The prudent approach is to run a version that is “mature” (e.g., v7.2.9 rather than v7.4.0), has been deployed for 3-6 months, and has a known security advisory bulletin. For regulated industries (finance, healthcare), staying one major version behind the bleeding edge is a common risk mitigation strategy.
For the network administrator, the lesson is clear: The proprietary nature of FortiOS means you cannot "backport" security patches yourself. When the firmware support ends for your hardware, your security posture dies with it.
: Enhancements to the Security Fabric and high-speed processing.
By working with Fortinet's support team and using their centralized management platform, BankSecure's security team was able to overcome the challenges associated with upgrading the firmware and ensure a smooth transition to the new version.
Fortinet firmware is a marvel of engineering efficiency, designed with a singular goal: to process packets as fast as possible while applying security logic. Its proprietary nature offers speed and stability but demands a "trust us" relationship with the vendor.