FORTINET launches FortiSOC, a cloud-based security operations platform
Fortinet (NASDAQ: FTNT) announced the availability of FortiSOC, a cloud-delivered security operations center (SOC) platform that consolidates six security operations functions into a single software-as-a-service offering.
The platform integrates security information and event management (SIEM), security orchestration, automation, and response (SOAR), threat intelligence, and behavioral and identity threat detection (ITDR) into one console under a single subscription model.
FortiSOC embeds agentic AI through a component called FortiAI-Assist, which is designed to autonomously investigate and correlate alerts across assets and identities, then recommend or execute response actions under analyst oversight. The platform also incorporates Model Context Protocol (MCP)-powered agent coordination across alerts, investigations, threat hunting, cases, and response actions.
"Security teams today are being challenged by faster attacks, growing investigation volume, and fragmented operations that simply don't scale," said Michael Xie, Founder, President, and Chief Technology Officer at Fortinet.
FortiSOC complements Fortinet's existing SOC portfolio, which includes FortiAnalyzer, FortiSIEM, and FortiSOAR. The company stated those products will continue to be developed and available alongside the new platform.
IDC Senior Research Director Michelle Abraham commented on the announcement, noting that "organizations are increasingly prioritizing analyst workflow and investigation experience as well as cloud-delivered security operations as they work to improve visibility, streamline processes, and accelerate response."
The platform includes native integrations across the Fortinet Security Fabric and third-party connectors, along with pre-built detection content and playbooks drawn from Fortinet's own global SOC operations. FortiGuard Labs threat intelligence and monthly content updates are also included.
