{"id":43767,"date":"2019-11-28T13:25:24","date_gmt":"2019-11-28T13:25:24","guid":{"rendered":"https:\/\/www.intelligentcio.com\/me\/?p=43767"},"modified":"2019-11-28T13:25:27","modified_gmt":"2019-11-28T13:25:27","slug":"fortinet-expert-on-re-assessing-network-security-strategies","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2019\/11\/28\/fortinet-expert-on-re-assessing-network-security-strategies\/","title":{"rendered":"Fortinet expert on re-assessing network security strategies"},"content":{"rendered":"\n<p><em>Digital Transformation has introduced new risks as the once well-defined network perimeter and the security protections associated with it have dissolved. Alain Sanchez, Senior CISO Evangelist at Fortinet, tells us why CISOs need to reassess their approach to network security to ensure their organisations are future-proof. \u00a0\u00a0<\/em><\/p>\n\n\n\n<p><strong>How\nwould you describe the current threat landscape?<\/strong><\/p>\n\n\n\n<p>The volume\nand velocity of threats continues to explode. There are many reasons for this\nexplosive growth, starting with the fact that the bar for accessing malware is\nlower than ever due to the availability of Malware-as-a-Service (MaaS) and\nother on demand services on the Dark Net. <\/p>\n\n\n\n<p>Advanced\nthreats are becoming more sophisticated at the same time. Many are now\nmulti-vector, concurrently targeting different points on the expanded attack\nsurface in coordination. <\/p>\n\n\n\n<p>All at\nonce, an attack can blitz an organisation from a central data centre out to the\nnetwork edge, targeting a full spectrum of endpoint devices and applications\nacross on-premises and cloud environments. These advancements are also making\nit more difficult to detect and respond to breaches. <\/p>\n\n\n\n<p><strong>How\nhave Digital Transformation initiatives impacted the attack surface?<\/strong><\/p>\n\n\n\n<p>Driven by\nthe desire to move faster at global scale and to transform customer\nexperiences, companies are reconsidering how they run their businesses \u2013 and Digital Transformation (DX) is at the\nforefront. Despite the wide-ranging business advantages DX offers, it also\ncomes with new challenges. <\/p>\n\n\n\n<p>Specifically,\nas DX touches a myriad of technological aspects and extends from the data centre\nand enterprise campus to the edges of the network and cloud, the network perimeter\nessentially dissolves, exposing additional risks while ratcheting up the\ncomplexity of an already-complex security architecture. <\/p>\n\n\n\n<p>Sensitive\ndata can now reside across multiple clouds and is within reach of a growing\narray of deployed IoT devices. Traffic moves across the public Internet instead\nof private networks and extends to the edges of the network \u2013 from mobile devices and wireless access\npoints to operational technology (OT). <\/p>\n\n\n\n<p>This\nexpanded, dynamic attack surface dissolves the once well-defined network\nperimeter and the security protections associated with it. <\/p>\n\n\n\n<p>Seeking to\naddress the new vulnerabilities posed by this new network reality, many organisations\nhave deployed an array of largely disaggregated point security products. This\nde facto security architecture is disconnected, engendering multiple security\nand compliance gaps and inefficiencies that, ironically, diminish holistic\nprotection. <\/p>\n\n\n\n<p>Disaggregated\nsecurity also wastes staff resources by requiring manual workflows and\nadministration. Worst of all, this increases risk to organisations and security\nteams find themselves in a perpetual reactive mode with regard to current\nthreats, which leaves them unable to plan and anticipate the attacks to come in\nthe near future.<\/p>\n\n\n\n<p><strong>Why\ndo CISOs need to reassess how they are approaching the security of their\nnetworks?