decryptingtech

Technology. Business models. Market debates.

Browse this section

Fortinet

Fortinet is often described as a firewall appliance vendor trying to become a software platform. That framing misses the source of the franchise. Fortinet is a network-security systems company built around a tightly coupled stack: FortiOS software, FortiGate enforcement points, custom FortiASIC processors, FortiGuard security services and a global channel. The architecture lets Fortinet inspect more traffic at a lower cost, then reuse the same policy layer across branches, campuses, data centres, operational technology and cloud-delivered access. Its next phase depends on turning that engineering advantage into durable service revenue and proving that the platform can extend beyond the firewall without losing specialist depth.

Summary

Fortinet owns one of cybersecurity’s most valuable distribution assets: a very large estate of network enforcement points already sitting in the path of customer traffic. The initial appliance sale matters, but the strategic value lies in what follows. Each FortiGate can carry security subscriptions, technical support, SD-WAN, switching, wireless networking, zero-trust access, local SASE enforcement and operational-technology controls. A hardware refresh therefore creates another chance to expand the customer’s architecture rather than merely replace a box.

The moat begins with system design. FortiOS provides a common policy and management foundation while FortiASIC accelerates the expensive work of routing, encryption and threat inspection. Most security vendors optimise software for general-purpose processors or public-cloud infrastructure. Fortinet designs important parts of the hardware and software together. That creates a persistent price-performance and power-efficiency advantage in environments where traffic volume, latency and inspection depth matter.

The company is strongest when networking and security become the same purchasing decision. Secure SD-WAN, branch firewalls, campus networking, internal segmentation and OT security all fit this model. Fortinet’s SASE proposition extends the same logic into the cloud, while retaining the option to inspect sensitive or latency-critical traffic locally. That hybrid flexibility is a genuine differentiator for regulated enterprises, governments, service providers and customers with substantial east-west traffic.

The limits are equally important. Fortinet does not yet have the same standing in endpoint security as CrowdStrike, the same cloud-security depth as Palo Alto Networks, or the same cloud-native user-to-application heritage as Zscaler and Netskope. FortiSOC, FortiCNAPP, FortiEndpoint and FortiAIGate expand the addressable market, but breadth alone does not establish leadership. The investment case should give full credit to Fortinet’s network-security moat while demanding evidence before valuing every adjacent product as another franchise.

The franchise: the firewall as a compounding distribution point

The firewall has repeatedly absorbed adjacent functions. Early products filtered traffic using addresses and ports. Unified threat management added antivirus, intrusion prevention, web filtering and virtual private networking. Next-generation firewalls added application awareness, encrypted-traffic inspection and more granular policy. Fortinet’s current strategy follows the same pattern: keep adding economically related functions to the enforcement point until separate products become one architecture.

This history explains why Fortinet is more than an appliance cycle. FortiGate is the physical or virtual enforcement layer, but FortiOS determines what the system can do. The same product can begin as a branch firewall, carry secure SD-WAN, manage attached switches and wireless access points, enforce zero-trust access and later operate as a local SASE point of presence. The customer’s first use case places Fortinet in the network; subsequent software and services increase the value of that position.

The model also explains the apparent tension between hardware and recurring revenue. Product sales expand the installed base and typically arrive with support and security subscriptions. FortiCare keeps the environment running. FortiGuard supplies threat intelligence and continuously updated security controls. Cloud-delivered services and software can then widen the relationship. Hardware is therefore both revenue and customer-acquisition infrastructure.

The weakness is cyclicality. Appliances age, product generations change and customers can bring purchases forward when supply or pricing becomes uncertain. A strong product period may reflect replacement timing rather than a permanent acceleration in demand. The correct question is whether each cycle leaves Fortinet with a larger, more deeply subscribed customer base. Product growth without higher service attachment would create activity without improving the quality of the franchise.

