilities in a victim’s network. As a result, the first line of defense should always be patch management and running fully patched systems. For organizations interested in focusing on specific vulnerabilities, CISA maintains a list of specific CVEs used in the past by Russian threat actors. But the better approach is to simply focus on being up to date all the time. This is also true for air-gapped environments, and now is a good time to ensure that these systems have been patched as well. And remember, patching is important not only for workstations and servers but also for security and networking products.
  2. Leverage Protection Databases: FortiGuard Labs continuously creates new detection rules, signatures, and behavioral models for threats that are discovered in our extensive threat intelligence framework. These are quickly propagated to all Fortinet products. Make sure that all protection databases are updated regularly.
  3. Backup Critical Systems: Many attacks come in the form of ransomware or wiper malware. The best defense against the destruction of data by such malware is to keep up-to-date backups. It is equally important that these backups are kept offline since malware often tries to find backup servers to destroy backups as well. The current crisis is a good opportunity to check whether backups really exist (not just on paper) and run recovery exercises with the IT team.
  4. Phishing: Phishing attacks are still the most common entry points for attackers. Now is a good time to run a phishing awareness campaign to heighten the awareness of everybody at your organization and to ensure they know how to recognize and report malicious emails.
  5. Hunt: The sad truth is that if your organization plays any sort of role in this conflict, then adversaries may already be in your network. Running threat hunting engagements can be vital in detecting adversaries before they install spyware or cause serious destruction. For threat hunting, you can use the known Tactics, Techniques, and Procedures (TTPs) below. 
  6. Emulate: The TTPs listed below can be also used to evaluate whether your security infrastructure is able to detect them. Running emulation exercises can uncover configuration problems and blind spots that attackers might leverage to move around in your network undetected.
  7. Response: A quick and organized incident response will be crucial when a compromise is discovered. Now is a good opportunity to review procedures for responding to an incident, including disaster recovery and business continuity strategies. If you have your own incident response team, you can run tabletop exercises or fictitious scenarios to ensure everything will run smoothly should a compromise occur.
  8. Stay up to Date: it is crucial that the actions listed here are not performed just once. Staying up to date and patched, monitoring vulnerabilities, and maintaining threat awareness are actions that must be performed continuously. One way to learn about the newest threats as they are discovered is to follow the FortiGuard Threat Signals.

Tactics, Techniques, and Procedures

For hunting for adversaries in your networks CISA recommends the following TTPs:

Tactic

Technique

Procedure

Reconnaissance [TA0043]

Active Scanning: Vulnerability Scanning [T1595.002]

 

Russian state-sponsored APT (Advanced Persistent Threat) actors have performed large-scale scans to find vulnerable servers.

Phishing for Information [T1598]

Russian state-sponsored APT actors have conducted spearphishing campaigns to gain credentials of target networks.

Resource Development [TA0042]

Develop Capabilities: Malware [T1587.001]

Russian state-sponsored APT actors have developed and deployed malware, including ICS-focused destructive malware.

Initial Access [TA0001]

Exploit Public Facing Applications [T1190]

Russian state-sponsored APT actors target publicly known vulnerabilities, as well as zero-days, in internet-facing systems to gain access to networks.

Supply Chain Compromise: Compromise Software Supply Chain [T1195.002]

Russian state-sponsored APT actors have gained initial access to victim organizations by compromising trusted third-party software. Notable incidents include M.E.Doc accounting software and SolarWinds Orion.

Execution [TA0002]

Command and Scripting Interpreter: PowerShell [T1059.003] and Windows Command Shell [T1059.003]

Russian state-sponsored APT actors have used cmd.exe to execute commands on remote machines. They have also used PowerShell to create new tasks on remote machines, identify configuration settings, exfiltrate data, and execute other commands.

Persistence [TA0003]

Valid Accounts [T1078]

Russian state-sponsored APT actors have used credentials of existing accounts to maintain persistent, long-term access to compromised networks.

Credential Access [TA0006]

Brute Force: Password Guessing [T1110.001] and Password Spraying [T1110.003]

Russian state-sponsored APT actors have conducted brute-force password guessing and password spraying campaigns.

OS Credential Dumping: NTDS [T1003.003]

Russian state-sponsored APT actors have exfiltrated credentials and exported copies of the Active Directory database ntds.dit.

Steal or Forge Kerberos Tickets: Kerberoasting [T1558.003]

Russian state-sponsored APT actors have performed “Kerberoasting,” whereby they obtained the Ticket Granting Service (TGS) Tickets for Active Directory Service Principal Names (SPN) for offline cracking.

Credentials from Password Stores [T1555]

Russian state-sponsored APT actors have used previously compromised account credentials to attempt to access Group Managed Service Account (gMSA) passwords.

Exploitation for Credential Access [T1212]

Russian state-sponsored APT actors have exploited Windows Netlogon vulnerability CVE-2020-1472 to obtain access to Windows Active Directory servers.

Unsecured Credentials: Private Keys [T1552.004]

Russian state-sponsored APT actors have obtained private encryption keys from the Active Directory Federation Services (ADFS) container to decrypt corresponding SAML (Security Assertion Markup Language) signing certificates.

