LOUISIANA CYBER INCIDENT WATCHIndependent. Sourced. Local.
BAYOUBREACH
Menu
FROM A LOCAL INCIDENT TO A PRACTICAL QUESTION

Understand the gap.
Know what to ask.

Each brief identifies an area to evaluate, recommends a Fortinet technology and explains how it could help. Hardware, virtual appliances, software and cloud services are clearly distinguished.

13Incident assessmentsOne practical question for each record
9Workbook account matchesEvent-linkage limits remain visible
9Technology familiesDeployment and coverage explained
A security gap is an area to examine.

It is not a finding that a named organization lacked a control. Recommendations describe present-day capabilities and conditions, not a guarantee that a product would have prevented the historical event. Specific appliance models need environment and capacity information.

How recommendations are made
INCIDENT BY INCIDENT

The gap and the recommended technology.

Open the full assessment for its evidence, uncertainty, conditional controls and sizing questions.

Confirmed incidentSep 30, 2026

Terrebonne Parish Consolidated Government

Isolate affected networks while keeping essential services available

RECOMMENDED FORTINET TECHNOLOGYFortiGate segmentation + IPSHardware or virtual firewall

Can you isolate one department’s network while maintaining dispatch, public-safety communications and other priority services, and has that procedure been tested?

Separate technical assessmentRead the assessment
Confirmed incidentSep 4, 2025

Orleans Parish Sheriff's Office

Exposure visibility and endpoint containment

RECOMMENDED FORTINET TECHNOLOGYFortiReconCloud service (SaaS)

Can your team demonstrate endpoint coverage and an approved isolation workflow for the computers that support public case access?

Workbook recommendationRead the assessment
Reported incidentOct 7, 2024

Vermilion Parish School System

Validate credential exposure and vendor access

RECOMMENDED FORTINET TECHNOLOGYFortiReconCloud service (SaaS)

Can you list every outside provider with remote access, its named account, its authentication method and who can disable it?

Workbook recommendationRead the assessment
Confirmed incidentJun 19–21, 2024

Acadian Ambulance Service, Inc.

Protect patient information outside the primary clinical application

RECOMMENDED FORTINET TECHNOLOGYFortiDLPCloud platform with endpoint agents

Can you locate exported patient records and demonstrate which copying, upload and sharing routes are controlled without disrupting patient care?

Workbook recommendationRead the assessment
Confirmed incidentMar 2024

East Baton Rouge Parish Sheriff's Office

Sensitive investigative records and controlled data movement

RECOMMENDED FORTINET TECHNOLOGYFortiDLPCloud platform with endpoint agents

Which shared locations contain investigative records, who can export them, and can your team demonstrate controls on those transfer paths?

Workbook organization match onlyRead the assessment
Confirmed incidentJul 26, 2023

St. Landry Parish School Board

Credential exposure and sensitive records outside core systems

RECOMMENDED FORTINET TECHNOLOGYFortiReconCloud service (SaaS)

Which shared folders contain student or employee identifiers, and can your team demonstrate how unusual copying would be detected or blocked?

Workbook recommendationRead the assessment
Confirmed incidentMay–Jun 2023

Louisiana Office of Motor Vehicles

Protect exposed file-transfer applications

RECOMMENDED FORTINET TECHNOLOGYFortiWebHardware, virtual, or container WAF

Who owns each internet-facing file-transfer service, and can they show patch status, supported blocking controls and access logs?

Separate technical assessmentRead the assessment
Confirmed incidentFeb 2023

Southeastern Louisiana University

Clarify exposure and verify access controls

RECOMMENDED FORTINET TECHNOLOGYFortiReconCloud service (SaaS)

Can your team show which administrator and vendor accounts are controlled, and retain evidence of how those controls are tested?

Workbook organization match onlyRead the assessment
Confirmed incidentOct 20–21, 2022

Lake Charles Memorial Health System

Sensitive files and visibility into data leaving the network

RECOMMENDED FORTINET TECHNOLOGYFortiDLPCloud platform with endpoint agents

Where do patient-file exports and shared copies live, and which of their transfer paths are actually monitored or controlled?

Separate technical assessmentRead the assessment
Confirmed incidentJun 24–29, 2022

Baton Rouge General / General Health System

Understand exposure and protect clinical continuity

RECOMMENDED FORTINET TECHNOLOGYFortiReconCloud service (SaaS)

Can IT and clinical leaders demonstrate a safe containment decision that preserves essential patient-care workflows?