FortiOS and FortiASIC: the architectural moat

FortiOS is the organising layer. It combines routing, firewall policy, SD-WAN, segmentation, secure access and threat protection within a common operating model. A shared policy framework matters because customers increasingly operate across branches, campuses, private data centres, public clouds and industrial sites. Security teams want consistent intent even when enforcement occurs in different form factors.

FortiASIC supplies the second half of the advantage. Deep inspection of encrypted traffic consumes substantial compute. Adding more security functions often reduces throughput or forces customers to buy larger systems. Fortinet’s purpose-built processors offload networking and security tasks from the general-purpose CPU, supporting more inspection with lower latency, cost and energy use. This matters most at high-throughput data centres, busy campus edges, service-provider networks and industrial environments where failure or delay has an operational cost.

The combination creates system-level economics that software-only comparisons can overlook. A competitor may match an individual feature, but the customer buys the aggregate performance of the appliance, operating system, subscriptions and management layer. Fortinet can use lower total cost to enter an account, then monetise the installed base through services and adjacent network functions.

This moat has boundaries. Custom silicon requires long planning cycles, depends on external foundries and introduces supply concentration. It cannot rescue a weak cloud service or an immature workflow outside network security. A common brand and console also do not mean that every product shares identical code or specialist depth. Fortinet’s strongest integration claim applies where FortiOS directly controls traffic; it becomes less automatic in cloud posture, endpoint, email, data security and security operations.

The business model: product creates the annuity

Fortinet sells mainly through distributors, resellers, service providers and managed security partners. This channel gives the company global reach across small businesses, large enterprises, public-sector customers and regions where direct enterprise sales coverage would be expensive. Fortinet supports larger accounts with its own sales and engineering teams, but the partner remains central to fulfilment and deployment.

Product revenue includes physical appliances, virtual appliances and software licences. Service revenue comes mainly from FortiGuard security subscriptions, FortiCare support and cloud-delivered products. Support and subscription contracts are recognised over their service periods, so a burst of appliance demand reaches reported service revenue slowly. Current product activity is therefore a leading indicator, but only if customers attach, retain and renew the services.

Bundling is becoming more important. Fortinet can combine a firewall, SD-WAN connectivity, cloud management, zero-trust access and starter SASE capacity in one commercial package. The bundle reduces procurement friction and gives customers a low-risk path into the broader platform. It also makes the appliance refresh a cross-sell event. The risk is opacity: a bundled sale can show platform adoption before it proves sustained use or willingness to renew each component.

The economic flywheel is straightforward. A broad channel places more FortiGates. The installed base produces renewals and more threat telemetry. FortiOS makes adjacent functions easier to activate. Each additional function increases switching cost and the value of common policy. The flywheel weakens if channel inventory gets ahead of deployment, service attachment falls, customers choose specialist products for important domains, or cloud architectures reduce the number of places where a FortiGate provides the natural control point.

The platform map

LayerCore productsStrategic roleAssessment
Secure networkingFortiGate, FortiSwitch, FortiAP, FortiLink, FortiNAC and secure SD-WANConverges network connectivity and security across branch, campus, data centre and edge.The strongest franchise and the source of distribution.
Unified SASEFortiSASE, FortiClient, zero-trust access, secure web gateway, CASB, DLP, remote browser isolation and digital experience monitoringExtends common access policy to remote users, SaaS and private applications.Credible installed-base expansion with a differentiated hybrid model; cloud execution still has to prove itself against specialists.
Operational technologyRuggedised FortiGate, secure switching, industrial visibility, segmentation and FortiGuard OT servicesProtects connected industrial assets that often cannot run endpoint agents.A natural fit for Fortinet’s local enforcement, networking and channel strengths.
Security operationsFortiSOC, FortiAnalyzer, FortiSIEM, FortiSOAR, FortiXDR, FortiNDR and managed servicesTurns network and endpoint telemetry into investigation and response.Strategically logical but much smaller and less established than secure networking.
Cloud and applicationsFortiCNAPP, cloud firewalls, FortiWeb, application security and code-to-cloud controlsExtends the platform into cloud posture, workload and application risk.Necessary for enterprise relevance; integration and specialist credibility remain the tests.
Endpoint, data and communicationsFortiEndpoint, FortiEDR, FortiDLP and FortiMailAdds endpoint enforcement, data protection, email and collaboration security.Useful within consolidation deals, but Fortinet lacks the category leadership it has in firewalls.
AI securityFortiAIGate, FortiAI, AI traffic controls and acquired AI validation technologyProtects models, prompts, agents, tools and data while automating defensive work.Promising and increasingly coherent, but early as a stand-alone revenue pool.
The platform map

