94% of Security Teams Start Threat Investigations with DNS but Under Use the Investment through the Hunt Cycle

203 senior security and risk professionals reveal a missed opportunity to leverage DNS throughout the threat analysis and response cycle

As cyberattacks escalate, Infoblox Inc., the leader in Secure Cloud-Managed Network Services, and Forrester Consulting investigated how security and risk (S&R) teams are using their DNS investments. The 203 respondents to the Accelerate Threat Resolution with DNS study reveal they most often use DNS to detect and block threats early in the kill chain, identify compromised devices, and investigate and respond to malware.

The top findings, as detailed in this infographic, underscore DNS is an effective but under-utilized tool for threat hunting and resolution even as alert fatigue challenges security teams to scale:

  • 94% of S&R leaders either use or consider DNS as a starting point for threat investigations but only 43% of security and risk leaders rely on DNS as a data source to complete their investigations.
  • 66% of respondents use DNS to catch threats — from DNS tunneling/data exfiltration, domain generation algorithms (DGAs), and lookalike domain attacks — that other security tools miss but only 34% anticipate using internal DNS to stop malicious attacks at scale.
  • 52% of leaders cite alert fatigue among teams and 51% report challenges dealing with threat triage; but only 58% of teams incorporate some automated processes for incident response.

“It’s good to see the vast majority of security and risk teams recognize DNS as a powerful threat hunting tool,” said Anthony James, Vice President of Product Marketing at Infoblox. “At the same time, most companies are leaving money on the table by under-using their DNS investments. With 56% of leaders looking to improve security ROI, DNS can help save the day by providing a single pane of visibility into threats across the network and the edges.”

“DNS can also help automate some of the more repetitive tasks in threat hunting, freeing up security teams who spend an average of 4 hours per incident investigation to address more complex problems,” continued James. “DNS is one of the most cost-effective ways that companies can fortify their security and risk frameworks and maximize their existing security investments.”

Register for the EMEA webinar taking place August 19 to hear Anthony James from Infoblox and guest speaker David Holmes, Senior Analyst from Forrester, discuss the study’s findings.

Forrester surveyed 203 security and risk leaders from companies that earned more than $1 billion in annual revenue in the financial services, health care, education, retail, and government sectors for this report. Respondents include all levels of decision-making, including C-level (48%), VP (11%), Director (34%), and Manager (7%) roles across companies.

Fortinet Unveils Cloud-to-Cloud SD-WAN Solution to Simplify and Enhance Multi-Cloud Applications

News Summary

Fortinet® (NASDAQ: FTNT), a global leader in broad, integrated and automated cybersecurity solutions, today announced Fortinet Secure SD-WAN for Multi-Cloud, a networking and security solution that solves common application performance, visibility, cost, and control challenges associated with multi-cloud deployments by enabling SD-WAN across multiple clouds and regions.

Most enterprises today – 93% by recent estimates – have a multi-cloud strategy in place and work with multiple cloud providers to meet a number of business needs, including disaster recovery, data backup, application resiliency, and global coverage. However, managing and securing an assortment of different private and public cloud workloads and environments remains a challenge, with many organizations choosing to connect their clouds via their on-premises data center WAN edge. The use of this type of traditional WAN infrastructure approach, though secure, inhibits multi-cloud capabilities and results in deployment complexity, inconsistent network performance, and expensive connectivity.

John Maddison, EVP of products and CMO at Fortinet

“For enterprises deploying applications and workloads across multiple clouds, the need to seamlessly manage connectivity and maintain security across the diverse infrastructure is higher than ever. Fortinet Secure SD-WAN solutions provide connectivity and security across diverse cloud infrastructures while optimizing application user experience. Fortinet enables enterprises to realize the true potential of SD-WAN by enabling it to be implemented anywhere. From home, campus to cloud, data center to cloud, and now cloud to cloud, Fortinet delivers the industry’s most scalable, cost effective and secure SD-WAN solution on the market.”

Fortinet Secure SD-WAN for Multi-Cloud is a new approach to establishing secure and high-performance connectivity between public cloud workloads running on multiple clouds without increasing cost and complexity. Available in all major cloud providers, Fortinet Secure SD-WAN for Multi-cloud enables a consistent network architecture leveraging SD-WAN capabilities between clouds and empowers application developers and enterprise IT to build a high speed and seamless cloud-to-cloud network and security architecture. Fortinet Secure SD-WAN for Multi-Cloud uniquely offers a secure and effective infrastructure for maximizing the benefits of enterprise multi-cloud deployments by:

  • Automating the deployment of a consistent overlay network across different cloud networks, reducing complexity and increasing agility to save teams time and resources.
  • Offers end-to-end visibility, control, and centralized management that unifies functionality across multiple cloud environments through cloud native integrations.
  • Securely transports application traffic between clouds without needing to backhaul through the data center, enabling better scaling of deployments and reducing latency.
  • Intelligently selects connections based on application characteristics employing dynamic path selection, improving performance and optimizing cost by selecting the best internet or leased line link.
  • Provides an application developer-friendly API to enable programmers the ability to consistently represent their network and security requirements.

Fortinet Performance Advantage On-Premises and in the Cloud

Fortinet delivers Secure SD-WAN as an integrated feature of its industry-leading FortiGate Next-generation Firewall, powered by the industry’s first SD-WAN ASIC to enable better application experience, higher performance, and better cost efficiency – with Security Compute Ratings up to 17 times better than competitor solutions. Fortinet Secure SD-WAN for Multi-Cloud, delivered via FortiGate-VM, a virtual appliance, is powered by Fortinet’s patented vSPU technology and maintains a performance advantage in the cloud, including over 20Gbps of IPsec performance – 10 times the industry average – for fast encrypted connections over internet and leased line links to reduce operational costs. By leveraging the broad FortiGate-VM footprint across all major cloud platforms, as well as market leading FortiGate appliances on-premises, enterprise organizations can benefit from cloud-agnostic consistent multi-cloud networks without compromising on security and performance.

Fortinet Secure SD-WAN for Multi-Cloud, which securely connects applications and workloads across multiple clouds, complements Fortinet’s existing Secure SD-WAN Cloud On-Ramp capabilities to securely connect users and offices to applications and cloud workloads. 

SD-WAN for the Entire End-to-End Enterprise

Fortinet delivers a Secure SD-WAN product portfolio designed for the entire end-to-end enterprise with physical appliances for large data centers, branch offices, remote sites, and home offices, as well as virtual appliances for multi-cloud deployments. Fortinet Secure SD-WAN’s ability to scale from home office to branch to cloud all tied to a single operating system via the Fortinet Security Fabric ensures networking and security policies seamlessly work across multiple environments and cloud platforms, enabled by the latest threat intelligence from FortiGuard Labs.