Cloud Security

Fortinet and Wiz Partner for Securing Cloud Workloads Using CNAPP

Fortinet and Wiz Partner for Securing Cloud Workloads Using CNAPP
  • Fortinet and Wiz partner for enhanced cloud workload protection, joining each other's tech programs.
  • Their collaboration combines Fortinet's network security with Wiz's cloud technology, bolstering cloud workload protection.
  • The partnership broadens Fortinet's Open Fabric Ecosystem, enabling unified cloud workload security for joint customers.

Fortinet and Wiz Technologies have formed a partnership to better secure cloud workloads. Wiz has joined Fortinet's Fabric-Ready Technology Alliance Partner Program, while Fortinet has become a part of the Wiz Integration (WIN) Program. Together, they have developed an integrated solution combining their technologies to safeguard cloud workloads.

Fortinet’s customers can utilize the Wiz Cloud-Native Application Protection Platform (CNAPP) to scan their cloud infrastructure, identify risks, and implement automation rules. On the other hand, Wiz customers can leverage Fortinet's Security Fabric to automate security enforcement and protect their cloud environments, utilizing tools like the FortiGate VM Next-Generation Firewall virtual appliance and FortiGate Cloud-Native Firewall (CNF) for traffic management.

This partnership allows Fortinet to expand its Open Fabric Ecosystem and offer joint customers comprehensive cloud workload security across different cloud environments. For Wiz, having Fortinet as part of WIN empowers security teams to meet diverse needs quickly and adopt an efficient cloud operating model.

Fortinet has numerous Open Fabric Ecosystem partners, including major players like Amazon Web Services (AWS), Cisco, Google Cloud, IBM Security, and Microsoft. The WIN Program facilitates technology integrations and offers a catalog of cloud security partner integrations from various cybersecurity and technology companies.

The Fortinet and Wiz partnership enhances cloud workload protection by combining Fortinet's network security with Wiz's cloud technology. It enables automation, provides comprehensive cloud security, and expands Fortinet's ecosystem of security partners. Customers gain unified cloud security solutions across various cloud environments and access to integrated technologies.

Concerns may arise regarding vendor lock-in and potential integration challenges. The partnership may not cover all cloud platforms, and overlapping features should be carefully assessed. Organizations relying on this partner ecosystem may have limitations in terms of security capabilities and offerings.

Spotlight

Spotlight

Related News

Cloud App Management

Red Hat Named a Leader in Multicloud Container Platforms by Independent Research Firm

Business Wire | October 04, 2023

Red Hat, Inc., the world's leading provider of open source solutions, today announced that Red Hat OpenShift has been recognized as a Leader by Forrester Research in The Forrester Wave™: Multicloud Container Platforms, Q4 2023. Forrester Research identified the 8 most significant providers and researched, analyzed and scored them. Red Hat and the other top providers were evaluated for The Forrester Wave™ against 32 criteria grouped into three categories: current offering, strategy, and market presence. In the evaluation, Red Hat received the highest possible scores in 29 criteria, including developer experience, operator experience, DevOps automation, development environments, security features and policies, AI/ML services, data management, multicloud and hybrid cloud support, vision, roadmap, innovation and more. According to Forrester’s evaluation, “With OpenShift’s systematic innovation and development on multiple fronts, Red Hat has helped transform the MCP market segment. What began as a rough-around-the-edges open source effort has become a full-blown multicloud development and infrastructure platform that handles anything from bespoke internal apps to digital operations platforms and complex AI/ML workloads.” View a complimentary copy of The Forrester Wave™: Multicloud Container Platforms, Q4 2023 here. Supporting Quote Joe Fernandes, vice president and general manager, Hybrid Cloud Platforms, Red Hat We are proud to be recognized as a leader in The Forrester Wave™. As they note in the report, ‘Red Hat sets the pace with enterprise IT capabilities and massive market presence.’ We believe receiving the highest possible scores across 29 criteria validates Red Hat OpenShift as a holistic application platform providing organizations with a trusted set of capabilities to more quickly and easily bring cloud-native applications to market. We designed Red Hat OpenShift to support organizations regardless of workload type or where an application lives across the hybrid cloud and will continue to evolve and refine its features to best support customer innovation today and in the future. About Red Hat, Inc. Red Hat is the world’s leading provider of enterprise open source software solutions, using a community-powered approach to deliver reliable and high-performing Linux, hybrid cloud, container, and Kubernetes technologies. Red Hat helps customers integrate new and existing IT applications, develop cloud-native applications, standardize on our industry-leading operating system, and automate, secure, and manage complex environments. Award-winning support, training, and consulting services make Red Hat a trusted adviser to the Fortune 500. As a strategic partner to cloud providers, system integrators, application vendors, customers, and open source communities, Red Hat can help organizations prepare for the digital future.

