Facing growing cloud adoption, rising security risks and performance constraints, Emirates National Oil Company Limited (ENOC) undertook a major overhaul of its network architecture. Mohammed Al Rais, CIO at ENOC, outlines how an integrated Secure SD-WAN approach is laying the foundations for scalable, secure growth.
First established in 1993 as a local oil and gas company, Emirates National Oil Company Limited (ENOC), a wholly owned company of the Government of Dubai, has grown to become a leading global player operating across the entire energy value chain. Committed to economic diversification and sustainable development, the group now comprises more than 30 related subsidiaries spanning refining, lubricant blending, storage, aviation and retail. To serve its many thousands of customers across 60 global markets, the organisation employs over 9,000 staff across more than 400 locations.
The need for Digital Transformation
Supporting the ongoing operations of an organisation of this scale requires fast, secure and reliable company-wide access to an increasing number of diverse IT applications and services, running both in-house and in the cloud.
Until 2021, this access was provided to ENOC via a managed networking service based on MPLS, configured in a typical hub-and-spoke architecture in which all external traffic from each branch passed through a single link to the central data centre.
This architecture met basic connectivity needs, with some security controls applied centrally at the hub. However, it lacked the performance, reliability and scalability required to support the group’s ambitious growth plans.
To remain competitive and continue enhancing customer experience through digital innovation, ENOC needed to introduce new services with network demands beyond the capabilities of the existing infrastructure. As more critical applications and services moved to the cloud, unnecessary backhauling through the data centre began to impact user response times, reduce efficiency and ultimately limit service levels for ENOC’s customers.
In addition, the lack of back-up connectivity at branch locations meant that occasional but inevitable link failures led to unacceptable downtime, degrading customer service and consuming valuable IT resources.
Security was another major concern. To keep pace with evolving cyber threats, additional protection measures such as data encryption would need to be layered onto the existing infrastructure, adding cost and complexity while further reducing performance.
Building the foundations for growth
As part of a AED 250 million investment programme launched in 2021, ENOC introduced a Digital Transformation strategy focused on placing customers at the centre of the business and enhancing overall service experience. For Mohammed Al Rais, CIO at ENOC, this required a fundamental overhaul of the organisation’s IT network and security infrastructure.
“We needed a faster, more resilient infrastructure with deeply embedded advanced security, but we also had to achieve this within budget and without increasing management complexity,” said Al Rais.
The most effective solution to ENOC’s wide-area network challenges was the deployment of a software-defined wide area network (SD-WAN). This approach preserved the privacy of ENOC’s MPLS network while enabling faster, lower-cost internet connectivity and direct cloud access at more than 400 remote sites.
However, with SD-WAN traffic no longer routing exclusively through a central security point, the expanded attack surface needed to be addressed through centrally managed yet locally enforced security controls.
Fully integrated networking and security
Following evaluation of several suppliers, ENOC selected Fortinet Secure SD-WAN, built on the FortiGate Next-Generation Firewall (NGFW).
“While several solutions met many of our technical requirements, only Fortinet offered the level of deep integration needed to create a single, secure and manageable SD-WAN infrastructure,” said Al Rais.
With advanced SD-WAN capabilities built into one of the industry’s highest-performing NGFWs, Fortinet Secure SD-WAN enables simplified, single-console management for both networking and security via FortiManager.
By maintaining real-time awareness of network path performance, the solution can intelligently reroute traffic during link failures, ensuring seamless failover and minimising service disruption.
The dedicated security processing unit (SPU) within FortiGate enables accurate identification of thousands of applications, supporting intelligent traffic steering, enhanced quality of service and high-speed, application-aware security processing. FortiManager delivers single-pane-of-glass visibility and control across the entire infrastructure, reducing complexity and total cost of ownership (TCO).
FortiAnalyzer was also deployed to provide actionable analytics and detailed reporting on web traffic, applications, users and threats, supporting regulatory compliance and further reducing operational overhead.


