en.Wedoany.com Reported - Fortinet has launched FortiSOC, a cloud-delivered security operations center platform that integrates six core capabilities—Security Information and Event Management (SIEM), Security Orchestration, Automation and Response (SOAR), threat intelligence, Identity Threat Detection and Response (ITDR), User and Entity Behavior Analytics (UEBA), case management, and AI-driven workflows—into a single Software-as-a-Service (SaaS) experience. The platform aims to unify these capabilities through one operational environment, helping enterprises address the growing volume of alerts, expanding attack surfaces, and operational pressures from fragmented security infrastructure.
Michael Xie, founder, president, and chief technology officer of Fortinet, stated that FortiSOC provides security teams of all sizes with a more streamlined way to operate the necessary SOC capabilities through a unified cloud-delivered platform. The platform incorporates built-in AI, integrated workflows, and best practices from Fortinet's own global SOC, helping customers automate threat detection and response processes while reducing operational complexity. Delivered via a unified subscription model, FortiSOC aims to consolidate tools, workflows, and response capabilities into a single platform, eliminating operational silos.
The platform integrates FortiAI-Assist, leveraging enterprise telemetry data and threat intelligence from FortiGuard Labs to enable autonomous alert investigation, cross-domain correlation of identities and assets, threat hunting support, AI-generated playbooks, and coordinated response actions under analyst supervision. According to Fortinet, the system can coordinate actions via the Model Context Protocol and facilitate collaboration among security, IT, and business stakeholders. The platform architecture also supports native integration across the Fortinet Security Fabric ecosystem, as well as thousands of third-party connectors, thereby automating detection and response activities across security, IT, and business systems while reducing manual intervention.
This launch reflects the cybersecurity industry's shift from isolated security tools toward integrated security operations platforms. Traditionally, security operations teams relied on standalone products for monitoring, investigation, threat intelligence, orchestration, and incident response, which often led to operational silos and management overhead. FortiSOC enables analysts to complete the entire process—from alert triage to investigation and response—without switching between multiple interfaces. The platform can adapt to organizations with varying levels of security operations maturity: small teams can establish basic monitoring and detection capabilities, while large enterprises can deploy advanced automation, extensive event correlation, and AI-assisted investigation.
Fortinet emphasizes three operational advantages of the platform: first, the unified SaaS platform consolidates multiple security operations capabilities under a single management framework; second, the single subscription model simplifies procurement and resource allocation; and third, built-in threat intelligence, detection content, and playbooks derived from Fortinet's global SOC operations are available immediately upon deployment. FortiSOC expands Fortinet's existing security operations portfolio (including FortiAnalyzer, FortiSIEM, and FortiSOAR), not replacing these products but unifying and enhancing their capabilities for customers seeking a cloud-native SOC platform. Fortinet stated that these products will continue to receive enhancements and remain available.
Michelle Abraham, senior research director for Security and Trust at IDC, noted that IDC research shows organizations are increasingly prioritizing analyst workflows, investigation experiences, and cloud-delivered security operations to improve visibility, streamline processes, and accelerate response. She believes that FortiSOC, built on Fortinet's established security operations portfolio, integrates mature technologies into a unified SaaS platform capable of supporting both basic and advanced SOC use cases. Looking ahead, Fortinet plans to continue expanding AI-driven security operations capabilities across its platform portfolio. As enterprises consolidate cybersecurity tools and improve operational efficiency, unified SOC architectures are expected to remain a key focus area for security investments.
This article is compiled by Wedoany. All AI citations must indicate the source as "Wedoany". If there is any infringement or other issues, please notify us promptly, and we will modify or delete it accordingly. Email: news@wedoany.com









