Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Fortigate: OT Application Control and Virtual Patching

Fortinet
10/09/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Depending on the framework you choose, Purdue, NIST, CSF, 62443, NIS2, or something else, you will need to implement device and application controls at various points within that framework. I'm Matt Bullock, Technical Marketing Engineer at Fortinet. Today we'll use our simulated OT environment to look at providing application controls and virtual patching using the OT Security Service on FortiGate firewalls in a Cyber Physical System, or CPS. We'll be simulating a large number of devices from various vendors and generations, some of which contain vulnerabilities for us to discover and mitigate. We started simulating more devices here, so if we refresh the asset identity list, we'll see quite a few more assets pop up. Let's take a look at the OT view now. Here we can see those same devices arranged in the Purdue model. Based already on what we know about the type of device and the interfaces that we're seeing those devices on. This is a pretty good guess by the CPS, but you can always rearrange devices if this doesn't exactly match your environment. We know that we have vulnerable devices in our environment, but we can't always patch those devices right away, especially in a production system. So let's enable virtual patching so that the CPS can provide a patch to block traffic to a vulnerable system that would match a known exploit. By default, we have a single virtual patching rule that patches any discovered vulnerabilities of any security level. We can configure this rule to only patch specific vulnerability levels, or to allow vulnerabilities so that they're logged and we can manually take action. Let's head back over to our firewall policies and look at the policies between our monitoring and operations networks. We'll turn on the same application control default profile and SSL certificate inspection we used earlier. As we discover more and more devices, we'll be discovering more vulnerabilities. Because we care about protecting those vulnerable assets from outside of the ICS environment, we'll be applying the virtual patch profile between HQ or the IT environment, and our various protected networks starting with the control network. This is where we activate the default virtual patching profile. All right, we've had some time to learn more details about the devices in the environment. So let's go back to the Asset Identity Center to find some vulnerable devices. It looks like we have several vulnerable devices now. Some aren't so bad with a single low severity vulnerability, while others have a whole stack of high priority vulnerabilities. We're getting all of this information from the detection tools the CPS has at its disposal with continuous updates from FortiGuard labs on the latest vulnerabilities discovered in the wild. There are enough vulnerabilities in our environment that we should start to see some virtual patches being applied. Let's look at our security events logs and filter them for virtual patching messages. Here it looks like we have a patch applied already against the Advantech device we just saw. Here we're dropping only the traffic that matches the attack profile. This could be a specific URL, a data pattern, a port number, or anything else that is identified in this CVE. FortiGuard also maintains our database of OT threats, protocols, and device definitions, as well as virtual patching signatures. We currently have over 1,300 virtual patching signatures for known OT vulnerabilities. You can view the currently installed list of signatures directly from the FortiGate, and we can search for a specific vendor, OS type, name, or well-known CVE. Similarly, our application signatures are continuously updated by FortiGuard. We currently have around 9,000 application signatures that a FortiGate can detect and take action on. Over 3,000 of those signatures are specific to OT environments. Looking at something as universal as SIP, you can see that we can get very granular in our definitions and can differentiate between different types of SIP commands or messages. Let's create a new application rule using some of these signatures. Our new application sensor monitors most application signatures by default, but doesn't take any action on them. Let's create an override for an application that we do care about. We're going to get very specific with a Modbus read command. When we select this application, there's more that we can configure. In this case, we're not just taking action on Modbus, or even Modbus read messages. We're getting more granular in controlling specific Modbus unit and address values in a Modbus read message. We'll give this some ranges that make sense in our environment, and we'll also give it some ranges that make sense in our environment. Now that we have our application rule, we can apply that rule to any of our firewall policies to control this traffic in our environment. The OT Security Service with continuous vigilance from FortiGuard Labs adds impressive levels of visibility and control to industrial control systems. This platform approach can be applied to any of our firewall policies. Let's take a look at some of the features of FortiGuard Labs. Let's take a look at some of the features of FortiGuard Labs. This platform approach gives you a consistent level of capability and management across both IT and OT environments, delivering robust security that is consistent, easy to implement, and continuously evolving along with the threat landscape in your environment. Thanks for watching.

