2026-08-27 · aws-security
AWS announced rule hit count support for AWS Network Firewall, a new capability that shows how often stateful rules are actually triggered. The update targets a common operational problem: security teams often carry large rule sets without clear proof that the controls they depend on are active, useful, or stale. That sounds like a tuning improvement, but it has real preservation implications. When unused or ineffective controls stay in place unnoticed, attackers get more room to move, and the gap between compromise and recovery gets much more expensive.
AWS added rule hit counts for stateful AWS Network Firewall rules, exposing which rules are actively matching traffic and which are consuming capacity without firing. AWS framed the feature as a way to reduce manual log analysis, speed incident response, and provide evidence that controls are functioning for frameworks such as PCI 4.0 and DORA.
Security teams that cannot verify control effectiveness often discover the problem only after an intrusion, lateral movement, or destructive campaign is already underway. In a ransomware or sabotage scenario, blind spots at the network layer can translate directly into corrupted systems, inaccessible backups, and longer recovery windows.
Cold storage is the backstop when live controls fail or are misconfigured. If immutable offline backups, recovery images, and critical key material are held outside the reachable network, attackers who slip past weak or stale firewall rules cannot easily encrypt, delete, or tamper with the last clean copy needed to restore operations.
Read Original Post →