← All articles

· Graybridge Software

Rockwell Extends SecureOT with Managed Fortinet Firewalls and Infrastructure Services

Rockwell Automation has announced two new managed services for its SecureOT suite: Fortinet FortiGate firewall management and Infrastructure Managed Services. The signal is clear: vendors are moving from selling products to running OT security operations.

OT securityRockwellFortinetmanaged servicesfirewall

Rockwell Automation announced two additions on Tuesday to its industrial cybersecurity suite, SecureOT. Industrial Cyber reported the news on October 8, 2026. The two services, Firewall Managed Services with Fortinet and Infrastructure Managed Services, are available immediately.

Managed firewalls: FortiGate arrives

The managed firewall service now supports Fortinet FortiGate firewalls. Rockwell manages them on the customer's behalf, handling monitoring, alarm management, rule change management, patching and firmware updates. The customer gets a single point of contact and a single contract.

According to the announcement, FortiGate offers multi-site scalability, threat detection backed by OT data from FortiGuard Labs, and a lower total cost of ownership than many alternatives. These are vendor claims and have not been independently verified.

Infrastructure Managed Services

The second service provides 24/7 global support, secure monitoring and hardware lifecycle management for industrial network and compute environments. It includes turnkey "defensible architectures":

  • Industrial Data Center (IDC)
  • VersaVirtual Appliance (VVA)
  • firewalls
  • network switches

What is new is the extension to infrastructure customers already own: servers, virtualization platforms, switches and backup systems from various vendors, including Fortinet.

The stated rationale

Rockwell argues that threats to industrial operations keep growing and that qualified OT security professionals are hard to find. It also cites its own research indicating that cybersecurity is now among the top external risks for manufacturers, driven by IT/OT convergence. Aaron White, global capability manager for infrastructure managed services, said manufacturers need solutions that "fit their operations, not the other way around."

Why it matters for decision-makers

The most interesting point is not the individual product but the direction. Automation vendors no longer sell only security tools: they offer to run the operational work, such as firewall rule changes, patching and lifecycle management. In addition, covering existing, multi-vendor infrastructure lowers the barrier to outsourcing, since there is no need to replace what you already have.

For organizations with limited specialized OT staff, this can be a practical way to close a skills gap. But outsourcing also shifts control, and it deserves careful evaluation.

Questions to ask before outsourcing

  • Change approval: who authorizes a firewall rule change? Is there a workflow that involves process engineering and production?
  • Patching windows: how are updates and reboots coordinated with production downtime and availability requirements?
  • Single-vendor dependency: entrusting both automation and security to the same partner concentrates risk and reduces separation of duties.
  • Data visibility and ownership: which logs, reports and access rights stay with the customer? What happens if you switch providers?
  • Scope of responsibility: where does the managed service end and internal responsibility begin, for example for network segmentation and incident response?

What we don't know

As reported, the announcement provides no pricing, contract terms or customer examples. Claims about effectiveness and cost should therefore be treated as marketing until verifiable data emerges.

Outsourcing security operations does not mean outsourcing accountability for risk.

In practice, it makes sense to first map the OT security activities currently performed in-house, identify those that lack resources, and consider a managed offering only with explicit approval processes and SLAs aligned to production windows.