TL;DR

  • Virtual patching provides immediate protection for vulnerable OT devices that cannot be patched during production operations, blocking traffic matching known exploit patterns without requiring device updates.
  • FortiGuard Labs maintains over 1,300 virtual patching signatures for OT vulnerabilities and 3,000+ OT-specific application signatures with continuous updates.
  • Application controls can be configured at granular levels, such as specific Modbus unit and address values within read commands, enabling precise industrial protocol management.
  • The Cyber Physical System automatically arranges discovered assets in the Purdue model and provides continuous vulnerability assessment with FortiGuard threat intelligence.

Asset Discovery and Virtual Patching for OT Environments

This demonstration walks through implementing application controls and virtual patching for operational technology environments using Fortinet's OT Security Service on FortiGate firewalls. The session begins with asset discovery in a simulated OT environment containing devices from various vendors and generations, some with known vulnerabilities. Using the Cyber Physical System (CPS), discovered assets are automatically arranged in the Purdue model based on device type and network interfaces. The virtual patching capability addresses a critical OT challenge: the inability to immediately patch vulnerable production systems. When enabled, virtual patching blocks traffic matching known exploits targeting vulnerable devices, effectively providing protection without requiring device-level updates. The demonstration shows how to configure virtual patching rules by severity level and apply them to firewall policies protecting the ICS environment from IT network traffic.

Granular Application Control with FortiGuard Signatures

The second half of the demonstration focuses on application-level controls using FortiGuard's extensive signature database. Fortinet maintains over 1,300 virtual patching signatures for known OT vulnerabilities and approximately 9,000 application signatures, with more than 3,000 specific to OT environments. The presenter demonstrates creating custom application rules with granular control, using Modbus read commands as an example. Beyond simply detecting Modbus traffic, administrators can configure rules targeting specific Modbus unit and address values within read messages, enabling precise control over industrial protocol communications. This level of granularity allows security teams to enforce policies that align with legitimate operational requirements while blocking unauthorized access patterns. The platform approach delivers consistent security management across both IT and OT environments with continuous signature updates from FortiGuard Labs.

Chapters

0:00 - Introduction and Framework Context
0:42 - Asset Discovery and OT View
1:10 - Virtual Patching Configuration
2:18 - Vulnerability Assessment
2:55 - Virtual Patching in Action
3:41 - Application Signature Database
4:06 - Creating Custom Application Rules
5:02 - Platform Benefits Summary

Key Quotes

1:10 "We know that we have vulnerable devices in our environment, but we can't always patch those devices right away, especially in a production system."
3:06 "Here we're dropping only the traffic that matches the attack profile. This could be a specific URL, a data pattern, a port number, or anything else that is identified in this CVE."
3:27 "We currently have over 1,300 virtual patching signatures for known OT vulnerabilities."
3:51 "Over 3,000 of those signatures are specific to OT environments."

FAQ

How does virtual patching protect OT devices without requiring actual patches?

Virtual patching works at the network level by blocking traffic that matches known exploit patterns for specific CVEs. When the FortiGate detects traffic targeting a vulnerability on a device, it drops only that malicious traffic while allowing legitimate communications. This provides protection for devices that cannot be immediately patched due to production requirements or vendor constraints.

How granular can application controls get for industrial protocols?

Application controls can be extremely granular. For example, with Modbus traffic, you can create rules that don't just detect Modbus or even Modbus read messages, but target specific Modbus unit and address values within those messages. This allows security policies that align precisely with legitimate operational requirements while blocking unauthorized access patterns.


Categories:
  • » Webinar Library » Fortinet
  • » Cybersecurity » Network Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • OT
  • IoT Security
  • Vulnerability Management
  • Network Security
  • Demo
  • Technical Deep Dive
  • OT Security
  • Virtual Patching
  • Application Control
  • Industrial Control Systems
  • Modbus Protocol
  • Purdue Model
  • FortiGuard Threat Intelligence
  • Network Segmentation
  • ICS Protection
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Fortigate: OT Application Control and Virtual Patching

              XStreaminars (watch here)

              • Oct
                28

                EnvZero: Near-Zero Time to Resolution--Live Agentic Remediation for Failed and Drifted Infrastructure

                10/28/202601:00 PM ET
                More events

                Industry Events (Sponsor Hosted)

                • Oct
                  13

                  Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance

                  10/13/202601:00 PM ET
                  • Oct
                    15

                    Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                    10/15/202611:00 AM ET
                    • Oct
                      20

