AWSCIO BriefingsRetrospectives

CIO Brief: Network Security Still Matters in the Cloud

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2020, written in 2026 with the benefit of hindsight.

The short version: Cloud servers can usually connect to anywhere on the internet by default. Attackers rely on that to steal data and control compromised systems. AWS released a managed firewall in 2020 that makes restricting outbound traffic much easier.

Why outbound traffic matters

Most security attention goes to stopping attackers getting in. But almost every attack needs to get something out: stolen data, instructions from the attacker's servers, or computing power for crypto mining. If your servers can only talk to approved destinations, many attacks fail even after the initial break-in.

The business impact

  • Reduced data theft if exfiltration paths are blocked.
  • Earlier detection when blocked connections are logged.
  • Containment for new risks, such as AI agents that shouldn't reach the open internet.

Questions to ask your team

  • Can our production servers connect to any website on the internet?
  • Do we log and review outbound connections?
  • Which systems genuinely need open internet access?

What good looks like

Production systems limited to approved outbound destinations, centralized logging of outbound traffic, and alerts for unusual connections.

The decision

Ask your cloud team to pick one sensitive production application and restrict its outbound traffic to what it actually needs. It is a manageable pilot that shows the value — and the effort — clearly.

aws network firewall impactAWS Network Firewall2020

More on this story