Command and Control [TA0011]

Proxy: Multi-hop Proxy [T1090.003]

Russian state-sponsored APT actors have used virtual private servers (VPSs) to route traffic to targets. The actors often use VPSs with IP addresses in the home country of the victim to hide activity among legitimate user traffic.

For Additional TTPs Review These Known Actors

How Fortinet Can Help

Fortinet provides multiple opportunities for organizations to mitigate serious cyberattacks and investigate possible breaches. Below are just a few popular examples of the technologies and solutions Fortinet offers.  

  • Fortinet Cyber Threat Assessment: Secure network architectures need to constantly evolve to keep up with the latest advanced persistent threats. There are two ways to find out if your solution isn’t keeping up—wait for a breach to happen or run validation tests.

  • Managed Detection and Response: Fortinet helps customers better understand the cybersecurity risks they face and improve how they identify and react to threats. 

  • Fortinet Virtual Patching solutions: FortiGuard Labs protects against specific exploits. 

  • FortiGuard Incident Response Service: The FortiGuard Incident Response Service provides organizations in the midst of a cybersecurity incident (including targeted ransomware attacks), with experienced staff, expert skills, and powerful tools. 

  • FortiGuard IPS and Anti-Virus: Services and engines utilize a variety of techniques including multiple machine learning and artificial intelligence strategies to protect our customers against advanced and zero-day threats.

Further Reading 

Sourced from Fortinet

The Art of War (and Patch Management)

With escalating tensions in Ukraine and threats of nation state attacks, it is worth noting that modern warfare is no longer only based on traditional ground, air, or sea assaults but it has progressed to the point where cyber attacks are a common part of the offensive arsenal.  They are commonly made on the financial, government and communications of target countries in order to destabilize the country’s critical infrastructure and delay any required response to an attack.

Even if you are not directly in the line of fire, it is a timely reminder during these concerning times that we all need to be taking our cybersecurity more seriously. This is a sentiment echoed by Department of Justice (DoJ) official – Deputy Attorney General Lisa Monaco in remarks at the Munich Cybersecurity Conference

“Given the very high tensions that we are experiencing, companies of any size and of all sizes would be foolish not to be preparing right now as we speak — to increase their defenses, to do things like patching, to heighten their alert systems, to be monitoring in real-time their cybersecurity. They need to be as we say, ‘shields up’ and to be really on the most heightened level of alert that they can be and taking all necessary precautions.”

Why do we even need to say this?

Anyone who has been keeping up with Fortinet blogs is aware that we have been saying this for some time, Prioritizing Patching is Essential for Network Integrity.  We are dealing ourselves from the fallout of some customers not patching. It has caused an ongoing news cycle related to an SSL-VPN issue resolved back in 2019, which remains unpatched for some customers. If you take nothing else away from this blog, check that you have taken action to remediate this issue.

Given that some organizations are not always taking action to patch, how can we better understand the reasons why, so that we can help to change this behavior?  Human psychology gives us some useful clues in why this is the case. 

Hyperbolic discounting is a cognitive bias that refers to the inclination to choose immediate rewards over rewards that come later in the future, even when these immediate rewards are smaller.  This is most clearly demonstrated by the phrase: “A bird in the hand is worth two in the bush.”

In cybersecurity terms: I will continue working on a time-sensitive project that my boss is chasing rather than patching systems against a cybersecurity issue that might never happen – “maybe we’ll get lucky and nobody will attack us.”

The situation in Ukraine and the warning from DoJ Official Lisa Monaco demonstrates we should not be taking this lightly but we need to change human nature if we want to succeed in prioritizing patch management. To do this, we need to give people an instant payback. 

Removing Cognitive Bias

This is where the Security Rating Service comes into play – helping to remove this cognitive bias. It gives customers immediate feedback that the actions they are taking have an impact on the security of their systems.  Whilst this has been available for some time, in the coming months we will push this to the next level, and will include patching (or lack of) into the rating and providing a roll-up report in FortiCare to help encourage this process even further.

Find out how the Fortinet Security Fabric platform delivers broad, integrated, and automated protection across an organization’s entire digital attack surface to deliver consistent security across all networks, endpoints, and clouds. 

Sourced from Fortinet

The Need for a Zero Trust Edge Strategy

Today’s hybrid workers require access to distributed applications deployed in the datacenter, multi-cloud environments, and SaaS locations. Digital acceleration involves adopting and implementing new technologies and practices to improve business agility and employee productivity. But it is also redefining the network edge—especially in today’s Work-from-Anywhere world where users move between on-premises locations, interconnected branch locations, home offices, and temporary locations during travel—thereby expanding the attack surface and exposing the business to new, advanced threats.

Unfortunately, most traditional network architectures were built using disparate and statically deployed point products that provide implicit access to all applications. However, such an approach is no longer effective at providing secure access to critical resources at scale, especially as users, devices, and applications are in constant motion. And the inevitable rerouting of traffic to fixed security points for inspection severely impacts user experience, especially when those tools cannot adequately examine encrypted application, data, and video streams. Far too often, the default response in many organizations has been to bypass security to not impact critical business operations. And the result has been disastrous, with ransomware, phishing, botnet, and other criminal activity now at an all-time high.

