Procurement teams often see a Fortinet appliance quoted with "FortiGuard" attached and assume it is one single add-on. It is not. If you are asking what does FortiGuard include, the practical answer is this: FortiGuard is Fortinet’s cloud-delivered security services portfolio, and the exact inclusions depend on the licence or bundle you buy.
That distinction matters. A firewall without the right FortiGuard services may still route traffic and enforce basic policy, but it will not deliver the same threat intelligence, web control, intrusion prevention, application awareness or advanced malware protection that most businesses actually expect when they invest in a next-generation security platform.
What does FortiGuard include in practice?
FortiGuard includes a range of subscription-based security services that feed intelligence, updates and enforcement capabilities into Fortinet products. On a FortiGate, that typically means threat prevention and content security services. Across the wider Fortinet estate, it can also extend to endpoint, email, cloud and security operations use cases.
For most buyers, the core FortiGuard services commonly discussed are antivirus, intrusion prevention, web filtering, application control, anti-spam, DNS security, sandboxing, outbreak protection and security rating or posture-related intelligence. Some bundles also include advanced support entitlements, but support and FortiGuard are not always the same thing. That is one of the first areas where buyers can get caught out.
If you are reviewing a quote, the right question is less "does it have FortiGuard" and more "which FortiGuard services are included, for how long, and on which device or workload?"
The main FortiGuard services most organisations use
Antivirus and anti-malware
This is the most familiar layer. FortiGuard antivirus services inspect files and traffic for known malware and malicious content using continuously updated signatures and detection logic. For many SMB and mid-market environments, this is considered baseline protection rather than a premium extra.
That said, antivirus on its own is not enough. It works best when paired with other inspection services, especially where encrypted traffic, web access and remote users are part of the normal operating model.
Intrusion Prevention System
IPS is one of the most valuable FortiGuard services for network protection. It identifies and blocks exploit attempts, vulnerability abuse and suspicious traffic patterns moving across the network. This is especially relevant for organisations running public-facing services, branch connectivity, hybrid work models or legacy systems that cannot always be patched as quickly as security teams would like.
The trade-off is performance. Deep inspection consumes resources, so the right appliance sizing matters. Buying the cheapest firewall and then enabling every inspection profile is not a cost-saving strategy if it degrades user experience or forces an early refresh.
Web filtering
Web filtering allows organisations to control access to categories of websites and reduce exposure to malicious, inappropriate or high-risk destinations. For many businesses, this is partly about security and partly about governance.
In regulated environments, it also supports policy enforcement. The real value is not just blocking obvious bad sites. It is having current category intelligence and reputation data that can adapt as sites change and new threats appear.
Application control
Application control gives visibility into the applications and services traversing the network, even when they use standard ports. That helps security and infrastructure teams distinguish between sanctioned SaaS, shadow IT, risky file-sharing tools and unnecessary traffic consuming bandwidth.
For operational teams, this is often where Fortinet starts to feel commercially useful rather than purely defensive. Better application visibility supports cleaner policy design, better bandwidth management and fewer blind spots.
DNS security
DNS security services help block requests to malicious or suspicious domains before a connection fully establishes. This layer is effective because many attacks rely on domain-based infrastructure for command-and-control, phishing or payload delivery.
It is not a substitute for broader inspection, but it is a strong control for reducing exposure early in the traffic flow. In lean IT environments, controls that stop threats sooner tend to return better value because they reduce the burden on downstream tools and teams.
Anti-spam and email-related protection
Where FortiGuard services are used with email security products, anti-spam and related inspection features help detect phishing, spam and malicious email-borne threats. The exact inclusions depend on the Fortinet product in play.
This is where buyers need to be careful about assumptions. A FortiGate with a security bundle does not automatically deliver every email security feature available across the Fortinet portfolio. Product scope matters.
Sandbox and advanced threat protection
Sandboxing is designed to analyse suspicious files or objects in a controlled environment to identify previously unknown or evasive threats. This is especially useful for organisations concerned about zero-day malware, targeted attacks or payloads that may slip past signature-based controls.
Not every business needs the most advanced sandboxing tier, but many should at least assess it. If your organisation handles sensitive data, supports distributed users, or operates in healthcare, finance, education or government-aligned environments, the added detection depth can be justified.
Outbreak protection and threat intelligence updates
FortiGuard is not just a box of features. A major part of its value is the ongoing intelligence feeding those controls. Threat research, signature updates, reputation services and emerging threat protections are what keep a Fortinet deployment current against active attack techniques.
Without current intelligence, even well-designed policies become less effective over time. This is why subscription renewal should be treated as part of operational resilience, not a discretionary afterthought.
Bundles matter more than the FortiGuard label
When buyers ask what does FortiGuard include, they are often really asking about Fortinet bundles such as UTP, Enterprise Protection or other licence combinations. This is where clarity matters, because bundles package different FortiGuard services together for different risk, compliance and operational needs.
A smaller business may choose a more economical bundle focused on core threat protection and web control. A multi-site organisation with tighter compliance requirements may need broader inspection, stronger advanced protection and more complete visibility. Neither approach is universally right. It depends on threat profile, internal capability, user count, application footprint and the commercial consequences of downtime or compromise.
The best buying decision is usually not the biggest bundle by default. It is the bundle that aligns with your operating model and risk tolerance without creating unnecessary spend.
What FortiGuard does not automatically include
This is where quotes need careful review. FortiGuard does not always mean 24x7 vendor support, hardware replacement entitlements, managed services, implementation, policy tuning or full platform-wide protection across every Fortinet product you own.
It also does not guarantee that every advanced feature is licensed on every appliance. For example, one deployment may include IPS and web filtering but not advanced sandboxing. Another may include broader coverage but only for a one-year term. If procurement is comparing offers on headline price alone, these differences can be missed.
For Australian organisations, this becomes even more relevant when internal teams need local deployment guidance, compliance alignment or post-sale technical support. The software subscription is one component. Getting the design, sizing and operational model right is another.
How to work out what you actually need
Start with the outcomes you are trying to achieve. If your priority is secure internet access for a growing office, core web filtering, IPS and antivirus may be the right baseline. If you are protecting multiple branches, remote users and cloud-connected workloads, deeper application control, DNS security and advanced threat services may quickly become worthwhile.
Then look at your internal capability. A well-resourced security team may be comfortable managing a broader set of features and extracting more value from them. A lean IT team may prefer a simpler, well-scoped bundle that is easier to operate consistently.
It is also worth checking performance expectations against inspection requirements. Security features are only valuable if they can be enabled without disrupting the business. Correct appliance sizing and licence selection should be done together, not as separate decisions.
A more useful way to ask the question
Instead of only asking what does FortiGuard include, ask these three things: which services are included, which products they apply to, and whether the bundle matches your risk and compliance requirements. That moves the conversation from product marketing to deployable security.
A good Fortinet design is not about stacking every available feature. It is about selecting the right intelligence and controls for your environment, then backing that decision with renewal discipline and the right operational support. That is where enterprise-grade protection starts to deliver commercial value, not just technical coverage.
If you are evaluating Fortinet for the first time, or refreshing an existing estate, take the time to map the licence to the real use case. It is a far better investment than discovering after deployment that the appliance was sound but the protections you assumed were included were never actually there.