SASE Firewall: a useful architecture, an unproven category

Cloud-delivered Secure Access Service Edge moved policy away from the corporate perimeter. Users connect from anywhere, applications live across public and private clouds, and the nearest corporate appliance may no longer sit in the traffic path. Cloud-native providers built distributed inspection networks to connect users directly to applications without backhauling through a data centre.

Fortinet accepts that shift but rejects the idea that every flow should travel through a vendor-operated cloud. Remote-user and internet-bound traffic often belongs in a cloud point of presence. Sensitive data, industrial traffic, busy office locations and east-west data-centre flows may be better inspected locally. FortiSASE Outpost turns a FortiGate into a customer-controlled SASE enforcement point while retaining central cloud management. Sovereign SASE gives organisations and service providers more control over where data, logs, policy and processing reside.

This hybrid design addresses real requirements. It can reduce latency and bandwidth cost, preserve local control and serve jurisdictions where data-residency rules constrain public-cloud inspection. The same FortiOS policy can follow the customer across cloud, on-premises and sovereign deployments. Fortinet also avoids an awkward internal conflict: a customer can move between local and cloud enforcement without necessarily leaving the platform.

“SASE Firewall” remains Fortinet’s own framing rather than a settled market category. It combines products that customers may still buy from separate budgets and operate through different teams. Cloud-native competitors have spent years optimising global traffic steering, user experience and direct-to-application access. Fortinet must show that its cloud-delivered service matches that operational quality, and that new customers choose the architecture rather than existing firewall customers accepting an attractive bundle.

AI creates three different opportunities

Securing AI infrastructure

The most immediate opportunity is conventional security applied to new infrastructure. AI data centres move large volumes of traffic among accelerators, storage, model servers, vector databases, APIs and applications. Much of that traffic flows east-west inside the environment. Customers need segmentation, encrypted-traffic inspection and high-throughput policy enforcement without adding excessive latency or power consumption.

Fortinet’s data-centre firewalls and virtual form factors fit this requirement. Custom silicon is relevant because AI infrastructure is already constrained by power and network performance. The opportunity extends beyond specialist AI-cloud operators. Enterprises bringing sensitive or predictable inference workloads into private infrastructure need the same control plane, while utilities and industrial sites require secure connectivity for the physical systems supporting new compute capacity.

Protecting AI applications and agents

The second opportunity is security specific to AI. Enterprises need to discover unsanctioned models and agents, control sensitive data entering prompts, inspect tool calls and APIs, validate models before deployment and stop unsafe behaviour at runtime. FortiAIGate provides an enforcement layer for model and application traffic. FortiOS adds visibility into AI applications and emerging agent protocols. Fortinet’s recent AI-security acquisition adds automated red teaming, continuous validation, agent discovery and runtime guardrails.

This strategy is coherent because AI activity crosses several Fortinet control points: network traffic, web access, endpoints, cloud workloads, data-loss controls and the SOC. The hard part is joining those views into a useful policy system. AI security is moving quickly, product definitions remain fluid and customers will resist another collection of disconnected consoles. Fortinet has acquired relevant technology, but integration and production use matter more than feature count.

