Pitchgrade
Pitchgrade

Presentations made painless

Research > Fortinet: Network Security Appliances and AI-Driven SASE Transition Dynamics

Fortinet: Network Security Appliances and AI-Driven SASE Transition Dynamics

Published: Mar 07, 2026

Inside This Article

menumenu

    Executive Summary

    Fortinet (FTNT) is navigating one of the most structurally complex transitions in enterprise security: the shift from on-premises network security appliances toward cloud-delivered Secure Access Service Edge (SASE) architectures. The company's FortiGate appliance franchise, which has generated decades of cash flow from firewall, VPN, and unified threat management hardware deployments, faces a secular architectural shift driven by remote work normalization, cloud application proliferation, and AI-assisted network management that collectively make hardware-based perimeter security inadequate. AI accelerates this transition in two ways: it enables more sophisticated cloud-native security policies that can replace hardware appliances, and it equips adversaries with capabilities that perimeter-focused defenses cannot detect.

    Fortinet's response has been to leverage its custom ASIC technology (FortiASIC) to build hardware appliances that outperform general-purpose silicon in throughput and latency, while simultaneously building a cloud-delivered security portfolio (FortiSASE, FortiAI) that competes in the SASE market. This dual strategy is resource-intensive and creates internal cannibalization risk: every SASE contract the company wins potentially displaces a FortiGate hardware refresh that would have generated higher near-term margins.

    For fiscal year 2025, Fortinet reported total revenues of approximately $5.6 billion, product revenues declining year-over-year due to post-pandemic inventory digestion, and service revenues growing at high-single to low-double-digit rates. Non-GAAP operating margins were in the mid-20s percentage range, reflecting the cost of funding the SASE transition while sustaining the hardware business.

    Business Through an AI Lens

    Fortinet's FortiAI initiative embeds artificial intelligence across the FortiOS security operating system, enabling real-time threat correlation, automated incident response, and behavioral anomaly detection that reduces the manual analysis burden on security operations teams. The FortiAnalyzer platform, which aggregates log data from FortiGate appliances, uses AI models to surface threat patterns that would be invisible to signature-based detection.

    However, the AI lens reveals a structural tension in Fortinet's business model. The company's competitive differentiation in the hardware segment relies on FortiASIC: custom chips that deliver firewall throughput at a lower cost per Gbps than software-defined alternatives running on commodity hardware. As AI workloads increase network bandwidth requirements, the value of raw throughput at low cost is significant. But AI simultaneously enables network segmentation and security policies that can be enforced in software at hyperscaler points of presence, reducing the need for on-premises throughput capacity entirely.

    FortiSASE, the company's cloud-native security service, uses AI for traffic classification, anomaly detection, and zero-trust policy enforcement. Its integration with FortiGate SD-WAN hardware creates a hybrid architecture that Fortinet positions as differentiated: enterprises can extend existing FortiGate investments into SASE rather than ripping and replacing. This is a credible go-to-market story but requires sustained R&D investment across both hardware and cloud simultaneously.

    Revenue Exposure

    Fortinet's product revenue (hardware) declined meaningfully in 2023-2024 due to the post-pandemic inventory digestion cycle. Customers had over-ordered FortiGate appliances during supply chain disruptions in 2021-2022, and the subsequent absorption period depressed new hardware orders. This cyclical dynamic obscures the underlying secular risk: the long-term question is whether FortiGate hardware refresh cycles will resume at historical rates or whether enterprises will increasingly choose SASE architectures that reduce appliance count per site.

    Revenue Category 2024 Trend AI Impact 3-Year Outlook
    FortiGate Appliance Sales Recovering from trough Negative (SASE substitution) Low single-digit growth
    Security Subscriptions High single-digit growth Mixed Mid-single-digit growth
    Support and Maintenance Mid-single-digit growth Neutral Stable
    FortiSASE and Cloud 30%+ growth Positive High growth
    Professional Services Low growth Negative (AI automation) Flat to declining

    The largest revenue risk is acceleration of SASE adoption beyond Fortinet's ability to capture through its own cloud offering. Zscaler, Palo Alto Prisma Access, and Netskope have built cloud-native SASE architectures without hardware legacy, allowing them to iterate faster on cloud delivery features. If enterprises that currently run multi-site FortiGate deployments shift to cloud-native SASE over the next five years, Fortinet could face a prolonged hardware revenue decline that its SASE revenue growth does not fully offset.

