FortiMail Secure Email Gateway Advanced Threat Defense Against Business Email Compromise, Spearphishing and Other Attacks May 2018
Email Remains the #1 Attack Vector 49% of malware was installed via email attachment 1 $675m estimated cost of business email compromise, from 15,670 incidents in 2017 15,071 Unique malware variants in 1Q18, an average of 170 every day of the quarter Notes/Sources: Verizon 2018 Data Breach Report. April 2018. Fortinet Threat Intelligence Newsletters, 2018. FBI. IC3. 2017 Internet Crime Report. May 2018. Gartner Market Guide for Secure Email Gateways, 2017. Advanced threats easily bypass the signature-based prevention mechanisms an SEG has traditionally used.
Most Incumbent Email Security Lags the Threat Landscape Most multiproduct vendors in this market, distracted by other products in a broader portfolio, had allowed development of their SEGs to wane. As the threat landscape shifted, they were caught flatfooted and scrambled to iterate their products. Supplement gaps (if replacement is not an option) in the advanced threat defense capabilities of an incumbent SEG by adding a specialized product that is tailored for this purpose.
Top-rated Email Security That Feeds Your Broader Security Fabric FortiMail Secure Email Gateway Top-rated in independent testing (and customer deployments) to stop spam, ransomware, malware and advanced email threats
Top-rated Email Security That Feeds Your Broader Security Fabric FortiMail Secure Email Gateway Top-rated in independent testing (and customer deployments) to stop spam, ransomware, malware and advanced email threats Security Fabric Integrated to uncover the full attack lifecycle starting with an email and share IoCs across your entire security infrastructure
Top-rated Email Security That Feeds Your Security Fabric FortiMail Secure Email Gateway Top-rated in independent testing (and customer deployments) to stop spam, ransomware, malware and advanced email threats Security Fabric Integrated to uncover the full attack lifecycle starting with an email and share IoCs across your entire security infrastructure Comprehensive, including home grown data protection, robust MTA and intuitive end user as well as administrator controls to minimize effort Reduce the risk and impact of security incidents entering via email, as well as across the entire attack surface.
Deploys as Primary or Supplemental Filtering On-premise FortiGuard Antispam Adult Image Analysis Antimalware Virus Outbreak Optional Sandboxing Mail Server FortiMail FortiSandbox IoC Distribution IPs File Hashes
Project Global 500 insurance provider $20bn in revenue, ~8,000 employees Initially working on a network redesign ( NGFW+Sandbox ) Experienced ransomware incident during end of year IT Freeze Key Requirements Stop ransomware seeking entry via email Why Fortinet over FireEye Responsiveness: within 48 hours of the incident FML/FSA VM was deployed in the data center Effectiveness: high detection rate stopped new ransomware Extensibility: although deployed for email, a clear path to integrate next gen network security What they Deployed 2 x FortiMail VM02 1 x FortiSandbox 3000D A Common Use Case is Stopping Ransomware
But We Also Deploy in the Cloud Mail Server Cloud SEG & Sandboxing Gartner client interactions indicate that 95% of new and transitioning buyers are choosing cloud-based delivery. FortiGuard Antispam Adult Image Analysis Antimalware Virus Outbreak Optional Sandboxing IoC Distribution IPs File Hashes
Project Children’s Hospital System ~2500 employees, including 750 doctors Students Added security for MS Office 365 and Exchange Online Key Requirements High effectiveness Ease of use SaaS form factor Why Fortinet over Microsoft 15% more spam caught Almost 100 known viruses caught Ramsomware targeting execs caught What they Deployed FortiMail Gateway Premium Often Strengthening the Security for Microsoft Office 365
Editable Hardware Appliances 7 models Filter 2.7k to 1.5m Messages Per Hour Support for 10GE Scalable Form Factors for Organizations of All Sizes SaaS Gateway or Server Mode Standard or Premium Per User Per Year Virtual Appliances 7 VM models CPU- and Domain- based Perpetual licensing
A Complete Set of Security Services Antispam Service Sender IP ratings Embedded URL ratings Content-based hashes for spam and phishing campaigns Separate “newsletter” identifiers Antivirus Service One-to-many signatures Heuristic rules Emulation Decrypting/ Unpacking Patented content pattern recognition language (CPRL) Outbreak Prevention Pre-signature intelligence Covers emerging spam and malware campaigns Leverages new sandbox and other intelligence Impersonation Analysis Identifies spoofed email Dynamically builds protections for common email addresses Complements sender authentication FortiSandbox Cloud FortiSandbox hosted by Fortinet Includes prefiltering , emulation and full instrumented analysis Subscription-based No separate sandbox required Content Disarm and Reconstruction Removes high risk active content Supports Microsoft Office and Adobe Can be applied by user, group or policy Original documents can be retained and restored Click Protect Dynamic reputation query Determines rating at the time of user click Identifies recently compromised sites changed shortly after campaigns are launched Base Bundle Enterprise ATP Bundle