Read More

Cloud Security

Darktrace Unveils New Cloud-Native Security Solution Using AI to Provide Real-Time Cyber Resilience for Cloud Environments

PR Newswire | October 30, 2023

Darktrace, a global leader in cyber security AI, today unveiled a new Darktrace/Cloud solution based on its unique Self-Learning AI. The new solution provides comprehensive visibility of cloud architectures, real-time cloud-native threat detection and response, and prioritized recommendations and actions to help security teams manage misconfigurations and strengthen compliance. When combined with insight from Darktrace solutions for network, email, apps, zero trust and endpoint, Darktrace/Cloud provides a deeper, contextualized understanding of the risks and threats currently facing an organization's digital estate. According to a recent report, "Gartner anticipates over 99 percent of cloud breaches will be based on a customer error, account takeover or misconfiguration until 2027". Cloud environments are constantly evolving so security professionals need to increase the level of visibility while keeping up with changing compliance, risk and security requirements. The rise of cloud-native technologies including containers, Kubernetes and microservices also require new tools and techniques for detecting and responding to known and novel threats. Unlike static cloud security tools that provide snapshots of a specific point in time, Darktrace/Cloud is real-time, all the time. Our Self-Learning AI continuously learns patterns between workloads, assets, policy configurations and identities to provide a dynamic view of cloud architectures. We analyze the entire cloud stack from data to control plane, combining an understanding of architecture and network with a new flexible, scalable deployment model, said Jack Stockdale, Chief Technology Officer, Darktrace. Our innovative approach to cloud security is built on more than a decade of leadership in Cyber AI that is already protecting our customers' critical business areas from network and email to operational technology. Available today, the new capabilities in Darktrace/Cloud include: Comprehensive visibility and architecture modelingfor insights into the constantly changing nature of cloud environments. This visibility is constructed dynamically from configuration, network, users and identity and access management (IAM) data. Darktrace establishes patterns of life for cloud resources, identities, and services to understand who has access to what and how. This is critical for detecting anomalies and unknown threats. Universal attack path modelingprovides a dynamic view of where attackers may look to move next. Darktrace brings together real-time cloud data and a deep understanding of your cloud environment with a platform approach that provides insights about risks from other covered areas of the business (e.g., network, email) to highlight potential attack paths and prioritize important assets to secure. Unique real-time and cloud-native threat detection and responsethat provides a dynamic view of known and novel threats within the cloud. Darktrace combines deep cloud attack path knowledge with real-time anomaly and threat detection through cloud-native autonomous response actions, such as detaching a policy from a user or removing a workload from a security group. Prioritized cloud posture managementthat starts by examining cloud configurations against common compliance frameworks. Where misconfigurations are detected, Darktrace provides a prioritized view of what to fix first, based on a risk profile generated from security and business context. Guided steps can be provided to help teams proactively address these before they become a significant issue. Cost discoveryto provide a better understanding of cloud resource allocation. This helps teams contextualize their cloud resources according to security and business priorities. Communication and collaboration capabilitiesto streamline workflows between security teams and DevOps teams. Tickets can be created on demand, teams can communicate directly via messaging platforms, and alerts and anomaly detections can be sent to Security Information & Event Management (SIEM) or Security Orchestration, Automation and Response (SOAR) products and the Darktrace Mobile app so they can be alerted on the go. Flexible deployment optionsinclude an agentless deployment by default so organizations can be up and running in minutes. Teams can use the dynamic architectural view and risk context to decide where to deploy agents for enhanced real-time actions and deeper inspection. Sykes Cottages, a cloud-native travel agency platform in the UK, has experienced significant growth in the last five years and has relied on the cloud to help them scale throughout this period. "When it comes to cybersecurity, having visibility and an understanding of what you've got and your risks is critical. If I don't know it's there, I can't protect it," said Jonny Mattey, Head of Cybersecurity, Sykes Cottages. "Having a holistic, live view of our cloud environment enables us to work pragmatically and use AI to cut down management time so that we can address security risks and improve our resilience." The new Darktrace/Cloud solution is now available on Amazon Web Services (AWS) through the AWS Marketplace, a curated digital catalog that makes it easy for customers to find, buy, deploy, and manage the third-party software they need to build solutions and run their business. Darktrace and AWS have been collaborating since 2017 to help organizations secure their AWS environments. Darktrace protects AWS environments for organizations around the world including Sunwest Bank and ProPhase Labs. Darktrace is an AWS Security Competency Partner and is part of the AWS ISV Accelerate program. "Security is job zero at AWS," said Paddy Fitzpatrick, Director – Independent Software Vendors, UK & Ireland at Amazon Web Services. "As the threat landscape continues to evolve, the availability of AI-based tools like Darktrace/Cloud on the AWS Marketplace will help customers to gain increased visibility, and respond more effectively to security risks and threats." Darktrace first extended its Cyber AI capabilities to cloud environments in 2016, applying its world class algorithms to granular network traffic. Darktrace/Cloud was recently named Cloud Security Product of the Year for Large Enterprises by Computing Magazine in its 2023 Cloud Excellence Awards. ABOUT DARKTRACE Darktrace (DARK.L), a global leader in cyber security artificial intelligence, is on a mission to free the world of cyber disruption. Breakthrough innovations in our Cyber AI Research Center in Cambridge, UK have resulted in over 160 patents filed and research published to contribute to the cyber security community. Rather than study attacks, Darktrace's technology continuously learns and updates its knowledge of 'you' and applies that understanding to optimize your state of optimal cyber security. Darktrace is delivering the first ever Cyber AI Loop, fueling a continuous end-to-end security capability that can autonomously spot and respond to novel in-progress threats within seconds. Darktrace employs over 2,200 people around the world and protects approximately 8,900 customers globally from advanced cyber threats. Darktrace was named one of TIME magazine's 'Most Influential Companies' in 2021. To learn more, visit http://www.darktrace.com.

