Caught in the Crossfire: How Palo Alto Networks Can Navigate China's Cybersecurity Review
China announced cybersecurity review of Palo Alto Networks
On August 6, the Cyberspace Administration of China’s Office of Cybersecurity Review announced that, in accordance with the National Security Law, the Cybersecurity Law, and the Measures for Cybersecurity Review, it would conduct a cybersecurity review of products sold in China by the U.S. cybersecurity company Palo Alto Networks.
At present, the CAC has not determined that the company’s products pose a national security risk, nor has it announced a blanket sales ban. However, given that the review targets cybersecurity products and that the notice specifically emphasizes “ensuring the safe and stable operation of critical information infrastructure,” government agencies, central state-owned enterprises, and operators of critical information infrastructure in sectors such as finance, energy, telecommunications, and transportation will very likely immediately suspend new purchases pending the review outcome. In commercial terms, this is already close to a de facto temporary restriction.
Palo Alto Networks is headquartered in Santa Clara, California, and is one of the world’s largest specialist cybersecurity companies. Its best-known product is the next-generation firewall. It also offers the GlobalProtect enterprise VPN, the Prisma cloud security platform, the Cortex endpoint detection and security operations platform, the WildFire malware analysis service, and Unit 42 threat intelligence and cyber incident response services. The company reported about $9.22 billion in revenue for fiscal year 2025, making it one of the representative firms in the U.S. cybersecurity industry.
What distinguishes Palo Alto from an ordinary software company is that its products are typically deployed at critical nodes such as enterprise network gateways, data centers, and cloud platforms. Firewalls can identify the applications, users, devices, and communication traffic operating within an enterprise network. VPNs control how employees access internal systems from outside. Security detection platforms, meanwhile, need to continuously collect domain names, IP addresses, attack logs, device status, and even submit suspicious files to the cloud for analysis. These products are not only the “guards” of a company’s network, but also sit at the network’s main gate. If they are secure and reliable, they can block attacks; if they are remotely controlled, stop receiving updates, or are used to collect information, they can also become a channel into the entire network.
Palo Alto’s public documents show that its firewalls can send the company telemetry data on applications, threats, and device operations. WildFire can also upload suspicious files to regional cloud infrastructure for analysis. Palo Alto’s WildFire cloud for the Asia-Pacific region is located in Singapore, and the company has not publicly listed any regional cloud located in mainland China. Although customers can disable some telemetry functions or use localized private cloud appliances, Chinese regulators still need to determine exactly what data products sold in China collect by default, whether such data and file samples are transferred abroad, whether overseas headquarters can remotely access them, and whether the U.S. government could require the company under U.S. law to provide relevant information. Palo Alto products can also be deployed locally, so not all data is automatically sent to the United States. For that reason, these questions require technical review before any conclusion can be reached, and cannot simply be equated with the discovery of a “backdoor.”
Palo Alto does have business operations in China. The company has had offices in Beijing, Shanghai, Guangzhou, and other cities. Public information indicates that it has more than 70 employees in China and has provided firewalls, VPN, and cloud security services to some multinational corporations and large enterprises. For example, Thoughtworks China once deployed Palo Alto firewalls, GlobalProtect, and WildFire for 2,817 employees. Even so, Palo Alto is not a mainstream vendor in China’s cybersecurity market. According to IDC data, China’s cybersecurity hardware market was worth about RMB 21 billion in 2024, and the top five vendors were Sangfor, Venustech, H3C, Huawei, and Topsec, each with a market share above 9 percent. Palo Alto did not rank among the top five. Because the company does not separately disclose its China revenue, the only safe conclusion is that its overall share of the Chinese market is below 9.3 percent, and more likely in the low single digits. It has relatively stronger influence among multinational companies, high-end manufacturers, and customers that require a globally unified network architecture, but in the government, central SOE, and critical information infrastructure markets, it has long been squeezed by indigenous innovation policies and domestic substitution.