Using AI inside security operations

The third opportunity applies AI to defensive work. FortiAI and FortiSOC aim to automate alert triage, investigation, threat hunting and response while keeping analysts responsible for consequential actions. Fortinet can enrich those workflows with FortiGuard intelligence and telemetry from its own products. This can improve the economics of support, managed security and customer SOC operations.

AI-assisted operations strengthen the platform but may not create a large independent revenue stream. Every major cyber vendor is embedding similar capabilities, and the underlying models will become cheaper. Fortinet’s defensible asset is the context and authority surrounding the model: which traffic it can see, how products share evidence and whether the platform can enforce a response. The investment case should underwrite productivity and retention before assigning value to a new AI software franchise.

Operational technology is more than another vertical

Operational technology security plays directly to Fortinet’s architecture. Industrial devices often run old software, use specialised protocols and cannot support an endpoint agent. Availability may matter more than confidentiality, and maintenance windows can be rare. Security therefore relies heavily on asset visibility, network segmentation, protocol-aware inspection and virtual patching around systems that cannot be changed safely.

Fortinet can supply ruggedised firewalls, secure switches, wireless networking, access control and central management through the same fabric used for enterprise IT. This matters as factories, utilities, transport systems and buildings connect operational assets to corporate networks and cloud applications. The customer can use one architecture across the IT boundary and the industrial environment while applying different policies to each.

The moat comes from fit rather than market labels. Fortinet already sells through partners that understand distributed infrastructure. Its appliances support local enforcement and high availability. FortiGuard can distribute signatures and virtual protections for known industrial weaknesses. A broad product set reduces the number of vendors required at remote sites.

OT also raises the stakes. False positives, failed updates and badly designed segmentation can interrupt physical operations. Product security matters because an exposed edge device can become the route into a critical environment. Fortinet must combine rapid vulnerability disclosure with practical remediation for customers that cannot patch quickly. Long-term demand looks durable; trust and operational execution determine who captures it.

The expansion problem: breadth outside the network

Fortinet’s network platform is proven. The broader cybersecurity platform remains a work in progress. Security operations is the most natural adjacency because the network estate generates valuable telemetry and already supports enforcement. FortiSOC packages analytics, SIEM, SOAR, threat intelligence and agentic investigation into a cloud service. It can appeal to customers seeking consolidation, especially those with substantial Fortinet infrastructure.

The challenge is data breadth. A modern SOC must ingest endpoint, identity, cloud, application and third-party telemetry at scale. CrowdStrike starts with rich runtime data; Microsoft starts with identity, endpoint and productivity distribution; Palo Alto combines network, cloud and SOC investments. Fortinet has network context and a large installed base, but it must prove that FortiSOC works as an open security system rather than a management layer for Fortinet products.

Cloud security presents a similar test. The Lacework technology behind FortiCNAPP adds cloud posture, workload and code-to-cloud capabilities. That fills an important portfolio gap, but the buyer and workflow differ from the network team. Deep integration with FortiGate and FortiSOC could create a useful hybrid-cloud proposition. Treating the acquired product as another tile in the Security Fabric would not be enough.

Endpoint, email and data security widen the consolidation conversation but currently function more as platform attachments than independent franchises. Fortinet can win when a customer values one agent, one contract and lower operating complexity. Specialist competitors retain stronger data, workflows and mindshare in their core domains. The sensible strategy is selective depth: own the network-security control plane, become genuinely strong in adjacencies that reinforce it, and integrate other capabilities well enough to support consolidation without claiming leadership everywhere.

