• New Fortinet cloud-native service integrates Amazon Web Services' cloud security tools.
  • Deep integration makes for more efficient and frictionless deployments on AWS.
  • From a customer perspective, the most difficult aspect of cloud-native security is understanding and getting ahead of the noise from various security tools in use at an organization, Fortinet Senior Director for Cloud Vince Hwang told SDxCentral.

Fortinet today announced a new cloud-native protection (CNP) service for multicloud environments that integrates with Amazon Web Services' (AWS) existing cloud security tools to provide actionable and prioritized insights to security teams.

The backbone of the FortiCNP service is the vendor's patented resource risks insights tech, which works by ingesting data and integrating across different clouds and security tools to provide a prioritized scoring of all security alerts within an organization's cloud environment, Fortinet Senior Director for Cloud Vince Hwang told SDxCentral in an interview.

“The broad integrated approach that we have is quite unique to us,” he touted. In terms of integrating insights from cloud provider-specific security tools, “we're starting off with AWS and really taking advantage of those cloud-native services that [are] already there today,” which reduces friction associated with deployment and visibility, Hwang noted.

Although FortiCNP is currently compatible with cloud environments ranging any combination of cloud providers, the service has a deeper level of integration with AWS at this time, according to the vendor.

This type of deep integration makes for more efficient and frictionless deployments on AWS in particular “because we're able to directly interact with our services and implement policies and controls” while “leveraging what's existing on AWS today,” Hwang explained. “Over the next few months we'll have deep integrations across those native security services on Azure and Google as well,” he added.

Those collected security insights are then displayed in a prioritized view for security teams. Hwang described it as a roadmap for each day that helps teams understand the top threats that need their attention.

In addition, Hwang said the service gives security teams added context behind alerts. “A lot of times when you have alerts, you don't understand where things are” without information on how different resources and threats are related to one another. Fortinet claims its CNP service adds in that context to render insights truly actionable, Hwang explained.

Embracing Complexity

From a customer perspective, the most difficult aspect of cloud-native security is understanding and getting ahead of the noise from various security tools in use at an organization, Hwang explained.

Many customers are in what Hwang calls an “accidental multicloud world.” They didn't seek to make their cloud environments more complex, “but business demands them to do that,” he said, citing the COVID-19 pandemic's influence as a forcing function in the rush to the cloud.

“As a result of that, there's just a lot of complexity in cloud that people didn't really sign up for, but they're dealing with today,”  which leads to amplified security risks for unprepared organizations,  Hwang said.

“Operational complexity is hard enough on one cloud,” let alone across multiple clouds, and that inflates the chances of misconfigurations and visibility loss, he said.

“How do you act on things you don't know? How do you act on things you can't see, or you're not putting your eyeballs on because there's so many alerts going on?” This is the cloud strategy perspective Fortinet says it prioritized with FortiCNP.

But instead of trying to change the complexity of the landscape, Hwang said this service aims to “enable all these different experiences and preferences” within an organization's cloud security ecosystem. “You can't dictate how customers are going to use cloud. But what you can do is you can support their journey at every step,” he explained.