Secure your Fortinet surface
Firewall policy sprawl, security profiles left in monitor mode, and firmware carrying known exploited flaws. We don’t connect to Fortinet to collect evidence for its own sake — we connect to secure it, and the compliance artefacts follow from that work.
Book a Demo[01] What This Surface Exposes
Where Fortinet goes wrong
Fortinet goes wrong through monitor mode: security profiles attached but not enforcing produce logs and no protection.
- Policies permitting any-any that were added temporarily and never removed
- Security profiles (IPS, antivirus, web filtering) attached in monitor mode rather than blocking
- Administrative access permitted from untrusted networks
- Firmware versions with actively exploited vulnerabilities
- VPN configurations with weak authentication or no MFA
[02] What We Secure
What we watch, catch and fix on Fortinet
On Fortinet we audit profile enforcement mode per rule and review policies with hit counts so dead rules can be retired.
- Policy review with hit counts so genuinely unused rules can be retired
- Profile enforcement mode audited, because monitor mode produces logs and no protection
- Admin access paths tested from outside
- Firmware tracked against known exploited vulnerability catalogues
- VPN authentication posture reviewed as a primary entry point
[03] Where It Lands
Where Fortinet lands in your registers
Every managed device becomes an asset register entry with its owner, encryption state, and OS currency. Access reviews cover the accounts bound to it, and the risk register carries what an unpatched or unencrypted endpoint actually exposes given the data that person handles. The gap that matters most is the device your MDM has never seen — we reconcile against your directory and HR record to find it.
[04] How We Engage
On Fortinet specifically
On Fortinet, we tighten policies and enable profile enforcement in agreed windows. Firmware upgrades and VPN authentication changes we plan and drive with your network team.
Platform licence
Everything you need to find and fix it yourself, with no ceiling on the depth of the answer.
- Every connected tool monitored for misconfiguration and drift, with findings mapped to the assets and risks they affect
- Remediation guidance that tells you what is wrong and exactly how to fix it — however deep or awkward the issue is. We are engineers running a security company, so the answer is the real one, not a link to vendor documentation
- Assets, access reviews, and risk register populated from the tools themselves rather than from spreadsheets
- Unlimited integrations and unlimited users, with anything missing built within two weeks
Managed service
Every tool you connect through Konfirmity comes under our care, with our team doing the work.
- Continuous misconfiguration and drift monitoring across every connected tool, watched by our analysts rather than by a dashboard waiting for you
- Incident response led by us, with containment coordinated with your team
- Remediation performed directly wherever you have granted us the authority to act — and where we cannot act, we project-manage the fix to completion rather than handing you a ticket
- Decision support on the tools themselves: where something is failing you on capability or costing more than it returns, we will tell you, and help you replace it
[05] Fortinet FAQs
What Fortinet access does Konfirmity need?
Konfirmity needs a read-only administrative profile via the API, covering policies, security profiles, VPN configuration and system status. That is sufficient for posture assessment. Changes are made in agreed windows and never automatically.
Why do you check enforcement mode specifically?
Because an IPS or antivirus profile in monitor mode looks identical to an enforcing one on a policy summary. Profiles are routinely set to monitor during troubleshooting and left there, which quietly removes protection while the configuration still appears correct.