Fortinet Launches FortiSOC: Unifying SIEM, SOAR, and Agentic AI into a Single SaaS Platform

Fortinet has announced the availability of FortiSOC, a cloud-delivered SaaS platform designed to centralise security operations centre functions. The solution unifies SIEM, SOAR and identity threat detection into a single console and subscription model.

author-image
DQChannels Bureau
New Update
Fortinet Launches FortiSOC: Unifying SIEM, SOAR, and Agentic AI into a Single SaaS Platform

Fortinet has announced the availability of FortiSOC, a unified, cloud-delivered Security Operations Centre (SOC) platform. Delivered as a native Software-as-a-Service (SaaS) architecture, the solution consolidates six critical security operations functions into a single console. The platform embeds autonomous agentic AI designed to investigate, contextualise, and correlate telemetry anomalies across disparate enterprise assets and user identities, executing rapid remediation workflows under human analyst oversight.

The introduction of FortiSOC addresses a severe bottleneck within modern enterprise Security Operations (SecOps) teams. As threat actors deploy automated scripting to exfiltrate data at machine speed, defenders remain hindered by fragmented security tools, high alerts volume, and disconnected operating matrices. By collapsing historically isolated tools into a single subscription model, FortiSOC aims to reduce procurement complexity and bridge the operational visibility gap.

Collapsing Corporate Security Silos via a Unified Data Pipeline

Rather than functioning as a surface-level portal that merely links out to disparate backend applications, FortiSOC operates on a common data pipeline. The cloud-native environment ingests data feeds from multi-vendor network nodes, endpoints, cloud infrastructures, and authentication servers. The platform normalises, enriches, and correlates this information once, ensuring that all integrated detection engines analyse an identical, unified data layer.

The architecture unifies four core security pillars natively within its console:

  • Security Information and Event Management (SIEM): Centralising big-data logging and high-velocity normalisation.

  • Security Orchestration, Automation, and Response (SOAR): Directing complex, multi-system playbooks to contain active breaches.

  • User and Entity Behaviour Analytics (UEBA) & ITDR: Tracking baseline identity behaviours to isolate hijacked session credentials or credential-stuffing exploits.

  • Threat Intelligence & Case Management: Ingesting real-time indicators of compromise (IoCs) directly from FortiGuard Labs to streamline legal compliance records.

The Power of Agentic AI and Model Context Protocol Coordination

The technical core of the platform isFortiAI-Assist, an embedded intelligence subsystem that transitions security operations from basic guided playbooks into true autonomous execution. Unlike traditional machine learning systems that rely on static, hardcoded conditional statements to flag anomalous behaviour, FortiSOC's reasoning agent connects fragmented, multi-stage attack indicators across an entire environment to map complete cyberattack paths.

To coordinate these automated workloads smoothly, the engine implements the Model Context Protocol (MCP). This open standard allows the central FortiAI-Assist agent to coordinate multiple sub-agents safely across security and IT systems. For instance, if an anomaly is identified, one sub-agent can parse user access privilege settings via an identity tracker, while a separate sub-agent pulls endpoint telemetry data to assess whether local malware files have modified system memory. By removing the manual administrative hand-offs that slow down containment workflows, the platform accelerates mean time to remediation (MTTR).

Platform Subscription TierIncluded Infrastructure ModulesCore Enterprise Target Workload
FortiSOC CoreFabric Telemetry, Baseline Playbooks, Agentic AITurnkey detection and response tailored for Fortinet Security Fabric environments.
FortiSOC AdvancedFull Multi-Vendor Ingestion, UEBA, Advanced SOARMature, highly distributed corporate infrastructures requiring cross-vendor tool correlation.

When an attack path is verified, FortiSOC can execute automated containment actions based on organisational configurations, such as instantly isolating infected endpoints, updating cloud firewall policies, or generating high-priority engineering tickets. When sensitive response adjustments are required, the analyst remains in full control via human-in-the-loop validation checkpoints.

Ecosystem Scaling and Industry Perspectives

Importantly, FortiSOC is engineered to complement and expand Fortinet’s existing portfolio of standalone security systems, including FortiAnalyzer, FortiSIEM, and FortiSOAR. The company confirmed that these individual systems will continue to be enhanced and sold for organisations preferring dedicated, non-unified infrastructure layers. Furthermore, for resource-constrained firms seeking outsourced security management, the new platform is available as a managed framework through the FortiGuard SOC-as-a-Service offering.

Michael Xie, Founder, President, and Chief Technology Officer at Fortinet, highlighted the need for simplicity in modern defence structures:

“Security teams today are being challenged by faster attacks, growing investigation volume, and fragmented operations that simply don’t scale. FortiSOC gives organizations a simpler way to operationalize the SOC capabilities they need through a unified, cloud-delivered platform designed to support security teams of all sizes, from teams building foundational capabilities to enterprises scaling advanced SOC environments. With embedded AI, integrated workflows, and built-in best practices informed by Fortinet’s own global security operations center, FortiSOC delivers the power of an AI SOC to help customers eliminate complexity, automate threat detection and response, and stay a step ahead of attackers.”

Michelle Abraham, Senior Research Director of Security and Trust at International Data Corporation (IDC), validated the enterprise market demand for SaaS-based SecOps orchestration:

“IDC research shows that organizations are increasingly prioritizing analyst workflow and investigation experience as well as cloud-delivered security operations as they work to improve visibility, streamline processes, and accelerate response. FortiSOC builds on Fortinet’s established security operations portfolio by combining proven technologies into a unified SaaS platform that can support both foundational and advanced SOC use cases.”

Advertisment