Day Three of Fortinet Accelerate 2026 spotlighted a major shift in cloud security maturity: risk now begins in code, not in production.
With real‑world validation from Microsoft Gaming’s global multicloud estate and FortiCNAPP’s role in securing one of the world’s largest gaming ecosystems, the day underscored CNAPP’s evolution from a runtime toolset to a full lifecycle risk‑intelligence platform. The message was clear, as AI accelerates development, enterprises need consistent, abstracted, federated security that prioritises impact over volume and resilience over reaction.
How CNAPP, Cloud Maturity, and AI‑Driven Risk Are Redefining Enterprise Security
Day three explored how cloud‑scale organisations are adapting to the rapid convergence of cloud security, AI‑powered development, and the expanding scope of code‑driven risk. Powered by deep insights from Microsoft Gaming and customer‑driven lessons across multicloud deployments, the conversations made one theme stand out unmistakably: security can no longer start in production, it must start in code.
A Real‑World Validation: Microsoft Gaming’s CNAPP Deployment
One of the most compelling stories came from Microsoft Gaming, who shared how FortiCNAPP now secures their globally distributed AWS environment, spanning iconic studios such as Activision, Blizzard, King, Mojang, ZeniMax, and Xbox Game Studios. Within just six months, FortiCNAPP helped secure 100% of their AWS footprint, enabling unified visibility across diverse teams and environments.
The impact extended far beyond tooling:
- Cloud teams across continents began working from the same shared insight layer.
- Remediation cycles accelerated dramatically, despite the complexity of multicloud pipelines.
- Custom controls built for Microsoft Gaming were later scaled across all FortiCNAPP customers, demonstrating product maturity and global extensibility.
The resulting posture uplift across their federated multicloud environment became a standout proof point of FortiCNAPP’s enterprise readiness.
Designing for Federated, Multicloud Enterprises
Microsoft Gaming’s environment is not only large, it is heavily federated, made up of multiple business units with their own cloud accounts, practices, and requirements. FortiCNAPP operates as a single organisational layer with multiple sub‑accounts, aligning perfectly with this structure.
The platform delivers:
- Centralised alerting
- Compliance & risk dashboards
- Workflow and ticketing integrations directly into DevOps pipelines
This operational model maps directly onto the realities of cloud‑mature enterprises, where one centralised “command view” must still adapt to semi‑autonomous teams.
Why Customers Choose FortiCNAPP
Customers consistently choose FortiCNAPP because it delivers strong out‑of‑the‑box control coverage while still allowing deep customisation for regulated or highly complex environments. Its architecture is designed to support large, federated operating models, and built‑in data isolation ensures sensitive information remains protected even at scale.
The platform’s agentless scanning removes operational friction for cloud and engineering teams, and automated deployment models make it easy to roll out across diverse clouds and organisational structures. Together, these strengths show why FortiCNAPP is viewed as both enterprise‑ready and adaptable, engineered for global scale yet flexible enough to empower local autonomy.
Baseline-Driven Cloud Security
Security consistency across AWS, Azure, and GCP was another dominant theme. Microsoft Gaming shared that they standardise on:
- AWS: AWS Foundational Security Best Practices + CIS Benchmarks
- Azure: Microsoft Cloud Security Benchmark (MCSB) + CIS
- GCP: CIS GCP Benchmarks
These baselines give large organisations an auditable foundation, critical in environments where engineering velocity traditionally outpaces governance.
How Modern Security Teams Are Structured
Microsoft Gaming showcased a highly sophisticated and modern security organisation, bringing together functions such as application and product security, cloud security and automation, security engineering and architecture, risk management and BizOps, threat detection and response, and security integration and remediation, all operating seamlessly across AWS, Azure, and GCP.
This cross‑cloud, high‑velocity model represents the new normal for cloud‑scale enterprises, where centralised platforms must enable consistent, intelligence‑driven decision‑making even as teams work across diverse technologies and environments.
Day Three Themes: Cloud, Code, and AI‑Accelerated Risk
1. Code Is the New Attack Surface
AI is accelerating development cycles, but that speed amplifies misconfigurations and insecure patterns long before workloads ever reach production. Cloud repositories now carry secrets, automation logic, and infrastructure definitions, making early‑stage risk visibility essential.
2. Abstraction Beats Cloud‑Specific Lock‑In
Microsoft Gaming described how early attempts to enforce cloud‑specific guardrails became unwieldy. Their strategic shift:
Abstract first. Map to cloud‑specific controls only when necessary.
In large, federated estates, consistency outweighs optimisation.
3. CNAPP Must See Everything, Not Just Runtime
The role of CNAPP has expanded from runtime scanning into full lifecycle risk awareness:
- Repositories
- Pipelines
- IaC
- Runtime orchestration
This provides teams with end‑to‑end visibility of how development decisions impact operational risk.
4. Prioritisation > Blanket Security
Rather than securing every asset equally, enterprises are shifting to business‑led prioritisation:
- Identify high‑value environments
- Determine where small changes yield large posture improvements
- Address what matters most, first
This avoids bottlenecks and unlocks faster security ROI.
5. CNAPP as a Decision‑Enhancement Engine
FortiCNAPP is increasingly valued for improving decision quality:
- What needs attention now
- What can safely wait
- What threatens availability, revenue, or brand
This marks a shift from alerting → prioritisation → resilience.
The Big Takeaway
Across Day Three, the message was unmistakable:
In an AI‑accelerated, cloud‑native world, risk doesn’t start at the perimeter, it starts in code.
This is why CNAPP matters more than ever. Not as a tool to “lock everything down,” but as a platform that empowers developers, architects, and security teams to make smarter, earlier, more impactful decisions.
Partners like Forge are positioned to play a critical role — not just by deploying tools, but by understanding how modern software is built and how risk propagates through cloud systems. With the right visibility, the right baselines, and the right abstraction model, enterprises can build resilient systems at global scale.