    Cost Exposure

    Fortinet's cost structure reflects its dual nature as both a hardware manufacturer and a cloud software company. FortiASIC development requires silicon design teams with costs comparable to fabless semiconductor companies. Cloud infrastructure for FortiSASE requires ongoing investment in hyperscaler capacity and the networking infrastructure to deliver consistent latency performance globally.

    R&D as a percentage of revenue has risen as the company simultaneously maintains the FortiOS hardware platform and builds the FortiSASE cloud platform. This dual-track investment is the primary margin headwind: the company cannot reduce hardware R&D without risking its appliance competitive position, and it cannot reduce cloud R&D without ceding the SASE market to pure-play competitors.

    Sales and marketing costs are also elevated relative to historical norms as the company pursues SASE customer acquisition that requires different selling motions than appliance hardware renewal. SASE sales cycles involve evaluation of zero-trust architecture strategies and tend to require more technical presales resources than transactional hardware upgrade conversations.

    Moat Test

    Fortinet's moat in the hardware appliance market is genuine: FortiASIC technology provides measurable throughput and cost advantages, and the FortiOS feature set has accumulated two decades of development that would be difficult for new entrants to replicate. The FortiGate installed base, comprising millions of devices globally across SMB, mid-market, and enterprise segments, creates a renewal flywheel that sustains service and subscription revenue.

    In the SASE market, the moat is narrower. Fortinet's hybrid hardware-plus-cloud positioning is appealing to customers with significant existing FortiGate investments but less compelling to greenfield SASE evaluations where cloud-native architectures have architectural purity advantages. The company's SASE market share is growing but from a smaller base than Zscaler or Palo Alto Prisma.

    Timeline Scenarios

    1-3 Years

    Near term, FortiGate appliance revenue should recover from the inventory digestion trough as refresh cycles resume for the approximately 600,000 FortiGate devices installed at the end of the over-order period. FortiSASE revenue growth will accelerate but will not offset hardware recovery in the near term. Operating margins should stabilize as dual-track R&D investment is partially offset by hardware gross margin recovery.

    3-7 Years

    Over the medium term, the SASE transition rate is the primary variable. If 30% of Fortinet's hardware installed base migrates to cloud-native SASE without Fortinet capturing that business, the product revenue headwind would be significant. The company's ability to retain customers through the FortiSASE offering is the primary moat test of this period.

    7+ Years

    Long term, the question is whether AI-powered network policy management makes hardware-based enforcement obsolete. If AI can dynamically adjust cloud-delivered security policies with sub-millisecond latency at any point of presence, the FortiASIC throughput advantage becomes irrelevant. This scenario is not imminent but represents the existential risk horizon for the hardware appliance business model.

    Bull Case

    Fortinet's hybrid strategy succeeds: enterprises choose FortiSASE because it preserves FortiGate investments, and the company captures 15-20% SASE market share by 2028. FortiASIC hardware continues to command premium pricing for high-throughput datacenter firewall deployments. Total revenues reach $8 billion with expanding margins as the SASE business scales. AI features in FortiOS command premium subscription pricing.

    Bear Case

    Enterprise SASE adoption accelerates beyond Fortinet's capture rate. Zscaler and Palo Alto dominate the cloud-native SASE market while Fortinet's hybrid positioning is perceived as architecturally compromised. FortiGate hardware revenue declines structurally rather than cyclically. Dual-track R&D investment prevents margin expansion. Revenue growth stalls in the mid-single digits with margin contraction from 25% to 20% non-GAAP operating margins.

    Verdict: AI Margin Pressure Score 6/10

    Fortinet scores in the mixed-to-significant range. AI accelerates the structural shift from hardware perimeter security to cloud-native SASE, directly threatening the company's most profitable product franchise. Fortinet's response is credible but resource-intensive, creating dual-track cost structures that compress margins during the transition. The hardware moat provides cushion, but the secular headwind is real and AI-accelerated.

    Takeaways for Investors

    Fortinet is a transition story with a strong installed base but real secular headwinds from AI-accelerated SASE adoption. Investors should focus on FortiSASE annual recurring revenue growth (the primary indicator of transition success), hardware refresh cycle recovery pace (the near-term revenue signal), and the ratio of new SASE wins that come from FortiGate installed base versus net-new customers (the moat retention metric). Valuation should reflect transition risk: Fortinet deserves a modest discount to pure-play SASE vendors like Zscaler until its cloud revenue mix demonstrates durable scale.

    Want to research companies faster?

    • instantly

      Instantly access industry insights

      Let PitchGrade do this for me

    • smile

      Leverage powerful AI research capabilities

      We will create your text and designs for you. Sit back and relax while we do the work.

    Explore More Content

    research