What’s needed is a secure Digital Acceleration strategy that ensures that new technologies can be adopted and new, highly dynamic edges can be established without compromising the protection of critical data or the security of users and devices. Zero-trust is based on the principle that every device or user is potentially compromised, and therefore every access request must be authorized and continuously verify. And even then, users and devices can only access those resources required to do their job and nothing more.

This same approach is now being applied to the remote edges of the network, a strategy known as the “Zero Trust Edge.” This new zero-trust approach to securing the expanding edges of today’s networks helps ensure that Security-Driven Networking – the critical convergence of security and networking – is everywhere. This enables security to seamlessly adapt to dynamic changes to the underlying network infrastructure, including connectivity, while providing explicit access to applications based on user identity and context.

Security-Driven Networking from Fortinet

Forrester recently described a solution they have dubbed the “All-In-One Zero Trust Edge” in the Now Tech Report published in December 2021. In that report, they described the future of next-generation networking infrastructure as bringing together networking and security in any combination of cloud, software, and hardware components, securely interweaving users, data, and resources using essential zero-trust principles.

Fortinet is recognized in this report. We believe that’s because we uniquely bring together all components needed to converge networking and security and can then deploy them on premises and in the cloud, including SD-WAN, NGFW and ZTNA. This ensures that we can deliver consistent convergence and zero implicit trust everywhere. We call this Security-Driven Networking.

Fortinet’s Security-Driven Networking approach starts with FortiOS-based innovations, including our on-premises SD-WAN and next-generation firewall secure access solutions, which also includes built-in ZTNA. It continues in the cloud with Fortinet’s cloud-based secure web gateway, CASB, and ZTNA solutions for remote users. 

What is a Zero Trust Edge solution?

Fortinet’s Security-Driven Networking innovations deliver the industry’s most complete Zero Trust Edge solution:

1. SD-WAN: Providing better path and user-experience to applications and services using SD-WAN is foundational for any Zero Trust Edge solution. Fortinet was the first vendor to blend advanced security and connectivity into a unified solution. Our Secure SD-WAN solution securely interconnects all offices to every datacenter, multi-cloud, and SaaS environment. And in addition to reliable connectivity and cloud on-ramp, it includes a full suite of advanced security, enables dynamic segmentation to prevent lateral threat movement for East-West protection, and maintains superior user experience through digital experience monitoring.

2. Hybrid Convergence of Networking and Security: Zero Trust Edge must also support today’s highly dynamic networks. Legacy security solutions struggle to provide consistent policy distribution, orchestration, and enforcement when the underlying network is in constant motion. Integrating security and networking into a unified system is essential for deploying consistent security everywhere, both for on-premises and remote users. Fortinet is the only vendor to deliver networking and security convergence powered by the same operating system (FortiOS) to offer seamless policy distribution and orchestration. We also provide the industry’s highest security performance using our purpose-built security ASICs, enabling the inspection of encrypted traffic, including streaming video, without impacting user experience.

3. Secure Remote Access: Cloud-delivered security that securely connects all remote users is essential to any Zero Trust Edge solution. Comprehensive web security from the cloud must provide multiple layers of defense with AI-driven web filtering, video filtering, DNS filtering, IP Reputation, Anti-botnet service including the ability to address data loss prevention and protect mobile users with in-line CASB integration.

4. ZTNA Everywhere: Finally, Zero Trust Network Access (ZTNA) is essential for securing access to the critical applications and resources today’s hybrid workforce demands. However, protecting a hybrid workforce that may be in the office one day, working from home the next, and traveling another requires a ZTNA solution that is available everywhere users or devices are located. Unlike traditional VPN, ZTNA provides explicit access to users per application based on identity and context. Fortinet is the only vendor with a ZTNA solution designed to protect access from any edge, not just a few edges.

Fortinet’s Security-driven Networking Approach to Zero Trust Edge

Fortinet’s innovative approach to Zero Trust Edge converges enterprise-class security and networking everywhere across the network. This unique ability ensures secure access to critical applications and resources, whether users are on-premises or accessing resources through the cloud. Our Security-Driven Networking approach—including our unique combination of exclusive purpose-built ASICs, cloud-delivered security solutions, and integrated networking capabilities—enables superior user experience combined with coordinated threat protection for every network edge.

Zero Trust Edge resolves one of the most enduring challenges facing today’s IT teams: extending enterprise-grade security and granular access control to remote workers. Fortinet’s Security-Driven Networking approach provides a unique solution to overcoming user experience, siloed and disconnected networking/security technologies, and implicit trust challenges that create obstacles for today’s organizations serious about digital acceleration and implementing an effective—and secure—work from anywhere strategy.               

Read more about Zero Trust Edge in the recent Forrester report and find out how you can implement an enterprise-wide Zero Trust Edge architecture with Fortinet’s Security-Driven Networking approach.

