OT / CPS / Fortinet

FortiNDR On Premises for OT

FortiNDR applies network threat detection to industrial traffic as well as IT traffic. Its OT deployment model is useful for understanding how sensors and central management fit around process networks. This is a network-detection option, not a substitute for every controller inventory or engineering change-management function.

Network detection for industrial environmentsResearch reviewed

What you are evaluating

This profile concerns the on-premises OT deployment described in the data sheet. FortiNDR Cloud is a distinct deployment. FortiGate, FortiNAC, FortiAnalyzer and FortiSOAR integrations do not imply that those products are included.

A useful evaluation context

Industrial security teams evaluating NDR alongside existing Fortinet network controls.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Traffic analysis includes support for named industrial protocols such as Modbus TCP, BACnet and OPC.
  • Standalone and centrally managed sensor layouts support different site designs.
  • Security Fabric integrations provide paths from detections to externally enforced response.

Where it fits in the work

  1. Choose sensor locations that observe the intended IT/OT boundary without becoming an inline dependency.
  2. Review a lab network anomaly against the relevant protocol and asset context.
  3. Tabletop the alert handoff to a separately authorized firewall or NAC action.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

Draw a sensor plan for an industrial DMZ, historian and control network. Trace a fictional abnormal connection through detection, analyst review and a proposed firewall change.

Evidence to look for

List any unobserved traffic and identify the owner who can reject an unsafe block. Demonstrate in the diagram that alert generation and enforcement are separate steps.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. Which OT protocol versions and traffic paths are actually observable?
  2. What works locally when central connectivity is unavailable?
  3. Which separate licenses and service accounts enable the response integration?

Find your next idea.

Tip: press / to open search. Escape closes this window.