Competitive landscape

BattlefieldMain competitorsFortinet’s advantageWhere Fortinet is vulnerable
Enterprise and data-centre firewallPalo Alto Networks, Check Point, Cisco and cloud-native controlsCustom silicon, broad appliance range, price-performance, power efficiency and a large installed base.Palo Alto has a stronger premium-enterprise platform story; cloud controls can absorb some virtual firewall demand.
Branch and campusCisco, HPE, Palo Alto Networks and networking specialistsFirewall, SD-WAN, switching, wireless and access control under FortiOS and FortiLink.Networking incumbents have deep customer relationships and can bundle security into wider infrastructure deals.
SASE and secure accessZscaler, Palo Alto Networks, Netskope, Cisco and cloud platformsOne policy layer across firewall, SD-WAN, cloud SASE, local Outpost and sovereign deployment.Cloud specialists have stronger heritage in distributed user-to-application access and digital experience.
Operational technologyPalo Alto Networks, Cisco, Claroty, Nozomi Networks and industrial vendorsLocal enforcement, ruggedised infrastructure, segmentation and integration across IT and OT networks.Specialists can offer deeper asset intelligence and industrial workflows in complex environments.
Security operations and endpointMicrosoft, CrowdStrike, Palo Alto Networks and SIEM specialistsNative network telemetry, FortiGuard intelligence and integrated response across the installed base.Weaker endpoint and identity control points, plus a smaller independent security-data ecosystem.
Cloud and application securityPalo Alto Networks, hyperscale clouds and cloud-native specialistsHybrid networking context and a growing code-to-cloud portfolio.Less developer distribution and less established cloud-security depth.
AI securityBroad cyber platforms, model providers and emerging specialistsCan join infrastructure, network, endpoint, SASE and SOC enforcement around AI activity.The market is early, integrations are recent and specialist product cycles move faster than custom hardware cycles.
Competitive landscape

Fortinet’s closest strategic comparison is Palo Alto Networks, but the two franchises start from different places. Palo Alto has built a broader enterprise security platform through sustained software investment and acquisitions. Fortinet has built a more vertically integrated network-security system with stronger cost and performance characteristics. Palo Alto is more likely to lead a top-down enterprise consolidation; Fortinet is more likely to expand outward from the network estate and win where economics, deployment flexibility and local control dominate.

Against Zscaler and Netskope, the debate is architectural. The cloud specialists assume that distributed inspection should usually occur in their cloud. Fortinet argues that enforcement should move between cloud and customer-controlled infrastructure according to the traffic. Both models can coexist. Fortinet’s outcome depends on whether hybrid and sovereign requirements are large enough to offset the specialists’ head start in cloud-delivered access.

The moat, properly assessed

  • System-level engineering: FortiOS and FortiASIC create a performance and cost advantage that is difficult to copy quickly. The moat is strongest in traffic-intensive network security.
  • Installed enforcement estate: FortiGate gives Fortinet distribution, telemetry and a point from which to add services. The moat compounds only when customers activate and renew more of the platform.
  • One network operating model: Common policy across firewall, SD-WAN, branch, campus and SASE reduces operational complexity. The claim becomes weaker in acquired and non-network products.
  • Channel reach: Partners extend Fortinet across geographies, customer sizes and service-provider models. The same structure creates distributor concentration and makes end demand harder to read.
  • Infrastructure ownership: Fortinet’s cloud locations and private infrastructure give it more control over SASE economics and deployment. It still has to match the service quality of cloud-native networks.
  • Threat intelligence and support: FortiGuard and FortiCare turn the installed base into recurring value and improve retention. Product vulnerabilities can damage the same trust quickly because firewalls are exposed and operationally critical.

The investment debate

Is the product cycle structural or temporary?

The constructive case combines several forces: an ageing appliance estate, customers moving to higher-performance systems, AI data-centre construction, internal segmentation, OT modernisation and continued SD-WAN adoption. Fortinet’s latest demand is broad enough that a simple replacement explanation looks incomplete. Higher-end product mix and genuine unit demand suggest that customers are buying more capability, not only replacing old capacity.

The cautious case is that product cycles always acquire a structural narrative near their peak. Price changes can pull demand forward, supply concerns can alter channel behaviour and easy comparisons can exaggerate acceleration. AI infrastructure wins may remain concentrated among a small number of projects. The decisive evidence will appear after the current product surge: stable deployed units, healthy channel inventory and a lasting increase in attached services.