Sourced from Fortinet

Fortinet’s Ken Xie Speaks About Growth, Securing WFA, and the Future of Cybersecurity

For over 20 years, Fortinet has been a driving force in the evolution of cybersecurity. Fortinet security solutions are the most deployed, most patented, and most validated in the industry. Fortinet’s broad, complementary portfolio of cybersecurity solutions is built with interoperability and automation in mind, enabling a rapid, unified response to known and unknown threats while simplifying management. They also extend that performance and functionality to every network edge, including the newly expanded remote workforce and adaptive cloud environments that require data and compute resources to reside as close to the end-user as possible.

Ken Xie, Founder, Chairman, and CEO, recently offered his perspective on the cybersecurity industry, company momentum, and important customer trends after releasing Fortinet’s financial results for Q4 of 2021, marking another successful quarter and fiscal year for Fortinet around the world.

Can you give a brief overview of Fortinet’s business momentum?

We are very pleased with our performance. Our teams navigated through a challenging environment to deliver excellent growth and financial results.

In Q4, bookings increased 49% to $1.43 billion and billings increased 36% to $1.31 billion. Our G2000 billings growth accelerated to over 90%. Total revenue grew 29% to $964 million, with product revenues up 31%. For the full year, revenue was $3.3 billion and GAAP operating margin was 20%. We generated a record $1.2 billion of free cash flow and we reported our thirteenth consecutive year of GAAP profitability. And we passed an important milestone of more than 10,000 employees.

This strong business momentum reinforces our focus on key growth areas, such as the convergence of security and networking, the continued expansion of the Security Fabric mesh platform and our leadership in OT. Another factor driving our record-setting product revenue growth and market share gains has been the growing adoption of our Secure SD-WAN and 5G-enabled SD-Branch.

What are you hearing from customers today? What is top of mind?

Customers are increasingly focused on convergence, vendor consolidation to a fabric mesh platform to reduce complexity, and increasing performance and speed. As the network perimeter continues to fragment, security teams and tools are increasingly operating in silos. And efforts to integrate point solutions only add to the complexity because such workarounds need to be reconfigured every time one of the solutions in place needs to be updated. Addressing this challenge requires a more integrated approach, which is why Gartner is predicting that “by 2024, organizations adopting a cybersecurity mesh architecture will reduce the financial impact of individual security incidents by an average of 90%.”

Where will Fortinet focus going forward?

The total addressable market for network security is rapidly expanding and growing at a faster rate. To support this evolution, we are focused on leveraging our ASIC-supported Security Fabric mesh platform across the expanding network to drive better-than-industry-average long-term growth. Our unrivaled SPUs (security processing units) offer 5 to 10 times more security computing power than comparable systems, resulting in greater integrated functionality, lower costs, and reduced power consumption compared to a general CPU. And our virtual SPUs (vSPU) extend much of that same performance to non-physical environments. We are also helping customers solve the challenges of complexity through our security-driven networking and Security Fabric platform approaches. And our organically developed Security Fabric solutions, like email, web, endpoint, FortiGate firewall, advanced networking, and connectivity solutions, like SD-WAN, offer much broader protection, integration, and automation than our competitors’ offerings.

How is Fortinet securing the expanding work-from-anywhere trend?

The COVID-19 pandemic greatly expanded the work-from-anywhere (WFA) model. According to Gartner, organizations are facing a hybrid future, with “75% of hybrid or remote knowledge workers [saying] their expectations for working flexibly have increased.” This has overwhelmed their staff, but it has also increased the complexity of their networks.

Fortinet last year announced the industry’s most complete solution for securing and connecting work-from-anywhere to better address this shift. Our Fortinet Security Fabric mesh platform delivers security, services, and threat intelligence that follows users at home, in the office, or on the road. This unified approach also includes critical networking and connectivity solutions to provide a complete enterprise-grade solution.

We are also working to secure WFA through our Training Advancement Agenda (TAA). On the heels of the Biden Administration calling for cross-sector leaders to tackle the cybersecurity challenges affecting organizations and people globally, we announced that we are furthering our commitment to significantly reducing the cyber skills gap. In addition to growing our programs and strategic partnerships to address the talent shortage plaguing our industry, we have pledged to train 1 million people globally across the next five years through our Fortinet NSE Institute and Fortinet TAA initiatives and programs. 

Can you speak to the evolving threat landscape? What should customers be thinking about?

The intensity and sophistication of cybercriminals continues to increase. They are taking a holistic approach to attacks. To address this challenge, organizations need to adopt a security-driven networking approach that weaves core security capabilities combined with actionable threat intelligence deep into every environment of their network.  

This security-driven networking strategy enables organizations to have complete visibility across their entire network—from the core, out to the branch, the cloud, the home office, and the emerging edge—helping keep them relevant, competitive, and resilient. With security woven into their core, networks can also evolve, expand, and adapt to the next generation of digital innovation, including hyperscale, hyperconnectivity, and 5G+ environments.  

Find out how the Fortinet Security Fabric platform delivers broad, integrated, and automated protection across an organization’s entire digital attack surface to deliver consistent security across all networks, endpoints, and clouds.

