What's Happening?
Fortinet, a leading cybersecurity solutions provider, is reinforcing its commitment to secure-by-design principles, aligning with initiatives like CISA’s Secure by Design Pledge. The company has implemented significant changes in its product development
and offerings since signing the pledge in 2024. Key advancements include the elimination of default passwords, requiring unique credentials during installation, and expanding multi-factor authentication (MFA) coverage to 97.1% across its online services. Fortinet is also driving the adoption of more secure MFA methods, moving away from less secure options like SMS and email. A major development is the introduction of automatic updates for eligible FortiGate devices, which has already updated over 1.8 million devices without manual intervention. Furthermore, Fortinet has reduced the number of devices running end-of-support firmware by 13% in the last three months through device monitoring, customer notifications, and a trade-in program. The company is also focusing on reducing vulnerability classes, such as SQL injection, through expanded code auditing and management accountability, leading to a 95% decrease in the use of high-risk functions in the FortiOS codebase over the past six months.
Why It's Important?
These enhancements by Fortinet are crucial for bolstering the cybersecurity posture of organizations across various sectors in the U.S. The elimination of default passwords and the widespread adoption of MFA significantly reduce common entry points for cyberattacks, making systems inherently more secure from the outset. Automatic updates are particularly vital as they ensure that critical security patches are applied promptly, closing known vulnerabilities before attackers can exploit them. This proactive approach minimizes the window of opportunity for N-Day exploits, which often leverage publicly known but unpatched flaws. By reducing the number of devices on unsupported firmware, Fortinet helps customers mitigate risks associated with outdated systems that no longer receive security updates. The focus on reducing vulnerability classes at the source, such as SQL injection, represents a strategic shift towards preventing entire categories of flaws, leading to more robust and resilient software. This benefits all users of Fortinet products by providing a more secure foundation against evolving cyber threats, ultimately reducing the financial and operational impact of security breaches.
What's Next?
Fortinet's immediate next steps include a continued focus on its secure-by-default initiatives, expanding automatic update coverage to more products, and supporting customer hygiene best practices through training and guidance. This may involve the removal of legacy protocols that are deemed insecure, with Telnet cited as a prime example for 2026. The company plans to further enhance forensic observability as a standard feature of network devices, aligning with initiatives like the UK National Cyber Security Centre’s efforts, to provide cyber responders with better tools for detecting tampering and investigating breaches. Fortinet will also continue to expand its hardening efforts, ensuring security controls are consistently applied and tested against real-world attack paths. The integration of Frontier AI into its Secure Product Development Lifecycle Policy is also underway, indicating a move towards leveraging advanced technologies for proactive security. Additionally, Fortinet offers managed firewall services and SOC-as-a-Service to support organizations that lack the internal resources for optimal security configuration and operations.
Beyond the Headlines
The deeper implications of Fortinet's secure-by-design approach extend to fostering a shared responsibility model in cybersecurity. While vendors like Fortinet are taking significant steps to build more secure products, the effectiveness of these measures still relies on customers maintaining current inventories, monitoring vendor alerts, and acting on guidance. The push for automatic updates and the deprecation of insecure legacy protocols highlight a broader industry trend towards mandating higher security standards, potentially shifting the burden of security from end-user configuration to vendor-provided defaults. This could lead to a more secure digital ecosystem overall, but also requires users to adapt to new operational paradigms, such as trusting automated patching. The emphasis on internal vulnerability discovery, with 60% of disclosed vulnerabilities in 2025 found internally, suggests a robust internal security testing culture that could become a benchmark for other cybersecurity firms. This commitment to transparency and proactive self-assessment is crucial for building trust and demonstrating genuine dedication to product security in an increasingly threat-laden landscape.











