SOAR / MDR / Fortinet

FortiSOAR

FortiSOAR is Fortinet's fabric-adjacent security orchestration product with SaaS and self-managed options. It documents playbooks, case management, expert agents, API and MCP connections, and multi-tenancy aimed at managed service providers. OT-oriented packs are advertised.

SOAR / automation softwareResearch reviewed

What you are evaluating

Software the buyer or an MSSP staffs. Connector counts change over time. OT playbooks are a capability claim to test, not a plant-safety certification or sign-off.

A useful evaluation context

Evaluation is whether Fortinet-heavy IT or OT estates want orchestration inside the Fortinet fabric rather than a standalone tool.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Playbooks and case management across Fortinet and third-party tools the buyer connects.
  • Expert agents plus API and MCP connections for actions the customer authorizes.
  • Multi-tenancy for managed service providers and advertised OT-oriented content packs that still require the buyer to validate plant impact.

Where it fits in the work

  1. Decide SaaS versus self-managed deployment and which tenants an MSSP would isolate.
  2. Encode a playbook that enriches an alert and requires human approval before OT-adjacent actions.
  3. Inventory connectors actually in use rather than relying on published connector counts.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

In an authorized lab tenant that is not connected to plant networks, run a synthetic workstation alert playbook that enriches asset data, pauses before any isolation, and never targets a safety-instrumented system.

Evidence to look for

The case shows enrichment and the human pause, and no OT or production host received a containment action.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. Which OT detections are read-only, and who authorizes any process-impacting containment?
  2. Does an MSSP tenant model match how you separate customers or plants?
  3. How are playbooks and cases exported if FortiSOAR is later replaced, including MSSP tenant separation?

Find your next idea.

Tip: press / to open search. Escape closes this window.