<\/strong><\/p>\n\n\n\n<p>The\njob scope of the CISO is becoming multi-dimensional; she or he needs to be a\nbusiness enabler, an agent of change and a human leader. In addition, the CISO needs to talk the\nlanguage of the business. And since managing a business is primarily managing risk,\nthe CISO needs to factor traditional network and security indicators into the\nrisk curve of his company. <\/p>\n\n\n\n<p>Instead of\nbeing Mr No: \u2018We cannot have this collaborative application, we can\u2019t have\npeople bringing in their own devices, we need to forbid social networks\u2019, the\nCISO of 2020 and beyond would say: \u2018These are the three possible scenarios\nregarding the use of social media inside our company, each of which is\nassociated to a risk level. The best ratio\/performance\/risk is the second one\nthat reduces the probability of GDPR infringement by 80% while enabling each\nemployee to connect to LinkedIn, Twitter and Office 365\u2019. <\/p>\n\n\n\n<p>This new\napproach will make the CISO part of the C-level suite, turning his cybersecurity\nknowledge into strategic recommendations based on business risk. <\/p>\n\n\n\n<p><strong>What\nare the key elements of Fortinet\u2019s network security solutions?<\/strong><\/p>\n\n\n\n<p>DX\nis an opportunity for nearly every organisation to achieve more flexibility and\ncost efficiency for itself and better experiences for its customers. At the\nsame time, DX increases the digital attack surface, gives hackers innovative\nways to generate increasingly sophisticated attacks and contributes to a\ngrowing complexity of regulations and security solutions. <\/p>\n\n\n\n<p>This\nwill not stop emerging leaders \u2013 the ones who build a foundation for managing\nrisk that enables their organisations to move faster than competitors in\nleveraging DX. <\/p>\n\n\n\n<p>The\nFortinet Security Fabric is that foundation. It unifies security solutions\nbehind a single pane of glass, makes the growing digital attack surface\nvisible, integrates AI-driven breach prevention and automates operations,\norchestration and response. In summary, it enables organisations\nto create new value with DX without compromising security for business agility,\nperformance and simplicity. <\/p>\n\n\n\n<p><strong>How\ndo Fortinet\u2019s solutions enable visibility and reduce complexity?<\/strong><\/p>\n\n\n\n<p>The\ninflux and speed of DX projects makes it harder for organisations to protect\nagainst advanced threats. Add new and evolving regulations and the adoption of\nsecurity standards, along with the fact that threats are faster and more\nadvanced than ever, and the complexity of security expands exponentially.<\/p>\n\n\n\n<p>Automated\nworkflows and orchestration \u2013 from detection, to protection, to response \u2013\nbecomes a requirement for any enterprise seeking to succeed in this complex\nworld of security management. This is where the Security Fabric delivers\ntangible dividends. <\/p>\n\n\n\n<p>Automation\nof network operations helps DevOps teams to focus on time to market, improves\noperational efficiencies through zero-touch provisioning and generates\nreal-time insights around branch network performance around issues such as\nspikes, scaling and priority routing of traffic.\nAutomation of security operations reduces risk through proactive threat\ndetection, threat correlation, intelligence-sharing alerts and threat research\nand analysis.<\/p>\n\n\n\n<p>Integration\nof IT service management (ITSM) tools unlocks automation of event analysis and\nresponses. This reduces response times from days to minutes or even seconds. <\/p>\n\n\n\n<p>The\nSecurity Fabric also uses automation to transform compliance audits, tracking\nand ongoing reporting across industry regulations and security standards. The\nlatter includes dashboards for the CISO, CIO, CEO and even the board of\ndirectors. This saves security teams myriad hours in manual log aggregation and\ncorrelation, a task that is particularly onerous with a disaggregated security\narchitecture lacking transparent visibility and centralised controls <\/p>\n\n\n\n<p><strong>Why\ndo organisations require a broad, integrated solution?<\/strong><\/p>\n\n\n\n<p>The\nvolume and velocity of malicious attacks, coupled with their increasing\nsophistication, makes it difficult for cybersecurity defences to keep pace.\nBlocking known threats is not enough today. Artificial intelligence (AI) and Machine\nLearning (ML) offer organisations the means stay ahead of cybercriminals.