Blog
FortiBleed: What I’m Telling Every Client With an Internet-Facing FortiGate This Week
Every few years, a vulnerability comes along that rewrites the conversation. This week, it is FortiBleed — CVE-2024-23113. A critical-severity, unauthenticated, pre-auth remote code execution in the FGFM (FortiGate-to-FortiManager) protocol.…
Read More →Securing Hospitals — What DICOM and HL7 Taught Me About Unpatchable Devices
There are devices in every hospital that cannot be patched, cannot be scanned, and cannot be replaced. And they’re on the same network as your patient data. I started working…
Read More →99.99% Uptime SD-WAN — The Architecture I Actually Deploy
Every vendor promises 99.99% uptime. Very few deliver it in an actual Indian network environment. I’ve designed, deployed, and managed SD-WAN architectures across this country — from multi-site manufacturing plants…
Read More →Ransomware in Under an Hour — What I’ve Learned About the First 60 Minutes
The first sixty minutes of a ransomware incident define everything that follows. I’ve responded to ransomware incidents across manufacturing, BFSI, healthcare, and government. I’ve watched teams make decisions in the…
Read More →Wi-Fi 6E Is a Security Upgrade, Not a Speed One
Everyone is talking about Wi-Fi 6E as a speed upgrade. They are missing the point. Yes, the 6 GHz band gives you more spectrum, lower latency, and higher throughput. But…
Read More →Zero-Trust Without the Buzzword — Explaining It to a CFO
A few months ago, I sat across from the CFO of a mid-size manufacturing company. He had asked for a meeting about their “network security upgrade.” Fifteen minutes in, he…
Read More →When I Tell Clients NOT to Buy Fortinet
This might surprise you coming from a Fortinet MSSP partner who sells and manages FortiGates every single day. But I have told clients not to buy Fortinet. More than once.…
Read More →From 12 Screens to One Pane of Glass — The Day I Stopped Tool-Juggling
A few years ago, I walked into a SOC that had been designed by committee. Each team had chosen their own tools. The network team used one NMS. The security…
Read More →A Firewall You Don’t Watch Is Just a Speed Bump — The NMS Manifesto
I will say it plainly: the best firewall in the world, configured perfectly, with the latest firmware and the tightest rules, is exactly as effective as a speed bump if…
Read More →5,732 Firewalls in One Year — The Misconfigurations I See on Almost Every Box
Last year, our team audited 5,732 firewalls. FortiGates, Palo Altos, Sophos, Cisco ASAs. Enterprise data centres, bank branches, hospital campuses, manufacturing plants. The smallest was a single FG-40F in a…
Read More →