
Firewall and endpoint: a stack that reports into one place
Buying a good firewall and a good endpoint product from two suppliers who do not talk to each other gives you two dashboards and no overview. The stack matters more than any single product in it.
For a mid-market organisation with several sites, Fortinet is usually the pragmatic choice: one console over all locations, firewalling, secure switching and VPN in one licence model. Palo Alto Networks makes sense in larger or more heavily regulated estates where inspection depth and policy granularity justify the cost and the operating effort.
Endpoint is a separate decision. Trend Micro and Bitdefender both cover servers and workstations well; what matters more is that alerts land somewhere a human reads them.
Add Okta for identity and single sign-on, and Cloudflare in front of anything public. Under NIS2, being able to show what you did and when matters as much as the controls themselves.
Four layers, four decisions
Security is not a product you buy, it is four decisions that have to fit together.
- Network edge. What comes in and goes out per site, and how sites reach each other.
- Endpoint. What runs on laptops and servers, and what happens when something suspicious does.
- Identity. Who gets to be who, with what second factor, and how quickly access disappears when somebody leaves.
- Public exposure. What of yours is reachable from the internet, and what sits in front of it.
The most common failure we see is three excellent products and no single place where an alert from one is visible next to an alert from another.
Fortinet or Palo Alto
| Fortinet | Palo Alto Networks | |
|---|---|---|
| Typical fit | Multi-site mid-market, retail chains, distribution | Larger estates, regulated sectors, complex segmentation |
| Strength | One console across firewalling, switching and VPN; predictable licensing | Depth of inspection and policy granularity |
| Cost of ownership | Lower, and manageable by a generalist team | Higher, and rewards a dedicated security function |
| Watch out for | Feature licences that get bought and never enabled | Buying capability the team has no time to operate |
Where the network is already Cisco end to end, Cisco firewalling is worth keeping in the comparison, purely for the single management plane.
Endpoint: the product matters less than the response
Trend Micro and Bitdefender both do the job on servers and workstations, and Microsoft Defender covers a great deal for organisations already licensed for it. Detection quality between serious products is close enough that it is rarely the deciding factor.
What decides the outcome is what happens at half past two in the morning when something is flagged. A tool that isolates a machine automatically and raises a ticket that a person picks up is worth more than a better detection engine with nobody watching it. That is why endpoint and managed IT belong in the same conversation.
Identity is the control that pays back fastest
Most incidents we are called into start with a credential, not an exploit. Single sign-on with a second factor, applied to everything rather than to the three applications that were easy, removes a large share of that exposure.
Okta handles identity and single sign-on across applications; Microsoft Entra covers it where the estate is already Microsoft-centric. The important part is not which one, it is that leaving the organisation removes access everywhere within the hour, and that this is provable.
What sits in front of your public services
Anything reachable from the internet, from a customer portal to a remote access gateway, benefits from something in front of it. Cloudflare handles DNS, DDoS protection and access control at that layer, and it is inexpensive relative to the alternative of a service being taken offline during a busy week.
What NIS2 actually expects
For organisations in scope, NIS2 shifts the question from whether you have security measures to whether you can show them. Risk analysis, incident handling, business continuity, supply chain security, and reporting an incident within tight deadlines. Management is accountable, which means the evidence has to be readable by people who are not engineers.
In practice that means three things we build in from the start: written policies that match what actually happens, logging retained long enough to reconstruct an incident, and a monthly report that a board can read. How we assemble that is described under cybersecurity, and the reporting rhythm under service governance.
Our own processes are externally audited to ISO 9001, ISO/IEC 27001 and ISO 14001, with Kiwa NEN 4400-1 covering our staffing work. That does not make you compliant, but it does mean your auditor gets a straight answer about your supplier.
The order we would do it in
If you are starting from a mixed estate and a limited budget, this is the sequence that removes the most risk per euro: multi-factor authentication everywhere, then an immutable backup you have tested, then endpoint with someone responding to it, then the firewall refresh, then segmentation.
Firewalls are usually where organisations want to start because it is a visible purchase. It is rarely where the exposure is.
Questions we get about this
What boards and IT leads ask us about security spending.
Fortinet or Palo Alto for a mid-market company?
For most mid-market organisations with several sites, Fortinet. One console across firewalling, switching and VPN, predictable licensing and a generalist team can run it. Palo Alto earns its place where segmentation is complex or the sector is heavily regulated, and where there is a dedicated security function to operate it.
Does NIS2 apply to us?
It depends on your sector and size. Essential and important entities in sectors such as energy, transport, health, digital infrastructure, manufacturing, food and waste are in scope, and so are many of their suppliers by contract even when not directly in scope. If a customer has started sending you security questionnaires, that is usually the first signal.
Do we need a SOC?
Not necessarily a dedicated one. What you need is somebody who sees the alert and acts on it within an agreed time. For a lot of mid-market organisations that is a managed service with defined response times rather than a security operations centre of their own.
Can you work with the security products we already have?
Yes. We take over and manage existing Fortinet, Palo Alto, Trend Micro, Bitdefender and Microsoft Defender estates. Replacing a working product is rarely the first thing we recommend; getting the alerts to a place where someone reads them usually is.
Where this lands in our work
Where security work lands.
Want this looked at for your own sites?
Half an hour on a call is usually enough to tell you whether we are the right party for it, and we will say so if we are not.