Ncerio measures FortiGate policy gaps across a four-client estate
Recent network intrusion highlights configuration risks; our latest audit quantifies exposure on the same vendor.
10 August 2026
Security Affairs reported that attackers in Poland moved from IT to OT through a Fortinet device and a private APN. The breach reached PLCs and disrupted operational systems.
We measured open configurations across 4 clients managing 7 FortiGate targets with Ncerio. The estate contained 295 high-severity, 47 medium-severity, and 38 low-severity findings. We recorded 136 findings for FG-POL-002, 67 for FG-POL-001, and 53 for FG-POL-004 across 7 targets.
This data does not indicate exposure to the reported vector. Both cases relate to FortiGate configuration exposure.
Review and remediate open permit policies before external access is provisioned.