Sourced from Fortinet

Fortinet’s Ken Xie on the Evolution of Cybersecurity & Work-From-Anywhere

For over 20 years, Fortinet has been a driving force in the evolution of cybersecurity. Fortinet security solutions are the most deployed, most patented, and most validated in the industry. Fortinet’s broad, complementary portfolio of cybersecurity solutions is built with interoperability and automation in mind, enabling a rapid, unified response to known and unknown threats while simplifying management. They also extend that performance and functionality to every network edge, including the newly expanded remote workforce and adaptive cloud environments that require data and compute resources to reside as close to the end-user as possible.

Ken Xie, Founder, Chairman, and CEO, recently offered his perspective on the cybersecurity industry, company momentum, and important customer trends after releasing Fortinet’s financial results for Q4 of 2021, marking another successful quarter and fiscal year for Fortinet around the world.

How Fortinet Leads the Evolution of the Cybersecurity Industry

To kick the interview off, we asked Ken Xie a few questions about how the cybersecurity industry is evolving and Fortinet’s business momentum. Here’s what he had to say:

Can you give a brief overview of Fortinet’s business momentum?

We are very pleased with our performance. Our teams navigated through a challenging environment to deliver excellent growth and financial results.

In Q4, bookings increased 49% to $1.43 billion and billings increased 36% to $1.31 billion. Our G2000 billings growth accelerated to over 90%. Total revenue grew 29% to $964 million, with product revenues up 31%. For the full year, revenue was $3.3 billion and GAAP operating margin was 20%. We generated a record $1.2 billion of free cash flow and we reported our thirteenth consecutive year of GAAP profitability. And we passed an important milestone of more than 10,000 employees.

This strong business momentum reinforces our focus on key growth areas, such as the convergence of security and networking, the continued expansion of the Security Fabric mesh platform and our leadership in OT. Another factor driving our record-setting product revenue growth and market share gains has been the growing adoption of our Secure SD-WAN and 5G-enabled SD-Branch.

What are you hearing from customers today? What is top of mind?

Customers are increasingly focused on convergence, vendor consolidation to a fabric mesh platform to reduce complexity, and increasing performance and speed. As the network perimeter continues to fragment, security teams and tools are increasingly operating in silos. And efforts to integrate point solutions only add to the complexity because such workarounds need to be reconfigured every time one of the solutions in place needs to be updated. Addressing this challenge requires a more integrated approach, which is why Gartner is predicting that “by 2024, organizations adopting a cybersecurity mesh architecture will reduce the financial impact of individual security incidents by an average of 90%.”

Where will Fortinet focus going forward?

The total addressable market for network security is rapidly expanding and growing at a faster rate. To support this evolution, we are focused on leveraging our ASIC-supported Security Fabric mesh platform across the expanding network to drive better-than-industry-average long-term growth. Our unrivaled SPUs (security processing units) offer 5 to 10 times more security computing power than comparable systems, resulting in greater integrated functionality, lower costs, and reduced power consumption compared to a general CPU. And our virtual SPUs (vSPU) extend much of that same performance to non-physical environments. We are also helping customers solve the challenges of complexity through our security-driven networking and Security Fabric platform approaches. And our organically developed Security Fabric solutions, like email, web, endpoint, FortiGate firewall, advanced networking, and connectivity solutions, like SD-WAN, offer much broader protection, integration, and automation than our competitors’ offerings.

Evolving Cybersecurity Strategy to Support Work-From-Anywhere

As organizations accelerate digital initiatives with the need to deliver faster and better application experiences they struggle to keep their expanding networks secure. This challenge is increased by operational complexity, visibility gaps, and an expanding attack surface created by the transition to work-from-anywhere. Here’s what Ken Xie had to say:

How is Fortinet securing the expanding work-from-anywhere trend?

The COVID-19 pandemic greatly expanded the work-from-anywhere (WFA) model. According to Gartner, organizations are facing a hybrid future, with “75% of hybrid or remote knowledge workers [saying] their expectations for working flexibly have increased.” This has overwhelmed their staff, but it has also increased the complexity of their networks.

Fortinet last year announced the industry’s most complete solution for securing and connecting work-from-anywhere to better address this shift. Our Fortinet Security Fabric mesh platform delivers security, services, and threat intelligence that follows users at home, in the office, or on the road. This unified approach also includes critical networking and connectivity solutions to provide a complete enterprise-grade solution.

We are also working to secure WFA through our Training Advancement Agenda (TAA). On the heels of the Biden Administration calling for cross-sector leaders to tackle the cybersecurity challenges affecting organizations and people globally, we announced that we are furthering our commitment to significantly reducing the cyber skills gap. In addition to growing our programs and strategic partnerships to address the talent shortage plaguing our industry, we have pledged to train 1 million people globally across the next five years through our Fortinet NSE Institute and Fortinet TAA initiatives and programs. 

Can you speak to the evolving threat landscape? What should customers be thinking about?

The intensity and sophistication of cyber criminals continues to increase. They are taking a holistic approach to attacks. To address this challenge, organizations must adopt a security-driven networking approach that weaves core security capabilities combined with actionable threat intelligence deep into every environment of their network.  

