Work Smarter Than Harder FortiAI-Assist from Fortinet
At AI Field Day 7, Fortinet presented its FortiAI Assist technology, emphasizing its integration across the Fortinet Security Operations Center (SOC) platform. Max Zeumer, the speaker, highlighted the growing burden on security teams dealing with massive volumes of alerts and limited personnel. FortiAI Assist was designed to alleviate this pain by embedding AI-driven support directly into the SOC interface. The AI assistant can efficiently prioritize alerts, triage investigations, and enrich incident details using available threat intelligence and telemetry. Analysts can interact with FortiAI Assist via typed or spoken queries, enabling them to focus on higher-level strategic decisions while the AI handles data gathering and analysis. Additionally, Fortinet employs a blend of generative AI and pre-built playbooks to orchestrate actions like isolating compromised hosts and compiling incident reports while maintaining a “human-in-the-loop” model for oversight.
Beyond SOC capabilities, FortiAI Assist also extends to Network Operations Centers (NOC), as described by Maggie Wu during her portion of the presentation. In the NOC context, FortiAI aims to simplify and expedite day-one deployment tasks, such as auto-generating configurations from topology diagrams and validating configuration scripts. Day-two operations are boosted by real-time network health assessments, troubleshooting, and suggested fixes, all guided through AI-driven dialogue with the admin. The AI assistant is capable of identifying root causes—like VPN or Wi-Fi failures—and proposing remediations that can be executed upon user confirmation. The technology allows customizable interaction levels so that organizations can maintain compliance with their change management processes.
Fortinet also addressed the flexibility of FortiAI Assist within both Fortinet-exclusive and multi-vendor environments. While native Fortinet deployments offer full capabilities with deep cross-platform interoperability, approximately 80-90% of AI-based functionality is available in broader ecosystems thanks to comprehensive APIs and collaborative integrations with over 500 partners. Organizations can build or customize their own automation connectors, reinforcing Fortinet’s commitment to open systems and vendor interoperability. Furthermore, FortiAI Assist supports scalable adoption strategies, offering options such as detailed change plans and rollback capabilities, enabling organizations to gain trust gradually through staged automation. Fortinet envisions a future where its AI agents collaborate with partner AI solutions, creating a cohesive and intelligent security and network management ecosystem.
Recorded live in Santa Clara, CA as part of AI Field Day 7 on October 29, 2025. Watch the entire presentation at https://techfieldday.com/appearance/fortinet-presents-at-ai-field-day-7/ or visit https://www.Fortinet.com or https://TechFieldDay.com/events/aifd7/ for more information.
Transcript
Work smarter, uh, than harder. Uh, let's talk about 40 AI assist. Remember, three buckets.
Um, I'm going to just walk through initially, um, 40 AI assist with the Fortinet SOC platform. Okay? Then my colleague will walk through the, uh, for AI, assist for the NOC and how we secure ai.
Okay? Um, when it comes to 40 AI assist, this is embedded throughout our entire, uh, platform, right? So if I'm going in, I'm logging into, um, our SOC platform, this can pop up as you know, uh, uh, within any window I'm in, with any view, with any dashboard, it's going to leverage all of the telemetry and capabilities of that platform, um, to help assist an augment speeding, specifically my, um, threat analysis alert, triage investigation and response.
I'm gonna go a little bit deeper to talk about like what we're seeing customers care about most when it comes to the SOC and 40 AI assist. Um, they, they have more work to go around than people, and they're just beat, especially, I mean, if you're, you might not even have a sock, right? You're, you're probably managing both IT and security.
You're wearing multiple hats. That's so much knowledge that you have to have on any given day, especially across different technologies and practices and so on and so forth. So, I want to be able to automate all the things that I can loosen up my workload with and help me, uh, focus on really the more advanced stuff that I can apply my skillset to.
That's what customers are telling us first. Then how can I speed my process, especially around alert, triage, um, and, and investigations. That's one of the most common kind of kickoff that we're seeing because why they're flooded without, they're flooded with tons of alerts.
The caveat here is they say, Hey, max, we don't want to add ai that's going to disrupt our day-to-day operations. Don't give me another headache. Make it as seamless and integrated as possible.
So, to give you a quick overview of the use case, and again, we do have some demos that are about to coming up, coming up, and we're short on time, so I don't wanna take up too much more. Um, but I just wanna give you a quick idea. Um, alert triage.