Read More

Cloud Security

Palo Alto Networks Revolutionizes Cloud Security With Industry-First Integrated Code to Cloud Intelligence

PR Newswire | October 23, 2023

In the last decade, organizations have begun building and deploying cloud applications at an unprecedented pace, and there's no sign of slowing down. According to Gartner, 65% of application workloads will be optimized or ready for cloud delivery by 2027 — up from 45% in 2022. Palo Alto Networks (NASDAQ: PANW) today reimagined how enterprises approach cloud security with the industry's first integrated Code to Cloud intelligence introduced as part of the Prisma® Cloud Darwin release. Today marks a "Darwin moment" for cloud security as Prisma Cloud pushes organizations to evolve beyond single point solutions and adopt a holistic approach that provides a single source of truth. While the cloud offers exceptional agility and efficiency, it introduces major security risks that have become increasingly widespread — 80% of security exposures are found in cloud environments, according to the company's Unit 42 Threat Intelligence team, which can result in large-scale breaches. These rising cloud attacks and the velocity of cloud application development are outpacing the speed at which security teams can protect their organizations. Current approaches for code-to-cloud security are siloed, with the average organization relying on six to ten tools for securing cloud infrastructure alone. Having disparate security tools leads to an incomplete security posture and creates a massive operational burden for security teams. With its new Code to Cloud intelligence, Prisma Cloud — the industry's most complete cloud-native application protection platform (CNAPP) — offers a single trusted place that connects insights from the developer environment through application runtime for security teams to contextualize alerts and pinpoint remediations. This intelligence effectively prevents risk and stops breaches while enhancing the end-user experience and improving developer and security team collaboration. "The only way to secure applications from code to cloud is by fending off risk from entering the development pipeline and preventing breaches of applications in production. This can only be achieved through an intelligent CNAPP platform like Prisma Cloud that gathers intelligence throughout the application lifecycle so security teams can precisely trace vulnerabilities and misconfigurations back to their origin in the source code. Prisma Cloud's Darwin release simplifies cloud security and improves productivity and collaboration across code, infrastructure, and runtime security." Ankur Shah, senior vice president, Prisma Cloud, Palo Alto Networks In many organizations, the ratio of developers to security professionals can be 100 to 1, resulting in understaffed teams. The current approach of working in silos does not guarantee comprehensive code to cloud security. This gap will widen as developers increasingly use AI to write and deploy code more quickly. Prisma Cloud, now with Code to Cloud intelligence, fosters collaboration between developers and security professionals by linking production security issues to specific remediation recommendations in code. Melinda Marks, practice director, Enterprise Security Group, said: "Today's reality is we face a cybersecurity skills shortage, especially in cloud security, while organizations are increasingly leveraging cloud services for faster application development to best serve customers and drive business results. At the same time, we have a rapidly evolving threat landscape increasingly targeting cloud workloads. So, it's crucial to invest in an effective security solution that supports increased development productivity from code to cloud to enable security teams to optimize security risk mitigation and protect their applications to enable business growth." Chris Bogaards, vice president of IT security, Global Atlantic Financial Group, said: "Our greatest challenge before Prisma Cloud was gaining clear visibility into what was occurring in our cloud applications and what security alerts to prioritize. Our developers freely create applications with a myriad of tools not knowing what risks they're introducing into the organization. With Prisma Cloud, we now have a simple, yet comprehensive view across our entire application portfolio to understand what vulnerabilities we have, which ones to prioritize and how to fix them." Watch Global Atlantic Financial Group's customer testimonial.

Read More