This security-driven networking strategy enables organizations to have complete visibility across their entire network—from the core, out to the branch, the cloud, the home office, and the emerging edge—helping keep them relevant, competitive, and resilient. With security woven into their core, networks can also evolve, expand, and adapt to the next generation of digital innovation, including hyperscale, hyperconnectivity, and 5G+ environments.    

Find out how the Fortinet Security Fabric platform delivers broad, integrated, and automated protection across an organization’s entire digital attack surface to deliver consistent security across all networks, endpoints, and clouds.

Sourced from Fortinet

New FortiGate 3000F Series Secures Digital Acceleration for Hybrid IT

The advantages—and challenges—of hybrid IT

Fortinet is pleased to announce the launch of the FortiGate 3000F, the latest next-generation firewall in Fortinet’s portfolio designed to protect today’s hybrid IT environments. This timely release is essential for today’s organizations struggling to secure their digital acceleration efforts. Hybrid IT architectures present critical security challenges that most legacy security solutions cannot address. While they enable organizations to implement critical new business applications and services, allowing users to work from anywhere, they also significantly increase the attack surface. And in addition to having more locations, devices, applications, and services to protect, most hybrid IT architectures are also in a state of constant flux as they expand and adjust to meet shifting business requirements.

Another security challenge for hybrid IT is that most legacy networks operate from a position of implicit trust, where users and devices inside the perimeter are assumed to be reliable and secure. Unfortunately, distributing such unfettered access to the internal resources across today’s hybrid IT architectures means malicious actors that breach the network—through unprotected home offices or compromised public access points—are also free to search for data to steal and resources to corrupt or hold for ransom.  

FortiGate—The only NGFW to support natively integrated ZTNA and security-driven networks

Today’s next-generation firewall must be able to secure today’s hybrid IT environments. The reality is, most can’t. Instead, they struggle to keep up as the network scales and adapts to changing digital requirements. That’s why, in addition to its traditional security functions, FortiGate NGFWs like the 3000F include industry-first innovations, such as having all its technologies and services running under a common operating system to simplify management and orchestration. They also include the industry’s first fully integrated Secure SD-WAN as well as built-in ZTNA proxy to provide a converged network and security approach to connectivity. And to top it all off, FortiGate features the world’s only purpose-built ASICs—Fortinet’s Security Processing Units (SPUs)—making it the industry’s fastest NGFW. These ASICs enable FortiGate solutions to efficiently handle processor-intensive functions, such as inspecting encrypted streaming video, which is increasingly critical for today’s remote workforce.

We believe it is this commitment to innovation that has led to Fortinet being ranked #1 for the Enterprise Data Center Use Case in the 2022 Gartner® Critical Capabilities for Network Firewalls report. In fact, Fortinet has received the highest score for the Enterprise Data Center use case three years in a row.

Introducing the FortiGate 3000F: designed to converge and accelerate digital transformation

The FortiGate 3000F is the latest addition to the NGFW portfolio, designed to help customers secure today’s hybrid IT campus and data center architectures in the following ways:

  • Hyperscale: The FortiGate 3000F delivers the most scalability in the industry due to its purpose-built Fortinet SPUs, including the NP7 and CP9, still the world’s only custom security processors.
  • Converge and Accelerate: The FortiGate 3000F seamlessly converges and accelerates networking and security. Its advanced routing capabilities allow it to peer with multiple providers on the WAN (Wide Area Network) side and interconnect with a wide array of vendors in the LAN (Local Area Network). Many enterprises have simplified their operations by replacing their edge router/firewall combinations with a single FortiGate device that offers both networking and security functions.
  • Latest and Most Innovative Video Policy: The FortiGate 3000F NGFW is the first in the industry to offer advanced content policies, like real-time video filtering for mainstream services like YouTube, Vimeo, and Dailymotion. Enterprises can build flexible policies to allow one or many categories and stringent network security controls that can allow or block video traffic up to the channel level.
  • Complete High-Fidelity Visibility and Protection: With unprecedented SSL inspection performance (including TLS 1.3), the FortiGate NGFW detects threats hidden in encrypted paths and provides automated threat protection with the least performance degradation in the industry.
  • AI/ML-powered Enterprise-Grade Security: FortiGate NGFWs seamlessly weave networking, security, and essential AI/ML-powered FortiGuard services into a single platform, enabling IT teams worldwide to effectively manage internal and external threats.
  • Micro- and Macro-Segmentation: The FortiGate NGFW also provides flexible and dynamic segmentation—built around business growth objectives, security, and compliance controls—to prevent the lateral spread of malware, including ransomware, to prevent business disruptions.
  • Automate & Simplify: A unified security strategy designed to span today’s dynamic, hybrid environments is essential. The centralized Fortinet Fabric Management Center provides single-pane-of-glass management, automation, and orchestration across the Security Fabric, including support for over 470 ecosystem partners, simplifying the enterprise-wide workflows essential for today’s hybrid networks.