You know, as an analyst, I have thousands of alerts coming in, and I sometimes it's much more than just a thousand, but thousands and thousands. And I have to determine what is a true potential threat, what might be correlated with that alert. Um, and then continue to triage and figure out, okay, what assets have been impacted?
What indicator or compromise I have to, you know, are associated, I have to enrich that information, validate it, and so on. That's tough. That's really tough.
That's a needle in a haystack. You're gonna get a ton of alerts that are, are nonsense, that are meaningless and take you on a wild goose chase. So, as an analyst, I wanna simplify that as much as possible and cut through the noise.
And so I'm using 40 AI assist within our SOC platform to help me prioritize that. I literally can, whether it's voice to text type to text, Hey, what I'm starting my shift, what were the high priority alerts that my team had been working on, or incidents either or that my team had been working on before I started. It will pull from across that platform and populate that in the, the chat.
Or I can say, Hey, what are, you know, the, the, the biggest threats we're facing right now? Right? From there, it will start leveraging the telemetry and threat intelligence and all those components and capabilities of the platform to then surface, Hey, here's the high risk alerts.
And not just that, but in fact we found a few things you should prioritize. We've enriched some, uh, indicator of compromise because we found a compromised host. This is the, this is the most, uh, critical one.
Um, and again, here's what's been impacted. This is where it might, where it came from, um, and the endpoint that, um, you know, has been potentially compromised. So Behind the scenes, this Calvin Hendricks, Parker was six feet up behind the scenes.
Are you using some ENT like tool calling to allow for some kind of determinism, or you've got some pre-canned reports that we're calling under the covers to make that that magic happen? So we, when it comes to the first on the report side, it's leveraging. So for instance, what we're looking at here, 'cause I just switched slides and it has a report on it conveniently.
Um, it's for within four to analyzer, which is part of our SOC platform. It has comprehensive reporting, so it actually will grab from those reports, we'll grab from those widgets will literally leverage the product as well. And then, um, can you remind me the first half of your question, well, Just to be, 'cause LLMs and generative AI being, you know, non-deterministic, I assume you're using some kind of tools or tool calling to query the data, and so you've got like pre-canned functions that you're calling to get to these kind of things?
Or are you relying on generative AI somehow pick out and prioritize? It's, yeah, so we do, we do have some pre-canned elements, um, but it's also leveraging like the, the, the platform faster than the human could, right? So it would be leveraging, you know, um, are you familiar with a sim, for instance?
Mm-hmm. Okay. SIM tool, um, security event.
Oh, okay. Yes. Okay.
That, Yes. Okay. And then on, that's My main question, I Think.
And then on top of that, it will leverage like the capabilities of the technology that the AI is layered on top of. Yeah, so similar question, but then more specific. So once you figured out there is an issue, can you, for example, is there a tool that basically says, well, in this particular category, I'm gonna shut down the ports, or I'm gonna slow down traffic, or completely shut down traffic until an analyst had the ability to look at it?
Yeah. Um, and, and this particular example here shows, Hey, I identified this compromised host. This, this endpoint, it's bad, has as has associated with an IOC.
And let's just say I'm a junior analyst too. Make it easy. Um, I can quarantine the end point.
Now what's happening is that it's leveraging, uh, for instance, within the, uh, SOC platform, we have playbooks, uh, prebuilt playbooks, for instance, that will quarantine an endpoint. So it will automatically then execute those playbooks or that playbook to then quarantine that endpoint, right? Take it off.
And then even better, I can say, create an incident and an incident report providing all the information so I can use it for an incident handoff to someone more senior than me as a junior analyst or attaching that report because maybe we need to do a forensics analysis. Maybe, you know, we have an audit later on, and it will attach to that incident and have a full timeline from the second it was identified and every touch point since including, um, quarantining endpoint. Now, um, we are tight on time.
We will expand on the agent ai, but, um, we are certainly, uh, part of our focus is, um, you know, agent ai, how can we make our, uh, customer's lives easier? And where we don't believe in, you know, um, having just this incredibly, everything's autonomous. Um, I don't have to do anything.