Workbook organization match onlyRead the assessment
Unverified claimSep 2020

Fourth Judicial District Court of Louisiana

Validate the allegation before diagnosing a gap

RECOMMENDED FORTINET TECHNOLOGYFortiReconCloud service (SaaS)

What independent evidence supports the allegation, and which current systems or access paths need validation before selecting a control?

Workbook recommendationRead the assessment
Confirmed incidentDec 13, 2019

City of New Orleans

Endpoint containment during ransomware disruption

RECOMMENDED FORTINET TECHNOLOGYFortiEDREndpoint software with cloud or on-premises management

Can your team test isolation of an infected administrative device while keeping essential public-safety services operating?

Separate technical assessmentRead the assessment
Confirmed incidentNov 18, 2019

Louisiana Office of Technology Services / State of Louisiana

Contain endpoint activity while preserving state services

RECOMMENDED FORTINET TECHNOLOGYFortiEDREndpoint software with cloud or on-premises management

Can each agency show endpoint coverage, ownership of isolation decisions and a tested path for restoring priority services?

Workbook recommendationRead the assessment
APPLIANCE, SOFTWARE OR SERVICE?

Choose the control before the model.

Use these plain-language explanations to prepare a discussion with your IT team or service provider. Product capabilities were reviewed October 9, 2026.

FortiReconExposure discovery and adversary intelligenceCloud service (SaaS)

How it works: Continuously discovers exposed assets and prioritizes vulnerabilities, while monitoring leaked credentials, ransomware activity, and other adversary intelligence so teams can remediate exposure and investigate emerging risk before or during an incident.

Deployment: Subscription exposure-management and intelligence service; not a physical network appliance.

When to consider it: When the agency needs external exposure, leaked-credential, or adversary-intelligence visibility and has an owner for remediation.

Coverage matters: Findings require investigation and remediation; exposure monitoring and ransomware intelligence do not directly block ransomware execution.

Before choosing a model or license

  • Which domains, IP ranges, brands, and vendors are in scope?
  • Who validates and acts on findings?
FortiEDREndpoint prevention, containment, and responseEndpoint software with cloud or on-premises management

How it works: An endpoint agent analyzes malware and suspicious process behavior, can block harmful file access and outbound communications, and supports automated isolation and remediation to limit ransomware damage on protected devices.

Deployment: Software agents protect supported endpoints and servers; management components can be cloud, on-premises, or hybrid. This is not an inline hardware firewall.

When to consider it: When managed workstations and servers need endpoint detection, ransomware containment, and a tested response process.

Coverage matters: Protection depends on supported devices running the agent with suitable prevention and response policies; this does not guarantee every ransomware attack is stopped.

Before choosing a model or license

  • Which endpoint operating systems and workloads are supported?
  • How many devices need protection?
  • Who monitors alerts and authorizes isolation?
FortiDLPSensitive data movement and egress controlsCloud platform with endpoint agents

How it works: Inspects sensitive data and user activity through endpoint agents and supported cloud integrations, using content, origin, and behavioral context to flag risky movement and enforce controls on covered egress paths.

Deployment: Cloud-native data-protection platform using endpoint agents and supported cloud integrations; not a universal inline appliance for all server traffic.

When to consider it: When sensitive information needs controls on covered endpoint, SaaS, or cloud-drive data flows.

Coverage matters: Coverage follows deployed agents and supported integrations or egress paths; it is not universal exfiltration blocking for arbitrary servers or unseen traffic.

Before choosing a model or license

  • Which devices, cloud drives, and egress paths need coverage?
  • What data is sensitive?
  • Which policies can safely block activity?
FortiAuthenticator + FortiTokenStronger authentication and centralized identity policyHardware or virtual identity server + mobile or hardware tokens

How it works: Centralizes authentication for integrated applications, VPNs, and administrative access, adding FortiToken factors and identity policies so a stolen password alone is less likely to provide access to protected resources.

Deployment: FortiAuthenticator is available as a physical or virtual appliance, including private/public-cloud deployment. FortiToken factors include mobile software and hardware tokens or security keys.

When to consider it: When VPN, administrator, and application access need centralized authentication and stronger sign-in verification.

Coverage matters: Phishing resistance requires an appropriate FIDO2 flow; OTP or push alone is not equivalent. Enabling MFA does not establish revocation of already stolen application sessions.