Every network is only as secure as its weakest point. Digital acceleration requires hybrid IT architectures to span and scale across multiple ecosystems to ensure that critical data is available to any user, on any device, from any location without compromise. Achieving this, however, requires consistent security everywhere—something that most legacy security solutions and strategies are unable to provide. The FortiGate NGFW Series, including the new FortiGate 3000F, enables organizations to establish and maintain consistent and converged network security while delivering the industry’s highest Security Compute Ratings.

Learn more about FortiGate NGFW solutions and the new FortiGate 3000F.


Gartner, Critical Capabilities for Network Firewalls, By Adam HilsRajpreet Kaur, 17 January 2022 

Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s Research & Advisory organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved.

Sourced from Fortinet

Fortinet Named a Strong Performer in the 2021 Forrester Wave™ for Industrial Control Systems (ICS) Security

Forrester recently published the Forrester Wave™: Industrial Control Systems (ICS) Security Solutions, Q4, 2021 report, and we are pleased to announce that Fortinet has been positioned as a Strong Performer. We believe our position in third-party reports such as the Forrester Wave highlights our scale, large customer base, and proven traction in the market to help organizations feel confident in their decision to work with Fortinet. We are also proud to be selected as one of only 12 vendors.

Besides receiving the highest score possible in the “number of customers” criterion, Fortinet received the highest score possible in six other criteria, including policy and rule management, microsegmentation, APIs and integrations, product security, partner ecosystem, and product revenue. We believe our 5/5 scores in the “Partner Ecosystem” and “APIs and Integrations” critieria are highly relevant considering, in our opinion, the placement of several Fortinet Fabric-Ready Technology Alliance partners in the Wave report. According to the Forrester report, “Fortinet’s strength in ICS security stems from its market-leading integration breadth with IT and OT technology vendors. This includes integrations with ICS security vendors and control system vendors.”

Fortinet’s technology integrations with top visibility and automation and control vendors, made possible through our open APIs via the Fabric-Ready Partner program, include such leaders as Claroty, Dragos, Microsoft, Nozomi, and Tenable. These close collaborations further emphasize the value Fortinet brings to securing OT environments. For example, our leading policy and microsegmentation capabilities are informed through these strategic partnerships, enabling our solutions to execute granular response and control of protocols and policies uniquely suited to each OT environment. The symbiotic relationship with our ecosystem partners’ technology provides customers with highly advanced cyber protection. We’re also proud that the majority of our OT ecosystem partners appreciate the breadth of Fortinet’s Security Fabric and integrate with multiple product families within the expansive Fortinet portfolio. This signals their commitment to Fortinet’s unique Security Fabric strategy of providing comprehensive defense-in-depth solutions that can span the most distributed OT environments.

While we are pleased to be identified as a Strong Performer in the Forrester report, we recognize that the Wave placed a relatively higher weighting on asset identification and visibility in evaluating the current offerings of all Wave participants. The first step any industrial asset owner should take is to segment their high CapEx OT assets away from their IT infrastructure. Segmenting critical assets should occur before investing in visibility and asset management infrastructure. One of our greatest strengths is that our market-leading FortiGate Next-Generation Firewalls are ideally suited to this task, especially given our focus on Industrial OT protocol support and ruggedized designs that can withstand the harsh environments found on plant floors, production yards, or in the field.

Additionally, our industry-first Security Fabric approach provides OT-targeted features and capabilities in each of our product families, such as our fully integrated endpoint and deception technologies. FortiEDR not only includes application allow/deny lists but also runs on legacy operating systems, such as Windows XP, rarely supported by other EDR vendors yet all too often found in OT environments. Similarly, FortiDeceptor can mimic the PLCs and HMIs frequently found in ICS environments and respond in an OT manner, using commonly found OT protocols to provide seamless protections indistinguishable from legitimate ICS traffic. Similar OT-specific benefits can be found in our FortiSandbox, FortiNAC, FortiSIEM, and other products.

Fortinet is deeply committed to providing advanced and integrated security solutions designed for the challenges of today’s expanding and converging OT environments. That is why Forrester’s recognition of Fortinet is deeply gratifying. It should signal to organizations that Fortinet is uniquely positioned to provide the level of protection their networks require—whether implementing an integrated OT security fabric, seamlessly combining Fortinet solutions with those from other leading OT vendors, or building a comprehensive cybersecurity mesh architecture designed to span today’s hybrid IT and OT environments.

Read the Forrester Wave: ICS Security Solutions, Q4 2021 report or learn more about Fortinet’s Operational Technology solutions.

Sourced from Fortinet

Fortinet Scores Highest in Three Use Cases in the 2022 Gartner Critical Capabilities for Network Firewalls Report

Cyberattacks are emerging as a global threat, not just to organizations but to the global digital economy. The US Treasury’s Financial Crimes Enforcement Network (FinCEN) recently reported that organizations paid out nearly $600 million in ransomware in the first half of 2021, which puts the US on track to surpass the combined payouts of the previous decade. And that’s just the start. Not only is ransomware predicted to increase, but more and different threats are looming on the horizon. So, while the World Economic Forum has estimated costs from cybercrime will come in this year at a staggering $2.2 trillion, that number is likely to increase by nearly 5X to $10.5 trillion by 2025.

