Fortinet enhances FortiRecon to align with CTEM framework

Fortinet, the global cybersecurity provider driving the convergence of networking and security, has turned the FortiRecon platform into a comprehensive solution aligned with the continuous threat exposure management (CTEM) framework.

The latest release introduces expanded internal attack surface monitoring, adversary-centric dark web intelligence, and security orchestration, all in a unified platform. These enhancements help organisations proactively identify and prioritise real-world exposures, validate risks like an attacker would, and accelerate response.

“CISOs and security teams are overwhelmed by growing attack surfaces and an endless stream of unprioritised alerts,” said Nirav Shah, Senior VP of Products and Solutions at Fortinet.

“With the latest enhancements to FortiRecon, we’re giving organisations an attacker’s eye view of their internal and external exposures, backed by AI-powered threat intelligence from FortiGuard Labs, real-world validation, and automated response. This allows organisations to cut through the noise, focus on what matters most, and measurably reduce risks and vulnerabilities before attackers can exploit them.”

The announcement comes amid growing demand for exposure-driven security strategies as organisations struggle to manage expanding attack surfaces, alert fatigue, and fragmented security operations, Fortinet said. According to Gartner: “By 2026, organisations prioritising their security investments based on a continuous exposure management programme will be 3x less likely to suffer from a breach.”*

FortiRecon, in combination with its strong integration with the Fortinet AI-Driven Security Operations Center (SOC) platform, now delivers capabilities across the five pillars of the Gartner CTEM framework—scoping, discovery, prioritisation, validation, and mobilisation—enabling organisations to operationalise these pillars within a single, tightly integrated platform and drive coordinated remediation efforts across security and IT teams.

The latest enhancements include: 

- Attack surface management: Continuously monitors and delivers an adversary’s view of the organisation’s internal and external digital attack surface. The latest release adds National Vulnerability Database (NVD) severity ratings, in addition to FortiRecon Active Exploitation severity ratings for faster and smarter patching.

- Adversary-centric intelligence: Provides actionable threat insights from dark web activity, ransomware intelligence, leaked credentials, vulnerabilities being exploited in the wild, and at-risk vendors. Enhancements include bulk indicators of compromise (IOC) downloads and stealer infection details, accelerating SOC workflows, and improving breach detection.

- Brand protection: Monitors for domain impersonation, rogue mobile apps, phishing campaigns, and executive targeting. FortiRecon Brand Protection helps protect executive online presence with proprietary algorithms to monitor, detect, and take down fake phishing domains, brand and executive impersonations, rogue mobile applications on multiple app stores, data leaks in code repositories, open bucket exposures, and phishing campaigns.

- Security orchestration: Leverages security orchestration and automated playbooks to investigate and respond to security threat findings. FortiRecon Security Orchestration reduces the time needed for responders to prioritise and take appropriate actions by automating and streamlining security workflows.

Existing FortiFlex customers may use their FortiFlex credits to deploy FortiRecon Cloud. FortiFlex offers usage-based licensing for customers with dynamic hybrid and multicloud environments and managed security service providers (MSSPs). When purchased through major cloud marketplaces, FortiFlex can also help customers meet cloud-committed spend obligations.

Fortinet was recently named an Overall Leader as well as a Market Leader and Innovation Leader in the KuppingerCole Leadership Compass for Attack Surface Management 2025. The report highlights the operational readiness of FortiRecon with broad support for Center of Internet Security (CIS), industrial control systems (ICS), Internet of Things (IoT), and operational technology (OT) environments, and its integrations with the broader Fortinet Security Fabric tools such as FortiGate NGFW, FortiSOAR, FortiSIEM, and FortiDAST.

*Gartner. How to Manage Cybersecurity Threats, Not Episodes, by Jeremy D’Hoinne. Gartner, 11 October 2023.

Comments

Popular posts from this blog

SentinelOne recognised as a 2025 Gartner Peer Insights Customers’ Choice for XDR

AWS: AI adoption grows 20% in Singapore