I can just set it and forget it for my entire security stack that that's, that's not quite there in, in, in the world of AI yet. Um, but what is there is, I can do that with goals, um, and, you know, goal oriented processes. So the process that I want walked through just before in the last two slides, detecting, validating, um, and, uh, stopping the spread by containing, um, that, that alert triage process investigation, I can, uh, pass off to a 40 AI reasoning, uh, 40 AI assist reasoning agent, which will do that entire process without me having to step in.
It does keep a human in the loop, right? It will give me these options. It's kind of hard for you to see from all the way over there, but, um, it will give me some different options.
Do I want to quarantine? Do I want this to email to execs? But at this point, it's already gone through and understood, okay, I found, uh, this brute force attempt, IFII found and enriched these different indicator compromise.
I found these, um, alerts that are linked, um, you know, have a common link. Um, I've, I've, I've done all of that process and, and, and executed these queries and so on so forth. And so we're at that stage right now where, you know, it's, it's gonna help around reasoning, um, especially these different multi campaign attacks where I could just use that air support, right?
I could use that, especially, you know, even if it's just focusing on brute force attacks, let's say as an analyst, I could use that breathing room. Um, with that said, uh, we've, we've gone over a little bit, so I do appreciate all the questions. I'll be here to comment a little bit more, but I'd love for my colleague Maggie Wu to, uh, take over and talk a little bit about 40 AI assist for the knock.
Here you go. Thank you so much, max. Thank you.
And, um, great opening session, uh, for introduce 40 ai, 40 ai, uh, for tech fort I secure and Fort I, um, assist. So my name is Maggie Wu. I'm the director of product marketing at Fortinet.
And, uh, I thank you for attending our sessions and, uh, thank you for all the audiences dialing online as well. Um, I'm going to carry on the torch on Forti AI assist. Um, max talk about the sock side of things, and I'm going to cover the NOx side of things, the network operation, and then I'll keep going on Forti ai, secure ai.
So on the NOx side, um, this is also works matter matters more than work harder. So in the world of network operation, you feel, you know, the network admins are always overwhelmed, right? Um, they have tons of network alarms to do each day, and, uh, how can AI help, right?
So this is where AI assist coming and doing the heavy lifting for you. So basically the smarter means, um, I can connect the dot, the AI can connect the dot instantly. I can speak your language, you don't need to speak code.
And, uh, I can be predictive rather than reacting, and I can do automatic fix if you desire to, and that will save you the network admin a lot of time and, uh, reduce a lot of repetitive work. So that's what smart for. So maybe this is more of a, a statement, and I'd love to see you react to this through your presentation.
I'm very, I'm Scott Ban. Mm-hmm. I'm very, very interested in a unified view of security operations and network operations.
If you can speak to your ability to ingest network alerting and telemetry and security sim alerting and telemetry, and bring those views together, I would love to hear that story. Wonderful. Yeah, I think that's one of, actually, you hit sweet on the Fortinet strengths, which is we are building a converged network where the networking and security are on the same fabric and same platform.
That's where when we deploy ai, we're able to, you know, leverage that in this integrated platform. Okay. Okay.
Um, okay. So same things about Nog. Which customer will, what customer cares, you know, we ask our customers and, uh, it's very predictable what they want the 40 AI assist do for them.
It boils down to their day to day operation from day one. They want it to be deployed faster. They want 40 AI to help them deploy their network provision network faster than currently they do.
And the second thing is, when they keep the network up, they want to keep it running. So on the day two type of operation, they want to monitor the network, they want to troubleshoot and they want to fix with the help of ai. The last thing is on the ongoing base, they want AI to be more advanced, to help them optimize the network on their, on their own, meaning that they help, uh, um, self-healing and, uh, uh, you know, do a lot of these, uh, matic, uh, workflows.
So these three buckets reflect what, you know, the customer desire for 40 ai. And, um, believe or not, you know, I think most of the business, when they run their network operation, they are taking effort to get smarter. It's not that we just started, uh, with gen ai.
So if you look back like 30 years ago, everything is manual. Think about the old days when you deploy one device at a time. You change one network policy at a time.
You know, that's really manual and that's very time consuming. And the moving to about 15, 20 years ago, the base, the scripting comes out and it helps a lot of people, but only the programmers who can code. And the limited, uh, there, they're limited on automation capabilities.
And, uh, it's, it saves a lot of time, but, you know, they're limited in the scope and things to What Wehi guy, Couri future. Um, I think a lot of organizations, especially larger ones, use, uh, blended, um, models. Mm.