Can services turn hardware strength into better growth?

Service revenue naturally lags product sales because subscriptions and support are recognised over time. That accounting effect can hide an improving cohort. It can also become an excuse. Investors should focus on service attachment, renewal, current service billings and whether SASE and SecOps usage expands after the initial bundle. If services strengthen as the product cohort matures, the franchise quality improves. If they do not, the product cycle was less valuable than the headline demand implied.

Can Fortinet become a platform beyond network security?

Fortinet already operates as a platform within network security. The harder question concerns SecOps, cloud, endpoint, data and AI security. The acquisitions of Lacework, Perception Point and Virtue AI bring useful technology, while FortiSOC creates a more coherent cloud-delivered operating layer. Success requires new buying centres to choose Fortinet on product merit, not only accept extra capabilities within a discount package.

Does hybrid SASE become a large category?

Fortinet has identified a real gap between traditional appliances and cloud-only access security. Regulated organisations, service providers and enterprises with busy local environments need more control over where inspection occurs. Fortinet is architecturally well placed to serve them. The open question is market size and repeatability. Sovereignty may support attractive wins without becoming the default SASE design, while many remote-work use cases will continue to favour a cloud-native service.

Risks that matter

  • Product-security risk: Firewalls and remote-access systems are valuable attack targets. A critical vulnerability, slow customer patching or weak disclosure can damage trust across the installed base.
  • Supply-chain concentration: Fortinet designs custom processors but relies on outside manufacturers and foundries, with substantial hardware production concentrated in Asia. The moat and the dependency come from the same architecture.
  • Channel and inventory risk: Distributors provide reach but can obscure end demand. Excess stock, ordering ahead of need or abrupt price changes can distort product growth.
  • Cloud substitution: More applications and access flows may move to cloud-delivered control points where a physical FortiGate is less central.
  • Platform dilution: Expanding into too many categories can create a broad but uneven suite, weaken research focus and increase integration work.
  • Commercial bundling: Attractive bundles can accelerate adoption but may reduce pricing transparency and mask low use of newer modules.
  • Operational concentration: More functions under one operating system simplify management but increase the impact of a serious platform failure.

What to watch

  • Whether appliance demand remains healthy after pricing effects and the easiest refresh comparisons pass.
  • Whether new product cohorts attach more FortiGuard, FortiCare, SD-WAN and SASE services, then renew them.
  • Whether FortiSASE wins new customers and large cloud-delivered deployments rather than relying mainly on the FortiGate base.
  • Whether SASE Outpost and Sovereign SASE become repeatable architectures across regulated enterprises and service providers.
  • Whether FortiSOC and FortiCNAPP attract independent workloads and third-party data, proving relevance beyond network management.
  • Whether AI data-centre and OT demand broadens across customers instead of depending on a few large projects.
  • Whether Virtue AI technology becomes a unified part of FortiAIGate, FortiOS and FortiSOC with visible production use.
  • How quickly Fortinet identifies, discloses and helps customers remediate critical product vulnerabilities.

Bottom line

Fortinet’s durable advantage is not a quarterly firewall surge. It is the combination of a large enforcement estate, one network operating system, custom silicon, recurring security services and a channel capable of carrying that architecture across the world. The franchise should remain strongest wherever performance, local control and the convergence of networking with security shape the purchase.

The fresh opportunity comes from using that foundation for hybrid SASE, AI infrastructure and operational technology. These markets reward the same properties that made FortiGate successful: efficient inspection, flexible form factors and integrated policy. AI application security and agentic operations add further upside, but they remain earlier and more competitive.

The central investment question is conversion. Fortinet must convert product demand into long-lived services, convert firewall customers into SASE users, and convert portfolio breadth into credible products outside the network. If it does, the appliance heritage becomes an asset that cloud-only narratives underestimated. If it does not, Fortinet remains an excellent network-security company whose expansion story runs ahead of its recurring economics.