Before choosing a model or license

  • Which applications and protocols will integrate?
  • How many users and authentication requests must be supported?
  • Is FIDO2 required for phishing resistance?
FortiPAMPrivileged credential and session controlsVirtual appliance

How it works: Vaults and rotates privileged credentials, brokers access under role-based policies, and records privileged sessions; administrators can restrict commands or terminate sessions to reduce credential exposure and misuse of elevated access.

Deployment: The current datasheet identifies a virtual appliance for privileged credential and session management. Do not label it a recommended physical box.

When to consider it: When shared administrator credentials, privileged vendor access, or unrecorded administrative sessions are a documented gap.

Coverage matters: Apply these controls to onboarded accounts and brokered sessions; unmanaged credentials or direct access that bypasses FortiPAM remain outside that enforcement path.

Before choosing a model or license

  • Which accounts and target systems will be onboarded?
  • How many concurrent sessions are expected?
  • How much session-recording storage and retention are needed?
FortiGate segmentation + IPSNetwork access restriction and exploit filteringHardware or virtual firewall

How it works: Separates network segments with firewall policies that restrict allowed communications, while IPS inspects traversing traffic for attack patterns and can block matching exploits, helping contain lateral movement between protected zones.

Deployment: Physical FortiGate appliances suit on-site network enforcement; FortiGate-VM supports private and public clouds. This classification does not select a model or claim all deployment types share identical capacity.

When to consider it: When network zones need restricted communications and inspected traffic paths, including between user, server, management, and externally accessible services.

Coverage matters: Traffic must cross the enforcement point, with restrictive policies and IPS enabled; encrypted payload inspection needs appropriate decryption and inspection configuration.

Before choosing a model or license

  • What throughput is needed with IPS and TLS inspection enabled?
  • What are peak concurrent sessions, VPN users, and interface speeds?
  • What availability and failover requirements apply?
FortiNDRNetwork behavior detection and response supportHardware/VM sensors; on-premises platform or cloud service

How it works: Analyzes observed network traffic to detect signs of lateral movement, command activity, and data exfiltration, providing investigation context and integrations that help security teams coordinate containment with enforcement tools.

Deployment: FortiNDR offers on-premises hardware and VM deployments; FortiNDR Cloud is SaaS with supported hardware or virtual sensors. Sensor placement determines the traffic available for analysis.

When to consider it: When network activity needs investigation beyond endpoint coverage, and staff or a service can investigate detections and execute containment.

Coverage matters: Detection depends on sensor visibility into relevant traffic; containment requires an enabled response workflow or integration with an enforcement tool.

Before choosing a model or license

  • Where will mirrored traffic or other supported telemetry come from?
  • What traffic volume and retention are needed?
  • Which tools will enforce containment?
FortiWebWeb request inspection for SQL injectionHardware, virtual, or container WAF

How it works: Inspects web application requests using attack signatures and syntax-based SQL injection detection, allowing configured blocking rules to reject suspicious inputs before they reach a protected application or its database.

Deployment: FortiWeb supports hardware, VM, and container deployments. FortiAppSec Cloud is the separately named SaaS option for application security and should be labeled as such.

When to consider it: When the agency operates web applications or APIs and can place their traffic behind a maintained application-protection policy.

Coverage matters: Requires the application traffic and blocking policy to be covered. For MOVEit, this is a generic SQL injection control fit, not proof it would stop the historical exploit.

Before choosing a model or license

  • Which applications and APIs are under agency control?
  • What HTTP/HTTPS throughput, TLS processing, and availability are required?
  • Who owns policy tuning and application patching?
FortiNACDevice discovery and network access controlHardware or virtual appliance

How it works: Identifies devices on the network and applies access policies through compatible network equipment. Quarantine workflows can restrict a suspicious device while the team investigates.

Deployment: The product line includes hardware appliances and virtual machines, with Control and Application Server functions and separate licensing. Enforcement depends on compatible network integrations.

When to consider it: When device inventory, onboarding, or access restriction is a documented gap across the network.

Coverage matters: Requires compatible network integrations and tested policies. Medical-device changes need clinical safety review; a hospital incident alone does not prove a device visibility gap.

Before choosing a model or license

  • Which switches, wireless systems, and other enforcement devices are supported?
  • How many switch ports and concurrent wireless connections are in scope?
  • How will isolation be tested without disrupting critical operations?

Start with one gap you can verify.

Bring your service priorities, current coverage and a question. We can discuss which technology fits the need.

Request conversation