Fortinet FortiCNAPP
Security has improved and VPN access saves time while support responds quickly
What is our primary use case?
FortiCNAPP is mainly used from a security point of view. Some VPNs charge for their solutions, but Fortinet provides a free-of-cost VPN solution, making it more reliable and cost-effective for clients.
What is most valuable?
FortiCNAPP definitely brings time-saving benefits, and security is the main concern for the company.
What needs improvement?
Policy implementation is quite complex, and the stability will take more time for the solutions. There is definitely room for improvement in policy implementation.
For how long have I used the solution?
I have been working with Fortinet FortiCNAPP for the last five to ten years.
How are customer service and support?
Fortinet's technical support is definitely helpful and responsive. The response time for solutions or support is quick compared to other UTMs, which is beneficial.
What about the implementation team?
I do deployment as well for my customers.
What's my experience with pricing, setup cost, and licensing?
The pricing is a mediator compared to other products; it is not that much higher and not much lower than other products, making it a very affordable price.
What other advice do I have?
Policy implementation is one part of the solution; every customer needs particular policies for groups or department-wise needs, which takes time. I am not currently using FortiCNAPP's integration with DevOps tools; some inquiries are running, but it will take time to close, and I hope it will be done in the future.
The time for implementation of this product depends on the network and users; it varies based on how many users and networks are involved, as well as what downtimes are allowed. The maximum number of users I have encountered is approximately 300 or 400.
It took me weeks to deploy, gradually applying the policies and all of that, and it depends on the circumstances. FortiCNAPP's continuous compliance and security monitoring are gradually upgraded, which is why the solutions also get upgraded, and it depends on the UTMs.
I would rate this product 9 out of 10.
Network segmentation has strengthened access control and now streamlines automated threat response
What is our primary use case?
What is most valuable?
FortiCNAPP's automated policy recommendations significantly help improve security measures as part of an overall service wrap. When deploying a Fortinet SD-WAN or network, these tools provide greater visibility to vulnerabilities and enhanced security on the network. It functions as a proactive tool, enabling me to identify threats quickly and automate responses.
What needs improvement?
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
Some of my colleagues may utilize FortiCNAPP's integration with DevOps tools, though I am not extensively familiar with this capability. My technical teams do utilize integration with DevOps tools, as it performs significantly with automation regarding sophisticated challenges. We have an in-house development team that works on this, focusing on how it integrates primarily with the security fabric. Fortinet has their own developer networks, and we also explore what they may have accomplished previously. In terms of integration, FortiCNAPP performs substantially with DevOps tools, though this would depend on what our teams choose to implement.
How was the initial setup?
What was our ROI?
What other advice do I have?
Unified Cloud Security Visibility with Smart Risk Prioritization
By consolidating CSPM, CIEM, vulnerability management, and runtime protection into a single platform, FortiCNAPP reduces complexity and improves risk prioritization. Instead of reacting to hundreds of low-impact alerts, it correlates findings to highlight the most critical attack paths. This has benefited me by improving efficiency in identifying high-risk issues, reducing manual investigation time, and strengthening overall cloud security posture. It also supports compliance monitoring, which makes reporting and audits much more manageable.
Neutral Cloud Visibility and Compliance, but Setup and Alert Tuning Take Time
Helpful posture management and compliance reporting
Easy-to-understand dashboards
Integrates well with other Fortinet security products
Good alerting for misconfigurations and risky cloud permissions
Some reports and dashboards could be more customizable
Occasionally too many alerts without proper tuning..
Diverse Apps, Trustworthy Security, and a Simple, Easy-to-Use Interface
Effortless Setup with Stellar Features
Improving security insights has been helpful but inconsistent vulnerability tracking needs attention
What is our primary use case?
The major use case for Lacework FortiCNAPP is for security.
I'm using it for security internally for my company.
What is most valuable?
The machine learning capability in Lacework FortiCNAPP is used for threat detection.
Automated policy recommendation helps to improve my security measures in general.
I usually use certain policies in my workspace, like if there are some alerts or something.
Continuous compliance and security monitoring are good, but they need more improvement in the vulnerabilities part.
What needs improvement?
The vulnerability part is not systematically organized; it is all clumsy in the web UI, and it is not user-friendly.
Regarding improvements, the vulnerability part, recent changes with user management, and Fortinet IM coming into place, which is not helpful at all because it cuts out the automation part, are the most important things.
Lacework FortiCNAPP should have a new clean UI and ease of access for the users as that should be the main concern.
There are limitations regarding the scalability of Lacework FortiCNAPP.
There are also more limitations with integrations like GitHub or any other pipeline, CI/CD, or ISD.
It is glitchy and works well only sometimes, and most of the time, the reports or other things are not properly calculated or circulated with the teams.
For how long have I used the solution?
I have been using Lacework FortiCNAPP for about two years.
What do I think about the stability of the solution?
The threat response time is good; we haven't faced any major threats as of now.
What do I think about the scalability of the solution?
There are limitations regarding the scalability of Lacework FortiCNAPP.
How are customer service and support?
Technical support from Fortinet is good; I get feedback and responses quickly.
How was the initial setup?
The installation of Lacework FortiCNAPP is quite complicated, especially regarding the settings.
We face some issues with troubleshooting the settings.
Which other solutions did I evaluate?
I see some big differences between Lacework FortiCNAPP and Microsoft.
The ease of access is better with Lacework FortiCNAPP, while Microsoft is more complex.
What other advice do I have?
I'm not aware of the pricing because I've seen it with my lead.
If I do these integrations, I see some impact on the DevSecOps workflow.
The integrations, like with GitHub, help with alerts directly over there.
The positive impacts I see from Lacework FortiCNAPP are majorly regarding security itself, but it has a long way to improve; there are many things to improve, and I have had many connects with the team to provide my feedback and requirements.
The review rating for Lacework FortiCNAPP is 6.