\nUnfortunately, only slightly more than one-third of security vendors use AI and\nML capabilities in their solutions. <\/p>\n\n\n\n<p>Fortinet\nrecognised the importance of doing so years ago in its development of FortiGuard\nAI. Specifically, FortiGuard Labs uses AI-driven capabilities, including ML,\nthat leverage 4.4 million sensors around the world and partnerships with over\n200 global organisations. This AI\/ML-driven threat intelligence uses five\nbillion nodes to identify unique malicious or clean features for both known and\nunknown threats. <\/p>\n\n\n\n<p>In all, FortiGuard Labs processes more than 100 billion web queries\nevery day and blocks 2,600 malicious URLs every second. Fortinet AI\/ML capabilities are also\nintegrated into FortiWeb and FortiInsight, enabling organisations to\ndramatically reduce false positives in the case of FortiWeb and to use\nforensics analysis at the user, system and network layers to detect and prevent\ninsider threats in the case of FortiInsight. <\/p>\n\n\n\n<p>Other\ncapabilities such as sandboxing and the use of decoys also play a critical role\nin stopping advanced threats before they impact operations or result in a data\nbreach. Specifically, both FortiSandbox and FortiDeceptor are fully integrated\ninto the Security Fabric, enabling them to automatically share their threat\nintelligence in real time across all of the security elements. <\/p>\n\n\n\n<p><strong>How\ndoes Fortinet ensure an organisation is future-proof?<\/strong><\/p>\n\n\n\n<p>From\nthe start, the Fortinet vision has been to deliver broad, truly integrated,\nhigh-performance security across the IT infrastructure. We provide top-rated\nnetwork and content security, as well as secure access products that share\nintelligence and work together to form a cooperative fabric. The Fortinet <a href=\"https:\/\/www.fortinet.com\/solutions\/enterprise-midsize-business\/enterprise-security.html\" target=\"_blank\" rel=\"noreferrer noopener\">Security Fabric<\/a>&nbsp;combines security\nprocessors, an intuitive operating system, and applied threat intelligence to\ngive organisations proven security, exceptional performance and better\nvisibility and control, while providing easier administration.&nbsp;&nbsp;<\/p>\n\n\n\n<p>The Fortinet Security Fabric delivers a unified approach that is\nbroad, integrated and automated. Reduce and manage the attack surface through integrated&nbsp;broad\nvisibility, stop advanced threats through&nbsp;integrated AI-driven breach\nprevention and reduce complexity through&nbsp;automated operations and\norchestration.<\/p>\n\n\n\n<p>Our flagship enterprise firewall\nplatform,&nbsp;<a href=\"https:\/\/www.fortinet.com\/products\/next-generation-firewall.html\" target=\"_blank\" rel=\"noreferrer noopener\">FortiGate<\/a>, is available in a wide range of sizes and form factors to fit any\nenvironment and provides a broad array of next-generation security and\nnetworking functions. Complementary products can be deployed with a FortiGate\nto enable a simplified, end-to-end security infrastructure covering:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/www.fortinet.com\/solutions\/enterprise-midsize-business\/network-security.html\" target=\"_blank\" rel=\"noreferrer noopener\">Network security<\/a>&nbsp;&#8211;&nbsp;Protect the entire attack surface from headquarters to\nbranch offices with advanced security<\/li><li><a href=\"https:\/\/www.fortinet.com\/solutions\/enterprise-midsize-business\/cloud-security.html\" target=\"_blank\" rel=\"noreferrer noopener\">Multi-cloud\nsecurity<\/a>&nbsp;&#8211;&nbsp;Complete visibility and\ncontrol across the cloud that enables secure applications and connectivity<\/li><li><a href=\"https:\/\/www.fortinet.com\/solutions\/enterprise-midsize-business\/secure-unified-access.html\" target=\"_blank\" rel=\"noreferrer noopener\">Secure access<\/a>&nbsp;&#8211;&nbsp;Deliver secure application, device access and\nmanagement without compromising performance and speed<\/li><li><a href=\"https:\/\/www.fortinet.com\/solutions\/enterprise-midsize-business\/security-operations.html\" target=\"_blank\" rel=\"noreferrer noopener\">Security operations<\/a>&nbsp;&#8211;&nbsp;Implement advanced threat intelligence to detect,\nprevent and respond to sophisticated malware and improve security awareness<\/li><li><a href=\"https:\/\/www.fortinet.com\/solutions\/enterprise-midsize-business\/network-operations.html\" target=\"_blank\" rel=\"noreferrer noopener\">Network operations<\/a>&nbsp;&#8211;&nbsp;Leverage a smart security