Cloud Firewalls Failed Security Tests

New findings show major cloud-based firewalls consistently miss encrypted malware threats.

Updated on Sept. 29, 2026 in Cybersecurity

Isometric editorial illustration showing modular server blocks and network cabling in muted blue and teal, representing complex cloud network infrastructure.
CyberRatings.org reported on September 29, 2026, that nine major cloud network firewalls failed security tests regarding malware detection and encrypted traffic inspection. AI Illustration. Upload story photo >

Live Poll

Do you trust that major cloud firewall providers adequately secure your encrypted data?

CyberRatings.org published a report on September 29, 2026, revealing that nine cloud network firewalls failed to adequately block malware or inspect encrypted traffic. The assessment evaluated products from cloud providers including Amazon Web Services and Microsoft.

Why it matters

As cloud infrastructure increasingly hosts sensitive data, the failure of standard network defenses to handle encrypted traffic represents a significant gap in enterprise security. This study highlights the ongoing difficulty of maintaining robust visibility within complex cloud environments.

The study assessed nine cloud network firewalls against benchmarks for malware inspection, encryption support, and false-positive management. Researchers found widespread failures in the ability to effectively inspect encrypted network traffic.

The players

CyberRatings.org

An independent organization that performs standardized security evaluations and benchmarks for enterprise software and cloud-based products.

Amazon Web Services

A dominant cloud computing platform providing a broad set of infrastructure, storage, and networking services to global enterprises.

Microsoft

A global technology firm providing integrated cloud platforms, enterprise operating systems, and network security solutions.

The details

CyberRatings.org evaluated these tools by testing security effectiveness, TLS support, and false-positive management, where a false-positive is a legitimate request incorrectly identified as a security threat. The firewalls failed to perform deep packet inspection on Transport Layer Security (TLS) traffic—a cryptographic protocol used to secure communications over a computer network. By failing to inspect these streams, the firewalls allowed potentially malicious code to bypass security filters.

Timeline

  1. September 29, 2026: CyberRatings.org published the security findings.

The Tech Race

This assessment challenges the security marketing of major cloud providers by subjecting their proprietary tools to standardized performance benchmarks. It follows a pattern of independent security audits that aim to hold cloud infrastructure providers accountable to uniform threat-protection requirements.

Organizations relying on these cloud firewalls should review their configurations to determine if additional secondary inspection tools are necessary. These results indicate that current default firewall settings may be insufficient for identifying malware hidden within encrypted streams.

The takeaway

The study confirms that reliance on single-layer cloud security remains a risk when facing modern encrypted attack vectors. IT departments should monitor for subsequent manufacturer responses or patches that address these specific inspection failures.

Further reading

For more on the latest trends in network protection, visit Cybersecurity.

Source note: This article includes information reported by Inside Cybersecurity.

Live Poll

Do you trust that major cloud firewall providers adequately secure your encrypted data?

Cloud Firewalls Failed Security Tests | Highwise Tech