They use services like a Fortinet, Fortinets, NOC, or SOC, as well as one of their own, maybe a few that they put together. Um, to what degree, is this your own Fortinet journey customer journey? Or in what way are they blended this, this, this particular journey towards being smarter?
Okay, so, um, of course, Fortinet, um, you know, can manage its own, um, like ecosystem environment, but we realize, you know, majority of the customers, right? 80% of the customers are in the multi-vendor environment, so nobody's in single vendor. So, um, when we build our ai, we keep that in mind.
We keep our partners in mind, we keep our open system, uh, in mind. So, um, when we, uh, collaborate, we actually already do, uh, with, you know, like 500 ecosystem partners with their tools. So on the operation and network operation side, we already have these workflow end to end, uh, integration with them.
So moving forward, I think the vision is that our AI will collaborate with somebody's, our partner's, AI to make that, uh, multi-vendor ecosystem work more efficiently. I would expect that because it's your business, you are farther to the right on this diagram than, than, than most, Yeah. Yeah.
So we, we definitely are. And, uh, um, we're also, you know, kind of, uh, um, partnership with some leading, um, providers in the networking network management field. Um, on doing that, I just, just from a, sorry, just from a Ivan mcfe, from Google, just from a, um, a, uh, a Fortinet versus a multi-vendor environment, what is the delta between the two?
Um, from our customer? Um, No, from, from, from how you can operate it within a Fortinet environment versus a multi-vendor environment. How we operate, How you can, so therefore, oh, you have certain capabilities that apply to a footed environment currently, correct?
Yes. But don't apply to multi ven environment. What's the delta?
Um, if, if we operate in our environment, you can consider that a hundred, right? Because we can turn on all the capabilities it's built for that, um, for multi-vendor. I don't know how I can come up with exact percentage of data.
Um, but I would say because our, um, APIs, um, are quite comprehensive, so I suspect for our partners, they can take in, you know, majority of the capabilities, you know, like 80, 90% is there, uh, for, for the customer to leverage. And, And just to expand a little bit on That, and another couple delta components. One would be the interoperability with the platform, because we really have deep native integration, not just with the AI into our security fabric, into our platform, but also across these products, right?
So, oops, that's not good spilled on myself. But, um, so across these products and that interopability, when you look at like a multi-vendor environment, a big problem can occur, um, for them in the sense that, uh, yeah, the technologies don't like to work together as well, right? So I have to now jump in and out of all these different tools, they're not working well together.
It makes it really difficult to, to automate across them. For a lot of organizations, it requires more resources. So, I mean, we can operate in both environments.
They're gonna get the majority of the capabilities, but in terms of the true, true delta, it's, it's na that native integration across the board is pretty, pretty big, pretty up there. And then who is responsible? Is it the, your, the third parties who responsible actually using an APIs and develop integration, or does for actually develop integration for all the third parties?
Because we're talking about security here, right? Yes, both. Both.
Yeah. We, we have our ecosystem of fabric, uh, ready, partners and technology partners that we work very closely with, and together, we, we build them out. Now there's also, um, we have to certify, of course, right?
Then there's vendors that will also build their own. There's also customers. For instance, we have a, a, a product where you can build out a connector and as many, um, auto automation actions as you'd like, or you can go into an existing connector that we've certified, right?
That integration we've built. And I want to add a couple more automation actions to it. Yeah.
So as, as a customer, I can go do that as well. So it's, it's, it's a little bit of a blend, but to give you a picture, Yeah, to summarize, uh, what Max just said, we build, we also, we, you know, we with a leading, uh, integrator with, uh, a partner if we do. And also, um, some third parties lead the development.
So they build, we provide all the libraries of APIs. And then the third part is we have a community of developers, and, uh, they build based on the, uh, library of APIs that we provide. I also can illustrate a little bit more in detail on this part, um, during my presentation later as well.
Okay, Great. Okay. So come to the exciting part of the use cases.
So I'll show you 40, uh, AI assists in our NOC platform. So the first one is day one. Uh, you figured is the deployment is the, um, the turning up the service.
So, um, what 48 assist can do over here is you basically, say example, you have a SD WAN network that, uh, you want to deploy. Um, and then you probably only know your network topology. And, uh, you probably only have a hand drawing, uh, topology map that you can reference to, which, you know, your, uh, IP address, your port configuration, et cetera.
