01
Client Profile & Background
A leading financial services company in Jakarta, with over 5,000 employees and 200 branches across Indonesia, faced increasing cyber threats and regulatory pressure. The company handles sensitive customer data, including transactions worth trillions of rupiah daily. Their existing firewall infrastructure, consisting of legacy Cisco ASA 5500 series, was over five years old and lacked support for modern encryption standards. The IT team managed a hybrid environment with on-premises data centers and hybrid cloud workloads. The company's growth, including a 30% increase in digital banking users, demanded a scalable and high-performance security solution. The company's security posture was assessed using NIST framework, revealing gaps in threat detection and response. The legacy firewalls could not handle the 50 Gbps peak traffic, leading to packet drops during high-volume periods. Additionally, the lack of unified threat management (UTM) features required multiple point products, increasing complexity and cost. The upgrade was part of a broader IT modernization initiative to support real-time analytics and mobile banking services.
02
Technical Challenge
The primary challenge was the inability to inspect encrypted traffic at scale. With 70% of network traffic now encrypted, the legacy firewalls could only decrypt 10% of SSL/TLS sessions, leaving a significant blind spot. This resulted in a 12-hour delay in detecting a ransomware attack that impacted 50 servers. Additionally, the firewalls had a maximum throughput of 20 Gbps, causing 15% packet loss during peak hours. The average latency for critical financial transactions was 5 ms, unacceptable for real-time trading systems. Compliance with OJK regulations required granular logging and audit trails. The legacy system could only store logs for 30 days, whereas the mandate was 90 days. The IT team spent 20 hours per week on manual log analysis and rule updates. Furthermore, the lack of integration with cybersecurity tools like SIEM and SOAR meant that threat response times averaged 4 hours, far above the industry benchmark of 15 minutes. The company needed a solution that could scale to 100 Gbps throughput, support 100,000 concurrent connections, and provide automated threat intelligence.
03
Implemented Solution
The implemented solution replaced the legacy Cisco ASAs with Fortinet FortiGate 600F appliances in an active-active HA cluster. Each appliance supports 80 Gbps firewall throughput and 40 Gbps IPSec VPN. The solution includes FortiGuard AI-powered threat intelligence for real-time updates. For identity-based access, Cisco ISE was integrated with FortiGate via RADIUS and TACACS+. This allowed dynamic policy enforcement based on user roles and device posture. To address encrypted traffic inspection, we deployed Fortinet's SSL/TLS decryption proxy, capable of inspecting 20 Gbps of encrypted traffic without performance degradation. The logs were centralized using FortiAnalyzer, providing 180-day retention and seamless integration with the existing SIEM (Splunk). The upgrade also included hyperconverged infrastructure for the security management plane, ensuring high availability. The entire deployment was completed in 4 weeks with zero downtime, thanks to a phased cutover strategy.
04
Results & ROI
Post-upgrade, the company achieved a 99.99% uptime for firewall services, with zero packet loss even during peak traffic of 60 Gbps. Latency for financial transactions dropped from 5 ms to 0.8 ms, improving user experience for 2,000+ traders. The SSL/TLS decryption capability enabled inspection of 95% of encrypted traffic, leading to a 70% increase in threat detection. The RPO for log data improved from 24 hours to 1 hour, and the RTO for threat response reduced from 4 hours to 10 minutes.
The ROI was realized within 6 months through reduced operational costs (20 hours/week saved on manual log analysis) and avoidance of potential breach costs (estimated at $2 million per incident). The solution also enabled secure remote access for 500 new employees during the pandemic, supporting business continuity. The company now meets all OJK compliance requirements, including real-time reporting to regulators. The upgrade positioned the firm for future growth, with the ability to scale to 100 Gbps without hardware changes.