In fact, this review did not come out of nowhere. As early as January this year, China had already instructed some domestic institutions to stop using U.S. and Israeli cybersecurity products from Palo Alto, Fortinet, VMware, Check Point, and others. According to reporting at the time, Chinese authorities were concerned that these products might collect sensitive information and transmit it overseas. The formal launch of a review into Palo Alto products by the Office of Cybersecurity Review means that restrictions that had previously been advanced mainly through procurement guidance and domestic substitution are now being converted into a national security review with a clear legal procedure.
As for what specific “bad record” or unfriendly conduct by Palo Alto may have drawn China’s attention, the official notice does not list any concrete facts, so it would be wrong to say that the company was punished because of one particular report or one particular action. Still, public records show at least several areas likely to have raised concern in Beijing.
The most sensitive issue is that Palo Alto’s Unit 42 threat intelligence team has long maintained cooperation with the U.S. government and intelligence community. The company has publicly stated that Unit 42 has established threat intelligence sharing mechanisms with the U.S. Department of Homeland Security, the U.S. intelligence community, and international law enforcement agencies. In 2025, when the U.S. Department of Justice indicted several Chinese citizens and personnel from i-Soon, it specifically thanked Unit 42 for assisting the investigation. From the perspective of a U.S. company, this is a common form of public-private cooperation in cybersecurity. From the perspective of Chinese regulators, however, a U.S. company that may have access to the network traffic, attack logs, and suspicious files of Chinese clients, while also sharing threat intelligence with U.S. homeland security, law enforcement, and intelligence agencies, clearly carries a high degree of national security sensitivity.
Unit 42 has also for years published reports about what it describes as “China-linked hackers” and “Chinese state-backed cyber operations,” attributing multiple campaigns targeting diplomatic entities, telecommunications, government bodies, and critical infrastructure to Chinese-related groups. In 2025, Unit 42 also named a group that had long targeted government and telecom organizations “Phantom Taurus,” and assessed it as having a “China nexus.” China has consistently opposed politicized attribution based solely on attack tools, language traces, working hours, IP addresses, and target selection. It argues that research by U.S. security firms is often used by the U.S. government to prosecute Chinese individuals, sanction Chinese companies, and amplify the narrative of a “China cyber threat.” From Beijing’s point of view, Palo Alto may be seen not merely as a commercial security vendor, but also as an intelligence provider within the broader U.S. cyber policy and law-enforcement system directed at China.
One episode in February this year is especially revealing. Reuters reported that Unit 42 had originally planned to directly attribute a cyber espionage campaign affecting 37 countries to Beijing, but Palo Alto management worried about triggering further Chinese retaliation and ultimately described the actor in the final report only as a “state-linked group active in Asia.”
In addition, Palo Alto products have in recent years suffered several serious vulnerabilities that were actively exploited in the wild. CVE-2024-3400 allowed an unauthenticated attacker to execute code with the highest privileges on certain firewalls. CVE-2024-3393 could cause firewalls to reboot repeatedly. After that, the PAN-OS management interface and GlobalProtect also saw a string of problems including authentication bypass. Several of these were added by the U.S. Cybersecurity and Infrastructure Security Agency to its Known Exploited Vulnerabilities catalog. These vulnerabilities do not prove that Palo Alto intentionally planted backdoors; any large cybersecurity product can have vulnerabilities. But because firewalls sit at the network perimeter, once compromised they pose risks far beyond those of ordinary application software, so they naturally become a focus of Chinese review.
The most relevant precedent for this review is Micron. In March 2023, China announced a cybersecurity review of Micron products sold in China. About seven weeks later, regulators concluded that the products posed relatively serious cybersecurity risks and required operators of critical information infrastructure in China to stop purchasing them. Whether Palo Alto will face the same outcome remains unclear. Under the Measures for Cybersecurity Review, regulators will focus on whether its products could lead to illegal control of, interference with, or damage to critical information infrastructure; whether supply could be interrupted for political or diplomatic reasons; and whether important data could be stolen, leaked, or unlawfully transferred abroad. If Palo Alto can demonstrate that data flows are controllable, that products can be fully deployed locally, that overseas headquarters cannot remotely interfere, and that the company will ensure continued supply and comply with Chinese law, it is still possible that the review could be cleared subject to remedial conditions. Even so, given that notices to stop using its products had already appeared in January, the probability of eventual restrictions on procurement by critical information infrastructure operators is not low.