Part of this trend is the result of cybercriminals actively targeting today’s expanding and increasingly complex networks. The adoption of multi-cloud networks to distribute and host applications and services, the demand for flexible and ubiquitous connectivity to highly dispersed applications by today’s hybrid workforce, and the push to accelerate digital transformation have not only expanded the attack surface but also created a perfect storm of complexity, lack of visibility, inconsistent security, and poor user experience. Organizations need solutions designed to address these challenges while providing ubiquitous and comprehensive threat protection without sacrificing flexibility, performance, or user experience.

Securing Your Digital Business Acceleration: Gartner’s 2022 Critical Capabilities for Network Firewalls

The January 2022 Gartner Critical Capabilities for Network Firewall report is an extension of their recently published Magic Quadrant™ for Network Firewalls, in which Fortinet was recognized as a “Leader.” We believe this report offers essential research and analysis to help technology practitioners evaluate vendors based on their performance in various use cases.

Gartner Critical Capabilities report evaluated nineteen Network Firewall vendors, for their performance across nine critical capabilities, with methodologies that assign different weights for each ability. We believe this information is designed to assist organizations in determining which solution will best help them achieve the strongest security posture, best ROI, and optimal operational efficiency for their digital business use case.

Fortinet’s FortiGate solution received the overall highest scores in the Enterprise Data Center, Distributed Enterprise Edge, and SMB Use Cases, and the second-highest score in the Public Cloud Use Case:

Enterprise Data Center Use Case

This marks the third year in a row that Fortinet has received the highest overall score for the Enterprise Data Center Use Case. 

Why it matters

Most organizations have critical applications and data that can’t be moved to the cloud for various reasons, such as compliance, control, and strategic business needs. But hosting them on-premises in the data center requires them to be protected from intruders while safely providing access to customers, employees, and partners and keeping pace with user experience expectations and digital acceleration efforts elsewhere.

The FortiGate Network Firewall’s deeply integrated networking and security capabilities protect corporate and customer data and applications as well as the service edge to enable hyperscale security-driven networks. 

Why it matters

Digital acceleration is driving WAN transformation. Enterprise Edge security must address rising ransomware and cyberattacks while enabling organizations to confidently adopt multiple clouds and maintain flexible connectivity. Consistent security coupled with reliable user experience allows users and applications to be located anywhere, addressing the needs of today’s highly flexible and mobile networks.

Fortinet’s innovative FortiGate Network Firewall has made us the first vendor to transform and secure the WAN. We were not just the first vendor to add SD-WAN to our NGFW solution. We also pioneered blending SD-WAN connectivity with integrated security—and now, ZTNA capabilities—all powered by a single operating system, FortiOS.

SMB Use Case

Why it matters

Despite their size, SMBs are adopting technology faster than ever, especially as staff becomes more knowledgeable and costs decrease. However, this rapid adoption is increasing their attack surface, and as a result, SMBs require powerful network security to prevent attacks. Fortinet’s FortiGate Network Firewall is designed with simplicity in mind, with entry-level models that enable even small businesses to deploy robust and consistent security both on-premises and in the cloud. 

Public Cloud Use Cases

Why it matters

Organizations are accelerating cloud adoption to address growing requirements for agility, scalability, and digital transformation. This invariably leads to multi-cloud adoption, which means that critical business resources and assets are increasingly reliant on secure cloud solutions and infrastructures. However, organizations often end up with a heterogeneous set of security technologies, with disparate cloud security controls in various cloud environments that do not work together as a unified solution. 

Fortinet’s virtual FortiGate solutions were not only the first to operate natively on every cloud platform but also use custom-built, turnkey cloud connectors to enable seamless orchestration and consistent policy enforcement end-to-end for data and applications that move between multiple clouds. 

Conclusion

As part of the Fortinet Security Fabric, FortiGate Network Firewalls enable and accelerate digital innovation initiatives. Their coordinated threat intelligence sharing and automated protections ensure security for today’s complex and fast-evolving threat landscape without ever compromising on digital innovation, performance, or user experience. In addition to the Fortinet Security Fabric components being fully integrated, they also use Open APIs to extend that interoperability to 450+ partners—streamlining enterprise-wide workflows and enabling customers to build scalable and composable end-to-end security architectures, like Gartner Cybersecurity Mesh Architecture.

Download the 2021 Gartner Magic Quadrant for Network Firewalls and the 2022 Gartner Critical Capabilities for Network Firewalls for more information.

 

Gartner, Critical Capabilities for Network Firewalls, Adam Hils, Rajpreet Kaur, 17 January 2022

Gartner, Magic Quadrant for Network Firewalls, Rajpreet Kaur, Jeremy D’Hoinne, Nat Smith, Adam Hils, 1 November 2021

Gartner and Magic Quadrant are registered trademarks of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved

This graphic was published by Gartner, Inc. as part of a larger research document and should be evaluated in the context of the entire document. The Gartner document is available upon request from https://www.fortinet.com/solutions/gartner-critical-capabilities-network-firewalls.

Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s research organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose.

Sourced from Fortinet