The firewall fallacy

Kris Voorspoels, Director of Products & Solutions at OPSWAT, looks at how financial institutions are leaving doors open.

In today’s financial world, connectivity is everything. Whether checking your balance at an ATM, executing a trade from a mobile app, or receiving instant alerts about stock movements, each seamless experience depends on tightly integrated networks. Banks are now woven into a vast ecosystem linking payment gateways, market data providers such as Bloomberg and Reuters, and partner systems across borders. All this is essential to deliver speed, accuracy and convenience for their customers.

But this same interconnectivity that powers modern finance, also broadens the attack surface. Every new API, data feed or digital service adds another potential entry point. The result is a financial system that is more capable than ever before, but also more exposed.

The growing threat to financial institutions

The evidence is clear. The IBM Cost of a Data Breach Report 2024 found that the financial sector suffered the second-highest average breach costs of any industry, at US$5.9 million per incident. In the Middle East, this interconnectedness has accelerated rapidly and with this surge in digitalisation, from mobile banking to instant payments and AI-driven trading, comes a dramatic increase in data exchange and therefore a wider attack surface for threat actors to exploit.

In such a scenario, financial institutions deploy a multi-layered security strategy: endpoint protection, intrusion detection, encryption, zero trust frameworks and of course, firewalls.

Familiar, but flawed

Firewalls have been the foundation of IT security for decades. Their strengths are well known. They act as gatekeepers, inspecting and filtering incoming and outgoing traffic based on pre-set rules. They are flexible, widely understood by IT teams and scalable. It’s no surprise they are a default component in almost every financial institution’s perimeter defence.

But herein lies the problem. Because they are so familiar, and because they have largely stood the test of time, many organisations lean too heavily on them. The thinking seems to be: if it isn’t broken, why fix it? Unfortunately, it may well be broken, or at the very least, badly frayed.

Why firewalls alone fall short

Overreliance on firewalls creates a significant blind spot. Firewalls were not designed to meet the sophisticated threats financial services now face. Attackers have developed a host of techniques that evade or even exploit firewalls, such as application-layer attacks, encrypted malware and insider threats.

Firewalls are software-based, which makes them susceptible to misconfiguration. This is a common problem in complex environments. They also operate bi-directionally by default. That’s fine when you trust both sides of the connection, but dangerous when an attacker has already breached one side and is using the firewall to exfiltrate sensitive data.

Ultimately, a firewall’s job is not to guarantee data integrity or enforce strict one-way flows. It’s simply to filter according to rules. And those rules can be bypassed.

When digital defences need a physical layer

Decades of digital transformation have left many believing that everything can be solved digitally. But just as banks still need both physical branches and mobile apps to fully serve their customers, protecting critical networks requires more than just digital tools. There are physical elements of infrastructure that are equally, if not more, important in keeping data safe.

This is where data diodes come in.

A data diode is a hardware-based security device that allows data to flow in only one direction. Unlike a firewall, which relies on software rules and configurations, a diode is a physical mechanism. By immutable design, they make it impossible for data to flow back. There is no reverse channel to exploit, no configuration error to undo years of planning.

For many in finance, data diodes are still unfamiliar. They are often perceived as slow or overly rigid for the high-speed world of trading. But that perception is outdated. Modern hardware-based diodes, such as those from OPSWAT, can securely transfer data at up to 10 gigabits per second. That’s roughly equivalent to downloading a full-length HD movie in less than a second. That means they can easily handle the demands of real-time trading, risk analysis and regulatory reporting without slowing performance or compromising protection.

Of course, it’s worth noting that because data diodes enforce strict one-way communication, they are not appropriate for every scenario. But for several, high-risk use cases, they are unmatched in their ability to protect sensitive systems while still enabling essential data flows.

Where data diodes shine

Financial institutions can deploy data diodes anywhere sensitive systems must send information out, but never receive data back. For example, they can ensure secure, one-way transfer of market feeds from Bloomberg or Reuters into trading systems, move operational data into backup archives, or send compliance reports to regulators without exposing internal networks.

They’re also invaluable in fraud detection or transaction monitoring, where data needs to be streamed into analytics tools like SPLUNK for real-time analysis without risking a two-way link. Even cloud migration can be made safer by using data diodes to replicate data outward while keeping core systems fully isolated.

Rethinking risk reduction

Firewalls, antivirus tools and other well-established defences have served financial institutions faithfully for decades. But relying solely on these familiar tools is no longer enough. As attackers evolve, the tools and mindsets defending against them must evolve too. What worked in the past may now represent the weakest link. Comfort zones are what cybercriminals are most likely to exploit.

True resilience in the financial sector demands fresh thinking and layered security models that combine digital and physical safeguards. Data diodes represent one such paradigm shift. In an environment where trust underpins every transaction, it’s time to move beyond the firewall mindset. Incorporating hardware-based isolation like data diodes isn’t about replacing what works. Rather it’s about reinforcing it with certainty.

This feature appeared in issue 146 of Security Middle East magazine. 

Tags:
No Comments

Sorry, the comment form is closed at this time.

1