strategy that prioritises\nautomation-driven network operations that spots and prevents network breaches<\/li><li><a href=\"https:\/\/www.fortinet.com\/solutions\/enterprise-midsize-business\/endpoint-and-device-protection.html\" target=\"_blank\" rel=\"noreferrer noopener\">Endpoint and\ndevice protection<\/a>&nbsp;&#8211;&nbsp;Proactive protection,\nvisibility and control for all endpoints and devices across the network<\/li><li><a href=\"https:\/\/www.fortinet.com\/solutions\/enterprise-midsize-business\/application-security.html\" target=\"_blank\" rel=\"noreferrer noopener\">Application security<\/a>&nbsp;&#8211;&nbsp;Protect critical business web applications with an\nintegrated set of products to thwart advanced threats<\/li><\/ul>\n\n\n\n<p>Our market position and solution\neffectiveness have been widely validated by industry analysts, independent\ntesting labs, business organisations and media outlets worldwide. We are proud\nto count the majority of Fortune 500 companies among our satisfied customers.<\/p>\n\n\n\n<p><strong>What\nbest practice approach should organisations take to ensure their networks are\nrobustly secured?<\/strong><\/p>\n\n\n\n<p>To effectively\nmanage and mitigate the cyber-risks organisations face today, it is essential that today&#8217;s security leaders monitor threat\nintelligence from a variety of sources and then prioritise those risks that map\nto their unique network environment. <\/p>\n\n\n\n<p>That\napproach needs to be coupled with a security strategy designed to see and stop,\nor at the least, strategically limit the impact of an attack coming from an\nunexpected quarter. That starts with an integrated security approach that\nincorporates every security element deployed anywhere across the distributed\nnetwork into a&nbsp;<a href=\"https:\/\/www.fortinet.com\/solutions\/enterprise-midsize-business\/security-fabric.html?utm_source=reuters&amp;utm_campaign=2018-reuters-security-fabric\">single security fabric<\/a>. <\/p>\n\n\n\n<p>That\nstrategy then needs to be augmented with&nbsp;<a href=\"https:\/\/www.fortinet.com\/solutions\/enterprise-midsize-business\/scalable-flexible-segmentation.html?utm_source=blog&amp;utm_campaign=2019-intent-based-segmentation\">intent-based segmentation<\/a>, consistent and relentless\nbest security practices, and automation combined with Machine Learning. AI is\nalso increasingly essential as it can take over tedious tasks such as patching,\nas well as find and respond to threats at digital speeds. <\/p>\n\n\n\n<p>Any\nsecurity strategy that does not include all of these essential elements will be\nunable to achieve the degree of visibility and control that today&#8217;s networks\nrequire. This, in turn, will unnecessarily expose the network to the efforts of\ntoday&#8217;s determined cybercriminal organisations.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Digital Transformation has introduced new risks as the once well-defined network perimeter and the security protections associated with it have dissolved. Alain Sanchez, Senior CISO Evangelist at Fortinet, tells us why CISOs need to reassess their approach to network security to ensure their organisations are future-proof. \u00a0\u00a0 How would you describe the current threat landscape? [&hellip;]<\/p>\n","protected":false},"author":28,"featured_media":43773,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,9961,13],"tags":[908,35,37],"class_list":["post-43767","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-thought-leadership","category-top-stories","tag-digital-transformation","tag-fortinet","tag-network-security"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/43767","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/28"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=43767"}],"version-history":[{"count":2,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/43767\/revisions"}],"predecessor-version":[{"id":43771,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/43767\/revisions\/43771"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/43773"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=43767"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=43767"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=43767"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}