What is our primary use case?
We have a team of specialists, of which I was a part years ago, but now I'm no longer directly involved. I'm still with the company, but a different set of engineers now work on it, and I manage them. I'm in a management role now.
Fortinet FortiGuard is a threat intelligence service that FortiGate makes available, which keeps updating itself with the latest threats, signatures of the latest malware and all of that, so that the FortiGate device will be able to detect some of those threats when they come through the FortiGate.
Fortinet FortiGuard helps prevent data breaches because it puts the device in a position to stop about 60% of these threats that Fortinet has learned of through their lab work. Once your FortiGuard update is fine, you are sure that almost all of the known attacks will be stopped by your device.
What is most valuable?
Fortinet FortiGuard's machine learning capabilities contribute to our cybersecurity by performing numerous predictions and assessing possibilities, enabling us to prepare ahead for potential incidents.
I have benefited from automated threat response, which is absolutely brilliant because if we have to go through logs to see what is going on, we would never finish. Automating these things allows alerts to be given so we can concentrate effort on critical areas, helping us to optimize our resources effectively. We are also looking at automating the response, where response can be automated, and then we can focus on forensic investigations to understand what happened and see whether we need to tweak the automation to make it work better.
The benefits I gain from using Fortinet FortiGuard include peace of mind. It has contributed to ensuring that we are always available and can meet our availability targets. This means that productivity is maintained, and revenues will rake in as planned. The moment something gets through and causes a breach, likely causing downtime, it means you're losing money.
What needs improvement?
I think that automated response could be improved if they can add automated response features into Fortinet FortiGuard.
For how long have I used the solution?
I have been familiar with Fortinet FortiGuard for more than five years.
How are customer service and support?
On a scale from 1 to 10, I would rate the technical support of Fortinet an eight; it works good.
How would you rate customer service and support?
How was the initial setup?
When it comes to deployment, it's not complex; it's easy to deploy.
Fortinet FortiGuard alone doesn't take long to deploy; it takes at most 30 minutes, which feels quite quick. Half an hour for FortiGuard, but FortiGate takes a longer time because FortiGuard is part of the FortiGate for us.
What's my experience with pricing, setup cost, and licensing?
Regarding pricing, I must say it is quite pricey, but if you look at the value it gives you, I think the value justifies the cost.
What other advice do I have?
Fortinet FortiGuard's content filtering feature is good. We use it a lot, and even though sometimes there are some false positives, the rate of false positives is not that high; it's very manageable.
We use the behavioral analysis feature, and it helps to detect zero-day threats because once we're able to do the baselining, any deviation from the baseline is flagged, and then attention is immediately concentrated there to ensure that nothing untoward is happening. There are sometimes one-off strange behaviors from legitimate users, such as copying large files, that also flag such activities. We investigate and find out that this is legitimate, so it helps a lot to stop zero-day attacks.
On a scale of 1-10, I rate Fortinet FortiGuard a 9.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other