This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Vers un SOC de nouvelle génération : unifier SIEM, SOAR et EDR

Download resources

About this session

David Krzesiak, a business development engineer for SecOps at Fortinet with prior hands-on experience in European SOCs, lays out Fortinet's vision for a next-generation security operations center. He contrasts traditional SOCs, alert-centric, siloed from network operations and heavily manual, with the pressures pushing them past their limits: an exploded attack surface, more targeted attacks, fragmented multi-vendor visibility, and analyst burnout from alert volume. He introduces a three-level maturity model, log collection, cross-vendor correlation, then automation, mapped to Fortinet's SOC-CMM-based ECOPS reference architecture, and argues organizations should assess real maturity before buying tools. He walks through three products that build on each other: FortiEDR for endpoint detection that extends into XDR-style actions on non-Fortinet tools; FortiSIEM, a vendor-agnostic correlation engine merging NOC performance data with SOC security events; and FortiSOAR, which uses bidirectional connectors and playbooks to automate response, plus a conversational 'FortiAI Assist' virtual analyst. A worked example shows detection collapsing from hours of manual triage to seconds of automated isolation. He closes with a brief Q&A on FortiEDR's origins and replacing an existing SIEM.

Avec l’explosion des menaces avancées et l’augmentation des volumes de données à surveiller, les entreprises doivent évoluer vers un SOC unifié, automatisé et orienté détection-réponse. Cette présentation montre comment l’écosystème Fortinet (FortiSIEM, FortiSOAR, FortiEDR, FortiAnalyzer, etc.) permet de bâtir une architecture de cybersécurité intégrée, optimisant la visibilité, l’automatisation et la réponse aux incidents.

Key takeaways

  • Assess your actual SOC maturity (people, process, technology) with a model like SOC-CMM before buying tools; not every organization needs or is ready for full Level 3 automation.
  • Focus improvement effort on the detect-to-remediate gap, not just detection; most organizations already have decent detection but lack automated response.
  • Reserve automation for low-value, repeatable actions (isolating a host, disabling a port, opening a ticket) so analysts spend their time on real investigation and post-mortem analysis instead.
  • Break down SOC/NOC silos deliberately: correlating security events with performance signals (CPU, bandwidth, availability) catches incidents that pure security-event correlation misses.
  • When evaluating a SIEM or SOAR replacement, confirm real log-source and connector coverage (Fortinet cites 250+ log sources for FortiSIEM and about 600 connectors for FortiSOAR) rather than assuming vendor lock-in with your existing tools is required.

Speakers

David Krzesiak
David Krzesiak
Expert en solutions de sécurité – SecOps · Fortinet
David Krzesiak est Expert en solutions de sécurité – SecOps chez Fortinet et cumul plus de 10 ans d'expérience en cybersécurité, réseaux et systèmes d'information. Il a occupé divers postes d'ingénieur avant-vente et consultant sécurité chez… Read moreRead less

David Krzesiak est Expert en solutions de sécurité – SecOps chez Fortinet et cumul plus de 10 ans d'expérience en cybersécurité, réseaux et systèmes d'information. Il a occupé divers postes d'ingénieur avant-vente et consultant sécurité chez Fortinet, Orange Cyberdefense et Atos, accompagnant des clients des secteurs publics et privés dans la conception et le déploiement de solutions de cyberdéfense. Passionné, rigoureux et constamment en veille technologique, il place l’innovation, l’échange et l’esprit d’équipe au cœur de sa démarche professionnelle.

Resources

Tags

More from GoSec 2025

Also from David Krzesiak

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.