As AWS environments expand into hybrid cloud, containerized applications and generative AI, Fortinet is positioning network, application and AI security as interconnected disciplines. Its approach combines cloud security, code-to-cloud protection and controls for LLMs and AI agents.
The expansion of AWS environments is changing the security challenge for enterprises. Organizations are not only operating more workloads across multiple accounts and regions, but are also connecting cloud infrastructure with on-premises systems and introducing AI applications, large language models and agentic workloads. Fortinet argues that this development is making fragmented security architectures harder to manage and is pushing organizations toward more centralized visibility and consistent policies.
Cloud security becomes more complex
Cloud security has become more complicated as enterprise infrastructures have moved beyond relatively stable network boundaries. According to Fortinet’s 2026 Cloud Security Report, 81% of organizations surveyed rely on two or more cloud providers for critical workloads, while 66% said they lacked confidence in their ability to detect and respond to cloud threats in real time. The report also identifies a cybersecurity skills shortage: 74% of respondents reported an active shortage of cybersecurity talent.
Fortinet links these challenges to the growing number of identities, applications, workloads and access paths that security teams have to monitor. The company cites identity- and access-related incidents as a significant problem and says that human error, particularly misconfiguration, remains a major contributing factor. Fragmented visibility and alert fatigue can add to the workload for already stretched security teams.
The company’s proposed response is to bring network, application and AI security together. Fortinet describes this as a unified security model for AWS and hybrid environments, with consistent policies and centralized visibility. Its Security Fabric integrates with AWS services including AWS Security Hub, Amazon GuardDuty, AWS Transit Gateway, AWS Gateway Load Balancer and Amazon CloudFront.
From the Landing Zone to the network edge
One element of the approach focuses on network security. Fortinet says its FortiGate VM Cloud Firewall can be deployed within AWS environments to provide firewall functions alongside secure connectivity, software-defined WAN, Zero Trust Network Access and network segmentation. The company also describes integrations with AWS Firewall Manager, AWS Cloud WAN, AWS Direct Connect and AWS Transit Gateway.
For organizations using an AWS Landing Zone, the objective is to apply network security controls across a multi-account environment and to maintain consistent policies as applications and workloads move between AWS regions and on-premises infrastructure. Fortinet’s management options include FortiManager for centralized security management and FortiAnalyzer for log management, analytics and incident response.
A customer example illustrates the intended use case. Fortinet says Best Buy implemented FortiGate VM Cloud Firewall together with SD-WAN and AWS Transit Gateway Connect to simplify connectivity between stores and AWS. According to the company, the deployment reduced latency between stores and AWS by 20% and improved uptime and operational efficiency. These figures are reported by Fortinet and relate to the specific customer environment.
Security moves into the development process
The second area is application and workload protection. Fortinet’s FortiCNAPP combines cloud security posture management, Kubernetes security posture management, cloud infrastructure entitlement management and workload protection. The platform is intended to identify configuration and security risks throughout the application lifecycle, from infrastructure-as-code and CI/CD processes to running workloads.
The emphasis is on moving security controls earlier into development. Infrastructure-as-code scanning can identify issues before deployment, while cloud security posture management monitors configurations against security and compliance requirements. Fortinet also describes data security posture management capabilities for Amazon S3, including the detection of potentially exposed sensitive data and malware files.
Fortinet cites LendingTree as an example of this approach. The financial services marketplace reportedly faced up to 200 alerts per day and required around ten hours of daily SOC triage in its multi-cloud environment. After deploying FortiCNAPP, Fortinet reports a 90% reduction in alert volume and a reduction in alert investigation time to five minutes per alert. The company also reports annual savings of $200,000.
The platform is designed to complement, rather than replace, existing AWS security services. Fortinet says FortiCNAPP integrates with AWS Security Hub, Amazon GuardDuty and Amazon Inspector. It also connects with FortiGate VM to provide a network-aware view of exposure to cloud workloads.
A new security layer for AI applications
The growing use of generative AI introduces another security layer. Fortinet identifies prompt injection, jailbreaking, model poisoning and data exfiltration among the risks associated with large language models and AI applications.
Its FortiAIGate technology is positioned between applications and LLMs. According to Fortinet, it can inspect model interactions, apply security guardrails and monitor data moving into and out of AI services. The company says the system can detect and block prompt injection and jailbreaking attempts, while context-aware data loss prevention is intended to identify sensitive information being transferred through AI traffic.
The architecture also addresses operational questions around AI use. Fortinet describes centralized monitoring of model costs, auditing and access control, allowing organizations to track which models are being used, by whom and with what data. Traffic routing, caching and workload optimization are intended to reduce unnecessary model calls and control consumption.
This reflects a shift in the security perimeter. Traditional network controls remain relevant, but organizations increasingly have to secure software development processes, APIs, cloud workloads and interactions with AI models at the same time. Fortinet’s proposition is to manage those areas through a common security architecture rather than a collection of isolated controls.
Consulting and incident response
Fortinet also includes professional services in its AWS security model. Its Cloud Consulting Services cover security assessments, AWS migrations, architecture recommendations and automation using tools such as AWS CloudFormation and HashiCorp Terraform. The company also describes an AWS Incident Response practice intended to support containment, investigation and recovery when security incidents occur.
A further customer example comes from Public Consulting Group. Fortinet says the company worked with AWS and Fortinet to replace a transit VPC architecture connecting about 50 VPCs through VPN tunnels with an architecture based on AWS Transit Gateway and FortiGate VMs. According to Fortinet, failover time was reduced from minutes to seconds and application downtime was minimized.
Fortinet ultimately presents AWS security as a combination of infrastructure, application and AI controls rather than a single technology layer. Its solutions are available through AWS Marketplace, with different licensing models. The underlying issue, however, extends beyond individual products: as cloud environments become more distributed and AI workloads become part of enterprise applications, security policies, visibility and response processes have to span more components than traditional network security alone.

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de