Why APAC’s SOCs Need a Nervous System, Not Another Box
- By Winston Thomas
- July 12, 2026

Asia-Pacific enterprises are pouring money into cybersecurity and are still getting hacked. It’s a contradiction that sits at the center of a conversation with Jack Chan, Fortinet’s global vice president of product management and field CTO for APAC, who has spent nearly 20 years watching the region’s security stacks grow taller without growing smarter.
“There’s no coherent architecture of how to use AI and machine learning,” Chan said. “Every vendor’s got their own agents now; they’re building their own agents, but those agents aren’t really talking to each other.”
That is the paradox that CISOs face in one sentence. Banks, airlines, hospitals and telcos across the region have spent a decade assembling what Chan calls “best of breed” — a firewall from one vendor, endpoint protection from another, and a ticketing system from a third, each bought through a separate, rational RFP. No single purchase was wrong. But nobody designed the whole. “Every RFP, every decision in the last four or five years was rational at that point, but no one’s looked at the big picture and gone, ‘Let’s do an RFP for AI for cybersecurity,’” Chan observed.
Meanwhile, attackers got faster. Generative AI has compressed the gap between a published vulnerability and an active exploit from weeks to minutes, Chan said: “Anything from CVEs to vulnerabilities gets turned into an outbreak in a matter of minutes.” Defenders, running fragmented tools bolted on year after year, are left with what Chan calls SOC fatigue — expensive analysts drowning in disconnected consoles, stuck doing correlation by hand: tracing a phishing click through to a botnet infection to data exfiltration, one dashboard at a time. ”How do you correlate all these attacks from endpoint, network, in a phishing ransomware? It's actually still quite manual at the moment,” he said.
The case for a network-level brain
Fortinet’s answer is network detection and response, or NDR — a layer that sits between the perimeter firewall and the endpoint agent, watching everything that moves across the wire. Don’t mistake it for another alert console; Fortinet’s pitch is that NDR does pattern recognition at scale, built on what Chan calls a magnifying glass over network metadata: connection logs, file hashes, and traffic timing.
The core insight, he said, is structural: “No attacks can actually escape the network.” An infected laptop can be wiped and restored from backup in minutes, but that erases the evidence of what the machine did before and after infection — who it talked to, what data it sent, and when. “For most enterprises, it’s fine to just restore with backup. But no one actually looks at what this endpoint has done.” NDR keeps that history.
This becomes as vital as attackers and defenders continue their decades-old cat-and-mouse game. The “tipping point” came a decade ago when sandboxes that detonated suspicious files inside a fake Windows machine got outsmarted by attackers checking whether “My Documents” had recently modified files — a tell that the environment was staged.
“So guess what we have to do,” Chan said. “We have to put some recently modified files in that Windows 11 to pretend that it’s an end user.” Attackers adapt, defenders adapt back. “That’s why cybersecurity is always a very interesting industry to work in,” he said. NDR not only levels the playing field but takes a granular look at what lurks behind an attack.
As a result, Chan offered two patterns the NDR platform, built out of the FortiAI deep-learning engine into a broader system of self-learning models and behavioral analytics, catches:
Domain-controller attacks. Domain controllers sync with each other constantly as routine housekeeping, so a rule-based tool waves it through. Fortinet’s models ask a more nuanced question: has this IP synced before? Has this controller ever synced at 2 a.m.? “It might not necessarily be an attack, but [we’re saying that] you should really have a look at it,” Chan said.
Attackers who spin up disposable command-and-control (C2) infrastructure on AWS or Azure — domains too new for any blocklist. “No vendor will actually detect that new IP or that new [Fully Qualified Domain Name],” Chan said. Instead, the model scores the traffic’s shape — beaconing intervals and connection statistics — against known command-and-control behavior.
Roughly half of Fortinet’s detection models arrive pretrained on attack patterns common across customers; the other half tune to an organization’s own baseline — what counts as a normal upload volume, login hour, or BitTorrent connection.
Chan is candid that vendor demos oversell the polish. “A lot of vendors, their console will light up — I call it like a Christmas tree. It looks good. But when you put such a solution into operation, that's when the SOC fatigue or the alert overload comes in.”