Email Represents The #1 Attack Vector 49% of installed malware in 2017 15,690 BEC incidents for $675m in 2017 Advanced attacks beat traditional SEG defenses Replace / Supplement Your Incumbent SEG, as Gartner Recommends Top-rated protection from spam, malware and advanced threats Security Fabric Integrated for proactive IoC distribution Comprehensive SEG capabilities Already protecting G2000 and every day organizations Available in all form factors for all use cases FortiMail Recap Top-rated Email Security that Feeds your Security Fabric for Proactive Protection
For Attachment-based Advanced Threats For URL-based Advanced Threats For Imposter-based Advanced Threats Network Sandbox Content Disarm & Reconstruction URL address rewriting Time of click analysis DMARC Display Name Spoof Detection Cousin Domain Name Detection Anomaly Detection RM All the Advanced Threat Defense Capability You Need FortiMail Secure Email Gateway
Leveraging your SEG for more Proactive Security FortiMail Secure Email Gateway Forti Gate Forti Mail HTTP Traffic Mail Server Forti Sandbox Files for Inspection Fabric Ready Endpoint Partners FortiSandbox Identify previously unknown threats Return file and URL ratings to FortiMail FortiGate , FortiClient , Fabric-Ready Partners Receive IoCs related to attacks starting with email Increase overall security posture FortiAnalyzer Aggregate and correlate security logs from email, network, endpoint and more Provide a single, enterprise-wide view of the security posture Ratings Returned IoCs to Block Forti Client Forti Analyzer IoCs to Block
Project Global 500 insurance provider $20bn in revenue, ~8,000 employees Initially working on a network redesign ( NGFW+Sandbox ) Experienced ransomware incident during end of year IT Freeze Key Requirements Stop ransomware seeking entry via email Why Fortinet over FireEye Responsiveness: within 48 hours of the incident FML/FSA VM was deployed in the data center Effectiveness: high detection rate stopped new ransomware Extensibility: although deployed for email, a clear path to integrate next gen network security What they Deployed 2 x FortiMail VM02 1 x FortiSandbox 3000D And Customer Proven
Project Global 500 commodities producer/trader $170bn in revenue, 100,000+ employees Often engaged in nationally sensitive business Key Requirements Deeper inspection, stronger security given sensitivity of business Why Fortinet Successful PoC - high catch rate, easy deployment Cisco IronPort-Threat Grid Cloud low catch rate, appliance didn’t work Significant Fortinet investment & strategic relationship (recent data center displacement) What they Deployed 2 x FortiMail VM04 4 x FortiSandbox 3000E 2 x FSA VM 3 Year 24 x 7 Support Trusted by a Global 500 Commodities Firm To Secure Email
Project European Bank Thousands of employees Hit by ransomware and seeing variants every couple of weeks Key Requirements Something to supplement existing SEG in BCC mode Close off ransomware delivery Why Fortinet over FireEye (and Trend Micro) Effectiveness: stopped Locky and other family variants Low administration: Started blocking email from the start without custom whitelists of Trend Micro Complete solution: Extends the firewall and simply integrates with the endpoint and even WAF What they Deployed (2) FortiMail 400E (2) FortiWeb 400E (1) FortiSandbox 1000D Stopping Ransomware for a European Banking Group
Project Global 500 financial company ~$25bn in annual revenue, ~6,000 employees Routinely targeted by email campaigns due to high profile sponsorships Experiencing ~10 compromised PCs/day Key Requirements High Effectiveness Easy Operation Why Fortinet over FireEye, (and McAfee/Trend) High Catch Rate SIEM Integration On-demand Scanning included Ability to integrate with firewall and endpoint What they Deployed (2) FortiMail 1000D (2) FortiSandbox 3000D And Proven With Global Brands
Project Regional High School 3500 Students Avoid ransomware that hit a neighboring school Key Requirements Effectiveness in stopping ransomware Ease of use for a small IT staff Affordability given limited budgets Why Fortinet over Cisco, (and later FireEye) Inability of Cisco to catch ransomware Cost of and complexity of FireEye Effectiveness, simplicity and scalability of FortiMail What they Deployed (1) FortiMail 400E (1) FortiSandbox VM As Well As Customers of All Sizes and Industries
Project Children’s Hospital System ~2500 employees, including 750 doctors Students Added security for MS Office 365 and Exchange Online Key Requirements High effectiveness Ease of use SaaS form factor Why Fortinet over Microsoft 15% more spam caught Almost 100 known viruses caught Ramsomware targeting execs caught What they Deployed FortiMail Gateway Premium And Industries