Politically, this cybersecurity review is closely aligned with the logic behind China’s recent retaliation against FCC-related restrictions. In recent years, the United States has repeatedly invoked “national security” to restrict Chinese telecom equipment, routers, inverters, robots, testing laboratories, and cybersecurity firms from entering the U.S. market. China is now also beginning to use its own tools of cybersecurity review, certification, entity lists, and export controls to impose more concrete reciprocal restrictions on U.S. companies. The Compliance Testing case was a named retaliation against a promoter of FCC policy. The CCC measure was a reciprocal response within the certification system. The Palo Alto review goes one step further, extending scrutiny to U.S. cybersecurity products and their ability to control data.
For Palo Alto, the direct economic loss may not be very large. Its Asia-Pacific and Japan business accounts for only about 12 percent of global revenue, and China is just a relatively small part of that. When the January stop-use news emerged, Palo Alto’s share price barely moved, which also suggests that investors do not see China as central to the company’s growth story. But the symbolic significance of this case is much larger than the short-term revenue impact: an American security company whose business is to protect networks has now itself become the object of a Chinese cybersecurity review. Taken together, these signs suggest that China is carrying out a cross-departmental, layered, “portfolio-style” retaliation strategy: naming and punishing U.S. firms involved in designing and promoting restrictive policies, creating reciprocal barriers for U.S. certification bodies, and formally reviewing U.S. security products that can enter China’s critical networks and access sensitive data.
If I were Palo Alto Networks’ Head of Government Affairs in China, I would try to move the discussion as quickly as possible away from geopolitical disputes and back toward product security and data compliance issues that can actually be verified, while taking several concrete steps in parallel.
The first step would be to fully cooperate with the review and submit, as soon as possible, the data-flow diagrams for the products sold in China, the network architecture, the software update mechanism, the scope of any remote access from outside China, telemetry fields, how file samples are handled, encryption key management, a bill of materials for third-party components, and records of vulnerability remediation. The Cybersecurity Review Measures explicitly require product suppliers to provide supplementary materials, with a focus on assessing risks such as unlawful control, supply disruption, cross-border data transfer, and influence by foreign governments. Refusing, delaying, or offering only high-level statements will almost certainly raise the probability of failing the review.
The second step would be to propose a genuinely executable “China edition” remediation plan. The point is not to make broad promises like “we protect privacy,” but to technically isolate sensitive capabilities. For example: deploy WildFire, log analytics, and threat intelligence service nodes within mainland China so that file samples and raw logs do not leave the country; disable device telemetry, automatic sample uploads, and cross-region metadata sharing by default, letting customers opt in; provide a fully localized, offline private-cloud version for critical information infrastructure operators; ensure that Chinese customers’ logs, keys, and administrative privileges are controlled by the China-based team and cannot be remotely accessed directly by headquarters abroad; complete security checks, signature verification, and distribution of software updates and threat signatures within China; and provide field-level explanations for any data that must be transmitted cross-border, completing procedures such as the security assessment for outbound data transfers or Standard Contract filings.
Palo Alto Networks currently hosts its WildFire regional cloud for Asia-Pacific in Singapore and allows firewalls to submit files and telemetry data, which is likely to be the easiest point to challenge during a review. The company already provides local WildFire regional clouds in other countries and also offers private-cloud appliances, which suggests that building a China-localized solution is not technically impossible.
The third step would be to accept independent security testing conducted within China. Palo Alto Networks could proactively propose that China-recognized third-party institutions test source code, firmware, the upgrade mechanism, data transmission interfaces, remote maintenance functions, and the supply chain, and produce reports on vulnerabilities and outbound data-transfer risk. If needed, the company can provide a controlled environment for source-code review or a code-hosting mechanism, but it should avoid handing over the complete source code outright, because that would involve intellectual property, could trigger U.S. export controls, and may introduce global security risks for the company. A more realistic approach is to provide a read-only review environment, restrict who can access it and for what purposes, and retain full operation logs.
