Fortinet Accelerate 2026 Day Three Recap: The New Era of Security: CNAPP, Cloud Maturity, and AI‑Accelerated Risk

Day Three of Fortinet Accelerate 2026 spotlighted a major shift in cloud security maturity: risk now begins in code, not in production.

With real‑world validation from Microsoft Gaming’s global multicloud estate and FortiCNAPP’s role in securing one of the world’s largest gaming ecosystems, the day underscored CNAPP’s evolution from a runtime toolset to a full lifecycle risk‑intelligence platform. The message was clear, as AI accelerates development, enterprises need consistent, abstracted, federated security that prioritises impact over volume and resilience over reaction.

 

How CNAPP, Cloud Maturity, and AI‑Driven Risk Are Redefining Enterprise Security

Day three explored how cloud‑scale organisations are adapting to the rapid convergence of cloud security, AI‑powered development, and the expanding scope of code‑driven risk. Powered by deep insights from Microsoft Gaming and customer‑driven lessons across multicloud deployments, the conversations made one theme stand out unmistakably: security can no longer start in production, it must start in code.

 

A Real‑World Validation: Microsoft Gaming’s CNAPP Deployment

One of the most compelling stories came from Microsoft Gaming, who shared how FortiCNAPP now secures their globally distributed AWS environment, spanning iconic studios such as Activision, Blizzard, King, Mojang, ZeniMax, and Xbox Game Studios. Within just six months, FortiCNAPP helped secure 100% of their AWS footprint, enabling unified visibility across diverse teams and environments.

The impact extended far beyond tooling:

  • Cloud teams across continents began working from the same shared insight layer.
  • Remediation cycles accelerated dramatically, despite the complexity of multicloud pipelines.
  • Custom controls built for Microsoft Gaming were later scaled across all FortiCNAPP customers, demonstrating product maturity and global extensibility.

The resulting posture uplift across their federated multicloud environment became a standout proof point of FortiCNAPP’s enterprise readiness.

 

Designing for Federated, Multicloud Enterprises

Microsoft Gaming’s environment is not only large, it is heavily federated, made up of multiple business units with their own cloud accounts, practices, and requirements. FortiCNAPP operates as a single organisational layer with multiple sub‑accounts, aligning perfectly with this structure.

The platform delivers:

  • Centralised alerting
  • Compliance & risk dashboards
  • Workflow and ticketing integrations directly into DevOps pipelines

This operational model maps directly onto the realities of cloud‑mature enterprises, where one centralised “command view” must still adapt to semi‑autonomous teams.

 

Why Customers Choose FortiCNAPP

Customers consistently choose FortiCNAPP because it delivers strong out‑of‑the‑box control coverage while still allowing deep customisation for regulated or highly complex environments. Its architecture is designed to support large, federated operating models, and built‑in data isolation ensures sensitive information remains protected even at scale.

The platform’s agentless scanning removes operational friction for cloud and engineering teams, and automated deployment models make it easy to roll out across diverse clouds and organisational structures. Together, these strengths show why FortiCNAPP is viewed as both enterprise‑ready and adaptable, engineered for global scale yet flexible enough to empower local autonomy.

 

Baseline-Driven Cloud Security

Security consistency across AWS, Azure, and GCP was another dominant theme. Microsoft Gaming shared that they standardise on:

  • AWS: AWS Foundational Security Best Practices + CIS Benchmarks
  • Azure: Microsoft Cloud Security Benchmark (MCSB) + CIS
  • GCP: CIS GCP Benchmarks

These baselines give large organisations an auditable foundation, critical in environments where engineering velocity traditionally outpaces governance.

 

How Modern Security Teams Are Structured

Microsoft Gaming showcased a highly sophisticated and modern security organisation, bringing together functions such as application and product security, cloud security and automation, security engineering and architecture, risk management and BizOps, threat detection and response, and security integration and remediation, all operating seamlessly across AWS, Azure, and GCP.

This cross‑cloud, high‑velocity model represents the new normal for cloud‑scale enterprises, where centralised platforms must enable consistent, intelligence‑driven decision‑making even as teams work across diverse technologies and environments.

 

Day Three Themes: Cloud, Code, and AI‑Accelerated Risk

1. Code Is the New Attack Surface

AI is accelerating development cycles, but that speed amplifies misconfigurations and insecure patterns long before workloads ever reach production. Cloud repositories now carry secrets, automation logic, and infrastructure definitions, making early‑stage risk visibility essential.

2. Abstraction Beats Cloud‑Specific Lock‑In

Microsoft Gaming described how early attempts to enforce cloud‑specific guardrails became unwieldy. Their strategic shift:

Abstract first. Map to cloud‑specific controls only when necessary.

In large, federated estates, consistency outweighs optimisation.

3. CNAPP Must See Everything, Not Just Runtime

The role of CNAPP has expanded from runtime scanning into full lifecycle risk awareness:

  • Repositories
  • Pipelines
  • IaC
  • Runtime orchestration

This provides teams with end‑to‑end visibility of how development decisions impact operational risk.

4. Prioritisation > Blanket Security

Rather than securing every asset equally, enterprises are shifting to business‑led prioritisation:

  • Identify high‑value environments
  • Determine where small changes yield large posture improvements
  • Address what matters most, first

This avoids bottlenecks and unlocks faster security ROI.

5. CNAPP as a Decision‑Enhancement Engine

FortiCNAPP is increasingly valued for improving decision quality:

  • What needs attention now
  • What can safely wait
  • What threatens availability, revenue, or brand

This marks a shift from alerting → prioritisation → resilience.

 

The Big Takeaway

Across Day Three, the message was unmistakable:

In an AI‑accelerated, cloud‑native world, risk doesn’t start at the perimeter, it starts in code.

This is why CNAPP matters more than ever. Not as a tool to “lock everything down,” but as a platform that empowers developers, architects, and security teams to make smarter, earlier, more impactful decisions.

Partners like Forge are positioned to play a critical role — not just by deploying tools, but by understanding how modern software is built and how risk propagates through cloud systems. With the right visibility, the right baselines, and the right abstraction model, enterprises can build resilient systems at global scale.

 

Martin Chapman

About the author

Martin is Forge’s CTO, shaping our technical strategy and leading solution design across services and delivery. With over 25 years in IT, he’s built and led expert teams for enterprise clients and spent the last decade developing large-scale cloud platforms for European and US markets. A passionate technology evangelist, Martin ensures our solutions are innovative, scalable, and aligned with client needs.

Related Articles

Building Resilience Across the UK Financial System: The Rise of Critical Third-Party Oversight

From 13 July 2026, UK financial regulators have taken a significant step to strengthen the resilience...

Community Innovation Becomes Industry Standard: The Next Chapter for Azure Landing Zones

Microsoft has announced that Azure Landing Zones (ALZ) will move from a community-led initiative into...

Elevating Endpoint Management with Microsoft Intune

From 1 July 2026, Microsoft has expanded Intune capabilities within Microsoft 365 E3 and E5 licences....

How can we help?

Considering a particular technology?
Got a question for our team?
Please get in touch, we’re here to help.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.