Solution for Air-gapped systems
Use Cases and Deployment Scope
The main reason we outsourced FortiDeceptor was to complement the existing Enterprise Security solution. This was because we realized the Enterprise Security and SOAR solutions only concentrate on attacks on the main assets (servers); so that in the event of an attack, lateral systems like CPUs are exposed. With FortiDeceptor, we however eliminate attacks on the lateral assets before significant damages.
Pros
- Management is simple - centralized deployment.
- Easy to deploy custom decoys for the Operational Technology.
Cons
- FortiSandbox integration has limited/basic Next Generation Firewall (NGFW) capabilities.
Likelihood to Recommend
From my experience FortiDeceptor works well alongside established SIEM systems for endpoint protection for instance secure, water-tight systems to send emails to clients and customers. It allows us to equally concentrate on the security of both external and internal OT environment. It is a smart solution to counter malware. However, its not sufficient enough to secure your networks that why we are using it with the SOAR software.