Skip to main content Skip to footer
CyberRatings
  • Research & Testing
    • Test Reports
      Browser Security
      Cloud Network Firewall
      Endpoint Protection
      Enterprise Firewall (formerly NGFW)
      Software-Defined Wide Area Network (SD-WAN)
      Security Service Edge (SSE) Threat Protection
      Zero Trust Network Access (ZTNA)
    • Mini TestsHow effective are the Cloud Service Provider (CSP) native cloud firewall offerings?What does "Secure by Default" mean for Security Service Edge solutions?
Our Ratings SystemResearch
  • Media
    • Blog
    • Press
    • Podcasts & Videos
  • Services
    • Test ToolsCyPerf Trial
  • NSS Labs Archive
0
Log inSign up
CyberRatings
Log inSign up
0
  • CyberRatings
  • Research & Testing
    • Browser Security
    • Cloud Network Firewall
    • Endpoint Protection
    • Enterprise Firewall (formerly NGFW)
    • Software-Defined Wide Area Network (SD-WAN)
    • Security Service Edge (SSE) Threat Protection
    • Zero Trust Network Access (ZTNA)
    • Mini Tests
    • How effective are the Cloud Service Provider (CSP) native cloud firewall offerings?
    • What does "Secure by Default" mean for Security Service Edge solutions?

    • Our Ratings System
    • Research
  • Media
    • Blog
    • Press
    • Podcasts & Videos
  • Services
    • Test ToolsCyPerf Trial
  • NSS Labs Archive
  • Log inSign up
  • CyberRatings
  • Research & Testing
    • Test Reports
    • Browser Security
    • Cloud Network Firewall
    • Endpoint Protection
    • Enterprise Firewall (formerly NGFW)
    • Software-Defined Wide Area Network (SD-WAN)
    • Security Service Edge (SSE) Threat Protection
    • Zero Trust Network Access (ZTNA)
    • Mini Tests
    • What does "Secure by Default" mean for Security Service Edge solutions?

    • Our Ratings System
    • Research
  • Media
    • Blog
    • Press
    • Podcasts & Videos
  • Services
  • NSS Labs Archive
  • Log inSign up

Read the press release on 2025 SSE Test Results

Press

« Back
« Back

New Test of Google Cloud Platform’s Next Generation Firewall Shows Dramatic Improvement

Security effectiveness score jumped from 50.57% to 86.97%.
January 21, 2025CyberRatings.orgPress

 Austin, TX – January 21, 2025 – CyberRatings.org (CyberRatings), the non-profit entity dedicated to providing confidence in cybersecurity products and services through its research and testing programs, has completed a follow up independent “Mini-Test” of Google Cloud Platform’s Next-Generation Firewall (GCP NGFW). This new test follows the same methodology for the test results of three Cloud Service Providers (CSPs) published November 26, 2024. The security effectiveness score for Google’s cloud firewall improved from 50.57% to 86.97%.

“Last November’s cloud native firewall test results from Cloud Service Providers surprised a lot of people, including the product team at Google,” said Vikram Phatak, CEO of CyberRatings.org. “They wanted to understand what had caused their low score, and after reviewing use cases with them, one key recommendation was to modify their firewall’s default behavior,” adds Phatak.

By applying Google’s guidance to modify the firewall’s behavior to block exploits targeting low to high severity vulnerabilities (vs. the default of just triggering alerts for low to medium, and only blocking for high), security effectiveness increased dramatically. Testing was conducted using the same set of exploits as the original test in November using the KeySight CyPerf 5.0 strikes library. Only known Common Vulnerabilities and Exposures (CVEs) from the last ten years with a severity of medium or higher were used to assess security effectiveness, usability, and protection. The exploits (CVE) targeted servers and cloud workload deployments.

“This improvement underscores the value of fine-tuning security settings based on vendor best practice recommendations to maximize protection,” said Ian Foo, CTO and EVP of Product at CyberRatings. “The collaboration exemplifies how open communication, and shared goals can drive positive outcomes. At CyberRatings, we’re proud to work with organizations like Google to help ensure enterprise users benefit from secure and effective cloud-native solutions,” adds Foo.

This updated test for GCP remains in part one of a two-part test. Part two (the comprehensive comparative test) will include a higher number of exploits, along with evasions and malware as outlined in the Cloud Network Firewall Methodology v3.0. The second part of the test is expected to publish in March, comparing cloud service provider native solutions against market leading third-party cloud network firewall providers.

The native firewalls were tested using Keysight’s CyPerf v5.0 software testing platform. Enterprises can easily replicate the results with a 2-week free trial from Keysight. Further details of the strike library can be found here: https://www.keysight.com/us/en/products/network-test/cloud-test/cyperf.html

The test report is available for free at cyberratings.org.

Related content

How effective are the Cloud Service Provider (CSP) native cloud firewall offerings?

November 26, 2024
Mini Test

Exploring Cloud Service Provider Native Firewalls

December 5, 2024
BLOG

CyberRatings.org Announces Test Results for Cloud Service Provider Native Firewalls

November 26, 2024
PRESS RELEASE

CyberRatings.org Announces Test Results for Cloud Network Firewall

April 3, 2024
PRESS RELEASE

2024 Best Practices for Cloud Network Firewall Deployment

April 3, 2024
Configuration Guide

Sign up for our Newsletter

515 South Capital of Texas Highway
Suite 225
Austin, TX 78746

Phone: +1 (512) 333-1734

Fax: +1 (512) 727-2130

Contact Us

Research & Testing

  • Browser Security
  • Cloud Network Firewall
  • Endpoint Protection
  • Enterprise Firewall (formerly NGFW)
  • Software-Defined Wide Area Network (SD-WAN)
  • Security Service Edge (SSE) Threat Protection
  • Zero Trust Network Access (ZTNA)
Mini TestsHow effective are the Cloud Service Provider (CSP) native cloud firewall offerings?What does "Secure by Default" mean for Security Service Edge solutions?Our Ratings SystemResearch

Services

  • Test Tools
  • CyPerf Trial

Media

  • Blog
  • Press
  • Podcasts & Videos

About Us

  • Our Mission
  • Leadership

Research & Testing

  • Browser Security
  • Cloud Network Firewall
  • Endpoint Protection
  • Enterprise Firewall (formerly NGFW)
  • Software-Defined Wide Area Network (SD-WAN)
  • Security Service Edge (SSE) Threat Protection
  • Zero Trust Network Access (ZTNA)
Mini TestsHow effective are the Cloud Service Provider (CSP) native cloud firewall offerings?What does "Secure by Default" mean for Security Service Edge solutions?Our Ratings SystemResearch

Services

  • Test Tools
  • CyPerf Trial

Media

  • Blog
  • Press
  • Podcasts & Videos

About Us

  • Our Mission
  • Leadership

Copyright © 2022 - 2025 CyberRatings.org, All Rights Reserved. Use of this site governed by the Terms of Service

Privacy PolicyCopyright & Quote PolicyCookie Policy
Forgot Password?
Lost your password? Please enter your username or email address. You will receive a link to create a new password via email.
body::-webkit-scrollbar { width: 7px; } body::-webkit-scrollbar-track { border-radius: 10px; background: #f0f0f0; } body::-webkit-scrollbar-thumb { border-radius: 50px; background: #dfdbdb }