                      Harnessing Data Governance for AI with Cyera and Snowflake

                      10/20/202611:00 AM ET
                      • Oct
                        27

                        Maximize Security, Value, and Returns on Your Microsoft Investment

                        10/27/202611:00 AM ET
                        • Oct
                          27

                          The HUMAN Experience: Real-Time Insights into Page Intelligence

                          10/27/202601:00 PM ET
                          More events

                          Upcoming Webinar Calendar

                          • 10/13/2026
                            01:00 PM
                            10/13/2026
                            Transitioning from CJIS to FERPA: Essential Audit Evidence for Compliance
                            https://www.truthinit.com/index.php/channel/2159/transitioning-from-cjis-to-ferpa-essential-audit-evidence-for-compliance/
                          • 10/15/2026
                            11:00 AM
                            10/15/2026
                            Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                            https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                          • 10/20/2026
                            11:00 AM
                            10/20/2026
                            Harnessing Data Governance for AI with Cyera and Snowflake
                            https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                          • 10/27/2026
                            11:00 AM
                            10/27/2026
                            Maximize Security, Value, and Returns on Your Microsoft Investment
                            https://www.truthinit.com/index.php/channel/2178/maximize-security-value-and-returns-on-your-microsoft-investment/
                          • 10/27/2026
                            01:00 PM
                            10/27/2026
                            The HUMAN Experience: Real-Time Insights into Page Intelligence
                            https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                          • 10/28/2026
                            01:00 AM
                            10/28/2026
                            [APAC:] Secure AI Everywhere: Visibility, governance and protection for the agentic era
                            https://www.truthinit.com/index.php/channel/2125/apac-ensuring-comprehensive-security-for-ai-applications/
                          • 10/28/2026
                            06:00 AM
                            10/28/2026
                            [EMEA:] Secure AI Everywhere: Visibility, governance and protection for the agentic era
                            https://www.truthinit.com/index.php/channel/2127/emea-ensuring-ai-security-across-all-platforms/
                          • 10/28/2026
                            01:00 PM
                            10/28/2026
                            [AMERICAS:] Secure AI Everywhere: Visibility, governance and protection for the agentic era
                            https://www.truthinit.com/index.php/channel/2126/securing-ai-across-the-americas-strategies-and-insights/
                          • 10/28/2026
                            01:00 PM
                            10/28/2026
                            EnvZero: Near-Zero Time to Resolution--Live Agentic Remediation for Failed and Drifted Infrastructure
                            https://www.truthinit.com/index.php/channel/2179/envzero-near-zero-time-to-resolution-live-agentic-remediation-for-failed-and-drifted-infrastructure/
                          • 11/04/2026
                            11:00 AM
                            11/04/2026
                            Leveraging CISA’s Zero Trust Maturity Model in an AI-Driven Landscape
                            https://www.truthinit.com/index.php/channel/2149/leveraging-cisas-zero-trust-maturity-model-in-an-ai-driven-landscape/
                          • 11/04/2026
                            11:00 AM
                            11/04/2026
                            Aligning Agentic Intent: Understanding Your Agents' Purpose vs. Their Actions
                            https://www.truthinit.com/index.php/channel/2158/aligning-agentic-intent-understanding-your-agents-purpose-vs-their-actions/
                          • 11/05/2026
                            02:00 PM
                            11/05/2026
                            HUMAN Dialogue: Embracing the Rise of the Agentic Consumer in AI
                            https://www.truthinit.com/index.php/channel/2160/human-dialogue-embracing-the-rise-of-the-agentic-consumer-in-ai/
                          • 11/05/2026
                            02:00 PM
                            11/05/2026
                            Reclaim Your Evenings: Leverage Data Intelligence to Minimize Risk and Boost AI Adoption
                            https://www.truthinit.com/index.php/channel/2172/reclaim-your-evenings-leverage-data-intelligence-to-minimize-risk-and-boost-ai-adoption/
                          • 11/19/2026
                            01:00 PM
                            11/19/2026
                            360View: Govern, Secure & Recover Your Microsoft 365 Environment
                            https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                          Truth in IT
                          • Sponsor
                          • About Us
                          • Terms of Service
                          • Privacy Policy
                          • Contact Us
                          • Preference Management
                          Desktop version
                          Standard version