Ice Manufacturer Consolidates onto the Fortinet Security Fabric to Freeze Out Attackers
When organizations expand into multiple locations, security gets more complex. When Home City Ice experienced this challenge, it consolidated fragmented security tools onto the Fortinet Security Fabric to improve visibility, simplify management, and reduce operational overhead. Get the story to learn from Home City Ice's success in deploying an integrated strategy that helps the company manage security and operate efficiently with a smaller team.
Why did Home City Ice consolidate on the Fortinet Security Fabric?
Home City Ice had grown quickly to **80 manufacturing plants and about 75 satellite distribution facilities**, all connected over a private MPLS network. As the environment expanded, the team was managing a mix of legacy firewalls, third-party IPS, separate VPN concentrators, and other point tools. This created complexity, higher labor costs, and more room for configuration gaps.
When the legacy firewalls reached end of life, the company decided to **rethink its security architecture** and consolidate onto **FortiGate Next-Generation Firewalls** and the broader **Fortinet Security Fabric**. Key reasons for the move included:
- Single platform, fewer vendors: FortiGate NGFWs could handle firewalling, VPN, intrusion prevention, wireless, and SD-WAN under a **single license**, reducing the need for multiple products.
- Consistent management at scale: With **FortiManager**, the team can centrally manage policies and push changes across roughly **150 Secure SD-WAN locations**, instead of configuring each site separately.
- Integrated visibility and analytics: **FortiAnalyzer** and **FortiSIEM** pull logs and events from across the Fortinet stack, giving the network architect one place to monitor and investigate issues.
- Operational efficiency for a small team: Because the Fortinet tools share similar interfaces and terminology, once the team learned one product, others became easier to operate. This helped keep staffing needs down while the network footprint grew.
Over more than a decade on Fortinet, Home City Ice reports **no major security incidents**, while gaining a more manageable and cost-effective security environment.
How is Home City Ice protecting its hybrid and OT-heavy environment?
Home City Ice runs a mix of **virtualized data centers**, **remote terminals in rural locations**, and **OT/IoT devices** such as programmable logic controllers (PLCs) that control icemaking equipment. To protect this hybrid and OT-heavy environment, the company has built a layered security approach on the Fortinet Security Fabric:
- Perimeter and data center protection: Two data centers host all servers in a virtual environment. Each data center is protected by **FortiGate NGFWs in high-availability (HA) pairs**, securing all backhauled MPLS traffic and providing internal segmentation.
- Remote site security and SD-WAN: FortiGates also secure the perimeter of terminals, sales offices, and other remote sites. **Fortinet Secure SD-WAN** provides load balancing and resilient connectivity for these locations.
- Segmentation and microsegmentation: FortiGates manage internal segmentation, and Home City Ice is experimenting with using FortiGates directly for microsegmentation as it moves away from VMware NSX. **FortiNAC** adds dynamic network access control, automatically recognizing and categorizing devices (IoT, managed workstations, BYOD) and placing them into the right granular segments.
- Cloud security: A **FortiGate VM** secures access to resources in the company’s **Microsoft Azure** environment, managed centrally alongside on-premises devices via **FortiManager**.
- Advanced threat protection:
- **FortiSandbox** provides AI-powered sandboxing when FortiGates detect suspicious content.
- **FortiWeb** protects web applications and APIs, adding an extra layer against web-based attacks.
- **FortiClient EMS** delivers antivirus, vulnerability scanning, and ZTNA proxies on endpoints.
- **FortiEDR**, delivered with **FortiGuard Managed Detection and Response**, acts as a final layer of defense, inspecting libraries and executables and blocking events before they execute. The managed service keeps watch during evenings and weekends when internal staff are not available.
- Identity and access control: **FortiAuthenticator** and **FortiToken** provide multi-factor authentication (MFA), especially for privileged access. All IT staff and selected executives use MFA to connect.
These components work together as a coordinated fabric. For example, if **FortiEDR** isolates a threat, it can use **FortiNAC** to locate the physical device and quarantine it, while threat intelligence from **FortiSandbox** is shared across FortiGates and FortiClient EMS. This integrated approach helps Home City Ice protect both IT and OT systems without adding significant operational overhead.
What business results has Home City Ice seen from using Fortinet?
Home City Ice’s move to the Fortinet Security Fabric has produced several tangible outcomes across security, operations, and cost:
- Strong security track record: The company reports **zero major security incidents in more than a decade** while running Fortinet solutions across about **150 locations**.
- Proven resilience in penetration testing: A third-party penetration test team struggled to gain access during both external and internal tests. Home City Ice had to repeatedly relax its security posture and create exceptions just so the testers could proceed—yet **FortiSIEM still blocked some of their activity**. This gave the team added confidence in the effectiveness of the controls.
- Lower total cost of ownership (TCO): By consolidating from a “hodgepodge” of vendors to a single integrated ecosystem, Home City Ice reduced the labor required to manage the network. The network architect notes that if they still ran multiple vendors, they would likely need a larger staff because each system would be more cumbersome to learn and operate.
- Operational efficiency for a small team: The **shared interface and terminology** across Fortinet products mean that once staff learn one tool, others are easier to adopt. The GUI-driven approach reduces reliance on command-line operations, which simplifies day-to-day management.
- Simplified wireless and access control: Moving to **FortiAP** access points, managed directly from FortiGate, made Wi-Fi deployment easier and less expensive to manage across all locations. **FortiNAC** further automates device onboarding and segmentation, reducing manual work.
- Faster, more coordinated response: With **FortiAnalyzer** and **FortiSIEM** aggregating logs and threat data, the team has clear, centralized visibility. When an issue arises, they can see it quickly and trigger an automated or guided response across multiple tools (e.g., FortiEDR, FortiNAC, FortiGate).
As Home City Ice continues to grow, it is now evaluating additional Fortinet offerings such as **FortiSASE** and **FortiSwitch**, largely because the existing integrations and cost profile have already helped the company **reimagine** how a small IT and security team can support a geographically distributed manufacturing business.
Ice Manufacturer Consolidates onto the Fortinet Security Fabric to Freeze Out Attackers
published by RYCOMM LLC
Trusted by many small and medium size businesses in New England and nationwide, RYCOMM is an IT services company, focused on helping businesses with their IT needs and challenges.
We have been providing simplified IT solutions for unique customers since 1998. We use the latest technology in the market and have years of experience supporting companies. Our expertise is unmatched in the Managed IT Service provider space because we have seen what works and what doesn’t, both operating as a service provider and on the receiving end, managing outsourced IT Service providers ourselves to fill in gaps in large enterprise deployments.
Our company has been designed to provide a better user experience, save money, prevent downtime, and provide a comprehensive IT solution to fit your business’s needs.
We provide a variety of IT support and managed IT solutions tailored to fit your business needs. We offer managed services, including end-user support, cloud migrations, disaster recovery, network and server monitoring, help desk, telephony, business continuity services and strategic planning. We also offer Managed IT Service plans with complete management on a per user, per month pricing model.
RYCOMM also provides a large selection of hardware and software choices for your IT environment. Our technology experts design and configure solutions using the latest technologies from industry leaders.
We are a comprehensive Technology Consulting firm providing complete IT outsourcing, that manages all your technology needs, so you can focus on your business.