The fourth step would be to launch targeted remediation around recent product vulnerabilities. The company should explain the root causes, impact scope, remediation timelines, and China-based device patching rates for CVE-2024-3400, CVE-2024-3393, and subsequent vulnerabilities in PAN-OS and GlobalProtect, and provide free inspections, patch upgrades, and configuration hardening for critical information infrastructure customers. The key is to demonstrate that these were general product defects that have been fixed, rather than covert access capabilities, while also establishing a local mechanism in China for rapid disclosure and remediation after critical vulnerabilities are discovered.
The fifth step would be to address concerns about “U.S. government influence and supply disruption.” China’s worry is not only cross-border data transfer, but also whether, if U.S.-China relations deteriorate, Palo Alto Networks might stop providing licenses, cloud services, vulnerability fixes, and security signature updates to customers in China under U.S. government orders. The company can make legally binding commitments: unless explicitly prohibited by law, it will not unilaterally terminate services for political or diplomatic reasons; it will stock replacement devices and upgrade servers in China; it will allow key customers to keep core functions running even if disconnected from the internet; and if U.S. export controls do affect delivery, it will notify customers in advance and provide a transition period. However, Palo Alto Networks cannot promise to violate U.S. law, so it needs to state any unavoidable risks truthfully rather than making commitments it cannot keep.
The sixth step would be to clarify the relationship between Unit 42 and the product business. China will find it hard to accept a company that collects threat data from customers in China while also sharing related intelligence with the U.S. Department of Homeland Security and law enforcement and intelligence agencies. Palo Alto Networks can establish clearer internal separation: raw data from customers in China should, in principle, not enter Unit 42’s global intelligence pool; before sharing any information involving Chinese customers with foreign governments, it should conduct reviews under Chinese law and outbound data-transfer requirements; it should manage commercial product data, incident response data, and public threat research separately; it should apply public, consistent, and verifiable evidentiary standards for attributing attacks to nation-state actors; and where alternative explanations cannot be ruled out, it should avoid elevating overlaps in language, time zones, or tools into direct nation-state attribution.
This does not mean the company must stop researching Chinese cyberattacks, nor should it alter research conclusions simply to preserve market access. The key is to demonstrate that customer data collected by its products will not automatically become an intelligence source for the U.S. government targeting China. Previously, the company was reported to have weakened an attribution report out of concern about Chinese retaliation, which instead can make both sides doubt the independence of its research.
The seventh step would be to immediately protect existing customers. After a review is initiated, even if there is no legal requirement for a full shutdown, government bodies, central SOEs, and large enterprises may freeze procurement. Palo Alto Networks should explain to customers whether existing products can continue operating, whether cloud services and patches will remain normal, what alternative plans exist, and provide localized operation, data export, and migration support for critical infrastructure customers. The worst move would be to abruptly stop services or restrict customers from exporting configurations and logs, because that would directly validate China’s concern about supply disruption.
On policy communications, Palo Alto Networks can use its China subsidiary, the American Chamber of Commerce, and professional technical institutions to explain the situation to regulators, but it should not place its main hopes on diplomatic pressure from the U.S. government. Publicly framing the review as “retaliation” could politicize an issue that might otherwise still be solvable through technical remediation. Legal challenges are also not the first choice: the Cybersecurity Review Measures do not provide a very clear corporate appeal process, and once national security is involved, administrative litigation is unlikely to change the substantive judgment.
In the end, three outcomes are possible. The best outcome is passing the review after remediation, but critical information infrastructure operators would be permitted to procure only a specific version that is locally deployed and has overseas telemetry disabled. A middle outcome is that ordinary commercial customers may continue to use the products, but government bodies, central SOEs, and critical infrastructure operators would be prohibited from new procurement. The worst outcome would resemble Micron’s case: the products fail the review, critical infrastructure operators stop purchasing, and existing customers gradually replace them.
Given Palo Alto Networks’ overall market share in China is not high, the company could financially exit the China market, but that would be the worst way to resolve the situation — though under today’s geopolitical realities, it may also be an unfortunate option.