From detection to response
Fortinet’s version of that pattern-recognition layer runs alongside what it calls FortiAI — not a single feature but, in Chan’s words, “the agent to help you across multiple solutions,” reachable through natural language like a chatbot. “This chatbot is actually quite powerful now with FortiAI to do many things for you,” he said. “You can do configuration, troubleshooting, and threat hunting.”
Bolting NDR onto an existing stack of EDR, SIEM and SOAR tools is where a lot of vendors’ promises fall apart, Chan acknowledged — those integrations are often “noisy and fragile” in practice. He said Fortinet designs toward three goals instead: bring down mean time to detect and triage time; increase accuracy by cross-checking a detection against other tools, so that if “NDR detected something and EDR detects something,” the finding gets upgraded in confidence; and provide the appropriate remediation — the R in both NDR and EDR. That can mean quarantining a device through a firewall, or moving an attacker and victim onto a separate network segment to contain the blast radius.
The more aggressive version of that last step is what Fortinet calls dynamic deception. “We can actually, in real time, spin up more fake targets for the attackers, to confuse the attacker in real time when we detect that attack is happening,” Chan said. The goal isn’t just containment but intelligence. ”You can collect more statistics from what the attacker”does before the connection gets cut.
Chan frames the current moment as an arms race that has gone agentic on both sides. “Hackers are using AI agentic capabilities to help organize their attack, and we are using the AI... to learn and organize the defense,” he said. “Cybersecurity is a game of offense and defense — think of it like chess.” How far a SOC lets that AI act on its own, he added, comes down to trust built over time.
Fortinet is also trying to standardize the playbooks that sit behind those decisions. In June 2026 the company launched FortiSOC, a SaaS platform Chan described as an attempt to bake in “best practice” playbooks so understaffed teams aren’t building triage logic from scratch. “We can’t hire enough analyst humans... to triage all the events,” he said, “so we start to write playbooks... to put these best practices back into the products for customers to enjoy.”
Chan’s broader pitch is consolidation. Many APAC enterprises, he said, are stuck in a “multi-vendor agent-like helplessness” — a decade of bolting new point solutions onto the stack, each with its own dashboard and its own agent that can't see what the others see. Fortinet’s answer is what it calls the Security Fabric: a shared data lake spanning Wi-Fi, NDR, EDR, endpoint, firewall, email and web traffic that a single FortiAI agent can query across.
Data stays home
The regional flashpoint right now is data sovereignty, which is why Fortinet stood up a FortiNDR Cloud point of presence in Singapore in June 2026 — its first on-shore NDR analytics hub for ASEAN and the wider APAC region, joining existing hubs in the U.S. and Europe. Chan ties the urgency to AI adoption anxiety.
“Many companies, they’re afraid to use AI because while they’re concerned that ‘I might fall behind the competition,’ they’re also afraid, ‘If I use AI, where’s my data going to sit?’” With the Singapore Point-of-Presence (PoP), network metadata for regional customers stays in-region. It creates a distinction increasingly demanded by regulators and boards, particularly in healthcare and critical infrastructure, where some operators keep sensitive operational technology (OT) systems entirely offline.
That OT gap is also the region’s stubborn blind spot. Industrial controllers, medical devices and smart-building systems generally can’t run endpoint agents. NDR’s passive, out-of-band design — tapping a switch port rather than sitting inline — lets it monitor those environments without risking production uptime.
However, Chan is upfront about the limits: it is not as simple as flipping a switch. He noted that companies need to consider the parts of the network that are most risky, the bandwidth, and the number of IP addresses. He also admitted that it comes down to a budget question: “Some people say, ‘I want to cover 100%.’ But it will cost you this much.”
So does NDR move the needle on how a CISO reports to the board? “Yes and no,” Chan said. Mean time to detect remains the primary number — the metric his own customers’ boards already push them on. What NDR does is that it also surfaces the slow, quiet attacks that traditional tools wave through entirely.
“Those advanced attacks are quite hidden,” Chan said, which is why Fortinet retains network history for customers — long enough to answer the question that matters most after a breach: what did this endpoint actually do, and when did it start?
Image credit: iStockphoto/gorodenkoff
Winston Thomas
Winston Thomas is the editor-in-chief of CDOTrends. He likes to piece together the weird and wondering tech puzzle for readers and identify groundbreaking business models led by tech while waiting for the singularity.