CIO Brief: Network Security Still Matters in the Cloud
Retrospective: this article looks back at events from November 2020, written in 2026 with the benefit of hindsight.
The short version: Cloud servers can usually connect to anywhere on the internet by default. Attackers rely on that to steal data and control compromised systems. AWS released a managed firewall in 2020 that makes restricting outbound traffic much easier.
Why outbound traffic matters
Most security attention goes to stopping attackers getting in. But almost every attack needs to get something out: stolen data, instructions from the attacker's servers, or computing power for crypto mining. If your servers can only talk to approved destinations, many attacks fail even after the initial break-in.
The business impact
- Reduced data theft if exfiltration paths are blocked.
- Earlier detection when blocked connections are logged.
- Containment for new risks, such as AI agents that shouldn't reach the open internet.
Questions to ask your team
- Can our production servers connect to any website on the internet?
- Do we log and review outbound connections?
- Which systems genuinely need open internet access?
What good looks like
Production systems limited to approved outbound destinations, centralized logging of outbound traffic, and alerts for unusual connections.
The decision
Ask your cloud team to pick one sensitive production application and restrict its outbound traffic to what it actually needs. It is a manageable pilot that shows the value — and the effort — clearly.
- AWS Network Firewall Goes GA (Nov 2020): Managed Stateful Inspection for VPCs Platform Changes
- How to Deploy AWS Network Firewall in a Centralized Inspection VPC How-To & Hardening
- VPC Egress Filtering Checklist How-To & Hardening