And then you upload your handwriting image to our 40 AI assist in the NOC platform. And our 40 AI assist can turn out and create, uh, the, uh, the configuration script for you. So that's one part, you know, quickly helping with the configuration script, what if you have existing ones, right?
Um, 40 a assist can help you validate your existing script and, uh, point out where you have, uh, conflict, where you should edit, uh, your scripts. Um, and it is all one click away, uh, from execution. So that's one part on day one, this helps the development.
Now, in day two, this is more about troubleshooting and fix things, right? So on same platform, uh, with our NOx platform, um, you bring up 40 AI assist and, uh, you it to check your network health for you like VPNs and tunnels and et cetera. So, uh, what 40 AI does is it helps you zoom into the, uh, the VPN issue area or the wifi issue area, and then not only identify where it's down, but what's the reason it's down.
And one more step, um, further it can recommend the fix for you, right? So this is where the man in the middle approach comes in. Every time it gives you recommendations for fix, it always asks you to confirm whether you want the 40 AI assist to execute that ex uh, the remediation for you.
If you confirm you building that trust, uh, 40 ai uh, assist will automatically bring up the install wizard and let you see the fixing progress. So this is, um, So you use the word or the term helps you. So when you do that, are you actually running these automatically behind the scenes, constantly on your network and then coming up with these opportunities to fix stuff and then only evolving you?
Or is it something that you've gotta trigger each time to run? Okay, so in this example, you ask, like you initiate, right? It's not in the background, but in the next slide I'll show you, you know, we can do your way and the, the way you mentioned.
So this is more about network optimization, auto adapts, and, uh, you know, kind of, uh, predict things and, uh, um, proactively doing things. This is where, um, we have multiple tools to work together, not only our NOx side, but our AI ops, right? So the AI ops and what, uh, max talk about the, uh, the SOC side of things, feeding the information about the network performance, the network insights, the threat analytics, the telemetry data, all into this network operation center.
And, uh, the good part of it is it's doing the baselining of your environment. And, uh, it do, it does the, uh, trend analysis. So anytime you find a derail from your normal standard of saying, you know, your wifi performance is below the threshold, um, it automatically trigger the analysis and the investigation, uh, with a playbook of things to check.
And, uh, once it's checked and find issues like, oh, you have over check channel overlapping issues, or you have too many clients jammed up on one, uh, channel, it will propose remediation and fix for you. And you can, same thing you can execute, uh, when you confirm, uh, the recommendation. Uh, hi there, it's Al Budin from MMB Networks.
Um, quick question on this, 'cause, um, this looks automated. Um, how does this fit into organizations change management and change control processes? Because making lots of automated changes continuously, if there's, if there's issues, whether it's initiated by, you know, a knob technician or whether it's done automatically, it would normally have to go through change control for me, uh, network changes.
So how does that fit into the process? Yeah, I think you are, you are raising a very good question about, um, all these might change the organization's, uh, NOC management process, uh, which is true. That's why, um, this is what we see from our customers, more advanced stage.
Um, I think not every customers are ready to jump into this stage. I think in order for them to do so, they do have to have a very, uh, well-defined, um, process and, and governance in order to, uh, go to this. And I also feel like the, you know, the trust, uh, of these AI capabilities are meant to be built and tested and validated along the way.
Um, not, you know, not all customers are comfortable, you know, just directly using your tool live in their production environment. Yeah. So there's going to be a lot of back and forth.
Yeah. Is it possible to generate like, uh, for example, a change and our rollback, like based on the suggested, um, actions from, uh, for the I, so for example, you could generate a, uh, implementation plan or change plan, take it to the change advisory board meeting, say, this is what we're going to do, and then once you get the approval, you know, you effectively execute the, the change. Is that a valid and Brooke?
Yes. I, I do believe so. Yeah.
Yeah. I mean that crawl, walk, run mentality is often very helpful, right? Mm-hmm.
So do you have a staged, like do you allow the, you know, we, we call it human in the loop. I like to say the click okay to continue loop. Um, do you offer that option to let people gain trust?
Yes. In the automations first? It would be great if we could see that.
Yeah. So We actually can allow you to see that. If you guys are interested, um, we go to our, uh, demo center.
Uh, we do have a read only demo that you can try, experiment with our 40 a assist.